Attachment_A_-_PWS.pdf

PDF 202 KB Posted

Attached to
FOIAXpress Implementation Federal contract opportunity
Solicitation number
EDEMCM16Q0008
Issued by
Department of Education Contracts and Acquisition Management

About this file

Performance Work Statement - FOIAXpress Implementation

View the file

Other files for this federal contract opportunity

Other files attached to FOIAXpress Implementation, newest first.
File Type Posted
Limited_Sources_Justification_-_FOIAXpress.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS)

FOIAXpress Implementation PWS

August 31, 2016

Table of Contents I. Introduction II. Background III. Period of Performance IV. Place of Performance V. Scope of Work VI. Additional Contractor Requirements VII. Contract Personnel Technical Exhibit 1 – Performance Requirements Summary Deliverables Delivery Schedule Technical Exhibit 2 -- Applicable Directives Technical Exhibit 3 – Applicable Acronyms

Performance Work Statement

Chief Privacy Office FOIAXpress Implementation

I. Introduction

The purpose of this acquisition is to provide support for the implementation of FOIAXpress using a Federal Risk and Authorization Management Program (FEDRAMP) certified Cloud service provider for the benefit of the Office of Management/ Chief Privacy Officer (OM/CPO) of the United States Department of Education (Department). OM/CPO is tasked with managing compliance and technical assistance to schools, districts, and states regarding compliance with federal student privacy statutes and best practices. The Department requires the assistance of a Contractor to implement and operate FOIAXpress in a cloud-based environment, make it available for use by CPO and Department staff and support achieving an Authorization to Operate (ATO) designation.

II. Background

OM/CPO proposes to enter into a contract on a basis of other than full and open competition for the FOIA Service Center (FSC). The FSC has been designated as the program lead for the implementation of FOIAXpress hosted version in support of FSC FOIA processing.

The Department currently utilizes the Commercial off-the-shelf (COTS) product FOIAXpress to automate our Freedom of Information Act (FOIA) request processing.

FOIAXpress provides the FSC with a centralized system to handle and track request/appeal submissions, electronically redact responsive documents, and compute and output statistics for the FOIA Annual Report as required by the Department of Justice. FOIAXpress is currently installed onsite at the Department. To remove the infrastructure burden from the agency, and to realize the many efficiencies provided by a Software-as-a-Service (SaaS) model, the Department now has a requirement to migrate the FOIAXpress solution to the cloud. FOIAXpress as a SaaS solution will realize the following benefits:

• Lower infrastructure and other IT costs for hardware and software maintenance

• More timely application of patches and software updates

• Alignment with ‘Cloud First’ Federal Computing Strategy

• More timely upgrade to latest version of the FOIAXpress software to maintain compliance with FOIA reporting requirements

• Reduce annual C&A cost

• Reduce overall IT burden on the agency

III. Period of Performance

The period of performance of this task order shall be one (1) 12-month base period and two 12-month option periods.

IV. Place of Performance

All work pertaining to hosting/support of FOIAXpress Implementation will take place at the Contractor’s facilities. Meetings will take place at the Department.

V. Scope of Work

The performance requirements described below are those expected to be performed under this task order. Work requirements include the following tasks and sub-tasks:

TASK 1: POST AWARD MEETING (BASE YEAR ONLY)

The Contractor must meet for one day in Washington, D.C. with the Contracting Officer’s Representative (COR), the Contracting Officer (CO) and/or his/her representative, and other Department staff as deemed appropriate, within one week after the effective date of the contract award. The purpose of this post-award kick-off meeting is to clarify the work to be performed and the procedures to be followed by the Contractor. The COR will identify a time and place for the meeting and will be responsible for inviting appropriate Department staff. The Contractor must contact the COR within three (3) days of the effective date of the contract award to make arrangements for the meeting and to set the agenda with the COR.

TASK 2: PROJECT MANAGEMENT

Sub-Task 2.1: The Contractor must develop a project management plan that manages all tasks under this Performance Work Statement (PWS) for:

• Schedule

• Quality

• Performance

Sub-Task 2.2: The Contractor must develop and update a Work Breakdown Structure (WBS) containing all work activities. The WBS must define all work contained under this PWS.

TASK 3: FOIAXpress CLOUD-BASED HOSTING ENVIRONMENT ANALYSIS

AND DESIGN

Sub-Task 3.1: The Contractor must perform a requirements analysis and produce a functional requirements document (FRD) that describes what the Cloud hosting environment must provide to support the FOIAXpress application. The requirements analysis must consist of one or more meetings with Government staff, where the

Contractor must identify and document the CPO functional requirements and add them to the FRD.

Sub-Task 3.2: The Contractor must deliver an enhanced FRD that incorporates modifications into the functional requirements, if requirements are modified in any way during the requirements analysis. Upon acceptance by the COR, the enhanced FRD will become the FRD.

Sub-Task 3.3: The Contractor must provide a Cloud Infrastructure Design Document.

The Contractor must obtain the Department’s approval of its design before deployment of the Cloud infrastructure. This document must contain the following minimum information:

1. The Cloud infrastructure system’s configuration;

2. The system’s architecture;

3. The system’s interface design (internal and external);

4. References to applicable design documents;

5. Assumptions, constraints, design goals, and decisions;

Sub-Task 3.4: The Contractor must procure the appropriate level of service from a FEDRAMP certified Cloud service provider to support the FOIAXpress configuration described in the approved design document.

TASK 4: FOIAXpress SYSTEM TESTING

The Contractor must perform the following series of tests on the Cloud-based FOIAXpress system under this contract:

Sub-Task 4.1: FOIAXpress Operational Testing The Contractor must perform operational testing related to FOIAXpress after deployment and prior to beginning operations. The Contractor must also support user acceptance testing of the FOIAXpress system after deployment. Testing will ensure an integrated operational system that meets all functional requirements with the appropriate operational capability, and correct sizing, performance, and stability. The Contractor must also provide a test procedure for this test. The Contractor must include the expected number of days following award for performance of these tests and delivery of these documents.

Sub-Task 4.2: FOIAXpress Load Testing The Contractor must perform load testing to verify those functional requirements related to system load. The Contractor must provide a test procedure for this test. The Contractor must include the expected number of days following award for the delivery of these documents.

Sub-Task 4.3: Change Advisory Board (CAB) and Enterprise Architecture Review Board (EARB) Support The Contractor must participate in CAB and EARB meetings to obtain approval to deploy FOIAXpress. The Contractor must be available to answer technical questions about the architecture, development and environment where FOIAXpress is maintained.

The Contractor must be responsible for the development and review of necessary documentation for all meetings.

Sub-Task 4.4: The Contractor must deliver a report document that incorporates the results from all testing. The Contractor must include the expected number of days following award for the delivery of these documents.

TASK 5: FOIAXpress DEPLOYMENT

The Contractor must install and make operationally ready (deploy) the FOIAXpress application in the Cloud infrastructure. The Contractor must include the expected number of days following award for the successful deployment. Completion of deployment requires receipt of accreditation and permission to operate by the Designated Accrediting Authority (DAA).

TASK 6: FOIAXpress OPERATIONS AND MAINTENANCE

Sub-Task 6.1: The Contractor must deliver an Operations and Maintenance Manual for the FOIAXpress system that describes how the FOIAXpress system is to be operated and kept up to date. The Contractor must provide this document following successful deployment of FOIAXpress and the Cloud infrastructure. The Contractor must include the expected number of days following award for the delivery of this document.

TASK 7: FOIAXpress SECURITY

Sub-Task 7.1: The Contractor must develop documentation necessary to obtain an ATO in accordance with Department requirements.

Sub-Task 7.2: The Contractor must comply with the Department's IT security policy requirements as set forth in the Handbook for Information Assurance Security Policy and related procedures and guidance.

Sub-Task 7.3: The Contractor must comply with IT security requirements as outlined in the Federal Information Security Management Act of 2002 (FISMA), OMB Circulars, and NIST standards and guidance. This also includes the Defense Information Systems Agency (DISA) Security Technical Implementation Guidelines (STIG) as set forth by the National Security Agency (NSA). These requirements include the successful certification and accreditation (C&A) of the system before it can be implemented and become operational.

Sub-Task 7.4: The Contractor must design and implement security controls in the system consistent with the NIST 800-53 rev 4 - Recommended Security Controls for Federal Information Systems identified for the impact level of the system.

Sub-Task 7.5: The Contractor must develop system security documentation to document the implementation of the security controls for the system. The Contractor must be https://connected.ed.gov/Documents/Handbook%20%E2%80%A6%20ormation%20Assurance%20Cybersecurity%20Policy_.pdf http://csrc.nist.gov/drivers/documents/FISMA-final.pdf http://disa.mil/news/conferences-and-events/%7E/media/files/disa/news/conference/cif/briefing/ia_stig_scap_and_data_metrics.pdf http://disa.mil/news/conferences-and-events/%7E/media/files/disa/news/conference/cif/briefing/ia_stig_scap_and_data_metrics.pdf http://dx.doi.org/10.6028/NIST.SP.800-53r4 available for interviews and demonstrations of security control compliance to support the ATO process.

Sub-Task 7.6: The Contractor must support the Department's Certification Review Group in conducting vulnerability scanning and penetration testing on the hosting facility and application, as part of the ATO process.

Sub-Task 7.7: The Contractor must provide appropriate access agreements before any scanning or testing occurs.

Sub-Task 7.8: The Contractor must provide support during the Security and Acceptance Testing to address any issues following review.

VI. Additional Contractor Requirements

Availability of Contractor Personnel

The tasks under this PWS require sustained availability of Contractor personnel to respond to internal and external customer requests and inquiries, and provision of technical expertise to CPO managers and staff during Department operating hours. The requirements for this availability are detailed below.

Core Business Hours Contractor personnel for this contract must be available to perform work under the tasks of this contract during the core business hours of 9:00AM to 5:00PM Eastern Time. On days when Department of Education employees are granted “Early Dismissal,” these core business hours will be reduced accordingly. At the request of the Contractor, the Contracting Officer (CO) can modify these Core Business Hours on a case by case basis for Contractor personnel performing work on specific tasks under this PWS.

Weekends, Holidays, and Inclement Weather Contractor personnel are not required to be available to perform work under the tasks of this contract on weekends, federal holidays, or days when federal government buildings in Washington, DC are closed due to inclement weather.

Illness, Extended Absences, and Vacancies Contractor personnel (as identified in the Contractor’s submitted Technical Proposal) performing work under Tasks 3-8 of this PWS are permitted to be unavailable to perform work under the tasks of this contract for up to ten (10) business days per contract year (calculable in whole-day increments), to cover illness, personal leave, and/or temporary vacancies resulting from staff turnover.

Any business days for which a Contractor staff member is not available to perform work under the tasks of this contract in excess of these must result in a pro-rated deduction in the invoiced price of the tasks to which that Contractor staff position was assigned. This is calculated by dividing the number of additional absences incurred during the billing period by the total number of business days for the billing period, and multiplying that ratio by the price for each task to which that position was assigned in the Contractor’s Technical Proposal.

Reporting of Data Security Breaches

The Contractor must ensure that breaches/disclosures of Personally Identifiable Information (PII) due to loss, theft, intercepted transfer, or any other reason, are reported to the Department as soon as the Contractor has knowledge of it. Per OMB Memorandum M-06-19, Federal agencies have a requirement to report breaches of PII security to a Federal incident response center. The Contractor must notify the Department within 30 minutes of discovering the incident (and the Department will not distinguish between suspected or confirmed breaches). The data security plan must be written to reflect this requirement, and the Contractor must provide sufficient notification and documentation of the suspected loss, as it is understood at the time of notification to the Department for this requirement to be met. The Contractor must prepare follow-up reports of the final status of loss events within a 5 business days as advised by the COR.

Operating Constraints

1. The Contractor is required to work with CPO and the Department’s Office of the Chief Information Officer (OCIO) to ensure compliance with C&A requirements of the Federal Information Management Security Act of 2002.

2. The Contractor must abide to any new regulations mandated by the Federal

Government. The Government must provide any regulation documentation as requested.

3. The Contractor must communicate any sensitive system information to the

Government via approved protocol (i.e. Government email).

4. The Contractor must ensure that FOIAXpress meets all Section 508 requirements.

If after completing testing issues are detected, the Contractor must address findings within 10 business days of receiving the final accessibility report from ED’s Assistive Technology Team.

Government Furnished Property/Equipment:

The Contractor must furnish any property and/or equipment for any work pertaining to FOIAXpress implementation support tasks. The Department will provide modules, schemas and historical data for its instance of FOIAXpress prior to decommission.

Templates used by the Department of develop documentation needed to obtain an ATO will be provided. Those documents include:

• System Security Plan http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2006/m06-19.pdf http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2006/m06-19.pdf http://www.gpo.gov/fdsys/pkg/PLAW-107publ347/pdf/PLAW-107publ347.pdf

• System Security Risk Assessment

• Federal Information Processing Standards-199 Risk Assessment Results

• System Contingency Plan

• System Configuration Management Plan

• Security Assessment Plan

• Security Assessment Report

• Privacy Impact Assessment (PIA)

• Privacy Threshold Assessment (PTA)

• Data Sensitivity Inventory

• Plan of Actions and Milestones

• Interconnection Agreements

• Incident Response Plan

Security

The work performed in accordance with this PWS is “business sensitive” and confidential. As such, all Contractor (and subcontractor, as applicable) personnel working on this task order are required to be cleared (and maintain security clearance), as follows:

• The Program Manager, Project Manager, and all Contractor (and subcontractor, as applicable) personnel who work on infrastructure security, information assurance, or certification and accreditation tasks – 5C (Moderate Risk) security clearance

• All other Contractor personnel- 5C (Moderate Risk) security clearance.

All Contractor (and subcontractor, as applicable) must complete IT Security training and obtain a Personal Identity Verification (PIV) card if access to the Department is required.

Substitutions of cleared Contractor personnel must not be made without express, written recommendation by the COR and final approval by the Contracting Officer.

Hostnames for Government Funded Websites

A “.gov” hostname (typically hostname.ed.gov) is required for all government funded websites under OMB Memorandum M-05-04 (http://www.usa.gov/webcontent/regs_bestpractices/omb_policies/domains.shtml)

Performance Standards

The FOIAXpress Implementation contract is a performance-based contract. As such, desired outcomes, performance standards and measurements are used to set expectations and to monitor the performance of this contract.

Records Management and Cloud Computing

The Department Records Officer, OM/OCPO, shall be included in the acquisition and http://www.usa.gov/webcontent/regs_bestpractices/omb_policies/domains.shtml development of IT services in a cloud computing environment. Compliance with NARA guidance and integration of cloud services with the Department’s current enterprise records management system will rely on the expert knowledge of the OM/OCPO Records and Document Management Division. ACS Directive OM: 06-103, Records and Information Management Program, specifically direct that records management requirements must be incorporated into information technology system design and acquisition. Contractors must consult with the Department’s Records Officer to ensure that Federal records, if any exist, in a cloud computing environment are covered by an existing ED records retention schedule or that a new schedule is developed that covers the records. Thus, the Department Records Officer will ensure that all the above NARA requirements are met.

Compliance with ED IT Security Policy

The contractor, and all sub-contractors, shall comply with the Department of Education’s IT security policy requirements, specifically those set forth in the ‘Handbook for Information Assurance Security Policy (OCIO-01)’, and other applicable procedures and guidance. The contractor, and all sub-contractors, shall develop and implement management, operational and technical security controls to assure required levels of protection for information systems. The contractor, and all sub-contractors, shall further comply with all applicable Federal IT security requirements including, but not limited to, the Federal Information Security Management Act (FISMA) of 2002, Office of Management and Budget (OMB) Circular A-130 Appendix III, Homeland Security Presidential Directives (HSPD), the National Institute of Standards and Technology (NIST) standards and guidance, and the Federal Risk and Authorization Management Program (FedRAMP) requirements and guidance.

These security requirements include, but are not limited to, the successful Security Authorization (SA) of the system (includes commercially owned and operated systems managed by the commercial vendor and its sub-contractors, supporting Department programs, contracts, and projects); obtaining a full Authority to Operate (ATO) before being granted operational status; performance of annual self-assessments of security controls; annual Contingency Plan testing; performance of periodic vulnerability scans;

updating all information system security documentation as changes occur; and other continuous monitoring activities, which may include, mapping, penetration and other intrusive scanning. Full and unfettered access for the Department’s third party Managed Security Services Provider (MSSP) must be granted to access all computers and networks used for this system. Additionally, when there is a significant change to the system’s security posture, the system (Federal and commercial prime- and sub- contractors included) must have a new SA, with all required activities to obtain a new ATO, signed by the Authorizing Official (AO).

System security controls shall be designed and implemented consistent with NIST SP 800-53 Rev 4, ‘Recommended Security Controls for Federal Information Systems and Organizations.’ All NIST SP 800-53 controls must be tested / assessed no less than every 3 years, according to federal and Department policy. The risk impact level of the system https://connected.ed.gov/Documents/Records_and_Information_Management_Program.pdf https://share.ed.gov/teams/OCIO/IA/CDT/EDSO%20%E2%80%A6%20or%20Information%20Assurance%20Security%20Policy.pdf https://www.epa.gov/emergency-response/homeland-security-presidential-directives https://www.epa.gov/emergency-response/homeland-security-presidential-directives http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html https://www.fedramp.gov/resources/documents-2016/ https://www.fedramp.gov/resources/documents-2016/ http://csrc.nist.gov/publications/PubsSPs.html%23SP%20800 http://csrc.nist.gov/publications/PubsSPs.html%23SP%20800 will be determined via the completion of the Department's inventory form and shall meet the accurate depiction of security categorization as outlined in Federal Information Publishing Standards (FIPS) 199, ‘Standards for Security Categorization of Federal Information and Information Systems.’

System security documentation shall be developed to record and support the implementation of the security controls for the system. This documentation shall be maintained for the life of the system. The contractor, and all sub-contractors, shall review and update the system security documentation at least annually and after significant changes to the system, to ensure the relevance and accurate depiction of the implemented system controls and to reflect changes to the system and its environment of operation. Security documentation must be developed in accordance with the NIST 800 series and Department of Education policy and guidance.

The contractor, and all sub-contractors, shall allow Department employees (or Department designated third party contractors) access to the hosting facility to conduct SA activities to include control reviews in accordance with NIST SP 800-53, Rev. 4 and NIST SP 800-53A. The contractor, and all sub-contractors, shall be available for interviews and demonstrations of security control compliance to support the SA process and continuous monitoring of system security. In addition, if the system is rated as ‘Moderate’ or ‘High’ for FIPS 199 risk impact, vulnerability scanning and penetration testing shall be performed on the hosting facility and application as part of the SA process. Appropriate access agreements will be reviewed and signed before any scanning or testing occurs.

Identified deficiencies between required NIST SP 800-53 Rev. 4 controls and the contractor’s, and all sub-contractor’s implementation, as documented in the Risk Assessment Report, System Security Plan (SSP) and Security Assessment Report (SAR), shall be tracked for mitigation through the development of a Plan of Action and Milestones (POA&M) in accordance with the ‘Handbook for Information Assurance Security Policy (OCIO-01).’ Depending on the severity of the deficiencies, the Department may require remediation before an ATO is issued.

All awarded contracts shall ensure that:

1. Their IT product/system is monitored during all hours of operations using entrusted detective/preventive systems;

2. Their IT product/system has current antiviral products installed and operational;

3. Their IT product/system is scanned on a reoccurring basis;

4. Vulnerabilities are remediated in a timely manner on their IT product/system; and

5. Access/view for cyber security situational awareness on their IT product/system is made available to the Department CIRC (cyber incident response capability).

IPv6 Requirements

The Contractor shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding http://webcache.googleusercontent.com/search?q=cache:Jib0vMZCf8EJ:csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf+&cd=3&hl=en&ct=clnk&gl=us http://webcache.googleusercontent.com/search?q=cache:Jib0vMZCf8EJ:csrc.nist.gov/publications/fips/fips199/FIPS-PUB-199-final.pdf+&cd=3&hl=en&ct=clnk&gl=us http://csrc.nist.gov/publications/PubsSPs.html%23SP%20800 http://csrc.nist.gov/publications/PubsSPs.html%23SP%20800 http://csrc.nist.gov/publications/PubsSPs.html%23SP%20800 https://share.ed.gov/teams/OCIO/IA/CDT/EDSO%20%E2%80%A6%20or%20Information%20Assurance%20Security%20Policy.pdf https://share.ed.gov/teams/OCIO/IA/CDT/EDSO%20%E2%80%A6%20or%20Information%20Assurance%20Security%20Policy.pdf

IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4.

An IPv6 Capable system must meet the IPv6 base requirements defined by the USGv6 Profile and Testing program as found here “http://w3.antd.nist.gov/usgv6/testing.html”.

Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities.

Systems shall implement IPv4/IPv6 dual-stack and shall also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems shall employ IPv6.

The contractor shall provide IPv6 technical support for system development, implementation and management.

System Development Standards:

Information systems shall be developed in accordance with the ED Lifecycle Management Framework (LCM), ACS-OCIO 1-106.

VII. Contract Personnel

Basic Requirements

The Contractor must provide a contract performance team comprised of individuals fully qualified to perform the specific work requirements described in this PWS. The specific performance requirements are described in the “Qualifications of Staff” section, below.

Contractor personnel must meet the criteria for eligibility to receive a Department security clearance and must maintain confidentiality of all work processes.

Contractor personnel responsible for answering the telephone and working with Department employees, other programs and organizations, and all other customers must be customer-service oriented, and must speak clearly, Contractor personnel must be able to understand the English language both verbally and in writing, and be able to communicate using a variety of telecommunication relay services.

Contractor personnel must demonstrate mastery of the components of the Microsoft Office Suite of applications (Word, Excel, Outlook, Access, and PowerPoint) relevant for the work they are performing under the Tasks of this PWS. Evidence should be provided in resumes of proposed staff. As the majority of the work to be performed under this PWS will be done in a networked office environment, Contractor personnel must demonstrate mastery of Microsoft SharePoint for document management and collaboration, and have the ability to track correspondence and documents through http://w3.antd.nist.gov/usgv6/testing.html https://connected.ed.gov/Documents/Lifecycle_Management.pdf multiple rounds of stakeholder review, consolidating, synthesizing, and prioritizing comments and edits as they are received.

Contractor personnel must be familiar with and experienced in standards of accessible product development and alternate forms of communication and dissemination, as required by Section 508 of the U.S. Rehabilitation Act (as amended) (29 U.S.C. 794 d).

Qualifications of Contractor Staff

In addition to the required qualifications for all Contractor personnel performing work under this PWS, several of the Tasks require specialized experience and/or expertise.

Therefore, there are additional minimum requirements that Contractor personnel working on these tasks must meet. The requirements are as followed:

Tasks 2-7 – FOIAXPRESS Development, Definition and Implementation

In addition to the basic requirements for all Contractor personnel listed above, any Contractor employee performing work under Tasks 2 – 7 must have a BS degree (though a graduate degree is preferred) in engineering, computer science, math or other related technical discipline. The candidate must have a minimum of 6 years’ experience exposed to activities associated with the development of a new system, from developing and analyzing system concepts, assessing system design options, analyzing requirements, monitoring development, integration and test activities, and in operations.

Key Personnel Because of the degree of expertise required, and the critical importance of these functions for the continued operations of the CPO, Contractor personnel assigned to perform work on the following Sub-Tasks must be considered “Key Personnel” and must not be replaced or re-assigned by the Contractor without prior approval by the CO. Initial assignment (or replacement) of any key personnel must require prior approval of the individual’s qualifications by the CO.

• Sub-Tasks 2 - 7 (Systems Engineer) http://www.gpo.gov/fdsys/pkg/USCODE-2010-title29/pdf/USCODE-2010-title29-chap16-subchapV-sec794.pdf

Technical Exhibit 1 – Performance Requirements Summary

Deliverables

The following table lists the frequency and deadlines for the major subtasks and deliverables that are required under this PWS and resulting award. The full list and detailed descriptions of required deliverables, actions, and activities are contained in Section V of the PWS.

For subtasks with formal documents as deliverables, the deadlines provided in this table represent deadlines for submission of final drafts of these documents. When time permits, the Contractor is encouraged to submit rough drafts of these documents for review by the CPO Team prior to these deadlines. Upon receipt of a rough draft, the CPO Team will provide comments/edits to the Contractor for inclusion in the final draft within ten business days of receipt.

The following quality standards will be used to assess Contractor deliverables that are documents:

• The document is complete, correct and includes all relevant information;

• The document meets the core requirements for the document;

• The document captures the relevant points raised during its creation;

• The overall business purpose of the document is achieved;

• The document contains few grammatical errors, is visually appealing, and is easy to read/understand;

• The document uses the format and terms currently used by Department staff;

• The document contains recommendations consistent with best practices;

• The document is submitted on time and incorporates any pre-submission feedback;

• The documents are stored in the appropriate locations and are accessible by appropriate staff.

Delivery Schedule

Due dates for deliverables listed below are for the initial draft document delivery. The Contractor must allow two weeks for Department to review and comment on the drafts, and two weeks to incorporate revisions, unless otherwise agreed. All plans and reports must be provided in electronic format.

Task Sub- Task

Delivery Frequency and Deadline Standard Method of

Surveillance

1 Once, within 3 business days of the effective date of contract

• Contractor attends meeting • 100% Inspection award.

2 2.1 Project management plan delivered within 10 business days of the effective date of contract award.

• Deliverables are free of errors ≥95% of the time.

• Deliverables are submitted by established deadlines ≥95% of the time.

• Spot Checks

• 100% Inspection

2.2 Once, within

15 business days of the effective date of contract award.

• Deliverables are free of errors ≥95% of the time.

• Spot Checks

• 100% Inspection

3 3.1 Within 5 business days of request by the COR, or as determined by mutual agreement

• Deliverables are free of errors ≥95% of the time.

• Deliverables are submitted by established deadlines ≥95% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

3.2 Within 5

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

3.3 Within 5

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Deliverables are submitted within one week of established deadlines 100% of

• Spot Checks

• 100% Inspection the time.

3.4 Within 5

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

4 4.1 Within 5 business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Spot Checks

• 100% Inspection

4.2 Within 5

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Spot Checks

• 100% Inspection

4.3 Within 5

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Spot Checks

• 100% Inspection

4.4 Within 5

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Spot Checks

• 100% Inspection

5 Within 5 business days

• Deliverables are free of errors ≥95% of the time.

• Spot Checks of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

6 6.1 Within 5 business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥95% of the time.

• Random Sampling

• Planned Sampling

• Spot Checks

• 100% Inspection

7 7.1 Within 10 business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

7.2 Within 10

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

7.3 Within 10

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

7.4 Within 10

business days of request by the COR, or as determined

• Deliverables are free of errors ≥95% of the time.

• Deliverables are submitted by established deadlines ≥75% of the time.

• Spot Checks

• Deliverables are submitted within one week of established deadlines 100% of the time.

7.5 Within 10

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

7.6 Within 10

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

7.7 Within 10

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

• 100% Inspection

7.8 Within 10

business days of request by the COR, or as determined

• Deliverables are submitted by established deadlines ≥75% of the time.

• Deliverables are submitted within one week of established deadlines 100% of the time.

• Spot Checks

Technical Exhibit 2 -- Applicable Directives

1. OCIO:1-102, “Freedom of Information Act (FOIA) Policies and Procedures:

Release or Denial of Department of Education Records Responsive to FOIA Requests,” dated 05/18/2004 (hereby superseded).

2. ACS OM: 6-104, “The Privacy Act of 1974 (The Collection, Use, and Protection of Personally Identifiable Information),” dated 8/31/2006.

3. U.S. Department of Education FOIA Regulations, 34 C.F.R. Part 5., dated July 1, 2011

4. U.S. Department of Education Privacy Act Regulations, 34 C.F.R. Part 5b, dated July 1, 2015.

5. The President’s “Transparency and Open Government” memorandum, dated January 21, 2009.

6. The Attorney General’s “Freedom of Information Act Guidelines”, dated March 19, 2009.

7. Executive Order 13392, “Improving Agency Disclosure of Information,” dated December 19, 2005.

8. The “Openness Promotes Effectiveness in our National Government Act of 2007,” Public Law 110-175.

https://www.whitehouse.gov/the_press_office/TransparencyandOpenGovernment https://www.justice.gov/sites/default/files/ag/legacy/2009/06/24/foia-memo-march2009.pdf

Technical Exhibit 3 – Applicable Acronyms

1. Change Advisory Board (CAB)

2. Chief Privacy Office (CPO)

3. Contracting Officer’s Representative (COR)

4. U.S. Department of Education (Department)

5. Enterprise Architecture Review Board (EARB)

6. Office of Management (OM)

7. Office of Management and Budget (OMB)

8. Performance Work Statement (PWS)

9. Privacy Impact Assessment (PIA)

10. Privacy Threshold Assessment (PTA)

I. Introduction
II. Background
III. Period of Performance
IV. Place of Performance
V. Scope of Work
VI. Additional Contractor Requirements
Core Business Hours
Weekends, Holidays, and Inclement Weather
Illness, Extended Absences, and Vacancies
Compliance with ED IT Security Policy
VII. Contract Personnel
Technical Exhibit 1 – Performance Requirements Summary
Deliverables
Delivery Schedule
Technical Exhibit 2 -- Applicable Directives
Technical Exhibit 3 – Applicable Acronyms

File details come from the government source that posted it. Updated .