The file's text, extracted by GovTribe without its formatting.
Schedule of Deliverables RFP D12PS00041 Attachment 5
RFP Deliverables
| Deliverable |
| Description |
| Due Date |
| Government Approval and Surveillance |
| Implementation and Project Management Plan |
| As requested in RFP Section L within Service Delivery, Management, and Technical Approach |
| Due with RFP Submission |
| Proposal Evaluation |
| Quality Assurance Plan |
| As requested in RFP Section L within Service Delivery, Management, and Technical Approach |
| Due with RFP Submission |
| Proposal Evaluation |
Government’s Operational Readiness and Acceptance Testing Deliverables
| Deliverable |
| Description |
| Due Date |
| Government Approval and Surveillance |
| Test Accounts |
| As described in SOO section 5.1, the Government will require test accounts to validate CECS functionality and perform user acceptance testing |
| 7 days after award |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
| Testing Plan |
| As described in SOO section 5.1, the Government will validate CECS functionality and perform user acceptance testing. Specific testing measures may be requested by the Offeror in order to develop systems architecture, coexistence, and interconnection strategies |
| No later than 14 days after award |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
| Training Plan and Materials |
| As described in the SOO, end user and administrator training plan and materials. |
| No later than 14 days after award |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
| Final Proposed Solutions Architecture |
| As described in SOO section 5.1 |
| 45 days after award |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
| Draft A&A Documentation |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| 45 days after award |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
| Migration Plan, Including proposed coexistence strategies |
| As described in SOO section 5.1 |
| 45 days after contract award |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
| Corrective Action Plan |
| As described in SOO section 5.1 |
| 7 days following issuance of Government’s GORAT report |
| Contracting Officer’s Representative (COR), Government assigned DOI project manager |
IT Security and Privacy Deliverables and Reporting Requirements
Deliverables and Reports:
| Title |
| Description |
| Due Date/Frequency |
| Government Approval and Surveillance |
| Information Assurance (IA) Documentation |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| System Security Plan (SSP) |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Continuous Monitoring Plan (CMP) |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Preliminary Privacy Impact Analysis (PIA - Privacy Threshold Analysis (PTA)) |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Privacy Impact Analysis (PIA) |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Contingency Plan |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Independent Assessor’s Security Assessment Plan and Report (SAP/SAR) |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Plan of Action and Milestones (POA&M) |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Prior to authorization to move to operational readiness status and Quarterly Thereafter |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Vulnerability and Security Configuration Scan Report |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Upon request |
| Contracting Officer’s Representative (COR), Government system owner |
| Continuous Monitoring Report |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Monthly according to plan |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Independent Penetration Testing and Report |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Annually |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Documentation for Audit Requirements |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| 30 calendar days after written request |
| Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO) |
| Training Compliance Report |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Annually |
| Contracting Officer’s Representative (COR), Government system owner |
| Security Incidents |
| As described in, and in accordance with, the CECS IT Security and Privacy Requirements document. |
| Per Incident (immediately) |
| Contracting Officer (CO), Contracting Officer’s Representative (COR), Government system owner, Government Authorizing Official (AO), DOI-CIRC |
| Contractor Employee Report |
| Report of all contractor employees that have access to DOI Data with status of required background checks as specified. |
| Annually on contract award anniversary date and within 3 business days upon written request |
| Contracting Officer’s Representative (COR) |