Attachment 1 - Statement of Work.pdf

PDF 274 KB Posted

Attached to
XBRL Subscription Services for 130 Licenses. Federal contract opportunity
Solicitation number
503102-20-Q-0113
Issued by
Securities and Exchange Commission

About this file

This statement of work describes XBRL subscription services required by the Securities and Exchange Commission. The SEC seeks a contractor to provide 130 user licenses for an XBRL data and analytics service including all XBRL filings submitted to the SEC since June 2009. The service must allow searches by company name, ticker, CUSIP or CIK to build profiles and retrieve financials and ratios. Users must also be able to perform targeted searches matching tags and terms, query companies by filters, and access insider rosters and ownership data. The contractor's solution shall comply with all applicable laws and SEC policies including FISMA, Section 508, and relevant NIST standards. Pricing shall be proposed to maintain a complete and up-to-date set of XBRL filings within the service.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 1

Page 1 of 3 RFQ: 503102-20-Q-0113

DESCRIPTION/SPECIFICATION/STATEMENT OF WORK

XBRL Subscription Services for 130 Licenses

RFQ: 503102-20-Q-0113

1.0 Scope. The SEC intends to enter into commercial subscription agreements for 130 licenses for

Contractor-hosted XBRL data and analytic services. The data set accessed through the service must include all public XBRL filings submitted to the SEC via the EDGAR disclosure system since 30 June

2009.

2.0 XBRL Data and Analytic Services. This data set must be available at the time Offeror responds to this solicitation. Going forward, the service must add XBRL data and exhibits subsequently filed with the SEC to the repository on a timely basis.

The cost of maintaining a complete, up-to-date set of XBRL filings must be included in the price proposal. Offerors are encouraged to provide access to additional publicly available interactive data files (e.g. XML, XBRL) from the SEC such as the Forms 3/4/5 and the Mutual Funds Risk/Return

Forms (starting in December 2010), and from other U.S. Government sources such as the FDIC.

2.1 Service Access. The Offeror's service must be accessible via the Internet. I t must have an intuitive and user-friendly interface for accessing and analyzing the service's data via any computer connected to the Internet through a standard browser (e.g., Internet Explorer), an application plug-in, or both. The service should provide robust analysis and reporting features that will maximize the utility to the SEC of interactive SEC filing data. The Contractor must keep the associated technologies, data, and services up-to-date with relevant technology standards, and must keep the methodology (of searches and data requests), stored searches and analyses, and search and analysis history, secure and up-to-date.

2.2 Minimum Performance Requirements. The Contractor's service must also allow user to do the following:

1. Perform financial data searches for a supplied search term such as company name.

2. Perform metadata or financial searches for a supplied company ticker, CUSIP or CIK to build company profiles and financial statements for analysis.

3. Perform targeted searches that match user defined tags and location terms.

4. Retrieve individual company’s descriptive information, financials and/or ratios.

5. Query for companies based on specific filters or screening criteria.

6. Retrieve insider rosters and trading activity.

7. Access institutional ownership data for investor targeting.

3.0 Applicable Documents. The Contractor shall comply with all applicable laws, regulations, federal mandates, and SEC policies and procedures in performing the Contract. Applicable documents include the following:

3.1 Federal Requirements and Industry Standards:

a. Title II1 of the E-Government Act of 2002 (Pub. L. 107-347,44 U.S.C. Chapter 36), Federal

Information Security Management Act of2002 (FISMA);

b. Section 508 of the Rehabilitation Act of 1973, as amended (29 U.S.C. 794d) for system accessibility requirements;

Page 2 of 3 RFQ: 503102-20-Q-0113

c. Office of Management and Budget (OMB) Memorandum M-09-29, FY 2009 Reporting

Instructions for the Federal Information Security Management Act and Agency Privacy

Management;

d. OMB Memorandum M-03-22, OMB Guidance for Implementing the Privacy

Provisions [Section 208] of the E-Government Act of 2002, September 30, 2003;

e. OMB Memorandum M-00-13, Privacy Policies and Data Collection on Federal Web Sites, June

22, 2000;

f. OMB Memorandum M-99-18, Privacy Policies on Federal Web Sites, June 2, 1999;

g. OMB Circular A-130, Appendix III, Security of Federal Automated Information Systems, http:/Icsrc.ncsl.nist.gov/secplcy/a130app3.txt;

h. NIST, Guide to Secure Web Services, SP 800-95, Aug 2007;

i. NIST, Guide to Computer Security Log Management, SP 800-92, Sep 2006;

j. NIST, Guidelines for Media Sanitization, SP 800-88, Sep 2006;

k. N I S T , Computer Security Incident Handling Guide, SP 800-61 Rev. 1, Mar 2008;

l. NIST, Recommended Security Controls for Federal Information Systems and

Organizations, SP 800-53 Rev. 3, Aug 2009;

m. NIST, Guide for Assessing the Security Controls in Federal Information Systems, SP 800-53 A, Jul 2008;

n. NIST, Guidelines on Securing Public Web Servers, SP 800-44 Version 2, Sep 2007;

o. NIST, Risk Management Guide for Information Technology Systems, SP 800-30, Jul 2002.

3.2 SEC Rulemakings:

a. Interactive Data to Improve Financial Reporting, Securities Act Release No. 33-9002;

b. Interactive Data for Mutual Fund Risk/Return Summary, Securities Act Release No. 33-9006;

c. Amendments to Rules for Nationally Recognized Statistical Ratings Organizations, Exchange Act

Release No. 34-59342.

3.3 SEC Administrative Regulations (Available Upon Request):

SECR No. Title Date

24-1.2 Introduction of New Technology Into the Agency 04/15/2004

24-1.6 Enterprise Architecture 11/25/2002

24-04 Information Technology Security Program 10/04/2005

24-04.A01 Rules of the Road 06/23/2010

24-08 Management and Protection of Privacy Act Records and other Personally Identifiable Information

04/14/2010

3.4 Other Relevant Security Policies and Procedures (Available Upon Request):

Document No. Title Date

OD 24-04.01 Security Policy, Program Management, and

Organizational Security

12/14/2005

OD 24-04.04 IT Security Operations and Communications Security

Management Program

03/20/2006

OD 24-04.06 IT Security Access Management Program 12/12/2005

II 24-04.06.01 Identification and Authentication 07/09/2008

II 24-04.06.03 Access Control 04/06/2006

OP24-04.08.01.03 Information Security Impact Analysis 09/09/2009

Page 3 of 3 RFQ: 503102-20-Q-0113

OD 24-04.09 IT Security Business Continuity Management Program 12/12/2005

OD 24-04.10 IT Security Compliance Program 04/12/2006

II 24-04.10.01 IT Security Certification and Accreditation 06/29/2005

II 24-04.10.02 IT Security Risk Management 12/22/2005

II 24-04.01.01 System Security Planning 12/29/2005

3.5 OIT Section 508 Policies and Procedures (Available Upon Request):

Document No. Title Date

00-35-010-001.0 Access to Electronic and Information Technology 10/09/2001

00-35-011-001.0 OIT Section 508/Rehabilitation Act Compliance

Standards and Guidelines 10/09/2001

00-35-012-001.0 Section 508/Rehabilitation Act Design Guidelines 10/09/2001

00-35-015-001.0 Section 508/Rehabilitation Project Management Checklist 10/09/2001

0IT-00020-001.1 OIT Section 508/Rehabilitation Act Technical Testing

Reference Guide

10/31/2002

II24-06.06.03.T01 Section 508/Rehabilitation Act Compliance Certification 07/30/2008

The Contractor shall use any documents and standards that supersede the above-cited documents during the course of work under this contract.

File details come from the government source that posted it. Updated .