FOIA Support PWS 05172021.docx

DOCX document 111 KB Posted

Attached to
FOIA Support Federal contract opportunity
Solicitation number
12FPC221Q0023
Issued by
Department of Agriculture Under Secretary for Farm Production and Conservation

About this file

This performance work statement describes requirements for mainframe interrogation and electronic data development support services to assist the Farm Service Agency's Freedom of Information Act/Privacy Act program. The contractor will be required to identify any needed clarification of FOIA/PA requests within one day, respond to statements of work within three days, perform technical clarifications, prepare responsive records and tasks, archive requests, participate in process improvements and problem resolution, provide training, and create extract files on a quarterly and annual basis. The contract period of performance is from June 2021 through June 2025 with option years extending to June 2026. The contractor must furnish key personnel and programmers with relevant technical expertise and security clearances. Work will be performed at the USDA facility in Kansas City, Missouri under the direction of a contracting officer's representative.

View the file

Other files for this federal contract opportunity

Other files attached to FOIA Support, newest first.
File Type Posted
FOIA Support Quality Assurance Surveillance Plan (QASP).docx DOCX document
FOIA Support Combined Synopsis-Solicitation.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS)

MAINFRAME INTERROGATION AND ELECTRONIC DATA DEVELOPMENT SUPPORT FOR THE FARM SERVICES AGENCY'S FREEDOM OF INFORMATION ACT/PRIVACY ACT (FOIA/PA) April 29, 2021

1.1 Introduction

The Freedom of Information Act (FOIA) is the statute (5 U.S.C. § 552) outlining that any person has a right, enforceable in court, to obtain access to Federal agency records, except to the extent that such records, or portions of those records, are protected from public disclosure by one of nine FOIA exemptions or by one of three special law enforcement record exclusions.

The Privacy Act of 1974 (PA) is the statute (5 U.S.C. § 552a) that establishes a code of fair information practices that governs the collection, maintenance, use, and dissemination of personally identifiable information about individuals that is maintained in systems of records by Federal agencies.

The objective of this effort is to assist the Farm Service Agency (FSA) in providing FOIA/PA requestors with releasable information that is in the possession of FSA organizations in Kansas City, Missouri. Information is assembled upon request to respond to Congressional, Federal, management, business, and private individual FOIA/PA requests.

1.2 Background

The FPAC-BC/EAD FOIA/PA employees do not have the capacity to interrogate the FSA mainframes and systems. Historically, since the FPAC-BC/EAD FOIA/PA employees do not have the ability to perform the work, a FOIA/PA Contract Staff has been used to perform the Information Technology based work required to compile the electronic data needed to respond to FOIA and PA requests for data contained in the FSA mainframes and systems.

1.3 Scope of Work

A Contracting Officer's Representative (COR) oversees the Contractor's performance and oversees the FOIA/PA program. Under the direction of the COR, Contractors shall be required to prepare records that are responsive to FOIA/PA requests.

Responsive record preparation involves the Contractor accessing information contained within FSA central databases (mainframes), systems and prepared flat files. Using a variety of mainframe software packages (i.e., JCL, COBOL, SYNCSORT, ISPF, SPUFFI, SQL, TSO,, and File Aid), database connection tools (i.e., IMB Informix Connect, Microsoft SQL Server,, Hyperion, ODBC, and Internet Explorer), and other software (i.e., FTP, Acrobat, WNBrowse, Textpad), the Contractor shall develop responsive records by compiling information obtained from a variety of database/non-database sources.

Contractors shall perform the work at the Beacon facility at 6501 Beacon Drive, Kansas City, Missouri. Normal duty hours at the FSA facility are Monday through Friday (excluding Federal holidays) from 6:00 A.M. to 6:00 P.M. Central Standard Time. The normal individual tour of duty shall be 40 hours per week. When mission requirements dictate, Contractor support could be required outside normal duty hours (nights, weekends, and/or Federal holidays). Outside normal duty hour support shall be coordinated with the Contractor as far in advance as is possible.

1.4 Requirements

The contractor shall:

1. Identify Non-Technical Clarification

1.1 The COR shall provide the initial FOIA/PA request to the designated Sr. IT Specialist who will be responsible for dissemination of work to contracting personnel and also to transfer completed tasks to the COR. Within 1 working day of receipt of the initial FOIA/PA request, the Contractor shall review the request and identify to the COR any non-technical clarification that needs to be done to place the Contractor in a position to process the request. Note: This step may not be necessary for all FOIA/PA requests.

Non-technical clarification is the performance of any request clarification action that can be conducted without the need to rely upon the technical expertise of the Contractor. Non-technical clarification involves activities such as working to determine the actual data being requested, making releasable/not releasable notifications, and responding to fees/date of responsive record delivery concerns. The non-technical request clarification shall be performed by the COR.

2. Respond to Statement of Work Required

2.1 The COR shall provide the initial FOIA/PA request to the designated Sr. IT Specialist who shall provide the Statement of Work Required (instructions identifying the core responsive record search parameters needed to meet the FOIA/PA request) to the Contracting personnel. Within 3 working days of receipt of the Statement of Work Required, the Contractor shall review the Statement of Work Required and provide to the COR the 1) number of requests in the appropriate production queue, 2) estimated Contractor effort minutes required to process the request, 3) estimated CPU (mainframe) cost, and 4) estimated responsive record delivery date.

3. Perform Technical Clarification

3.1 The Project Manager shall provide the Request Perfection Notice to the Contractor. The Request Perfection Notice indicates that the Contractor can now place the request into the proper processing queue. Upon receipt of the Request Perfection Notice, the Contractor is cleared to conduct technical clarification (as required). The Contractor shall be responsible to perform all technical clarification directly with the FOIA/PA requestor.

Technical clarification is accomplished to enable the Contractor to develop a detailed understanding of the FOIA/PA requestor's technical needs. Technical clarification involves activities such as coordinating the required electronic deliverable format and responding to Information Technology concerns. Within 1 working day, the Contractor shall inform (via copy of e-mails, personal discussion, etc.) the Contracting Officer's Representative of all communication with the requestor.

4. Prepare Responsive Record

4.1 The Contractor shall prepare the responsive record. The responsive record shall be developed according to the Statement of Work Required. Responsive record preparation involves detailed research of FOIA/PA requests, information analysis and data compilation, preparation of request documentation, and occasional recommendation and/or development of data retrieval software. The Contractor shall prepare the responsive record based on the order the request was received, or according to the instructions received from the program manager.

5. Prepare Tasks

5.1 The Contractor shall prepare the Task. The task shall consist of all information developed in response to the FOIA/PA request. The completed Task shall include items such as the responsive records, ReadMe document, Deliverable document, Central Processing Unit (CPU) utilization log, System Development Life Cycle (SLC) Information, Flow Chart (detailing the relationship between input files and specific fields), Source Code, Work Flow tracking document, Express Mail authorization document, and records (e.g., e-mail, memo for record of telephone calls) of all technical clarification performed by the Contractor. The Contractor shall save all correspondence (e-mail, memo for record of telephone calls, hardcopy material scanned toe-format, etc.) relating to each request.

Additionally, the correspondence shall be included on the completed Task provided to the FOIA/PA Specialist at the completion of the request. The Task completion requirement for a FOIA/PA request is twenty working days. The 20-working day requirement begins upon the date the FOIA/PA request is perfected. Note: A perfected request is a FOIA/PA request for records which 1) adequately describes the records sought, 2) which has been received by the FOWPA office of the agency component in possession of the records, and

3) for which there is no remaining question about the payment of applicable fees.

6. Prepare Request Archive

6.1 The Contractor shall archive electronically and place on external hard drive.

7. Participate in Process Improvement

7.1 The Contractor shall participate in process improvement efforts and shall make suggestions to implement cost reduction methodologies and improve operational efficiencies.

8. Participate in Problem Resolution

8.1 The Contractor shall participate in problem resolution efforts. Problem resolution includes participating with Government personnel and other Contractor personnel in problem identification, reporting, definition, research, tracking, and the development of recommended solutions.

9. Provide Training

9.1 Upon request, the Contractor shall provide training required to familiarize Government personnel with the activities being performed by the Contractor.

10. Additional Tasks

10.1 For large efforts, tasks may be divided by subtask. The following table provides a complete listing of the required tasks. The table includes, Task No. and Name, End Result/Deliverable, Tool for creating it, Acceptance Criteria, and Intended Use, as applicable.

In addition to the Tasks listed above (1-9), the other Tasks required are large efforts required by the Contractors to create extract files on a quarterly and annual basis. For #12 listed below, the miscellaneous extract files are FOIA/PA request dependent. All extract files are used by the Contract staff to fill FOIA/PA requests. Creating these extracts files are necessary to prevent the contractors from doing daily runs against production files to extract data. The daily runs have proven to slow down production.

Task
End Result/Tasks
Schedule/Milestone
10
Create Name, Address, Payment extract files
Daily
11
Create Colossal Raw Asset Package (CRP) extract files
Quarterly
12
Create Misc extract files upon request
Upon request

1.5 Period of Performance

This section identifies the period of performance for the funding to be obligated under this action. If this action is for incremental funding, then the projected total period of performance to project completion, should also be included.

Base Year - 6/11/2021 – 6/10/2022 Option Year 1- 6/11/2022 – 6/10/2023 Option Year 2- 6/11/2023 – 6/10/2024 Option Year 3- 6/11/2024 – 6/10/2025

1.6 Schedules/Milestones

The contractor shall maintain a single project schedule. The following reports shall be provided:

· A Monthly Task Report that describes the Delivery and Status of FOIA Requests.

· A Monthly request status spreadsheet that shows all requests and the status of each request.

1.7 Who Does What When Report - What do you need from me?

The "Who does what when" report shall be provided by the contractor with the initial submission, and again following negotiations. This report will be used by the Government to assess the adequacy of the resources proposed by the contractor to accomplish the SOW.

1.8 Progress/Compliance

The Government requires the following from contractors in order to monitor progress and ensure compliance:

· A Monthly Task Report that describes the Delivery and Status of FOIA Requests.

· A Monthly request status spreadsheet that shows all requests and the status of each request.

1.9 Deliverables

For each FOIA request delivered, the Contractor shall electronically archive the Deliverable and place on external hard drive.

1.10 Key Personnel

The contractor shall be required to furnish personnel with qualifications meeting or exceeding the criteria specified in the Contract document governing the issuance of this Contract. The contractor must specify in their response to this Contract the number(s) and categories of personnel required to perform the work. The "Substitution of Key Personnel" of the contract, is applicable to this contract.

Contractor employees designated as Key Personnel under this Contract are listed as follows: 1 - Project Lead (Primary).

1. Key Personnel

1.1 The Contractor shall furnish key personnel that have demonstrated the ability to lead employees and manage programs towards the successful accomplishment of assigned responsibilities. Key personnel shall also have one year expertise the following software applications:, JCL, COBOL, SYNCSORT, ISPF, SPUFFI, SQL, TSO,, File Aid, IMB Info1mix Connect, Microsoft SQL Server, Hyperion,, ODBC, Internet Explorer, FTP, Acrobat, WNBrowse, Textpad, and . The Contractor shall furnish key personnel that have demonstrated successful communication skills.

2. Personnel The Contractor shall furnish the following personnel: 4 Programmers, with the option to use 2 - Part-Time Programmers to replace 1 Full-Time Programmer and have the expertise (or the demonstrated ability to gain expertise) in the following software applications:, JCL, COBOL, SYNCSORT, ISPF, SPUFFI, SQL, TSO,, File Aid, IMB Informix Connect, Microsoft SQL Server, Hyperion,, ODBC, Internet Explorer, FTP, Acrobat, WNBrowse, Textpad, and . The Contractor shall furnish personnel that have demonstrated successful communication skills. The Contractor shall be required to be available for any Administrative documentation when needed by the COR such as: (e.g... Saving documents to FPAC-BC/EAD FOIA Request folders, logging requests on FSA-534, sending acknowledgments to requestors, etc.)

3. Substitution of Task Key Personnel The contractor shall notify the Contracting Officer (CO) prior to making any changes in key personnel. No changes in key personnel shall be made unless the contractor can demonstrate qualifications of prospective personnel are equal to or better than the qualifications of the personnel being replaced. All requests for approval of substitutions in key personnel must be in writing and provide a detailed explanation of the circumstances proposed substitute and other information requested by the CO to approve or disapprove the proposed substitution. The CO will evaluate such requests and promptly notify the Contractor of his/her approval or disapproval by way of a modification to the contract. All disapprovals will require re-submission of another substitution within 15 calendar days.

1.11 Travel

No travel is anticipated

1.12 Telework

Telework may be authorized, depending on availability of government computing resources and on the nature of the work tasks involved. All contractor personnel approved for telework shall comply with the specific Guidelines for Telework.

Guidelines for Telework:

All work performed at locations other than those identified as FSA government facilities in Kansas City, MO., shall be authorized prior to performing the work. Contractors are not governed by Office of Personnel Management (OPM), GSA, or the individual agency government employee telework policies; however, this does not prohibit contractor employees from actually working at an alternate site, when/as appropriate and specifically authorized by the Government. Contractors may telework during non-standard business hours and during certain uses of standard business hours with Government approval.

Approval for telework for individual contractor staff members is at the discretion of the authorized contractor management representative, with agreement by the COR.

A regular schedule of telework shall be established, approved by the COR, published, and the telework schedule must not negatively impact the Government. Changes to the schedule must be pre-approved by the COR. Each technology supply or service delivery area must have on-site coverage every business day. For example, if one member of a two-member team is on leave, the remaining team member must be on-site during that time, regardless of whether telework is scheduled or not. Teleworking contractor staff must be able to return to the FSA government facility at no cost to the government, within 5 hours of receiving the request.

· Telework is permitted for certain uses of standard business hours. Reasons include:

· Following standard Telework schedule as approved by the COR with the concurrence of the authorized contractor management representative

· Extenuating personal circumstances as approved by the COR

· Due to Beacon weather line status or other dire Beacon building circumstances (e.g. "the Beacon Facility will be open with the option for unscheduled leave or unscheduled telework")

· Telework is permitted for certain uses of non-standard business hours. Reasons include:

· Work planned to be performed outside of standard business hours (e.g. database maintenance)

· Unplanned contingency technical support

· Is required by the government

· Professionalism

· Contractors shall manage any necessary telework in a way that allows them to successfully meet job responsibilities to provide the government quality products and services.

· Contractors shall forward the office phone to either home or cell phone on the regularly scheduled telework days so that teleworking will not cause a missed conversation.

· Contractors who telework on a regular schedule shall indicate Telework on the Outlook shared calendar. To do this, create a new "All Day Event", give it a meaningful title, like "Telework Day", make sure the "Show As" indicator or dropdown indicates "Free" (the indicator color will be white or clear) and make it a reoccurring event for the day of the week of the scheduled telework.

· Business meetings are usually more effective face-to-face.

Contractors shall avoid calling in to meetings when an onsite presence is required or better suits the needs of the government.

· Contractors shall NOT use duty time for providing dependent care or any purpose other than official duties. Telework is NOT a substitute for day care. Teleworkers shall NOT have a dependent needing attention and care at the telework site during working hours, unless a care-provider is present at the telework site. Children over 12, who can take care of themselves, may be at the telework site during duty hours.

· Conducting personal business or providing services for other than official duties under this Task Order are NOT permitted during either telework or on- site duty hours.

· Two separate emails shall be sent each telework day by teleworkers.

One email states the work Start Time and another email states the work End Time. These emails must be sent to the authorized contractor management representative, copying the government COR and Technical Point of Contact (TPOC). The format of this email follows:

1. To: authorized contractor management representative

2. CC: COR and TPOCs

3. SUBJECT: 'Telework Start Time - x:xx am/pm' or ' Telework End Time - x:xx am/ pm

1.13 Government Furnished Property

Government furnished property (GFP) will be provided under this contract. The contractor will be provided office workspace, office automation equipment with appropriate software, telephones, office supplies and 'furnishings for Contractor personnel. The Government will also provide access to all required and applicable documentation including technical and architecture guidelines and standards. The COR will assist and interface with Contractor staff for the duration of this contract. The contractor shall maintain the GFP and return to COR when the contractor performance ends.

1.14 Government Roles and Responsibilities & Performance Evaluation Methods The Contracting Officer Representative (COR) is authorized to interact, inspect and monitor contractor performance under this contract. The Contracting Officer (CO) is the only person to make contractual decisions obligating the Government. The COR will keep the CO informed about the emerging performance and seek the CO's advice and input for non-technical issues that arise. However, close working relationships among the COR and the CO are seminal to ensuring effective Contractor performance.

The COR shall have the following responsibilities under this task order:

· Coordinate with the Contractor

· Conduct periodic inspections and keep records of inspections

· Establish an Inspection Schedule using the Quality checklists from the contractor's Quality Control Plan (as appropriate)

· Minimize disruption of Contractor's work

· Report findings obtained from the inspections to the Contracting Officer (CO).

· Schedule review meetings. (Follow through to ensure agreed to actions are taken by the contractor.)

· Identify performance deficiencies

· Coordinate with the CO

· Give the Contractor the first right to make the corrections

· Accept Deliverables

· Provide timely feedback on submitted deliverables

· Advise Contractor when deliverable is accepted and that the Government will take title and ownership of the outputs/products

· Review changes to the Quality Control Plan before submitting to the CO for sign-off

· Perform annual and final Performance Evaluations using the Performance Criteria defined in this task order and prepare Contractor Performance Assessment Report (CPAR) annually.

· Act as Personal Identity Verification (PIV) sponsor for contractor personnel.

1.15 Performance Requirements Summary (PRS)

Performance Requirements Summary (PRS)

Performance Requirement
Performance Standard
Acceptable Quality Level (AQL)
Surveillance Method*
Monthly Rating**

1. Identify Non-Technical Clarification

Within 1 working day of receipt of the initial FOIA/PA request, the Contractor shall review the request and identify to the COR any non-technical clarification that needs to be done to place the Contractor in a position to process the request.

No more than 2 violations per month

Customer Review

Pass/Fail

2. Respond to Statement of Work Required

1. to Statemenr

Within 3 working days of receipt of the Statement of Work Required, the Contractor shall review the Statement of Work Required and provide to the COR the 1) number of requests in the appropriate production queue, 2) estimated Contractor effort minutes required to process the request, 3) estimated CPU (mainframe) cost, and 4) estimated responsive record delivery date.

No more than 2 violations per month

3. Perform Technical Clarification

Upon receipt of the Request Perfection Notice, the Contractor is cleared to conduct technical clarification

No more than 2 violations per month

4. Prepare Responsive Record

The Contractor shall prepare the responsive record based on the order the request was received, or according to the instructions received from the program manager.

5. Prepare Tasks

The Contractor shall prepare the Task. The task shall consist of all information developed in response to the FOIA/PA request.

6. Prepare Request Archive

The Contractor shall archive electronically and place on external hard drive.

7. Participate in Process Improvement

The Contractor shall participate in process improvement efforts and shall make suggestions to implement cost reduction methodologies and improve operational efficiencies.

8. Participate in Problem Resolution

The Contractor shall participate in problem resolution efforts. Problem resolution includes participating with Government personnel and other Contractor personnel in problem identification, reporting, definition, research, tracking, and the development of recommended solutions.

9. Provide Training

Upon request, the Contractor shall provide training required to familiarize Government personnel with the activities being performed by the Contractor.

Customer Review

10. Additional Tasks

For large efforts, tasks may be divided by subtask. The following table provides a complete listing of the required tasks. The table includes, Task No. and Name, End Result/Deliverable, Tool for creating it, Acceptance Criteria, and Intended Use, as applicable.

In addition to the Tasks listed above (1-9), the other Tasks required are large efforts required by the Contractors to create extract files on a quarterly and annual basis.

For #12 listed below, the miscellaneous extract files are FOIA/PA request dependent. All extract files are used by the Contract staff to fill FOIA/PA requests. Creating these extracts files are necessary to prevent the contractors from doing daily runs against production files to extract data. The daily runs have proven to slow down production.

Customer Review

1.1 See Attachment 1 for Mandatory IT Clauses

INFORMATION SECURITY

1.1. Information Security Incidents

An Information Security Incident is an incident that includes the known, potential, or suspected exposure, loss of control, compromise, unauthorized disclosure, unauthorized acquisition, or unauthorized access of any Contractor or Government systems or information, including, but not limited to, Sensitive Information.

1.1.1. Information Security Incident Reporting Requirements

All Information Security Incidents must be reported in accordance with the requirements below, even if it is believed the Incident may be limited, small, or insignificant.

a) The Contractor must report all Information Security Incidents immediately, but not later than 30 minutes after becoming aware of the Incident.

b) Copy the Contracting Officer Representative (COR) if possible, or if Contracting Officer Representative (COR) email is not immediately available; contact the Contracting Officer Representative (COR) immediately after reporting the incident.

c) Do NOT include any Sensitive Information in the subject or body of any e-mail. To transmit Sensitive Information, use FIPS 140-2 compliant encryption methods to protect Sensitive Information in attachments to email. Passwords must not be communicated in the same email as the attachment.

1.1.2. Information Security Incident Response Requirements

a) All determinations related to Information Security Incidents, including response activities, notifications to affected individuals and/or Federal agencies, and related services (e.g., credit monitoring) must be made by authorized USDA officials.

b) The Contractor must provide full access and cooperation for all activities (determined by the authorized Government official to be required) to ensure an effective Incident Response, including providing all requested images, log files, and event information to facilitate rapid resolution of Information Security Incidents.

c) Incident Response activities determined to be required may include but are not limited to: inspections, investigations, forensic reviews, data analyses & processing, and final determinations of responsibility for the Incident and/or liability for any additional Response activities.

d) USDA, at its sole discretion, may obtain the assistance of Federal agencies and/or third-party firms to aid in Incident Response activities.

1.2. Information Types

The term Information is synonymous with Data, regardless of format or medium. Personally Identifiable Information (PII) is a subset of Sensitive Information. Sensitive PII is a subset of PII, and therefore a subset of Sensitive Information. All requirements for Sensitive Information apply to PII and Sensitive PII. All requirements for PII apply to Sensitive PII.

Attachment 1 – Mandatory IT Security Clauses

1.2.1. Sensitive Information

Sensitive Information is any information, which if lost, compromised, or disclosed, could result in substantial harm, embarrassment, inconvenience, or unfairness to an individual, the Government, or the Government’s interests. Sensitive Information is subject to stricter handling requirements because of the increased risk if the data is compromised. Some categories of Sensitive Information include Financial, Medical/Health, Legal, Strategic, Security, Intellectual Property & Business, Human Resources, Personally Identifiable Information (PII), and Sensitive PII. These categories of information require appropriate protection as stand-alone information and may require additional protection in aggregate.

1.2.2. Personally Identifiable Information (PII)

PII, as defined in OMB Memorandum M-07-16, refers to information that can be used to distinguish or trace an individual’s identity, either alone or when combined with other personal or identifying information that is linked or linkable to a specific individual. The definition of PII is not anchored to any single category of information or technology. Rather, it requires a case-by-case assessment of the specific risk that an individual can be identified. In performing this assessment, it is important to recognize that non-PII can become PII whenever additional information [that is publicly available] — in any medium and from any source — is or can be combined to identify an individual. As an example, PII includes a name and an address because it uniquely identifies an individual, but alone may not constitute Sensitive PII.

1.2.3. Sensitive PII

Sensitive PII refers to information that can be used to target, harm, or coerce an individual or entity, assume or alter an individual’s or entity’s identity, or alter the outcome of an individual’s or entity’s activities. Sensitive PII requires stricter handling because of the increased risk to an individual or associates if the information is compromised. Some categories of Sensitive PII include stand-alone information, such as Social Security numbers (SSN) or biometric identifiers. Other information such as a financial account, date of birth, maiden names, citizenship status, or medical information, in conjunction with the identity of an individual (directly or indirectly inferred), is also considered Sensitive PII. In addition, the context of the information may determine whether it is sensitive, such as a list of employees with poor performance ratings or a list of employees who have filed a grievance or complaint.

1.3. Compliance with Security IT Policies

Information systems and system services provided by the Contractor must comply with the current USDA IT security and privacy policies, specifically the 3500 – 3599 Cyber Security Department regulations - https://www.ocio.usda.gov/policy-directives-records-forms/directives-categories.

The Contractor is required to comply with current Federal regulations and guidance found in the Federal Information Security Modernization act of 2014 (FISMA); Privacy Act of 1974; E-Government Act of 2002, Section 208; National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS) and the 800-Series Special Publications (SP), specifically 800-40, Guide to Enterprise Patch Management Technologies; Office of Management and Budget (OMB) memoranda; USDA Information Security Program policies and other relevant Federal laws and regulations with which USDA must comply.

House Resolution 83-15 “Consolidated and Further Continuing Appropriations Act, 2015” requires that USDA demonstrate each project/investment is “being managed in accordance with applicable lifecycle management policies and guidance.” This mandates that USDA development projects are required to follow the Agency’s System Development Lifecycle (SDLC). All projects listed in Farm Service Agency Farm Programs IT plan for expenditure can expect to be audited for compliance. Audits may occur at any time after the plan for expenditure is submitted to Congress.

The Contractor must protect information regarding security issues and associated documentation to limit the likelihood that vulnerabilities in operational client software are exposed. If new vulnerabilities are identified after the acceptance of COTS software, the vendor must review and remediate the vulnerabilities and present the results for Government approval within the timeframes documented in USDA IT security policies.

1.4. Security Assessment and Authorization

a. This contract requires the Contractor to develop, deploy, and/or use information systems to access and/or store Government information, including Sensitive Information. The Contractor must cooperate and support the Government in the development of required documentation and artifacts.

b. All information systems that input, store, process, and/or output Government information must be provided an Authority to Operate (ATO) signed by the authorizing official as identified by the CIO. The Contractor must adhere to current policies, procedures, and guidance for security Assessment and Authorization (A&A) activities.

1.5. Federal Reporting Requirements

Contractors operating information systems must comply with Federal Information Security Modernization Act (FISMA) reporting requirements. Annual and quarterly data collection will be coordinated by the Government. Contractors must provide the Government with the requested information based on the timeframes provided with each request. Reporting requirements are determined by the Office of Management and Budget (OMB), and may change each reporting period. The Contractor must provide the Government with all information to fully satisfy FISMA reporting requirements for Contractor systems.

1.6. Acquiring And/Or Implementing Software Applications

Secure Coding Skills: Contractor must certify that at least one member of each programming team working on any code (including C, Java, .Net, ASP.NET, Visual Basic) to be delivered to the Govt. has earned the Global Information Assurance Certification for Secured Software Programming or equivalent.

Source code testing, binary code testing, application scanning, and penetration testing: At least one (1) week prior to delivery of any code due under this contract, Contractor must deliver to the COR the following reports covering all code that will be delivered:

A. Source code testing results showing all potential security flaws identified by at least one of the commercial source code testing tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor must highlight all vulnerabilities rated “critical” and “high.” The Contractor must then correct the vulnerabilities, resend the code, and ensure the health of delivered source code.

B. For web applications, web application scanning test results showing all potential security flaws identified by at least one of the commercial web application scanning tools approved by the Office of the Chief Information Officer of USDA. On the report, the Contractor must highlight all vulnerabilities rated “critical” and “high.”

C. For all applications: application penetration results.

Copyright Management and Responsibility: By delivering applications or programming code to the Federal Government, the vendor or Contractor certifies that they have the proper authority to transfer the property and will defend the Government against copyright or other lawsuit resulting from the application or programming delivered.

1.7. Processing, Storing, Transmitting Government Data to Non-Government System The Contractor or other external organizations must develop, provide, implement, and maintain an IT System Security Plan for any system that includes acquisition, transmission or analysis of data owned by the Government with significant replacement cost should the Contractor’s and other external organization’s copy be corrupted. This plan must describe the processes and procedures that must be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. The plan must describe those parts of the contract to which this clause applies. The Contractor or other external organization’s IT System Security Plan must be compliant with applicable Federal laws that include, but are not limited to: (e.g., the Clinger-Cohen Act of 1996 and the Federal Information Security Management Act of 2002). The IT System Security Plan must meet IT security requirements in accordance with Government policies and procedures that include, but are not limited to: National Institute of Standards and Technology (NIST) SP 800-53 Guidelines.

The Contractor and other external organizations must ensure that the appropriate security banners are displayed on all Government systems (both public and private) operated by the contractors and other external organizations prior to allowing anyone access to the system.

PERSONNEL

2.1. Personnel Security

2.1.1. Background Investigation Requirements

Contractor personnel must be able to obtain a favorable suitability decision in accordance with 5 CFR part 731.

The duties of this contract range from low risk to high risk positions and, as such, Contractor personnel will be required to submit all required documentation necessary for the agency to provide a favorable preliminary decision on suitability. This decision is required prior to commencing work on the contract.

Contractor personnel who receive an unfavorable suitability decision must be immediately removed from consideration for work on the contract.

The company is accountable for selecting personnel capable of receiving favorable suitability determinations; consequences for advancing personnel not able to pass government background checks may include providing invoice credits effectively reimbursing the government for background check expenses. Performance delays or detrimental project outcomes due to not onboarding or removal of staff will be directly attributable to the vendor and documented.

2.1.2. HSPD-12 -Credentials

Contractor personnel must complete necessary requirements to obtain HSPD-12 credentials immediately upon beginning work on the contract. Failure to obtain HSPD-12 credentials is grounds for removal/suspension of Contractor personnel from the contract.

2.2. Training

2.2.1. Mandatory Government Training

Mandatory training must be completed by the required dates by all contract employees. Mandatory Government training classes may be completed during work hours. It is the intent of USDA to provide thirty (30) calendar days written notice of annual training requirements to the Contractor. In the event the Contractor does not receive thirty (30) calendar day notice, the Contractor is still required to complete the training by the specified required date(s).

These mandatory courses are typically provided through USDA’s education/learning application and are free-of-charge. The education/learning application will typically load mandatory training to the individual’s education/learning application profile to-do list. The COR will notify the Contractor of new training requirements. Training can typically be completed within 30-60 minutes. This training includes:

· Information Security Awareness Training (ISAT) - All Contractor personnel working on this contract are required to complete USDA provided ISAT both before beginning work and annually thereafter. Failure to take this training within the prescribed window will result in removal of the Contractor employee from the contract.

· Records Management training - is a one-time training that is required for everyone within ninety

(90) days of their start date.

· Other training that is federally mandated or required by the agency.

SECTION 508 – ACCESSIBILITY OF INFORMATION AND COMMUNICATIONS TECHNOLOGY

(a) This Statement of Work (SOW) is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220). Specifically, subsection 508(a)(1) requires that when the Federal Government procures Information and Communications Technology (ICT)1, the ICT must allow Federal employees and members of the public with disabilities comparable access to and use of information and data provided to Federal employees and members of the public without disabilities.

(b) The ICT accessibility standards as 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board (also known as the Access Board) and apply to contracts, task orders, and indefinite quantity contracts on or after June 25, 2001.

(c) Each Information and Communications Technology (ICT) product or service furnished under this contract must comply with the Information and Communications Technology Accessibility Standards (36 CFR 1194), as specified in the contract, at a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing.

1 Please note that the term Information and Communications Technology (ICT) is synonymous with Electronic and Information Technology (EIT), the previously used term. The term ICT will be used to meet international standards after the release of the Section 508 Refresh.

The Contractor must, without charge to the Government, repair or replace the non-compliant products or services within a period of time specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government must have the following recourses:

1) Cancellation of the contract, delivery, or task order, purchase, or line item without termination liabilities; or

2) In the case of custom Information and Communications Technology (ICT) being developed by a contractor for the Government, the Government must have the right to have any necessary changes made or repairs performed by itself or by another firm for the non-compliant ICT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.

(d) The contractor must ensure that all ICT products and services that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements.

(e) For every ICT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor must, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date, whichever must occur first.

3.1. Section 508 Compliance

The software must comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this SOW, the SOW must take precedence.

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

3) http://www.access-board.gov/sec508/508standards.htm (Section 508 standards)

4) FAR 39.2 (Section 508)

5) http://www.ocio.usda.gov/document/departmental-regulation-4030-001 (USDA standards, policies, and procedures for Section 508) In addition, all contract deliverables are subject to these standards.

All web content or communications materials produced, regardless of format (text, audio, video, etc.), must conform to the applicable Section 508 standards to allow Federal employees and members of the public with disabilities comparable access to and use of information and data provided to Federal employees and members of the public without disabilities. All contractors (including sub-contractors) and consultants responsible for preparing or posting content must comply with the applicable Section 508 accessibility standards and, where applicable, those set forth in the referenced policy or standards document above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the SOW must be the responsibility of the contractor or consultant.

The following Section 508 provisions apply to the products and/or services identified in this SOW:

· 36 CFR Part 1194.21 provisions a-l

· 36 CFR Part 1194.22 provisions a-p

· 36 CFR Part 1194.23 provisions a-k[4]

· 36 CFR Part 1194.24 provisions a-e

· 36 CFR Part 1194.25 provisions a-j[4]

· 36 CFR Part 1194.26 provisions a-d

· 36 CFR Part 1194.31 provisions a-f

· 36 CFR Part 1194.41 provisions a-c The following Section 508 provisions apply for software development material identified in this SOW:

For software development, software applications, and operating systems the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.21 provisions a-l

b. 36 CFR Part 1194.31 provisions a-f

c. 36 CFR Part 1194.41 provisions a-c

For web-based applications (intranet, internet information and applications, 16 rules), the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.21 provisions a-l

b. 36 CFR Part 1194.22 provisions a-p

c. 36 CFR Part 1194.31 provisions a-f

d. 36 CFR Part 1194.41 provisions a-c

For telecommunication products and services, the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.23 provisions a-k

b. 36 CFR Part 1194.31 provisions a-f

c. 36 CFR Part 1194.41 provisions a-c

For video and multimedia applications (including training materials), the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.24 provisions a-e

b. 36 CFR Part 1194.31 provisions a-f

c. 36 CFR Part 1194.41 provisions a-c

For self-contained and closed products, the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.21 provisions a-l

b. 36 CFR Part 1194.25 provisions a-j

c. 36 CFR Part 1194.31 provisions a-f

d. 36 CFR Part 1194.41 provisions a-c

For desktop and portable computers, the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.21 provisions a-l

b. 36 CFR Part 1194.26 provisions a-d

c. 36 CFR Part 1194.31 provisions a-f

d. 36 CFR Part 1194.41 provisions a-c

For help desk and other support services, the Vendor must comply with the following standards, policies, and procedures:

Section 508 Accessibility Standards

1) 29 U.S.C. 794d (Rehabilitation Act as amended)

2) 36 CFR 1194 (Section 508 standards)

a. 36 CFR Part 1194.31 provisions a-f

b. 36 CFR Part 1194.41 provisions a-c

If the help desk or other support services include training, Vendor must also comply with the following standards, policies, and procedures in addition to 36 CFR Part 1194.31 provisions a-f and 36 CFR Part 1194.41 provisions a-c:

a. 36 CFR Part 1194.21 provisions a-l (installable and web-based training)

b. 36 CFR Part 1194.22 provisions a-p (web-based software)

All Information and Communications Technology (ICT) subject to the 36 CFR 1194 standards must have a Section 508 usability and acceptance test where Section 508 compliance will be validated. This test must be administered by a Federal Section 508 Testing Center.

All maintenance for Information and Communications Technology that requires upgrades, modifications, installations, and purchases must adhere to the Section 508 standards and 36 CFR 1194.

3.2. WCAG 2.0 Compliance

The software must comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this SOW, the SOW must take precedence.

Custom ICT Development Services When Vendor provides custom ICT development services pursuant to this contract, Vendor must ensure the ICT fully conforms to the applicable Revised 508 Standards prior to delivery and before final acceptance.

Installation, Configuration, and Integration Services When Vendor provides installation, configuration, or integration services for equipment and software pursuant to this contract, the offeror must not install, configure, or integrate the equipment and software in a way that reduces the level of conformance with the applicable Revised 508 standards.

Maintenance, Upgrades, and Replacements Vendor must ensure maintenance upgrades, substitutions, and replacements to equipment and software pursuant to this contract do not reduce the original level of conformance with the applicable Revised 508 standards at the time of the contract award.

Service Personnel Vendor must ensure the personnel providing the labor hours possess the knowledge, skills, and ability necessary to address the applicable Revised 508 standards defined in this contract and must provide supporting documentation upon request.

Hosting Services When providing hosting services for electronic content provided by the agency, Vendor must not implement the hosting services in a manner that reduces the existing level of conformance of the electronic content with applicable Revised 508 standards. Throughout the life of the contract, the agency reserves the right to perform testing on a vendor or contractor’s hosted solution to verify conformance with this requirement.

Validation for ICT Items When purchasing ICT where 1) 508 validation is not possible prior to award, 2) when ICT will be changed after the award, or 3) ICT will be hosted in a third-party environment, Vendor must test and validate the ICT solution for conformance to the Revised 508 standards, in accordance with the requirement testing methods, as defined by the agency. Throughout the life of the contract, the agency reserves the right to perform testing to verify conformance with this requirement.

Documentation Vendor must maintain and retain full documentation of the measures taken to ensure compliance with the applicable requirements, including records of any testing or demonstrations conducted.

Conformance Reporting

Prior to acceptance, Vendor must provide an Accessibility Conformance Report (ACR) for each ICT item that is developed, updated, configured for the agency, and when product substitutions are offered. The ACR should be based on the latest version of the Voluntary Product Accessibility Template (VPAT) provided by the Information Technology Industry Council (ITI). To be considered for award, an ACR must be submitted for each ICT item, and must be completed according to the instructions provided by ITI.

When the contractor is required to perform testing to validate conformance to the agency’s accessibility requirements, Vendor must provide a Supplemental Accessibility Conformance Report (SAR) that contains the following…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .