Draft IRPE Elements v 5.0.2 September 4_2020.docx

DOCX document 4 MB Posted

Attached to
Pre-Solicitation Conference for the Interim Servicing Solution Federal contract opportunity
Solicitation number
September_8_2020
Issued by
Department of Education

About this file

This notice announces a pre-solicitation conference for the Interim Servicing Solution (ISS) solicitation to be held on September 8, 2020. The ISS is a follow-on to existing Title IV student loan servicing contracts and will expand the Department of Education's operational efficiency through consolidating multiple systems and enhancing customer service. Interested vendors are invited to register for the conference to receive information about ISS and provide feedback.

The notice includes draft documents that will be released with the ISS solicitation, such as the statement of work, service level metrics, program elements, and pricing template instructions. It directs vendors to submit any questions in advance of the conference to the listed email and notes additional information will be posted online. The conference will clarify solicitation details and release timing in October 2020.

View the file

Other files for this federal contract opportunity

Other files attached to Pre-Solicitation Conference for the Interim Servicing Solution, newest first.
File Type Posted
Draft ISS Pricing Template Instructions September 4_2020.docx DOCX document
Draft Service Level Methodology_Performance Metrics September 4_2020.docx DOCX document
Draft SOW_ Interim Servicing Solution September 4_2020.docx DOCX document
Draft ISS Pricing Template September 4_2020.xlsx XLSX spreadsheet
Draft ISS SLA - Performance Measurement Template September 4_2020.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Information Resources Program Elements (IRPE) Standard Work Statement Elements Version 5.0.2 ● 6/5/2020 Part 2: IRPE Elements (requirements)

Version: 5.0.2 4 6/5/2020

Revision History

Version
Date
Author
Description
Version 5.0
4/9/2019
FSA
Moved IRPE Elements Guidance to include elements only.
5.0.1
9/17/2019
FSA
Updated version numbering.
5.0.2
6/05/2020
FSA
Added Element 4.3 Cybersecurity Monitoring

Acquisition Contractor Qualifications Contractor shall demonstrate its achievement of the Capability Maturity Model Level III, and shall maintain that capability as a minimum during the entire contract performance period. Personnel assigned to the contract must comply with the vendor’s CMMI Level III processes and be familiar with this contract agreement between FSA and the vendor.

Instructions: This requirements needs to be CMMI Level III.

Do you meet this requirement?
If Yes, provide the SCAMPI Assesement
If no, Time required to meet this requirement
Artifacts

Architecture Contractor Compliance with FSA Technology Standards and Products Instructions: This requirement is specific to the software and hardware being used to support borrower servicing. Please list any software that you do NOT find in the FSA Technology Standards Guide, which can be found at https://studentaid.gov/about/contracting-info/it-standards

List of software or Hardware NOT found in the FSA Technology Standards Guide
What is it used for?
If no, Time required to meet this requirement
Artifacts

The Contractor shall ensure that the solution is defined, designed, developed, and maintained in a manner such that it aligns with the FSA Technology Standards and Products Guide in effect on the date of the solicitation. The FSA Technology Standards and Products Guide documents FSA’s enterprise technology standards and products, that should be used to build all FSA solutions. Existing software standards should be used to prevent duplication, redundancy, and incompatibility. These standards will lower costs and reduce technical complexity.

If business or technical requirements require functionality or capabilities that do not exist or replicate an existing standard, the Contractor shall seek approval for adoption of a new standard and/or request an exception to the FSA Engineering Review Board (ERB) from the CO. Refer to the FSA Technology Standards and Products Guide for additional information:

https://studentaid.ed.gov/sa/sites/default/files/fsawg/static/gw/docs/ciolibrary/Technology_Standards_and_Products_Guide.pdf

Data Center Operations Collaboration and Support Instructions: If you are making changes that affect other FSA systems, those change must be coordinated with FSA Stakeholders.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

For software application(s) hosted in the FSA data center(s) or in another facility that connects with the FSA data center(s)/cloud solutions through government provided networks or telecommunication services, coordination is required when adding/changing/modifying that application. The contractor shall coordinate all changes it wishes to make with all FSA IT operations and services that will be impacted by the proposed change. The contractor shall submit a written request for the change.

Technology Refreshment and Evergreening Support Contractor Support of FSA Technology Refreshment and Evergreening Instructions: This does not affect any custom software developed for servicing since by default the software is the most current version. However, as with the ATO review, this does include OS, utilities and other support software.

Do you meet this requirement?
If, no why?
Time required To Meet This Requirement
Artifacts

As part of its standard technology refreshment program (evergreening), FSA requires regularly-scheduled and periodic upgrades of the underlying infrastructure, support software, and enabling frameworks to (at minimum) N-1 versions (where N is the latest version and N-1 is the second latest version).

Evergreening of SaaS, PaaS, and/or IaaS Solutions: The Contractor performing integration services for FSA in connection with FISMA-approved cloud computing services (SaaS, PaaS, IaaS) shall ensure the infrastructure, support software, and enabling components and frameworks are maintained to (at minimum) N-1 versions as part of a standard technology refreshment program (evergreening).

Evergreening of Infrastructure and COTS Software: The Contractor shall support evergreening activities, including infrastructure and software upgrades and patches led by FSA’s infrastructure and middleware vendors. As needed, the Contractor shall regularly support planning and scheduling, impact analysis, changes to the application, and testing.

Contractor Support of Application and Enabling Components and Frameworks Evergreening

Evergreening of Applications and Enabling Components and Frameworks:To ensure that functionality and application design are optimized, maintenance is cost efficient, and the enabling technology remains under support by third party vendors (e.g. IBM, Oracle, or Microsoft),.the vendor is responsible for maintaining the application code and its underlying frameworks at the N-1 version. Refer to the Federal Student Aid Technology Standards and Products Guide for additional information.

Instructions: This does not affect any custom software developed for servicing since by default the software is the most current version. However, as with the ATO review, this does include OS, utilities and other support software.

Do you meet this requirement?
If, no why?
Time required To Meet This Requirement
Artifacts

Contractor Software Usage The Contractor shall state in its offer, the information technology assets (software name, manufacturer, version, platform, and other relevant technical specifications) that it deems necessary to provide services and deliverables outlined in the solicitation, and it shall assure its assets’ compatibility with FSA assets.

Instructions: This is a one-time listing and can be updated at FSA’s request. There are other ATO requirements that require a maintained listing of hardware and software and this does not override those requirements.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

Access

Use of PIV and PIV-I Cards to Implement Multifactor Authentication Instructions: Section 3.1.2 applies to this solicitation. Section 3.1.1 only applies if the software is hosted in a FSA internally hosted Data Center.

PIV Card for Internally Hosted Solutions Instructions: If you are planning to host the solution in an FSA internally hosted Data center you MUST complete the table below.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

Requirements for Personal Identity Verification Credential (PIV card) for U.S. Department of Education (ED) Educate Network and Federal Student Aid (FSA) Data Center (NGDC) Access

General Requirement: All contractors accessing ED and FSA networks and/or data centers Next Generation Data Center (NGDC) who are classified as Privileged Users (PU) are required to use government furnished Personal Identity Verification (PIV) cards for authentication and access. Note: FSA prohibits contractors from granting access to FSA systems without approval by the Department.

Reporting Requirement: Although PIV cards are issued and managed by FSA, the Contractor shall still provide a monthly PIV Card report to FSA including:

· Number of privileged users with PIV cards disabled in the last 30 days.

· Number of privileged users with PIV cards enabled in the last 30 days.

· Total number of privileged users with PIV cards.

PIV Card Readers: PIV Card Readers shall comply with the requirements specified in NIST SP800-96 and conform to the [ISO7816] standard for the card-to-reader interface. These readers shall conform to the Personal Computer/Smart Card (PC/SC) Specification [PCSC] for the reader-to-host system interface in general desktop computing environment.

How PIV Cards are issued: FSA issues PIV cards according to the following criteria:

a) If there are 25 or fewer employees performing duties as privileged user at the place of performance; AND the place of performance is located within 2.5 hours of the Department of Education Headquarters or Regional Office by motor vehicle: The individual will be required to travel to a Department of Education Headquarters or Regional Office.

b) If the number of privileged users in a place of performance exceeds 25 persons, or the place of performance exceeds a 2.5-hour trip by motor vehicle, then an ED representative will travel to the vendor’s place of performance to issue the PIV card.

FSA will not provide PIV card readers.

Additional Instructions:

Please ensure the following information is addressed in technical and cost proposals:

· Total number of privileged users

· A list of the user roles being considered as privileged

· A list of user roles being excluded

· Contractor / Subcontractor company name(s)

· Number of privileged users at place of performance

· Resource(s) being accessed, including location

· Current method of accessing the resource

Please refere to Appendix IRPE-E for examples of Privileged User Roles and Job Functions (All Environments).

PIV-I Card for Externally Hosted Solutions Instructions: This is a requirement under the current FSA ATO processes used by loan servicers.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

Requirements for Personal Identity Verification Interoperable (PIV-I card) Credential for Access to Federal Student Aid (FSA) Partner-Hosted Solutions General Requirement: The Contractor shall ensure that all Privileged Users who work on IT resources and applications containing or accessing FSA’s data utilize the PIV-I cards that their organization secure. The Contractor shall provide PIV-I cards, provide card readers, and require Privileged Users to use the PIV-I card for authentication and access to IT resources and applications containing or accessing FSA’s data satisfying an Identity Assurance Level (IAL3) and Authentication Assurance Level 3 (AAL3) as defined in NIST SP 800-63-3 (Level of Assurance 4 (LOA4) as defined in OMB Memorandum 04-04 and NIST 800-63-2).

There are approved and trusted 3rd Party vendors that can be contracted to provide card issuance services. The complete list of approved PIV-I vendors is available at https://www.idmanagement.gov/trust-services/

Note: FSA prohibits contractors from granting access to FSA systems without approval by the Department.

PIV-I Card Issuance Requirement:

· The Contractor shall not issue the PIV-I card to the Privileged Users of the FSA system until after FSA has approved access for these users.

Reporting Requirement: The Contractor shall provide a monthly PIV-I Card report to FSA including:

· Number of privileged users with PIV-I cards disabled in the last 30 days.

· Number of privileged users with PIV-I cards enabled in the last 30 days.

· Total number of privileged users with PIV-I cards.

PIV/PIV-I Card Readers: The Contractor shall provide PIV/PIV-I compatible Card Readers that comply with the requirements specified in NIST SP800-96 and conform to the [ISO7816] standard for the card-to-reader interface. These readers shall conform to the Personal Computer/Smart Card (PC/SC) Specification [PCSC] for the reader-to-host system interface in general desktop computing environment.

Additional Instructions:

Please ensure the following information is addressed in technical and cost proposals:

· Total number of privileged users

· A list of the user roles being considered as privileged

· A list of user roles being excluded

· Contractor / Subcontractor company name(s)

· Number of privileged users at place of performance

· Resource(s) being accessed, including location

· Current method of accessing the resource

· How the organization will confirm successful implementation/deployment of a system satisfying NIST 800-63-3 IAL3 and AAL3 (LOA4 per NIST 800-63-2 and OMB Memorandum 04-04) requirements.

· Level of effort (identify labor categories, labor rates (consistent with contract rates if applicable), and number of hours by labor category) required to implement and maintain IAL3 and AAL3 (LOA4 per NIST 800-63-3 and OMB M-04-04), as well as the hardware and software and other materials, if required

Note: The Contractor is advised to design procurement procedures and technical implementation for compliant system for Privileged Users (IAL3 and AAL3 per NIST SP 800-63-3 or LOA4 per OMB M-04-04 and NIST SP 800-63-2) in such a way that they can be expanded in the near future to include the Non-Privileged, general user population (your employees, contractors, and partners).

Trust

Technical Requirements
PIV
PIV - Interoperable

Identity Assurance

· Level of Assurance 4

· Identity Assurance Level 3 (draft NIST SP 800-63-3)

Authenticator Assurance

· Level of Assurance 4

· Authenticator Assurance Level

Sustainability Assurance

· Favorable Adjudicated National Agency Check with Inquiries (minimum) or other Tier 1 Investigation

PIV policy object identifier on PIV Authentication Certificates

PIV-I Equivalent policy object identifier on PIV-I Authentication Certificates

PIV Content Signing object signing certificate

PIV-I Content Signing equivalent object signing certificate

Card stock certified

PIV Application Identifier (AID)

Command edge and NIST SP 800-85 conformant

Credential Edge NIST SP 800-73-4 conformant GUID present in the CHUID

RFC 4122 conformant UUID required in the GUID datat element of the CHUID

RFC 4122 conformant UUID present in the Authentication Certificates

Refer to Appendix IRPE-E for:

· Examples of Technical Implementation of Compliant System using PIV/PIV-I Credentials:

· Examples of Privileged User Roles and Job Functions (All Environments):

· Other reference materials.

Contractor ED Network Access Instructions: Based on government review section 3.2 does not apply to this solicitation.

In order to access ED network through the following websites, the Contractor must establish an ED user account and be issued a PIV card and a soft or hard token as Government-furnished Equipment (GFE.)

· Citrix environment can be accessed remotely from https://gotowork.ed.gov/vpn/index.html and http://anywhere.ed.gov/

· Citrix environment can be accessed internally on the ED network from http://citrix.ed.gov using the “ED Standard Desktop” link.

For a contractor using a Government Furnished Equipment (GFE) Laptop, the preferred method for remote access is the Aventail Virtual Private Network (VPN) connection. The Aventail VPN Connection client will be automatically pushed to each GFE laptop to enable ED users to use this service offering. The Aventail VPN Connection client allows users to connect to the ED network from remote locations and it provides an access experience very similar to that available to onsite users at ED locations.

Note: To use this feature, a contractor must be using a GFE laptop with the Aventail VPN Connection (client installed), and the contractor must be located outside the ED wired network.

Property Management Plan Instructions: This only applies to Government Furnished Equipment if any is issued.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

Please refer to FAR clause 52.245-1 Government Property and FSA local clause 45-1 Special Contract Requirements for Government Furnished Property – Two Factor Authentication Tokens (TFA) (latest version) which reads:

In addition to the requirements of FAR 52.245-1(b) – Property Management, the contractor shall:

a) Ensure the contractor’s Government Property Manager or designee shall,l sign a distribution letter provide by the Contracting Officer upon receipt of Government Property;

b) Comply with instruction on how to register the tokens using the Federal Student Aid Two Factor Authentication Token For FSA User Handout distributed with the tokens;

c) Seek immediate assistance with any challenges encountered with FSA CITRIX and TFA and immediately report any security or other incidents by telephone or email to the helpdesk at: 1-877-603-4188 or ed.customer.service@ed.gov and;

d) Provide a Property Management Plan to the Contracting Officer within 5 business days of receipt of the Government Furnished Property. Among other requirements required under FAR 52.245-1(b) the Property Management Plan must contain at minimum the following:

· Description on how the contractor will establish and maintain an auditable record of the token assignment to its employees by individual name and token Serial Number (AVT+9 digits, where AVT is an Active Identify time-based token);

· Method by which the contractor shall ensure that the serial number label on the back of each token remains legible and secure to the device.

· Security and management process for the physical devices and changes in assignment.

e) Upon written notification from the Contracting Officer, the contractor shall affirm its understanding of, and compliance with, the Government’s requirement for quarterly re-certification of user access and token activation. In the event of any reported security breach, without prior notice, the Government shall immediately disable or deactivate contractor access to its network.

f) Soft Tokens can be used instead of hard tokens. The soft token is an app that runs on the user’s mobile device. After downloading and registering the free Symantec VIP Access app on a phone or tablet, a user simply opens the app and a One-Time Password (OTP) is automatically generated. This one-time password is similar to a hard token. Use of a soft token is optional, however users who have a compatible mobile device are encouraged to transition to a soft token. There is no requirement to maintain property records on soft tokens.

Contact Information. For additional information on TFA or the use of a soft token, contact the TFA Support Center at 800/330-5947, option 2 (TDD/TTY 800/511-5806) or by email at TFASupport@ed.gov.

Security

Contractor Personnel Security Personnel Security Position Risk Designations Instructions: This is for all personnel working to service borrowers.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

The Excel document (FSA Contractor Mapping Worksheet) Contractor Position Mapping and System Access Form in Appendix IRPE-F provides a list of common job functions or position descriptions that Federal Student Aid (FSA) uses in the performance of Information Technology (IT) or IT related contracts. FSA has identified the applicable position risk designation (PRD) level for each commonly used job function or position description. The information provided is consistent with guidance provided by the National Institutes of Standards and Technology (NIST) , the Federal Information Standards (FIPS) and ED’s ACS Directive OFO: 5-101 Contractor Employee Personnel Security Screenings (FIPS). Offerors are instructed to complete the following steps:

1. Offerors shall review the attached FSA Contractor Position Mapping and System Access Worksheet and determine which job functions are applicable to the scope of requirements described in the solicitation. Upon reviewing the project scope, Offerors may select some of the job functions listed, all job functions listed, or Offerors may identify other job functions they feel are necessary to perform successfully but are not included on the standardized list.

2. Offerors shall use the FSA Contractor Position Mapping and System Access Worksheet Tab A to identify all proposed contractor positions that are necessary to support the contract. Offerors shall crosswalk the job functions of each proposed position to the related FSA job function, as applicable. Since contractors do not adhere to the same position titles, FSA job functions are classified by position number rather than position title. As a result, Offerors must map their company job titles (i.e. labor categories) to FSA job functions.

3. Once all proposed contractor positions are mapped to the applicable FSA job functions, Offerors shall indicate the number of resources required for each position and propose any recommended changes to the FSA identified, system and facility access requirements. (Note: FSA designated PRDs are not negotiable.) In addition, for each proposed contractor position, Offerors shall include the position/job title(s) that your company uses to identify that function.

4. Offerors shall use the Contractor Position Mapping and System Access Worksheet Tab B to identify any additional or new contractor positions they wish to propose that are not included on Tab A. If the Offeror would like to propose additional positions, the Offeror shall use the Office of Personnel Management’s (OPM) Position Designation Automated Tool (PDT) to determine the proper designation of a position and its required corresponding level of security investigation. OPM’s position designation system consists of a four-step process that will guide the designator through an examination of the position’s duties and responsibilities. Once the Offeror has completed this process, the Offeror shall complete Tab B of the FSA Contractor Mapping Worksheet.

5. The link to the OPM tool is below:

https://www.opm.gov/suitability/suitability-executive-agent/position-designation-tool/

6. The contractor can also access the below NIST publication for further guidance on proposing additional positions: Review the NIST Special Publication 800-181, National Initiative for Cybersecurity Education (NICE) Cybersecurity Workforce Framework, Appendix B - Work Role Detail Listing located at https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-181.pdf

7. Offerors shall use the following criteria to determine which positions should be included on the FSA Contractor Mapping Worksheet: ALL positions or personnel that will require access to FSA systems and/or FSA Sensitive Personally Identifiable Information (PII) or data. In all cases, the successful Offeror is responsible for ensuring that only authorized personnel cleared under the resultant contract have access to FSA systems and/or FSA Sensitive PII or data.

8. Offerors shall submit the completed FSA Contractor Mapping Worksheet with its proposal response. The sole purpose of the required mapping is: (1) to identify the specific positions the contractor is proposing to meet FSA’s commonly used job functions or skillsets, and (2) to designate the applicable risk level for each contractor proposed position for personnel security clearances.”

Please refer to the following applicable FSA Terms and Conditions sections:

· EDAR 3452.239-70 – Internet Protocol Version 6 (IPv6)

· EDAR 3452.239-71 (Provision) – Notice to Offerors of Department Security Requirements

· EDAR 3452.239-72 – Department Security Requirements

· EDAR 3452.239-73 – Federal desktop core configuration (FDCC) compatibility

· FSA 39-2 (Provision) – Electronic and Information Technology

· FSA 39-3 – FSA Section 508 and Electronic and Information Technology Accessibility Standards Compliance

· FSA 39-4 Remedies for Contractor’s Violation of System Security Requirements

· FSA 39-5 – Monthly Vendor Employee Report

· FSA 39-7(Revision 1 or current version) – Contractor Security Responsibilities

· FSA 39-8 (Revision 1 or current version) – Supplemental Instructions to EDAR 3452.239-72, Department Security Requirements

Background Investigation Processing Metric Instructions: This is for all personnel working to service borrowers.

Do you meet this requirement?
If no why?
Time required To Meet This Requirement
Artifacts

FSA Personnel Security, in coordination with the COR, will provide initial screening and submission training to the contractor’s designated eQIP initiator(s) upon contract award. After initial training, FSA will offer periodic training based on clause 39-8, to include refresher sessions. The contractor will be responsible for completion of all required training. In addition, the contractor’s e-QIP initiators are responsible for ensuring that their employees’ background investigation packages are complete prior to sending to FSA. The contractor will comply with any service level metrics identified in the contract.

Cybersecurity Requirements Instructions: Please note you must complete Appendix IRPE-G.

Appendix IRPE-G Cybersecurity Checklist is a 6-column spreadsheet that itemizes and includes all the cybersecurity requirements to be fulfilled by the contractor. Four of the columns are used to accommodate the contractor’s responses to each requirement. The contractor must respond to each requirement by saying Yes or No. If the contractor’s response to a requirement is Yes, the contractor must state, in the adjacent column, how it will meet the requirement. If the contractor’s response is “No,” the contractor must state, in the adjacent column G to the right, why they cannot meet the requirement, the mitigation strategy and give the Technical proposal, and milestones, for meeting the requirement. A separate attachment is allowed.

4.3 Cybersecurity Monitoring

Instructions: FSA will not allow a mitigation strategy for this element.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

The Contractor shall ensure the solution is defined, designed, developed, and maintained in a manner such that it implements the cybersecurity requirements and standards.

FSA and the Department have implemented a risk-based approach and measurement methodology for each system and the information system’s cybersecurity performance under FSA contracts. The Contractor shall ensure that the FSA system and associated technologies “meets all requirements” for cybersecurity including but not limited to the cybersecurity scorecard.

The Contractor shall ensure that they fully participate, and enter in the appropriate agreements, with the FSA and Department of Homeland Security (DHS) Cyber Hygiene programs.

Development

Contractor Release of COTS Configuration and Custom Application Source Code to Government Instructions: FSA is not purchasing the intellectual property of the commercial loan servicing software. FSA does require the offeror to purchase any licenses required to meet security requirements and will allow for COTS liceneses.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

SaaS, PaaS, and/or IaaS Solutions, and/or systems hosted externally to the FSA Data Center:: The Contractor performing integration services for FSA in connection with FISMA-approved cloud computing services (SaaS, PaaS, IaaS) will acquire for FSA any and all licenses and subscriptions necessary to meet FSA’s requirements for the use of such cloud services as specified in the contract. Such licenses and subscriptions shall be transferred by the Contractor to FSA upon acquisition and managed in compliance with FSA 27-2 Contractor Use of Government Commercial Software.

COTS Licenses: For all COTS software authorized to be procured by the Contractor in performance of the contract, the Contractor will acquire for FSA any and all licenses necessary to meet FSA’s requirements, as specified in the contract, for the operation of the system. Ownership of such licenses shall be transferred by the Contractor to FSA upon acquisition and managed in compliance with FSA 27-2 Contractor Use of Government Commercial Software.

COTS Configuration: The Contractor shall submit all COTS configuration information (including documentation) to FSA Task Manager or appointed Project Manager, as well as the Contracting Officer. For all COTS software configurations established and managed by the Contractor, including software configuration performed in connection with FISMA-approved cloud computing services, the contractor will provide documentation of complete COTS configuration necessary to support FSA requirements, for the continued, unrestricted use of such configurations.

The code and development artifacts shall be made available upon request to support audit and/or independent quality assurance efforts, integration, test, or other life-cycle activities.

All rights for technical data and software developed at private expense and used in the performance of the contract will be as delineated in FAR 52.227-14- Rights in Data – General and any alternates included therewith.

Test Standards Instructions: FSA will accept any Systems Development Life Cycle (SDLC) plan an offeror has in place. FSA will require the offeror to explain how its SDLC will interface with FSA’s Lifecycle Management Methodology (LMM). Also, for any new development work FSA will specify testing requirements in the Change Request.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

The contractor shall comply with standards for test management within the Lifecycle Management Methodology. For additional information, refer to the Enterprise Test Management Standards.

https://studentaid.ed.gov/sa/sites/default/files/fsawg/static/gw/docs/ciolibrary/FSA_Enterprise_Test_Management_Standards.pdf

Performance Testing .

Instructions: The initial request is a performance test to ensure the offeror’s system can process the large volumes of borrowers.

Do you meet this requirement?
If no, why?
Time required To Meet This Requirement
Artifacts

Externally Hosted Solutions For externally hosted solutions (such as a contractor’s facility or located in the cloud, the Contractor shall conduct performance testing of their responsible areas, and shall provide data, scenarios, volumes, support of performance testing activities, and capacity estimates, including trending of performance data, and test results. The Contractor shall resolve issues identified during performance testing activities. The Contractor shall support the testing of any interfacing application. The Contractor shall provide a document summarizing the changes associated with architecture and design of the system to support capacity planning and optimization of the performance profile of the solution.

For this solicitation FSA is requiring a Performance Test to show the offeror’s system can handle the voluems of borrower being projected to migrate. Future requests for performance testing will be done through the Change Request process.

NDGC Hosted Solutions For internally hosted solutions (such as the FSA Next Generation Data Center), the Contractor shall support FSA independent performance testing of solutions by providing data, scenarios, volumes, support of performance testing activities, and capacity estimates, including trending of performance data. The Contractor shall resolve issues identified during performance testing activities. The Contractor shall support the testing of any interfacing application. The Contractor shall provide a document summarizing the changes associated with architecture and design of the system to support capacity planning and optimization of the performance profile of the solution.

Partner Testing Instructions: Should this be the CR process or should be make them test with partners when PARTNERs need testing?

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The contractor shall conduct and support intersystem testing between its area of responsibility and other entities that do business with FSA. The contractor shall provide resources, interface control documents, test data, and test cases/scenarios in support of intersystem testing. FSA has a weekly maintenance window that allows it to facilitate scheduled testing.

Documentation of Defects Instructions: FSA is not purchasing the intellectual property of the commercial loan servicing software therefore we are NOT requesting requesting defect reports on anything other than what is being created from the Change Request process.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

In accord with FSA's Enterprise Test Management Standards, the Contractor shall document defects found during testing. The contractor shall resolve issues identified during all phases of the inter-system testing and shall provide to the FSA its defect resolution report or documentation.

https://studentaid.ed.gov/sa/sites/default/files/fsawg/static/gw/docs/ciolibrary/FSA_Enterprise_Test_Management_Standards.pdf.

Configuration Management Plan and Activities Instructions: FSA will accept any Systems Development Life Cycle (SDLC) plan an offeror has in place. FSA will require the offeror to explain how its SDLC will interface with FSA’s Lifecycle Management Methodology (LMM).

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The contractor shall develop a configuration management plan, for all systems in development and production, in accord with the standards defined in the Lifecycle Management Methodology. Refer to the Lifecycle Management Methodology section of the Federal Student Aid Technology Office IT Standards Library for additional information.

https://studentaid.ed.gov/about/contracting-info/it-standards

Independent Verification and Validation Instructions: This is only required if FSA creates a solicitation for and IV&V contractor

Will you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

This contract is subject to Independent Verification and Validation (IV&V) and the contractor shall support Federal Student Aid IV&V activities. Explicit deliverables of Federal Student Aid Information under the contract may include, but is not limited to, project management, technical, quality control, and quality assurance work products. Refer to the Federal Student Aid Independent Verification and Validation Handbook for additional information.

Operations Instructions: This is a statement of responsibility.

Will you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

Contractor shall be liable for breaches of security resulting from failure to follow FSA security processes and the federal law, guidance documents, and security standards referenced herein below in FSA Clause 39-4: Remedies for Contractor’s Violation of System Security Requirements

Contractor Employee Security Clearance Monitoring Instructions: This is part of the ATO requirements now.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The Contractor shall comply with service level agreement measurements to facilitate prompt and effective processing of contractors’ and employees’ security clearances. See “Service Level Agreements for Contractor Employee Clearance Monitoring” in IRPE Appendix-D below.

Contractor Operations Locations Security Language Instructions: This is part of the ATO procedurese now.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

Please refer to the following applicable FSA Clause:

FSA Clause 39-4: Remedies for Contractor’s Violation of System Security Requirements

Capacity Planning and Management Capacity Collaboration Requirement Instructions: Since we are going down to two Servicing vendors capacity planning is now a critical process within Servicing.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The contractor shall collaboratively and actively participate in FSA information technology resources capacity reviews and provide information to support: usage of current capacity; forecast for infrastructure resources including telecommunications; current and new systems to meet Federal Student Aid’s business needs

Capacity Planning Requirement Instructions: Since we are going down to two Servicing vendors capacity planning is now a critical process within Servicing.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

As per FSA directions, the Contractor will-create/revise, new and existing Information Technology Resources, including, periodic capacity-planning reports and recommendations. . In order to produce a forecast and recommendations with specific sizes, quantities, types and timing, the reports and recommendations shall evaluate Information Technology Resources requirements and trends.

The contractor shall support the data center capacity planning schedule and process. The contractor will provide input relative to the performance of the application/tool and its supporting infrastructure. This will, include but not be limited to system response time and/or latency, system capacity, storage requirements, utilization, performance, etc.

Capacity Management Requirement Instructions: Since we are going down to two Servicing vendors capacity planning is now a critical process within Servicing.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

As per the Department’s approval, the contractor shall, for all Information Technology Resources that it supports, completely monitor and manage capacity to ensure that information technology resources are being operated within minimum and maximum thresholds.

The contractor shall produce written capacity management reports at intervals stipulated in the deliverables table, which summarize actions taken since the last report and which provide prescriptive recommendations to minimize cost and maximize efficiency.

Data Migration Planning Instructions: The ISS Solicitation is already asking for each offerors solution to receiving

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The contractor shall provide a Data Migration Plan for solutions that involve the movement, creation, modification, or decommissioning of operations data supporting any Federal Student Aid information system in alignment with the approved federal records schedule and in compliance with the Records Act. Refer to the Lifecycle Management Methodology section of the Federal Student Aid Technology Office IT Standards Library for additional information.

Data Segregation Instructions: We are not expecting any of our offerors to meet this requirement as of Go Live, but we will need detailed information on how each offeror will meet this requirement and the time frames for completing this work. Please feel free you use other documents to attach as artifacts to answer this element.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

Contractor shall maintain a segregation of FSA data from all non-FSA data within its infrastructure, both in storage and during the transmission of the data. This will also be a requirement for Trusted Internet Connections (TIC), Managed Trusted Internet Protocol Services (MTIPS), and Domain Name System Security Extensions (DNSSEC).

· Physical Separation

· Contractor shall provide and maintain a physically segregated network based upon the FSA defined landing zones documented in the FSA Network Operating Standards and the function of systems operating in the FSA environment.

· Contractor shall ensure separate hardware for each landing zone to include, but not limited to network devices, routers, switches, firewalls, and load balancers.

· Contractor shall ensure virtual machines exist on physically separate equipment for each landing zone including virtual routers and switches.

· Logical Separation

· FSA data and transactions on mainframes shall be hosted in separate partitions that do not share resources with other IT users of the mainframe.

· Monitoring and reporting segregation

· The Contractor shall provide a quarterly report that identifies systems by name and IP address to identify potential problems in maintaining segregation of systems.

· The Contractor shall monthly monitor, track, and report on physical segregation to ensure it is maintained.

· The Contractor shall follow an FSA approved process for changes to network configurations.

· The Contractor shall provide a report to validate that moves, additions, and changes have been appropriately requested and implemented.

· The Contractor shall use the change-management process to identify potential security gaps in segregation maintenance, and shall report status and findings quarterly.

Data Management Documentation Instructions: FSA is not requesting this information now but we are asking if you have this information available for FSA to request in the future.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The Contractor shall provide detailed file layouts for all production data files, loads, and extracts comprising or supporting any Federal Student Aid information system per the guidance provided in the Federal Student Aid Data Standardization Policies and Procedures in effect at the time of the solicitation. Additionally, the contractor shall include detailed source target mapping, conceptual (where applicable), logical and physical data models, and detailed data dictionaries for all production database structures per the guidance provided in Federal Student Aid Data Model Standards and Guidelines, Registration Policies and Procedures, and Federal Student Aid Enterprise Data Dictionary Standards in effect at the time of the solicitation.

Network Management Instructions: This is part of the current ATO procedures.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The contractor shall request by written submittal all telecommunications requirements and changes through the Federal Student Aid Enterprise Change Management (ECM) process. All communication changes, new or existing, shall conform to Federal Student Aid Security standards and shall undergo security reviews. All applications and infrastructure residing in or connecting to an FSA data center shall be IPV6 compatible and compliant.

Software Licensing and Technical Data Rights and Management Please refer to the following FAR and FSA clauses as determined applicable by the Contracting Officer and included elsewhere in the contract:

· FAR Provision 52.227-15 – Representation of Limited Rights Data and Restricted Computer Software

· FAR Clause 52.227-14 – Rights in Data - General and the following alternates to 52.227-14

· Alternate II – If contractor represents that limited rights data will be provided

· Alternate III – If contractor represents that restricted computer software will be provided

· FSA Clause 52.227-16 – Additional Data Requirements if all data delivery requirements have not been identified.

· FSA Clause 52.227-17 Rights in Data – Special Works if the Government needs to restrict the contractor from use and release of data such as privacy data.

· FSA Clause 52.227-21 – Technical Data Declaration, Revision, and Withholding of Payment – Systems in all major system contracts.

· FSA Clause 52.227-22 – Major System – Minimum Rights in all major system contracts.

· FSA Clause 52.227-23 – Rights to Proposal Data (Technical) if there may be technical data in the proposals for which the Government may require unlimited rights.

· FSA Clause 52.227-19 – Commercial Computer Software Licenses in all direct orders for commercial off-the-shelf (COTS) software.

· FSA local clause 27-2 Contractor Use of Government Commercial Software in all contracts.

Incident and Problem Management Instructions: These are current requirements for all FSA contractors.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

The contractor shall use the FSA data center services and the Department of Education Help Desk to report all incidents. “All incidents” includes those occurring inside the FSA data center environment, and also those incidents occurring in contractor’s applications outside the FSA data center environment. Until service is restored, the contractor shall assist immediately in timely notification,within 30 minutes of the incident occurance and within 24 hours of follow up issues, escalation and resolution of any incidents that impact application degradation or outages. The contractor shall collaboratively participate in identifying the root cause of incident. The contractor shall also, develop solutions that resolve the issues and implement and test any corrective actions. In matters relevant to FSA systems impacted by the contractor’s work effort, the Contractor shall provide FSA and the FSA data center support and input into root-cause analysis.

Disaster Recovery and Continuity of Services Instructions: This is currently work done for all FSA contractors.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

If the system/application is hosted and operates separate from and external to the Next Generation Data Center (NGDC), the contractor shall ensure that externally hosted FSA operations may be fully recovered. The contractor shall do so by implementing (execute) its Disaster Recovery Plan every year and shall provide evidence that it conducted the following efforts:

· To enable Federal Student Aid to continue operating during and after a disaster, the contractor shall develop, create, test, and maintain a Disaster Recovery Plan and its attending processes and procedures.

· If FSA launches the Disaster Recovery plan, the plan’s procedures shall precisely describe each Disaster Recovery team-member’s duties, responsibilities, and actions.

· A Disaster Recovery Plan will manage incidents that impact any/all FSA business-critical processes and activities. Incidents could range from a single server’s or server room’s failure, to a major facility’s complete malfunction.

· The contractor shall participate in and support testing of end-to-end transaction processing. In all appropriate Disaster Recovery tests (or exercises), the contractor will include internal FSA units and appropriate external entities.

· The contractor shall participate in annual Disaster Recovery Plan reviews, and in Disaster Recovery awareness and training exercises. Systems staff and support contractors shall contribute to annual business impact analyses and shall annually update VDC Business processes and applications. When a major system change (update to servers etc.) necessitates additional analyses or testing, the contractor shall provide additional input into VDC Business processes and applications.

· The contractor shall also assume responsibility for, and/or the following Disaster Recovery actions:

· Escalation authority

· Team members’ notification and team members’ responsibility assignments

· Disaster Recovery Plan storage

· Compilation of all contact lists that include phone numbers and email addresses

· Application server mapping

· Recovery/Reconstitution Plan

· Documentation will comply with current NIST 800-34 and NIST 800-53 requirements.

(NOTE: The plan will yield full recovery of FSA’s current, day-to-day, operations’ infrastructure, network and databases. After any disaster, Federal Student Aid expects a 99.9% recovery to pre-disaster function status.)

Please also refer to the applicable FSA local clauses as determined applicable by the Conracting Offficer and included elsewhere in the contract: FSA 37-2 Continuation of Mission Critical Contractor Services and FSA 37-2 Continuation of Mission Critical Contractor Services – Alternative 1.

Information Technology Resources Retirement Instructions: This is currently part of the ATO procedures.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

When an Information Resource reaches the end of its life cycle, and access to the resource by all users has been terminated, data resident on the resources shall be protected and transferred to the Government in a usable form within [fill in, e.g. prior to final payment, or after 120 days after resource retirement, whichever comes first] so it is available for future use, and other assets shall be disposed of in accordance with NIST publication 800-88.

Transition Support Instructions: Although not a new requirement this is now a standard process for FSA procurements.

Do you meet this requirement?
IF, NO WHY?
TIME REQUIRED TO MEET THIS REQUIREMENT
Artifacts

Transition Support Instruction To ensure a smooth transition, and support of such continuity of service requirements as may be stipulated in the contract by the CO, The Contractor shall submit a Phase-In Plan as a part of its technical proposal in accordance with the Contract. The government will provide existing contract phase-out plans, if available and requested, to the proposing contractors to assist their efforts.

The Contractor shall also establish and implement plans for an orderly phase-out of the contracted operations at the termination of this Contract. The Contractor shall submit a Phase-out Plan to the CO for evaluation and approval six-months after contract start. The Contractor's phase-out procedures shall not disrupt or adversely impact the day-to-day conduct of Government business. The Contractor shall provide the CO with the copies of changes and revisions for review and approval prior to implementation.

Transition Support (Phase-In) The Contractor shall develop comprehensive procedures for phasing in contractor performance to the level prescribed and within the time allowed under the terms of this contract.

The period between Contract award date and Contract start date will constitute the phase-in period. During the phase-in period, the Contractor shall prepare to assume full responsibility for all areas of operation in accordance with the terms and conditions of this contract. The Contractor shall take all actions necessary for a smooth transition of the contracted operations.

This period will be approximately 120 calendar days in duration. The Government will make all facilities and equipment accessible to the Contractor during the phase-in period. During the last 60 days of the phase-in period, the Contractor's management personnel will be permitted to observe any on-going operations, as approved by the CO.

During the phase-in period, the Contractor shall at a minimum:

· Establish a Contractor’s Project Management Office to coordinate phase-in tasks and to be the single point of contact for…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .