DRAFT RFP_36C10B23R0011.docx
DOCX document 454 KB Posted
- Attached to
- DA01--Transformation Twenty-One Total Technology Next Generation 2 (T4NG2) Federal contract opportunity
- Solicitation number
- 36C10B23R0011
About this file
This draft request for proposal (RFP) is for the Transformation Twenty-One Total Technology Next Generation 2 (T4NG2) effort to provide information technology services and solutions to the Department of Veterans Affairs (VA). The RFP will be finalized in February 2023. Interested offerors can submit questions about the draft RFP by January 20, 2023 to the email address provided. The RFP will result in multiple award indefinite delivery/indefinite quantity contracts to support the full range of IT requirements for the VA, including systems/software engineering, cybersecurity, training, and facilities, over a five-year base period and one five-year option. Pricing will be on firm-fixed-price, time-and-materials, and cost reimbursement bases at the task order level. The maximum value of the contracts is $60.7 billion over ten years.
View the file
Other files for this federal contract opportunity
Show all 50
DA01--Transformation Twenty-One Total Technology Next Generation 2 (T4NG2) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
36C10B23R0011
PART I - THE SCHEDULE1. THIS CONTRACT IS A RATED ORDER
RATING
PAGE OF
PAGES
UNDER DPAS (15 CFR 700)
2. CONTRACT NUMBER
3. SOLICITATION NUMBER
4. TYPE OF SOLICITATION
5. DATE ISSUED
6. REQUISITION/PURCHASE NUMBER
SEALED BID (IFB)
NEGOTIATED (RFP)
7. ISSUED BY
CODE
8. ADDRESS OFFER TO
(If other than Item 7) NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".
9. Sealed offers in original and _____________________________ copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in Until local time _______________________ (Hour) (Date) CAUTION - LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All Offers are subject to all terms and conditions contained in this solicitation.
A. NAME
B. TELEPHONE (NO COLLECT CALLS)
C. E-MAIL ADDRESS
AREA CODE
NUMBER
EXT.
(X)
SEC.
DESCRIPTION
PAGE(S)
(X)
SEC.
DESCRIPTION
PAGE(S)
PART I - THE SCHEDULE
PART II - CONTRACT CLAUSES
A
SOLICITATION/CONTRACT FORM
I
CONTRACT CLAUSES
B
SUPPLIES OR SERVICES AND PRICES/COSTS
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACH.
C
DESCRIPTION/SPECS./WORK STATEMENT
J
LIST OF ATTACHMENTS
D
PACKAGING AND MARKING
PART IV - REPRESENTATIONS AND INSTRUCTIONS
E
INSPECTION AND ACCEPTANCE
F
DELIVERIES OR PERFORMANCE
G
CONTRACT ADMINISTRATION DATA
L
INSTR., CONDS., AND NOTICES TO OFFERORS
H
SPECIAL CONTRACT REQUIREMENTS
M
EVALUATION FACTORS FOR AWARD
K
REPRESENTATIONS, CERTIFICATIONS AND OTHER
STATEMENTS OF OFFERORS
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
12. In compliance with the above, the undersigned agrees, if this offer is accepted within ________ calendar days (60 calendar days unless a different period is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
10 CALENDAR DAYS (%)
20 CALENDAR DAYS (%)
30 CALENDAR DAYS (%)
CALENDAR DAYS (%)
(See Section I, Clause No. 52-232-8)
14. ACKNOWLEDGEMENT OF AMENDMENTS
AMENDMENT NO.
DATE
AMENDMENT NO.
DATE
(The offeror acknowledges receipt of amendments to the SOLICITATION for offerors and related documents numbered and dated:
DUNS:
DUNS+4:
CODE
FACILITY
16. NAME AND TITLE OF PERSON AUTHORIZED TO SIGN OFFER
15A. NAME AND
ADDRESS OF
OFFEROR
(Type or print)
15B. TELEPHONE NUMBER
17. SIGNATURE
18. OFFER DATE
AREA CODE
NUMBER
EXT.
15C. CHECK IF REMITTANCE ADDRESS IS DIFFERENT FROM
ABOVE - ENTER SUCH ADDRESS IN SCHEDULE
19. ACCEPTED AS TO ITEMS NUMBERED
20. AMOUNT
21. ACCOUNTING AND APPROPRIATION
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
23. SUBMIT INVOICES TO ADDRESS SHOWN IN
ITEM
(4 copies unless otherwise specified) 10 U.S.C. 2304(a) ( ) 41 U.S.C. 253(c) ( )
24. ADMINISTERED BY (If other than Item 7)
25. PAYMENT WILL BE MADE BY
CODE
CODE
PHONE:
FAX:
26. NAME OF CONTRACTING OFFICER (Type or print)
27. UNITED STATES OF AMERICA
28. AWARD DATE
IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.
(Signature of Contracting Officer)
(REV. 9-97)
10. FOR INFORMATION CALL:
11. TABLE OF CONTENTS
AUTHORIZED FOR LOCAL REPRODUCTION
STANDARD FORM 33
Previous edition is unusable Prescribed by GSA-FAR (48 CFR) 53.214(c)
SOLICITATION, OFFER AND AWARD
SOLICITATION
OFFER (Must be fully completed by offeror) AWARD (To be completed by Government) N/A 36C10B23R0011 X Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 T4NG2.TAC@va.gov See Attached Table of Contents X X X X X X X X X X X X X Department of Veterans Affairs Technology Acquisition Center 23 Christopher Way Eatontown NJ 07724 Department of Veterans Affairs Technology Acquisition Center Financial Services Center PO Box 149971 Austin TX 78714-8971
SECTION A - SOLICITATION/CONTRACT FORM
SF 33 SOLICITATION, OFFER AND A
CONTENTS
| PART I - THE SCHEDULE | 1 |
| SECTION A - SOLICITATION/CONTRACT FORM | 1 |
| SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS | 3 |
SECTION C - DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK
| SECTION D - PACKAGING AND MARKING | 82 |
| SECTION E - INSPECTION AND ACCEPTANCE | 83 |
| SECTION F - DELIVERIES OR PERFORMANCE | 84 |
| SECTION G - CONTRACT ADMINISTRATION DATA | 85 |
| SECTION H - SPECIAL CONTRACT REQUIREMENTS | 87 |
| PART II - CONTRACT CLAUSES | 94 |
| SECTION I - CONTRACT CLAUSES | 94 |
| PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS | 119 |
| SECTION J - LIST OF ATTACHMENTS | 119 |
| PART IV - REPRESENTATIONS AND INSTRUCTIONS | 120 |
| SECTION K - REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFERORS | 120 |
| SECTION L - INSTRUCTIONS, CONDITIONS, AND NOTICES TO OFFERORS | 128 |
| SECTION M - EVALUATION FACTOR FOR AWARD | 152 |
SECTION B - SUPPLIES OR SERVICES AND PRICE/COSTS
B.1 GOVERNING LAW
Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S. Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.
B.2 HYBRID CONTRACT TYPE
The contract type is a hybrid containing: Firm-fixed-Price (FFP), Time-and-Materials (T&M)/Labor-hour (LH), Cost reimbursement (CR) line items.
B.3 PRICE SCHEDULE:
NOTE: FOR PROPOSAL PURPOSES ONLY, CLIN PRICING IS NOT REQUIRED IN SECTION B OF THIS SOLICITATION.
All price proposals must be submitted in the format provided at Section J, Attachment 001. The deliverables associated with Contract Line Item Numbers (CLIN) 0004 through 0011 shall be submitted for each task order and included in the price/cost of each task order. The specific deliverables under CLINs 0004 through 0011 will not be set forth under individual Task Orders.
PRICE SCHEDULE
BASE PERIOD
| CLIN |
| DESCRIPTION |
| QUANTITY |
| UNIT |
| UNIT COSTS |
| TOTAL COST |
| 0001 |
| Firm-Fixed-Price Line Item |
SECURITY CLASS: Determined at Task Order Level This CLIN is to provide Information Technology (IT) services and incidental supplies on a FFP basis for a period of 60 months from date of award in accordance with (IAW) the Transformation Twenty-One Total Technology Next Generation Two (T4NG2) Performance Work Statement (PWS) set forth in Section C.
Specific requirements and pricing shall be set forth under individual Task Orders.
Inspection, Acceptance, and Free on Board (FOB) Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.
The delivery or performance schedule shall be determined on each individual Task Order.
| 0002 |
| Time-and-Materials/Labor-Hour Line Item |
SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a T&M/LH basis for a period of 60 months from date of award IAW the T4NG2 PWS set forth in Section C.
Specific requirements and pricing shall be set forth under individual Task Orders.
Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.
| 0003 |
| Cost Reimbursement Line Item |
SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a CR basis for a period of 60 months from date of award IAW the T4NG2 PWS set forth in Section C.
Specific requirements and pricing shall be set forth under individual Task Orders.
Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.
| 0004 |
| Contractor’s Progress, Status, and Management Report |
Monthly Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.1(A) and (B)(C)(D) and (E), and Section J Attachment 003 when applicable to Task Order contract type.
FOB Point: Destination Inspection/Acceptance: Destination
| NSP |
| NSP |
| 0005 |
| Contract Performance Report |
Contract Performance Report shall be provided IAW Section C, PWS, Paragraph 8.1.2 (A) and (B), and Section J Attachments 004 (T&M) and 005 (CR) when applicable to Task Order contract type. Report not applicable for FFP Task Orders.
| NSP |
| NSP |
| 0006 |
| Government Furnished Equipment Status Report |
Government Furnished Equipment Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.3 (A-K) and Section J, Attachment 006.
| NSP |
| NSP |
| 0007 |
| Personnel Contractor Manpower Report |
Personnel Contractor Manpower Report shall be provided IAW Section C, PWS, Paragraph 8.1.4 (A-S) and Section J, Attachment 008.
| NSP |
| NSP |
| 0008 |
| Contractor Staff Roster |
Contractor Staff Roster shall be provided IAW Section C, PWS, Paragraph 8.1.5 and Section J, Attachment 009.
| NSP |
| NSP |
| 0009 |
| Small Business Participation Report |
Small Business Participation Report shall be provided IAW Section H, clause H-4 Small Business Participation Requirements, and Section J, Attachment 010.
| NSP |
| NSP |
| 0010 |
| Veterans Employment Certification Report |
Veterans Employment Certification Report IAW Section H, clause H-5 and Section J, Attachment 011.
| NSP |
| NSP |
| 0011 |
| Final Section 508 Compliance Test Results |
Final Section 508 Compliance Test Results IAW PWS Paragraph 8.1, Reporting Requirements.
| NSP |
| NSP |
Option Period One This 60-month option period may be exercised at the Government’s discretion IAW FAR 52.217-9, Option to Extend the Term of the Contract (MAR 2000). Work shall not commence until, and unless, a formal modification is issued by the Contracting Officer (CO). If exercised, this option shall commence immediately after expiration of the base period.
PRICE SCHEDULE
OPTION PERIOD
| CLIN |
| DESCRIPTION |
| QUANTITY |
| UNIT |
| UNIT COSTS |
| TOTAL COST |
| 1001 |
| Firm-Fixed-Price Line Item |
SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a FFP basis for a period of 60 months from date of option exercise IAW the T4NG2 PWS set forth in Section C.
Specific requirements and pricing shall be set forth under individual Task Orders.
Inspection, Acceptance, and Free on Board (FOB) Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.
| 1002 |
| Time-and-Materials/Labor-Hour Line Item |
SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a T&M/LH basis for a period of 60 months from date of option exercise IAW the T4NG2 PWS set forth in Section C.
Specific requirements and pricing shall be set forth under individual Task Orders.
Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.
| 1003 |
| Cost Reimbursement Line Item |
SECURITY CLASS: Determined at Task Order Level This CLIN is to provide IT services and incidental supplies on a CR basis for a period of 60 months from date of option exercise IAW the T4NG2 PWS set forth in Section C.
Specific requirements and pricing shall be set forth under individual Task Orders.
Inspection, Acceptance, and FOB Point shall be specified by incorporating the appropriate clauses from Sections E and F on each individual Task Order.
| 1004 |
| Contractor’s Progress, Status, and Management Report – Task Order Level |
Quarterly Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.1(A) and (B)(C)(D) and (E), and Section J Attachment 003 when applicable to Task Order contract type.
| NSP |
| NSP |
| 1005 |
| Contract Performance Report - |
Task Order Level
Quarterly Contract Performance Report shall be provided IAW Section C, PWS, Paragraph 8.1.2 (A) and (B), and Section J Attachments 004 (T&M) and 005 (CR) when applicable to Task Order contract type. Report not applicable for FFP Task Orders.
| NSP |
| NSP |
| 1006 |
| Government Furnished Equipment Status Report – Task Order Level |
Quarterly Government Furnished Equipment Status Report shall be provided IAW Section C, PWS, Paragraph 8.1.3 (A-K) and Section J, Attachment 006.
| NSP |
| NSP |
| 1007 |
| Personnel Contractor Manpower Report – Task Order Level |
Quarterly Personnel Contractor Manpower Report shall be provided IAW Section C, PWS, Paragraph 8.1.4 (A-S) and Section J, Attachment 008.
| NSP |
| NSP |
| 1008 |
| Contractor Staff Roster - Task Order Level |
Due within thee (3) business days of Task Order award. Contractor Staff Roster shall be provided IAW Section C, PWS, Paragraph 8.1.5 and Section J, Attachment 009.
| NSP |
| NSP |
| 1009 |
| Small Business Participation Report |
Quarterly Small Business Participation Report shall be provided IAW Section H, clause H.4 Small Business Participation Requirements, PWS Paragraph 8.1.6 and Section J, Attachment 010.
| NSP |
| NSP |
| 1010 |
| Veterans Employment Certification Report |
Quarterly Veterans Employment Certification Report IAW Section H, clause H.5, PWS Paragraph 8.1.7 and Section J, Attachment 011.
| NSP |
| NSP |
| 1011 |
| Final Section 508 Compliance Test Results |
Final Section 508 Compliance Test Results IAW PWS Paragraph 8.1, Reporting Requirements.
| NSP |
| NSP |
Contract Maximum/Minimum Ceiling:
IAW Section I, clause 52.216-22 entitled, “Indefinite Quantity” the Maximum value of the T4NG2 contract is $60.7 Billion. The maximum overall value of the T4NG2 contract for both the base period and options is $60.7 Billion. IAW Section I, clause 52.216-22 entitled, “Indefinite Quantity” the Minimum guaranteed value under the T4NG2 contract is $1,000. The Government reserves the right to award initial orders at the time of the basic contract award on a sole source basis pursuant to FAR 16.505(b)(2)(iv) at amounts which may exceed the minimum guaranteed value. There will be no guaranteed minimum order for the option period, if exercised.
The ceiling price as set forth in Section I, clause 52.232-7 entitled, “Payments under Time-and-Materials and Labor-Hour contracts” will be established for each individual Time-and Materials Task Order.
36C10B23R0011
SECTION C - DESCRIPTION/SPECIFICATIONS/STATEMENT OF WORK
Performance Work Statement (PWS) for the
Transformation Twenty-One Total Technology Next Generation (T4NG)2 Program
DATE: December 5, 2022 Department of Veterans Affairs Office of Procurement, Acquisition and Logistics Technology Acquisition Center (TAC)
Version History
| Version # |
| Version Description |
| Release Date |
Contents
| 1.0 | SCOPE | 19 |
| 2.0 | APPLICABLE DOCUMENTS | 19 |
| 3.0 | GENERAL REQUIREMENTS | 23 |
| 3.1 | Contract Type | 23 |
| 3.2 | Ordering Period | 23 |
| 3.3 | Hours of Work | 23 |
| 3.4 | Place of Performance | 23 |
| 3.5 | Travel | 24 |
| 3.6 | Materials, Equipment and Locations | 24 |
| 3.6.1 | Government-Furnished | 24 |
| 3.6.2 | Contractor-Acquired | 24 |
| 3.6.3 | Non-Developmental Items and Commercial Processes | 24 |
| 3.6.4 | Connectivity | 24 |
| 3.6.5 | Facilities | 25 |
| 3.6.5.1 | Government Facilities | 25 |
| 3.6.5.2 | Non-Government Facilities | 25 |
| 3.6.6 | Warranty | 25 |
| 3.6.7 | Marking, Handling, Storage, Preservation, Packaging, Tracking & Shipping | 25 |
| 3.6.8 | Export Control | 25 |
| 3.7 | Safety and Environmental | 25 |
| 3.8 | Enterprise and IT Framework | 26 |
| 3.8.1 | VA Technical Reference Model | 26 |
| 3.8.2 | Federal Identity, Credential, And Access Management (FICAM) | 26 |
| 3.8.3 | Internet Protocol Version 6 (Ipv6) | 27 |
| 3.8.4 | Trusted Internet Connection (TIC) | 28 |
| 3.8.5 | Standard Computer Configuration | 28 |
| 3.8.6 | Enterprise Management Framework | 28 |
| 3.8.7 | Authoritative Data Sources | 29 |
| 3.8.8 | Social Security Number (SSN) Reduction | 29 |
| 3.9 | Development Methodologies | 30 |
| 3.10 | Integrated Product Teams | 30 |
| 3.11 | Quality Assurance | 31 |
| 3.12 | Transition and Orientation Support | 31 |
| 3.13 | Government Inspection and Oversight | 31 |
| 4.0 | TECHNICAL FUNCTIONAL AREAS | 33 |
| 4.1 | Program Management, Strategy, Enterprise Architecture and Planning Support | 33 |
| 4.1.1 | Strategy and Planning | 33 |
| 4.1.2 | Standards, Policy, Procedure and Process Development, and Implementation Support | 33 |
| 4.1.3 | Requirements Development and Analysis Support | 33 |
| 4.1.3.1 | Requirements Packages | 34 |
| 4.1.4 | Technology Refresh and Configuration Reviews | 34 |
| 4.1.5 | Studies and Analyses | 34 |
| 4.1.6 | Program Management Support | 35 |
| 4.1.7 | Product Data | 35 |
| 4.1.8 | IT Services Management Support | 35 |
| 4.1.9 | Development Toolkits | 36 |
| 4.2 | Systems/Software Engineering | 36 |
| 4.2.1 | Design and Development | 37 |
| 4.2.2 | Architecture Development | 37 |
| 4.2.3 | IT Service Management Implementation | 37 |
| 4.2.4 | Enterprise Application/Services | 38 |
| 4.2.5 | Cloud Computing | 38 |
| 4.2.6 | Web Application Design and Development | 38 |
| 4.2.7 | Mobile Application Design and Development | 38 |
| 4.2.8 | Human-Computer Interaction | 38 |
| 4.2.9 | System/Software Integration | 39 |
| 4.2.10 | Modeling and Simulation | 39 |
| 4.2.11 | Informatics Services | 39 |
| 4.2.12 | Engineering and Technical Documentation | 39 |
| 4.2.13 | Current System and Data Migration | 39 |
| 4.2.14 | Development Toolkit Support | 40 |
| 4.3 | Software Technology Demonstration and Transition | 40 |
| 4.4 | Test & Evaluation (T&E) | 40 |
| 4.5 | Independent Verification and Validation (IV&V) | 40 |
| 4.6 | Enterprise Network | 40 |
| 4.6.1 | Systems/Network Administration | 41 |
| 4.6.2 | Network and Telecommunications Infrastructures | 41 |
| 4.7 | Enterprise Management Framework | 42 |
| 4.8 | Operations and Maintenance (O&M) | 42 |
| 4.8.1 | Systems/Network Administration | 43 |
| 4.8.2 | Application Support | 43 |
| 4.8.3 | Hardware Support | 43 |
| 4.8.4 | Security Management | 43 |
| 4.8.5 | Disaster Recovery (DR) and Continuity of Operations (COOP) | 43 |
| 4.8.6 | Capacity/Availability Planning and Management | 44 |
| 4.8.7 | Service/Help Desk/Call Center Support | 44 |
| 4.8.8 | Asset Management | 44 |
| 4.8.9 | License Maintenance | 44 |
| 4.8.10 | Database and Data Warehouse Administration | 44 |
| 4.8.11 | Data Center Administration | 45 |
| 4.9 | Cyber Security | 45 |
| 4.9.1 | Information Assurance (IA) | 45 |
| 4.9.2 | Logical Security | 45 |
| 4.9.3 | Assessment and Authorization | 46 |
| 4.9.4 | Cyber Security Operational Support | 46 |
| 4.9.5 | Cyber Threat Intelligence | 46 |
| 4.9.6 | Cyber Business Intelligence | 46 |
| 4.9.7 | Insider Threat Analysis | 46 |
| 4.9.8 | External Assessment Services | 47 |
| 4.9.9 | Cyber Security Exercise Coordination Support | 47 |
| 4.10 | Training | 47 |
| 4.11 | Information Technology Facilities | 48 |
| 4.11.1 | Incidental Facility Design and Modification Services | 48 |
| 4.11.2 | Site Surveys | 48 |
| 4.11.3 | Facility Connectivity | 48 |
| 4.11.4 | Installation | 48 |
| 4.11.5 | Physical Security Systems | 49 |
| 5.0 | DELIVERABLES | 49 |
| 5.1 | Products | 49 |
| 5.2 | Data | 49 |
| 6.0 | SECURITY AND PRIVACY | 49 |
| 6.1 | Information Security and Privacy Security Requirements | 49 |
| 6.2 | Personnel Security Requirements | 49 |
| 6.3 | Facility/Resource Provisions | 51 |
| 6.4 | Badges | 52 |
| 6.5 | Classified Work | 52 |
| 6.6 | Incident Reporting and Management | 52 |
| 6.7 | Security and Privacy Awareness Training | 53 |
| 6.8 | Security Role Based Training | 53 |
| 7.0 | CONTRACT MANAGEMENT | 53 |
| 7.1 | Government Support | 53 |
| 7.1.1 | Task Order COR | 53 |
| 7.2 | Contractor Program Management | 53 |
| 7.2.1 | Work Control | 53 |
| 7.3 | Pre-Award Procedures | 53 |
| 7.3.1 | Request for Task Execution Plan (RTEP) Process | 53 |
| 7.3.1.1 | Yes/No Bids | 54 |
| 7.3.2 | Task Execution Plan (TEP) | 54 |
| 7.3.3 | TEP Evaluation | 58 |
| 7.4 | Issuance of Task Orders | 58 |
| 7.5 | Logical Follow-Ons | 58 |
| 8.0 | REPORTING AND MEETING REQUIREMENTS | 59 |
| 8.1 | Reporting Requirements | 59 |
| 8.1.1 | Contractor’s Progress, Status and Management Report | 59 |
| 8.1.2 | Contract Performance Report (CPR) | 60 |
| 8.1.3 | Status of Government Furnished Equipment (GFE) Report | 60 |
| 8.1.4 | Personnel Contractor Manpower Report | 61 |
| 8.1.5 | Contractor Staff Roster | 61 |
| 8.1.6 | Small Business Participation Report | 62 |
| 8.1.7 | Veterans Employment Certification Report | 63 |
| 8.2 | Meetings and Reviews | 63 |
| 8.2.1 | Project Office Initial Program Review (IPR) | 63 |
| 8.2.2 | Post-Award Conferences | 63 |
| 8.2.3 | Program Reviews | 63 |
| 8.2.4 | Quarterly Collective Prime Program Reviews | 64 |
| ADDENDUM A– ADDITIONAL VA REQUIREMENTS, CONSOLIDATED | 65 | |
| ADDENDUM B- VA INFORMATION AND INFORMATION SYSTEM SECURITY / PRIVACY LANGUAGE | 71 |
1.0 SCOPE
This PWS establishes the requirements for Contractor-provided solutions and services in support of Information Technology (IT). Contractor-provided solutions may support the Department of Veterans Affairs (VA) and other Federal Agencies. The Contractor shall provide total IT service solutions to include the following functional areas: program management, strategy, enterprise architecture and planning; systems/software engineering; software technology demonstration and transition; test and evaluation; independent verification and validation; enterprise network; enterprise management framework; operations and maintenance; cybersecurity; training; IT facilities; and other solutions encompassing the entire range of IT and Health IT requirements, to include software and hardware incidental to the solution. Accordingly, Task Orders may include acquisitions of software and IT products. T4NG is not intended as a mechanism to solely purchase IT products. Such products may be purchased to the extent that those products are necessary to deliver the solution required. IT services, as well as related IT products, may encompass the entire life-cycle of a system. Moreover, IT services and related products covered under this contract shall be global in reach and the Contractors must be prepared to provide services and deliverables worldwide.
This PWS provides general requirements. Specific requirements shall be defined in individual Task Orders. Functional area requirements are described in Section 4.0 and are not mutually exclusive for Task Order requirements. Requirements may fall within one specific functional area but in many cases, the requirements will encompass and apply across and within multiple functional areas to provide the total life cycle solution.
2.0 APPLICABLE DOCUMENTS
The Contractor shall comply with the documents listed below. Additional documents may be listed in individual Task Orders.
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”
4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004
5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
7. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
8. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, title IX Information Security Matters
9. 10 U.S.C. § 2224, "Defense Information Assurance Program"
10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, (https://www.va.gov/vapubs/index.cfm)
12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016 (https://www.va.gov/vapubs/index.cfm)
13. VA Directive 6102 (Internet/Intranet Services), August 5, 2019 (https://www.va.gov/vapubs/index.cfm)
14. VA Handbook 6102 (Internet/Intranet Services), August 5, 2019 (https://www.va.gov/vapubs/index.cfm)
15. Health Insurance Portability and Accountability Act (HIPAA); 45 CFR Part 160, 162, and 164; Health Insurance Reform: Security Standards; Final Rule dated February 20, 2003
16. VHA Directive 1605.05, Business Associate Agreements, November 17, 2020, (https://www.va.gov/vhapublications/ViewPublication.asp?pub_ID=9178)
17. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017
18. Office of Management and Budget Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
19. U.S.C. Section 552a, as amended
20. Title 32 CFR 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
21. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008
22. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. Section § 794d), as amended, January 18, 2017
23. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
24. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 (https://www.va.gov/vapubs/index.cfm)
25. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” February 24, 2021 (https://www.va.gov/vapubs/index.cfm)
26. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019 (https://www.va.gov/vapubs/index.cfm)
27. VA Handbook, 6500.5, Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010 (https://www.va.gov/vapubs/index.cfm)
28. VA Handbook 6500.6, “Contract Security,” March 12, 2010 (https://www.va.gov/vapubs/index.cfm)
29. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011 (https://www.va.gov/vapubs/index.cfm)
30. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018
31. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017
32. Office of Information and Technology (OIT) Process Asset Library (PAL) https://www.va.gov/process/. Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
33. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)
34. Federal Travel Regulation (FTR) (www.gsa.gov/federaltravelregulation)
35. One-VA Technical Reference Model (TRM) (https://www.va.gov/trm/TRMHomePage.aspx)
36. Federal Segment Architecture Methodology (FSAM) v1.0, December 2008
37. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014 (https://www.va.gov/vapubs/index.cfm)
38. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
39. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016
40. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017
41. VA Directive 6300, “Records and Information Management,” September 21, 2018 (https://www.va.gov/vapubs/index.cfm)
42. VA Handbook, 6300.1, “Records Management Procedures,” March 24, 2010 (https://www.va.gov/vapubs/index.cfm)
43. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018
44. OMB Memorandum “Security Authorization of Information Systems in Cloud Computing Environments,” December 8, 2011 (FedRAMP Policy Memorandum)
45. VA Directive 6609, “Mailing of Sensitive Personal Information,” May 20, 2011 (https://www.va.gov/vapubs/index.cfm)
46. VA Enterprise Technology Strategic Plan, February 28, 2014
47. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015 (https://www.va.gov/vapubs/index.cfm)
48. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014 (https://www.va.gov/vapubs/index.cfm)
49. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005
50. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019
51. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008
52. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)
53. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,” June 2018
54. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020
55. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014
56. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices (Draft),” October 2012
57. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
58. IAM Identity Management Business Requirements Guidance document, May 2013, (https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
59. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896
60. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents
61. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019
62. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008
63. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
64. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
65. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018
66. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
67. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013 (https://www.va.gov/vapubs/index.cfm)
68. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013 (https://www.va.gov/vapubs/index.cfm)
69. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
70. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
71. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
72. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
73. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
74. NIST SP 500-267B Revision 1, ”USGv6 Profile,” November 2020
75. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),“ November 19, 2020
76. Social Security Number (SSN) Fraud Prevention Act of 2017
77. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018
78. VA Enterprise Cloud (VAEC) Technical Reference Guide, July 2018 version 1.3
3.0 GENERAL REQUIREMENTS
The Contractor shall provide and/or acquire the services, hardware, and software required by individual Task Orders pursuant to the general requirements specified below.
3.1 Contract Type
This is an Indefinite Delivery/Indefinite Quantity (IDIQ) Multiple Award Task Order (MATO) contract. Individual Task Orders shall be issued on a performance-based T&M, CR, and/or FFP basis.
3.2 Ordering Period
The ordering period for the basic contract shall be five years with one five-year option.
3.3 Hours of Work
Generally, work at a Government site shall not take place on Federal holidays or weekends unless directed by the CO or individual Task Order; however, the Contractor may be required to support 24/7 operations 365 days per year as identified in individual Task Orders.
There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, five are set by date:
| New Year's Day | January 1 |
| Juneteenth | June 19 |
| Independence Day | July 4 |
| Veterans Day | November 11 |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January |
| Washington's Birthday | Third Monday in February |
| Memorial Day | Last Monday in May |
| Labor Day | First Monday in September |
| Columbus Day | Second Monday in October |
| Thanksgiving | Fourth Thursday in November |
3.4 Place of Performance
The place of performance shall be identified in individual Task Orders. Locations can be Government or non-Government sites within the continental United States (CONUS) and/or outside the continental United States (OCONUS). Locations may include but are not limited to Federal, State, VA, or military data centers, facilities, regional offices, benefits delivery centers, medical treatment facilities, health clinics and Tricare facilities as defined in individual Task Orders.
3.5 Travel
Travel shall be in accordance with (IAW) individual Task Order requirements. Travel details must be provided to and approved by the CO’s Representative (COR) or the Government designee prior to the commencement of travel. All travel shall be IAW the Federal Travel Regulations (FTR). OCONUS travel may require additional authorization and approvals as specified in the individual Task Order.
3.6 Materials, Equipment and Locations
3.6.1 Government-Furnished
Government Furnished Property (GFP) which includes Government Furnished Material (GFM), Government Furnished Information (GFI), and Government Furnished Equipment (GFE) may be provided and shall be identified in the individual Task Order. The Contractor shall be responsible for conducting all necessary examinations, inspections, maintenance, and tests upon receipt. The Contractor shall be responsible for reporting all inspection results, maintenance actions, losses, and damage to the Government through the VA Technology Acquisition Center (TAC) website.
VA may provide VA-specific software as appropriate and required in individual Task Orders. The Contractor may utilize VA-provided software development and test accounts, document and requirements repositories and others as required for the development, storage, maintenance and delivery of products. Contractors shall comply with VA security policies and procedures with respect to protecting sensitive data. See Section 6.0 for detailed security requirements.
3.6.2 Contractor-Acquired
The Contractor shall acquire and/or provide any hardware and/or software required to accomplish each Task Order that is not provided as GFP. Software integrity shall be maintained by the Contractor within the licensing agreement of the producer until such software is delivered to the Government, or otherwise disposed of IAW Government direction. Items delivered to the Government shall be approved by the Government in advance of purchase and shall be in compliance with PWS paragraphs 3.8 and A3.0. See Section 6.0 for detailed security requirements.
3.6.3 Non-Developmental Items and Commercial Processes
Non-Developmental Items (NDI), Commercial-Off-The-Shelf (COTS) and Government-Off-The-Shelf (GOTS) products shall be used to the maximum extent. The Contractor shall apply commercially available and industry best processes, standards and technologies to the maximum extent.
3.6.4 Connectivity
VA will provide connectivity to VA-specific systems/network as required for execution of the task via VA approved remote access technology. Currently this may include but is not limited to Citrix Access Gateway (CAG), Azure Virtual Desktop, site-to-site VPN, or VA Remote Access Security Compliance Update Environment (RESCUE). This remote access will provide connectivity to VA-specific software such as Veterans Health Information System and Technology Architecture (VistA), Electronic Health Record Modernization (EHRM), ServiceNow, ClearQuest, PAL, Primavera, and Remedy, including appropriate seat management and user licenses. VA may install equipment at the Contractor’s site to ensure security requirements are in place. The Contractor must meet the requirements of VA Handbook 6500 and will bear the cost to provide connectivity to VA. Other connectivity to VA systems may be authorized as appropriate in individual Task Orders.
3.6.5 Facilities
Work may be performed at either a Government or non-Government facility. Each Task Order shall delineate the facility and location requirements.
3.6.5.1 Government Facilities
Certain Government office or laboratory space may be made available for performance of individual Task Orders. Contractors may be required to establish operations and support Government locations and shall comply with VA and/or Federal assessment and authorization (A&A) requirements. Such facilities shall be specified in the individual Task Order.
3.6.5.2 Non-Government Facilities
Personnel may perform at Contractor or remote facilities if specified in the individual task order. Contractors may be required to establish operations and support Contractor facilities and shall comply with VA and/or Federal A&A requirements. Such facilities shall be specified in the individual Task Order. The Contractor shall disclose specific facility information during the Request for Task Execution Plan (RTEP) process. All facilities shall be approved by VA and in compliance with PWS paragraph 6.0, Security and Privacy.
3.6.6 Warranty
Items acquired under this contract may require warranty protection. Commercial warranties shall be transferred to the Government. The type of warranty and extent of coverage shall be determined on an individual Task Order basis.
3.6.7 Marking, Handling, Storage, Preservation, Packaging, Tracking & Shipping The Contractor shall establish/maintain procedures IAW VA Handbook 6500 and VA Directive 6609 for handling, storage, preservation, packaging, marking, tracking and shipping to protect the quality of products and prevent damage, loss, deterioration, degradation or substitution of products.
3.6.8 Export Control
The Contractor shall comply with all applicable laws and regulations regarding export-controlled information and technology and shall not use, distribute, transfer or transmit technology (even if incorporated into products, software or other information) except in compliance with such laws and regulations. In addition, the Contractor shall plan for, obtain, and maintain all export licensing required to satisfy individual Task Order requirements.
3.7 Safety and Environmental
Safety and environmental procedures shall be identified in individual Task Order requirements.
The Contractor shall comply with the Office of Federal Sustainability Acquisition and Electronics Stewardship initiatives as identified in individual Task Orders IAW the policies referenced at https://www.sustainability.gov/resources-eo-efo.html
3.8 Enterprise and IT Framework
3.8.1 VA Technical Reference Model
For VA-specific task orders, the Contractor shall support the VA Enterprise Management Framework (EMF). In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM) and consider the VA Enterprise Technology Strategic Plan. The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the IT used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT.
3.8.2 Federal Identity, Credential, And Access Management (FICAM) The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls,” and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://georgewbush-whitehouse.archives.gov/omb/memoranda/fy2005/m05-24.pdf and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems can support the following:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers is the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
3.8.3 Internet Protocol Version 6 (Ipv6)
The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.
3.8.4 Trusted Internet Connection (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.
3.8.5 Standard Computer Configuration
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
3.8.6 Enterprise Management Framework
The EMF provides an enterprise-wide view of VA IT systems comprised of tools, reports, databases, dashboards, and analytics. EMF enables OIT to view the health and performance of systems and provides intelligent analysis and trending that enables proactive enterprise system management. Performance, availability, user experience and reliability of IT service delivery is improved as OIT can make strategic, operational and investment decisions based on real-time information.
EMF supports a unified enterprise service management model including release management, configuration management, change management, and incident management aligned with industry standard IT Infrastructure Library (ITIL) service management best practices. The EMF Federated Data Repository (FDR) includes the implementation of a foundational component. The EMF FDR is a national repository that collects enterprise IT management data from VA Managed Data Repositories (MDRs) and integrates with existing VA monitoring and performance systems.
Additional frameworks may be specified in individual task orders.
3.8.7 Authoritative Data Sources
The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .