Attachment_1_NIMS_IDIQ_SOW_FINAL.pdf
PDF 165 KB Posted
- Attached to
- FDA Nonclinical Information Management System (NIMS) Federal contract opportunity
- Solicitation number
- FDA-SOL-13-1116203
About this file
Attachment 1 - NIMS IDIQ SOW
View the file
Other files for this federal contract opportunity
Show all 21
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1
Nonclinical Information Management System (NIMS)
Indefinite Delivery/Indefinite Quantity (IDIQ)
Statement of Work (SOW)
Table of Contents
1. Introduction
1.1 Background
1.2 NIMS Overview
2. Objectives
3. Scope
4. Constraints
4.1 Technical Standards and Guidelines
4.2 Change Control and Configuration Management
4.3 Contractor Compliance
4.4 508 Standard Requirements
4.5 Compatibility with FDA’s Environment
4.6 IT Security
5. Description of Task Areas
5.1 Transition In
5.2 Project Management
5.3 NIMS Operations and Maintenance Support
5.4 Training
5.5 Software Licensing
5.6 Development, Modernization, and Enhancements (DME)
5.7 Data Standardization
5.8 Transition Out
6. Deliverables
7. Personnel Requirements
8. Inspection and Acceptance
1. Introduction
1.1 Background
Acquiring, storing, managing and presenting nonclinical toxicology and animal model data is a fundamental aspect of accomplishing FDA’s mission. FDA recognizes that access to electronic structured scientific data about regulated products improves science-based, regulatory decision making. Furthermore, it is expected that nonclinical data will be increasingly submitted in electronic standard format as the pharmaceutical and related industries adopt electronic formats and standards for data warehousing and transfer.
FDA recognizes that the study size and variety of formats that will need to be supported for nonclinical data require robust, innovative tools and database systems. It is understood that tools that facilitate better access and analysis for nonclinical toxicology and animal model data review will ultimately lead to safer, more effective and higher quality products in the market. In light of this, FDA purchased, customized, and put into production in 2012, the Nonclinical Information Management System (NIMS).
1.2 NIMS Overview
NIMS provides for continued nonclinical study data management, analysis, and visualization functionalities for approximately 180 pharmacology and toxicology reviewers. NIMS is comprised of the following COTS PointCross LifeSciences Inc. components: Nonclinical Study Data Repository (NSDR) or Equal, Study Data Integration and Search System (SDIS) or Equal, ToxVision++ or Equal, and XTEND or Equal. Enhancements have been made to study activities views, export functions to CDER reviewer templates in MS Word as well as integration of exports with GraphPad’s Prism software. These native capabilities and enhancements significantly broaden CDER reviewers’ ability to quickly and easily conduct safety assessments on nonclinical data that are otherwise not available to reviewers. To continue to support the capabilities of NIMS FDA needs operations and maintenance for NIMS, user support, training, application enhancements, and project management services to oversee the integration and implementation of the tool(s), training tools and services to better equip the end users.
2. Objectives As a direct result of contract performance, the FDA expects to achieve the following outcomes:
Demonstrate the capability and utility of publishing out a schema or template that would allow submitters to map their data for submission to FDA and successful loading into NIMS Standardize and load safety pharmacology, reproductive toxicology and “harmful and potentially harmful constituent” studies into NIMS production environment
Support/maintain NIMS by providing Steady State Activities described in SOW including software, interface, and configuration updates.
Create and maintain accurate documentation in accordance with DHHS’s / FDA’s Enterprise Performance Life Cycle (EPLC) for IT systems for O&M releases, O&M and DME change requests, and other Development activities identified in future DME task orders issued against this contract. More information on the EPLC can be found here: http://www.hhs.gov/ocio/eplc/
Participate in EPLC Stage Gate Reviews and document lessons learned.
Develop, provide and deliver new on-site training, clinics, and on –demand training inclusive of on line training modules this is inclusive of associated materials for training and reviewer resources
Update existing on-site training, clinics, and on –demand training inclusive of on line training modules and training materials and resources
Provide technical and customer helpdesk support Develop iterative release schedule for minor and major releases informed by NIMS platform upgrades, identified bugs, or Task Orders for development of NIMS enhancements.
Enhance NIMS functionality through visualization, data model, searching, or intersystem interoperability enhancements Conduct contract management
3. Scope The scope of this contract is as follows:
Operations & Maintenance of NIMS NIMS Training NIMS Help Desk Services Development, Modernization, and Enhancements to NIMS NIMS Documentation
4. Constraints
4.1 Technical Standards and Guidelines
Current standards and guidelines that must be considered in the execution of this contract include:
1. FDA Tailored Enterprise Performance Life Cycle (EPLC). Refer to the attachment “EPLC Overview for Contracts” in Task Order 1 for more information.
2. FDA Approved Technologies List - The FDA Master Approved Technology (MAT) List contains a list of approved and not approved technologies including applications (software), infrastructure and peripherals (hardware), and scientific software and devices.
3. FDA Security Authorization Process - Security Authorization is the approach FDA follows to fulfill Federal Information Security Management Act (FISMA), Office of Management and Budget (OMB) and Department of Health and Human Services (HHS) requirements to ensure that information resources have adequate security to protect the Confidentiality, Integrity and Availability of information collected, processed, transmitted, stored, or disseminated by the agency. For further information see: FDA Security Authorization Toolkit (see attachment entitled Security Authorization Toolkit) SP 800-37 Rev. 1: Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach.
4. National Institute of Standards and Technology (NIST) SP800-53 - This publication was developed by the Joint Task Force Transformation Initiative Interagency Working Group with representatives from the Civil, Defense, and Intelligence Communities in an ongoing effort to produce a unified information security framework for the federal government— including a consistent process for selecting and specifying safeguards and countermeasures (i.e., security controls) for federal information systems. SP 800-53 Rev. 3: Recommended Security Controls for Federal Information Systems and Organizations.
5. Federal Information Security Management Act (FISMA)—The E-Government Act (Public Law 107-347), passed by the 107th Congress and signed into law by the President in December 2002 recognized the importance of information security to the economic and national security interests of the United States. Title III of FISMA requires each federal agency to develop, document, and implement an agency-wide program to provide information security for the information and information systems that support the operations and assets of the agency, including those provided or managed by another agency, contractor, or other source. Federal Information Security Management Act (FISMA).
6. NIST The E-Government Act [Public Law 107-347] passed by the 107th Congress and signed into law by the President in December 2002 recognized the importance of information security to the economic and national security interests of the United States. Title III of the E-Government Act, entitled the Federal Information Security Management Act of 2002 (FISMA), included duties and responsibilities for the Computer Security Division in Section 303 of the National Institute of Standards and Technology document: NIST: Computer Security Division - Computer Security Resource Center.
7. FDA 3250 series of Staff Manual Guide (SMG) policies, as well as HHS security policies. Note:
SMG 3251.4 Outsourcing and Third Party Arrangements - The FDA Staff Manual Guides (SMGs) are the Agency directives that document organizations and functions; delegations of authority; and administrative and program policies, responsibilities and procedures.
8. FDA Security Program: Contractor Oversight Guide - Section 2, Defining Contractor Systems and Related Security Requirements - Information systems subject to Departmental and Federal requirements are predominantly maintained by Department personnel within HHS facilities;
however, there exist a substantial number of contractor-run systems. This section clarifies security requirements for these contractor-based systems as well as defines the related roles of contractors and Departmental personnel.
4.2 Change Control and Configuration Management
The Contractor shall participate in and support Change Control and Configuration Management (CM) for major/minor releases, patches, enhancements activities, and in accordance with FDA standards and processes as defined by EPLC artifacts.
4.3 Contractor Compliance
The Contractor shall be responsible for knowledge and compliance with all applicable federal information technology and information management laws, regulations, policies, and standards at the government-wide, HHS, and FDA levels. At the government-wide level, these include Office of Management and Budget (OMB), National Institute of Standards and Technology (NIST), and General Accountability Office (GAO). These can be primarily found at or through the Federal CIO Council website at http://www.cio.gov/. HHS documents are found at http://www.hhs.gov/oirm/.
4.4 508 Standard Requirements All electronic and information technology (EIT) must meet the applicable accessibility standards at 36 CFR 1194, unless an agency exception to this requirement exists. 36 CFR 1194 implements Section 508 of the Rehabilitation Act of 1973, as amended, and is viewable at http://www.access-board.gov/sec508/standards.htm. Pursuant to the HHSAR clause 352.270- 19, incorporated into this contract, the Section 508 standards applicable to this contract are:
§ 1194.41 Information, documentation, and support § 1194.21 Software applications and operating systems
4.5 Compatibility with FDA’s Environment
The enhancements, version upgrades, and patches must be compatible with FDA’s technical environment, upgrades to technical environment and/ or be capable of being configured to be compatible.
4.6 IT Security
The Contractor shall ensure the system is compliant with Federal and agency security requirements. The contractor shall support all security related activities including the certification and accreditation process. The contractor shall comply with:
FDA Security Authorization process, which closely resembles NIST SP800-37 http://csrc.nist.gov/publications/nistpubs/800-37-rev1/sp800-37-rev1-final.pdf NIST SP800-53 http://csrc.nist.gov/publications/nistpubs/800-53-Rev3/sp800-53-rev3-final_updated-errata_05-01-2010.pdf FISMA http://www.whitehouse.gov/sites/default/files/omb/memoranda/m03-19.pdf HHS Information Security and Privacy Program http://www.hhs.gov/ocio/securityprivacy/index.html http://www.cio.gov/ http://www.hhs.gov/oirm/
5. Description of Task Areas
5.1 Transition In
The Contractor shall facilitate transition in support to ensure a knowledge transfer occurs from the outgoing contractor. Representative activities may include the following:
Conduct and coordinate all on-boarding activities with the Government and obtain secure badging for contractor team personnel.
Engage in regularly scheduled meetings.
Become familiar with documented requirements, policies, and procedures.
5.2 Project Management
For the task orders released under this contract in support of NIMS, the Contractor shall provide task order level project management to establish control, management, monitoring and notification mechanisms, ensuring that contracted tasks stay on track and important milestones and performance measures are met. For each task order, the Contractor shall prepare a Project Management Plan (PMP) describing the technical approach, risks, organizational resources, roles, responsibilities, and management controls to be used to meet the cost, performance, and schedule requirements throughout contract execution.
Contractor Project Manager shall work in conjunction with the FDA Project Managers and other FDA staff and contractor staff. Activities may include project planning, scheduling, project cost management, scope management, change management, issues management, risk management, quality management, problem solving and conflict resolution, inventory reporting, and status reporting.
5.3 NIMS Operations and Maintenance Support
Operations and maintenance activities focus on maintaining the functionality, reliability, availability, performance, stability, sustainability and security of the NIMS application. It is expected that the Contractor shall work directly with available FDA IT personnel and third-party vendors to perform the IT functions necessary to further develop, support and implement NIMS and its underlying components (PopChart, SAS, JAVA, Apache Tomcat) in all environments. The performance of O&M may have dependencies upon FDA and other contract personnel that maintain the FDA data centers where NIMS is housed. It is further expected that the Contractor shall perform the administrative functions for this tool as well.
Representative activities for O&M may include:
Application Maintenance Support Application Problem Resolution Help Desk Support Reporting and Other Documentation System Performance Support
Technical Refresh Migration Release Management Configuration and Change Management
5.4 Training
As tasked, the Contractor shall plan, develop and deliver training support of NIMS. Training programs will be evaluated, tracked, and measured for effectiveness in meeting business goals and objectives.
Representative activities under training may include:
Performance of training assessments, evaluations and analysis Development of training plans Development of training materials Delivery of training Revision of training materials and plans as needed Schedule and organize training sessions
5.5 Software Licensing
The Contractor shall provide software licensing to support NIMS. This can include both server side licenses and user licenses.
5.6 Development, Modernization, and Enhancements (DME)
The Contractor shall provide full development life cycle support to enhance, augment, modernize, or even create new modules within NIMS to meet evolving programs needs and strategic goals. Full development life cycle support includes requirements gathering; analysis and validation; code generation; testing; deployment; and documentation. DME activities may be identified due to new legislative or regulatory mandates, emerging health concerns, and shifting FDA priorities.
Deliverable produces shall be validated and tested to ensure that they meet applicable/specified standards, policy, business requirements, and quality measures.
Representative DME activities may include:
Additional Project Management Activities for DME tasks (if applicable) Future Major Version Releases Ensuring the application is compatible with Technical Refreshes to Software and Hardware environment.
Additional enhancement to increase efficiency and capacity of the NIMS application.
Build interfaces in order to disseminate information to other Government systems or take in information to increase data provided to users Additional Support due to increased number of users and future rollouts
Draft and submit Alternatives analysis for long term resolution to outstanding performance issues due to changes in user needs.
Additional Configuration to increase functionality including, but not limited to, segmentation of NIMS for different user groups or Centers.
Integration of the tool with other Agency data systems Expansion of the tool’s ability to accept, store, visualize, and analyze additional data types Interface to load nonclinical data into, and retrieve from, FDA’s Janus data repository.
Expanding and customizing visualization and analysis capabilities.
5.7 Data Standardization
The Contractor shall perform data standardization and loading efforts related to the software tool.
This comprises the loading of data in paper/PDF formats and non-standardized electronic formats into the data repository and available for visualization, search, and analysis.
Representative Data Standardization tasks include:
Extraction, normalization (nomenclature, units, taxonomy), updating search indexing, curation, and loading of data from PDF and non-standard xpt data sources into the NIMS data repository.
5.8 Transition Out
As tasked, the Contractor shall facilitate the transition of contracted activities and services to the Federal Government or to a follow-on contractor at the end of the contract period of performance.
Representative activities under this task area may include:
Providing the FDA with current versions of all system and user documentation;
Providing FDA all licensing and renewal information, asset management records, software documentation, and training materials;
Providing FDA with a current inventory of all Government-owned assets used by the Contractor along with full support in the reconciliation of this inventory;
Providing FDA with current versions of all CONOPS, operational procedures, standard operating procedures, guidelines, performance reports, specifications for hardware and software, and other pertinent information needed to continue the services being performed by the Contractor;
Providing “shadowing” and other knowledge transfer meetings and opportunities to facilitate the transfer of information, processes, and data needed to continue the services being performed by the Contractor;
Providing full documentation of custom code, reports, process automations, scripts and configurations (not COTS source code) with applicable configuration management information;
and, Providing up-to-date-EPLC and program/project management documents.
6. Deliverables Deliverables shall be specified in the Task Orders released under this contract. Deliverable products shall be reviewed, validated and tested as appropriate to ensure that they meet applicable/specified standards, policy, business requirements and quality measures.
7. Personnel Requirements The Contractor shall ensure that all Contractor support personnel are adequately trained, possess the credentials specified in the appropriate labor categories, and are otherwise fully qualified to provide the high level of support required by this SOW prior to being assigned to Task orders awarded. Key personnel will be identified in Task Orders. All Contractor assigned to this contract must provide verification of completion of all mandatory FDA training, including Annual Security Awareness Training.
8. Inspection and Acceptance Requirements for inspection and acceptance are as follows:
The COR, or the POC designated in an IDIQ task order, will inspect and accept the services provided to ensure they meet the requirements detailed in the applicable IDIQ task order.
Inspection and acceptance will occur at the location designated by the COR and take place within ten (10) days of task being completed.
Inspection will include testing of the deliverables to ensure that they perform adequately and in accordance with the applicable task order.
The Government will accept goods, reports and services only if they conform to all terms and conditions of the IDIQ and Task Order SOW.
The Government will provide written notification of acceptance or rejection within ten (10) business days of receiving the service.
The Government will reject non-conforming products and services. The Contractor shall correct any deficiencies within ten (10) business days of when the Government issues the rejection notice. If the Contractor cannot correct the deficiencies within this time frame, the Contractor shall immediately notify the COR of the reason for the delay and provide a proposed corrective action plan within five (5) business days.
9. Appendices Appendix A – EPLC Overview Appendix B – NIMS Software Salient Characteristics
*****This page is intentionally left blank*****
| 1. Introduction |
| 1.1 Background |
| 1.2 NIMS Overview |
| 2. Objectives |
| 3. Scope |
| 4. Constraints |
| 4.1 Technical Standards and Guidelines |
| 4.2 Change Control and Configuration Management |
| 4.3 Contractor Compliance |
| 4.4 508 Standard Requirements |
| 4.5 Compatibility with FDA’s Environment |
| 4.6 IT Security |
| 5. Description of Task Areas |
| 5.1 Transition In |
| 5.2 Project Management |
| 5.3 NIMS Operations and Maintenance Support |
| 5.4 Training |
| 5.5 Software Licensing |
| 5.6 Development, Modernization, and Enhancements (DME) |
| 5.7 Data Standardization |
| 5.8 Transition Out |
| 6. Deliverables |
| 7. Personnel Requirements |
| 8. Inspection and Acceptance |
| 9. Appendices |
File details come from the government source that posted it. Updated .