Attachment 1 Performance Work Statement.docx
DOCX document 183 KB Posted
- Attached to
- RD Application Sustainment Operations & Maintenance Support Federal contract opportunity
- Solicitation number
- 12SAD125R0002
About this file
This Performance Work Statement (PWS) details a contract for the United States Department of Agriculture (USDA) Rural Development Technology Office to obtain information technology support services across four primary focus areas. The solicitation is a 100% 8(a) small business set-aside for an Indefinite Delivery Indefinite Quantity (IDIQ) contract with a three-year ordering period and a potential six-month extension, targeting IT services for Rural Development's loan and grant program systems.
The four focus areas include: 1) Production Support Operations (PSO), providing infrastructure and platform management; 2) Sustainment Engineering (SE) for Salesforce Applications, maintaining application lifecycle and DevOps processes; 3) Sustainment Engineering for Legacy Applications, supporting mainframe and hosted systems; and 4) Development, Modernization, and Enhancements (DME), delivering new capabilities and system improvements. The contract will utilize Agile methodologies, with an emphasis on continuous integration, DevSecOps principles, and maintaining robust cybersecurity standards. Key requirements include supporting various technology platforms, maintaining application integrations, conducting system testing, managing documentation, and ensuring Section 508 accessibility compliance across all deliverables.
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement (PWS) RD Application Sustainment and Production Support Operations As of 3/21/2025
I. DEFINITIONS/ACRONYMS
· A&A: Assessment & Authorization
· ACIO: RD Assistant Chief Information Officer
· Agile Development Increment: depends on the methodology required by the Task Order. RD uses Scaled Agile Framework (SAFe), SCRUM, and Kanban agile methodologies.
· AMAS: Automated Multifamily Accounting System
· API: Application Programming Interface
· ART: Agile Release Train
· BPFD: Business Process Flow Diagram
· CEC: Client Experience Center
· CI/CD: Continuous Integration/Continuous Delivery
· CICS: Customer Information Control System
· CISO: RD Chief Information Security Officer
· CLIN: Contract Line Item
· CO: Contracting Officer, a person with authority to enter, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. A CO is only individual who can legally bind the government.
· COR: Contracting Officer's Representative, a representative from the requiring activity appointed in writing by the CO to perform surveillance and to act as liaison to the contractor. This individual has authority to provide technical direction to the Contractor if that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.
· COTS: Commercial off the shelf, for the purpose of the performance work statement, COTS refer to commercially developed software.
· CPU: Central Processing Unit
· DB: Database
· DD: Data Dictionary
· DFD: Data Flow Diagram
· DEPLOYMENT: Software and administrative changes made in the Production environment
· DISC: Digital Infrastructure Services Center (formerly National Information Technology Center (NITC))
· DME: Development, Modernization, and Enhancement
· DR: Disaster Recovery
· ERD: Entity Relationship Diagram
· FA: Focus Area
· FEATURE: A service that fulfills a stakeholder need. Each feature includes a benefit hypothesis and acceptance criteria and is sized or split as necessary to be delivered by a single Agile Release Train (ART) in a Program Increment (PI).
· FISMA: Federal Information Security Management Act of 2002 (FISMA)
· FPAC: Farm Production and Conservation
· GFE: Government Furnished Equipment
· HYPERCARE: The period immediately following a system Release where an elevated level of support is available to ensure the seamless adoption of a new system.
· IPP: Invoice Processing Platform
· ITERATION: Each iteration is a standard, fixed length timebox, where Agile Teams deliver incremental value in the form of working, tested software and systems.
· ITIL: IT infrastructure library
· LDM: Logical Data Model
· O&M: Operations and Maintenance
· OCI: Organizational Conflict of Interest
· OCIO: Office of the Chief Information Officer – An Office within the Office of Administration and Management at RD. OCIO is responsible for providing state-of-the-art, reliable, and quality products, and services whenever and wherever needed with customer collaboration and teamwork. OCIO ensures that the products and services provided emanate from RD’ strategic goals and values. Additionally, OCIO provides proper resource alignment for the delivery of reliable and sustainable information services. Finally, OCIO ensures infrastructure services are readily accessible to all RD customers.
· OMB: Office of Management and Budget
· OWAS: Open Web Application Security
· PDR: Preliminary Design Review
· PII: Personally identifiable information
· PIV: Personal Identity Verification Card, all employees and contractors working for USDA must be issued a PIV card, known as LincPass.
· PMO: Procurement Management Office
· PO: Product Owner
· PSO: Production Support Operations
· PWS: Performance Work Statement
· QA: Quality Assurance
· QASP: Quality Assurance Surveillance Plan - An organized written document specifying the surveillance methodology to be used for surveillance of Contractor performance to assure services meets the requirements of the PWS.
· RD: Rural Development
· RDTO: Rural Development Technology Office
· SDLC: System Development Lifecycle, RDTO guide for successful planning, execution, and control of IT projects by providing a framework to ensure that all aspects of a project are properly and consistently defined, planned, and communicated.
· SAFe: Scaled Agile Framework
· SE: Sustainment Engineering Team
· SLA: Service Level Agreement, a provision within a contract between a service provider (Contractor) and the end user that defines the level of service expected from the service provider. SLAs may include provisions related to requirements for the reliability of services (limits on outages or down time), responsiveness (service availability percentages of time, procedures for reporting problems (who will be contacted, how to report, when and how to escalate), monitoring a reporting service levels (who will monitor, what data will be collected, how often).
· Shall: denotes a mandatory duty or obligation
· UAM: User Access Management tool - is an in-house developed tool.
· UAT: User Acceptance Testing
· USDA: United States Department of Agriculture
II. GENERAL REQUIREMENTS
Introduction The United States Department of Agriculture (USDA) Rural Development (RD) Business Center has a need for contractor technology support in three focus areas:
· Focus Area 1: Production Support Operations (PSO) (O&M) – support PSO by implementing, enforcing, and maintaining separation of duties between IT development and operational support efforts and keep RD applications running smoothly by providing infrastructure/platform support, monitoring/dashboard, analysis, incident management, change management, release management, and continual service improvements.
· Focus Area 2: Sustainment Engineering Team (SE) Salesforce Applications (O&M) - sustaining lifecycle support of deployed/production applications/systems, covering everything from new feature requests, bug fixes, product improvements, vulnerability mitigation, application testing, integration services, application and security documentation management, and continual process improvements. Provide consistency in the way the product source code is developed, tested, and managed. Implementing best practices to streamline a DevOps model for lowering cost/price of operations and maintenance (O&M) across the RD system portfolio.
· Focus Area 3: Sustainment Engineering Team (SE) Legacy Applications (O&M) - sustaining lifecycle support of deployed/production applications/systems, covering everything from new feature requests, bug fixes, product improvements, vulnerability mitigation, application testing, integration services, application and security documentation management, and continual process improvements. Provide consistency in the way the product source code is developed, tested, and managed. Implementing best practices to streamline a DevOps model for lowering cost/price of operations and maintenance (O&M) across the RD system portfolio.
· Focus Area 4: System Development, Modernization, and Enhancement (DME) - legacy system enhancement or modernization planning, using an Agile approach to address complex IT objectives incrementally to increase the likelihood of achieving workable solutions for attainment of those objectives.
Background The USDA RD Technology Office under the guidance of the Assistant Chief Information Officer (ACIO) is responsible for developing, maintaining, and operating a portfolio of IT systems in support of RD's core programs. These programs provide financial assistance in the form of guaranteed and direct loans and grants.
The systems inventory includes grant and loan intake, origination, servicing, and reporting applications and non-financial applications that support RD business and operational needs. Users of the RD systems include employees, private sector lending institutions, management agents, other mission areas or agencies and their finance offices, customers, potential customers, and the public. Each of these constituents has both common and unique information and support needs. Each of the agency program management constituents use both direct and guaranteed loans in the execution of their program activities. The financial systems have components which interface, exchange data, and use certain common processes. Our external constituents including lending institutions, management agents, customers, and potential customers have different informational and servicing needs than our internal constituents.
With mandated initiatives, our existing legacy components must be fully managed and/or enhanced to allow all constituents the necessary access to information and the functionality to implement our programs more efficiently. Once implemented these initiatives will:
· Improve the availability, accuracy, and timeliness of management information.
· Provide the servicing office with the capability to maintain and manage their guaranteed and direct loan portfolios.
· Improve our grant and loan programs to be more attractive to our lending institutions and potential customers.
· Facilitate continuous process improvements within the business and the automation development organizations.
· Enable agency management to proactively monitor and manage individual loans, program portfolios, and funding authorities. Provide agency management timely access to information required by Congress, Office of Management and Budget (OMB), Department of the Treasury, General Accounting Office, Office of Inspector General, and USDA.
The Production Support Operations (PSO) Branch is within the Systems Engineering Division of RDTO’s Business Center Operations Office. The PSO team’s purpose is to establish the separation of duties between IT development and operation efforts and keep RD applications running smoothly by providing production support and monitoring services. The PSO’s responsibilities include infrastructure and platform management, change and release management, vulnerability management, tool-chain management, strategic advisory and counseling, documentation, and process engineering; continuous service improvement; database management and IT Contingency/Disaster Recovery operations.
The Sustainment Engineering Team (SE) serves in the PSO Branch and works with RDTO leadership to implement operations and maintenance (O&M) industry best practices, processes, procedures, actions, definitions, and workflows to successfully realize long-term application sustainment. One of the goals for SE is to implement an application sustainment capacity-based DevOps model for lowering cost/price of O&M across the legacy RD system portfolio. SE supports the production systems portfolio and addresses all functional defects, including security application vulnerabilities and 508 issues, and resolves them prior to code being promoted to a higher environment. Production system enhancement or modernization planning to address complex IT objectives incrementally to increase the likelihood of achieving workable solutions for attainment of those objectives, using a SAFe Agile approach.
The Government Product Owner will specify high-level requirements/capabilities to the Agile team. As in typical Scrum-based Agile processes, the USDA Product Owner will work together with the team to develop and estimate user stories and establish acceptance criteria. These acceptance criteria will specify expected functionality for a user story, as well as any non-functional requirements that must be met in the development of the story. The USDA Product Owner, supported by subject matter experts and business analysts, will determine whether acceptance criteria have been satisfied.
New capabilities or strategic training may be needed to design, enhance, configure, tailor, test, implement, train, and document new capabilities that will be required to deliver new enhancement and/or training on behalf of the USDA RD. Consistent with Agile- and Sprint-based development, any new capabilities, features, or requirements are subject to change based on Sprint planning during the period of the contract. Legacy system enhancement or modernization planning of system solutions may include software development or COTS integration and tailoring, test and evaluation, information assurance, operational test support, and system training. Efforts may support the SE team processes for system approval and acceptance.
Software sustainment is a priority for RDTO in that operations and sustainment costs can easily reach 60% to 80% of a system’s total lifecycle costs. The Contractor shall leverage Agile methods, which may combine practices from traditional and Agile methods to create a software sustainment method that works well within RDTO’s environment.
2.1 Statutory authority, regulations, or policy affecting the overall requirement as applicable include but are not limited to:
· Clinger-Cohen Act (also known as the “Information Technology Management Reform Act of 1996”) (40 U.S.C. § 11101-11704).
· E-Government Act of 2002 (44 U.S.C. Chapters 35 and 36).
· Federal Information Security Modernization Act of 2014 (44 U.S.C. Chapter 35, Subchapter II).
· Federal Information Technology Acquisition Reform Act (FITARA) (Pub. L. 113-291).
· Paperwork Reduction Act (PRA) of 1980, as amended by the Paperwork Reduction Act of 1995 (44 U.S.C. Chapter 35).
· Privacy Act of 1974, as amended (5 U.S.C. § 552a).
· Digital Accountability and Transparency Act of 2014 (Pub. L. 113-101).
· Electronic Signatures in Global and National Commerce Act (E-Sign) (15 U.S.C. Chapter 96).
· Government Paperwork Elimination Act of 1998 (44 U.S.C. § 3504).
· Government Performance and Results Act (GPRA) of 1993, as amended by the Government Performance and Results Modernization Act (GPRA Modernization Act) of 2010 (5 U.S.C. § 306 and 31 U.S.C. §§ 1115 et seq.).
· Office of Federal Procurement Policy Act (41 U.S.C. Chapter 7).
· Budget and Accounting Procedures Act of 1950, as amended (31 U.S.C. Chapter 11).
· Chief Financial Officers Act (31 U.S.C. § 3512 et seq.)
· USDA RD Resources, Directives, and Regulations: https://www.rd.usda.gov/resources
· USDA Departmental Regulations, Notices, Manuals, and Secretary Memoranda: https://www.ocio.usda.gov/policy-directives-records-forms/directives-categories
· USDA Digital Strategy: https://www.usda.gov/digital-strategy
· CIO.gov Policies and Priorities: https://www.cio.gov/policies-and-priorities/
Type of Contract USDA Rural Development intends to establish a single Indefinite Delivery Indefinite Quantity (IDIQ) to issue Firm-Fixed Price (FFP) Task Orders for services as defined in the PWS Scope and identified by CLINS.
Non-personal and Not Inherently Governmental Services All services requested under this acquisition and PWS are non-personal and not inherently governmental in nature.
Place(s) of Performance The Contactor shall perform the requirements of this contract at the authorized Government work locations unless otherwise specifically stated in this PWS. The current work locations are:
1. USDA Rural Development 1400 Independence Ave SW Washington DC, 20250
2. USDA Rural Development 211North Broadway St. Louis, MO 63120
3. Customer Site Location
The above listed locations are locations in which all tasks may be performed. Tasks can be completed at any location and as stated in the PWS. They may be completed remotely at Contractor proposed location(s).
USDA expects to have a mixed (virtual/in person) workforce but largely does not expect the bulk of the contractors onsite at government locations unless requested to attend in-person meeting, which would be infrequent. The Government has limited space available to house Contractor’s workforce, for this acquisition efforts, in its new District of Columbia or St. Louis locations.
Changes in Authorized Work Locations Work locations are subject to change when it is advantageous to the Government to eliminate or add a work location or change work locations to remote. Should a change occur, the contractor will be notified in writing by the CO. Should the Contractor decide to relocate existing employees due to a change, employee relocation will be done at no cost to the government.
The Contractor may propose contractor work locations in addition to those identified in Places of Performance when it is advantageous to the government. This includes contractor employee telework locations during specified periods when the government facilities are closed due to weather and other emergency situations and/or when government facilities are unavailable due to other events making a government facility uninhabitable. The alternate work locations will be coordinated with the COR in advance and shall be at no additional cost to the government.
The Contractor shall ensure all Government Furnished Equipment (GFE) assigned to individual employees are safely and securely operated and maintained regardless of the location where the work is performed.
Note: USDA expects to have a mixed workforce, but largely does not expect any contractors to perform work onsite at government locations unless requested to attend in-person meeting, which would be infrequent. The government has limited space available to house Vendor’s workforce, for this acquisition efforts, in its new DC or MO locations.
Days and Hours of Performance The Contractor is required to be available on non-government holidays from 6:00 am EST until 6:00 pm EST, Monday through Friday to correspond with USDA RD’s point of contacts, such as the Contracting Office, Contracting Officer’s Representative, and the Program/Technical Office. The Contractor is required to provide emergency phone numbers, along with regular contact phone numbers and email addresses. FA1 PSO provides a 24/7 “on-call” production infrastructure/application support on a rotating basis.
Federal Holiday Schedule
New Year’s Day
Martin Luther King, Jr. Birthday
Washington’s Birthday
Memorial Day
Juneteenth National Independence Day
Independence Day
Labor Day
Columbus Day
Veterans Day
Thanksgiving Day
Christmas Day
Performance Period or Delivery Date The period of period for the IDIQ is a three-year ordering period.
12/9/2025 through 12/8/2028
A Task Order must be awarded before the POP (Period of Performance) on the IDIQ ends. A Task Order could be issued for a year. Therefore, it is possible that a Task Order could have a POP date that is 364 days past the end date of the IDIQ POP.
Kickoff Meeting Upon award of the initial IDIQ, and subsequent IDIQ Task Orders, at a mutually agreeable time, Offeror shall initiate work on this contract by meeting with key government agency representatives to ensure a common understanding of the requirements, expectations, and ultimate end products. Offeror shall discuss the overall understanding of the initial and overall projects and review the background information and materials provided by the government. Discussions will also include the scope of work, deliverables to be produced, how the efforts will be organized, and project conducted, assumptions made/expected and results. A concerted effort shall be made to gain a thorough understanding of the government agency expectations. However, nothing discussed in this or in any subsequent meeting(s) or discussions between the government and Offeror shall be construed as adding, deleting, or modifying any IDIQ Task Order requirements, including deliverable specifications and due dates. Any additions, deletions or modifications to any IDIQ Task Order requirement must be approved by the CO. Similar “kickoff” meetings shall be accomplished with each subsequent order placed.
Travel Travel will not be authorized under this acquisition.
Government-furnished Property, Equipment, and/or services The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to provide transition support as defined in this Performance Work Statement (PWS) except for those items specified below as government furnished property and services:
· Laptops – Receipt of government issued laptops are contingent upon Contractor employees passing Suitability Requirements.
· Mobile Phone for on call purposes (where applicable). Receipt of government issued laptops are contingent upon Contractor employees passing Suitability Requirements.
· PIV Card – A USDA Personal Identity Verification (PIV) card, which contains the necessary data for the cardholder to be granted to Federal facilities and information systems and assure appropriate levels of security for all applicable Federal applications will need to be obtained by Contractor employees. The COR will work with Contractor to obtain PIV cards for Contractor’s employees.
· Workspace and utilities shall be provided at USDA’s if applicable.
a) USDA Rural Development 1400 Independence Ave Washington, D.C. 20250
b) USDA Rural Development 211 North Broadway St. Louis, MO 63120
c) Other government offices as required
Identification of Contractor Employees All contractor personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. When performing work outlined in this PWS while in USDA facilities or RDs sites, Contractor employees are required to wear a federal government-issued personal identification card.
Non-Disclosure and Confidentiality The work to be performed under this acquisition and the data released to the Contractor’s personnel shall be treated as sensitive and confidential in nature and is not to be discussed with or released to anyone except USDA employees assigned to work with the contractor and other contractor personnel working on this acquisition. The Contractor is responsible for requiring all its employees working under this acquisition, who have access to privileged information, to sign the USDA Non-Disclosure Agreement, provided as an attachment to the solicitation and contract. USDA, as it deems appropriate, may require additional certifications be completed by the contractor at any time during acquisition performance.
The Contractor is required to develop and utilize procedures for custody, use/handling, reproduction, preservation, storage, safeguarding, and disposition of all documents and information of this nature so that there is no unauthorized disclosure of such documents and information throughout the course of performance. The Contractor shall be responsible for the security of all project documents provided to them for work under this acquisition. It is essential that this information be properly handled, stored, and protected from the risk and magnitude of loss or harm that could result from inadvertent or deliberate disclosure, alteration, or destruction. The Contractor shall protect and not disclose any PII.
Contractor-generated preliminary and final deliverables, all associated working papers, and other material RD deems relevant in the performance of this acquisition are the property of the U.S. Government and must be submitted to the CO by the conclusion of this acquisition and shall not be reproduced or retained by the Contractor. The Contractor shall not release any information without the written consent of the CO.
When no longer required, this information, data, or equipment shall be returned to Government control; destroyed; or held until otherwise directed by the CO. Items returned to the Government shall be hand carried or emailed to the CO or other designee. The Contractor shall destroy unneeded items by burning, shredding or any other method that precludes the reconstruction of the material.
The Contractor shall immediately notify the appropriate CO upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records, or equipment.
This non-disclosure agreement does not bar disclosures to Congress or to an authorized official of an executive agency or the Department of Justice that are essential to reporting a substantial violation of law and this Agreement does not prohibit disclosures which are required under order of a court of competent jurisdiction. These provisions are consistent with and do not supersede, conflict with, or otherwise alter the obligations, rights, or liabilities created by existing statutes or Executive orders relating to (1) classified information, (2) communications to Congress, (3) the reporting to an Inspector General of a violation of any law, rule, or regulation, or mismanagement, a gross waste of funds, an abuse of authority, or a substantial and specific danger to public health or safety, or (4) any other whistleblower protection. The definitions, requirements, obligations, rights, sanctions, and liabilities created by controlling Executive orders and statutory provisions are incorporated into this agreement and are controlling. These controlling Executive orders and statutory provisions include Executive Order No. 12958, as amended; Section 7211 of Title 5, United States Code (governing disclosures to Congress); Section 2302(b)(8) of Title 5, United States Code, as amended by the Whistleblower Protection Act (governing disclosures of illegality, waste, fraud, abuse or public health or safety threats); the Intelligence Identities Protection Act of 1982 (50 USC 3121 et seq.) (governing disclosures that could expose confidential government agents); and the statutes which protect against disclosure that may compromise the national security, including Sections 641, 793, 794, 798, and 952 of Title 18, United States Code, and Section 4(b) of the Subversive Activities Act of 1950 (50 USC 783(b)).
Training. All Contractor employees assigned to this acquisition who create, work with, or otherwise handle records are required to take USDA-provided records management training. The Contractor is responsible for confirming training has been completed according to agency policies, including initial training and any annual or refresher training. To the extent an agency requires contractors to complete records management training, the agency will provide the training to the contractor.
Proprietary Information In the event that performance of any work under this acquisition causes the Contractor to gain access to proprietary or confidential information of other firms/contractors, the Contractor is required to immediately execute Technology Exchange Agreements/Non-Disclosure Agreements with those firms/contractors, in order to protect the information from unauthorized use. The Contractor is required to refrain from using any such information for any purposes other than for which it was furnished. The Contractor must immediately provide the CO with a copy of any such agreements with original signatures affixed.
Homeland Security Presidential Directive HSPD-12 Credentials Contractor personnel must complete necessary requirements to obtain HSPD‐12 credentials immediately upon beginning work on the contract. Failure to obtain HSPD‐12 credentials is grounds for removal/suspension of contractor personnel from the contract.
https://www.dhs.gov/homeland-security-presidential-directive-12
Personal Identity Verification of Contractor Employees
a. The Contractor must comply with the personal identity verification (PIV) policies and procedures established by the United States Department of Agriculture (USDA) Directive 4620-002.
b. Should the USDA Directive 4620-002 require the exclusion of a contractor's employee, the CO will notify the contractor in writing.
c. The Contractor must appoint a representative to manage compliance with the PIV policies established by the USDA Directive 4620-002 and to maintain a list of employees eligible for a USDA LincPass required for performance of the work.
d. The responsibility of maintaining a sufficient workforce remains with the Contractor. Contractor employees may be barred by the Government from performance of work should they be found ineligible or to have lost eligibility for a USDA LincPass. Failure to maintain a sufficient workforce of employees eligible for a USDA LincPass may be grounds for termination of the contract.
e. The Contractor must insert this language in all subcontracts when the subcontractor is required to have routine unaccompanied physical access to a Federally controlled facility and/or routine unaccompanied access to a Federally controlled information system.
f. The PIV Sponsor for this contract is a designated program point of contact, which in most cases is the COR, unless otherwise specified in this contract. The PIV Sponsor will be available to receive Contractor identity information from * (hours and days) to * (hours and days) at * (office address for registration). The Government will notify the Contractor if there is a change in the PIV Sponsor, the office address, or the office hours for registration; however, it is the Contractor's responsibility to meet all aspects of paragraphs (c), (d), and (e).
Contractor Personnel Security Requirements
· Information Technology Systems Requirements:
The Contractor shall establish and implement appropriate administrative, technical, and physical safeguards to ensure the security and confidentiality of sensitive Government information, data, and/or equipment.
The Contractor shall comply with IT systems security and/or privacy specifications set forth in Rural Development and USDA directives, policy, and procedures; the Computer Security Act of 1987; OMB Circular A-130; and the Federal Information Security Management Act of 2002 (FISMA).
The Contractor shall be responsible for assuring that each Contractor employee who requires routine unaccompanied physical access to a Federally controlled facility and/or unaccompanied access to a Federally controlled information system, including a Rural Development- issued computer, completes Computer Security Awareness training prior to performing any work under this contract.
The Contractor is required to maintain a listing of all individuals who have completed Computer Security Awareness training and submit this listing to the COR with a copy to the Contracting Officer within ten calendar days of an individual starting work on this contract.
Access Requirements - Contractor Access to USDA’s Network/Systems The Contractor shall require access to the USDA’s Network/Systems to perform work under the contract. The COR will oversee such access.
Information Assurance The Contractor shall protect and not disclose any PII. The term “PII,” as defined in OMB Memorandum M-07-1616 refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important for an agency to recognize that non-PII can become PII whenever additional information is made publicly available - in any medium and from any source that, when combined with other available information, could be used to identify an individual.
Records Management Obligations
a. The Contractor shall comply with all applicable records management laws and regulations, as well as National Archives and Records Administration (NARA) records policies, including but not limited to the Federal Records Act (44 U.S.C. chs. 21, 29, 31, 33), NARA regulations at 36 CFR Chapter XII Subchapter B, and those policies associated with the safeguarding of records covered by the Privacy Act of 1974 (5 U.S.C. 552a). These policies include the preservation of all records, regardless of form or characteristics, mode of transmission, or state of completion.
b. In accordance with 36 CFR 1222.32, all data created for Government use and delivered to, or falling under the legal control of, the Government are Federal records subject to the provisions of 44 U.S.C. chapters 21, 29, 31, and 33, the Freedom of Information Act (FOIA) (5 U.S.C. 552), as amended, and the Privacy Act of 1974 (5 U.S.C. 552a), as amended and must be managed and scheduled for disposition only as permitted by statute or regulation.
c. In accordance with 36 CFR 1222.32, Contractor shall maintain all records created for Government use or created in the course of performing the contract and/or delivered to, or under the legal control of the Government and must be managed in accordance with Federal law. Electronic records and associated metadata must be accompanied by sufficient technical documentation to permit understanding and use of the records and data.
d. RD and its Contractors are responsible for preventing the alienation or unauthorized destruction of records, including all forms of mutilation. Records may not be removed from the legal custody of RD or destroyed except for in accordance with the provisions of the agency records schedules and with the written concurrence of the Head of the Contracting Activity. Willful and unlawful destruction, damage or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. In the event of any unlawful or accidental removal, defacing, alteration, or destruction of records, Contractor must report to RD. The Government must report promptly to NARA in accordance with 36 CFR 1230.
e. The Contractor shall immediately notify the appropriate CO upon discovery of any inadvertent or unauthorized disclosures of information, data, documentary materials, records or equipment. Disclosure of non-public information is limited to authorized personnel with a need-to-know as described in the RFQ and resulting contract. The Contractor shall ensure that the appropriate personnel, administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, documentary material, records and/or equipment is properly protected. The Contractor shall not remove material from Government facilities or systems, or facilities or systems operated or maintained on the Government’s behalf, without the express written permission of the Head of the Contracting Activity. When information, data, documentary material, records and/or equipment is no longer required, it shall be returned to RD control, or the Contractor must hold it until otherwise directed. Items returned to the Government shall be hand carried, mailed, emailed, or securely electronically transmitted to the CO or address prescribed in the RFQ and resulting contract. Destruction of records is EXPRESSLY PROHIBITED unless in accordance with Paragraph (4).
f. The Contractor is required to obtain the CO’s approval prior to engaging in any contractual relationship (sub-contractor) in support of this contract requiring the disclosure of information, documentary material and/or records generated under, or relating to, contracts. The Contractor (and any sub-contractor) is required to abide by Government and RD guidance for protecting sensitive, proprietary information, classified, and controlled unclassified information.
g. The Contractor shall only use Government IT equipment for purposes specifically tied to or authorized by the contract and in accordance with RD policy.
h. The Contractor shall not create or maintain any records containing any non-public RD information that are not specifically tied to or authorized by the contract.
i. The Contractor shall not retain, use, sell, or disseminate copies of any deliverable that contains information covered by the Privacy Act of 1974 or that which is generally protected from public disclosure by an exemption to the Freedom of Information Act.
j. RD owns the rights to all data and records produced as part of this contract. All deliverables under the contract are the property of the U.S. Government for which RD shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. Any Contractor rights in the data or deliverables must be identified as required by FAR 52.227-11 through FAR 52.227-20.
k. Training. All Contractor employees assigned to this contract who create, work with, or otherwise handle records are required to take RD-provided records management training. The Contractor is responsible for confirming training has been completed according to Government policies, including initial training and any annual or refresher training.
Onboarding Process The Contractor shall manage the onboarding of its staff for all Contractor personnel who have not yet been onboarded at USDA. Onboarding includes steps to obtain a USDA network and email account, complete training, initiate background investigations, and gain physical and logical access, which may include elevated privileges to the necessary development and test environments for the various systems to be enhanced.
A single Contractor Onboarding point of contact (POC) shall be designated by the Contractor that tracks the onboarding status of all Contractor personnel. The Contractor Onboarding POC shall be responsible for accurate and timely submission of all required USDA onboarding paperwork to the COR. The Contractor shall be responsible for tracking the status of all its staff’s onboarding activities and report the status at the staff level during onboarding status meetings. The Contractor shall provide, to the COR, an Onboarding Status Report for any staff with outstanding onboarding requests. Additional information regarding the Onboarding process is addressed in the attachment “Background Investigation Requirements”.
Additional information regarding the Onboarding process is addressed in the attachment “BACKGROUND INVESTIGATION REQUIREMENTS”.
Deliverable:
A. Onboarding Status Report – due weekly.
This report is to include:
1. All outstanding onboarding requests that need to be reviewed by the COR.
2. Contractor personnel who began the onboarding process in the last 7 days.
3. Report of Contractor personnel who completed the onboarding process in the last 7 days.
Contractor Personnel Staffing and Assignments
(a) Federal employees, contractors, subcontractors, experts, consultants, and paid/unpaid interns hired for work within the United States or its territories who require access to USDA Mission Areas, Agencies and Staff Offices or controlled facilities, Information Technology (IT) systems or security items or products, must be either U.S. citizens or Lawful Permanent Residents, also known as “green card,” holders.”
(b) In the event that any of the key personnel named in the Contractor’s quotation, as accepted by the Government at award, are unable to perform because of death, illness, resignation from the Contractor’s employ, dissolution of agreement, or other reasons, the Contractor shall submit within 24 hours to the CO/COR, detailed written explanations of the circumstances necessitating the proposed substitutions, complete resumes for the proposed substitutes, and any other information that the CO/COR deems pertinent to approve the substitution. No substitution is to be made without the prior written approval of the CO/COR. No increases in pricing will be allowed when substitutions are authorized by the Government.
(c) Personnel possessing unique technical specialties may be required for certain services related to the acquisition tasks. Such personnel shall have qualifications as required by the applicable tasks and approved by the CO/COR, which are appropriate to the nature of the services that will be provided.
(d) The CO will have the right to effect removals of any Contractor employees working under the awarded acquisition, if those employees are deemed not to possess the proper level of competence or abilities or otherwise found to be unsuitable for work required. In such cases, the Contractor must promptly submit the names and any other information pertinent to approvals of substitutions if requested.
(e) Failure or delays by the Contractor in providing qualified personnel who meet the stated requirements of this acquisition, may be deemed sufficient reason by the COR to recommend termination for cause to the CO.
(f) The Contractor shall provide the CO with a primary and alternate administrative point of contact (POC) after award. One of these points of contact must be a Contract Executive. The Contractor shall notify USDA RD of any changes in contact information as expeditiously as possible.
Compliance with IT Security Policies:
· Information systems and system services provided to USDA by the Contractor must comply with the current USDA/ IT security and privacy policies, specifically the 3500 – 3599 Cyber Security Department regulations - https://www.ocio.usda.gov/policy-directives-records-forms/directives-categories.
· Contractors are also required to comply with current Federal regulations and guidance found in the:
· Federal Information Security Modernization act of 2014 (FISMA).
· Privacy Act of 1974; E-Government Act of 2002, Section 208.
· National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS)
· 800-Series Special Publications (SP), specifically 800-40, Guide to Enterprise Patch Management Technologies.
· Office of Management and Budget (OMB) memoranda.
· USDA Information Security Program policies,
· and other relevant Federal laws and regulations with which USDA must comply.
· USDA departmental regulation DR 3575-002, System, and Information Integrity (08/16/18), mandates that information technology development projects follow the Agency’s accepted System Development Lifecycle (SDLC). All projects with congressional visibility can expect to be audited for compliance. Other projects may be audited at Agency discretion. Audits may occur at any time.
· Contractors are required to protect information regarding security issues and associated documentation to limit the likelihood that vulnerabilities in operational software are exposed. If new vulnerabilities are identified after the acceptance of COTS software, the Contractor must review and remediate the vulnerabilities and then present the results for Government approval within the timeframes documented in USDA IT security policies.
Special Considerations Contractor Collaboration: At the CO’s direction, the Contractor may be required to work in conjunction with other vendors. In addition, the Contractor may be required to meet and work with said other vendors regularly. However, it is expected that vendor collaboration working meetings would not be more frequent than twice a week at a duration of not more than 3 hours per meeting. These meetings may be obligatory to address project issues/concerns/improvements, etc.
Collaboration working meetings are in addition to the meetings listed in the deliverables table.
At the CO’s direction, the Contractor may be required to provide PMO ad hoc status reports in addition to any status reports in the deliverable table.
This authority shall not be delegated to any COR.
Meetings: Please be advised that most acquisition meetings are held in Microsoft TEAMS. Meetings may be recorded for the contract file. The COR or CO is to set up meetings in TEAMS to facilitate meeting transcripts.
Organizational Conflict of Interest (OCI) Contractor and subcontractor personnel performing work under this acquisition may receive, have access to proprietary or information (e.g., cost/pricing, specifications, work statements, etc.) or perform services which may create a current or subsequent OCI as defined in FAR Subpart 9.5. The Contractor shall notify the CO immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the CO to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the CO and in the event the CO unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the CO may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.
The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the CO and in the event the CO unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the CO may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent acquisition requirements which may be affected by the OCI.
An example of preclusion of participation/bidding on a subsequent acquisition requirement may be the following scenario: Contractor One, per Contract One developed the architectural structure, strategic plan, etc. (aka PWS Tasks/Plan) for Requirement Two which will be competed to award Contract Two. Because of Contractor One created/wrote the PWS Tasks/Plan, Contractor One will be precluded from bidding on Requirement Two solicitation. Preclusion in this instance helps to ensure best value for the government while keeping a fair and unbiased acquisition competition environment.
Data Rights The Government has unlimited rights to all documents/material produced under this IDIQ and subsequent IDIQ Task Orders. All documents and materials produced under this acquisition shall be Government-owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the Contractor without written permission from the Contracting Officer. This right does not abrogate any other Government rights.
USDA Visual Identity Guidelines All visual materials intended for release to the public, both electronic and printed, delivered in the performance of this contract, must wholly conform to the current USDA Rural Development Visual Identity Guidelines. See attachment, “USDA Visual Identity Guidelines”.
Constraints or Assumptions Contractor shall adhere to USDA Digital Strategy, US Web Design Standards, and Chief Information Officers Council (CIO.gov) policies and priorities.
Key challenges that need to be addressed under this contract:
1. Focus Area 1 Production Support Operations:
· RDTO has made recent strides to enhance the RD Release Management program/process. Additional capacity working with the RDTO release manager is required to support the overall management and governance for the program.
· General Support Toolchain (GSS) management
· Additional capacity is required for the support of the Atlassian Jira Service Desk/Jira. Design, Implementation, Management, and Governance.
· Additional capacity is required for the support of BitBucket.
· Additional capacity is required for the support of Jenkins.
· Technical Architecture (Salesforce, Mulesoft, Hosted components)
· Salesforce administration capacity
· Including Salesforce infrastructure administration.
· Common component management and deployments
2. Focus Area 2 and 3 Sustainment Engineering:
· Implementing best practices to streamline/mature Dev/Sec/Ops model.
· Utilizing and supporting automated testing
· Quality Assurance and testing integration
· Salesforce application support capacity
· Capacity based support model utilizing an Agile Kanban methodology.
· Enhanced Communication:
· Enhance communication, share lessons learned, defect iteration demos, scrum of scrums, etc.
· Facilitate rapid identification and mitigation of dependencies between various functional entities. Meet with and provide full functional overviews of support systems with various “development, modernization, and enhancement (DME) vendors, RD Program staff, and other functional areas within the RD Technology Office.
3. Focus Area 4: Implementing a SAFe Agile approach for legacy system enhancements and modernization planning in line with the developing RDTO SDLC 3.0.
4. Each awarded FA task order is anticipated to be operational within 30 days of Task Order award.
Order of Precedence In the event of inconsistencies, between the Contractor’s proposal/quote and PWS, the required work specified in this PWS will take precedence over the Contractor’s proposal/quote.
III. SCOPE OF WORK
Below is an explanation of how the Sustainability Engineering branch (SE) and the Production Support Operations (PSO) branch interact.
Production Support Operations (PSO)
· This Group serves as the technical experts who ensure IT infrastructure services are delivered effectively and efficiently. This includes fulfilling service requests, resolving service failures, fixing problems, as well as carrying out routine operational tasks in the Cloud, webhosting, and Mainframe infrastructures that includes the development, test, disaster recovery, certification, and production environments.
· Interfaces with developers to place applications properly into the Hosting environment to conform to technical architecture and applicable security requirements.
· Works with developers throughout the development and testing process to assist in successful integration and implementation of new applications and enhancements. Promotes developer application code into the Certification/Production environment.
· Provides release management services to the production environments consistent with applicable security, change, and release management guidelines. Provides technical assistance in interface of hosted applications with Hosting managed components.
· Serves as the general technical liaison to…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .