D17PS00639_Attachment_1_-_SOW.pdf

PDF 81 KB Posted

Attached to
Electronic Legal-Based Case Management System Federal contract opportunity
Solicitation number
D17PS00639
Issued by
Department of the Interior Departmental Offices Interior Business Center

About this file

SOW

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CFTC Case Management System

D17PS00639 ATTACHMENT 1

Statement of Work: Requirements

Case Management System

PART I – STATEMENT OF WORK: REQUIREMENTS

The scope of work is to perform; design, configure, test, data conversion, production deployment, training, and production support of the CFTC Case Management System within the Division of Enforcement, in accordance with CFTC’s life cycle policies and procedures. The COTS legal-based Case Management System (CMS) must be based on a current commercially released software product. The CMS system requirements are contained in Attachment 2, CMS Mandatory Requirements Matrix.

1. Background

The Commodity Futures Trading Commission (CFTC) is a federal government agency with offices located in Washington, DC, Chicago, IL, New York, NY and Kansas City, MO. The CFTC’s mission is to protect commodity market users and the public from fraud, manipulation, and abusive practices related to the sale of commodity and financial futures and options, and to foster open, competitive, and financially sound futures and option markets. The CFTC has five Divisions utilizing the current case management system, including the Division of Enforcement which investigates and prosecutes alleged violations of the Commodity Exchange Act (CEA or Act) and Commission regulations.

Advances in information technology present the federal government with opportunities to enhance mission capabilities and improve efficiency. An electronic legal-based Case Management System (CMS) provides essential support to CFTC enforcement investigation activities, including litigation, and also supports many other CFTC requirements. CFTC currently uses Practice Manager by Automon software to support these activities. The CMS is used by CFTC as the official method of documenting matter activity. This documentation includes the date the matter was received, the names of parties involved in the matter, critical activities and dates, corresponding documents, time spent on the matter, as well as other pieces of relevant data such as the settlement figures, restitution and civil monetary penalties. The CMS is also used to generate statistical data on CFTC activities. This data is used in workforce analysis, press releases, and to respond to requests from Congress and the public. Finally, the CMS is used to preserve and produce documents in litigation.

Practice Manager is deployed in the CFTC’s Division of Enforcement (DOE), the Office of the General Counsel (OGC), the Office of the Secretariat (Secretariat), the Office of Proceedings (Proceedings) and the Division of Market Oversight (DMO) with use currently being considered for additional divisions. Any new software being proposed as a replacement for Practice Manager shall be an enterprise solution that is able to meet the diverse needs of the multiple divisions within CFTC.

2. General Scope

CFTC is seeking to replace its existing CMS utilizing state of the art, commercial off the shelf (COTS) legal-based CMS software. The software must meet all of the requirements listed in Attachment 2. These requirements must be available as out-of-the-box features within the COTS product and not require custom development to meet any of the requirements.

All services provided under this contract shall be provided by the contractor, including software implementation, training, licenses and maintenance, and technical support. If the successful vendor is a reseller, the vendor shall ensure that the software manufacturer complies with the performance requirements of this contract. In order to avoid confusion, this document refers to “contractor” and “software manufacturer” in the event they are different parties.

The Contractor shall provide software licenses and annual maintenance of the system.

Additionally, the Contractor shall provide technical support, as required, through its annual maintenance agreement. The contractor shall ensure that the software manufacturer provides a COTS software-only based CMS that will allow access to the application and related Information.

The Contractor shall perform supervised implementation of one Division (the Division of Enforcement) where the contractor shall install, design, configure, and implement the software to meet the needs of that Division. As part of the implementation, the contractor shall perform data conversion in an effort to recreate, in as much as possible, the existing reports, templates, screens, and portal integration for the Division of Enforcement that is in the current CMS system (see Section 2, Division of Enforcement (DOE)). CFTC staff will shadow the contractor’s team during this process. The intent is for the Contractor to demonstrate the implementation process so that the CFTC is in a position to design, configure and implement the other four CFTC divisions (see Section 2, Divisions to be Designed and Implemented by CFTC Trained Staff).

The contractor shall create and document the implementation approach, processes (including data migration), and provide all required tools for CFTC staff to roll out the solution to the remaining CFTC divisions.

The Contractor shall provide annual maintenance and help desk support for their solution. The Contractor shall ensure that the proposed solution will maintain compatibility with commercial off-the-shelf software releases such as Windows and SQL Server.

3. Current Implementation

Division of Enforcement is provided below.

Division of Enforcement (DOE)

Number of Users: 225 Reports: 75 of low to medium complexity with most written in ad-hoc reporting module, some developed in SQL Reporting Services (SSRS) and one custom developed module.

Document Assembly Templates: 100

Case Management modules currently used: Matters, Entities, Document Assembly, Document Management, eMail Integration, Calendar, Notes, Reporting and Time Slips

Matter and Related Information Screens

3 screens tracking a variety of information including phase status (e.g. leads through various phases culminating in settlement or litigation), details of sanctions, status of parallel work with other domestic/international agencies, etc.

Specialized

1. Integration using Web API that accepts XML submissions from external portal, using a service account to create matters and entities. Function also uploads documents and completes custom fields.

Notes:

Division of Enforcement matters progress from leads through various phases culminating in settlement or litigation. A matter can be closed at any stage in the process. Data is captured for each phase (e.g. lead, investigation) including date phase start and date phase closed. All internally developed work products (e.g. subpoenas, pleadings, briefs, emails) are associated with a specific matter. A document can be associated with multiple matters. All externally produced discovery documents are maintained in a separate system outside the case management system.

At a matter level, the fields the CFTC currently tracks include, but are not limited to, matter name, three levels of categorization, CFTC-created matter number, court-assigned docket number, date matter opened, date matter closed, jurisdiction, source of matter (e.g. other federal agency, whistleblower), allegations of wrongdoing and matter disposition. Additional fields are tracked for each matter phase including date phase opened and date phase closed.

For each entity associated with a matter, the fields the CFTC currently tracks include but are not limited to, name, address, phone number, type and role.

For calendar events (e.g. tasks, appointments, critical dates, court events, phone calls, etc.)

associated with a matter, the fields the CFTC currently tracks include, but are not limited to, date, time and responsible entity.

In the time entry module, the fields the CFTC currently tracks include but are not limited to matter, date, transaction (e.g. activity code), and duration.

For each document associated with a matter, the fields the CFTC currently tracks include but are not limited to name, date, author, document category, document type, and file path.

Objectives

CFTC anticipates awarding one (1) contract as a result of solicitation.

4. Legal-Based CMS COTS Software Functional Requirements

Refer to Appendix A for the functional requirements.

5. Software Licenses

The Contractor shall provide CMS licenses for end users and system administrators, as listed below:

End-Users (350 users) and, Systems Administrators (10 users).

The proposed licenses must include options to increase the number of users beyond the base year. CFTC expects a 5–10% increase in the number of users per year. While it is unlikely that all users will be in the system at the same time, the software license must be flexible enough to allow 200 concurrent users to access the software.

Software proposed under this contract shall be the most current version that is available, and include support for the current version and, at a minimum, the previous major release. The CFTC has a strong preference for a perpetual license although other license terms and conditions may be considered.

The Contractor shall deliver all software media and product documentation no later than 30 days after award of the contract. The product documentation shall be provided in searchable electronic formats.

6. Software Implementation

The contractor shall install the software in all identified CFTC technical environments, and perform supervised implementation of one Division (the Division of Enforcement) including design, configuration, and implementation of the software to meet the needs of that Division. As part of the implementation, the contractor shall perform data conversion to migrate the existing data from the existing legacy Practice Manager implementation to the new case management solution. During this process, CFTC staff will shadow the contractor’s team. The intent is for the Contractor to demonstrate the implementation process so that the CFTC is in a position to design, configure and implement the other four CFTC divisions.

Implementation Plan (IP). The Contractor shall provide an Implementation plan that describes the steps required to implement the legal-based case management system (from requirements clarification through training) and includes dates (elapsed time from date of award) for major milestones.

Project Schedule. The Contractor shall provide a project schedule which will outline the milestones, deliverables, interdependencies, staff responsible for tasks, and start to finish dates.

Overall Transition Strategy Plan. The Contractor shall provide a final Overall Transition Strategy Plan that describes their transition approach through production roll-out. The contractor shall complete the Transition Plan for the proposed solution within 3 months of contract award. The transition plan will include the creation of a project schedule that will include and outline milestones and the related tasks that will be required to reach the milestones.

The Contractor shall ensure timely migration while minimizing the impact to the CFTC user community. The Contractor shall use integration techniques to maximize interoperability and integration between the solution and legacy systems. The transition strategy shall minimize management, reconfiguration, and scrap/rework. The plan shall include the contractor’s level of experience in developing and supporting interfaces to migrate data from existing legacy systems. The final overall transition strategy plan shall be submitted within 3 months of contract award. The contractor shall update the draft overall transition strategy plan (submitted with the proposal) after receipt of comments from the COR in preparation of the final version.

6.1. Software Installation

The contractor shall install and configure the COTS legal-based Case Management software platform, on premise, in CFTC’s technical environments. The CMS shall primarily support CFTC’s Headquarters in DC, however must also support users in the CFTC Regional offices in Chicago, IL; New York, NY; and Kansas City, MO. The contractor shall complete this task within 3 month of contract award.

The installed technical environments will include:

Production* Test (configured to match Production) Development

*Production license must cover the failover environment which runs in an active-passive configuration. The Production environment includes automatic replication to the alternate computing location.

6.2. Supervised Implementation for DOE

Proposed Implementation Requirements Division of Enforcement (DOE) Number of Users: 225

Reports:

The contractor shall create (5) DOE reports using their built-in reporting module.

See Attachment 4 - Report Definitions and Samples

Document Assembly Templates:

The contractor shall create (5) document assembly templates.

See Attachment 5 - Document Assembly Samples

Case Management Required Functionality Matters, Entities, Document Assembly, Document Management, eMail Integration, Calendar, Notes, Reporting and Timekeeping.

Configuration of Current Application – In addition to using the above listed modules, there are specific features and data that will need to be captured, tracking a variety of information including phase status (e.g. leads through various phases culminating in settlement or litigation), details of sanctions, status of parallel work with other domestic/international agencies, etc.

See Attachment 8 - Data Elements There is also a database trigger that takes the matter number and prepends a 5 digit number code to a field in the data base and populates the date of the change in another date field. Both of these fields are read only.

Specialized Integration using Web API that accepts XML submissions from external portal, using a service account to create matters and entities, function also uploads documents and completes custom fields.

See Attachment 7 - Capturing Portal TCR and WB Submissions

The contractor shall perform supervised implementation of one Division (DOE) where the contractor will design, configure, and implement the software to meet the needs of one of the CFTC Divisions. CFTC staff will shadow the contractor’s team during this process. The intent is for the Contractor to demonstrate the implementation process so that the CFTC is in a position to design, configure, and implement the other divisions.

The CFTC will provide an IT Specialist for the purpose of acting as a technical expert regarding CFTC’s systems during installation of the COTS legal-based Case Management system CMS.

The CFTC will provide business process experts to work with the software manufacturer during the requirements gathering and implementation phases of the rollout.

The contractor shall provide a Requirements Traceability Matrix that tracks each requirement through the testing, showing that all software requirements are implemented and verified.

The testing performed by the contractor and implementation team shall include all pre/post-testing of the system, including maintaining quality control and performing Pilot Group and user acceptance testing. The CFTC will use the User Acceptance Testing as part of its acceptance process.

During implementation, and at the discretion of the Contracting Officer’s Representative (COR), the contractor shall participate in project progress meetings with the COR. The frequency of the meetings will vary, and may be daily at times. The purpose of the meetings will be to discuss the project status, as well as to identify and discuss configuration/integration issues, and to coordinate schedules.

Acceptance of implementation will be made upon installation and configuration of the software at the CFTC and successful completion of an acceptance test period. CFTC anticipates that this testing period will last 14 calendar days.

Successful completion means that the software operates in the CFTC production environment with access by all concurrent users for 14 consecutive days, and otherwise performs in accordance with all contract requirements and as described in the Contractor’s proposal.

Acceptance by the CFTC shall be in writing signed by the COR. In the event the software does not successfully complete the first acceptance test, the Contractor shall have up to 14 days to make appropriate corrections and commence a second 14 calendar day acceptance test.

Note: Maintenance and technical support shall not commence prior to implementation and acceptance.

7. Data Migration

As part of the implementation of DOE, existing data shall be migrated from the existing legacy Practice Manager implementation to the new case management solution. The contractor shall provide a fully- documented data dictionary of the software. The contractor shall create a data conversion plan which shall include a timeline of the schedule, the overall approach, assumptions and processes to extract and load data that will be used in the data conversion. The plan shall also include the tools needed to execute the conversion. The data conversion specification shall include a cross reference of the source data tables and fields as well as the target data tables and fields any transformation rules and notes. The specification shall be outlined in a table structure similar to the following:

Source Data Table Source Data Field Target Data Table Target Data Field Notes

Per CFTC policy, no data shall leave the premises; all data migration activities must be performed on premise.

The contractor shall complete a test data migration in the development environment within 4 months of contract award. Prior to going live with the system a final database conversion will also be conducted.

The migration of legacy case management data includes the data sources listed below (All sources are by case). This summary list of technical features outlined below is intended to inform prospective vendors of the depth of migration required. While the features listed below may not be all-inclusive, critical data stored in MS SQL data tables for this legacy system must be accessible for read, write and update capabilities in the new product. There is approximately 23 GB of data in the current DOE database, that will need to be converted to the new system by the contractor .

A. All matter/case information B. Calendar data/events, tasks, docketing C. Document Repository/Management D. Case Management Email Repository

E. Timekeeping data F. Entity Information G. Case Notes

The contractor shall migrate CFTC’s existing data in its current state with no loss in the quality of that data. The current data resides in a SQL database. All data pertinent from the tables within the SQL database will need to be migrated into the new system. All work related to the migration shall be done on-site during normal business hours. Any programs related to migration not already in the CFTC environment must first be approved by CFTC’s Change Control Board. Disruption to the business unit shall be minimized during normal business hours. The data must not change during migration. For example, when migrating a .msg file, the MD5 hash must be identical to the original prior to migration. The migration plan shall be developed and approved by the CFTC prior to commencing the migration which includes data mapping, tools used, quality assurance, and workflow. The Contractor shall prepare and deliver a Data Migration Plan (all required processing and quality assurance steps from data mapping through quality assurance).

Conversion Testing Document - The Contractor shall provide a testing document that details the test cases and summarizes the test results. The Testing Document works in conjunction with the Requirements Traceability Matrix assuring that all requirements have been validated.

8. Training

The contractor shall provide train-the-trainer training for up to 10 CFTC staff. The training will be provided to staff located in Washington, DC, New York, Kansas City, and Chicago. This training shall cover at a minimum:

Navigation within the application Creating matters Creating entities Assigning entities to matters Time entry Creating documents Creating emails within application Associating document or emails to a matter Creating calendar items Creating and saving an ad-hoc report Creating and saving queries Output reports or queries to MS-Excel or other formats Access and security controls Using metadata fields to track information about individual records

The Contractor shall also train up to ten (10) system administrators (semi-technical staff, not programmers or developers) on how to configure, operate and maintain the CMS and shall cover at a minimum:

Configuration of the application Creating custom screens, Database structures (e.g. overview of fields and tables, primary and foreign key relationships) Creating document templates Configuring and managing the workflow engine Advanced reporting capabilities Implementing appropriate access and other security controls, and user restrictions Implementing and using metadata fields to track information about individual records

(e.g., record category, sensitivity level and record retention period)

The training shall commence post user acceptance testing and the contractor shall complete this task within 9 months of contract award.

The Contractor shall provide relevant system training documentation for all trained individuals.

The Contractor shall provide a Training Plan that includes the competencies to be obtained, how the training will be conducted, and the schedule of the classes. The Contractor shall provide a User Guide which describes to the end-user how to use the software.

9. Maintenance Support

The Contractor shall provide annual maintenance support for the CMS. The maintenance support shall include, at a minimum, bug fixes and software updates as well as telephone support for issue remediation.

10. Release/Upgrade Strategy

The contractor shall maintain and sustain a qualified solution, including maintaining integration and interoperability with the commercial off-the shelf (COTS) products and version upgrades that comprise the CMS. The contractor shall provide version upgrades that minimize changes to configurations and minimize the impact to users of the solution. The Contractor shall prepare and deliver a Version Description Document for each major release. The CMS shall support installation and operation on Microsoft Window Server 2012 and Microsoft SQL Server 2014 and later versions. The CMS shall support Microsoft Office 2010 and later versions. The CMS shall support Windows 7 (and later versions) and Internet Explorer 11 (and later versions) for any client interfaces.

The CMS shall be capable of being upgraded with minimal technical complexity. Application upgrades shall not require the CFTC to archive and restore managed data, procure additional hardware, make significant configuration changes, or develop custom code. Application upgrades shall be performed during off peak hours and shall minimize negative impacts for system availability to end users. The contractor shall identify, manage, and mitigate potential risks and key challenge areas for any upgrade efforts.

The contractor shall develop, manage and mitigate potential risks and key challenge areas related to synchronization of version upgrades for increment configurations.

11. Help Desk Support

The contractor shall provide Tier II Help Desk support during deployment and sustainment.

Software problems will be reported to the vendor by a small number of CFTC staff such as CMS System Administrators or designated CMS staff (20 at the most). Tier I support will be provided by CFTC staff. Tier I support includes overall end-user support or troubleshooting a problem that involves the CFTC’s infrastructure, whereas Tier II involves a problem or error directly related to the software itself. Help desk support will be provided Monday through Friday from 8AM to

6PM EST.

The contractor shall provide Operations and Maintenance Procedures which includes information required to support and maintain the system after its deployment in the CFTC production environment as well as help desk support information.

12. Senior Software Support Engineer (Surge Support)

The contractor shall provide surge support for the CMS based on mission needs. The contractor shall be given a minimum five (5) day notice for the need of surge support. The contractor shall, as requested by CFTC, provide maintenance and technical support on the CMS. Surge shall be billed hourly in accordance with the contracted labor rate and shall not exceed the authorized amount of hours.

Any surge services to be furnished under this contract shall be ordered by issuance of written direction by the Contracting Officer. The Contracting Officer direction shall be for a not to exceed amount based upon the surge submission (estimated level of effort) of the contractor. The contractor shall expend no effort on a surge without written direction of the Contracting Officer.

13. Documentation Requirements

The required documents are listed below.

Architecture and Design Document - ensures that the architecture and design of the system is in compliance with the CFTC’s architecture principles and development best practices.

Project Schedule - The Contractor shall provide a project schedule which will outline the milestones, deliverables, interdependencies, staff responsible for tasks, and start to finish dates.

Requirements Traceability Matrix – Provides traceability of the requirements from the statement of work all the way through the design, development and implementation process. Ensures all customer requirements have been included in the solution. Links requirements throughout the validation process. It associates the requirements with the test cases and test results that demonstrate how these requirements are satisfied.

Implementation Plan - describes the steps the offeror will take to install the proposed legal-based case management system (i.e., testing, production installation and configuration of the system) and includes dates (elapsed time from date of award) for major milestones.

Transition Strategy Plan - describes how their proposed roll out approach will ensure a timely migration while minimizing the impact to the CFTC user community.

Data Migration Plan - describes the strategy, preparation, and specifications for converting data from the legacy system to the vendor’s system. This plan describes the overall approach, assumptions, processes that will be used in the data conversion and quality assurance.

Training Plan - the Training Plan identifies the competencies to be obtained, how the training will be conducted, and the schedule of the classes.

Operations and Maintenance Procedures - provides information required to support and maintain the system after its deployment in the CFTC production environment.

Test Document - the Test document defines an effective approach for testing, details the test cases, and summarizes the test results.

User Guide(s) – describes to the end-user how to use the software.

14. CFTC Technical Environment

The contractor’s CMS solution must be supported for installation and configuration within CFTC’s technical environment. The software shall be deployed and updated from a centralized on-premises server. The CMS must meet all specified technical architecture requirements. The contractor must provide an Architecture and Design Document to ensure that the architecture and design of the system is in compliance with the CFTC’s architecture.

15. Server Infrastructure

The CMS software must be supported for installation in a virtualized environment:

Operating System: Microsoft Windows Server 2012 R2 Virtualization: VMWare version 5.5 Database: Microsoft SQL Server 2014

16. User Workstations

The CMS must be accessible from workstations with the following configuration:

Operating System: Microsoft Windows 7, 64 bit Web Browser: Internet Explorer 11 Office Applications: Microsoft Office 2010, Adobe Reader 11

The contractor’s CMS solution must be able to be deployed in both a virtual and traditional desktop environment and follow the United States Government Configuration Baseline (USGCB). The virtual desktop application currently being tested at the CFTC is VMWare’s Horizon View. The application shall support a non-persistent environment and shall work with non-local administrative permissions settings with UAC (User Access Controls) enabled. It shall be Section 508 compliant and if working with Microsoft Office, shall be Microsoft Office 2010 and 2013 compliant. The pilot program is currently testing the virtual desktop environment and will be pushed to all of CFTC by FY 2016.

17. Integration - CMS Application Programming Interface (API) The CMS shall provide a fully documented Application Programming Interface (API) using a non-proprietary communication language that exposes all essential functions and works with Microsoft technologies such as .NET.

18. Security

The CMS shall fully comply with CFTC’s existing Windows based Directory Services (Lightweight Directory Access Protocol, Active Directory) to support user access. The CMS shall also comply with other government standards including OMB Circular A-130, Federal Information Security Management Act (FISMA), NIST Special Publication 800 Series, including NIST SP 800-53 rev. 4, and the Privacy Act of 1974 as amended.

The Contractor shall certify that the system is fully functional and operates correctly as intended on systems using the United States Government Configuration Baseline (USGCB) for Windows

7. For the Windows 7 settings, see: http://enterprise.microsoft.com/en-us/industries/government/federal/government-mandates/.

The installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved Federal Desktop Core Configuration (FDCC). The information technology should also use the Windows Installer Service for installation to the default “program files” directory and should be able to install and uninstall.

Certification that the proposed product has been evaluated against security standards such as Common Criteria is preferred. If applicable, the contractor should submit copies of applicable documentation showing certification.

The CFTC reserves the right to test all delivered information technology to verify the Contractor’s certification required above. In the event the information technology does not meet the requirements, the Contractor shall correct the defect at no cost to the Government.

19. Accessibility

The CMS, all material rendered by it, and all documentation shall be in full compliance with the applicable requirements of Section 508 of the Rehabilitation Act of 1973, as amended.

20. Technical Support Requirement

The contractor shall furnish the software licenses and provide all required implementation, documentation, training, and software maintenance and technical support for the life of the contract.

21. Key Personnel

The contractor shall provide qualified staff to implement the new COTS legal-based CMS including two key personnel; a Program Manager and a Senior Software Support Engineer.

22. Program Manager (PM)

Preferred/General Experience: The PM should have at least six (6) years of management experience with demonstrated experience and skill in deploying a legal-based case management system. A Bachelor’s Degree in management or equivalent experience (four (4) years).

Functional Responsibility: The PM shall coordinate the assignment of tasks for their team.

Additionally, the PM will be responsible for the management of the schedule, staffing, and reporting. The PM shall coordinate and participate in the planning, requirements analysis, and project deliverables. The contractor shall track performance of the requirements to ensure that requirements are met/implemented.

23. Senior Software Support Engineer

Preferred/General Experience: The implementation, configuration, and customization of a legal-based CMS necessitates in-depth knowledge and expertise. The Senior Software Support Engineer must possess substantial, hands-on experience of implementing legal-based case management systems. The Senior Software Support Engineer should have at least five (5) years of relevant experience implementing legal-based case management systems, preferably with the proposed software. College degree in information technology or equivalent experience (four (4) years).

Functional Responsibilities: The Senior Software Support Engineer will be responsible for the requirements analysis, installation, implementation, configuration, customization, and testing of the CMS in both the development and production environments. The Senior Software Support Engineer shall be the primary technical point of contact for applicable tasks and share in the responsibility in managing the systems team.

24. Option for Increased Quantity - Concurrent Users

As ordered by the Contracting Officer during the term of this contract, the Contracting Officer may exercise an option to add concurrent users for the software product initially licensed under this contract.

25. IT Systems and Support Services Contract Requirements

General All contractors and contractor personnel shall be subject to the same Federal laws, regulations, standards and CFTC policies as CFTC, and CFTC personnel, regarding information and information systems security. Contractors must follow policies and procedures outlined in CFTC IT Security Program to ensure appropriate security controls are in place.

Access to CFTC Information and CFTC Information Systems A contractor shall request logical (technical) and/or physical access to CFTC information and CFTC information systems for employees, subcontractors, and affiliates only to the extent necessary: (1) to perform the services specified in the contract, (2) to perform necessary maintenance functions for electronic storage or transmission media necessary for performance of the contract, and (3) individuals must satisfy the same conditions, requirements and restrictions comparable to CFTC employees in order to access the same type of CFTC information.

All contractors and subcontractors working with CFTC information are subject to the same investigative requirements as those of regular CFTC appointees or employees who have access to the same types of information. Contractors are responsible for screening their employees.

Furthermore, contract personnel who require access to national security programs must have a valid security clearance. National Industrial Security Program (NISP) was established by Executive Order 12829 to ensure that cleared U.S. defense industry safeguards the classified information in their possession while performing work on contracts, programs, bids, or research and development efforts. Defense Security Service (DSS) administers the NISP on behalf of the Department of Defense and 23 other federal agencies within the Executive Branch. CFTC will verify clearance through DSS.

CFTC Information Custodial Requirements Information made available to the contractor by CFTC for the performance or administration of this contract or information developed by the contractor in performance or administration of the contract shall be used only for those purposes and shall not be used in any other way without the prior written agreement of the Contracting Officer.

CFTC information shall not be co-mingled with any other data on the contractor’s/subcontractor’s information systems/media storage systems in order to ensure CFTC requirements related to data protection and media sanitization can be met. CFTC also reserves the right to conduct IT resource inspections to ensure data separation and on-site inspection of information destruction/media sanitization or disposal procedures to ensure they are in compliance with CFTC policy requirements.

Prior to termination or completion of this contract, the contractor shall not destroy information received from CFTC or gathered or created by the contractor in the course of performing this contract without prior written approval by the CFTC Contracting Officer. Any data destruction done on behalf of CFTC by a contractor must be done in accordance with National Archives and Records Administration (NARA) requirements.

The contractor shall receive, gather, store, back-up, maintain, use, disclose and dispose of CFTC information only in compliance with the terms of the contract and applicable Federal and CFTC information confidentiality and security laws, regulations and policies. Applicable Federal information security regulations include all Federal Information Processing Standards (FIPS) and Special Publications (SP) issued by the National Institute of Standards and Technology (NIST).

If Federal or CFTC information confidentiality and security laws, regulations and policies become applicable to the CFTC information or information systems after execution of this contract, the parties agree to negotiate in good faith to implement the information confidentiality and security laws, regulations and policies, including FIPS or SP, in the contract.

Contractors collecting, storing, or disseminating personally identifiable information (PII) data must conform to all pertinent regulations, laws, and CFTC directives related to privacy.

The contractor shall not make copies of CFTC information except as necessary to perform the terms of the agreement or to preserve electronic information stored on contractor electronic storage media for restoration in case any electronic equipment or data used by the contractor needs to be restored to an operating state.

If CFTC determines that the contractor has violated any of the information confidentiality, privacy, and security provisions of the contract, it shall be sufficient grounds for CFTC to terminate the contract for default or terminate for cause under Federal Acquisition Regulation (“FAR”) part 12.

The contractor shall store, transport or transmit CFTC sensitive information in an encrypted form, using a CFTC-approved encryption application that meets the requirements of NIST’s FIPS 140-2 standard.

Information System Design and Development Information systems that are designed or developed for or on behalf of CFTC at non-CFTC facilities shall comply with all CFTC policies developed in accordance with Federal Information Security Management Act (FISMA), NIST, and related CFTC security and privacy control requirements for Federal information systems. This includes information and system security categorization level designations in accordance with FIPS 199 and FIPS 200 with implementation of all baseline security controls commensurate with the FIPS 199 system security categorization.

The security controls must be designed, developed, approved by CFTC, and implemented in accordance with the provisions of CFTC security system development life cycle as outlined in NIST Special Publication 800-37.

The contractor agrees to:

(1) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies:

i. The systems of records; and

ii. The design, development, or operation work that the contractor is to perform;

(2) Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and,

(3) Include this Privacy Act clause, including this subparagraph in all subcontracts awarded under this contract which requires the design, development, or operation of such a system of records.

Information System Hosting, Operation, Maintenance or Use For information systems that are hosted, operated, maintained, or used on behalf of CFTC at non-CFTC facilities, contractors are fully responsible and accountable for ensuring compliance with all Privacy Act, FISMA, NIST, FIPS, and CFTC security and privacy directives and handbooks. The contractor security control procedures must be identical, not equivalent, to those procedures used to secure CFTC systems. A privacy impact assessment (PIA) must also be provided to the COR and approved by CFTC’s Chief Privacy Officer prior to operational approval. All external Internet connections involving CFTC information must be reviewed and approved by CFTC prior to implementation.

Adequate security controls for collecting, processing, transmitting, and storing of personally identifiable information, as determined by the CFTC’s Chief Privacy Officer, must be in place, tested, and approved by CFTC prior to hosting, operation, maintenance, or use of the information system, or systems by or on behalf of CFTC. These security controls need to be stated within the PIA and supported by a risk assessment. If these controls are determined not to be in place, or inadequate, a Plan of Action and Milestones (POA&M) must be submitted and approved prior to the collection of PII.

Outsourcing (contractor facility/contractor equipment/contractor staff) of systems or network operations, telecommunications services, or other managed services requires certification and accreditation (C&A) of the contractor’s systems in accordance with NIST Special Publication 800-37 and privacy impact assessment of the contractor’s systems prior to operation of the systems. Government-owned (government facility/government equipment) contractor operated systems, third party or business partner networks require a system interconnection agreement and a memorandum of understanding (MOU) which detail what data types will be shared, who will have access, and the appropriate level of security controls for all systems connected to CFTC networks.

The contractor shall adhere to all FISMA, FIPS, and NIST standards related to the annual FISMA security controls assessment and review and update the PIA. Any deficiencies noted during this assessment must be provided to the CFTC Contracting Officer and the Information

Security Officer (ISO) for entry into CFTC’s Plan of Action and Milestone (POA&M) management process. The contractor shall use CFTC’s POA&M process to document planned remedial actions to address any deficiencies in information security policies, procedures, and practices, and the completion of those activities. Security deficiencies must be corrected within the timeframes approved by the Government. Contractor procedures will be subject to periodic, unannounced assessments by CFTC officials. The physical security aspects associated with contractor activities will also be subject to such assessments. As updates to the system occur, an updated PIA must be submitted to the Chief Privacy Officer through the COR for approval.

All electronic storage media used on non-CFTC leased or owned IT equipment that is used to store, process, or access CFTC sensitive information shall have all CFTC sensitive information removed, cleared, sanitized, or destroyed in accordance with CFTC policies and procedures upon: (1) completion or termination of the contract or (2) disposal or return of the IT equipment by the contractor or any person acting on behalf of the contractor, whichever is earlier.

Security Incident Investigation The term “security incident” means an event that has, or could have, resulted in unauthorized access to, loss or damage to CFTC assets, or sensitive information, or an action that breaches CFTC security procedures. The contractor shall immediately notify the COR and simultaneously, the designated ISO/Privacy Officer for the contract of any known or suspected security/privacy incidents, or any unauthorized disclosure of sensitive information, including that contained in systems(s) to which the contractor has access.

To the extent known by the contractor, the contractor’s notice to CFTC will identify the information involved, the circumstances surrounding the incident (including to whom, how, when, and where the CFTC information/assets were placed at risk or compromised), and any other information that the contractor considers relevant.

To the extent practicable, the contractor shall mitigate any harmful effects on individuals whose CFTC information was accessed or disclosed in a security incident. In the event of a data breach with respect to any CFTC sensitive information processed or maintained by the contractor or subcontractor under the contract, the contractor is responsible for liquidated damages to be paid to CFTC.

Security Controls Compliance Testing On a periodic basis, CFTC reserves the right to evaluate any or all of the security controls and privacy practices implemented by the contractor under the clauses contained within the contract.

The Government may conduct a security control assessment on shorter notice (to include unannounced assessments) determined by CFTC in the event of a security incident or at any other time.

Training All contractor employees and subcontractor employees requiring access to CFTC information and CFTC information systems shall complete the following before being granted access to CFTC networks:

(1) Sign and acknowledge understanding of and responsibilities for compliance with the CFTC

Rules of Behavior relating to access to CFTC information and information systems;

(2) Successfully complete CFTC Cyber Security Awareness Training (CSAT) and annual refresher training as required;

(3) Successfully complete CFTC General Privacy training and annual refresher training as required; and

(4) Successfully complete any additional cyber security or privacy training, as required for CFTC personnel with equivalent information system access – e.g., any role-based information security training required in accordance with NIST Special Publication 800-16, Information Technology Security Training Requirement.

The contractor shall provide to the Contracting Officer a copy of the training certificates for each applicable employee within 1 week of the initiation of the contract and annually thereafter, as required.

26. Deliverables

The contractor shall prepare deliverables using Microsoft Office Suite 2010, or compatible formats, as approved by the COR. The COR will review all deliverables and provide comments and/or approvals/disapprovals in a timely manner so as not to adversely impact the project schedule.

The Contractor shall produce the following deliverables. The CFTC requires a review period of at least five business days in order to accept deliverables. The CFTC may request bi-weekly interim reviews of deliverables to ensure deliverables are on schedule to meet the intended need.

All uses of “days” in the following table refer to business days.

Section Deliverables Due Date

14 Architecture and Design Document No later than 5 business days after task order award

13 Release Notes Within 30 days of task order award

6 Implementation Plan Within 2 months of task order award

6.2 Requirements Traceability Matrix Within a month of task order award

6 Project Schedule Within a month of task order award

6 Transition Strategy Plan Within 2 months of task order award

7 Data Migration Plan Within 4 months of task order award

8 Training Plan Within 6 months of task order award

11 Operations and Maintenance Procedures Within 8 months of task order award

8 Test Document Within 8 months of task order award

9 User Guide Within 8 months of task order award

27. Attachments

Refer to the following applicable documents:

- Attachment 2: CMS Mandatory Requirements Matrix

- Attachment 3: Demonstration Guidelines

- Attachment 4: Report Definitions and Samples

- Attachment 5: Document Assembly Samples

- Attachment 6: Pricing Template

- Attachment 7: Capturing Portal TCR and WB Submissions

- Attachment 8: Data Elements

File details come from the government source that posted it. Updated .