Attachment D - FCC Auction Bidding System and Support Services - Requirements Template.xlsx
XLSX spreadsheet 45 KB Posted
- Attached to
- FCC Auction Bidding System and Support Services Federal contract opportunity
- Solicitation number
- 273FCC23R0018
- Issued by
- Federal Communications Commission
About this file
This document outlines requirements for an FCC Auction Bidding System and Support Services. The system must provide functionality for multiple auction designs including ascending and descending clock auctions, as well as sealed-bid auctions. It must allow configuration of auction parameters, qualification of bidders, management of the bidding process, determination of winning bids, and reporting. The system is required to support auctions with complex rules involving package bidding, budget constraints, and assignment phases. It must be able to accommodate bidding by up to 500 bidders on 85,000 items. The solution must include cloud-based hosting that meets FedRAMP Moderate requirements and provide 99.999% uptime. Comprehensive security, reliability, and data integrity are required. The contractor must demonstrate the system within six months to one year and provide ongoing maintenance and support.
View the file
Other files for this federal contract opportunity
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Instructions
| Instructions For Requirements Template |
| There are 3 worksheets/tabs in this Workbook. Complete each worksheet/tab in its entirety. |
| Each worksheet corresponds to the sections A, B, and D in Appendix 1 of the SOW (Minimum Software Requirements, Reqs. For Production Services, and Hosting Technical Reqs, respectfully). |
| For each requirement on each worksheet/tab, in Column C select your response from the dropdown options about your ability to meet the requirement in the designated timeframe. |
| If you select "can meet requirment on time," the requirement will be included as part of the product delivery under this contract. Offeror shall provide an explanation that demonstrates the capability. Offeror should include evidence* of meeting requirement on time, such as screenshots of features that have been implemented, provisions of signed SLA agreement with cloud service provider (CSP), etc., which will not be included in the 40-page limit. |
| If you select "can meet requirement but not on time," an explanation is required that describes why the requirement can not be met on time, any issues, risks, or concerns about the requirement, and include any relevant information such as plans, what is needed in order to implement the requirement, and timeframes for eventually meeting the requirement. Offeror should also include relevant evidence*, such as screenshots of what has been implemented (e.g., if full implementation is not completed), provisions of agreements in negotiation, etc., which will not be included in the 40-page limit. |
| If you select "can not meet requirement," an explanation is required that describes why the requirement cannot be met, any issues, risks, or concerns about the requirement, and indicate whether your Bidding System software provides a comparable feature that might fulfill the purpose of the requirement. Offeror should also include relevant evidence*, such as screenshots of comparable features, which will not be included in the 40-page limit. |
| You must select an answer in Column C on every worksheet for each requirement. |
| *There is a 50-page limit for all evidence provided, such as screen shots, etc. In Column D of each worksheet/tab include a reference page number and other volume related location identification so the evidence can be easily found by the Government. In the proposal volume where the evidence is provided, include the worksheet/tab name and requirement number (e.g., Minimum Soaftware Requirements tab; Req. # 1.1). |
Minimum Software Requirements
| Minimum Software Requirements | |||
| Req # | Description of Requirement | Requirement Met at Time of Proposal Due Date | Further Explanation, Notes, and Comments |
| 1 | General Auction Parameters | ||
| 1.1 |
The auction bidding system shall include the ability to select among the following multi-round auctions:
| • | Ascending SMR without package bidding | |
| • | Ascending clock auction with assignment phase | |
| • | Ascending clock auction without assignment phase | |
| • | Descending clock auction (reverse auction) with budget constraint and competition across items and by item | |
| 1.2 | The auction bidding system shall provide the ability for winner assignment/determination as appropriate to auction design. This includes, for the descending clock auction with budget constraint, determining winning bidders based on competition across items for a share of the budget and on competition among bidders for an item. | |
| 1.3 | The auction bidding system shall provide the ability to bid on specific items (e.g., frequency-specific licenses) or generic blocks (i.e., place bids item-by-item). | |
| 2 | Auction Setup | |
| 2.1 | The auction bidding system shall provide the ability to setup and configure all auction parameters for internal auctions (acceptance testing and training) and external auctions (demonstrations and production auction). | |
| 2.2 | The auction bidding system shall provide the ability to assign a unique identifier to each bidder. | |
| 2.3 | The auction bidding system shall provide the ability to assign user access level by roles (e.g., auction administrators, bidder, and telephonic assistants). | |
| 2.4 | The auction bidding system shall allow the import of a set of qualified bidders, including persons authorized to bid on behalf of the bidder and auction items the bidder is qualified to bid for. | |
| 2.5 | For each qualified bidder, the auction bidding system shall provide three (3) authorized users access to the auction environment. | |
| 2.6 | The auction bidding system shall have the ability to run varying amounts of rounds (from 1-12) for clock auctions in a single day, with the ability to add or remove rounds during a live auction. | |
| 2.7 | The auction bidding system shall have the ability to run varying amounts of rounds (e.g., 1-8) for SMR auctions in a single day, with the ability to add or remove rounds during a live auction. | |
| 2.8 | During a live auction, the auction bidding system shall provide the ability to revert a configured auction back to an earlier state (i.e., a specific date/time that has already occurred during an open, live auction). When reverting back to an earlier state, the auction bidding system shall make available all communications, auction parameters, action logs, and bids and carry them forward to the reverted auction environment. | |
| 3 | Auction Administration | |
| 3.2 | The auction bidding system shall provide the ability for FCC users to delete an auction. | |
| The auction bidding system shall display a persistently viewable countdown clock to show how much time remains in the current round or how much time remains until the next round. | ||
| 3.3 | The auction bidding system shall provide the ability to control (change/modify) auction parameters for current and future rounds during the auction (such as and including minimum acceptable bids; round number; time or duration of rounds; changing the closing rule). | |
| 3.4 | The auction bidding system shall provide the ability to modify or add authorized bidders during a live auction. | |
| 3.5 | The auction bidding system shall provide the ability for FCC to electronically compose and send messages to all bidders. | |
| 3.6 | The auction bidding system shall provide full current and historical content for all auction communications (e.g., announcements, messages sent to bidders, and messages sent from bidders). | |
| 3.7 | The auction bidding system shall provide an area displaying overall bidder status for the current and past rounds, which must include bid data, eligibility, required activity, and submitted activity. The information must be displayed on screen with the capability of being downloaded. | |
| 3.8 | For clock auctions, the auction bidding system shall provide an area displaying overall status for items for the current and past rounds, which must include the posted price, next round price, and aggregate demand. The information must be displayed on screen with the capability of being downloaded. | |
| 3.9 | For SMR auctions, the auction bidding system shall provide an area displaying overall status for items for the current and past rounds, which must include provisionally winning bids, minimum acceptable bid, posted price, next round price, number of bids per item, and aggregate demand. The information must be displayed on screen with the capability of being downloaded. | |
| 3.10 | The auction bidding system shall provide the ability to monitor a bidder's activities, including: |
i. Equipment and screens; and
ii. Read receipt of communications.
| 4 | Bidder Interface |
| 4.1 | The bidder interface shall run without error on industry standard computers (including supported versions of the Microsoft Windows and Apple macOS operating systems) and web browsers (at a minimum the current supported versions of Microsoft Edge, Google Chrome and Mozilla Firefox browsers) using a high-speed Internet connection. |
| 4.2 | The auction bidding system shall not require installation of any special software or plug-ins. |
| 4.3 | All auction bidding system screens shall be printable in all supported browsers without loss of information. |
| 4.4 | The auction bidding system shall display a persistently viewable countdown clock to show how much time remains in the current round or how much time remains until the next round. |
| 4.5 | The auction bidding system shall allow a bidder to send private messages to the auction administrators through the web interface. |
| 4.6 | The auction bidding system shall provide an area for individual bidders displaying overall bidder status for the current and past rounds, which must include eligibility, submitted activity, and bid status after bid processing at the end of a round. The information must be displayed on screen and the ability for the information to be downloaded. |
| 4.7 | The auction bidding system shall support viewing of results for the current and all previous rounds based on the information policy. |
| 4.8 | The auction bidding system shall provide a telephonic bidding interface. |
| 4.9 | The auction bidding system shall display bid information according to the auction disclosure policy. |
| 4.10 | The auction bidding system shall indicate to bidders if any bids have not been submitted prior to the closing of a round. |
| 5 | Bid Submission |
| 5.1 | During a bid submission period, the auction bidding system shall allow qualified bidders to enter their bids electronically via a web interface (GUI). |
| 5.2 | The auction bidding system shall allow the bidder the ability to upload files for submitting bids, depending on auction design and number of auction items. |
| 5.3 | The auction bidding system shall validate each submitted bid to ensure it satisfies all requirements. |
| 5.4 | The auction bidding system shall not accept any bid if it violates a rule(s) for acceptable bids, and shall provide an error message with an explanation of the unacceptable bid. |
| 5.5 | The auction bidding system shall record a unique identifier, a date and time stamp, and a number generated by a pseudo-random process for each submitted bid by each bidder. |
| 5.6 | The auction bidding system shall accommodate the submission of offers by up to 500 unique bidders and 85,000 items. |
| 5.7 | The auction bidding system shall provide the ability to: i. Match bidders to specific items based on qualifications. |
| 5.8 | After verifying that a bid would be acceptable, the auction bidding system shall display a screen with the bid submission details for confirmation of its accuracy. The bidder shall be able to print and/or download the screen and verification as a record of bid submission, and this record must have a visible time and date stamp and identify the authorized bidder. |
| 5.9 | The auction bidding system shall allow bidders to edit, remove, or replace their bid before the close of the bidding round. |
| 5.10 | The auction bidding system shall only allow bidding during the specified bidding round. |
| 5.11 | The auction bidding system shall allow bidders to submit and act on multiple bids at once. |
| 5.12 | The auction bidding system shall allow each bidder to only place bids on the items for which they are qualified to bid. |
| 6 | Bid Processing |
| 6.1 | At the end of a round, the auction bidding system shall determine and display provisional winning bids (i.e., SMR), processed demand (Clock auctions), next round prices, next round eligibility and required activity. The auction bidding system shall break ties according to the auction design. |
| 6.2 | At the end of each round, the auction bidding system shall determine whether the auction stopping rule has been satisfied according to auction design. If the stopping rule has not been satisfied, the auction bidding system shall configure the next round. If the stopping rule has been satisfied, the auction bidding system shall conclude the auction. |
| 6.3 | The auction bidding system shall allow auction administrators to initiate bid processing at the end of each round. |
| 6.4 | The auction bidding system shall allow auction administrators to change auction parameters prior to configuring the next round. |
| 6.5 | If the stopping rule has been satisfied, the auction bidding system shall determine the winning bids according to the auction design. |
| 6.6 | The auction bidding system shall provide the ability to determine the price for each winning bid according to the auction design (e.g., as bid, and variations of Vickrey/second prices). |
| 6.7 | The auction bidding system shall provide the ability to determine the prices winning bidders will pay or receive per bid and per item as appropriate to the auction design. |
| 7 | Auction Results (Administrator) |
| The auction bidding system shall allow an administrator with authorized permission to see real time auction results, including the bids placed by each bidder. | |
| 7.1 | The auction bidding system shall, at the close of each round, and before results are processed, create a backup file. |
| 7.2 | The auction bidding system shall create a file that can be used to validate both the winning bids and the associated prices, presented in a text file that includes the time and date stamp of the bid, bid round, bidder ID, authorized bidder, pseudo random number, item(s) ID(s), and associated demand and prices. |
| 7.3 | The auction bidding system shall allow an administrator to post the results from the previous round and announce next round prices if stopping rules have not been satisfied. |
| 8 | Reporting |
| 8.1 | The auction bidding system shall generate Standard Reports (i.e., “canned” reports), which can be saved by the user for later use. The reports shall be able to contain real-time and previous round information. |
| 8.2 | The auction bidding system shall provide the ability to execute Report Options (i.e., to choose from a selection of report options to accommodate user preferences for the viewing of standard reports, including display, print, and download). |
| 8.3 | The auction bidding system shall display real-time results (i.e., display results of the auction in real-time for auction administrators) and all previous round results. |
| 8.4 | The auction bidding system shall provide round results reports in three modes: general public information, private (authorized) bidder-specific information, and full information reports for administrators. |
| 8.5 | The auction bidding system shall provide the ability to view reports on screen, print, or download in a non-proprietary, editable format. |
| 8.6 | The reporting auction bidding system shall have the ability to be customized or modified according to FCC-specific auction design. |
| 9 | Login and Security Requirements |
| 9.1 | The auction bidding system shall provide bidder access support including support for all authentication mechanisms used by the system. |
| 9.2 | If authentication fails, the auction bidding system shall deny the user access to the system, terminate the login process, and notify the user that the authentication failed. |
| 9.3 | If the authentication fails, the auction bidding system shall not reveal which authentication parameter was incorrect. |
| 9.4 | The auction bidding system shall permit the use of dedicated SSL Encryption/Decryption technology. |
| 9.5 | The auction bidding system shall digitally sign all bid data for non-repudiation. |
| 9.6 | The auction bidding system shall provide a login/landing page which includes a FCC-approved graphic and security disclaimer. |
Reqs. for Production Services
| Minimum Software Requirements For Production Service to Support Live Auctions | |||
| Req # | Description of Requirement | Requirement in Test Environment within 6 Months after Contract Effective Date | Further Explanation, Notes, and Comments |
| 1 | General Auction Parameters | ||
| 1.1 | The auction bidding system shall provide the ability to set multiple budget constraints for descending clock (reverse) auctions with the ability to move funds not used in one budget to another budget. | ||
| 1.2 | For each auction design, the auction bidding system shall provide the ability to implement winning bid limitation (e.g., 4 out of 10 blocks) | ||
| 1.3 | For descending clock (reverse) auctions. the auction bidding system shall provide the ability for various bid collection procedures, including: |
i. The ability to submit a group of bids with the requirement that none will be assigned unless a sufficiently large subset of the items can be assigned
1.4 The auction bidding system shall provide the ability for winner assignment/determination:
As appropriate to auction design, including more complex methods (such as and including integer programming optimization).
| 1.5 | For all forward auction designs, the auction bidding system shall provide the ability to determine the prices winners will pay taking into account bidding credits and any other adjustments to bids. |
| 1.6 | The auction bidding system shall provide for the ability to set multiple activity stages (with specific activity requirements). |
| 1.7 | The auction bidding system shall be configurable to meet FCC auction rules and procedures and other auction-specific criteria, such as and including: |
i. Reserve pricing, public or otherwise, aggregate or by item
ii. Bid discounts/credits, item-specific or bidder-specific
iii. Stopping rules, etc.
iv. Budget constraints
v. Activity requirements
vi. Categories (for items)
vii. Tracking waiver and withdrawals
viii. Contingent bidding limits (for bid submissions and processing)
| 2 | Auction Setup |
| 2.1 | For each item for which the bidder is initially qualified to bid, the auction bidding system shall be capable of assigning a bidding credit percentage for each bidder and item combination (e.g., the same bidding credit across all items or different bidding credits for selected items). |
| 2.2 | The auction bidding system shall provide the ability to establish information disclosure policy (i.e., full information is not available to bidders). |
| 2.3 | The auction bidding system shall provide the ability to allow the FCC to specify information for each bidder, such as and including: name, bidder ID, username, password, RSA token serial number, email address, eligibility which may be based on an upfront deposit, and limits on items for any specific bidder. |
| 2.4 | The auction bidding system shall provide the ability for FCC staff to configure and set up auction formats meeting the General Auction Parameters identified in Appendix A. |
| 2.5 | For all auction designs, the auction bidding system shall provide the ability for FCC staff to specify auction parameters (e.g., general and auction-specific information) and to import auction-specific data (such as and including auctionable products (e.g. licenses or other items) and bidder information). |
| 3 | Auction Administration |
| 3.1 | The auction bidding system shall provide the ability for auction administrators to enable or disable access to persons authorized to submit bids on behalf of the bidder during an auction. |
| 3.2 | The auction bidding system shall provide auction administrators permission to perform bidding actions on behalf of a bidder during an auction (i.e., act as the bidder), producing system data logs that identify any actions using this method. |
| 3.3 | The auction bidding system shall allow auction administrators to view (as a screenshot) all screens accessed by an authorized user. Screenshots should be accompanied with the date and timestamp, last action by the user, authorized bidder, and browser/operating system. |
| 3.4 | The auction bidding system shall provide the ability to monitor, on a screen, in real time, the content of all auction-related activity for the current auction (such as and including bidder data, item data, activity logs, and connections). |
| 3.5 | The auction bidding system shall support full data access mode for use on secured equipment and limited information mode for telephonic and technical support monitoring. |
| 3.6 | The auction bidding system shall provide auction administrators an area to view and filter bidder activity for the current round, with the ability to be refreshed on command, including filters as defined by the FCC. |
| 3.7 | The auction bidding system shall provide the ability for FCC to electronically send and respond to messages to/from a qualified bidder. |
| 3.8 | The auction bidding system shall provide the ability to format text (such as and including bold, underline, italicize, and add hyperlinks) for all communications. |
| 3.9 | The auction bidding system shall allow administrators to search, sort, and filter bidder and user data for all auction designs. |
| 3.10 | For SMR auctions, the auction bidding system shall provide an option for automatic bid processing at the closing of a round and an automatic posting feature. |
| 3.11 | The auction bidding system shall allow the auction administrator to control what data is made available to a specific class of users. |
| 3.12 | For clock auctions, the auction bidding system shall provide a feature for the administrator to view real-time activity by market, to include the identity of the bidder, category(s) or block(s) in the market, the previous round processed demand, current round requested demand, and current round clock price. |
| 4 | Bidder Interface |
| 4.1 | In cases where information is limited during the auction, the auction bidding system shall provide the ability to disclose specified information at any point after the close of the auction. |
| 4.2 | The auction bidding system shall allow bidders to search the data displayed on bidding and results screens for all auction designs. |
| 4.3 | The auction bidding system shall provide bidder help tools (e.g., links to auction specific user guides and manuals). |
| 5 | Bid Submission |
| 5.1 | The auction bidding system shall provide the ability to display the net bid amount. |
| 5.2 | For SMR auctions, the auction bidding system shall allow bidders to withdraw bids from previous rounds if permitted under FCC auction rules. |
| 5.3 | The auction bidding system shall allow bidders to revert bids prior to the closing of a round. |
| 5.4 | The auction bidding system shall provide context sensitive help for bidders. |
| 5.5 | The auction bidding system shall provide bidders the ability to maintain their prior round bids at the next round prices, taking provisionally winning bids into account. |
| 5.6 | For ascending and descending clock auctions, the auction bidding system shall provide bidders the ability to place bids for future rounds. |
| 5.7 | The auction bidding system shall provide the ability to submit bids through an user interface that is agreed upon by the FCC for all auction designs. |
| 5.8 | The auction bidding system shall provide bidders with a dynamic watchlist based on certain criteria for SMR auctions (such as and including outbid lists, provisionally winning bids, and FCC-held list). |
| 5.9 | For a SMR auction, the auction bidding system shall allow bidders to submit waivers during rounds to maintain their eligibility. |
| 5.10 | For a SMR auction, the auction bidding system shall allow bidders to reduce their eligibility to maintain their waivers or to meet eligibility requirements. |
| 6 | Reporting |
| 6.1 | The auction bidding system shall provide authorized bidders the ability to filter on auction data, and display and download the results. |
| 6.2 | The auction bidding system shall provide a download/export capability so that FCC can export its data in an open (non-proprietary) format for use in other applications. |
| 7 | Public Reporting |
| 7.1 | The public reporting auction bidding system shall be linked to the bidding auction bidding system and automatically populated with data from the bidding auction bidding system. |
| 7.2 | The system shall be a auction bidding system that includes public auction data, including, for example, the auction number, auction status, current stage number, items available, current stage status, clearing target and/or licensed spectrum available, clearing costs, final stage rule information, number of qualified bidders, and round results (if applicable). |
| 7.3 | The public reporting auction bidding system shall provide standard reports. Reports shall be available on bids and results, item status, bidder status, round summary. Reports should have sorting and filtering capabilities, and will be available for download. |
| 7.4 | The public reporting auction bidding system shall adhere to the information disclosure policy. |
| 7.5 | The public reporting auction bidding system shall not require users to log in or otherwise accept any click-through agreements, except to the extent required by FISMA. |
| 7.6 | The public reporting auction bidding system shall allow the FCC to upload additional reports and /or files (e.g., PDF and zip files) that can populate the auction bidding system. |
| 7.7 | The public reporting auction bidding system shall include a customizable text box that will be displayed at the top of the dashboard screen for each auction. |
| 7.8 | The public reporting auction bidding system shall include a dashboard screen for each auction that includes general auction information. |
| 7.9 | The public reporting auction bidding system dashboard screen shall allow for the inclusion of hyperlinks. |
| 7.10 | The public reporting auction bidding system shall provide a landing page that includes all current and historical FCC auctions, and allow users to navigate to specific auctions. |
| 7.11 | The public reporting auction bidding system shall provide FCC authorized users to login in as administrators with rights to the system, as necessary. |
| 8 | Testing and Verification |
| 8.1 | The auction bidding system shall support and facilitate manual and automated testing by third parties (e.g., consistently using object identification and html tags in the code). |
| 9 | Login and Security Requirements |
| 9.1 | Shall require FCC -approved two factor authentication to log into the auction. |
| 9.2 | Shall, for each qualified bidder, provide up to three (3) authorized users access using FCC approved two factor authentication mechanism. |
Hosting and Technical Reqs
| Infrastructure, Hosting, and Security Requirements | |||
| Req # | Description of Requirement | Requirement in Test/ Production Environment within 1 Year after Contract Effective Date | Further Explanation, Notes, and Comments |
| 1 | Hosting, Infrastructure, and Service/System Reliability (including Recoverability) | ||
| 1.1 | The Contractor shall provide an auction system implementation with redundancy and failover capability to the redundant system. | ||
| 1.2 | The Contractor shall provide a cloud-based solution, that is hosted with a cloud service provider (CSP) that is FedRAMP moderate authorized for the IaaS and PaaS service models, with environments cordoned off from other systems so as not to be shared with any other services and that is able to connect to/integrate with the FCC’s network and designated systems (e.g., CORES II, RSA). | ||
| 1.3 | The Contractor shall provide software, hosting, and operations and maintenance support as part of the overall service provided under this contract. | ||
| 1.4 | The services provided shall ensure that all data are stored (in-transit and at-rest) and processed only in the Continental United States. | ||
| 1.5 | The auction system must reside in the United States. | ||
| 1.6 | The services, technical environment, and bidding system shall be capable of complying with and adhering to all FCC IT policy requirements and all relevant Federal IT security, privacy, and accessibility standards, controls, guidelines, regulations, laws, and other mandates. | ||
| 1.7 | The Contractor shall provide for ease of data exchange through use of standard and transparent data formats conforming to modern conventions. | ||
| 1.8 | The service shall be engineered to sustain a 99.999% uptime during auction operation. |
Outside of auction operation, the bidding system shall be continuously available 24 x 7, except that the Contractor is permitted not more than two (2) short-term (less than two hours) planned or unplanned outages in the production environment in any given performance quarter, and not more than one (1) (less than eight hours) single major planned or unplanned outage in any given performance quarter.
The FCC’s COR shall be notified of any unplanned outages in the production environment no more than five (5) minutes after the beginning of the outage, subject to practicality. In the event of major outages, whether occurring during auction operation or otherwise, the repairs shall be completed within two (2) hours, unless extenuating circumstances are identified to the FCC and approved by the COR.
| 1.9 | In the case of an infrastructure or auction software failure, the service shall have the ability to pause the system processes and restore the system and data to its last known good configuration and restart the auction process from that point. The restore shall take no longer than 30 minutes. |
| 1.10 | The auction bidding system shall be able to disable bidder access to the software and provide bidders with a system status message. |
| 1.11 | The auction bidding system shall provide a way for the auction administrator to keep track of bids that are coming in and identify bidders who may be experiencing technical difficulties. The system shall support the Auction Manager team in contacting such bidders and resolving the issues. |
| 1.12 | The auction bidding system shall have the ability to make backup copies of the auction state at any time, during or between rounds. |
| 1.13 | The auction bidding system shall automatically make backups at regular intervals or specific times according to the auction schedule. |
| 1.14 | The auction bidding system shall have the ability to “mount” snapshots as a running Auction with either full, limited, or admin only access while other auctions continue to run. |
| 1.15 | The auction bidding system backups shall store all information related to the auction and replicate the exact state of the system at the point of the backup. |
| 1.16 | The Contractor shall not be responsible for the reliability of a bidder’s internet connection or IT infrastructure, with the exception of reliability problems traceable to malfunctioning or errant bidder interface functionality provided by the Contractor. |
| 1.17 | The service shall have the ability to record the auction state at any point in time, in round, between rounds, or before round. The service shall be able to restore a recorded auction state within 30 minutes. “Any point in time” is defined as between any two sequential bids or transactions. |
| 1.18 | The service shall be designed to remain responsive while handling simultaneous actions by internal and external users (i.e., uploading bid files, initiating bid processing, generating data files for download, etc.). |
| 2 | Authentication and Security |
| 2.1 | The Contractor's solution shall require secure authentication of the auction bidders using the FCC’s two-factor authentication over the Internet. The proposed auction bidder authentication architecture must be approved by FCC. |
| 2.2 | The authentication solution shall allow three logins for each authorized bidder (the qualified bidder, and up to two additional authorized bidders for each qualified bidder) to connect to the auction service from different computers. Each login shall be limited to use by only one user at a time. |
| 2.3 | The service shall incorporate a FIPS 140-3 validated encryption solution, or an alternative means of protecting the security and secrecy of the bids, both over the Internet and while stored in the database(s), for non-repudiation purposes. |
| 2.4 | Server shall include a digital certificate issued by a recognized certificate authority (CA) such as VeriSign. The service shall incorporate encryption of data at rest as in database or other data storage. |
| 2.5 | Software shall use Role Based Access Control (RBAC) or similar means to ensure that only authorized individuals have access to service data and features. Roles to be defined by the FCC. |
| 2.6 | If user authentication fails, the service shall not allow access and shall also provide a reason for the failed authentication. Further, the service will log failed events and provide alerts to the FCC system owner after a FCC-defined threshold has been breached. |
| 2.7 | All auction-related communication shall be encrypted using FIPS 140-3 evaluated hardware, software, and configuration. Earlier versions of previously evaluated software is acceptable with approval from FCC. The Contractor will be required to submit the specification of the encryption hardware, software, and configuration to FCC for FIPS 140 validation. |
| 2.8 | The service shall use a server digital certificate issued by FCC or approved FCC vendor to allow the site to be verified as FCC. Two certificates will be made available to support two geographic locations. |
| 2.9 | The authentication solution shall allow authorized FCC administrators (direct staff and contractors) access using a minimum two factor authentication with heavy preference towards HSPD-12 card authentication or as otherwise mutually agreed. |
| 2.10 | The service shall have a non-repudiation mechanism to verify users and administrators’ actions using or managing the service. The non-repudiation mechanism should not be part of the bidding system. An independent party of the FCC’s choice shall verify that all actions from users and administrators are recorded for non-repudiation purposes. |
| 3 | General and Information Security Requirements |
| 3.1 | The hosting service and auction software shall comply with and be kept current to the latest NIST 800-53 standard and NIST SP 800-218 and validated by a third-party assessor. An ATO is required, including all required documentation, onsite audits, and other features of the process. The contractor shall document corporate policies and procedures, which shall be validated annually by Contractor’s third party assessor . The Contractor shall work with the COR and the FCC CISO or a delegate of the CISO’s choosing, as needed to coordinate this requirement. The COR will provide the CISO’s contact information. |
| 3.2 | The Contractor shall use FedRAMP authorized cloud technologies for hosting FCC systems and Infrastructure. |
| 3.3 | FCC shall have online access to real-time application logs. |
| 3.4 | FCC requires access to the FedRAMP technology documentation and may require audit within the FedRAMP framework. |
| 3.5 | The Contractor shall provide support to the FCC in its preparation of all FISMA documentation as it pertains to production software and systems, including by reviewing documentation as necessary to satisfy FCC security requirements in order to receive ATO on the hosting and production system service. FCC may require access to the Contractor’s facility and may require audit within the FedRAMP framework. |
| 3.6 | Section 508 compliance: The Contractor shall describe how the proposed auction software solution complies with Section 508 of the Rehabilitation Act. The FCC requirement for telephonic bidding is designed, in part, to address accessibility issues for the time-sensitive bidding component of the auction system. |
| 4 | Security Operations |
| 4.1 | The hosting service shall have monitoring service(s) that will continually monitor and provide near real-time review of events from the bidding and public reporting service, the infrastructure, security tools, communication systems, servers, and applications in accordance with FCC cybersecurity policy. |
| 4.2 | The hosting service shall include an operational independent Web-Application Firewall (WAF) or other technology to protect the bidding service against parameter manipulation and data injections. |
| 4.3 | The hosting service shall provide an interface for FCC NSOC to access near real-time security events from the infrastructure, security tools, and application logs. |
| 4.4 | The Contractor shall permit the FCC to audit and assess the hosting environment, the bidding system, and peripheral systems and devices to ensure compliance with Federal laws, rules, and regulations. |
| 5 | Traceability of the Auction Process |
| 5.1 | The service shall provide real-time monitoring of all authorized bidders and administrators logged into the auction system, including on-demand forensic tracking and monitoring (real-time and historical) for all bidder and administrator activity to assist the administrator in resolving disputes with bidders during and after the auction. The monitoring access described here is to be via a web-based, thin client. |
| 5.2 | The service shall store all data (including detailed application and logs of interactions between the bidders, the system, and the FCC), as well as, but not limited to the following: all bid data, all information sent to the bidder’s interface, any inputs received from the bidder, and any information entered into the system by the Auction Contractor, the FCC or other related and authorized FCC Contractors. This information shall be available to the FCC at any point during an auction and up to 30 days after the close of an auction. The logs must be produced in a standard format such as defined XML or CSV and provided electronically. |
| 5.3 | Within 30 days after the close of the auction, the Contractor shall deliver to the FCC within the FCC environment/boundary application logs, complete data export file(s), and audit logs for the entire auction in a mutually agreed format that will allow the FCC to conduct its own inspections and enable the FCC to retain the data for future access and use. The Contractor will include a formal certificate signed by a company officer, that the contents provided are authentic and accurate. |
File details come from the government source that posted it. Updated .