Attachment 2 - SOW_042522 CDER Oracle DBA Support Task Order.pdf
PDF 811 KB Posted
- Attached to
- ORACLE Enterprise Database and Application Server Administration Support IDIQ Federal contract opportunity
- Solicitation number
- FDA-RFP-22-1249753
About this file
This document outlines a solicitation for Oracle database and application server administration support services. The solicitation is a competitive 8(a) set-aside seeking these services for the Food and Drug Administration's Office of Information Management and Technology. Offerors must carefully review the solicitation and all attachments, which include statements of work and pricing sheets for Oracle support for the Center for Drug Evaluation and Research, Center for Food Safety and Applied Nutrition, and Office of Information Management and Technology. The closing date for proposals was not provided. The services required include standard database and application server upgrades, migrations, monitoring, backup strategies, performance tuning, security patching, account management, and disaster recovery documentation for FDA environments including development, test, and production instances.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 - SOW_042522 CDER Oracle DBA Support Task Order rev1.pdf | ||
| Instructions to Offerors rev2.pdf | ||
| Attachment 4 - SOW_042522 DAS OIMT Oracle DBA Support Task Order rev1.pdf | ||
| Attachment A - PRICING SHEETS rev1.xlsx | XLSX spreadsheet | |
| FDA-RFP-22-1249753 Questions and Responds.pdf | ||
| Attachment 3 - SOW_042522 CFSAN Oracle DBA Support Task Order rev1.pdf | ||
| Instructions to Offerors rev1.pdf | ||
| FDA-RFP-22-1249753.pdf | ||
| Attachment 4 - SOW_042522 DAS OIMT Oracle DBA Support Task Order.pdf | ||
| Attachment A - PRICING SHEETS.xlsx | XLSX spreadsheet | |
| Attachment 1 - SOW_042522 IDIQ DAS Oracle Support.pdf | ||
| Attachment 3 - SOW_042522 CFSAN Oracle DBA Support Task Order.pdf | ||
| Instructions to Offerors.pdf | ||
| Attachment D - EPLC FRAMEWORK.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK (SOW)
Task Order Title: Task Order Title: Oracle Database Administration Support for the Center for Drug
Evaluation and Research (CDER)
1. Background
An Agency database administration support and application server administration support across all of Food and Drug Administration (FDA). This effort includes standard upgrades, migrations, and Oracle Database Administration Support and Application Server Support required ensuring all databases and applications comply with the agency’s current enterprise IT architecture requirements. Task orders will be issued using the TUVA STAR2 contract for Oracle Database support to assist with the compliance within FDA's new IT environment.
2. Objectives
The work to be performed under this contract task order shall provide ongoing operations and maintenance support on database and application servers hosting Center for Drug Evaluation and Research (CDER) applications.
3. Scope
The Contractor shall provide operations and maintenance support on 12 application servers and 16 database servers hosting CDER applications and approximately 50 databases.
4. General Requirements
The Oracle database and application support and optimization project requires a number of complex tasks for successful completion. The tasks may include but are not limited to:
Task 1: Oracle Application Server Administration Support (White Oak Data Center and Ashburn Data
Center Development, Test, Pre-Production and Production environments for the CDER applications listed below)
The Contractor shall:
4.1.1 Performance monitoring and tuning
4.1.2 Implement backup strategy plan
4.1.3 Assist and recommend tuning on Solaris/Linux Administration side
4.1.4 Capacity planning and storage configuration
4.1.5 Coordinate after-hours shutdowns and restarts of Oracle software with systems administrators and application developers during patching and maintenance
4.1.6 Apply one-off and security patches to application servers
4.1.7 Monitor system performance at all tiers and implement tuning recommendations as necessary
4.1.8 Provide support on configuration and maintenance of agency-wide SSO/OID and Oracle Access Manager
CDER Oracle Applications
The Contractor shall provide O&M support for the following CDER Oracle Applications:
o DARRTS – (Document Archiving, Reporting Regulatory Tracking System): Tracks INDs, NDAs, ANDAs, Master Files, Post Marketing Commitment, and others (umbrella system).
o EDR /EDRSTAFF – (Electronic Document Room) o SRS/ID –( Substance Registration System/Ingredient Dictionary): Enables FDA to efficiently, effectively, and reliably maintain unique identifiers for substances in drugs, biologics, foods, and devices, and make them available for use in health information systems.
o UAC – (User Access Control): Manages user access to LX, DARRTS, and EES, both UAC tables and
Oracle roles. Front end for user access / accounts management team.
o FAERS – (FDA Adverse Events Reporting System) o eDRLS – (Electronic Drug Listing System) o Panorama: A modernized work management initiative that gives users a more robust and accurate method to managing work across offices.
o eCTD – Electronic Common Technical Document/Electronic Regulatory Submission System o POCA – (Phonetic-Orthographic Computer Analysis System) o Electronic Orange Book – Electronic Orange Book Approved Drug Products with Therapeutic Equivalence
Evaluations o LX Main – Legacy CDER system o Precedent Tracking o Mercado – CDER Mercado o Integrity – CDER Data Quality and Integrity o Janus/Clinical Trial Repository (CTR) – The Janus Program is proposed to be a set of interoperable databases that will allow reviewers to examine structured scientific data across applications, centers and phases of the regulatory life-cycle. The program includes warehouses for clinical data, non-clinical (animal), pharmacogenomics, and adverse event data to name a few.
o Central Triage Unit (CTU) – a web-based application that tracks all the inbound potential Adverse Events received in different formats through different media such as email, fax, manual document upload, and so
on. This is used by pharmaceutical companies, affiliates, partners, consumers, healthcare providers, Clinical Research Organizations (CROs), and Headquarters (HQ), for managing and transferring compliant regulatory files to the authorities and partners.
Task 2: Oracle Database Administration Support (White Oak Data Center, Development and Test environments, Ashburn Data Center, Pre-Production and Production environments, and CHDC PPS Environment) for the CDER databases listed below.
The Contractor shall:
4.2.1 Set and modify initialization parameters in the databases
4.2.2 Manage and install routine and regularly-scheduled COTS Updates
4.2.3 Work with application team and business customers / centers in diagnosing and resolving problems in response to user-reported incidents, customer functional issues, technical problems, and other database-related issues.
4.2.4 Provide user account management consisting of: account creation, password resets, and requested modifications
4.2.5 Provide analysis, design, evaluation, and architectural support for IT systems deployed.
4.2.6 Troubleshoot, resolve, and document inquiries and report possible discrepancies in data quality and data integrity
4.2.7 Provide database administration and ad-hoc support for all CDER databases
4.2.8 Monitor server status, utilizing provided software tools, and report anomalies to the correct application owner
4.2.9 Manage the installation and integration of systems fixes, updates, and patches
4.2.10 Provide/Update disaster recovery documentation
4.2.11 Monitor and analyze audit logs, report any concerns, repeated failed login attempts, possible security threats
4.2.12 Perform system back-up functions on a daily, weekly and monthly basis as required
4.2.13 Assist systems administrators in implementing corrective actions required as a result of vulnerabilities uncovered during system scans
4.2.14 Maintain copies of the baseline initialization parameters on the file system for reference and emergency startup
4.2.15 Contribute to the design of the enterprise system architecture, especially with respect to Oracle technologies such as RAC, OID/SSO, Oracle Application Server
4.2.16 Create privileged database users as required by the projects
4.2.17 Install and configure Oracle Clusterware/ASM/database and application server, including recommended
OS configuration based on best practices
4.2.18 Monitor system performance at all tiers while implementing tuning recommendations as necessary
4.2.19 Implement DDL changes such as tablespace creation and sizing, new database objects
4.2.20 Monitor database and ASM alert logs for ORA-errors that might affect current or future performance and availability
4.2.21 Manage new technologies in the development environment
4.2.22 Open and manage Service Requests with Oracle Support, as pertains to any of the core Oracle technologies
4.2.23 Use tools such as SQL*Loader to load data for applications when necessary
4.2.24 Establish service-level agreements with development teams for each database and application server installation. Factors include, but are not limited to, hours of availability; backup frequency, backup type, backup retention requirements; mean time to recovery.
4.2.25 Review of database designs for new systems.
4.2.26 Implement and adhere to new database management policies, procedures and standards adopted by Senior
Management
4.2.29 Conduct Random health checks on the databases and prepares performance reports.
4.2.30 Troubleshoot problems related to availability of data to system users, space, database software, data flow, and data storage or data access
4.2.31 Assist in cloning databases in development and test environments, for use by application teams in masking sensitive data.
4.2.32 Support Database refreshes in all lower environments
4.2.33 Support database deployments
4.2.34 Support data cleanup activities in all environments
4.2.35 Support on database consolidation efforts, where practical
4.2.36 Support cloud initiative (CDER-EDM-Prod and PreProd)
4.2.37 Support EXALYTICS for Mercado/Data Integrity
4.2.38 Assist in finding sensitive data and helping the app team to mask the data
4.2.39 Assist the application team and security on DB scans
4.2.40 Assist Puppet team on the auto deployment prepping database scripts
4.2.41 Assist the DXC/HP team on tablespace data encryption.
4.2.42 Assist and monitor Grid control Metrix setup and alerts
CDER Oracle Databases
The Contractor shall provide O&M support for the following Oracle Databases:
Infradev -- Infrastructure metadata repository Dardevwo -- DARRTS 0 & M Development Dardnwwo -- DARRTS New Release Development Lxeesdwo -- LX/EES Development POCA -- POCA Development Infratst -- Infrastructure metadata repository Dartstwo -- DARRTS O&M Test Dartnwwo -- DARRTS New Release Test Lxeestwo -- LX/EES Test DBARtst -- Office management (Michel Cu) POCAtst -- POCA Test OBIDEV – Office of Business Informatics Prototype dev OBITEST – Office of Business Informatics prototype test OCD1T11 (TSKDEV) – ed04 OCD2T11 (AMSDEV) – ed04 CDEDVT34 (AMSOME) – ed12 SIGPREP-- Empirica Signal CDER database SIGPROD---Empirica Signal CDER production database OBIDEV ---Diabetic information development database CDERPP----CDER Pre-prod database (O&M) CDERPPNW--CDER pre-prod database (NW) POCAPP --POCA pre-prod database POCA --POCA production database
CDERPROD: CDER PRODUCTION DATABASE
ECTDDWO--- ECTD development database ECTDTST----ECTD test database ECTDPP ----ECTD pre-prod database ECTDPROD: ECTD production database Ctipspp –ctips PreProd Ctipsprd –Ctips prod DBARPP -- -DBAR PreProd DBAR ---DBAR production FAERSDEV – FAERS Development FBISDEV – FBIS Development FAERSTS – FAERS Test FAERSTN -- FAERS Training FBISTS – FBIS Test FBISTN – FBIS Training FAERSPP – FAERS Pre-Production FBISPP – FBIS Pre-Production FAERSPD – FAERS Production FBISPD – FBIS Production CDEPPT31- Mercado Pre-production CDEPDT31- Mercado Production CDEPPT13- Mercado/OBIEE Pre-production CDEPDT13- Mercado/OBIEE production OCPPT11 – OBITSKPP(Panorama) - ED06 OCPP1T11 – (AMSPREPROD) Panorama Preproduction -ED06 OCPDT11 –OBITSKPD(Panorama) – ED07
OCPD1T11 (AMSPROD)
CDEPPT26 –Integrity Pre-production
CDEPDT26 –Mercado Production CDEPDT26 –Integrity Production
CDEPDT14, CDE1PD14 – CDER Portes CDEPDT09, CDEPDT09 – CDER Mobile
CDEPPT39, CDEPDT39 – CDER EMD
5. Project Management
The schedule of deliverables requires delivery of reports, meetings and draft documentation. The intention of these deliverables is to monitor the contractor’s progress towards delivering final documentation, specifications and systems of superior quality within schedule and cost. The FDA understands that timely feedback will have to be provided to the contractor after the review of these deliverables.
The Contractor shall provide the following:
5.1 In Progress Review Support
Provide a monthly status report monitoring progress against the Task Order Management Plan, and the project schedule applied to the task order. List everything that has been accomplished during the prior month, broken down according to the project that was worked on. This report shall be delivered by the tenth day of the following month.
5.2 Deliverable and Document Dissemination
Each document deliverable shall be delivered via e-mail. When a new document is delivered, or an update to existing documentation is made, the Contractor shall alert the Contracting Officer’s Representative of these changes.
5.3 Meeting Minutes and Agendas
The Contractor shall maintain and provide minutes of all meetings held with the FDA.
These minutes shall include the following:
o Summary description of all issues discussed o Action Items o Personnel to whom the Actions Items are assigned o List of meeting attendees, including name, organization, phone number, and email address.
All agendas shall be delivered at least 1 working day prior to the meeting unless the meeting is called at the last minute.
All meeting minutes shall be delivered within 4 working days following the meeting.
5.4 Weekly Status Meetings
Weekly status meetings shall be held with the FDA Project Team to discuss general status of the project and any issues as they occur, as well as to gain any FDA management updates and feedback.
Attend adhoc meetings as needed. Assist in producing reports to management detailing CDER database and application issues and risks. Review of project risks shall occur quarterly, as a part of the status meeting.
(January, March, October) All agendas shall be delivered at least 1 working day prior to the meeting.
All meeting minutes shall be delivered within 4 working days following the meeting.
5.5 Informal Project Review Meetings
Informal project reviews shall occur throughout the project. The primary purpose of these informal reviews shall be to discuss specific project activities and to address any potential problem areas that might arise, or have already arisen. These reviews may be called by the FDA COR or by the Contractor on an as needed basis and may include participants from FDA senior management.
All agendas shall be delivered at least 1 working day prior to the meeting.
All meeting minutes shall be delivered within 4 working days following the meeting.
6. Deliverables
Task Description Estimated Quantity / Frequency Due Date Delivered to
5.1 Monthly Status Report Monthly By the 15 of
each month COR
5.2 Meeting Agenda
As needed One (1) day prior to meeting
COR
5.3 Meeting Minutes
As needed Four (4) days after meeting
COR
7. Inspection and Acceptance
The Government will review all reporting requirement deliverables in accordance with specifications and standards identified in the statement of work or any directives issued by the Contracting Officer Representative (COR). Reporting Requirements/Deliverables shall be submitted to the COR in accordance to the delivery schedule. The acceptance of deliverables and satisfactory work performance shall be based upon the timeliness and accuracy/quality of the deliverables.
The Contractor shall implement necessary changes within 10 business days, or a mutually agreed upon period of time, from the day of change notification.
The Contracting Officer’s Representative shall perform inspection and acceptance of materials and services.
8. Place of Performance
Due to the pandemic, contractor services will be performed offsite for the time being. If services are performed onsite at some point in the future, onsite contractors will work at 11601 Landsdown Street, North Bethesda, MD. If occasional local travel is required to conduct meetings with business stakeholders within the Rockville, MD area, local travel will not be reimbursed.
9. Hours of Performance
The Contractor shall ensure that the Development, Test, and Pre-Production environments are up and running during the workweek from 07:00am through 7:00pm unless pre-approved COR or COR designee scheduled downtime has been approved.
The Contractor shall ensure that the production environment is up and running 24/7/365 in order to meet specific customer requirements unless COR or COR designee scheduled downtime has been approved.
10. Government Furnished Equipment
Government Furnished Equipment will consist of laptop computers and telephones.
11. Period of Performance
The anticipated period of performance shall be Base: May 1, 2022 through October 31, 2022.
Optional: Option Year 1: November 1, 2022 through October 31, 2023 Optional: Option Year 2: November 1, 2023 through October 31, 2024 Optional: Option Year 3: November 1, 2024 through October 31, 2025 Optional: Option Year 4: November 1, 2025 through October 31, 2026
12. Technical Guidance Letter
1. As necessary, technical guidance or clarification concerning the details of specific services to be performed under the terms of this contract/order shall be given through issuance of Technical Guidance Letters (TGL) by the Contracting Officer's Representative (COR) using email or other electronic means. To be valid a TGL, it must be within the general scope of work stated in the contract/order, and it would not require any increase to the negotiated price and/or adjust the delivery terms under the contract.
2. Each TGL issued hereunder is subject to the terms and conditions of this contract. It shall be in writing and include, as a minimum, the following information:
a. Effective date of TGL;
b. Contract/Order and sequential TGL number;
c. Reference to the relevant section in the statement of work; and
d. Requirements to be performed.
3. The Contractor shall not comply with any TGL, if the Contractor believes it is not a valid TGL.
In the event of a conflict between a TGL and the scope of the contract/order, the terms of the contract/order shall prevail. If the Contractor believes or has reason to believe that a TGL is not valid, the Contractor shall notify the COR and Contracting Officer thereof by email within two (2) days of receiving the TGL in question. The Contracting Officer will give appropriate direction to the Contractor and COR to resolve the TGL issue.
4. Oral technical directions may be given by the COR only in emergency circumstances. The Contractor shall notify the Contracting Officer by email that it has received such direction within 24 hours of having received the directions. If the COR does not follow-up the oral directions within two (2) working days by issuing a written TGL, the Contractor is to notify the Contracting Officer and cease compliance unless the Contractor concurs the direction is a valid TGL.
5. Technical Guidance provided in meetings with minutes submitted by the Contractor for Government acceptance does not need to be documented via TGL. The Technical Guidance shall be documented in the meeting minutes.
6. Contractor’s failure to comply with this clause is grounds for finding that incurred costs are not allowable.
13. Method of Quality Monitoring
Technical Performance: The Contractor will be evaluated monthly as to the quality of the output of their work and results will be documented in the COR’s file. The Contractor's personnel shall be technically competent in the tasks identified in the SOW or other ordering document under the contract. Included in the technical performance is the Contractor’s contribution in meetings and reviews, the quality of the Contractor's technical reports, the Contractor's productivity and the overall quality of the technical support provided.
SOW
Item No.
Description Performance Standard Acceptable Quality Level
Surveillance Method & Assessment
5.1, 5.2, 5.3, 5.4
Documents All documents are submitted in a timely manner
Documents are 95% accurate, complete, concise, and clear
100% Inspection
Inspection and Evaluation Definitions:
• 100 Percent Inspection - With this method, performance is inspected/ evaluated at each occurrence.
This method is often costly but can be necessary due to health, safety and other considerations.
• Random Sampling - Random sampling works best when the number of instances of the services being performed is very large and a statistically valid sample can be obtained.
• Customer Feedback - Although usually not a primary method, this is a valuable supplement to more systematic methods. For example, in a case where random sampling indicates unsatisfactory service, customer complaints can be used as substantiating evidence. In certain situations where customers can be relied upon to complain consistently when the quality of performance is poor, e.g., dining facilities, building services, customer surveys and customer complaints may be a primary surveillance method, and customer satisfaction an appropriate performance standard. In all cases, complaints should be documented, preferably on a standard form.
14. Government Points of Contact
Contracting Officer’s Representative (COR):
Delores Johnson U.S. Food and Drug Administration Office of Information Management and Technology 3 White Flint North: Rm 11A21 11601 Landsdown Street North Bethesda, MD 20852 301-796-7771 delores.johnson@fda.hhs.gov
Contracting Officer (CO)
TBD
The COR may be changed at any time by the Government without prior notice to the Contractor by a unilateral modification to the Contract. The responsibility and limitation of the COR are as follows: (1) The COR is responsible for the technical aspects of the project and serves as the technical liaison with the Contractor. The COR is also responsible for the final inspection and acceptance of all reports, and such other responsibilities as may be specified in the contract. (2) The COR is not authorized to make any commitments or otherwise obligate the Government or authorize any changes which affect the Contract price, terms or conditions. Any Contractor request for changes shall be referred to the Contraction Officer directly or through the COR. No such changes shall be made without the expressed prior authorization of the Contracting Officer (CO). The CO may designate assistant or alternate COR to act for the COR by naming such assistant/alternate(s) in writing and transmitting a copy of such designation to the Contractor.
15. Key Personnel
The Key Personnel specified in each Order are considered to be essential to work performance. At least 30 days prior to diverting any of the specified individuals to other programs or contracts (or as soon as possible, if an individual must be replaced, for example, as a result of leaving the employ of the contractor), the contractor shall notify the Contracting Officer and shall submit comprehensive justification for the diversion or replacement mailto:delores.johnson@fda.hhs.gov request (including proposed substitutions for Key Personnel) to permit evaluation by the Government of the impact on performance under each Order. The contractor shall not divert or otherwise replace any Key Personnel without the written consent of the Contracting Officer. The Government may modify the Orders to add or delete key personnel at the request of the contractor or Government.
Role
Senior Principal Consultant (Sr DB Management Specialist)
16. Contract Type
The contract type for this Task Order is Firm-Fixed-Price.
17. Payment and Invoice Instructions
The Contractor shall invoice 1/12th the value of the Financial Systems Support requirement task order (FFP) monthly.
FDA Electronic Invoicing and Payment Requirements - Invoice Processing Platform (IPP) (Jan 2022)
(a) All Invoice submissions for goods and or services must be made electronically through the U.S.
Department of Treasury’s Invoice Processing Platform System (IPP).
http://www.ipp.gov/vendors/index.htm
(b) Invoice Submission for Payment means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in in FAR 32.905(b), “Content of Invoices” and the applicable Payment clause included in this contract, or the clause 52.212-4 Contract Terms and Conditions – Commercial Items included in commercial items contracts. The IPP website address is: https://www.ipp.gov.
(c) -----
(1) The Agency will enroll the Contractors new to IPP. The Contractor must follow the IPP registration email instructions for enrollment to register the Collector Account for submitting invoice requests for payment. The Contractor Government Business Point of Contact (as listed in SAM) will receive Registration email from the Federal Reserve Bank of St. Louis (FRBSTL) within 3 – 5 business days of the contract award for new contracts or date of modification for existing contracts.
(2) Registration emails are sent via email from ipp.noreply@mail.eroc.twai.gov. Contractor assistance with enrollment can be obtained by contacting the IPP Production Helpdesk via email to IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.
(3) The Contractor POC will receive two emails from IPP Customer Support, the first email contains the initial administrative IPP User ID. The second email, sent within 24 hours of receipt of the first email, contains a temporary password. You must log in with the temporary password within 30 days.
(4) If your company is already registered to use IPP, you will not be required to re-register.
(5) If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment as authorized by HHSAR 332.7002, a written request must be submitted to the Contracting Officer to explain the circumstances that require the authorization of alternate payment procedures.
(d) Invoices that include time and materials or labor hours Line Items must include supporting documentation to (1) substantiate the number of labor hours invoiced for each labor category, and (2) substantiate material costs incurred (when applicable).
(e) Invoices that include cost-reimbursement Line Items must be submitted in a format showing expenditures for that month, as well as contract cumulative amounts.
(1) At a minimum the following cost information shall be included, in addition to supporting documentation to substantiate costs incurred.
- Direct Labor - include all persons, listing the person's name, title, number of hours worked, hourly rate, the total cost per person and a total amount for this category;
- Indirect Costs (i.e., Fringe Benefits, Overhead, General and Administrative, Other Indirects)- show rate, base and total amount;
- Consultants (if applicable) - include the name, number of days or hours worked, daily or hourly rate, and a total amount per consultant;
- Travel - include for each airplane or train trip taken the name of the traveler, date of travel, destination, the transportation costs including ground transportation shown separately and the per diem costs. Other travel costs shall also be listed;
- Subcontractors (if applicable) - include, for each subcontractor, the same data as required for the prime Contractor;
- Other Direct Costs - include a listing of all other direct charges to the contract, i.e., office supplies, telephone, duplication, postage; and
- Fee – amount as allowable in accordance with the Schedule and FAR 52.216-8 if applicable.
(f) Contractor is required to attach an invoice log addendum to each invoice which shall include, at a minimum, the following information for contract administration and reconciliation purposes:
(1) list of all invoices submitted to date under the subject award, including the following:
- invoice number, amount, & date submitted
- corresponding payment amount & date received
- total amount of all payments received to date under the subject contract or order
- and, for definitized contracts or orders only, total estimated amounts yet to be invoiced for the current, active period of performance.
(g) Payment of invoices will be made based upon acceptance by the Government of the entire task or the tangible product deliverable(s) invoiced. Payments shall be based on the Government certifying that satisfactory services were provided, and the Contractor has certified that labor charges are accurate.
(h) If the services are rejected for failure to conform to the technical requirements of the task order, or any other contractually legitimate reason, the Contractor shall not be paid, or shall be paid an amount negotiated by the CO.
(i) Payment to the Contractor will not be made for temporary work stoppage due to circumstances beyond the control of U.S. Food and Drug Administration such as acts of God, inclement weather, power outages, and results thereof, or temporary closings of facilities at which Contractor personnel are performing. This may, however, be justification for excusable delays.
(j) The Contractor agrees that the submission of an invoice to the Government for payment is a certification that the services for which the Government is being billed, have been delivered in accordance with the hours shown on the invoices, and the services are of the quality required for timely and successful completion of the effort.
(k) Questions regarding invoice payments that cannot be resolved by the IPP Helpdesk should be directed to the FDA Employee Resource and Information Center (ERIC) Helpdesk at 301-827-ERIC (3742) or toll-free 866-807-ERIC (3742); or, by email at ERIC@fda.hhs.gov. Refer to the Call-in menu options and follow the phone prompts to dial the option that corresponds to the service that's needed. All ERIC Service Now Tickets will either be responded to or resolved within 48 hours (2 business days) of being received. When emailing, please be sure to include the contract number, invoice number and date of invoice, as well as your name, phone number, and a detailed description of the issue.
18. Conformance with Applicable Laws, Regulations, Standards, and Policies
Section 508 Standard Requirements
HHSAR Clause 352.239-74 Electronic and Information Technology Accessibility is applicable to this task order.
See clause section for full text.
19. Security and Privacy Requirements
A. Baseline Security Requirements
1) Applicability. The requirements herein apply whether the entire contract or order (hereafter “contract”), or portion thereof, includes either or both of the following:
2) Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.
a. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.
3) Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:
a. Protect government information and information systems in order to ensure:
• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;
• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and
• Availability, which means ensuring timely and reliable access to and use of information.
b. Provide security for any Contractor systems, and information contained therein, connected to an FDA network or operated by the Contractor on behalf of FDA regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party. This includes notifying the FDA Systems Management Center (SMC) within one (1) hour of discovery/detection in the event of an information security incident.
c. Adopt and implement the policies, procedures, controls, and standards required by the HHS/FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing your ISSO.
d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.
4) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:
Confidentiality: [ ] Low [ X ] Moderate [ ] High
Integrity: [ ] Low [ X ] Moderate [ ] High
Availability: [ ] Low [X ] Moderate [ ] High
Overall Risk Level: [ ] Low [ X] Moderate [ ] High
Based on information provided by the Privacy Office, system/data owner, or other privacy representative, it has been determined that this solicitation/contract involves:
[ ] No PII [ X ] Yes PII
Complete this section using the information obtained from the Security and Privacy Checklist in Appendix A, parts A and B.
Personally Identifiable Information (PII). Per the OMB Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother’s maiden name, biometric records, etc.
PII Confidentiality Impact Level has been determined to be: [ ] Low [ X ] Moderate [ ] High
5) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa). As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:
a. marked appropriately;
http://csrc.nist.gov/publications/nistpubs/800-60-rev1/SP800-60_Vol2-Rev1.pdf
b. disclosed to authorized personnel on a Need-To-Know basis;
c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and
d. returned to FDA control, destroyed when no longer needed, or held until otherwise directed.
Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization and the FDA IS2P Appendix T: Sanitization of Computer- Related Storage Media.
6) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.
Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.
The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS/FDA sanction policies and/or governed by the following laws and regulations:
a. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);
b. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and
c. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).
7) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).
8) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.
9) Contract Documentation. The Contractor shall use FDA-provided templates, policies, forms and other agency documents to comply with contract deliverables as appropriate.
10) Standard for Encryption. The Contractor (and/or any subcontractor) shall:
a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.
b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.)
and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.
c. All devices (i.e.: desktops, laptops, mobile devices, etc.) that store, transmit, or process non-public FDA information shall utilize FDA-provided or FDA information security authorized devices that meet HHS and FDA-specific encryption standard requirements.
Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).
d. Verify that the encryption solutions in use are compliant with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.
e. Use the Key Management system on the HHS Personal Identification Verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys (PIV card) shall be provided to the COR upon request and at the conclusion of the contract. Upon completion of contract, contractor ensures that COR is able to access and read any encrypted data.
11) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the FDA non-disclosure agreement (3398 Form), as applicable. A copy of each signed and witnessed NDA shall be submitted to the CO and/or COR prior to performing any work under this acquisition.
12) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.
a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist procuring activity representative, program office and the FDA SOP or designee with http://csrc.nist.gov/publications/fips/fips140-2/fips1402.pdf http://inside.fda.gov:9003/downloads/administrative/forms/fda/ucm013733.pdf http://inside.fda.gov:9003/downloads/administrative/forms/fda/ucm013733.pdf completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).
b. The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee in reviewing and updating the PIA at least every three years throughout the Enterprise Performance Life Cycle (EPLC) /information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.
B. Training
1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable FDA Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete FDA Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS and FDA training policies.
2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy and FDA Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Standard Operating Procedures (SOP).
3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.
C. Rules of Behavior
1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.
2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior (ROB) before accessing HHS and FDA data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines.
D. Incident Response
The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA SMC /Incident Response Team (IRT) teams within 24 hours, whether the response is positive or negative.
FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity, confidentiality, or availability of information or an information system; or (2) constitutes a violation or imminent threat of violation of law, security policies, security procedures, or acceptable use policies.”
The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines incidents as events involving cybersecurity and privacy threats, such as viruses, malicious user activity, loss of, unauthorized disclosure or destruction of data, and so on.
A privacy breach is a type of incident and is defined by FISMA as the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or any similar occurrence where (1) a person other than an authorized user accesses or potentially accesses personally identifiable information or (2) an authorized user accesses or potentially accesses personally identifiable information for an other than authorized purpose. The HHS Policy for IT Security and Privacy Incident Reporting and Response further defines a breach as “a suspected or confirmed incident involving PII.”
In the event of a suspected or confirmed incident or breach, the Contractor (and/or any subcontractor) shall:
1) Protect all sensitive information, including any PII created, stored, or transmitted in the performance of this contract to avoid a secondary sensitive information incident with FIPS 140-2 validated encryption.
2) NOT notify affected individuals unless so instructed by the Contracting Officer or designated representative. If so instructed by the Contracting Officer or representative, the Contractor shall send FDA approved notifications to affected individuals as directed by FDA’s SOP.
3) Report all suspected and confirmed information security and privacy incidents and breaches to the FDA Systems Management Center, COR, CO, and other stakeholders, including incidents involving PII, in any medium or form, including paper, oral, or electronic, as soon as possible and without unreasonable delay, no later than one (1) hour of discovery/detection, and consistent with the applicable FDA and HHS policy and procedures, NIST standards and guidelines, as well as US- CERT notification guidelines. The types of information required in an incident report must include at a minimum: company and point of contact information, contract information, impact classifications/threat vector, and the type of information compromised. In addition, the Contractor shall:
a. cooperate and exchange any information, as determined by the Agency, necessary to effectively manage or mitigate a suspected or confirmed breach;
b. not include any sensitive information in the subject or body of any reporting e-mail; and
c. encrypt sensitive information in attachments to email, media, etc.
4) Comply with OMB M-17-12, Preparing for and Responding to a Breach of Personally Identifiable Information and HHS and FDA incident response policies when handling PII breaches.
5) Provide full access and cooperate on all activities as determined by the Government to ensure an effective incident response, including providing all requested images, log files, and event information to facilitate rapid resolution of sensitive information incidents. This may involve disconnecting the system processing, storing, or transmitting the sensitive information from the Internet or other networks or applying additional security controls. This may also involve physical access to contractor facilities during a breach/incident investigation demand.
E. Position Sensitivity Designations
All Contractor (and/or any subcontractor) employees must obtain a background investigation commensurate with their position sensitivity designation that complies with Parts 1400 and 731 of Title 5, Code of Federal Regulations (CFR). The following position sensitivity designation levels apply to this solicitation/contract:
F. Homeland Security Presidential Directive (HSPD)-12
The Contractor (and/or any subcontractor) and its employees shall comply with Homeland Security Presidential Directive (HSPD)-12, Policy for a Common Identification Standard for Federal Employees and Contractors;
OMB M-05-24; FIPS 201, Personal Identity Verification (PIV) of Federal Employees and Contractors; HHS HSPD-12 policy; and Executive Order 13467, Part 1 §1.2.
Roster. The Contractor (and/or any subcontractor) shall submit a roster by name, position, e-mail address, phone number and responsibility, of all staff working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a government information system(s). The roster and any revisions to the roster as a result of staffing changes shall be submitted to the COR and/or CO per the COR or CO’s direction. Any revisions to the roster as a result of staffing changes. The COR will notify the Contractor of the appropriate level of investigation required for each staff member.
If the employee is filling a new position, the Contractor shall provide a position description and the Government will determine the appropriate suitability level.
G. Contract Initiation and Expiration
1) General Security Requirements. The Contractor (and/or any subcontractor) shall comply with information security and privacy requirements, Enterprise Performance Life Cycle (EPLC) processes, HHS Enterprise Architecture requirements to ensure information is appropriately protected from initiation to expiration of the contract. All information systems development or enhancement tasks supported by the contractor shall follow the FDA EPLC framework and methodology in accordance with the HHS Contract Closeout Guide (2012).
HHS EA requirements may be located here: https://www.hhs.gov/ocio/ea/documents/proplans.html
2) System Documentation. Contractors (and/or any subcontractors) must follow and adhere to NIST SP 800-64, Security Considerations in the System Development Life Cycle, at a minimum, for…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .