Digital Images-PWS-Draft.pdf

PDF 290 KB Posted

Attached to
DIGITAL IMAGES Federal contract opportunity
Solicitation number
HE1254-23-Q-0013
Issued by
Department of Defense Education Activity

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

Department of Defense Education Activity 4800 Mark Center Drive

Alexandria, VA 22350

16 Nov 22 1

PERFORMANCE WORK STATEMENT

Digital Images for Classroom Instruction and Professional Learning

1. General Information and Scope of Work

1.1 Agency

For school year 2022-23, the Department of Defense Education Activity (DoDEA) will provide PK-12 instruction to over 66,000 dependents of active-duty military and civilian employees. In the Americas, DoDEA operates 50 schools located in seven states, Puerto Rico, and Cuba. In Europe and the Middle East, DoDEA operates 64 schools located in Germany, England, Netherlands, Belgium, Spain, Italy, Turkey, and Bahrain. In the Pacific, DoDEA operates 45 schools located in Korea, Japan (mainland and Okinawa), and Guam. DoDEA also operates a full time K-12 virtual school option with teaching hubs in each DoDEA region: Americas, Europe, and Pacific.

DoDEA's curriculum, resources and student achievement scores on standardized assessments compare favorably to those of high-performing US public school systems.

1.2 Background

For over a decade the Instructional Design Services Branch has provided selected visual design services consisting primarily of just-in-time online coursework and blended learning for students and professional development courses/resources for educators and other agency staff. Per federal regulations, DoDEA must recompete the expiring contract.

1.3 Scope of Work

DoDEA requires digital images that are professional quality and that conform to US copyright laws to create online coursework for our Virtual High School students and a wide variety of products for our educators. To this end, DoDEA purchases digital images from various sources and stores them in a common network space on a DoDEA server/Digital Asset Manager (DAM). Online distribution of coursework and resources occurs primarily through our designated learning management system (LMS, currently Schoology) and our website, http://www.dodea.edu/.

2 Requirements

2.1 Digital Images: DoDEA requires digital images that are professional quality and that conform to US copyright laws to store in a common network space on a DoDEA server. Online distribution of coursework and resources occurs primarily through our designated learning management system (LMS, currently Schoology) and our website, http://www.dodea.edu/.

The tasks below are provided to help the Contractor gain a better understanding of the requirements.

The tasks are not all inclusive. The Contractor is expected to develop the total solution to meet all the requirements in accordance with a performance-based approach.

Supporting Tasks

2.1.1 Task 1, Digital Images—DoDEA expects that the Contractor’s digital image library will have a minimum of 200 million images and will be adding additional images new images periodically. The Contractor shall:

2.1.1.1 Provide the most recent edition of its asset libraries, which communicate current subject matter and provide upgrades and updates to the libraries and licensed assets during the contract period. Notify the contracting officer’s representative (COR) when new product updates are available for downloading/claiming.

2.1.1.2 Demonstrate all assets are royalty-free and attribution-free. If copyrighted assets are included, permission for such use has been obtained by the Contractor from the copyright owner.

16 Nov 22 2

2.1.1.3 Provide access for up to 20 users in the base year to conduct direct searches and digital image downloads through a vendor-provided search engine that uses a keyword metadata search; ensures that image keywords are viewed along with the image when images are viewed online and ensures keywords can be migrated to DoDEA’s Integrated Digital Asset Management System. Note:

DoDEA may increase the number of users by an estimated one user per year in the option years.

2.1.1.4 Images shall be downloaded from an intuitive search interface from an online asset library in a variety of formats that conform to current and near-future industry-supported standards and are usable in e-learning software, mobile and desktop web browsers, and desktop publishing applications, including, but not limited to the following:

1) Graphics/Illustrations in bitmap (.jpg, .png) and vector (.eps, .svg) formats that encompass the following characteristics: a wide variety of subject matter and purposes (e.g., icons and symbols, clipart of objects/ food and people/animals, PK-12 subject matter), age-level appropriate; in color; range of output dimensions and resolutions (e.g., 72 ppi, 300 dpi, HD, retina-ready) that are appropriate for use in various media (e.g., web, video, print, PDF).

2) Photos in .jpg format and in a range of output dimensions and resolutions (e.g., 72 ppi, 300 dpi, HD, retina-ready) that are appropriate for use in various media (e.g., web, video, print, PDF);

in color; show PK-12 students and adults in authentic environments to include PK-12 classroom settings and adult learning/professional development situations; encompass a wide variety of PK-12 subject areas (e.g., science, math, history, fine arts, world languages) including objects of study and people studying/ working in those areas; and diversity of human subjects (i.e., gender and racial diversity).

2.1.1.5 Allow DoDEA the rights to retain any downloaded images in perpetuity.

2.1.1.6 Ensure DoDEA can manage user members’ access to online asset libraries.

2.1.1.7 Download options based on an annual subscription. Allows images to be downloaded and used multiple times for no additional fee if they are needed more than once.

2.1.1.8 Provide users access to the images from any workstation with Internet access. Note: DoDEA prefers but does not require access to special collections, such as curated photos/images and/or editorial photos/images.

2.1.2 Task 2, Product Training: The Contractor shall provide digital modules and/or asynchronous webinars that provide users an overview of the Contractor’s digital library/collection, navigation, etc.

2.1.3 General Requirements—The Contractor shall:

2.1.3.1 Meetings: Provide the medium through which each meeting occurs, record each meeting’s minutes.

Submit the draft minutes to the COR within two business days of the event. Finalize the minutes two business days after receipt of written feedback from the COR.

1) Post-Award Conference: Participate in a video- or teleconference with the COR five business days after award in accordance with FAR Subpart 42.5.

2) IT Meeting: Convene a video- or teleconference with DoDEA Information Technology staff ten business days after award, per Technical Exhibit #1.

3) Other Post-Award Meetings: Meet with the Contracting Officer (KO), COR, and/or other Agency personnel, as appropriate, to review Contractor performance, as required by DoDEA. The KO may discuss the Agency’s view of Contractor performance, and the Contractor shall apprise the Agency of any problems being experienced. The Contractor shall take appropriate action to resolve any outstanding issues the Agency raises.

2.1.3.2 Technical Support: Provide industry-standard technical support for its digital resources for the life of the contract via telephone or by email within one business day or less from the initial contact to include but not limited to assisting with service problems, product setup, upgrades, and troubleshooting.

2.2 Performance Standard and Acceptable Quality Level (AQL)

2.2.1 Performance Standard: Tasks shall be completed per the AQL (below).

2.2.2 AQL: All tasks shall be completed by the required completion date.

3 Constraints

3.1 Place of Performance: Work shall be performed at the Contractor’s facilities.

16 Nov 22 3

3.2 Liaison and Alternate Liaison—The Contractor shall:

3.2.1 Provide a liaison and alternate to be responsible for the performance of work. Their names shall be designated in writing to the Contracting Officer. They shall have full authority to act for the Contractor on all contract matters relating to the daily operation of this contract. Each of them shall have at least one year of experience working in a similar role.

3.2.2 Notify the COR in writing regarding any change in either liaison’s role ten business days in advance of the change If the liaison is changed post-award, the replacement shall meet or exceed the qualifications and experience of the person assigned upon contract award.

3.3 Holidays and Hours of Operation

3.3.1 The liaison or alternate shall be available during the hours of 9AM to 3PM Eastern Standard Time (EST), except for Federal holidays and Federal government closures/shutdowns. The following list shows recognized Federal holidays: New Year’s Day, Martin Luther King Jr.’s Birthday, Presidents Day, Memorial Day, Juneteenth National Independence Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas Day.

3.3.2 Although there are different time zones within Europe and the Pacific and different hours for specific schools throughout DoDEA, the normal business hours for the regions roughly correspond to the following:

Americas, 0700-1500 EST; Europe, 1300-2100 EST; and Pacific, 2000-0400 EST.

3.4 Availability: The Contractor shall make all resources available for the life of the contract.

3.5 Privacy—The Contractor shall:

3.5.1 User Accounts: Require, wherever applicable, that individual accounts possess unique usernames and passwords that do not require personally identifiable information (PII) to access online content, i.e., first & last name and any other unique personal information.

3.5.2 Contractor Personnel: Ensure personnel assigned to this contract take proper precautions to protect information from disclosure. Collect and/or store all agency-owned or agency-controlled PII IAW the relevant requirements of the Privacy Act, 5 U.S.C, per http://www.archives.gov/about/laws/privacy-act- 1974.html.

3.5.3 Privacy Training: Ensure Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information take the DoD Privacy Act/Personally Identifiable Information (PA/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates of completion to the COR which can be audited at any time by the Chief Information Security Officer (CISO) or his/her designee.

3.5.4 Privacy Verification: Provide the COR written verification of compliance to the Privacy requirements (listed above) 120 calendar days prior to the expiration of each year’s contract option period or annually, as required. Note: After reviewing the Contractor’s verification, DoDEA reserves the right to ask for further verification data in order for DoDEA to comply with DoD’s evolving privacy mandates.

3.6 Section 508 Compliance—Ensure Contractor resources, wherever applicable, meet the following requirements:

3.6.1 IT Requirement: Ensure all electronic hardware and software that is procured under this contract/purchase order comply with Section 508 of the Rehabilitation Act of 1973, as amended, (29 U.S.C. 794d) and the Architectural & Transportation Barriers Compliance Board Electronic Information Technology (EIT) Accessibility Standards (36 CFR part 1194). More information may be found at http://www.section508.gov.

3.6.2 Deliverable Requirement: Ensure the following occur:

Outputs/deliverables do not adversely affect accessibility features of existing EIT technologies.

EIT related to the requirements of the contract are accessible to people with disabilities, per 29 U.S.C

794(d).

Outputs/deliverables including functional performance, information, documentation, and support requirements are considered. Standards from 36 CFR Part 1194 Subpart B, C, and D apply to this acquisition.

3.7 Optical Character Resolution (OCR): The Contractor shall provide, upon request, two digital OCR copies of print materials in one or more of the following formats:

Digital Accessible Information System/National Instructional Materials

16 Nov 22 4

Accessibility Standard (NIMAS) with cascading style sheet HyperText Markup Language (HTML) Portable Document Format (PDF), (unlocked, embedded fonts, single page) Rich Text Format (RTF)/Word document

3.8 Organizational Conflict of Interest (OCI): The Contractor (including any subcontractor) personnel performing work under this contract may receive, have access to, or participate in the development of, proprietary or Privacy Act information (e.g., personal information, education, etc.) may create a current or subsequent OCI as defined in FAR Subpart 9.5. Whenever the Contractor becomes aware that such access or participation may result in actual or potential OCI, the Contractor shall (1) immediately notify the Contracting Officer (KO) in writing and (2) promptly submit a plan to the KO to avoid or mitigate any such OCI. Note: The KO will unilaterally determine if the Contractor’s plan is acceptable. If the KO determines the plan cannot satisfactorily avoid or mitigate an OCI, s/he may implement other remedies to include prohibiting the Contractor’s further participation in contracted requirements.

4 Government-Furnished Information / Resources

None

5 Contract Deliverables

Milestone/Deliverable Word / Excel

Digital Copies

Task /

PWS

Planned Frequency

Access to Image Collection(s) Yes Yes Task 1 Ongoing three business days after receipt of initial delivery order

Access to Product Training Yes Yes Task 2 Ongoing three business days after receipt of initial delivery order

Technical Support Yes Yes 2.1.3.2 Ongoing three business days after receipt of initial delivery order

Privacy Training Yes Yes 3.6.2 Proof of completion provided upon written request from the COR

Privacy Verification Yes Yes 3.6.4 Proof provided 120 days before the end of the contract year

6 Acronyms and Definitions

DoD/DOD Department of Defense DFARS Defense Federal Acquisition Regulation Supplement EIT Electronic Information Technology FAR Federal Acquisition Regulations IAW In Accordance With PA/PII Privacy Act/Personally Identifiable Information

Contract Line Item Number (CLIN) – Basic structural element in a procurement instrument describing and organizing the required product or service for pricing, delivery, inspection, acceptance, invoicing, and payment.

The use of the term “line item” includes “subcontract line number”, (SLIN), as applicable.

Contracting Officer (KO) – The only individual with expressed authority to obligate (bind) the Government by means of entering, administering, and terminating contracts within the limits of the authority delegated via a Contracting Officer’s warrant.

Contracting Officer’s Representative (COR) – Qualified and trained Government employee, nominated by the requiring activity (RA) and appointed in writing by a KO primarily to perform specific technical or administrative functions on a specific contract(s); serves as the ‘eyes and ears’ of a KO to assure the Government’s best interests are protected via the terms and conditions of the contract(s) appointed. COR’s do not have authority to obligate (i.e., bind) the Government.

Contractor - Supplier or vendor having a contract to provide specific supplies or service to the Government. The term used in this contract refers to the prime.

16 Nov 22 5

Deliverable – Usually physically delivered items but may include such items as digital documents/reports.

Performance Requirements Summary (PRS) – Tabular listing of performance objectives and standards that provides the basis for a meaningful QASP.

Performance Work Statement (PWS) - A statement of work for performance-based acquisitions describing the required results in clear, specific, and objective terms with measurable outcomes.

7 Performance Requirement Summary (PRS)

Performance Objective

Performance Standard AQL Inspection Method

Access to Image Collection(s)

100% compliance with the PWS

Images are professional quality and their attributes and usage complies with the other requirements set forth in Task 1

COR inspection and stakeholder feedback

Access to Product Training

100% compliance with the PWS

Access is available 365/24/7, except for scheduled downtimes.

COR inspection and stakeholder feedback

Meetings 100% compliance with the PWS

No more than one meeting per year will need to be rescheduled due to Contractor issues

COR inspection

Technical Support 100% compliance with the PWS

Acknowledge inquiries within ten minutes of receipt. Resolve 90% of issues within one business day and the remaining 10% within five business days.

COR inspection and stakeholder feedback

Privacy Training 100% compliance with the PWS

Provided within ten business days of receipt of written request COR inspection

Privacy Verification 100% compliance with the PWS

Provided in the timeframe defined in the PWS. COR inspection

Technical Exhibit #1 - TECHNICAL REQUIREMENTS

The Contractor shall comply with the applicable technical requirements detailed below.

1.1 Software and Cloud Security Requirements—The Contractor shall:

1.1.1 Ensure all online resources, cloud-based services and instructional software meet the Department of Defense (DoD) and DoDEA Cybersecurity requirements as defined below. Note: Software, cloud services and associated websites are rigorously tested to ensure no security risks are posed to DoDEA infrastructure and its users.

1.1.2 Complete the Cloud Services questionnaire that was submitted as part of the proposal submission and provide copies of and/or access to any software listed in the proposed solution.

1.1.3 Ensure on-premises software support post-installation integration of the necessary Security Technical Implementation Guides (STIG) for applicable systems and applications, including Microsoft Windows 10, Microsoft Windows Server 2016, Windows Server 2019, Microsoft Windows IIS, Apache, Oracle databases, and Microsoft SQL Server databases. Note: The application to obtain the STIG Viewer is found at https://public.cyber.mil/stigs/srg-stig-tools/, and the STIGs themselves may be downloaded from https://public.cyber.mil/stigs/downloads/.

1.1.4 Ensure its content accessible from the web is compatible with the following browser platforms: Google Chrome and Microsoft Edge. Ensure that any applicable STIGs are implemented.

1.1.5 Ensure on-premises software, which is subject to static and dynamic analysis testing, imposes no risk to DoDEA systems, users and/or data. Note: DoDEA assesses software products to ensure compatibility with existing system configurations and software, testing may also include reverse engineering analysis.

16 Nov 22 6

1.1.6 Provide a plan of actions and milestones (POA&M) to mitigate any cybersecurity findings resulting from non-compliant and/or vulnerable components within 30 calendar days of written notification from DoDEA.

1.1.7 Participate, as needed, in interviews and deep system architecture inspections. Note: Per DoD policy for cloud-based services, DoDEA conducts a supplemental series of validations, which closely mirror the Federal Risk and Authorization Management Program (FedRAMP) Internet Cloud vetting processes.

Contractor participation/cooperation is normally required to complete this process.

1.2 System Requirements—The Contractor shall:

1.2.1 Ensure, per Section 1.1 (above), any software installed and/or accessed in or by a DoDEA system, network whether stand-alone or web-based, is compatible with standards cited herein.

1.2.2 Provide minimum desktop/server system technical specifications, available reference architectures, networking specifications and diagrams, and applicable systems configuration documentation for the proposed product solution.

1.2.3 Ensure all software is compatible with the following minimum baseline:

Specifications Minimum

Memory 4 GB Hard Drive 100 GB

Processor Intel® Core™ i5-8365U Processor 8th Generation (up to 4.1GHz, 6MB cache) equivalent or better (Must show benchmark/passmark scores)

Video Graphics Integrated Intel HD Graphics 620 (1920x1080) equivalent or better Operating System Windows 10

Browser Environment Chrome; Edge; Edge Chromium

1.2.4 Ensure software is completely functional on a standard DoDEA desktop without the need / requirement for administrative-level user rights and/or permissions or the requirement to use or insert external media to execute the software.

1.2.5 Provide software that does not require modifications to folder permissions while executing.

1.2.6 Ensure, if applicable, that software packages support unattended installation methods used by enterprise software packaging and deployment systems. Notes: DoDEA currently distributes software packages via Microsoft System Center Configuration Manager (SCCM). Older 16-bit software are automatically denied.

1.3 Data Management Requirements—The Contractor shall:

1.3.1 Provide a mechanism for batch administration and automation of routine data management tasks via flat file import, or representational state transfer (REST) based web service application programming interfaces (APIs). The mechanism shall provision and manage data objects within the Contractor’s system, including but not limited to organizational structures, student accounts, staff accounts, courses, and class rosters.

1.3.2 Provide all necessary documentation and assets to facilitate batch administration and automation of routine data management tasks, including but not limited to roster template files (i.e., comma separated value templates); data element/field definitions documentation; data interchange formats and schemas (XML/JSON); and/or data dictionaries for the purpose of mapping organizational student information system (SIS) data to the Contractor’s required input formats.

1.3.3 Provide a single point of contact to support DoDEA in performing the required data integration activities within the Contractor’s system.

1.3.4 Configure DoDEA enterprise within its system and/or databases as the appropriate organizational entity (i.e., region, district, school) upon a request in writing from the contracting officer’s representative (COR). Note: DoDEA’s organization hierarchy consists of the following: one system, three regions, eight districts, 62 communities, and 160 schools, including the K-12 virtual school programs.

1.3.5 Participate in a technical meeting with DoDEA within ten business days after award for the purposes of preparing for onboarding of new services and initial configuration of administrator-level accounts.

1.3.6 Ensure the transfer of any Sensitive and/or Confidential data including but not limited to PII data be transferred in a secure means meeting any requirements set by DoDEA’s Chief Information Security Officer (CISO).

16 Nov 22 7

1.4 DoDEA Software License Keys: The Contractor shall provide (1) license keys and electronic downloads for software required under this Contract to the COR and (2) software directly to DoDEA schools, districts, or regions only if explicitly required to do so in the contract or in writing by the COR.

1.5 Cybersecurity Supporting Elements/Requirements and Scalability—The Contractor shall:

1.5.1 Comply with the same Federal law and DoD policies and guidance to which DoDEA is subject. These requirements include but are not limited to the cybersecurity requirements defined in the following documentation:

DoD Directive (DoDD) 8500.01E, Information Assurance, which may be found at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf.

DoD Security Technical Implementation Guidance (STIG), which may be found at the following

URL: https://public.cyber.mil/stigs/downloads/.

DoD Risk Management Framework (DODRMF) per DoD Instruction 8510.01 found at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf?ver=2019-02- 26-101520-3004.5.2.

1.5.2 Provide security patches/upgrades to include third-party applications in response to public-released security vulnerabilities associated with its software solution. Provide a POA&M for any security vulnerabilities within five business days of discovery. Software upgrades/patches shall be included in the licensing cost and be performed at the least disruptive times as determined by DoDEA in writing. Note: Any exception to this requirement must be approved in advance and in writing by DoDEA’s Chief Information Officer (CIO) or designated official.

1.5.3 Ensure any portion of its solution that involves Internet access by DoDEA students complies with the relevant requirements of the Children's Internet Protection Act, Pub.L. 106-554, § 1(a)(4) [Div. B, Title XVII, § 1701], Dec. 21, 2000, 114 Stat. 2763, 2763A-335.

1.5.4 Ensure its solution is robust enough to serve the needs of a large community of learners dispersed across the world using a variety of bandwidths and scalable to meet future growth, both in terms of instruction and the number of users.

1.5.5 Ensure Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information take the DoD Privacy Act/ Personally Identifiable Information (PA and PPI/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates of completion to the COR which can be audited at any time by the CISO or his/her designee.

1.6 Program and System Integration

1.6.1 Single Sign-On (SSO) Capabilities / Platform—The Contractor’s solution shall:

1) Integrate with an Industry Standard SSO login solution. (ClassLink, Google, Azure, etc.)

2) Support Oauth 2.0, Security Assertions Markup Language (SAML) for integration with Azure

Active Directory (AD) or Google AD.

3) Authenticate using Azure AD or Google AD.

1.6.2 Data rostering standards—The Contractor’s solution shall support industry standard rostering via ClassLink and standard data formats such as OneRoster.

1.6.3 Data Storage, Handling, and Security:

1) Data shall be secured in data center located in the United States.

2) Data transit shall be secured with Transport Layer Security (TLS) encryption.

3) Data at rest shall be secured with Advanced Encryption Standard (AES)-256 encryption

4) All Contractor personnel that have access or may potentially have access to DoDEA data in any form shall be US citizens, including any third-party penetration (PEN)/security testers.

1.6.4 Data Integration:

1) The automated industry standard form of data integration using Representational State Transfer Application Program Interface (RESTful API), Learning Tools Interoperability (LTI), or Secure File Transfer Protocol (SFTP) data sets (ClassLink, OneRoster, etc.) shall be used.

2) Integration scheduling shall be flexible to meet DoDEA’s required timeframes. Provide fully automated data uploads per Agency schedule(s) and Agency requirements.

3) SFTP capabilities using a single set of login credentials shall be supported.

4) A single data set of DoDEA information shall be provided. Note: The Contractor’s solution shall support DoDEA at all levels: School, Community, District, Region, and HQ.

16 Nov 22 8

5) If an integration transmission results in errors on the Contractor’s side, the Contractor shall provide detailed feedback on what caused the errors.

1.6.5 System Features—The system shall:

1) Allow user accounts to be created automatically based on a file provided by DoDEA either nightly or on another pre-determined scheduled feed.

2) Allow DoDEA to be able to choose the format of user login identification, e.g., an email address, and be able to create manual accounts if needed.

3) Require the user—for manually created accounts—to reset the password on the user’s initial login or, upon request, a password reset.

PERFORMANCE WORK STATEMENT
PERFORMANCE WORK STATEMENT

File details come from the government source that posted it. Updated .