DRAFT RFP 2023 12 13.pdf

PDF 1 MB Posted

Attached to
Synopsis: Unified User Interface (UUI) Federal contract opportunity
Solicitation number
47PM0024R0003
Issued by
General Services Administration

About this file

This is a draft request for proposals from the General Services Administration seeking a unified user interface solution. Key details include that the GSA seeks an on-premise, government site-hosted interface to integrate and converge data from various building operational technologies for remote monitoring and control. The solution should begin with a commercial off-the-shelf product. The base period of performance is one year with four optional one-year extensions. Pricing will be firm fixed price based on performance milestones. Security requirements and existing systems that must integrate include building automation, a fault detection platform, a computerized maintenance system, energy analytics software, and a construction management platform. The contractor must propose an agile development approach and provide various plans, documentation, and training.

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT R

FP

47PM0024R0003 - Unified User Interface

PART I - The Schedule Placeholder - Section A - will be integrated into pdf before final RFP

DRAFT DOCUMENT 47PM0024R0003 - UNIFIED USER INTERFACE (UUI)

1/73

47PM0024R0003 - Unified User Interface

TABLE OF CONTENTS

SECTION B - CLIN SCHEDULE

B.1 Services to be provided

B.2 CONTRACT LINE-ITEM NUMBERS (CLIN) & PRICING SCHEDULE

SECTION C - Description/Specifications/Statement of Objectives C.1 Purpose and Background C.2 Scope

C.2.1 Period of Performance C.3 Objectives

C.3.1 Business Objectives C.3.2 Technical Objectives

C.3.3 Training C.4 Constraints

C.4.1 Security Requirements C.4.2 IT Requirements C.4.3 HSPD-12 Compliance C.4.4 Government Furnished Equipment/Government Furnished Information C.4.5 Non Disclosure Agreements C.4.6 Data and Deliverables C.4.7 Confidentiality, Security, and Privacy C.4.8 Unauthorized Commitments C.4.9 Agile Program & Project Management Methodologies C.4.10 Other Direct Costs (ODC) C.4.11 Invoicing

SECTION D - Packaging and Marking - RESERVED SECTION E - Inspections and Acceptance - RESERVED SECTION F - Deliveries or Performance - RESERVED SECTION G - Contract Administration Data - RESERVED SECTION H - Special Contract Requirements

H.1.0 KEY PERSONNEL

H.2.0 INFORM

H.3.0 OPTIONS (Additional Buildings and Enhancements)

SECTION I - Contract Clauses SECTION J - List of Attachments SECTION K - Representations, Certifications, and Other Statements of Offerors or Respondents SECTION L - Instructions to Contractors

L.0 Provisions L.1 Questions Submission L.2 Proposal Submission

2/73

47PM0024R0003 - Unified User Interface

L.3 Cover Page L.4 Volume 1: Past Performance (no page limitation) L.5 Volume 2: Technical (100 page limitation excluding Small Business Participation and Subcontracting Plan) L.6 Volume 3: Price (no page limitation) L.7 Proposal Organization

SECTION M - Evaluation Criteria M.0 Provisions Example of Rating Chart:

M.1 Past Performance Volume 1 M.2 Technical Volume 2 M.2.1 Technical Approach M.3 Price Volume 3

3/73

47PM0024R0003 - Unified User Interface

SECTION B - CLIN SCHEDULE

B.1 Services to be provided

The principal purpose of this performance-based contract is to provide a ‘Single Pane of Glass’, otherwise known as ‘Unified User Interface’, able to highlight pertinent data from facility management systems to help bring to the surface information for a bigger picture view. The users will still be able to ‘deep dive’ into individual systems, but this tool provides the opportunity to streamline the experience and get a high-level overview of performance.

B.2 CONTRACT LINE-ITEM NUMBERS (CLIN) & PRICING SCHEDULE

Each performance milestone will be paid a Firm Fixed Price (FFP) price upon completion of each task. Other than recurring maintenance, invoice payments are performance-based payments tied to negotiated milestones.

GSA is required to track spending for the emerging and sustainable technologies appropriation it received under the Inflation Reduction Act of 2022 (IRA).

BASE PERIOD XX JULY 2024 to XX JULY 2025

CLIN Description of Supplies or Services QT Y

UNIT UNIT

PRICE

AMOUNT

0001 IRA Emerging & Sustainable (E&S) Technologies - performance based-payment per milestone schedule

1 LOT

0002 IRA Emerging & Sustainable (E&S) Technologies - on demand training modules

1 LOT

0003 IRA Emerging & Sustainable (E&S) Technologies - Maintenance and support

- software updates, platform, and server health

2 MO

0005 DATA (Not Separately Priced) NOT SEPARATELY PRICED

Total Base Year XX JULY 2024 to XX JULY 2025

4/73

47PM0024R0003 - Unified User Interface

OPTION PERIOD ONE XX JULY 2025 to XX JULY 2026

CLIN Description of Supplies or Services QTY UNIT UNIT

PRICE

AMOUNT

1001 IRA Emerging & Sustainable (E&S) Technologies - performance based-payment per milestone schedule

1 LOT

1002 IRA Emerging & Sustainable (E&S) Technologies - on demand training modules

1 LOT

1003 IRA Emerging & Sustainable (E&S) Technologies Maintenance and support -software updates, platform, and server health

12 MO

1004 IRA Emerging & Sustainable (E&S) Technologies Other Direct Costs (Travel)

NOT TO EXCEED

(NTE)

$20,000.00

1005 DATA (Not Separately Priced) NOT SEPARATELY PRICED

1006 OPTIONAL SERVICE: Additional sites (additional buildings) Prepriced: loaded price per integration hour _______ (NTE)

1 LOT NTE Completed before final

RFP

release

Total Option Year One XX JULY 2025 to XX JULY 2026

OPTION PERIOD TWO XX JULY 2026 to XX JULY 2027

CLIN Description of Supplies or Services QTY UNIT UNIT

PRICE

AMOUNT

2001 IRA Emerging & Sustainable (E&S) Technologies - performance based-payment per milestone schedule

1 LOT

2002 IRA Emerging & Sustainable (E&S) Technologies - on demand training modules

1 LOT

2003 IRA Emerging & Sustainable (E&S) Technologies Maintenance and support -software updates, platform, and server health

12 MO

5/73

47PM0024R0003 - Unified User Interface

2004 IRA Emerging & Sustainable (E&S) Technologies Other Direct Costs (Travel)

NOT TO EXCEED $20,000.00

2005 DATA (Not Separately Priced) NOT SEPARATELY PRICED

2006 OPTIONAL SERVICE: Additional sites (additional buildings) Prepriced: loaded price per integration hour _______ (NTE)

1 LOT NTE Completed before final

RFP

release

Total Option Year Two XX JULY 2026 to XX JULY 2027

OPTION PERIOD THREE XX JULY 2027 to XX JULY 2028

CLIN Description of Supplies or Services QTY UNIT UNIT

PRICE

AMOUNT

3001 Performance based-payment per milestone schedule

1 LOT

3002 On-Demand training modules 1 LOT

3003 Maintenance and support - software updates, platform, and server health

12 MO

3004 Other Direct Costs (Travel) NOT TO EXCEED $20,000.00

3005 DATA (Not Separately Priced) NOT SEPARATELY PRICED

3006 OPTIONAL SERVICE: Additional sites (additional buildings) Prepriced: loaded price per integration hour _______ (NTE)

1 LOT NTE Completed before final

RFP

release

Total Option Year Three XX JULY 2027 to XX JULY 2028

OPTION PERIOD FOUR XX JULY 2028 to XX JULY 2029

CLIN Description of Supplies or Services QTY UNIT UNIT

PRICE

AMOUNT

4001 Performance based-payment per milestone schedule

1 LOT

4002 On-Demand training modules 1 LOT

6/73

47PM0024R0003 - Unified User Interface

4003 Maintenance and support - software updates, platform, and server health

12 MO

4004 Other Direct Costs (Travel) NOT TO EXCEED $20,000.00

4005 DATA (Not Separately Priced) NOT SEPARATELY PRICED

4006 OPTIONAL SERVICE: Additional sites (additional buildings) Prepriced: loaded price per integration hour _______ (NTE)

1 LOT NTE Completed before final

RFP

release

Total Option Year Four XX JULY 2028 to XX JULY 2029

TOTAL CONTRACT PRICE (BASE PLUS FOUR (4) OPTION YEARS):

7/73

47PM0024R0003 - Unified User Interface

SECTION C - Description/Specifications/Statement of Objectives

C.1 Purpose and Background In order to improve asset management, increase operational efficiencies, and reduce energy waste, the General Services Administration (GSA), in support of the Public Buildings Service, Office of Facility Management (OFM), is seeking a Unified User Interface (UUI) solution to integrate, converge, and view data from various operational technologies (OT) for remote control and monitoring of facility equipment and systems.

Traditionally, various building OT systems (e.g. access control, building automation system (BAS), lighting, computerized maintenance management system (CMMS), energy management, metering, etc.) have been siloed from each other. GSA is seeking to unify aspects of these building OT systems by integrating them to a centralized platform to orchestrate integrated sequences of operation (ISOO).

ISOOs allow data in one system or platform to permit an action to occur in another. This Use Case is to develop a platform that pulls the data from the disparate OT systems and enterprise solutions, improving the ease with which facility members are able to access information and make data-driven decisions. The integration and convergence of various systems and ISOOs improves the efficiency and experience of the building. A UUI will be implemented for the monitoring, supervision, and OT control from a centralized location without a dependency on the end user knowing the disparate system(s) nuances.

Example Capabilities:

● Allow technicians to train on a singular building management and control graphics platform

● Act as an orchestration engine between disparate OT systems

● Streamline the most important and influential insights from various operational and enterprise solutions into one platform.

● Preference will be placed on a UUI solution that will enable users with elevated rights to independently self-configure reports, Key Performance Indicators (KPIs), trends, graphics, etc. without the need for additional custom programming or heavy involvement or licensing requirements from the vendor or provider.

The purpose of this work is to install and construct IRA-funded emerging and sustainable technology (E&ST) scope items. IRA-funded E&ST scope items shall be constructed, installed, and certified as complete and operable.

C.2 Scope The Contractor will provide an on-premise, government site-hosted, enterprise-wide unified user interface solution for operational technologies and all support for the configuration, implementation, operation, maintenance and performance of the solution.

The solution should begin with the contractor's industry-tested commercial-off-the-shelf (COTS) product to minimize costs and schedule risks associated with developmental work. The vendor solution shall meet performance standards and availability described in the vendor’s quote, shall be integrated with other Information Technology (IT) systems, shall be operated and maintained in accordance with industry best practices

8/73

47PM0024R0003 - Unified User Interface and Federal guidelines, and shall include a Service Level Agreement (SLA).

The Contractor will coordinate all technical implementation tasks with Government-designated support teams including server, application, network and/or security teams. This task includes the technical support, changes and architectural expertise to maintain the application in compliance with all existing GSA policies and guidelines. Issues that may be discovered through scan, reviews and audits shall be resolved in the timeframes defined by GSA policy. The scope of the resulting task order shall include all products and support services required to deploy, host, license, configure, integrate, enhance, and support as well as train end-users.

No additional onsite hardware or network bridge is to be required to deploy, implement, or operate the UUI solution. Proprietary protocols and naming conventions will also not be acceptable.

C.2.1 Period of Performance

C.2.1.1 The base period of performance is for one year from contract award with four, one -year option periods.

C.2.1.2 The Government envisions three execution phases:

a. Phase 1: Obtain all security approvals to deploy a fully operational, secure, on-premise, unifying platform in GSA with all required connections to source-systems, graphics and views, as well as user administration, training and support for a to-be-agreed-upon initial number of sites within the GSALink portfolio.

b. Phase 2: Iteratively enhance and extend views, functionality, training & support through balance of GSALink sites (approximately 140 sites as of fall 2023).

c. Phase 3: Operate & Maintain a high-quality enterprise solution, fully configured, compliant, licensed, and integrated, with tier 1 through tier 3 level support. The contractor is responsible for implementing and managing extension and enhancement of the solution as required by the GSA.

C.3 Objectives

C.3.1 Business Objectives

C.3.1.1 Empower building operator efficiencies with the ability to monitor actionable and key performance insights relevant to their role from disparate operational technologies through a single user interface.

a. The UUI shall serve as the front end and be built upon the existing smart building’s OT solutions and will provide a centralized platform for GSA OT operations and business systems.

b. The OT solution currently includes, but is not limited to : GSALink (SkyFoundry’s SkySpark) as the database and analytics engine for interval point data, National Computer Maintenance Management System or NCMMS (IBM Maximo), Building Automation Systems (BAS), Advanced Metering Systems (IBM Envizi), Smart Sensor platforms, and Project management systems (Kahua). The UUI solution

9/73

47PM0024R0003 - Unified User Interface will also provide flexibility to connect to future platforms as required by the Government.

c. The UUI provider shall be responsible for enhancements as goals evolve over the life of the support contract. Enhancements do not include configuration changes, technology changes, security or application patches or actions required to ensure the application remains operational (e.g. maintaining already implemented API connections). As new business needs develop, GSA will seek to leverage the existing platform(s) to meet those needs. GSA will provide detailed plans of how to implement these enhancements for review and approval of the contractor. Once agreement is reached, the contractor shall be responsible for implementing the enhancement(s). The contractor’s design approval is critical as they are responsible for the GSALink platform health and availability.

d. UUI views, rights, and insights are to be relevant to the role of the user.

The GSA estimates a minimum of five (5) user roles with distinct reporting needs, system rights, and privileges defined by their portfolio scope. Contract awardee shall refine these in collaboration with GSA upon successful award and provide flexibility to add additional roles needed. The initial proposed user roles are:

- Facility Manager - site level role

- Operations and Maintenance - site level role

- Regional Director

- Energy Manager

- Superuser

- Additional roles as needed, not yet defined

Example insights that shall be required, as source systems are available and identified by the Government, include:

- Capability to monitor equipment schedules

- Occupancy density

- Environmental metrics (energy usage intensity, greenhouse gas emissions)

- Digital signage content

- Planned and corrective work order SLAs, schedules, and requirements

- OFM KPIs

e. Portfolio, building, and/or equipment level graphics on the UUI shall be interactive to support editing of content (e.g. write back to BAS schedule or update a work order from within the UUI ) on a case-by-case basis and have redirect capability to the source system(s) of record (e.g. the BAS or NCMMS).

Typical BAS systems across the national portfolio include, but are not limited to :

Niagara, Johnson Controls, Siemens, Honeywell, others. At a minimum, provide write capability from the UUI for:

- BAS (read and write)

1. Schedules

2. Setpoints

3. Overrides

- NCMMS (read and write capability) - Update work order from UUI (e.g.

reassign a work order, edit date, add log comment, change priority)

10/73

47PM0024R0003 - Unified User Interface

- Additional future applications as needed (read and write capability)

f. UUI shall enable hoteling and/or third party event-based scheduling software to push (write) individual occupancy schedules down to BAS controllers to provide appropriate space conditioning as needed (e.g. meeting room schedule maintained in Google Calendar can provide current schedules at a more granular level than global building level schedule maintained in the BAS).

C.3.1.2 Equip building operators and managers with insights supportive of GSA goals for energy savings, emission reductions, and the extension of useful life of mechanical assets.

a. Beyond KPI summaries, the UUI shall visually indicate elevated priority of opportunities for corrective measures that support GSA-wide operational goals.

Example of such insights to visually emphasize might be:

- Display equipment summaries identifying zones impacting primary equipment, such as identifying which air handling units (AHUs) drive chiller operation or which zones drive AHU operation.

- To alert a site-level user when time, temperature, and equipment status are approaching those observed during past peak kW demand with correlations to Energy Usage Intensity (EUI) and GreenHouse Gas (GHG) emission impacts.

C.3.1.3 Provide facility operations and management teams standardized view(s) of mechanical and energy systems including statuses, settings, faults and alarms.

a. Equipment graphics are to be standardized. Equipment graphics should include digital video recorder (DVR)-style replay of BAS graphics utilizing fault detection and diagnostics (FDD) trend historian data to visualize heating ventilation and air conditioning (HVAC) equipment status, temperatures, setpoints, damper and valve positions during alarms and faults. Enable floor plan level replay for identifying zones driving larger primary equipment. Equipment graphics shall provide “chalkboard” capability for operators to communicate current equipment status and challenges (Note: drive in hand, waiting on variable frequency drive

(VFD).

C.3.1.4 Identify opportunities for improved tenant comfort levels and indoor environmental quality (IEQ).

a. The UUI shall utilize thermographic floor plans. These graphics will visually identify zones with heating and cooling setpoints outside acceptable ranges.

Zones unable to meet heating or cooling setpoints, especially zones farthest from the desired temperature, should be visually prioritized. The capability for visual alerts of high CO2, high humidity, high volatile organic compounds (VOCs), or particulate matter are required where the requisite sensing is available. Parent/child relationship to avoid overwhelming the summaries with constant alerts from a single sensor or zone is strongly desired.

11/73

47PM0024R0003 - Unified User Interface

C.3.2 Technical Objectives

The following are existing enterprise solutions required for integration and the minimum requirements contractors must expand upon in their contractor provided Performance Work Statement (PWS):

C.3.2.1 Existing Enterprise Solutions

a. FDD Analytics – GSALink (SkyFoundry’s SkySpark)

- Total Estimated Cost Impacts

- Comfort Tracking

- Autocorrection Monitoring

- High Performance Sequences

- Equipment Demand Events

- Weather

b. BAS - Standardized Equipment Graphics, Schedules, Alarms – 80 plus building monitoring and control systems (BMC)

- Equipment Lockouts

- Operating Hours

- Setpoints

- Thermographic Floor Plans

c. NCMMS - Work Orders & Program Management Asset Attributes Key Performance Indicators (KPIs) – IBM Maximo (current NCMMS application)

- Approaching SLAs Work Plan

- PM Dates/Demand

- Equipment metadata

d. Metering Utilities Sustainability Energy (MUSE) - Meter Status, Demand Events, and Utility Trends – source is IBM Envizi EMIS

- Meter Connectivity

- Peaks

- Billing

- Profile

- Electric Vehicle Supply Equipment (EVSE) Chargers

e. Construction Management Software (Kahua) - Tracking design and construction projects

- Milestone Dates

12/73

47PM0024R0003 - Unified User Interface

C.3.2.2 Initial UUI Work Breakdown Structure (WBS) - (chart below)

C.3.2.3 UUI Work Breakdown Structure Dataflow - (chart below)

13/73

47PM0024R0003 - Unified User Interface

C.3.2.4: Existing Technology Architecture (chart below)

C.3.3 Training

C.3.3.1 User Acceptance Training (UAT) The contractor shall provide ongoing demos, training, and support throughout the configuration process to enable GSA team members and designated testers to fully test the system and configurations.

C.3.3.2 Training Plan The contractor shall also provide a training plan detailing the materials, resources, and timeline to deliver Go-Live Training to GSA team members and user support contractors. All training is expected to be virtual and include live training, on-demand recordings, and provide accessible material and resources.

C.3.3.3 Go-Live Training & Train-the-Trainer Go-Live Training will cover the initial launch of the solution, offered over a handful of sessions and will provide a format that allows for the submission of question and answer. The Train-the-Trainer will be a separate training for GSA subject matter experts (SMEs) to develop in-house training to provide training for those new to the UUI solution.

C.4 Constraints This section lists laws, rules, regulations, standards, technology limitations, and other constraints that the service and/or service provider must adhere to or work under.

14/73

47PM0024R0003 - Unified User Interface

C.4.1 Security Requirements The contractor shall comply with all GSA IT security requirements.

C.4.1.1 The contractor shall comply with GSA on-premise security for an on-premise solution hosted by GSA. Internal on-premise information systems reside in GSA facilities and may connect to the GSA network. Internal systems are operated on behalf of GSA. Please reference IT Security Requirements for on-premise solutions in the UUI Security Requirements-Mobile document attached.

C.4.1.2 The contractor shall comply with Mobile application requirements if a mobile application solution is being proposed. A mobile application, most commonly referred to as a mobile app, is a type of application software designed to run on a mobile device, such as a smartphone or tablet computer. GSA IT Security Requirements for Mobile Applications are contained in the UUI Security Requirements-Mobile document attached.

C.4.1.3 The solution is expected to meet moderate security requirements.

GSA Tailoring of NIST 800-53 Controls. The GSA Control Tailoring Workbook contains GSA defined values for NIST SP 800-53 Security and Privacy Controls. The workbook is not publicly available; contact the contracting officer who will coordinate with the GSA Office of the Chief Information Security Officer to determine if it can be made available.

However, the NIST 800-53 control information can be referenced here:

https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final.

C.4.2 IT Requirements

The contractor shall propose and adhere to industry standard level of support services including proposing response rates to GSA requests.

C.4.2.1 The contractor shall ensure all software is fully supported through the lifecycle of the proposed solution and is listed on the GSA Enterprise Architecture IT Standards List. This list is internal to the GSA network and vendors will not be able to access it until after award. The requirements are listed below:

a. The contractor shall identify and track all software components and associated end-of-life dates, including third-party software, used with the proposed solution as part of the system inventory.

b. As soon as the end-of-life upgrade is identified, the contractor shall notify the government of hotfixes or end-of-life dates to the operating system, middleware, database, third-party components or technical platforms (including patches) that impact the security posture or usability of the application.

DRAFT DOCUMENT 47PM0024R0003 - UNIFIED USER INTERFACE (UUI)

15/73 https://docs.google.com/document/d/15vro-zdtMyn-shcf7UL3oHQhupDVjEUbkYujQBPbZp4/edit#heading=h.32hioqz https://docs.google.com/document/d/15vro-zdtMyn-shcf7UL3oHQhupDVjEUbkYujQBPbZp4/edit#heading=h.2fk6b3p https://docs.google.com/document/d/15vro-zdtMyn-shcf7UL3oHQhupDVjEUbkYujQBPbZp4/edit#heading=h.2fk6b3p https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final

47PM0024R0003 - Unified User Interface

c. The contractor shall replace or upgrade unsupported information system components prior to the end-of-life date or provide documented justification for the continued use of supported components.

d. The contractor shall ensure all software used is approved via the GSA Enterprise Architecture IT Standard.

The IT Standards program is governed by GSA’s policy. The GSA Office of the Chief Technology Officer (OCTO) manages the process and review of IT Standards and approves changes to the IT Standards Profile and approves any software used to process, store, or transmit GSA's data. Proposed technologies must go through the Software Approval Process, which begins with a security and accessibility assessments at a minimum, and is then reviewed by the OCTO for alignment with Federal Information Technology Reform Act (FITARA) and GSA's Digital Strategy. The Building Technologies Technical Reference Guide (BTTRG) references the approval process and other information applicable to this requirement. PBS’ Technology Policy is also applicable to this requirement.

C.4.2.2 The contractor shall follow the Public Building Information Technology Services (PB-ITS) Enterprise Quality Program (EQP) and all GSA IT Security Policies.

This includes assessing vendor-developed code against requirements, validating code quality, and providing the necessary artifacts and deliverables when submitting application releases.

a. See (https://www.it-cisq.org/standards/code-quality-standards/) for guidance on how to measure, evaluate and improve software. Particular areas of importance are Performance Efficiency, Reliability, Maintainability, and Security.

b. PB-ITS reviews software code quality for security and resilience. PB-ITS references the Consortium for IT Software Quality (CISQ) (https://www.it-cisq.org/standards/code-quality-standards/) for guidance on how to measure, evaluate and improve software. Particular areas of importance are Performance Efficiency, Reliability, Maintainability and Security. PB-ITS currently uses CAST Application Intelligence Platform (AIP) and CAST Highlight to evaluate code quality for on premise non-COTS solutions.

C.4.2.3 The Contractor shall use GSA’s provided release management software, which is currently Jira.

C.4.2.4 The Contractor shall manage all releases through the DevSecOps process and shall follow the GSA DevSecOps Guide and all other PB-ITS and GSA policies, procedures, and guidance for releases. The contractor shall adhere to industry best practice-defined by DevSecOps processes using PB-ITS tools.

a. The contractor shall be responsible for providing its own development environment.

DRAFT DOCUMENT 47PM0024R0003 - UNIFIED USER INTERFACE (UUI)

16/73 https://www.gsa.gov/about-us/newsroom/congressional-testimony/the-federal-information-technology-reform-acts-fitara-role-in-reducing-it-acquisition-risk-part-ii-measuring-agencies-fitara-implementation https://www.gsa.gov/technology/government-it-initiatives/digital-strategy https://www.it-cisq.org/standards/code-quality-standards/ https://www.it-cisq.org/standards/code-quality-standards/ https://tech.gsa.gov/guides/dev_sec_ops_guide/

47PM0024R0003 - Unified User Interface

b. PB-ITS Applications Operations provides two lower environments for on-premise solutions, Integration (INT) and Test (TST), and one Production (PRD) environment. Contractor can upload and manage code to INT. GSA’s PB-ITS Applications Operations team manages the TST and PRD environments; no elevated contractor access is permitted.

c. Contractors shall submit code to a lower, non-production environment (INT) for scheduled testing and security scanning. The government PM reviews testing to determine acceptance. PB-ITS Application Operations pushes code to test environments, then production environments.

d. PB-ITS has implemented DevOps processes and tools for the automation of application installations. This solution is a collection of open source and standards-based tools currently using Jira as the front end for project managers and developers with Jenkins and Ansible for automation. The current tool set includes Jira, Jenkins, Ansible, Gitlab, Docker, Invicti, Artifactory, and Alfresco.

The level of access of these tools will vary. PB-ITS is the admin of the tools and will be responsible for certain pieces/processes as a part of the deployment process. There is an access request process for these tools and vendors will be granted access with the appropriate level of access.

Note: Database = DB, Operating System = OS

17/73

47PM0024R0003 - Unified User Interface

e. The contractor shall provide artifacts to ensure a compliant build. Those currently include Source Code, Executables and Build and TestScripts. All build scripts must be supported by Ansible, Bash or Powershell.

f. The contractor shall provide installation instructions, documentation, and data dictionary updates.

C.4.2.5 The contractor shall ensure all systems, software, equipment or their replacements are supported by Internet Protocol Version 6 (IPv6) by the year 2025 as mandated in the Office of Management and Budget (OMB) memorandum, M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” dated November 19, 2020.

C.4.2.6 The contractor shall propose dedicated support for Tier II and Tier III support and provide industry-standard SLAs.

C.4.2.7 The contractor shall use GSA’s single-sign on and multi-factor authentication (MFA) protocols to securely access the UUI solution.

a. The contractor shall support configurable integrations with GSA operated, and government-wide operated, identity and authentication / single sign on services.

The contractor shall support Security Assertion Markup Language (SAML) 2.0 and/or OpenID Connect integrations. GSA will identify and provide the service(s) upon award.

b. The contractor shall support multi-factor authentication for GSA administrator users (privileged/administrative users) through integrations with a GSA managed identity and authentication service. The contractor shall support SAML 2.0 and/or OpenID Connect integrations. GSA will identify and provide the service(s) upon award.

c. The contractor shall support SCIM (System for Cross-domain Identity Management) or a vendor secured representational state transfer application programming interface RESTful (API) for GSA to create and manage GSA end user accounts. This includes creation, assignment of roles, and termination.

d. The contractor information system/IT solution shall support role-based access controls to distinguish between end users needing access to different levels of data (e.g., end users only needing access to non-sensitive data and end users needing access to sensitive data).

C.4.2.8 The contractor shall use human-centered design practices to create a product that is easy for the government to use. This contract requires the delivery of functional products in a manner that enhances our end-users’ experience. The contractor shall:

a. Provide expert guidance and direction on user experience (UX) strategy, research, and design.

DRAFT DOCUMENT 47PM0024R0003 - UNIFIED USER INTERFACE (UUI)

18/73 https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf

47PM0024R0003 - Unified User Interface

b. Articulate a user-centered vision for the future of the product, and establish mechanisms to measure progress.

c. Optimize products for mobile-first operation, with all solutions being equally usable on mobile and desktop.

d. Incorporate robust accessibility principles into design, and testing for all products to deliver high-quality digital experiences to users of assistive devices.

e. Follow plain language content guidelines (https://www.plainlanguage.gov/).

f. Ensure content has been optimized for Search Engine Optimization (SEO) to make information easier to find.

g. Use data and analytics along with user research to drive product decisions.

h. Create and maintain documentation for all activities, recommendations, and decisions that captures value to users as defined by them from user feedback.

i. At the start of work on a new or existing product/project, the contractor shall participate in and conduct a product kick-off meeting with GSA’s Public Building Service / Office of Facility Management / Facility Technology and Innovation / Smart Building personnel and other designated stakeholders.

j. Facilitate discovery activities, such as research with business stakeholders, an assessment of current related features, a content review, an information architecture review, an accessibility review, a business process review; and collection of any available data and analytics.

k. Conduct periodic user research to understand customers’ and users’ goals, needs, journeys, and pain points with respect to the product.

l. Conduct frequent user research to validate and iterate on all aspects of the product. This may include usability testing, content-focused testing, card sorting, tree testing, observations, etc.

m. For public-facing websites, leverage Digital Analytics Program (DAP) data in determining user goals, needs, and behaviors, or, if not available, include DAP code in the product.

n. Create a User Research Plan and Finding Summary for each study, which shall include a documentation of research questions, hypotheses, methodology, recruiting needs, synthesis, and next steps, and where applicable house findings with the code base.

o. Apply research insights to define product functionality and to continually improve content, information architecture, design, functionality, and accessibility.

p. Align with GSA’s style guide for content. This may include developing relationships with GSA subject matter experts, creating a governance and approvals process, maintaining content style guide, planning for iteratively testing content with customers and users.

q. Write and edit content using plain language best practices. Includes labeling, form questions, short guidance, long-form guidance, etc. Collaborate with GSA subject matter experts to translate complex language into user-friendly language.

DRAFT DOCUMENT 47PM0024R0003 - UNIFIED USER INTERFACE (UUI)

19/73 https://www.plainlanguage.gov/

47PM0024R0003 - Unified User Interface

r. Design interfaces such as page layout, content design, menus and navigation, information architecture, and user flows; mobile and desktop wireframes and high-fidelity interactive prototypes.

s. Create designs that use the U.S. Web Design System and, when applicable, align with GSA’s design system.

t. Conduct usability and user acceptance testing on new designs, features, content, navigational elements, etc. to ensure a quality end-user experience.

u. Employ inclusive design, accessibility, and user experience best practices with all research, content, and design activities to foster a quality experience for customers and users.

v. Create a plan for continuous user research and validation that can continue to guide product direction post-contract.

C.4.2.9 Inclusive Design/Accessibility/Section 508 Compliance: The contractor shall ensure that the product is designed to serve a diverse user population. This includes, but is not limited to, users with physical and cognitive disabilities (who may use a variety of assistive technology), low English proficiency, low English literacy, different cultural backgrounds, a lack of access to fast internet connection, and/or whose primary access is with a mobile device. The contractor shall comply with Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d). In accordance with Federal Register, 25 APR 01, FAC 97-27, Executive Order 12866, Part 2.101, FAR Part 7.103, FAR Part 10.001, FAR Part 11.002, FAR Part 12.202, FAR Part 39.000 & 39.2, access to electronic and information technology (EIT) by individuals with disabilities must be compliant with the accessibility standards at 36 CFR 1194, unless it falls under one of the exceptions noted in FAR 39.204. Additional information and requirements related to 508 Compliance can be located http://www.section508.gov.

The contractor shall conduct automated and manual accessibility tests using common screen readers and diagnostic tools; GSA may need access to these tests to ensure full 508 compliance. At a minimum, this should be done before each launch, major update, or new release. The contractor shall also create and maintain documentation for all related activities, recommendations, and decisions.

C.4.2.10 Integration/Data The contractor shall integrate their proposed UUI solution with BAS, GSALink (SkyFoundry’s SkySpark), NCMMS (IBM Maximo), Muse (IBM Envizi) and Kahua. (see UUI Work Breakdown Structure Dataflow image above)

Capabilities of Existing Systems

BAS Kahua GSALink NCMMS MUSE

Connectors ✔ ✔ ✔ ✔ ✔

Flexible ✔ N/A ✔ ✔ N/A

20/73

47PM0024R0003 - Unified User Interface

Connection

Bulk Data Transfer ✔ ✔ ✔ ✔ ✔

Bi-directional Data Feed

Synchronous Communication

✔ Unknown ✔ ✔ N/A

Asynchronous Communication

✔ Unknown ✔ ✔ N/A

Monitor Transactions

✔ ✔ ✔ ✔ N/A

Send Task N/A ✔ ✔ ✔ N/A

Receive Tasks TBD ✔ ✔ ✔ N/A

a. Building Automation System (BAS) is a diverse set of inventory.

- Currently integrates with GSALink (via SkySpark); sparks are event triggers to identify equipment operating outside of expected thresholds

- Connectors: flexible (open system)

b. Kahua is a construction management software solution

- Dashboards and reporting capability

- Workflow system capable of understanding tasks; Automation is built-in which enables workflows to be completed

- Transaction Monitoring: capable as automation is built-in

- System Limitation: push and pull data via API, no ETL integration capabilities at this time

c. GSALink is a fault detection and diagnostic platform

- It integrates building automation systems (BAS) data via Skyspark

- If something breaks a rule, it sets off a “spark” and a notification is sent to the building manager through NCMMS

- GSALink uses Skyspark for Analytics (data capture, trending rules) and NCMMS is used for reporting

- When faults are detected in GSALink they come through NCMMS

- Connectors: flexible; open system/BACnet

- GSALink leverages IBM Maximo to establish a connection with NCMMS via

REST API

- Capable of synchronous/asynchronous communication and monitoring transactions

d. NCMMS (IBM Maximo) is a computerized maintenance management system

(CMMS),

21/73

47PM0024R0003 - Unified User Interface

- Hosted on vendor managed Amazon Web Services (AWS) but accessible through GSA Firewall

- Transaction Monitoring: system is capable of performing preventative actions+listener+auto generating tickets

- Connectors: manual when not API; automatic orchestration possible

- Flexibility of Connectors: capability exists to add connectors however not implemented

- Synchronous Communication: capable but may need additional assessment;

- Asynchronous Communication: extract, transform, and load (ETL) translator for 2-way communication capable; ability to initiate workflows, can integrate with MUSE

- Send Task or Work Orders w/ building information modeling (BIM) : future integration

- Bulk Data Transfer: data ingested via web services call, comma separated values (CSV) format, ETL, REST Interfaces

e. MUSE (IBM ENVZI) is SaaS reporting and analytics dashboard; it only ingests data and analyzes the data

- Connectors: application programming interface / secure file transfer protocol

(API/SFTP)

- Information is received every 15 min from utilities and daily for other systems outside GSA

- Data push via API, data pull via SFTP, no other connectors supported

- Business intelligence (BI) connection is only to share information with users getting reports from BI

- Fully cloud service

- Internal GSA users only, no external users

f. Additional Platforms as GSA needs evolve (see Phase 3 requirements above)

C.4.3 HSPD-12 Compliance The contractor shall comply with agency personal identity verification procedures identified in the contract that implement Homeland Security Presidential Directive 12 (HSPD-12), Office of Management and Budget (OMB) guidance M-05-24, and Federal Information Processing Standards Publication (FIPS PUB) Number 201.

For any contractor personnel performing work under this contract who will require access to GSA IT applications, systems or data, the contractor shall comply with the HSPD-12 security clearance process. This means first obtaining a fingerprint clearance, which typically takes 3-4 weeks. At that point, the Authorizing Official (AO) can grant limited access on a case-by-case basis. Next, a preliminary favorable adjudication of their Tier 2S clearance level must be received. This process can take 1 to 2 months.

Only when a full Tier 2S adjudication is received will full access be granted. This process usually takes 4 to 8 months, though it could take as many as 12 months. Higher levels of clearance may also be required depending on the level of trust required to perform specific duties or perform a specific task.

Contractors shall not be granted access to a GSA facility or to any GSA IT system prior to a favorable response to the fingerprint portion of this background investigation. An

22/73

47PM0024R0003 - Unified User Interface individual contractor’s failure to return satisfactory results from the background investigation shall result in immediate removal of that contractor.

The Contracting Officer, through the Contracting Officer’s Representative (COR) or GSA Program Manager (PM) will ensure that a completed Contractor Information Worksheet (CIW) for each Applicant is forwarded to the Federal Protective Service (FPS) in accordance with the GSA/FPS Contractor Suitability and Adjudication Program Implementation Plan dated 20 February 2007 and ADM 2181.1 Homeland Security Presidential Directive-12 Personal Identity Verification (PIV) and Credentialing Policy, and Background Investigations for Contractor Employees dated March 18, 2020. FPS will then contact each Applicant with instructions for completing required forms and releases for the particular type of personnel investigation requested.

Applicants will not be reinvestigated if a prior favorable adjudication is on file with FPS or GSA, there has been less than a one-year break in service, and the position is identified at the same or lower risk level.

Once a favorable FBI Criminal History Check (Fingerprint Check) has been returned, Applicants may receive a GSA identity credential, a PIV card, (if required) and initial access to GSA information systems. The HSPD-12 Handbook contains procedures for obtaining identity credentials and access to GSA information systems as well as procedures to be followed in case of unfavorable adjudications.

The contractor shall be required to fund their employees’ security clearance and background investigation processes. The Government will not provide funding for these requirements.

HSPD-12 requirements do not apply to contractor IT applications, systems or data.

HSPD-12 applies to all GSA IT systems owned or operated on behalf of GSA.

C.4.4 Government Furnished Equipment/Government Furnished Information Government Furnished Equipment (GFE) including PIV cards or Government Furnished Information (GFI) may be provided to the contractor during the period of performance of the contract, under the following conditions (see CIO 2160.4A Provisioning IT resources policy described below):

C.4.4.1 Use of the GFE and GFI is for the sole purpose of completing the requirements of this contract.

C.4.4.2 The contract employee has received a pre-favorable background investigation determination/adjudication; expected to result in a final favorable determination/adjudication, or the contract employee has already received a final favorable background investigation determination/adjudication.

C.4.4.3 GFE may include virtual desktop access provided by GSA and does not necessarily constitute the distribution of hardware to the Contractor. Access to the GSA network, whether direct or through other means, such as the GSA Virtual Private Network (VPN), is contingent upon each contract employee having successfully received a pre and final favorable background investigation.

C.4.4.4 The estimated GFE is to be determined (TBD) and can include virtual desktops or laptops as determined by the Government.

23/73

47PM0024R0003 - Unified User Interface

C.4.4.5 All Government unique information related to this requirement, which is necessary for contractor performance, will be made available to the contractor.

C.4.5 Non Disclosure Agreements Standard non-disclosure statements shall be completed by all vendor system administration and other personnel who may have or potentially could have access to government data. The vendor shall sign and return these agreements to the CO before but no later than 5 days after the post award orientation.

C.4.6 Data and Deliverables All data (asset information, tickets, contact information, project information, content metadata, etc) is and shall remain the property of the Government.

C.4.6.1 The contractor shall ensure that the government retains access and download capability of all data for research, investigation, transfer, or migration to other systems. Data management and retention will be handled as directed by GSA and in conjunction with current Controlled Unclassified Information (CUI) guidelines.

C.4.6.2 The contractor shall deliver the deliverables outlined in the contractor-developed PWS and WBS, (and any additional deliverables that the Contracting Officer may require in writing) on dates as the Contracting Officer may specify. All deliverables expected to be included in the contractor-developed PWS are included as data as well as deliverables.

C.4.6.3 All documentation, including, but not limited to, documented processes, procedures, software tools and applications, test materials, text, notes, electronic files, data, new capabilities or modification of existing applications, source code and records generated, modified, acquired or produced by the contractor under the resultant contract shall become the property of the Government. In accordance with the Federal Acquisitions Regulation (FAR) 52.227-14(b), the Government shall have unlimited rights to all produced materials, including the right to modify, distribute and publish. The contractor shall deliver electronic copies of all produced materials to the Government quarterly (or as requested) and upon expiration or termination of this contract. The contractor may mark the deliverables to indicate its authorship, provided, however, that it shall not include any markings inconsistent with the Government’s unlimited rights.

The contractor agrees that the Government may release any deliverable in response to a Freedom of Information Act (FOIA) request, subject to any right to object or to request redactions that the contractor may otherwise have under the Act or under applicable agency regulations.

C.4.6.4 All deliverables in printed or other media forms containing personally identifiable information (PII) and/or SBU information shall follow applicable policies including GSAs PBS P 3490.3 or latest order. The contractor shall ensure and deliver the application is designed to function in accordance with applicable Federal Information Processing Standards Publication (FIPS PUB) 140-2 and all applicable annexes or subsequently approved federally recognized policy for the protection, operation and/or delivery of Federal information technology systems.

24/73

47PM0024R0003 - Unified User Interface

C.4.7 Confidentiality, Security, and Privacy The contractor shall be responsible for the privacy and security safeguards in accordance with the FAR clause 52.239-1.

C.4.7.1 The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under the contract. In addition, the contractor shall protect all government data, equipment, or information by treating the material as CUI information, data, and/or equipment shall only be disclosed to authorized personnel. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected. When no longer required,the CO/COR will give instructions whether this information, data, and/or equipment shall be returned to Government control, destroyed, or held until otherwise directed. Items returned to the Government will be hand carried or mailed to the COR using certified mail. Per instructions, the contractor shall destroy unneeded items by burning, shredding, or any other method that precludes the reconstruction of the material.

a. The contractor shall not publish or disclose in any manner, without the CO’s written consent, the details of any safeguards used by the contractor under the resulting contract or otherwise provided by or for the Government.

b. To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of any non public government data collected and stored by the contractor, the contractor shall afford the Government access to the contractor’s facilities, installations, technical capabilities, operations, documentation, records, and databases.

c. If new or unanticipated threats or hazards are discovered by either the Government or the contractor, or if existing safeguards have ceased to function, the discoverer shall immediately bring the situation to the attention of the other party.

d. The contractor’s solution shall meet the NIST Special Publication (SP) 800 53, Revision 4, control requirements for FIPS 199 Moderate Impact systems.

e. The contractor's solution shall comply with the GSA CIO IT Security Procedural Guide CIO IT Security 09 48, Security Language for IT Acquisition Efforts. The critical requirements from this guide are covered in the SOO attachment titled "UUI Security Requirements-Mobile".

f. Work on this project may require or allow contractor personnel access to Privacy Information. Contractor personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.

g. The contractor’s solution shall meet the requirements of the Federal Information Security Management Act of 2002 (FISMA), 44 U.S.C. § 3541.

C.4.8 Unauthorized Commitments The COR, PM, or any other government representative is not authorized to change any of the terms and conditions of the contract. Changes, if any, shall be made by the Contracting Officer only.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .