RFQ_88310319Q00132_CMMS.pdf

PDF 788 KB Posted

Attached to
Computerized Maintenance Management System Federal contract opportunity
Solicitation number
88310319Q00132
Issued by
National Archives and Records Administration

About this file

CMMS RFQ

View the file

Other files for this federal contract opportunity

Other files attached to Computerized Maintenance Management System, newest first.
File Type Posted
RFQ_88310319Q00132_8.15.pdf PDF
Amendment_001_88310319Q00132.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

This is a combined synopsis/solicitation for commercial items prepared in accordance with the format at FAR Subpart 12.6, Streamlined Procedures for Evaluation and Solicitation for

Commercial Items as supplemented with additional information included in this notice. This announcement constitutes the only solicitation; quotations are being requested and a written solicitation will not be issued. The solicitation number is 88310319Q00132 and is issued as a

Request for Quotation (RFQ). The solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular 2019-03 effective July 12, 2019. This is a full and open RFQ under NAICS code 511210, Software Publishers. CONTRACT LINE

ITEM NUMBER(S): See Attachment 1, Schedule of Prices. REQUIREMENT: The National

Archives and Records Administration (NARA) has a requirement to obtain a Computerized

Maintenance Management System (CMMS). See Attachment 2, Performance Work Statement.

PERIOD OF PERFORMANCE: The period of performance will consist of a base year and four

(4) option years. The following Federal Acquisition Regulation (FAR) provisions are incorporated into the solicitation and will be removed prior to award. FAR provision FAR provision 52.212-1, Instructions to Offerors - Commercial Items (Oct 2018). Addenda: (1)

Change paragraph (c) to read: Period for acceptance of offers. The offeror agrees to hold the prices in its offer firm for 90 calendar days from the date specified for receipt of offers. (2)

Delete paragraph (h), Multiple Awards. - see below for additional quotation submission instructions. EVALUATION (In lieu of FAR provision 52.212-2): Evaluation and award will be in accordance with Simplified Acquisition Procedures at FAR 13.106, Soliciting Competition, Evaluation of Quotations or Offers, Award and Documentation authorized by FAR Subpart 13.5, Simplified Procedures for Certain Commercial Items as prescribed by FAR 12.301(c)(2). See

Attachment 9, Quotation Submission Instructions and Evaluation Criteria for additional instructions. Selection of the Contractor for this contract will be based on NARA’s assessment of the best overall value to the Government. Accordingly, best value for this contract will be obtained through a Lowest Price Technically Acceptable evaluation. Exceptions taken to any terms and conditions stated in the RFQ must be clearly outlined on a separate page of the

Contractor’s quotation entitled “Exceptions”. The Contractor must also include a justification and the cost impact of each exception noted. The Government reserves the right to make an award on the initial quotation without communicating with contractors. FAR provision 52.212-3, Offeror Representations and Certifications - Commercial Items (Oct 2018) -

The Offeror shall complete only paragraph (b) of this provision if the Offeror has completed the annual representations and certification electronically in the System for Award Management

(SAM) accessed through https://www.sam.gov. If the Offeror has not completed the annual representations and certifications electronically, the Offeror shall complete only paragraphs (c) through (u) of this provision. The following FAR clauses are incorporated and are to remain in full force in any resultant contract. FAR clause 52.212-4, Contract Terms and Conditions -

Commercial Items (Oct 2018) – see Attachment 3, Additional NARA Terms and Conditions

(Addenda to FAR clause 52.212-4). FAR clause 52.212-5, Contract Terms and Conditions

Required to Implement Statutes or Executive Orders - Commercial Items (May 2019) - see

Attachment 7, FAR Clauses for the full text of this clause and for additional applicable FAR clauses. FAR provision 52.217-5, Evaluation of Options (Jul 1990). Full text provisions and clauses can be found at http://www.acquisition.gov. The Contractor is required to be registered in the System for Award Management (SAM) and maintain registration until final payment in accordance with FAR provision 52.204-7, System for Award Management (Oct 2018).

QUESTIONS: Questions regarding this RFQ must be submitted in writing to the Contract

NARA – 88310319Q00132, CMMS Cloud Subscription and Maintenance

Specialist, Mr. Shawn Xiong (Contractor) at shawn.xiong@nara.gov no later than 12:00 PM ET on August 8, 2019 to be considered. Questions submitted in any other manner will not be answered. Contractors are requested to group and submit questions in the same order found in the RFQ while making reference to the particular paragraph number. The Government will answer questions or requests for clarification via a written RFQ amendment. QUOTATION

DUE DATE: Quotations must be received by 12:00 PM ET on August 23, 2019. Failure to submit quotations by the due date and time may result in rejection of the quotation as untimely.

Contractors submitting via e-mail are cautioned to allow one extra business day for delivery and confirm receipt of quotation as the e-mail will need to pass through IT security. QUOTATION

SUBMISSION INSTRUCTIONS: NARA requests that contractors email one (1) copy of the quotation to: shawn.xiong@nara.gov.

ATTACHMENT 1

SCHEDULE OF PRICES

Base Year: Months 1 - 12

CLIN DESCRIPTION QTY UNIT OF

ISSUE

FIRM-FIXED

UNIT PRICE

TOTAL PRICE

0001 Computerized

Maintenance

Management System

(CMMS)

subscription & services in accordance with PWS

12 Months

0002 Data Migration and

Other Services in accordance with PWS paragraph 5.4

1 Lot --

0003 Reserved 1 -- --

TOTAL BASE YEAR PRICE:

Option Year I: Months 13 - 24

ISSUE

FIRM-FIXED

UNIT PRICE

TOTAL PRICE

0004 Computerized

Maintenance

Management System

(CMMS)

subscription & services

12 Months --

0005 Reserved 1 -- --

TOTAL OPTION YEAR I PRICE:

Option Year II: Months 25 - 36

ISSUE

FIRM-FIXED

UNIT PRICE

TOTAL PRICE

0006 Computerized

Maintenance

Management System

(CMMS)

subscription & services

0007 Reserved 1 -- --

TOTAL OPTION YEAR II PRICE:

Option Year III: Months 37 - 48

ISSUE

FIRM-FIXED

UNIT PRICE

TOTAL PRICE

0008 Computerized

Maintenance

Management System

(CMMS)

subscription & services

0009 Reserved 1 -- --

TOTAL OPTION YEAR III PRICE:

Option Year IV: Months 49 - 60

ISSUE

FIRM-FIXED

UNIT PRICE

TOTAL PRICE

0010 Computerized

Maintenance

Management System

(CMMS)

subscription & services

0011 Reserved 1 -- --

TOTAL OPTION YEAR IV PRICE:

TOTAL CONTRACT PRICE:

ATTACHMENT 2

PERFORMANCE WORK STATEMENT

COMPUTERIZED MAINTENANCE MANAGEMENT SYSTEM

LICENSING AND MAINTENANCE

1.0 BACKGROUND

1.1 The National Archives and Records Administration (NARA)’s mission is to safeguard and preserve the records of the United States Government, ensuring that the public can discover, use, and learn from this documentary heritage. NARA ensures ready access to essential evidence that documents the rights of American citizens, the actions of

Federal officials, and the national experience. The agency meets thousands of information needs daily, ensuring access to records on which the entitlements of citizens, the credibility of the United States Government, and the accuracy of history depend.

1.2 NARA must effectively perform, track, monitor and report on all facility maintenance and property management activities for all NARA locations in accordance with the

Office of Management and Budget (OMB) and the Government Accountability Office (GAO) guidelines. NARA requires a comprehensive solution for managing assets throughout their lifecycle, and manages planned and unplanned work activities from initial request through completion. To achieve this, NARA was utilizing an off-the-shelf software package from IBM called Maximo.

1.3 Users include property accountability officers, facility managers, facilities maintenance contractors, and other authorized users. Users accessed the system from various

NARA locations, by typing the internal NARA Internet Protocol (IP) address of the application server into the URL field of a web browser, which enables them to perform their respective job functions.

1.4 NARA’s Current Architecture. NARA currently owns Maximo version

7.1.1.6 perpetual licenses and has data stored in Maximo versions 7.1.1.6 and 7.6.0. The data is not currently running on any servers due to lack of maintenance.

2.0 PERIOD OF PERFORMANCE

2.1 The period of performance for this requirement is one (1) year plus four (4) option years.

3.0 PLACE OF PERFORMANCE

The primary place of work for technical coordination and meetings will be at the

Archives II facility in College Park, Maryland, located at 8601 Adelphi Road, College Park, MD, 20740-6001 or other venues as appropriate. It is expected that the Contractor will perform during the typical core business days and business hours of 8:00 AM - 4:30 PM Eastern Time

(ET). The Archives II facility is closed on all federal holidays. Some of the work related to this

Performance Work Statement (PWS) can be accomplished off-site or via webcast or conference call. Contractor staff shall not be permitted on-site during the hours when the Government is closed unless otherwise approved by the COR.

4.0 SCOPE OF WORK

4.1.1 CMMS functionality: The system shall, minimally, perform these or similar functions:

4.1.1.1 Track assets

4.1.1.2 Track asset maintenance, including:

a. Scheduled maintenance

b. Preventative maintenance

c. Unscheduled maintenance

d. Dates

4.1.1.3 Track work orders on assets,including:

a. Order information

b. Reorder information based on inventory level

4.1.1.4 Track labor time on an asset work order from start to finish when performing:

a. Preventative maintenance

b. Scheduled maintenance

c. Unscheduled maintenance

4.1.1.5 Track asset repairs to:

a. Main equipment

b. Equipment sub-assembly

4.1.1.6 Report as needed on:

a. Maintenance

b. Work orders

c. Repairs

d. Labor

e. Inventory

f. Assets

g. Costs

4.1.2 CMMS data and auditing. The system shall contain and provide audit reports of user actions and dates on the following or similar asset information, at a minimum:

4.1.2.1 Asset

a. Asset number

b. Serial number

c. Other identifying number

d. Description

e. License

f. Manufacturer

g. Creation date

h. Disposal date

4.1.2.2 Asset Warranty

a. Coverage period

b. Start date

c. End date

4.1.2.3 Asset or Property Types:

a. Accountable; Non-accountable

b. Capital; Non-capital

c. Active; Disposed; Surplused; Lost; and Excess

d. Environmental or Hazardous Substance; Non-hazardous

e. Leased; Owned

f. Exchanged; Trade-in

g. Type: Hardware; Software; Other

4.1.2.4 Asset Status or Condition

a. Current - e.g. Operating, Inactive

b. When acquired

c. When disposed

d. When lost

e. Date

4.1.2.5 Asset Physical Location

a. Address

b. Room

c. Start date

d. End date

4.1.2.6 Asset Parts

a. Equipment Parts List

b. Parts Inventory

c. Quantity

d. Date

4.1.2.7 Technical Documentation and Images

a. Assembly instructions

b. Maintenance instructions

c. Warranty information

d. Computer Aided Design (CAD) drawings

e. Scanned data

4.1.2.8 Work Order

a. Number

b. Asset Number being worked on

c. Status

d. Prioritization

e. Start date

f. End date

4.1.2.9 Property Transfers

a. Transfer to new owner

b. Transfer to new organization

c. Start date

d. End date

4.1.2.10 Ownership information for all owners, current and prior:

a. Name

b. Organization

c. Organization code

d. Property Accountability Officer (PAO) name

e. Start date

f. End date

4.1.2.11 Cost information

a. Original cost

b. Install date

4.1.2.12 Acquisition and Disposal information

a. Asset Description

b. Organization

c. Organization Address

d. Date

e. Contract number

f. Accounting information

g. Quantity

h. Manufacturer

4.1.3 CMMS user creations. The system shall allow users to create, at a minimum:

a. Authorized users and privileges

b. Data fields and validation rules

c. Searches

d. Reports and reports criteria

e. Exports to spreadsheets and documents

f. Dashboards

g. Mass actions to multiple records simultaneously

h. Electronic and scanned file attachments and links

i. Automated preventive maintenance work order generation

j. Custom screen changes

4.1.4 CMMS system interfaces. If required, the system shall have the capability to interface with systems such as:

a. Barcode readers and scanner systems

b. Electronic inventory or property systems

c. Procurement systems

d. Excess or surplus systems

e. Configuration management systems

f. Financial systems

g. Non-financial systems

h. Service management systems

4.2 The scope of this requirement will include 1) a FedRAMP authorized Software-as-a-

Service (SaaS) CMMS and 2) data conversion and migration services to the SaaS. The

FedRAMP SaaS subscription includes Cloud Services, Cloud Application Support Services, IT

Security Services, and Disposition. The SaaS will operate on the FedRAMP authorized

Infrastructure-as-a-Service (IaaS) that was utilized in the SaaS authorization. The SaaS and the

Data Conversion and Migration service requirements are described below.

5.0 REQUIREMENTS

5.1 The Contractor shall furnish all necessary labor, material, services, equipment, supplies, power, accessories, and such other things as necessary, except as otherwise specified, to provide a FedRAMP moderate, or higher, CMMS SaaS in accordance with this PWS.

5.2 Cloud Subscription. The Contractor shall provide FedRAMP authorized CMMS subscriptions for 12 concurrent users or at least 82 individual users. Although the CMMS system will service multiple locations, the data must be centrally stored and accessed so that all NARA organizations are operating from a central database. Users will access the system from various

NARA locations, by typing the Internet Protocol (IP) address of the application server into the

URL field of a web browser, which enables them to perform their respective job functions. At a minimum, the FedRAMP SaaS subscription includes Cloud Services, Cloud Application Support

Services, IT Security Services for the SaaS and the IaaS the SaaS runs on, and Disposition, as described in the sections below. The Contractor shall advise if NARA’s understanding of the items included in the FedRAMP authorized SaaS subscription are erroneous or different from what is listed below:

5.2.1 Cloud Services. The Contractor shall provide the cloud services that meet

FedRAMP requirements as well as NARA’s IT Security requirements. Any security controls for which NARA has full or shared responsibility shall be identified by the Contractor. The

Contractor shall provide basic maintenance services for the infrastructure test and production environments to include, but not limited to:

● Provisioning and deployment services;

● Service utilization and reporting;

● Backup and recovery;

● Failover and contingency operations;

● Capacity and performance monitoring;

● Security monitoring; and

● Configuration management.

5.2.2 Cloud Application Support Services. The Contractor shall operate, maintain, and support the CMMS system software application to ensure that services are provided without interruption to the production environment. Included in the SaaS subscription is an SLA that includes: 1) Technical Support for severity 1, 2, and 3 incidents during normal business hours;

and 2) a minimum of 99.5% availability for the CMMS SaaS.

5.2.2.1 The Contractor shall support the operation and maintenance of the CMMS system, keeping the system operating with supported Contractor releases or off-the-shelf software upgrades. Application-specific operations and maintenance of the system shall include all software and hardware associated with the servers, web-based applications, and networking.

These tasks may include, but are not limited to, the following:

● Operation support;

● Software maintenance and upgrades;

● Configuration and change management;

● Network/hardware support;

● Tier 1, 2 and 3 Support;

● Virtual Private Network (VPN) and Lightweight Directory Access Protocol

(LDAP) integration;

● Backup and recovery management;

● Installation, configuration, and tuning

● Software license services including deployment, management, tracking, upgrading, etc;

● System monitoring; and

● Continuous service improvement.

5.2.2.2 The Contractor shall take an active and collaborative role in defining and enforcing clear demarcation points of responsibilities as well as acceptable operational levels with other service providers including, but not limited to, Infrastructure Operations and Maintenance, Quality Assurance and Security components.

5.2.2.3 Types of Services. The Contractor shall provide the production environment support services summarized below to assure seamless operation and maintenance of the CMMS system.

Designated NARA staff will provide basic on-site or telephone support for the following:

● User application assistance;

● Account provisioning/deactivation;

● Password reset;

● Log-in support; and

● Open/close and escalate tickets.

5.2.2.4 Support Levels. The Contractor shall provide the production environment support services summarized below, within the timeframes listed based on severity, to assure seamless operation and maintenance of the CMMS system.

● Tier 1 – Basic help desk ticket resolution and service delivery assistance

● Tier 2 – In-depth technical support for the issues escalated by Tier 1

● Tier 3 – Expert product and contractor support for the issues escalated by Tier 2

5.2.2.5 Support Levels Response Time.

Urgency Category Definition Response Time/Availability

Severity 1 -

Critical

Critical business impact/service down

Within 1 hour/M-F Normal Business

Hours

Severity 2 -

Significant

Significant business impact/a service feature or function is significantly impacted

Within 2 hours/M-F Normal Business

Hours

Severity 3 –

Minor

Minor business impact/service is usable but not functioning at full capacity

Within 4 hours/M-F Normal Business

Hours

5.2.3 Disposition. Upon request by the COR, the Contractor shall assist with disposition activities when the system is ready for disposition. These activities include:

● Decommissioning;

● Creating and storing backups;

● Closing documentation; and

● Orderly sanitization of all environments and media.

5.2.3.1 All data entered into the CMMS system and the information linking the data is

NARA property and can be moved to other software or infrastructure platforms if NARA chooses. If NARA chooses to move the data, the Contractor shall provide all data to NARA within 30 days of request.

5.3 IT Security Requirements

5.3.1 The Contractor must comply with Attachment 11, NARA IT Security Requirements which reflect NIST FISMA requirements. These requirements establish and implement specific

NARA IT security requirements. NARA will complete the hybrid portion of the security controls in order to achieve a NARA ATO of the CMMS. NARA will use the SaaS FedRAMP authorized security assessment package to assist in completion of the NARA ATO.

5.3.2 Upon award, the Contractor shall provide to NARA the SaaS security assessment package developed for and authorized by FedRAMP. This SaaS security assessment package will include information inherited from the FedRAMP authorized IaaS which hosts the

FedRAMP authorized CMMS SaaS.. If available, the Contractor shall also provide to NARA the security assessment package for the IaaS upon which the SaaS operates.

5.4 Data Conversion and Migration Services. Because NARA currently has approximately 27 GB of data in the Maximo environment as described above in paragraph 1.4, the Contractor shall convert (if applicable) and migrate the data from NARA’s current architecture to a supported CMMS system. The Contractor shall test the new system with the new clean data and provide a test report prior to delivery to the COR. The data must be migrated by September 18, 2019. The Contractor shall correct errors and refine the system as needed in order to provide a clean system with minimal (no more than five (5)) data and system errors.

NARA Information Technology will review all testing, operational readiness, and deployment documentation in Staged Gate Review meetings. The Contractor shall implement a go live date no later than September 30, 2019 when the new version is fully operational.

5.4.1 Other Services for Data Conversion and Migration Services. As needed for Data

Conversion and Migration Services, the Contractor will provide services necessary for Program, Project, and Contract Management activities in support of periodic reporting and respond to audit findings and recommendations in accordance with NARA’s Governance principles. The

Contractor must provide personnel, resources, and facilities as appropriate to provide efficient and cost effective services for the requirements described above along with the required support processes described below.

5.4.1.1 Integrated Project Team (IPT) Meetings. As needed for the Data Conversion and

Migration Services, the Contractor shall participate in CMMS system IPT meetings as required for the execution of this PWS.

5.4.1.2 Required Standards. All products delivered for the Data Conversion and Migration

Services under this PWS shall be developed in accordance with paragraph 6.0, Government

Furnished Information.

6.0 GOVERNMENT FURNISHED INFORMATION (GFI)

6.1 NARA will provide the Contractor the data and information required in the performance of this contract. This will include applicable NARA directives, policies and regulations. The Contractor shall safeguard information and records from being compromised, altered, destroyed, mutilated, damaged, or lost.

6.2 NARA will provide the Contractor with the following list of documentation for the

CMMS system. Per FedRAMP and NIST guidance, the Contractor may be required to update security documents when major changes or software application releases and/or updates occur.

The GFI includes:

6.2.1 NARA 804 and Supplements, Information Technology (IT) Systems Security

(https://work.nara.gov/nara_policies_and_guidance/directives/0800_series/nara0804.html#804.1)

6.2.2 NARA 805, Systems Development Lifecycle Handbook and Systems Development

Guidelines

(https://work.nara.gov/nara_policies_and_guidance/directives/0800_series/nara0805.html)

7.0 DELIVERABLES

7.1 The Contractor shall provide the following reports and deliverables. All deliverables will be delivered in the format specified by FedRAMP or in the format listed below to the

NARA security assessor(s) approved by NARA and submitted to FedRAMP for NARA’s security documentation review and NARA ATO. NARA’s security assessors will advise the

COR of receipt of the security deliverables.

7.2 Deliverables for IT Security Services. The Contractor shall provide the following system security documentation from the FedRAMP CMMS SaaS ATO for the CMMS SaaS

(prior to NARA ATO, and periodically thereafter) which documents the security controls. If possible, the Contractor shall also provide this security documentation for the FedRAMP authorized IaaS which the SaaS operates on.

PWS

Reference

Deliverables Title Format Due

5.3 System Security Plan for CMMS system

application in accordance with the FIPS 199 rating of the system (updated and provided annually)

PDF or MS Word or

FedRAMP format

Annually

5.3 Security Assessment Report PDF or MS Word or

FedRAMP format

Annually

5.3 Plan of Actions and Milestones PDF or MS Word or

FedRAMP format

Monthly

5.3 Contingency Plan (CP) in accordance with the

Business Impact Analysis of the system

PDF or MS Word or

FedRAMP format

Annually

5.3 Contingency Plan Test Results PDF or MS Word or

FedRAMP format

Annually

5.3 Vulnerability Scan Results PDF or MS Word or

FedRAMP format

Monthly

ATTACHMENT 3

QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)

1.0 INTRODUCTION:

This Quality Assurance Surveillance Plan (QASP) has been developed to provide the Quality

Assurance Evaluator / Contracting Officer’s Representative (COR) and other Government evaluators a summary of the key performance standards required in the contract, performance levels, and method of surveillance normally used for that performance standard. These are listed in Attachment 4, Performance Requirements Summary (PRS).

The QASP describes a systematic method to evaluate receipt by the Government of acceptable services the Contractor is required to furnish. The Contractor is required to provide satisfactory performance in all areas of the contract. Before invoices can be paid, a determination by the

COR must first be made that satisfactory services have been received.

Any non-conformance with contract requirements is a “defect”. A defect may be recorded for each item evaluated that failed to meet the standards as required by the subject

Performance Work Statement (PWS) paragraph(s). Examples of defects that will be recorded include, but are not limited to:

a. Failure to perform a required task;

b. Failure to take corrective action to prevent reoccurrence of less than satisfactory performance; or

c. Performance of less than satisfactory work (quality work consists of completing the work in accordance with the appropriate PWS specifications, manufacturer’s recommendations, Government regulations, or best industry practices).

Quality Assurance is based on the premise that the Contractor, and not the Government, is responsible for management and quality control actions to meet the terms of the contract. The

Government will follow the guidance in FAR 52.212-4, Contract Terms and Conditions -

Commercial Items when performance is other than satisfactory.

Good management and use of an adequate quality control (QC) plan will allow the Contractor to operate within specified performance requirements. The COR and Government evaluators shall be objective, fair, and consistent in evaluating Contractor performance against contract requirements and standards. The main emphasis is on quality performance.

2.0 ACTUAL SURVEILLANCE:

Actual surveillance will be performed on a periodic basis, 100% surveillance, or as otherwise specified in the PRS in conjunction with the PWS.

If satisfactory performance is not achieved, the COR will determine the possible cause of the less than satisfactory performance. The COR will initiate a Contract Discrepancy Report (CDR) for all defects that could not be re-performed and for all defects not corrected by the Contractor in a timely or satisfactory manner when requested by the Government. The COR will submit the

CDR documentation recording the less than satisfactory performance and stating a recommended action to the Contracting Officer (CO) including any proposed contract deductions.

3.0 SURVEILLANCE METHODS:

Services shall have the results of the surveillance documented. The surveillance methods the

Government will use to evaluate the Contractor’s performance for the listed tasks are specified in the PRS. Customer complaints may be used in conjunction with the above surveillance methods as an indicator of performance or as areas to emphasize further for future surveillance.

4.0 INFORM CONTRACTOR:

a. Regardless of the surveillance method, the Contractor should be kept informed of performance status. The COR will notify the Contractor of any defect(s) to be corrected. The time to re-perform and correct defects after notification will vary depending on the type of defect, the item being inspected, the level of the item (i.e., routine, urgent, or emergency), etc.

The COR will inspect re-performed or corrected discrepancies. If corrected properly and timely, the defect(s) will not result in a payment deduction. However, the COR will maintain all documentation for file maintenance and turn this information over to the CO upon completion of the contract. Performance issues should also be an item of discussion during contract status meetings.

b. CDRs should be used to officially notify the Contractor of a performance problem.

CDR use includes notifying the Contractor of:

(i) Non-performance or less than satisfactory performance when the Government elects not to have the Contractor re-perform the service;

(ii) Failure of the Contractor to re-perform non-performed or less than satisfactory performed services;

(iii) Non-performed or less than satisfactory services that cannot be re-performed due to the nature or the timing of the required services; and

(iv) Continuous, less than satisfactory service whether the service is re-performed or not.

c. Critical performance problems should be immediately communicated with a follow-up written CDR. The COR will complete the CDR and forward it to the CO for review and approval. The COR will sign and forward the CDR to the Contractor for the Contractor’s response and comments. The Contractor will have seven (7) calendar days (or such lesser time that the COR stipulates) to complete a response. After evaluating the Contractor’s response, the

COR will forward the CO any CDR requiring further action (contract interpretation, problem resolution, reduced payments, deficiency letter notification, cure notice, etc.). The COR will provide the CO recommended actions with supporting rationale.

5.0 REVISIONS TO QASP:

Revisions to this surveillance plan are the responsibility of the COR and the CO.

ATTACHMENT 4

PERFORMANCE REQUIREMENTS SUMMARY (PRS)

1.0 PERFORMANCE REQUIREMENTS SUMMARY (PRS). The PRS captures key requirements of the Performance Work Statement (PWS) at an outcome level (performance standard) and states the performance level and method of surveillance for the requirement. The absence of any contract requirement from the PRS does not limit the rights or remedies of the

Government within the contract.

2.0 METHOD OF SURVEILLANCE. The PRS provides the surveillance method(s) the

Government will use to evaluate the Contractor’s performance for the listed tasks. The primary surveillance methods used will be 100% surveillance, periodic surveillance, or customer complaints.

3.0 GOVERNMENT QUALITY ASSURANCE. The Quality Assurance Surveillance

Plan, Attachment 3, describes how the Government will inspect, in conjunction with this PRS, and how the COR, other performance evaluators, the Contractor, and the Contracting Officer will communicate to ensure satisfactory performance of contract requirements.

PERFORMANCE REQUIREMENTS SUMMARY

REQUIREMENT

SUMMARY ITEM (RS)

PERFORMANCE

STANDARD

PERFORMANCE

LEVEL

METHOD OF

SURVEILLANCE

(RS-1) Application

Availability PWS paragraph 5.2

Uninterrupted service availability of systems.

99.5% Periodic Surveillance

(RS-2) IT Security

Services

PWS paragraph 5.3

100% of security issues resolved

100% Periodic Surveillance

(RS-3) Data Migration

PWS paragraph 5.4

100% of data migrated to new platform

100% Periodic Surveillance

ATTACHMENT 5

CONTRACT ADMINISTRATION

I. GOVERNMENT CONTRACT ADMINISTRATION

A. This contract will be administered by:

National Archives and Records Administration

Office of the Chief Acquisition Officer

8601 Adelphi Road, Room 3340

College Park, MD 20740-6001

B. Contract Specialist (CS):

See award document.

C. Contracting Officer (CO):

Any Z Warranted CO

The Contracting Officer (CO) has the overall responsibility for the administration of this contract. Written communication to the Contract Specialist (CS) must make reference to the contract number and must be emailed or mailed with postage prepaid, to the above address.

The CO alone, without delegation, is authorized to take actions on behalf of the Government to amend, modify, or deviate from the contract terms, conditions, requirements, specifications, details and/or delivery schedules; make final decisions on disputed deductions from contract payments for non-performance or unsatisfactory performance; terminate the contract for convenience or default; and issue final decisions regarding contract questions or matters under dispute. However, the CO may delegate certain other responsibilities to authorized representatives.

II. DESIGNATION OF CONTRACTING OFFICER'S REPRESENTATIVE (COR)

a. COR: See award document.

b. The individual named above is designated as the Contracting Officer's Representative (COR) to assist the Contracting Officer (CO) in the discharge of the CO's responsibilities. The COR is responsible for monitoring, giving progress reports to the Contract Specialist (CS), and overall technical surveillance of services to be performed under this contract and should be contacted regarding questions or problems of a technical nature. In no event will any understanding or agreement, modification, change order, or other matter deviating from the terms of the contract between the Contractor and any person other than the CO be effective or binding upon the

Government.

c. When, in the opinion of the Contractor, the COR requests effort outside the existing scope of the contract, the Contractor must promptly notify the CO in writing.

d. No action will be taken by the Contractor under such technical instruction unless the CO has issued a contractual change.

e. The responsibilities of the COR include, but are not limited to, the following:

(1) Serve as the point of contact through which the Contractor can relay questions or problems of a technical nature to the CS and the CO;

(2) Be responsible for the inspection and acceptance of the services performed and determining the adequacy of performance by the Contractor in accordance with the terms and conditions of this contract;

(c) Confer with representatives of the Contractor regarding any non-performance or unsatisfactory performance; follow through to assure that all non-performance or unsatisfactory performance is performed/corrected or payment adjustment is recommended to the CS/CO;

(3) Review and certify invoices in accordance with invoicing instructions of the contract. Maintain a file with copies of these documents;

(4) Review and evaluate Contractor's deliverables;

(5) Advise the CS of any performance problems and make recommendations for corrective action to correct performance issues;

(6) Furnish the CS with any requests for change, deviation, or waiver (whether generated by Government personnel or Contractor personnel), including all supporting paperwork in connection with such change, deviation, or waiver;

(7) Submit a written evaluation to the CS/CO within 60 days of contract completion or annually on the anniversary date for contracts that include options. The evaluation should include:

(i) The quality and timeliness of the Contractor's performance; and

(ii) A statement as to the uses made of any deliverables furnished by the

Contractor.

III. INVOICE SUBMISSION INSTRUCTIONS

(a) The preferred method for invoicing is through the Invoice Processing Platform (IPP), which is a secure web-based electronic invoicing and payment information system. This service is provided by the U.S. Treasury’s Bureau of the Fiscal Service free of charge to federal agencies and contractors. IPP allows contractors to view information regarding their contracts and orders, electronically submit invoices and view payment information.

(b) The IPP website address is https://www.ipp.gov. Contractors can obtain enrollment assistance by contacting the Fiscal Service Accounts Payable Help Desk via e-mail at

AccountsPayable@fiscal.treasury.gov or by phone at 304-480-8000, Option 7.

(c) Contractors that are not able to utilize the IPP system for submitting payment requests may submit invoices electronically by email to AccountsPayable@fiscal.treasury.gov. Microsoft

Excel, Adobe Acrobat Portable Document Format (PDF) and Microsoft Word are acceptable formats.

(d) Invoices for services shall be submitted monthly unless otherwise stated elsewhere in the contract.

(e) For invoice and payment questions call the Fiscal Service AP Help Desk at 304-480-8000, Option 7.

IV. FINAL PAYMENT

Before final NARA payment is made, the Contractor must furnish to the CO a written release of all claims against the Government arising by virtue of the contract, other than claims in stated amounts as may be specifically excluded by the Contractor from the operation of the release. If the Contractor’s claim to amounts payable under the contract has been assigned under the

Assignment of Claims Act of 1940, as amended (31 U.S.C. § 203, 41 U.S.C. § 15), a release may also be requested of the assignee. To ensure that all necessary adjustments for non-performance or unsatisfactory performance have been made and a release of claims has been submitted before the contract is closed out, the final NARA payment will be made in thirty (30) calendar days after receipt of a proper invoice, date of completion of performance, or receipt of release of claims by the CO, whichever is later.

ATTACHMENT 6

ADDITIONAL NARA TERMS AND CONDITIONS

(Addenda to FAR Clause 52.212-4)

I. SECURITY OF INFORMATION AND PROTECTION OF CONTROLLED

UNCLASSIFIED INFORMATION, INCLUDING PERSONALLY IDENTIFIABLE

INFORMATION (APRIL 2017)

(a) Applicability

This clause applies to all controlled unclassified information, which may include personally identifiable information, as defined in Section B, regardless of the medium in which it is found and includes paper records.

(b) Definitions. As used in this clause:

“Breach” means the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar situation where persons other than authorized users, and for other than authorized purpose, have access or potential access to personally identifiable information, in usable form whether physical or electronic.

“Controlled Unclassified Information” means information the Government creates or possesses, or that an entity creates or possesses for or on behalf of the Government, that a law, regulation, or Government-wide policy requires or permits an agency to handle using safeguarding or dissemination controls. However, CUI does not include classified information or information a non-executive branch entity possesses and maintains in its own systems that did not come from, or was not created or possessed by or for, an executive branch agency or an entity acting for an agency. Law, regulation, or Government-wide policy may require or permit safeguarding or dissemination controls in three ways: Requiring or permitting agencies to control or protect the information but providing no specific controls, which makes the information CUI Basic;

requiring or permitting agencies to control or protect the information and providing specific controls for doing so, which makes the information CUI Specified; or requiring or permitting agencies to control the information and specifying only some of those controls, which makes the information CUI Specified, but with CUI Basic controls where the authority does not specify.

“Personally identifiable information (PII)” means any information that permits the identity of an individual to be directly or indirectly inferred, including any other information that is linked or linkable to that individual regardless of whether the individual is a citizen of the United States, legal permanent resident, or a visitor to the United States. Examples of PII include the following:

(1) Name.

(2) Date of birth.

(3) Mailing address.

(4) Telephone number.

(5) Social Security Number.

(6) Email address.

(7) Zip code.

(8) Account numbers.

(9) Certificate/license numbers.

(10) Vehicle identifiers including license plates.

(11) Uniform resource locators (URLs).

(12) Internet protocol addresses.

(13) Biometric identifiers (e.g., fingerprints).

(14) Photographic facial images.

(15) Any other unique identifying number or characteristic.

(16) Any information where it is reasonably foreseeable that the information will be linked with other information to identify the individual.

“Sensitive personally identifiable information (sensitive PII)” means a subset of PII, which if lost, compromised or disclosed without authorization, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual.

(1) Complete social security numbers, alien registration numbers (A-number) and biometric identifiers (such as fingerprint, voiceprint, or iris scan) are considered sensitive PII even if they are not coupled with additional PII.

(2) Additional examples include any grouping of information that contains an individual’s name or other unique identifier plus one or more of the following elements:

(i) Driver’s license number, passport number, or truncated social security number (such as last 4 digits);

(ii) Date of birth (month, day, and year);

(iii) Citizenship or immigration status;

(iv) Financial information such as account numbers or electronic funds transfer information;

(v) Medical information; and/or

(vi) System authentication information such as mother’s maiden name, account passwords or personal identification numbers.

(3) Other PII may be “sensitive” depending on its context, such as a list of employees with less than satisfactory performance ratings or an unlisted home address or phone number. In contrast, a business card or public telephone directory of agency employees contains PII but it is not sensitive.

(c) Data Security.

(1) The Contractor shall limit access to the data covered by this clause to those employees and subcontractors who require the information in order to perform their official duties under this contract.

(2) The Contractor employees, and subcontractors must physically or electronically secure CUI, which may include sensitive PII, when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss.

(3) When CUI is no longer needed or required to be retained under applicable Government records retention policies, it must be destroyed in accordance with NIST 800-88 standards.

(4) The Contractor shall only use CUI obtained under this contract for purposes of the

Contractor; it shall not be disclosed, released, disseminated, or published without the prior written consent of the Contracting Officer.

(5) If it is established elsewhere in this contract that information to be utilized under this contract, or a portion thereof, is subject to the Privacy Act, The Contractor shall follow the rules and procedures of disclosure set forth in the Privacy Act of 1974, 5 U.S.C. 552a, and implementing regulations and policies, with respect to systems of records determined to be subject to the Privacy Act.

(6) At expiration or termination of this contract, the Contractor shall turn over all CUI obtained under the Contractor that is in its possession.

(d) Systems Access. Work to be performed under this contract may require the handling of CUI, including PII. The Contractor shall provide the Government access to, and information regarding those systems handling CUI, including sensitive PII for the Government under the

Contractor, when requested by the Government, as part of the Contractor’s responsibility to ensure compliance with security requirements, and shall otherwise cooperate with the

Government in assuring compliance with such requirements. Government access shall include independent testing of controls, system penetration testing by the Government, Federal

Information Security Management Act data reviews, and access by agency Inspectors General

(IG) for IG reviews.

When requested by the NARA CO or COR or other NARA official as described herein, in connection with NARA’s efforts to ensure compliance with security requirements and to maintain and safeguard against threats and hazards to the security, confidentiality, integrity, and availability of NARA Information, Contractor shall provide NARA, including the NARA OIG,

(1) access to any and all information and records, including electronic information, regarding a

Covered Information System, and (2) physical access to Contractor's facilities, installations, systems, operations, documents, records, and databases. Such access may include independent validation testing of controls, system penetration testing, and FISMA data reviews by NARA or agents acting on behalf of NARA, and such access shall be provided within 72 hours of the request. Additionally, the Contractor shall cooperate with NARA’s efforts to ensure, maintain, and safeguard the security, confidentiality, integrity, and availability of NARA information.

(e) Systems Security.

(1) In performing its duties related to management, operation, and/or access of systems containing PII under this contract, the Contractor, its employees and subcontractors shall comply with all applicable security requirements and rules of conduct applicable to the agency’s systems as described in:

a) NARA Directive 1608 http://www.archives.gov/foia/directives/nara1608.pdf and

b) FedRAMP baseline controls for moderate IT systems.

(2) In addition, the use of Contractor-Owned laptops or other portable storage devices to process or store sensitive PII is prohibited under this contract until the Contractor provides, and the

Contracting Officer, in coordination with the Senior Agency Official for Privacy (SAOP) or the

SAOP’s designee, approves the Contractor’s written acknowledgment that the following requirements are met:

(i) Laptops and other portable storage devices must employ encryption that is NIST Federal

Information Processing Standard (FIPS) 140-2 validated (or its successor) http://csrc.nist.gov/publications/PubsFIPS.html, and approved.

(ii) The Contractor has developed and implemented a process to ensure that security and other applications software are kept current.

(iii) Mobile computing devices utilize anti-virus software and a host-based firewall mechanism.

(iv) Removable media, such as hard drives, flash drives, devices with flash memory, CDs and floppy disks containing CUI, which may include sensitive PII shall not be removed from a Government facility unless they are encrypted using a NIST FIPS 140-2 or successor approved product.

(v) When no longer needed, all removable media, hard drives, and flash memory shall be destroyed in accordance with Government security requirements identified in NARA’s

Media Protection Methodology.

(vi) The Contractor shall maintain an accurate inventory of devices used in the performance of this contract.

(3) All NARA information obtained under this contract shall be removed from Contractor-

Owned information technology assets at the direction of the Contracting Officer or Contracting

Officer’s Representative. Removal must be accomplished in accordance with standard

FedRAMP controls for media protection in moderate IT systems and NIST 800-88 standards.

Certification of data removal will be performed by the Contractor’s Project Manager and written notification confirming acknowledgment will be delivered to the Contracting Officer within 30 days of the direction to remove the information.

(4) Back up or mirrors of any systems or files containing CUI shall be treated in the same manner as the original data containing CUI, with the same protections and obligations.

http://www.archives.gov/foia/directives/nara1608.pdf http://www.archives.gov/foia/directives/nara1608.pdf http://csrc.nist.gov/publications/PubsFIPS.html http://csrc.nist.gov/publications/PubsFIPS.html

(5) The Contractor shall require FIPS 140-2 (or successor) encryption of any sensitive PII when transmitted electronically across the Internet or other public works.

(f) Breach Notification to Government.

(1) The Contractor has been provided with: NARA Directive 1608, and is aware of its roles, responsibilities, and relationship with the Government in case of data breach.

(2) In the event of any actual or suspected breach of sensitive PII, the Contractor shall immediately, and in no event later than one hour of discovery, report the breach to the

Contracting Officer, the COR, the Senior Agency Official for Privacy (currently NARA’s

General Counsel garymstern@nara.gov) and the Chief Information Officer (only for IT requirements) in accordance with NARA Directive 1608.

(3) The Contractor is responsible for positively verifying that notification is received and acknowledged by appropriate Government parties identified in subparagraph (2) above.

(4) In the event of a confirmed, potential or suspected Security Breach, involving unauthorized exposure, loss of control, compromise, exfiltration, manipulation, disclosure, acquisition, or accessing of any Covered Information System or any NARA Information accessed by, retrievable from, processed by stored on, or transmitted within, to or from any such system, Contractor shall immediately (and in no event later than within 1 hour of discovery) report any

Confirmed Breach to the NARA CO and the CO's Representative (''COR").

(5) NARA, at its sole discretion, may obtain, and Contractor will permit, the assistance of other federal agencies and/or third party contractors or firms to aid in response activities related to any security incident, PII or Security Breach. Additionally. NARA, at its sole discretion, may require

Contractor to retain, at the Contractor's expense, a Third Party Assessing Organization (3PAO) acceptable to NARA, with expertise in incident response, compromise assessment, and federal security control requirements, to conduct a thorough vulnerability and security assessment of all affected Information Systems.

(6) Any report submitted in accordance with paragraphs (1), (2) and (3) above, shall identify (I) both the Information Systems and NARA Information involved or at risk, including the type, amount, and level of sensitivity of the NARA Information and, if the NARA Information contains PII, the estimated number of unique instances of Pll, (2) all steps and processes being undertaken by Contractor to minimize, remedy, and/or investigate the Security Incident, (3) any and all other information as required by the USCERT Federal Incident Notification Guidelines, including the functional impact, information impact, impact to recoverability, threat vector, mitigation details, and all available incident details; and (4) any other information specifically requested by the NARA. Contractor shall continue to provide written updates to the NARA CO regarding the status of the Security incident at least every three (3) calendar days until informed otherwise by the NARA CO.

(7) Response activities related to any security incident or PII or Security Breach undertaken by

NARA, including activities undertaken by Contractor, other federal agencies, and any third-party contractors or firms at the request or direction of NARA, may include inspections, investigations, forensic reviews, data analyses and processing, and final determinations of responsibility for the

Security Incident and/or liability for any additional response activities. Contractor shall be responsible for all costs and related resource a locations required for all such response activities related to any Security…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.