Attachment 1 - SOW_042522 IDIQ DAS Oracle Support.pdf

PDF 778 KB Posted

Attached to
ORACLE Enterprise Database and Application Server Administration Support IDIQ Federal contract opportunity
Solicitation number
FDA-RFP-22-1249753
Issued by
Department of Health and Human Services Food and Drug Administration Office of Acquisition and Grant Services

About this file

This solicitation is for an Indefinite Delivery Indefinite Quantity (IDIQ) contract to provide Oracle Enterprise Database and Application Server Administration Support services to the Food and Drug Administration (FDA). The contractor will support FDA's Oracle databases, application servers, and related products including operations and maintenance, upgrades, migrations to cloud environments, and new development. The contract has a five-year ordering period and a $95 million ceiling. Pricing will be on a time and materials, labor hour, or firm fixed price basis as specified in individual task orders. The solicitation is set aside for 8(a) small businesses and responses are due by May 9, 2022. The contractor must have the capability to provide strategic planning, development, operations and maintenance for Oracle databases, middleware, and identity management products across FDA environments. The selected contractor will also support specific task orders for individual FDA centers.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TABLE OF CONTENTS

PART I – THE SCHEDULE

SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS

B.1.BRIEF DESCRIPTION OF SUPPLIES OR SERVICES

B.2. CONTRACT TYPE

B.3. OVERVIEW OF PRICING SCHEDULES

B.4. PRICING TERMS

B.5 AUTHORIZED ORDERING OFFICIALS

B.6. MINIMUM AND MAXIMUM CONTRACT VALUE

B.7. MATERIAL HANDLING FEE

SECTION C – STATEMENT OF WORK

C.1. INTRODUCTION

C.2. DESCRIPTION OF WORK

C.3. DELIVERABLES AND MILESTONES

C.4. LOCATION, WORK SCHEDULE, AND TRAVEL

C.5. SECURITY AND PRIVACY REQUIREMENTS

SECTION D - PACKAGING, MARKING AND SHIPPING

SECTION E - INSPECTION AND ACCEPTANCE

E.1. CLAUSES INCORPORATED BY REFERENCE

SECTION F - DELIVERIES OR PERFORMANCE

F.1. CLAUSES INCORORATED BY REFERENCE 52.252-2 (FEB 1998)

F.2. PERIOD OF PERFORMANCE

F.3. PLACE OF PERFORMANCE

F.4. DELIVERIES

SECTION G - CONTRACT ADMINISTRATION DATA

G.1 CONTRACTING OFFICER

G.2 CONTRACTING OFFICER’S AUTHORITY

G.3. CONTRACTING OFFICER REPRESENTATIVE (COR)

G.4. TASK ORDER CONTRACTING OFFICER REPRESENTATIVE (TO COR)

G.5. TECHNICAL DIRECTION

G.6. KEY PERSONNEL, HHSAR 352.237–75 (DEC 2015)

G.7. FDA INVOICE REQUIREMENTS

G.8. CONTRACT FINANCIAL REPORTING

G.9. GOVERNMENT FURNISHED PROPERTY

G.10. POST AWARD EVALUATION OF CONTRACTOR PERFORMANCE

G.11. TRAVEL COSTS

G.12. GOVERNMENT CLOSURES

G.13. ORDERING PROCESSES AND PROCEDURES

SECTION H - SPECIAL CONTRACT REQUIREMENTS

H.1. CLAUSES INCORORATED BY REFERENCE

H.2. HHSAR 352.203-70 - ANTI-LOBBYING (DEC 2015)

H.3. HHSAR 352.222-70 CONTRACTOR COOPERATION IN EQUAL EMPLOYMENT OPPORTUNITY

INVESTIGATIONS (DEC 2015)

H.4. HHSAR 352.224-70 PRIVACY ACT, (DEC 2015)

H.5. HHSAR 352.227-70 PUBLICATIONS AND PUBLICITY (DEC 2015)

H.6 HHSAR 352.232-71 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (FEB 2022)

H.7 HHSAR 352.233-71 LITIGATION AND CLAIMS (DEC 2015)

H.8. HHSAR 352.239-74 ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY (DEC 2015)

H.9. HHSAR 352.232-71 ELECTRONIC SUBMISSION OF PAYMENT REQUESTS (FEB 2022)

H.10. NON-PERSONAL SERVICES AND INHERENTLY GOVERNMENT FUNCTIONS

H.11. REPORTING MATTERS INVOLVING FRAUD, WASTE AND ABUSE

H.12. DISCLOSURE OF INFORMATION

H.13. INFORMATION SECURITY

H.14. EARNED VALUE MANAGEMENT SYSTEM

H.15. FDA 1335 PERSONNEL SECURITY CLEARANCE REQUIREMENTS (AUG 2006)

H.16. ACOUNTABILITY AND SECURITY

H.17. FDA 1350 ACCESS TO NON-PUBLIC INFORMAITON

H.18. IDENTIFICATION OF CONTRACTOR EMPLOYEES

H.19. NON-PERSONAL SERVICES

H.20. GOVERNMENT-FURNISHED DATA AND MATERIALS

H.21. ORGANIZATIONAL CONFLICT OF INTERESTS

H.22. TRANSITION

H.23. INSURANCE REQUIREMENTS

PART II - CONTRACT CLAUSES AND SOLICITATION PROVISIONS

SECTION I - CONTRACT CLAUSES

I.1. CLAUSES INCORPORATED BY REFERENCE

I.2. FAR CLAUSE 52.217-8 OPTION TO EXTEND SERVICES (NOV 1999)

I.3. FAR CLAUSE 52.217-9 OPTION TO EXTEND THE TERM OF THE CONTRACT (MAR 2000)

I.4. FAR CLAUSE 52.216-18 ORDERING (OCT 1995)

I.5. FAR CLAUSE 52.216-19 ORDER LIMITATIONS (OCT 1995)

I.6 FAR CLAUSE 52.216-22 INDEFINITE QUANTITY (OCT 1995)

I.7 FAR CLAUSE 52.219-17 SECTION 8(a) AWARD (OCT 2019)

I.8 Cost Reduction

I.9 Kick-Off Meeting and Report

I.10 Weekly Status Reports

I.11 Monthly Financial Report

I.12 Monthly Status Report

I.13 Staffing

SECTION II - SOLICITATION PROVISIONS

II.1. SOLICITATION PROVISIONS INCORPORATED BY REFERENCE

PART III LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS

SECTION J - LIST OF ATTACHMENTS

Attachment A – PRICING SHEETS (See Attached Excel Worksheet)

Attachment B – DETAILED DESCRIPTION OF LABOR CATEGORIES

Attachment C – COMMITMENT TO PROTECT NON-PUBLIC INFORMATION

Attachment D – EPLC FRAMEWORK

PART I – THE SCHEDULE

SECTION B - SUPPLIES OR SERVICES AND PRICES/COSTS

B.1.BRIEF DESCRIPTION OF SUPPLIES OR SERVICES

The Food and Drug Administration (FDA) requires contractor support to ensure that FDA’s Oracle databases and applications remain operational, are compatible with current and future operating systems (hardware and software), conform to FDA data governance standards and architecture, and continue to meet the ongoing needs of the FDA Centers.

B.2. CONTRACT TYPE

This is an 8(a) Indefinite Delivery Indefinite Quantity (IDIQ) type contract with a five (5) year ordering period being processed under a Partnership Agreement (PA) between the Department of Health and Human Services (HHS) and the Small Business Administration (SBA), under which the SBA has delegated to HHS, authority to enter into 8(a) contracts directly with eligible 8(a) firms in accordance to Section 8(a) of the Small Business Act (15 U.S.C. 637(a).

FDA has chosen to pursue an IDIQ contract to reduce lead time to award task orders and maximize the flexibility of selecting contract types appropriate to the specific tasks under consideration. At the discretion of the Contracting Officer, the government may use a Time and Materials, Labor-Hour, Firm Fixed Price or a combination thereof for the task orders. Each Request for Task Order Proposal (RFTOP) issued under this contract will identify the Government’s determination of contract type.

B.3. OVERVIEW OF PRICING SCHEDULES

The Contractor’s pricing schedules for labor categories are incorporated in Section J, Attachment A for the Pricing Sheet. The tables shall contain fully burdened hourly rates for both Government-site and Contractor-site requirements. The fully burdened hourly rates for each labor category shall include wages, indirect costs, fringe benefits, overhead, general and administrative, and profit.

The Government reserves the right to perform an annual review of labor rates to ensure the continued fairness and reasonableness of pricing.

See Attachment B Detailed Labor Categories a list of labor categories the Government anticipates will be necessary to perform the task orders expected to be issued under this contract.

B.4. PRICING TERMS

The unit prices specified in labor hour task order shall be fixed for the task order period of performance and shall not be subject to adjustment; except, as a result of a direct action or inaction by the Government which delays the Contractor from completing the task order within the time specified in the task order. However, in no event shall the Contractor perform, or be paid for any http://uscode.house.gov/uscode-cgi/fastweb.exe?getdoc+uscview+t13t16+492+90++%2815%29%20%20AND%20%28%2815%29%20ADJ%20USC%29%3ACITE%20%20%20%20%20%20%20%20%20 http://uscode.house.gov/uscode-cgi/fastweb.exe?getdoc+uscview+t13t16+492+90++%2815%29%20%20AND%20%28%2815%29%20ADJ%20USC%29%3ACITE%20%20%20%20%20%20%20%20%20 work which exceeds the not-to exceed dollar amount of a task order.

For Firm Fixed Price (FFP) task orders issued under this contract, the applicable unit price for a task order shall be the unit price for the time period in which the services are estimated to be performed, as agreed to by the Government and the Contractor at the time the task order is issued.

Each Time and Material or Labor Hour task order shall contain a ceiling price. The Contractor shall comply with FAR 52.232-7 in regards to the ceiling price for the individual task order(s).

B.5 AUTHORIZED ORDERING OFFICIALS

U.S Department of Food and Drug Administration, Office of Acquisitions & Grant Services Contracting Officers are authorized as ordering officials to place task orders under this contract.

B.6. MINIMUM AND MAXIMUM CONTRACT VALUE

(a) Award of the base period of the initial task order satisfies the guaranteed minimum for the IDIQ contract.

(b) The maximum ceiling for this award is $95 million.

B.7. MATERIAL HANDLING FEE

Reimbursement for material handling fee shall not be in excess of 5% on any subcontractor and material expenses on task orders issued under this contract.

SECTION C – STATEMENT OF WORK

C.1. INTRODUCTION

1.1. Background

The Office of Information Management and Technology /Division of Application Services (OIMT/DAS) at FDA is responsible for the administration, development, maintenance and support of Oracle databases, application servers and related products. These databases and application servers are hosted at both Government and Contractor operated sites, as well as off-site cloud-based platforms and serve to support the business/systems requirements of the FDA’s Centers.

FDA requires contractor support to ensure that the databases, applications, and products remain operational, are compatible with current and future operating systems (hardware and software), conform to FDA data governance standards and architecture, and continue to meet the ongoing needs of its centers.

1.2. Objective

The purpose of this IDIQ contract is to obtain Agency-wide Oracle, AppDynamics and other related products and technologies such as cloud migration, data architecture, data migrations to cloud, data governance, metadata management and DEVOPS support services. These services will include operations and maintenance of the current databases and applications, server transition and re-hosting, including re-hosting and migration efforts of on-premises databases and applications to off-premises cloud-based platforms, operations and maintenance of the shared middleware infrastructure, support of the enterprise Oracle Identity and Access Management configuration, and enterprise application deployment support, as well as development of new or additional features and capabilities.

1.3. Project Scope

The contractor shall provide strategic planning, new development, operation, and maintenance (O&M) support for Oracle and AppDynamics and other related products including, but not limited to Databases both non-Relational Databases as well as Relational Database Management Systems (RDBMS), Oracle Identity and Access Management, Oracle Internet Directory, Thesaurus Management System, and the entire suite of Oracle Fusion Middleware (FMW) products. The contractor shall provide logical and physical database design in adherence to FDA data governance standards of best practices and architecture, RDBMS as well as non RDBMS and related database products software installation and configuration, database creation, Fusion/WebLogic Middleware component implementation, performance tuning, applying recommended Database patches, custom application deployment, functional testing, backup/recovery, support for hardware upgrades and support for database and application server software version upgrades. The contractor shall support middleware and database software integration effort support between current and future agency on-premises datacenter databases and applications with planned off-premises/cloud databases and applications, including database architecture, design, tuning, configuration, migrations, and maintenance. The AppDynamics Support includes providing professional services for Operational and Maintenance (O&M) support services to maintain and improve the existing Enterprise Application Performance Monitoring (APM) solution including the AppDynamics Dashboards for the FDA shared and enterprise applications. The contractor shall provide support in alignment with all phases of the project lifecycle to achieve business and operational performance requirements to ensure operational and business requirements are met and best practices are maintained as specified at the task-order level

1.4 Systems and Applications Environment

FDA’s current applications and systems consist of Oracle applications and COTS products as well as third party software including but not limited to:

# Name Description Overview 1 Oracle Identity

Access Management Suite Single Sign On

The Oracle Identity Access Management Suite 11g and 12c stacks include Oracle Internet Directory (OID), Oracle Virtual Directory (OVD), Oracle Access Manager (OAM), Oracle Unified Directory (OUD) and Oracle Identity Manager (OIM) with Service-Oriented Architecture (SOA).

Versions: 10g, 11g, 12c and higher

The current 11g Identity Access Management server configuration includes two Exalogic compute nodes per environment in development and test in WODC. There are an additional two Exalogic compute nodes per environment in pre-production and production at CHDC. The configuration also includes one database per environment, running on two Real Application Cluster (RAC) database nodes on Exadata. The Contractor shall provide O&M support services for a total of eight Exalogic compute nodes, four in each of the two data centers.

We are in the process of migrating to the 12c suite of products, which reside on the x86 platform. That should be mostly completed by the end of the calendar year. Depends upon application development teams for integration.

2 Oracle

Enterprise Manager Grid Control and Cloud Control

Oracle Enterprise Manager is Oracle’s on-premise management platform that provides a single dashboard to manage all of your Oracle deployments, in your data center or in the cloud.

Through deep integration with Oracle’s product stack, it provides market-leading management and automation support for Oracle applications, databases, middleware, hardware, and engineered systems.

Versions: 11g, 12c, 13c and higher for shared, Enterprise Use.

Environment currently includes eight servers (four Oracle 12c RAC database servers, four Oracle OEM Cloud 12c servers).

This has fully migrated to 13c for both WODC and ADC. Server count is accurate for both ADC and

WODC.

3 MiddleWare Support

Oracle Weblogic Server Application Middleware support includes the FDA’s Enterprise Shared Environment in the White Oak Data Center and Full Middleware Deployment Services for the Pre- Production and Production Environments in the Ashburn Data Center.

We do full middleware support in both WODC and ADC – patching, software installation, configuration, error analysis and correction, monitoring, application deployment automation support, backups

4 Database Server Software

Enterprise Relational Database Management System (RDBMS)

Versions: 10g, 11g, 12c and later versions

Currently hosted in Dev, Test, PreProd, and Prod on LDOMS, Exadata and x86 hardware platforms running Oracle Solaris, Oracle Enterprise Linux and RedHat Enterprise Linux

5 AppDynamics AppDynamics is an application performance management (APM) and IT operations analytics tool that monitors application systems from the JVM and from the

Currently licensed for Pre-Production and Production host operating system level.

The software focuses on managing the performance and availability of applications across the enterprise, whether on premises or in the cloud.

6 Oracle Weblogic Server

Oracle WebLogic Server. Oracle WebLogic Server is a unified and extensible platform for developing, deploying and running enterprise applications, such as Java, for on-premises and in the cloud. WebLogic Server offers a robust, mature, and scalable implementation of Java Enterprise Edition (EE) and Jakarta EE.

Weblogic 12.2.1.3 and higher

7 Oracle Service Bus

The Oracle Enterprise Service Bus (OSB) provides message delivery services, based on standards including SOAP, HTTP and Java Messaging Service (JMS). It is typically designed for high-throughput, guaranteed message delivery to a variety of service producers and consumers. It supports XML as a native data type, while also offering alternatives for handling other data types.

OSB 12.2.1.4 and higher

C.2. DESCRIPTION OF WORK

The contractor shall provide support for FDA Oracle database servers, Oracle application servers, and Oracle Identity and Access Management server infrastructure and related database and applications performance monitoring products such as AppDynamics. In addition, the contractor shall provide support for enterprise-wide application migration, upgrades and deployment support. In the task orders, the Contractor shall be required to do one or more of the following tasks (required data format and tasks will be specified at the task-order level):

2.1. Project Management Tasks:

The contractor shall manage the work effort to coordinate among and provide services as required by individual Task Orders (TOs). Examples of activities may include:

Provide project management support that ensures that the scope, performance, schedule, and cost are controlled and consistent with this contract.

2.1.1. As stipulated in the task orders, provide the capability to plan, track, and report cost, schedule and performance for the effort required to provide O&M support and upgrades to FDA Oracle Application Servers and Databases.

2.1.2. Analyze current installations and provide strategic upgrade recommendations

2.1.3. Comply with reporting requirements stipulated in the task orders.

2.1.4. Schedule and provide resources for required application deployment tasks.

2.2. Operations and Maintenance (O&M) Support Tasks:

O&M support is an integral part of the day-to-day operation of a system. The contractor shall provide O&M support for FDA’s Oracle Application Servers and Databases as well as other software products and databases, specified by Government-issued TOs. The contractor shall provide ongoing O&M support for existing and new FDA servers and applications to include software patching, installs, server upgrades and re-hosting to existing and new FDA architectural platform(s) as required by FDA. The Contractor shall provision databases, middleware components, and application servers for the existing and new FDA applications. The contractor shall provision and provide O&M support services for the existing and new FDA applications. The Contractor shall implement FDA system software releases, install and configure databases and other related technology components, and other related Commercial Off-The-Shelf (COTS) products that are used by FDA systems. The Contractor shall performance analysis, conduct troubleshooting, develop plans, and write scripts and/or other documentation for implementation of the above. The contractor shall provide technical guidance to ensure a coordinated effort in promoting the software to the upper environments at the FDA Data Centers. The Contractor all maintain the system documentations and expected to support and participate in the System Security Annual Review for the FDA system and maintain ATO for Systems.

The TOs will provide tailored requirements that align with Phase 9 O&M activities and deliverables described within the Department of Health and Human Services (HHS) Enterprise Performance Life Cycle Framework (EPLC). See Attachment D – EPLC Framework v2 final for 508 compliant, for FDA EPLC information.

2.3. Database and Application Server Upgrade and Migration Tasks:

The contractor shall provide software version upgrades and hardware platform upgrades for FDA’s Application Servers and Databases as specified by Government-issued TOs. The TOs will provide tailored requirements that align with Phase 3 (Planning) through Phase 8 (Implementation) activities and deliverables described within the HHS EPLC.

The Contractor shall implement new upgraded designs, migration and patching procedures, and new database connection methods, to re-architect FDA’s database to the new Multi-Tenant architecture platform. This will include assisting and coaching the development teams with the new database platform.

In addition to the database related support activities, there are tasks associated with the upgrade of the middle-tier components. The contractor shall function as the process architect for middleware upgrades to the long-term support release process, including but not limited to creating schedules, identifying roles and responsibilities, and guiding the various contractor and application teams though the upgrade process.

These upgrade activities will also include migrating existing upgraded middleware servers to new hardware using the same or new operating systems. All of these upgrades and migration activities will be performed in the Development and Test environments at the White Oak Data Center (WODC) and in the Pre-Production and Production environments at the Ashburn Data Center (ADC) located in the Ashburn, VA as well as cloud based environments.

2.4. ORACLE Internet Directory (OID) and ORACLE Identity and Access Management (OIAM), Administration, New Development and Production Support Tasks.

The contractor shall manage the work effort to coordinate among and provide services as required by individual Task Orders (TOs). The Contractor shall provide support services for Oracle Identity Access Management (OIAM) Application Server Administration, Production Support which encompasses the Enterprise Single Sign-On (SSO) on development, test, pre-production and production that includes supporting Oracle 10g, 11g, 12c and higher versions concurrently. Additionally, the Contractor shall provide ad-hoc support for the Oracle Internet Directory (OID) and SSO environments in the FDA environments at all FDA data centers including WODC and ADC. Examples of activities may include:

2.4.1. Performance monitoring and tuning.

2.4.2. Planning, Configuration and implementation of latest OID and OIAM product installations.

2.4.3. Assist application teams with the design of role-based access controls through groups mapped in OID

2.4.4. Support application teams with updates to OIAM access policy definitions

2.4.5. Support and assist with testing of new custom application releases.

2.4.6. Design and support high availability configurations.

2.5. Enterprise Application Deployment Support:

2.5.1. Communication with application teams to determine resources required.

2.5.2. Detailed review of Version Description Documents to ensure required tasks are clearly specified and understood.

2.5.3. Execution of application deployment tasks as specified in VDD.

2.5.4. Assistance in application deployment testing and troubleshooting.

2.6. Transparent Data Encryption:

2.6.1. Develop Repeatable process for in place encryption of Oracle Databases to comply with agency standards.

2.6.2. Implement in place encryption of all agency Oracle Database systems.

2.6.3. Maintain standards, processes, and procedures to take encryption into account.

2.6.4. Develop and maintain strategy for backup and protection of encryption keys.

2.7. AppDynamics Application Performance Monitoring (APM) Operation and Maintain Support

The contractor shall provide professional services for operations and maintenance (O&M) of the FDA AppDynamics APM tools and support services to maintain and improve the AppDynamics based APM dashboards for the FDA shared, enterprise and critical applications. The contractor shall maintain and upgrade the current AppDynamics based APM solution running in the FDA data centers. The contractor shall work with other FDA system owners requesting the application performance monitoring services using the FDA APM solution and provide support in installing and configuring the AppDynamics agents for their servers as needed. AppDynamics O&M support services include:

2.7.1. Installation and configuration of the AppDynamics Controllers and monitoring agents in

Test, Pre-Production and Production environments.

2.7.2. Maintaining Configuration of the AppDynamics Agents for the FDA applications.

2.7.3. Maintenance of AppDynamics custom Dashboards for Application Performance monitoring.

2.7.4. System Security Annual Review for the FDA APM Solution and maintain ATO for APM

System.

2.7.5. APM system troubleshooting and providing support to application teams.

2.7.6. APM Training and maintaining the system documentations.

2.8 Cloud Migration support, Operation and Maintenance

Assist the government with implementing the overall enterprise cloud computing strategy at the FDA. This may include, but may not be limited to performing data and server migration to the cloud, assisting development teams with application deployments in cloud, configuring and maintaining hosts and operating environments, storage management, providing cloud security expertise and best practices, weighing the relative costs and benefits of cloud vs. on-premises computing resources, and handling other day to day operations such as project planning, transit gateway updates and firewall change requests. Other responsibilities include:

2.8.1 Guide development teams on how to build instances, servers, load balancers, databases and add different types of storage based on the existing TSD and cloud infrastructure

2.8.2 Assist in server/instance build and software configuration in the cloud

2.8.3 Evaluate tools and software being used in the cloud and provide recommendations on possible configuration changes for each server/instance

2.8.4 Provide advice on best practices on using financial monitoring tools provided by AWS services or other cloud service providers

2.8.5 Use best practices to guide and configure resource monitoring of instances, servers and other services in the cloud

2.8.6 Assist in configuration of automation tools such as Docker containers and deployments focused on the FDA cloud environment

2.8.7 Guide and assist in promoting installed software to the next environment in the cloud

(i.e. from Test to Pre-Production)

2.9 Transition Services (Optional Tasks)

The purpose of the Transition is to transfer expert knowledge, data, and artifacts that are used to support the FDA’s deployed or to be deployed Oracle Products from the incumbent Contractor staff and/or Government FTEs to the incoming Contractor staff efficiently and orderly to commence upon award of task.

2.9.1 Transition-In

The Contractor shall perform the following Transition tasks, but not limited to:

• Submit Transition Plan that reflect transition activities and timetables to include the sequence of the transfer of key system knowledge from the incumbent Contractors and/or Government FTEs, as well as risks with mitigation strategies, and issues.

• Identify Contractor staff required to manage the O&M activities for the FDA’s current Oracle Products and any planned upgrades, as stated in the task list.

• Present staffing plan to the COR and Data Management team for the on-going O&M task for review and discussion.

• Onboard Contractor employees, i.e., complete background screening; obtain FDA badges, laptops, network, and systems access.

• Ensure Contractor employees understand their roles and responsibilities along with the requirements of this Task Order, i.e. deliverables/timelines, deployment environment (e.g., Cloud Service Provider, WODC, ADC for on-premise applications), and required templates.

• Interview the COR, Data Management team, and/or business stakeholders to fully understand and access the current operational state of the various applications, processes, environments, and tools.

• Report Transition activities, risks and issues during the weekly status meetings.

• Ensure an understanding of the existing systems documentation, source code, systems architectures, and planned releases.

• Participate in transition meetings and activities as scheduled by the COR with the ServiceNow team and/or the incumbent Contractors to transfer knowledge and processes.

• Conduct an analysis of outstanding defects to establish, develop and deliver a defects baseline report, with the COR and/or the incumbent Contractors by the end of the Transition period.

• Participate in database and development activities with incumbent Contractor and/or FTE staff to gain awareness of FDA’s environments.

• Participate in the release scheduled, if available, during the transition period with the Data Management team and the incumbent Contractors.

• Participate in transitioning all RBAC information/forms, including certificates, software keys, etc. are transitioned.

2.9.2 Transition-Out

The Contractor shall facilitate the transition out of contracted activities and services to the Federal Government or to a follow-on Contractor by the end of the contract period of performance.

The Contractor shall provide transition out activities, to include a transition out plan, leading Technical Exchange Meetings (TEMs) with the successor to impart knowledge transfer of all EDRMP infrastructure platform processes, projects, systems, applications, and databases, as well as sustainment activities to meet the task. The contractor shall ensure the TEMs will detail the technology used for EDRMP projects and prototypes. During this period, the Contractor shall ensure no degradation in support provided under the task order. After the COR designated turnover date, the outgoing Contractor shall ensure all task order closeout activities and provide sustainment support to complete the transition.

Representative activities under this task area include but are not limited to:

• Submit Transition Out Plan that reflect transition activities and timetables to include the sequence of the transfer of key system knowledge to the Government FTEs.

• Provide FDA with current versions of all documentation developed under this contract, to include the native format for diagrams and attachments (e.g., Visio), even those embedded in documents

• Provide FDA with all licensing and renewal information, asset management records, software documentation, and training materials

• Provide FDA with a current inventory of all Government-owned assets used by the Contractor along with full support in the reconciliation of this inventory

• Provide FDA with full documentation of custom code, reports, process automations, scripts and configurations (not COTS source code) with applicable configuration management information

• Provide the successor with the ability to participate in other knowledge transfer meetings and opportunities to facilitate the transfer of information, processes, and data needed to continue the services being performed by the Contractor

• Participate in transitioning all RBAC information/forms, including certificates, software keys, etc. are transitioned.

C.3. DELIVERABLES AND MILESTONES

The acceptance of deliverables and satisfactory work performance required herein shall be based upon the timelines, accuracy and suitability of the deliverable. The specific deliverables and schedule for delivery shall be as agreed upon and documented with each new task order. All documents, plans, diagrams, presentations, etc., are to be submitted solely in electronic form and in the native file format of MS Word 2007, MS Excel 2007 or MS Power Point 2007 or higher versions. Only the COR that initiated the tasking has the authority to accept or reject deliverables.

3.1 IDIQ Summary Report: The Contractor shall provide a summary report of all IDIQ activities to the IDIQ COR and Contracting Officer on a quarterly basis. The summary report shall be delivered in the following format:

Section 1 – A short introduction covering the purpose and scope of work.

Section 2 – A List of Task Orders awarded, a short narrative of the effort and accomplishments, and a description of the labor categories provided for each task order.

Section 3 – A summary of the costs incurred during the reporting period and for the cumulative period of the contract. The costs will be broken down by hours per labor category with separation of the prime contractor and any subcontractors and detail compliance with 52.219-14, Limitations on Subcontracting.

Section 4 – Any other data the contractor deems appropriate.

3.2 IDIQ Monthly Progress Report: The Contractor shall submit monthly Progress Reports and meet with the IDIQ COR either in-person or telephonically at least once a month to discuss the status of all active Task Orders.

C.4. LOCATION, WORK SCHEDULE, AND TRAVEL

Work may be performed at Food and Drug Administration or contractor facilities. The location and schedule of performance will be specified in each individual task order. Any travel requirements will be also be stated in each task order.

C.5. SECURITY AND PRIVACY REQUIREMENTS

A. Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:

2) Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

a. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

3) Safeguarding Information and Information Systems. In accordance with the

Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an FDA network or operated by the Contractor on behalf of FDA regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party. This includes notifying the FDA Systems Management Center (SMC) within one (1) hour of discovery/detection in the event of an information security incident.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS/FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing your ISSO.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.

4) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II:

Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [ ] Low [ X ] Moderate [ ] High Integrity: [ ] Low [ X ] Moderate [ ] High Availability: [ ] Low [X ] Moderate [ ] High Overall Risk Level: [ ] Low [ X] Moderate [ ] High

Based on information provided by the Privacy Office, system/data owner, or other privacy representative, it has been determined that this solicitation/contract involves:

[ ] No PII [ X ] Yes PII

Personally Identifiable Information (PII). Per the OMB Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother’s maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [ ] Low [ X ] Moderate [ ] High

5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa). As implemented the term “handling” refers to “…any use of CUI, including but not limited to http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf marking, safeguarding, transporting, disseminating, re- using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for

Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

d. returned to FDA control, destroyed when no longer needed, or held until otherwise directed.

Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization and the FDA IS2P Appendix T:

Sanitization of Computer-Related Storage Media.

6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06- 16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS/FDA sanction policies and/or governed by the following laws and regulations:

a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

7) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).

8) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

9) Contract Documentation. The Contractor shall use FDA-provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.

10) Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.

c. All devices (i.e.: desktops, laptops, mobile devices, etc.) that store, transmit, or process non-public FDA information should utilize FDA-provided or FDA information security authorized devices that meet HHS and FDA-specific encryption standard requirements. Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use are compliant with FIPS 140-2. The

Contractor shall provide a written copy of the validation documentation to the COR.

e. Use the Key Management system on the HHS Personal Identification Verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys.

Encryption keys (PIV card) shall be provided to the COR upon request and at the conclusion of the contract. Upon completion of contract, contractor ensures that COR is able to access and read any encrypted data.

http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf

11) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the FDA non-disclosure agreement (3398 Form), as applicable. A copy of each signed and witnessed NDA shall be submitted to the CO and/or COR prior to performing any work under this acquisition.

12) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.

a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist procuring activity representative, program office and the FDA SOP or designee with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).

b. The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee in reviewing and updating the PIA at least every three years throughout the Enterprise Performance Life Cycle (EPLC) /information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

B. Training

1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable FDA Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract.

Thereafter, the employees shall complete FDA Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS and FDA training policies.

2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy and FDA Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Standard Operating Procedures (SOP).

http://inside.fda.gov:9003/downloads/administrative/forms/fda/ucm013733.pdf http://inside.fda.gov:9003/downloads/administrative/forms/fda/ucm013733.pdf

3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

C. Rules of Behavior

1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.

2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior (ROB) before accessing HHS and FDA data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines.

D. Incident Response

The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA SMC /Incident Response Team (IRT) teams within 24 hours, whether the response is positive or negative.

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.” The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.

A privacy breach is a type of incident and is defined by FISMA as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII.”

In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:

1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.

2) NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send FDA approved notifications to affected individuals as directed by FDA’s SOP.

3) Report all suspected and confirmed information security and privacy incidents and breaches to the FDA Systems Management Center, COR, CO, and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour of discovery/detection, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US-CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:

a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;

b. not include any sensitive information in the subject or body of any reporting e-mail;

and

c. encrypt sensitive information in attachments to email, media, etc.

4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information and HHS and FDA incident response policies when handling PII breaches.

5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents.

This may involve disconnecting the system processing,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .