Attachement_J-1_Statment_of_Work.pdf

PDF 2 MB Posted

Attached to
DHS Enterprise Financial Management Systems (EFiMS) Federal contract opportunity
Solicitation number
DHS-70RTAC18RFI000004
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

Statement of Work

View the file

Other files for this federal contract opportunity

Other files attached to DHS Enterprise Financial Management Systems (EFiMS), newest first.
File Type Posted
SF 30 Page 2_11-20-19.pdf PDF
EFiM S RFP Updated - 11-20-19.pdf PDF
Attachment J-2 EFiMS Pricing Structure 11-20-19.xlsx XLSX spreadsheet
SF30 Page 1 _11-20- 19.pdf PDF
Attachment J-1 EFiMS Statement of Work 11-18-19.pdf PDF
S F 30- Page 1 11-18-19.pdf PDF
Responses to company questions 11-18-19.pdf PDF
Attachement J-4 Past Performance Information Form 11-18-19.docx DOCX document
Attachment J-5- Ordering_Guide 11-18-19.pdf PDF
Attachment J-3 Functional Requirements 11-18-19.xls XLS spreadsheet
SF 1449_11-18-19.pdf PDF
SF 30-Page 2_11-18-19.pdf PDF
EFiMS Request for Proposal 11-18-19.pdf PDF
EFiMS_Responses_to_Vendor_Questions_10-30-19.xls XLS spreadsheet
Attachment_J-2_EFiMS_Pricing_Structure_10-30-19.xlsx XLSX spreadsheet
Attachment_J-5-_Ordering_Guide.pdf PDF
SF_1449_FINAL.pdf PDF
Attachment_J-1_EFiMS_Statement_of_Work_10-30-19.pdf PDF
Attachment_J-3_Requirements_10-30-19.xls XLS spreadsheet
Attachement_J-4_Past_Performance_Information_Form.pdf PDF
EFiMS_Request_for_Proposal.pdf PDF
Attachement_J-2__Pricing_Structure.xlsx XLSX spreadsheet
Attachment_J-5_Ordering_Guide.pdf PDF
Request_for_Proposal.pdf PDF
Attachment_J-3_Requirements.xlsx XLSX spreadsheet
Attachement_J-4_Past_Performance_Information_Form.pdf PDF
Attachment_J-1-_Statement_of_Work.pdf PDF
Attachment_J-5-_Ordering_Guide.pdf PDF
Attachment_J-2-_EFiMS_Pricing_Structure_9-5-19.xlsx XLSX spreadsheet
Attachement_J-4_Past_Performance_Information_Form.pdf PDF
EFiMS_Draft_RFP_09-05-2019.pdf PDF
Attachment_J-3-EFiMS_Requirements.xlsx XLSX spreadsheet
EFiMS_Industry_Day_Presentation.pdf PDF
EFiMS_Vendor_Question_Responses_-_FBO_Posting_-_7.2.19-v2.pdf PDF
EFiMS_Software_SOW_for_FBO_Posting_7-2-19.pdf PDF
DRAFT_EFiMS_SOW.pdf PDF
DRAFT_EFiMS_Pricing_Structure.xlsx XLSX spreadsheet
Draft_EFiMS_Evaluation_Factors.pdf PDF
Show all 38

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Homeland Security

Enterprise Financial Management Software (EFiMS) Statement of Work

Joint Program Management Office

Financial Systems Modernization (JPMO FSM)

October 8, 2019

Version 27.0

Enterprise Financial Management Software (EFiMS) SOW – Draft

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 2 of 171

PROCUREMENT SENSITIVE – NOT FOR DISTRIBUTION - See FAR 3.104

TABLE OF CONTENTS

SECTION C – STATEMENT OF WORK 4

1 General 4

1.1 Approach 4

1.2 Integrated Services Model 5

1.3 Federal Laws, Regulations, Standards, and Guidance 5

2 Background 9

2.1 DHS Key Success Factors 10

2.2 DHS Component Current State 11

3 Objectives 14

4 Scope 15

5 Requirements 16

5.1 Functional Requirements 16

5.1.1 Concept of Operations 16

5.1.2 FMSS Taxonomies and Requirements 16

5.1.3 DHS FMSS Standard Business Process Requirements 16

5.1.4 Data Exchange 17

5.2 Non-Functional Requirements 17

5.2.1 Security 17

5.2.2 Software as a Service (SaaS) 18

5.2.3 Identity and Access Management (IAM) 18

5.2.4 Data Management and Data Integrity 19

5.2.5 DHS Enterprise Architecture Compliance 20

5.2.6 Section 508 Compliance Requirements 20

5.2.7 Product Support 22

5.3 Technical Specification 22

5.4 Software Configuration and Implementation Capability 23

5.5 License / Subscription Management 23

5.5.1 License Transfer Requirement 28

5.5.2 Current User Information 29

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 3 of 171

5.5.3 License Audits and Compliance Reviews 29

5.6 Technical Support and Software Maintenance 29

5.7 Transition 30

5.8 Professional Services Requirements 30

5.9 Deliverables 30

5.10 Policies, Standards, and Regulations 31

5.10.1 Federal Laws 31

5.10.2 Federal Standards and Guidance 31

5.10.3 OMB Memoranda and Circulars 31

5.10.4 DHS Directives, Policies and Guidance 32

5.10.5 DHS FSM Guidance 33

5.10.6 Federal Standards and Guidance 33

5.11 Order Reporting 34

6 Support Personnel 35

7 Acronyms 36

8 Glossary 38

9 Attachments 44

Attachment A: Treasury Financial Management Use Cases 45

Attachment B: J-CONOPS and Operational Requirements 52

Attachment C: FMSS Taxonomies and Requirements 59

Attachment D: DHS FMSS Business Process Requirements 81

1 Budget Formulation to Execution (B2FE) 81

2 Record to Report (R2R) 90

3 Request to Procure (R2P) 110

4 Procure to Pay (P2P) 118

5 Bill to Collect (B2C) 134

6 Reimbursable Management (RM) 139

7 Cost Management (CM) 144

8 Acquire to Dispose (A2D) 154

9 Business Intelligence and Decision Support Reporting (BI) 165

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 4 of 171

SECTION C – STATEMENT OF WORK

1 GENERAL

The Department of Homeland Security (DHS) requires Enterprise Financial Management Software (EFiMS) that will support integrated financial management, procurement, and asset management operations. DHS seeks commercial off-the-shelf (COTS) software with the ability to move to Software as a Service (SaaS) to modernize Directorates and Components (“Components”) existing and future financial, procurement, and asset management systems.

DHS anticipates that the initial orders under this IDIQ contract will be for COTS. Throughout this document, procurement includes the full lifecycle from advanced acquisition planning, contract writing, and contract closeout. Asset management as defined in this procurement means the core financial aspects of asset management, including asset additions, transfers, depreciation, and retirement. The high-level goals of modernization are intended to improve the speed and accuracy of financial reconciliation and reporting of consolidated financial statements, improve managerial decision-making, achieve operational efficiencies, and address legal, regulatory, and policy compliance requirements across the Department.

The DHS Office of the Chief Financial Officer (OCFO) Joint Program Management Office (JPMO) will oversee the Financial Systems Modernization (FSM) Program. This procurement, EFiMS, is anticipated to be a multi-award vehicle that is available for use by all Components to purchase software with a fair opportunity competition and selection methodology when the Component has the need to modernize. A separate Enterprise Financial System Integrator (EFSI) multi-award vehicle will be utilized to support the EFiMS selected from this vehicle. The Government anticipates that once the EFiMS and EFSI vehicles are awarded, Components will conduct and award the fair opportunity competition for the software before conducting the competition for the system integration. Anticipated services on EFSI that can be used to support EFiMS include, but are not limited to: program management, discovery, configuration/implementation, technical support, help desk, and training.

1.1 Approach

This procurement is intended to satisfy multiple, potentially competing, business objectives by standardizing the systems supporting financial management, asset management and procurement management while also addressing customer-specific mission needs and capability gaps and minimizing potential organizational disruption due to technological change. Components will follow the fair opportunity requirement outlined in the ordering guide for this the multi-award vehicle to select software that will meet component specific requirements. DHS reserves the right, and Components may decide to elect at the task order level, to purchase and implement

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 5 of 171 software on a per module basis. After Component software selection, DHS OCFO JPMO, in collaboration with the DHS Office of the Chief Information Officer (OCIO), will coordinate deployment, hosting, and support of the software utilizing the EFSI vehicle. The Government reserves the right to host COTS software in a DHS cloud environment. With the exception of SaaS, software hosting is not within the scope of this procurement. If Components select software under the EFiMS multi-award vehicle that has already been implemented by DHS under the EFSI vehicle, no new instances or platform will be required. Services to support the deployment activities, including program management, discovery, and configuration/implementation, will be acquired under EFSI.

1.2 Integrated Services Model

Multiple contract vehicles, including EFiMS and EFSI, will be leveraged as part of Component modernization efforts. EFiMS contractors must work cooperatively and collaboratively with other contractor support resources. The Government Contracting Officer’s Representative (COR), JPMO Program Manager, Branch Chiefs, and OCIO representatives will oversee all contractor integration activities, and will communicate with CORs and Government management personnel that are tasked with oversight of other FSM program support contract vehicles to ensure integrated system engineering support and cross-contract coordination.

1.3 Federal Laws, Regulations, Standards, and Guidance

The EFiMS COTS software or SaaS offering must be compliant with the following mandated requirements. For the DATA Act, the COTS software or SaaS offering must address how the software is compliant with this Act.

INFORMATION SECURITY LAWS, REGULATIONS, STANDARDS, AND GUIDANCE

Primary Sources Overview Federal Information Security Management Act of 2002 (FISMA 2002) DHS 4300A and 4300B

Establishes the foundation of information security in the Federal government. As the primary legislation governing federal information security programs, FISMA builds upon earlier legislation through added emphasis on the management dimension of information security. FISMA delegates responsibility to develop detailed information security standards and guidelines for federal information systems, with the exception of national security systems, to NIST.

• FISMA designates OMB with the oversight of federal agencies’ information security implementation.

• FISMA provides a comprehensive framework for securing federal government information resources.

Federal Information Security Modernization Act of 2014 (FISMA 2014)

The FISMA 2014 updates the Federal Government’s cybersecurity practices by:

• Codifying Department of Homeland Security (DHS) authority to administer the implementation of information security policies for non-national security federal Executive Branch systems, including providing technical assistance and deploying technologies to such systems;

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 6 of 171

INFORMATION SECURITY LAWS, REGULATIONS, STANDARDS, AND GUIDANCE

Primary Sources Overview

• Amending and clarifying the Office of Management and Budget (OMB) oversight authority over federal agency information security practices;

• Requiring OMB to amend or revise OMB A-130 to “eliminate inefficient and wasteful reporting.”

OMB Circular A-130 (Management of Federal Information Resources, Appendix III, Security of Federal Automated Information Resources)

Establishes a minimum set of security controls to be included in federal information security programs, assigns federal agency responsibilities for the security of automated information, and links agency automated information security programs and agency management control systems. Security controls are the management, operational, and technical safeguards or countermeasures prescribed for an information system to protect the confidentiality, integrity, and availability of the system and its information.

Homeland Security Presidential Directive

7 (HSPD 7)

Homeland Security Presidential Directive 7 establishes a national policy for Federal departments and agencies to identify and prioritize critical infrastructure and to protect them from terrorist attacks. The directive defines relevant terms and delivers 31 policy statements.

Homeland Security Presidential Directive

12 (HSPD 12)

This Presidential Directive was released in August 2004, and specifies a “policy for a common identification standard for all Federal employees and contractors.” HSPD-12 intends to increase identification security and interoperability by standardizing the process to issue a Federal employee or contractor an identification credential, and also by specifying the electronic and physical properties of the credential itself. The HSPD-12 credential is known as the Personal Identity Verification card.

Government Performance and Results Act (GPRA) of 1993

Establishes the foundation for budget decision making to achieve strategic goals in order to meet agency mission objectives.

Paperwork Reduction Act (PRA) of 1995 Requires agencies to perform their information resource management activities in an efficient, effective, and economical manner. The term “information resources” means the planning, budgeting, manipulating, and controlling of information throughout its life cycle.

Government Paperwork Elimination Act of 1998 (GPEA)

GPEA requires federal agencies to provide for the option of electronic maintenance, submission, or disclosure of information, when practicable as a substitute for paper; and use and acceptance of electronic signature, when practicable. The Act specifically states that electronic records and their related electronic signatures are not to be denied legal effect, validity, or enforceability merely because they are in electronic form. To provide for a broad framework for ensuring the implementation of electronic systems in a secure manner, OMB directs agencies to use Circular A-130, Appendix III for guidance.

Federal Financial Management Improvement Act (FFMIA) of 1996

FFMIA does three things: 1) Establishes in statute certain financial management system requirements; 2) Requires auditors to report on agency compliance with three stated requirements as part of financial statement audit reports; and 3) requires agency heads to determine, based on the audit report and other information, whether their financial systems comply with FFMIA. If not, agencies are required to develop remediation plans and file them with OMB. OMB implementation guidance for this act states that agencies shall ensure security over financial management information systems in accordance with OMB Circular A-130, Appendix 3. Financial management systems shall have general and application controls in place in order to support management decisions by providing timely and reliable data.

Federal Managers Financial Integrity Act (FMFIA) of 1982

Requires ongoing evaluations and reports of the adequacy of the systems of internal accounting and administrative control of each executive agency.

This Act established the requirement for Executive agencies to have internal accounting and administrative controls in order to provide “reasonable

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 7 of 171 assurance” that funds, property, and other assets are safeguarded against waste, loss, unauthorized use, or misappropriation.

Information Technology Management Reform Act of 1996 (Clinger-Cohen Act)

Supplements the information resources management policies contained in the PRA by establishing a comprehensive approach for executive agencies to improve the acquisition and management of their information resources and:

• Focus on information resource planning to support their strategic missions;

• Implement a capital planning and investment control process that links to budget formulation and execution, and

• Rethink and restructure the way they do their work before investing in information systems.

Digital Accountability and Transparency Act of 2014; DATA Act; Public Law No.

113-101

The purposes of this Act are to:

• Expand the Federal Funding Accountability and Transparency Act of

2006 (31 U.S.C. 6101 note) by disclosing direct Federal agency expenditures and linking Federal contract, loan, and grant spending information to programs of Federal agencies to enable taxpayers and policy makers to track Federal spending more effectively;

• Establish Government-wide data standards for financial data and provide consistent, reliable, and searchable Government-wide spending data that is displayed accurately for taxpayers and policy makers on USASpending.gov (or a successor system that displays the data);

• Simplify reporting for entities receiving Federal funds by streamlining reporting requirements and reducing compliance costs while improving transparency;

• Improve the quality of data submitted to USASpending.gov by holding Federal agencies accountable for the completeness and accuracy of the data submitted; and

• Apply approaches developed by the Recovery Accountability and Transparency Board to spending across the Federal Government.

Federal Funding Accountability and Transparency Act of 2006

This act describes the reporting requirements for acquisitions and grants over the $25,000 to the public using standard data requirements in a searchable website. The searchable website allows the public to:

• Search and aggregate Federal funding by any element required by subsection (b)(1);

• Ascertain through a single search the total amount of Federal funding awarded to an entity by a Federal award described in paragraph (2)(A)(i), by fiscal year;

• Ascertain through a single search the total amount of Federal funding awarded to an entity by a Federal award described in paragraph (2)(A)(ii), by fiscal year; and

• Download data included in subparagraph (A) included in the outcome from searches.

E-Government Act of 2002 Promotes better use of the Internet and other information technology (IT) resources to improve government services for citizens and internal government operations and provide opportunities for citizen participation in government. The Act also requires agencies to:

• Comply with FISMA, included as Title III of the E-Government Act;

• Support government-wide, e-government initiatives;

• Leverage cross-agency opportunities to further e-government through the Federal Enterprise Architecture (FEA) initiative, and

• Conduct and submit to OMB privacy impact assessments for all new

IT investments administering information in identifiable form collected from or about members of the public.

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 8 of 171

Standards and Guidance Overview NIST Federal Information Process Standards (FIPS) Csrc.nist.gov/publications/fips/index.html

FIPS are developed in accordance with the FISMA. FIPS are approved by the Secretary of Commerce and are compulsory and binding for federal agencies. Since FISMA requires that federal agencies comply with these standards, agencies may not waive their use. See the following recent and relevant FIPS:

• FIPS PUB 199, Standards for Security Categorization of Federal

Information and Information Systems

• FIPS PUB 200, Minimum Security Requirements for Federal

Information and Information Systems

• FIPS PUB 201-1, Personal Identify Verification (PIV) of Federal

Employees and Contractors NIST Special Publications 800 Series Cscr.nist.gov/publications/nistpubs/index.

Html

Guidance documents and recommendations are issued in the NIST Special Publication (SP) 800 series. The special publication 800 series reports on ITL’s research, guidance, and outreach efforts in computer security, and it collaborative activities with industry, government, and academic organizations. Office of Management and Budget (OMB) policies (included OMB Memorandum, Reporting Instructions for the Federal Information Security Management Act and Agency Privacy Management) state that for other than national security program and systems, agencies must follow NIST standards and guidance. See the following relevant NIST Standards:

• NIST 800-37 – Guide for Applying the Risk Management Framework to Federal Information Systems

• NIST 800-53 – Defines the baseline security controls, which are chosen from FIPS 199 and FIPS 200

• NIST 800-171 – Protecting Controlled Unclassified Information in

Nonfederal Information Systems and Organizations (SaaS)

• NIST 800-95 – Guide to securing web services

Federal Risk and Authorization Management Program (FedRAMP)

FedRAMP is a result of the Cloud First policy issued in 2011 and OMB memo Security Authorization of Information Systems in Cloud Computing requiring the use of FedRAMP authorized cloud services by Federal agencies. FedRAMP is a centralized assessment program for Cloud Service Providers (CSPs) that mandate a security assessment be performed by a third-party assessment organization (3PAO) to provide Government cloud services (Infrastructure as a Service (IaaS), Platform as a Service (PaaS), or Software as a Service (SaaS)).

Additional requirements related to policy, standards, and regulations, can be found under Section 5.10.

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 9 of 171

2 BACKGROUND

DHS was established in 2002, combining 22 separate federal agencies, each with its own accounting and financial management system, into a unified, integrated Cabinet agency. None of these systems were developed with a view to executing the DHS mission to prevent terrorist attacks within the United States, reduce the Nation’s vulnerability to terrorism, and minimize the damage and assist in the recovery from terrorist attacks. For these reasons, DHS needs to ensure that management control systems are comprehensively designed to achieve the mission and execute the strategy of the Department.

DHS is working toward increasing efficiencies and reducing expenses to improve the cost, quality, and performance of DHS federal financial systems by focusing government resources on fewer, more standardized software solutions that will result in streamlining systems and services where possible. The goal is to provide senior leaders and stakeholders with timely access to standard financial information to support strategic decision-making through solutions that provide increased functionality, real-time integration, improved security and reduced audit risk, while reducing costs and duplication.

In response to the Office of Management & Budget memorandum M-13-08, DHS established the FSM Program. At present, Countering Weapons of Mass Destruction (CWMD) is currently on a software solution and Transportation Security Administration (TSA) and U.S. Coast Guard (USCG) are in the process of fully transitioning onto the same solution. These three Components, which are collectively known as the Trio, are implementing a unique software solution that has no bearing on this solicitation. The Trio Components, collectively or individually, may leverage the EFiMS multi-award vehicle in the future. DHS Components are working together to ensure the FSM Program is planned and executed to meet key financial management requirements, to minimize investment in duplicative systems, to meet Federal guidance, and to deliver financial management information to leadership to support the DHS mission.

Foundational tenets for the FSM program are:

• Increased business process standardization across DHS through efforts to define a common set of financial management business processes and then ensuring component business process re-engineering and modernization efforts reflect the DHS process standard.

• Implement standard financial data element structures such as the DHS Accounting Classification Structure (ACS) and Common Appropriation Structure (CAS) across components to standardize reporting and reduce manual reporting processes and

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 10 of 171 inconsistent data.

• FSM projects should leverage existing infrastructure, shared services, and technologies to the extent possible, following guidance and lessons learned from previous DHS financial management system modernization efforts.

• Leverage the FSM JPMO to lead and manage all aspects of the FSM program, in partnership with DHS components. The JPMO will provide strong project management and oversight, coordinating with our Executive Steering Committee as governance, which includes the Chief Financial Officer (CFO) as the chair, along with the Chief Information Officer (CIO), Chief Readiness Support Officer, the Chief Procurement Officer, and component CFOs and CIOs as voting members.

In addition to operating under Executive Steering Committee oversight, the JPMO coordinates all FSM efforts in partnership with DHS Components under multiple DHS policies governing the management of shared (“joint”) requirements, acquisitions lifecycle, and systems engineering (respectively – Management Directive (MD) 107-01 Joint Requirements Information Management System, and MD 102-01 inclusive of the Systems Engineering Lifecycle). Under these policies, JPMO prepared two overarching governance documents for FSM: Joint Concept of Operations (J-CONOPS), and Joint Operational Requirements Document (J-ORD). These two documents establish the basis under DHS governance for requirements of the materiel solutions to be procured for FSM. The J-CONOPS describes DHS’s strategic vision for financial management involving standardized business processes, improved financial reporting, and compliance with federal laws, regulations and policies. When implemented, EFiMS under this multi-award vehicle will constitute a portion of one or more materiel solutions for FSM. As such, all software to be qualified under this vehicle must satisfy joint DHS requirements.

2.1 DHS Key Success Factors

The software must support the DHS requirement to have all Components on standard business processes with the intent to minimize cost, improve efficiency, ensure data quality and strengthen internal controls. The software must support the following key success factors:

Success Factor Description Integrated financial, procurement and asset management system(s)

The capability to provide integrated financial, procurement, and asset management system(s) that minimizes the need for customization and manual workarounds.

Timely and accurate financial reporting

The capability to support access to the data via ad-hoc queries and various types of standard reports without requiring the use of technical personnel and without the need for complex data calls.

This includes data warehousing, robust reporting capabilities and archiving functions to support decision making, as well as

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 11 of 171

Success Factor Description supporting the Department’s goal to achieve an integrated data capability.

Sustainment, Effectiveness, and Performance

The ability to function efficiently and effectively throughout the solution’s lifecycle. This includes minimizing the cost of operations/sustainment while maximizing performance.

Scalability for future needs

The ability to adapt to emerging needs, requirements and standards and adopting new technologies.

Ability to address security risks and ensure auditability

The capability to detect and resolve issues regarding internal control and security and have the adaptability to address future risks. The solution must also provide controls and audit trails to ensure auditability and compliance with operational and reporting requirements.

2.2 DHS Component Current State

DHS Components currently rely on various platforms, tools, and applications to perform functions related to financial, procurement, and asset management. The Component solutions are varied in their integration capabilities and compliance with standards developed by the Department (e.g., DHS Accounting Classification Structure (ACS)) and/or other Federal laws and mandates (e.g., DATA Act). When the DHS Component is able to meet DHS standards/requirements, they often do so through customized automated or manual processes that are expensive to maintain. Some DHS Components continue to use systems comprised of legacy technology, which are mostly non-integrated, and rely on compensating manual processes that leads to inconsistent data and reporting. As shown in the table below, there are many separate core financial management systems across DHS Components.

NOTE: Green indicates the system/module is integrated with the financial management system.

Tan indicates the system/module is interfaced with the financial management system.

Blue indicates the system/module is NOT integrated or interfaced with the financial management system.

DHS Component Current State Component Financial Management

System Acquisition

Management System Asset Management

System

Federal Emergency Management Agency

(FEMA)

Integrated Financial Management Information Systems (WebIFMIS)

PRISM (HQ) Sunflower Assets (HQ)

Oracle Fixed Assets

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 12 of 171

Component Financial Management System

Acquisition Management System

Asset Management System

U.S. Coast Guard

(USCG)

Core Accounting System (CAS) Oracle Federal Financials 11.5.10

Contract Information Management System (CIMS), Financial and Procurement Desktop

(FPD)

Shore Asset Management System (SAMS) (w/Tririga) Housing Management Information System (HMIS), Aids to Navigation System (ATONIS), Asset Logistics Management Information System (ALMIS), Naval and Electronic Supply Support System (NESSS)

Transportation Security Administration (TSA)

Core Accounting System (CAS) Oracle Federal Financials 11.5.10

(USCG)

Contract Information Management System (CIMS), Financial and Procurement Desktop

(FPD)

Oracle Fixed Assets

Sunflower Assets (TSA)

Countering Weapons of Mass Destruction

(CWMD)

DHS HQ Oracle Federal Financials 12.2

Contract Lifecycle Management (CLM)

Oracle Fixed Assets

Sunflower Assets (HQ)

U.S. Immigration and Customs Enforcement (ICE)

Federal Financial Management System (FFMS) Release 3.6.1

PRISM (HQ) Sunflower Assets (HQ) (Personal Property) Vehicle Management Information System (VMIS) Tririga

U.S. Citizenship and Immigration Services

(USCIS)

Federal Financial Management System (FFMS) Release 3.6.1

(ICE)

PRISM (HQ) Sunflower Assets (HQ)

Cybersecurity and Infrastructure Security Agency

(CISA)

Federal Financial Management System (FFMS) Release 3.6.1

(ICE)

PRISM (HQ) Sunflower Assets (HQ)

Science & Technology Directorate (S&T)

Federal Financial Management System (FFMS) Release 3.6.1

(ICE)

PRISM (HQ) Sunflower Assets (HQ)

Office of the Secretary & Under Secretary for Management

Federal Financial Management System (FFMS) Release 3.6.1

(ICE)

PRISM (HQ) Sunflower Assets (HQ)

Federal Law Enforcement Training Center

(FLETC)

Momentum 7.1.2 PRISM (HQ) Sunflower Assets (HQ)

Office of Intelligence and Analysis (I&A)

Momentum 7.1.2

(FLETC)

PRISM (HQ)

(Classified actions are manual, outside of

PRISM)

FileMakerPro

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 13 of 171

Component Financial Management System

Acquisition Management System

Asset Management System

Office of Operations Coordination and Planning (OPS)

Momentum 7.1.2

(FLETC)

PRISM (HQ) Sunflower Assets (HQ)

U.S. Secret Service

(USSS)

Enterprise Financial Management System (TOPS) Oracle Federal Financials version 12

PRISM (USSS) Sunflower Assets (USSS)

Customs and Border Protection (CBP)

SAP Business Suite 7 SAP NetWeaver 7.5

SAP Procurement for Public Sector

Seized Currency and Asset Tracking System (SEACATS) Tririga

Firearms, Armor, & Credentials Management System (FACTS) Computerized Aircraft Reporting & Material Control (CARMAC) Customs Automated Marine Inventory Tracking System (CAMITS) Maximo Vehicle Management Information System (VMIS)

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 14 of 171

3 OBJECTIVES

The objective of this procurement is to obtain mature and proven integrated financial, procurement, and asset management software that meets DHS requirements. The software shall provide functionality for federal financial management, procurement, and asset management, and must have the capability to interface with Component specific systems (these will be identified when task orders are competed under the vehicle), commercial systems (e.g., eTravel, Purchase Card), and federal system initiatives (e.g., Grants and Payroll).

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 15 of 171

4 SCOPE

The scope of this SOW includes: COTS software licenses, SaaS subscriptions, software documentation and accessory products (only if incorporated into the proposed software), and professional services. In general, these include:

• Licenses for COTS software providing the required functionality, inclusive of product support under a vendor’s Software Maintenance Lifecycle (SMLC) program;

• SaaS subscription providing the required functionality, including product support and software updates;

• Supporting documentation, system specifications, implementation guides and related accessory products that are incorporated into the proposed software, operations and maintenance of the software within operational environments; and

• Professional services to include Tier 4 consultative services support to address software issues escalated through Component(s)’ service desk process.

The scope of the SOW excludes services provided under other existing or anticipated vehicles, including: PMO support, program/project management support, discovery support, implementation support, system operations and maintenance, infrastructure provisioning, training curriculum development and training delivery.

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 16 of 171

5 REQUIREMENTS

This section identifies the joint DHS requirements for all software. In addition to meeting the joint requirements qualification, fair opportunity requirement, and selection of software under this vehicle may include additional operational, functional and non-functional requirements as specified by each Component under subsequent Task Orders.

5.1 Functional Requirements

The procured software shall provide the capability to implement standard business functions according the DHS requirements, and provide the capability to implement data exchanges between modules and systems based on open standards and toolsets.

5.1.1 Concept of Operations

The FSM J-CONOPS outlines the DHS financial management modernization approach. It describes how EFiMS systems will support DHS components by facilitating standard business processes, improving financial reporting, and supporting DHS’s strategic vision for a financial management approach that complies with federal requirements. See Attachment B for all J- CONOPS and Operational Requirements.

5.1.2 FMSS Taxonomies and Requirements

For business process standardization, the DHS FSM initiative uses an enterprise-wide taxonomy to list the business processes that support the DHS core financial management capabilities (i.e., Core Financial, Procurement, Asset Management and Business Intelligence). See Attachment A for details on how the DHS business processes map to the Treasury-defined use cases and business processes. See Attachment C for all Financial Management Systems Standards (FMSS) Taxonomies and Requirements. Software procured under this multi-award vehicle shall support the FMSS Taxonomies and Requirements.

5.1.3 DHS FMSS Standard Business Process Requirements

The nine business processes in FMSS include Budget Formulation to Execution, Record to Report, Request to Procure, Procure to Pay, Bill to Collect, Reimbursable Management, Acquire to Dispose, Business Intelligence and Decision Support Reporting, and Cost Management. See Attachment D for all FMSS Standard Business Process Requirements. Software procured under this multi-award vehicle shall support FMSS Standard Business Process Requirements.

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 17 of 171

5.1.4 Data Exchange

The software shall provide the ability to import and export data in an open, standard-based nonproprietary format. The product shall be able to interface with external systems and other products using open application programming interfaces (APIs) and open documented standard data exchanges. The product shall be capable of supporting modern web-based data services.

5.2 Non-Functional Requirements

5.2.1 Security

The management of security, including documentation for all applications and environments, shall be in accordance with NIST 800-53, DHS Policy Directive 4300A and 4300B and in conjunction with the DHS Information Security Office (ISO) and the DoDI 8510 – Risk Management Framework (RMF) for DoD Information Technology (IT). DHS Policy 4300.A – Information Assurance (IA) shall be considered a requirement for all systems used to enter, process, store, display or transit sensitive or national security information. IA shall be achieved through the acquisition and appropriate implementation of evaluated or validated IA and IA-enabled IT products. These products shall provide for the availability of systems. The products also shall ensure the integrity and confidentiality of information and the authentication and non-repudiation of parties in electronic transactions.

The Contractor shall provide any and all documentation to the IA team as required to ensure the EFiMS does not pose security threats or IA issues to installation into Government data centers.

It is the responsibility of the Contractor to ensure that all software enhancements and maintenance activities, provided for under this contract and all task orders are compliance with DHS Information Security Policy, DHS 4300 as implemented by DHS MD 4300A Sensitive Systems Handbook or National Security Systems Policy Directive 4300B and NIST 800-53.

The software shall be configurable to support the ability to obtain an Authority to Operate (ATO). The specific FISMA level (Low, Medium, High) support required will be defined by the Component during their fair opportunity process. EFiMS shall be designated as “Sensitive but Unclassified” (SBU) and is subject to DHS Management Directive (MD) 11042.1 Safeguarding

SBU.

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 18 of 171

5.2.2 Software as a Service (SaaS)

SaaS is defined under this procurement as:

The capability provided to the consumer is to use the provider’s applications running on a cloud infrastructure. The applications are accessible from various client devices through either a thin client interface, such as a web browser (e.g., web-based email), or a program interface. The consumer does not manage or control the underlying cloud infrastructure including network, servers, operating systems, storage, or even individual application capabilities, with the possible exception of limited user-specific application configuration settings.

NIST 800-145: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800- 145.pdf

Software is on a standardized code base and updates are pushed out to all customers. Software can be available in a single- or multi-tenant architecture.

At the time of the multi-award vehicle, vendors must either (i) demonstrate that they have a documented plan to migrate existing software to SaaS or (ii) meet one of the following three FedRAMP requirements: (a) Provisional Authority to Operate (P-ATO), (b) Agency Authority to Operate (ATO), or (c) FedRamp Ready. At the IDIQ level, vendors will be evaluated based on whether they meet one of the requirements under (i) or (ii), above.

At the Component ordering level, vendors must meet one of the requirements under (ii), above, and all requirements under this SOW. Any SaaS offering must be FedRAMP Authorized before implementation within any DHS HQ or Component environment. IaaS and PaaS are not included in the scope of this vehicle.

5.2.3 Identity and Access Management (IAM)

IAM is the security that enables the right individuals to access the right resources at the right times and for the right reasons. The software proposed must support IAM requirements. The following requirements shall be met for IAM:

• Role-based access control (RBAC)

• Support DHS Single Sign-on/Personal Identity Verification (SSO/PIV) card access.

• User authentication and authorization of access to function components of the software suite

• Security incident identification, recording, and alerts https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-145.pdf

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 19 of 171

• Audit and accountability: track user access and activity in the software and its functional components

5.2.4 Data Management and Data Integrity

All software proposed for EFiMS shall have the capability for internal verification and audit procedures to ensure data integrity. The software shall support the seven (7) dimensions of data quality:

• Completeness o The proportion of stored data against the potential of "100% complete"

• Uniqueness o An event or entity will be not be recorded more than once based upon exclusivity identified.

• Timeliness o The degree to which data represent temporal event

• Validity/Conformity o Data must conform to the syntax (format, type, range) of its definition.

• Accuracy o Data must correctly represent the event or entity being captured

• Consistency o Standardization when comparing two or more similar categorizations of an event or entity thing against standard system definition.

• Currency o The degree to which data represents reality from the required point in time.

The vendor shall maintain, publish, and provide the Government with data architectures, physical data models, data structures, data dictionaries, and Application Program Interfaces (APIs) for the product(s). The vendor shall maintain and provide to the Government an inventory, summarization and documentation of each interface specification to include API(s) that are corporately developed or included with the software.

It is the intent of this effort to maintain Government ownership of all extracted/migrated data and related documentation and that any existing proprietary information concerning the software be converted or shielded such that DHS Component support teams may freely configure, implement, maintain, extract information from, and perform other support tasking in the system as required to provide a solution to DHS users.

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 20 of 171

The software must provide the capability to mask or obfuscate data on production and non-production environments. The software must also provide the capability to encrypt data at the row, column, table, and file level of the database.

5.2.5 DHS Enterprise Architecture Compliance

All solutions and services shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the contractor shall comply with the following Homeland Security (HLS) EA requirements:

• All developed solutions and requirements shall be compliant with the HLS EA principles.

• All IT hardware and software shall be compliant with the HLS EA Technical Reference

Model (TRM) Standards and Products Profile; all products are subject to DHS Enterprise Architectural approval. No products may be utilized in any production environment that is not included in the HLS EA TRM Standards and Products Profile.

• Description information for all data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the Enterprise Data Management Office (EDMO) for review, approval and insertion into the DHS Data Reference Model and the enterprise architecture information repository.

• Development of data assets, information exchanges and data standards will comply with the DHS Data Management Policy MD 103-01 and all data-related artifacts will be developed and validated according to DHS data management architectural guidelines.

• Applicability of Internet Protocol Version 6 (IPv6) to DHS-related components (networks, infrastructure, and applications) specific to individual acquisitions shall be in accordance with the DHS Enterprise Architecture (per OMB Memorandum M-05-22, August 2, 2005) regardless of whether the acquisition is for modification, upgrade, or replacement. All EA-related component acquisitions shall be IPv6 compliant as defined in the U.S. Government Version 6 (USGv6) Profile (National Institute of Standards and Technology (NIST) Special Publication 500-267) and the corresponding declarations of conformance defined in the USGv6 Test Program

5.2.6 Section 508 Compliance Requirements

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) (codified at 29 U.S.C. § 794d) requires that when Federal agencies develop, procure, maintain, or use information and communications technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public with

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 21 of 171 disabilities must be afforded access to and use of information and data comparable to that of Federal employees and members of the public without disabilities.

1. All products, platforms and services delivered as part of this work statement that, by definition, are deemed ICT or that contain ICT shall conform to the revised regulatory implementation of Section 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and available at https://www.gpo.gov/fdsys/pkg/CFR-2017-title36-vol3/pdf/CFR-2017-title36-vol3-part1194.pdf. In the revised regulation, ICT replaced the term electronic and information technology (EIT) used in the original 508 standards.

Item that contains Information and Communications Technology (ICT):

Enterprise Financial Management Software

Applicable Exception: N/A Authorization #: N/A

Applicable Functional Performance Criteria: All functional performance criteria in Chapter 3 apply to when using an alternative design or technology that results to achieve substantially equivalent or greater accessibility and usability by individuals with disabilities than would be provided by conformance to one or more of the requirements in Chapters 4 and 5 of the Revised 508 Standards, or when Chapters 4 or 5 do not address one or more functions of ICT.

Applicable 508 requirements for electronic content features and components (including Internet and Intranet website; Electronic documents; Electronic forms; Electronic document templates; Electronic reports; Electronic training materials): All requirements in E205 apply, including all WCAG Level AA Success Criteria Apply

Applicable 508 requirements for software features and components (including Web, desktop, server, mobile client applications; Electronic content and software authoring tools and platforms; Service Offerings):

All requirements in Chapter 5 apply, including all WCAG Level AA Success Criteria, 502 Interoperability with Assistive Technology, 503 Application, 504 Authoring Tools

Applicable 508 requirements for hardware features and components:

Does not apply

Applicable 508 requirements for support services and documentation: All requirements in Chapter 6 apply https://www.gpo.gov/fdsys/pkg/CFR-2017-title36-vol3/pdf/CFR-2017-title36-vol3-part1194.pdf https://www.gpo.gov/fdsys/pkg/CFR-2017-title36-vol3/pdf/CFR-2017-title36-vol3-part1194.pdf

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 22 of 171

2. When providing installation, configuration or integration services for ICT, the contractor shall not reduce the original ICT item’s level of Section 508 conformance prior to the services being performed.

3. When providing maintenance upgrades, substitutions, and replacements to ICT, the contractor shall not reduce the original ICT’s level of Section 508 conformance prior to upgrade, substitution or replacement. The agency reserves the right to request an Accessibility Conformance Report (ACR) for proposed substitutions and replacements prior to acceptance. The ACR should be created using the on the Voluntary Product Accessibility Template Version 2.2 508 (or later). The template can be located at https://www.itic.org/policy/accessibility/vpat

4. Contractor personnel shall possess the knowledge, skills and abilities necessary to address the applicable revised Section 508 Standards for each ICT.

5. Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer and a determination will be made according to DHS Directive 139-05, Office of Accessible Systems and Technology, dated November 12, 2018 and DHS Instruction 139-05-001, Managing the Accessible Systems and Technology Program, dated November 20, 2018.

5.2.7 Product Support

The EFiMS vendor shall provide service level agreements (SLAs), to include expected response times to inquiries from government federal and contract support personnel to provide product support. They shall outline the forms of communication, their access to report issues, seek guidance, etc. (i.e., email, phone, web, and chat) to address issues relating to software installation, configuration, software updates, bug tracking and fixes. In addition, the EFiMS vendor shall provide user and administrative documentation (electronic via files and also online) for the proposed EFiMS.

Minimum COTS SLAs

# Category Response Time Resolution Time 1 Production Outage 15 Minutes 2 Hours 2 Production – Critical Functionality Issue 1 Hour 4 Hours 3 Non-Production – Functionality Issue 4 Hours 72 Hours

5.3 Technical Specification

The vendor shall provide Technical Requirements/Specification documentation for the software to include installation and configuration guides, software functional use guides, technical requirements for servers or client work stations for the product, and any other technical https://www.itic.org/policy/accessibility/vpat

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 23 of 171 documentation required by the Government to implement, configure, support, extract data, build reports and interfaces, etc.

5.4 Software Configuration and Implementation Capability

The software offering shall provide the capability to:

• Support DHS/Component financial management, asset management and procurement management business processes using configurable options.

• To be widely supported by market leaders/vendors such that DHS can acquire contract support for implementation and operations and maintenance.

● Integrated financial, procurement, and asset management software

● Integrated with Business Intelligence

● Logging/audit tracking including tracking user action

● Industry standards based open interfaces and data exchange

● Compliant with NIST and DHS Chief Information Security Officer (CISO) Standards

● Software with end-user configurability that eliminates or minimizes the need for custom software development

● Provide capabilities that simplify and automate migration to the cloud.

● Secure and scalable software suite

● Role based Access Control and Segregation of Duties Capability

● Single Sign On functionality

● Support User Access Management Capability

● Interfaced with internal and external systems using open API standards to exchange information with external systems

● Ability to export/import data in industry standard formats using service-oriented architect methodologies

● Allow data to be loaded from external sources and ensure data integrity, validation, and ability to transact using loaded data.

● The vendor shall coordinate with system support team on issues reported. If there is a system failure and the root-cause analysis traces it back to the vendor, then the Government would require the vendor to provide a patch to the software.

5.5 License / Subscription Management

The following tables provide a list of elements and a description of the information the COTS vendor/SaaS provider shall provide in their proposals for software license agreements, maintenance agreements and software related services. The COTS vendor/SaaS provider shall describe any additional elements not listed below that provide the Government with a clear understanding of their license services, costs, terms, and other relevant information. If there are

Sources Sought Notice: DHS-70RTAC18RFI000004 May 14, 2019 Page 24 of 171 additional software products bundled with the proposed software that would be required by the implementation / configuration or O&M support teams, those should be included as well.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.