Attachment 4 Task Order 0002 - ASSC Ops and Maint.doc

DOC document 107 KB Posted

Attached to
Application Support Services Federal contract opportunity
Solicitation number
A10006
Issued by
Department of the Treasury Departmental Offices

About this file

Attachment 4 - O M PWS

View the file

Other files for this federal contract opportunity

Other files attached to Application Support Services, newest first.
File Type Posted
Amendment 5.pdf PDF
A10006Amend4.pdf PDF
A10006AMEND3 ASSC.pdf PDF
Attachment 9A - ASSC Applicatitions List —
Attachment 4 Task Order 0002 - Revision 1.doc DOC document
Attachment 21.pdf PDF
Attachment 2 Price ASSC Schedule Revision 1.doc DOC document
Attachment_20_-_Sample_Task_Order Revision 1.docx DOCX document
Attachment 1 IDIQ PWS-ASSC Revision 1.doc DOC document
A10006Responses.doc DOC document
A10006 Amendment 0002.pdf PDF
Amendment 1 A10006 Feb.pdf PDF
Attachment 7 ASSC_Major Apps on Web.ppt PPT presentation
Attachment 8 - ASSC_Major Apps on DOLAN.ppt PPT presentation
Attachment 2 Price ASSC Schedule.doc DOC document
Attachment 6 - Project Profiles_ASSC.ppt PPT presentation
Attachment 20 - Sample Task Order.docx DOCX document
Attachment 11 HQ IT Apps Environment Table.doc DOC document
Attachment 3 - Transition.doc DOC document
Attachment 16- Inventory of Data Subscription Services.doc DOC document
A10006 RFP ASSC.pdf PDF
Attachment 9 - ASSC Application List.pdf PDF
Attachment 5 ASSC IT Definitions.docx DOCX document
Attachment 18 DD254.pdf PDF
Attachment 19 PP.doc DOC document
Attachment 12 Software CMP.pdf PDF
Attachment 10 DO Coding.pdf PDF
Attachment 1 IDIQ PWS-ASSC.doc DOC document
Attachment 14 Life Cycle.pdf PDF
Attachment 17 - Non-disclosure Agreement.doc DOC document
Show all 30

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S Department of the Treasury

Applications Support Services Contract

Office of the Chief Information Officer

A10006 – Attachment 4

Task Order 0002

Performance Work Statement - FFP Provide Application Systems Operations and Maintenance Support

1.

INTRODUCTION

This Task Order is issued under the U.S. Department of the Treasury (Treasury), Application Support Services Contract (ASSC) to perform ongoing operations and maintenance support for the installed base of software application systems owned and operated by the Departmental Offices (DO) and other Treasury Bureau.

2.

DESCRIPTION OF SERVICES & TASK AREAS

The ASSC Contractor shall operate and maintain the portfolio of applications supported by the Treasury Office of the Chief Information Officer (OCIO) on behalf of the DO Program Offices and the Bureaus. “Installed base” is defined as that inventory of applications and solutions that are in an operational/production status as of: (1) the contractor’s assumption of control under this contract and (2) the end of each Government fiscal year. Details on these applications including their functionality, technical description, hardware and software components, their connectivity, and relation to the overall DO IT infrastructure are included as Attachments in the base ID/IQ.

Contractor shall provide support in the following areas:

· Program Management

· Program Management Support Services

· Application Software Maintenance

· System Maintenance Procedures

· Fault and Problem Management

· Change and Configuration Management

· Database Administration

· Application/System Performance Reviews/Capacity Planning

· Documentation Maintenance

· Performance Reviews and Analysis of Operational Applications

· Application Helpdesk/Customer Support

· Application Information System Security

· Continuity of Operations and Disaster Recovery Capability

· Access Control and Authentication

· Infrastructure Environment Interoperability and Compatibility

· Technology Review and Refresh

· Support of Data Subscription Services

Contractor shall perform all activities necessary to maintain, operate, and administer applications in accordance with the government-approved Project Management Plan (PMP) developed at the outset of this task.

Unless otherwise identified explicitly, all tasks and activities described throughout this PWS shall be included in the firm-fixed price of this task order.

2.1

PROGRAM MANAGEMENT

The contractor shall provide program management services to plan, initiate, execute, administer, and closeout the entire range of application support services programs and projects that the OCIO supports on behalf of the DO Program Offices and the Bureaus. The contractor shall provide expert advice, assistance, and guidance in support of the OCIO application support services to include project leadership and communications with stakeholders; project planning and management; earned value management support (if required); performance monitoring and measurement; schedule management; risk management; reporting and documentation associated with project/program/portfolio objectives; program integration services; and project close-out services.

The contractor shall attend key events such as configuration control board meetings; program management meetings, reviews, and briefings; and other direct support events to ensure that the requirements of the ASSC program are accomplished.

2.1.1 Program Management Plan (PMP)

Within 15 calendar days of the award of this Task Order, the contractor shall revise, update and finalize the draft PMP submitted with their proposal. The final PMP shall describe contractor’s overall management approach, milestones, staffing and allocation of responsibilities, quality assurance plan, and any other best practices aimed at ensuring effective program administration in partnership with the Treasury OCIO. The strategies provided shall clearly indicate the contractor’s understanding and ability to apply Federal and Treasury guiding policies/processes (i.e. ISLC, IT Security Program, IT Strategic Plan, etc.) as identified in the base contract list of references.

The Government will provide comments/recommendations within 5 calendar days. Within 10 calendar days after receipt of the Government’s comments/recommendations, the contractor shall deliver the final PMP. The Government will provide approval within 5 calendar days after receipt.

Contractor shall review and update the PMP on an as needed basis throughout the performance of this task order to reflect changes proposed by the contractor and accepted by the government. Changes shall be proposed via the Quarterly Program Review meetings. Upon receiving approval, the contractor shall update the plan within 15 calendar days and deliver a softcopy update to the COTR.

Contractor’s Program Management Plan shall demonstrate:

· A proven strategy/methodology for managing the daily operational aspects of the scope of work in parallel with multiple inter-dependent and individual project requirements.

· Contractor’s ability to coordinate and prioritize resources across multiple projects.

· Strategy for ensuring that the services provided are in compliance with all Federal and Treasury rules, regulations, processes and/or policies. Emphasis shall be placed on Contractor’s ability to respond to changes in the Federal IT environment.

The contractor shall follow PMI standards and PMBOK (http://www.pmi.org/Resources/Pages/Library-of-PMI-Global-Standards.aspx) best practices in developing the PMP content and format. In addition to the PMI and PMBOK suggested content, the following topics shall be submitted as part of the contractor’s PMP.

Management Plan: The Offeror shall provide a management plan that describes how the Offeror intends to accomplish, administer, and manage the tasks identified and described in the PWS. Response to this Section shall be submitted as the Offeror’s Draft Program Management Plan (PMP), and it shall comprise the following sections:

(a) Program Organization: The Offeror shall describe in detail the program organization and its relationship to corporate management clearly establishing the roles and responsibilities assigned to each and identifying the level of autonomy at the program-level compared to decisions that need to be referred to corporate management.

(b) Staffing Plan: The Offeror shall develop an initial staffing plan. The staffing plan shall describe the Offeror’s approach to staffing allocations, proposed labor categories and the roles and responsibilities associated with them. Offeror shall provide personnel possessing the appropriate qualifications, skill sets and experience for the successful performance of the work. The staffing plan shall address such attributes as key personnel, personnel security and administration of personnel security, retention and training of personnel, approach to personnel changes, professional development of personnel, and any other element pertinent to staff management.

(c) Task Order Management Plan: The Offeror shall describe the various processes, procedures, and methods to be employed at both the program- and at the corporate-level in managing the:

i. Fixed-price operation and maintenance services task; and

ii. The development-oriented, task orders that are placed against the contract in response to technical task area requirements described in the PWS.

(d) Schedule Management Plan: The Offeror shall describe how a project schedule in the form of a Gantt chart will be created, preferably using a project tracking tool such as MS Project. The Offeror shall describe the control mechanisms used to measure the progress of the work completed at milestones. The plan shall describe the methods and tools used to compare actual schedule performance to planned performance and to implement corrective action when actual performance deviates from planned or required performance. Describe how a project schedule in the form of a Gantt chart will be created, preferably in a project tracking tool such as MS Project. Describe how contingency buffers will be tapped and revised when actual performance falls behind estimates. Describe how and when schedules will be modified and how agreement and commitment to the revised schedules will be achieved.

(e) Risk Management Plan: The Offeror shall describe its approach for identifying, analyzing, prioritizing, and controlling program and task order (project) risks. The plan shall describe the procedures for contingency planning and the methods used in tracking risks, evaluating changes in individual risk exposures, and responding to those changes. Include a plan for ongoing risk identification throughout the program life cycle. Describe how the Offeror incorporates risk management into each task order (project) schedule and budget.

(f) Configuration Management and Change Control Plan: The Offeror shall describe the activities and methods that will be used for configuration identification, control, status accounting, auditing, and release management. The configuration management plan should address the initial baselining of work products, logging and analysis of change requests, change control board procedures, tracking of changes in progress, and procedures for notifying concerned parties when baselines are established and changed. Include who within the Program Organization will be responsible for establishing the baselines, maintaining the configuration management system, and conducting CM reviews and audits.

(g) Quality Assurance Plan: The Offeror shall describe the activities and methods used to build high-quality products by the sensible application of an appropriate process. The plan should indicate the relationships among the quality assurance, testing (or verification and validation), peer review, audit, and configuration management activities. Describe the process that will be used to identify the quality-related tasks to be performed, assigning responsibility, estimating the percentage of project effort or the number of hours for quality assurance activities, and incorporating quality assurance tasks into the project schedule and budget. Include who within the Program Organization will be responsible for performing quality assurance.

In this section the Offeror shall also describe its approach to ensuring how they will meet the performance metrics defined in the SLAs to include technical, management and quality assurance processes and procedures supported by automated tools to objectively collect, track, and report on actual performance against the established SLAs. This shall include contractor performance monitoring and control activities to ensure all deliverables and performance metrics are fully met.

(h) Communications Plan: The Offeror shall describe how it plans to communicate within its own organization, with treasury OCIO management, and with the various departmental offices who are the stakeholders and business owners of the applications serviced through the ASSC contract. The plan shall identify the regular reports and communications expected of the program, such as weekly status reports, regular reviews, and as-needed communication. This shall include specifying the reporting mechanisms, report contents, and information flows used to communicate the status of requirements, schedule, budget, quality, risks, and other status indicators both within the project and to external stakeholders.

(i) Subcontractor Management Plan: The Offeror shall describe to what extent subcontractors and/or team members will be involved in the performance of the proposed tasks, identify the functional area for which they will be responsible, and describe how the Offeror will manage the subcontractor and/or team member participation. The Offeror shall describe how it will ensure subcontractors deliver quality products on-time and within budget.

(j) Budget and Financial Management Plan: The Offeror shall describe the control mechanisms used to measure the cost of work completed, compare actual to budgeted cost, and implement corrective actions when actual cost deviates excessively from budgeted cost. The plan shall specify the intervals or points at which cost reporting is needed and the methods and tools that will be used to manage the budget. The plan shall describe who within the Program and Corporate Management ranks is responsible for forecasting and controlling budgets and expenses on an annual basis, and who is responsible for tracking actual hours and for reporting actual and estimated program and task order costs by milestone to the Government.

2.1.3 Monthly Status Reports

The contractor shall submit Monthly Status Reports, no later than the tenth (10th) calendar day of the following month, to address progress on the Program Management Plan, any on-going task orders, and other contractually established tasking. In this status report, the contractor shall consider approaching milestones and identify potential project issues. The contractor shall submit a single Monthly Status Report that addresses project status by funding source and/or major project group as well as adherence to respective project schedules, budgets, and project milestones. Specifically, the Monthly Status Report shall provide details on:

a) Contractor’s assessment of acquisition, maintenance, and support tasks associated with the ASSC Contract.

b) Contractor’s assessment of each on-going project or task by project title and tracking number to include the progress to date; impact issues and recommendations to address such issues; accomplishments over the past reporting period; proposed steps over the next reporting period; and a financial status to include dollars and hours expended and dollars obligated to date and expectations (financially) for the balance of the project.

c) Report on staffing to include current on-board strength for contractor and subcontractor personnel as well as any changes to personnel for this reporting period.

d) The contractor’s tracking of major issues, initiatives, or program refinements relative to Status of Performance.

2.1.4 Monthly Program Review Meetings

The contractor shall schedule with the CO and COTR a monthly Program Review Meeting no later than the 15th day (or first business day after) of each month. The contractor shall provide a review presentation of all issues contained in the prior monthly status report as well as any additional items requested by the COTR.

2.1.5 Quarterly Program Review

On a quarterly basis, following the transition period, the contractor shall host a quarterly program review session with the CO, COTR and senior OCIO management. The Quarterly Program Review shall be held monthly for the first six months after award and quarterly thereafter on the 10th day (or first business day after) of the new quarter, in lieu of the Monthly Program Review Meeting. The contractor shall coordinate the meeting, prepare all presentation materials, and provide a summary of the discussion and outputs from the review. The purpose of the program review is to report on contractual goal accomplishments, fiscal health relative to funded tasking, and key performance “dash board” indicators, as well as to identify items for the next quarterly reporting period. The horizon for the content scope shall be of one or more quarters completed and pending. This program review shall incorporate the quality performance report outlined in the contractor’s Quality Assurance Plan. The contractor and Treasury program manager shall pre-coordinate special interest agenda items of either programmatic or technical interest for discussion relative to technical direction, funding, and/or business direction.

2.1.6 Budget Forecast

Within 55 calendar days of the award of this Task Order, the contractor shall submit an initial Budget Forecast for the first three option periods of the contract. The contractor shall prepare and maintain a budget forecast for each option period. The budget forecast shall estimate the level of effort for the current option periods, plus the two succeeding fiscal years. The report shall be developed by funding source and by project/system within each funding source. For each project/system it shall estimate: a) the on-going operations and maintenance of the baseline system as of the end of the previous fiscal year; and b) new work or enhancement projected to that baseline spread over one or more fiscal years as driven by the specific initiative’s requirements. The ASSC Budget Forecast shall only pertain to the products and services obtained via the ASSC contract.

2.2

APPLICATION SOFTWARE OPERATIONS AND MAINTENANCE

The contractor shall provide technical and administrative support for the maintenance and enhancement of application systems. Work shall include all system and application development lifecycle tasks in accordance with the ISLC as well as other Federal and Treasury rules, regulations and guiding policies/procedures. Additional activities within this tasking area include granting access to systems for new accounts, maintaining application system tables, setting up new work groups, creating views, developing application migration plans in support of new software releases and providing system modifications for new capabilities.

Contractor shall utilize and adhere to the OCIO- published “Maintenance Windows,” in the performance of all maintenance activities. These maintenance windows are defined times to install and cutover changes to the production systems during the seven day work week. Contractor shall establish process and structures to coordinate maintenance activities with the appropriate infrastructure contractors to ensure awareness and mitigate schedule conflicts.

The maintenance windows are currently:

· Wednesday nights (10 PM) to the following Thursday morning (4 AM);

· Weekends from Saturday evening (4PM) to noon Sunday;

Contractor is cautioned that exceptions or extensions to the above identified maintenance windows are only granted on rare occasion. Further, emergency maintenance is an exception, and is addressed on a case-by-case basis.

2.2.1

SYSTEM MAINTENANCE PROCEDURES

The contractor shall update and maintain documentation on systems maintenance procedures, ensuring they are complete and current at all times. Contractor shall perform ongoing analysis of application system maintenance procedures and processes. Based on the results, the contractor shall recommend ways to improve the procedures relating to efficiency, ease of maintenance, responsiveness to user requests, and similar objectives.

2.2.2

FAULT AND PROBLEM MANAGEMENT

The contractor shall perform fault and problem management services throughout the duration of the task order. In addition to effectively and efficiently addressing individual problems and faults, the contractor shall identify chronic issues, trends, or security risks. Upon determination and validation of such chronic conditions, the Contractor shall prepare a root cause analysis and a remediation plan 2.2.3

CHANGE AND CONFIGURATION MANAGEMENT

Contractor shall establish and sustain a configuration management and change control plan, consistent with the objectives described in the Treasury ISLC, for all of the systems and applications supported.

2.2.4

PERFORMANCE REVIEWS AND ANALYSIS OF OPERATIONAL APPLICATIONS

The Contractor shall establish and sustain integrated business processes, procedures and records for effective surveillance of application performance, database efficiencies, and infrastructure resources to ensure: a) effective and efficient use of resources; b) forecasting resource changes well in advance of provisioning timelines; or c) mitigation of any operational shortcomings. The contractor shall follow PMI standards and PMBOK best practices in developing the PMP content and format to include: communications plan, risk management plan, schedule management plan, personnel management plan, subcontractor management plan, configuration management and change control plan, quality assurance plan, and cost management.

2.2.5

APPLICATIONS HELPDESK/CUSTOMER SUPPORT

Contractor shall provide an applications helpdesk/customer support service. This service shall be provided in two formats.

Staffed Helpdesk: Contractor shall provide a “level 1 helpdesk” between the hours of 7:00 AM and 5:30 PM Eastern time each Federal business day. The helpdesk shall provide basic support such as application status questions, scheduled maintenance/downtime, and system access issues for all applications and data services included for support under this task order. Contractor’s help desk may receive escalated calls from the DO IT Helpdesk (Infrastructure Support Contractor) for ASSC managed applications and services. The ASSC level 1 helpdesk shall escalate problem calls to applications technical specialists as appropriate. Contractor shall implement appropriate mechanisms and business processes to ensure access to level 2 and 3 contractor technical specialists for timely resolution of requests. All calls shall be logged, tracked and managed following industry best practices.

After-Hours On-Call: Contractor shall provide after-hours, weekend, and holiday on-call support for the ASSC contractor-supported portfolio of applications. In accordance with the business process and funded tasking for that application, the Contractor shall determine the level and form of response or remedial action and support to be provided on an after-hours basis.

2.2.6

APPLICATION INFORMATION SYSTEM SECURITY

The Contractor shall ensure that all applications and systems managed are in compliance with all Federal Information Security regulations/mandates and Treasury guiding policies/procedures (i.e. Treasury Information Technology Security Program, TD P 85-01, Treasury Security Manual TD P 15-71, the Federal Information Security Management Act (FISMA), NIST SP 800-53 and -53a current revision, etc.). Contractor shall be responsible for ensuring changes, updates, new federal mandates, etc., issued by Federal and Treasury authorities are implemented accurately and in a timely manner. Contractor’s personnel shall be aware of and capable of implementing the latest, most technologically advanced Information Security guidelines and practices. Additionally, all contractor employees with DO LAN and/or application access must complete DO-provided IT security awareness training on an annual basis.

2.2.7

ACCESS CONTROL AND AUTHENTICATION SUPPORT

The contractor shall ensure that, in addition to the above guidance, access control and authentication applied to the applications supported herein are in compliance with the most updated versions of the following:

· HSPD-12 for logical access;

· OMB Directive M4-04 for level of authentication;

· Treasury IT Security Policy as described in TD P 85-01;

· NIST SP 800-53 and -53a (current revision); and

· Employ the Treasury Directory System, Public Key Infrastructure, and Portals for standard solutions.

2.2.8

CONTINUITY OF OPERATION AND DISASTER RECOVERY CAPABILITY

The Departmental Offices have established, at a Departmental level, Continuity of Operations (COOP) and Disaster Recovery (DR) Plans consistent with the guidance in NIST 800.34 (Contingency Planning Guide for Information Technology Systems). The OCIO has established policy and practices for the OCIO and its services to support the Departmental Program and Policy Offices in the event of plan activation. The OCIO currently has two application hosting environments each with maturing COOP/DR infrastructures.

Contractor’s COOP/DR responsibilities shall include the following:

· Applications developed and maintained shall be designed and implemented to support COOP/DR within the context of a common OCIO architecture.

· Support shall include participation in COOP/DR exercises and tests as scheduled by Treasury. Contractor shall provide trained, experienced personnel for such exercises, which will be conducted approximately three times per year. Contractor personnel assigned to COOP/DR exercises will be required to travel within 320 miles of Washington, D.C. for the duration of each exercise.

· Applications shall be documented to enable operation and support in a COOP/DR scenario.

2.3 Provide Content and Data Subscription Service Support

The contractor shall perform ongoing operations and maintenance support for the Government furnished content and data subscription services licensed and used by the Departmental Offices (DO). These content and data services support the core responsibilities of the Department’s Domestics Finance, International Affairs, and Office of Financial Stability organizations. These content and data subscription services are commercial and Government content data services offerings (as funded and provided by the Government) accessed through the internal DO infrastructure. A profile of these content and data subscription services is provided in Attachment (16).

The contractor shall administer, support and monitor the DO content and data subscription licensed services as used within the Departmental Offices under an OCIO Content and Data Subscription Service Coordinator. The support to be provided includes:

Operational Support

· Support DO client requested adds/change/deletes of content and data subscription services to include –

· Provide consulting support to DO client offices to assist them in establishing the add/change/delete requirements of this GFP.

· Coordination of site readiness by the DO ITIMS contractor and/or Government client office, upon Government completion of contract actions to enable an add/change/delete.

· Coordination of desktop licensed product installation to include: product licensed software, product keyboard or other hardware, or desktop/PDA setup of related subscription service assets.

· Service implementation and cutover (add/change/delete) with the DO environment.

· Provide service installation performance testing and results validating “ready-to-use”.

· Provide installation follow-up not more than 5 business after installation to confirm standard performance of service.

· Maintain records and documentation of Subscription Services

· Work Request Tracking: Information to ensure an account and timely completion of these work requests.

· Configuration Information: Maintain a Profile of installed content and data subscription services

· Asset Inventory Information: Maintain a Profile of hardware and software assets (both installed and “warehoused”.

· Support Operations of Data and Subscription Service

· Fault and Problem Management: Respond to and resolve DO helpdesk tickets regarding client operational problems in accessing existing content and data subscription services.

· Helpdesk/Customer Support: Provide status through closure and after action reports to the ITIMS helpdesk for all ITIMS helpdesk tickets tasked regarding content and data subscription services.

· Risk Mitigation: Monitor reports from Government provided Employee Entry Exit system to track subscription service account owner relocations, separations, or other actions changing the disposition of current license owners of content and data subscription services.

· Change and Configuration Management: Monitor: Maintain, validate, and review with Government Service Coordinator sound configuration process and tool for the content and data subscription services.

· Continuity of Operations and Disaster Recovery Capability: During OCIO testing or in actual circumstances support the OCIO in COOP and DR activities relative to content and data subscription services to ensure service availability and performance with established levels.

· Access Control and Authentication: Quarterly review DO user offices practices and compliance with product license agreements for service access and authentication either through DO LAN access or PDA access for those authorized.

· Infrastructure Environment Interoperability and Compatibility: ITIMS contractor planned infrastructure and environmental changes and activities to determine and report impact upon current content and data subscription services.

· Technology Review and Refresh: At least semi-annually review the content and data subscription service provider web sites and other trusted sources for information as to product and product environmental enhancement to advise the Government POC of needed Government action to leverage or sustain interoperability.

Service Management Support

· Status of Service Support activities reported in Monthly Status Report

· Performance Metrics reported as outline in the PMP

2.3.1 Service Support Procedures

The contractor shall update and maintain documentation on service support procedures, ensuring they are complete and current at all times. Contractor shall perform ongoing analysis of service maintenance procedures and processes to include interface with infrastructure service providers partnering in the DO client community ability to access and utilize these content and data subscription services. Based on the results, the contractor shall recommend ways to improve the procedures relating to efficiency, ease of maintenance, responsiveness to user requests, and similar objectives.

2.3.2 Fault and Problem Management

The contractor shall perform fault and problem management support for content and data subscription services installed. In addition, in effectively and efficiently addressing individual problems and faults, the contractor shall identify chronic issues, trends, or security risks. Upon determination and validation of such chronic conditions, the Contractor shall prepare a root cause analysis and a remediation plan.

2.3.3 Change and Configuration Management

Contractor shall establish and sustain a configuration management and change control plan, consistent with the objectives described in the Treasury ISLC, for all of the various subscription services supported.

2.3.4 Performance Reviews and Analysis of Operational Applications

The Contractor shall establish and sustain integrated business processes, procedures and records for effective surveillance of service performance and infrastructure resources to ensure: a) effective and efficient use of resources; b) forecasting provider service changes well in advance of provisioning timelines; or c) mitigation of any operational shortcomings. These facets of content and data service management shall be reflected in the PMP.

2.3.5 Helpdesk/Customer Support for Subscription Services

Contractor shall utilize its applications helpdesk/customer support service to create helpdesk tickets and facilitate customer support for the content and data subscription used within the DO.

2.3.6 Information System Security Surveillance

The Contractor shall review and assess that the content and data subscription services managed are in compliance with all Federal Information Security regulations/mandates and Treasury guiding policies/procedures (i.e. Treasury Information Technology Security Program, TD P 85-01, Treasury Security Manual TD P 15-71, the Federal Information Security Management Act (FISMA), NIST SP 800-53 and -53a current revision, etc.).

2.3.7 Continuity of Operation and Disaster Recovery Capability

The content and data subscription service, where a COOP and DR capability for the service is funded, shall be supported. This shall include support to transition to COOP/DR operation, validation of service usability once transition, and support for transition back when directed.

3.0

DELIVERABLES

The contractor shall provide the following deliverables in the execution of this task order:

No.
DELIVERABLE
TO PWS Reference
INITIAL DUE DATE
UPDATE FREQUENCY
001
Program Management Plan
Section 2.1
15 calendar days following award of funded Task Order Task 0002
Annually (December 10th)
001A
Budget Forecast
Section 2.1.1
15 calendar days following award of funded Task Order Task 0002
February 15th and June 15th each Fiscal Year
001B
Staffing Plan
Section 2.1.2
15 calendar days following award of funded Task Order Task 0002
Annually (December 10th with Program Management Plan)
001C
Quality Assurance Plan
Section 2.1.3
15 calendar days following award of funded Task Order Task 0002
Annually (December 10th with Program Management Plan)
002
Monthly Status Report
Section 2.1.4

Monthly (10th of each month or first business day after the 10th)

003
Monthly Program Review Meetings
Section 2.1.5

Monthly (15th of each month or first business day after the 15th)

004
Quarterly Program Review
Section 2.1.6

First month of each Fiscal Year Quarter on 10th day of first month

(In lieu of Monthly)

005
Quality Assurance Report
Section 2.1.3

Semi- Annually on the 10th of February and August or first business day after.

006
Definitive software library and software asset inventories
Section 2.2.3

Due within 10 business days after the 1st of each month

007
Change/configuration Management Requests

Section 2.2.3

As required

008
Trouble Ticket Updates to DO LAN Trouble Ticket System
Section 2.2.5

As Required

009
After action and incident reports
Section 2.2.2

As required w/in 24 hours of incident

010
Performance analysis report
Section 2.2.4

Monthly, due 10 business day

011
System and user manual updates
Section 2.2

As required w/in 10 business days of system change

012
Weekly Help Desk Call Report
Section 2.2.5

Due by 10am on Mondays, covering previous weeks activities

013
System Operations and Maintenance Standard Operating Procedures
Section 2.2

Annual updates, coincident with the Contract Option Year

014
System Monitoring Plan
Section 2.2

Annual updates, coincident with the Contract Option Year

4.0 Period of performance:

Base Period: September 1, 2010 – September 30, 2010 Option Period One: October 1, 2010 – September 30, 2011

Option Period Two: October 1, 2011 – September 30, 2012

Option Period Three: October 1, 2012 – September 30, 2013

Option Period Four: October 1, 2013 – September 30, 2014

Option Period Five: October 1, 2014 – June 30, 2015

5.0 Government Furnished Equipment (GFP)/ Government Furnished Information (GFI)

· Attachment 5 - ASSC IT Definitions

· Attachment 6 – Application Project Profiles of Departmental Offices

· Attachment 7 – ASSC Major Applications on the DO Intranet/Internet

· Attachment 8 – ASSC major Applications on the DOLAN

· Attachment 9 – Active DO ASSC Applications

· Attachment 10 – DO Software Coding Platforms

· Attachment 11 – HQIT Applications Environment Table

· Attachment 12 – Software Configuration Management Plan v2.6

· Attachment 13 – Department of the Treasury: TD P 15-71, Department of the Treasury Security Manual (Reading Room Item)

· Attachment 14 – Department of the Treasury: TD P 84-01, Information System Life Cycle

· Attachment 15 – Department of the Treasury: TD P 85-01, Information Technology (IT) Security Program Publication (Reading Room Item) Task Order 0002

File details come from the government source that posted it. Updated .