DRAFT_EFiMS_SOW.pdf

PDF 2 MB Posted

Attached to
DHS Enterprise Financial Management Systems (EFiMS) Federal contract opportunity
Solicitation number
DHS-70RTAC18RFI000004
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

Draft EFiMS SOW

View the file

Other files for this federal contract opportunity

Other files attached to DHS Enterprise Financial Management Systems (EFiMS), newest first.
File Type Posted
Attachment J-2 EFiMS Pricing Structure 11-20-19.xlsx XLSX spreadsheet
SF 30 Page 2_11-20-19.pdf PDF
EFiM S RFP Updated - 11-20-19.pdf PDF
SF30 Page 1 _11-20- 19.pdf PDF
Attachment J-5- Ordering_Guide 11-18-19.pdf PDF
S F 30- Page 1 11-18-19.pdf PDF
Responses to company questions 11-18-19.pdf PDF
Attachement J-4 Past Performance Information Form 11-18-19.docx DOCX document
Attachment J-1 EFiMS Statement of Work 11-18-19.pdf PDF
Attachment J-3 Functional Requirements 11-18-19.xls XLS spreadsheet
SF 1449_11-18-19.pdf PDF
SF 30-Page 2_11-18-19.pdf PDF
EFiMS Request for Proposal 11-18-19.pdf PDF
EFiMS_Responses_to_Vendor_Questions_10-30-19.xls XLS spreadsheet
Attachment_J-1_EFiMS_Statement_of_Work_10-30-19.pdf PDF
Attachment_J-3_Requirements_10-30-19.xls XLS spreadsheet
Attachement_J-4_Past_Performance_Information_Form.pdf PDF
EFiMS_Request_for_Proposal.pdf PDF
SF_1449_FINAL.pdf PDF
Attachment_J-2_EFiMS_Pricing_Structure_10-30-19.xlsx XLSX spreadsheet
Attachment_J-5-_Ordering_Guide.pdf PDF
Attachment_J-3_Requirements.xlsx XLSX spreadsheet
Attachement_J-1_Statment_of_Work.pdf PDF
Attachement_J-2__Pricing_Structure.xlsx XLSX spreadsheet
Attachment_J-5_Ordering_Guide.pdf PDF
Request_for_Proposal.pdf PDF
Attachement_J-4_Past_Performance_Information_Form.pdf PDF
EFiMS_Draft_RFP_09-05-2019.pdf PDF
Attachment_J-3-EFiMS_Requirements.xlsx XLSX spreadsheet
Attachment_J-5-_Ordering_Guide.pdf PDF
Attachment_J-2-_EFiMS_Pricing_Structure_9-5-19.xlsx XLSX spreadsheet
Attachement_J-4_Past_Performance_Information_Form.pdf PDF
Attachment_J-1-_Statement_of_Work.pdf PDF
EFiMS_Industry_Day_Presentation.pdf PDF
EFiMS_Vendor_Question_Responses_-_FBO_Posting_-_7.2.19-v2.pdf PDF
EFiMS_Software_SOW_for_FBO_Posting_7-2-19.pdf PDF
DRAFT_EFiMS_Pricing_Structure.xlsx XLSX spreadsheet
Draft_EFiMS_Evaluation_Factors.pdf PDF
Show all 38

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Department of Homeland Security

Enterprise Financial Management Software (EFiMS) Draft Statement of Work

Joint Program Management Office

Financial Systems Modernization (JPMO FSM)

December 18, 2018

Version 5.0

Enterprise Financial Management Solution (EFiMS) SOW – Draft

SECTION C – STATEMENT OF WORK

1 GENERAL

The Department of Homeland Security (DHS) requires integrated financial, procurement, and asset management commercial off the shelf (COTS) application software licenses along with the associated/related COTS software license maintenance, software tools to support the application and subject matter expertise for level 3 technical support (on-site and off-site) that will require the COTS contractor to work with a Government contractor supporting the COTS software. The integrated finance, procurement, and asset management software licenses will enable timely and accurate reporting, be sustainable and effective, scalable, secure and auditable, adhere to Federal regulations, Treasury Financial Innovation and Transformation (FIT) and DHS policies as well as meet or exceed the DHS standard business processes for finance, procurement, and asset management. EFiMS shall allow DHS and Components to streamline and standardize business processes and procedures across the entire organization providing more accurate, timely, and useful financial, procurement, and asset data to managers and shall enable DHS to derive financial statement data both at the consolidated and component level more efficiently. In addition, the COTS software shall help DHS improve financial management performance and aid Department Components in addressing financial audit material weaknesses in internal controls, accounting standards, and system security. Finally, the COTS software shall provide procurement community users the capability to meet all mandatory requirements of the Federal Acquisition Regulation (FAR) and Homeland Security Acquisition Regulations (HSAR).

2 BACKGROUND

DHS was officially created in January 2003 as a means to merge 22 disparate agencies comprised of 180,000 employees into one cabinet-level department. DHS currently includes fourteen (14) operational and support Components. The DHS FSM initiative is Department-wide and consists of multiple Component-Level FSM initiatives. At DHS’ formation, one of the main objectives was to consolidate the mission support systems of the entire department to realize cost benefits and operational efficiencies. The department’s Under Secretary for Management (USM), Chief Financial Officer (CFO), Chief Information Officer (CIO), Chief Procurement Officer (CPO), and Chief Readiness Support Officer (CRSO) are unified in achieving efficiencies in the business processes and systems used throughout the department.

When DHS was first established, there were 13 separate core financial systems across its Components, operating under legacy policies and disparate business processes. These systems were comprised of outdated technology, were mostly non-integrated—with many still relying on manual processes which led to inconsistent data and reporting—and did not fully support DHS goals of strong, integrated internal controls and enhanced efficiency and security.

DHS established the Financial Systems Modernization (FSM) Program in accordance with the Under Secretary for Management (USM) September 2011 memorandum, Moving Forward with Financial Systems Projects. DHS leadership and Components are working together to ensure the FSM Program is planned and executed to meet key financial management requirements, to minimize investment in duplicative systems, to meet Federal guidance, and to deliver financial management information to leadership to support the DHS mission.

The DHS Office of Financial Management (OFM) Financial Systems Modernization (FSM) Program established the Joint Program Management Office (JPMO), who is responsible for coordinating all efforts to support the FSM Program. JPMO functions include program management, information technology management, and business transformation. The JPMO works with the DHS component agencies, DHS leadership, and external stakeholders from the Office of Management and Budget (OMB), the General Services Administration (GSA), and the Unified Shared Services Management (USSM) and oversee the Financial System Modernization Program.

The Department of Homeland Security (DHS) Agency Reform Plan (DARP) addresses Executive Order 13781, Comprehensive Plan for Reorganizing the Executive Branch, with the intent to improve the effectiveness, accountability and efficiency. DARP major reform initiatives that apply to the EFiMS contract include:

• IT Acquisition – Assess Information Technology (IT) acquisition planning, requirements and standards across DHS to streamline towards best in class buying practices, leveraging total demand via category management, and strategic sourcing across the Department, interagency, and private sector. Desired Outcome: Leveraging the Department’s buying power, reduce IT procurement costs.

– Key Measure: Savings identified/saving realized.

• DHS Procurement Delivery Model – Assess the categories of spend and capabilities of

Headquarters and Component/Heads of Contracting Agencies (HCA) operational buying activities to promote more efficient and effective procurement delivery services, and leverage total demand through category management and strategic sourcing practices (e.g., IT procurements, classified acquisitions). Desired Outcome: Implement efficient and effective procurement delivery structure and business processes.

– Key Measure: Correct 100% of system inefficiencies.

• Financial Transactions – Identify the most cost-effective way to manage and execute financial transactions across the Department, interagency, and private sector. Desired Outcome: Reduce cost, improve efficiency and data quality, and strengthen internal controls through standardizing processes and streamlining systems and services

– Key Measure:

• Modernized financial systems for CWMD, USSS, TSA, USCG, FEMA, &

ICE, NPPD, DHS HQ, S&T, USCIS

• Develop standards for 80% of financial transaction processes.

• Consolidate DHS financial transaction processing centers from 10 to 2-4

DHS and its Components currently rely on various platforms, tools, and applications to perform functions related to financial management, procurement, and asset management. These individual solutions are varied in their integration capabilities and many of these systems struggle to adapt to standards developed by the Department (e.g., DHS Accounting Classification Structure (ACS)) and/or other Federal laws and mandates (e.g., DATA Act) and often do so through customized automated or manual processes that are expensive to maintain. Enterprise-level solutions that comply with developed DHS standards are needed to aggregate key Department-wide financial data for management, oversight, and decision making purposes.

By Fiscal Year 2025, DHS intends to have all DHS HQ and Components on standard business processes and related systems; with consolidation to as few software solutions as is practicable and cost effective. This is intended to reduce cost, improve efficiency and data quality and strengthen internal controls through standardizing processes and streamlining systems and services. Key success factors for DHS follow:

Success Factor Description Integrated financial, procurement and asset management solution

The capability to provide an integrated financial, procurement, and asset management software solution that minimizes the need for customization and manual workarounds. The software solution shall allow for integration with required internal and external systems/tools.

Timely and accurate financial reporting

The capability to support access to the data via ad hoc queries and various types of standard reports without requiring the use of technical personnel and without the need for complex data calls.

This includes data warehousing, robust reporting capabilities and archiving functions to support decision making, as well as supporting the Department’s goal to achieve an integrated data capability.

Sustainment, Effectiveness, and Performance

The ability to function efficiently and effectively throughout the solution’s lifecycle. This includes minimizing the cost of operations/sustainment while maximizing performance.

Scalability for future needs

The ability to adapt to emerging needs, requirements and standards and adopting new technologies.

Ability to address security risks and ensure auditability

The capability to detect and resolve issues regarding internal control and security, and have the adaptability to address future risks. The solution must also provide controls and audit trails to ensure auditability and compliance with operational and reporting requirements.

3 OBJECTIVES

The objective of this procurement is to obtain mature and proven integrated financial, procurement, and asset management commercial off the shelf (COTS) application software licenses that address DHS mission gaps as found in the current environments. The software licenses and support shall provide functionality for federal financial management with existing modules for procurement management and asset management and/or must have demonstrated the ability to integrate/interface with other Component and federal systems. DHS intends to acquire COTS application software and COTS support software tools that addresses the following gaps:

# Capability Gap Description 1 Data Integrity Legacy systems require extensive manual adjustments to transaction level data (e.g. journal vouchers and top side adjustments) that create data integrity risks and potential audit risks. This also leads to Federal Financial Management Improvement Act (FFMIA) non-compliance (US Standard General Ledger (USSGL) at transaction level). Discrepancy between data stored in multiple systems cause issues and require manual reviews and reconciliations.

2 Insufficient security and internal controls

The security and internal controls employed by the legacy systems are insufficient and difficult to manage. This is primarily due to the lack of access control, configuration management, and segregation of duties role-based user assignments. As a result, manual compensation controls are used and increases audit risk.

3 Lack of integrated financial systems

Legacy systems do not effectively or efficiently integrate or interface with required internal and external systems that have a financial impact, requiring numerous manual processes and workarounds. This includes entering data and transactions into multiple systems manually. The manual processes increase the risk of poor data integrity, are inefficient and ineffective, and do not facilitate a paperless work environment.

4 Restricted legacy system flexibility and reporting capabilities

The legacy environment’s inflexibility inhibits effective and efficient use of financial analysis and reporting tools. DHS customers must routinely resort to non-standard methods to respond to financial information requests and produce repots requested by DHS, Office of Management and Budget (OMB), Congress, etc.

This prevents DHS from obtaining information timely and efficiently to support critical decisions.

5 Absent or impaired integrated business systems capability

DHS lacks the ability to streamline financial data collection and sharing across the enterprise. The Department relies on manual labor-intensive data calls to generate Department-level financial reports. The department lacks the capability to share information across organizational boundaries and from disparate systems.

6 Cannot adapt to emerging requirements

The legacy systems cannot adapt to anticipated and emerging requirements without additional customization and workarounds.

The financial system requires numerous system changes and enhancements to preserve functionality, to meet changing or new requirements from DHS and authoritative sources or to correct system issues.

7 Lack of an open system

Legacy system proprietary constraints contribute to a closed system environment with limited web-services and application

# Capability Gap Description programming interfaces (APIs). This reduces optimal access to an understanding of system structure. These limitations impair flexibility, and limit resources available to enhance performance and improve operational support.

8 Limited capability to support Department’s efforts to standardize systems, data and processes

Legacy operations restrict DHS’ ability to fully support Department efforts to evolve financial systems management governance policy and standards to ultimately achieve the capability to standardize data and operational processes.

9 Non-compliance with Federal regulation and accounting standards

Current systems do not comply with government-wide financial and accounting requirements and guidance for timely, reliable and accurate accounting. There is inconsistent reporting from financial systems that do not comply with United States Standard General Ledger (USSGL) and DHS Accounting Classification Structure.

Inconsistent standards and processes from manual entries are required for non-integrated systems.

10 Lack of enterprise view of resources across the department

The department lacks the capability to share information across organizational boundaries and from disparate systems.

For the purposes of this document, an “integrated software suite” or “software suite” or “software license” or “suite” or “EFiMS suite”, or “application software” is defined as a commercial off the shelf (COTS) configurable software package with three fully integrated and functional capabilities: financial, procurement, and asset management. For this SOW, the definition of interface and integrate follows:

Interface

Also known as a bridge, an interface is where two or more separate software products communicate under limited capacity. Data is maintained in multiple locations, thus, requiring more administration.

Integrate

A fully integrated system means that the products are one. This happens when two or more products work closely together to combine different functionality into one product. The data is maintained in one location.

4 SCOPE OF WORK

The scope of this procurement is the acquisition by multiple Component customers of an enterprise level integrated COTS software product that efficiently and effectively execute DHS’s financial, procurement and asset management standard business processes ensuring compliance with federal financial directives, regulations, and guidelines. The software provider shall ensure that the COTS software product has an established and documented Software Release Life Cycle Maintenance program. The Software Release Life Cycle Maintenance program will ensure the functionality performance, continuity and interoperability of the enterprise software.

While the IDIQ SOW focuses on the DHS standard business processes that support all DHS HQ and Components, Task Orders issued off the IDIQ will focus on the Component specific processes or sub-processes in order to complete a fair opportunity competition and selection of the final COTS software product for that DHS HQ organization or DHS Component.

The scope includes COTS application software for integrated finance, procurement, asset management, as well as and business intelligence, vendor maintenance, COTS software tools, and support services from the COTS subject matter experts for level 3 technical support. The scope does NOT include provision of hardware systems to host the integrated software solution or system integration services.

The COTS software products shall be part of the operational system, including application products/modules, products in the software development environment, products that document the system requirements, and products that manage the maintenance of the system. The COTS products shall support the following key requirements:

● Commercial Off the Shelf (COTS) integrated software application suite

● Fully integrated and interoperable financial, asset management, and procurement management

● Fully Integrated with Business Intelligence, which also includes the ability to pull data from the COTS software on an Ad-Hoc basis

● Logging/audit tracking including tracking user action

● Industry Standards based open interfaces and data exchanges

● Compliant with NIST and DHS Chief Information Security Officer (CISO) Standards

● Out-of-the-Box software solution with easy configurability that avoids custom software development, with the goal of minimizing operations and maintenance (O&M) cost

● Supports an automated path to migrate to the cloud

● Secure and scalable Software suite

● Provides Role based Access Control

● Out of the Box Single Sign On capability

● Support business processes related to financial management, Asset Management and

Contract Management across DHS and its components

● Allow Automatic, timely and accurate reporting

● Interoperate with internal and external systems

● Interface with external systems as required by federal initiatives

● Ability to export/import data in industry standard formats using service oriented architecture methodologies

● Allow data to be loaded from external sources and ensure data integrity, validation, and ability to transact using loaded data.

5 REQUIREMENTS

The requirements listed in this section are from the DHS Joint Concept of Operations (CONOPS), DHS Joint Operational Requirements (J-ORD), DHS Standard Business Process Taxonomies and Derived Requirements. Each level of requirement provides a different view into the DHS need that will support DHS and Components. The Joint CONOPs provide the concept of operations, is the next level requirement below the Mission Need Statement (MNS), and is derived from the DHS and Component’s MSNs. The CONOPs is further decomposed in the Joint ORD.

The Joint ORD defines the Financial Management System in terms of the DHS end-to-end business processes and operational and support concepts that apply to DHS and Components that will be used to modernize their financial systems. The J-ORD is the next level requirement below the CONOPs and is further decomposed in the Business Process Taxonomies and Derived Requirements.

The Business Process Taxonomies and Derived Requirements define the enterprise-wide taxonomy, utilized by all Components, encompassing the business processes that support the DHS core financial management capabilities (i.e., Core Financial, Procurement, Asset Management and Business Intelligence). The Business Process Taxonomies is the next level requirement below the J-ORD. The Business Process Derived Requirements is the next level requirement below the Business Process Taxonomies.

5.1 FSM Joint Concept of Operations (CONOPS)

The FSM CONOPS articulates, at a high-level, the DHS financial management modernization approach. It builds on each Component’s legacy Mission Need Statements (MNS). The CONOPS describes how FSM solutions will support DHS components by facilitating standard business processes, improving financial reporting, and supporting DHS’s strategic vision for a financial management approach that complies with federal requirements. See Attachment B for all CONOPS and Operational Requirements.

5.3 FMSS Taxonomies and Requirements

Building toward the goal of business process standardization, Joint Program Management Office (JPMO) leadership and key stakeholders determined in September 2017 that the Department of Homeland Security (DHS) Financial Systems Modernization (FSM) initiative should have an enterprise-wide taxonomy, utilized by all Components, encompassing the business processes that support the DHS core financial management capabilities (i.e., Core Financial, Procurement, Asset Management and Business Intelligence). See Attachment C for all FMSS Taxonomies and Requirements.

5.4 FMSS Standard Business Process Derived Requirements

The nine business processes in FMSS include Budget Formulation to Execution, Record to Report, Request to Procure, Procure to Pay, Bill to Collect, Reimbursable Management, Acquire to Dispose, Business Intelligence and Decision Support Reporting and Cost Management. See Attachment D for all FMSS Standard Business Process Derived Requirements.

5.5 Non-Functional Requirements

5.5.1 Security

The management of security including documentation for all applications and environments shall be in accordance with NIST, DHS Policy Directive 4300A and 4300B and in conjunction with the DHS Information Security Office (ISO) and the DoDI 8510 – Risk Management Framework (RMF) for DoD Information Technology (IT). DHS Policy 4300.A – Information Assurance (IA) shall be considered a requirement for all systems used to enter, process, store, display or transit sensitive or national security information. IA shall be achieved through the acquisition and appropriate implementation of evaluated or validated commercial-off-the-shelf (COTS) IA and IA-enabled IT products. These products shall provide for the availability of systems. The products also shall ensure the integrity and confidentiality of information and the authentication and non-repudiation of parties in electronic transactions.

The Contractor shall provide any and all documentation to the IA team as required to ensure the EFiMS application software suite does not pose security threats or IA issues to installation into Government data centers. It is the responsibility of the Contractor to ensure that all software enhancements and maintenance activities, provided for under this contract and all task orders are compliance with DHS Information Security Policy, DHS 4300 as implemented by DHS MD 4300A Sensitive Systems Handbook or National Security Systems Policy Directive 4300B.

The software suite shall be configurable to support the ability to obtain Authority to Operate (ATO). The specific FISMA level (Low, Medium, High) support required will be defined by the component during their Fair Opportunity process. The EFiMS shall be designated as “Sensitive but Unclassified” (SBU) and is subject to DHS Management Directive (MD) 11042.1 Safeguarding SBU

The following federal NIST security standards are also applicable:

1. NIST 800-53 Rev 4. Security and Privacy Controls for Federal Information Systems and Organizations. https://nvd.nist.gov/800-53 https://nvd.nist.gov/800-53

2. NIST 800-95 Guide to Securing Web Services.

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf

3. NIST Special Publications 800-37, 800-53r4

Any future or current cloud based components of the EFiMS suite shall be Federal Risk and Authorization Management Program (FedRAMP) certified. FedRAMP requirements can be found at the following link:

1. https://www.fedramp.gov/

5.5.2 Identity and Access Management (IAM)

IAM is the security that enables the right individuals to access the right resources at the right times and for the right reasons. The software suite proposed must support IAM requirements.

The following requirements shall be met for IAM:

• Role-based access control (RBAC)

• Support DHS Single Sign-on/Personal Identity Verification (SSO/PIV) card access.

• User authentication and authorization of access to function components of the software suite

• Security Incident response

• Audit and accountability: track user access to software suite and its functional components

5.5.3 Data Management and Data Integrity

All software proposed for EFiMS shall have the capability for internal verification and audit procedures to ensure that the data, including financial and inventory data, is complete and correct. The software suite shall support the six demotions of data quality:

• COMPLETENESS

o The proportion of stored data against the potential of "100% complete"

• UNIQUENESS

o An event or entity will be not be recorded more than once based upon exclusivity identified.

• TIMELINESS

o The degree to which data represent temporal event

• VALIDITY/CONFORMITY

o Data must conform to the syntax (format, type, range) of its definition.

• ACCURACY

o Data must correctly represent the event or entity being captured

• CONSISTENCY

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf o Standardization when comparing two or more similar categorizations of an event or entity thing against standard system definition.

The vendor shall maintain, publish, and provide the Government with data architectures, physical data models, data dictionaries, and Application Program Interface (API) designs or data structures for the COTS product. The vendor shall maintain and provide to the Government an inventory, summarization and documentation of each interface specification to include API(s) that are corporately developed or included with the application provider’s packaged software.

The information provided will be used by the Government and/or Government support contractors to migrate data from legacy systems to the new software solution, create reports, extract data for validation routines, etc.

In addition, any contractor developed, customized code created and paid for by the Government shall be considered Government property and shall be made available for review by the COR or other designated staff at any time, and shall be furnished to the Government as directed by the Contracting Officer Representative (COR), the Contracting Officer (CO) or other designated staff. All deliverables (e.g. monthly reports, weekly reports, SDLC artifacts – requirements, design, installation, test documents, etc.) developed under this contract or under task orders associated with this contract shall be considered Government property and shall be delivered with unlimited data rights. It is the intent of this effort to maintain Government ownership of all extracted/migrated data and related documentation and that any existing proprietary information concerning the COTS product be converted or shielded such that any software tools provided may be freely used by all DHS and DHS components.

The EFiMS COTS software shall provide the capability to mask or obfuscate data on production and non-production environments.

The EFiMS COTS software shall provide the capability to encrypt data or the database.

5.5.4 Data Exchange

The software suite shall provide the ability to import and export data in an open, standard-based nonproprietary format. The COTS product shall be capable to interface with external systems, other COTS products, etc. using open application interfaces and standard data exchanges.

5.5.5 Section 508 Compliance Requirements

Pursuant to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C 794d) as amended by P.L.

105-220 under Title IV (Rehabilitation Act Amendments of 1998) All Electronics and Information Technology (EIT) products and services, developed, procured, maintained and/or used under this contract shall fully comply with the “Electronic and Information Technology Accessibility Standards” set forth by the Architecture and Transportation Barriers Compliance

Board (also referred to as the “Access Board”) in 36 CFR Part 1194. The Complete text of Section 508 standards can be accessed at (www.access-board.gov) or at (www.section508.gov)

5.5.6 Product Support

The software vendor shall provide product support via email, phone, web, and chat to address issues relating to software installation, configuration, software updates, bug tracking and fixes. In addition the solution vendor shall provide user and administrative documentation (electronic via files and also online) for the proposed EFiMS software.

5.6 System Requirements

The software vendor shall provide details on recommended minimum system requirements for the software suite based on number of users described in Table for each DHS component.

5.7 Software Configuration and Implementation

The COTS software product shall provide the ability to:

• To be widely supported by market leaders/vendors such that DHS can acquire contract support for Integration(s) and operations and maintenance.

● Fully integrated and interoperable financial, asset management, and procurement management Commercial Off the Shelf (COTS) integrated software application suite

● Integrated with Business Intelligence

● Logging/audit tracking including tracking user action

● Industry standards based open interfaces and data exchange

● Compliant with NIST and DHS Chief Information Security Officer (CISO) Standards

● Out-of-the-Box software solution with easy configurability that avoids custom software development

● Supports an automated path to migrate to the cloud

● Secure and scalable Software suite

● Role based Access Control

● Single Sign On functionality

● Support business processes related to financial management, Asset Management and

Contract Management across DHS and its components

● Allow Automatic, timely and accurate reporting

● Interoperate with internal and external systems using open application programming interface (APIs) standards to exchange information with external systems

● Interface with external systems as required by federal initiatives

● Ability to export/import data in industry standard formats using service oriented architect methodologies

● Allow data to be loaded from external sources and ensure data integrity, validation, and ability to transact using loaded data.

http://www.access-board.gov/

5.8 License / Subscription management

The COTS vendor shall describe their license/subscription services for

● Integrated financial, procurement, and asset management software licenses

● COTS software required by support teams to perform the following functions:

1 Data warehouse and consolidation,

2. High Availability,

3. Security,

4. Unstructured Data Management,

5. Embedded and Open Source Databases,

6. Data Integration,

7. Portals and Composite Applications,

8. Content Management,

9. Service Oriented and Event Driven Architecture,

10. Governance,

11. Business Process Analysis & Management,

12. Application Integration,

13. Access Management,

14. Directory Services,

15. Core Fusion Middleware Services,

16. Web Tier/Web Development Tools,

17. Business Intelligence,

18. Database Tools/Development Tools,

19. Database Management,

20. Application Management,

21. Middleware Management,

22. Systems Maintenance,

23. Application Quality Management,

24. Training Type Applications, Maintenance on the COTS Software (O&M).

25. Any other function that the COTS vendor believes will support the Government effort

• Maintenance Cost for the Licenses (O&M)

The description shall include at a minimum the following information:

• The License Name

• The License Description

• What the License supports (functions/technology)

• Licensing Metrics – Application User, Unlimited License, Perpetual, Server, Processor, etc.

• Technology/Business Solution

• Functionality – Full, Read Only, Limited, unlimited license agreement (ULA), etc

• License cost structure – Initial cost per license, yearly maintenance cost, etc.

Vendors shall provide technical refreshes to the list of products/licenses addressed in this section quarterly. The vendor should address how often they expect to do a technical refresh of the list provided to the Government. The technical refresh shall capture additional products that may change or be new products, updates to product pricing, obsolete products.

5.8.1 License Transfer Requirement

The COTS software vendor shall provide information on the following transfer requirements:

• Transfer user, unlimited license agreement (ULA), perpetual, licenses within DHS when requested at no additional cost to DHS

• Upgrade current licenses to the latest version at no additional cost to DHS

• Provide licenses for software testing at no additional cost to DHS

• Transfer of purchased licenses to a DHS SaaS or off-premise hosting at no additional cost to DHS

• Licenses purchased by any component shall be transferable to DHS and its other components.

5.8.2 Current User Information

Vendor shall support DHS license usage levels in the following table, as a minimum:

Component User Summary

DNDO TSA USCG ICE S&T NPPD CIS DMO FEMA FLETC USSS

Financial 105 1658 2425 1360 284 509 720 169 1300 256 6500 Procurement 15 153 9960 276 200 243 100 311 325 50 0 Budget 0 9 285 0 75 354 100 198 210 17 0 Asset Mgmt 22 403 1175 967 150 125 732 82 800 192 0 Total 142 2223 13845 2623 709 1231 1652 760 2635 515 6500

5.9 Technical Support and Software Maintenance

Software maintenance refers to the set of activities that are performed to keep the sytem operational as software changes after the system has been fielded. Software maintenance begins as soon as a system has been released to users for the first time. A COTS Life-Cycle Management Plan must address the following maintenance requirements to include:

• Corrective maintenance: reactive modification (or repairs) of a software product performed after delivery to correct discovered problems. Included in this category is emergency maintenance, which is an unscheduled modification performed to temporarily keep a software product operational pending corrective maintenance.

• Adaptive maintenance: modification of a software product performed after delivery to keep a software product usable in a changed or changing environment. For example, the operating system might be upgraded and some changes to the software may be necessary.

• Perfective maintenance: modification of a software product after delivery to provide enhancements for users, improvement of program documentation, and recoding to improve software performance, maintainability, or other software attributes.

• Preventive maintenance: modification of a software product after delivery to detect and correct latent faults in the software product before they become operational faults

5.9.1 License Management: Tracking and Usage Reporting

The software suite shall include a secure web-based tool for license management. The secure web-based tool shall allow DHS to:

• View current inventory of licenses and associated maintenance costs.

• Provide component level view by enrollment number that shows all component license activity, training, and consulting services.

• Provide a mechanism for purchasing products, services, and training while providing up to date status.

• View all available transfer requests and up to date status

• Create dynamic customized reports.

5.10 Transition

5.10.1 Transition of Licenses across data centers

The COTS software product proposed by the vendor shall have the capability to transfer the software between data centers with no additional cost to the Government to support Disaster Recovery requirements, testing, development etc.

5.10.2 Transition of Licenses to Cloud Environment from Data Center

The vendor shall propose a methodology to transition applications and licenses from DHS HQ and component agency equipment to a cloud environment when DHS determines that it is ready and able to make such a move, and that the cloud environment can support all required functionality,

5.10.3 Transition Out

The software suite proposed by vendor shall have the capability of easy transfer of configuration files and data from one environment to another.

5.11 Professional Services Requirements -

The software suite vendor shall provide Tier 3 level support the following services requirements:

● Installation of Software suite

● Configuration of Software suite

● Data Migration

● Initial Setup & Training

● Planning Support to Configure and Install the Software suite

5.12 Deliverables

The vendor shall deliver the following documents in a form and on a schedule to be specified after contract award:

• Weekly progress report

• Software configuration requirements and installation schedule for DHS HQ and each component agency

• Results of acceptance tests for each software installation

• Transition plan and schedule for DHS HQ and each component agency

• COTS Software product logical data model for the software suite.

• Software suite documentation (User guide, software installation guide, API guide)

5.13 Policies, Standards, and Regulations

The following is a list of policies, standards, guidance and regulations that the COTS software products as described in this SOW shall comply with.

Federal Legislation

• Chief Financial Officers Act of 1990

• Federal Financial Management Improvement Act of 1996 (FFMIA)

• Federal Information Security Management Act (FISMA) 2002

• Federal Managers’ Financial Integrity Act (FMFIA) of 1982

• Digital Accountability and Transparency Act (DATA Act) of 2014

• Government Performance and Results Modernization Act (GPRA) of 2010

• Government Management and Reform Act of 1994

• The Privacy Act of 1974

• Rehabilitation Act of 1973, in particular Section 508 compliance

• Homeland Security Act of 2002

• Homeland Security Financial Accountability Act of 2004

• DHS Audit Requirement Target Act of 2012

Federal Standards and Guidance:

• Federal Accounting Standards Advisory Board (FASAB) Handbook, June 30, 2017

• Federal Acquisition Regulation (FAR)

• Federal Information Systems Controls Audit Manual (FISCAM), February 2009

• Federal Risk and Authorization Management Program (FedRAMP) Guidance

• FedRAMP Certification. https://www.fedramp.gov/

• OMB Circular A-11, Preparation, Submission. Execution of the Budget

• NIST Special Publications 800 Series

• NIST Federal Information Process Standards (FIPS) 200, Minimum Security

Requirements for Federal Information and Information Systems, March 2006

• Department of the Treasury Financial Manual (TFM)

• Treasury Financial Manual. https://tfm.fiscal.treasury.gov/v1/p6/c950.html

OMB Memoranda and Circulars:

• OMB Circular A-123, Management’s Responsibility for Internal Control

• OMB Circular A-127, Financial Management Systems

• OMB Circular A-130, Management of Federal Information Resources

• OMB Circular A-136, Financial Reporting Requirements

• OMB Memorandum M-10-06, Open Government Directive

• OMB Common Approach to Federal Enterprise Architecture

• OMB 25 Point Implementation Plan to Reform Federal Information Technology

Management

• OMB Memorandum M-09-32, Updated on the Trusted Internet Connection Initiative

• OMB Memorandum M-08-27, Guidance for Trusted Internet Connection (TIC)

• OMB Memorandum M-10-26, Immediate Review of Financial Systems IT Projects

• OMB Memorandum 13-08, Improving Financial Systems Through Shared Services

• OMB 25 Point Implementation Plan To Reform Federal Information Technology

Management, 9 December 2010

• OMB Common Approach to Federal Enterprise Architecture, 2 May 2012

• Statement of Federal Financial Accounting Standards Number 4 (SFFAS 4)

DHS Directive, Policies and Guidance

• DHS Quadrennial Homeland Security Review (QHSR)

• DHS Strategic Plan (Fiscal Years 2014-2018), February 2014

• DHS CFO Strategic Plan FY2017-2021

• DHS Common Appropriation Structure

• DHS ACS Guidebook

• DHS CFO Financial Management Policy Manual (FMPM) https://www.fedramp.gov/ https://tfm.fiscal.treasury.gov/v1/p6/c950.html https://tfm.fiscal.treasury.gov/v1/p6/c950.html

• DHS Binding Operational Directive 16-03 Agency Cybersecurity Reporting Requirement

• DHS Policy Directive 034-03 Continuous Improvement of DHS Cyber Defenses

• Homeland Security System Directive 101-01, Planning, Programming, Budgeting, and

Execution

• Homeland Security Acquisition Directive 102-01, Acquisition Management

• Homeland Security Acquisition Instruction/Guidebook 102-01-001

• Homeland Security Acquisition Directive 102-02, Capital Planning and Investment

Control

• Homeland Security Management Directive 103-01 Enterprise Data Management Plan

Policy

• Homeland Security System Directive 140-01, Information Technology Systems Security

• Homeland Security System Directive 141-01, Records and Information Management

• Homeland Security System Directive 262093, DHS Information Sharing Environment

Technology

• Homeland Security System Directive 262-05, Information Sharing and Safeguarding

• Homeland Security Management Directive 4010.2: Section 508 Program Management

Office & Electronic and Information Technology Accessibility

• Homeland Security Management Directive 4200, IT Capital Planning and Investmetn

Control Portfolio Management

• Homeland Security Management Directive 4300, IT System Security and Publications

• DHS MD 4300A: “Sensitive Systems Policy” March 14, 2011

• DHS MD 140-01: Information Technology Security Services, July 31, 2007

• DHS MD 9300.1: Continuity of Operations Program s and Continuity of Government

Functions

• DHS TIC Reference Architecture, September 1, 2011

DHS FSM Guidance:

• DHS Financial System Modernization Roadmap, October 2018

• DHS Financial Management Systems Standards (FMSS)

Federal Regulations

The following Federal Mandates/Regulations apply to the EFiMS software suite:

• NIST SP 800-144, Guidelines on Security and Privacy in Public Cloud Computing

• NIST SP 800-145, NIST Definition of Cloud Computing

• NIST SP 800-146, Cloud Computing Synopsis and Recommendations

• NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal

Information Systems

• NIST SP 800-53, Recommended Security Controls for Federal Information Systems and Organizations

• NIST SP 800-53A, Guide for Assessing the Security Controls in Federal Information Systems and Organizations

• NIST 800-53 Rev 4. Security and Privacy Controls for Federal Information Systems and Organizations. https://nvd.nist.gov/800-53

• NIST 800-95 Guide to Securing Web Services.

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf

• FIPS PUB 200. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf

• FIPS 140-2 Security Requirements for Cryptographic Modules

• Office of Federal Financial Management (OFFM), Core Financial System Requirements, OFFM-NO-0106, January 2006

• Office of Management and Budget (OMB) Circular No. A-11, Preparation, Submission, and Execution of the Budget

• Treasury U.S. Standard General Ledger (USSGL)

6 KEY PERSONNEL

For all task orders issues under EFiMS, the Contractor shall provide qualified personnel to perform work as defined in the task order. The Contractor shall provide appropriately trained personnel and shall be responsible to ensure that necessary certifications are kept up-to-date in relevant areas.

https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-95.pdf https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.200.pdf

ATTACHMENT A: TREASURY FINANCIAL MANAGEMENT USE CASES

Treasury Office of Financial Innovation and Transformation (FIT) is the Line of Business (LoB) Managing Partner for the Federal Financial Management (FFM) service area. FIT developed 42 FFM business use cases in 2017 which reflects the business needs of the FM service customers.

The use cases were reviewed by financial management representatives from across the Federal Government and are intended to be broad enough to apply Federal Government-wide. The use cases are reviewed and updated annually by FIT, refer to the Treasury FIT website for the latest version https://www.fiscal.treasury.gov/fsservices/gov/fit/fit_usecase.htm.

Treasury developed a list of end to end business processes in order to organize the FFM user cases. Treasury’s business processes are similar to DHS but there are minor differences. Table 22 shows a cross-walk between Treasury and DHS business processes.

Treasury Business Process DHS Business Process Budget Formulation to Execution Budget Formulation to Execution Acquire to Dispose Acquire to Dispose Request to Procure Request to Procure Procure to Pay Procure to Pay Bill to Collect Bill to Collect Record to Report Record to Report Agree to Reimburse Reimbursable Management Hire to Retire N/A – Payroll covered in Record to Report Book to Reimburse (Travel) N/A – Travel covered in Request to Procure and Procure to Pay N/A Cost Management N/A Business Intelligence

Each use case may cover multiple business scenarios. The following tables list Treasury user cases aligned to the DHS business processes.

DHS & Treasury Process: Budget Formulation to Execution Service Area(s): Budget Formulation (BFM); Financial Management (FFM) Business Use Cases and Associated Business Scenario(s) 010.FFM.L1.01 Budget Authority Set-Up

• Funds Control at Appropriation, Apportionment, Allotment, Allocation, Sub-allocation 1, and Sub-allocation 2 Levels.

• Accounting Segments of Treasury Account Symbol/Fund, Organization, Program, Project, and Activity

• Discretionary Appropriated Funds

• Single Year, Multi-Year and No-Year Appropriations

• Program Allocation Exceeding Organization Allotment

010.FFM.L1.02 Spending Authority from Offsetting Collections (Reimbursables)

• Reimbursable Authority https://www.fiscal.treasury.gov/fsservices/gov/fit/fit_usecase.htm

DHS & Treasury Process: Budget Formulation to Execution Service Area(s): Budget Formulation (BFM); Financial Management (FFM) Business Use Cases and Associated Business Scenario(s)

• Revolving Funds

010.FFM.L1.03 Budget Authority Transfers

• Appropriation Transfers

• Non-Expenditure Transfers

010.FFM.L3.01 Special Authorities

• Spending Authority from Offsetting Collections (e.g., Donation Revenues, Reimbursable

Revenues)

• Special Limitations from Budget Formulation

• Direct and Guaranteed Loan Authority

• Contract Authority

010.FFM.L1.04 Continuing Resolution

• Continuing Resolution

DHS & Treasury Process: Acquire to Dispose Service Area(s): Acquisition (ACQ); Financial Management (FFM) Business Use Cases and Associated Business Scenario(s) 020.FFM.L1.01 Property, Plan, and Equipment (PP&E) Assets

• Acquiring a PP&E Asset

• Leasing a PP&E Asset

• Depreciation of a PP&E Asset

• Disposing of a PP&E Asset

• Replacing an Asset

020.FFM.L2.01 Complex Systems

• Complex Systems

• Internal Use Software

• Work in Progress

• Increase Life and Value of Asset

• Enhancing an Asset

• General PP&E

020.FFM.L3.01 Real Property: Stewardship Land, Heritage Assets, Construction, and Impairment

• Heritage Assets

• Stewardship Land

• Construction in Progress

• Capitalization of Labor Costs

• Environmental Hazardous Substances on/in Property

• Impairment

• Construction in Abeyance

DHS & Treasury Process: Acquire to Dispose Service Area(s): Acquisition (ACQ); Financial Management (FFM) Business Use Cases and Associated Business Scenario(s)

020.FFM.L2.02 Leasehold Improvements

• Leasehold Improvement

020.FFM.L1.03 Bulk Purchase Immediately Distributed

• Bulk Purchase Immediately Distributed

DHS & Treasury Process: Request to Procure

Business Use Cases and Associated Business Scenario(s) 030.FFM.L1.01 Procurement Within a Single Fiscal Year

• Single Year Funds

030.FFM.L2.01 Procurement Across Fiscal Years Using Multi-Year Funds

• Multi-Year Funds

• Multiple Funding Sources

• Multiple Vendors on a Procurement Request

030.FFM.L2.02 Single Award from Multiple Procurement Requests

• Single Award from Multiple Procurement Requests

030.FFM.L1.02 Procurement During Continuing Resolution

• Procurement During a Continuing Resolution on Procurement

020.FFM.L1.03 Bulk Purchase Immediately Distributed

• Bulk Purchase Immediately Distributed

DHS & Treasury Process: Procure to Pay

Business Use Cases and Associated Business Scenario(s) 040.FFM.L1.01 Expenditures Within a Single Fiscal Year

• Invoice into FM Solution

• Three-Way Match

040.FFM.L2.01 Expenditures Across Fiscal Years Using Multi-Year Funds with Invoicing Options

• Multi-Year Funds Expenditure

• Multiple Funding Sources

• Receiving Report Accrual

• Credit Memo

• Vendor Submit Paper Invoice

• Vendor Submits to Program Office

• Two-Way Matching

DHS & Treasury Process: Procure to Pay Service Area(s): Acquisition (ACQ); Financial Management (FFM) Business Use Cases and Associated Business Scenario(s)

• Progress Payment

• Final Payment

040.FFM.L2.02 Four-Way Match

• Four-Way Matching

• Prompt Payment

040.FFM.L2.03 Purchase Card

• Purchase Card

• Non-Matching

• PCard Purchase of Operating Materials and Supplies

040.FFM.L1.02 Leased Property

• Operating Lease

• Capital Lease

040.FFM.L1.03 Acquiring Services

• Acquiring Services

040.FFM.L2.04 Novation

• Novation

DHS & Treasury Process: Request to Procure and Procure to Pay/Treasury Process: Book to Reimburse (Travel) Service Area(s): Financial Management (FFM); Human Resources Management (HRM);

Travel and Relocation Management (TRF) Business Use Cases and Associated Business Scenario(s) 100.FFM.L1.01 Temporary Duty (TDY) Travel

• TDY Travel

• Travel Card

• Split Disbursement

100.FFM.L2.01 Permanent Change of Station (PCS)

• Relocation

• Supplemental PCS Voucher

• Advance on Account

100.FFM.L3.01 Travel Sponsored by Non-Government Source

• Travel Sponsored by Non-Government Sources

• Non-Government Source Payment In-Kind

DHS & Treasury Process: Bill to Collect Service Area(s): Financial Management (FFM); Sales Order and Fulfillment Management

(SFM)

Business Use Cases and Associated Business Scenario(s) 050.FFM.L1.01 Penalties, Interest, and Collections

• Individual Receivable

• Disputes

• Credit Memo

• Penalties, Interest, and Administrative Fees

• Collectable by Agency

• Non-Treasury Deposits

050.FFM.L1.02 Delinquent Debt Processing

• Insufficient Funds on Debtor’s Payment

• Referral To Treasury

• Delinquent Collection and Write-off

050.FFM.L3.01 Aggregated Receivables for Custodial Revenues

• Unbilled Collections

• Aggregated Receivables

• Custodial Revenues

050.FFM.L3.02 Receivable Collection from Third Party Debtor

• Receivables Allocated Among Multiple Payers

• Third Party Payers as Responsible Debtors

• Installment Agreement

050.FFM.L3.03 Miscellaneous Receipts

• Miscellaneous Receipts

050.FFM.L2.01 AR/AP Netting

• AR/AP Netting

DHS & Treasury Process: Record to Report Service Area(s): Financial Management (FFM); Property Management (PRM) Business Use Cases and Associated Business Scenario(s) 060.FFM.L1.01 Period End Adjustments and Reporting

• Audit Adjustments

• Allowance for Uncollectable Amounts

• Financial Statements

060.FFM.L2.01 Consolidated Financial Statements

• Liabilities Not Covered by Budgetary Resources

• Liabilities Arising from…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.