Attachment I and Statement Work Revised.pdf
PDF 610 KB Posted
- Attached to
- DHS Mentoring Platform Federal contract opportunity
- Solicitation number
- 70RDAD22Q00000210
About this file
This is a solicitation for a commercial mentoring platform to support the Department of Homeland Security's mentoring program. The contractor shall provide a Software as a Service solution that is FedRAMP authorized or compliant and includes a mentoring platform, hosting, security updates, customer support, and accessibility compliance. The base period of performance is one year with four optional one-year extensions. The contract will be a firm fixed price purchase order awarded on a best value basis considering technical approach, past performance, and price. The solicitation targets small businesses and has a NAICS code of 511210. Quotes are due by September 19th and award is expected on or around September 23rd. The contractor must meet security and IT requirements and provide program support, a guided mentoring experience, and administrative resources through the platform.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment VI Amendment 002 Vendor Questions and Government Responses.pdf | ||
| Attachment IV Past Performance Information Form.docx | DOCX document | |
| Attachment V Schedule B and Statement Work Revised.docx | DOCX document | |
| Attachment II Revised Solicitiation and Synopsis.pdf | ||
| Attachment III Questions and Government Responses.pdf | ||
| Combined Synopsis and Solicitation-70RDAD22Q00000210.pdf | ||
| Attachment I and Statement of Work.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ATTACHMENT I
Schedule B and Statement of Work Revised
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 1 of 52
Schedule B
Schedule of Contract Line Items Numbers (CLINs)
CLIN Description Quantity Unit Unit Price Extended
Price
The Contractor shall provide Mentoring Program Support to include a personalized and configurable mentoring platform, including ongoing hosting, security updates, award winning customer support, WCAG 2.1 AA Compliance, and relevant product developments in accordance with the Statement of Work.
0001 Mentoring Program Support and Commercial SaaS Mentoring Platform (Note: The Period of Performance for the base year may be less than 12 months and billing shall not commence until ATO Approval. This CLIN will be prorated based on when proposed Mentoring Platform receives DHS ATO approval.)
12 MO
0002 Authorization to Operate (ATO) 1 LO 0003 One (1) Time Setup 1 LO 1001 Option Year I: Mentoring Program
Support and Commercial SaaS Mentoring Platform
12 MO
2001 Option Year II: Mentoring Program Support and Commercial SaaS Mentoring Platform
12 MO
3001 Option Year III: Mentoring Program Support and Commercial SaaS Mentoring Platform
12 MO
4001 Option Year IV: Mentoring Program Support and Commercial SaaS Mentoring Platform
12 MO
TOTAL
Request for Quotation 70RDAD22Q00000210
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 0 of 52
STATEMENT OF WORK (SOW)
Mentoring Program Support and Commercial SaaS Mentoring Platform
1.0 INTRODUCTION
The Department of Homeland Security (DHS) has recognized the need to continue a Mentoring Program as part of the leadership and succession programs within the Office of the Chief Human Capital Officer’s (OCHCO) Learning, Education, and Development Strategy Office (LEADS). The Mentoring Program supports the Department’s human capital goals, and the Chief Human Capital Officer’s (CHCO) priorities relating to leadership development, diversity, and career planning. The program will continue to address the potential loss of institutional knowledge through retirements and other employee attrition, enhance leadership skills, and encourage a culture of learning and sharing within the Department.
The Mentoring Program supports the Office of Personnel Management’s (OPM) requirements for the Pathways Program and DHS’s Cornerstone Program, as well as other priority programs within the Department.
DHS wants to create a modernized, software-based mentoring program that will significantly improve efficiency and availability and create strategic value to the organization. The system will enable an all-inclusive, open communication network across all participants who are matched using algorithms and filters based on member preferences. The capability to automate matching and communications allows a structured, manageable enterprise-wide program resulting in a sustainable mentoring program.
Additionally, a modernized software-based mentoring program creates strategic value providing business analytics to gauge the health of the mentoring connections and the overall program. In addition, mentoring is a low-cost approach/option to enhance employee engagement, morale, and wellness.
1.1 SCOPE
The contractor shall provide a compliant commercial Software as a Solution (SaaS) mentoring program product. The product shall be scalable and configurable to DHS needs. The commercial product shall have a demonstrated industry presence with quantifiable results such as case studies or customer reports.
The product shall have a framework to provide connections with a guided experience through a mentoring relationship. The product shall have the capacity to hold up to 24,000 profiles. The product shall employ a data-driven architecture to allow analytics on all data entered. The product shall employ an algorithmic-based capability to optimize matching. The product shall be fully app enabled supported on Android and IOS devices, meet DHS compliance requirements, and be accessible from all workstations, regardless of domain (.gov, .mil, .com etc). Provide dedicated staff for major program elements, and a 24x7 tech support staff for routine queries.
DHS requires the following capabilities from a commercial software-based mentoring program:
Matching Algorithm Software that provides an algorithm that automatically suggests best match options by analyzing data in each participant profile. Software that allows matching based on factors such as location, unit, rank, gender, ethnicity, availability, duration of partnership, education, experience, expertise, etc. Algorithms in the software that will match thousands of participants simultaneously which is humanly impossible with the current manual program.
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 1 of 52
Reporting & Analytics Software that provides a full suite of business data analytics that provides robust reports highlighting various indicators of program satisfaction and connection health/effectiveness. The data quickly tracks and analyzes the performance of the mentoring program and provides senior leaders metrics for oversight.
Automated Surveys Software that enables a more agile mentoring program by automatically surveying participants at pre-defined intervals. Providing automated survey results conveyed in a way that’s easy to digest; visually allowing managers and participants to determine the health of the program.
Automated Communications Software that automates targeted emails and reminder communications which can be scaled enterprise-wide.
Mobile Responsiveness & Mobile Apps Convenience to access all mentoring tracks and resources to increase enrollment. Scaling all content to be Mobile-enabled and responsive.
1.2 OBJECTIVE
The objective of the DHS Mentoring Program is to prepare employees for future leadership position at DHS, to enhance current capabilities and engagement, and to begin creating a mentoring culture within the agency that is integrated with other learning and development programs, leadership philosophies, and overall organizational goals. The Mentoring Program is intended to:
• Develop a diverse, high-performing workforce to support succession planning
• Establish and institutionalize a DHS workforce with a platform to enable connection to a mentor in DHS
• Provide a platform that will allow access, connection methods, and a plan for mentoring pairs to guide them in their relationship
• Increase the number of senior executives and managers who serve as mentors
• Provide another vehicle for employee professional and personal growth to augment
• Enhance the leadership, coaching, and interpersonal skills of both mentors and mentees
• Promote the development of career paths and achievement of goals
1.3 Period of Performance
The period of performance for this contract is one (1) twelve-month base period and four (4) twelve-month option periods.
1.4 Place of Performance
The primary place of performance will be contractor’s facilities with occasional visits to the DHS facilities in the Washington Metro Area.
2.0 SPECIFIC REQUIREMENTS/TASKS
Provide a Commercial SaaS Enterprise Mentoring platform with the following capabilities:
• The ability to publish a DHS Consent to Use and Monitoring Flash Screen as condition of logging in and having system access
• Provide full Admin roles for DHS administrators, to employ fast and agile system changes
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 2 of 52
• Provide admin ability to monitor PII/HIPAA/OPSEC/spillage
• Provide admin ability to create fully customizable profile fields
• Provide an algorithm-based matching process that can be automated, semi-automated, or manual
• Provide ability for multiple mentoring sub programs with walled –off metrics (i.e., Communities, reverse, flash, and one to one)
• Provide an integrated survey feedback system that is administratively customizable
• Provide confidential user messaging to Administrative
• Provide the capability to log and track mentoring meetings/times/dates for DHS reporting
• Provide the ability to export program data and analytics
• Provide IOS/Android supported device applications (app) integration and access
• Provide a framework to enable admins to monitor connection health for accountability and feedback
• Provide a capability to deploy digital data resources such as documents, videos, and podcasts
• Provide a means of having each mentoring connection complete a mentoring partnership agreement within the system electronically
• Provide the ability to set and track mentoring connection goals
• Provide ability for all users to take notes in various areas in the system
• Provide ability for users to capture reflective notes on their interactions
• Provide the ability to advertise and market program events and updates
• Provide the ability to administer/organize/conduct group mentoring for specific targeted topics/groups with the same data collection
• Provide a customizable program executive dashboard and individual track dashboards to collect and display key admin-defined performance indicators and outcome metrics
• Provide the ability to conduct training and interactive system/program user guides
• Provide full data transparency on all data collected for business intelligence analytics, including every field of data entered by any participant and system interaction metrics (logins etc.)
• Provide consulting representative for program build-out and monitoring throughout the contract term
• Provide help-desk support to remedy technical issues
• Meet DHS information technology compliance certifications,
• Work towards becoming FEDRAMP and DISA compliant
• Enables all eligible DHS federal employees to apply to the Mentoring Program using an online form for program participants
• Provides participants’ (mentor/mentee) profile information representative of meaningful data for future reporting within the program
• Provides a program calendar and reminders of mentoring events to program participants to ensure timely program submission
2.1 Provide a Single Commercial Software as a Service (SaaS) Mentoring Platform
2.1.1 Must be a Commercial Software as a Service solution that requires no software or hardware from
DHS.
2.1.2 Must be accessible from any desktop, tablet, or mobile device. Must have a dedicated mobile device app for Apple and Android devices. Being ‘web-optimized’ is not acceptable as a mobile device use.
2.1.3 The Contractor must be able to be branded to DHS specifications and have a customized DHS
URL.
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 3 of 52
2.1.4 The Contractor must provide a variety of configurable mentoring formats (one-to-one, circle mentoring, situational mentoring, etc.). Configuration ability must be enabled to DHS admins for building to the unique formats, types, and needs of DHS program. These formats must be able to support potential DHS Strategic goals for mentoring such as (but not limited to): career development, recruiting, leadership development, retention, diversity and inclusion, professional development, executive development, knowledge transfer, coaching, and networking.
2.1.5 Provide the ability for different matching types. These types must include self-matching, admin matching, and algorithm-based automated matching. System must allow user level filtering based on any of the profile field components.
2.2 TASK TWO. Provide a Guided Experience
2.2.1 The contractor shall provide a facilitation holistic relationship for mentees and mentors to follow in their mentoring relationship. All elements of the connection framework must be admin customizable.
2.2.2 The connection framework should be in the form of a user-friendly reference checklist, tailored to a time-based connection. For example, the beginning to the checklist may include (1) resources/tips on how to break the ice for having a successful mentor/mentee relationship, (2) reminders to set up a communication plan and routine, (3) tips for setting up a first meeting, etc. The connection plan should also allow for situations such as prompting survey completion, goal setting, recurring meeting scheduling, and healthy ways to close out a relationship.
2.2.3 The Contractor shall provide a suite of connection matching capabilities. At a minimum, the contractor shall provide a system allowing for (1) self-selected matches, (2) admin selected matches, and
(3) an automated matching algorithm using customer-supplied weighted criteria.
2.2.4 The Contractor shall provide a means to schedule meetings that has the capability to sync with standard calendar programs like outlook, google calendar etc.
2.2.5 The Contractor shall provide a means to communicate through the platform in the form of messaging.
2.2.6 The Contractor shall provide a means for connection partners to keeps notes/reflections on their relationship.
2.3 TASK THREE. Administrative Resources
2.3.1 The Contractor shall provide a dedicated customer service representative to work with DHS Admin for system setup, configuration, design, and front-end build work. This representative shall be a primary partner for program marketing, launching and enrollment. This representative shall be a conduit for programmatic issues during the execution phase of the mentoring program.
2.3.2 The Contractor shall provide Live Technical Help Desk support and resources 24x7. This service shall be used to provide technical help to Admins.
2.3.3 The Contractor shall provide strategic consulting in evaluating program performance for future improvements, at a minimum of annually.
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 4 of 52
2.3.4 The Contractor shall provide a Library capability within the interface based on a standard electronic file hierarchy. The library structure should be configurable to the customer’s needs of structure, access, warehousing, and curating.
2.3.5 The Contractor shall provide a library that shall be initially furnished with standard documents and user guides for users to help indoctrinate them and provide guidance for using all aspects of the platform.
2.3.6 The Contractor library shall also be configurable with the ability for the customer to populate specific program resources. These mentoring training resources may be in the form of any standard document type, presentation, video, or audio podcasts
2.4 TASK FOUR. Data and Analytics
2.4.1 The Contractor shall provide a suite of analytic and reporting software tools that can look at data at the following levels: individual, connection (mentor/mentee), mentoring communities (i.e., one-to-one), global program (all sub-programs together). Data must be exportable to other desktop applications. Data must be stored and backed-up for the duration of the contract
2.4.2 The Contractor shall provide a flexible data architecture that will allow data to be collected and analyzed based on DHS strategic mentoring goals and Key Performance Indicators. Examples of data to be included is static enrollment data, fluid connection engagement data, and customer satisfaction and all other survey data.
2.4.3 The Contractor shall provide a fully customizable enrollment profile form. The contractor shall have all standard suite of question formats - i.e., select one, multiple choice, ordered options, date, multiple lines, etc.).
2.4.4. Provide a fully customizable survey system. Shall have all the standard suite of question formats (i.e., select one, multiple choice, ordered options, date, multiple lines, etc.).
2.5 Post Award Conference
The contractor shall attend a Post Award Conference no later than ten (10) business days after the date of award or as otherwise scheduled by the Contracting Office. The purpose of the Post Award Conference, which will be chaired by the Contracting Office, is to discuss contractual objectives of this Purchase Order. The Post Award Conference will be held via teleconference or Microsoft Teams. The Post Award Conference, may or may not be held concurrently with the Kick-Off meeting as scheduled by the Contracting Office.
2.6 Kick-Off Meeting
The purpose of the Kick-Off meeting, which will be chaired by the Contracting Officer’s Representative, will be to discuss technical requirements and to review the Contractor's draft implementation plan. The Kick-Off meeting will be scheduled by the COR. The Kick-Off meeting will be held in person, virtually via Microsoft Teams, or via teleconference. The date and time will be provided after award by the COR. Upon award of the Purchase Order, the contractor shall contact the COR and coordinate the date, time, attendees and agenda for the conference.
2.7 Implementation Plan (Project Plan)
The Contractor shall provide a draft Implementation Plan at the Kick-Off meeting for Government review and comment. The plan, at a minimum, shall include: (a) list of work to be performed;(b) project
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 5 of 52 schedule; (c) description of intended results; (d) role of key personnel, if applicable and (e) how quality of service (project) will be maintained throughout life of contract. The Vendor shall provide a final Implementation Plan to the COR not later than 14 business days after the Government’s approval of the draft.
3.0 CONTRACTOR PERSONNEL
3.1 Qualified Personnel
The Contractor shall provide qualified personnel to perform all requirements specified in this SOW. The Government requires that all Contractor personnel positions be filled in accordance with Section III, 8.0 Deliverables and Delivery Schedule. All personnel shall have a security clearance obtained before working on any task.
3.2 Key Personnel
3.2.1Replacement of Key Personnel Before replacing any individual designated as Key by the Government, the Contractor must notify the Contracting Officer and the COR no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes must possess qualifications equal to or superior to those of the Key person being replaced.
The Contractor must not replace Key Contractor personnel without acknowledgment from the Contracting Officer.
3.2.2 Project Manager
The Contractor shall provide a Project Manager who shall be responsible for all Contractor work performed under this SOW. The Project Manager shall be a single point of contact for the Contracting Officer and the COR. The name of the Project Manager, and the name(s) of any alternate(s) who shall act for the Contractor in the absence of the Project Manager, shall be provided to the Government as part of the Contractor's proposal. The Project Manager is further designated as Key by the Government. During any absence of the Project Manager, only one alternate shall have full authority to act for the Contractor on all matters relating to work performed under this contract. The Project Manager and all designated alternates shall be able to read, write, speak, and understand English. Additionally, the Contractor shall not replace the Project Manager without prior approval from the Contracting Officer.
The Project Manager shall be available to the COR between the hours of 8:00 a.m. and 4:30 p.m. EST, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within 24 hours of notification
3.3 Continuity of Support
The Contractor shall ensure that the contractually required level of support for this requirement is maintained at all times. The Contractor shall ensure that all contract support personnel are present for all hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the Contracting Officer’s Representative (COR) and the contracting officer prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.
3.4 Employee Identification
Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level, and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 6 of 52 requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
3.5 Employee Conduct
Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities.
The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security.
The Project Manager shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.
3.6 Removing Employees for Misconduct or Security Reasons
The Government may, at its sole discretion (via the Contracting Officer*), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons. Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
3.7 Non-Disclosure Agreement
All Contractor staff members are required to sign the DHS Non-Disclosure Agreement (Attachment II) before initiating any work on this Purchase Order which will be provided at the time of award.
4.0 OTHER PERTINENT INFORMATION OR SPECIAL C ONSIDERATIONS:
4.1. Travel
The Government does not anticipate travel for this requirement. However, Contractors are authorized to utilize the various DHS shuttles while conducting “official business” on behalf of the Government in performance of this requirement.
Travel performed for personal convenience or daily travel to and from work at the Contractor’s facility or local Government facility (i.e. designated work site) shall not be reimbursed.
5.0 GENERAL REPORT REQUIREMENTS
The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS workstations. (Windows 8, Windows XP, Windows 10 and Microsoft Office Applications).
6.0 PROTECTION OF INFORMATION
Contractor access to proprietary information is required under this SOW. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with DHS MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information.
The Contractor shall ensure that all Contractor personnel having access to business or procurement sensitive information sign a non-disclosure agreement (DHS Form 11000-6).
7.0 GOVERNMENT ACCEPTANCE PERIOD
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 7 of 52
7.1 The COR and PM will review deliverables prior to acceptance and provide the Contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.
7.2 The COR and PM will have the right to reject or require correction of any deficiencies found in the deliverables that are contrary to the information contained in the Contractor’s accepted proposal. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.
7.3 The COR and PM will have 10 business days to review deliverables and make comments. The Contractor shall have 5 business days to make corrections and redeliver the invoice with an “R” after the invoice document number to denote a revision and resubmission.
7.4 All other review times and schedules for deliverables shall be agreed upon by the parties based on the final approved Project Plan. The Contractor shall be responsible for delivering deliverables in a timely matter to Government personnel in the agreed upon project plan, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to assure that the established schedule is maintained.
8. DELIVERABLES AND DELIVERY SCHEDULE
All deliverables shall reference the DHS Contract number and the Purchase Order number. The contractor shall ensure and the Government will review all draft and final deliverables to ensure accuracy, functionality, completeness, professional quality, and overall compliance with government policies, regulations, laws, and directives. Written documents shall be concise and clearly written.
1. Final documentation deliverables shall be provided in hard and soft copy using MS Office products as specified below. Daily, weekly, interim, informal deliverables and working-copy products may be provided by e-mail or disk, as arranged.
2. All Deliverables shall be submitted to the COR identified in this Purchase Order. A copy of the Monthly Status Report shall be submitted to the COR, PM, and CO.
3. All DHS training materials (visual, digital, or print) shall use official DHS branding in accordance with DHS office of Public Affairs Brand and Identity Program Policy. Use of Contractor branding and logos shall only be used with permission from the DHS COR and PM and shall not be used in conjunction with the DHS branding.
In the event the Contractor anticipates difficulty in complying with any deliverable, the Contractor shall provide written notification immediately to the CO and COR. Each notification shall give pertinent details, including the date by which the Contractor expects to make delivery; provided that this data shall be informational only in character and that receipt thereof shall not be construed as a waiver by the Government of any purchase order delivery schedule.
9. DELIVERABLE TABLE
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 8 of 52
Deliverable SOW Paragraph
Ref.
Due Date Distribution
Post Award Conference 2.5 5 Days of Award CO, CS, COR
Kick-Off Meeting 2.6 10 Days After Post Award Meeting
COR
Contractor Project Implementation Plan
2.7 Draft at Kick-Off / Final 14
Days of Draft Approval
COR, PM
Mentoring Program Support and Commercial SaaS i l f
2.0 Upon ATO Approval COR, PM
Section 508 Deliverables See below Upon Request COR Independent assessment and verification of security l
See below Upon ATO Approval and Annually thereafter.
COR
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 9 of 52
OTHER APPLICABLE CONDITIONS
SECURITY
Contractor access to unclassified, but Security Sensitive Information may be required under this SOW.
Contractor employees shall safeguard this information against unauthorized disclosure or dissemination.
Requests for Exception to U.S. Citizenship Requirement Special procedures apply for exception to the requirement that persons accessing DHS systems be U.S.
citizens. Under normal circumstances, only U.S. citizens are allowed access to DHS systems and networks; but there is a need at times to grant access to foreign nationals. Access for foreign nationals is normally a long-term commitment, and exceptions to citizenship requirements are treated differently from security policy waivers. Exceptions to the U.S. citizenship requirement should be requested by completing a Foreign National Visitor Access Request, DHS Form 11052-1, which is available online or through the DHS Office of the Chief Security Officer (OCSO). Components who have access may file their request via the Foreign National Vetting Management System (FNVMS), a part of the DHS OCSO Integrated Security Management System’s (ISMS). For further information regarding the citizenship exception process, contact the DHS OCSO
This Policy Directive and the DHS 4300A Sensitive Systems Handbook apply to all DHS employees, contractors, detailees, others working on behalf of DHS, and users of DHS information systems that collect, generate, process, store, display, transmit, or receive DHS information unless an approved waiver has been granted. This includes prototypes, telecommunications systems, and all systems in all phases of the Systems Engineering Life Cycle (SELC).
POST-AWARD INSTRUCTIONS REGARDING SECURITY REQUIREMENTS FOR
CONTRACTS/ORDERS
The procedures outlined below shall be followed for the DHS Security Office to process background investigations and suitability determinations, as required, in a timely and efficient manner.
Carefully read the security clauses in the Order. Compliance with the security clauses in the contract is not optional.
Contract employees (to include applicants, temporaries, part-time and replacement employees) under the contract, requiring access to sensitive information, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigation s will be processed through the DHS Security Office.
Prospective Contractor employees shall submit the following completed forms to the DHS Security Office. The Standard Form 85P will be completed electronically, through the Office of Personnel Management's e-QIP SYSTEM. The completed forms must be given to the DHS Security Office no less than thirty (30) days before the start date of the contract or thirty (30) days prior to entry on duty of any employees, whether a replacement, addition, subcontractor employee, or vendor:
a. Standard Form 85P, "Questionnaire for Public Trust Positions"
b. FD Form 258, "Fingerprint Card" (2 copies)
c. DHS Form 11000-6 "Conditional Access to Sensitive But Unclassified Information
d. Non-Disclosure Agreement"
e. DHS Form 11000-9, "Disclosure and Authorization Pertaining to Consumer Report
Pursuant to the Fair Credit Reporting Act"
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 10 of 52
Only complete packages will be accepted by the DHS Security Office. Specific instructions on submission of packages will be provided upon award of the contract.
DHS may, as it deems appropriate, authorize and grant a favorable entry on duty (EOD) decision based on preliminary suitability checks. The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation.
The granting of a favorable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow. A favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar DHS from withdrawing or terminating access to government facilities or information, at any time during the term of the contract. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable EOD decision or suitability determination by the Security Office. No employee of the Contractor shall be allowed to EOD and/or access sensitive information or systems without a favorable EOD decision or suitability determination.
Limited access to Government buildings is allowable prior to the EOD decision if the Contractor is escorted by a Government employee. This limited access is to allow Contractors to attend briefings and non-recurring meetings in order to begin transition work.
The DHS Security Office shall be notified of all terminations /resignations within five (5) days of occurrence. The Contractor shall return to the Contracting Officer Technical Representative (COR) all DHS issued identification cards and building passes that have either expired or have been collected from terminated employees. If an identification card or building pass is not available to be returned, a report shall be submitted to the COR, referencing the pass or card number, name of individual to who it was issued and the last known location and disposition of the pass or card.
When sensitive Government information is processed on Department telecommunications and automated information systems, the Contractor shall provide for the administrative control of sensitive data being processed. Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level. Contractors who fail to comply with Department security policy are subject to having their access to Department IT systems and facilities terminated, whether the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).
Failure to follow these instructions may delay the completion of suitability determinations and background checks. Note that any delays in this process that are not caused by the government do not relieve a contractor from performing under the terms of the contract.
Your POC at the Security Office is:
DHS OCSO/PSD Security Customer Service Center Telephone: (202) 447-5010 E-mailbox: officeofsecurity@dhs.gov.
SECTION 508 REQUIREMENTS
Section 508 of the Rehabilitation Act (classified to 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.
mailto:officeofsecurity@dhs.gov https://uscode.house.gov/view.xhtml?req=(title:29%20section:794d%20edition:prelim)%20OR%20(granuleid:USC-prelim-title29-section794d)&f=treesort&edition=prelim&num=0&jumpTo=true
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 11 of 52
All products, platforms and services delivered as part of this statement of work that, by definition, are deemed ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Appendixes A, C & D, and available at https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards. ICT includes IT and other equipment.
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018, or any successor publication
Section 508 Requirements for Technology Services
1. When providing installation, configuration or integration services for ICT, the Contractor shall not reduce the original ICT item's level of Section 508 conformance prior to the services being performed.
2. When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed upgrades, substitutions and replacements prior to acceptance. The ACR should be created using the on the Voluntary Product Accessibility Template Version 2.2 508 (or successor versions). The template can be located at https://www.itic.org/policy/accessibility/vpat
3. When providing Platform as a Service (PaaS) or Software as a Service (SaaS), the contractor shall ensure services conform to the applicable Section 508 standards (including the requirements in Chapter 5 for software and WCAG Level A and AA Level 2.0 success criteria for web and software. When the requirements in Chapter 5 do not address one or more software functions, the Contractor shall ensure conformance to the Functional Performance Criteria specified in Chapter 3.) The agency reserves the right to request an Accessibility Conformance Report (ACR) for PaaS and SaaS offerings. The ACR should be created using the Voluntary Product Accessibility Template Version 2.2 508 (or later). The template can be located at https://www.itic.org/policy/accessibility/vpat
4. When providing cloud hosting services (Infrastructure as a Service, Platform as a Service, Software as a Service, etc.) the Contractor shall ensure user administrative screens, dashboards and portals used to configure, and monitor cloud services conform to the Section 508 standards.
5. The Contractor shall ensure cloud hosting services shall not reduce the level of Section 508 conformance for ICT migrated by DHS to the cloud hosting environment.
6. When developing or modifying ICT, the Contractor is required to validate ICT deliverables for conformance to the applicable Section 508 requirements. Validation shall occur on a frequency that ensures Section 508 requirements is evaluated within each iteration and release that contains user interface functionality.
7. When modifying, installing, configuring or integrating commercially available or government-owned ICT, the Contractor shall not reduce the original ICT Item’s level of Section 508 conformance.
8. When developing or modifying ICT deliverables that contain the ability to automatically generate electronic documents and forms in Microsoft Office and Adobe formats, or when the capability is provided to enable end users to design and author web based electronic content (i.e. surveys, https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5 https://www.ecfr.gov/cgi-bin/text-idx?SID=e1c6735e25593339a9db63534259d8ec&mc=true&node=pt36.3.1194&rgn=div5 https://www.itic.org/policy/accessibility/vpat
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 12 of 52 dashboards, charts, data visualizations, etc.), the Contractor shall demonstrate the ability to ensure these outputs conform to the applicable Section 508 standards (including WCAG 2.0 Level A and AA Success Criteria). The Contractor shall demonstrate conformance by conducting testing and reporting test results based on representative sample outputs. For outputs produced as Microsoft Office and Adobe PDF file formats, the Contractor shall use the test methods published under “Accessibility Tests for Documents”, which are published at https://www.dhs.gov/compliance-test-processes. For outputs produced as web based electronic content, the Contractor shall use the DHS Trusted Tester for Web Methodology Version 5.0, or successor versions. This methodology is published at https://www.dhs.gov/trusted-tester
9. When developing or modifying software functions of ICT, the Contractor shall demonstrate conformance to the applicable Section 508 standards (including the requirements in Chapter 5 and WCAG 2.0 Level A and AA Success Criteria). When the requirements in Chapter 5 do not address one or more software functions, the Contractor shall demonstrate conformance to the Functional Performance Criteria specified in Chapter 3. The Contractor shall use a test process capable of validating conformance to all applicable Section 508 standards for software functionality delivered pursuant to this contract. The Contractor may utilize the DHS Trusted Tester Methodology for Web and Software Version 4.0 as a component of the overall test process used. This version of the test process provides partial test coverage of the Section 508 standards that apply to software. If the Contractor uses this test process, the Contractor shall address the test coverage gaps through additional test procedures. Information on the DHS Trusted Tester Methodology for Web and Software Version 4.0, including coverage against the applicable Section 508 standards for software as well as gaps that need to be addressed through other test methods, related test tools, and training is published at https://www.dhs.gov/trusted-tester.
10. Contractor personnel shall possess the knowledge, skills and abilities necessary to address the accessibility requirements in this work statement.
Section 508 Deliverables
1. Section 508 Test Plans: When developing or modifying ICT pursuant to this Purchase Order, the Contractor shall provide a detailed Section 508 Conformance Test Plan. The Test Plan shall describe the scope of components that will be tested, an explanation of the test process that will be used, when testing will be conducted during the project development life cycle, who will conduct the testing, how test results will be reported, and any key assumptions.
2. Section 508 Test Results: When developing or modifying ICT pursuant to this Purchase Order, the Contractor shall provide test results in accordance with the Section 508 Requirements for Technology Services provided in this solicitation.
3. Section 508 Accessibility Conformance Reports: For each ICT item offered through this Purchase Order (including commercially available products, and solutions consisting of ICT that are developed or modified pursuant to this Purchase Order), the Offeror shall provide an Accessibility Conformance Report (ACR) to document conformance claims against the applicable Section 508 standards. The ACR shall be based on the Voluntary Product Accessibility Template Version 2.0 508 (or successor versions). The template can be found at https://www.itic.org/policy/accessibility/vpat. Each ACR shall be completed by following all of the instructions provided in the template, including an explanation of the validation method used as a basis for the conformance claims in the report.
4. Other Section 508 Documentation: The following documentation shall be provided upon request for ICT items offered through this Purchase Order:
o Documentation of features provided to help achieve accessibility and usability for people with disabilities.
https://www.dhs.gov/compliance-test-processes https://www.dhs.gov/compliance-test-processes https://www.dhs.gov/trusted-tester https://www.dhs.gov/trusted-tester
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 13 of 52 o Documentation on how to configure and install the ICT Item to support accessibility.
o Documentation of core functions that cannot be accessed by persons with disabilities.
o Documentation of remediation plans to address non-conformance to the Section 508 standards.
ARCHITECTURAL COMPLIANCE
DHS Enterprise Architecture Compliance Terms and Conditions
All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures.
Specifically, the contractor shall comply with the following Homeland Security (HLS) EA requirements:
• All developed solutions and requirements shall be compliant with the HLS EA.
• All IT hardware and software shall be compliant with the HLS EA Technical Reference
Model (TRM) Standards and Products Profile.
• Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and Enterprise Architecture Information Repository.
• Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.
• Applicability of Internet Protocol Version 6 (1Pv6) to DRS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be! Pv6 compliant as defined in the US. Government Version 6 (USGv6) Profile National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.
IT SECURITY COMPLIANCE
Compliance with DHS IT Security Policy Terms and Conditions All hardware, software, and services provided under this Purchase Order must be compliant with DHS 4300A DHS Sensitive System Policy and the DHS 4300A Sensitive Systems Handbook.
The IT solution shall meet all US Federal and DHS specific Systems and Security and Privacy requirements criteria.
Encryption Compliance Terms and Conditions If encryption is required, the following methods are acceptable for encrypting sensitive information:
1. FIPS 197 (Advanced Encryption Standard (AES)) 256 algorithm and cryptographic modules that have been validated under FIPS 140-2.
2. National Security Agency (NSA) Type 2 or Type 1 encryption.
3. Public Key Infrastructure (PKI) (see paragraph 5.5.2.1 of the Department of Homeland
Security (DHS) IT Security Program Handbook (DHS Management Directive (MD) 4300A) for Sensitive Systems).
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 14 of 52
Security Review Terms and Conditions The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this Purchase Order are being implemented and enforced. The Contractor shall afford DHS, including the organization of the DHS Office of the Chief Information Officer, the Office of the Inspector General, authorized COR, and other government oversight organizations, access to the Contractor's facilities, installations, operations, documentation, databases and personnel used in the performance of this Purchase Order. The Contractor will contact the DHS Chief Information Security Officer to coordinate and participate in the review and inspection activity of government oversight organizations external to the DHS. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of DHS data or the function of computer systems operated on behalf of DHS, and to preserve evidence of computer crime.
Interconnection Security Agreements Terms and Conditions Interconnections between DHS and non-DHS IT systems shall be established only through controlled interfaces and via approved service providers. The controlled interfaces shall be accredited at the highest security level of information on the network. Connections with other Federal agencies shall be documented based on interagency agreements; memoranda of understanding, service level agreements or interconnect service agreements.
Required Protections for DHS Systems Hosted in Non-DHS Data Centers If the IT Solution and database is hosted and maintained at a non-DHS facility then applicable DHS managed server provider (MSP) requirements will be applicable including FISMA/ FEDRAMP.
Contractors are fully responsible and accountable for ensuring compliance with all Federal Information Security Management Act (FISMA), National Institute of Standards and Technology (NIST) Federal Information Processing Standard (FIPS) and related DHS security control requirements (to include configuration guides, hardening guidance, DHS Security Policy, Procedures, and Architectural guidance). The contractor security procedures shall be the same or greater than those that are provided by DHS Enterprise Data Center(s).
Security Authorization Terms and Conditions A Security Authorization of any infrastructure directly in support of the DHS information system shall be performed as a general support system (GSS) prior to DHS occupancy to characterize the network, identify threats, identify vulnerabilities, analyze existing and planned security controls, determine likelihood of threat, analyze impact, determine risk, recommend controls, perform remediation on identified deficiencies, and document the results. The Security Authorization shall be performed in accordance with the DHS Security Policy and the controls provided by the hosting provider shall be equal to or stronger than the FIPS 199 security categorization of the DHS information system.
At the beginning of the Purchase Order, and annually thereafter, the contractor shall provide the results of an independent assessment and verification of security controls. The independent assessment and verification shall apply the same standards that DHS applies in the Security Authorization Process of its information systems. Any deficiencies noted during the assessment shall be provided to the COR for entry into the DHS’ Plan of Action and Milestone (POAM) Management Process. The contractor shall use the DHS’ POAM process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies shall be corrected within the timeframes dictated by the DHS POAM management Process.
Contractor procedures shall be subject to periodic, unannounced assessments by DHS officials. The physical aspects associated with contractor activities shall also be subject to such assessments.
Mentoring Program Support and Commercial SaaS Mentoring Platform Page 15 of 52
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .