Attachment_1_-_Performance_Work_Statement.pdf

PDF 906 KB Posted

Attached to
Native American Student Information System Recompe Federal contract opportunity
Solicitation number
140A2325Q0066
Issued by
Department of the Interior Bureau of Indian Affairs Bureau of Indian Education

About this file

This is a Performance Work Statement (PWS) for the Native American Student Information System (NASIS) issued by the Bureau of Indian Education (BIE). The PWS outlines requirements for a contractor-owned and contractor-operated student information system that serves 186 BIE-funded schools across 23 states, supporting approximately 46,000 students in grades K-12 and Family and Child Education (FACE) programs.

The contractor must provide licenses, application hosting, help desk support, training, and system operation and maintenance. Key requirements include EDFacts reporting capabilities, ISEP reporting, federal/state reporting, special education tracking, and maintaining compliance with DOI security standards. The system must achieve Authority to Operate certification within 12 months of award and provide 99.97% uptime with 24/7 availability. The contractor must supply three full-time help desk staff and deliver regular training sessions. Data migration from the existing NASIS system must be completed within 180 days if there is a new contractor. The PWS includes detailed requirements for system security, privacy controls, disaster recovery, and mandatory reporting capabilities to meet BIE's federal and statutory obligations under ESSA, IDEA, and other regulations. Version 2.0 of this PWS is dated February 7, 2025.

View the file

Other files for this federal contract opportunity

Other files attached to Native American Student Information System Recompe, newest first.
File Type Posted
Sol_140A2325Q0066_Amd_0007.pdf PDF
Sol_140A2325Q0066_Amd_0006.pdf PDF
Sol_140A2325Q0066_Amd_0005.pdf PDF
Small_Business_Q_A_for_NASIS_0004.pdf PDF
Sol_140A2325Q0066_Amd_0004.pdf PDF
Sol_140A2325Q0066_Amd_0003.pdf PDF
Sol_140A2325Q0066_Amd_0002.pdf PDF
Q_A_for_NASIS_0001.pdf PDF
Sol_140A2325Q0066_Amd_0001.pdf PDF
Attachment_3_-_Requirement_Definition_Document.pdf PDF
Attachment_2_-_Performance_Requirement_Summary.pdf PDF
Sol_140A2325Q0066.pdf PDF
Attachment_4_-_Pricing_Schedule.xlsx XLSX spreadsheet
Show all 13

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

This Document Contains Controlled Unclassified Information (CUI)

Bureau of Indian Education Programs

Native American Student Information System (NASIS) Performance Work Statement (PWS)

Bureau of Indian Affairs

Last Updated: 0 7 F e b r u a r y 2 0 2 5 Version: 2.0

Performance Work Statement

Office of Information Technology 2

Table of Contents

1. Introduction

1.1. Project Description

1.2. Background

1.3. Concept of Operations

2. GENERAL REQUIREMENTS

2.1. SYSTEM REQUIREMENTS

2.2. DEPARTMENT OF THE INTERIOR REQUIREMENTS

2.2.1. Services Delivery Method

2.2.2. Contingency Planning and Disaster Recovery

2.2.3. System Security Plan

2.2.4. Annual System Security Review

2.2.5. Assessment and Authorization

2.2.6. Infrastructure

2.2.7. Section 508 Compliance

2.2.8. Background Investigations

2.2.9. Non-disclosure Agreement

2.2.10. Security Awareness Training (SAT)

2.2.11. Personnel Changes

2.2.12. Contractor Location

2.2.13. Intellectual Property Rights

2.2.14. Independent Validation and Verification (IV&V)

2.2.15. System Logon Banner

2.2.16. Incident Reporting

2.2.17. Quality Control (Malware Code)

2.2.18. Annual Self-Assessment

2.2.19. System Logon Banner Acknowledgement

2.2.20. Security Controls

2.2.21. Contingency Plan Test

2.2.22. Vulnerability Analysis

2.2.23. Privacy Impact Assessment (PIA)

Office of Information Technology 3

2.2.24. System Of Record Notice (SORN)

2.2.25. List of IT Security Related Deliverables:

2.3. PROGRAM TECHNICAL SUPPORT

2.4. BIE CSP OPERATIONAL CONTROL

3. SPECIFIC TASKS

3.1. PROJECT MANAGEMENT AND PLANNING (Task 1)

3.1.1. Implementation and Test Plan (I&TP)

3.1.2. Monthly Status Reports

3.1.3. Weekly Status Report

3.1.4. Weekly Progress Meetings

3.1.5. Action Item Tracking

3.1.6. Quarterly Progress Review (QPR)

3.1.7. Web-based Project Information Exchange

3.1.8. Project Kick-off Meeting

3.2. REPORTING AND ANALYSIS SERVICES (Task 2)

3.2.1. ESSA Reporting

3.2.1.1. Consolidated State Performance Report (CSPR)

3.2.1.2. Annual Measurement of Accountability (AMA)

3.2.1.3. Consolidated BIE State Report Card

3.2.1.4. Individual School Report Cards

3.2.1.5. Teacher Qualifications Report

3.2.2. ISEP Reporting

3.2.2.1. Instructional Average Daily Membership (ADM)

3.2.2.2. Residential Membership Report

3.2.2.3. Weighted Student Unit (WSU) Report

3.2.2.4. Instructional Certification Report

3.2.2.5. Residential Certification Report

3.2.2.6. Student CIB Report

3.2.2.7. Student Tribal Code Report

3.2.2.8. Student ISEP Data Field Completion Report

3.2.2.9. Student Count Waiver Request Form

3.2.2.10. 30 Day Residential Report

Office of Information Technology 4

3.2.2.11. First 10 Instructional Days of School Year

3.2.2.12. 10 Consecutive Days Absent

3.2.3. U.S. Department of Education Reporting

3.2.3.1. Coordinated Early Intervening Service

3.2.3.2. State Performance Plan Indicators

3.2.4. Federal Reporting

3.2.5. Management Reporting

3.2.5.1. Revised Utilization Report

3.2.5.2. Data Integrity Reports

3.2.6. EDFacts Reporting Module

3.2.6.1. Assessment Set-up/Load

3.2.6.2. Full Academic Year (FAY) Set-up

3.2.6.3. Participation Rate Set-up

3.2.6.4. Attendance Rate Set-up

3.2.6.5. Graduation Rate Set-up

3.2.6.6. Data Validation

3.2.6.7. Military Student Data Identifier

3.2.6.8. Foster Care Student Data Identifier

3.2.6.9. Homeless Student Data Identifier

3.3. FEDERAL GOVERNMENT REPORTING REQUIREMENTS – Configuration (Task 3)

3.3.1. Special Education IEP Forms and BIE State Reports

3.3.2. Special Education Process Forms and BIE State Reports

3.3.3. FACE Program Process Forms and BIE State Reports

3.3.4. Gifted and Talented Process Forms and BIE State Reports

3.3.5. English Learners Forms and BIE State Reports

3.3.6. Native Language Learners and BIE State Reports

3.3.6.1. Homeless Students

3.4. TRAINING (Task 4)

3.4.1. Interchange Training

3.4.2. Virtual User Training

3.4.3. NASIS User Training

3.4.3.1. System Administrator Training

Office of Information Technology 5

3.4.3.2. Registrar/Census Training

3.4.3.3. Teacher Grade Book Training

3.4.3.4. Residential Training

3.4.4. Special Education Forms/Process Training and Other Supplemental Programs

3.4.5. Class Scheduling Training

3.4.6. BIE NASIS Certification Training

3.4.6.1. BIE Specific Topics

3.4.6.2. BIE Specific Training Materials

3.5. DATA CLEAN-UP (Task 5)

3.5.1. Data Synchronization

3.5.2. Data Standardization

3.6. NASIS SYSTEM OPERATION AND MAINTENANCE (O&M) (Task 6a, 6b & 6c)

3.6.1. License (Task 6a)

3.6.2. Application Hosting (Task 6b)

3.6.2.1. Managed Hosting

3.6.2.2. Cloud Hosting

3.6.3. Help Desk Support (Task 6c)

3.6.3.1. Support Summary Reports

3.6.3.2. Data Integrity Assistance

3.6.3.3. Data Integrity Assistance/Other

3.6.3.4. Ongoing Technical Support

3.7. DELIVERABLES

Office of Information Technology 6

1. Introduction The Performance Work Statement (PWS) has been prepared in conjunction with the Requirements Definition Document (RDD), and the RDD should be considered as part of the PWS in its entirety.

This Requirements Definition Document (RDD) describes the Native American Student Information System (NASIS) business and functionality requirements.

This RDD was prepared by the Bureau of Indian Education (BIE) Chief Academic Office (CAO), School Operations; BIE Education IT; and the Indian Affairs, Office of Information Management Technology (IA-OIMT). The RDD supports the following activities:

• Procurement of the system

• Design and development of the system

• Evaluation of the product in all subsequent phases of the life cycle

• Enhancement of the product in all subsequent phases of the life cycle

• Monitor and determine the success criteria of the project

1.1. Project Description

The purpose of the Native American Student Information System (NASIS) investment is to collect and store student data. This data will be used to improve student achievement through a student information data management system for BIE-funded schools. In addition, the data supports statutory and regulatory reporting requirements.

1.2. Background

School Year 2006-2007 was the first year of the Bureau of Indian Education’s (BIE) Native American Student Information System (NASIS). The current NASIS system is implemented and utilized by 186 bureau-funded schools and peripheral dormitories, Albuquerque Service Center (ASC), Education Resource Centers (ERC) and Central BIE offices. NASIS is hosted by a contracted Internet Service Provider (ISP) in a third-party data center by a contractor operated contractor owned (CoCo) independent software provider. NASIS collects student information through a system that meets the unique geographical, environmental, and technological requirements and constraints of the BIE’s national school system located in 23 states, with approximately 46,000 students in grades kindergarten to twelve as well as Family and Child Education (FACE). The Indian School Equalization Program (ISEP) is the base school program funding source for all bureau-funded schools. The BIE is comprised of a Central office (Office of the Director) located in Washington, DC, other offices located in Albuquerque, NM are the Deputy Director (School Operations), Division of Performance and Accountability (DPA) and Chief Academic Office (CAO). Three Associate Deputy Director Offices, Education Resource Centers, and 186 schools and dormitories in

Office of Information Technology 7 the are located nationwide continental United States. Relative to Federal reporting requirements, the BIE is considered a state entity. NASIS is set up as a bureau-wide system supporting both state and school level functionality.

The reporting and analysis include the requirements of the Indian School Equalization Program, the Educational Amendments of 1978 P.L. 95-561, Elementary and Secondary Education Act of 1965, reauthorized as the “Every Student Succeeds Act (ESSA)”, P.L. 114-95, and the Individuals with Disability Education Act (IDEA). ESSA mandates BIE to collect and report on Title I, II, IV, VI, and X requirements. In addition, reporting and analysis includes the Department of the Interior, Indian School Equalization Program with the 15% set-aside for Special Education (SPED), ISEP supplemental programs (Gifted and Talented, Language Development, Enhancement Program, and FACE).

Hyperlinks:

• NIST SP 800-53 Rev. 5

• NIST SP 800-37 Rev. 2

1.3. Concept of Operations

BIE successfully implemented NASIS with required reporting and analysis identified in the Requirements Definition Document (RDD). This PWS addresses the need for on-going operations and maintenance, continued and new training, and updates to provide data for the Indian Student Equalization Program (ISEP) counts for funding that supports base school operational requirements, staffing and non-pay operating costs, and to meet the BIE’s federal reporting and analysis requirements as mandated by Public Law 114-95 Every Student Succeeds Act (ESSA), and Individuals with Disabilities Act (IDEA). The contractor will provide BIE a web-based, Contractor owned and contractor operated student information system on per student basis at all bureau-wide sites. NASIS is a centralized system for supporting teachers, other school staff, students, parents, and bureau-wide staff.

The BIE will provide reports required by Federal and State education agencies and provide the data to analyze student performance to use in school improvement planning.

The contractor shall submit key personnel resumes, who are planned to be utilized to provide services. Key personnel resumes shall highlight their understanding of implementing a large-scale Student Information System. The Government will evaluate the key personnels resumes for their depth, breath and overall experience related to this type of work, as well as their education and certifications. It is expected that a total of key personnel to provide services on this contract is 5-10.

Resume requirement shall be a total of five (5) pages that will be submitted for review, this includes three (3) pages for the general statement plus two (2) pages for the resume.

https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Office of Information Technology 8

2. GENERAL REQUIREMENTS

2.1. SYSTEM REQUIREMENTS

The Contractor shall provide centralized, school administration services as a contractor owned and contractor operated model for three organizational levels within the BIE system. These levels include:

BIE State (including Central Office staff located in sites other than the DC Office):

Offices reviewing or collecting data from all BIE schools for appropriate purposes as required by law on an annual and as needed basis. Data access shall be limited to read only and to specific types or categories of school data as determined by BIE. The system shall provide BIE state reporting capability and the capability to download and/or export data in a variety of formats for appropriate compilation and submission of reports to U.S. Congress, U.S. Department of Interior, U.S. Department of Education, and all federal reporting entities. Changes may be made to the system when new Federal reporting requirements are identified by the BIE and as authorized by the Authorizing Official, Business Owner, and the System Owner.

Education Resource Center (ERC): An ERC is a regional office that provides oversight to an assigned number of schools. Data access for system users in this category shall be limited to read only and to specific types or categories of school data as determined by BIE. The system shall have the ability to restrict data access for each ERC to those schools under its purview. Currently, there are 15 regional ERCs; however, this number may change. The system shall accommodate organizational changes that include realignment of the specific schools under each ERC which is required to be completed by the contractor. Data access for system users in this category shall be restricted to only that data pertinent to said user specific to their school. Within each BIE school, data access shall be limited by definitive school positions and follow the read/write, read only, or no access provisions of the contractor's application and database management software as reviewed and accepted by BIE. The system shall accommodate additions, restructuring, and elimination of instructional and residential programs.

School and/or Residential Sites: A BIE-funded schools are funded by the Bureau of Indian Education that is an educational institution, including elementary, junior high or middle, high school, peripheral, cooperative, and contract schools serving students in grades Kindergarten through 12.

2.2. DEPARTMENT OF THE INTERIOR REQUIREMENTS

The technology used by the system shall comply with the technology standards approved by the Indian Affairs Associate Chief Information Officer (ACIO). The Contractor shall operate and maintain the contractor owned and contractor operated system to include the following:

1. Application software system support

2. Updates and new software version releases

3. Help desk support

Office of Information Technology 9

4. User training The contractor will provide and perform program Information Technology services in a Department of the Interior (DOI) or Indian Affairs (IA) Office of Information Management Technology (OIMT) approved development and/or test environments only. The DOI, IA-OIMT or one of their approved hosting entities are the only entities allowed to procure, operate, secure, and maintain infrastructure and operational environments. The contractor, through the guidance of Contracting Officer (CO) and/or Contracting Officer Representative (COR), will adhere to all DOI and IA-OIMT established Information Technology (IT) regulations, policies, and directives to include, but not limited to, capital planning, investment review, lifecycle management, change management, security, and authority to operate. All production environments regardless of the hosting entity will be operated by IA- OIMT to include any system environment provided by any approved external hosting provider. Any new IT systems or services must be approved by the IA-OIMT executive currently known as the Associate Chief Information Officer (ACIO) or delegate. All new IT systems or services that may be developed or supported by this contract will be approved by the ACIO prior to them being released. The contractor will follow change management and related processes to deploy any new IT service or system.

2.2.1. Services Delivery Method

To reduce overall life cycle costs and simplify system support, and to take advantage of proven technology, NASIS must be a Contractor owned and contractor operated (CoCo) system. This is akin to the contractor performing as an Application Service Provider (ASP) specifically for the BIE.

This Contractor owned and contractor operated (CoCo) system must, at a minimum:

• Be able to achieve an Authority to Operate (ATO) certification within 12 months of award.

• Be able to be minimally modified as necessary to achieve ATO (such as implementing pre-login warning banners)

• Be assessed by a third-party assessment organization (3PAO), either federal or commercial.

See appendix C, DOI Baseline Contract Compliance Guidelines in the Requirements Definition Document (RDD).

2.2.2. Contingency Planning and Disaster Recovery

Office of Management and Budget (OMB) Circular A-130 Revised, and DOI policies require that information systems have a contingency plan (described by National Institute of Standards and Technology Special Publication NIST SP 800-34 Rev. 1, Contingency Planning Guide for Information Technology Systems) that is updated on an annual basis and that the plan be tested and documented on an annual basis.

Hyperlinks:

Office of Information Technology 10

• NIST SP 800-34 Rev. 1

2.2.3. System Security Plan

OMB Circular A-130 and DOI policies require that information systems have a System Security Plan (SSP) as described by NIST SP800-18, Guide for Developing Security Plans for Federal Information Systems. For delivery of services by a Cloud Service Provider (CSP), the requirement must be fulfilled by contractor.

2.2.4. Annual System Security Review

The Federal Information Security Modernization Act (FISMA) requires that information systems undergo annual security review. For delivery of services by a CSP, the government will require administrative rights access to the system and any contractor operated data center and development facility to perform the annual review.

https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act

2.2.5. Assessment and Authorization

OMB Circular A-130 and DOI policies require information systems to be assessed and authorized prior to going into production. For delivery of services by a CSP, the government will require timely access to the NASIS system and any NASIS contractor operated hosting facility to perform the Assessment and Authorization (A&A). Contractor will provide information as required. The NASIS system will be subjected to network-based vulnerability scans by a third-party assessor either contracted by the Federal Government or provided by the contractor by an approved vulnerability scan platform. Reassessments shall occur whenever there is a major change that affects security. The contractor must follow current NIST Special Publications listed below “List of Information Assurance and IT Security Guidelines and Regulations”. The Government will reserve the right to conduct the Security Test and Evaluation (ST&E) using either Government personnel or an independent contractor.

The contractor will take appropriate and timely action (this will be specified in the contract) to correct and/or mitigate any weaknesses discovered during such testing, at no additional cost to the Government.

The Designated Approving Authority (DAA) for the system will be the official identified in DOI Secretarial Order No. 3255.

List of Information Assurance and IT Security Guidelines and Regulations:

• OMB Circular A-130

• 800-18 Rev. 1

• 800-30 Rev. 1

• NIST SP 800-37 Rev. 2

• 800-60 Vol. 1 Rev. 1 https://csrc.nist.gov/publications/detail/sp/800-34/rev-1/final https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act https://www.cisa.gov/topics/cyber-threats-and-advisories/federal-information-security-modernization-act https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A130/a130revised.pdf https://csrc.nist.gov/publications/detail/sp/800-18/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final

Office of Information Technology 11

• 800-60 Vol. 2 Rev. 1

• 800-53 Rev. 5

• 800-53A Rev. 5

• 800-53B Rev. 5

Standards for Security Categorization of Federal Information Systems

• 800-60 Vol 1. Rev. 1

• 800-60 Vol 2. Rev. 1

• 800-63-3

• 800-63A

• 800-63B

• 800-63C

• 800-86

• 800-88 Rev. 1

• 800-111

• 800-114 Rev. 1

• 800-122

• 800-124 Rev. 1

• 800-140

• 800-144

• 800-160 Vol. 1 Rev. 1

• 800-160 Vol. 2 Rev. 1

• 800-161 Rev. 1

• 800-163 Rev. 1

• 800-171 Rev. 2

• 800-171A

• 800-172

• 800-172A

• 800-184

• 800-207

• 800-209

• Information Processing Standard (FIPS)

• Minimum Security Requirement for Federal Information and Information https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53B.pdf https://csrc.nist.gov/publications/detail/sp/800-60/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-60/vol-2-rev-1/final https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63-3.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63a.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63b.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-63c.pdf https://csrc.nist.gov/publications/detail/sp/800-86/final https://csrc.nist.gov/publications/detail/sp/800-88/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-111/final https://csrc.nist.gov/publications/detail/sp/800-114/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-122/final https://csrc.nist.gov/publications/detail/sp/800-124/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-140/final https://csrc.nist.gov/publications/detail/sp/800-144/final https://csrc.nist.gov/publications/detail/sp/800-160/vol-1-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-160/vol-2-rev-1/final https://csrc.nist.gov/publications/detail/sp/800-161/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-163/rev-1/final https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-171a/final https://csrc.nist.gov/publications/detail/sp/800-172/final https://csrc.nist.gov/publications/detail/sp/800-172a/final https://csrc.nist.gov/publications/detail/sp/800-184/final https://csrc.nist.gov/publications/detail/sp/800-207/final https://csrc.nist.gov/publications/detail/sp/800-209/final https://csrc.nist.gov/publications/detail/fips/199/final https://csrc.nist.gov/publications/detail/fips/199/final https://csrc.nist.gov/publications/detail/fips/200/final

Office of Information Technology 12

Systems (FIPS) 200

• DOI Security Assessment &

Authorization (AS&A) Guide

• DOI Privacy Impact

Assessment

2.2.6. Infrastructure

For CSP delivery of services and for contractor operation of a BIE-owned system, the contractor shall provide the infrastructure necessary to operate and maintain NASIS. NASIS is required to be available on a 24x7 basis with 99.97% uptime.

(Reference C.3.6.2 for the host site locations.)

It is desirable that the SIS be provided in its own tenant environment.

2.2.7. Section 508 Compliance

The contractor shall ensure that all electronic and information technology delivered in compliance with this PWS meets the accessibility standards of 365 Code of Federal Regulations (CFR) 1194.36. CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended March 23, 2018. This standard is viewable at http://www.section508.gov. In June 2001, the Federal Acquisition Regulations (FAR) was modified to comply with CFR 1194 via the addition of a new Subpart

39.2. The FAR is viewable at https://www.acquisition.gov/browsefar.

2.2.8. Background Investigations

Contractor employees who will have access to DOI information and/or will develop custom applications are subject to background investigations. The level/complexity of background investigations must be the same as for a federal employee holding a similar position. The following links provide guidance for the appropriate background investigations based on types of access with elevated rights.

https://www.doi.gov/sites/doi.gov/files/elips/documents/441-dm-3.pdf https://www.doi.gov/sites/doi.gov/files/elips/documents/441-dm-5.pdf The solicitation and contract should state the levels required for applicable labor categories or positions with the appropriate background investigation. Contractor shall not begin work until clearance has been approved by the appropriate BIE Official.

2.2.9. Non-disclosure Agreement

Contractor employees who will have access to DOI or Service information or will develop custom applications must sign a non-disclosure agreement prior to gaining access. Each agreement must be tailored to the contract. A draft or sample agreement may be included in solicitations. After award, the COR and BIE Acquisitions will develop the final Non-Disclosure Agreement (NDA) agreements, with the review and approval of the DOI Solicitor Office.

2.2.10. Security Awareness Training (SAT)

https://csrc.nist.gov/publications/detail/fips/200/final https://www.doi.gov/ocio/customers/assessment https://www.doi.gov/ocio/customers/assessment https://www.doi.gov/privacy/pia https://www.doi.gov/privacy/pia http://www.section508.gov/ http://www.acquisition.gov/browsefar https://www.doi.gov/sites/doi.gov/files/elips/documents/441-dm-3.pdf https://www.doi.gov/sites/doi.gov/files/elips/documents/441-dm-5.pdf

Office of Information Technology 13

Contractor employees must take DOI’s end-user computer security awareness training prior to being granted access to DOI data or being issued a user account.

Security Awareness Training must be renewed annually. The contractor must complete yearly DOI Information Management Training (IMT) mandated security awareness training, and the completed certificates must be submitted to the COR/ACOR on a yearly basis.

https://www.doi.gov/doitalent/training-download

2.2.11. Personnel Changes

The contractor must notify the COR immediately when an employee working on the NASIS system has been reassigned or leaves the contractor’s employment or a new employee has been added to replace a missing employee.

2.2.12. Contractor Location

Work is to be completed virtually and/or in the contractor facility under direction of the CO and the contractor Lead Point of Contact (POC). BIE does not anticipate travel or access to government facilities.

CONUS Clause: Access, transmit, process, house, and store all sensitive agency information, including information subject to the Privacy Act and Personally Identifiable Information (PII), only within the sole jurisdiction of the United States Federal Government (i.e., within the continental United States, Hawaii, Alaska, Puerto Rico, Guam, and the Virgin Islands).

2.2.13. Intellectual Property Rights

DOI will own the intellectual property rights to any software developed on its behalf to the maximum extent practical. In accordance with FAR 52.227-14, Rights in Data-General (May 2014) (https://www.acquisition.gov/far/52.227-14), and its alternates will be used in the contract. However, deviation from this regulation may be necessary as circumstances warrant. The Federal Government will retain all rights to all data that is input into all storage device or database that is developed or managed under this contract.

2.2.14. Independent Validation and Verification (IV&V)

An IV&V process is performed to ensure the system meets the stated requirements of the BIE. The BIE will perform the initial validation and verification during acceptance testing and reserves the right to bring in an independent group to perform an IV&V in future years of the contract. The BIE will fund this IV&V.

Contractor testing must be performed on the development and pre-deployment environments before production is upgraded or patched.

2.2.15. System Logon Banner

A DOI-approved logon banner must be displayed on the first page of any accessible web pages owned by DOI/BIE. Applications developed or maintained under this contract must contain a BIE approved logon warning advising users of rules, restrictions, and privacy expectations for that application. The text of such warning https://www.doi.gov/doitalent/training-download

Office of Information Technology 14 will be provided by the Government system owner.

Figure 1: System Warning Banner

2.2.16. Incident Reporting

The contractor must report computer security incidents affecting DOI/BIE data or systems in accordance with the DOI Computer Incident Response Guide.

Solicitations must include either the complete publication or a reference to public facilities, such as a website and/or office, where it may be accessed. The DOI Computer Incident Response Center (CIRC) requires all incidents to be report within one hour of the occurrence of the suspected incident. Until the background investigations have been complete and Non-Disclosure Agreement’s (NDA) have been signed by incumbent contractors, the DOI Computer Incident Response Guide cannot be distributed.

2.2.17. Quality Control (Malware Code)

All software and hardware must be free of malicious code.

https://www.whitehouse.gov/briefing-room/presidential-actions/2021/02/24/executive-order-on-americas-supply-chains/

2.2.18. Annual Self-Assessment

The contractor must conduct an annual self-assessment in accordance with NIST SP 800-53 Rev. 5 and NIST SP 800-53A Rev. 5 on all MAs, GSSs, and outsourced applications in production or a reference to public facilities, such as a website or office, where it may be accessed. An electronic copy of the self-assessment completion will be provided to the COR. The Government will reserve the right to https://www.whitehouse.gov/briefing-room/presidential-actions/2021/02/24/executive-order-on-americas-supply-chains/ https://www.whitehouse.gov/briefing-room/presidential-actions/2021/02/24/executive-order-on-americas-supply-chains/

Office of Information Technology 15 conduct such an assessment using Government personnel or another contractor.

The contractor will take appropriate and timely action to correct or mitigate any weaknesses discovered during such testing, at no additional cost.

Hyperlinks:

• NIST SP 800-53 Rev. 5

• NIST SP 800-53A Rev. 5

• NIST SP 800-53B

2.2.19. System Logon Banner Acknowledgement

Anyone who will access DOI data must acknowledge a government-approved logon warning prior to each new logon to the system.

2.2.20. Security Controls

Contractors will be required to ensure compliance with the security control requirements of NIST SP 800-53 Rev. 5, or current version, and Federal Information Processing Standard (FIPS) 200, which are appropriate to the sensitivity and criticality of the data or system. NIST FIPS 199 (as amended) will be used to determine sensitivity and criticality. The incumbent contractor must include either the complete publication or a reference to public facilities, such as a website or office, where they will be accessed in the development or maintenance of custom applications. The incumbent contractor shall, with the knowledge and concurrence of the Government system owner (SO) and the contracting officer representative (COR), be responsible for IT security for all non-government-owned systems used in the development of and systems intended for eventual delivery to the DOI/BIE in fulfillment of contract requirements. This includes IT, hardware, software, databases, networks, and telecommunications systems. The incumbent contractor shall follow the NIST special publications:

https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-172/final Security functionality in applications or integrated systems delivered here under must operate with the Government systems on which or with which it will eventually be deployed. Products delivered hereunder must not cause the incorrect operation of government resources or loss of integrity, confidentiality, or availability of electronic information or data.

The Contractor shall ensure compliance with the security control requirements of the current version of NIST SP 800-53 Rev. 5 (as amended) and FIPS 200 (as amended) appropriate to the sensitivity and criticality of the application/system assigned by the Government based on FIPS 199 (as amended).

The NIST documents are available on the internet at https://csrc.nist.gov/publications/sp800 The FIPS documents are available on the internet at https://csrc.nist.gov/publications/fips https://csrc.nist.gov/publications/detail/sp/800-53/rev-5/final https://csrc.nist.gov/publications/detail/sp/800-53a/rev-5/final https://csrc.nist.gov/publications/detail/sp/800-53b/final https://csrc.nist.gov/publications/detail/sp/800-171/rev-2/final https://csrc.nist.gov/publications/detail/sp/800-172/final https://csrc.nist.gov/publications/sp800 https://csrc.nist.gov/publications/fips

Office of Information Technology 16

The Department of Homeland Security (DHS) Continuous Diagnostic and Mitigation (CDM) Phase 1 project requires the Operating Systems hosting the NASIS application have installed the CDM required current version of the HCL Bigfix Endpoint Management/IEM hardware/software inventory scanning tool. The HCL BigFix Endpoint Management/IEM tool must be installed with administrative rights.

The Splunk Forwarder client/agent will be required to be installed on all servers hosting the NASIS application. An antiviral product meeting at a minimal Microsoft Endpoint Defender baseline must be installed on all servers hosting the NASIS application. A Microsoft Endpoint Configuration Manager (MECM) must be installed on all servers hosting the NASIS application.

2.2.21. Contingency Plan Test

The contractor will submit a contingency plan in accordance with NIST SP 800-34 Rev. 1 (as amended) or current version and the DOI Contingency Plan Guide. The plan must be approved by the COR and the BIE Information Systems Security Officer (ISSO). A copy of the annual test results will be provided to the COR and the BIE ISSO. This requirement concerns BIE systems residing at contractor-controlled sites or on contractor-owned systems that host DOI/BIE data. See Appendix A, page 72, section 2.6.1.3 for DOI guidance. The contingency plan must be consistent with the business impact analysis as identified by the BIE program.

2.2.22. Vulnerability Analysis

All systems operated and managed by the incumbent contractor shall be scanned at a minimum monthly with a vulnerability analysis tool to be consistent with Government requirements. All “safe” or “non-destructive” checks must be turned on.

All digital copies of each monthly vulnerability report and session data shall be provided to the COR, BIE ISSO, System Owner, and Information Owner.

The Government may conduct additional independent vulnerability scans, prearranged or unannounced. All systems accessible from the Internet will be tested monthly for remote vulnerabilities. Independent penetration testing may be performed by the Government or by another contractor.

With the knowledge and concurrence of the Government system owner; the incumbent contractor shall take immediate action to correct or mitigate any IT security vulnerability discovered during any vulnerability testing, as needed, to bring the system into compliance with security standards invoked elsewhere in this work statement. The incumbent contractor shall meet vulnerability patching and remediation time requirements. All identified Critical vulnerabilities will be patched within 15 days from the release date of the patch by the OEM. All identified High vulnerabilities will be patched within 30 days from the release date of the patch by the OEM.

The contractor will perform security testing on designated BIE/DOI systems using testing techniques described in NIST SP 800-115, or current revision, Technical Guide to Information Security Testing and Assessment, including vulnerability analysis and penetration testing. When DOI provides the testing tool, all “safe” and “non-destructive” checks must be turned on. All electronic copies of each report and

Office of Information Technology 17 session data shall be provided to the applicable Government system owner, the COR, and the BIE ISSO. Please see Appendix A, Page 94, section 2.1.3 for DOI guidance.

The following Department of Homeland Security’s binding operational directives shall be followed:

https://www.cisa.gov/news-events/directives/binding-operational-directive-19-02 https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01

2.2.23. Privacy Impact Assessment (PIA)

The DOI has published Privacy Impact Assessment guidance for assistance with creating PIA documentation and for the annual review. The DOI privacy guide will be provided to the contractor at the award kickoff meeting.

2.2.24. System Of Record Notice (SORN)

The NASIS system must have the current SORN updated to the new requirements in the RDD. The Privacy Act of 1974, as amended, requires the creation of a SORN to be completed and reviewed annually. OMB has published Circular A-108 (https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A108/omb_circular_a-108.pdf) guidance on the creation and annual review of SORN’s.

https://www.cisa.gov/news-events/directives/binding-operational-directive-19-02 https://www.cisa.gov/news-events/directives/binding-operational-directive-22-01 https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A108/omb_circular_a-108.pdf https://www.whitehouse.gov/wp-content/uploads/legacy_drupal_files/omb/circulars/A108/omb_circular_a-108.pdf

Office of Information Technology 18

2.2.25. List of IT Security Related Deliverables:

Table 1: IT Security Related Deliverables

Title Description Due Date/Frequency

Government Approval and Surveillance

Plan of Action and Milestones

(POA&M)

As described in, and in accordance with, the IT Security and Privacy

Requirements document.

Upon completion prior to authorization to move to Service Ready status and quarterly thereafter

Contracting Officer’s Representative (COR), Government system owner, Government

Technical Lead

Vulnerability and Security Configuration Scan Report

As described in, and in accordance with, the IT Security and Privacy

Requirements document.

Monthly

Contracting Officer’s Representative (COR), Government system owner, Government

Technical Lead

Continuous Monitoring

Report

As described in, and in accordance with, the IT

Monthly

Representative (COR), Government system owner, Government

Technical Lead

Documentation for Audit

Requirements

As described in, and in accordance with, the IT

30 calendar days after written request

Contracting Officer’s Representative (COR), Government system owner, Government

Technical Lead

Training Compliance

Report

As described in, and in accordance with, the IT

Annually

Representative (COR), Government system owner, Government

Technical Lead

Security Incidents

As described in, and in accordance with, the IT Security and Privacy

Requirements document.

Per Incident (immediately but not more than 1 hour)

Contracting Officer (CO), Contracting Officer’s

Representative (COR), Government system owner, Government Authorizing Official (AO), DOI-CIRC

Office of Information Technology 19

Contractor Employee

Report

Report of all contractor employees that have access to Government Data with status of required background checks as specified.

Annually on contract award anniversary date and within 3 business days upon written request

Representative (COR)

2.3. PROGRAM TECHNICAL SUPPORT

The Contractor shall provide program technical support as requested by the BIE team, to assist with:

• Program Reviews

• Product Briefings and Demonstrations

• System Management

• Future Planning

• Other support as may be required by BIE

2.4. BIE CSP OPERATIONAL CONTROL

The current Contractor shall support the BIE transition and migration to the incumbent NASIS contractor Operational Control as required. This transition should take place up to 180 days after award of the contract. If the incumbent contractor is not the current contractor, there must be a migration of all government data from the existing NASIS system to the future NASIS system.

Office of Information Technology 20

3. SPECIFIC TASKS

The PWS encompasses the tasks as delineated below.

3.1. PROJECT MANAGEMENT AND PLANNING (Task 1)

Contractor shall provide a full-time (40 hours per week) Senior Project Manager dedicated to the NASIS system to lead execution of the provisions of this contract, including the efforts of subcontractors. All requests of the BIE program office to the Senior PM contractor should be answered within 1 workday. Senior PM contractor will work with the BIE NASIS program office and will be supported by the government Senior PM in the planning and execution of this project.

3.1.1. Implementation and Test Plan (I&TP)

Contractor will develop and maintain an Implementation and Test Plan (I&TP) with Milestones to track progress against the project plan. A draft I&TP with Milestones will be provided to the BIE not later than 10 calendar days following the execution of the contract. An updated project plan shall be provided with the Monthly Status Report. The I&TP with Milestones will include:

• appropriate narrative descriptions, a project schedule showing a detailed work breakdown structure with task dependencies. These schedules shall be submitted monthly in both printed and PDF electronic format. The Project Plan must be developed in Microsoft Project.

• QUAD Chart (See Appendix A), the Contracting Officer of record will provide an example QUAD Chart upon award of the contract at the project kickoff meeting.

• Data center development and implementation: the incumbent contractor, upon negotiation and agreement with the government, may have the option of hosting the NASIS instance in the ADC with replication to the DOI Azure cloud for backup and recovery purposes.

• Data conversion that includes all existing and historical data through date of conversion for both state and district/schools’ editions.

• All existing state and district/school’s edition reports and data fields shall be converted and functional to the new system.

• A role-based training plan will be created for all BIE and NASIS users from BIE funded schools.

• The Disaster Recovery Plan shall outline and describe the disaster recovery measures that will be deployed at the cloud hosting facility and any secondary and tertiary backup sites. The plan shall incorporate best commercial practices, describes the backup and recovery utilities and detailed procedures for data back-up and recovery, and include, at a minimum, initial testing and thereafter, annual testing. There shall be a written policy describing the requirement for backup and recovery with annual testing at a minimum.

Office of Information Technology 21

• The System Security Plan (SSP) shall outline and describe the security measures that will be deployed to protect BIE school data at the hosting facility. The plan shall incorporate best commercial practices for United States educational environments and adherence to Federal, DOI, BIA, and BIE security policies. The plan shall also specifically address the use of virtual private network (VPN) technology. The Private Internet Protocol (PIP) shall include a section that specifically addresses those security measures that BIE must have in place at each BIE site and when.

• The Risk Mitigation Plan shall address identified risks and describe the actions necessary to mitigate those risks.

• The Risk Management Plan shall identify actual and potential risks identified in the project and their mitigation strategies.

• The Plan of Action and Milestones (POA&Ms) will be developed to address weaknesses and remediation of non-compliance with NIST guidance.

• The Corrective Action Plan (CAP) will be developed to address identified POA&Ms.

3.1.2. Monthly Status Reports

Contractor shall provide Monthly Status Reports. The monthly report, due by the 10th of each month for the preceding month, shall describe accomplishments for the reporting period, issues, current and cumulative financial status, and projected activities for the next reporting period. The Project Plan with Milestones and Action Items List will be provided with the report.

3.1.3. Weekly Status Report

Contractor shall provide a Status Report weekly to the COR, Supervisory Education Specialist, and the Government Senior Project Manager by the close of business on the last working day of each week. Each report shall describe accomplishments for the reporting period, issues, current and cumulative financial status, and projected activities for the next reporting period. The updated Project Plan and Milestones and Action Items List will be provided with the report. With each Weekly Status Report the Contractor shall provide metrics and lists that clearly show by school, NASIS usage by type (production, test, etc.), user support provided by category, data migration status, and training status. Contractor shall require such reports from its sub-contractors.

3.1.4. Weekly Progress Meetings

The Contractor shall schedule and conduct Weekly Joint Progress Meetings with the BIE program office, Government Senior Project Manager, and the BIE COR. The Contractor shall prepare the agenda and send the agenda 2 business days prior to the program office for any additions or changes. Weekly progress meetings shall be used to raise issues, present status and progress, and make decisions. If any issues arise that can’t be addressed in the weekly progress meeting, an Ad-Hoc will be scheduled by the Contractor Senior Project Manager.

Office of Information Technology 22

3.1.5. Action Item Tracking

Contractor shall maintain and manage an Action Items List at the Contractor level and review the status of the items at the Weekly Progress Meetings. Contractor shall also maintain and execute a list of action items assigned to the Contractor by the BIE Supervisory Education Specialist or the NASIS program manager.

3.1.6. Quarterly Progress Review (QPR)

Contractor shall host a QPR, the purpose of which is for the contractor to provide a comprehensive review of the status of the contract to include execution against the schedule and expenditures plan, progress toward addressing action Items, potential issues, recommendations for project enhancements, and plans for the next quarter.

The first QPR will be held on a date as mutually agreed by the government and the contractor.

3.1.7. Web-based Project Information Exchange

The contractor shall investigate the need to implement a Web-based information exchange capability to facilitate the sharing of documents, schedules, and other information required by the project team and will recommend a course of action to the government. The contractor will implement a capability as approved by the government. As many individuals will be involved in the project, a convenient way of exchanging information will be needed. The website would be deactivated when its continued use is not necessary. Selected individuals will have the ability to post information to the website. Access to the website shall be controlled using passwords or similarly effective technology.

Contractor recommendation shall be delivered to the Government within three (3) weeks after execution of this contract and have an operational website not later than three (3) weeks from the Governments approval to proceed. The incumbent contractor shall follow guidelines as described in 800-47 Rev. 1 (as amended) for a moderate system.

https://csrc.nist.gov/publications/detail/sp/800-47/rev-1/final

3.1.8. Project Kick-off Meeting

An integrated team project kick-off meeting to be held not later than ten (10) business days following execution of the contract. The date and location of the meeting shall be determined once both parties have mutually agreed.

3.2. REPORTING AND ANALYSIS SERVICES (Task 2)

3.2.1. ESSA Reporting

The Bureau of Indian Education receives funds from the U.S. Department of Education to carry out programs authorized under Every Student Succeeds Act (ESSA). NASIS will produce the reports required by ESSA. Required reports include:

3.2.1.1. Consolidated State Performance Report (CSPR)

https://csrc.nist.gov/publications/detail/sp/800-47/rev-1/final

Office of Information Technology 23

The Contractor will produce, maintain, and update the summative data that will facilitate inputting data by the BIE into the CSPR portion of the Education Data Exchange Network (EDEN). In general, data included can be found within the NASIS system and includes summative data and disaggregated data. Examples of data include the following:

Students by grades served under ESSA:

• Males and females

• Students with disabilities

• Students with status of active-duty military parent(s)

• Students with status of living in a homeless condition

• Students with status of foster care placement

• English Learners (EL)

• Progress of English Learners

• Students by race and ethnicity

• Student proficiencies on state assessments in English language arts, mathematics, and science

• Schools progressing or not progressing in meeting measures of accountability

• Suspensions, expulsions, violence incidents

• Graduation by 4-year cohort and option for multiple-year cohort

3.2.1.2. Annual Measurement of Accountability (AMA)

The Contractor will produce, maintain, and update reports from information within NASIS that makes an AMA determination for each school using the criteria for AMA determination as described in the BIE’s Agency Plan. BIE’s Agency Plan is contingent upon continued negotiated rulemaking and will be reviewed and updated annually.

The BIE Agency Plan can be found at:

https://www.bie.edu/topic-page/bie-essa-agency-state-plan

3.2.1.3. Consolidated BIE State Report Card

Consolidated and Individual State Report Cards may be altered by the results of the negotiated rulemaking to allow flexibility as future decisions are made. Example, additional elements may be added that are not addressed in this document.

State report cards must include information related to BIE’s system of accountability that uses indicators of school success, possibly including: (1) academic achievement as measured by proficiency on the annual assessments in English language arts, mathematics, , and science for K-12 students; (2) an indicator of student growth for K-8 students; (3) graduation rates for high schools; (4) progress in achieving English Proficiency for K-12 students; and at least one indicator of https://www.bie.edu/topic-page/bie-essa-agency-state-plan

Office of Information Technology 24 school success or school support for elementary, middle schools, and high school, (i.e., chronic absenteeism, student engagement, educator engagement, postsecondary readiness, school climate and safety, and student access to and completion of advanced coursework. The data must include all schools in the BIE system.

The following three (3) components of assessment data must include all students in the grades tested in the State, not just those students enrolled for a full academic year, as defined by the State. At a minimum, States must provide assessment data from their English language arts, mathematics, and science assessments. The State report card shall include but not limited to assessment data for each grade and subject tested:

• Information on the percentage of students tested.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .