ACADIS_Bridge_SOW.doc
DOC document 183 KB Posted
- Attached to
- Intent to Sole Source Award of One Year Bridge Contract For ACADIS SOFTWARE Federal contract opportunity
- Solicitation number
- CBPR3301
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSJ_One_Year_Contract_(ACADIS)_1_25_18.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work
Customs and Border Protection Academy Class Management System
January, 2018 Prepared by
Office of Training and Development
Training Production and Standards Division
BACKGROUND:
It is the mission of U.S. Customs and Border Protection (CBP) to protect the nation’s borders while facilitating legitimate trade and travel. The CBP Office of Training and Development (OTD) supports the CBP mission by coordinating and providing the training necessary to meet this mission. OTD requires a Commercial off the Shelf (COTS) web-based Academy Class Management System that will provide CBP an effective and standardized method of managing various academies and training facilities, course curriculum, registration, evaluation and student transcripts and records.
CBP is joining with the Federal Protective Services (FPS) to seek IT COTS software and services for their academies.
The software must be able to handle multiple locations, with a highly configurable, scalable and 508 compliant. Implementation of the new solution shall provide CBP with the ability to do the following:
1. Eliminate fragmented and redundant processes
2. Reduce operational costs of residential training
3. Reduce/eliminate costly paper-based field reporting
4. Reduce litigation risks
5. Increase training academy throughput
6. Automate critical training administration functions to reduce reliance on contractor staff
7. Standardize law enforcement training procedures
8. Eliminate hardware-based scanning technology
SCOPE:
The management and accurate recordation of training is crucial to CBP and Federal Protective Service (FPS) as a law enforcement agency for tracking qualifications and certifications to ensure agents are qualified to perform their duties. Law enforcement training includes numerous complex assessment types with varying custom grading scales including unique attributes for physical fitness, firearms, defensive tactics and other skills-based assessments. Failure to accurately document these attributes could adversely affect CBP’s mission. For example after a shooting incident it was learned that the CBP employee failed firearms, without that information the employee remained on the job and was not fired which led to a law suit. The successful completion of courses, exams, and assessments are major components that are evaluated for an agent to graduate from the academies and have complex weighting factors that must be calculated in the system and rolled up to graduation scores across the entire curriculum model. It is critical to support the various assessment types and grading scales as well as maintain complete detailed training records in the event there are high-costs of litigation associated with use of force incidents.
CBP/FPS currently has both a legacy ACMS and a .Net ACMS system which are both being utilized. The .Net ACMS system provides enterprise resource planning (ERP) and is very effective at managing complex law enforcement training and, field observation reporting across various locations at the enterprise level. The selected product must provide at a minimum the current functionality that CBP already has in place in the current .Net ACMS in the initial implementation. It must also provide a platform that will assist CBP in standardizing law enforcement training operations and provide a vehicle to ensure that each academy’s programs meet the Federal Law Enforcement Training Accreditation (FLETA) guidelines while maintaining a secure, end-to-end training architecture.
| Service Period |
| April 1, 2018 – March 31, 2019 |
| · New Training Requirements as they become known |
· New Academies or Training centers as appropriate
· System maintenance and future enhancements to be defined by CBP
APPLICABLE DOCUMENTS:
Handbook for Safeguarding Sensitive Personally Identifiable Information at the Department of Homeland Security
DHS Information Security Policy, identified in MD4300.1, Information Technology Systems Security Program and 4300A Sensitive Systems Handbook."
HB 1400-05D CBP Information Systems Security Policies and Procedures Handbook
Version 1.1, July 27, 2009, http://pods.cbp.dhs.gov/index.asp?dto=4&doc=HB%201400-05 DHS 4300A Sensitive Systems Handbook Version 7.2.1, August 9, 2010, 4.1.5 Information Security Awareness, Training, and Education http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sspolicy.aspx HSAR Clauses 3052.204-70 Security Requirements for Unclassified Information Technology Resources (JUN 2006) OAST (Office on Accessible Systems and Technology) Compliance DHS Accessibility Requirements Tool (DART)
National Information Exchange Model (NIEM)
Section 508 of the Rehabilitation Act
DHS Standard Operating Architecture (SOA)
36 CFR 1194.22
36 CFR 1194.31
36 CFR 1194.41
DHS MD 4010.2
36 CFR 1194.2(b)
36 CFR 1194.3(b)
Information Technology Systems Security Program and 4300A Sensitive Systems Handbook.
3052.204-70 Security Requirements For Unclassified Information Technology Resources (JUN 2006) Computer Security Act of 1987 (40 U.S.C. 1441 et seq.);
Government Information Security Reform Act of 2000
Federal Information Security Management Act of 2002
OMB Circular A-130
Critical Infrastructure Information Act of 2002 (Title II, Subtitle B, of the Homeland Security Act, Public Law 107-296, 196 Stat. 2135), Title 49, Code of Federal Regulations, Part 1520 4.
SPECIFIC TASKS:
The Contractor shall provide licenses and maintenance service for ACADIS, a COTS software using a .NET platform for the Academy Class Management System solution that will contain at a minimum the existing functionality currently available in the existing .Net Academy Class Management System.
This applications must support all CBP/FPS Law Enforcement personnel nationwide and various international locations. The Contractor shall identify the current functions in the existing .Net system and the legacy ACMS in a requirements document which will also include Section 508 compliance requirements for CBP/FPS..
The Contractor shall also provide the following services:
1. COTS Software Procurement, Implementation and Licensing
2. Academy Management System Maintenance and Technical Support
3. Modifications/Customizations – Phase V (systems analysis, programming, quality assurance testing and training to implement enhancements).
4. Consulting support, including training and documentation required to support implementation and management of the system.
5. Maintain user data.
6. Support 24/7access to the Academy Management System solution for CBP personnel.
7. Help Desk Support for Tier 3 (Technical Support)
8. Maintain an environment at the contractors work site accessible to OTD personnel for level one user acceptance testing and training.
9. Provide the systems analysis, programming, quality assurance testing and training to implement enhancements to support evolving and emerging training requirements.
10. Provide the systems analysis, programming, quality assurance testing and training to on-board additional academies, training facilities.
11. Modifications/Customizations of business specific reports to support enhancements made for evolving and emerging training requirements.
4.1 Meeting and Reporting Requirements 4.1.1 Meetings Weekly status meetings will be conducted to discuss the following topics:
· Issues
· Anomalies
· Upgrades, enhancements, and modifications
· Projects (provide status, updates to schedules, milestones)
· Contractor shall deliver minutes of the meeting to the CBP Contracting Officer’s Representative (COR) within two (2) business days of the end of the meeting
Semi-annual meetings will be held at a CBP location in Washington, DC to discuss the plans for future releases. The purpose is to review and discuss CBP’s future system needs for system support planning purposes. The Contractor shall deliver minutes of the meeting to the COR within five (5) business days of the meeting.
4.1.2 Monthly Status Report
The Contractor shall submit a monthly status report to the COR by the tenth (10th) workday of each month. The monthly status report shall address the functional accomplishments, issues, unresolved problems and a plan of action for resolving any problems identified by the customer. This report shall contain the following information:
· A cover letter with the Contractor’s name and address, the contract number, the date of the report, and the period covered by the report;
· Significant changes to the Contractor's organization or method of operation;
· Description of significant events occurring during the reporting period;
· Status of pending deliverables with expected delivery dates;
· Problem areas affecting technical, schedule, or cost elements of the contract, including background, impact and recommendations for resolution;
· Results related to previously identified problem areas with conclusions and recommendations;
· Trip reports and significant results;
· Name and telephone number of the preparer of the report;
· Planned accomplishments for the next reporting period;
· For each task area the Contractor shall provide a budget including cumulative expenditures and balance remaining, hours utilized by labor category for the month and cumulative hours utilized by labor category for the period of performance of the contract (in the form of a spreadsheet).
4.1.3 Ad Hoc Reports
The Contractor shall submit Ad Hoc reports, in the Contractor’s choice of layout, when requested by the Government. These Ad Hoc reports can cover, but are not limited to such areas as:
· Trip reports
· Meeting agenda reports
· Meeting minutes
· Extracting system information in support of internal and external investigations
4.1.4 Report Formats
The Contractor shall deliver all reports in hardcopy and softcopy format. Softcopies shall be delivered using Microsoft Office in a version compatible with current CBP usage. The Contractor shall submit all reports electronically via CBP electronic mail system in a format specified by the COR. In the event the system is unavailable or not accessible due to a system malfunction, the Contractor shall submit all reports in a typewritten format to be followed simultaneously with an electronically transmitted copy as soon as the system becomes operational.
4.2 Documentation Requirements 4.2.1 Requirements/Design Documents
The Contractor shall deliver all identified requirements in a softcopy to the Government for approval prior to designing a system solution. The Contractor shall submit the requirements document electronically via CBP electronic mail system in a format specified by the COR.
The Contractor shall deliver the design solution in a softcopy to the Government. Programming shall not begin before the Government approves the solution.
4.2.2 System Operation Manuals
The Contractor shall deliver to the Government Operation manuals for the maintenance of the system environments (test and production). The manuals shall be written in a format that will provide a description of the operating environments and instructions for trouble shooting the environments in the event of a system environmental failure. The manual shall include a schematic of the environments. All interfaces to the system shall be included in the manuals. All servers must be documented with an identifier (name of the server) noted. The manuals shall be submitted to the COR for use by the CBP OIT Support Staff.
4.2.3 System Diagrams
The Contractor shall deliver to the Government system diagrams that include server identification, server purpose, exhibit connections/interface to other processors and the system flow. The diagrams must be included in the operation manuals for each environment. If the environments (SAT & PROD) are slightly different, a notation must be made in the operations manuals.
4.3 Estimated Staffing/Labor Category Description and Key Personnel 4.3.1 Estimated Staffing/Labor Category Requirements The Contractor shall provide full-time and part-time personnel necessary to meet the CBP requirements as outlined in this SOW. Recommended personnel and skill mix are listed below; however, the Government will consider alternatives to allow Contractor flexibility in meeting the CBP requirements.
Project Manager – extensive experienced in managing projects and personnel who will be responsible for the planning, execution and implementation of projects
Senior Application Developer – extensive software development experience with web-based technologies
Application Developer – software development experience with web based technologies
Senior Business Analyst – extensive development experience with functional requirements, specifications and system design
Quality Assurance Specialists – experienced in planning and managing software testing
4.3.2 Key Personnel
Key personnel are considered to be essential to the work being performed under this contract. Prior to changing any of the specified individuals to other programs for whatever reason, the Contractor shall notify the COR reasonably in advance, preferably more than thirty days, and shall submit a detailed explanation of the circumstances necessitating the proposed substitutions, a complete resume for each proposed substitute and any other information requested by the COR, to permit evaluation of the impact on the program. The COR shall evaluate such requests and promptly notify the Contractor whether the proposed substitution has been approved or disapproved. No diversion shall be made by the Contractor without the written consent of the COR; provided the COR may confirm in writing such diversion and such confirmation shall constitute the consent of the COR. The key personnel identified in the Contractor’s proposal for award of this contract, shall be assigned to the first order(s) awarded under this contract for the area in which they were proposed. As appropriate, the list of key personnel may be modified during the term of the contract to either add or delete personnel.
The Contractor agrees to assign tasks to those persons who are necessary to fill the requirements of the Contract whose resumes are submitted with its proposal and who has been specifically defined as key personnel. The Contractor shall propose key personnel responsible for CBP evaluation that include subject matter experts on .NET, Advanced Distributed Learning (ADL), Section 508 and the COTS solution. CBP also requires a senior level project manager and a senior level software developer.
4.4 Travel
All travel must be pre-approved in writing by the COR and must be in accordance with the Federal Travel Regulation (FTR). E-mail from the COR is acceptable for written authorization.
4.5 Other Direct Costs
No ODCs are anticipated under this contract.
4.6 Compliance The contractor, both in everyday work activities and within the ACMS software and system, shall comply with the DHS Handbook for Safeguarding Sensitive personally identifiable Information (PII) to safeguard PII in paper and electronic form as well as comply with the other documents and policies listed in Section 3.
4.6.1 Enterprise Architecture (EA) Compliance
The Offeror shall ensure that the design conforms to the DHS and CBP enterprise architecture (EA), the DHS and CBP technical reference models (TRM), and all DHS and CBP policies and guidelines as promulgated by the DHS and CBP Chief Information Officers (CIO), Chief Technology Officers (CTO) and Chief Architects (CA) such as the CBP Information Technology Enterprise Principles and the DHS Service Oriented Architecture – Technical Framework.
The Offeror shall conform to the federal enterprise architecture (FEA) model and the DHS and CBP versions of the FEA model as described in their respective EAs. Models will be submitted using Business Process Modeling Notation (BPMN 1.1, BPMN 2.0 when available) and the CBP Architectural Modeling Standards for all models. Universal Modeling Language (UML2) may be used for infrastructure only. Data semantics shall be in conformance with the National Information Exchange Model (NIEM). Development solutions will also ensure compliance with the current version of the DHS and CBP target architectures.
Where possible, the Offeror shall use DHS/CBP approved products, standards, services, and profiles as reflected by the hardware software, application, and infrastructure components of the DHS/CBP TRM/standards profile. If new hardware, software and infrastructure components are required to develop, test, or implement the program, these products will be coordinated through the DHS and CBP formal technology insertion process which includes a trade study with no less than four alternatives, one of which shall reflect the status quo and one shall reflect multi-agency collaboration. The DHS/CBP TRM/standards profile will be updated as technology insertions are accomplished.
All developed solutions shall be compliant with the HLS (Homeland Security) EA (Enterprise Architecture).
All IT hardware or software shall comply with the HLS EA.
Compliance with the HLS EA shall be derived from and aligned through the CBP EA.
All data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the DHS Enterprise Data Management Office (EDMO) for review and insertion into the DHS Data Reference Model. Submittal shall be through the CBP Data Engineering Branch and CBP EA.
In compliance with Office of Management and Budget (OMB) mandates, all network hardware provided under the scope of this Statement of Work and associated Task Orders shall be IPv6 compatible without modification, upgrade, or replacement.
The Contractor shall visit the data center where the servers reside when appropriate. If travel costs are involved, the visits shall occur only after consulting with the COR and receiving written permission from the COR. E-mail from the COR is acceptable for written authorization.
4.6.2 Accessibility Requirements (Section 508 Compliance)
Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology, they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.
All Electronic and Information Technology (EIT) deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable standards have been indentified:
36 CFR 1194.22 – Web-based Intranet and Internet Information and Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous Javascript and XML (AJAX) then “1194.21 Software” standards also apply to fulfill functional performance criteria.
36 CFR 1194.31 – Functional Performance Criteria applies to all EIT deliverables regardless of delivery method. All EIT deliverables shall use technical standards, regardless of technology, to fulfill the functional performance criteria.
36 CFR 1194.41 – Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required “1194.31 Functional Performance Criteria”, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offers telephone support such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.
Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COR and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply:
36 CFR 1194.2(b) – (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meet some, but not all, of the standards the agency must procure the product that best meets the standards.
When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires approval from the DHS Office of Accessible Systems and Technology (OAST) in accordance with DHS MD 4010.2.
36 CFR 1194.3(b) – Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.
4.7 Engineering Platforms Common Enterprise Services (CES) – Deliver the systems, infrastructure, and operational capabilities to fully implement the three service levels defined as part of the DHS/CBP Common Enterprise Services and support DHS Component use of those services. This includes the build out and integration of all required services and infrastructure, which must include the Single Sign-on Portal and CBP Enterprise Services Bus (ESB), required for the CES. Capabilities shall be designed to the DHS standard operating architecture (SOA), transportable between DHS data centers (CBP National Data Center, Stennis, and DHS 2nd data center).
Single Sign-on Portal – Design, build, and operate a single sign-on Portal - consistent with DHS’ enterprise portal solution to provide a common point of access, with a single sign-on capability to existing applications and to provide the infrastructure for integrating diverse internal and/or external information and transactional resources.
4.8 Portfolio Review
This acquisition aligns to both the Infrastructure and Training DHS IT Portfolios.
4.9 Acceptance Criteria and User Acceptance Testing Acceptance Criteria: The general quality measures, as set forth below will be applied to each deliverable received from the Contractor under this contract.
Accuracy: The work performed shall meet CBP objectives and the COR prior approval for providing software support.
Documentation of work shall be accurate in presentation, technical content, and adherence to accepted elements of style.
Clarity: Work products shall be clear and concise; engineering terms shall be used, as appropriate. All diagrams shall be easy to understand and relevant to the supporting narrative.
File Editing All text and diagrammatic files shall be editable by the Government.
Timeliness: Work products shall be submitted on or before due dates specified in project schedules.
Format – Microsoft Office files compatible with CBP versions of software. There are several different versions of Microsoft in use within CBP, and as of January, 2012, the oldest Microsoft version still in use within CBP is Microsoft 2000.
User Acceptance Testing: The Contractor shall perform the system programming and development testing on their premises. The Contractor shall support two (2) levels of User Acceptance Testing (UAT) conducted by CBP personnel but will not be required to be at a CBP location. The first level of UAT shall be conducted by OTD personnel and shall be performed in an environment maintained by the Contractor whose software and hardware mimics CBP’s environment. The second level of acceptance testing will be conducted in the system acceptance environment (SAT) at CBP. This test will be performed by the Office of Information Technology (OIT) test personnel.
All software implementations shall be supported by the Contractor. The Contractor shall be present (when applicable) and available to CBP OIT Support staff when software is implemented to the CBP environments (SAT and PROD) and to troubleshoot any anomalies that may occur throughout the life of this contract.
4.10 Service Coverage and Contractor Employee Conduct
4.10.1 Service Coverage
Priority 1 - Operational System Down
Priority 1 occurs when the system is failing in an operational environment resulting in a complete loss of capability. This type of problem severely impacts CBP objectives and requires a timely response and corrective action. Examples of operational down time are a no read instances or the complete failure of one of the system components.
Acknowledgement is required 15 minutes after notification. Initial response is required 30 minutes following notification. Corrective action is required on the same day or no later than one day after required parts become available.
Priority 2 - System is not functioning as specified
Priority 2 occurs when a function of the system is not behaving as specified. Operational work can continue but the system is not performing to specification (degraded) and corrective action is required. Examples are data latency or intermittent operation. Acknowledgement is required one hour after notification. Initial response is required three hours following notification. Corrective action is required on the same day or no later than one day after required parts become available.
4.10.2 Contractor Employee Conduct
The Contractor shall be responsible for maintaining satisfactory standards of employee competency, conduct, appearance and integrity, and shall be responsible for their employee’s performance or the quality of their services.
4.10.3 Contractor Work Hours
The Contractor shall adhere to CBP hours of operations and federal holidays as shown below.
HOLIDAYS AND ADMINISTRATIVE LEAVE
U.S. Customs and Border Protection (CBP) personnel observe the following days as holidays:
New Year's Day Labor Day
Martin Luther King's Birthday Columbus Day
Presidents' Day Veterans Day
Memorial Day Thanksgiving Day
Independence Day Christmas Day
Any other day designated by Federal statute, by Executive Order or by the President's proclamation.
When any such day falls on a Saturday, the preceding Friday is observed. When any such day falls on a Sunday, the following Monday is observed. Observance of such days by Government personnel shall not be cause for an extension to the delivery schedule or period of performance or adjustment to the price, except as set forth in the contract.
Except for designated around-the-clock or emergency operations, contractor personnel will not be able to perform on site under this contract with CBP on holidays set forth above. The contractor will not charge any holiday as a direct charge to the contract. In the event Contractor personnel work during a holiday other than those above, no form of holiday or other premium compensation will be reimbursed as either a direct or indirect cost. However, this does not preclude reimbursement for authorized overtime work.
In the event CBP grants administrative leave to its Government employees, at the site, on-site contractor personnel shall also be dismissed if the site is being closed. However, the Contractor shall continue to provide sufficient personnel to perform around-the-clock requirements of critical efforts already in progress or scheduled and shall be guided by the instructions issued by the Contracting Officer or her/his duly appointed representative. In each instance when the site is closed to Contractor personnel as a result of inclement weather, potentially hazardous conditions, emergencies, or other special circumstances; the Contractor will direct its staff as necessary to take actions such as reporting to its own site(s) or taking appropriate leave consistent with its policies. The cost of salaries and wages to the Contractor for the period of any such site closure are a reimbursable item of direct cost under the contract for employees whose regular time is normally a direct charge if they continue to perform contract work; otherwise, costs incurred because of site closure are reimbursable as indirect cost in accordance with the Contractor's established accounting policy.
4.10.4 Additional Contractor Personnel Requirements
The Contractor shall ensure that its employees will identify themselves as employees of their respective company while working on CBP contracts. For example, Contractor personnel shall introduce themselves and sign attendance logs as employees of their respective companies, not as CBP employees.
The Contractor shall ensure that their personnel use the following format signature on all official e-mails generated by CBP computers:
[Name]
[Position or Professional Title]
[Company Name]
Supporting the XXX Division/Office…
Bureau of Customs and Border Protection
[Phone]
[FAX]
[Other contract information as desired]
GOVERNMENT-FURNISHED EQUIPMENT AND INFORMATION:
CBP will furnish laptop computers and CBP system access as needed to be used by properly cleared and authorized contractor personnel for use in executing the tasks named in this contract.
The contractor will be able to access all pertinent data including but not limited to class schedules, training requirements, training plans and student data by accessing the current ACMS.
The contractor will have access to all applicable documents identified in Section 3.
PLACE OF PERFORMANCE:
The Contractor shall perform the majority of their work on their premises; however they shall also attend meetings and perform system related work at various CBP and FPS locations.
PERIOD OF PERFORMANCE:
The period of performance will be 12 months.
SECURITY:
The Contractor shall comply with the Customs administrative, physical and technical security controls to ensure that the Government’s security requirements are met. During the course of this Order, the Contractor shall not use, disclose, or reproduce data, which bears a restrictive legend, other than as required in the performance of this Order.
The project is UNCLASSIFIED, and the selected solution will be designated Limited Official Use (LOU). The Contractor staff must possess a minimum of a Public Trust government clearance to perform the work described herein.
All contractor employees involved in the work of this contract will execute a Non-Disclosure Agreement before beginning any work on this contract.
9.1 Information Security COMPLIANCE
Information Security
"All services provided under this task order must be compliant with DHS Information Security Policy, identified in MD4300.1, Information Technology Systems Security Program and 4300A Sensitive Systems Handbook."
Interconnection Security Agreements (ISAs) Interconnections between DHS and non-DHS IT systems shall be established through controlled interfaces and via approved service providers. The controlled interfaces shall be accredited at the highest security level of information on the network. Connections with other Federal agencies shall be documented based on interagency agreements; memoranda of understanding, service level agreements or interconnect service agreements. Components shall document interconnections with other external networks with an Interconnection Security Agreement (ISA). Interconnections between DHS Components shall require an ISA when there is a difference in the security categorizations for confidentiality, integrity, and availability for the two networks. ISAs shall be signed by both DAAs or by the official designated by the DAA to have signatory authority.
System Security documentation appropriate for the SDLC status Security Certification/Accreditation
CBP shall provide personnel with the appropriate clearance levels to support the security certification/accreditation processes under this Agreement in accordance with DHS MD 4300A, DHS Sensitive Systems Policy and Handbook. During all SDLC phases of CBP systems, CBP personnel shall develop documentation and provide any required information for all levels of classification in support of the certification/accreditation process. In addition, all security certification/ accreditation will be performed using the DHS certification/accreditation process, methodology and tools.
Security Review and Reporting
(a) The Contractor shall include security as an integral element in the management of this contract. The Contractor shall conduct reviews and report the status of the implementation and enforcement of the security requirements contained in this contract and identified references.
(b) The Government may elect to conduct periodic reviews to ensure that the security requirements contained in this contract are being implemented and enforced. The Contractor shall afford DHS including the Office of Inspector General, CBP ISSM, and other government oversight organizations, access to the Contractor's and subcontractors' facilities, installations, operations, documentation, databases, and personnel used in the performance of this contract. Access shall be provided to the extent necessary for the government to carry out a program of inspection, investigation, and audit to safeguard against threats and hazards to the integrity, availability, and confidentiality of DHS/CBP data or the function of computer systems operated on behalf of DHS/CBP, and to preserve evidence of computer crime.
SPECIAL CONSIDERATIONS:
APPENDIX A: ACRONYMS
| Acronym |
| Definition |
| ACE |
| Automated Commercial Environment |
| ACMS |
| Academy Classroom Management System |
| ACS |
| Automated Commercial System |
| ADA |
| Americans with Disabilities Act |
| ADL |
| Advanced Distributed Learning |
| ADL |
| Advanced Distributive Learning |
| ADP |
| Automated Data Processing |
| AES |
| Automated Export System |
| API |
| Application Programming Interface |
| BPMN |
| Business Process Modeling Notation |
| CA |
| Chief Architects |
| CAF |
| CMM Appraisal Framework |
| CBP |
| Customs and Border Protection |
| CES |
| Common Enterprise Services |
| CIO |
| Chief Information Officer |
| CM |
| Configuration Management |
| CMM |
| Capability Maturity Model |
| CMMI |
| Capability Maturity Model Integrated |
| CO |
| Contracting Officer |
| COOP |
| Contingency of Operations Plan |
| COR |
| Contracting Officer’s Representative |
| COTS |
| Commercial off the Shelf |
| CPU |
| Central Processing Unit |
| CR |
| Change Request |
| CRF |
| Commercial Recovery Facility |
| CSO |
| Chief Security Officer |
| CTO |
| Chief Technology Officers |
| DHS |
| Department of Homeland Security |
| DROC |
| Disaster Recovery Operations Center |
| EA |
| Enterprise Architecture |
| eCP |
| Enterprise Customs Partnership |
| EDMO |
| Enterprise Data Management Office |
| EHRI |
| Enterprise Human Resource Integration |
| EIT |
| Electronic and Information Technology |
| EPO |
| Enabling Performance Objectives |
| ESB |
| Enterprise Services Bus |
| FEA |
| Federal Enterprise Architecture |
| FIP |
| Federal Information Processing |
| FLETA |
| Federal Law Enforcement Training Accreditation |
| FLETC |
| Federal Law Enforcement Training Center |
| FTR |
| Federal Travel Regulation |
| GFE |
| Government Furnished Equipment |
| GOTS |
| Government Off-the-Shelf |
| GSA |
| General Services Administration |
| HLS |
| Homeland Security |
| HVAC |
| Heating, Ventilation and Air Conditioning |
| ISA |
| Interconnection Security Agreement |
| ISO |
| International Standards Organization |
| IT |
| Information Technology |
| JTA |
| Job Task Analysis |
| LAN |
| Local Area Network |
| LOU |
| Limited Official Use |
| NCC |
| National Communications Center |
| NDC |
| National Data Center |
| NIEM |
| National Information Exchange Model |
| OAST |
| Office of Accessible Systems and Technology |
| OBP |
| Office of Border Patrol |
| OC |
| Oleoresin Capsicum |
| OEM |
| Original Equipment Manufacturer |
| OEP |
| Occupant Emergency Plans |
| OFO |
| Office of Field Operations |
| OIT |
| Office of Information and Technology |
| OMB |
| Office of Management and Budget |
| OMR |
| Optical Mark Recognition |
| OTD |
| Office of Training and Development |
| PAL |
| Process Asset Library |
| PCII |
| Protected Critical Infrastructure Information |
| SASS |
| Student Administration and Scheduling System |
| SAT |
| System Acceptance Testing |
| SDLC |
| System Development Life Cycle |
| SEI |
| Software Engineering Institute |
| SOW |
| Statement of Work |
| SSI |
| Sensitive Security Information |
| SW-CMM |
| Software Capability Maturity Model |
| TECS |
| Treasury Enforcement Communications System |
| TPO |
| Terminal Performance Objectives |
| TRAEN |
| Training Records and Enrollment Network |
| TRM |
| technical reference models |
| UML |
| Universal Modeling Language |
File details come from the government source that posted it.