Attachment 3 Contract Deliverables.pdf
PDF 671 KB Posted
- Attached to
- CENTRALIZED INFORMATION TECHNOLOGY SYSTEM FOR THE NIH BLUEPRINT NEUROTHERAPEUTICS NETWORK Federal contract opportunity
- Solicitation number
- 75N95021Q00001
About this file
This document outlines contract deliverables and information security requirements for a federal contract supporting the National Institutes of Health Blueprint Neurotherapeutics Network. Key deliverables include COTS software and licenses to be provided within 30 days of award, technical support within 24 hours of request, general and advanced training as directed, and quarterly, annual, and final reports. Information security requirements consist of maintaining an accurate roster of personnel and their roles, completing background checks and executing NDAs prior to starting work, providing training records with the award, signing rules of behavior annually, and reporting incidents within an hour of discovery. The contractor must also submit security authorization documentation such as a system security plan and PIA within 30 days of award, conduct continuous monitoring and vulnerability scanning, and decommission systems according to federal guidelines.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 75N95021Q00001 Combined Synopsis.pdf | ||
| Attachment 6 Invoice Instructions.pdf | ||
| Attachment 7 Guidance Invoice Submission Email.pdf | ||
| Attachment 1 SOW.pdf | ||
| Attachment 2 Addendum.pdf | ||
| Attachment 4 52.204-24 Representation.pdf | ||
| Attachment 5 Evaluation Criteria.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Contract Deliverables
Item Description Due Date COTS software and Licenses
See SOW Project Requirements section and section 6
On or Before 30 Days after award
Technical Support See SOW Section 4 Within 24 hours of a request for support
General Training See SOW Section 4.a As directed by COR Advanced Training See SOW Section 4.b As needed Quarterly Report See SOW Section 9.a Initially 90 days after software is installed and recurring every 90 days Annual/Final Report See SOW Section 9.b Prior to the completion of each contract period, the final report for the final contract period will take the place of the last quarterly report.
Section 508 Annual Report
See SOW Section 9.c In accordance with the Health and Human Services Section 508 Annual Report for Vendors
Transition Out See SOW Section 8 30 Days prior to contract end
Information Security Deliverables
Item Description Due Date Roster and Personnel Security Responsibilities
Roster Changes •Onboarding •Offboarding
List of Personnel with defined roles and responsibilities
Onboarding- Prior to performing any work on behalf of NIH/NINDS, and monthly thereafter.
Offboarding- documentation, equipment and badge when leaving contract within 3 business days
Background Investigation Onboarding documentation when beginning contract.
Prior to performing any work on behalf of NIH/NINDS
Contractor Employee Non- Disclosure Agreement (NDA)
Contractor Employee Non- Disclosure Agreement (NDA)
Prior to performing any work on behalf of NIH/NINDS
Training Records Copy of NIH training records for all mandatory training
In conjunction with contract award and annually thereafter or upon request
Rules of Behavior Signed ROB for all employees Initiation of contract and at least annually thereafter
Incident Response Incident Report (as incidents or breaches occur)
NIH/NINDS policy states as soon as possible or no later than 1 hour of discovery
Incident Response Incident and Breach Response Plan
Upon request from government
Attachment 3
Certification of Sanitization of Government and Government Activity- Related Files, Information, and Devices
Form or deliverables required by NIH
NIH/NINDS requires NIH Form NH270 Certification: Removal of Data and Software
Contract Initiation and Expiration
If the procurement involves a system or cloud service, additional documentation will be required, such as Disposition/Decommission Plan
At contract expiration
Security Assessment and Authorization (SA&A)
SA&A Package
•SSP
•SAR
•POA&M
•Authorization Letter •CP and CPT Report •E-Auth (if applicable) •PTA/PIA (if applicable) •Interconnection/Data Use Agreements (if applicable) •Authorization Letter •Configuration Management Plan (if applicable) •Configuration Baseline
NIH/NINDS requires the contractor to complete the SA&A package within 90 days of initial contract award. This includes the delivery of the following items within 30 days of contract award.
•SSP
•PIA
Protection of Information in a Cloud Environment
Contract expiration NIH/NINDS requires this within 2 weeks.
FedRAMP (applicable if the product/service meets the NIST definition of a
CSP)
FedRamp Authorization NIH/NINDS requires FedRAMP Authorization due prior to using product
Reporting and Continuous Monitoring
POA&M updates; Revised security documentation/Agreements, vulnerability and application scans
Monthly/as requested by NINDS ISSO
Other IT Procurements (Non-Commercial and Open Source Computer Software Procurements)
Computer software, including the source code
Prior to performing any work on behalf of NIH/NINDS
Attachment 3
File details come from the government source that posted it. Updated .