8. PWS-DRAFT-20230505.pdf

PDF 242 KB Posted

Attached to
Enterprise Applications Training and Certification Services Federal contract opportunity
Solicitation number
2032H323N00009
Issued by
Department of the Treasury Departmental Offices

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Applications Training and Certification Services, newest first.
File Type Posted
I-5. RFI_Atch_1_Course_Info_V1.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT -- Performance Work Statement (PWS)

Department of the Treasury Enterprise Application Cybersecurity (EAC) Training & Certifications

May 5, 2023

C.1 INTRODUCTION

The Enterprise Applications (Enterprise Apps) office resides within the US Department of the Treasury’s Departmental Offices (DO), Office of the Chief Information Officer (OCIO). The OCIO provides leadership to the Department of Treasury and its’ Bureaus in all areas of information and technology management and supports Treasury's mission by implementing strategies that improve the efficiency and performance of Treasury Information Technology (IT) systems and business processes. OCIO has Department-wide responsibility for the direction and development of Treasury’s IT strategy, management of IT investments, and leadership of key technology initiatives. As a pillar of Treasury OCIO, Enterprise Apps is a service provider of information technology solutions through shared and scalable products, platforms and services.

Enterprise Apps offers its’ customers a variety of services available through five (5) distinct product suites: HRConnect (HRC), Talent Management Solutions (TMS), Enterprise Content Management (ECM), Enterprise Data Management (EDM), and Enterprise Apps Digital (Digital).

Supporting these product suites are the Business Operations and Enterprise Application Cybersecurity (EAC) programs, which provide backend management of acquisition, budget, operations, and administration of the programs and their respective application portfolios.

C.2 BACKGROUND

Enterprise Apps is part of Treasury’s Departmental Offices (DO) within the Office of Management, serving as the enterprise applications arm of the Office of the Chief Information Officer (OCIO). Enterprise Apps operates as a Shared Service Provider and is a designated HR line of Business (HRLOB), offering shared and scalable products, platforms, and services across the Federal landscape. Enterprise Application Cybersecurity (EAC) is a Shared Service Provider within Enterprise Apps that addresses cybersecurity needs within and outside of departmental offices. In fiscal year 2021, Treasury-wide priorities were revised to place greater emphasis on Treasury’s cybersecurity posture. As a result, EAC’s federal workforce began expanding in FY21, and this expansion continued into FY22 and FY23.

C.3 TASKS / STATEMENT OF NEED

Enterprise Apps has identified a need to procure specialized cybersecurity training courses and certifications for Treasury-wide use. These courses will help facilitate the development of current federal EAC employees, future EAC employees, and other DO offices requiring specialized cybersecurity training and certifications. The following provides additional details regarding the training requirements, which may be required in performance under this contract, as follows:

Enterprise Applications has identified a need to establish an Indefinite Delivery Indefinite Quantity (IDIQ) Firm Fixed Price (FFP) contract for specialized cybersecurity training courses & certifications from leading industry provider per Treasury Directive 85-01 (TREASURY DIRECTIVE 85-01 | U.S. Department of the Treasury). These courses will help facilitate the development of current Treasury employees, future Treasury employees, and other DO offices requiring specialized cybersecurity training and certifications. It is recognized that the course listing may require updates in order to keep pace with the growing and changing cyber threats.

Should such changes be required, they will be submitted through the Contracting Officer for determination to incorporate to the contract and approval. Pricing for such updates shall not create a need to increase the value of the contract for the Base and Option periods.

https://home.treasury.gov/about/general-information/orders-and-directives/td85-01 https://home.treasury.gov/about/general-information/orders-and-directives/td85-01

C.3.1 Class Size, Attendance and Class Survey

The Class Size will be specified at the Task Order level. A class roster will be provided to the vendor no earlier than ten (10) business days prior to the start of each scheduled class.

The vendor shall track attendance for each day of training and provide an end of class survey to each student to complete. The survey shall allow students to provide feedback based on a scaling system relevant to the course materials, instructions, length of course, etc. Additional requirements may be required and will be negotiated at the individual Task Order level. Both the attendance roster and surveys shall be provided to the Contracting Officer Representative

(COR).

C.3.2 Methods of Training and Scheduling. The method of training will be specified at the individual Task Order level. In general, training will be provided either on-site or virtually, as follows:

C.3.2.1 Virtual Training. The vendor shall provide and host virtual training which will allow the presentation of the material as well as verbal interaction between the instructor and students. Verbal communications will be through the web-based tool as well as a back-up toll-free phone number. The vendor shall own or have licenses to hosting software. Department of Treasury licenses will not be used to host Contractor provided training. Some examples of software that have been used by Department of the Treasury would include, but are not limited to, Zoom, Adobe Connect, WebEx, GoTo Meeting, Microsoft Teams, etc.

C.3.2.2 Training Scheduling. When a training need is determined, the COR will contact the vendor to discuss preliminary class details, such as dates, locations, method of training, required materials, etc. This exchange of information will not include pricing nor is the government liable for any costs executed during this exchange of information until such time as the Contracting Officer authorizes obligation via release of a Task Order.

C.3.2.3 Course Materials.

The vendor shall provide electronic versions of all class materials to include books, handouts, and other materials as specified at the individual Task Order level.

At a minimum, materials shall cover topics discussed in the training. An electronic version of the class materials shall be made available to the students for both in-class and virtual training courses. Electronic materials must be formatted using Microsoft products, adobe or available for download through internet access.

Printed materials for on-site training will remain with students upon completion of the class. The vendor shall be responsible for delivering all materials to the students at on-site trainings, and as further specified at the individual Task Order level. Shipping to a Federal location is neither desired nor an option.

C.3.2.4 Student Surveys. The contractor shall provide each student a survey to be completed which will provide sufficient information in order to determine if course content, materials, class size, instruction, etc. is at a minimum satisfactory to participants. The survey will be provided in a contractor format to the Contracting Officer Representative (COR) and will be utilized in determining future instructional needs, as well as to address any performance issues at the individual Task Order level.

C.3.2.5 Duration of Training. The length of training courses will vary per course. The duration of each required course will be specified at the Task Order level. The Government observes the following holidays:

o New Year’s Day o Martin Luther King’s Birthday o President’s Day o Memorial Day o Juneteenth Day o Independence Day o Labor Day o Columbus Day o Veteran’s Day o Thanksgiving Day o Christmas Day

The Contractor shall also follow any other holiday or Government closure, as declared by the President.

C.4 SCOPE

The vendor shall provide the training courses captured in Attachment 1, Course Information.

The courses shall include, but not be limited to, all relevant course materials, registration confirmations, and any certifications or examinations offered as part of the training. Specifics regarding training course requirements will be negotiated at the individual Task Order level. The following Table provides the IDIQ Delivery Schedule.

Enterprise Apps identified a need to procure specialized & industry leading cybersecurity training services to support the expansion of Treasury’s federal cybersecurity workforce expansion. Following the reprioritization of Treasury’s cybersecurity posture in response to the Solar Winds breach, Enterprise Apps determined it is in DO’s best interest to prioritize specialized, high quality, and industry recognized cybersecurity trainings for its current and expanding workforce. Per Treasury Directive 85-01 internal training is keystone to strengthening Treasury’s internal security posture. The purpose of this IDIQ contract is to ensure that staff provides training resources that will help decrease risks to computer systems, identifying cyber threats proactively, and identifying and minimizing future phishing attacks.

CLIN Description 0001 Cybersecurity Trainings and Certifications – Base Period 1001 Cybersecurity Trainings and Certifications – Option Period 1 2001 Cybersecurity Trainings and Certifications – Option Period 2 3001 Cybersecurity Trainings and Certifications – Option Period 3 4001 Cybersecurity Trainings and Certifications – Option Period 4 5001 FAR 52.217-8 Option to Extend Services (up to six months)

C.5 DELIVERABLES

Deliverables shall be provided in Microsoft Word, Excel or PDF format, and provided to the Contracting Officer Representative (COR) and Alternate COR. The following Table provides the types of deliverables required.

PWS

Section

Description Due Date

All PWS Sections

Monthly Status Reports (MSR): The contractor shall provide a MSR each month covering performance across all awarded Call (Task) Orders. The MSR will provide an overall assessment of performance and highlighting any known issues, attendance levels, survey trends, etc. as coordinated with the COR.

BPA, 5th of Each Month

PWS

Section 3.0

Materials: As specified under each Individual Task Order, the contractor shall provide required Materials.

As needed, specified at the individual Task Order level

PWS

Section 3.0

Student Surveys

As needed, specified at the individual Task Order level

C.6 PLACE OF PERFORMANCE

The required training shall be provided in person, OnDemand, and/or in a live-online capacity. A determination of the performance location for each course shall be made and negotiated at the individual Task Order level and may require an off-site location. For on-site Travel within the local DC/MD/VA area, it is considered local travel and will not be separately reimbursed under the individual Task Orders awarded under this IDIQ contract. Therefore, there will be no reimbursement for travel and other associated travel expenses. For Virtual training hosted by the vendor, training requirements will meet the aforementioned PWS requirements.

C.7 PERIOD OF PERFORMANCE

The period of performance for this contract is, as follows:

Contract Term Period of Performance Base Period July 10, 2023 – July 9, 2024

Option Period 1 July 10, 2024 – July 9, 2025 Option Period 2 July 10, 2025 – July 9, 2026 Option Period 3 July 10, 2026 – July 9, 2027 Option Period 4 July 10, 2027 – July 9, 2028 FAR 52.217-8 *Up to six-months extension, if needed

C.8 GOVERNMENT FURNISHED PROPERTY (GFP)

There is no anticipated GFP in performance of subsequent Task Orders awarded under this contract.

C.9 CONTRACT ADMINISTRATION

The Contracting Officer responsible for administration of this contract is: Ramona L. Hanson

The Contracting Officer, in accordance with FAR Subpart 1.6, is the only individual authorized to enter into, administer, and terminate work under this contract. Notwithstanding any clauses contained elsewhere in this contract, this said authority remains solely with the Contracting Officer. In the event the Contractor makes any changes at the direction of any person other than the Contracting Officer, the change will be considered to have been made without authority and no adjustment will be made in the contract price to cover any increase in cost incurred as a result, thereof. All correspondence related to this order shall be directed as follows:

Contracting Officer:

Ramona L. Hanson IRS, Office of Business Solutions Acquisition (OBSA) Treasury Operations Branch Phone: (240)613-9385 Email: Ramona.L.Hanson@irs.gov

The Contracting Officer Representative (COR) for the contract is:

TBD

C.10 SECURITY AND PRIVACY REQUIREMENTS

C.10.1 Security Categorization.

The clauses listed below apply to the Prime Contractor and any of its subcontractors employed during the course of this contract. The clauses below also apply to tasks, work requests or other identified method of requesting work be performed that flow from this document. No Contractor personnel may perform any work under this Contract until the Government grants specific permission to do so, regardless of existing clearance or investigation.

This Contract is categorized as unclassified at the Moderate (Tier 2/MBI) Level. This

Contract does not have Tasks that require different levels of investigations.

Contractors are required to comply with the Treasury Directive P 15-71, Treasury Security Manual in the handling, protection, and safeguarding of government information in their possession. The TD P 15-71 will be followed as it specifies Treasury-specific personnel, physical, industrial and information security policy, processes and requirements that apply to this contract.

C.10.2 General Security.

Department of Treasury, otherwise known as the Department, retains the right to request removal of Contractor personnel, regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, clearly conflict with the interest of the Government.

Lack of the ability to obtain or maintain the required investigation level is included in the reasons the Department may remove a contractor employee. The reason for removal shall be documented in writing by the Contracting Officer. Additionally, the Contractor must notify the

OSP of all terminations/resignations within 24 hours of occurrence. When and if such removal occurs, the Contractor is responsible for assigning qualified replacement personnel in a timely manner or ensuring that performance of the contract is not adversely affected. The Contractor shall return all Departmentally issued identification cards, building passes, keys, and any other government issued material of those terminated employees to the COR. If government issued material is not available to be returned, a report must be submitted to the COR referencing the number, name of individual to whom it was issued, the last known location, and disposition of the items. Failure to return government materials may result in remedial actions against the contractor. Contractor personnel shall visibly wear Departmentally issued identification badges when working in Government facilities. If any current or prospective employee is found to be ineligible for access to Government facilities or information by the Department, the COR will notify the contractor that the employee shall not continue to work or to be assigned to work under the contract. The Department may require drug screening for probable cause at any time.

The contractor must also ensure that, prior to the end of the contract, all Departmental information, systems and equipment is returned to the appropriate Department personnel. All contractors must be vetted and approved by OSP prior to beginning work on any portion of this contract.

Any employee assigned to support the Department shall comply with Personal Identity Verification One and Two (PIV-1, PIV-2) requirements as described in Homeland Security Presidential Directive 12 (HSPD-12), “Policy for a Common Identification Standard for Federal Employees and Contractors,” and “Federal Information Processing Standard 201, Personal Identity Verification Standards for Federal Employees and Contractors,” dated August 2013.

T2/Moderate Risk contract employees must be a U.S. Citizen or Lawful Permanent Resident Alien with at least three or more years of U.S. residency from the legal entry date in the U.S..

Contractor personnel will have access to Department facilities, information and equipment limited to that which is needed to perform contract scope.

The Contractor shall provide the CO the name of all entities to be used as subcontractors for each type of work to be performed prior to performing any work under this contract in accordance with the FAR Subpart 44.2. The Government reserves the right to accept or reject any subcontractors proposed. Contractors should not serve as the escort for their subcontractors or for any other contractor; escorts used should be Departmental Federal employees.

The Contractor is responsible for obtaining the approval of the CO prior to release of any information received or generated under the contract per 48 CFR 252.204-7000. The CO should complete this item as required by internal agency directives to direct the prime contractor to the appropriate office that has public release authority. Prime contractors should serve as focal point for their subcontractors’ public release requests and refer them to the CO. SBU (also known as Controlled Unclassified Information (CUI)) must be protected in accordance with EO 13556, 32 CFR 2002 (full implementation expected to be reached in November 2018), and Treasury Security Manual (TD P 15-71). For Official Use Only must be protected in accordance with the providing Agency’s directives. Data contained within all Department computer systems are governed by Agency Security Regulations as well as the Federal Privacy Act of 1974.

Contractor personnel assigned to this project will be held accountable for adherence to these regulations. If the security classification or security requirements are changed by the Government subsequent to the date of this Contract, and if the changes cause an increase or decrease in security costs or otherwise affects any other term or condition of this Contract, any resulting financial burden will be the sole responsibility of the Contractor.

Contractors and their subcontractors must perform all initial, annual, contemporaneous, specialized and termination training required per Department guidance and TD P 15-71 as appropriate for their position. This is in addition to any training their company requires them to have.

Per the TD P 15-71, the Contractor shall report to the COR within 24 hours any adverse information coming to its attention concerning employees working under this contract, to include loss or suspension of favorable adjudication, or security issues involving the scope being completed for the contract. Reports based on rumor or innuendo should not be made. The subsequent termination of an employee does not obviate the requirement of the contractor to submit this report. The report shall include each employee’s name, social security number, and the adverse information. The Contractor shall also report within 24 hours any event the Contractor becomes aware of that would be deemed a potential security incident, violation or any compromise involving Treasury systems, material, or data or systems with Treasury material or data on them. The Contractor shall comply with all Federal laws and regulations regarding computer security, information security and privacy.

While the Contractor’s personnel are at the government facility, the Contractor is responsible for compliance with all laws, rules, and regulations governing conduct with respect to security – not only as they relate to its employees and agents, but also to other personnel who are government employees or agents of the government and to property at the site regardless of ownership. While on government premises and in possession of government property, the Contractor is responsible for such property and any damages or compromise thereto by Contractor’s employees. The Contractor and its employees shall exercise the utmost discretion in regard to all matters relating to their duties and functions, and in the safeguarding of pre-decisional or sensitive information (privacy, etc.) from inadvertent release. At the completion of the contract vehicle, the Contractor shall send a written notice from the authorized principle of the company attesting that all file records pertaining to this contract in possession of the Contractor was destroyed.

The contractor will avoid any improprieties located in FAR Part 3 and 52.203-16 regarding gratuities, kickbacks, conflicts of interest and other ethics issues.

Work on this contract may require personnel to have access to private information covered by the Privacy Act, Title 5 of the U.S. Code, Section 552a (in addition to other types of non-public information). All Contractor personnel shall adhere to the requirements of the Privacy Act as well as any applicable Department or Federal rule/regulation regarding private information or other types of non-public information.

As a condition for access for Government‐Owned Systems and data, all Contractor personnel must pass background investigations in accordance with OMB Circular A‐130 which requires screening of all individuals involved with sensitive applications or data in Federal automated information systems.

Contractor will abide by requirements set forth in the applicable guidance for the protection of unclassified information. If Contractor fails to follow requirements above, this may result in revocation of favorable public trust adjudication for offending employees and potential negative actions against the contract vehicle itself.

Per FAR 52.222-54, the contractor is required to comply with enrollment and verification requirements for all contractors except those previously verified by acceptable means.

The contractor agrees and understands that the latest version (if superseded) of the

U.S.C., CFRs, Executive Orders, Treasury policies and all other government issued documents that are referenced above will be followed.

DRAFT -- Performance Work Statement (PWS)
Department of the Treasury
Enterprise Application Cybersecurity (EAC) Training & Certifications
May 5, 2023
C.1 INTRODUCTION
C.3 TASKS / STATEMENT OF NEED
C.4 SCOPE
C.7 PERIOD OF PERFORMANCE

File details come from the government source that posted it. Updated .