CORHQ-24-R-0686 Amendment 0001.pdf
PDF 1 MB Posted
- Attached to
- Enterprise Test Data Management Federal contract opportunity
- Solicitation number
- CORHQ-24-R-0686
- Issued by
- Federal Deposit Insurance Corporation
About this file
This is a 91-page Request for Proposal (RFP) issued by the Federal Deposit Insurance Corporation (FDIC) seeking Enterprise Test Data Management (ETDM) services to support software and platform development requirements. The RFP uses a two-phase evaluation approach, with Phase 1 proposals due January 13, 2025 by 5:00 PM focusing on Factor A (Demonstrated Experience), and Phase 2 submissions due January 31, 2025 by 5:00 PM for remaining factors after advisory notification.
The contractor will provide test data management services including design, implementation, operations, maintenance, data masking, obfuscation, synthetic data generation, and test environment support. The contract will be awarded as a best value source selection with a 12-month base period and four 12-month options. Evaluation factors in descending order of importance are: Technical & Management Approach, Key Personnel, Scenario Based Oral Presentation, Past Performance, Demonstrated Experience, and Price. Key personnel required are Project Manager/Scrum Master, Data Architect, and Test Engineer. The NAICS code is 541519 with a $34 million size standard. The RFP includes provisions for both Firm Fixed Price and Time & Materials CLINs, with projects categorized as small, medium, or large complexity based on defined criteria.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| CORHQ-24-R-0686 Amendment 0005.pdf | ||
| CORHQ-24-R-0686 Amendment 0004.pdf | ||
| Enterprise TDM Pricing Workbook Version 2.xlsx | XLSX spreadsheet | |
| CORHQ-24-R-0686 Amendment 0003.pdf | ||
| Summary of Changes Amendment 0003.pdf | ||
| CORHQ-24-R-0686 Amendment 0002.pdf | ||
| ETDM Live Session Presentation Slides.pdf | ||
| BISS SOO Attachment C 2027 Target State Architecture v1.1updated.pdf | ||
| BISS SOO Attachment C - 2027 Target State Architecture v1.1 updated.pdf | ||
| BISS SOO Attachment B - Sample BISS Portfolio Data Sets.xlsx | XLSX spreadsheet | |
| Enterprise TDM Pricing Workbook.xlsx | XLSX spreadsheet | |
| BISS SOO Attachment D - ETDM Accomplishments to Date.docx | DOCX document | |
| Questions and Answers Sheet.xlsx | XLSX spreadsheet | |
| CORHQ-24-R-0686.pdf | ||
| BISS SOO Attachment A - Software Tools Inventory.xlsx | XLSX spreadsheet | |
| BISS SOO Attachment C - 2027 Target State Architecture v1.1.pdf |
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOLICITATION/AWARD
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
1. REQUISITION NUMBER PAGE 1 OF
2. CONTRACT NO. 3. AWARD/EFFECTIVE
DATE
4. ORDER NUMBER 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE
DATE
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME b. CONTACT INFORMATION 8. OFFER DUE DATE/
LOCAL TIME
9. ISSUED BY
13b. N/A
14. METHOD OF SOLICITATION
CODE
15. DELIVER TO 16. ADMINISTERED BY CODE
18a. PAYMENT WILL BE MADE BY CODE17a. CONTRACTOR/
OFFEROR
CODE
FACILITY
CODE
CODE
TELEPHONE NO.
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN
OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK
BELOW IS CHECKED
RFQ RFP
Price only
SEE ADDENDUM
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. N/A 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY ADDITIONAL
SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED
29. AWARD OF CONTRACT: REF.
YOUR OFFER ON SOLICITATION
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE SET FORTH
HEREIN, IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR
30b. NAME AND TITLE OF SIGNER (Type or print) 30c. DATE SIGNED
31a. FEDERAL DEPOSIT INSURANCE CORPORATION (SIGNATURE OF CO)
31b. NAME OF CONTRACTING OFFICER (Type or print) 31c. DATE SIGNED
FDIC 3700/55 (3-08)
10. SOCIO-ECONOMIC STATUS
NO
NAICS:
ETHNICITY:
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
OFFER
13a. SUB-CONTRACTING
PERMITTED/APPROVED
YES
SDB
MWOB
SERVICE-DISABLED VETERAN-
OWNED SMALL BUSINESS
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
YES NO
YES NO
27a. SOLICITATION INCLUDES ATTACHMENTS 27b. AWARD INCLUDES ATTACHMENTS
RFI RFP
Best Value
CORHQ-24-R-0686
19.
ITEM NO.
20.
SCHEDULE OF SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23.
UNIT PRICE
24.
AMOUNT
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED:
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
40. PAID BY
32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f. TELPHONE NUMBER OF AUTHORZED GOVERNMENT REPRESENTATIVE
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
33. SHIP NUMBER 34. VOUCHER NUMBER 35. AMOUNT VERIFIED
CORRECT FOR
PARTIAL FINAL
37. CHECK NUMBER
38. S/R ACCOUNT NO. 39. S/R VOUCHER NUMBER
36. PAYMENT
COMPLETE PARTIAL FINAL
FDIC 3700/55 (3-08)
Section B - Supplies or Services and Prices/Costs
Attachments for this section start after this page.
Section B - Supplies or Services and Prices/Costs PAGE 3 OF 91
CONTROLLED//FDIC BUSINESS
Price Schedule
The Offeror is required to complete the Excel workbook provided in the email with Request for Proposal(RFP). If you did not receive the Excel workbook when you received the RFP please contact the Contracting Officer immediately. , The instructions for completing the workbook are included in Attachment B-1 Pricing Instructions.
Section B - Supplies or Services and Prices/Costs PAGE 4 OF 91
Section C - Description/Specifications/Work Statement
Attachments for this section start after the clauses.
Clauses Incorporated By Reference
Clause # Title Date
No reference clauses were found for this section.
Full Text Clauses
7.3.2-21 - Description/Specifications/Work Statement - October 2008 The name/description of the goods or services being acquired is as follows:
Test Data Management Services.
The specifications for and the description of the work to be performed under this award are fully detailed in either a
Statement of Work (SOW) or a Statement of Objective coupled with a Performance Work Statement (PWS), which is included as an attachment in Section J of this award document.
7.3.2-34 - Duty to Deliver or Perform - July 2008 Contractor agrees to perform the services (the "Services") or provide the goods (the "Goods"), in accordance with the terms and conditions set forth herein and in any attachments to the contract.
Section C - Description/Specifications/Work Statement PAGE 5 OF 91
Enterprise Test Data Management (ETDM) Statement of Objectives (SOO)
1. Introduction The Federal Deposit Insurance Corporation (FDIC) is seeking an industry partner to provide expert technical services in support of Enterprise Test Data Management (ETDM). The ETDM effort meets at the intersection of application development, enterprise data management, and independent test and evaluation activities.
Figure 1: Enterprise Test Data Management CONOPs
The ETDM requirement covers the spectrum of test data lifecycle management, to include but not limited to implementing a robust test data management framework, supported by effective implementation strategies and methods. By adopting a systematic approach to test data management, FDIC can accelerate testing cycles, minimize data handling risks in the test environment, and optimize development resources, ultimately enhancing the reliability and security of their software products.
1.1 BISS Background
As part of the Application Platforms & Delivery Branch (APDB) within the Chief Information Officer Organization (CIOO), the Business Intelligence Services Section (BISS) provides FDIC customers with enterprise-wide capabilities and corporate support in data acquisition, data management, and data analytics. This SOO adds another service offering under the BISS portfolio, which enhances test data management services. Current service offerings include data orchestration across a hybrid cloud and onsite IT environment, data lifecycle management for enterprise data assets, development across multiple data visualization and analysis platforms, and rapid prototyping in areas like robotic process automation, artificial intelligence, and machine learning.
Section C - Description/Specifications/Work Statement PAGE 6 OF 91
The BISS mission is “Deliver the right data to the right people, in a timely, decision-making context.”
1.2 Workstream Coordination and Generation
Workstream coordination and planning will be directed and managed by the BISS team but may include collaboration across organizational boundaries within the CIOO and with external business partners.
The contractor shall provide all necessary resources with the appropriate expertise to successfully support the implementation of requirements set forth in the Performance Areas section of this document.
1.2.1 ETDM Projects: The FDIC will assign each ETDM project a level of complexity (small, medium, or large) in accordance with the table below.
Projects may encompass both service and solutions activities (1.2.3) and development work (1.2.4).
Table 1 – Project Activities by Complexity
Required Project Activity Small Medium Large Customize data or application test environment No No Yes Receive security, privacy, and business approval of test methods (e.g. obfuscation, masking, etc.)
No Yes Yes
Create test data scripts No Yes Yes Stand up and operate test server No Yes Yes Integrate with more than two applications in test environment No Yes Yes Conduct tests data ops Yes Yes Yes Support testing integration and UAT Yes Yes Yes Update existing test data elements Yes Yes Yes Verify and validate test results Yes Yes Yes
Table 2 – Estimated Effort by Complexity
Project Complexity
Level
Effort Description
Small Likely to be completed within 4 two-week sprints, may not require full time support, and likely would not require more than three different labor categories
Section C - Description/Specifications/Work Statement PAGE 7 OF 91
Medium Likely to be completed in 5-24 two-week sprints, may require specialized expertise across multiple labor categories.
Large May require more than 24 two-week sprints, some dedicated full time support, specialized expertise across multiple labor categories, and a higher degree of customization.
1.2.2 Contract Type: The Contract Line Item Numbers (CLINs) in this contract are of two types: 1) Firm Fixed Price (FFP) by Project Complexity and 2) Time and Materials (T&M). The CLINs are listed below:
CLIN 1: Small Project (FFP) CLIN 2: Small Project (FFP) CLIN 3: Medium Project (FFP) CLIN 4: Large Project (FFP) Optional CLINs (FFP and T&M) o The purpose of these optional CLINs is to complete future projects and supplemental activities beyond those ordered in CLINs 1-4
1.2.3 Service & Solutions Activities: Service & Solutions work is generated by customers within FDIC through formal or informal service requests. These activities are prioritized and assigned by BISS.
1.2.4 Development Work: Development work covers improvements to or extensions of existing systems, capabilities, or processes to meet desired performance metrics. For applications, development work means design, implementation, operations, maintenance, and enhancements of software tools. For data, development means design, modeling, integration of existing data, developing new datasets, and ensuring test data meets prescribed requirements. These test data requirements are derived from system owners, privacy experts, and security practitioners aligned to FDIC policy, guidance, and operational best practices. This work is generated and directed by BISS.
2. Objectives
The ETDM objectives are covered in three sections – Business, Technical, and Security Objectives.
2.1 Business Objectives
Section C - Description/Specifications/Work Statement PAGE 8 OF 91
Business objectives describe the desired performance outcomes from activity delivery and execution for stakeholders within the CIOO and across the FDIC. These objectives align with FDIC, CIOO, APDB, and/or BISS strategic goals.
Ensuring Regulatory Compliance and Data Privacy
• Support the protection of sensitive information and ensure compliance with data protection regulations by implementing data masking, anonymization, obfuscation, and encryption techniques.
• Ensure regulatory compliance and data privacy instills trust and confidence among customers, partners, and stakeholders, safeguarding FDIC’s reputation and mitigating legal and financial risks.
Accelerate Release Cycles
• Enable development and testing teams to iterate rapidly, identify defects early, and release software updates more frequently through timely access to high-quality test data.
• Develop, maintain, and administer a registry of reusable test data assets, minimizing the amount of new work required to execute application testing activities.
Enhance Software Quality and Reliability
• Support the identification of defects, vulnerabilities, and performance issues early in application development by provisioning high-quality test data that accurately reflects production operations, to include edge case testing and other test scenarios.
• Enhance customer satisfaction, reduce post-release defects, and minimize the risks of service disruptions or security breaches with improved software quality and reliability.
Optimizing Resource Utilization and Cost Efficiency
• Reduce manual effort, accelerate testing cycles, and minimize inefficiencies by improving automation, test data design, development, and test lifecycle management.
• Enable FDIC to allocate resources more effectively, maximize return on investment (ROI), and achieve better cost predictability in software development and testing cycles by optimizing resource utilization and cost efficiency.
Facilitating Collaboration and Alignment
• Enhance communication, coordination, and knowledge sharing across the organization by providing a centralized repository for test data assets.
• Facilitate collaboration and organizational alignment enabling teams to work towards common goals, share best practices, and leverage collective expertise to drive continuous improvement and innovation.
Section C - Description/Specifications/Work Statement PAGE 9 OF 91
2.2 Technical Objectives
Technical objectives describe the desired performance outcomes from activity delivery and execution, focusing on the technical aspects that contribute to the success of ETDM initiatives within the organization. These objectives generally align to the target state architecture, the target data ecosystem, infrastructure modernization efforts, cloud adoption objectives, and emerging technology needs.
Automate Test Data Development and Lifecycle Management
• Use automation to reduce the risk of human error, ensure consistency in test data generation, and enable on-demand access to relevant data for testing purposes.
• Contribute to overall lifecycle management of data assets to include data modernization and data readiness activities.
Implement Data Masking, De-identification, and Synthetic Test Generation Techniques
• Evaluate and describe with key metrics the practical methods to ensure security and privacy of data in the test environment.
• Use data masking, obfuscation, encryption, de-identification, and anonymization techniques to protect sensitive information in test environments while maintaining representative data for testing purposes.
• Use synthetic test data generation tools to generate quantities of test data based on business rules without leveraging any production data.
• Use subsets of production data that is relevant to specific testing scenarios, reducing the volume of data at risk while preserving data integrity and realism.
Integrate ETDM with Continuous Integration/Continuous Delivery (CI/CD) Pipelines and Data Orchestration Tools
• Automate test data provisioning, validation, and updating as part of the automated build, test, and deployment workflows through integration with CI/CD pipelines using FDIC DevSecOps tools.
• Leverage existing data orchestration tools to automate test data procedures.
• Evaluate technology, develop prototypes, and advance automation and systems integration efforts within the FDIC IT environment.
Implement and Administer Secure Test Data Repositories and/or Servers
• Perform installation, configuration and administration of test data tools.
• Implement security procedures, including access control, encryption, Section C - Description/Specifications/Work Statement PAGE 10 OF 91 patches, and regular security audits to safeguard the test data tools, systems, environments, and test data repositories.
2.3 Security Objectives
Security objectives describe the desired performance outcomes from activity delivery and execution as it relates to the FDIC, and industry standard security requirements and best practices. These objectives generally align to federal government and FDIC security policies and standards.
Policy Compliance
• Support and enhance FDIC policies, procedures, and practices as they relate to the enterprise test data management functions.
• Support the security-related activities, policies, and procedures performed by partner and customer organizations.
• Ensure that the work performed complies within the stated laws, rules, and guidelines of the FDIC IT security and privacy procedures and policies. Examples include the Privacy Act of 1974, the FDIC Test Data Strategy, and internal policy documents.
• Collaborate with the Office of the Chief Information Security Officer (OCISO) Privacy and Security sections for review of test data to meet policy thresholds.
Security Implementation
• Support FDIC’s Assess & Authorize (A&A) process to address the
National Institute of Standards and Technology (NIST) 800-53 controls identified as in-scope of the System Security Plan (SSP) and OMB A-130 for FDIC Authority to Operate (ATO).
• Document and demonstrate implementation of security and internal controls designed to mitigate information systems security risk.
• Provide ongoing support as required during FDIC’s annual security assessment requirement. Provide support as required to address security findings and POA&Ms resulting from FDIC’s periodic security assessments by OCISO and FDIC Information Security Managers (ISMs).
3. Performance Areas
This section contains detailed descriptions for services required in connection with this effort. Contractors are expected to comply with all requirements described below.
3.1 Project Management, Strategy, & Governance
• Manage cost, schedule, and performance of assigned work efforts, to include mitigating risks, identifying issues, and sequencing work based on technical or business dependencies.
• Organize work efforts, team skill mix, and resources into
Section C - Description/Specifications/Work Statement PAGE 11 OF 91 increments, sprints, and other iterative blocks of time.
• Conduct kickoff and retrospective events coinciding with the start and conclusion of each iteration or work increment.
• Develop, track, and report performance metrics for work throughput, velocity, quality, and return on effort.
• Ensure source code, data, technical documentation, and derivative products are stored on the FDIC network and within collaboration platforms directed by FDIC.
• Propose process improvements to enhance customer service, reduce costs, strengthen operational efficiency, or reduce risk.
• Develop documentation and project artifacts for planning, knowledge management, training, and compliance purposes.
3.2 Planning & Analysis
• Understand and synthesize detailed business requirements to execute the ETDM lifecycle.
• Analyze requirements to identify the appropriate methodology for test data creation such as obfuscation, masking, synthetic data generation, or encryption.
• Establish and maintain referential integrity across enterprise systems and applications for test data assets.
• Design a test data management architecture that describes processes and infrastructure to access source data, create and manage test data, interface with systems and applications in the test environment, and archive test data assets.
3.3 Enterprise Test Data Management – Design, Build, and Test Operations
• Deploy scalable ETDM solutions that integrate with both on-prem and cloud data infrastructure, strengthened by data catalog integration where available.
• Develop repeatable processes for data subsetting, obfuscation, masking, or encryption to protect sensitive information while enforcing referential integrity and preserving its utility for testing purposes enterprise-wide.
• Develop and leverage automated tools and algorithms for synthetic data generation based on application business rules with referential integrity.
• Develop capabilities to consume and publish data from APIs, web services, and system interfaces.
• Ensure scalability to accommodate large volumes of data generation, evolving testing requirements, and dynamic data needs across different testing scenarios.
• Provide access to relevant data without exposure of production data and minimize use of manually created test data.
Section C - Description/Specifications/Work Statement PAGE 12 OF 91
• Ensure that ETDM processes are automated and ready for integration into the test application's CI/CD pipelines.
• Collaborate with Privacy, Security, and business organizations to ensure sensitive data is protected and test data meets security and privacy protection thresholds.
• Work with customer to ensure test data integrates with application and business rules.
• Provide technical documentation on test data in the form of data quality reports, data models, and architecture diagrams.
• Provide test scenario design and support for various projects across the agency.
3.4 Systems Administration & Enabling Support
• Keep test data generation software, tools, and servers up to date through installation, configuration, administration, patching and updating best practices
• Configure, manage, and safeguard executables and software in FDIC’s code repositories.
• Implement comprehensive security controls, including access controls, encryption, security patching and regular security audits, to safeguard the virtual servers hosting the tools and the test data repository.
• Provide technical support for adjacent emerging technology efforts in intelligent automation, business intelligence, advanced analytics, and artificial intelligence.
• Provide systems integration support for upstream and downstream consumers of data.
• Provide enabling support to enterprise data catalog, ICAM, and ZeroTrust efforts.
• Provide enabling support for rapid prototyping and application testing.
4. Key Personnel
The following personnel are key personnel under this contract. The Contractor shall ensure that all personnel filling key personnel positions are retained in those positions for a minimum of 180 calendar days following FDIC approval of their resumes. Substitution of key personnel prior to 180 calendar days after contract award shall be allowed only in the event the designated person is ill, and, or otherwise unable to perform the functions of the position or leaves the employ of the Contractor.
4.1 Project Manager / Scrum Master
Section C - Description/Specifications/Work Statement PAGE 13 OF 91
• Shall have at least seven (7) years of experience managing and orchestrating Agile teams delivering business intelligence and data services
• Shall be proficient in the use of tools and methods to efficiently manage product releases, sprints, and development cycles
• Certification in Agile methods, Microsoft Azure, Oracle, and GitHub are highly desired
• Shall have experience utilizing program and project management tools, including GitHub, ServiceNow, and Microsoft Teams to plan, execute, and measure projects
• Shall have demonstrated experience overseeing an enterprise data management, data analytics, or cloud migration efforts similar in scope and size to this contract
4.2 Data Architect
• Shall have at least seven (7) years of experience managing enterprise data management infrastructure, to include managing on-premises systems and cloud migration efforts, data base administration, including referential/data integrity, point in time recovery, and custom coding
• Shall be proficient in database technologies to include but not limited to Oracle, SQLServer, Postgres, MariaDB, MySQL and Azure Database services
• Shall have demonstrated experience in leading transformation projects related to establishing an enterprise-wide data layer and establishing mature DataOps practices
4.3 Test Engineer
• Shall have at least ten (10) years of experience managing enterprise data management infrastructure, to include managing on premises systems and cloud migration efforts
• Shall be familiar with in configuration and administration of enterprise level data stores, ETL/ELT methods, batch and streaming data transport, and API development.
• Shall have at least three (3) years of experience in test data management, including test data generation and production data obfuscation.
• Shall have an understanding of database technologies to include but not limited to Oracle, SQLServer, Postgres, MariaDB, MySQL, and Azure Database services.
• Shall have experience utilizing program and project management tools, such as Microsoft Team Foundation Server, Git, JIRA, or Microsoft Project to plan, execute, and measure projects.
Section C - Description/Specifications/Work Statement PAGE 14 OF 91
• Shall have demonstrated experience overseeing enterprise level data operations of similar size and scope to this contract.
5. Timing and Deliverables
5.1 Deliverables
The Deliverables to be provided by Contractor are set forth below. This is not an exhaustive set and is subject to change. The Contractor shall deliver the following to the FDIC Technical Monitor and the FDIC Oversight Manger.
Deliverable Description Delivery Date
ETDM Kickoff Presentation Information exchange between FDIC and contractor to discuss roles and responsibilities, near team objectives, reporting and work cadence, and governance process for issue escalation and resolution.
5 calendar days after Contract Effective Date
Current State Analysis – Test Data Operationalization Analytic report with narrative and visual description of current test data management processes. Current state analysis should identify the data stores where test data has been generated, number of records, for which systems, how (obfuscated versus synthetic data generated), and scripts used.
Within 30 calendar days after Contract Effective Date
Future State Analysis – Test Data Operationalization Analytic report that defines the future state of test data management. Report should include process improvements, measuring proof of value, and description of the future enterprise test data management ecosystem.
Within 180 calendar days after Contract Effective Date
Implementation of Future State Analysis – Test Data Operationalization Implement approved Future State Analysis to include intake process for new work efforts, establishing core test data infrastructure, and routine work procedures.
Initial implementation within 180 calendar days of approval of Future State Analysis.
Assigned Test Data Management Deliverable (Product Backlog Items or User Stories) Complete assigned test data management deliverable to support new and existing systems on an on-going basis.
As directed by the government client and in alignment with increment and sprint cycles.
Tech Evaluation, Rapid Prototyping, and Integration Support Provide integration support for data and systems adjacent to test data activities to include activities like automation, DevSecOps, data architecture, and emerging technology development
As directed by the government client and in alignment with increment and sprint cycles.
Solution Release Notes - Data & Systems Every software release or new test dataset requires documentation that includes the specifics of the release and will be communicated broadly. Additionally, updates shall be made to related documentation, e.g. CONOPS, SOPS as appropriate.
3 business days prior to planned production release or achieving a key project milestone (e.g. Increment conclusion, new software release)
User Training For new functionality and enhancements, virtual trainings and written documentation as necessary that aligns with the FDIC train-the-trainer activities.
As directed by the government
Monthly Project Report Reporting on key performance metrics (cost, schedule, performance) and status of deliverables.
Monthly. Submitted 15 calendar days after the end of the month.
Other Deliverables and/or Reporting (as needed) As directed by the Oversight Manager
Section C - Description/Specifications/Work Statement PAGE 15 OF 91
6. Third-Party Management
6.1 Third-Party Dependencies
The third-party service providers in the table below are examples of solutions implemented in other parts of FDIC that may require integration, interconnection, or project coordination during ETDM execution.
Third-Party Service Provider Dependency
Legacy IT Infrastructure Systems that may be managed within or outside of the BISS team.
Middleware Applications Data and platform integration using tools such as Mulesoft.
Commercial Platforms Software as a Service tools such as Salesforce, ServiceNow, Appian, or other business systems.
IRI Voracity tool suite Current tool for data obfuscation and synthetic data generation.
Microsoft Azure Migration of data transport, management, and analytics are dependent upon availability of cloud services provided by Microsoft Azure.
FDIC Enterprise Data Catalog Publishing or exposing datasets for discovery are dependent upon the deployment of FDIC’s Enterprise Data Catalog.
Security for Open-Source Software
Candidate open-source software tools will be dependent upon successful screening and approval by FDIC security.
7. Period of Performance
The period of performance for this contract shall not exceed five years, with a 12-month base period and four 12-month option periods.
8. Place of Performance
The Contractor shall determine places of performance for its team members;
however, all places of performance shall be within the contiguous forty-eight US states. FDIC will not pay Contractor for travel in the event travel is required for onboarding activities such as fingerprinting, renewing PIV cards, etc. If the FDIC Program Manager requests that personnel attend in-person meetings or other engagements any travel time and/or travel costs shall be billed separately as travel.
Section C - Description/Specifications/Work Statement PAGE 16 OF 91
9. Travel
Contractor travel is allowable under the contract when deemed necessary by the FDIC. Travel expenses will be reimbursed. The Contractor must adhere to the FDIC Contractor Travel Reimbursement Guidelines. All travel must be approved in advance by the Contracting Officer or Oversight Manager.
10. Attachments
Artifact Name BISS SOO Attachment A - Software Tools Inventory BISS SOO Attachment B – Sample BISS Portfolio Data Sets BISS SOO Attachment C– 2027 Target State Architecture v1.1 BISS SOO Attachment D– ETDM Accomplishments To Date
Section C - Description/Specifications/Work Statement PAGE 17 OF 91
Section E - Inspection and Acceptance
No attachments were added for this section.
7.6.4-01 - Inspection and Acceptance - July 2008
(a) All goods and services shall be subject to inspection and test by the FDIC Oversight Manager, to the extent practicable, at all times and places during the term of the award. All inspections by the FDIC shall be made in such a manner as not to unduly delay the work.
(b) The FDIC shall have Ten [10] business days from the date of Contractor''s delivery to determine if such goods and services are in compliance with the requirements of the contract. If any services performed or goods delivered hereunder are not in conformity with the requirements of this Award, the FDIC shall have the right to require
Contractor to reperform the services or redeliver the goods in conformity with the requirements of the Award, at no additional increase in total contract amount. When the services to be performed are of such a nature that the defect cannot be corrected by reperformance of the services, the FDIC shall have the right to (1) require Contractor immediately to take all necessary steps to ensure future performance of the services in conformity with the requirements of the contract; and (2) reduce the contract price to reflect the reduced value of the services performed. In the event Contractor fails promptly to reperform the services or redeliver the goods, or to take necessary steps to ensure future performance of the services or delivery of the goods in conformity with the requirements of the Award, the FDIC shall have the right to either (1) by contract or otherwise, have the services performed or the goods delivered in conformity with the contract requirements and charge to Contractor any cost occasioned to the FDIC that is directly related to the performance of such services or the delivery of such goods; or
(2) terminate this Award for default as provided in 7.6.6-02, Termination for Default.
(c) Contractor shall provide and maintain an inspection system acceptable to the FDIC covering the goods or services to be delivered or performed hereunder. Records of all inspection work by Contractor shall be kept complete and available to the FDIC during the term of this Award and for such longer period as may be specified elsewhere in this Award.
Section E - Inspection and Acceptance PAGE 18 OF 91
Section F - Deliveries or Performance
7.3.1-10 - Place of Delivery or Performance - November 2013 The place of delivery or performance is: The Contractor shall determine places of performance for its team members; however, all places of performance shall be within the contiguous forty-eight US states. FDIC will not pay Contractor for travel in the event travel is required for onboarding activities such as fingerprinting, renewing PIV cards, etc. If the FDIC Program Manager requests that personnel attend in-person meetings or other engagements, any travel time and/or travel costs shall be reimbursable in accordance with the FDIC’s Contract Travel Reimbursement Guidelines.
7.3.1-11 - Deliverables - July 2008 The Contractor must provide all deliverables described in the statement of work.
7.3.1-12 - Period of Performance - July 2023 The Initial Period of Performance begins on to be decided (TBD) and expires on TBD If all option periods are exercised, the final expiration date is TBD.
See clause 7.5.5-01, Option Period.
Section F - Deliveries or Performance PAGE 19 OF 91
Section G - Contract Administration Data
7.3.2-41 - FDIC Personnel - July 2008
(a) FDIC Oversight Manager. The Oversight Manager is the person designated in writing by the Contracting
Officer to represent the FDIC for the purpose of monitoring technical performance and accepting goods or services.
The Oversight Manager is not authorized to issue any instructions or directions which effect any substantive change in this contract, including, but not limited to, an increase or decrease in the price of this contract, or a change in the delivery date(s) or Period of Performance. Specific areas of delegated authority are more particularly defined in the
Oversight Manager Appointment Memorandum. The Oversight Manager is TBD.
(b) FDIC Contracting Officer. The Contracting Officer is the person with FDIC-delegated authority to enter into, modify, administer, and terminate contracts and orders. The Contracting Officer is Jomo Haldane.
7.5.13-01 - Method of Payment - Electronic Fund Transfer (EFT) - March 2014
(a) Payment methods. Payments by the FDIC may be made by check or electronic funds transfer (EFT), or by a third party in lieu of payment directly from the FDIC, at the option of the FDIC. If the FDIC makes payment by EFT, the FDIC may, at its option, also forward the associated payment information by electronic transfer. Any third party payments will be made by the FDIC''s commercial purchase card issuer. In the event Contractor certifies in writing to the payment office that Contractor does not have an account with a financial institution or an authorized payment agent, the FDIC would make payments by other than EFT.
(b) Contractor Payment Requests. If the FDIC elects for third party payments to be made, Contractor shall make payment requests through a charge to the FDIC purchase card with the third party, at the time and for the amount due in accordance with the terms of this contract. Contractor and the third party shall agree that payments due under this contract shall be made upon submittal of payment requests to the third party in accordance with the terms and conditions of an agreement between Contractor, the Contractor''s financial agent (if any), and the third party and its agents (if any). No payment shall be due the Contractor until such agreement is made. Payments made or due by the third party are not subject to the Prompt Payment Act or any implementation thereof in this contract. Documentation of each charge against the FDIC''s purchase card shall be provided to the Contracting
Officer upon request.
Contractor is required, as a condition to any payment, to maintain current information in the System for Award
Management (SAM) database. Any invoice submitted with incorrect EFT information shall be deemed not to be a proper invoice as defined in the Prompt Payment Act clause herein.
Section G - Contract Administration Data PAGE 20 OF 91
7.5.13-06 - Compensation Ceiling - Contract or Task Order - July 2008 Not-to-Exceed
Period of Performance Ceiling Amount
Initial Period: $TBD
Option Period 1: $________________
Option Period 2: $________________
Option Period 3: $________________
Total (if all option periods are exercised): $TBD
In no event will total FDIC compensation to Contractor, including any reimbursed costs and expenses, exceed the sum of ________________ Dollars ($__________) for the entire Period of Performance, including the initial period and all options, if any. Contractor must notify the Contracting Officer, in writing, when Contractor has incurred charges amounting to seventy-five percent (75%) of the ceiling amount for each performance period.
7.5.13-12 - Schedule for Invoicing - July 2008 [CONTRACTING OFFICER MUST SPECIFY THE TERMS IN WHICH THE INVOICE(S) MUST BE SUBMITTED
(e.g., within 10 days after the end of each month.)]
For Labor-Hour or Time-and-Material, Contractor must submit invoices within Ten (10) days after the end of each month. For Firm-Fixed-Price, Contractor must submit invoice upon completion of the service or delivery of the goods.
7.5.13-13 - Contents of Invoice - March 2014 Contractor''s invoices must include the following items in order to be processed for payment:
(a) Contractor name, address and phone number.
(b) Invoice date. (Contractors must date invoices as close as possible to the date of electronic transmission to
FDIC.)
(c) Invoice number.
(d) Contract Number (e.g., Contract Number, Task Order Number, Delivery Order Number, etc.)
(e) Line Item Number(s), as identified in the contract, and the amount invoiced for each Line Item Number.
(f) Allocation of all hours and expenses to Financial Institution Number (FIN) and Asset Name/Number, if applicable.
(g) Description, quantity, unit of measure, unit price, extended price of goods delivered or services performed.
(h) Total invoice amount.
(i) Payment terms (discount for prompt payment terms).
(j) Remittance address.
(k) Billing Point of Contact (e.g., name (where practicable), title, phone number, and mailing address of person to notify if there are questions regarding the invoice).
(l) Shipping information (e.g., shipment number, date of shipment, bill of lading number and weight of shipment.
Shipping charges, if any, must be shown as a separate item on the invoice).
(m) For time and material or labor hour awards, copies of time sheets in support of direct labor charges.
(n) If travel expenses are reimbursable under the award, Contractor must submit travel documentation, receipts and other proof of expenses as required by the FDIC Contractor Travel Reimbursement Guidelines.
(o) If subcontractor expenses are reimbursable under a labor-hour or time-and-material award, Contractor must:
Section G - Contract Administration Data PAGE 21 OF 91
(1) identify subcontractor expenses and costs separate from prime contractor expenses and costs on the invoice it submits to FDIC;
(2) submit with its invoice, as supporting documentation, a copy of its subcontractor''s invoice when seeking reimbursement of subcontractor expenses.
(p) Pass through costs - If expenses or costs are reimbursable under the terms of the award, a description of each shall be provided in the invoice along with the quantity, unit amount, and total amount. Also, if amounts are derived from application of any formula, calculation, percentage, etc., such application must be clearly evident in the supporting documentation provided with the invoice.
(q) The following certification statement, signed by an authorized company representative:
"This is to certify that the services set forth herein [goods described herein] were performed [delivered] during the period stated.
Contractor''s Authorized Representative Date"
(r) Any other information or supporting documentation required by the award.
If an invoice does not contain the above required information; contains errors; or exceeds the total compensation ceiling limit for this award, the invoice will be returned to Contractor and processing of the invoice for payment will be delayed until the deficiency is corrected.
In addition, the FDIC requires Contractors to maintain current information in the System for Award Management
(SAM) database and complete the annual renewal process, in order to receive timely invoice payments. FDIC may reject any invoice received from Contractor where processing of the invoice cannot be completed because
Contractor has failed to maintain its registration, including electronic funds transfer (EFT) information, in the SAM database.
7.5.13-14 - Electronic Invoice Preparation and Submission (CORHQ Business Unit) -
November 2023 Contractor must follow the FDIC’s electronic invoice preparation and submission instructions stated below:
(a) Contractor must email electronic invoices to the FDIC’s Division of Finance/Accounts Payable (DOF/AP) at the following address: DOFAPInvoice@fdic.gov
(b) Contractor must only email their invoices to the above DOF/AP email address and not the Oversight Manager or
Contracting Officer. The FDIC will not accept hand-delivered invoices or invoices sent to any other address (i.e., FDIC street address or any other email addresses).
(c) Contractor must submit the electronic invoice as a single file document, in PDF or Excel (.xlsx) format. If the size of a single PDF/Excel file exceeds 30 MB, the invoice may either be submitted as two PDF/Excel files, with neither
PDF/Excel file exceeding 30 MB, or it may be submitted as a zip file that does not exceed 30 MB. If two PDF/Excel files are used, each email must clearly identify that the invoice has been separated into two PDF/Excel files to accommodate the size limitation. If a zip file is used, the individual files inside the zip file must be kept to a minimum and each must have a descriptive file name, such as "Invoice cover page", "Timesheets", etc.)
Section G - Contract Administration Data PAGE 22 OF 91
If submitting in Excel, the following applies:
(1) The Excel file must be formatted in a manner acceptable to the Contracting Officer. The first tab or worksheet
(“Sheet”) in the Excel workbook must be the invoice itself, and subsequent tabs may be used for supporting information and calculations;
(2) The entire workbook (all tabs) must be formatted for printing in portrait format using letter-size pages, unless the Contracting Officer allows for landscape format and/or legal-size pages for one or more specified tabs;
(3) The entire workbook must allow for searching, sorting, filtering, and other data viewing options by FDIC personnel. All formulas in cells must be visible to FDIC personnel;
(4) Any unit price or hourly rate must be an exact amount as rounded and displayed in the contract schedule or pricing attachment, and all calculations using the unit price or hourly rate must use that exact displayed amount.
The Contractor must not use a unit price or hourly rate on an invoice that differs from the amount displayed in the contract. For example, if a unit price or hourly rate is displayed as $135.15 in the contract, all calculations in the workbook must be based on $135.15 (with no decimals beyond the cent), and must not be based on a pre-rounded amount from elsewhere in the Contractor’s systems; and
(5) Any cell containing a calculation or formula using dollar amounts must be rounded to two decimal places (no decimals beyond the cent). This rounding guideline must be applied to both intermediate and final calculations.
(d) Contractor must not include more than one electronic invoice in the same email. (For example, if a Contractor has four task orders, a separate email with a single invoice must be submitted for each of the four task orders.)
(e) Contractor must name the PDF/Excel file or zip file in the following format (with invoice date shown as year/month/date followed by a space and the invoice number):
Invoice date and invoice number (e.g., 2023-01-31 1067876)
(f) Contractor’s email subject line must include the words, “Contractor Invoice”, followed by a hyphen and the
Contract Number (or Task Order Number, or Delivery Order Number, as applicable), as shown in the example below:
"Contractor Invoice – CORHQ-23-C-0000"
(g) Task Assignments: For contracts and task orders containing provisions for Task Assignments, a separate invoice must be submitted via a separate email for each Task Assignment.
(h) The counting of days for Prompt Payment begins on the date the invoice is received in the inbox of the DOF/AP email address, until 4PM. Invoices received after 4PM will be counted as being received the following FDIC workday.
Section G - Contract Administration Data PAGE 23 OF 91
Section H - Special Contract Requirements
Attachments for this section start after the clauses.
7.1.3-02 - Post-Government Employment Certification (Post-Award) - May 2009 Any former Federal Deposit Insurance Corporation (FDIC) or Resolution Trust Corporation (RTC) employee who the contractor intends to use in performance of work under the contract or its subcontracts must complete and submit the post-government employment certification found at FDIC website https://www.fdic.gov/buying/goods/acquisition/index.html. The certification must be submitted to the Contracting
Officer prior to the former employee commencing work under the contract. The FDIC Legal Division Ethics Unit will review the certification to determine compliance with the post-government employment restrictions. The former employee may be required to provide additional information as to their position and responsibilities while employed at FDIC or RTC and as a post-government employee working on the FDIC contract or subcontract.
7.3.2-43 - Key Personnel - January 2023
(a) The following key personnel are essential to the proper performance of Contractor''s duties under this contract:
Name Title
_TBD____________________________ _______________________
(b) Contractor must make the above named key personnel available for performance under this contract as long as such persons are employed by Contractor or its related entities. All key personnel changes must be authorized in writing by the FDIC Contracting Officer prior to the new key personnel beginning work. Contractor must give a minimum of a 14-day advance written notice to the FDIC Contracting Officer of any proposed substitutions of key personnel. The notice must describe the reason for the proposed change and give the name of the proposed substitute individual with a description of their educational and professional background. A completed background investigation questionnaire is required for any key personnel that will work on-site and have unescorted access to
FDIC offices or facilities, have access to FDIC networks/systems, or have access to sensitive information. The determination of acceptability of proposed substitute personnel is in the sole discretion of the FDIC.
7.4.2-01 - Security and Privacy Compliance for IT Services - September 2024
(a) Security and Privacy Compliance. The Contractor is responsible for Information Technology (IT) security for
Contractor personnel and subcontractor personnel granted access to: sensitive information as defined in FDIC
Directive 1360.09 (and referenced throughout this contract as ‘sensitive’ or ‘FDIC-sensitive information’); the FDIC network; systems connected to the FDIC network; and systems developed, maintained, implemented or operated
Section H - Special Contract Requirements PAGE 24 OF 91 by the Contractor for FDIC. All IT products and services provided by the Contractor that collect, process, maintain, or store FDIC-sensitive information shall comply with all FDIC information security and privacy directives, policies and requirements unless Contractor obtains a written waiver from FDIC Information Security/Privacy staff.
(b) Laws and Standards. All IT products and services provided by the Contractor that collect, process, maintain, or store FDIC-sensitive information must comply with Federal laws and standards addressing information security and privacy. These include but are not limited to:
(1) The Privacy Act of 1974 (5 U.S.C. § 552a) as amended (if incorporated in the contract);
(2) Office of Management and Budget (OMB) Circular A-130, Management of Federal Information Resources
(Transmittal Memorandum No. 4) including Appendices;
(3) E-Government Act of 2002 (P. L. 107-347) including Title II, Section 208 - Privacy Provisions and Title III -
Federal Information Security Modernization Act of 2014 (FISMA), and related OMB guidance; and
(4) National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) and
Special Publications.
(c) FDIC Policy and Guidance. All IT products developed by and IT development services provided by the
Contractor, specifically for FDIC, shall address information security and privacy requirements throughout their design, development, implementation, maintenance, operation, and termination as provided in FDIC system development life cycle policy and guidance. This includes completing or providing the necessary information for the
FDIC to complete privacy impact assessments, security assessments, risk assessments, security plans, contingency plans, and other security and privacy artifacts as required.
(d) Subcontracts. Contractor must ensure this clause is included in all first-tier subcontracts and lower-tier levels of subcontracts to which the conditions and requirements described in this clause would apply.
7.4.2-02 - Off-site Processing and Storing of FDIC Information - August 2018
(a) Control and Protection of FDIC Information. The Contractor shall implement effective, administrative, technical, and physical safeguards to ensure that all FDIC information in its possession or under its control is adequately protected from loss, misuse, and unauthorized access or modification. The creation, collection, use, processing, storing, maintenance, dissemination, disclosure, and disposal of FDIC information shall comply with all applicable federal and state laws and FDIC directives, rules and regulations regarding protection of information. The
Contractor shall not use any FDIC information except to the extent necessary to carry out its obligations under the contract. The Contractor shall not disclose FDIC information to any third party unless disclosure is authorized in the contract, the Contractor obtains the prior written consent of the Contracting Officer, or to the extent expressly required by applicable law, in which case the Contractor shall notify the Contracting Officer at least ten (10) business day before such disclosure, to allow the FDIC to object or concur.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .