Attachment A-Statement of Objectives.docx
DOCX document 54 KB Posted
- Attached to
- Space Management Services Federal contract opportunity
- Solicitation number
- 05GA0A22Q0029
About this file
This statement of objectives document outlines requirements for an integrated workplace management system and space management services. The Government Accountability Office seeks a commercial off-the-shelf software as a service solution to manage its 1.9 million square foot headquarters building and 215,000 square feet across eleven field offices. The selected contractor must provide 100 user licenses, including the ability to reserve 6,000 workspaces and 400 conference rooms. Key capabilities of the required system include floor plans, employee and asset data management, space forecasting and utilization reporting, and integration with AutoCAD, ServiceNow, Maximo and other existing platforms. The contract would have a one year base period and four one year options, with full implementation expected in the base year. The contractor must host the solution in a FedRAMP moderate impact cloud environment and provide related project management, data migration, training, help desk support and maintenance services.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 05GA0A22Q0029-Questions and Answers 11Aug 2022.pdf | ||
| RFQ Amendment 0001 (SF30 - 05GA0A22Q0029).pdf | ||
| RFQ Amendment 0001 (GAO Records Retention Schedules - Space Management Services).pdf | ||
| 05GA0A22Q0029-SF1449 (Signed Copy).pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Integrated Workplace Management System (IWMS)/ Attachment A-Space Management SOO
Government Accountability Office
STATEMENT OF OBJECTIVES FOR INTEGRATED WORKPLACE MANAGEMENT SYSTEM (IWMS)/ SPACE MANAGEMENT:
Table of Contents
| 1. | Purpose | 3 |
| 2. | Scope | 3 |
| 3. | Period and Place of Performance | 3 |
| 4. | Background | 3 |
| 5. | Objectives | 4 |
| 5.1. | Software License Objectives: | 4 |
| 5.2. | System Configuration and Installation Objectives | 5 |
| 5.3. | Cloud Hosting Objectives | 8 |
| 5.4. | Project Management Objectives | 9 |
| 5.5. | Data Migration and Integration Objectives | 10 |
| 5.6. | Training Objectives | 10 |
| 6. | Requirements: IT Security and Operations Management | 11 |
| 6.1. | Audit Log Management | 12 |
| 6.2. | Authentication | 12 |
| 6.3. | Backup and Restoration | 12 |
| 6.4. | Data Management | 13 |
| 6.5. | Incident Response | 13 |
| 6.6. | Media Protection | 13 |
| 6.7. | Personnel Security | 14 |
| 6.8. | Privacy Protections | 15 |
| 6.9. | Protection of Information at Rest | 15 |
| 6.10. | Secure Communications | 15 |
| 6.11. | Security Alerts, Advisories, and Directives | 16 |
| 6.12. | System Availability | 16 |
| 6.13. | System Use Notification Banner | 16 |
| 6.14. | Testing Services | 16 |
| 6.15. | Vulnerability Management | 17 |
| 6.16. | Deployment of System | 18 |
| 7. | Deliverables | 18 |
1. Purpose The purpose of this acquisition is to acquire an Integrated Workplace Management System (IWMS) that will be delivered as a web-based, commercial-off-the-shelf, managed services product in a secure cloud environment that is designed and configured within the continental United States for the Government Accountability Office (GAO). The Contractor supporting GAO shall follow the Federal Information Security Modernization Act of 2014 (FISMA) and, at a minimum, shall offer an IT solution that is compliant with the legislation’s Agency Program requirements. GAO requests that the Contractor provide a system that includes the functions and capabilities specified in this SOO. The Contractor shall incorporate both industry and federal government best practices and standards with the proposed system.
2. Scope The scope of this acquisition is to acquire a managed services Integrated Workplace Management System (IWMS) that is in a FedRamp Certified cloud based environment. This system must specifically support GAO's Infrastructure Operations personnel with the ability to maintain space inventory. It needs to act as a repository for AutoCAD and Revit drawings, employee data, provide interactive stack diagrams and block planning, and access floor plans for redlining and scenario markups. It needs to establish workflow-enabled space survey processes that will include equipment, furniture, assets, new hires, separating employees, and in-depth reporting attributes.
Additional attributes shall include: listing square footage for each space, linking employees to locations, creating new or adding to existing move orders, managing individual and group moves, creating an automated workflow with email notifications, providing move scenarios for comparison, triggering move projects, and updating completed move seat assignments.
3. Period and Place of Performance This acquisition will be for 1 base year and four (4) one (1) year option periods. The system / solution shall be fully implemented during the base year of the contract. All configurations and designed and cloud hosting services must be within the continental United States.
4. Background The Government Accountability Office (GAO) is an independent, nonpartisan agency that works for Congress. GAO is headquartered in Washington DC. GAO has eleven (11) field offices around the continental USA. GAO’s headquarters (HQ) comprises seven (7) floors, a penthouse, basement, and subbasement level. The GAO HQ building has 1.9 million square feet and currently houses 4000 employees. GAO’s field offices total an estimated 215,000 square feet. GAO’s Infrastructure and Operations (IO) team has a need for an Integrated Workspace Management Software and Service (IWMS), also described as a Space Management (SM) contract.
5. Objectives The following objectives listed below describes in details GAO requirements for a fully operational.
· Objective 1 – Software Licenses
· Objective 2- System Configuration and Installation
· Objective 3 – Hosting
· Objective 4 – Project Management
· Objective 5 – Data Migration and Integration
· Objective 6- Training
· Objective 7- Maintenance and Post Implementation Support
5.1. Software License Objectives:
5.1.1. Provide GAO with a detail list of software licenses for IWMS System to include different modules licenses that are needed to accommodate one hundred (100) concurrent user licenses. The 100 software licenses must include an option to reserve/schedule 6,000 workspaces (offices and cubicles) and 400 Conference/Team rooms. The software license must incorporate the functional and technical capabilities requested in this SOO listed below in the system configurations section.
5.1.2. The software shall include the capability to breakout user licenses by read-only users, standard users (ability to input data and create service requests), and enterprise users/system admins.
5.1.3. Software /System requirements shall include a pre-integrated modular structure with a shared database, data input and analysis, workflow automation, that is interoperable with enterprise and other platforms that have analytics and reports, AutoCAD document management, and the ability to add-on capacity/increase scale.
5.1.4. The software licenses shall have the capability to allow users to access the software on GAO networked device such as any Dell, HP, or Macintosh desktop, laptop and mobile devices such as Apple IPhone, android devices, or tablets such Dell, Microsoft Surface Pros, or IPad.
5.2. System Configuration and Installation Objectives
5.2.1. The Contractor shall install and configure the Integrated Workplace Management System (IWMS) for GAO. The IWMS system shall operate as a managed service within an authorized cloud environment by the vendor.
5.2.2. The system shall provide configurable access to contractor’s hosted system through a dedicated Virtual Private Network (VPN).
5.2.3. The system shall authenticate GAO users using modern authentication services such as Active Directory Federation Services (ADFS).
5.2.4. The system shall allow for Single Sign-On (SSO)
5.2.5. The system shall allow users to log in from any equipment using internet
5.2.6. The system shall be able to do a 2-way interface with 5 GAO systems from AutoCAD, Service Now, Maximo (IBM) software, Human Resource Data Source (my locator) and Microsoft 365 in the cloud
5.2.7. The system shall be able to provide 2 way interfaces with 5 GAO systems and/or software (AutoCAD, Service Now, Maximo, Human Resource Data Source (my locator) and Microsoft 365 in the cloud).
5.2.8. The system shall provide information on all spaces in the GAO building.
5.2.9. The system shall provide floor plans that contain the following for GAO occupied locations: Space function, vacant or occupied, occupants’ name (except for vacant spaces), and square footage (Sf. ft.).
5.2.10. The system shall provide accurate reports, downloadable to EXCEL, that list all spaces.
5.2.11. The system shall provide the capability for architectural modifications due to alterations.
5.2.12. The system shall provide entry fields for space finish tracking that supports a space planning program to capture space finishes, such as the last paint job and carpet replacement.
5.2.13. The system shall provide a function to upload, reflect, and integrate new floor plans.
5.2.14. The system shall reflect any changes being made in AutoCAD software and uploaded to the space management system
5.2.15. The system shall provide illustrations of spaces of different types such as floors, rooms, administrative units and workstations.
5.2.16. The system shall provide the capability of maintaining a robust list of attributes about individual spaces, for example: Room number, date of entry, date of exit, Type of office – (SES window office, standard window office, standard interior office, window workstation, interior workstation, intern workstation, touch-down workstation)
5.2.17. The system shall provide Data Input and/or Drop Down Fields for each room/cubicle: Team Name, Square Footage, Occupant Name, Telephone #, Email Address, Accommodations, Employee Status (FTE/Contractor/Intern), Special use room – conference, team, VTC, file, storeroom, secure room, furniture type, floor finishes, wall finishes
5.2.18. The system shall provide tracking of occupancy and vacancy based on capacity for multiple buildings
5.2.19. The system shall provide delineated space and usage by the teams /organizations
5.2.20. The system shall list square footage for every space in the building including corridors, elevators, and vertical spaces
5.2.21. The system shall provide data fields for conference room characteristics such as AV equipment, rooms set-up and capacity
5.2.22. The system shall provide predefined space utilization reports on demand
5.2.23. The system shall have the ability to assign employees to temporary or permanent available space
5.2.24. The system shall manage space requirements and link them to scenarios and projects
5.2.25. The system shall provide the ability to plan mass moves, as well as one time individual moves
5.2.26. The system shall provide mass move sequencing scenarios and recommendations
5.2.27. The system shall provide automated workflows with email notifications
5.2.28. The system shall provide a way to estimates for move costs
5.2.29. The system shall generate and track move request inputted by employees, space contacts, and teams
5.2.30. The system shall provide entry fields and track contents of an employee’s boxes and furnishings that need to be moved with them
5.2.31. The system shall have capability to track move-in and move-out dates to prevent an employee moving into a space that has yet to be vacated
5.2.32. The system shall generate reports (i.e., move history, move costs, move trends over user-defined time periods, conference room reports, space utilization reports, and buildings layout
5.2.33. The system shall generate ad-hoc reports
5.2.34. The system shall provide reporting that outline changes to workspaces data and buildings layouts and designs
5.2.35. The system shall provide audit log and account management reports
5.2.36. The system shall provide space projections / forecasts based on headcount projections, percentage growth or total area
5.2.37. The system shall provide interactive blocking plans and stacking diagrams based on various scenarios in a graphical display
5.2.38. The system shall generate a comparison between space standards and space allocations
5.2.39. The system shall provide both graphical display and text reporting of vacant, underutilized or over utilized spaces
5.2.40. The system shall provide bi-directional link to AutoCAD for area calculations, space labeling and graphic displays of database queries
5.2.41. The system shall integrates legacy and current data for AutoCAD and Revit
5.2.42. The system shall create presentations to share space options
5.2.43. The system shall provide Redline drawings for project comments within the system
5.2.44. The system shall provide workspace reservation scenarios with social distancing principles and parameters pre-programed on 6,000 workspaces (offices and cubicles) and 400 Conference/Team rooms
5.2.45. The system shall provide a configurable dashboard
5.2.46. The system shall provide a configurable module to create business rules and criteria associated with managing COVID related building data-driven re-entry requirements
5.2.47. The system shall provide the following system modules: Space Planning, Asset Management, Strategic Planning, Move Management, Facility Management, and Reporting
5.2.48. Provides compliance with the Federal Section 508 requirements or the Web Content Accessibility Guidelines (WCAG) 2.0 AA or higher. Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use information and communication technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public who have disabilities must have access to, and use of, information and data that is comparable to people without disabilities. Published and maintained by The Web Accessibility Initiative (WAI) of The World Wide Web Consortium (W3C), The Web Content Accessibility Guidelines (WCAG) covers a wide range of recommendations for making Web content more accessible. Following these guidelines will make content accessible to a wider range of people with disabilities, including blindness and low vision, deafness and hearing loss, learning disabilities, cognitive limitations, limited movement, speech disabilities, photosensitivity and combinations of these. Following these guidelines will also often make your Web content more usable to users in general. These guidelines were incorporated by reference in Section 508 in the final rule Published by the US Access Board in the Federal Register on January 18, 2017, and which went into effect on January 18, 2018. Products, platforms and services delivered as part of this work statement that are ICT, or contain ICT, must conform to either the provisions of the Revised 508 Standards, or the Web Content Accessibility Guidelines (WCAG 2.0)-AA or higher (or both). The latest addition of the 508 standards may be found on the US Access Board’s web site at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines, and the Web Content Accessibility Guidelines may be found on The World Wide Web Consortium (W3C) Web Accessibility Initiative (WAI) page at https://www.w3.org/WAI/Compliance with the above standards must be documented with a Voluntary Product Accessibility Template (VPAT) or an Accessibility Conformance Report (ACR). These standard reporting documents were developed by the Information Technology Industry Council (ITIQ), and can be found at https://www.itic.org/policy/accessibility/vpat Provide a master test plan that will outline all of GAO testing requirements. The required testing documentation must describe how a Quality Assurance (QA) environment will be able to support User Acceptance Testing (UAT)
5.3. Cloud Hosting Objectives
5.3.1. The contractor shall provide either infrastructure (IaaS), platform (PaaS) or software (SaaS) IWMS solution that will be installed, configured and operated as a managed service within an authorized cloud environment. GAO staff and contractors will access the system using a modern web browser.
5.3.2. The cloud-based managed service shall have a Fed RAMP hosting authorization at either the infrastructure (IaaS), platform (PaaS) or software (SaaS) with at least a FIPS security classification of Moderate. The system shall not use proprietary code that cannot transferable to other environments.
5.3.3. The Contractor shall manage and control the underlying cloud infrastructure, including network, servers, operating systems, and storage. GAO shall be permitted access to limited user-specific application configuration settings.
5.3.4. The Contractor shall work with the GAO ISTS security team to design, configure, and test the application security, including establishing end-user roles and organizational access security templates.
5.4. Project Management Objectives
5.4.1. The contractor shall describe in detail the Project Management methodology that constitute a successful implementation space management system by effectively outlining and describe the following PM areas; People, Plan Process?
5.4.2. The Contractor shall provide a dedicated and experienced project manager (PM) responsible for all services and deliverables, and who shall work to ensure on-time delivery and successful deployment of the IWMS solution. This individual will be dedicated to the project and will function as GAO's primary point of contact. The PM shall comply with the following:
Understand the stakeholder's requirements, effectively communicate with GAO, and manage issues and resources throughout the project.
Identify risk and provide mitigation/resolution plans early in the planning phase and throughout the project's lifecycle.
Develop and maintain a plan that describes activities, roles, responsibilities, and scheduling related to the review, coordination, scheduling, and testing of the implementation deployment.
Meeting with GAO Infrastructure and Operations subject matter experts to understand our business processes and gather more detailed business requirements;
Identification of GAO's current operational processes and procedures (as is) and provision of recommendation for improving the processes;
Identification of change impacts in terms of process, policy, and skillsets;
Delivery of documentation of a fully designed integrated IWMS, identifying requirements met, and functionality delivered. Documentation should indicate the functionality which is delivered.
5.4.3. The Contractor shall provide system design document that incorporates GAO's technical requirements. Before creating a detailed design or start of any development/configuration, and development strategy document to the GAO based on requirements. During the configuration and installation phase, the Contractor shall meet onsite at GAO and/or virtually for a project kick-off, business process workshops, and presentations of business design solutions, a prototype of configuration, training, and phase closeouts.
5.4.4. The contractor shall provide a staffing plan for the project management task.
5.4.5. The Contractor shall develop and provide a comprehensive system IWMS design document.
5.4.6. The Contractor shall provide an architecture and Data Flow Diagram
5.4.7. Provide a schedule outlining tasks and deliverables for the entire project with critical milestones to identify critical paths and project progress.
5.4.8. Conduct weekly status meetings and provide weekly progress reports.
5.5. Data Migration and Integration Objectives
5.5.1. The Contractor shall migrate all data from GAO Buildings such as AutoCAD drawings and Excel spreadsheets to the IWMS. Examples of legacy data include: building floor plans details for headquarters and field offices, employee data, building equipment assets, furniture, building equipment systems, leases, facility modification projects, utility invoices, and service work orders.
5.5.2. The Contractor shall conduct all data mapping of legacy data and archiving when necessary.
5.5.3. The Contractor shall be responsible for verifying the migrated data's accuracy and complete successful test runs of the end-to-end data migration process.
5.5.4. The Contractor shall verify data elements of the new IWMS system with legacy floor plans and employee data information.
5.5.5. The Contractor shall provide a Data Dictionary.
5.6. Training Objectives
5.6.1. The Contractor shall deliver 3 day training with training materials. The training shall include the system administration training and user training 20 GAO employees to assume future ongoing training responsibilities. All training materials must be reviewed and approved by GAO before the start of training delivery. The Contractor shall provide training to the GAO core functional groups and support staff to facilitate knowledge transfer before concluding the post-implementation support responsibilities. Training content should include, but not be limited to, software configuration, system user group security, and system operation procedures. The Contractor shall provide training to GAO personnel, to include the security controls capabilities and application account management
5.6.2. The Contractor shall develop materials appropriate for end-user and system administrative training. Materials may require customization depending on the user group but shall include instructor guides, user guides, quick reference guides, videos, and user exercise and engagement materials. Training materials shall include but are not limited to comprehensive user guides, training manuals, instructor manuals, webinars, and reference guides.
5.6.3. The Contractor shall provide all electronic source documents and media used to develop and present training across all training delivery channels. All training is expected to be delivered to the GAO HQ location physically or remotely.
5.6.4. The Contractor will work with the GAO to incorporate policies, procedures, and specific personnel roles into the materials. All end-user training materials must be reviewed and approved by GAO before the start of training.
5.7. Maintenance and Post Implementation Support Objectives
5.7.1. The contractor shall describe or explain their Maintenance and Support Change Management Process approach.
5.7.2. The contractor shall provide and describe a Maintenance and Support Change Management Process approach for the handling of System Bug fixes, Enhancements, and Upgrades after normal business hours or on weekends.
5.7.3. The contractor shall describe and provide written notifications for any maintenance and system updates?
5.7.4. The contractor shall provide incident-based help desk Tier 2 & 3 support between the hours of 8am and 5pm (Eastern Standard Time) on normal business days Monday thru Friday. GAO will handle the Tier 1 help desk requests.
5.7.5. The contractor shall provide tier 2 & 3 technical assistance via phone and email.
5.7.6. The Contractor shall provide post-implementation support for all implemented functionality and changes to the system.
5.7.7. The Contractor shall provide this support for the duration of the contract. This will support the system's stabilization, minimize the impact of any early system issues, and prepare to transition the system to the GAO for ongoing support and contract conclusion.
5.7.8. The Contractor shall be responsible for the system’s availability and usability, including reports, interfaces, and development for the IWMS.
5.7.9. The Contractor and GAO will jointly assess the post-implementation and system stability status, providing that final acceptance shall be determined by GAO in its sole discretion. The assessment shall include reviewing the status of outstanding issues and adherence to service level requirements. The IWMS will not be considered accepted until GAO confirms final acceptance in writing. The GAO will grant final acceptance no sooner than six (6) months post-implementation (go-live), and all issues have been resolved.
6. Requirements: IT Security and Operations Management To ensure compliance with the Federal Information Security Modernization act of 2014 (FISMA), the Contractor, and any subcontractor supporting the implementation of the solution, must demonstrate knowledge and understanding of the NIST SP 800-53 security controls for information systems. The security controls baseline implemented by the Contractor (and subcontractor) must be consistent with the FIPS 199 Moderate Impact level. Additionally, the implementation of the Contractor’s (and subcontractor’s) security controls must be documented in the manner described in the NIST Risk Management Framework, NIST SP 800-37, and Revision 2. The security documentation must describe how the security controls have been implemented for the infrastructure, platform, and software/application.
Within 15 days of the request, the Contractor (and subcontractor) shall provide access to GAO, or their designee acting as their agent, security documentation needed to verify compliance with the requirements for an Information Technology security program. The Contractor (and subcontractor) shall make appropriate personnel available for interviews and provide all necessary documentation during this review.
The Contractor (and subcontractor) shall ensure that GAO will have an opportunity to review, at least annually, the current security artifacts mandated by the Fed RAMP Program Management Office, by the current versions of NIST SP 800-37 and NIST SP 800-53 guidelines, or by the internationally accepted security practices.
The Contractor (and subcontractor) shall ensure that its environment remains compliant with the control standards of Federal Information Security Modernization Act of 2014 (FISMA), the current NIST standards related to: FIPS 140-2, and current NIST Special Publications 800-37, 800-53, 800-60, 800-61, 800-70, and 800-163. In addition, the Contractor (and subcontractor) must provide GAO with any documentation it requires for its security-related reporting requirements within 15 days of a request.
If the Contractor (and subcontractor) has its provisional authorization revoked, the Contractor’s hired independent third party assessment organization (3PAO) indicates that an authorization/re-authorization is not recommended, and/or the system’s Plan of Action and Milestones (POA&M) lists any critical or high risk deficiencies that are not being addressed in a timely manner as outlined by Fed RAMP and/or NIST guidelines.
The following system and security capabilities shall be implemented by the Contractor. The subcontractor, if hired, must implement the capabilities, as well, depending on the nature of their support:
6.1. Audit Log Management
| • | The system shall provide an automated mechanism to collect log files (including syslog, web and application server logs, event logs, etc.) for security and other analysis purposes and shall be reviewed by the Contractor on a routine basis. |
| • | The Contractor shall ensure that the automated mechanism allows GAO to periodically review the logs that can be exported into a format ingestible by an event correlation engine such as Splunk or in an .xlsx, .csv, .pdf, or .txt file format.. |
| • | The Contractor shall retain audit log records on-line for at least ninety (90) days and preserve audit log records off-line for a period of 365 days. |
6.2. Authentication
• The system shall authenticate GAO users using modern authentication services such as Active Directory Federation Services (ADFS).
6.3. Backup and Restoration
| • | The Contractor shall have a backup and restoration process that will ensure no more than 24 hours of data is loss. |
| • | The Contractor shall respond to GAO’s restoration request within one (1) business day of request. |
| • | The Contractor shall restore an agreed upon GAO dataset that is part of the regular backup schedule. The Contractor shall ensure that such testing takes place, semi-annually, at a minimum. |
| • | Data backups shall be maintained or replicated at a site geographically disparate from the production site such that the loss of one data center does not prohibit recovery of data within the prescribed RTO. The backup site must be in the continental United States. |
6.4. Data Management
| • | The Contractor shall maintain all of GAO’s data, including backup data, within the continental United States. The staff managing the data and/or systems maintaining GAO data shall be employed within and working from a system that is within the continental United States. |
| • | The Contractor shall ensure that GAO maintains ownership of all data stored in the hosted environment and that GAO will be permitted to access the data at any time. |
| • | The Contractor shall ensure that GAO data is being properly segregated from and thus inaccessible by the Contractor’s other clients. |
| • | The Contractor shall not access, use, or disclose GAO data unless specifically authorized by the terms of this contract or a task order issued hereunder. If authorized by the terms of this contract or a task order issued hereunder, any access to, or use or disclosure of, GAO data shall only be for purposes specified in this contract or task order. |
| • | The Contractor shall provide the Contracting Officer all GAO data and GAO-related data in the format specified in this document or as directed by the Contracting Officer. |
| • | The Contractor shall dispose of/purge GAO data and GAO-related data in an agreed upon manner and provide the confirmation of disposition to the Contracting Officer in accordance with contract closeout procedures. The data disposal/sanitization process shall be consistent with the current version of NIST SP 800-88, Guidelines for Media Sanitization. |
| • | The Contractor shall adhere to GAO Records Management Program Order 0410.1 and GAO’s Records Retention Schedules. The documents are available upon request. |
6.5. Incident Response
| • | The Contractor shall have an incident/breach notification process that is tested annually. The GAO ISSO for the system shall have an opportunity to review the annual test results. |
| • | The Contractor shall ensure that GAO is notified of all incidents, to include system outages and equipment failures, within an agreed upon timeframe consistent with federal government guidance. |
| • | The Contractor shall report incidents in a manner consistent with the current NIST SP 800-61 guidelines that is ultimately agreed upon by GAO to ensure that critical information is provided in a timely manner. |
| • | The Contractor will share contact information, to include GAO staff, of key incident response personnel for the hosting environment. The contact information shall be reviewed periodically to ensure accuracy and completeness. |
6.6. Media Protection
| • | The Contractor shall ensure that all deliverables, such as electronic or hard copy reports or CDs/DVDs, are labeled in a manner that is agreed upon by GAO. |
| • | The Contractor shall ensure that GAO data that resides on mobile/portable devices (e.g., USB flash drives, external hard drives, and SD cards) is encrypted using a NIST-approved tool. In all cases where GAO data are stored in mobile, easily transportable devices, the data must be encrypted at rest. |
| • | The Contractor shall ensure that external transmission/ dissemination of any GAO data is encrypted. Certified encryption modules must be used in accordance with the current FIPS Publication, “Security requirements for Cryptographic Modules,” FIPS 140-2, level 2, at a minimum. The transport layer security (TLS) protocol shall be version 1.2, at a minimum. There shall be no obsolete TLS protocols used in the transmission of GAO data. |
| • | The Contractor’s chain of custody practices for media containing GAO information that is transported outside of controlled areas, such as the data center, must ensure accountability. This can be accomplished through appropriate actions such as logging and/or a documented chain of custody form. |
| • | The Contractor shall ensure that data that is being shared with GAO or with GAO-designated recipients by e-mail shall also be encrypted and password-protected by contract staff using an agreed upon tool such as PKZip. Password distribution shall be handled securely to minimize potential compromise. Alternatively, a secure portal for secure messaging or for secure file transfers, for example, can be used. |
6.7. Personnel Security
| • | The Contactor shall require all employees and representatives, and any others (e.g., subcontractor employees) who will have access to GAO data, the architecture that supports GAO data, or any physical or logical devices/code, to pass the appropriate background investigation required by the Government in compliance with HSPD -12 and OPM’s Federal Investigations Notice 15-03. |
| • | Contractor personnel performing work under this contract shall have, at a minimum, a Tier-2, Public Trust, favorably adjudicated background investigation before accessing GAO data, the architecture that supports GAO data, or any physical or logical devices/code. The assigned personnel must maintain the level of clearance required for the life of the contract. |
| • | If the Contractor does not have staff meeting this requirement, the Contractor shall be responsible for costs associated with GAO’s efforts to initiate the background investigation process. |
| • | If more than ten contract staff can access GAO’s hosted environment and data, the Contractor shall assign specific staff who (1) will support GAO’s overall coding, troubleshooting, and system administration needs, and (2) has and can sustain a favorably adjudicated Tier-2 security clearance. |
| • | Contract personnel must sign a non-disclosure agreement, and must be a U.S. citizen or have lawful U.S. resident status. |
| • | Upon contract award, if the Contractor personnel assigned to support GAO do not meet the Tier-2 background investigation requirement, GAO will require that completed SF-85P forms be submitted securely to GAO’s Industrial Security section for review and processing. |
| • | Any time changes occur with a contractor’s personnel security clearance, the Contractor shall contact the GAO COR, who will ensure that GAO’s Personnel Management Branch is informed. GAO will conduct the appropriate reviews and will request pertinent information for review. |
| • | The Contractor will be responsible for the cost for any Tier-2 background investigations for newly assigned Contractor personnel supporting GAO’s hosted environment. |
6.8. Privacy Protections
| • | The Contractor shall provide privacy protections that are consistent with the NIST Special Publication 800-144 – “Guidelines on Security and Privacy in Public Cloud Computing” and other applicable standards and guidelines. |
| • | The Contractor shall adhere to GAO Privacy Program Order, 0450.1. The documentation will available, upon request. |
6.9. Protection of Information at Rest
• The Contractor shall provide security mechanisms for handling data at rest and in transit in accordance with the current, implemented version of the FIPS Publication “Security Requirements for Cryptographic Modules,” or FIPS 140-2, level 2, at a minimum. The transport layer security (TLS) protocol shall be version 1.2, at a minimum. There shall be no obsolete TLS protocols used in the transmission of GAO data.
6.10. Secure Communications
| • | As described in the NIST SP 800-53 System and Communications Protection control family, the Contractor, upon request, must be able to restrict access to GAO’s hosted environment based on an agreed upon public (non-RFC 1918) IPv4 address through a secure connection or through the use of an IP restrictions/whitelisting mechanism. |
| • | The solution must provide connectivity that is able to access the Contractor’s main and disaster recovery locations from GAO’s Headquarters and Alternate Computing Facility locations. Oftentimes, the VPN connectivity will require two (2) VPNs with four (4) tunnels. If an IP whitelisting/restrictions mechanism is used, it must be able to detect, reject and log attempts at spoofing IP addresses per IETF Best Common Practice 38 (https://tools.ietf.org/html/rfc2827). |
| • | The Contractor shall deploy strong cryptography and end-to-end application layer encryption to protect customer PINs, user passwords, email transmissions, web traffic, and other sensitive data in networks and data at rest. The level of encryption used must comply with the current, implemented version of the FIPS Publication “Security Requirements for Cryptographic Modules,” or FIPS 140-2, level 2, at a minimum. The transport layer security (TLS) protocol shall be version 1.2, at a minimum. There shall be no obsolete TLS protocols used in the transmission of GAO data. |
| • | The Contractor shall encrypt customer account and transaction data which is transmitted, transported, delivered or couriered to external parties or other locations, taking into account all intermediate junctures and transit points from source to destination. |
6.11. Security Alerts, Advisories, and Directives
• The Contractor shall ensure that contractor personnel with responsibilities for system administration, monitoring, and/or security, receive security alerts, advisories, and directives for the Contractor’s solution(s). The Contractor shall ensure that designated GAO personnel receive the same alerts, advisories and directives.
6.12. System Availability
| • | Whenever there is an interruption in service, the Contractor must inform GAO of the estimated time that the system or data will be unavailable. The estimated timeframe for recovery of the service must consistent with the agreed upon service level agreements (SLA) and system availability requirements. |
| • | The Contractor must provide regular updates to GAO on the status of returning the service to an operating state according to SLA and system availability requirements. |
6.13. System Use Notification Banner
· The Contractor shall ensure that a system use notification banner is placed on the webpages and/or portals that are used to gain access to the system. GAO will provide the appropriate language prior to the official deployment of the system.
· Here is an example of a banner that will be confirmed upon award - “This system is for official use by U.S. GAO-authorized personnel only and is covered by the rules, regulations, and guidelines on the ethical behavior of government employees and the appropriate use of government resources. All activities may be monitored, recorded or copied by authorized personnel and such information may be provided to law enforcement officials. Use of this system by any user constitutes consent to these conditions.”
6.14. Testing Services
The Contractor shall be responsible for developing and providing test plans, scripts, processes, tools, and test execution services that are necessary, including, but not limited to:
• Unit Testing – validates the configuration values operate according to approved design specifications
• Business Process Testing – validates that business processes are designed and configured as expected and can be fully executed and produced the pre-defined and desired results for each test script
• Parallel testing – validates the configured environment by comparing individual and summary results of an existing process run in the legacy system against a process run in the IWMS using the same data inputs
• Performance Testing – validates the readiness of the application to support the GAO's transaction level
• User Testing – validates the IWMS is functioning as designed, verifies the data migration process, and confirms that the IWMS is ready to be moved into the production environment
• Regression Testing – validates the operation of the IWMS after the application of patches and updates and identifies any IWMS and functionality problems resulting from the application of patches and updates.
The Contractor shall develop test scenarios, test cases, and test scripts that map testing according to the GAO business functionality, performance, and technical requirements. All test plans shall include: procedures for tracking, reporting, correcting issues identified during testing, approaches to address testing for failed results, and regression testing to ensure reported problems are resolved.
6.15. Vulnerability Management
· Prior to deployment, the Contractor shall ensure that the scan results (OS/APP/DB) for GAO’s hosted environment are provided for review by the GAO Project Manager and Information System Security Officer.
· The Contractor shall be responsible for all patching and vulnerability management (PVM) of software and other systems’ components supporting services provided under this agreement so as to proactively prevent the exploitation of IT vulnerabilities that may exist within the Contractor’s operating environment. Such patching and vulnerability management shall meet the requirements and recommendations of the current version of NIST SP 800-40.
· The Contractor shall ensure that the CVSS v3.0 specifications for critical and high risk vulnerabilities are patched within 7 and 30 days of discovery, respectively.
6.16. Deployment of System
· The Contractor shall provide a detailed Deployment Plan that documents all the activities for a successful migration from test environments to production environment. This includes the organization and execution of actions that need to transition operations to the IWMS. During the entire deployment period, the Contractor shall confirm readiness, ensure support services, and in place, tested and confined the 'go live' plan.
· To confirm readiness, the Contractor shall maintain a readiness checklist that tracks significant milestones required to determine whether the IWMS is ready for deployment. This checklist must be reviewed by GAO no later than three months before go-live. The checklist will establish that all testing has successfully been completed, personnel has completed end-user training, and data has been cleansed, migrated, and accepted by GAO. All interfaces are functioning as required; all site preparation requirements have been met, and the system is determined production-ready.
· To confirm support services readiness, the Contractor shall develop planned procedures accepted by GAO for providing the support that includes all activities, procedures, and steps necessary to provide required functional support and a tracking mechanism for all incidents.
· To confirm the system is ready to roll out agency wide, the Contractor shall provide a detailed roll-out plan to reflect all project activities that affect the deployment of IWMS into the production environment. The plan shall include specific roll-out tasks, planned dates for task completion, task responsibilities, task dependencies, and sign-off for each completed task. The Contractor shall provide an overview of the roll-out plan to the GAO team to ensure a common understanding of assignments, activity interdependencies, and deadlines.
7. Deliverables Deliverable Name:
| Description of Deliverable Item |
| Quantity |
| Due Date |
| Recipient |
| Start Background Investigations on vendor project team members |
| Fill out the GAO form 618A |
| 1 |
| 30 Days After Award |
| COR, CO, CS |
| Provide a system security Point of Contact |
| Provide a Name, email, phone number of the Security POC |
| 1 |
| 30 Days After Award |
| COR, CO, CS |
| Software licenses |
| Software licenses keys/ reference document |
| 100 |
| 60 Days after Award |
| COR, CO, CS |
| Set-up the VPN /Single Sign-On Connection |
| System configuration Set-Up |
| 1 |
| 90 days After Award |
| COR, CO, CS |
| Configuration of system and software install |
| System Configuration Prep for Production |
| 1 |
| 180 Days After Award |
| COR, CO, CS |
| Staff training |
| Training sessions completed |
| 3 days |
| 30 days before Go-Live |
| CO, COR, CS |
| End-User training materials |
| Written documentation |
| 1 |
| 30 days before Go-Live |
| CO, COR, CS |
| System Configuration Complete/ Go-Live |
| System Configuration Ready for Production |
| 1 |
| 220 Days After Award |
| COR, CO, CS |
| Project Schedule |
| A detail excel spreadsheet of due dates and milestones for the project. |
| 1 |
| 30 days After Award |
| CO, COR, CS |
| System Design and Develop Strategy |
| Written documentation |
| 1 |
| 60 Days after Award |
| CO, COR, CS |
| Status Reporting |
| Written Documentation |
| 1 |
| Every 2 Weeks after Project Kickoff |
| CO, COR, CS |
| Change Management Plan |
| Written documentation |
| 1 |
| 60- Days After Award |
| CO, COR, CS |
| Data Migration Strategy Plan |
| Written documentation on plan of action for data migration |
| 1 |
| 30 days after award |
| CO, COR, CS |
| Validation of End to End Data Migration in Development environment |
| Ensuring that the data migration is ready to be migrated into the system |
| 1 |
| 30 days before Go-Live Date |
| CO, COR, CS |
| Provide Data migration and integration design documents |
| Written documentation |
| 1 |
| 30 days before Go-Live date |
| CO, COR, CS |
Provide an architecture and Data Flow Diagram and Data Dictionary
| Written documentation |
| 1 |
| 30 days before go-live date |
| CO, COR, CS |
| Data Migration into the Production Environment |
| Completing data migration into the production environment |
| 1 |
| 15 days before go live date |
| CO, COR, CS |
| Provide post-implementation support personnel |
| Post-Implementation support |
| 1 |
| 30 days after go-live date |
| CO, COR, CS |
Provide notification on periodic maintenance repairs, patch fixes, functional enhancements to the system, and security upgrades
| Written documentation |
| 1 |
| 30 days after Go-Live and 15 days before any updates |
| CO, COR, CS |
Provide Help Desk services between 8:00 a.m. – 5:00 p.m. Monday – Friday Eastern Standard Time
| Phone and email help desk service |
| 1 |
| Start 10 days after Go-Live |
| CO, COR, CS |
| Test plans for performance |
| Written documentation |
| 1 |
| 60-days before Go-live |
| CO, COR, CS |
| Testing Scenarios |
| Written documentation |
| 1 |
| 45-days before Go-live |
| CO, COR, CS |
| Complete Tests |
| Written documentation |
| 1 |
| 30 days before Go-Live |
| CO, COR, CS |
| Document procedures for monitoring and capture user-response time metrics |
| Written documentation |
| 1 |
| 30 days after Go-Live |
| CO, COR, CS |
| System preparation and change –over activities |
| Written documentation |
| 1 |
| 30 days before Go-Live date |
| CO, COR, CS |
| Resolution of all identified security and functional defects |
| Written documentation |
| 1 |
| 15 days before Go-Live date |
| CO, COR, CS |
| Development of a go-live activities checklist |
| Written documentation |
| 1 |
| 90 days before Go-Live date |
| CO, COR, CS |
| End –User Support Procedures |
| Written documentation |
| 1 |
| 30 days before Go-Live date |
| CO, COR, CS |
| A Contingency Plan |
| Written documentation |
| 1 |
| 30 days before Go-Live date |
| CO, COR, CS |
Recent vulnerability scan results of GAO’s hosted environment (OS/DB/APP)
| Written documentation |
| 1 |
| 30 days before Go-Live date |
| CO, COR, CS |
Recent security vulnerability remediation plan (Plan of Action and Milestones (POA&M)
| Written documentation |
| 1 |
| 30 days before Go-Live date |
| CO, COR, CS |
File details come from the government source that posted it. Updated .