PWS.pdf
PDF 99 KB Posted
- Attached to
- Radio IP (RCoIP) System Maintenance - RAVIN Federal contract opportunity
- Solicitation number
- AG-7604-S-17-0040
About this file
PWS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 52.209-11_Clause.pdf | ||
| QASP_RAVIN.pdf | ||
| RAVIN_Pricing_Table.docx | DOCX document | |
| GPAT.docx | DOCX document | |
| RFQ_JOFOC.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement ___________________________ February 2017
Performance Work Statement (PWS) For
RAVIN Radio Control Over IP (RCoIP) Maintenance Support
February, 2017
PART 1
Statement of Requirements
1.0 Introduction: The contractor shall provide all personnel, equipment, tools, materials, supervision, and other items and non-personal services necessary to perform remote support for all channels, licenses, profiles, and configurations of all radio channels and users hosted by the existing Forest Service RAVIN servers. The task includes full system troubleshooting, remote support to USFS technical staff.
The Forest Service shall not provide facilities or equipment. Contractor support is intended to be via telephone and network. Access to the Forest Service network via VPN services is assumed, but the Contractor must meet all Forest Service Computer Security requirements.
1.1 Background and Objectives: The objective of this PWS is to secure maintenance services for RAVIN radio control over IP (RCoIP) solutions installed in the Forest Service infrastructure.
The Forest Service employs multiple RCoIP solutions across its enterprise. RAVIN is one of these solutions. The need has been established for maintenance support of the RAVIN solution for the support of day-to-day operations, troubleshooting, configuration, alteration, software maintenance, and some hardware support.
The current RCoIP systems hosted by the RAVIN servers are currently supported with a maintenance contract. The maintenance agreement for all hardware and software expires on October 6, 2017. This PWS includes a task for a base period of one year of maintenance on all of the existing RAVIN software and equipment as well as three option years for continued maintenance.
This PWS does not include the replacement or re-engineering of any USFS RCoIP system or solution or wide-area network architecture.
1.2 Scope: The Contractor shall provide full configuration and software support for all RAVINs RCoIP solutions hosted by the Forest Service’s Enterprise RAVIN servers. The current software and hardware is covered by maintenance and support until 6 October, 2017. The Contractor shall provide remote support, troubleshooting, test, and configuration services in support of the all RAVIN systems and components. This support shall be available via telephone during normal business hours. A web-based trouble reporting tools shall also be made available by the Contractor. The Contractor shall provide a maximum 2-hour callback service for all problems reported through the web-based trouble reporting tool.
1.3 SERVICES REQUIRED:
1.3.1 Maintenance Task: The task of this PWS is for one year of maintenance to the RCoIP systems hosted by the Forest Service RAVIN servers. Five RAVIN servers currently host all RAVIN RCoIP solutions in the Forest Service.
The goal of this PWS is to have a single contract resource to support all RAVIN systems in the Forest Service architecture. The contractor shall support all radio and user channels on the servers as well as the configuration of RAVIN hardware (models listed below).
The contract services of this PWS are intended to provide support for the installed system by maintaining embedded firmware and all RAVIN-related software at most-current levels. Additionally, the contractor is expected to provide configuration support for the installed systems. This would include support for channel licensing and configuration, user profiling, and all of the necessary enhancements and maintenance of the various software components within the complete system.
The contractor is expected to provide expertise on the configuration of RAVIN systems and aid in the troubleshooting and repair of the installed systems. The contractor shall provide guidance and advice to the Forest Service for the optimal use of the systems.
The Contractor is expected to participate in recurring, scheduled, RAVIN-related conference calls. The Contractor shall act as a technical expert in RAVIN systems.
The contractor shall provide support to the software and hardware items listed below. The list below shows a breakdown of the hardware and software components which comprise the current RAVIN RCoIP systems in the Forest Service. It does not show the configurations of any of the specific systems on these Forests. Configuration information is located on the RAVIN servers and is subject to change.
The support shall be identified as software support, hardware support, configuration support and break-fix support.
Software Support shall include:
• Maintaining all software licenses for all radio and user channels on all USFS RAVIN media and management servers.
• Maintaining client software versioning to the most current revision. This would include the client software. Revisions shall be provided for all client licenses.
• Maintaining dispatch user software versioning to the most current revision on all dispatch clients.
• Maintaining necessary software patches and enhancements to the operating system software on all RAVIN servers and dispatch devices.
• Maintaining all RAVIN software to the most current revision on all USFS RAVIN media and management servers and dispatch devices.
• Installing, patching, enhancing, or maintaining anti-virus software on all USFS RAVIN media and management servers and dispatch devices.
• Installing, patching, enhancing, or maintaining security software on all USFS RAVIN media and management servers and dispatch devices.
• Coordination and maintenance of any third-party software licenses involved with the RAVIN solution (OS software, client software, software within embedded processes, etc)
Hardware Support shall include:
• Installing, patching, or enhancing embedded software within any hardware component listed below.
• Maintaining all software licensing for embedded software for the hardware devices.
Configuration Support shall include:
• Creating, modifying, or deleting user profiles, including dispatch client profiles.
• Creating, modifying, or deleting channel configurations.
• Creating, modifying, or deleting other system attributes necessary to provide the desired performance of the RCoIP systems
• Remote consultation with Forest Service personnel for all aspects of RAVIN system configuration
• Guidance, feedback, and expert opinion on the configuration of Forest Service RAVIN system configuration.
• Operational testing and evaluation with Forest Service personnel for changes which involve the RAVIN systems in this contract. This could include support of USFS network architects and system administrators.
• Remote instructions and advice to Forest Service personnel for the configuration, upgrade, or enhancement of any RAVIN-related software item.
• Remote instructions and advice to Forest Service personnel for the hardware configuration of any RAVIN-related hardware item
• Remote instructions and advice to Forest Service personnel for troubleshooting and testing
Break-fix Support shall include:
• A web-based trouble reporting system available to all Forest Service maintenance personnel
• 2 hour callback on all reported problems
• Remote troubleshooting support
• Next-business-day replacement of failed items listed in Section 1.3.3.
It is expected that all support shall be provided remotely. On-site work and travel is not included. Should the Contractor choose to provide on-site work, the Forest Service shall not be responsible for additional costs incurred. The contractor shall be available via telephone and email. The contractor shall obtain VPN access to the Forest Service network to allow for remote management of all RAVIN hardware devices.
The contractor shall be available via telephone from 0800-1630 Mountain Time, Monday through Friday of all weeks, except as listed in section 1.4 below.
The contractor shall also create a web-based trouble-reporting tool to allow for 24-hour trouble-reporting from the Forest Service.
The current history of maintenance indicates that there are on the order of 10 support requests per week made by the Forest Service.
The Base Year Maintenance task shall begin on 7 October, 2017 through 6 October, 2018, and have three option years.
1.3.2 Existing RAVIN Hardware:
The RAVIN LMR gateways (RAV-LMR-4A and RAV-645H) are 4-port appliances which provide an I/O point for analog audio. The RAVIN LMR gateways run embedded Windows operating systems and provide analog-to-IP transcoding, packetization, and audio stream management functions for the RAVIN systems.
The RAVIN IPUs are an appliance that acts as a media processing engine for RAVIN LMR gateways and other third-party IP gateway devices, which, for the case of the Forest Service are Telex/Vega devices. The IPU runs an embedded Windows operating system and performs digitizing, mixing, audio transcoding and multicast-to-unicast conversions for the RAVIN systems.
The RAVIN IP remotes are dedicated appliances which allow users to access and control radios. They provide two-way audio and use a touch-screen for radio or channel selection and push-to-talk. The IP remotes connect directly to the USFS LAN via RJ45 connection.
1.3.3 Supported Inventory
The following list identifies the current inventory of RAVIN hardware and software for which the Contractor shall provide support (as described in Section 1.3.1), exclusive of next-business-day replacement.
3 EA: RAVIN Server – SDR-S1702-T02 server with Windows 2008 Web Edition And RAVIN Management Software 4.8, License Management: RAV 4.8.1
2 EA: RAVIN Media Server - SDR-S1702-T02 server with Windows 2008 Web Edition
95 EA: RAVIN LMR Gateway (4 Port) AC Power Version
29 EA: RAVIN LMR Gateway (4 Port) DC Power Version
25 EA: RAVIN IPU AC Power Version (RAV-IPU-MS)
2 EA: RAVIN IPU DC Power Version (RAV-IPU-MSD)
103 EA: RAVIN IP Remote (RAV-LMR-R12HO)
233: EA RAVIN Standard Radio Channels – RAVIN 4.5
515: EA RAVIN Desktop PC Communicator Clients – RAVIN 4.5
8: EA RAVIN Standard Dispatch Communicator Clients – RAVIN 4.5
1.3.4 Contractor Invoicing
The Contractor may invoice the Government on a monthly basis.
1.4 Quality Requirements
1.4.1 Quality Control: The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s quality control program is the means by which he assures himself that his work complies with the requirement of the contract.
As a minimum, the contractor shall develop quality control procedures that address the areas identified in Technical Exhibit 1, “Performance Requirements Summary”. After government acceptance of the contractor’s proposed quality control plan the contractor shall receive the contracting officer’s acceptance in writing of any proposed change to his QC system.
1.4.2 Quality Assurance: The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP).
This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). See Technical Exhibit 2.
1.4.3 Government Remedies: The contracting officer shall follow FAR 52.212-4, “Contract Terms and Conditions-Commercial Items” or 52.246-4, “Inspection of Services-Fixed Price” for contractor’s failure to perform satisfactory services or failure to correct non-conforming services.
1.5 Period of Performance:
The base period of performance is 12 months from date of the award with three, one-year, option periods.
Base Period: October 7, 2017- October 6, 2018 Option Year 1: October 7, 2018- October 6, 2019 Option Year 2: October 7, 2019- October 6, 2020 Option Year 3: October 7, 2020- October 6, 2021
1.6 Administrative Considerations:
1.6.1 Hours of Operation/Place of Performance: The contractor is responsible for providing all services between the hours of 8:00AM-6:00PM MST, Monday- Friday, except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this statement of work when the Government facility is not closed for the above reasons. All support is required to be provided from the contractor site.
1.6.2 Recognized Holidays:
New Year's Day Martin Luther King Jr.'s Birthday President's Day Memorial Day Independence Day
Labor Day Columbus Day Veteran's Day Thanksgiving Day Christmas Day
For Task C, the contractor shall maintain the web-based trouble-reporting website during these holidays and sustain the 2-hour callback requirement.
1.6.3 Contractor Travel: Travel is not necessary to support this requirement.
1.6.4 PHYSICAL Security: The contractor shall be responsible for safeguarding all Government property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured and are not used by unauthorized persons. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor's employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer. In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the
Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.
NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer.
1.6.5 COR and Team Responsibilities: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements to the Contracting Officer, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies;
coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract or order. The (COR) is identified below:
Contracting Officer’s Representative: Alicia Vallejos
Telephone Number: 505-563-7716 Email: ajvallejos@fs.fed.us
1.6.6 Conservation of Utilities. The contractor shall instruct employees in utilities conservation practices. The contractor shall be responsible for operating under conditions that preclude the waste of utilities in work areas. This includes use of electrical power and turning off the water faucets or valves after use.
1.6.7 Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5.
The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings the contracting officer will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced.
Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
1.6.8 Contractor Manager: The contractor shall provide a contractor manager or lead who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the contracting officer. The contractor manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract.
1.6.9 Identification of Contractor Employees: All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.
1.6.10 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the
OCI.
1.7 IT Security Requirements:
1.7.1 Acceptance of Security Requirements: By accepting this contract/agreement, the Contractor/Cooperator and other external organizations (hereafter called Contractor) providing Information Technology (IT) services to the US Forest Service (FS) agrees to comply with the applicable IT security policy as outlined in this document, the solicitation, and resultant contract. The Contractor and other external organizations will be responsible for IT security for all systems connected to the FS network or operated by the Contractor and other external organizations for the FS, regardless of location. The term 'information technology', as used in this clause, means any equipment or interconnected system or subsystem of equipment, that is used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data or information. This includes both major applications and general support systems as defined by OMB Circular A-130.
1.7.2 Protection: The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this task. The Contractor shall also protect all unclassified Government data, equipment, etc., by treating information as sensitive business, confidential information, controlling and limiting access to the information, and ensuring the data and equipment are secured within their facility.
1.7.3 Non-Disclosure: The Contractor or other external organization will not publish or disclose in any manner, without the FS Contracting Officer's written consent, the details of any programs, documentation, data, or safeguards either designed or developed by the Contractor or other external organization under this Contract or otherwise provided by the Government. Contractor may be required to sign non-disclosure agreement. A written agreement between the FS and any contractors and other external organizations will be entered into before FS data and information otherwise exempt from public disclosure may be disclosed to the contractors and other external organizations. The contractor and other external organizations will agree to establish and follow security precautions considered by the FS to be necessary to ensure proper handling of data and information. As may be identified elsewhere in this contract, the Contractor agrees that:
1.7.4 Documentation Ownership: The draft and final deliverables and all associated working papers and other materials deemed relevant by the COTR that have been generated by the Contractor in the performance of this contract are the property of the U.S.
Government and must be submitted to the COTR at the conclusion of the tasks to include concept of operations (CONOPS).
1.7.5 Document Reproduction: Documents produced for this project are the property of the U.S. Government and cannot be reproduced or retained by the Contractor.
1.7.6 Contractor Cooperation with Federal Agencies: To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor will afford the Government access to the Contractor's or other external organization's facilities, installations, technical capabilities, operations, documentation, records, and databases. The Contractor will cooperate with Federal agencies and their officially credentialed representatives during official inspections or investigations concerning the protection of FS information. Cooperation may include providing relevant documentation showing proof of compliance with federal and agency requirements, and rendering other assistance as deemed necessary.
1.7.7 Threats or Hazards: If new or unanticipated threats or hazards are discovered by either the Government or the Contractor or other external organization, or if existing safeguards have ceased to function, the discoverer will immediately bring the situation to the attention of the other party. The Contractor will report real or suspected incidents or violations to the FS Computer Incident Response Team (CIRT), by e-mail, at CIRT@fs.fed.us.
mailto:CIRT@fs.fed.us
1.7.8 Subcontractor: The Contractor shall insert these clauses in all subcontracts when the subcontractor is required to have routine physical access to a Federally-controlled facility and/or routine access to a Federally-controlled information system. Failure to comply with said requirements will constitute cause for termination.
The Contractor Agrees To –
(a) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies—
(i) The systems of records; and
(ii) The design, development, or operation work that the contractor is to perform;
(b) Include the Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and
(c) Include this clause, including this paragraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a system of records.
In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.
Definitions of the clause:
(a) “Operation of a system of records,” as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.
(b) “Record,” as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person’s name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.
(c) “System of records on individuals,” as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.
The contractors and other external organizations will ensure that the following banner is displayed on all FS systems that contain Privacy Act information operated by the contractors and other external organizations prior to allowing anyone access to the system:
“This system contains information protected under the provisions of the privacy act of 1974 (public law 93-579). Any privacy information displayed on the screen or printed must be protected from unauthorized disclosure. Employees who violate privacy safeguards may be subject to disciplinary actions, a fine of up to $5,000, or both.”
1.7.9 If your contract/agreement is bringing on contractors/cooperators that need building access and/or computer access:
1.7.10 IT Security Training: The Contractor and other external organizations will ensure that its employees performing under this contract fulfill all Forest Service requirements for mandatory security awareness and role-based advanced security training in accordance with OMB Circular A-130, FISMA, and NIST requirements, and sign all applicable FS statements of responsibilities.
1.7.11 Background Investigations: All non-government employees with unescorted access to FS facilities, computer systems and/or FS information must have background investigations commensurate with the level of risk and magnitude of loss or harm. The FS will determine the level of background investigation and position classification needed.
1.7.12 Personal Identity Verification of Contractor Personnel: The Contractor shall be responsible for ensuring compliance by its employees with all applicable federal regulations, to include those of GSA, NIST, USDA, FS and HSPD-12. Contractors and their employees are subject to all Federal laws applicable to Government installations and are under the jurisdiction of the Federal Protective Service (FPS). The Contracting Officer Representatives (CORs; also known as Contracting Officer Technical Representatives) , or other designated program/project officers, in conjunction with the FS HCM HSPD-12 staff, will assist the Contractor in processing the required Security Background Investigations/Clearances.
(1) The contractor shall comply with the personal identity verification (PIV) policies and procedures established by Department of Agriculture (USDA) Directives 3800 series.
(2) Should the results of the PIV process require the exclusion of a contractor's employee, the contracting officer will notify the contractor in writing.
(3) The contractor must appoint a representative to manage this activity and to maintain a list of employees eligible for a USDA PIV ID Badge required for performance of the work.
(4) The responsibility of maintaining a sufficient workforce remains with the contractor. Employees may be barred by the Government from performance of the work should they be found ineligible or to have lost eligibility for a USDA PIV ID Badge.
Failure to maintain a sufficient workforce of employees eligible for a USDA PIV ID Badge may be grounds for termination of the contract.
(5) The contractor shall insert this clause in all subcontracts when the subcontractor is required to have access to a federally-controlled facility or information system.
(6) The PIV Sponsor for this contract is the contracting officer representative (COR), unless otherwise specified in this contract. The P1V Sponsor will be available to receive contractor identity information from 8:00AM-6:00PM, Monday -Friday at 1601 N. Kent Street, RPC, Arlington, VA 22209. The Government shall notify the contractor if there is a change in the PIV Sponsor, the office address, or the office hours for registration.
(7) At this time, the Government will pay for and process all required security investigations/clearances, except as identified differently within this clause.
(8) The Contractor should be aware of any of its employees possibly having had a background investigation through another government agency. The investigation that was conducted, if verifiable by the FS HSPD-12 staff and, if it was completed within the last 5 years, can be accepted by the Government in lieu of a background check.
(9) The Contractor shall comply with any facility badging requirements for the issuance of building access, badges, etc.:
a. Badging: Ensure that each of the Contractor's employees has been issued either a temporary or permanent badge from the Government. A permanent badge will not be issued until the security questionnaire has been completed and favorably reviewed. Temporary or visitor badges will be provided for persons who are identified as having an infrequent or temporary legitimate business need for access to the site. As noted above, periods that exceed 180 days will require a permanent badge. The badge must be worn at all times while in the facility. It must be displayed above the waist. The individual will retain possession of the badge as long as continued admittance to the site is needed.
b. Ensure the safekeeping, wearing, and visibility of Government furnished badges.
c. Immediately return all badges and permits to the Government when such need ceases to exist.
(10) The Contractor shall comply with any facility security requirements for access to the facility.
(11) The Contractor shall comply with all applicable rules governing parking at USDA locations.
1.7.13 Acquired Software Applications: If your contract or agreement will acquire and/or implement software applications:
1.7.14 Secure Coding Skills: Contractor certifies that at least one member of each programming team working on any code (including C, Java, .Net, ASP.NET, Visual Basic) to be delivered to the Forest Service has earned the Global Information Assurance Certification for Secured Software Programming or equivalent.
http://asp.net/
1.7.15 Source code testing, binary code testing, application scanning, and penetration testing: At least one week prior to delivery of any code due under this contract, Contractor will deliver to the COTR the following reports covering all code that will be delivered:
A. Source code testing results showing all potential security flaws identified by at least one of the commercial source code testing tools approved by the Office of the Chief Information Officer of USDA. On the report, the contractor will highlight all vulnerabilities rated "critical" and "high". The contractor must then correct the vulnerabilities, resend the code and ensure delivered source code health.
B. For web-applications, web application scanning test results showing ail potential security flaws identified by at least one of the commercial web application scanning tools approved by the Office of the Chief Information Officer of USDA. On the report, the contractor will highlight all vulnerabilities rated "critical" and "high".
C. For all applications: application penetration results.
1.7.16 Copyright Management and Responsibility: By delivering applications or programming code to the Federal Government, the vendor or Contractor certifies that they have the proper authority to transfer the property and will defend the government against copyright or other lawsuit resulting from the application or programming delivered.
1.7.17 Ownership/Copyright: Any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.7.18 Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer.
All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.7.19 IT Hardware/Software: The Contractor and other external organizations will ensure that the appropriate security banners are displayed on all FS systems (both public and private) operated by the contractors and other external organizations prior to allowing anyone access to the system.
The Contractors and other external organizations will submit proof to the Contracting Officer that hardware and/or software products acquired as a part of any contract/agreement are appropriate to their risk environment, and will confirm the proof of information assurance showing a cost-effective selection of security measures with appropriate security specifications and requirements.
1.7.20 Section 508 Compliance for IT Services, Hardware, Software, and Equipment: All electronic and information technology (EIT) procured through this Statement of Work/Bill of Materials and any resulting contract, task order, delivery order, or purchase order must meet the applicable accessibility standards at 36CFR 1194, unless an agency exception to this requirement exists. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at http://www.section508.gov/. The contractor shall indicate for each line item in the schedule whether each product or service is compliant or noncompliant with the accessibility standards at 36 CFR 1194. Further, the proposal must indicate where full details or compliance can be found (e.g., vendor’s website or other exact location). The Technical Exhibit 5 with GPAT Checklist that shall be completed and submitted by the contractor with the POSS Proposal.
PART 2
DEFINITIONS & ACRONYMS
PWS – Performance Work Statement
Contracting Officer’s Representative (COR): A representative from the requiring activity assigned by the Contracting Officer to perform surveillance and to act as liaison to the contractor
Defective Service. A service output that does not meet the standard of performance associated with it in the Performance Work Statement.
Quality Assurance Surveillance Plan (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
Quality Control. Those actions taken by a contractor to control the performance of services so that they meet the requirements of the PWS.
Quality Assurance. Those actions taken by the government to assure services meet the requirements of the Performance Work Statement.
ACRONYMS:
AGAR Agriculture Acquisition Regulation COR Contracting Officer Representative COTR Contracting Officer's Technical Representative
COTS Commercial Off-the-Shelf FAR Federal Acquisition Regulation FS Forest Service FSAR Forest Service Acquisition Regulation FFP Firm Fixed Price KO Contracting Officer OCI Organizational Conflict of Interest CONUS Continental United States (includes Alaska and Hawaii) ODC Other Direct Costs PIPO Phase In/Phase Out POC Point of Contact PRS Performance Requirements Summary SDS Service Delivery Summary PM Program Manager PRS Performance Requirement Summary PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Program TE Technical Exhibit USDA United States Department of Agriculture
PART 3
GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND
SERVICES
3.0 GENERAL: The government shall provide, the facilities, equipment, materials, and/or services listed below.
3.1 Equipment: The Government will provide the contractor two laptop computers operating a USDA-approved operating system. The laptops are necessary for network access for system maintenance.
3.2 Government-furnished information (GFI): The Government will provide information on the users, sites and relevant RAVIN system information as deemed necessary such as technical designs, architectural diagrams, requirements, project plans, training manuals, release notices, test scenarios and results (test readiness review package) and change requests. All documentation that we provide that is considered confidential, we ask that the contractor complete a confidentiality form.
PART 4
APPLICABLE PUBLICATIONS
5.0 Publications applicable to this PWS are listed below:
• Public Law 107-347, Federal Information Security Management Act of 2002, (FISMA) – http://csrc.nist.gov/drivers/documents/FISMA-final.pdf
• Public Law 99-474, Computer Fraud and Abuse Act of 1986, (18
USC 1030) –
http://energy.gov/sites/prod/files/cioprod/documents/ComputerFr aud-AbuseAct.pdf
• Public Law 93-574, Privacy Act of 1974, (5 USC 552a) – http://www.foia.cia.gov/txt/pa.pdf
• Public Law No: 107-347, E-Government Act of 2002 (H.R. 2458/S. 803) – http://www.gpo.gov/fdsys/pkg/PLAW- 107publ347/pdf/PLAW-107publ347.pdf
• FIPS PUB 199, Security Categorization of Federal Information and Information Systems – http://csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf
• OMB Circular A-123 (revised), Management Accountability and Control – http://www.whitehouse.gov/sites/default/files/omb/assets/omb/circ ulars/a123/a123_rev.pdf
• OMB Circular A-130 (revised), Information Resources Management, Appendix III, Security of Federal Automated Information Resources – http://www.whitehouse.gov/sites/default/files/omb/assets/omb/circ ulars/a130/a130trans4.pdf
• Public Law 93-502, Freedom of Information Act – http://www.justice.gov/oip/1974attachb.htm
• NIST SP 800-18, Rev. 1 Guide for Developing Security Plans for Information Technology Systems – http://csrc.nist.gov/publications/nistpubs/800-18-Rev1/sp800-18- Rev1-final.pdf
• NIST SP 800-30, Risk Assessment Guide for Information Technology Systems – http://csrc.nist.gov/publications/nistpubs/800-30/sp800-30.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fdrivers%2fdocuments%2fFISMA-final.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fenergy.gov%2fsites%2fprod%2ffiles%2fcioprod%2fdocuments%2fComputerFraud-AbuseAct.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fenergy.gov%2fsites%2fprod%2ffiles%2fcioprod%2fdocuments%2fComputerFraud-AbuseAct.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.foia.cia.gov%2ftxt%2fpa.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.gpo.gov%2ffdsys%2fpkg%2fPLAW-107publ347%2fpdf%2fPLAW-107publ347.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.gpo.gov%2ffdsys%2fpkg%2fPLAW-107publ347%2fpdf%2fPLAW-107publ347.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2ffips%2ffips199%2fFIPS-PUB-199-final.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2ffips%2ffips199%2fFIPS-PUB-199-final.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.whitehouse.gov%2fsites%2fdefault%2ffiles%2fomb%2fassets%2fomb%2fcirculars%2fa123%2fa123_rev.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.whitehouse.gov%2fsites%2fdefault%2ffiles%2fomb%2fassets%2fomb%2fcirculars%2fa123%2fa123_rev.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.whitehouse.gov%2fsites%2fdefault%2ffiles%2fomb%2fassets%2fomb%2fcirculars%2fa130%2fa130trans4.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.whitehouse.gov%2fsites%2fdefault%2ffiles%2fomb%2fassets%2fomb%2fcirculars%2fa130%2fa130trans4.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.justice.gov%2foip%2f1974attachb.htm https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-18-Rev1%2fsp800-18-Rev1-final.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-18-Rev1%2fsp800-18-Rev1-final.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-30%2fsp800-30.pdf
• NIST SP 800-60, Guide for Mapping Types of Information and Information Systems to Security Categories, Rev. 1 – http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800- 60_Vol1-Rev1.pdf
• NIST SP 800-53, Recommended Security Controls for Federal Information Systems and Organizations, Rev. 3 – http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf
• Check Clearing for the 21st Century Act of 2003 – http://www.gpo.gov/fdsys/pkg/PLAW-108publ100/pdf/PLAW- 108publ100.pdf
• USDA Certification and Accreditation Guide – http://www.ocio.usda.gov/directives/doc/DM3555-000.pdf
• USDA DM 3140-001, Management ADP Security Manual – http://www.ocio.usda.gov/directives/doc/DM3140-001.pdf
• USDA DR 3140-002, USDA Internet Security Policy – http://www.ocio.usda.gov/directives/doc/DR3140-002.pdf
• USDA DR 3300-001, Telecommunications and Internet Services and Use Memorandum Telecommunications and Internet Services and Use Memorandum – http://www.ocio.usda.gov/directives/doc/DR3300-001.pdf
• USDA DR 3440-002, Control and Protection of Sensitive Security Information – http://www.ocio.usda.gov/directives/doc/DR3440- 002.pdf
• USDA DR 3500-000, USDA Computer Incident Response Procedure – http://www.ocio.usda.gov/directives/doc/DM3505- 000.pdf
• USDA DM 3515-002, Privacy Impact Assessment – http://www.ocio.usda.gov/directives/doc/DM3515-002.pdf
• USDA DM 3520-001, CM Policy & Responsibilities, Chapter 4, Part 1 – http://www.ocio.usda.gov/directives/doc/DM3520-001.pdf
• USDA DM 3530-001 USDA Vulnerability Scan Procedures – http://www.ocio.usda.gov/directives/doc/DM3530-001.pdf
• USDA DM 3530-004, Firewall Technical Security Standards – http://www.ocio.usda.gov/directives/doc/DM3530-004.pdf
• USDA DM 3530-005, Encryption Security Standards – http://www.ocio.usda.gov/directives/doc/DM3530-005.pdf
• USDA DR 3535-001, USDA’s C2 Level of Trust – http://www.ocio.usda.gov/directives/doc/DM3535-001.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-60-rev1%2fSP800-60_Vol1-Rev1.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-60-rev1%2fSP800-60_Vol1-Rev1.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-53-Rev3%2fsp800-53-rev3-final_updated-errata_05-01-2010.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fcsrc.nist.gov%2fpublications%2fnistpubs%2f800-53-Rev3%2fsp800-53-rev3-final_updated-errata_05-01-2010.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.gpo.gov%2ffdsys%2fpkg%2fPLAW-108publ100%2fpdf%2fPLAW-108publ100.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.gpo.gov%2ffdsys%2fpkg%2fPLAW-108publ100%2fpdf%2fPLAW-108publ100.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3555-000.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3140-001.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDR3140-002.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDR3300-001.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDR3440-002.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDR3440-002.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3505-000.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3505-000.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3515-002.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3520-001.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3530-001.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3530-004.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3530-005.pdf https://mail.usda.gov/owa/redir.aspx?C=d88GCd6Z_0qrwFStmCcvaTzb9eXnSc8IqrhO9vhJmK5lQdgN_OJnQIqGNIEhrKalCK-Bumd2odg.&URL=http%3a%2f%2fwww.ocio.usda.gov%2fdirectives%2fdoc%2fDM3535-001.pdf
• USDA DM 3540-001, Risk Assessment Methodology – http://www.ocio.usda.gov/directives/doc/DM3540-001.pdf
• USDA FSM 6680.1, Security of Information, IS, and IT:
Authority – https://fs.usda.gov/FSI_Directives/wo_6680-6682.doc
• USDA FSM…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .