2B_Performance_Work_Statement_-_SEVIS_-_MNII_v0.8.docx

DOCX document 557 KB Posted

Attached to
FBO FLASH UPDATE- Reconsideration Federal contract opportunity
Solicitation number
DHS-AGILE-00001
Issued by
Department of Homeland Security Office of Procurement Operations

About this file

2B Performance Work Statement

View the file

Other files for this federal contract opportunity

Other files attached to FBO FLASH UPDATE- Reconsideration, newest first.
File Type Posted
FBO_FLASH_Notice_of_Awardees_11-28.pdf PDF
Attachment_2A_SEVIS_Manage_Nonimmigrant_Letter_to_Offerors.pdf PDF
Additional_Questions_081516.docx DOCX document
Additional_Questions_081516.docx DOCX document
FLASH_RFP_Q As.pdf PDF
Corrected_Attachment_4_Pricing_Template-FLASH.xlsx XLSX spreadsheet
Corrected_Attachment_4_Pricing_Template-FLASH.xlsx XLSX spreadsheet
FLASH_RFP_Q As.pdf PDF
2A_Initial_Task_Order_Letter_to_Offerors_8_8_16.docx DOCX document
AGILE_RFP.pdf PDF
Attachment_4_Pricing_Template-FLASH_.xlsx XLSX spreadsheet
Industry_Questions.docx DOCX document
FLASH_RFP_Q A's.xlsx XLSX spreadsheet
Copy_of_Attachment_3_-_FLASH_Past_Performance_Questionnaire_v1.xlsx XLSX spreadsheet
Attachment_2B_-_Initial_Task_Order_PWS.pdf PDF
FLASH_RFP_No__HSHQDC-16-R-00118.pdf PDF
Attachment_5_-_Challenge_Exercise_Attendees_List.xlsx XLSX spreadsheet
Attachment_3_-_FLASH_Past_Performance_Questionnaire.xlsx XLSX spreadsheet
Attachment_2A_-_Initial_Task_Order_Solicitation_for_U.S._ICE_Letter_to_Offerors.pdf PDF
Attachment_4_-FLASH_Pricing_Template.xlsx XLSX spreadsheet
Attachment_6_-_Frequently_Asked_Questions.pdf PDF
Attachment_3_-_Past_Performance_Questionnaire.pdf PDF
Attachment_4_-FLASH_Pricing_Template_071916.xlsx XLSX spreadsheet
Attachment_5_-_Challenge_Exercise_Attendees_List.xlsx XLSX spreadsheet
Draft_FLASH_RFP_07192016.pdf PDF
DHS_Amendment_4_Attachment.pdf PDF
DHS_FLASH_Industry_Day_List_of_Registrants.xlsx XLSX spreadsheet
DHS_FLASH_Industry_Day_Slides.pptx PPTX presentation
RFI_Responses_To__Industry_Questions.xlsx XLSX spreadsheet
FLASH_Industry_Day_Location_Announcement.pdf PDF
FLASH_Registration_Form.xlsx XLSX spreadsheet
FLASH_Industry_Day_Announcement.pdf PDF
FLASH_Video_Submission_Instructions.pdf PDF
Attachment_C_-_Draft_Government_Feedback_Video_Instructions.pdf PDF
Attachment_A_-_Draft_Scope_-_DHS_Agile_Design_and_Development_Support.pdf PDF
Attachment_B_-_Draft_Proposed_Technical_Evaluation_-_Instructions_and_Criteria.pdf PDF
Attachment_D_-_Draft_Agile_Pricing_Methodology.pdf PDF
Show all 37

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

U.S. Immigration and Customs Enforcement (ICE) Office of the Chief Information Officer (OCIO)

April 2016

Performance Work Statement Student Exchange Visitor Information System Manage Nonimmigrant Information Procurement Sensitive

Table of Contents

C.1Project Title2
C.2Background2
C.3Scope of Work2
C.4Overview3
C.4.1SEVIS Manage Nonimmigrant Information To-Be Technology Overview9
C.4.2SEVIS Information Sharing To-Be Environments Overview9
C.5Applicable Publications10
C.6Tasks10
C.6.1Design, Develop, Test and Maintain the SEVIS Modernization Manage Nonimmigrant Information Module10
C.6.1.1Software Development Processes and Tools11
C.6.1.2Tier 3 Support12
C.6.2Transition13
C.6.3Disposition13
C.6.4Create/Edit System Lifecycle Management (SLM) Documentation14
C.7Deliverables14
C.7.1Weekly Status Report14
C.7.2Quality Control Plan (QCP) and Quality Assurance Surveillance Plan (QASP)15
C.7.3Configuration Management16
C.7.4Transition-Out Plan16
C.7.5Written Acceptance/Rejection by the Government16
C.7.6Non-Conforming Products or Services16
C.7.7Notice Regarding Late Delivery16
C.8General Requirements17
C.8.1Period of Performance17
C.8.2Place of Performance17
C.8.3Hours of Operations17
C.8.4Non-Personal Services17
C.8.5Business Relations17
C.8.6Contract Management18
C.8.7Contract Administration18
C.8.8Subcontract Management18
C.8.9Organizational Conflict of Interest (OCI)18
C.8.10Invoicing18
C.8.11Other Direct Costs (Optional)18
C.8.12Contractor Acquired Property18
C.8.13Government Furnished Equipment (GFE)/ Government Furnished Property (GFP)19
C.8.14Government Furnished Information (GFI)19
C.9DHS Enterprise Architecture Compliance19
C.10Security20
C.10.1Preliminary Determination20
C.10.2Background Investigations20
C.10.3Transfers from Other DHS Contracts:21
C.10.4Continued Eligibility22
C.10.5Required Reports22
C.10.6Employment Eligibility22
C.10.7Security Management23
C.10.8Information Technology23
C.10.9Information Technology Training and Oversight24
C.11Contract Clauses24
C.12Section 508 Compliance40
C.12.1Accessibility Requirements (Section 508)40
C.12.2Section 508 Applicable Exceptions41
C.12.3Section 508 Compliance Requirements41
C.12.4Section 508 Testing Requirements41
C.13Key Personnel41
C.14Contractor Employee Access43
Attachment A: List of Acronyms45

ICE OCIO SEVIS Manage Nonimmigrant Information PWS

- Page ii -

PROCUREMENT SENSITIVE INFORMATION

DESCRIPTION/SPECS/WORK STATEMENT

Project Title Student and Exchange Visitor Information System (SEVIS) Manage Nonimmigrant Information.

Background The Student and Exchange Visitor Program (SEVP) was established as part of the Homeland Security Investigations (HSI) National Security Investigations Division (NSID) within Immigration and Customs Enforcement (ICE). SEVP is responsible for delivering SEVIS – an Internet-based application that facilitates timely electronic reporting and monitoring of international students and exchange visitors (EVs) and their dependents in the United States. Student and Exchange Visitor Information System (SEVIS) enables schools and exchange programs to transmit electronic information to the Department of Homeland Security (DHS) and the Department of State (DoS) throughout a student’s or EV’s program in the United States. SEVIS improves customer service by streamlining the application and adjudication processes. It also addresses deficiencies in the current student and schools system process by providing information technology solutions and modifying business processes.

SEVIS allows schools to submit school certification applications, update certification information, submit updates to the DHS that require adjudication, and create and update F-1 (academic) as well as M-1 (vocational) student and dependent records. DHS Managers and Adjudicators have the capability to adjudicate updates made to school records using SEVIS, and Principal Designated School Officials (PDSO) and Designated School Officials (DSO) are notified through SEVIS of the adjudication results.

SEVIS also allows EV program sponsors to submit certifications form for J-1 visa programs, creating program designations, and updating program designation information. DoS personnel have the capability to adjudicate information submitted by Responsible Officers (RO) and Alternate Responsible Officers (ARO). ROs and AROs are notified through SEVIS of any adjudication results.

SEVIS shares information with other systems to better monitor the status of a student or EV throughout their stay in the United States. This allows SEVIS to meet requirements of the Unifying and Strengthening America by Providing Appropriate Tools Required to Intercept and Obstruct Terrorism (USA PATRIOT) Act (Public Law 107-56 passed on October 26, 2001). Among other things, the PATRIOT Act stated that for each nonimmigrant for whom information is collected under the IIRIRA Section 641, the Attorney General, in consultation with the Secretary of State, will include information on the date of entry and Port of Entry (POE).

Scope of Work The scope of work for this effort provides SEVP with Design, Development, and Operations and Maintenance (O&M) support for the SEVIS Manage Nonimmigrant module, a component of the SEVIS Modernization effort. This support includes processes, procedures, people, material, and information required to deliver, support, operate, and maintain the software aspects of the system. It also includes, as required, modifying the software system or component after delivery to correct faults; improving performance or other attributes; adapting to a changed environment or maintenance activities focused on anticipated problems; and performing preventative maintenance to support a continuously operating and reliable, stable, and secure application.

The Contractor shall be aware that the Government and other contractors are engaged in similar and supporting work, requiring close cooperation. Contractors are expected to form a cohesive team with all OCIO and SEVP team members to include the Government and other contractors, by fostering transparency and information sharing for successful task execution.

It is the Government’s intention to continually pursue improvements to processes and practices, which will result in meeting mission requirements at the lowest possible cost. The contractor is expected to partner with the government to support this goal by actively studying existing processes and making recommendations for improvements.

Overview The Manage Nonimmigrant module will provide school and program officials, as well as government users with the functionality to manage the data and processes required for a nonimmigrant’s participation in the student and exchange visitor program.

Figure 1. Business and System Capabilities Overview The following business capabilities represent the business level functionality to be delivered as a part of the Manage Nonimmigrant Information module. These capabilities combine to allow the system to show the nonimmigrant’s immigration status, the relationship(s) with schools and programs, certificates of eligibility with the status of the certificate, and the details of status-related activities. Schools and programs must be able to use the real time interface or the batch process in order to report the information needed to manage nonimmigrant information.

Table 1 – Business Capabilities

Business Capability
Description
Create nonimmigrant record
A designated program or certified school creates a Certificate of Eligibility (COE) with detailed information on the nonimmigrant when the program/school finds the nonimmigrant eligible to participate in a program. This creates a relationship with the program/school and details a program of study. The COE contains information on the person’s biographical details, contact/address information, financial information, and any nonimmigrant dependents.

Information that is already in SEVIS will be leveraged to create new certificates of eligibility. The system must be able to track the relationship between the nonimmigrant and the school/program. It must also be able to determine the status of the COE. COE information is also combined with other immigration information to determine the immigration status(es) of the individual nonimmigrant.

Currently school and program officials initiate the creation of a record. If the nonimmigrant is already in a period of status, SEVIS will populate some of the data from the existing record. If the nonimmigrant is starting a period of status, every institution that the nonimmigrant applies to creates a record. At some point in the modernization process, the capability to use person-centric information will be made available for creating a certification for a new period of status. This functionality will leverage the account created by a nonimmigrant (the contractor will not create the nonimmigrant account).

Approve reduced course load
There are some exceptions to the requirement that nonimmigrant students must take a full course load. These capabilities allow a school official to approve a reduced course load for those specific reasons. The capability includes managing eligibility for and the length of the reduction.
Update nonimmigrant biographical information
This capability allows updating of the nonimmigrant’s biographical information within the constraints imposed by the governing policies.

The system must also have the capability to automatically update this information based on business rules that look at information in the system and/or received through an interface.

Register/validate nonimmigrants and dependents
At the beginning of a program, the program official must validate that a nonimmigrant began their program by the required deadline. School officials must register the attendance of every student at the beginning of the program of study and every term. The validation/registration processes are key to monitoring status.
Update nonimmigrant program information
Each nonimmigrant has a program that serves as the basis for their intended activities within the United States. For all nonimmigrants this includes one or more CIP codes that indicate the area of interest/major, program start date, and program end date.

Other program information varies for exchange visitors based on their specific category.

For students it also includes the level of study.

The system must also have the capability to automatically update this information based on business rules that look at information in the system and/or received through an interface.

Report EV employment
Most Exchange Visitors (EV) are employed. Reporting requirements vary with the EV’s specific category but all must report site(s) of activity. Depending on the category, the employment reporting may contain a great deal of detail to include the purpose of the employment and details about the employers.
Align nonimmigrant information with unique nonimmigrant
Nonimmigrants may participate in multiple F, M, or J programs. A single individual may have multiple separate periods of status and the records on that individual must reflect the activities and school/program relationships during each period of status.

Currently the system tracks a person’s information through one period of status by SEVIS ID. Modernization will create the capability to associate information across SEVIS ID. It is important to continue to differentiate among periods of status when aligning the information.

Each current SEVIS record has only one status. When the record is person-centric, the person can have multiple records that are in active use.

The system must also have the capability to automatically update this information based on business rules that look at information in the system and/or received through an interface.

View student/EV lists based on criteria (including download)
In order to help schools and programs manage nonimmigrant reporting requirements, the system maintains lists and alerts. These provide information by activity, pending deadlines, status of the COE, benefit application status, etc. Currently list/alert functionality negatively impacts system performance. As part of the modernization, this capability needs to be enhanced to provide more meaningful information, ensure information is current information, allow customization, sorting/downloading, and other improvements while ensuring system responsiveness does not suffer.
Transfer nonimmigrant
Nonimmigrants can transfer to another school or program. There are very specific rules governing transfers based on the class of admission. Rules also vary by EV category. The current student transfer process must be completely reengineered. Currently the school where the student is attending initiates the transfer and the COE is created after the fact. This process must be changed so the school the student is transferring to must create the COE in order to initiate the transfer.
Submit correction request
Ensuring the information is SEVIS is correct requires the ability for a school/program to have the government correct a record. The errors may be due to a missed deadline, user error in completing an action, a system error, or failure of an interface to update correctly or on time. Officials must be able to request a correction or data fix, provide supporting evidence, and see the status of the request.
Request reinstatement of nonimmigrant
When a nonimmigrant falls out of status, they may apply to the government to be reinstated to that status. Officials must have the capability to recommend reinstatement and provide supporting COE information.
Recommend/authorize employment for nonimmigrant, including J-2 employment
Students may be eligible for certain types of employment. In some cases the school official can authorize the employment and in other cases, a school official may recommend employment and USCIS adjudicates the application. The system must have the capability to enforce eligibility rules and track employment information.

J-2 dependents may also apply to USCIS for employment and this information must be associated with their record.

Shorten/complete/extend nonimmigrant program
The system must provide school/program officials the ability to change the program within the regulatory guidelines. The system must have the capability to enforce the business rules and update status related information based on the changes. The system must also provide the capability to extend a student program where the student is eligible based on a properly filed H1B that does not go into effect until after the student’s program would have normally completed. The system must also have the capability to automatically update this information based on business rules that look at information in the system and/or received through an interface.
Terminate nonimmigrant
When nonimmigrants do not comply with the rules governing their program of study, the nonimmigrant’s period of status must be terminated. The system must support the capability for officials to terminate the record or for the system to auto-terminate the record based on the business rules.
Report OPT participation/employer information
The system must allow all relevant parties to report on a student’s participation in Optional Practical Training (OPT), including details about the employer and the specific job.

The system must also have the capability to automatically update this information based on business rules that look at information in the system and/or received through an interface.

Add/update dependent information
Students and exchange visitors may be accompanied by a spouse and children. Officials must have the capability to update information on dependents. The system must also have the capability to automatically update this information based on business rules that look at information in the system and/or received through an interface.
Submit EV requests for DoS review
Certain activities/decisions about an EV program must be adjudication by Department of State (DoS). The system must have the capability to allow program officials to submit request that meet the business rules for that functionality.
Support analysis of nonimmigrant activities
To enable government users and school/program officials to understand and analyze nonimmigrant activities the system will provide the capability to show:

· Indicators/flags. Apply business rules and show when a record meets the criteria. Examples showing when a nonimmigrant has not paid a required fee, the nonimmigrant has post-completion OPT, etc.

· Event based history

· Time based history

· Counters that indicate the amount of time of elapsed between certain events or the number of times certain events occurred

· Eligibility/status indicators.

The following system capabilities represent the system functionalities required to implement the business capabilities as a part of the Manage Nonimmigrant Information module.

Table 2 – System Capabilities

System Capability
Description
Manage data via end user interface(s)
Generally representing the User Interface aspect of the system, applies to any interaction with an end user via a user interface.
Manage data via service interface (Batch)
Generally representing the Service Interface aspect of the system, applies to any interaction with an end user via a service interface.
Maintain user support via help system
Allows Help content to be deployed without a release. Does not require regression testing against system functionality to assure correct implementation
Communicate with users
Capability for Gov't users to communicate and exchange information (including documents) with non-Gov't users
Manage tasking, assignments, and scheduling
Capability for a supervisor to manage a workload by assigning tasks/workflow actions to users or groups based on how they manage their staff. Applies to Gov't and non-Gov't users.
Automate workflows and approvals
Capability to create, manage, and use workflows to implement business processes and enforce rules at the process/workflow level.
Apply business rules
Capability to create, manage, and use business rules that enable business processes and enforce rules at the data element(s) level.
Validate specific data elements (e.g., addresses)
Primarily address validation
Store information
Underlying database(s) to store system information. Separated into the entities whose data are managed
Manage and store documents
Document Management
Exchange data via service interfaces
System capability to share data with external systems (Other SEVP Systems, ICE Systems, Federal Partners, etc.) via system interfaces
Control access
Broad category covering authentication and authorization, role-based access control, account creation and management.
Resolve entities
System capability covering entity resolution which will apply to data migration and to business capabilities surrounding person centric capabilities. This will include the capability for a government user to manage the process of linking an additional record to an individual entity (for example, the information associated with a particular SEVIS ID) and the ability to remove the association.
Search
This capability represents explicit search actions taken by users, including both structured and unstructured searching, as well as supporting any other system capabilities or business capabilities requiring enabling search capabilities.
Provide reporting
Provides the system capability to report on stored data. Assumption is that there will be Gov't User reporting capabilities and non-Gov't user reporting capabilities.
Produce documents
Creation of documents, whether digital or on paper, whenever a signature or attestation is required, largely will support "paperless” and the processes needed to support non-repudiation of an electronic signature event.
Audit and report transactions and user activity
The capability to audit user activity, store the audit information, make the audit information available to consumers as necessary, and provide reporting on audit data as required.

The following diagram presents the system capabilities in an n-tier logical architecture.

Figure 2. System Capabilities Logical Architecture

SEVIS Manage Nonimmigrant Information To-Be Technology Overview The Manage Nonimmigrant module will be implemented using the following technology components:

· AWS EC2

· Docker

· ForgeRock

· Wildfly application server

· Spring Framework

· Mulesoft Anypoint Platform

· iText

· Smarty Streets

· Database

· SQL – AWS Aurora or PostgreSQL

· NoSQL – AWS DynamoDB or MongoDB

· Data Warehouse – AWS Redshift

· Search

· AWS Elasticsearch or Elastic

· Splunk

· Tableau

The government will provide all technology components. Additional technology components may be included in the implementation as needed to meet requirements. Decisions regarding the use of additional technology components will be made in collaboration among the government as well as other contractor teams.

SEVIS Information Sharing To-Be Environments Overview The SEVIS Manage Nonimmigrant Information application will be hosted in the SEVIS cloud infrastructure, hosted in AWS. This infrastructure will provide the following environments:

· Virtual Development Workstations

· Development Integration (DEV-INT)

· Functional Qualification Testing (FQT)

· Performance Testing (PERF)

· Staging (Pre-PROD)

· Production (PROD) Support for these environments is provided by the Government.

Applicable Publications The Contractor shall abide by all applicable Federal, DHS, and ICE laws, regulations, policies, standards, publications, manuals and procedures. Note that not all laws and regulations are listed below; the guidance listed provides ICE and/or DHS implementation policies and/or procedures for higher level guidance. If newer versions of these documents are officially released, the Contractor shall comply with the updated versions within the timeframe established by the Government.

· ICE Technical Architecture Guidebook

· ICE Technical Reference Model (TRM) (Standards Profile)

· ICE Enterprise Systems Assurance Plan

· ICE Agile Development Framework

· DHS Management Directive (MD) 4300.1, Information Technology Systems Security

· DHS 4300A Sensitive Systems Policy, Version 9.1, July 17, 2012

· DHS 4300B National Security Systems Policy, Version 8.0, December 27, 2010

· DHS Management Directive (MD) 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information, January 6, 2005

· ICE Management Directive (MD) 4003.1, Safeguarding Law Enforcement Sensitive Information, March 23, 2007

· ICE Management Directive (MD) 4001.1, Electronic and Information Technology and Accessibility, March 12 2009

· DHS Directive 047-01, Privacy Policy and Compliance, July 7, 2011

· The Government recommends that the Contractor use the Information Technology Infrastructure Library (ITIL) framework in the performance of this task

· DHS Memorandum: Class Deviation 15-01 from the Homeland of Security Acquisition Regulation: Safeguarding of Sensitive Information, March 9, 2015 Tasks The following sections (C.6.1 – C.6.4) describe the tasks that the Contractor shall perform.

Design, Develop, Test and Maintain the SEVIS Modernization Manage Nonimmigrant Information Module The contractor shall implement the SEVIS Manage Nonimmigrant Information module, as described in Section C.4. The module will integrate with existing SEVIS and with the application modules developed as a part of the SEVIS Modernization effort as necessary throughout the iterative development of the SEVIS Modernization effort. The following describes the tasks to implement the Manage Nonimmigrant Module. Section C.6.1.1 describes the software development processes and tools that the contractor shall use when performing the tasks. Section C.6.1.2 describes the operations and maintenance (O&M) requirements.

The Contractor shall work extensively with users, product owners, IT Project Manager(s) and other requirements and application architecture contractors to ensure that the project (on whole) delivers the right solutions and value to the business and users.

· Requirements Gathering - Working with the product owner and end users to define and document user requirements

· Code Development - Defining, authoring and delivering custom application code that conforms to the requirements and application architecture provided by the government

· Integration Support - Integrating COTS solutions into the custom built modernized system, providing configuration, customization and implementation services

· Data Migration – Developing, implementing and documenting data migration strategies/plan(s)

· Deployment Activities - Planning for, creating and validating the implementation and deployment instructions (version description document [VDD], deployment plan) for use during application deployment

· DevOps – Work collaboratively and cross functionally with engineering and ICE Planning Team to implement Continuous Integration and Continuous Delivery

· Participating in integrated program/project teams and/or Scrum teams to enhance communication, share lessons learned, and facilitate rapid identification and mitigation of dependencies between various functional entities The contractor shall implement the Manage Nonimmigrant Information module in the SEVIS cloud service provider environment.

The application shall integrate with the ICE Active Directory (AD) for authentication of ICE users. The application shall support Single Sign-On (SSO) for ICE users.

The application shall be designed and developed for browser independence; i.e. it should generally work with any of the major browsers. ICE currently uses Internet Explorer (IE) version 11 configured with numerous Group Policy Objects (GPOs) as well as Chrome for Work, similarly secured with centrally managed security policies. Browser specific implementations or limitations on browser independence must be approved in writing by the ICE Chief Information Officer. Web Applications should be designed utilizing a responsive web design (RWD) approach, to provide an optimal viewing and interaction experience, independent of the particular platform capabilities the end user is utilizing. If ICE Office of the Chief Information Officer (OCIO) upgrades to a newer version of IE or Chrome for Work, the contractor shall ensure the application is compatible with the future version. The application shall support modern web browsers, including desktop and mobile web browsers. Specifically it shall support IE version 11 and newer, Firefox v38 and newer, Chrome for Desktop v41 and newer, Safari v7.x and newer, Mobile Safari v7.x and newer, and Chrome for Mobile (Android and iOS) v41 and newer. The contractor shall ensure the application is compatible with the future versions of as they are released. The application shall support multiple screen sizes and resolutions, i.e. mobile phones, tablets, and desktop screens.

The Contractor shall assist the Government in resolving any security issues and Plan of Action and Milestones (POA&Ms) that arise during any of the phases of development, testing, and/or deployment.

The Manage Non-Immigrant Information module shall audit the following system and user activities:

· User access

· Query strings submitted

· Records viewed (e.g., selected from results list)

· Records created, modified, and deleted

· Records or reports extracted or downloaded

· Records or reports printed

The application shall have an overall availability of 99.7%.

Software Development Processes and Tools The Contractor shall use agile development methodologies, such as Scrum or Kanban. The Contractor shall be primarily concerned with the implementation cycle, which in the case of Scrum includes sprint planning, application design, development and testing, deployment, sprint review, and sprint retrospective. SEVP currently implements four week sprints. The Government will provide a Scrum Master to facilitate the agile development process and perform the traditional duties of the Scrum Master role.

User stories will be written by the business owners and issued to the Contractor for implementation in the form of a backlog. The Government Product Owner will provide prioritization of user stories to the SEVIS Planning Team who will provide the Contractor with the implementation prioritization in the form of development sprints.

The Contractor shall use the Government-provided virtual environment including development workstations, development integration, testing and production. The Government will provide and support these environments, which are hosted in cloud service provider infrastructure, currently Amazon Web Services (AWS). The Government will provide and support the infrastructure. The Contractor shall support the Government in the stand-up of the environments including application specific software components, as well as application specific infrastructure implementations, such as load balancing. The Contractor shall be responsible for shake-out and validation of each environment.

The Contractor shall use the Government-provided Product Backlog Repository and defect management tool, currently JIRA, to track user story and task progress.

The Contractor shall use the Government-provided Source Code Version Management tool, currently Subversion, for version control of the code base.

The Contractor shall use the Government-provided Continuous Integration (CI) toolset, currently Jenkins, for automated builds and deployments to all environments.

The Contractor shall use an industry standard unit testing library, such as JUnit, to execute all unit tests. The Contractor shall use the Government-provided code coverage toolset to report on unit testing code coverage. The unit testing and code coverage toolset is integrated with the CI toolset to provide reports on unit testing. The Contractor shall ensure that required integration points with the developed code base shall be supported in order to enable the reports in the CI toolset.

The contractor shall use the Government-provided static code analysis tools, planned to be SonarQube, and integrate the execution of the analysis with the CI toolset for automated execution and reporting of results.

The contractor shall use the Government-provided static code analysis tools, planned to be Fortify, and integrate the execution of the analysis with the CI toolset for automated execution and reporting of results.

The contractor shall perform code peer reviews and document the results via an electronic medium, such as a wiki, JIRA, or using a Government-provided tool if available.

The Contractor shall develop automated test cases using an industry standard automated functional testing toolset, such as Selenium. An automated test case suite shall be maintained and executed on a regular basis, at least weekly. The automated testing toolset shall be integrated with the CI toolset to allow for automated scheduled execution and results reporting.

The contractor shall support the full lifecycle of integration testing with interface partners, including test planning, test script creation, data staging, test execution, troubleshooting, and test result reporting.

The Contractor shall support performance testing of the application. The Government is responsible for performance test creation and execution. The contractor shall work to resolve defects and/or performance issues that are identified during performance test execution.

If non-standard technology components are used by the application, the Contractor shall support the Government during the ICE Technology Reference Model (TRM) Information Technology Change Request (ITCR) process. This support shall include documentation and justification for the need for the specific technology components being used.

Tier 3 Support Following the production deployment of the application, the Contractor shall provide Tier 3 Operations and Maintenance (O&M) support. The Government will provide Tier 1 and Tier 2 support. During this support period, the Contractor shall identify and correct software, performance and implementation failures. Corrective work includes performing changes that reflect a change to requirements or technical specifications, as well as updating and maintaining the required System Lifecycle Management (SLM) documentation.

Tier 3 Support includes the following responsibilities:

· Production support of this mission critical application and availability 24/7/365 in the event of production issues.

· All maintenance activities that reach this level shall have a ticket opened and be reported using the ICE approved tracking tool.

· Tickets will be prioritized and agreed to by the authorized government personnel and entered into the ICE approved management-tracking tool.

· Known issues that cannot be addressed through a ticket shall be documented and coordinated with the OCIO Operations Tier 1 Help Desk for inclusion as a troubleshooting script.

· The Contractor shall respond to all Software Maintenance Tier 3 trouble tickets in accordance with the service level agreements agreed upon by the government.

· The Contractor shall implement automated monitoring and alerting in order to proactively detect issues.

Transition The Contractor shall be responsible for the Transition-out of all technical activities. The Contractor shall ensure smooth transitions from/to the current activities and responsibilities of the incumbent. The Contractor shall provide a Transition-Out Plan and a supporting project schedule identifying the support necessary to coordinate the transfer of all activities. Transition management activities for Transition-Out shall be incorporated into the Project Schedule, see Section C.7.4 for specific Transition-Out activities. The Contractor shall transition systems with no disruption in operational services.

The technical activities the Contractor shall include, as part of the Transition-Out plan, are:

· Transfer of all Government Furnished Equipment/Property (GFE/GFP), inventory, software and licenses

· Transfer of documentation currently in progress

· Transfer of all software code in progress

· Coordinate transition with DHS/ICE IT personnel

· Baseline release schedules

· Fully support the transition of application requirements to any successor Contractor

Disposition Disposition is the act of eliminating all or parts of a system to include IT and non-IT system belongings. Although ICE currently has no plans to dispose of the Information Sharing Module, based on future developments within the program the Contractor may be required to initiate disposition activities. The contractor shall initiate disposition activities in accordance with DHS ICE SLM at the conclusion of its lifecycle when a determination is made to retire the system. Disposition activities:

· Develop system disposition plan

· Assist in publishing notice of deletion in federal register

· Retire system and archive system components, data, and documentation

· Execute project close out

· Coordinate with Contracting Officer’s Representative (COR) to schedule Disposition Review

Create/Edit System Lifecycle Management (SLM) Documentation The Contractor shall provide SLM deliverables identified and required by the appropriate SLM phase to the Project Manager (PM) and ELMS. Documentation shall be prepared in accordance with the guidelines specified by the SLM and the approved Tailoring Plan. The Contractor shall deliver draft versions, revised versions, and final versions of required system documents. The Contractor shall provide deliverables electronically, virus free and in the acceptable electronic format mutually agreed to by the Government and Contractor. The contractor shall support the creation and maintenance of Interface Control Agreements (ICAs) for each of the interfaces. The contractor shall support the creation and maintenance of the System Design Document (SDD), Development Test Plan, Development Test Analysis and Results (DTAR), Version Description Document (VDD), Notice of Intent to Release (NIR), and all other SLM documents identified in the approved Tailoring Plan.

Deliverables The Contractor shall provide the deliverables identified in Table 3 below throughout the task order period of performance.

Table 3: List of Deliverables Table 3: List of Deliverables (Required)

Deliverables Description / Title
Frequency
Date of Submission
ICE

Distribution Desired Format

Weekly Status Report
Weekly
Tuesday
Release Manager/ICE Program Manager
MS Powerpoint
Daily Status at Stand up
Daily
Daily
ICE Program Manager
JIRA
Issue/Risk Inventory
As Needed
As Needed
ICE Program Manager
JIRA
Design Document
As Needed
As Needed
ICE Program Manager
Wiki
Development Test Plan (DTP)/ Development Test Analysis Report (DTAR)
As Needed
As Needed
ICE Program Manager
Wiki/MS Word
Version Description Document
As Needed
As Needed
ICE Program Manager
Wiki/MS Word
Notice of Intent to Release (NIR)
As Needed
As Needed
ICE Program Manager
Wiki/MS Word
DHS Integrated Change Control Board (ICCB) Change Request (CR) Implementation
As Needed
As Needed
ICE Program Manager
Wiki/MS Word

Weekly Status Report Status meetings will be held periodically between the Contractor’s Technical Lead and the PM to apprise the Contractor of how the government views the Contractor’s performance and for the Contractor to apprise the Government of any issues or obstacles. The Contractor shall prepare a weekly status report by COB every Tuesday. The initial weekly status report is due 15 calendar days after award and shall cover the first week of performance. The final delivery shall occur ten days before the end of the final option period and shall summarize performance during the period of performance and provide the status of any planned transition activity. The weekly status report shall contain the following:

· Description of the work

· Description of work accomplished

· Analysis of the difference between planned and accomplished

· Work planned for the following month

· Open issues

· Risk Register

· System Performance metrics

· SCRs/CRs received, resolved and open

Quality Control Plan (QCP) and Quality Assurance Surveillance Plan (QASP) The Contractor is required to develop a comprehensive program of inspections and monitoring actions. This comprehensive program is known as a Quality Control Plan (QCP). The QCP is intended to ensure that the Contractor’s quality control program provided the processes needed to lead the Contractor to project success. The Contractor’s QCP will set forth the staffing and procedures for self-inspecting the quality, timeliness, responsiveness, customer satisfaction, and other performance requirements in the PWS. Once the quality control program is approved by the Government, careful application of the process and standards presented in the QCP document will ensure a robust assurance program.

The QCP is due within 15 calendar days after task order award.

The Quality Assurance Surveillance Plan (QASP) is the document used by the Government to evaluate Contractor actions while implementing the PWS. The QASP provides a systematic method to evaluate the services the Contractor is required to furnish. The Contractor, and not the Government, is responsible for the management and quality control actions to meet the terms of this contract. The role of the Government is quality assurance monitoring to ensure that the contract standards are achieved.

For this requirement, the quality control program developed by the Contractor is the driver for service quality. The QASP is intended to verify that the Contractor’s quality control program approved at the beginning of the Task Order provides the measures needed to lead the Contractor to project success. Once the quality control program is approved by the Government, careful application of the process and standards presented in the QASP document will ensure a robust quality assurance program. The draft QASP will be completed by the Awardee and due 15 calendar days (or the first business day should this fall on a weekend) after award of this Task Order. The QASP is subject to discussions /negotiations.

The Contractor shall establish and provide details within the QASP of the system performance baseline, and how it will be utilized to measure system performance and response times throughout the life of the order.

The final QASP is due within 30 calendar days after task order award.

Configuration Management The Contractor shall assist the Government in conducting application-level configuration management for all changes made to the system. The Contractor shall also assist the Government in handling all requests for changes to established baselines and configuration management thereof via the ICE approved SCR process, including the conducting of a system-specific Change Control Board (CCB) as required. The Contractor shall assign proper identification of all configuration items in accordance with agreed upon conventions.

Transition-Out Plan The Contractor shall provide a final Transition-Out Plan as well as the support necessary to coordinate the transfer of all activities during the 45 calendar day transition out period. The final Transition-Out Plan will be provided 60 calendar days (or the first business day should this fall on a weekend) prior to the end of the period of performance.

The Transition-Out Plan shall include and/or address the following elements:

· Coordinate transition with DHS/ICE IT personnel

· Transfer of all software code in progress

· Fully support the transition of application requirements to any successor Contractor

· Technical walkthrough of the application, environment, interfaces, backlog, and help desk logs, etc.

· Transfer of all GFE/GFP, inventory, peripherals, software and licenses

· Transfer of documentation currently in progress

· Briefing on all in-progress and committed items

· Provide the necessary support to ensure current and archived data is transferred to the COR including current system data, data archived to secondary storage, and I-515A Tracking System related documentation generated since the contract awarded

Written Acceptance/Rejection by the Government The Government shall provide written notification of acceptance or rejection of all final deliverables within 15 calendar days of receipt. All notifications of rejection will be accompanied with an explanation of the specific deficiencies causing the rejection.

Non-Conforming Products or Services Non-conforming products or services will be rejected. The Government will provide written notification of non-conforming products or services within fifteen (15) calendar days of receipt. Deficiencies shall be corrected within thirty (30) calendar days of the rejection notice. If the deficiencies cannot be corrected within thirty (30) calendar days, the Contractor shall immediately notify the COR of the reason for the delay and provide a proposed corrective action plan within ten (10) calendar days of receiving the non-conforming products or service notification.

Notice Regarding Late Delivery The Contractor shall notify the COR as soon as it becomes apparent to the Contractor that a scheduled delivery will be late. The Contractor shall include in the notification the rationale for late delivery, the expected date for the delivery, and the impact of the late delivery on the project. The COR will review the new schedule with the PM and provide guidance to the Contractor.

General Requirements Period of Performance The period of performance for this solicitation is one (1) 12-month Base period and one (1) 12-month Option periods.

Place of Performance Contractor employees shall preferably be working at the Government’s facilities in Arlington Virginia (Crystal City) however remote working can be accepted. Frequent travel to other ICE offices in the Washington, DC metropolitan area for meetings and briefings will be required. Travel to sites outside of the Washington, DC area may be required. Local travel expenses within the Washington Metropolitan area will not be reimbursed (this includes parking).

Hours of Operations Contractor employees are expected to be available during core hours (8:00 a.m. to 5:00 p.m. Monday thru Friday local time) except on Federal holidays or when the government facility is closed (http://www.opm.gov/fedhol/index.asp). Work may occasionally occur before or after business hours to accommodate planned maintenance outages required during off-hours and/or to support outages or incident resolution activities.

In emergency situations (including but not limited to special police actions; terrorist investigations; ad hoc school and student investigations; and other emergency actions requiring Manage Non-Immigrant Information Module support) and upon the COR’s request, the Contractor will be required to provide information system support on an around-the-clock (twenty-four hour) basis. Such support will be provided on a demand-only basis (not to exceed two (2) events per year), and is not to be construed as a permanent change to the Contractor’s normal working hours hereunder. The duration of an event may last up to five (5) days.

Non-Personal Services The Government shall neither supervise Contractor employees, nor control the method by which the Contractor performs the tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual Contractor employees. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the Contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s responsibility to notify the Contracting Officer (CO) or COR immediately.

Business Relations The Contractor shall successfully integrate and coordinate all activities needed to execute the tasks. The Contractor shall manage the timeliness, completeness, and quality of identified issues. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all Contractor personnel.

Contract Management The Contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned. The Contractor must maintain continuity between the support operations and the Contractor’s corporate offices.

Contract Administration The Contractor shall establish processes and assign appropriate resources to effectively administer the contract. The prime Contractor will manage work distribution to ensure there is no Organizational Conflicts of Interest (OCI), but will promptly notify the Government when such a situation occurs, and provide the CO with the associated mitigation plan. The Contractor shall respond to Government requests for contractual actions in a timely fashion. The Contractor shall assign work effort and maintain proper and accurate time-keeping records of personnel assigned to work under this task.

Subcontract Management The Contractor shall be responsible for any subcontract management necessary to integrate work performed under this task and shall be responsible and accountable for subcontractor performance. Upon approval from the CO and COR, Contractors may add subcontractors to their team.

Organizational Conflict of Interest (OCI) Pursuant to Federal Acquisition Regulation (FAR) 9.5 and HSAR 3052.209-72, the Contractor shall manage work distribution to ensure there are no OCI. The Contractor shall promptly notify the Government when such a situation occurs, and provide the CO with the associated mitigation plan.

Invoicing In accordance with the terms and conditions of the contract, the Contractor shall submit invoices and supporting documentation by the 15th of the following month. Each monthly invoice shall be submitted in sufficient detail, with costs segregated at the project and Contract Line Item Number (CLIN) level.

Other Direct Costs (Optional) There shall be no additional Other Direct Costs (ODCs) on this Task Order.

Contractor Acquired Property All Contractor Acquired Property (CAP) shall be in full compliance with ICE IT security policies for systems and equipment. The Contractor shall not use contractor equipment connected to any DHS/ICE network without prior written approval.

Government Furnished Equipment (GFE)/ Government Furnished Property (GFP) The Government will provide the Contractor with basic equipment and property (e.g., laptops, desktops, VPN tokens, and mobile smart phones). The Government will provide access to ICE mandated tools such as JIRA, Remedy, and other applications as needed for this effort. ICE reserves the right to add, delete, or modify at its discretion any hardware or software at any time during contract performance, based upon what in ICE’s judgment is necessary to most effectively and efficiently perform the mission.

All GFE/GFP provided to the Contractor to perform work under this task order shall be returned to the Government at the end of the period of performance. The Contractor shall keep an inventory of GFE/GFP, which shall be made available to the COR or CO upon request. All GFE/GFP shall be entered into ICE’s Property Inventory System (Sunflower) within 48 hours of receipt. The Contractor shall ensure that all GFE/GFP provided for their use shall be secured. The Contractor shall manage, maintain, and control all GFE/GFP in support of this contract and subsequent task orders in accordance with the clause at FAR 52.245-1.

Government Furnished Information (GFI) The Government will provide Government Furnished Information (GFI) (e.g., technical data, applicable documents, plans, regulations, specifications, etc.) in support of this task.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .