FileOnQ Draft Statement of Work.docx

DOCX document 104 KB Posted

Attached to
FileOnQ Software Licenses and Maintenance Federal contract opportunity
Solicitation number
70CTD020Q00000050
Issued by
Immigration and Customs Enforcement

About this file

This statement of work outlines technical support requirements for FileOnQ software licenses, maintenance, and enhancements. The Department of Homeland Security's Immigration and Customs Enforcement agency requires annual FileOnQ platform fees, maintenance for deployed applications, and technical support services including installation, operations, database administration, security, and issue resolution. The contractor must provide support from 8am to 5pm eastern time Monday through Friday, with some weekend or evening work as needed. Deliverables include monthly status reports, and the government will provide laptops and VPN access for contractor personnel, who must meet security screening requirements. The related pre-solicitation notice indicates DHS ICE's intent to solicit a sole-source, 12-month base contract plus four option years for FileOnQ software licenses, maintenance, and support for the currently deployed FileOnQ system.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION C - STATEMENT OF WORK

1. Overview

1.2 Background

The Department of Homeland Security (OHS) was created by enactment of H.R. 5005, the Homeland Security Act of 2002. The Department's primary mission is the protection of the American people and includes preventing terrorist attacks within the United States, reducing the vulnerability of the United States to terrorism, and minimizing the damage and assisting in the recovery from terrorist attacks that do occur with the United States.

The Immigration and Customs Enforcement (ICE), the largest investigative arm in OHS, is responsible for identifying and shutting down vulnerabilities in the nation's border, economic, transportation, and infrastructure security.

The Office of the Chief Financial Officer (OCFO) is responsible for all financial and fiscal management aspects of ICE. OCFO provides direction and coordination in the administrative, business planning, accounting, and budgeting efforts of the agency. The subordinate, Office of Financial Management (OFM), serves as the owner of the FileOnQ (FOQ) and provides functional leadership.

1.3 Office of Financial Management (OFM)

The Office of Financial Management (OFM) provides financial services oversight and accountability through quality financial stewardship, valuable customer service, and alignment with the Department of Homeland Security (OHS).

1.4 FileOnQ (FOQ)

FileOnQ is a Records Management software application which the Office of Financial Management uses for payment processing and other financial services to its OHS customer components.

2. Task Order

2.1 Period of Performance

The base period of performance for this Task Order is March 29, 2020 through March 28, 2021.

A one-year option period was added with a POP of March 29, 2021 through March 28, 2022.

A second-year option period was added with a POP of March 29, 2022 through March 28, 2023.

A third-year option period was added with a POP of March 29, 2023 through March 28, 2024.

A fourth-year option period was added with a POP of March 29, 2024 through March 28, 2025.

2.2 Hours of Operation

The Contractors' Technical Support staff should be available, by request, on a regular basis Monday - Friday, 8 a.m. to 5 p.m. Eastern. In addition, planned weekend/ evening support for projects, such as adding a new database, is sometimes required. Altogether, the government expects approximately 20 hours per week of technical support, but will vary depending on issues and activities.

2.3 Overtime

Neither the Contractor nor any teaming partners will be authorized to invoice for overtime.

2.4 Other Direct Costs (CLIN 0004 / 1004 / 2004 / 3004 / 4004)

Section C

The Contractor is not authorized to incur any ODCs without the prior written approval of the Program Manager or COR on an ICE Request for ODC Authorization form. The government does not foresee substantial or recurring ODC expenditures for travel, training, or equipment against this Task Order. There are two types of ODCs applicable under this task order: Materials and Travel.

2.5 Materials

Materials are those incidental items that are not included, but are chargeable under the Task Order. However, materials shall not include items such as office supplies, training, and other materials needed by the Contractor to provide personnel under this Task Order.

2.6 Travel

The Contractor must obtain advance written approval from the COR for all travel performed about this Task Order. Any travel expenses incurred, without prior written approval from the OCIO FOQ Program Manager and the COR, will not be reimbursed by the government. Travel expenses will be reimbursed based on the Federal Travel Regulations and the per diem rates established by the General Service Administration (meals and incidental expenses) in effect at the travel location, with lodging reimbursed at actual costs. Local travel under this Task Order is not authorized. Any travel time incurred by the Contractor shall not be subject to reimbursement.

2.7 Task Order Objectives

The primary objective of this task order is to procure FOQ licensing and maintenance, technical support, and optionally, enhancement work. The task order includes, but is not limited to, the activities listed in detail in section 3, Scope of Work.

3. Scope of Work

The Contractor shall provide the following products and services to support continuous and efficient operation of FileOnQ for ICE and the OHS components.

3.1 Enterprise Licensing and Software Maintenance (CLIN 0001 / 1001 / 2001 / 3001 / 4001)

· Annual Base Enterprise Platform Fee

· Maintenance and Support for each application deployed

· Software maintenance includes in-version product upgrades and telephone and email support for troubleshooting software issues.

3.2 Technical Support (CLIN 0002 / 1002 / 2002 / 3002 / 4002)

The contractor shall provide technical support for all 11 currently installed FileOnQ Production applications, 11 applications installed for Disaster Recovery, 12 applications installed on the Test server (including training), and any additional that may be installed over the course of the contract. Activities include, but are not limited to, the following tasks:

The function requires technical support for all 12 currently installed FileOnQ applications and any additional that may be installed over the course of the contract. Activities include, but are not limited to, the following tasks:

Installation: Application and Database Installation on Test, Disaster Recovery, and/or Production instances in compliance with OHS security rules.

Operational Maintenance; IIS management, ASP.NET patches and upgrades, SSL Certificate, SQL Server IIS patches, maintenance, crystal report patches/updates, Database administration: Monitoring size, performance, and ensuring backups are complete.

New release support: Planning and scheduling ICE with ICE personnel, preparing or assisting with SDLC documentation in OHS formats (to be provided), Executing scripts for new releases on test and production system, ensure security measures are tested and confirmed.

System Maintenance: Perform administration procedures on Production, Test and Disaster Recovery Systems (i.e. monitor performance, disk space, backups, etc.)

System Security: Participate in system security discussions, evaluate results of system security scans, provide strategies to mitigate findings, and implement system modifications as required to address system security issues on all production, test, and disaster recovery servers.

The FileOnQ application hosting has been newly migrated to a OHS Data Center. Because OFM does not have historical data to accurately predict what the support requirements will be, OFM will reserve an Optional CLIN for additional, but related, scope. The purpose will be to support FileOnQ in the Data Center, if necessary.

The COR or designated Task Manager will direct a support call or email through the FileOnQ support process (Email: dhs.support@ fileonq.com, Phone: 1-800-603-6802, menu option 4).

The Contracting staff will be responsible for acknowledging the issue with an email response to the requester, analyzing the cause of the issue, determining an interim, and/or recommending action to correct the issue permanently within the parameters as defined below:

Severity of Issue
Definition
Acknowledgement Due
Interim Solution Due
Resolution (or SCR, if

appropriate) Due

1 - Critical
The request must be acted upon

immediately. This

2 hours
Immediately
3 business days

severity is intended to address critical business functionality that is having a negative business impact on multiple users' ability to perform essential functions payment functions. The impact is clear and requires no further approval to proceed.

2-High
The request must be

acted on as soon as possible. Any delay in

1 business day
2 business days
3 business days

implementing a solution could result in additional system issues and impact business functions. Impacts 2 or more users.

3-Medium
The request must be

acted on in the near term. Issue has

2 business days
5 business days
1 week

limited impact on an individual user.

4-Low
The request is more of a "nice-to-have" or cosmetic feature or enhancement. This has minimal business impact.
1 week
Between one week and one month.
1 month

3.3 Software Enhancements - (CUN 0003 / 1003 / 2003 / 3003 / 4003)

The government may request additional Professional Services as the need may arise on a Labor Hour (LH) basis. This may include a request for custom reports, creating new profiles, interfaces to other software applications, custom routines/applets that are outside of the FileOnQ software code, workflow notification consulting, set up for additional/new applications/databases.

Complexity of the request and the level of effort required to complete the tasks will be discussed with and approved by the COR prior to the work being performed.

3.4 Schedule and Location of Work

Technical Support must be available Monday through Friday, between the hours of 8:00 a.m. and 5:00 p.m. Eastern, excluding Federal Holidays. Also, on occasion, contractors may be asked to perform scheduled additional activities after-hours.

The work may be performed remotely.

3.5 Roles and Responsibilities for Task Order Management

3.5.1 ICE Contracting Officer

Only the Contracting Officer can initiate changes to the terms and conditions or scope of this task order.

3.5.2 Contracting Officer's Representative (COR)

The COR is responsible for the task order administration to ensure that activities are accomplished within the general scope of the task order and that adequate funding is available for authorized work. The COR monitors cost and schedule performance, resolves task order level management and programmatic issues, approves direct cost expenditures (when authorized by the PM), accepts deliverables, reviews and approves invoices, enforces task order terms and conditions, recommends task order change requests, and performs other duties as specified by the Contracting Officer.

The COR may assign an additional Task Manager(s) as needed to issue support requests and provide oversight of contractor activities as they relate to the Statement of Work.

4. Deliverables

4.1 Monthly Status Report

The Contractor shall prepare a Monthly Status Report for the FOQ project describing the work that was requested and the work performed. The report shall be delivered to the COR with the invoice.

The status report should be limited to the requests that fall under the Time and Materials portion of the contract.

5. Contractor Personnel

The Contractor will provide staff fully trained in FileOnQ technologies, each having at least 5 years of experience with IT/Development responsibilities. The Contractor will require passing a security background, completing security training, and may not begin any work on the Task Order until they have received approval from the COR.

6. Government and Contractor Furnished Property

The government will provide the contractors with three government issued laptops and VPN tokens to access the network. The contractor is responsible for accessing an Internet connection from where the VPN can access.

7. Accessibility Requirements

Note: The FileOnQ product currently in use at OHS has been reviewed by OHS for 508 compliances. FileOnQ has a plan in place with OHS Compliance Review to meet Section 5408 requirements.

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-

220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology, they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.

All EIT deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable standards have been identified:

36 CFR 1194.21 - Software Applications and Operating Systems, applies to all Electronic Information Technology (EIT) software applications and operating systems procured or developed under this work statement including but not limited to Government off-the-shelf (GOTS) and Commercial off-the-shelf (COTS) software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.

36 CFR 1194.22 - Web-based Intranet and Internet Information and Applications, applies to all Web based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then "1194.21 Software" standards also apply to fulfill functional performance criteria.

36 CFR 1194.23 - Telecommunications Products, applies to all telecommunications products including end-user interfaces such as telephones and non end-user interfaces such as switches, circuits, etc. that are procured, developed or used by the Federal Government.

36 CFR 1194.24 - Video and Multimedia Products, applies to all video and multimedia products that are procured or developed under this work statement. Any video or multimedia presentation shall also comply with the software standards (1194.21) when the presentation is through the use of a Web or Software application interface having user controls available. This standard applies to any training videos provided under this work statement.

36 CFR 1194.31 - Functional Performance Criteria applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.

36 CFR 1194.41 - Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required "1194.31 Functional Performance Criteria", they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, for example a help desk shall have the ability to transmit and receive messages using TTY.

Exceptions for this work statement have been determined by OHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COR and determination will be made in accordance with OHS MD 4010.2. OHS has identified the following exceptions that may apply:

36 CFR 1194.2(b) - (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product is not commercially available because no product in the marketplace meets all the standards. If products are commercially available and meet some but not all of the standards, the agency must procure the product that best meets the standards.

When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirement than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires approval from the OHS Office on Accessible Systems and Technology (OAST) in accordance with OHS MD 4010.2.

36 CFR 1194.3(b) - Incidental to Contract, all EIT that is exclusively owned and used by the Contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those Contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.

8. Security Requirements

The Department of Homeland Security (OHS) has determined that performance of the tasks as described in this contract require that the Contractor, subcontractor(s), vendor(s), etc. (herein known as Contractor) have access to sensitive DHS information, and that the Contractor shall adhere to the following.

8.1 Suitability Determination

OHS will have and exercise full control over granting, denying, withholding or terminating unescorted Government facility and/or sensitive Government information access for Contractor employees, based upon the results of a background investigation. OHS may, as it deems appropriate, authorize and make a favorable entry on duty (EOD) decision based on preliminary security checks. The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation. The granting of a favorable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow as a result thereof. The granting of a favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar the withdrawal or termination of any such access by OHS, at any time during the term of the contract. No employee of the Contractor shall be allowed to EOD and/or access sensitive information or systems without a favorable EOD decision or suitability determination by the Office of Professional Responsibility, Personnel Security Unit (OPR-PSU). No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable EOD decision or suitability determination by the OPR-PSU. Contract employees assigned to the contract not needing access to sensitive OHS information or recurring access to OHS ' facilities will not be subject to security suitability screening.

8.2 Background Investigations

Contract employees (to include applicants, temporaries, part-time and replacement employees) under the contract, needing access to sensitive information, shall undergo a position sensitivity analysis based on the duties everyone will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. Background investigations will be processed through the Personnel Security Unit. Prospective Contractor employees with adequate security clearances issued by the Defense Industrial Security Clearance Office (DISCO) may not be required to submit complete security packages, as the clearance issued by DISCO may be accepted.

Prospective Contractor employees without adequate security clearances issued by DISCO shall submit the following completed forms to the Personnel Security Unit through the COR, no less than 5 days before the starting date of the contract or 5 days prior to the expected entry on duty of any employees, whether a replacement, addition, subcontractor employee, or vendor:

1. Standard Form 85P, "Questionnaire for Public Trust Positions" Form will be submitted via e-QIP (electronic Questionnaires for Investigation Processing) (2 copies)

2. FD Form 258, "Fingerprint Card" (2 copies)

3. Foreign National Relatives or Associates Statement

4. OHS 11000-9, "Disclosure and Authorization Pertaining to Consumer Reports Pursuant to the Fair Credit Reporting Act"

5. Optional Form 306 Declaration for Federal Employment (applies to Contractors as well)

6. Authorization for Release of Medical Information

Required forms will be provided by OHS at the time of award of the contract. Only complete packages will be accepted by the OPR-PSU. Specific instructions on submission of packages will be provided upon award of the contract.

Be advised that unless an applicant requiring access to sensitive information has resided in the US for three of the past five years, the Government may not be able to complete a satisfactory background investigation. In such cases, OHS retains the right to deem an applicant as ineligible due to insufficient background information.

The use of Non-U.S. citizens, including Lawful Permanent Residents (LPRs), is not permitted in the performance of this contract for any position that involves access to, development of, or maintenance to any OHS IT system.

8.3 Continued Eligibility

If a prospective employee is found to be ineligible for access to Government facilities or information, the COR will advise the Contractor that the employee shall not continue to work or to be assigned to work under the contract.

The OPR-PSU may require drug screening for probable cause at any time and/ or when the Contractor independently identifies, circumstances where probable cause exists.

The OPR-PSU may require reinvestigations when derogatory information is received and/or every 5 years.

OHS reserves the right and prerogative to deny and/ or restrict the facility and information access of any Contractor employee whose actions conflict with the standards of conduct, 5 CFR 2635 and 5 CFR 3801, or who DHS determines to present a risk of compromising sensitive Government information to which he or she would have access under this contract.

The Contractor shall report any adverse information coming to their attention concerning contract employees under the contract to the OPR-PSU through the COR Reports based on rumor or innuendo should not be made. The subsequent termination of employment of an employee does not obviate the requirement to submit this report. The report shall include the employees' name and social security number, along with the adverse information being reported.

The OPR-PSU must be notified of all terminations/ resignations within five days of occurrence. The Contractor shall return any expired OHS issued identification cards and building passes, or those of terminated employees to the COR If an identification card or building pass is not available to be returned, a report must be submitted to the COR, referencing the pass or card number, name of individual to whom issued, the last known location and disposition of the pass or card. The COR will return the identification cards and building passes to the responsible ID Unit.

8.4 Employment Eligibility

The Contractor shall agree that each employee working on this contract will have a Social Security Card issued and approved by the Social Security Administration. The Contractor shall be responsible to the Government for acts and omissions of his own employees and for any Subcontractor(s) and their employees.

Subject to existing law, regulations and/ or other provisions of this contract, illegal or undocumented aliens will not be employed by the Contractor, or with this contract. The Contractor shall ensure that this provision is expressly incorporated into all Subcontracts or subordinate agreements issued in support of this contract.

8.5 Security Management

The Contractor shall appoint Point of Contact to act as the Corporate Security Officer. The individual will interface with the OPR-PSU through the COR on all security matters, to include physical, personnel, and protection of all Government information and data accessed by the Contractor.

The COR and the OPR-PSU will have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this contract. Should the COR determine that the Contractor is not complying with the security requirements of this contract; the Contractor shall be informed in writing by the Contracting Officer of the proper action to be taken to effect compliance with such requirements.

The following computer security requirements apply to both Department of Homeland Security (OHS) operations and to the former Immigration and Naturalization Service operations (FINS). These entities are hereafter referred to as the Department.

8.6 Information Technology Security Clearance

When sensitive Government information is processed on Department tele-communications and automated information systems, the Contractor agrees to provide for the administrative control of sensitive data being processed and to adhere to the procedures governing such data as outlined in OHS IT Security Program Publication OHS MD 4300.Pub. or its replacement. Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level.

Contractors who fail to comply with Department security policy are subject to having their access to Department IT systems and facilities terminated, if the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).

8.7 Information Technology Security Training and Oversight

All Contractor employees using Department automated systems or processing Department sensitive data shall be required to receive Security Awareness Training. This training will be provided by the appropriate component agency of OHS.

Contractors, who are involved with management, use, or operation of any IT systems that handle sensitive information within or under the supervision of the Department, shall receive periodic training at least annually in security awareness and accepted security practices and systems rules of behavior.

Department Contractors, with significant security responsibilities, shall receive specialized training specific to their security responsibilities annually. The level of training shall be commensurate with the individual's duties and responsibilities and is intended to promote a consistent understanding of the principles and concepts of telecommunications and IT systems security.

All personnel who access Department information systems shall be continually evaluated while performing these duties. Supervisors should be aware of any unusual or inappropriate behavior by personnel accessing systems. Any unauthorized access, sharing of passwords, or other questionable security procedures should be reported to the local Security Office or Information System Security Officer (ISSO).

File details come from the government source that posted it. Updated .