About this file

This document outlines contract deliverables and information security requirements for a federal contract supporting the National Institutes of Health Blueprint Neurotherapeutics Network. Key deliverables include COTS software and licenses to be provided within 30 days of award, technical support within 24 hours of request, general and advanced training as directed, and quarterly, annual, and final reports. Information security requirements consist of maintaining an accurate roster of personnel and their roles, completing background checks and executing NDAs prior to starting work, providing training records with the award, signing rules of behavior annually, and reporting incidents within an hour of discovery. The contractor must also submit security authorization documentation such as a system security plan and PIA within 30 days of award, conduct continuous monitoring and vulnerability scanning, and decommission systems according to federal guidelines.

View the file

Other files for this federal contract opportunity

Other files attached to CENTRALIZED INFORMATION TECHNOLOGY SYSTEM FOR THE NIH BLUEPRINT NEUROTHERAPEUTICS NETWORK, newest first.
File Type Posted
75N95021Q00001 Combined Synopsis.pdf PDF
Attachment 6 Invoice Instructions.pdf PDF
Attachment 7 Guidance Invoice Submission Email.pdf PDF
Attachment 1 SOW.pdf PDF
Attachment 2 Addendum.pdf PDF
Attachment 4 52.204-24 Representation.pdf PDF
Attachment 5 Evaluation Criteria.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Contract Deliverables

Item Description Due Date COTS software and Licenses

See SOW Project Requirements section and section 6

On or Before 30 Days after award

Technical Support See SOW Section 4 Within 24 hours of a request for support

General Training See SOW Section 4.a As directed by COR Advanced Training See SOW Section 4.b As needed Quarterly Report See SOW Section 9.a Initially 90 days after software is installed and recurring every 90 days Annual/Final Report See SOW Section 9.b Prior to the completion of each contract period, the final report for the final contract period will take the place of the last quarterly report.

Section 508 Annual Report

See SOW Section 9.c In accordance with the Health and Human Services Section 508 Annual Report for Vendors

Transition Out See SOW Section 8 30 Days prior to contract end

Information Security Deliverables

Item Description Due Date Roster and Personnel Security Responsibilities

Roster Changes •Onboarding •Offboarding

List of Personnel with defined roles and responsibilities

Onboarding- Prior to performing any work on behalf of NIH/NINDS, and monthly thereafter.

Offboarding- documentation, equipment and badge when leaving contract within 3 business days

Background Investigation Onboarding documentation when beginning contract.

Prior to performing any work on behalf of NIH/NINDS

Contractor Employee Non- Disclosure Agreement (NDA)

Contractor Employee Non- Disclosure Agreement (NDA)

Prior to performing any work on behalf of NIH/NINDS

Training Records Copy of NIH training records for all mandatory training

In conjunction with contract award and annually thereafter or upon request

Rules of Behavior Signed ROB for all employees Initiation of contract and at least annually thereafter

Incident Response Incident Report (as incidents or breaches occur)

NIH/NINDS policy states as soon as possible or no later than 1 hour of discovery

Incident Response Incident and Breach Response Plan

Upon request from government

Attachment 3

Certification of Sanitization of Government and Government Activity- Related Files, Information, and Devices

Form or deliverables required by NIH

NIH/NINDS requires NIH Form NH270 Certification: Removal of Data and Software

Contract Initiation and Expiration

If the procurement involves a system or cloud service, additional documentation will be required, such as Disposition/Decommission Plan

At contract expiration

Security Assessment and Authorization (SA&A)

SA&A Package

•SSP

•SAR

•POA&M

•Authorization Letter •CP and CPT Report •E-Auth (if applicable) •PTA/PIA (if applicable) •Interconnection/Data Use Agreements (if applicable) •Authorization Letter •Configuration Management Plan (if applicable) •Configuration Baseline

NIH/NINDS requires the contractor to complete the SA&A package within 90 days of initial contract award. This includes the delivery of the following items within 30 days of contract award.

•SSP

•PIA

Protection of Information in a Cloud Environment

Contract expiration NIH/NINDS requires this within 2 weeks.

FedRAMP (applicable if the product/service meets the NIST definition of a

CSP)

FedRamp Authorization NIH/NINDS requires FedRAMP Authorization due prior to using product

Reporting and Continuous Monitoring

POA&M updates; Revised security documentation/Agreements, vulnerability and application scans

Monthly/as requested by NINDS ISSO

Other IT Procurements (Non-Commercial and Open Source Computer Software Procurements)

Computer software, including the source code

Prior to performing any work on behalf of NIH/NINDS

Attachment 3

File details come from the government source that posted it. Updated .