FCHS2_Section_J_Attachment_9_Day_One_USDA_DISC.pdf
PDF 797 KB Posted
- Attached to
- DOI Foundation Cloud Hosting Services (FCHS2) Federal contract opportunity
- Solicitation number
- 140D0423R0002
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Foundation Cloud Hosting Services II (FCHS2) Section J
J09-1
SECTION J – ATTACHMENT 09
Introduction Day One Use Case – USDA OCIO Digital Infrastructure Services Center (DISC)
The Department of the Interior (DOI) has prepared this Day One Use Case to support the United States Department of Agriculture (USDA) to provide cloud-based infrastructure computing and related services to enable the flexible and scalable delivery of cloud environments that can be provisioned and de-provisioned by USDA agencies to develop, test, certify and release USDA business applications by authorized USDA Information Technology (IT) specialists.
Performance Work Statement
1. Background
The United States Department of Agriculture (USDA) Digital Infrastructure Services Center (DISC) provides cloud brokerage services as a consolidated point of entry for cloud (HyperScaler / Infrastructure as a Service [IaaS] / Platform as a Service [PaaS]) procurements through the Cloud Brokerage office. This has historically been viewed as the easy button for access to cloud, shared USDA Authority to Operate (ATO) inheritance beyond the Federal Risk and Authorization Management Program (FedRAMP) controls, consistent billing and approved services, and ability to access cloud integrator services to support USDA mission areas and federal government customers.
While this model has allowed for flexibility in its current state, there are drawbacks. The model that exists today effectively allows each mission area or customer to have a direct line to the Department of the Interior’s (DOI) cloud contract. Silos have been raised between the various customer cloud and service implementations, causing a lack of visibility and negated scalability, metric collection, and lack of a cohesive enterprise architecture approach. The USDA is now maturing from these early phases of cloud brokerage into a true cloud solutions organization that will enable DISC to offer well curated, managed services that better control costs, are properly secured, promote reusability, and significantly increase speed to market for customers. In support of this new Complex Solutions organization, DISC leveraged industry best practices to create a new operating model, processes, and a roadmap for the growth of the existing AgCloud environment to meet the ever-increasing demands of USDA mission areas, federal agency customers, and create a true USDA Digital Enterprise.
AgCloud facilitates USDA’s efforts to migrate applications to a cloud environment, allowing the consolidation of USDA data centers to support the Federal Data Center Consolidation Plan
(FDCCP).
As the Complex Solutions organization grows to meet the demands of its customers, it will increasingly incorporate commercial cloud capabilities as curated, managed services, and further extend them with mature platform and DevSecOps capabilities. This posture creates increased efficiencies across the entire spectrum of USDA IT operations, allowing customer Associate Chief Information Officers (CIOs) to focus on mission applications while consuming DISC services for infrastructure, and potentially platform support. Over time, USDA will be able to save costs and better allocate resources, evolving USDA’s IT enterprise to meet the needs of the
J09-2
USDA mission area supporting FITARA, Cloud Smart and other federal guidance as needed throughout the lifecycle of this task order.
2. Objectives
2.1 General Objectives
The USDA seeks to demonstrate the flexibility, efficiency and economies of scale related to hosting in the cloud. The general objectives include the following:
● Reduce demand levels and competition for limited resources on internal telecommunications networks, enablement of IPv6, TIC3 standards and Zero Trust Architecture.
● Improved system reliability, availability and accountability, enablement of FinOps practices and TBM alignment to USDA investments.
● Improved infrastructure service delivery efficiency: Leverage economies of scale of cloud service providers and pay only for the resources consumed when such resources are designated as non-persistent.
● Improved responsiveness to internal customer need for environments: Demonstrate “user” ability to provision and release infrastructure “on-demand”, using an API’s and other advanced capabilities to support programmatic modernization and efficiencies.
● Elasticity of supply: Demonstrate ability of supporting infrastructure to adjust capacity to meet changes in demand.
● Service Metering: Demonstrate ability to attribute processing costs at an hourly rate or lower to specific consuming accounts and IT applications.
● Ease of Integration: Facilitate the use of customer tools such as, but not limited to Rational, and Service Now with the management platform.
● Enablement of the NIST Defined Cloud Actors with DISC’s Complex Solutions as the Cloud Broker, DISC-ENS as the Cloud Carrier, USDA Staff Offices, OCIO & Mission Areas, and DISC customers as the Cloud Consumers.
Cloud solutions may comprise any combination of the services offered by USDA approved cloud service providers, if it achieves the objectives specified herein. Cloud service providers include, but are not limited to, Microsoft Azure, Amazon AWS, Google Cloud, and Oracle Cloud Infrastructure.
● The Contractor may provide professional services as needed based on specific sub-task order deliverables with well-defined goals, objectives and a defined Quality Assurance Support Plan as agreed upon between the contractor and the USDA.
● The Contractor shall provide customer support for USDA agencies, including, but not limited to their system owners and managers, as required.
● The Contractor shall provide the ability for services to be acquired through the CSP marketplace(s) or catalog of services.
● The Contractor shall provide associated support services which may be required to enable identification, analysis, prioritization, preparation and migration of IT systems from the current operating environment to the target operating environment as required.
J09-3
2.2 Common Objectives
Objectives common to all Cloud Consumer Use Cases as described in the provided cloud inventory include the following:
● The Contractor shall establish and maintain a security program and security controls per
FedRAMP and Cloud Security and Privacy Requirements as specified in Appendix A. as well as compliance with current Federal, USDA policies and directives.
● The Contractor shall provide a turn-key cloud-based platform with service level guarantees as specified in Appendix B.
● The Contractor solution shall support high availability, fail-over, and managed re- hosting of virtual servers and database systems in accordance with Appendix B.
● The Contractor solution shall accommodate on-line bulk loading and data updates as specified in Appendix B and provide support for loading very large datasets delivered by physical shipping of media.
● The Contractor shall maintain appropriate security programs, processes and certifications as required.
● The Contractor shall provide computing infrastructure including virtual servers, storage, and networking and all supported IaaS, PaaS and SaaS solutions provided by the Awardee Cloud Service Providers.
● The Contractor shall provide a variety of server operating systems including current versions of, including but not limited to, Windows Server and two or more distributions of Linux, such as Red Hat, Ubuntu and CentOS that meet or exceed Federal and USDA standards.
● The Contractor shall provide the ability for USDA agency users to provision and manage services remotely via secure connection through the internet as required, and through integration with client owned workflow management tools, including but not limited to, Service Now or contractor provided tools via secure connection through the internet.
● The Contractor shall provide the ability for USDA agency users to create new and start-up, shutdown, and delete existing VMs.
● The Contractor shall provide the capability to itemize services consumed and the monthly billable cost for each USDA agency’s IT system.
3. Tasks
3.1 General Tasks
General tasks for all USDA systems supported under this task order include:
● Provide department/agency designated USDA IT staff system administrators and application developers with the ability to provision cloud infrastructure on demand.
● Provide department/agency designated USDA IT staff system administrators and application developers with the ability to provision cloud software on demand through the CSP catalog/marketplace.
3.2 Common Tasks
Tasks common to all Mission Use Cases supported under this task order include the following:
3.2.1 Customer Services
J09-4
The Contractor shall provide the following:
• Provide USDA full administrative, direct, continuous access to Cloud Services via CSP maintained methods without the need to engage the contractor or use contractor pre-provisions/pre-purchased CSP resources.
• Provide USDA access to multiple Cloud Service providers (CSPs). At a minimum;
Microsoft Azure, Amazon AWS, Google Cloud, and Oracle Cloud Infrastructure including where applicable Public Cloud, Community Cloud and Government Cloud options.
• Provide access to additional CSPs at USDA’s request as they become available on the contract.
• Maintain USDA CSP accounts independent from all non-USDA CSP accounts, should there be extenuating circumstances the contractor is to engage USDA Complex Solutions/Cloud Broker to support a documented agreement.
• Provide USDA with temporary root credentials to any new accounts requested by USDA Complex Solutions. Immediately upon receipt of the temporary root credentials, USDA will change the root credentials to eliminate contractor access to the account. Upon award, USDA will indicate the name of the individual approved to request new accounts and to whom the contractor shall provide temporary root credentials.
• Support transfer of existing CSP accounts used by USDA directly or used indirectly by USDA through other arrangements with other contractors, integrators, or federal contractors. USDA shall be responsible for all subsequent costs incurred within transferred accounts. USDA shall coordinate requests with the contractor and existing USDA CSP account owner to transfer existing USDA CSP accounts, including ensuring their approval, cooperation, and involvement in CSP account transfer steps.
• Ensure that USDA has the required administrative access to coordinate with the CSP and USDA telecom providers as necessary to ensure new or existing connectivity between USDA and the CSP.
• Ensure that all CSP communications and alerts be directly and immediately communicated to USDA identified contacts. USDA will provide contact information for these communications.
• Provide consolidated monthly invoice per CSP that includes each account (master, sub, linked) to USDA for all resources and services.
• Calculate monthly CSP support costs, at the level determined by USDA, based on consolidated costs for all USDA accounts (master, sub, or linked) within the CSP.
• Provide Inventory, Billing and Invoicing Monthly, no later than the 14th of each month, with consistent data and linkage of inventory, costs, rates, and invoices.
• Provide a well-defined method for automated data extraction for inventory, billing and invoicing leveraging automation, API’s or other modern, industry standard methods with a requirement for machine readable content for automated processes for USDA billing, inventory and reporting that aligns with contractor billing, invoicing and payment practices outlined in this contract.
• Provide a cloud-based hosting solution based on current and emerging industry standards and best practices throughout task order life-cycle.
• Provide best value to Government, while at the same time allowing the USDA the flexibility to meet current and future capacity requirements and provide detailed reporting of how “best value” is determined and aligned to USDA cloud consumer objectives.
J09-5
• Provide BYOL (bring your own license) software at the best value to Government, while at the same time allowing the USDA the flexibility to transfer existing hybrid licenses to the CSP tenant.
• Provide lifecycle management tools or integration with client managed tools such as Rational and Service Now for Configuration Management.
• Provide a Change Control Process to secure the functionality of the environment without interfering with USDA’s use of the environments.
• Provide the capability to import existing VMware-based VMs to create VMs in the contractor cloud environment. Support for other virtual machine support environment
THE GOVERNMENT WILL;
• Be considered the “Account Holder” of all CSP Accounts (master, sub, and linked) supported under this BPA, with all associated rights and responsibilities, excluding the direct payment to the CSP, which will be the responsibility of the contractor.
• Require full administrative control and direct access to the commercially available CSP portal/console, API’s, and other CSP provided methods available to CSP customers without the need to engage the contractor or use pre-provisioned/pre-purchased contractor resources.
• Determine the distribution of workloads across CSPs.
• Be responsible for configuring and controlling all access for USDA CSP accounts, including billing, cost management, and USDA owned cloud management tools.
• Require direct access to CSP support including the ability to open troubleshooting tickets, or otherwise engage CSP for assistance or guidance.
• Create its own account hierarchy under its CSP master accounts and control the root credential for these accounts. USDA will inform the contractor whenever USDA creates a new CSP sub-account.
• Allocate/deallocate cloud resources in the CSP directly without the need to engage the contractor or use contractor pre-provisioned/pre-purchased CSP resources.
• Purchase any available level of CSP support plans available, based on USDA’s requirements.
• Purchase all CSP offered cost discount programs such as reserved, spot, pricing plans, or on-demand CSP resources.
• Retain ownership of all USDA purchased cost discount programs upon each account’s transfer from the contractor to another entity.
• Retain ownership of all USDA purchased cloud resources and services, including on premises deployed solutions throughout the life of the BPA and transfers at the end of contract.
• Retain ownership of all data, metadata, USDA provided images and USDA provided software.
3.2.2 Help Desk Support and Services
The Contractor shall:
• Meet or exceed the service level requirements specified in Appendix B.
• Provide online trouble ticketing with email capabilities available to USDA parties as agreed upon during task order award and sub-task-order as needed.
J09-6
• Provide a mechanism to the USDA for the bulk retrieval of all data, scripts, software, virtual machine images, and so forth such as mirroring or copying to the USDA-supplied industry standard media within 30 days.
3.2.3 Usage Reporting
• Provide a mechanism to track system usage based on Account and Information System codes so that usage by designated account holders can see and track costs by information system according to their usage.
• Provide on-line reporting capability that will allow designated account holders to see the status of their usage with at least daily updates.
3.2.4 Administration Capabilities
• Provide network storage, server and virtualization layer management to include the performance monitoring of internal technology and refresh cycles applicable to the environment.
• Provide automated monitoring of VM performance, resource utilization, storage capacity, and other events such as failure or degradation of the service through dashboards or API access available at the contractor’s boundary.
• Support Physical-to-Virtual (P2V) and, for VMware virtual servers, Virtual-to-Virtual (V2V), and Virtual-to-Physical migration methods for systems, including private Local Area Network (LAN) integration with provider network via secure channel(s) as required.
• Provide migration planning and support to USDA as an on-demand optional service, such as configuring external connections to the hosted infrastructure, and the ability to upload database backups and VM images to the hosting environment.
A. Recovery Point Objective (RPO), the Contractor shall be able to recover a system or files in accordance with the Service Portfolio SLAs specified in Appendix B for that Mission Use Case service.
B. Recovery Time Objective (RTO), the Contractor shall have the ability to recover systems or files in accordance with the Service Portfolio SLAs specified for that Mission Use Case service. The most current VM system images and files shall be available to the USDA staff for restarting non-resident services per the Service Portfolio SLA specified in Appendix B. (Note - Non-resident VM services refers to services running on virtual servers in the local USDA agency environment. USDA agencies will take system images of these services to create the VMs in the cloud. Once in the cloud environment, the VMs should be capable of elastic scaling in response to load testing by USDA.)
C. Data Backup Location – Data backups shall be maintained or replicated at a site geographically disparate from the hosting site such that the loss of one data center does not prohibit recovery of data within the prescribed RTO.
D. Specific Snapshot Objective – USDA staff shall be able to create and delete system snapshots and have the ability to restore from a full snapshot in accordance with the Service Portfolio SLA specified in Appendix B for that Mission Use Case
J09-7 service.
3.2.5 Comprehensive Backup
• Provide a system that allows restoration of a data base system, set of files, or an individual file or folder on request in accordance with the USDA Service Level Agreements (SLA) as defined in Appendix B.
• Describe and implement a backup procedure and process that supports the following objectives:
3.2.6 Technology Refresh
• Comply with technology refresh requirements necessary to ensure that security requirements are met.
• Comply with technology refresh requirements necessary to ensure service level agreements (SLA) are met.
• When providing VM services where the operating system is provided as part of the service by the Contractor, use an operating system version that is within two minor versions of the most current released operating system version.
3.2.7 Operational FISMA Compliance
• Comply with the USDA Cloud Security and Privacy Requirements specified in Appendix
A.
• Comply with IDIQ level security requirements Comply with directed mandates to protect and defend information systems from recurring security threats or in response to real-time vulnerabilities.
3.2.8 Migration Support Services
• Demonstrate the architecture to support the operating requirements for the outlined inventory that will be provided post-award.
• Provide tools and processes for monitoring the availability of assigned applications, responding to system and application outages with troubleshooting activities designed to identify and mitigate operational issues.
• Provide planning and migration support services in support of individual USDA projects when required.
• Upon request by the USDA customer, the Contractor shall make all USDA cloud data available for electronic transfer out of the Contractors environment within 60 days from the date of request. The Contractor shall also ensure that no residual USDA data exists on all storage devices that are disposed of, reused in an environment not governed by the agreement between the USDA and the Contractor, or transferred to a third party. The Contractor shall ensure this by, at minimum, clearing all data devices prior to disposal, reuse or transfer in accordance with NIST 800-88. Devices that are unable to be cleared or purged must be physically destroyed as defined in NIST 800-88.
J09-8
3.2.9 Transition-In Tasks
The Contractor Shall:
• Transition-In services are defined as the period to execute the stand-up of the initial
USDA services environment, operating procedures, supporting applications, and migration of the current USDA Cloud tenants/accounts/subscriptions, workload and applications.
• This would include any Contractor/integrator provided services being used by USDA under the provisions of the master contract vehicle and tasking.
• The Contractor shall develop and execute a Transition-In Plan to accomplish the transition of operations from the current operating environment to the Contractor and USDA Cloud environment without disruption of service.
• The Transition-In plan will include the means and plan for communication with the Government and incumbent for sharing, data, technical knowledge, expertise and/or resources essential to this effort to ensure the greatest degree of cooperation and successfully meet the terms of the contract (task order)
• The Contractor shall work with any incumbent contractors and other stakeholders to establish and execute plans for the transition of the ownership of cloud tenant/accounts or, if not technically feasible, transitioning existing cloud applications and account information for the USDA accounts on the DOI contract.
• The Contractor shall plan and execute a technical handoff and other non-administrative transition activities, in addition to transitioning accounting information, to establish the requisite proficiency to assume operational responsibility for the migrated Cloud tenants/accounts/subscriptions, workloads and applications.
• A snapshot in time of the updated cloud inventory will be provided to the incoming Contractor post-award and updated on agreed-upon intervals with USDA and the out-going Contractor.
Government Requirement 1 The Contractor shall coordinate with USDA to onboard and change ownership of existing USDA accounts/tenants.
2 The Contractor shall transition any Contractor/integrator provided services being used by USDA under the provisions of the master contract vehicle and tasking.
3 The Contractor shall provide knowledge transfer with the incumbent contractor and/or Government staff to ensure adequate transition of all responsibilities including documented and non-documented processes.
4 The Contractor shall document transition progress and results in a weekly Transition Status Report.
5 The Contractor shall ensure timely submission of on-boarding documents for personnel and facilitate knowledge transfer with a minimum of 60 days overlap after credentialing.
3.2.10 Transition-Out Tasks
J09-9
The Contractor Shall:
• Transition-Out provides a period to execute an orderly transition of the USDA Cloud environments (tenants/accounts/subscriptions) and applications to another Contractor or the Government.
• Transition-Out activities include the Contractor developing a Transition Out Plan and, upon Government approval, executing that plan to a successful completion in accordance with the established Transition Out SLAs.
• The Transition-Out Plan shall detail the planned transition methodology in logical sequence to ensure a smooth transition of all tasks without interruption or degradation of service.
• The Contractor retains full responsibility to manage the transition to ensure USDA Cloud operations and environments continue to execute at full capacity, capability and functionality during the transition period.
• The Contractor’s Transition-Out Plan shall be a comprehensive plan for the transition and transfer of full operational responsibilities to a potential follow-on Contractor.
• The approved Transition-Out plan shall be followed to ensure an orderly, secure, efficient, and expedient transition of all contract activities by the contract completion date.
ID Government Requirement
1 The Contractor shall successfully complete the execution of the Transition- Out plan no later than 120-calendar days prior to the expiration of the order.
2 The Contractor shall work with any incoming Contractor to ensure a smooth transition of the USDA workloads.
3 The Contractor shall provide an outgoing transition plan no later than 180-calendar days after award of this contract. This transition plan shall include, but is not limited to:
a. Coordination with Government representatives,
b. Review, evaluation and transition of current support services, that
c. Current inventory of all cloud resources to be updated monthly,
d. Transition of historic data,
e. Transition of all code developed to support USDA activities,
f. Government-approved training and certification process,
g. Transfer of hardware warranties and software licenses (if applicable),
h. Transfer of all necessary business and/or technical documentation,
i. Transfer of compiled and un-compiled source code, to include all versions, maintenance updates, and patches (if applicable),
j. Transfer of Contractor developed tools, scripts, and source code,
k. Orientation phase in program to introduce Government personnel, programs, and users to the Contractor’s team, tools, methodologies, and business processes,
l. Disposition of Contractor purchased Government owned assets, including facilities, equipment, furniture, phone lines, computer equipment, etc., J09-10
m. Transfer of GFE, Government Furnished Information, and GFE inventory management assistance,
n. Applicable debriefing and personnel out-processing procedures, and
o. Turn-in of all Government keys, ID/access cards, and security codes
p. Facilitate a process for USDA to sign-off and approve on all transition activities.
4 The Contractor shall provide the Government at any point during and at the conclusion of the contract access to or copies of data and materials created, captured or stored required to support the services of this contract and transition.
5 The Contractor shall deliver in accordance with the Transition Out plan: all materials, data, documentation, and software used and developed to support contract activities, as well a snapshot of the current inventory
4. Security Requirements
Specific Security Requirements are identified in Appendix A – USDA Cloud Security Control Requirements and in accordance with the DOI Foundation Cloud Hosting Services IDIQ contract.
5. Network Capabilities
The Contractor shall provide or support the following network capabilities:
• The infrastructure shall provide the ability to create a network connection that allows complete control over the virtual networking environment based on DISC ENS USDANet. In, the infrastructure shall allow for either dedicated network circuits or a hardware Virtual Private Network (VPN) connection between the cloud and the USDA network(s). (Note, USDA’s preference is to use a single (or as few as feasible) Express- Route, Direct Connect or similar Enterprise capability to each CSP, connectivity will be coordinated and approved by USDA DISC ENS & Complex Solutions)
• The network connection shall be available at a minimum of two geographically diverse locations. Each location shall be able to service connections to all USDA virtual networks and instances inside the cloud. Each location must also be able to support a BGP routing protocol interface for route flow management.
• The infrastructure must meet Trusted Internet Connection (TIC) 2.0 standards per OMB Memorandum M 08-05 to allow inter-connecting the networks.
• The Service Provider must support both IPv4 and IPv6 service connections and instance management. However, USDA would be willing to support a 6-to-4 tunnel for up to one year after award. Please note - a teredo tunnel would not be a supported option.
• The provider must submit statements with their submissions explaining their options and services regarding the following network components:
J09-11
A. The vendor’s ability to support the USDA use of RFC1918 and RFC4193 (private address space) for making USDA client connections to instances inside the cloud service.
B. The vendor’s ability to use any RFC1918 or RFC4193 (private address space) in their infrastructure that may have an impact on USDA services.
C. The vendor’s ability to support DNS services for USDA as an option. If this ability exists, the vendor is to provide documentation on standard operating procedures (SOP) for how USDA would use them.
D. The vendor’s ability to support the use of USDA assigned addresses inside the cloud environment or the ability for the vendor to provide their own address assignments.
E. The vendor’s ability to provide near-real time address management for instances running inside their environment.
6. Section 508 Compliance
6.1 Section 508 Accessibility of Information and Communications Technology
a) This Assessment Work is subject to Section 508 of the Rehabilitation Act of 1973 (29
U.S.C. 794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220).
Specifically, subsection 508(a)(1) requires that when the Federal Government procures Information and Communications Technology (ICT)1, the ICT must allow Federal employees and members of the public with disabilities comparable access to and use of information and data provided to Federal employees and members of the public without disabilities.
b) The ICT accessibility standards as 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board (also known as the Access Board) and apply to contracts, task orders, and indefinite quantity contracts on or after June 25, 2001.
c) Each Information and Communications Technology (ICT) product or service furnished under this contract shall comply with the Information and Communications Technology Accessibility Standards (36 CFR 1194), as specified in the contract, at a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing.
The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within a period of time specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:
1) Cancellation of the contract, delivery, or task order, purchase, or line item without termination liabilities; or
1 Please note that the term Information and Communications Technology (ICT) is synonymous with Electronic and Information Technology (EIT), the previously used term. The term ICT will be used to meet international standards after the release of the Section 508 Refresh.
J09-12
2) In the case of custom Information and Communications Technology (ICT) being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the non-compliant ICT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.
d) The contractor must ensure that all ICT products and services that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements.
e) For every ICT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date, whichever shall occur first.
Section 508 Compliance
The Assessment team shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this, the Assessment Work shall take precedence.
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
3) http://www.access-board.gov/sec508/508standards.htm (Section 508 standards)
4) FAR 39.2 (Section 508)
5) http://www.ocio.usda.gov/document/departmental-regulation-4030-001 (USDA standards, policies, and procedures for Section 508)
In addition, all contract deliverables are subject to these standards.
All web content or communications materials produced, regardless of format (text, audio, video, etc.), must conform to the applicable Section 508 standards to allow Federal employees and members of the public with disabilities comparable access to and use of information and data provided to Federal employees and members of the public without disabilities. All contractors (including sub-contractors) and consultants responsible for preparing or posting content must comply with the applicable Section 508 accessibility standards and, where applicable, those set forth in the referenced policy or standards document above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the Assessment Work shall be the responsibility of the contractor or consultant.
The following Section 508 provisions apply to the products and/or services identified in this http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/document/departmental-regulation-4030-001
J09-13
Assessment Work:
• 36 CFR Part 1194.21 provisions a-l
• 36 CFR Part 1194.22 provisions a-p
• 36 CFR Part 1194.23 provisions a-k[4]
• 36 CFR Part 1194.24 provisions a-e
• 36 CFR Part 1194.25 provisions a-j[4]
• 36 CFR Part 1194.26 provisions a-d
• 36 CFR Part 1194.31 provisions a-f
• 36 CFR Part 1194.41 provisions a-c
The following Section 508 provisions apply to software development material identified in this Assessment Work:
For software development, software applications, and operating systems the Assessment team shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
• 36 CFR Part 1194.21 provisions a-l
For web-based applications (intranet, internet information and applications, 16 rules), the Assessment team shall comply with the following standards, policies, and procedures:
2) 36 CFR 1194 (Section 508 standards)
• 36 CFR Part 1194.21 provisions a-l
• 36 CFR Part 1194.22 provisions a-p
For telecommunication products and services, the assessment team shall comply with the following standards, policies, and procedures:
2) 36 CFR 1194 (Section 508 standards)
• 36 CFR Part 1194.23 provisions a-k
• 36 CFR Part 1194.31 provisions a-f
• 36 CFR Part 1194.41 provisions a-c
For video and multimedia applications (including training materials), the Assessment team shall comply with the following standards, policies, and procedures:
J09-14
2) 36 CFR 1194 (Section 508 standards)
• 36 CFR Part 1194.24 provisions a-e
For self-contained and closed products, the Assessment team shall comply with the
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
• 36 CFR Part 1194.21 provisions a-l
• 36 CFR Part 1194.25 provisions a-j
For desktop and portable computers, the Assessment team shall comply with the
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
• 36 CFR Part 1194.21 provisions a-l
• 36 CFR Part 1194.26 provisions a-d
• 36 CFR Part 1194.31 provisions a-f
• 36 CFR Part 1194.41 provisions a-c
For help desk and other support services, the Assessment team shall comply with the
2) 36 CFR 1194 (Section 508 standards)
If the help desk or other support services include training, Assessment team must also comply with the following standards, policies, and procedures in addition to 36 CFR Part
1194.31 provisions a-f and 36 CFR Part 1194.41 provisions a-c:
1) 36 CFR Part 1194.21 provisions a-l (installable and web-based training)
2) 36 CFR Part 1194.22 provisions a-p (web-based software)
J09-15
All Information and Communications Technology (ICT) subject to the 36 CFR 1194 standards will have a Section 508 usability and acceptance test where Section 508 compliance will be validated. This test must be administered by a Federal Section 508 Testing Center.
All maintenance for Information and Communications Technology that requires upgrades, modifications, installations, and purchases will adhere to the Section 508 standards and 36
CFR 1194.
WCAG 2.0 Compliance The Assessment team shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this Assessment Work, the Assessment Work shall take precedence.
Custom ICT Development Services When Assessment team provides custom ICT development services pursuant to this contract, Assessment team shall ensure the ICT fully conforms to the applicable Revised 508 Standards prior to delivery and before final acceptance.
Installation, Configuration, and Integration Services When Assessment team provides installation, configuration, or integration services for equipment and software pursuant to this contract, the offeror shall not install, configure, or integrate the equipment and software in a way that reduces the level of conformance with the applicable Revised 508 standards.
Maintenance, Upgrades, and Replacements Assessment team shall ensure maintenance upgrades, substitutions, and replacements to equipment and software pursuant to this contract do not reduce the original level of conformance with the applicable Revised 508 standards at the time of the contract award.
Service Personnel
Assessment team shall ensure the personnel providing the labor hours possess the knowledge, skills, and ability necessary to address the applicable Revised 508 standards defined in this contract and shall provide supporting documentation upon request.
Hosting Services When providing hosting services for electronic content provided by the agency, Assessment team shall not implement the hosting services in a manner that reduces the existing level of conformance of the electronic content with applicable Revised 508 standards. Throughout the life of the contract, the agency reserves the right to perform testing on a vendor or contractor’s hosted solution to verify conformance with this requirement.
Validation for ICT Items When purchasing ICT where 1) 508 validation is not possible prior to award, 2) when ICT will be changed after the award, or 3) ICT will be hosted in a third-party
J09-16 environment, Assessment team shall test and validate the ICT solution for conformance to the Revised 508 standards, in accordance with the requirement testing methods, as defined by the agency. Throughout the life of the contract, the agency reserves the right to perform testing to verify conformance with this requirement.
Documentation Assessment team shall maintain and retain full documentation of the measures taken to ensure compliance with the applicable requirements, including records of any testing or demonstrations conducted.
Conformance Reporting Prior to acceptance, Assessment team shall provide an Accessibility Conformance Report (ACR) for each ICT item that is developed, updated, configured for the agency, and when product substitutions are offered. The ACR should be based on the latest version of the Voluntary Product Accessibility Template (VPAT) provided by the Information Technology Industry Council (ITI). To be considered for award, an ACR must be submitted for each ICT item, and must be completed according to the instructions provided by ITI.
When the contractor is required to perform testing to validate conformance to the agency’s accessibility requirements, Assessment team shall provide a Supplemental Accessibility Conformance Report (SAR) that contains the following information:
• Accessibility test results based on the required test methods.
• Documentation of features provided to help achieve accessibility and usability for people with disabilities.
• Documentation of core functions that cannot be accessed by persons with disabilities.
• Documentation on how to configure and install the ICT item to support accessibility.
• When an ICT item is an authoring tool that generates content (including documents, reports, videos, multimedia productions, web content, etc.)., provide information on how the ICT item enables the creation of accessible electronic content that conforms to the Revised 508 Standards, including the range of accessible user interface elements the tool can create.
• Before final acceptance, the contractor shall provide a fully working demonstration of the completed ICT Item to demonstrate conformance to the agency's accessibility requirements. The demonstration shall expose where such conformance is and is not achieved.
• Before acceptance, the agency reserves the right to perform independent https://www.section508.gov/sell/vpat http://www.itic.org/policy/accessibility http://www.itic.org/policy/accessibility
J09-17 testing to validate that the ICT solution provided by the contractor conforms to the applicable Revised 508 standards.
Non-Compliance Before final acceptance of any ICT item, including updates and replacements, if Assessment team claims its products or services satisfy the applicable Revised 508 standards specified in the contract vehicle, and the contracting officer determines that any furnished ICT item is not in compliance with such requirements, the contracting officer will promptly inform Assessment team in writing of the non-compliance. Assessment team shall, at no cost to the agency, repair or replace the non-compliant products or services within the period specified by the contracting officer.
6.2 Standards of Conduct
The contractor will be responsible for maintaining satisfactory standards of employee competency, conduct, appearance, and integrity. The contractor is also responsible for ensuring that its employees and those of its subcontractor(s) do not disturb papers on desks, open desk drawers or cabinets, use Government telephones, except as authorized, or otherwise jeopardize the security and the privacy of Government employees, its clientele, and the contents and property of the federal building(s) in which the TO work is performed. Each employee or supervisor of the contractor is expected to adhere to standards of behavior that reflect credit on themselves, their employer, and the Federal Government. The contractor will be responsible for taking such disciplinary action, including suspension without pay or removal from the worksite, with respect to its employees, as may be necessary to enforce those standards.
Where applicable, the requirements of this clause must be expressly incorporated into subcontract(s) and must be applicable to all subcontractor employees who may perform recurring services or work at the federal building and grounds of this TO. The Government retains the right to permanently remove any employee of the contractor from performing duties assigned under this TO at the federal building should the employee's performance so warrant. The Government will request the contractor to immediately remove any employee of the contractor from the federal building/work-site should it be determined by the Contracting Officer that the individual employee of the contractor is "unsuitable" for security reasons or for otherwise being found to be unfit for performing his assigned duty at a federal building. The following areas (not all-inclusive) are considered justification for requesting the contractor to immediately remove an employee from a federal building/work site:
a) Neglect of assigned duty and refusing to render assistance or cooperate in upholding the integrity of the security programs at the worksite;
b) Falsification or unlawful concealment, removal, mutilation, or destruction of any official documents or records, or concealment of material facts by willful omissions from official documents or records;
c) Disorderly conduct, use of abusive or offensive language, quarreling, intimidation by words or actions, or fighting; participation in disruptive activities which interfere with the normal and efficient operations of the Government;
J09-18
d) Theft, vandalism, immoral conduct, or any other criminal actions;
e) Selling, consuming, or being under the influence of intoxicants, drugs, or controlled substances which produce similar effects;
f) Improper use of official authority or credentials, as a supervisor or employee of the contractor;
g) Violation of agency and Contractor security procedures and regulations; and
h) Violation of the rules and regulations governing federal public buildings and grounds set forth in 41 CFR Subpart 101-20.3 Conduct on Federal Property.
Following a recommendation from an agency program official or security officer, the Contracting Officer will make all determinations regarding the removal of any employee of the contractor from and denial/termination of clearance and access to the federal building worksite for non-performance, misconduct, or failure to abide by all laws and regulations.
The Contracting Officer will verbally inform the contractor about the employee, followed by a written confirmation or determination. Specific reasons for the removal of an employee will be provided to the contractor in writing. In the event of a dispute, the Contracting Officer will make a final determination.
Upon a determination of the Government that an employee of the contractor be removed from or denied access to a federal building worksite, the employee's clearance and access to the federal building must be immediately revoked or otherwise terminated. Furthermore, if applicable, the building pass and/or other access device(s) previously given to the employee must be immediately surrendered, returned, or delivered to the security officer of the federal building.
6.3 Release of News Information
No news release (including photographs and films, public announcements, denial or confirmation of same) on any part of the subject matter of this effort or any phase of any program hereunder shall be made without the prior written approval of the Contracting Officer.
6.4 Release of Reports
The Contractor is prohibited from releasing to any source, other than the sponsoring activity any interim, draft and final reports or information pertaining to services performed under this TO until report approval or official review has been obtained. Furthermore, the contractor shall insure that the cover of all interim, draft and final reports contain the following statement: “The view, opinions, and/or findings contained in the report are those of the author(s) and should not be construed as an official Government position, policy or decision, unless so designated by other documentation.”
6.5 Dissemination of Information
There shall be no dissemination or publication, except within and between the Contractor and any subcontractors, of information developed under this TO or contained in the reports to be furnished pursuant to this effort without prior written approval from the Contracting Officer.
J09-19
6.6 Disclosure of Information
The contractor will maintain, transmit, retain in strictest confidence, and prevent the unauthorized duplication, use, and disclosure of personnel information. The contractor will provide personnel information only to employees, contractors, and subcontractors having a need to know such information in the performance of their duties for this project.
Information made available to the contractor by the Government for the performance of administration of this effort shall be used only for those purposes and shall not be used in any other way without the written agreement of the Contracting Officer.
The contractor agrees to assume responsibility for protecting the confidentiality of Government records, which are not public information. Each contractor or employee of the contractor to whom information may be made available or disclosed shall be notified in writing by the contractor that such information may be disclosed only for a purpose and to the extent authorized herein.
6.7 Data Ownership
a) All data is and shall remain the exclusive property of the government. The scope and pricing of the agreement must ensure that the government may have access and download capability of all data for research, investigation, transfer, or migration to other systems in a readable format.
b) The Contractor shall provide notice immediately of any third-party request for DOI data and the request cannot be serviced without DOI prior approval.
6.8 Contractor Personnel
The Contractor shall be responsible for managing and overseeing the activities of all Contractor personnel, as well as subcontractor efforts used in performance of this effort. The Contractor’s management responsibilities shall include all activities necessary to ensure the accomplishment of timely and effective support, performed in accordance with the requirements contained herein.
6.9 Notice Regarding Late Delivery/Delayed Performance
The contractor will immediately notify the Contracting Officer in writing in the event the contractor encounters difficulty in performance by giving pertinent details, including the date by which it expects to complete performance or make delivery. However, the notification will be informal only in character and will not be construed as a waiver by the Government of any contractual delivery schedule or date, or any rights or remedies provided by law or under this effort.
6.10 Prohibition Against Soliciting and Performing Personal Services
a) The performance of personal services under this TO is strictly prohibited.
b) Personal service contracting is described in Section 37.104 of the Federal Acquisition Regulations (FAR). There are a number of factors, when taken individually or collectively, which may constitute personal services.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .