AMENDMENT 3 75D301-23-Q-76498 Face App QA_3.pdf
PDF 521 KB Posted
- Attached to
- Face Measuring Mobile Application Federal contract opportunity
- Solicitation number
- 75D301-23-Q-76498
About this file
This document is an amendment to a solicitation for a face measuring mobile application. The Centers for Disease Control and Prevention is seeking a mobile application that can locally perform face scans, measurements, data collection, storage and analysis on Apple and Android devices. The app must include user profiles, the ability to export analysis for reporting to the CDC, and meet security requirements outlined in NIST SP 800-53 Rev. 5. Questions were answered providing clarification around supported device models, data transfer processes, authentication methods, and the development technology stack. The deadline for questions is June 16, 2023 and quotes must be received by June 28, 2023. The award will be a firm-fixed price contract issued to the best value offeror.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| RFQ Face App 75D301-23-Q-76498 6-26-23 Amendment 2.pdf | ||
| AMENDMENT 2 75D301-23-Q-76498 Face App_06-26-2023.pdf | ||
| AMENDMENT 1 75D301-23-Q-76498 Face App QA_1 DJM.pdf | ||
| Attachement D1 -CDC Secure Software Development.pdf | ||
| RFQ Face App 75D301-23-Q-76498 6-2-23.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NSN 7540-01-152-8070 STANDARD FORM 30 (REV. 10-83)
PREVIOUS EDITION UNUSABLE 30-105 Prescribed by GSA
FAR (48 CFR) 53.243
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
1. CONTRACT ID CODE
PAGE OF PAGES
1 5
2. AMENDMENT/MODIFICATION NO.
00003
3. EFFECTIVE DATE
See Block 16C.
4. REQUISITION/PURCHASE REQ. NO.
5. PROJECT NO. (If applicable)
6. ISSUED BY CODE 3635 7. ADMINISTERED BY (If other than Item 6) CODE 3635 Ctrs for Disease Control & Prevention PGH Office of Acquisition Services, Branch 4 626 Cochrans Mill Rd Pittsburgh, PA 15236-0070
8. NAME AND ADDRESS OF CONTRACTOR (No., street, county, State and ZIP Code)
X
9A. AMENDMENT OF SOLICITATION NO.
75D301-23-Q-76498
9B. DATED (See Item 11)
June 5, 2023
10A. MODIFICATION OF CONTRACT/ORDER NO.
10B. DATED (See Item 13)
CODE FACILITY CODE
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offers is extended, X is not extended.
Offers must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended, by one of the following methods:
(a) By completing Items 8 and 15, and returning one(1) copy of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted; or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT ORDER NO. IN
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor is not, X is required to sign this document and return one (1) copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
The purpose of this amendment is to provide answers to questions. See pages 2-5.
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print)
16A. NAME OF CONTRACTING OFFICER
Diane J Meeder
15B. CONTRACTOR/OFFEROR
(Signature of person authorized to sign)
15C. DATE SIGNED
16B. UNITED STATES OF AMERICA
BY ___________________________________________
(Signature of Contracting Officer)
16C. DATE SIGNED
ITEM 10A.
Amend 3. Answers to Questions #1 RFQ 75D301-23-R-76498 for project entitled, "Face Measuring Mobile Application"
1. Are NIOSH and CDC familiar and comfortable with cross platform mobile development technology stacks such as React Native?
-CDC has past experience with React but are not currently using it for other development.
2. Does the CDC have any more specifics about the preferred method of integration with NIOSH for sending de-identified scan results?
-CDC approved systems must be utilized to transfer the data (i.e., MoveIT, SAMS, SFTP).
3. In addition to local data storage, does the CDC anticipate sending face scan information to a server, which could enable data aggregation across multiple devices and support additional reporting?
-Based on the RFQ there is a requirement to have the capability to send exports for reporting purposes.
4. The RFQ specifies that "the app shall use preferred technology stacks that are in use within NIOSH and CDC for ease of maintenance and supportability throughout the application's lifecycle." Please elaborate on the preferred technology stack concerning iOS development.
-Since this is not a web app nor does it require a database there is no server side infrastructure stack needed at this time.
5. As stated in the RFQ, "data collection, storage, and analysis shall be performed locally on the device." However, there is also a request for a voice command feature. Apple's Speech framework indicates that on-device speech recognition is available for some languages, but it also relies on Apple's servers for speech recognition, assuming a network connection is required. Therefore, there might be a need to transmit data off-device to support the voice command feature. Please clarify this requirement.
-There are no non-English requirements.
6. In the statement, "Provide Continuous Monitoring after the mobile app is cleared and approved," what does "continuous monitoring" mean?
-This is required per the Federal Information Modernization Act of 2014 and is used to identify threat information for proper remediation. The security controls in NIST 800-53 REV.5 (attached) for Continuous Monitoring must be in place.
Definition(s):
Maintaining ongoing awareness to support organizational risk decisions. See information security continuous monitoring, risk monitoring, and status monitoring Source(s):
CNSSI 4009-2015 from NIST SP 800-137.
7. What is the oldest iPhone/iOS version combination that the app needs to support? Considering the app development phase spans three years, supporting iOS 17 (in beta as of June 2023) and newer versions would allow the developer to leverage the latest Apple SDKs.
-As old as possible to provide the most compatibility. IOS15 unless a required feature in the SDK requires a higher version.
8. Most of the links in the file titled “Attachment D1 - CDC Secure Software Development Standard v1.0” doc are not working for us. Is there a way for us to get access to these links (or the documents they reference)?
o Are there any restrictions against using 3rd party / Open Source algorithms and software libraries when developing the solution?
o Are there any restrictions against embedding 3rd party software that carries licensing fees?
-NIST Special Publication (SP) 800-218, Secure Software Development Framework (SSDF) Version 1.1: Recommendations for Mitigating the Risk of Software Vulnerabilities https://www.cnss.gov/CNSS/issuances/Instructions.cfm https://doi.org/10.6028/NIST.SP.800-137 https://csrc.nist.gov/publications/detail/sp/800-218/final https://csrc.nist.gov/publications/detail/sp/800-218/final
“Following the SSDF practices should help software producers reduce the number of vulnerabilities in released software, reduce the potential impact of the exploitation of undetected or unaddressed vulnerabilities, and address the root causes of vulnerabilities to prevent recurrences.”
9. Is there a minimum Apple iPhone / iPad hardware version and software version the system must support?
-Not unless the app will rely on Apples LIDAR sensor.
11. Where do we get access to the “CDC equipment standards” for this spec?
o E.g. iPhone 12 Pro and beyond and iPad 2020 11 inch and 12.9 inch Pro support LIDAR in the device camera, which can have significant implications on the quality of the facial scans, as well as the overall project cost estimate.
-CDC equipment standards don’t apply since this app will be for the general public.
11. Section 4, Mobile Application Requirement #5 states that all data collection, storage and analysis shall be performed locally on the device.
o Does that mean that we can’t capture data and have the calculations / number crunching be performed by more powerful compute capabilities in the Cloud?
-If cloud computing is required we can discuss.
o Is there a maximum time for the scan to be completed (e.g. 20 second)?
-No o Does this change by device type (e.g. iPhone 13 Pro vs iPhone 8)?
-No
12. Is there a requirement for the solution to use the Apple iOS 12+ version of “Measure App” in the ARKit to measure distance of face from phone and measure points on face.
-No
13. Should users have a login and a profile for the CDC facial scanning app?
-Yes
14. If there are historical scans for multiple humans on the same device, can any user with access to that device share any of the historical scans with the CDC or can a single user only share the scans associated with their own person?
(coming back to the login and storing scans on the device until shared by a person) -No
15. Is the scanning device (e.g. user’s phone) expected to be authenticated for the individual user with the CDC before sharing analysis? What are the authentication requirements?
-The security controls in NIST 800-53 REV.5 (attached) for authentication must be in place.
16. If sharing the analysis by email, does the email need to be encrypted, or is it sufficient that the analysis is de-identified? (If there is a name, race, sex, age, etc. meta-data associated with the scan, how can this be considered de-identified?)
-See the options described above for the CDC approved data transfer methods. Email does not currently meet federal standards.
17. Is the device expected to be aware of which facial scans have been shared previously with the CDC?
-Yes
18. What happens if the same analysis is attempted to be shared multiple times with the CDC?
-There should be a response saying it has already been shared.
19. Is there a time period after which the scans should be purged from the local device?
-No
20. Is there any requirement for the CDC to be able to remotely activate / deactivate the app on the local device?
-No
21. The company often employs software engineers from other countries. What sort of restrictions are placed on a potential awardee from using said contractors?
-Additional securty reviews and requirements would be required.
22. The RFQ says “The app shall use preferred technology stacks that are in use within NIOSH and CDC for ease of maintenance and supportability throughout the application’s lifecycle”. What are NIOSH’s and the CDC’s preferred technologies?
-There is currently no requirement for server-side infrastructure. But we are mainly a Postgres and Linux shop.
23. Attachment D1 - CDC Secure Software Development.pdf says “Ensure the use of source code repositories approved by CDC Software Assurance Program”. However, the hyperlinks provided do not work. What/where are the approved source code repositories? Does this mean that only open source libraries that the CDC has pre-approved can be used and all other code must be developed from the ground up?
-Mainly Github, TFS, and Bitbucket. All open source libraries are allowed because all code will be scanned.
24. What is the number of profiles requested in the requirement?
-Unlimited. There may be cases when a plant manager logs in but several workers would need to create profiles for face scanning.
25. Should the cybersecurity service be included in the bid and supported by the bidder?
-Unknown, cybersecurity referenced RFQ are related to IoT.
26. Do you recommend any technology stack or platform ?
-Xcode platform would be preferred if we have to take over maintenance.
27. "2. The app shall use preferred technology stacks that are in use within NIOSH and CDC for ease of maintenance and supportability throughout the application’s lifecycle." What is the Government's preferred technology stack?
-See answer to 22.
28. "3. The app shall be designed to work on iPad and iPhone models which adhere to CDC's equipment standards. Only iPad and iPhone models which adhere to CDC's equipment standards can be used for testing."
To ensure we are developing to the correct standards, please confirm which models adhere to the CDC equipment standards -Since this will be a general public use app it goes beyond the CDC’s equipment standards for employees. So this is N/A.
29. Is there a certain tech stack that you prefer to be used? For example, Native or React Native development.
-Xcode would be preferred.
30. Does the app require login?
-Based on the answer to 13, yes.
31. What are the CDC equipment standards referenced in the Mobile Application Requirements? All I could find online was related to PPE.
-This is N/A since this will be used by the general public.
32. During our development process, is there a need for us to access any CUI?
-No.
33. Is the SA&A package referenced in the list of deliverables related to the Secure Software Development Standard Version 1.0 which was attached to the RFQ? I couldn't find a reference to an SA & A DCD SOP online.
-The SA&A documentation will include scans and security control descriptions addressing the software development, vulnerabilities, remediations, etc.
34. Like other developers, we often use third-party components licensed for use - does the want to CDC exclude the use of those components, since it couldn’t own that data?
-It depends if web services are used to transmit data off the device.
35. I recently learned about a concerning technical fact about Android after consulting with my team of 3D computer vision experts. The engineering team has launched many face measuring apps before (including mask-fitting). This is their domain expertise, they've shipped hundreds of mobile apps in the 3D/Augmented Reality/Computer Vision space for companies like Nike, Toyota, Twitter, Mercedes Benz, etc.
Technical Problems with Android:
• Android phones do not have the proper built-in hardware (they do not have cameras with a depth sensor).
Without a 3D depth camera it means that the phone is unable to "take measurements".
• There's a myriad of different Android brands and models, however, there is no uniformity across the cameras used in the various devices because the manufacturers are all different. This means that the face measuring app would not be applicable across multiple android brands and models.
• A physical attachment can be added to the camera to attempt to enable depth sensing, however, those manufacturers located overseas, often go out of business for lack of demand and lack of compatibility.
I'm unable to bid on this as it is currently written because integrity is very important to my company. Because if the CDC decides to execute Android Option 5 thru Option 9, we don't want to risk jeopardizing our rating and ability to do future business with the government.
-Unknow what hardware is missing. Is a 3D ToF sensor required because if so, some by very few android phones have this. On the IOS side it looks like the LIDAR sensor would need to be used by only certain iphones and ipads have that as well.
| 2023-07-07T14:50:37-0400 | |
| Diane J. Meeder -S |
File details come from the government source that posted it. Updated .