Attachment 3 - SOW_042522 CFSAN Oracle DBA Support Task Order.pdf

PDF 1 MB Posted

Attached to
ORACLE Enterprise Database and Application Server Administration Support IDIQ Federal contract opportunity
Solicitation number
FDA-RFP-22-1249753
Issued by
Department of Health and Human Services Food and Drug Administration Office of Acquisition and Grant Services

About this file

This is a solicitation for Oracle database administration and application server support services. The solicitation is a competitive 8(a) set-aside for small businesses certified through the SBA 8(a) Business Development Program. The Food and Drug Administration seeks a contractor to provide ongoing operations and maintenance support for Oracle databases, Fusion Middleware components, and WebLogic application servers supporting various FDA applications. Services include database and system administration, software upgrades and patching, performance monitoring and issue resolution, system re-hosting, and security services to ensure compliance. The period of performance is one base year with four optional one-year periods. Pricing will be on a firm-fixed-price basis paid monthly at 1/12 the annual value. Proposals are due by the specified date in the solicitation and posted on SAM.gov.

View the file

Other files for this federal contract opportunity

Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK (SOW)

Task Order Title: ORACLE ADMINISTRATION SUPPORT FOR THE FDA (ENTERPRISE and

CFSAN Support Order

1. Background

The Office of Information Management and Technology/Division of Application Services (OIMT/DAS) at FDA is responsible for the administration, maintenance, and support of Oracle databases and application servers. These databases and application servers are hosted at both Government and Contractor operated sites and supports the FDA’s Centers.

The support services include: 1) standard server upgrades and patching, 2) server migrations, 3) new environment provisioning, configuration, and maintenance, 4) Oracle Database Administration (DBA) support, and 5) Oracle Fusion Middle-ware and WebLogic Application Server (WLS) support including proactive system upgrades and patches that comply with security standards. Continuous support services are required in these areas to ensure all databases and applications remain operational, are compliant with the Agency’s current and future operating systems (hardware and software) and meet FDA enterprise IT architecture requirements. Orders are to be issued as needed under the contract for server support to meet the compliance standards within FDA's new IT environment.

This support service order under the Contract is essential in assisting the FDA the Center for Food Safety and Applied Nutrition (CFSAN) and Enterprise applications in: 1) the general Operations and Maintenance (O&M) of new and existing systems, databases, servers, and technologies the Oracle databases and new systems/technologies,

2) the support of the systems development lifecycle environments and application releases for the CFSAN and Enterprise applications, 3) the provision of aid to CFSAN’s ongoing IT initiatives for enhancement and modernization of the CFSAN business systems in response to congressional mandates, and in accordance with initiatives to improve food safety for the general population.

FDA has recently increased emphasis on security due to the growth in threats and additional effort is required to ensure all systems are thoroughly protected. The HHS and FDA security teams have instituted increased regular scanning for system vulnerabilities which have identified additional steps to bring our middleware and database components into full compliance with current expectations.

2. Objectives

This Statement of Work describes the requirements for obtaining continuous support services to fulfill the following objectives:

• Perform Oracle database, middle-tier infrastructure, and application server administration. Perform software upgrades, patching, and support services for Enterprise and CFSAN’s systems and environments.

• Perform ongoing O&M, performance monitoring, tuning, troubleshooting, and issue resolution for the existing Enterprise and CFSAN databases and applications.

• Perform server transition and re-hosting to a new architectural platform(s) per FDA and CFSAN information technology directives.

• Assist in the planning for database optimization and application performance efforts.

• Increase emphasis on security via increased scanning, patching, and upgrade efforts to prevent vulnerabilities and bring middleware, database, and other system components into full compliance with current security protocols. The National Institutes of Standards and Technology defines the required security protocols and defers to the vendor to ensure security items are addressed in each available update.

The Contractor shall apply these updates in an order fashion once they are released from the vendor.

• Provide infrastructural provisioning, configuration, maintenance, and patching of systems to ensure a 24x7 operation capability.

• Successfully install, implement, configure, and support new releases from a security perspective for the existing CFSAN systems, new systems/technologies, and related software products.

• Migrate outdated system environments that no longer comply with security standards to a new environment that supports current security requirements and allows the standards to be maintained.

3. Scope

The Contractor shall provide ongoing O&M support for existing and new Enterprise and CFSAN servers and production applications to include software patching, installs, server upgrades and re-hosting to existing and new FDA architectural platform(s) as required by FDA. The Contractor shall provision Oracle databases, Fusion Middleware (FWM) components, and WebLogic application servers for existing and new CFSAN applications. The Contractor shall implement CFSAN system software releases and install and configure Oracle and other related technology components and other related Commercial off the Shelf (COTS) products that are used by CFSAN systems. The Contractor shall perform analysis, conduct troubleshooting, develop plans, and write scripts and/or other documentation for implementation of the above. The Contractor shall provide technical guidance to ensure a coordinated effort in promoting the software to the upper environments at the Ashburn Data Center (ADC) located in Ashburn, VA. The Contractor shall maintain a comprehensive inventory of administered CFSAN databases and application servers. Support documentation is maintained at a central repository that is accessible to project teams.

The Contractor shall provide application database support services necessary for the ongoing operation and maintenance of CFSAN applications at both the White Oak Data Center (WODC) and the Ashburn Data Center (ADC) to include the following activities: 1) manage user accounts, 2) field customer requests and data calls, 3) resolve Tier 2 and 3 support and account related issues, 4) conduct research, 5) perform analysis, 6) perform regular and periodic security patching and upgrades, 7) troubleshoot and resolve data issues, 8) generate periodic and ad hoc reports, 9) assist in preparing application version rollout(s), and 10) provide and maintain system documents and artifacts.

The Contractor shall provide technical expertise and support services associated with project activities related to installing, configuring, and maintaining Oracle Fusion Middleware (FMW) for CFSAN systems at both the WODC and the ADC to include the following activities: 1) create system domains, 2) install and configure application specific components, 3) troubleshoot and resolve installation and operational issues, 4) conduct research efforts, 5) perform analysis, 6) perform regular and periodic security patching and upgrades, 7) assist in preparation efforts for application version rollout(s), and 8) provide and maintain system documents and artifacts. The Contractor shall review and validate software auto-deployment scripts and implementation plans prepared for installing CFSAN applications in the systems development lifecycle environments. During application deployments and releases, and at other times during normal operations, the contractor shall support CFSAN project teams and data center teams in:

1) executing scripts, 2) implementing manual installation steps when required, 3) identifying issues, and 4) troubleshooting, resolving problems, and assisting in rollback efforts where necessary.

4. Requirements

The contractor shall provide Enterprise Oracle database and application server support to include the following:

Task 1: Oracle Application Server Administration Support for Development, Test, Pre-Production, and Production environments:

1.1 The Contractor shall perform the following:

1.2 Install and configure Oracle WebLogic and other CFSAN application servers while following the recommended

OS configuration based on Oracle suggested best practices.

1.3 Manage, maintain, and monitor Oracle 12c and later WebLogic Application Server versions. Propose and provide server performance monitoring and tuning, as well as a written proposal for major performance tuning changes, as necessary.

1.4 Collaborate with other CFSAN IT project Contractors to plan and establish an integration environment at the ADC to support frequent releases by multiple CFSAN applications.

1.5 Research, document, and propose application server upgrades and migration alternatives to minimize impact on system availability to end users.

1.6 Review planned application server maintenance and enhancements. Provide feedback and recommendations.

1.7 Perform server software installation and configuration (memory size, clustering, write startup, and shutdown scripts).

1.8 Manage the Oracle Service Bus (OSB) Intranet/Extranet security model and documentation.

1.9 Prepare installation and configuration guides and detailed documentation on application server provisioning based on installations and configurations completed at all FDA data centers, including on-premises and cloud environments.

1.10 Perform application configuration in Oracle 12c and higher environments.

1.11 Capture and maintain an inventory of configuration details for the administered application server environments and systems in a spreadsheet at the CFSAN Infrastructure SharePoint site accessible to CFSAN project managers and technical leads. The information shall include: data center environment and location, host name and model, server operating system and version, application name, server resources, and usage.

1.12 Provide, document, and maintain software release information to include monitoring, verification, troubleshooting, lessons learned, and problem resolution.

1.13 Conduct/complete the application software version description document (VDD) modification and certification for the ADC installation.

1.14 Provide system hardening guide modification and certification for the ADC installation.

1.15 Implement a system backup strategy to ensure operation continuity of CFSAN systems.

1.16 Provide emergency recovery and support for CFSAN applications in all environments.

1.17 Assist and recommend tuning of Operating Systems that host CFSAN applications.

1.18 Provide server and system capacity planning and storage configuration information.

1.19 Coordinate after-hours shutdowns and restarts of Oracle software with systems administrators and application developers during patching and maintenance. Perform application system restarts during business hours, in coordination with other O&M and application development teams and with the approval of project stakeholders, to address performance or functionality issues or in response to any other adverse systems events.

1.20 Apply “one-off” and quarterly patches to application servers based on scheduled or ad hoc patch releases from the vendors to address all known common vulnerabilities and exploits. All patches shall, as much as possible, be applied in an automated fashion with reusable scripts deployed in all FDA environments.

1.21 Fully document and maintain routine activities, scripts, and SOPs on application domain maintenance procedures including routine activities. Review and update SOPs periodically.

1.22 Conduct knowledge transfer among the team members to enable efficient resource loading and coverage.

1.23 Establish SLAs with the development teams for each application server installation. Factors include, but are not limited to: hours of availability, backup frequency, backup type, backup retention requirements, and mean time to recover.

1.24 Provide a weekly written progress report detailing work performed, issues encountered, and resolution implemented.

1.25 Proactively upgrade and patch Oracle WebLogic Application Server, Java, ORACLE HTTP server, Fusion Middleware (WebCenter content, WebCenter Portal, and ORACLE Service Bus) to comply with current and evolving security standards which help prevent security breaches.

Applicable Enterprise Oracle Applications

The contractor shall provide O&M support for oracle database and Oracle application servers administration for the following applications:

HPSM – HP Service Manager ACD –Automated Call Directory ERwin – ERwin Data modeling tool Documentum – Document storage database REQPRO – Enterprise Requirements Repository

CISPRO

PRODEDCS – Enterprise Documentum JIRA – Enterprise Version Manager CDER Data Visualization CDRH Data Quality Management

ALM

RUEI

Extranet Oracle Access Manager Extranet Oracle Internet Directory

Task 2: Oracle Database Administration Support (Development, Test, Pre-Production, and Production environments): 180+ databases on 18 servers, Each environment has 45 databases listed below under applicable Enterprise and CFSAN Oracle Databases

The Contractor shall provide the following support for 250 databases on 18 servers in the 4 environments

(Development, Test, Pre-Production and Production)

• Provide Ongoing Operational & Maintenance of the CFSAN databases as well as decommission and consolidate existing databases as directed.

• Create and manage database objects.

• Create privileged database user accounts as required, while remaining in compliance with FDA ISSO security requirements. Implement database security best practices. Implement FDA IT Security policy on Role-based Access Control (RBAC).

• Perform database exports, imports, data refreshes, and transfers.

• Set and modify initialization parameters in the databases. Document all implemented changes.

• Manage new technologies and troubleshoot database related application issues.

• Monitor database performance at all tiers and implement tuning recommendations as necessary.

• Monitor database and ASM alert logs for CFSAN databases for any errors that might affect current or future performance and availability.

• Open and manage Service Requests with Oracle Support as pertains to any of the core Oracle technologies.

• Provide detailed installation and configuration documentation completed in the WODC environments. The documentation will be referenced for installation at the ADC to ensure consistency in all environments.

• Perform environment capacity planning for new databases and projected three-year growth in business operations volume.

• Review planned data center maintenance and enhancements when published. Provide feedback and recommendations. Provide staffing coverage for all maintenance activities that occur during business hours as well as evenings and weekends.

• Capture and maintain an inventory of configuration details for the administered database in a spreadsheet at the CFSAN Infrastructure SharePoint site accessible to CFSAN project technical leads. The information shall include: data center environment and location, host name and model, server operating system and version, database name, server and database resources, applications hosted, and usage.

• Fully document and maintain routine support activities, scripts, and standard operation procedures (SOPs) on database back up procedures. Review and update periodically.

• Conduct knowledge transfer to FDA DBAs and other Contractors to enable efficient resource loading and coverage.

• Establish service-level agreements (SLAs) with the development teams for each database server installation. Factors include hours of availability, backup frequency, backup type, backup retention requirements, and mean time to recover.

• Provide a written weekly progress report detailing work performed, issues encountered, and resolution implemented.

• The Contractor shall provide ongoing O&M support, patching, installs, and upgrades for new and existing CFSAN servers and applications. The Contractor shall support re-hosting to new FDA architectural platform(s) as required by FDA. The Contractor shall focus on preventing security issues through increased security monitoring, regular and periodic patching, timely upgrades, and by evaluating overall security protocols across CFSAN systems to mitigate risks.

• Monitor database performance at all tiers and implement tuning recommendations as necessary

• Monitor database and ASM alert logs for CFSAN databases for any errors that might affect current or future performance and availability.

• Open and manage Service Requests with Oracle Support as pertains to any of the core Oracle technologies.

• Provide detailed installation and configuration documentation completed in the WODC environments. The documentation will be referenced for installation at the ADC to ensure consistency in all environments.

• Provide Backup and Recovery including emergency recovery of systems as needed

• Manage and modify Security Hardening Guides as required by FDA IT Security

Applicable Enterprise Oracle Databases The contractor shall provide O&M support for the following Oracle Databases:

HPSC – HP Service Center ACD –Automated Call Directory ERwin – Data modeling tool Documentum – Document storage database REQPRO – Enterprise Requirements Repository

CISPRO

PRODEDCS – Enterprise Documentum PVCS – Enterprise Version Manager CDER Data Visualization

ALM

Applicable CFSAN Oracle Databases The contractor shall provide O&M support for the following Oracle Databases:

CAEMS

CAERS

ESD

TMS

STARI

DSLD

RAFT-MAP

IFTRACK II

FARM

CERES

CFORCE

CARTS

IMS

DSLD

WebMod

VCRP

FSMA108

CASPER

SBNLE

ColorCert

RSVP

Shellfish Shipper Food Defense 101 Food Defense Mitigation

FCRS

Seafood HAACP App Command

AWP

FLAPS

CARD

CASPER

ARCH

5. Project Management Support

The schedule of deliverables requires delivery of reports, meetings and draft documentation. The intention of these deliverables is to monitor the contractor’s progress towards delivering final documentation, specifications and systems within schedule and cost. The FDA understands that timely feedback will have to be provided to the contractor after the review of these deliverables.

The contractor shall provide the following:

5.1 In Progress Review Support

Provide a monthly status report monitoring progress against the Order Management Plan and the project schedule applied to the order. List everything that has been accomplished during the prior month broken down according to the project that was worked on.

Provide a monthly financial report by labor category, the monthly and cumulative hours, and dollars planned and expended, along with a projection of work to be completed to bring the contract to completion.

The reports shall be delivered by the tenth day of the following month.

5.2 Deliverable and Document Dissemination

Each document deliverable shall be delivered via e-mail to the COR. When a new document is delivered, or an update to existing documentation is made, the Contractor shall alert the COR of these changes.

5.3 Meeting Minutes and Agendas

The Contractor shall maintain and provide minutes of all meetings outlined in this SOW.

These minutes shall include the following:

• Summary description of all issues discussed

• Action Items

• Personnel to whom the Actions Items are assigned

• List of meeting attendees, including name, organization, phone number, and e-mail address.

All agendas shall be delivered at least 1 working day prior to the meeting unless the meeting is called at the last minute. All meeting minutes shall be delivered within 4 working days following the meeting.

5.4 Weekly Status Meetings

Weekly status meetings shall be held with the FDA Project Team to discuss general status of the project and any issues as they occur, as well as to gain any FDA management updates and feedback. Attend adhoc meetings as needed. Assist in producing reports to FDA senior management detailing data center migration status and answering various data calls.

All agendas shall be delivered at least 1 working day prior to the meeting.

All meeting minutes shall be delivered within 4 working days following the meeting.

5.5 Informal Project Review Meetings

Informal project reviews shall occur throughout the project. The primary purpose of these informal reviews shall be to discuss specific project activities and to address any potential problem areas that might arise, or have already arisen. These reviews may be called by the FDA COR, other Program Staff or by the Contractor on an as needed basis and may include participants from FDA senior management. All agendas shall be delivered at least 1 working day prior to the meeting. All meeting minutes shall be delivered within 4 working days following the meeting.

6. Deliverables

Task Description Estimated Quantity / Frequency Due Date Delivered to

5.1 Weekly report of all Open RFCs Weekly Weekly COR

5.2 Monthly Status Report Monthly By the 10th

of each month

COR

5.3 Meeting Agenda As needed One (1)

working day prior to meeting

COR

5.4 Meeting Minutes As needed Four (4) working

days after meeting COR

5.5 Project Reviews Monthly Monthly or as

requested by COR

COR

7. Inspection and Acceptance

The Government will review all reporting requirement deliverables in accordance with specifications and standards identified in the statement of work or any directives issued by the Contracting Officer Representative (COR). Reporting Requirements/Deliverables shall be submitted to the COR in accordance to the delivery schedule. The acceptance of deliverables and satisfactory work performance shall be based upon the timeliness and accuracy/quality of the deliverables.

The Contractor shall implement necessary changes within 10 business days, or a mutually agreed upon period of time, from the day of change notification.

The Contracting Officer’s Representative shall perform inspection and acceptance of materials and services.

8. Place of Performance

Due to the pandemic, contractor services will be performed offsite for the time being. If services are performed onsite at some point in the future, onsite contractors will work at 11601 Landsdown Street, North Bethesda, MD.

If occasional local travel is required to conduct meetings with business stakeholders within the Rockville, MD area, local travel will not be reimbursed.

9. Government Furnished Equipment

Government Furnished Equipment will consist of laptop computers and telephones.

10. Period of Performance

The anticipated period of performance shall be Base: May 1, 2022 through October 31, 2022.

Optional: Option Year 1: November 1, 2022 through October 31, 2023 Optional: Option Year 2: November 1, 2023 through October 31, 2024 Optional: Option Year 3: November 1, 2024 through October 31, 2025 Optional: Option Year 4: November 1, 2025 through October 31, 2026

11. Hours of Performance

The Contractor shall ensure that the Development, Test, and Pre-Production environments are up and running during the workweek from 07:00am through 7:00pm unless pre-approved COR or COR designee scheduled downtime has been approved.

The Contractor shall ensure that the production environment is up and running 24/7/365 in order to meet specific customer requirements unless COR or COR designee scheduled downtime has been approved.

12. Section 508 Compliance

HHSAR Clause 352.239-74 Electronic and Information Technology Accessibility is applicable to this task order. See clause section for full text.

13. Government Points of Contact

Contracting Officer (CO)

TBD

Contracting Officer’s Representative (COR):

Delores Johnson U.S. Food and Drug Administration Office of Information Management and Technology 3 White Flint North: Rm 11A21 11601 Landsdown Street North Bethesda, MD 20852 301-796-7771 delores.johnson@fda.hhs.gov

The COR may be changed at any time by the Government without prior notice to the Contractor by a unilateral modification to the Contract. The responsibility and limitation of the COR are as follows: (1) The COR is responsible for the technical aspects of the project and serves as the technical liaison with the Contractor. The COR is also responsible for the final inspection and acceptance of all reports, and such other responsibilities as may be specified in the contract. (2) The COR is not authorized to make any commitments or otherwise obligate the Government or authorize any changes which affect the Contract price, terms or conditions. Any Contractor request for changes shall be referred to the Contraction Officer directly or through the COR. No such changes shall be made without the expressed prior authorization of the Contracting Officer (CO). The CO may designate assistant or alternate COR to act for the COR by naming such assistant/alternate(s) in writing and transmitting a copy of such designation to the Contractor.

14. Order Type

The Order Type is Firm-Fixed-Price.

mailto:delores.johnson@fda.hhs.gov

15. Payment and Invoice Instructions

The Contractor shall invoice 1/12th the value of the order monthly.

FDA Electronic Invoicing and Payment Requirements - Invoice Processing Platform (IPP) (Jan 2022)

(a) All Invoice submissions for goods and or services must be made electronically through the U.S.

Department of Treasury’s Invoice Processing Platform System (IPP).

http://www.ipp.gov/vendors/index.htm

(b) Invoice Submission for Payment means any request for contract financing payment or invoice payment by the Contractor. To constitute a proper invoice, the payment request must comply with the requirements identified in in FAR 32.905(b), “Content of Invoices” and the applicable Payment clause included in this contract, or the clause 52.212-4 Contract Terms and Conditions – Commercial Items included in commercial items contracts. The IPP website address is: https://www.ipp.gov.

(c) -----

(1) The Agency will enroll the Contractors new to IPP. The Contractor must follow the IPP registration email instructions for enrollment to register the Collector Account for submitting invoice requests for payment. The Contractor Government Business Point of Contact (as listed in SAM) will receive Registration email from the Federal Reserve Bank of St. Louis (FRBSTL) within 3 – 5 business days of the contract award for new contracts or date of modification for existing contracts.

(2) Registration emails are sent via email from ipp.noreply@mail.eroc.twai.gov. Contractor assistance with enrollment can be obtained by contacting the IPP Production Helpdesk via email to IPPCustomerSupport@fiscal.treasury.gov or phone (866) 973-3131.

(3) The Contractor POC will receive two emails from IPP Customer Support, the first email contains the initial administrative IPP User ID. The second email, sent within 24 hours of receipt of the first email, contains a temporary password. You must log in with the temporary password within 30 days.

(4) If your company is already registered to use IPP, you will not be required to re-register.

(5) If the Contractor is unable to comply with the requirement to use IPP for submitting invoices for payment as authorized by HHSAR 332.7002, a written request must be submitted to the Contracting Officer to explain the circumstances that require the authorization of alternate payment procedures.

(d) Invoices that include time and materials or labor hours Line Items must include supporting documentation to (1) substantiate the number of labor hours invoiced for each labor category, and (2) substantiate material costs incurred (when applicable).

(e) Invoices that include cost-reimbursement Line Items must be submitted in a format showing expenditures for that month, as well as contract cumulative amounts.

(1) At a minimum the following cost information shall be included, in addition to supporting documentation to substantiate costs incurred.

- Direct Labor - include all persons, listing the person's name, title, number of hours worked, hourly rate, the total cost per person and a total amount for this category;

- Indirect Costs (i.e., Fringe Benefits, Overhead, General and Administrative, Other Indirects)- show rate, base and total amount;

- Consultants (if applicable) - include the name, number of days or hours worked, daily or hourly rate, and a total amount per consultant;

- Travel - include for each airplane or train trip taken the name of the traveler, date of travel, destination, the transportation costs including ground transportation shown separately and the per diem costs. Other travel costs shall also be listed;

- Subcontractors (if applicable) - include, for each subcontractor, the same data as required for the prime Contractor;

- Other Direct Costs - include a listing of all other direct charges to the contract, i.e., office supplies, telephone, duplication, postage; and

- Fee – amount as allowable in accordance with the Schedule and FAR 52.216-8 if applicable.

(f) Contractor is required to attach an invoice log addendum to each invoice which shall include, at a minimum, the following information for contract administration and reconciliation purposes:

(1) list of all invoices submitted to date under the subject award, including the following:

- invoice number, amount, & date submitted

- corresponding payment amount & date received

- total amount of all payments received to date under the subject contract or order

- and, for definitized contracts or orders only, total estimated amounts yet to be invoiced for the current, active period of performance.

(g) Payment of invoices will be made based upon acceptance by the Government of the entire task or the tangible product deliverable(s) invoiced. Payments shall be based on the Government certifying that satisfactory services were provided, and the Contractor has certified that labor charges are accurate.

(h) If the services are rejected for failure to conform to the technical requirements of the task order, or any other contractually legitimate reason, the Contractor shall not be paid, or shall be paid an amount negotiated by the CO.

(i) Payment to the Contractor will not be made for temporary work stoppage due to circumstances beyond the control of U.S. Food and Drug Administration such as acts of God, inclement weather, power outages, and results thereof, or temporary closings of facilities at which Contractor personnel are performing. This may, however, be justification for excusable delays.

(j) The Contractor agrees that the submission of an invoice to the Government for payment is a certification that the services for which the Government is being billed, have been delivered in accordance with the hours shown on the invoices, and the services are of the quality required for timely and successful completion of the effort.

(k) Questions regarding invoice payments that cannot be resolved by the IPP Helpdesk should be directed to the FDA Employee Resource and Information Center (ERIC) Helpdesk at 301-827-ERIC (3742) or toll-free 866-807-ERIC (3742); or, by email at ERIC@fda.hhs.gov. Refer to the Call-in menu options and follow the phone prompts to dial the option that corresponds to the service that's needed. All ERIC Service Now Tickets will either be responded to or resolved within 48 hours (2 business days) of being received. When emailing, please be sure to include the contract number, invoice number and date of invoice, as well as your name, phone number, and a detailed description of the issue.

16. Technical Guidance Letter

1. As necessary, technical guidance or clarification concerning the details of specific services to be performed under the terms of this contract/order shall be given through issuance of Technical Guidance Letters (TGL) by the Contracting Officer's Representative (COR) using email or other electronic means. To be valid a TGL, it must be within the general scope of work stated in the contract/order, and it would not require any increase to the negotiated price and/or adjust the delivery terms under the contract.

2. Each TGL issued hereunder is subject to the terms and conditions of this contract. It shall be in writing and include, as a minimum, the following information:

a. Effective date of TGL;

b. Contract/Order and sequential TGL number;

c. Reference to the relevant section in the statement of work; and

d. Requirements to be performed.

3. The Contractor shall not comply with any TGL, if the Contractor believes it is not a valid TGL.

In the event of a conflict between a TGL and the scope of the contract/order, the terms of the contract/order shall prevail. If the Contractor believes or has reason to believe that a TGL is not valid, the Contractor shall notify the COR and Contracting Officer thereof by email within two (2) days of receiving the TGL in question. The Contracting Officer will give appropriate direction to the Contractor and COR to resolve the TGL issue.

4. Oral technical directions may be given by the COR only in emergency circumstances. The Contractor shall notify the Contracting Officer by email that it has received such direction within 24 hours of having received the directions. If the COR does not follow-up the oral directions within two (2) working days by issuing a written TGL, the Contractor is to notify the Contracting Officer and cease compliance unless the Contractor concurs the direction is a valid TGL.

5. Technical Guidance provided in meetings with minutes submitted by the Contractor for Government acceptance does not need to be documented via TGL. The Technical Guidance shall be documented in the meeting minutes.

6. Contractor’s failure to comply with this clause is grounds for finding that incurred costs are not allowable.

The Contractor shall meet and adhere to the following security requirements:

• Comply with the Federal Information Security Management Act (FISMA) 2002

• Comply with and supply a resource to assist with the FDA Security Authorization process, which closely resembles NIST SP800-37

• Establish a continuous monitoring capability in accordance with NIST SP 800-137

• Maintain an accurate inventory of all devices used in the performance of the contract

• Complete the FDA recommended templates of security artifacts for development or maintenance of any IT system

• Review all identified and applicable weaknesses within the Plan of Action and Milestones and provide a resolution within the required timeline

• Employees with access to data will be required to undergo a Level 5 Public Trust security clearance

• Sign non-disclosure agreement FDA Form 3398: Contractor’s Commitment to Protect Non-Public

Information (NPI) Agreement

• Comply with NIST SP800-53

• Comply with all FISMA, NIST and OMB requirements

• Comply with FDA 3250 series of SMG policies, as well as HHS security policies. Note: SMG 3251.4

Outsourcing and Third-Party Arrangements

• Comply with the FDA approved technologies list and use FDA issued laptop/workstations

17. Key Personnel

The Key Personnel specified in each Order are considered to be essential to work performance. At least 30 days prior to diverting any of the specified individuals to other programs or contracts (or as soon as possible, if an individual must be replaced, for example, as a result of leaving the employ of the contractor), the contractor shall notify the Contracting Officer and shall submit comprehensive justification for the diversion or replacement request (including proposed substitutions for Key Personnel) to permit evaluation by the Government of the impact on performance under each Order. The contractor shall not divert or otherwise replace any Key Personnel without the written consent of the Contracting Officer. The Government may modify the Orders to add or delete key personnel at the request of the contractor or Government.

Role

Senior Principal Consultant (Sr DB Management Specialist)

18. Security and Confidential Treatment of Sensitive Information

18.1 Security Requirements

A. Baseline Security Requirements

1) Applicability. The requirements herein apply whether the entire contract or order (hereafter

“contract”), or portion thereof, includes either or both of the following:

a. Access (Physical or Logical) to Government Information: A Contractor (and/or any subcontractor) employee will have or will be given the ability to have, routine physical (entry) or logical (electronic) access to government information.

b. Operate a Federal System Containing Information: A Contractor (and/or any subcontractor) will operate a federal system and information technology containing data that supports the HHS mission. In addition to the Federal Acquisition Regulation (FAR) Subpart 2.1 definition of “information technology” (IT), the term as used in this section includes computers, ancillary equipment (including imaging peripherals, input, output, and storage devices necessary for security and surveillance), peripheral equipment designed to be controlled by the central processing unit of a computer, software, firmware and similar procedures, services (including support services), and related resources.

2) Safeguarding Information and Information Systems. In accordance with the Federal Information Processing Standards Publication (FIPS)199, Standards for Security Categorization of Federal Information and Information Systems, the Contractor (and/or any subcontractor) shall:

a. Protect government information and information systems in order to ensure:

• Confidentiality, which means preserving authorized restrictions on access and disclosure, based on the security terms found in this contract, including means for protecting personal privacy and proprietary information;

• Integrity, which means guarding against improper information modification or destruction, and ensuring information non-repudiation and authenticity; and

• Availability, which means ensuring timely and reliable access to and use of information.

b. Provide security for any Contractor systems, and information contained therein, connected to an FDA network or operated by the Contractor on behalf of FDA regardless of location. In addition, if new or unanticipated threats or hazards are discovered by either the agency or contractor, or if existing safeguards have ceased to function, the discoverer shall immediately, within one (1) hour or less, bring the situation to the attention of the other party. This includes notifying the FDA Systems Management Center (SMC) within one (1) hour of discovery/detection in the event of an information security incident.

c. Adopt and implement the policies, procedures, controls, and standards required by the HHS/FDA Information Security Program to ensure the confidentiality, integrity, and availability of government information and government information systems for which the Contractor is responsible under this contract or to which the Contractor may otherwise have access under this contract. Obtain the FDA Information Security Program security requirements, outlined in the FDA Information Security and Privacy Policy (IS2P), by contacting the CO/COR or emailing your ISSO.

d. Comply with the Privacy Act requirements and tailor FAR clauses as needed.

3) Information Security Categorization. In accordance with FIPS 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60, Volume II: Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories, Appendix C, and based on information provided by the ISSO or other security representative, the risk level for each Security Objective and the Overall Risk Level, which is the highest watermark of the three factors (Confidentiality, Integrity, and Availability) of the information or information system are the following:

Confidentiality: [ ] Low [ ] Moderate [X] High

Integrity: [ ] Low [ ] Moderate [X] High

Availability: [ ] Low [ ] Moderate [X] High

Overall Risk Level: [ ] Low [ ] Moderate [X] High

Note that the ORA systems are managed within several security “boundaries”, and thus different Risk Levels may be assigned to different systems. The assessment above is for the highest risk systems.

Based on information provided by the Privacy Office, system/data owner, or other privacy representative, it has been determined that this solicitation/contract involves:

[ ] No PII [X] Yes PII

Note that some, but not all, ORA systems contain PII.

Personally Identifiable Information (PII). Per the OMB Circular A-130, “PII is information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual.” Examples of PII include, but are not limited to the following: Social Security number, date and place of birth, mother’s maiden name, biometric records, etc.

PII Confidentiality Impact Level has been determined to be: [ ] Low [ ] Moderate [ x ] High

4) Controlled Unclassified Information (CUI). CUI is defined as “information that laws, regulations, or Government-wide policies require to have safeguarding or dissemination controls, excluding classified information.” The Contractor (and/or any subcontractor) must comply with Executive Order 13556, Controlled Unclassified Information, (implemented at 3 CFR, part 2002) when handling CUI. 32 C.F.R. 2002.4(aa). As implemented the term “handling” refers to “…any use of CUI, including but not limited to marking, safeguarding, transporting, disseminating, re-using, and disposing of the information.” 81 Fed. Reg. 63323. All sensitive information that has been identified as CUI by a regulation or statute, handled by this solicitation/contract, shall be:

a. marked appropriately;

b. disclosed to authorized personnel on a Need-To-Know basis;

c. protected in accordance with NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations applicable baseline if handled by a Contractor system operated on behalf of the agency, or NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations if handled by internal Contractor system; and

d. returned to FDA control, destroyed when no longer needed, or held until otherwise directed. Destruction of information and/or data shall be accomplished in accordance with NIST SP 800-88, Guidelines for Media Sanitization and the FDA IS2P Appendix T:

Sanitization of Computer-Related Storage Media.

5) Protection of Sensitive Information. For security purposes, information is or may be sensitive because it requires security to protect its confidentiality, integrity, and/or availability. The Contractor (and/or any subcontractor) shall protect all government information that is or may be sensitive in accordance with OMB Memorandum M-06-16, Protection of Sensitive Agency Information by securing it with a FIPS 140-2 validated solution.

Confidentiality and Nondisclosure of Information. Any information provided to the contractor (and/or any subcontractor) by FDA or collected by the contractor on behalf of FDA shall be used only for the purpose of carrying out the provisions of this contract and shall not be disclosed or made known in any manner to any persons except as may be necessary in the performance of the contract. The Contractor assumes responsibility for protection of the confidentiality of Government records and shall ensure that all work performed by its employees and subcontractors shall be under the supervision of the Contractor. Each Contractor employee or any of its subcontractors to whom any FDA records may be made available or disclosed shall be notified in writing by the Contractor that information disclosed to such employee or subcontractor can be used only for that purpose and to the extent authorized herein.

The confidentiality, integrity, and availability of such information shall be protected in accordance with HHS and FDA policies. Unauthorized disclosure of information will be subject to the HHS/FDA sanction policies and/or governed by the following laws and regulations:

1. 18 U.S.C. 641 (Criminal Code: Public Money, Property or Records);

2. 18 U.S.C. 1905 (Criminal Code: Disclosure of Confidential Information); and

3. 44 U.S.C. Chapter 35, Subchapter I (Paperwork Reduction Act).

6) Internet Protocol Version 6 (IPv6). All procurements using Internet Protocol shall comply with OMB Memorandum M-05-22, Transition Planning for Internet Protocol Version 6 (IPv6).

7) Government Websites. All new and existing public-facing government websites must be securely configured with Hypertext Transfer Protocol Secure (HTTPS) using the most recent version of Transport Layer Security (TLS). In addition, HTTPS shall enable HTTP Strict Transport Security (HSTS) to instruct compliant browsers to assume HTTPS at all times to reduce the number of insecure redirects and protect against attacks that attempt to downgrade connections to plain HTTP. For internal-facing websites, the HTTPS is not required, but it is highly recommended.

8) Contract Documentation. There are no specific privacy/security deliverables for this contract.

9) Standard for Encryption. The Contractor (and/or any subcontractor) shall:

a. Comply with the HHS Standard for Encryption of Computing Devices and Information to prevent unauthorized access to government information.

b. Encrypt all sensitive federal data and information (i.e., PII, protected health information [PHI], proprietary information, etc.) in transit (i.e., email, network connections, etc.) and at rest (i.e., servers, storage devices, mobile devices, backup media, etc.) with FIPS 140-2 validated encryption solution.

c. All devices (i.e.: desktops, laptops, mobile devices, etc.) that store, transmit, or process non-public FDA information should utilize FDA-provided or FDA information security authorized devices that meet HHS and FDA-specific encryption standard requirements.

Maintain a complete and current inventory of all laptop computers, desktop computers, and other mobile devices and portable media that store or process sensitive government information (including PII).

d. Verify that the encryption solutions in use are compliant with FIPS 140-2. The Contractor shall provide a written copy of the validation documentation to the COR.

e. Use the Key Management system on the HHS Personal Identification Verification (PIV) card or establish and use a key recovery mechanism to ensure the ability for authorized personnel to encrypt/decrypt information and recover encryption keys. Encryption keys (PIV card) shall be provided to the COR upon request and at the conclusion of the contract. Upon completion of contract, contractor ensures that COR is able to access and read any encrypted data.

10) Contractor Non-Disclosure Agreement (NDA). Each Contractor (and/or any subcontractor) employee having access to non-public government information under this contract shall complete the FDA non-disclosure agreement (3398 Form), as applicable. A copy of each signed and witnessed NDA shall be submitted to the CO and/or COR prior to performing any work under this acquisition.

11) Privacy Threshold Analysis (PTA)/Privacy Impact Assessment (PIA) – The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee with conducting a PTA for the information system and/or information handled under this contract to determine whether or not a full PIA needs to be completed.

a. If the results of the PTA show that a full PIA is needed, the Contractor shall assist procuring activity representative, program office and the FDA SOP or designee with completing a PIA for the system or information after completion of the PTA and in accordance with HHS and FDA policy and OMB M-03-22, Guidance for Implementing the Privacy Provisions of the E-Government Act of 2002. The PTA/PIA must be completed and approved prior to active use and/or collection or processing of PII and is a prerequisite to agency issuance of an authorization to operate (ATO).

b. The Contractor shall assist the procuring activity representative, program office and the FDA SOP or designee in reviewing and updating the PIA at least every three years throughout the Enterprise Performance Life Cycle (EPLC) /information lifecycle, or when determined by the agency that a review is required based on a major change to the system, or when new types of PII are collected that introduces new or increased privacy risks, whichever comes first.

B. Training

1) Mandatory Training for All Contractor Staff. All Contractor (and/or any subcontractor) employees assigned to work on this contract shall complete the applicable FDA Contractor Information Security Awareness, Privacy, and Records Management training (provided upon contract award) before performing any work under this contract. Thereafter, the employees shall complete FDA Information Security Awareness, Privacy, and Records Management training at least annually, during the life of this contract. All provided training shall be compliant with HHS and FDA training policies.

2) Role-based Training. All Contractor (and/or any subcontractor) employees with significant security responsibilities (as determined by the program manager) must complete role-based training annually commensurate with their role and responsibilities in accordance with HHS and FDA policy and FDA Role-Based Training (RBT) of Personnel with Significant Security Responsibilities Standard Operating Procedures (SOP).

3) Training Records. The Contractor (and/or any subcontractor) shall maintain training records for all its employees working under this contract in accordance with HHS and FDA policy. A copy of the training records shall be provided to the CO and/or COR within 30 days after contract award and annually thereafter or upon request.

C. Rules of Behavior

1) The Contractor (and/or any subcontractor) shall ensure that all employees performing on the contract comply with the HHS Information Technology General Rules of Behavior.

2) All Contractor employees performing on the contract must read and adhere to the Rules of Behavior (ROB) before accessing HHS and FDA data or other information, systems, and/or networks that store/process government information, initially at the beginning of the contract and at least annually thereafter, which may be done as part of annual FDA Information Security Awareness Training. If the training is provided by the contractor, the signed ROB must be provided as a separate deliverable to the CO and/or COR per defined timelines.

D. Incident Response

The Contractor (and/or any subcontractor) shall respond to all alerts/Indicators of Compromise (IOCs) provided by HHS Computer Security Incident Response Center (CSIRC)/FDA SMC /Incident Response Team (IRT) teams within 24 hours, whether the response is positive or negative.

FISMA defines an incident as “an occurrence that (1) actually or imminently jeopardizes, without lawful authority, the integrity,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .