70RTAC24R00000016_J.1_SOW_Amendment 0002.pdf

PDF 429 KB Posted

Attached to
Adobe ELA - FINAL Solicitation Federal contract opportunity
Solicitation number
70RTAC24R00000016
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

This document is a Statement of Work (SOW) for a Department of Homeland Security (DHS) wide Adobe Enterprise License Agreement (ELA). The key details are:

The SOW outlines the scope, objectives, and requirements for a department-wide, single award contract vehicle for the purchase of Adobe products including software, maintenance, and consulting services. The ELA shall cover Adobe software and maintenance for over 200,000 DHS devices across multiple DHS components. Key requirements include providing technical support, maintenance, and upgrades; facilitating migration of existing licenses; offering consistent pricing; tracking and managing licenses; and providing consulting services. The SOW also includes compliance requirements related to DHS enterprise architecture, security, accessibility, and other federal regulations. The period of performance is a 3-year base with two 12-month option periods.

View the file

Other files for this federal contract opportunity

Show all 20

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Homeland Security

DHS Department-wide Adobe

Enterprise License Agreement

(ELA)

Contents

1. STATEMENT OF WORK

1.1. Background

1.2. Scope:

1.3. Objective

1.4. Licensing Coverage for all DHS Components

1.4.1. Technical Support and Maintenance

1.4.2. Existing Maintenance

1.4.3. Migration to Current ELA

1.4.4. New Vendor Products

1.4.5. ELA Technology Refresh and Product Offerings

1.4.6. Licensing Audits and Compliance Reviews

1.4.7. Increases in the Number of Licenses

1.4.8. Enterprise Term License Agreements

1.4.9. Notification of Changes to Software Publisher Licensing or Support

1.4.10. Renewal Grace Period and Portal Update

1.4.11. Timely Quotes/Orders

1.4.12. Digital Signature

1.5. DHS Technical Reference Model

1.6. Online Tracking Website Requirements

1.7. Order Identification

1.8. ELA Orders Report

1.9. IT Professional Services Requirements

1.9.1. Training Resources

1.10. ELA Management and Oversight Requirements

1.10.1. Support Service Levels

1.10.2. Pricelist for Items on Contract

1.11. Contractor Personnel

1.11.1. Qualified Personnel

1.11.2. Continuity of Support

1.11.3. Declared DHS National Emergency applicable at the ELA Order level

1.11.4. Employee Identification

1.11.5. Employee Conduct

1.11.6. Removing Employees for Misconduct or Security Reasons

1.11.7. Standard of Conduct at Government Installations

1.12. Security Requirements

1.13. Period of Performance

1.14. Place of Performance

1.15. Hours of Operation

1.16. Post Award Conference

1.17. General Report Requirements

1.18. Access to and Protection of Information

1.19. Access to Unclassified Facilities, Information Technology Resources, and Sensitive Information

1.20. Government Furnished Resources

1.21. Contractor Furnished Property

1.22. Government Acceptance Period

1.23. Deliverables

2. ENTERPRISE ARCHITECTURE (EA) COMPLIANCE LANGUAGE

2.1 DHS-CBP Enterprise Architecture Compliance

2.2. DHS-TSA Enterprise Architecture Compliance

2.3. DHS-USCG Enterprise Architecture Compliance

3. OTHER COMPLIANCE REQUIREMENTS

3.1 Compliance with DHS Security Policy Terms and Conditions

3.2 Encryption Compliance Terms and Conditions

3.3 Security Authorization

3.4 Enterprise Security Architecture Terms and Conditions

3.5 Continuous Monitoring Terms and Conditions

3.6 Specific Protections Terms and Conditions

3.6.1. Physical and Information Security and Monitoring Terms and Conditions

3.6.2 Vulnerability Assessments Terms and Conditions

3.6.3 Personal Identification Verification (PIV) Credential Compliance Authorities:

3.6.4 Personal Identification Verification (PIV) Credential Compliance Terms and Conditions

3.7. Non-disclosure Agreements

3.8. Third Party Contractor and Non-DHS Agency Purchases on Behalf of DHS

3.9. Security Review applicable at the Order level

3.10. Information Security Standards

3.11. Technical Reference Manual, Application Protocol Interface (API)

3.12. Section 508 Requirements

3.12.2. Section 508 Requirements for Technology Products

3.12.3. Section 508 Requirements for Technology Services

3.12.4. Section 508 Deliverables

3.13. Federal Information Security Management Act (FISMA) Requirements

3.14. Occupational Safety and Health Act Requirements

3.15. Supply Chain Risk Management (C-SCRM) SOW Language

3.16. Artificial Intelligence / Machine Learning Requirements

3.17. DHS Geospatial Information System Compliance

3.18. DHS Cloud / FedRAMP Requirements

3.19. Secure Software Development Attestation

1. STATEMENT OF WORK

1.1. Background

The Office of the Chief Information Officer (OCIO), in conjunction with the Strategic

Solutions Office, intends to issue a department-wide, single award contract vehicle for the purchase of Adobe products including software, maintenance, and consulting services.

DHS requirements for this procurement are driven by individual DHS component needs for Adobe software products and services. DHS has an estimate of more than 200,000 DHS devices that are licensed with Adobe products and availability of the latest upgrades and rights are essential to continue the mission of DHS. The Department requires Commercially available off-the-shelf

(COTS) software to meet its requirement.

1.2. Scope:

The Contractor shall accept Orders from all DHS components. The participating DHS components include but are not limited to subcomponents of:

• U.S. Customs and Border Protection (CBP)

• Cybersecurity and Infrastructure Security Agency (CISA)

• Countering Weapons of Mass Destruction Office (CWMD)

• Department of Homeland Security Headquarters (DHS HQ)

• Federal Emergency Management Agency (FEMA)

• Federal Law Enforcement Training Center (FLETC)

• Immigration and Customs Enforcement (ICE)

• Intelligence and Analysis (I&A)

• Office of Homeland Security Situational Awareness

• Office of the Inspector General (OIG)

• Science and Technology Directorate (S&T)

• Transportation Security Administration (TSA)

• United States Coast Guard (USCG)

• U.S. Citizenship and Immigration Services (USCIS)

• United States Secret Service (USSS)

• Other DHS organizations that may be enrolled during the term of the ELA

1.3. Objective

DHS has a requirement to continue software maintenance for its existing Adobe licenses as well as the need to procure additional Adobe software licenses, maintenance, and consulting services as they relate to the implementation of Adobe products. DHS requires COTS software to meet this requirement.

This ELA shall provide for:

• The availability of Adobe products by download of media and the maintenance for each Order issued;

• Improved data capture for forms;

• E-forms over multiple software and hardware platforms;

• Any and all products purchased outside of the Department’s predecessor Adobe

ELA, to be transitioned to the current ELA and co-terminated with the maintenance period. (Note: Any products purchased outside of the Department’s predecessor Adobe ELA at the time of current ELA award or at any point during the current ELA’s ordering period are/will be included in the transition.);

• Standard pricing across DHS for common products, including consistent pricing for License Maintenance;

• Standard order template for all DHS components;

• Upgrading of current licenses to the latest version at no additional cost;

• Accurate tracking and management of Adobe licenses and associated costs and savings, ELA Cost versus DHS ELA Pricing;

• Single Adobe POC for each component for all Adobe Products;

• Consulting Services;

• Ability to reduce the number of unused licenses required during annual maintenance renewal without significantly increasing the unit price for other products; and

• The ability to place ELA orders for products and services that fall in-between the

3-month/quarterly pricing to be co-termed to allow flexibility for period of performance start dates.

1.4. Licensing Coverage for all DHS Components

This ELA shall only include Adobe products and services and shall provide immediate Adobe

Acrobat licensing and maintenance for all DHS components over the term of the agreement. This

ELA will also provide the ability to purchase Adobe’s full suite or individual components of additional devices and server products. This ELA shall be structured to allow for any existing licenses with unexpired software maintenance bought outside of the ELA to be incorporated into the overarching DHS-wide ELA, once those maintenance agreements have expired. Those existing maintenance agreements shall be included at the unit prices established under this ELA. The software included in this contract shall allow for files and documents created in one software on this contract to be manipulated by another software on this contract without the creation of an interface by DHS.

To help support interoperability across its enterprise, DHS requires that the software titles provided through this contract shall also have existing integrations for Microsoft 365, Microsoft Power

Platform, and Azure Services. These integrations shall be approved by Microsoft before the software is included on the contract pricelist.

1.4.1. Technical Support and Maintenance

The Contractor shall provide software maintenance, which includes upgrades to the latest versions of the products as they become commercially available, and 24 hours per day, 7 days a week, and

365 days a year product and technical support, at no additional cost to the Government. The

Contractor shall provide the option for 24/7/365 support for Adobe software and licenses. The

Contractor shall also offer U.S.-based support.

All software upgrades or updates must be listed on the monthly “ELA Orders Report” (see

Section 1.8). The Contractor shall provide notice of update or upgrade availability on the

Contractor’s website and notify the DHS HQ Program Manager via email within three (3) business days.

The Government will evaluate its technical support and maintenance requirements annually, prior to the designated co-termination date. The Government reserves the right to terminate technical support and maintenance on any software or item covered under this ELA once a year with or without prior written notice to, or advance authorization from, the ELA holder without any additional cost to the Government. It is the general policy of the Government for the Program

Manager (PM) or Contracting Officer (CO) to notify the ELA holder in writing, of its intent to terminate technical support and maintenance. Such “terminations”, as used in this provision, ARE NOT considered Terminations for Convenience as defined in the Federal Acquisition

Regulation (FAR).

1.4.2. Existing Maintenance

DHS plans to migrate existing licenses for products covered by this Statement of Work (SOW) into the ELA. The initial period of maintenance shall be prorated (a date will be established after award). The Contractor shall allow for and facilitate this process.

1.4.3. Migration to Current ELA

Upon migration of any software requirements to the ELA, the terms of this ELA will supersede any terms and conditions listed on previous ELAs/contractual actions through which the software requirements were ordered. The Contractor shall develop a plan to migrate current requirements from the old ELA to the new ELA, irrespective of the period of performance of the current ELA.

The end state of this initiative is to simplify contract administration and property management by having all license support services currently being received, start at the same time and conclude at the same time.

1.4.4. New Vendor Products

The ELA will be modified to include new relevant products that become commercially available and based on component requirements. The Contractor shall provide a tech refresh and the CO will issue a “Tech Refresh” modification to add relevant new products quarterly based on component needs. In addition, the “Tech Refresh” shall delete products that have been discontinued and are no longer available. Tech Refresh modifications may be issued each quarter of the ELA year, or sooner (if required). If DHS requires a product that is not currently offered under this ELA, pricing associated with these products shall also incorporate discounts equal to or better than the discounts stated in ELA.

1.4.5. ELA Technology Refresh and Product Offerings

DHS reserves the right to add new Adobe products under the agreement if they become available during the ordering period of the ELA. DHS also reserves the right to refresh the clauses and terms and conditions of the ELA as necessary during the ordering period based upon the technology available under the agreement. The product lines offered under the ELA shall not be removed or combined with other product lines under this agreement without the consent of the

Government.

1.4.6. Licensing Audits and Compliance Reviews

DHS policies do not permit the scanning, audit or review of systems by personnel, equipment or software that have not been specifically authorized to do so, in writing, by DHS. However, if a situation arises and a license review of a DHS facility or system is warranted, the following may occur: Once per ELA year a data report surrounding a particular hardware or software in question, may be requested by DHS, and presented to the contractor, with the advance written agreement of the Program Office and the Contracting Officer.

1.4.7. Increases in the Number of Licenses

Ordering Contracting Officers are encouraged to follow a “pay-as-you-go” approach in the event additional licenses are required during ELA order performance. An order modification, including the obligation of funds, should be issued prior to the acquisition of licenses that are above the baseline purchase to avoid potential anti-deficiency act violations. Additional licenses purchased throughout the year shall be added to the relevant DHS Component’s or HQ office’s Adobe console/inventory no later than 30 days after purchase.

1.4.8. Enterprise Term License Agreements

Contractors shall provide Adobe Enterprise Term License Agreements (ETLA) with pricing for up to three (3) years based on the DHS order requirement. The Contractor shall also provide

DHS with a breakdown of how an increase or decrease in individual licenses could affect the

ETLA prices, as well as potential options for keeping the pricing the same for the period chosen by the DHS Component or HQ office.

1.4.9. Notification of Changes to Software Publisher Licensing or Support

The contractor shall notify DHS of any changes to the software publisher’s licensing or support model within 30 days of said change. The notification shall include any potential effects on future software and support purchases for all licenses, subscriptions and software maintenance.

The contractor shall also notify DHS within thirty (30) days of notification from the software publisher of an in-scope software title’s end of life (EOL), meaning when the publisher plans to stop providing updates, security patches and other support.

1.4.10. Renewal Grace Period and Portal Update

The Contractor shall allow a thirty (30) day grace period when a DHS Component or HQ office is placing an order before late or reinstatement fees are applied. During this grace period, end-users shall not be notified that their licenses have expired. The Contractor shall alert the DHS

Component or HQ offices when the Adobe portal has been updated. In addition, the Contractor shall provide the DHS Component or HQ offices guidance on how they can obtain patches and new files if the Adobe portal is down for maintenance.

1.4.11. Timely Quotes/Orders

The Contractor shall make all efforts to submit a quote in response to an order-level Request for

Quotes (RFQ) within fourteen (14) calendar days. If more time is required, the Contractor shall alert the ordering DHS Component or HQ ordering office. The Contractor shall support both large, potentially multi-year, purchase requests and Government Purchase Card (PCard) purchases for small purchases. The Contractor shall be prepared to support multiple large and small orders from multiple DHS Components and HQ offices before the end of the Federal

Government’s Fiscal Year on September 30th through the duration of this contract. The

Contractor shall also provide budgetary requests to the DHS Components and HQ offices within fifteen (15) business days. These budgetary requests shall include the expected price of the software based on both the price in the ELA and any related volume discounts. For emergency or disaster situations, the Contractor shall make its best effort to provide a quote 48 hours after being notified of an emergency quote request.

1.4.12. Digital Signature

Within DHS, legally binding signatures using a digital signature or other electronic signature method are executed on systems whose system clocks have been synchronized via Network Time

Protocol (NTP) with DHS networks and are managed to prevent unauthorized changes to the system clock. When the signature is executed, the date and time from the system clock are captured and incorporated as part of the record of the signature. The software offered on this contract shall include digital signatures that comply with this DHS protocol. The digital signatures shall also be able to be used on Portal Document Format (PDF) files. These digital signatures shall include functionality so that:

• The signer cannot successfully repudiate that he/she intended to sign, or that he/she applied the electronic signature.

• The integrity of the signed content cannot be successfully challenged.

In addition, the software shall also offer the ability to change the digital signature image to show an actual signature.

1.5. DHS Technical Reference Model

Enterprise products and services available through the Contractor under this ELA shall be compliant or submitted to DHS for a compliance review (see below), with the Homeland Security Enterprise

Architecture (HLS EA) Technical Reference Model (TRM) Standards and Products Profile. This information will be provided to the contractor upon request.

All data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the DHS Enterprise Architecture Office (EA) for review and insertion into the DHS

Data Reference Model, within thirty (30) days of receiving the then current TRM standards and products listing from DHS.

All IT assets being developed, procured, or acquired shall be Internet Protocol version 6 (IPv6) capable or greater.

1.6. Online Tracking Website Requirements

The Contractor shall ensure that the Adobe Admin Console has the most recent purchases and licensing information for this contract.

An automated process to facilitate the recapture and redistribution of excess or un-used assets is crucial for DHS. The ability to track new licenses and avoid duplicative costs through harvesting and redeployment of existing unused assets is important to DHS components.

The Contractor shall be responsible for tracking the inventory of new and existing licenses upon migration to the ELA, maintenance costs, services, and transfers by DHS components using separate enrollment numbers on the Contractor’s license tracking website.

DHS shall have access to the web-based tool 24 hours per day, 7 days per week and 365 days per year.

The Contractor shall notify the Government PM at least forty-eight (48) hours in advance of any scheduled maintenance outages.

The Contractor shall provide DHS access to a secure, online tracking website that allows DHS the ability to:

• view the current inventory of license and associated maintenance costs;

• provide a component-level view by enrollment number that shows all component license activity, and consulting services;

• provide a mechanism for purchasing products and services while providing an up to date status;

• view all available transfer requests and up to date status; and,

• create dynamic customized reports.

1.7. Order Identification

Each ELA Order placed by a DHS component must include its respective enrollment number, generated by the Contractor. In addition, it shall include the Purchase Request (PR) number and the component POC who placed the order which corresponds to the determination contained in the

Online License Tracking Website. The Contractor shall not accept an Order from DHS or its components without assigning the proper enrollment number. The Contractor shall use the enrollment number, PR number, and POC as an identification method on all Orders to ensure proper tracking, reporting of inventories, usage, and spending.

1.8. ELA Orders Report

A report of all orders placed shall be submitted on a monthly basis or as otherwise requested by the DHS Contracting Officer (CO), Program Management Office, task order CO, or the

Contracting Office Representative (COR). The Contractor shall maintain responsibility for tracking all orders online, corresponding to each DHS component, and provide associated new order quantities and costs for the reporting period. The monthly report is due, in electronic format, on the 15th day of each month for the term of the vehicle, using the DHS template to be provided post award. The report shall have two (2) tabs as follows:

Task Summary Report (Tab 1)

This report shall include the following information related to usage of the Adobe ELA:

• Order ID

• Contract Name

• Functional Category

• Socioeconomic Category

• NAICS Code

• PSC

• Contractor Name

• Contractor UEI

• Reverse Auction Marketplace Used?

• Reverse Auction Marketplace Fee

• Purchase Card Transaction

• Order PoP Start Date

• Order PoP End Date

• Order Total Value

• Software Publisher

• Component Name

• Component or Office Enrollment Code

• Delivery Date

• Contractor Name

• Base Period Order PoP Start Date

• Base Period Order PoP End Date

• Base Period Value

• Option Period 1 PoP Start Date

• Option Period 1 Order PoP End Date

• Option Period 1 Value

• Option Period 2 PoP Start Date

• Option period 2 Order PoP End Date

• Option period 2 Value

• Reporting Month

• Reporting Year

• Total List Cost

• Total Invoiced Cost

Usage Task Detail Report (Tab 2)

The Usage Detail Report shall contain the following:

• Reporting Month

• Reporting Year

• Component Name

• Order Number

• Contracting Officer Email

• Contracting Office Name

• Software Publisher

• Hardware OEM

• Product Description

• Product Type

• Version

• New/Renewal

• Start Date of License

• End Date of License

• SKU Number

• Part Number

• Number of Licenses or Subscriptions purchased

• Number of each unit of hardware purchased

• Unit Price

• Total Price

• Comparative Price

• Order Date

• Purchase Method

• DHS Labor Hours

• Labor Costs

1.9. IT Professional Services Requirements

The Contractor shall provide IT professional services incidental to software purchased under this

ELA in accordance with the labor categories listed in this ELA. Rates shall be fixed and apply throughout the term of the Department-wide ELA. IT professional services, including consulting services, shall be contracted for specific engagements as specified in individual ELA Orders. The requirement for professional services is minimal; however, it should be available to the

Government on an as needed basis. Orders for IT professional services shall only be permitted on a firm-fixed price basis – time and materials orders are not permitted under this ELA.

1.9.1. Training Resources

The Contractor shall provide multiple modes of training, including online, computer-based, and in person training. The training shall be 508 compliant.

1.10. ELA Management and Oversight Requirements

There shall be no direct cost or charge to the ELA for the PM’s efforts; there will be no ELA Order directly funding the ELA level PM. Additional duties of the ELA-level PM shall include component briefings and the facilitation of and participation in annual product review meetings to preview any new products or product versions that may become available during upcoming years.

The Contractor shall participate in regular Program Management Reviews (PMR) throughout the term of the ELA. Reviews shall be held at least quarterly as scheduled by the DHS Enterprise License

Agreement PM. During these reviews, the Contractor shall report at a minimum on the status of ELA

Orders and any outstanding issues concerning the ELA. The PMR agenda and presentation shall be provided to the Contractor at least one week prior to each PMR.

The Contractor PM, or the designated Assistant PM, shall be available to engage in meetings as required within one (1) business day of notification. Travel expenses will not be reimbursed by the

Government.

Phone calls placed in an emergency situation such as a work stoppage by the Government ELA CO or COR / PM to the Contractor PM shall be returned by the PM not exceeding a two (2) hour window.

1.10.1. Support Service Levels

The Contractor shall provide access to Adobe’s help desk, including:

• Levels of service – Contractor shall identify the types of services that will be accommodated via the Adobe service desk versus Adobe premiere support. DHS customers shall be able to select a priority per service type (high, medium, low). The Contractor shall also identify the price points and support included in each service type.

• Response time – Contractor shall identify the time it takes for a customer service representative to get back to a customer when clarification is needed based on service type.

• Time to Resolve – Contractor shall identify the time it takes for an incident to be resolved.

• Customer satisfaction – Contractor shall provide a method for a customer to provide a satisfaction rating with comment, per incident. Contractor shall also provide performance reporting to include customer provided ratings with comment per incident for each DHS

Component or HQ office.

1.10.2. Pricelist for Items on Contract

The Contractor shall provide DHS with a pricelist of all software titles and services included on the contract. The pricelist shall include any discount off of commercial prices on the same row as the DHS unit price. This pricelist shall be updated as new products are added to this contract.

1.11. Contractor Personnel

1.11.1. Qualified Personnel

The Contractor shall provide qualified personnel to perform all requirements specified in this

ELA and SOW.

1.11.2. Continuity of Support

The Contractor shall ensure that the contractually required level of IT professional services support for these requirements are maintained at all times. The Contractor shall ensure that all contract support personnel are present for all required hours of the workday. If for any reason the Contractor staffing levels are not maintained due to vacation, leave, appointments, etc., and replacement personnel will not be provided, the Contractor shall provide e-mail notification to the COR prior to employee absence. Otherwise, the Contractor shall provide a fully qualified replacement.

1.11.3. Declared DHS National Emergency applicable at the ELA Order level

The Contractor shall provide DHS with a Business Continuity Plan (BCP) within ninety (90) days after ELA order award when applicable. This plan will be updated on an annual basis. The

BCP shall document Contractor plans and procedures to maintain support during an emergency, including natural disasters and acts of terrorism. The BCP, at a minimum, shall include the following:

• A description of the Contractors emergency management procedures and policy

• A description of how the Contractor will account for their employees during an emergency

• How the Contractor will communicate with the Government during emergencies

• A list of primary and alternate Contractor points of contact, each with primary and alternate:

o Telephone numbers o E-mail address

Individual BCPs shall be activated immediately after determining that an emergency has occurred and shall be operational within six (6) hours of activation or as directed by the

Government and shall be sustainable until the emergency situation is resolved and normal conditions are restored or the ELA is terminated, whichever comes first. In case of a life-threatening emergency, the COR will immediately make contact with the Contractor Program

Manager to ascertain the status of any Contractor personnel who were located in Government controlled space affected by the emergency. When any disruption of normal, daily operations occurs, the Contractor Program Manager and the COR shall promptly open an effective means of communication and verify:

• Key points of contact (Government and Contractor)

• Temporary work locations (alternate office spaces, telework, virtual offices, etc.)

• Means of communication available under the circumstances (e.g., e-mail, web-mail, telephone, FAX, courier, etc.)

• Essential Contractor work products expected to be continued, by priority.

1.11.4. Employee Identification

Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.

Contractor employees working on-site at Government facilities shall wear a Government issued identification badge. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and display the Government issued badge in plain view above the waist at all times.

1.11.5. Employee Conduct

Contractor’s employees shall comply with all applicable Government regulations, policies and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at

Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Contractor’s PM shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.

1.11.6. Removing Employees for Misconduct or Security Reasons

The Government may, at its sole discretion (via the CO or COR), request the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons.

Removal does not relieve the Contractor of the responsibility to continue providing the services required under the ELA. The CO will provide the Contractor with a written explanation to support any request to remove an employee.

1.11.7. Standard of Conduct at Government Installations

The Contractor shall be responsible for maintaining satisfactory standards of employee competency, conduct, appearance, and integrity and shall be responsible for taking such disciplinary action with respect to employees as may be necessary. The Contractor is also responsible for ensuring that their employees do not disturb papers on desks, open desk drawers or cabinets, or use Government resources except as authorized by the Government.

1.12. Security Requirements

Security requirements will be designated in each ELA Order issued.

1.13. Period of Performance

The period of performance of this ELA is for three (3) years; one 12-month base ordering period and two additional 12-month optional ordering periods. Individual ELA Orders will be written to terminate on an annual basis, with the initial period prorated as necessary to establish the co-termination date.

Base Period: 12 months

Optional Ordering Period One: 12 months

Optional Ordering Period Two: 12 months

1.14. Place of Performance

The place of performance will be designated in each Order issued hereunder. The work that is outlined in this SOW will be performed at DHS offices and at the contractor locations specified by

DHS. DHS anticipates that the vast majority of the work performed under this contract will occur within the continental United States, although efforts outside the continental United States are permitted under this contract.

1.15. Hours of Operation

Contractor employees performing services shall generally perform all work between the hours of

8:00 am and 5:00 pm Eastern Time, Monday through Friday, except for Federal holidays observed that are designated per ELA Order.

1.16. Post Award Conference

The Contractor shall attend a Post Award Conference (also referred to as the ELA Kickoff

Meeting) conducted by the ELA CO and other DHS officials within five (5) business days after the date of award. The purpose of the Post Award Conference, which will be chaired by the CO, is to discuss the technical and contracting objectives of the ELA and discuss all requirements of the

ELA. The Post Award Conference will be held at the Government’s facility, located in

Washington, DC or via video/teleconference.

At the Post Award Conference, the Contractor will present a live demonstration of its Online

License Tracking Website. The website shall be fully active within twenty (20) business days after ELA award.

1.17. General Report Requirements

The Contractor shall provide all written reports in electronic format with read/write capability using applications that are compatible with DHS (i.e., Windows Operating System and

Microsoft Office Applications).

1.18. Access to and Protection of Information

Contractor access to information protected under the Privacy Act is required under this SOW.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation. Contractor access to proprietary information is required under this SOW. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with DHS MD

11042.1, Safeguarding Sensitive but Unclassified (For Official Use Only) Information. The

Contractor shall ensure that all Contractor personnel having access to business or procurement sensitive information sign a non-disclosure agreement (DHS Form 11000-6).

1.19. Access to Unclassified Facilities, Information Technology Resources, and Sensitive

Information.

ELA Call Contractors that need access to information protected under the Privacy Act is required under this SOW. Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with the law and Government policy and regulation.

Contractor employees shall safeguard this information against unauthorized disclosure or dissemination in accordance with DHS MD 11042.1, Safeguarding Sensitive but Unclassified (For

Official Use Only) Information. The Contractor shall ensure that all Contractor personnel having access to business or procurement sensitive information sign a non- disclosure agreement (DHS

Form 11000-6).

1.20. Government Furnished Resources

Each ELA order that requires workspace shall be provided for by the requesting component. Each component shall provide Government Furnished Equipment (GFE) and supplies necessary to perform the on-site portion of Contractor services required under this ELA.

1.21. Contractor Furnished Property

The Contractor shall furnish all labor, management, supervision, facilities, materials, equipment, quality control and services necessary to fulfill the requirements of this ELA, except for the

Government Furnished Resources specified in Section 1.20.

1.22. Government Acceptance Period

The COR for each ELA order shall review deliverables for their respective ELA Orders prior to acceptance and provide the Contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying that the deliverable has been accepted.

The COR will have the right to reject or require correction of any deficiencies found in the deliverables for their respective ELA Orders that are contrary to the information contained in the

Contractor’s accepted Quotation Package, or not in accordance with the terms of this ELA. In the event of a rejected deliverable, the Contractor will be notified in writing by the COR of the specific reasons for rejection. The Contractor shall have an opportunity to correct the rejected deliverable and return it per delivery instructions.

For all deliverables, The Contractor shall have three (3) business days to make corrections and redeliver deliverables after comments are received from the task order COR.

All other review times and schedules for deliverables shall be mutually agreed upon by the parties. The Contractor shall be responsible for the timely delivery to Government personnel in the agreed upon review chain at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to ensure that the established schedule is maintained.

1.23. Deliverables

The following deliverables are applicable to this contract and subsequent orders:

ITEM

SOW

REFERENCE

DELIVERABLE /

EVENT

RECIPIENT DUE DATE

1 1.4.3 ELA Migration

Plan

ELA CO and

ELA COR

Within 20 Business Days after

ELA Award

2 1.4.4 Technical Refresh ELA CO and

ELA COR

Within 20 Business Days after request

3 1.5 Data Assets Report

DHS HQ

Enterprise

Architecture office

Within 20 Business Days after

ELA Award, then updated as new products added

4 1.6 On Line Tracking

Website

ELA CO and

ELA COR

Within 20 Business Days after

ELA Award

5 1.8 ELA Orders Report ELA CO and

ELA COR

15th Calendar Day of Each Month

6 1.10

Quarterly Product

Management

Reviews

ELA CO and

ELA COR

As scheduled by

ELA PM

7 1.10 Annual Product

Review Meetings

ELA CO and

ELA COR

Annually, on anniversary of ELA award

8 1.10.2 Contract Pricelist

ELA CO and

ELA COR

Within 5 Business Days After New Product Added

9 1.16 Post-Award

Conference

ELA CO and

ELA COR

Within 5 Business Days After

Award

10 3.3 Security

Authorization and

ELA CO and

ELA COR

Annually, on anniversary of ELA

Verification of

Security Controls award

2. ENTERPRISE ARCHITECTURE (EA) COMPLIANCE LANGUAGE

This is a list of EA Architecture Compliance language agreed upon between Components and HQ

DHS to be used in preparing SOW, PWS & SOO for IT acquisitions & services. The following

Components (CBP, TSA & USCG) have their own customized version listed below that must be used. All other Components must use the DHS Enterprise Architecture Compliance language that follows.

DHS Enterprise Architecture Compliance

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures.

Specifically, the contractor shall comply with the following HLS EA requirements:

• All developed solutions and requirements shall be compliant with the HLS EA.

• All IT hardware and software shall be compliant with the HLS EA Technical Reference Model

(TRM) Standards and Products Profile.

• Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Architecture Division (EAD) for review, approval and insertion into the DHS Data Reference Model and Mobius.

• Development of data assets, information exchanges and data standards will comply with the DHS

Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government

Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special

Publication 500-267) and the corresponding declarations of conformance defined in the

USGv6 Test Program.

2.1 DHS-CBP Enterprise Architecture Compliance

The Offeror shall ensure that the design conforms to the Department of Homeland Security (DHS) and

Customs and Border Protection (CBP) Enterprise Architecture (EA), the DHS and CBP Technical

Reference Models (TRM), and all DHS and CBP policies and guidelines (such as the CBP Information

Technology Enterprise Principles, as promulgated by the DHS and CBP Chief Information Officers

(CIO), Chief Technology Officers (CTO) and Chief Architects (CA)).

The Offeror shall conform to the Federal Enterprise Architecture (FEA) model and the DHS and CBP versions of the FEA model, as described in their respective EAs. All models will be submitted using

Business Process Modeling Notation (BPMN 1.1 or BPMN 2.0 when available) and the CBP

Architectural Modeling Standards. Universal Modeling Language (UML2) may be used for infrastructure only. Data semantics shall be in conformance with the National Information Exchange

Model (NIEM). Development solutions will also ensure compliance with the current version of the

DHS and CBP target architectures.

Where possible, the Offeror shall use DHS/CBP approved products, standards, services, and profiles, as reflected by the hardware, software, application, and infrastructure components of the DHS/CBP

TRM/standards profile. If new hardware, software, or infrastructure components are required to develop, test, or implement the program, these products will be coordinated through the DHS and CBP formal Technology Insertion (TI) process (to include a trade study with no less than four alternatives, one of which reflecting the status quo and another reflecting multi-agency collaboration). The

DHS/CBP TRM/standards profile will be updated as TIs are resolved.

All developed solutions shall be compliant with the Homeland Security (HLS) EA. All IT hardware and software shall be compliant with the HLS EA.

Compliance with the HLS EA shall be derived from and aligned through the CBP EA.

Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Architecture Division (EAD) for review, approval, and insertion into the DHS Data Reference Model and Mobius.

Development of data assets, information exchanges, and data standards will comply with the DHS Data

Management Policy MD 103-01. All data-related artifacts will be developed and validated according to

DHS Data Management Architectural Guidelines.

Applicability of Internet Protocol version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS

EA (per OMB Memorandum M-05-22, August 2, 2005), regardless of whether the acquisition is for modification, upgrade, or replacement. All EA related component acquisitions shall be IPv6 compliant, as defined in the USGv6 Profile (NIST Special Publication 500-267) and the corresponding declarations of conformance, defined in the USGv6 Test Program.

2.2. DHS-TSA Enterprise Architecture Compliance

Per December 2022 version

a) The Contractor shall ensure that all architectural artifacts including but not limited to solutions, business, Data, IT elements for legacy Transportation Security Equipment (TSE), Information

Systems Security Agreements (ISSAs), System Design documents (SDDs), deliverables, and services are aligned and compliant with the current DHS and TSA Enterprise Architecture, and the

(The Common Approach to Federal Enterprise Architecture), the Technology Business Management

(TBM) Taxonomy, and Federal Information Technology Acquisition Reform Act (FITARA).

i. All solutions and services shall meet DHS and TSA Enterprise Architecture policies, standards, and procedures. Specifically:

a. DHS and TSA Enterprise Architecture policies, standards, and procedures.

b. Homeland Security Enterprise Architecture (HLS EA) and TSA EA requirements.

c. TSA and DHS IT Security, Cloud, Infrastructure (including Network), Application/Systems, Information/Data, Performance, and Business Architecture policies, directives, guidelines, standards, segment architectures and reference architectures.

d. TSA functional capabilities

e. TSA operational capabilities

f. TSA lines of business

g. TSA business processes

h. TSA funding sources

i. TBM Taxonomy for IT cost transparency

ii. All software and tools that are used to build, develop, or deploy IT solutions for TSA, shall leverage the TSA NextGen Architecture (NGA) Technology Stack known as “The

Kit”. In accordance with TSA CIO Priority 2.1 “Modernize, Simplify, Reduce and

Enforce TSA IT and Data Toolkit”, use of “the Kit” will achieve modernization and simplification, with the ultimate goal of reducing the current TSA Technology Footprint.

iii. This includes new Transportation Security Equipment (TSE) and Legacy TSE that utilizes IT software, services, or equipment including embedded IT elements such as network switches, routers, In printers, etc.

iv. All solutions shall implement, and leverage TSA information and data standards as defined and approved per TSA policy.

v. All solution architectures and services (e.g., Application, System, Network, Security, Information/Data, Cloud) shall be reviewed and approved by TSA EA as part of the TSA

SELC (System Engineering Life Cycle) review process and in accordance with TSA IT

Governance Management Directive 1400.20 with applicable DHS and TSA IT governance policies, directives, and processes. This includes the Solution Engineering

Review (SER), Preliminary Design Review (PDR) and Critical Design Review (CDR) stage gates. The required design artifacts include solution approach document, the PDR document, and the System Design Document (SDDs) as directed by EAD. Successful completion of the PDR/CDR stages results in an approved architecture which is required before proceeding to development. An approved architecture is also a necessary critical https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/common_approach_to_federal_ea.pdf step in receiving an Authority to Operate (ATO). All implementations shall follow the approved solution architecture/design without deviation. Any changes, to either the prior approved solution and/or prior approved design that are identified during subsequent

SELC phases, including testing, implementation and deployment, shall undergo additional EA review prior to proceeding.

vi. TSA Offices acquiring Enterprise architecture type services at segment or solution levels shall engage and collaborate with the TSA Enterprise Architecture Division (EAD) to ensure strategic alignment of people, process, information, and technology and comply with enterprise level architecture governance, artifacts and standards.

a. The Contractor shall engage domain architect(s) in EAD before SELC Obtain Phase, i.e., during SELC Need or “Analyze and Select” Phase.

b. The Contractor shall collaborate with the EA domain architect(s) to deliver the required design artifacts and desired outcome under the guidance.

c. The Contractor shall provide architecture and system/application data and models in prescribed formats to be stored in TSA’s Enterprise Architecture Repository.

b) In accordance with the TSA Cloud Strategy 2.0, April 2019, TSA’s approach to cloud computing and governance of migration to the cloud, the contractor shall ensure that the cloud solutions utilize the SaaS (Software as a Service) model as its primary approach to cloud implementation, and also, when necessary, will use Platform as a Service (PaaS) or Infrastructure as a Service (IaaS). The contractor shall adhere to the principles of cloud strategy to systematically retire or replace legacy applications by use of an integrated approach to cloud planning, architecture, hybrid deployment, and operation.

c) Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the

DHS Enterprise Architecture (per OMB Memorandum M-21-07, November 2020) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile

(National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program.

Information and Data Governance and Management

a) The Contractor shall develop, use, and dispose of TSA information and data assets following the

TSA governance processes established by the Enterprise Information/Data Governance Board

(EIDGB), in compliance with the DHS Enterprise Data Governance and Management MD

(Management Directive) 103-01.

i. TSA information and data assets include but are not limited to the TSA Data Catalog, TSA information and data standards, TSA Data Management Plan, TSA data sets

(including open data sets for public consumption), TSA information and data stored in https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf https://www.dhs.gov/xlibrary/assets/foia/mgmt_directive_103_01_enterprise_data_management_policy.pdf https://www.dhs.gov/xlibrary/assets/foia/mgmt_directive_103_01_enterprise_data_management_policy.pdf

TSA repositories, TSA information and data in systems and applications (internal and external), and TSA information exchanges.

ii. All TSA information and data, and all solutions that capture, store, use and provide TSA information and data shall comply with the Geospatial Data Act (GDA) of 2018 (P.L.

115-254) that requires agencies to foster efficient management of geospatial data/information, technologies, and infrastructure through enhanced coordination among

Federal, state, local, and tribal governments, along with private sector and academia.

iii. Description information for all data assets shall be submitted to the TSA Enterprise

Architecture Team, who will be responsible for coordination with DHS, and for review, approval and insertion into the TSA Data Reference Model and Enterprise Architecture

Repository.

iv. In addition to the Federal Acquisitions Regulations (FAR) Subpart 27.4 – ‘Rights in Data and Copyrights’ and Section 35.011 detailing technical data delivery, the contractor shall provide all TSA-specific data in a format maintaining pre-existing referential integrity and data constraints, as well as data structures in a format understandable to TSA.

Examples of data structures can be defined as, but not limited to:

a. Data models containing entities and attributes, identifying authoritative and trusted data sources, and depicting relationship mapping and, or linkages

b. Metadata information to define data definitions

c. Detailed data formats, type, and size

d. Delineations of the referential integrity (e.g., primary key/foreign key) of data schemas, structures, and or taxonomies

e. Information exchange specifications

v. All TSA-specific data shall be delivered in a secure and timely manner to TSA. Data security is defined within the ‘Requirements for Handling Sensitive, Classified, and/or

Proprietary Information’, section of this…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .