Attachment 1_Statement of Work (SOW).pdf

PDF 478 KB Posted

Attached to
Engineering and Application Support Services Federal contract opportunity
Solicitation number
FDA-SSN-125075
Issued by
Department of Health and Human Services Food and Drug Administration Office of Acquisition and Grant Services

About this file

This document is a Statement of Work (SOW) for a federal contract opportunity to acquire DevSecCXOps, Innovation, Modernization, and Engineering Services to modernize the IT infrastructure and application environments for the Food and Drug Administration (FDA).

The SOW outlines key objectives such as infrastructure modernization, mobility, cloud adoption, technology innovation, and application modernization. It describes various task areas including transition activities, project/task order management, innovation services, cloud computing/cloud adoption, enterprise architecture support, application design and integration, prototyping, infrastructure modernization, DevSecCXOps engineering support, endpoint engineering services, and microservices development. The contract has a 5-year ordering period with a $100 million total ceiling value, and work will be performed at the contractor's location as well as FDA facilities. The related federal contract opportunity is a pre-solicitation for Engineering and Application Support Services, issued by the FDA Office of Acquisition and Grant Services.

View the file

Other files for this federal contract opportunity

Other files attached to Engineering and Application Support Services, newest first.
File Type Posted
SSNT_125075_Amendment_0001.pdf PDF
Attachment 1_SOW_updated_Amend_0001.pdf PDF
SSNT_125075.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CTO Engineering and Application Support Contract

Office of Digital Technology and Technology

FY25 CTO Engineering and application Support BPA

Statement of Work (SOW)

1. Introduction The Food and Drug Administration (FDA) requires DevSecCXOps, Innovation, Modernization, and Engineering Services to modernize the IT infrastructure and application environments to support FDA’s mission which is responsible for protecting the public health by ensuring the safety, efficacy, and security of human and veterinary drugs, biological products, and medical devices; and by ensuring the safety of our nation's food supply, cosmetics, and products that emit radiation.

2. Background

2.1 Organizational Background

The FDA employs more than 20,000 scientific, technical, and support personnel that are responsible for protecting and promoting the public health through the regulation and supervision of food safety;

tobacco products; dietary supplements; prescription, and over-the-counter pharmaceutical drugs (medications); vaccines; biopharmaceuticals; blood transfusions; medical devices; electromagnetic radiation emitting devices (ERED); veterinary products; and, cosmetics.

One of the ways that FDA advances its broad public health mission is by working to transform administrative and scientific systems, along with infrastructure, to support FDA operations. Specifically, FDA Office of Digital Technology (ODT) manages IT and other related services including technical oversight of system development plans, processes, policies, and methodologies and management of IT infrastructure to ensure FDA has a robust IT foundation that enables interoperability across FDA and allows development of enterprise-wide systems necessary to meet FDA's mission of promoting and protecting public health in an efficient, effective, productive, and timely manner. ODT strives to consistently meet the business needs of its customers providing services that adhere to the agency's IT standards and policies.

The ability to rapidly develop and deploy information systems and resources plays a critical role in enabling the FDA’s efforts to transform agency operations and respond quickly and accurately to emerging scientific, technological, and economic trends affecting its regulatory mission. To support rapid development and deployment, the FDA is increasingly leveraging methodologies to help streamline FDA modernization efforts, such as Agile development (e.g. SCRUM, Kanban), Information Technology Infrastructure Library (ITIL), IT Asset Management (ITAM), DevSecCXOps, Containerization, Microservices based architecture, Software Defined Networking (SDN), among other contemporary innovations.

The Office of Digital Technology (ODT) Information Technology Strategic Plan was established to provide an effective enterprise architecture aligned with IT environments to define interconnecting processes and workflows, standardization, and cost-effective measures driven to improve customer satisfaction, quality, security and while promoting automated delivery of service. The approach that ODT is taking consists of strategic initiatives spanning three general areas: People, Process, and Technology. These initiatives are being tracked as part of an overall set of ODT’s Strategic Plan Milestones and laid out in the CIO Council Strategic Roadmap.

Each component of ODT is responsible for different functional areas of providing information technology services to the Agency but works collaboratively together to accomplish the strategic mission. The Office of the Chief Technology Officer (CTO) collaborates as a unified IT support system for the agency. The Office of Innovation conducts technology surveillance, prototyping, and the advancement of new technologies in conjunction with the FDA IT Strategic mission. This contract will cover the work of and Division of Application Services (DAS) and Division of Engineering implementation ( DEI) to enhance and modernize the IT infrastructure. Both teams are responsible for ensuring excellence through the design, development, and application of information technology using proven and emerging strategies to reduce cost, improve services, reduce security and system failure risks to support the FDA in protecting the public health. Increased focus on the delivery of services in alignment with approved requirements.

ODT strives to follow the ITIL model, each functional area participates in multiple phases.

2.2 Technical Background

FDA currently has a data center contractor to manage and operate its data centers and IT infrastructure, provide cybersecurity support to protect sensitive information at the data centers, and maintain an inventory of the FDA’s IT hardware and software. The operations of these services and locations are not included in the scope of this contract. These data centers will require modernization to meet 21st century capabilities. However, it is anticipated the specific tasks areas will impact the locations below. This requirement includes providing architectural, engineering, and subject matter expertise on a variety of IT issues that impact FDA’s enterprise infrastructure. This requirement includes implementation engineering which includes strategic engineering, new technologies, researching new solutions etc. The contractor will work with the Engineering Project Teams for the transition of new technology into operational status and work with the FDA Data Center contractor. Until explicitly instructed by the FDA

Contracting Officer, all other forms of Operational Engineering, such as operational changes to infrastructure are approved via the FDA change control process (i.e., updates, patches, and configuration changes) and break fix solutions are out of scope for this contract. The locations of the FDA Data Centers are listed below in Table 1:

Table 1 - FDA Data Center Locations

Data Center Address FDA ODT Ashburn Data Center (ADC) (Also known as “Contractor Hosted Data Center” or

CHDC)

44480 Hastings Drive Acc4 Data Center Ashburn VA 20147-6043

FDA ODT White Oak Data Center (WODC)

Building 2 10903 New Hampshire

Ave.

Silver Spring, MD 20993

FDA Wiley Scientific Data Center

5001 Campus Drive College Park, MD 20740

FDA ODT NCTR Data Center

Building 5 and Building 10 3900 NCTR Road Jefferson, AR 72079

Additional field laboratory and office locations are throughout the US and a few international sites. A complete listing can be found via https://www.fda.gov/downloads/ICECI/Inspections/IOM/UCM123522.pdf.

FDA has begun migrating applications to various cloud service providers, however, more effort is anticipated to support this initiative through the duration of the period of performance for this BPA.

FDA remains committed to its cloud presence and continues to establish and implement the Cloud Smart Initiative. In late 2017, ODT established an initial cloud governance model to assist with the implementation and usage of cloud resources. This model includes establishing two teams to handle various areas of a typical cloud deployment. The Cloud Regulatory, Engineering, and Steering Team (CREST) handles all cloud governance matters including the development and input into the cost allocation model, review and approval of new cloud technologies for the agency and maintains cloud related policies and procedures for the agency. The Cloud Advisory & Implementation Team provides technical expertise to FDA application project teams on new and existing cloud projects. Additionally, this team assesses the requirements and architectural review of each project moving into the cloud along with providing alternatives to match the business requirements. FDA has developed a trusted set of cloud solutions that are targeted to be leveraged as part of the enterprise. Table 1 provides a current listing of IaaS, PaaS, and SaaS offerings that FDA considers part of our “Trusted Cloud Platform”.

Table 1 – Trusted Cloud Service Providers

Cloud Service Provider CSP Service Model Type Actively Using

Amazon Web Services (AWS) GovCloud

IaaS Application Development/Hosting https://www.fda.gov/downloads/ICECI/Inspections/IOM/UCM123522.pdf https://www.whitehouse.gov/briefings-statements/omb-announces-cloud-smart-proposal/ https://www.whitehouse.gov/briefings-statements/omb-announces-cloud-smart-proposal/

Amazon Web Services (AWS) East/West

IaaS Application

Salesforce PaaS Application

Appian Cloud PaaS Application

Cloud File Sharing (BOX) SaaS File Sharing

ServiceNow SaaS IT Service Management

Microsoft Outlook 365 EaaS Email

WebEx SaaS Online Meeting

SkyHigh SaaS Access Security

ODT continues to evolve in the modernization of its Software Development Lifecycle. One discipline FDA and ODT is looking to establish is DevSecCXOps. DevSecCXOps applies agile values, which emphasize discipline, response to change, and collaboration, with a focus on delivering working software, to tasks such as deployment, environment configuration, monitoring and maintenance.

"DevSecCXOps," made up of "dev" from "development", “sec” from security, and "ops" from "operations," addresses the schism that exists between the two teams. DevSecCXOps inherits from methodologies such as agile and lean.

Therefore, agile is a prerequisite for DevSecCXOps. DevSecCXOps extends Agile's cross-functional team consolidation of business analysts, developers, and testers to include operations staff (for example, infrastructure, production operations and security personnel). Using these methodologies, FDA has developed a continuous delivery/continuous integration (CI/CD) pipeline for application delivery, however, it is anticipated that there will be some additional engineering needed to complete this task.

Currently, FDA has components of DevSecCXOps sprinkled throughout the organization including leveraging Puppet for deploying applications in a defined and repeatable process. The Operations and Maintenance of this CI/CD pipeline is out of scope for this contract; however, it is anticipated that the contractor will provide onboarding and engineering support for new applications moving to this application delivery model. On the mobility side, ODT continues to provide Government Furnished Devices to FDA employees and contractors in support of the FDA mission. Additionally, FDA Centers/Offices have been purchasing and building apps to help support their mobile needs and ODT continues to develop a mobile “playbook” to help guide these business units set requirements. To support these various initiatives, FDA has established a Mobile Governance Board which focuses on governance with a vision complemented by a technology roadmap. This entity focuses on mobile devices, applications, lifecycle management, and evolving the governance model for mobile devices. FDA requires the infrastructure, processes, and tools to enable the availability, usability, connectivity, inter-operability, security, analysis, and visualization of the vast array of data types and processes that stream into, through and out of FDA on a daily basis. Overtime, individual projects have housed the agency’s data in individual, siloed applications that are not able to share data with each other. This has hampered the agency’s ability to conduct an efficient review process, conduct risk-based analytics, and ensure seamless collaboration with private and public partners. FDA needs capabilities to promote global data-sharing, risk analytics, and reliance on third parties that is envisioned in FDA’s 2011 special report, Pathway to Global Product Safety and Quality. As a result, there is a need to make data available and consumable within and across the FDA and to enable a learning and knowledge network that facilitates risk-based analytics on a scale that routinely handles global sources and volumes of data. The need to establish solid data governance principals around new applications.

3. Objective The primary objective of this effort is to acquire professional DevSecCXOps, Innovation, Modernization, and Engineering Services to modernize FDA’s applications and infrastructure which includes IT architecture, prototyping, deploying, and delivering new technical solutions for ODT. ODT expects to work on projects such as establishing a best-in-class technology strategy, consult and provide expertise on establishing and enhancing use of cloud computing services, develop new systems and processes for managing and monitoring IT. It is envisioned that this acquisition will facilitate a contractor staffed team of key personnel, with subject matter experts being added and removed from the staffing as needed to support the projects and dynamic IT priorities.

The scope of this SOW includes working within established FDA guidelines, standards, and Enterprise Performance Life Cycle (EPLC) policies, processes, and templates, which include both Waterfall and Agile methodologies.

able 2 – Key Objectives

Objective Key Success Criteria

Infrastructure Modernization - Improve performance, stability and monitoring capabilities of the overall FDA network and unified communications infrastructure to deliver consistently reliable services to the end user community.

1. The ability to define, manage, and quantify performance and customer expectations.

2. Systematic improvements to parts of the infrastructure which are unstable.

3. The establishment and communication of performance-based SLAs.

4. A proactive infrastructure management capability with better monitoring, cross team reporting and root cause analysis.

Mobility - Define a comprehensive mobility strategy and implement capabilities to support the increasing mobile work needs of FDA staff.

1. Implementation of a comprehensive, standardized mobility strategy that directly support FDA business requirements.

2. A solution that adheres to FDA ODT standards and is compliant with all federally mandated information security policies and requirements.

Cloud - Define and enhance FDA/ODT strategy to maintain, implement, and leverage the various cloud service models for improved performance and cost savings.

1. Create and establish a FDA cloud strategy that incorporates governance, security, standardization, and key performance indicators for cloud adoption.

2. Implement and assist with the migration of FDA’s on-premises data center/IT infrastructure application and services to a FedRAMP-certified cloud service provider and post-migration managed services with an integrated platform for monitoring, managing and optimizing the cloud infrastructure

Technology Innovation – Enhance FDA/ODT strategy to maintain its innovation program that supports an emerging technology adoption process, understand future business blind spots, reduce risks of misunderstood technologies to ultimately support business transformation efforts.

1. Implement a successful technology evaluation process to quickly identify enterprise technologies to meet FDA business needs.

2. Review and identify new technologies that can accelerate delivery of the agencies mission

3. Utilize human centric design techniques that are incorporated with application modernization efforts.

Application Modernization – enhance FDA/ODT application modernization strategy to include tools, techniques, and process that delivers business value faster

1. Establish a roadmap to application standardization to achieve business value.

Business Continuity - Development and implementation of a comprehensive disaster recovery strategy that would ensure the continuity of business operations and maintain the availability of mission critical systems, infrastructure, and vital records.

1. Development and implementation of a comprehensive disaster recovery solution that provides business continuity for critical applications and vital records.

2. A proactive capacity planning process to ensure proper infrastructure and systems growth.

4. Task Areas FDA will issue individual Orders for the Contractor to provide DevSecCXOps, Innovation, Modernization, and Engineering Services to modernize FDA ODT IT infrastructure as needed.

Representative tasks to be performed by the Contractor are included in the following task areas below:

The task areas are as follows:

1. Transition Activities

2. Project/Task Order Management

3. Innovation Services

4. Cloud Computing/Cloud Adoption

5. Enterprise Architecture Support

6. Application Design and Integration

7. Prototyping

8. Infrastructure Modernization

9. DevSecCXOps Engineering Support

10. Endpoint Engineering Services

11. Microservices Development

4.1 Transition Activities

Transition In

As tasked, the Contractor shall provide Transition-In support in order to provide an orderly transition from the incumbent Contractor to the Contractor. The Contractor shall ensure minimal disruption to the current system and operational activities. The purpose of the transition is to transfer expert knowledge, data, and artifacts that are used to support applications from the incumbent contractor to the successor contractor efficiently and orderly. Detailed requirements and schedule for any transition activities will be defined at the Order level.

While individual orders will detail specific requirements, the representative task include but are not limited to:

• Develop a Transition-In plan;

• Participate in Transition-In meetings;

• Participate in knowledge transfer activities such as “shadowing”;

• Conduct and coordinate all knowledge transfer activities such obtain secure badging for team personnel;

• Ensure complete understanding of the documented requirements

• Ensure complete understanding of the ODT technical environment

• Ensure complete understanding of the current implementations and activities

• Ensure staff identified as key personnel are available to work with Subject Matter Experts (SME) from the Government and the incumbent Contractor immediately after Order award;

Transition Out

The contractor shall provide support services to the orderly transition of functions from this contract to the FDA and/or successor contractor. The contractor shall be the lead on the transition activities during the transition period, leading Technical Interchange Meeting (TIMs) with the successor to impart complete and full knowledge transfer of ODT projects, systems, applications, and databases, as well as sustainment activities that are in progress to include the technology used for all projects initiated under this contract. During this period, the contractor shall ensure no degradation in support to the Government. At the COR designated turnover date, the successor contractor shall assume full responsibility of the contract, while the outgoing contractor focuses on contract closeout activities and providing sustainment support to complete the transition.

While individual orders will detail specific requirements, the representative task shall include but are not limited to:

• Providing the FDA with current versions of all system and user documentation, to include the native format for diagrams (e.g., Visio), even those embedded in documents

• Providing FDA all licensing and renewal information, asset management records, software documentation, and training materials;

• Providing FDA with a current inventory of all Government-owned assets used by the Contractor along with full support in the reconciliation of this inventory;

• Providing FDA with current versions of all CONOPS, operational procedures, standard operating procedures, guidelines, performance reports, specifications for hardware and software, and other pertinent information needed to continue the services being performed by the Contractor, i.e., any documentation developed under this contract Within 30 days of contract award, the BPA COR will identify the repository will all documentation is to be stored; however, it will be the contractor’s responsibility to update/maintain the repository for all orders.

• Providing “shadowing” and other knowledge transfer plans, meetings and opportunities to facilitate the transfer of information, processes, and data needed to continue the services being performed by the Contractor;

• Providing full source code sets (not COTS source code) with configuration management information; and,

• Providing up-to-date-EPLC and program/project management documents

• Providing COR with a current inventory of all Government-owned assets used by the Contractor along with full support in the reconciliation of this inventory

4.2 Project/Task Order Management

The Contractor shall establish and maintain necessary controls, TO management oversight, documentation, reporting, customer support, and notification functions as well as ensuring that required tasks stay on track and milestones are met. The Contractor shall manage its own personnel, sub-contractors, and consultants, including providing all necessary reports, deliverables, plans, and controls. The Contractor shall ensure all PM duties performed under this contract are executed in accordance with Project Management Institute (PMI) standards, defined in the Project Management Body of Knowledge (PMBOK) guide. The Contractors shall only utilize FDA-approved applications, COTS, and custom-built software for contract task management, reporting, and resource management.

Accordingly, the Contractor shall:

Program Management

Develop and maintain a Task Order Management Plan (TOMP) describing the technical approach, organizational resources and management controls to be employed to meet the cost, performance and schedule requirements throughout task order execution. The TOMP shall include a Subcontractor Management Plan, Risk Management Plan, Communications Plan, Task Management Plans, System

Security Plan for the General Support Systems, Staffing Plan, and Quality Assurance Plan (QAP). The QAP, at a minimum, shall include a Performance Requirements Summary (PRS) and Performance Measurements Plan, and a Document Change Management Plan.

a. Prepare all required CR and Information Technology Investment Management (ITIM) request forms in accordance with FDA Change Control and ITIM processes and procedures.

b. Coordinate all required on-boarding and off-boarding activities including the following:

i. HHS ID Badge Request Form (HHS-745)

ii. E-QIP Initiation Form

iii. Standard Form 85 or 85P

iv. Commitment to Protect Non-Public Information (FDA 3398 Form)

v. User account requests (FORM FDA 3530)

vi. Security Awareness Training

vii. Submit new or replacement personnel resumes to the COR for review. The COR will verify that the new personnel meet the requirements of the proposed Labor Category and Statement of Work (SOW) before the candidate starts the FDA on-boarding process.

viii. Provide the COR with a minimum of 30 days’ notice prior to a change to a designated Key personnel resource due to reassignment. The Contractor shall provide the COR with the resume of the key personnel candidate for review and approval before the candidate starts the FDA on-boarding process.

c. Create, review and maintain all Order documentation.

d. Update, review and maintain the Order Management Plan related to overall O management.

e. Create, manage, and revise all work plans and Work Breakdown Structures (WBS)

f. Identify designated points of contact to provide information on task progress, issues, and concerns.

i. Create and maintain an organization chart by Functional Area.

ii. Maintain a list of personnel system, application and building access. Ensure the list is updated as staff are on-boarded and off-boarded.

g. Track and manage TO management cost expenditures.

h. Respond to data calls regarding financial status and other TO information.

i. Create the required TO Monthly Reports (including activities performed and planned risks, financial information, and metrics).

j. Prepare and conduct periodic progress reports when requested by the COR.

k. Identify improvements by reviewing TO processes and procedures and document resolutions and solutions.

l. Coordinate all required Contractor staff training. This includes FDA mandated training courses such as, FDA Records Management Training, Computer Security Awareness Training, and IT Security Recertification.

m. Prepare and import all required data into the FDA project management tool.

n. Create, manage, and control all project schedules.

o. Perform all TO risk management.

p. Manage to the TO communications plan to ensure adequate communication between all stakeholders.

q. Manage all TO deliverables and resources. Create a Deliverable Repository, a single FDA-accessible location where all deliverables will be posted.

r. Implement quality control measures.

s. Track and report all TO metrics.

Project Management

In addition to management of the TO tasks, the Contractor shall also perform project management activities that support the FDA Infrastructure and projects under this TO. The Contractor shall document and update their detailed approach for managing FDA Infrastructure and projects in the TOMP. These activities shall include managing:

a. scope

b. milestones

c. deliverables

d. requirements

e. schedule

f. resources

g. costs

h. risks and issues

i. processes

The Contractor shall manage all required activities to ensure alignment with multiple schedules and requirements across the FDA Infrastructure and projects. This could also involve alignment with Government directives that impact the FDA Enterprise. Project managers should be identified for individual projects when the level of work is beyond regular operational tasks. The work includes the following activities:

i. Multi-discipline and multi-system stakeholder requirements negotiations and resolution

ii. Interface negotiation between the FDA and other entities

iii. Internal and external systems interfaces negotiation

iv. Project Schedule alignment

v. FDA systems software licenses tracking, coordination, and documentation

vi. FDA systems hardware warranty tracking, coordination, and documentation

vii. Identification of resource limitations

viii. Risk identification and mitigation

As necessary, the Contractor shall work with the government to reprioritize TO activities to refocus TO work efforts and support activities to address new or changing FDA Business and ODT.

4.3 Innovation Services

The Contractor shall provide professional services of various skill levels necessary to consult with FDA on in developing and advancing a sustainable innovation program. This program encourages creativity and experimentation, as well as the development of the skills necessary to perform effective investigation and evaluation of innovative projects.

4.4 Cloud Computing/Cloud Adoption

The contractor shall provide various levels of expertise in the design, creation, and execution of an ODT cloud adoption strategy. The contractor shall provide resources to support to review selected applications and develop the artifacts necessary to initiate their delivery into cloud-based environments, including but not limited to business cases, assessments, and work scope. The contractor shall provide staff with development capability and necessary skills to support a cloud environment and facilitate integration.

The contractor shall provide integration services and cloud architecture migration expertise, cloud management support to the FDA’s cloud teams to include providing best practices for cloud governance, cloud native application design, cloud strategy, and overall cloud adoption services.

The contractor shall meet the following business objectives:

• Enable strategic decisions by FDA to effectively migrate applications to the cloud, maximizing cost reduction and efficiency of IT environment.

• Provide maximum alignment to Federal Data Center Consolidation Initiative (FDCCI) requirements and cloud migration mandates and requirements, amplifying FDA’s ability to achieve management objectives.

• Provide cloud migration services that accommodate considerations from an enterprise perspective including impact on FDA’s business units, contracts, management, and technical components (application, infrastructure, and security).

• Provide all support operations necessary to fully develop and deliver services for the appropriate phases.

While individual orders will detail specific requirements, the representative task for Cloud Computing services to be performed under this BPA include but are not limited to:

• Enable strategic decisions by FDA to effectively migrate applications to the cloud, maximizing cost reduction and efficiency of IT environment.

• Provide maximum alignment to Federal Data Center Consolidation Initiative (FDCCI) requirements and cloud migration mandates and requirements, amplifying FDA’s ability to achieve management objectives.

• Provide cloud migration services that accommodate considerations from an enterprise perspective including impact on FDA’s business units, contracts, management, and technical components (application, infrastructure, and security).

• Establish cloud adoption project plans with validated business, technical, cybersecurity, and reporting requirements

• Provide daily, weekly and monthly reporting deliverables as defined by Trusted Cloud Platform team

• Provide recommendations on the long-term sustainability of the ODT cloud environments, to include the number and skill sets of staff members required. Recommended structure must allow FDA/ODT to leverage the flexibility and diverse capabilities required by a hybrid, multi-cloud, management and service organization including but not limited to prototyping infrastructure, data analysis, cost tracking and capacity estimation services as examples.

• Assess readiness of mission IT organizations, application owners, policy and process updates to support modern digital practices and cloud computing environments

• Assess the current state of cloud governance within FDA/ODT, and suggest to the ODT leadership alternative approaches from other successful cloud governing models in both commercial and governmental organizations.

• Provide expertise for brokering multiple cloud platforms and migration activities to prioritize, manage, and report on migration tasks

• Ensure that applications meet FISMA security requirements, and leverage FedRAMP security standards and guidelines.

• Review current FDA/ODT cloud architecture patterns including networking, approved services and identity related considerations. Suggest to ODT leadership new patterns and/or modifications to existing patterns.

• Provide technical subject matter expertise to support the cloud environments managed on an enterprise basis by FDA/ODT.

• Revise the list of cloud environments to reflect all services in use within FDA, as well as services not currently in use but desired by FDA, its mission areas and component agencies.

• Provide subject matter expertise in security and compliance requirements for federal cloud consumption, promoting and documenting a modular, iterative, enterprise approach to Authorities to Operate

• Review agency security and architecture needs across several dimensions: shadow services, data governance, privacy and confidentiality, access, identity policies, and overall IT governance including FITARA

• Provide subject matter expertise on strategic planning for all enterprise-level and agency-level IT infrastructure optimization, networking, and data center programs

• Review and analyze related agency and government planning artifacts to provide subject-matter expertise on matters relating to efficiency, cost-modeling and cost-benefit-analyses

4.5 Enterprise Architecture Support

The Contractor shall provide the skills and subject matter expertise necessary to support FDA’s Enterprise Architecture activities, in response to Office of Management and Budget (OMB), Health and Human Services (HHS) and General Accountability Office (GAO) mandates.

While individual orders will detail specific requirements, the representative task of the EA activities include but are not limited to:

• EA Program Planning – The contractor shall assist the Enterprise Architecture team in developing and maintaining an EA Program Management Plan (EA PMP), based on industry best practice, as well as mandates and governance organizations which are unique to the FDA. The existing EA PMP will be provided upon award of an EA task-order.

• Current State (“As-is”) Architecture Modeling – The contractor shall maintain FDA’s Current- State Architecture on an ongoing basis using HHS and FDA provided tools. Previously, the primary tool was provided by HHS, based on Troux Metis, but that tool is currently being migrated to a yet-to-be-determined tool, likely some combination of RSA Archer and ServiceNow. Whatever tool is used, data-elements to be captured and maintained for the EA current state likely include (depending on what tool replaces Troux Metis):

o Investment o IT System, and associated information, such as:

Technologies (both hardware and software) Database servers Application servers o Federal Enterprise Architecture (FEA):

Performance Reference Model (PRM) Business Reference Model (BRM) Data Reference Model (DRM) Application Reference Model (ARM) Infrastructure Reference Model (IRM) Technology Reference Model (TRM) Security Reference Model (SRM)

• Current State Architecture Reporting – Fixed/standardized reports, as well as “ad-hoc” one-time reports shall also be produced by the contractor as-needed, based on the Current State Architecture Modeling data collected and entered.

• IT System Roadmaps – The contractor shall develop IT System Roadmaps as part of FDA’s overall IT modernization activities, to document modernization planning from the current-state to the future state. IT System Roadmaps will include information such as:

o Business Capability – The “line(s) of business” applicable to the IT System.

o IT Systems Included – The IT system(s) included (an IT System Roadmap can consider multiple IT systems at the same time), along with a description of each IT system(s).

o Technologies – Technologies associated with each IT system, both hardware and software, including information about the technology category and end-of-life planning.

o Microservices – Proposed reusable modular components suitable for an Application

Programming Interface (API) or Enterprise Service Bus (ESB) environment, based on the Business Capability and technology analysis indicated above.

o Findings and Recommendations – To analyze areas such as:

Technology Drivers System/Technology Relationships Current-state Technology End-of-Life determination Promising new technologies Technology Standard Recommendations IT Service Recommendations Implementation recommendations, regarding the strategic and tactical approaches o Timeline – A timeline, summarizing the chronological aspects of recommendations.

• Reference Architectures – The contractor shall also provide detailed reference architectures – basically engineering summary documentation – for both current-state (a.k.a. “as-is”) and future-state (a.k.a. “to-be”) . Reference architectures will include (adjusted as appropriate depending on the needs for current-state or future-state documentation) information such as:

o Mandates – Applicable mandates and constraints.

o Business Capabilities – The Business Capabilities that the IT Capability Blueprint would support. Additionally:

Identify possible microservices at a high level Decompose Business Capabilities to level 4 and determine what services are required – decompose to lower level microservices and make recommendations.

o Requirements – The requirements that the IT Capability needs to satisfy, as applicable, such as:

Business requirements Technical requirements (functional & non-functional) Data requirements o Requirements Ranking – Rank requirements, based on stakeholder input.

o Solution Alternatives – One or more solution alternatives, describing, as appropriate:

Software products involved Hosting environment (in-house, Cloud, etc.)

Customization required For HVAs, Identify ARM, User System Services and identify any redundancies Gather information on Information Exchanges, Subcomponents to determine system dependencies Identify associated technologies and services of system dependents Perform gap analysis and identify duplicative (redundant) systems o Solution Selection Recommendation – A recommended solution, from the pool of solution alternatives, based on analysis of the requirements ranking.

o Design Template – A reusable architectural design, which can be leveraged in IT projects, FDA-wide.

• Target Architecture – The contractor shall develop an FDA End-State Architecture, based in part on various Target Architecture deliverables provided by prior contractor and FDA staff. The Target Architecture will provide a future view of FDA’s IT architecture to be realized over the next three to five years. As appropriate, the Target Architecture will be developed as a “federated” document set, with a summary-level Target Architecture, and associated Reference Architectures and IT System Roadmaps as described above.

• Data Calls – The contractor shall respond to data-calls relevant to Enterprise Architecture and Detailed Requirements activities from FDA and external sources (e.g. HHS, OMB, Congress, etc.), gathering, compiling and documenting data-call results as appropriate to the associated data-call.

• Presentations – The contractor shall prepare presentations to a broad variety of FDA stakeholders on subject areas listed above, and as needed, participate in meetings.

4.6 Application Design and Integration Services

The Contractor shall provide the skills and subject matter expertise necessary to consult with FDA customers on specific solutions and technologies that ODT may deploy as a prototype or pilot. The contractor will interact with FDA business units and experts to gain understanding of requirements and translate those requirements and other architectural-level designs, specifications, and inputs (including constraints) into product and solution recommendations as well as designs that may be implemented.

The contractor shall generate assessments, reports and recommendations on products and solutions researched to: ODT on the feasibility of using these products in the FDA’s IT enterprise, recommend a configuration or product, and provide designs and details to be used for a prototype or pilot.

The contractor shall provide subject matter expertise around architecture, design, and development of service-oriented architecture (SOA), Microservices Architecture (MSA), and other integration platform solutions to allow information sharing and management between business partners, processes, and systems–and to help enable effective end-to-end business processes.

The Contractor may be tasked to research and evaluate recommended solutions and develop technical specifications.

While individual orders will detail specific requirements, the representative tasks shall include but are not limited to:

• Meeting with experts and customers to refine high-level, strategic, and business requirements into tactical and technical requirements.

• Meeting with experts and customers to consult and provide “ask-the-expert” type guidance for customer next steps to move a customer idea toward an innovative solution or prototype.

Example: Customers have a business need or suggestion for improvement- consultants would meet with the customer for one-on-one discussions about the potential for moving their idea forward. These interactions would result in guidance to the customer or recommendations to further investigate. These interactions would typically be in person and not require more than meeting-summary style write-ups (e.g., meeting minutes) of the consulted advice.

• Identify equipment, technologies, software, systems, tools, and techniques to satisfy requirements and design specifications to include 508 specifications.

• Research and report on specific products, technologies, and concepts.

• Perform product assessments (e.g., market research as well as hands-on tests and trials) and generate reports and recommendations.

• Generate system components lists, product cost comparisons for planning and budgeting, technical specifications and technical requirements and tactical level designs that may be used to acquire and/or build systems or components.

• Analyzing and reporting on the impact of infrastructure, connectivity, capacity, and other changes to the Enterprise environment.

• Engineering, troubleshooting, devising connections between systems and endpoints (e.g., workstations, mobile devices, external systems, and data sources)

4.7 Prototyping

Components and systems that ODT selects or is directed to implement start as smaller contained deployments and then are transitioned to other FDA Divisions and Offices for full-scale production operations - these implementations are referred to as pilots. Pilots are defined to be systems implemented with the intent of becoming production systems. Pilots will have multiple stages that expand the number of participants or the level of functionality in each successive phase. Pilot participants begin with members from the FDA’s IT organizations and expand to incorporate designated personnel from business units (names provided by business liaisons) internal and external to the FDA and may also include randomly selected participants in near-end stages of a pilot. The number of phases depends on the project.

The primary objectives of the pilots are to ensure that the system performs as expected in the “real-world” business environment as well as to ensure that all integrated and supporting business processes are ready to support the production use (e.g., is the help/call center ready, is logistics ready, does policy cover the necessary use cases, is documentation and training adequate, does the interface with the personnel system work?)

As pilot systems will become operational in production, this will typically involve a need for an ATO and other approvals and documentation (e.g., ITIM, CCBs, EPLC activities etc.). Pilots will also include a transition phase component for handoff to the FDA business units that will be responsible for production operations. The contractor shall be responsible for all necessary training and transition work necessary to prepare the accepting business unit for receipt and responsibility for the solution.

These business units will typically provide staff to participate directly as project team members to better enable this transition.

Any systems used in the prototyping that are not moved to production shall be setup, configured, and decommissioned in an orderly way.

The contractor shall provide FDA a “Lab as a Service” for the ability to evaluate the introduction of new technology, existing investments, and upgrades to determine if identified technologies will help FDA achieve desired business objectives. The contractor shall provide the ability for FDA to access an environment (on-prem or cloud based) that will meet FDA’s performance, security, and access requirements.

While individual orders will detail specific requirements, the representative tasks shall include but are not limited to:

• Project Planning

• Staffing with necessary SMEs and personnel needed to execute on the plan.

• Documentation and Training (primarily within the IT organization, but also for end users in the pilot.) A train the trainer strategy will typically be used, and the contractor shall perform 2-3 initial training sets before training transitioned to the recipient trainer.

• Participate in required governance processes and prepare all necessary documentation for approvals to implement a prototype system including documents needed for Technology Approval, EPLC, ATO, etc.

• Implement install and configure systems.

• Perform operations, maintenance, and support activities within the pilot for the duration of the pilot period including a phase down for these activities until transitioned.

• Provide technical assistance to pilot participants.

• Decommission systems when piloting completes.

• Track equipment and licenses used in the pilot/prototype – a format will be developed by the contractor and approved by the COR.

• Coding, data and database definitions and scripting to create, customize, modify, test and document databases, and applications for multiple platforms such as the web, mobile devices, and workstations.

• Contractor shall identify equipment, technologies, software, systems, tools, and techniques to be used in the labs, and provide information and documentation to the FDA.

• Generate reports and recommendations on systems/prototypes developed in the FDA Innovation Lab

• Create, demonstrate, and prototype approaches for data architecture, data management, data sanitization, and data transfer/exchange.

• Provide recommendations and analysis of using and manipulating large data sets and databases such as DNA sequence and protein databases.

4.8 Infrastructure Modernization

The contractor shall provide various levels of engineering, quality management, and investment management services to ensure a strategically planned and stable growth for the FDA network and delivered services. Subject Matter Expertise requirements may span any FDA IT domain, but in general the following will be the most common skillsets needed.

The Contractor shall support the FDA cybersecurity program by assisting in preventing, detecting, and mitigating external and internal cyber threats, vulnerabilities, and risks to the FDA networks, systems, and applications to ensure confidentiality, integrity, and availability to FDA.

The Contractor shall work in conjunction with the FDA Data Center contractor to design, deploy, and configure new solutions that will be deployed in the FDA Data Centers, or throughout the FDA Enterprise Network. The contractor will be responsible for all new Data Center/Enterprise solutions deployed and shall provide documentation for the transition to the Data Center contractor using the transition documents identified in Appendix H.

While individual orders will detail specific requirements, the representative tasks shall include but are not limited to:

• Provide technical recommendation for enterprise compute and storage enhancements based upon documentation provided by FDA to support various application workloads that are supported by FDA infrastructure.

• Provide design and engineering best practices for authentication (PKI, SAML, AD, etc) API management, microservices deployment for new applications.

• Design, engineer, develop deployment configurations, and assist in the installation and provisioning of any new Local Area Network (LAN), Wide Area Network (WAN), and Metro Area Network (MAN) components (e.g. routers, switches, WAN accelerators, access points, NAC devices, repeaters, WIDS/WIPS sensors, NAC sensors, firewalls, Identity Service Engine (ISE) appliances) to be deployed within the FDA MAN and all FDA field locations (including international sites)

• Design, engineer, develop deployment configurations, and assist in the installation and provisioning of any new WLAN infrastructure components (e.g. access points, repeaters, controllers, switches, WIDS/WIPS sensors).

• Design, engineer, develop deployment configurations, and assist in the installation and provisioning of any new network components (e.g. core backbone, distribution, access layer devices, load balancers, routers, switches, WAN accelerators, VPN concentrators, access points, Network Access Control (NAC) devices, repeaters, Dense Wave Division Multiplexing (DWDM), and Wireless Intrusion Detection System (WIDS)/Wireless Intrusion Prevention System (WIPS) sensors)

• Provide technical recommendation for enterprise network enhancements based upon documentation provided by FDA, which would include traffic flow diagrams, design diagrams, closet layout diagrams, spare part inventories, network topology diagrams that depict layer 2 and layer 3 switching, layer 3 diagrams that illustrate routing protocols, Open Shortest Path First (OSPF) area boundaries, Border Gateway Protocol (BGP) autonomous systems, Virtual Route Forward (VRF) and other layer 3 routing configurations, layer 2 diagrams illustrating LAN and Virtual Local Area Network (VLAN) trunks, Spanning Tree, Root Bridge Assignment, Hot Stand-by Routing Protocol (HSRP) Primary/Secondary Configurations and any other layer 2 link state configurations.

4.9 DevSecCXOps Engineering Support

The Contractor shall engineer, update, and transition a DevSecCXOps Pipeline to operations that includes the following technology: GitLab, Atlassian JIRA, CloudBees, Jenkins, Cucumber, Selenium, Sonatype Nexus, Docker, Appium, and HP Fortify. The Contractor shall work in conjunction with the FDA Data Center contractor to design, deploy, and configure the DevSecCXOps pipeline that will be deployed in the FDA Data Centers.

While individual orders will detail specific requirements, the representative tasks shall include but are not limited to:

• Updating documentation to deploy DevSecCXOps Pipeline to the White Oak Data Center (WODC), Ashburn Data Center (ADC), and AWS Environment for Development, Test, Preproduction, and Production Environments

• Write a DevSecCXOps Pipeline Test Plan to verify that DevSecCXOps Pipeline technologies are integrated per the DevSecCXOps Processes Pipeline Design

• Update a DevSecCXOps Pipeline Operations and Maintenance Plan based upon engineering changes and transition to O&M.

• Engineer changes to technologies of the DevSecCXOps Pipeline in Development, Test, Preproduction, and Production Environments within WODC, ADC, and AWS environment

• Obtain approval of the DevSecCXOps Pipeline Test Plan Results prior to DevSecCXOps Pipeline Implementation in the Test, Preproduction, and Production Environment

• Integrate with Puppet Configuration Management (CM) project to manage all CaaS -related configuration changes.

• Install, manage and monitor technologies (new and upgrades) across all environments

• Ensure connectivity across all automated infrastructure components

• Develop SOPs, run book and other operation documentation as required.

• Define and document the release management procedures, processes and RACI matrix and work with various ODT support teams,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .