70RDAD20R00000014_ Revised_RFP_1SEP2020.pdf

PDF 2 MB Posted

Attached to
FOIA Workflow as a Service (FWaaS) Platform Federal contract opportunity
Solicitation number
70RDAD20R00000014
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This is a combined synopsis/solicitation from the Department of Homeland Security seeking offers for a Freedom of Information Act Workflow as a Service platform. Key details include:

  • The platform must be a cloud-based Software as a Service solution to support FOIA case management and electronic discovery activities. Pricing is fixed price by line item for hosting, licenses, project management and technical support over one base year and four option years.

  • Responses are due August 18 with anticipated award by September 4. The solution must integrate with DHS systems and support at least 500 concurrent users with potential growth to over 2,000.

  • Required capabilities include public user account management, FOIA request submission and tracking, fees calculation, redaction tools, reporting and dashboards. The platform must meet federal IT security and Section 508 standards.

  • Offerors must complete representations and certifications through SAM and submit pricing on the provided schedule. Questions are due by August 12 with responses only to the contracting officers. The acquisition is not small business set aside.

View the file

Other files for this federal contract opportunity

Other files attached to FOIA Workflow as a Service (FWaaS) Platform, newest first.
File Type Posted
FWaaS-QuestionsSupplemental - 20200901- Final Clarification.pdf PDF
70RDAD20R00000014_SF30_0002.pdf PDF
70RDAD20R00000014_SF30_0001.pdf PDF
Final Questions_Answers for DHS Privacy Office - FWaaS_20200813.pdf PDF
70RDAD20R00000014_RFP Conformed_3AUG2020.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

(x)

70RDAD20R00000014

x x copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted ; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGEMENT TO BE RECEIVED AT

THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted , such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.

x

Washington DC 20528-0115

DHS/OPO/DEPT.OPS

245 Murray Lane, SW, #0115 Dept. Operations Acquisition Div.

Office of Procurement Operations U.S. Dept. of Homeland Security

09/01/20200003

13. THIS ITEM ONLY APPLIES TO MODIFICATION OF CONTRACTS/ORDERS. IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

12. ACCOUNTING AND APPROPRIATION DATA (If required) is not extended.is extended, Items 8 and 15, and returning

Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended , by one of the following methods: (a) By completing

The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS

FACILITY CODE CODE

10B. DATED (SEE ITEM 13)

10A. MODIFICATION OF CONTRACT/ORDER NO.

9B. DATED (SEE ITEM 11)

9A. AMENDMENT OF SOLICITATION NO.

CODE

8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)

7. ADMINISTERED BY (If other than Item 6)CODE 6. ISSUED BY

PAGE OF PAGES

4. REQUISITION/PURCHASE REQ. NO.3. EFFECTIVE DATE2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO. (If applicable)

1. CONTRACT ID CODE

AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT

07/31/2020

CHECK ONE A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority) appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

E. IMPORTANT: Contractor is not, is required to sign this document and return __________________ copies to the issuing office.

ORDER NO. IN ITEM 10A.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

The purpose of Amendment 0003 is a follows:

1) Incorporate Responses to Vendor Questions for Clarification,

2) Incorporate Revised Request for Proposal - 70RDAD20R00000014_1SEP2020 which includes the

DHS Special Contract Clauses and the removal of Sections 2.3.23 and 4.7.

16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)15A. NAME AND TITLE OF SIGNER (Type or print)

15C. DATE SIGNED 16B. UNITED STATES OF AMERICA 15B. CONTRACTOR/OFFEROR 16C. DATE SIGNED

(Signature of person authorized to sign) (Signature of Contracting Officer)

Janice Brinkley

STANDARD FORM 30 (REV. 10-83)

Prescribed by GSA

FAR (48 CFR) 53.243

NSN 7540-01-152-8070

Previous edition unusable

Except as provided herein, all terms and conditions of the document referenced in Item 9 A or 10A, as heretofore changed, remains unchanged and in full force and effect .

TEL: EMAIL: 202-254-6783 janice.brinkley@hq.dhs.gov

Combined Synopsis Solicitation 70RDAD20R00000014

Privacy and Freedom of Information Act Processing System

Amendment to Solicitation

ATTACHMENT A

SECTION I – SCHEDULE B

1.0 Pricing Schedule

Base Period (12 months)

IAW

SOW

CLIN Description Quantity Unit Price Extended Price

2.1.1 – 2.1.10,

2.3 – 2.6

0001 Platform Hosting 12

2.1.1 – 2.1.10,

2.3 – 2.6

0002 Licenses 500

2.1.1 – 2.1.10,

2.3 – 2.6

0002A (Optional) Surge CLIN - Firm Fixed Price

- Licenses

2.1.1 – 2.1.10

0003 Project Management (PMP) 12

2.1.1 – 2.1.10

0004 Technical Architect 12

2.1.1 – 2.1.10

0005 Technical SME 12

2.1.1 – 2.1.10

0006 Sr. Developer 12

Base Period Total

Option Period One

(12 months)

IAW

SOW

CLIN Description Quantity Unit Price Extended Price

2.1.1 – 2.1.10,

2.3 – 2.6

1001 Platform Hosting 12

2.1.1 – 2.1.10,

2.3 – 2.6

1002 Licenses 500

2.1.1 – 2.1.10,

2.3 – 2.6

1002A (Optional) Surge CLIN - Firm Fixed Price

- Licenses

2.1.1 – 2.1.10

1003 Project Management (PMP) 12

2.1.1 – 2.1.10

1004 Technical Architect 12

2.1.1 – 2.1.10

1005 Technical SME 12

2.1.1 – 2.1.10

1006 Sr. Developer 12

Option Period One Total

Option Period Two

IAW

SOW

CLIN Description Quantity Unit Price Extended Price

2.1.1 – 2.1.10,

2.3 – 2.6

2001 Platform Hosting 12

2.1.1 – 2.1.10,

2.3 – 2.6

2002 Licenses 500

2.1.1 – 2.1.10,

2.3 – 2.6

2002A (Optional) Surge CLIN - Firm Fixed Price

– Licenses

2.1.1 – 2.1.10

2003 Project Management (PMP) 12

2.1.1 – 2.1.10

2004 Technical Architect 12

2.1.1 – 2.1.10

2005 Technical SME 12

2.1.1 – 2.1.10

2006 Sr. Developer 12

Option Period Two Total Option Period Three

(12 months)

IAW

SOW

CLIN Description Quantity Unit Price Extended Price

2.1.1 – 2.1.10,

2.3 – 2.6

3001 Platform Hosting 12

2.1.1 – 2.1.10,

2.3 – 2.6

3002 Licenses 500

2.1.1 – 2.1.10,

2.3 – 2.6

3002A (Optional) Surge CLIN - Firm Fixed Price

– Licenses

2.1.1 – 2.1.10

3003 Project Management (PMP) 12

2.1.1 – 2.1.10

3004 Technical Architect 12

2.1.1 – 2.1.10

3005 Technical SME 12

2.1.1 – 2.1.10

3006 Sr. Developer 12

Option Period Three Total

Option Period Four

IAW

SOW

CLIN Description Quantity Unit Price

Extended Price

2.1.1 – 2.1.10,

2.3 – 2.6

4001 Platform Hosting 12

2.1.1 – 2.1.10,

2.3 – 2.6

4002 Licenses 500

2.1.1 – 2.1.10,

2.3 – 2.6

4002A (Optional) Surge CLIN - Firm Fixed Price

– Licenses

2.1.1 – 2.1.10

4003 Project Management (PMP) 12

2.1.1 – 2.1.10

4004 Technical Architect 12

2.1.1 – 2.1.10

4005 Technical SME 12

2.1.1 – 2.1.10

4006 Sr. Developer 12

Option Period Four Total Total Proposed Price

Base Period + Option Periods One through Four Total

*Personnel are equal to a Full Time Equivalent (FTE) of 1,920 labor hours

SECTION II – STATEMENT OF WORK

Contents

1.1 Objective

1.2 Scope

1.3 Background

2 Requirements

2.1 General Requirements

2.1.1 Graphical User Interface (GUI)

2.1.2 Data Exchange

2.1.3 Purge and Archive

2.1.4 Data Management and Storage

2.1.5 Data Migration

2.1.6 Public Access and Public User Account Creation

2.1.7 FOIA Case management

2.1.8 Internal Government User Features

2.1.9 Architecture

2.1.10 System Requirements

2.2 Access to Unclassified Facilities, IT Resources, and Sensitive Information

2.3 Security

2.3.1 Compliance with DHS IT Security Policy Terms and Conditions

2.3.2 Encryption Compliance Terms and Conditions

2.3.3 Security Review Terms and Conditions

2.3.4 Interconnection Security Agreements Terms and Conditions

2.3.5 Required Protections for DHS Systems Hosted in Non-DHS Data Centers

2.3.6 Security Authorization Terms and Conditions

2.3.7 Enterprise Security Architecture Terms and Conditions

2.3.8 Continuous Monitoring Terms and Conditions

2.3.9 Specific Protections Terms and Conditions

2.3.10 Vulnerability Assessments Terms and Conditions

2.3.11 Malware (e.g., virus, spam) Terms and Conditions

2.3.12 Patch Management Terms and Conditions

2.3.13 Log Retention Terms and Conditions

2.3.14 Personal Identification Verification (PIV) Credential Compliance

2.3.15 Controls

2.3.16 General Security Responsibilities for Contract Performance

2.3.17 Configuration Management (hardware/software)

2.3.18 Federal Desktop Core Configuration

2.3.19 Certification and Accreditation

2.3.20 Information Technology Security Performance

2.3.21 Security Policy and Architecture

2.3.22 Data Stored/Processed at Contractor Site

2.3.23 SBU Data Privacy and Protection

2.3.24 Disposition of Government Resources

2.3.25 Erasure of Classified Data

2.3.26 Contractor Personnel……………………………………………………………………………………………………. 32

2.3.27 Key Personnel……………………………………………………………………………………………………………….. 32

2.3.28 Replacement of Key Personnel……………………………………………………………………………………….33

2.3.29 Continuity of Support……………………………………………………………………………………………………..33

2.3.30 Employee Identification………………………………………………………………………………………………….34

2.3.31 Employee Conduct………………………………………………………………………………………………..………..34

2.3.32 Removing Employees for Misconduct or Security Reasons……………………….……….………..….34

2.3.33 Other Applicable Conditions: …………..………………………………………………………..…….…………….34

2.3.34 Security……………………………………………………………………………………………………………………….34

2.3.35 Requests for Exception to U.S. Citizenship Requirement……………………………………………...34

2.3.36 Post-Award Instructions Regarding Security Requirements for Contracts/Orders……..…35

2.4 Safeguarding of Sensitive Information (MAR 2015):

2.4.1 Applicability

2.4.2 Definitions

2.4.3 Authorities

2.4.4 Handling of Sensitive Information

2.5 Information Technology Security and Privacy Training (MAR 2015):

2.5.1 Applicability

2.5.2 Security Training Requirements

2.5.3 Privacy Training Requirements

2.6 Section 508 Compliance

2.6.1 Information and Communications Technology (ICT): FOIA Privacy Act System

2.6.2 Installation, configuration or integration services for ICT

2.6.3 Maintenance upgrades, substitutions, and replacements to ICT

2.6.4 Developing or modifying ICT for the government

2.6.5 Developing or modifying web and software ICT

2.6.6 Developing or modifying ICT delivered in electronic format

2.6.7 Developing or modifying software that generates electronic content

2.6.8 Commercially available Information and Communications Technology (ICT)

2.6.9 ICT developed, modified, installed, configured, integrated, or hosted by contractor

2.6.10 Commercially available authoring tool offered that generates electronic content

2.6.11 Acceptance Criteria

3 Deliverables

4 Service Level Agreement

4.1 Continuity of Operations (COOP)

4.2 Availability

4.3 Case Priority

4.4 Response Time

4.5 Maintenance and Technical Support:

4.6 Data availability upon termination of contract

4.6.1 Data Portability

4.6.2 Transition Services

4.7 Security Breach Notification

5.0 Contract Kick-Off Meeting….……………………………………………………………………………………………….…64

1.1 Objective

The Contractor shall provide to the Department of Homeland Security, Privacy Office (PRIV), in accordance with this Statement of Work, a Software as a Service (SaaS) platform to support the activities associated with processing Freedom of Information Act (FOIA) requests. The services shall include FOIA management and electronic discovery (e-Discovery) capabilities that are required to search and review functions as part of request processing. In addition, the Contractor shall provide project management, data migration and integration activities, and help desk support.

1.2 Scope

The Contractor shall provide a SaaS solution hosted in a FedRAMP authorized cloud provider.

Connectivity between DHS OneNet to the SaaS shall be provisioned, operated, and monitored by the Contractor. The Contractor shall be responsible for all operations, enhancement, maintenance, planning, implementation, and security validations to ensure FOIA operations and the SaaS meet all service level agreements.

1.3 Background

DHS PRIV is the first statutorily required comprehensive privacy office in any U.S. Federal agency. It operates under the direction of the Chief Privacy Officer and Chief FOIA Officer, who is appointed by the Secretary of Homeland Security. PRIV serves as a steward of Section 222 of the Homeland Security Act of 2002, as amended, and has programmatic responsibilities with the Privacy Act of 1974, as amended;

the Freedom of Information Act; Public Law 110-93; White House and U.S. Department of Justice memoranda; provisions of the E-Government Act; and DHS policies that protect the collection, use, and disclosure of personal information.

In addition to the privacy-related mission, it is responsible for DHS-wide disclosure policy development, training, and FOIA processing for senior-level headquarters offices. DHS consistently receives the largest number of FOIA requests of any federal department or agency, receiving almost 40 percent of all requests within the Federal Government. DHS and its components currently have approximately 450 staff and processes approximately 385,000 FOIA, Privacy, and other requests per year. The number of pages DHS released in response to initial requests was almost 35 million pages in fiscal year 2018. The scope of each search can range from one page to one terabyte of records.

Given the volume and complexity of the matters that are handled, PRIV has a substantial need for e- Discovery and FOIA solution to manage requests. The service needs to support:

Configuration to meet specific PRIV needs;

Integration with DHS communications to support data exchange, user access, and reporting;

Provides end-to-end FOIA case processing and tracking;

Ease of use to ensure rapid and consistent adoption by personnel; and Accommodate at least 500 simultaneous users with the capability to increase beyond 2,000 users.

The SaaS must facilitate the collection, identification, review and production of electronically stored information (ESI) for the DHS FOIA workflow. These services include:

Identifying and removing duplicate data;

Ensuring electronic documents are in a searchable format;

Searching and filtering large amounts of ESI;

Bates numbering; and Ensure production of ESI in native format.

All ESI is trackable and metadata is tagged throughout the FOIA processing lifecycle.

2 Requirements

2.1 General Requirements

The Contractor shall provide a service that supports the FOIA case management lifecycle and all associated activities. A high-level illustration of the FOIA case management lifecycle is described in Figure 1 below. The service shall meet the detailed requirements and function with the service level agreements (SLAs) listed within this document.

Figure 1. FOIA Case Management Lifecycle

2.1.1 Graphical User Interface (GUI)

The system shall exhibit industry standard web design attributes for user-friendly interfaces with clear, plain language instructions.

2.1.2 Data Exchange

2.1.2.1 Data Ingestion and Processing

The offeror shall provide a system that affords data ingestion and processing:

2.1.2.1.1 Collections: The system shall provide for data collection that allows users to upload data into the FOIA Workflow as a Service (FWaaS).

2.1.2.1.2 The system shall not require customization or substantial configuration for basic use.

2.1.2.1.3 Use by end-users: The system shall be able to be used by end-users no later than five business days after final operating capability.

2.1.2.1.4 The system shall allow users to upload data. The system shall load native files (and at a minimum 200GB per workstation/server in a 24-hour period) and the Contractor shall provide their system's upper limit in their response to this SOW. Also, the system shall load e-mail files (at least PST, MSG, NSF, EML, DBX and at a minimum 200GB per workstation/server in a 24-hour period) and the Contractor shall provide their system's upper limits.

2.1.2.1.5 Data and metadata extraction: During the data loading process, the system shall automatically extract text and metadata from DHS systems : I.e., all Microsoft Office, TIFs, JPGs, GIFs, PDFs, BMP, Corel WordPerfect (wpd), XML, HTML, RTF, DAT, CSV, VCF, PNG, PSD, PCT, DB, DBF, ZIP, SIT, TMP, EML, MSG (individual email files) and PST, OST (email archive files).

2.1.2.1.6 Loading metadata values: During the data loading process, the system shall load metadata values without modifying the original document or changing system and document metadata values.

2.1.2.1.7 Files unable to be processed: During the data loading process, the system shall identify any files unable to be processed in a log file with the reason why the file could not be processed;

such as, unknown file type, or password-protected.

2.1.2.1.8 Extraction from native files to prepopulate fields in the system: During the data loading process, the application shall extract text from all native files (including Email messages) and load all text in a field. The system shall extract metadata about the native files and load it in the fields. The system shall create a separate record for each native file. During the data loading process, the system shall uniquely number the native files, email messages and attachments in a field.

2.1.2.1.9 Load Exception Files and Problem Reports: The system shall create load exception files (i.e.

non-supported, corrupted, password-protected) and include exception fields describing the problem; extract metadata available; and create a link to the native file. During the auto data loading process, the system shall provide a problem file report to include the file name and path of the document and problem description.

2.1.2.1.10 Decryption: During auto load process, the system shall automatically decrypt encrypted files (i.e. route file paths to separate server where password cracker system resides).

2.1.2.1.11 Document Identification: The system shall identify documents with tracked changes; hidden rows; hidden columns; and hidden text including font text that is the same color as the background (typically white on white).

2.1.2.1.12 Statistics: The system shall store statistics upon data load such as document types and number of documents in the repository, date documents were loaded and provide ability to generate report on that information real time. Also, the system shall store statistics upon data load such as number of emails and number of attachments and provide ability to generate report on that information.

2.1.3 Purge and Archive

The offeror shall provide a system/solution that enables purge and archive of data:

2.1.3.1 Ability to archive and retrieve completed and closed requests and purge based upon NARA defined schedule and criteria.

2.1.3.2 Ability to set and adjust retention schedules based on NARA approved records retention schedules.

2.1.3.3 Ability to schedule the running of purge and archive jobs.

2.1.4 Data Management and Storage

The offeror shall provide a solution that provides the following data management capabilities:

2.1.4.1 Allow users to search the database for information on FOIA and Privacy requests and similar correspondence.

2.1.4.2 Store, display and maintain the full contents and current status of each request received, including the complete copy of the request and any attachments.

2.1.4.3 Store, display and maintain metadata regarding the request, (i.e., date of receipt of the request, name of requester, etc.)

2.1.4.4 Store, display and maintain requester information (i.e. such as name, address, and email address (email address must be a required field when collecting data)).

2.1.4.5 Store, display and maintain due dates for responses to requesters (initial and expedited processing, and appeals).

2.1.4.6 Store, display and maintain initial determination letter to the requester.

2.1.4.7 Store, display and maintain copies of clean responsive records and redacted responsive records.

2.1.4.8 Store, display and maintain administrative appeals and agency appeals decisions.

2.1.4.9 Store, display and maintain identify of duplicate requests.

2.1.4.10 Store, display and maintain the classification/categorization of requests, appeals, and other types of correspondence in the system.

2.1.4.11 Ability to track and age requests and referrals.

2.1.4.12 Store, display and maintain a history of documents (i.e., original documents, working documents, final documents with and without metadata).

2.1.4.13 Store all documents in a compressed manner to reduce the amount of storage and transmitted.

2.1.5 Data Migration

The offeror shall provide data migration support:

2.1.5.1 Migrate legacy data (~10 Terabytes of FOIA data and stored responsive records and history).

2.1.5.2 Deliver a Data Migration Plan, which includes an overall design and plan for a successful, end to end data migration process, and migration schedule.

2.1.5.3 Define procedures for and execute data profiling, data quality assessments and data enrichment processes and perform/assist in carrying these out.

2.1.5.4 Provide expertise in business and system data reconciliation strategies and execution across multiple test phases.

2.1.5.5 Provide expertise in target data store architecture and optimization.

2.1.6 Public Access and Public User Account Creation

The following features are to be performed by public users. Please refer to Figure 1. The offeror shall provide a system/solution in which public user accounts may be managed:

2.1.6.1 Provide a secure browser-agnostic web-based solution for public access.

2.1.6.2 Allow public to retrieve FOIA records and other documents and correspondence via secured account-based access.

2.1.6.3 Allow the public to create a multi-factor authentication secure user account.

2.1.6.4 Ability to allow a person to submit a FOIA request, upload required documents for submission, check their status of requests, retrieve documents once completed, request an appeal etc.

2.1.6.5 Receive and log-in requests, including duplication detection, metadata tracking, on-line review and redaction, and billing.

2.1.6.6 Ability for the public to attach documents to requests.

2.1.6.7 Ability to post commonly requested documents/information to a web reading room.

2.1.6.8 Ability to track (on-line) FOIA and Privacy request through intake, processing and completion.

2.1.6.9 Ability to authenticate the identity of requester when personally identifiable information (PII) is requested.

2.1.6.10 Ability for the service to deliver invoices to the account for requested information.

2.1.6.11 Ability to exchange data with Pay.Gov to track payment status.

2.1.6.12 Ability for the requester to select delivery options (electronically or postal delivery) for a given request.

2.1.6.13 Provide account lifecycle management and help desk support.

2.1.6.14 Ability to transfer FOIA and Privacy requests to other Component and Office users throughout the system.

2.1.6.15 Ability to provide public and secure private reading rooms for responses to requests.

2.1.6.16 Ability to transfer responsive records from the processing application to the public/private reading rooms (as required by law).

2.1.6.17 Ability to develop notifications such as banners to be displayed to provide notifications to users regarding system status, change in processing, etc.

2.1.6.18 Ability to set retention schedules on public and private reading rooms allowing administrators to change the schedule per NARA guidelines.

2.1.6.19 Ability to integrate with FOIA.gov (as required by law) with secure login and multi-factor authentication.

2.1.6.20 Ability to share and integrate data with other systems as needed via Application Programming Interfaces (API).

2.1.7 FOIA Case management

The following features are to be performed by DHS users. Please refer to Figure 1.

2.1.7.1 Administration

2.1.7.1.1 Ability for administrators to override data values as part of role-based FOIA processing.

2.1.7.1.2 Support record modification using role-based permissions.

2.1.7.1.3 Ability to delete records based on role-based permissions.

2.1.7.1.4 Ability for users to add custom data fields.

2.1.7.1.5 Ability for user to input requests through a configurable User Interface.

2.1.7.1.6 Ability to conduct full text searches.

2.1.7.1.7 Ability to create user defined and maintained redaction templates.

2.1.7.1.8 Ability to provide options for document headers, footers, watermark, and review flags and comment.

2.1.7.1.9 Ability to receive, scan, log, track and manage requests, including duplication detection and duplication consolidation, metadata tracking.

2.1.7.2 Fees

The offeror shall provide a system/solution that supports fee and invoice transaction management via Pay.gov as applicable. The Contractor’s service must compute fees associated with a given FOIA request. During the processing FOIA requests, the Contractor’s solution shall generate an invoice that incorporates all activities associated with the request.

2.1.7.2.1 The vendor’s solution shall provide the ability to assign a fee for the time required to complete the request on an hourly basis and quantity of data returned.

2.1.7.2.2 At the completion of the request, the solution shall generate an invoice that reflects the level of effort required to complete the request, the quantity of data returned, and delivery to the requester.

2.1.7.2.3 Ability to receive invoices, access account information and make secure payments through a single, unified electronic point of access.

2.1.7.2.4 Ability to exchange data with Pay.Gov in order to track FOIA fee payment status.

2.1.7.2.5 Compute, generate, and track invoices and fees.

2.1.7.3 Identify Authentication

The offeror shall provide a system/solution that provides identity authentication:

2.1.7.3.1 Ability for multi-factor authentication to identity of requester (through self-certification) when PII is requested.

2.1.7.3.2 Ability for requesters to create accounts in a secure environment, enter information regarding the request (including PII), authenticate their identity, and attached relevant documentation to items received via that come in via mail, delivery service or Electronic fax.

2.1.7.4 Processing Categories

The offeror shall provide a system/solution that affords the ability to categorize and track at least three different types of request such as simple, complex, expedited for both FOIA and Privacy requests.

2.1.7.5 Roles Based User Access

The offeror shall provide a system/solution in which user access may be managed:

2.1.7.5.1 Ability to establish and maintain multi-level role-based access control and privileges, including the ability to add, modify and delete (manage) users from within the system in real-time.

2.1.7.5.2 Ability to configure screens displays so that only the information needed by the current user is displayed and unnecessary information is excluded from sight.

2.1.7.6 System Interfaces

The offeror shall provide a system/solution in which system interface may be managed:

2.1.7.6.1 Ability to add, modify or delete (manage) interfaces and APIs with other systems.

2.1.7.6.2 Ability to accept scanned documents in an image format for processing, including importing files into the system from our existing data stores (i.e., PDF files). All files and images uploaded and scanned into the system must be scanned via automated virus and malware scanners that detect all industry known threats.

2.1.7.6.3 Ability to refer request and request consultation electronically within DHS and across other Federal Agencies.

2.1.7.6.4 Ability to store and exchange data in open standard formats and with minimal latency to support integration with other potential systems.

2.1.7.7 Unique Identifier

2.1.7.7.1 Ability to Assign a unique identifier to requests, tasks, appeals, or any part of a case.

Identifier must contain information to assist the user in identifying characteristics of the data including year, component, and type.

2.1.7.7.2 Ability to automatically reset the year component of the unique identifier/case number.

2.1.8 Internal Government User Features

2.1.8.1 Research, Analysis

The offeror shall provide the following functions workflows within the system:

2.1.8.1.1 Ability to track and organize FOIA requests through an account-based FOIA Request Submission and Tracking process.

2.1.8.1.2 Ability to require users to establish an account prior to submitting a FOIA request. If a requestor has previously submitted FOIA request(s), ability to enforce them to log-on to their pre-established account.

2.1.8.1.3 Ability to enter FOIA and Privacy requests and appeals into the system.

2.1.8.1.4 Ability to create cases using an integrated workflow capability.

2.1.8.1.5 Ability to track FOIA and Privacy requests through intake, processing, and completion.

2.1.8.1.6 Ability to automatically and manually assign and transfer cases among employees and automatically notify employees when work is available.

2.1.8.1.7 Ability to identify duplicate records at intake of new cases and automatically notate both cases and merge records as needed.

2.1.8.1.8 Ability to process appeals using an integrated workflow capability.

2.1.8.1.9 Ability to link related requests (original, duplicates, follow-ups, or appeals).

2.1.8.1.10 Provide means to search, identify, and display similar FOIA and Privacy requests and correspondence.

2.1.8.1.11 Store, display, and maintain the full contents and current status of each request received, including the complete copy of the request and any attachments.

2.1.8.1.12 Store, display, and maintain metadata regarding the request. (e.g., date of receipt of the request)

2.1.8.1.13 Store, display, and maintain requester information such as name, address and email address (email address must be a required field when collecting data).

2.1.8.1.14 Store, display, and maintain due dates for responses to requesters (initial and expedited processing and appeals).

2.1.8.1.15 Store, display, and maintain initial determination letter to the requester.

2.1.8.1.16 Store, display, and maintain copies of clean responsive records and redacted responsive records.

2.1.8.1.17 Store, display, and maintain administrative appeals and agency appeals decisions.

2.1.8.1.18 Store, display, and maintain identify of duplicate requests.

2.1.8.1.19 Store, display, and maintain the classification/categorization of requests, appeals, and other types of correspondence in the system.

2.1.8.1.20 Ability to track and age requests and referrals.

2.1.8.1.21 Store, display, and maintain a history of documents (e.g., original documents,).

2.1.8.2 Queries

The offeror shall provide a system/solution that affords query capability:

2.1.8.2.1 Ability to view the real-time the status of a case within any given workflow.

2.1.8.2.2 Ability for a user to drill down to review/log/audit data at the user level through a User Interface.

2.1.8.2.3 Conduct searches of the database for information on all requests, and similar correspondence, or cases with metadata.

2.1.8.3 Redaction Tool/Capabilities

The offeror shall provide a system/solution that provides redaction capabilities:

2.1.8.3.1 Ability to find, redact, strike through or highlight one or many documents simultaneously.

2.1.8.3.2 Allow for electronically citing exemptions when redacting.

2.1.8.3.3 Maintain count of pages, redacted pages, and exemptions used.

2.1.8.3.4 The system should ingest and redact file sizes anywhere from 1 KB to 2TB.

2.1.8.3.5 Ability to redact polygon shaped objects.

2.1.8.3.6 Ability to create and configure exemption or marking codes through a drop-down menu option.

2.1.8.3.7 Ability to create and configure multiple exemptions or marking codes through a drop-down menu option.

2.1.8.3.8 Ability to view exemption codes that have been applied to pages.

2.1.8.3.9 Ability to report on the number of exemption codes that have been applied by case.

2.1.8.4 General Document and File Review

The offeror shall provide a system/solution that provides file review capabilities:

2.1.8.4.1 Native/Image Document Review: The system shall have the ability to review files in native format and image format.

2.1.8.4.2 Mixed Media Formats: The system shall provide support for review of mixed media formats including audio and video.

2.1.8.4.3 Admin Created Fields/Tags: The system shall have the ability to create fields/tags that can be associated with documents and objects subject to review. The system shall provide functionality for bulk tagging.

2.1.8.4.4 Universal - Integrated Document Viewer: The system shall have an integrated document viewer that allows users to open and display a variety of documents in their native format without the need for the original application that was used to create the document.

2.1.8.4.5 File and Object Properties - Metadata Search: The system shall have functionality that enables users to search and filter on metadata of files and objects.

2.1.8.4.6 Web-Based Application: The system shall have web-based document review. This review shall be available without the need to download and install client system or agent (an exception to this requirement is made for the off-line review functionality specified in section 10.1.7).

2.1.8.4.7 Off-Line Document Review: The system shall allow documents and objects subject to review to be downloaded for offline review.

2.1.8.4.8 Bates Numbering: The system shall have functionality that provides users the option of Bates stamping documents and objects. It shall include the ability to run reports that indicate Bates number gaps (missing Bates numbers), Bates number overlaps (Bates number appears on multiple documents), and invalid Bates ranges or numbers and modify Bates numbers based on overlaps, gaps, and invalid ranges. It shall also include functionality to retain sets of Bates-stamped un-redacted documents.

2.1.8.4.9 Document Redaction: The system shall have the ability to make redactions to multiple documents as well as on an individual basis. Redaction commenting, privilege log creation, and other features shall also be available for bulk redactions. Redactions shall remain visible until they are published or produced, at which time they are burned onto images. If a document goes through multiple iterations of redaction, the application shall maintain each iteration of the redacted document. The application shall also maintain un-redacted versions of documents.

2.1.8.4.10 Redaction Commenting: The system shall have the ability to create comments and codes associated with redactions and allow users the option to include the code or comment in the redaction box when documents are published.

2.1.8.4.11 De-Duplication/Un-dupe Functionality: The system shall have functionality to de-duplicate multiple data types custodially or globally to reduce workload. The product shall also provide the ability to un-duplicate data. This shall also apply to the processing of e-mails. The system shall also indicate whether multiple custodians had an identical document (i.e. a CUSTODIANALL field can be populated). In addition, the system shall identify near-dupes (electronic files with "near duplicate" similarities, yet some differences in terms of content or metadata, or both). Examples shall include document versions, emails sent to multiple custodians, different parts of email chains, or proposals sent to several clients.

2.1.8.4.12 Page-Specific Review: The system shall have the ability to jump to a specific page of a document for review without the requirement to traverse a document.

2.1.8.4.13 Back-up and Restore Functionality: The system shall have the ability to back up reviewed documents and be able to restore backed-up documents.

2.1.8.4.14 Audit Trail / Chain of Custody: The system shall have the ability to track all user actions through the entire document review and production process.

2.1.8.5 Search Capability

The offeror shall provide a system/solution that provides search capability:

2.1.8.5.1 Keyword Searches: The system shall have the ability to locate documents and information based on keywords.

2.1.8.5.2 Boolean, Proximity, and Fuzzy Searches: The system shall have the ability to use the Boolean operators "AND, "OR", or "NOT" in searches. The system shall have the ability to conduct proximity searches that allow for searches based on the proximity of words in a sentence, paragraph or page.

2.1.8.5.3 Wildcard Searches and Results based on Possible Variations: The system shall have support for wildcard characters in searches and provide results for all matching variations of the wildcard search.

2.1.8.5.4 Multiple query searches: The system shall have functionality that runs multiple queries simultaneously and provides results for the entire search as well as for the individual queries.

2.1.8.5.5 Search Filters: The system shall have the ability to filter the results of searches by individual queries or variations.

2.1.8.5.6 Search Report: The system shall track and document the execution of searches.

2.1.8.5.7 Hit-Highlighting: The system shall highlight search terms in the result set. This feature shall be available for textual documents as well as e-mail.

2.1.8.6 Reporting and Dashboards

The offeror shall provide a system/solution in which reporting is available:

2.1.8.6.1 Permits import and export of data and reports to and from desktop and server applications

2.1.8.6.2 Automatically produce draft and final versions of annual Department of Justice (DOJ) FOIA Report and backup data.

2.1.8.6.3 Provide live Dashboard reports (as required by DOJ) and reports pertaining to user and component metrics.

2.1.8.6.4 Ability to configure and develop custom reports or exports without impacting other users and the daily workflow (i.e., tracking/reporting user actions, including modification/deletion history).

2.1.8.6.5 Ability to produce dashboards showing activities by user within the workflows.

2.1.8.6.6 Display cases by track and sub branch identifiers.

2.1.8.6.7 Ability to track performance per case and overall use of the system by activity and by finite time.

2.1.8.7 Case Management/Workflow Client

2.1.8.7.1 Track and organize FOIA requests through an account-based FOIA Request Submission and Tracking process.

2.1.8.7.2 Require users to establish an account prior to submitting a FOIA request. If a requestor has previously submitted FOIA request(s), ability to enforce them to log-on to their pre-established account.

2.1.8.7.3 Ability to enter FOIA and Privacy requests and appeals into the system.

2.1.8.7.4 Ability to create cases using an integrated workflow capability.

2.1.8.7.5 Ability to track FOIA and Privacy requests through intake, processing, and completion.

2.1.8.7.6 Ability to automatically and manually assign and transfer cases among employees and auto notify employees when work is available.

2.1.8.7.7 Ability to identify duplicate records at intake of new cases and automatically notate both cases and merge records as needed.

2.1.8.7.8 Ability to process appeals using an integrated workflow capability.

2.1.8.7.9 Ability to link related requests (original, duplicates, follow-ups, or appeals).

2.1.8.8 Calculations/Reminders:

The offeror shall provide the following calculation functions within the system:

2.1.8.8.1 Ability to auto-calculate due dates based on configurable criteria, such as request type.

2.1.8.8.2 Ability to issue a reminder to follow up on consultation cases.

2.1.8.8.3 Ability to calculate expedited and fee waiver adjudication periods.

2.1.8.8.4 Ability to automate reminders for case deletion based on National Archives and Records Administration (NARA) approved retention guidelines.

2.1.8.8.5 Ability to provide estimated dates for completion based upon real-time data completion rates by individual office, component or department.

2.1.8.9 Correspondence

2.1.8.9.1 Ability to use templates to generate correspondence.

2.1.8.9.2 Ability for the user to create and use email document templates to deliver document to multiple internal/external recipients.

2.1.8.9.3 Ability for user to communicate with requester through email and chat functions.

2.1.8.9.4 Ability to create 508 compliant correspondence.

2.1.8.9.5 Ability to suppress the printing of a responsive record where entire page is being withheld in full under an applicable exemption.

2.1.8.9.6 Ability to suppress the printing of a responsive record where entire page is being referred to appropriate federal agency.

2.1.8.10 Legal Hold

The offeror shall provide a system with Legal Hold capability:

2.1.8.10.1 Create and Customize Legal Holds: The system shall allow the ability to create and customize (by administrators) legal holds and create and add notifications according to recipient types.

2.1.8.10.2 Legal Hold Templates: The system shall allow the ability to create legal hold templates.

2.1.8.10.3 Tracking Status: The system shall have the ability to track the status of legal holds in a dashboard interface.

2.1.8.10.4 View Report Notification Activity: The system shall have the ability to view report notification recipient activity. It shall include viewing survey results, statistics and responses.

Also, it shall allow generation, export and download of legal hold and defensibility data (i.e.

issuance, acknowledgments and reminder dates).

2.1.8.10.5 Archive and Restore: The system shall have the ability to archive and restore old or previously inactive legal holds and update custodian lists as needed.

2.1.8.11 Configuration

2.1.8.11.1 The offeror shall provide a system that allows DHS System Administrators to configure it to meet DHS needs and standards.

2.1.9 Architecture

The offeror shall work with DHS and third-party vendors to determine the best architecture. The offeror shall produce and update as needed the following documents:

2.1.9.1 System Design Document

2.1.9.2 Concept of Operations (CONOPS)

2.1.9.3 Functional Requirements Document

2.1.9.4 Network diagrams

2.1.9.5 FOIA processing Work flows

2.1.9.6 User Acceptance & Quality Assurance Plan

2.1.9.7 Login & Role-Based Access Rules and Methods

2.1.9.8 IT Help Desk Instruction and Points of Contacts

2.1.9.9 System Security Plan

2.1.9.10 508 and Security Requirements: Any documents that are required to attain final DHS Authority to Operate (ATO) per DHS IT Security and 508 Compliance policies.

2.1.9.11 Change Control documentation: The Contractor shall submit and represent all Change Requests to the appropriate DHS Control Boards, such as the DHS Infrastructure Change Control Board, documenting all changes, presenting the changes, and then following ICCB- or DHS-required change control protocols and methods.

2.1.10 System Requirements

2.1.10.1 Administrative Tools

The offeror shall provide a system that provides administrative functions:

2.1.10.1.1 Ability to monitor system and resource utilization, including processing times and pending requests.

2.1.10.1.2 Ability to provide full restart capabilities, database access activity logging and transaction back out capabilities.

2.1.10.1.3 Ability to collect and track the metrics associated with FOIA effectiveness. These metrics are statistics as reported to the US Attorney General and the Office of Government Information Services for the annual Fiscal Year Freedom of Information Act Report.

2.1.10.2 Application Support

The offeror shall provide a system where application production support is defined as the completion of activities required to maintain the applications operational and responsiveness to the user components.

2.1.10.3 Authentication

The offeror shall provide a system that has authentication capabilities:

2.1.10.3.1 Ability to provide secure processing for requests and public/private reading rooms.

2.1.10.3.2 Ability for system to provide a platform-agnostic application interface for use on mobile devices.

2.1.10.3.3 Ability to prevent threats from robots and scan all attachments for viruses.

2.1.10.4 Audit Trails

The offeror shall provide a system/solution which has audit trail capability:

2.1.10.4.1 Ability to generate and maintain audit logs including the sources of all data modification, including additions, changes, and deletions.

2.1.10.4.2 Ability to archive and retrieve completed and closed requests.

2.1.10.4.3 Search for data, with appropriate indicators displayed to the user based on acceptance of search criteria.

2.1.10.4.4 Search for data, with appropriate indicators displayed to the user based on progress of the search.

2.1.10.4.5 Ability to retain metadata associated with native files.

2.1.10.4.6 Ability to ingest files with a range from several KB to 500GB without impacting system performance.

2.1.10.5 Cloud Interface

The offeror shall provide a system/solution that utilizes cloud-based storage and meets the following cloud specifications:

2.1.10.5.1 Cloud environment must be FedRamp certified.

2.1.10.5.2 Cloud service provider must, at a minimum, adhere to DHS’s security architecture constraints.

2.1.10.5.3 DHS will retain full ownership of its data stored in the vendor cloud environment and shall have access to their data at all times. The vendor must ensure it has the ability to provide a complete copy of DHS’s data upon written request.

2.1.10.5.4 The FOIA Cloud environment must allow for data and FOIA processing partitions specific to individual Components, while also allowing aggregation of data, completed FOIA requests, and processing metrics to be gathered at the Enterprise level. This includes Data controls and access policies to determine where data can be stored and who can access physical and virtual locations.

2.1.10.5.5 Cloud service provider must provide clear pricing of storage and processing bandwidth increases and redundancy options to accommodate higher demand and higher overall utilization. This includes documentation of demand or usage patterns for cloud services utilized and pricing models for each service type with detailed specifications.

2.1.10.5.6 DHS must be informed in writing if their data is going to be used by the SaaS vendor for any non-DHS purpose such as internal benchmarking purposes.

2.1.10.5.7 Ability to integrate with common administrative tools (e.g., MS Outlook and MS Office).

2.1.10.6 Expandability

The offeror shall provide a system that can process over 145,000 cases per year with an estimated growth of 4 – 5 TB of data storage annually.

2.1.10.7 Integration and Interoperability

The offeror shall provide a system that has the ability to interface with existing systems to pull data or documents.

2.1.10.8 IT Security

The offeror shall provide a system that conforms to the requirements of DHS application security. ) The system must comply with Federal and DHS requirements for maintaining privacy of Personally Identifiable Information (PII). The system shall be capable of conforming to the NIST 800-53 “Moderate” security requirement. Additionally, the system must be able to integrate with DHS’s Identity, Credentialing, and Access Management (ICAM) capabilities to provide PIV-enabled access to services.

The system must also be able to obtain an Authority to Operate (ATO), ability to interpret FISMA Scans, recommend and prepare solutions to be applied, and the ability to delete records based on role-based permissions that control user access, which includes the ability to delete records from the database, file stores, and all instance of a record including backups.

2.1.10.9 DHS Enterprise Architecture Compliance

The offeror shall provide a system/solution that meets DHS Enterprise Architecture (EA) policies, standards, and procedures. Specifically, the contractor shall comply with the following Home Land Security (HLS) EA requirements:

2.1.10.9.1 All developed solutions and requirements shall be compliant with the HLS EA.

2.1.10.9.2 All IT hardware and software shall be compliant with the HLS EA Technical Reference Model (TRM) Standards and Products Profile.

2.1.10.9.3 Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Architecture Division for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.

2.1.10.9.4 Development of data assets, information exchanges, and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

2.1.10.9.5 Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

2.1.10.10 Notifications

The offeror shall provide a system/solution that provides the capability to store and retrieve Personally Identifiable Information (PII) data and provide email notification to sending and receiving parties. This should include the ability to create PDFs of responsive records and the ability to interface with other applications.

2.1.10.11 Performance

The offeror shall provide a system with the following performance characteristics:

2.1.10.11.1 System should also leverage file types that include text layers (I.e.DOC, XLS, RTF, TXT,) as options for machine-reading actions such as keyword searching.

2.1.10.11.2 The system should convert prepared, redacted documents to flat image files.

2.1.10.11.3 The system shall provide real-time access to and searchable within five seconds, with appropriate indicators displayed to the user of search acceptance and progress.

2.1.10.11.4 Maintenance and enhancements to the system shall be applied without interruption to the user.

2.1.10.11.5 Ability to access data real-time by over 2,000 users.

2.1.10.12 Scalability

The offeror shall provide a system/solution that may be appropriately scalable to incorporate additional users. The system would need to accommodate approximately 400 users with a possible increase to over 2,000 users. Vendor should allow for standard annual termination for convenience, annual usage level alignment, monthly “roll-over” plans to address spikes and dips in usage, and long-term price protection. DHS retains the ability to scale usage up and down as needed during the term of the cloud subscription agreements. As usage decreases, the SaaS vendor shall provide DHS with the ability to reduce its commitment to align with actual need at that point in the term, with a corresponding reduction of the fees or a credit towards future usage.

2.1.10.13 Scanning

The offeror shall provide a system that has scanning features:

2.1.10.13.1 Ability to scan in documents in an image format for processing.

2.1.10.13.2 All image files uploaded into a DHS enterprise FOIA system should be at least 300 dpi and in full color.

2.1.10.13.3 Ability to leverage use of Optical Character Recognition (OCR) technologies and automated processing methods.

2.1.10.13.4 The solution must be able to…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .