RFQ_04480_Final.pdf
PDF 318 KB Posted
- Attached to
- NCEH Geocoding Data Tracking Tool Federal contract opportunity
- Solicitation number
- 75D301-19-Q-69994
About this file
RFQ: 75D301-19-Q-69994
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ_6994_QandA.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
REQUEST FOR QUOTATIONS
(THIS IS NOT AN ORDER)
THIS RFQ IS X IS NOT A SMALL BUSINESS SET-ASIDE.
PAGE OF PAGES
1 30
1. REQUEST NO.
75D301-19-Q-69994
2. DATE ISSUED
04/16/2019
3. REQUISITION/PURCHASE REQUEST NO.
00HCUGED-2019-29589
4. CERT. FOR NAT. DEF.
UNDER BDSA REG. 2
AND/OR DMS REG. 1
RATING
5a. ISSUED BY Centers for Disease Control and Prevention Office of Acquisition Services (OAS) 2920 Brandywine Rd, RM 3000 Atlanta GA 303415539
6. DELIVERY BY (Date)
5b. FOR INFORMATION CALL (No collect calls)
NAME TELEPHONE NUMBER
AREA CODE NUMBER
Sean Sessions. Golan (404) 498-5647 x
8. TO: 9. DESTINATION
a. NAME b. COMPANY a. NAME OF CONSIGNEE
c. STREET ADDRESS b. STREET ADDRESS
c. CITY
d. CITY e. STATE f. ZIP CODE d. STATE e. ZIP CODE
10. PLEASE FURNISH QUOTATIONS TO
THE ISSUING OFFICE IN BLOCK 5a ON OR BEFORE CLOSE OF BUSINESS (Date)
IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or services.
Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this Request for Quotations must be completed by the quoter.
11. SCHEDULE (Include applicable Federal, State and local taxes)
ITEM NO.
(a)
SUPPLIES/SERVICES
(b)
QUANTITY
(c)
UNIT
(d)
UNIT PRICE
(e)
AMOUNT
(f)
REQUEST FOR QUOTATION NUMBER:
75D301-19-Q-69994
QUESTIONS ARE DUE ON OR BEFORE Monday, April 22, 2019 AT 8:00AM E.S.T.
QUOTATIONS ARE DUE ON OR BEFORE Tuesday, April 29, 2019 AT 5:00PM E.S.T.
ALL QUESTIONS & QUOTATIONS SHALL BE
SUMBITTED VIA EMAIL ONLY TO: yto1@cdc.gov
12. DISCOUNT FOR PROMPT PAYMENT a. 10 CALENDAR DAYS
b. 20 CALENDAR DAYS
c. 30 CALENDAR DAYS
d. CALENDAR DAYS
NUMBER PERCENTAGE
NOTE: Additional provisions and representations are are not attached.
13. NAME AND ADDRESS OF QUOTER 14. SIGNATURE OF PERSON AUTHORIZED TO
SIGN QUOTATION
15. DATE OF
QUOTATION
a. NAME OF QUOTER
b. STREET ADDRESS 16. SIGNER
a. NAME (Type or print) b. TELEPHONE
c. COUNTY AREA CODE
d. CITY e. STATE f. ZIP CODE c. TITLE (Type or print) NUMBER
AUTHORIZED FOR LOCAL REPRODUCTION STANDARD FORM 18 (REV. 6-95)
Previous edition not usable Prescribed by GSA FAR (48 CFR) 53.215-1(a)
7. DELIVERY
FOB
DESTINATION
OTHER
(See Schedule)
SECTION B – Services and Prices
Line Items
ITEM SUPPLIES / SERVICES QTY / UNIT UNIT PRICE EXTENDED PRICE
0001 Base Year
Geocoding Data Tracking Tool
The Contractor shall provide services & deliverables in accordance with the attached Statement of Work.
Period of Performance: TBD Estimated Base Year: April 22, 2019 - April 21, 2020
This is a Firm Fixed Price Line Item for Non-Severable Services.
1 Each $___________ $______________
Option 1 OY1 Items:
ITEM SUPPLIES / SERVICES QTY / UNIT UNIT PRICE EXTENDED PRICE
0002 Option Year1
Geocoding Data Tracking Tool
The Contractor shall provide services & deliverables in accordance with the attached Statement of Work.
Period of Performance: TBD Estimated Option Year 1: April 22, 2020 - April 21, 2021
This is a Firm Fixed Price Line Item for Non- Severable Services.
0003 Option Year2 Geocoding Data Tracking Tool
The Contractor shall provide services & deliverables in accordance with the attached Statement of Work.
Period of Performance: TBD Estimated Option Year 2: April 22, 2021 - April 21, 2022
This is a Firm Fixed Price Line Item for Non- Severable Services.
SECTION C – Description/Specification/Work Statement
Statement of Work
Title: NCEH Geocoding Data Tracking Tool
C.1 – BACKGROUND
CDC’s National Center for Environmental Health (NCEH) Division of Environmental Health Science and Practice (DEHSP) Lead Poisoning Prevention and Environmental Health Tracking Branch (LPPEHTB) seeks to improve the health of communities by collecting and geocoding data for better environmental public health tracking.
Environmental public health tracking is a type of surveillance. Surveillance is a method to monitor trends by collecting, interpreting, and reporting data. CDC's Environmental Public Health Tracking Network (Tracking Network) brings together health and environment data in one place, making it easier to compare hazards and exposures with health outcomes at a local and national level. The goal of the Tracking Network is to provide information to help improve where we live, work, and play.
The Tracking Network is part of CDC's National Environmental Public Health Tracking Program. The Tracking Program includes not only the Tracking Network but the people, resources, and program management involved in building this network. Tracking funds 25 states and one city who are awardees of Tracking’s notification of funding opportunity. The Tracking program receives data directly from these funding recipients. The recipient’s aggregate important health and environmental data counts in to state and county geographies. The Tracking program has a goal of providing finer geographic levels focused on census tracts and aggregates of census tracts to be displayed on our public web-based data portal. In order to assure accurate and reliable data from our states they need the resources and tools to geocode their record level data into census tracts. Geocoding is a process of transforming a description of a place or location into an actual location on the earth’s surface. It is a very complex process with many tools and decisions that must be made and that greatly affect the data that would be reported to us. Having a common tool that uses standard protocols available to our recipients would allow the Tracking Network to display standardized, consistent, high quality data that can easily be documented for users of our portal.
C.2 – DEFINITIONS
“Award” – Shall mean the final Order for Supplies or Services signed by the CDC Contracting Officer.
“Contractor” – Shall mean the commercial organization designated in box 7a. of the Award and individuals employed by that organization.
“Point of Contact” – Shall mean the CDC program staff designated in box 17b. of the Award as the CDC Point of Contact (POC).
“COR” – Shall mean the individual CDC program staff designated in the award as the Contract Officer’s Representative (COR)
C.3 – PURPOSE
The goal of the Project is to provide a software tool to be used by Tracking grant recipients to geocode a large number of diverse datasets to census tracts with a high degree of accuracy and a standard process.
C.4 – SCOPE OF WORK
The Tracking Program will work with awardee to establish required functionality of software, security protocols and connections, inputs and outputs, statistical logs, and customer support. Once implemented the geocoding services will need to be updated at a minimum yearly basis with new geo data and new functionality. The need for the geocoding services will be ongoing as new records are generated and submitted to CDC by the grantees on a yearly basis.
C.5 – TASKS TO BE PERFORMED
1. Contractor shall produce the NCEH Geocoding Data Tracking Tool including, but not limited to the following:
A. Implement a standardized geocoding service/portal on SAMS servers which:
• Accepts expected inputs and returns outputs in format approved by CDC Program
Manager, including but not limited to:
1. 4 fields provided in a comma separated values file
a. Street number and name
b. City
c. State
d. And/or ZIP code
• Returned fields include latitude, longitude, census tract, & zip code centroids.
B. Establish role based security to geocoding service:
• Access will be controlled through CDC Security Access Management Systems
(SAMS)
• Create an interface with SAMS to accept users
• Limit users access to designated data only
C. Geocode Data Received from SAMS that:
• Matches to finest resolution possible based on input:
1. Latitude and longitude
2. Land parcel
3. Street centroid
4. Street estimation
5. Census tract ID
6. ZIP code +4 ID
7. ZIP code ID
8. County ID (FIPS)
9. State ID (FIPS)
• Accepts expanded geographies from 3rd parties:
1. E911 data
2. County and state Parcel data
3. Other proprietary data that is matched to addresses
• E911 geographic data for more accuracy should be dynamically accepted D. Establish separate servers or virtual servers for data and application:
• Assure Tracking/CDC data is kept separate from other users
• Have the capability to automatically have data erased and not stored
• Capable of processing and storing up to 1 million records a day
E. Deliver geocoding statistics and data to CDC via a webpage dashboard:
• Include breakouts by state
• Number of records submitted
• % matched of records submitted to each resolution
C.6 – GOVERNMENT FURNISHED MATERIALS
This contract will not utilize any government furnished property.
C.7 – PERIOD OF PERFORMANCE
An estimate of the period of performance is outlined in the table below:
Contract Year Deliverable/Item Description Period of Performance Base Year NCEH Geocoding Data Tracking Tool 1 year from date of award (2019-2020) Option Year 1 NCEH Geocoding Data Tracking Tool (2020-2021)
Option Year 2 NCEH Geocoding Data Tracking Tool (2021-2022) The period of performance includes an evaluation period, after the final deliverable is due, during which the Government will evaluate the contractor’s deliverables and performance. The Division of Prevention will then decide whether to exercise the option.
C.8 – PLACE OF PERFORMANCE
Performance of all activities will take place at the contractor’s facility.
C.9– DELIVERABLES/REPORTING SCHEDULE
C.9.1 Base Year NCEH Geocoding Data Tracking Tool
Deliverable Delivered to Due Date Kickoff Meeting CDC Project manager Within 7 days of award.
Establish Standard Geocoding Format and Digital Data Input Portal on SAMS Servers
CDC Project manager Within 45 days of award.
Process & Geocode All Data Records
CDC Project manager Within in 120 Days of entry.
C.9.1 Option Year(s) NCEH Geocoding Data Tracking Tool Deliverable Delivered to Due Date Review & Planning Meeting CDC Project manager Within first 7 days of
Option period.
Adjust SAMS Portal Functions (e.g. Add new users, Lockout old users, Add additional input variables)
CDC Project manager Within 45 days of award.
Process & Geocode All Data Records
CDC Project manager Within in 120 Days of entry.
C.10 - Payment Schedule Offerors are encouraged to propose a milestone/performance payment schedule that best fits their proposed work flow, provided payments are no more frequent than monthly, in arears. If accepted without changed it will be incorporated into the final contract at the time of award. If necessary, discussions may be opened and the final milestone/performance payment schedule may be negotiated between the parties. Once the parties agree the final milestone/performance payment schedule will be incorporated into in the contract. If necessary, the finalized chart will be incorporated in the contract via modification.
Upon successful completion of the event, the contractor may submit an invoice. The determination of eligibility for receipt of payment will be made by the Contracting Officer upon written certification from the COR that the performance milestone has been met. It is anticipated that each milestone payment will approximate the estimated timeline listed below. Milestone payments are subject to the terms of FAR 52.232-32 incorporated in Section I of this contract.
Proposed Payment Schedule
Core Tasks
Milestone
Payment frequency Payment
Final Deliverables delivered to CDC Project Manager and all data received during POP is processed, geocoded, and delivered.
Annually
100%
C.11– TRAVEL
No travel is required.
C.12 – SPECIAL REQUIREMENTS
INFORMATION TECHNOLOGY (IT) SECURITY
Contractor performance and resulting deliverables must adhere to all federal, HHS, and/or CDC IT security policies and procedures.
Government Information Processed on GOCO or COCO Systems A. Security Requirements for Government Owned Contractor Operated (GOCO) and Contractor Owned Contractor Operated (COCO) Resources
1) Federal Policies. The Contractor (and/or any subcontractor) shall comply with applicable federal directives that include, but are not limited to, the HHS Information Security and Privacy Policy (IS2P), the CDC Protection of Information Resources policy; Federal Information Security Modernization Act (FISMA) of 2014, (44 U.S.C. 101);
National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations; Office of Management and Budget (OMB) Circular A-130, Managing Information as a Strategic Resource; and other applicable federal laws, regulations, NIST guidance, and Departmental policies.
2) Security Assessment and Authorization (SA&A). A valid authority to operate (ATO) certifies that the Contractor’s information system meets the contract’s requirements to protect the agency data. If the system under this contract does not have a valid ATO, the Contractor (and/or any subcontractor) shall work with the agency and supply the deliverables required to complete the ATO prior to any use of the system in a production capacity, i.e., its intended users able to collect, store, process or transmit data to fulfill the system’s function. The Contractor shall conduct the SA&A requirements in accordance with HHS IS2P/ CDC Protection of Information Resources; the CDC IT Security Program Implementation Standards; the CDC Security Assessment and Authorization (SA&A) Standard Operating Procedure; and NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach (latest revision).
CDC acceptance of the ATO does not alleviate the Contractor’s responsibility to ensure the system security and privacy controls are implemented and operating effectively.
a. SA&A Package Deliverables - The Contractor (and/or any subcontractor) shall provide an SA&A package to the C/I/O Information System Security Officer (ISSO) in accordance with the timeline, process and formats proscribed for a Full system authorization in the CDC Security Assessment and Authorization Standard Operating Procedure (CDC SA&A SOP). The following SA&A deliverables are required to complete the SA&A package:
• Baseline System Information (BSI) – The Contractor will document a system overview, in accordance with the timeline, process and formats described in the CDC SA&A SOP. The BSI will include information concerning: system identification and ownership; system data, information types, impact levels and system categorization; system functional description / general purpose; system authorization boundary and environment;
system user descriptions; and system interconnections and dependencies. The Contractor shall update the BSI at least annually thereafter.
• Privacy Threshold Analysis / Privacy Impact Analysis – The Contractor (and/or any subcontractor) shall provide a PTA/PIA (as appropriate), in accordance with the timeline, process and formats described in the CDC SA&A SOP, if applicable. Also see the sections of this contract concerning “Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA)” and “Requirements for Procurements Involving Privacy Act Records.”
NOTE: If social security numbers (SSN) are expected to be handled by the system, the program and Contractor must include a SSN Elimination or Usage Approval Request along with the PTA/PIA. That request will be processed in accordance with the OCISO Standard for Limiting the Use of Social Security Numbers in CDC Information Systems.
• System Security Plan (SSP) – The SSP must be provided in a digital format supporting copy or export of all content into the HHS/CDC automated SA&A tool. The SSP shall comply with the NIST SP 800-18, Guide for Developing Security Plans for Federal Information Systems, the Federal Information Processing Standard (FIPS) 200, Recommended Security Controls for Federal Information Systems, and NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline requirements, and other applicable NIST guidance as well as HHS and CDC policies and other guidance. The SSP shall be consistent with and detail the approach to IT security contained in the Contractor’s bid or proposal that resulted in the award of this contract.
The SSP shall provide an overview of the system environment (including an inventory of all devices and software contained within the system boundary) and security requirements to protect the information system as well as describe all applicable security controls in place or planned for meeting those requirements. It should provide a structured process for planning adequate, cost-effective security protection for a system. The Contractor shall update the SSP at least annually thereafter.
• Risk Assessment Report (RAR) The initial security assessment shall be conducted by the Contractor in conjunction with the program’s Information System Security Officer, consistent with NIST SP 800-53A, NIST SP 800-30, and HHS and CDC policies. The assessor will document and submit the assessment results in the RAR, in accordance with the process and formats described in the CDC SA&A SOP. The Contractor shall address all “High” deficiencies before submitting the package to the Government for acceptance. All remaining deficiencies must be documented in a system Plan of Actions and Milestones (POA&M) for CDC OCISO approval in accordance with the CDC SA&A SOP. Thereafter, the Contractor, in coordination with CDC shall conduct an assessment of the security controls and update the RAR within 365 days.
POA&M –The POA&M shall be documented consistent with the HHS Standard for Plan of Action and Milestones and CDC policies. Identified risks stemming from deficiencies related to the security control baseline implementation, assessment, continuous monitoring, vulnerability scanning, and other security reviews and sources, as documented in the Security Assessment Report (SAR), shall be documented and tracked by the Contractor for mitigation in the POA&M document. Depending on the severity of the risks, CDC may require designated POAM weaknesses to be remediated before an ATO is issued. Thereafter, the POA&M shall be updated at least quarterly.
• Contingency Plan and Contingency Plan Test –The Contingency Plan must be developed in accordance with NIST SP 800-34, Contingency Planning Guide for Federal Information Systems, and be consistent with HHS and CDC policies. Upon acceptance by the System Owner, the Contractor, in coordination with the System Owner, shall test the Contingency Plan and prepare a Contingency Plan Test Report that includes the test results, lessons learned and any action items that need to be addressed. Thereafter, the Contractor shall update and test the Contingency Plan at least annually.
• E-Authentication Assessment – The contractor (and/or any subcontractor) shall collaborate with government personnel to ensure that an E-Authentication Threshold Analysis (E-auth TA) is completed to determine if a full E-Authentication Risk Assessment (E-auth RA) is necessary. System documentation developed for a system using E-auth TA/E-auth RA methods shall follow OMB 04-04; NIST SP 800-63, Digital Identity Guidelines; the OCISO Standard for Electronic Authentication (E-Authentication); and the CDC SA&A SOP.
Based on the level of assurance determined by the E-Auth, the Contractor (and/or subcontractor) must ensure appropriate authentication to the system, including remote authentication, is in-place in accordance with the assurance level determined by the E-Auth (when required) in accordance with HHS policies.
b. Information Security Continuous Monitoring. Upon the government issuance of an Authority to Operate (ATO), the Contractor (and/or subcontractor)-owned/operated systems that input, store, process, output, and/or transmit government information, shall meet or exceed the information security continuous monitoring (ISCM) requirements in accordance with FISMA and NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations, and HHS IS2P. The following are the minimum requirements for ISCM:
• Annual Assessment/Pen Test - Assess the system security and privacy controls (or ensure an assessment of the controls is conducted) at least annually to determine the implemented security and privacy controls are operating as intended and producing the desired results (this may involve penetration testing conducted by the agency or independent third-party). In addition, review all relevant SA&A documentation (SSP, POA&M, Contingency Plan, etc.) and provide updates by specified due date.
• Asset Management - Using any available Security Content Automation Protocol (SCAP)-compliant automated tools for active/passive scans, provide an inventory of all information technology (IT) assets for hardware and software, (computers, servers, routers, databases, operating systems, etc.) that are processing HHS-owned information/data. It is anticipated that this inventory information will be required to be produced at least annually. IT asset inventory information shall include IP address, machine name, operating system level, security patch level, and SCAP-compliant format information. The contractor shall maintain a capability to provide an inventory of 100% of its IT assets using SCAP-compliant automated tools.
• Configuration Management - Use available SCAP-compliant automated tools, per NIST IR 7511, for authenticated scans to provide visibility into the security configuration compliance status of all IT assets, (computers, servers, routers, databases, operating systems, application, etc.) that store and process government information. Compliance will be measured using IT assets and standard HHS and government configuration baselines at least annually. The contractor shall maintain a capability to provide security configuration compliance information for 100% of its IT assets using SCAP-compliant automated tools.
• Vulnerability Management - Use SCAP-compliant automated tools for authenticated scans to scan information system(s) and detect any security vulnerabilities in all assets (computers, servers, routers, Web applications, databases, operating systems, etc.) that store and process government information. Contractors shall actively manage system vulnerabilities using automated tools and technologies where practicable and in accordance with HHS policy. Automated tools shall be compliant with NIST-specified SCAP standards for vulnerability identification and management. The contractor shall maintain a capability to provide security vulnerability scanning information for 100% of IT assets using SCAP-compliant automated tools and report to the agency at least annually.
• Patching and Vulnerability Remediation - Install vendor released security patches and remediate critical and high vulnerabilities in systems processing government information in an expedited manner, within vendor and agency specified timeline per OCISO Vulnerability Remediation Framework Standard.
• Secure Coding - Follow secure coding best practice requirements, as directed by United States Computer Emergency Readiness Team (US-CERT) specified standards and the Open Web Application Security Project (OWASP), that will limit system software vulnerability exploits.
• Boundary Protection - The contractor shall ensure that government information, other than unrestricted information, being transmitted from federal government entities to external entities is routed through a Trusted Internet Connection (TIC).
1) Government Access for Security Assessment. In addition to the Inspection Clause in the contract, the Contractor (and/or any subcontractor) shall afford the Government access to the Contractor’s facilities, installations, operations, documentation, information systems, and personnel used in performance of this contract to the extent required to carry out a program of security assessment (to include vulnerability testing), investigation, and audit to safeguard against threats and hazards to the confidentiality, integrity, and availability of federal data or to the protection of information systems operated on behalf of HHS, including but are not limited to:
a. At any tier handling or accessing information, consent to and allow the Government, or an independent third party working at the Government’s direction, without notice at any time during a weekday during regular business hours contractor local time, to access contractor and subcontractor installations, facilities, infrastructure, data centers, equipment (including but not limited to all servers, computing devices, and portable media), operations, documentation (whether in electronic, paper, or other forms), databases, and personnel which are used in performance of the contract.
The Government includes but is not limited to the U.S. Department of Justice, U.S. Government Accountability Office, and the HHS Office of the Inspector General (OIG). The purpose of the access is to facilitate performance inspections and reviews, security and compliance audits, and law enforcement investigations. For security audits, the audit may include but not be limited to such items as buffer overflows, open ports, unnecessary services, lack of user input filtering, cross-site scripting vulnerabilities, SQL injection vulnerabilities, and any other known vulnerabilities.
b. At any tier handling or accessing protected information, fully cooperate with all audits, inspections, investigations, forensic analysis, or other reviews or requirements needed to carry out requirements presented in applicable law or policy. Beyond providing access, full cooperation also includes, but is not limited to, disclosure to investigators of information sufficient to identify the nature and extent of any criminal or fraudulent activity and the individuals responsible for that activity. It includes timely and complete production of requested data, metadata, information, and records relevant to any inspection, audit, investigation, or review, and making employees of the contractor available for interview by inspectors, auditors, and investigators upon request. Full cooperation also includes allowing the Government to make reproductions or copies of information and equipment, including, if necessary, collecting a machine or system image capture.
c. Segregate Government protected information and metadata on the handling of Government protected information from other information. Commingling of information is prohibited. Inspectors, auditors, and investigators will not be precluded from having access to the sought information if sought information is commingled with other information.
d. Cooperate with inspections, audits, investigations, and reviews.
2) End of Life Compliance. The Contractor (and/or any subcontractor) must use Commercial off the Shelf (COTS) software or other software that is supported by the manufacturer. In addition, the COTS/other software need to be within one major version of the current version; deviation from this requirement will only be allowed via the HHS waiver process (approved by HHS CISO). The contractor shall retire and/or upgrade all software/systems that have reached end-of-life in accordance with HHS End-of-Life Operating Systems, Software, and Applications Policy.
3) Desktops, Laptops, and Other Computing Devices Required for Use by the Contractor. The Contractor (and/or any subcontractor) shall ensure that all IT equipment (e.g., laptops, desktops, servers, routers, mobile devices, peripheral devices, etc.) used to process information on behalf of HHS are deployed and operated in accordance with approved security configurations and meet the following minimum requirements:
a. Encrypt information categorized as moderate or high impact as required by OMB Memorandum A-130, Managing Information as Strategic Resource, in accordance with the HHS Standard for Encryption of Computing Devices and Information and FIPS 140-2.
b. Configure laptops and desktops in accordance with the latest applicable United States Government Configuration Baseline (USGCB) and HHS Minimum Security Configuration Standards;
c. Maintain the latest operating system patch release and anti-virus software definitions;
d. Validate the configuration settings after hardware and software installation, operation, maintenance, update, and patching and ensure changes in hardware and software do not alter the approved configuration settings; and
e. Automate configuration settings and configuration management in accordance with HHS security policies, including but not limited to:
• Configuring its systems to allow for periodic HHS vulnerability and security configuration assessment scanning; and
• Using Security Content Automation Protocol (SCAP)-validated tools with USGCB Scanner capabilities to scan its systems at least on a monthly basis and report the results of these scans to the CO and/or COR, Project Officer, and any other applicable designated POC.
4) Change Management. Once a system is authorized, all changes must be approved by CDC in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations; the HHS IS2P; and the timeline, process and formats proscribed in the CDC OCISO Change Management Standard Operating Procedure.
5) Retirement / Decommissioning. When the CDC program and Contractor determine the system is no longer required, it must be decommissioned in accordance NIST SP 800-88, Guidelines for Media Sanitization; the HHS IS2P; and the timeline, process and formats proscribed in the CDC OCISO System Retirement Standard Operating Procedure.
Deliverable Title/Deliverable Type Description Due Date
Security Assessment and Authorization (SA&A)
SA&A Package
SSP
SAR
POA&M
Authorization Letter CP and CPT Report E-Auth (if applicable) PTA/PIA (if applicable) Interconnection/Data Use Agreements (if applicable) Authorization Letter Configuration Management Plan (if applicable) Configuration Baseline Other OpDiv-specific documents
Due within 120 days of system planned go-live date.
Information Technology Application Design, Development, or Support
1. The Contractor (and/or any subcontractor) shall ensure IT applications designed and developed for end users (including mobile applications and software licenses) run in the standard user context without requiring elevated administrative privileges.
2. The Contractor (and/or any subcontractor) shall follow secure coding best practice requirements, as directed by United States Computer Emergency Readiness Team (US-CERT) specified standards and the Open Web Application Security Project (OWASP), that will limit system software vulnerability exploits.
3. The Contractor (and/or any subcontractor) shall ensure that computer software developed on behalf of HHS or tailored from an open-source product, is fully functional and operates correctly on systems configured in accordance with government policy and federal configuration standards. The contractor shall test applicable products and versions with all relevant and current updates and patches updated prior to installing in the HHS environment. No sensitive data shall be used during software testing.
4. Contractor (and/or any subcontractor) shall protect information that is deemed sensitive from unauthorized disclosure to persons, organizations or subcontractors who do not have a need to know the information.
Information which, either alone or when compared with other reasonably-available information, is deemed sensitive or proprietary by HHS shall be protected as instructed in accordance with the magnitude of the loss or harm that could result from inadvertent or deliberate disclosure, alteration, or destruction of the data. This language also applies to all subcontractors that are performing under this contract.
5. The Contractor (and/or any subcontractor) shall remediate all risks or vulnerabilities immediately after the risks or vulnerabilities have been identified in the software.
Deliverable Title Description Due Date Geocoding Tool Computer software and documentation, including the source code.
Due within 120 days of system planned go-live date and at the end of the contract.
Development or implementation of any federal information system1 or any electronic data collection effort conducted in the performance of this contract will be required to complete Security Authorization (also known as
1 Defining federal information systems:
- “Federal Information System” [40 U.S.C., Sec. 11331]: An information system used or operated by an executive agency, by a contractor of an executive agency, or by another organization on behalf of an executive agency.
- “Information System” [44 U.S.C., Sec. 3502]: A discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information.
“C&A”) prior to operation resulting in an Authority of Operate (ATO) from CDC. The contractor shall be required to complete all security documentation and materials necessary to obtain and maintain an ATO. The contractor shall comply with all applicable HHS, CDC, FISMA, HIPPA, NIST, and other federal policies and regulations in the performance of the security requirements.
All information systems developed, implemented, or maintained in support of this contract must adhere to the security controls outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations (as of the date of the SOW review, the current version can be found at http://csrc.nist.gov/publications/PubsSPs.html) and NIST 800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations.
The Contractor must follow the guidance available from NIST and other recognized sources, including:
• NIST Special Publication 800-60, Guide for Mapping Types of Information and Information Systems to
Security Categories Vol. 1 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf) and Vol. 2 (http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf).
• NIST Special Publication 800-63, Electronic Authentication Guideline (http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf)
SOCIAL MEDIA AND OTHER THIRD-PARTY WEBSITE USAGE
Use of any and all third-party2 / social media3 sites must be approved in advance, and comply with HHS and CDC policies, procedures and best practices (including security and privacy) such as those found at:
http://www.hhs.gov/web/socialmedia/ and http://www.cdc.gov/SocialMedia/Tools/guidelines/. Contractor will submit necessary documentation, in cooperation with the Project Officer, to obtain approval through designated CDC Social Media governance, as well as Information Security and Privacy Officers.
CAPITAL PLANNING AND INVESTMENT CONTROL/PROJECT MANAGEMENT
The Clinger-Cohen Act (CCA2) legislatively mandates the prudent management of IT investments. Capital Planning and Investment Control (CPIC) is a continuous and integrated process for managing the risks and returns of information technology (IT) investments. The CPIC process fully integrates with the CDC’s overall budget, finance, acquisition, strategic planning, enterprise architecture, security, and other relevant processes. CPIC also aligns with DHHS Enterprise Performance Life Cycle (EPLC) framework and is used for all IT related decisions.
The contractor will follow the EPLC framework which will provide a standard structure for planning, managing, and overseeing IT projects over their entire life cycle. The framework consists of ten life cycle phases. Within each phase, activities, responsibilities, reviews and deliverables are defined. Templates for the deliverables are available to the contractor after award. Exit criteria are established for each phase and Stage Gate reviews are conducted through CDC’s IT Governance process to ensure that the project’s management quality, soundness, and technical feasibility remain adequate and the project is ready to move forward to the next phase. All IT projects in support of this task must adhere to the EPLC requirements and pass each State Gate as appropriate. More information about EPLC can be found at http://www.hhs.gov/ocio/eplc/.
MOBILE APPLICATION DEVELOPMENT
All mobile applications must comply with CDC-related technical and security standards, processes and procedures as stated in the IT Security section of the RFTOP. In addition, the following considerations should be addressed in the proposal:
• The target platform(s) for the mobile application (e.g. iPhone, iPad, Android, Blackberry)
• Approach to 508 compatibility for the platform of choice
• If the mobile application will be made available in a related platform’s online store (e.g. iTunes, Android
Market), the process for making it available in a desired store will be managed by and through CDC, 2 Third-party websites are Internet-based commercial and other non-CDC information services that offer information gathering, storage and processing services, without the usual contracting mechanisms. Examples include SurveyMonkey, DiscoveryCast and Google collaboration sites.
3 "Social media are various activities that integrate technology, social interaction, and content creation. Social media uses many technologies and forms, such as blogs, wikis, photo and video sharing, podcasts, social networking, mash-ups, and virtual worlds." U.S. General Administration (GSA) http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol1-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-63/SP800-63V1_0_2.pdf http://www.hhs.gov/web/socialmedia/ http://www.cdc.gov/SocialMedia/Tools/guidelines/ http://www.hhs.gov/ocio/eplc/ http://www.gsa.gov/graphics/staffoffices/socialmediapolicy.pdf resulting in a CDC branded mobile application. The contractor will also be responsible for ensuring the mobile application complies with all standards and specifications for the desired store.
WEB TECHNOLOLGY
The contractor must follow CDC development standards and use the CDC web template package. The CDC Secure Web Application Coding Guidelines and CDC Template Package can be provided by the CDC Project Officer.
All IT development must adhere to Section 508 of the 1986 addition to the Rehabilitation Act of 1973.
RECORDS RETENTION
• All data created during the course of this contract must be retained, stored and disposed of in accordance with the appropriate CDC Records Control Schedule.
DATA RIGHTS
• The Government has unlimited rights to all documents/material or other products produced under this contract. All documents, materials or other products, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
C.13 – REFERENCE MATERIALS
• Federal Section 508 Laws and Guideline http://www.access-board.gov/508.htm
• Federal Information Security Management Act of 2002 (FISMA).
http://csrc.nist.gov/groups/SMA/fisma/index.html
• The Privacy Act of 1974 - adequate administrative, operational, and technical security controls must be implemented to prevent unauthorized access to or disclosure of any personally identifiable information (PII) that will be accessed by the contractor http://www.hhs.gov/foia/privacy/index.html
• Paperwork Reduction Act (PRA) http://www.hhs.gov/ocio/policy/collection/index.html
• E-Government Act of 2002 http://www.archives.gov/about/laws/egov-act-section-207.html
• CDC Information Technology Guidelines (May be made available by the COR upon request, after execution of a CDC/HHS Non-disclosure Agreement)
• CDC Web Template Guidelines http://www.cdc.gov/healthcommunication/ToolsTemplates
• CDC Social Media Guidelines http://www.cdc.gov/SocialMedia/Tools/guidelines/index.html
• Other guidelines as produced and sanctioned by the CDC.gov web Council and the CDC Social Media
Council http://www.cdc.gov/healthcommunication/index.html
• Office of Management and Budget (OMB), National Institute of Standards and Technology (NIST), and General Accounting Office (GAO) policies that can be primarily found at or through the Federal CIO Council website at http://cio.gov
• NCEH/ATSDR Information Resources Governance Board See CDC/HHS Enterprise Performance Life Cycle {EPLC} http://www2a.cdc.gov/cdcup/library/other/eplc.htm
NOTE: Copies of relevant non–public CDC internal information security and privacy guidance can be made available upon execution and submission of an appropriate non-disclosure form to the supporting Information System Security Officer, via the Contracting Officer.
http://intranet.cdc.gov/ociso/pandp/documents/CDC_Secure_Web_App_Coding_Guidelines.pdf http://intranet.cdc.gov/ociso/pandp/documents/CDC_Secure_Web_App_Coding_Guidelines.pdf http://knowledgeshare.cdc.gov/08._Web_Development/CDC.gov_Internet_Templates http://www.access-board.gov/508.htm http://csrc.nist.gov/groups/SMA/fisma/index.html http://www.hhs.gov/foia/privacy/index.html http://www.hhs.gov/ocio/policy/collection/index.html http://www.archives.gov/about/laws/egov-act-section-207.html http://www.cdc.gov/healthcommunication/ToolsTemplates http://www.cdc.gov/SocialMedia/Tools/guidelines/index.html http://www.cdc.gov/healthcommunication/index.html http://cio.gov/ http://www2a.cdc.gov/cdcup/library/other/eplc.htm
C.14– CONTRACTING PERSONNEL INFORMATION
The Contract Specialist for this procurement is:
Sean Golan Telephone Number: 404-498-5647 E-mail Address: yto1@cdc.gov Preferred method of communication: e-mail
The Contracting Officer for the procurement is:
H. Dale Bish Telephone Number: 404-498-1312 E-mail Address: uwo8@cdc.gov Preferred method of communication: e-mail
SECTION D – Clauses
D.1 Clauses Incorporated by Reference
FAR 52.252-2 -- CLAUSES INCORPORATED BY REFERENCE. (Feb 1998) This contract incorporates one or more clauses by reference, with the same force and effect as if they were given in full text. Upon request, the Contracting Officer will make their full text available. Also, the full text of a clause may be accessed electronically at this/these address(es):
http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/far1toc.htm http://www.hhs.gov/policies/hhsar/subpart301-1.html
FAR SOURCE TITLE AND DATE
52.204-13 System for Award Management Maintenance (Oct 2018) 52.204-18 Commercial and Government Entity Code Maintenance (Jul 2016) 52.212-4 Contract Terms and Conditions- Commercial Items (Oct 2018) 52.232-39 Unenforceability of Unauthorized Obligations (Jul 2013) 52.232-40 Providing Accelerated Payments to Small Business Contractors (Dec 2013) 52.227-14 Rights in Data—General (May 2014)
HHSAR SOURCE TITLE AND DATE
352.222-70 Contractor Cooperation in Equal Employment Opportunity Investigations (Dec 2015)
(End of Clause)
FAR 52.212-5 -- Contract Terms and Conditions Required to Implement Statutes or Executive Orders -- Commercial Items (Jan 2019)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
mailto:yto1@cdc.gov mailto:uwo8@cdc.gov http://farsite.hill.af.mil/reghtml/regs/far2afmcfars/fardfars/far/far1toc.htm
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (Jan 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (Jul 2018) (Section 1634 of Pub. L. 115-91).
(3) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (Nov 2015)
(4) 52.233-3, Protest After Award (AUG 1996) (31 U.S.C. 3553).
(5) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77, 108-78 (19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the contracting officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial items:
[Contracting Officer check as appropriate.]
___ (1) 52.203-6, Restrictions on Subcontractor Sales to the Government (Sept 2006), with Alternate I (Oct 1995) (41 U.S.C. 4704 and 10 U.S.C. 2402).
___ (2) 52.203-13, Contractor Code of Business Ethics and Conduct (Oct 2015) (41 U.S.C. 3509).
___ (3) 52.203-15, Whistleblower Protections under the American Recovery and Reinvestment Act of 2009 (Jun 2010) (Section 1553 of Pub L. 111-5) (Applies to contracts funded by the American Recovery and Reinvestment Act of 2009).
_X__ (4) 52.204-10, Reporting Executive Compensation and First-Tier Subcontract Awards (Oct 2018) (Pub. L. 109-282) (31 U.S.C. 6101 note).
___ (5) [Reserved]
___ (6) 52.204-14, Service Contract Reporting Requirements (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
___ (7) 52.204-15, Service Contract Reporting Requirements for Indefinite-Delivery Contracts (Oct 2016) (Pub. L. 111-117, section 743 of Div. C).
_X__ (8) 52.209-6, Protecting the Government’s Interest When Subcontracting with Contractors Debarred, Suspended, or Proposed for Debarment (Oct 2015) (31 U.S.C. 6101 note).
___ (9) 52.209-9, Updates of Publicly Available Information Regarding Responsibility Matters (Oct 2018) (41 U.S.C. 2313).
___ (10) [Reserved]
___ (11) (i) 52.219-3, Notice of HUBZone Set-Aside or Sole-Source Award (Nov 2011) (15 U.S.C. 657a).
___ (ii) Alternate I (Nov 2011) of 52.219-3.
___ (12) (i) 52.219-4, Notice of Price Evaluation Preference for HUBZone Small Business Concerns (Oct 2014) (if the offeror elects to waive the preference, it shall so indicate in its offer)(15 U.S.C. 657a).
___ (ii) Alternate I (Jan 2011) of 52.219-4.
___ (13) [Reserved]
_X__ (14) (i) 52.219-6, Notice of Total Small Business Aside (Nov 2011) (15 U.S.C. 644).
___ (ii) Alternate I (Nov 2011).
___ (iii) Alternate II (Nov 2011).
___ (15) (i) 52.219-7, Notice of Partial Small Business Set-Aside (June 2003) (15 U.S.C. 644).
___ (ii) Alternate I (Oct 1995) of 52.219-7.
___ (iii) Alternate II (Mar 2004) of 52.219-7.
___ (16) 52.219-8, Utilization of Small Business Concerns (Oct 2018) (15 U.S.C. 637(d)(2) and (3)).
___ (17) (i) 52.219-9, Small Business Subcontracting Plan (Aug 2018) (15 U.S.C. 637 (d)(4)).
___ (ii) Alternate I (Nov 2016) of 52.219-9.
___ (iii) Alternate II (Nov 2016) of 52.219-9.
___ (iv) Alternate III (Nov 2016) of 52.219-9.
___ (v) Alternate IV (Aug 2018) of 52.219-9.
___ (18) 52.219-13, Notice of Set-Aside of Orders (Nov 2011) (15 U.S.C. 644(r)).
___ (19) 52.219-14, Limitations on Subcontracting (Jan 2017) (15 U.S.C. 637(a)(14)).
___ (20) 52.219-16, Liquidated Damages—Subcontracting Plan (Jan 1999) (15 U.S.C. 637(d)(4)(F)(i)).
___ (21) 52.219-27, Notice of Service-Disabled Veteran-Owned Small Business Set-Aside (Nov 2011) (15 U.S.C. 657f).
_X__ (22) 52.219-28, Post Award Small Business Program Rerepresentation (Jul 2013) (15 U.S.C.
632(a)(2)).
___ (23) 52.219-29, Notice of Set-Aside for, or Sole Source Award to, Economically Disadvantaged Women-Owned Small Business Concerns (Dec 2015) (15 U.S.C. 637(m)).
___ (24) 52.219-30, Notice of Set-Aside for, or Sole Source Award to, Women-Owned Small Business Concerns Eligible Under the Women-Owned Small Business Program (Dec 2015) (15 U.S.C. 637(m)).
_X__ (25) 52.222-3, Convict Labor (June 2003) (E.O. 11755).
___ (26) 52.222-19, Child Labor—Cooperation with Authorities and Remedies (Jan 2018) (E.O. 13126).
_X__ (27) 52.222-21, Prohibition of Segregated Facilities (Apr 2015).
_X__ (28) (i) 52.222-26, Equal Opportunity (Sep 2016) (E.O. 11246).
___ (ii) Alternate I (Feb 1999) of 52.222-26.
_X__ (29) (i) 52.222-35, Equal Opportunity for Veterans (Oct 2015) (38 U.S.C. 4212).
___ (ii) Alternate I (July 2014) of 52.222-35.
_X__ (30) (i) 52.222-36, Equal Opportunity for Workers with Disabilities (Jul 2014) (29 U.S.C. 793).
___ (ii) Alternate I (July 2014) of 52.222-36.
_X__ (31) 52.222-37, Employment Reports on Veterans (Feb 2016) (38 U.S.C. 4212).
___ (32) 52.222-40, Notification of Employee Rights Under the National Labor Relations Act (Dec 2010) (E.O. 13496).
_X__ (33) (i) 52.222-50, Combating Trafficking in Persons (JAN 2019)
(22 U.S.C. chapter 78 and E.O. 13627).
___ (ii) Alternate I (Mar 2015) of 52.222-50, (22 U.S.C. chapter 78 and E.O. 13627).
___ (34) 52.222-54, Employment Eligibility Verification (Oct 2015). (E. O. 12989). (Not applicable to the acquisition of commercially available off-the-shelf items or certain other types of commercial items as prescribed in 22.1803.)
___ (35) (i) 52.223-9, Estimate of Percentage of Recovered Material Content for EPA-Designated Items (May 2008) (42 U.S.C. 6962(c)(3)(A)(ii)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
___ (ii) Alternate I (May 2008) of 52.223-9 (42 U.S.C. 6962(i)(2)(C)). (Not applicable to the acquisition of commercially available off-the-shelf items.)
___ (36) 52.223-11, Ozone-Depleting Substances and High Global Warming Potential Hydrofluorocarbons (Jun 2016) (E.O.13693).
___ (37) 52.223-12, Maintenance, Service, Repair, or Disposal of Refrigeration Equipment and Air Conditioners (Jun 2016) (E.O.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.