DRAFT SIS-PWS-18Dec2019.docx

DOCX document 547 KB Posted

Attached to
DoDEA Student Information System (SIS) Federal contract opportunity
Solicitation number
HE125420R3001
Issued by
Department of Defense Education Activity

View the file

Other files for this federal contract opportunity

Other files attached to DoDEA Student Information System (SIS), newest first.
File Type Posted
HE125420R3001 Price Template (Attachment 2).xlsx XLSX spreadsheet
DODEA SIS RFP HE125420R3001.pdf PDF
HE125420R3001_Past Performance Questionnaire (Attachment 3).docx DOCX document
HE125420R3001_ DoDEA Cloud Questionnaire_SIS (Attachement 1).docx DOCX document
SIS NOTICE.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Disclaimer

PERFORMANCE WORK STATEMENT (PWS)This document was produced under contract to the Department of Defense Education Activity (DoDEA). The product vision described herein has been developed through interviews, data analysis, working group collaborations, and requirement vetting with DoDEA personnel. Secondary sources include: publicly available documents, websites, discussion forums, Department of Defense policy, directives, and standards.

Requirements and performance summaries were developedwith and validated by DoDEA personnel.

DEPARTMENT OF DEFENSE EDUCATION ACTIVITY (DoDEA) DoDEA School Information System (SIS) 1 General Information

1.1 Agency

1.1.1 The Department of Defense Education Activity (DoDEA) serves the dependents of United States of America military and civilian employees by providing PK-12 instruction to approximately 70,000 students in 162 brick-and-mortar schools and one virtual high school. DoDEA schools are located in 11 countries, seven states, and two territories. DoDEA operates across ten time zones resulting in schools are in session every day of the week. Student enrollment is based primarily on deployment of military troops worldwide. In the Americas, DoDEA operates 51 schools located in seven states, Commonwealth of Puerto Rico, and Guantanamo Bay, Cuba. In Europe and the Middle East, DoDEA operates 64 schools located in: Germany, Italy, England, Netherlands, Belgium, Spain, Turkey and Bahrain. In the Pacific, DoDEA operates 45 schools located in South Korea, Japan (mainland and Okinawa), and territorial Guam.

DoDEA's curriculum, resources, and student achievement scores on standardized assessments compare favorably to those of high-performing United States (U.S.) public school systems. DoDEA Virtual High School (DVHS) is a fully accredited program with teaching hubs in each DoDEA region: U.S., Europe, and Pacific.

1.1.2 DoDEA schools have various grade configurations, with the most common being K-5, 6-8, 9-12, and K-12. Of DoDEA’s 162 brick-and-mortar schools, 102 schools have students in at least three of the grades K-5; 62 schools with at least one grade 6-8; and 40 schools with grades 9-12. Of the 6-8 schools, ten are part of an elementary school and five have only grades 7-8.

Table 1: Student Enrollment – SY 2019-20 (rounded to nearest 50 students)

Grade
Students
Grade
Students
Grade
Students
Grade
Students
PK
3,800
3
6,550
7
5,100
11
3,050
K
7,000
4
5,950
8
4,500
12
2,800
1
6,900
5
5,800
9
3,700
K-12

Total 70,400

2
6,550
6
5,400
10
3,300

1.1.3 Military-connected students experience high mobility rates in and out of school systems across the nation and the world; thus, DoDEA makes a concerted effort to mitigate transitional barriers to military-connected students’ success, working toward a world-wide systemic education network.

1.2 Background

1.2.1 DoDEA implemented a current school information system (SIS) over ten years ago and has become an integral part of DoDEA’s technology and culture. To meet sometimes unforeseen requirements, the current system has been customized many times. Features include, but are not limited to: class attendance, student grades, demographic information, addresses, graduation credits, school reports, student services, and standardized test scores.

1.2.2 DoDEA has implemented a continual service improvement program to align our current business processes with industry best practices and standards to ensure consistent, repeatable, documented business processes.

1.2.3 Technical Exhibit (TE) #5 describes DoDEA’s current technical environment.

1.3 Scope of Work

1.3.1 DoDEA requires a Software as a Service (SaaS) SIS to maintain, support, enable intuitive use and comprehensive privacy security of students’ educational past and current records, accommodate students’ future records, and perform administrative reporting for all DoDEA organizational hierarchy business operations from the classroom to the Director. In supporting all aspects of each student’s education, the SIS must:

· Allow parents/sponsors and student access to user interface portal for educational, health, and financial welfare records/reports, agendas, communications, and classroom to school to district information links/portals.

· Provide transparent, efficient, personalized, and secure accessibility for operational and functional capabilities to the six different levels of functional users: community, complex/installation, school, district, region, and headquarters.

DoDEA Organizational Hierarchy Chart

· Intuitive, user-friendly, system applications to administer and perform holistic learning and administration activities and tasks such as, but not limited to: master scheduling, information management, interface with data repositories and third-party applications/systems to enhance and provide the latest in modern student information system capabilities.

1.3.2 DoDEA requires a DoDEA requires a Service Level Agreement (SLA) from the vendor to include specifics of services provided in order to ensure continuity of services and conditions of service availability. The SLA shall provide description of services such as, but not limited to: timeliness of services, roles and responsibilities of each supporting capability, explanation of procedural escalation processes, cost of service tradeoffs, and management elements for reporting, dispute resolution (e.g., risk mitigation), service level breach notifications, and upkeep of SLA relevancy throughout contract period of performance.

1.3.3 The contractor shall provide industry-standard technical support via telephone, ticketing system or email within one day or less from the initial contact, excluding federal holidays, to include but not limited to: providing assistance with service problems, product setup, upgrades, and troubleshooting throughout the life of the contract

1.3.4 Provide migration of, at a minimum 500 gigabytes of data, associated tables, provide a data dictionary to map interfaces, and plan to support validation of data migration accuracy in a timely manner to the new system.

1.3.5 DoDEA expects to make one award for a 12-month base year and nine 12-month option years.

2 REQUIREMENTS

Requirements have been developed utilizing DoDEA Subject Matter Experts from all functional areas. Capabilities identified as “Desirable” are operational aspects DoDEA wishes industry to provide response solutions to enhance system performance as well as user experience.

2.1 Objective 1: Project Management and SIS

Provide project management to include a dedicated liaison to DoDEA and a defined project plan that covers all aspects of the SIS.

2.1.1Task #1, Management—The Contractor shall:
2.1.1.1Provide a dedicated project manager and alternate who will have authority full authority to act for the Contractor on all contract matters relating to the daily operation of this contract.
2.1.1.2Provide an organizational chart with names, titles, and qualifications of the people leading this project.
2.1.1.3Notify the contracting officer’s representative (COR) in writing of changes in the organizational chart five business days in advance of the change. Verify in writing to the COR that the replacement’s qualifications meet or exceed those of his/her predecessor.
2.1.2Task #2, Project Plan and Implementation— The Contractor shall:
2.1.2.1Provide a draft project plan for delivering the SIS for each item listed in TE #2, Deliverables,. At a minimum the project plan shall include the following:

1) Management (including organizational chart)

2) Schedule (including detailed explanation of interdependencies and detailed data migration schedule, if applicable)

3) Deliverables (including all relevant elements listed in TE #2)

4) Challenges/Risks

5) Unforeseen Changes (a detailed way forward when DoDEA presents the Contractor with future unforeseen requirements)

6) Budget (broken down by the categories in TE #2)

7) Evaluation to include internal evaluation and quality assurance controls

2.1.2.2Provide a final project plan based on written feedback from COR. The final project plan shall include an executive summary addressing all of the key requirements.
2.1.2.3Implement the project plan, providing DoDEA with an SIS that meets the requirements set forth in this performance work statement (PWS).
Performance Standards and Acceptable Quality Levels (AQL)

Objective 1, Project Management

Performance Standard and Related Task
AQL
Inspection Method
Incentives*

* Unless specified otherwise, possible ratings are as follows: exceptional, very good, satisfactory, marginal, or unsatisfactory, per FAR 42.1503, Table 42-1, and “Evaluation Ratings Definitions”.

Task 1, Management, PWS 2.1.1 Zero deviation from the PWS.

From post-award conference until contract expiration.

Manager or alternate shall be able to act on behalf of the Contractor on all contract matters relating to the daily operation of this contract
COR inspection
N/A

Task 2A, Project Plan, PWS 2.1.2.1-2.1.2.2 Zero deviation from the PWS.

Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback from the COR Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

COR inspection
N/A

Task 2B, Implementation, PWS 2.1.2.3 Zero deviation from the PWS.

Implemented per project plan

Implement the project plan, providing the required SIS
COR inspection and feedback from SIS users system wide
N/A

2.2 Objective 2: System Security and Protection

Provide the following: general security controls, SIS authentication, incident response, media protection, maintenance, physical & environmental protection, security planning policy, personal security, risk assessment, system & communication protection, system & information integrity. All policies shall be presented to DoDEA in writing and finalized within ten business days after receipt of written responses from the COR.

2.2.1Task #3, General Security Controls—The Contractor’s SIS shall:
2.2.1.1Support personal identification number (PIN) and password authentic-cation capability.
2.2.1.2Include a web management portal.
2.2.1.3Offer or support multi-factor authentication such as a “Shared Secret”; something the user knows, (i.e., PIN and/or password) with forgotten username and password support capability and notification capability through Short Message Service (SMS) and/or email.
2.2.1.4Provide use of a temporary password for system logons with an immediate change to a permanent password.

2.2.1.5 Enable users to reset(s) the password for a temporary password so as to unlock the account making password use available upon next log in.

2.2.1.6 Enforce minimum password complexity of: case sensitive, minimum of twelve characters, and at least one each of upper-case letters, lower-case letters, numbers, and special characters. Employ automated tool(s) to determine password authenticators are sufficiently strong to satisfy DoDEA password complexity requirements. Provide enforcement of at least one of the following number of changed characters when new passwords are created—either stores and transmits only encrypted representations of passwords or enforces password minimum and maximum lifetime restrictions of a 3-day minimum and 90-day maximum.

2.2.1.7 Prohibit password reuse for eight past used passwords.

2.2.1.8 Report results of database audits to include but not limited to the following: database schema and object changes, failed and successful logon and logoff attempts, data type changes, field changes, permissions changes and changes to jobs/functionality in order to ensure suspicious activity is traceable and reported.

2.2.1.9 Support single sign-on compatibility with Google authentication in accordance with the OAuth 2.0 and SAML 2.0 protocols.

2.2.2 Task #4, SIS Authentication—The Contractor’s SIS shall:

2.2.2.1 Verify—as part of the initial authenticator distribution—the identity of the individual, group, role, or device receiving the authenticator.

2.2.2.2 Define and establish initial authenticator content to perform the following:

1) Ensure authenticators have sufficient strength of mechanism for each intended use.

2) Establish/implement administrative procedures for initial authenticator distribution, lost/compromised or damaged authenticators, and revoking authenticators.

3) Change default content of authenticators prior to SIS installation.

4) Establish (1) minimum and maximum lifetime restrictions and (2) reuse conditions for authenticators.

5) Change/refresh authenticators to include ninety days for passwords.

6) Protect authenticator content from unauthorized disclosure and modification.

7) Provide specific security safeguards to protect authenticators.

8) Change authenticators for group/role accounts when membership to those accounts changes.

2.2.3 Task #5, Incident Reporting—The Contractor’s SIS shall:

2.2.3.1 Provide an incident response plan with the following reporting criteria:

1) Roadmap for implementing its incident response capability.

2) Structure and organization of the incident response capability.

3) High-level approach to fit the incident response capability into the overall organization.

4) Meeting the unique requirements of the Government.

5) Defining reportable incidents.

6) Metrics for measuring the incident response capability.

7) Defining the resources and management support needed to effectively maintain and mature an incident response capability.

8) Reviewing/updating the incident response plan at least annually to address system/organizational changes or problems encountered during plan implementation, execution, or testing.

9) Protecting the incident response plan from unauthorized disclosure and modification.

2.2.3.2 Develop, document, disseminate, and institute (1) an incident response policy that addresses purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the incident response policy and associated incident response controls. Review/update the current policy once every two years and the procedures at least once each year.

2.2.3.3 Develop/institute incident response capability within United States Computer Emergency Readiness Team (US-CERT) incident reporting timelines as specified in the National Institute of Standards and Technology (NIST) Special Publication 800-61 (as amended); and reports security incident information to US-CERT and law enforcement as necessary.

2.2.3.4 Provide two hours of virtual incident response training to SIS users consistent with assigned roles and responsibilities, as required by SIS changes, and not less than once per year.

· Webinar Option: Deliver live, synchronous webinars during school hours that are based on the time zone of the DoDEA Regions—Americas, Europe, and Pacific. Provide recordings of the presentations for placement on DoDEA’s learning management system (LMS currently Schoology).

· Module Option: Provide one digital modules, which shall include video clips of the incident reporting functionality.

· Each online module’s contact time shall be equivalent to the Webinar Option described above—six hours.

· All digital content must be packaged and delivered for publishing and reusability in Sharable Content Object Reference Model® (SCORM®) packaging, and made available for placement and use on DoDEA’s LMS (currently Schoology) for the life of the contract. The Department of Defense Instruction (DoDI) 1322.26 mandates that electronic courseware be developed in compliance with the latest possible version.

2.2.3.5 Report suspected security incidents to the Contractor’s program manager and DoDEA’s Contracting Officer. Incident response shall not exceed one hour after discovery/detection for incidents involving PII/PHI. Non-PII/PHI incident responses shall not exceed two hours after discovery/ detection. Report security incident information to the Contract Officer and/or designee, Program Manager, and COR and appropriate incident response center, e.g., US-CERT if the incident involves personally identifying information and protected health information (PII/PHI).

2.2.3.6 Test incident response capability at least every six months for high availability and at least every 12 months for low/medium availability. Provide the COR with a written summary of each test’s results.

2.2.4 Task #6, Media Protection (Policy)—The Contractor shall develop, document, disseminate, and institute a media protection policy and procedures that includes a PII/PHI policy for all personnel, including contractors with potential access to that sensitive information. Ensure the policy and procedures address (1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate policy implementation. Review/update the current policy once every two years and procedures every six months.

2.2.5 Task #7, Media Protection (Access)—The Contractor’s SIS shall:

2.2.5.1 Restrict access to any digital or non-digital media containing PII/PHI to authorized individuals as prescribed by DoDEA.

2.2.5.2 Identify SIS media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information.

2.2.5.3 Protect SIS media until they are destroyed or sanitized using Government-approved equipment, techniques, and procedures.

2.2.5.4 Physically control and store removable media that contain PII/PHI within any securable area or in a locked container.

2.2.5.5 Protect and control all media with sensitive information during transport outside of controlled areas and prior to leaving secure/controlled environ-ments. Note: This requirement applies to digital media, encryption using a Federal Information Processing Standard (FIPS) 140-2 validated encryption module, and non-digital media, secured in locked container.

2.2.5.6 Maintain accountability for all SIS media during transport outside of controlled areas. Document activities associated with the transport of SIS media. Restrict the activities associated with transport of SIS media to authorized personnel for review and approval by the COR.

2.2.6 Task #8, Media Protection (Sanitization) )—The Contractor’s shall:

2.2.6.1 Notify the Contracting Officer and COR within two business days of any intent to conduct sanitization operations. Provide a plan of operations in writing before conducting sanitization operations. Implement the plan only upon written approval from the COR.

2.2.6.2 Sanitize digital media that contains PII/PHI prior to disposal, release out of organizational control, or release for reuse using FIPS-validated media sanitization techniques or procedures in accordance with applicable federal and organizational standards and policies. Employ a sanitization mechanisms with the strength and integrity commensurate with the security category or classification of the information

2.2.6.3 Restrict the use of portable storage and mobile devices on information systems and networks containing PII/PHI using device ownership, media sanitization, and encryption controls.

2.2.6.4 Test sanitization equipment and procedures at least annually to verify that the intended sanitization are achieved. Provide the COR a written summary of the test results.

2.2.7 Task #9, Maintenance—The Contractor shall develop, document, disseminate, and institute a system maintenance policy and procedures addressing (1) the purpose, scope, roles, responsibilities, management commitment, and coordination among organizational entities, (2) compliance and (3) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy once every two years and procedures every six months.

2.2.8 Task #10, Physical & Environmental Protection (Policy)—The Contractor shall develop, document, disseminate, and institute a physical and environmental policy that addresses (1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the policy once every three years and procedures every six months.

2.2.9 Task #11, Physical & Environmental Protection (Practices) — The Contractor shall:

2.2.9.1 Maintain temperature and humidity levels within the facility where the SIS resides consistent with American Society of Heating, Refrigerating and Air-conditioning Engineers (ASHRAE) document entitled Thermal Guidelines for Data Processing Environments.

2.2.9.2 Monitor temperature and humidity levels continuously.

2.2.9.3 Authorize, monitor, and control all SIS components entering and exiting the facility and maintains records of those items.

2.2.9.4 Provide/maintain a list of individuals with authorized access to the facility where the SIS resides.

2.2.9.5 Issue authorization credentials for facility access.

2.2.9.6 Review authorization credentials at least annually. Remove individuals from the facility access list within eight business hours from the time access is terminated or is no longer required. Notify the Contracting Officer and COR in writing on the same business day that an individual’s access is terminated or is no longer required.

2.2.9.7 Enforce physical access authorizations by the following procedures:

1) Verify individual access authorizations before granting access to the facility.

2) Control ingress/egress to the facility using electronic locks.

3) Monitor physical access to the facility where the SIS resides to detect and respond to physical security incidents.

4) Maintain physical access audit logs for entry/exit points.

5) Document physical access logs at least monthly and upon suspicion of unauthorized entry or attempt of entry.

6) Maintain visitor access records to the facility where the SIS resides for a minimum of one year. Review visitor access records at least weekly reporting any foreign national visitors

7) Provide physical and administrative safeguards to control access to areas within the facility officially designated as publicly accessible.

8) Escort visitors and monitor visitor activity in all circumstances within restricted access areas where the SIS resides.

9) Secure keys, combinations, and other physical access devices. Change combinations and keys at least annually and/or when keys are: lost, combinations are compromised, or individuals are transferred or terminated.

10) Inventory physical access devices at least annually.

2.2.9.8 Coordinate/document results of reviews and investigations involving physical and environmental protection (practices) with the Contracting Officer and COR.

2.2.10 Task #12, Security Policy— The Contractor shall:

2.2.10.1 Develop, document, disseminate, and institute a security policy and procedures addressing (1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy once every three years and procedures every six months. Update more frequently, if necessary, to address changes to the SIS environment of operation or to address either problems identified during plan implementation or security control assessments.

2.2.10.2 Provide a security policy that is consistent with the enterprise architecture, defines the authorization boundaries for the system, and includes the following descriptions/information:

1) SIS’s operational context in terms of mission and business processes.

2) Overview of the SIS’s security requirements to include the (1) security categorization and supporting rationale for each entry and (2) security controls in place or planned for meeting those requirements including a rationale for the tailoring and supplementation decisions.

3) SIS’s operational environment and relationships with or connections to other information systems.

4) List of relevant overlays, if applicable, for the COR review and approval.

2.2.10.3 Protect the security plan from unauthorized disclosure and modification.

2.2.10.4 Ensure individuals requiring access to the SIS have access to the rules that describe their responsibilities and expected behavior vis-à-vis information and SIS use. Ensure these individuals sign a document testifying that they understand the rules cited above. Provide the documentation to the COR, upon request only.

2.2.10.5 Require individuals who have signed the rules of behavior to re-sign any revisions of the rules within ten business days of receiving the revisions. Provide the documentation to the COR, upon request only.

2.2.10.6 Review/update the rules of behavior at least once every three years.

2.2.11 Task #13, Personal Security—The Contractor shall:

2.2.11.1 Develop, document, disseminate, and institute a personal security policy for all individuals accessing the SIS—DoDEA, Contractor, and subcontracted/ third-party personnel—that addresses (1) the purpose, scope, responsibilities, roles, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update the current policy once every three years and procedures every six months.

2.2.11.2 Assign a risk designation to all organizational positions. Provide screening criteria for individuals filling those positions. Review/update position risk designations at least once every three years. Provide the documentation to the COR, upon request only.

2.2.11.3 Ensure that individuals accessing the SIS—that is, processing, storing or transmitting information—have valid authorization and are assigned their rights by the appropriate official. Ensure that DoDEA, Contractor, and subcontracted or third-party personnel working on the SIS complete and sign non-disclosure agreements protecting sensitive information. Provide the documentation to the COR, upon request only.

2.2.11.4 Screen all individuals—DoDEA, contracted, and subcontracted/third-party personnel—prior to authorizing access to the SIS. Ensure the level of screening is proportionate to the level of risk and responsibility associated with their access to or use of PII/PHI. Document the screening results. Provide the documentation to the COR, upon request only.

2.2.11.5 Disable SIS access upon each individual’s termination of employment or termination of being assigned to work on the SIS within one business day. Notify COR in writing within one business day. Note: Termination includes terminating or revoking any authentication credentials associated with the individual and retrieving all security-related organizational information and SIS-related property. Termination also means retaining access to organizational information and information systems formerly controlled by terminated individual.

2.2.11.6 Review and confirm ongoing operational need for current physical access authorizations to information systems/facilities when individuals are reassigned or transferred to other positions. Provide the documentation to the COR, upon request only.

2.2.11.7 Initiate changes to personnel physical access, including reassignment and transfer, within one business day of the formal transfer action. Modify access authorization as needed to correspond with any changes in operational need due to reassignment or transfer. Provide documentation to the COR within one business day of completion.

2.2.12 Task #14, Risk Assessment—The Contractor shall:

2.2.12.1 Develop, document, disseminate, and institute a risk assessment policy and procedures that address (1) the purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the system maintenance policy and associated system maintenance controls. Review/update risk assessment results once every three years or whenever there are significant changes to the SIS or environment of operation, including identification of new threats or vulnerabilities. Note: The COR will inform the Contractor in writing if “significant” changes have occurred. Review the risk assessment procedures every six months.

2.2.12.2 Conduct a risk assessment including the likelihood and magnitude of harm, from the unauthorized access, use, disclosure, disruption, modification, or destruction of the SIS and the information it processes, stores, or transmits. Document risk assessment results in a security assessment report and provide to the COR within one business day of completion.

2.2.12.3 Scan for vulnerabilities in the SIS and hosted application operating system/ infrastructure monthly. Scan web applications and databases and when new vulnerabilities potentially affecting the system/applications are identified and reported. Update the SIS vulnerabilities scanned prior to a new scan. Analyze vulnerability scan reports and results from security control assessments. Provide the COR with the results of the analysis within three business days of completion.

2.2.12.4 Utilize vulnerability scanning tools and techniques that facilitate inter-operability among tools and automate parts of the vulnerability manage-ment process by using standards for (1) enumerating platforms, software flaws, and improper configurations, (2) formatting checklists and test procedures, and (3) measuring vulnerability impact.

2.2.12.5 Remediate high-risk vulnerabilities mitigated within 20 business days from date of discovery and moderate-risk vulnerabilities mitigated within 60 business days from date of discovery in accordance with an organizational assessment of risk. Provide documented results within two business days of completion to the COR.

2.2.13 Task #15, System and Services Authenticators—The Contractor’s SIS shall:

2.2.13.1 Verify—as part of initial authenticator distribution—the identity of the individual, group, role, or device receiving the authenticator. Ensure authenticators have sufficient strength of mechanism for intended use. Provide the COR documentation about system and services acquisition every six months.

2.2.13.2 Ensure the following actions occurs:

1) Establish and implement administrative procedures for initial authenticator distribution, lost/compromised or damaged authenticators, and revoking authenticators.

2) Change default content of authenticators prior to SIS installation.

3) Establish minimum and maximum lifetime restrictions and reuse conditions for authenticators.

4) Change/refresh authenticators to include 90 calendar days for passwords

5) Protect authenticator content from unauthorized disclosure and modification.

6) Require individuals to implement specific security safeguards to protect authenticators.

7) Change authenticators for group/role accounts when membership to those accounts changes.

2.2.14 Task #16, System and Communication Protection—The Contractor shall:

2.2.14.1 Develop, document, disseminate, and institute system and communication protection policy that addresses (1) purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the policy and associated controls. Review/update the current policy once every three years and procedures every six months.

2.2.14.2 Produce, control, and distribute symmetric cryptographic keys using FIPS-compliant key management technology and processes to ensure the confidentiality and integrity of PII/PHI in transit or at rest. Note: Compliance means in accordance with applicable federal laws, executive orders, directives, policies, regulations, and standards.

2.2.14.3 Provides an SIS with the following functionality:

1) Generates a unique session identifier for each session and recognizes only session identifiers that are system-generated.

2) Provides an explicit indication of use to users physically present at the devices.

3) Terminates network connection associated with a communications session at the end of the session or after 15 minutes of inactivity.

4) Protects the confidentiality and integrity of data-at-rest, including PII/PHI.

5) Protects against or limits the effects of denial of service attacks.

6) Prohibits remote activation of collaborative computing devices.

7) Allows only incoming communications from authorized sources routed to authorized destinations.

2.2.14.4 Isolate key information security tools, mechanisms, and support components associated with system and security administration. Isolate those tools, mechanisms, and support components from other internal SIS components via physically or logically separate subnets.

2.2.14.5 Prevent unauthorized disclosure of information and detect changes to information during transmission unless otherwise protected by a hardened or alarmed carrier, e.g., Protective Distribution System (PDS).

2.2.14.6 Prevent unauthorized disclosure of PII/PHI during transmission unless otherwise protected by physical safeguard measures to prevent unauthorized access to or alteration of the PII/PHI contained therein.

2.2.14.7 Implement a managed interface for each external telecommunication service that includes the following:

1) Written traffic flow policy for each managed interface.

2) Protection of the confidentiality and integrity of the information being transmitted across each interface.

3) Documentation of each exception to the traffic flow policy with a supporting mission/business need and duration of the need.

4) Review of exceptions at least once per year and removal of exceptions that are no longer required by an explicit mission/business need.

2.2.15 Task #17, System & Information Integrity—The Contractor shall:

2.2.15.1 Develop, document, disseminate and institute system an information integrity policy and procedures that address (1) purpose, scope, roles, responsibilities, management commitment, coordination among organizational entities, and compliance and (2) procedures to facilitate the implementation of the policy and associated controls. Review/update the current policy once every three years and procedures every six months.

2.2.15.2 Ensure the SIS performs the following:

1) Checks the validity of PII/PHI.

2) Generates error messages that provide information necessary for corrective actions without revealing information that could be exploited by adversaries.

3) Reveals error messages only to authorized individuals with a need for the information in the performance of their duties.

4) Protects its memory from unauthorized code execution.

2.2.15.3 Provide an automated mechanism to perform the following:

1) Determine the state of information no less than once every 30 calendar days with regard to flaw remediation.

2) Identify, report, and correct SIS flaws.

3) Test software and firmware updates related to flaw remediation for effectiveness and potential side effects before installation.

4) Install security-relevant software and firmware updates within 30 calendar days of the release of the updates.

5) Incorporate flaw remediation into a documented configuration management process.

2.2.15.4 Provide tools and techniques to analyze malicious code and perform the following:

1) Incorporate the results from malicious code analysis into organizational incident response and flaw remediation processes.

2) Detect and block/eradicate malicious code at SIS entry and exit points.

3) Update malicious code protection mechanisms whenever new releases are available in accordance with organizational configuration management policy and procedures.

4) Perform periodic SIS scans at least weekly and real-time scans of files from external sources at the endpoint or network entry/exit points as the files are downloaded, opened, or executed in accordance with organizational security policy.

5) Document the receipt of false positives during malicious code detection and eradication and the resulting potential impact on SIS availability.

6) Implement additional monitoring of individuals who have been identified as posing an increased level of risk.

2.2.15.5 Provide an SIS that (1) monitors inbound and outbound communications traffic continually for unusual or unauthorized activities or conditions, (2) generates system alerts in accordance with the incident response plan when the indications of compromise or potential compromise occur, (3) receives system security alerts, advisories, and directives from US-CERT on an ongoing basis and (4) has the following functionality:

1) Generates internal security alerts, advisories, and directives as deemed necessary.

2) Disseminates security alerts, advisories, and directives to system security personnel and administrators with configuration/patch-management responsibilities.

3) Performs an integrity check of security relevant events at least monthly.

4) Implements security directives in accordance with established timeframes, or notifies the issuing organization of the degree of noncompliance.

· Performs this verification to include upon system startup and/or restart at least monthly.

· Notifies system administrators and security personnel of failed security verification tests.

· Restarts or shuts down the SIS when anomalies are discovered.

2.2.15.6 Provide integrity verification tools employed to detect unauthorized changes to software, firmware, and information and provide to the Contracting Officer and COR, including unauthorized changes to PII/PHI. Provide written notification and supporting information of unauthorized PII/PHI data to the Contracting Officer and COR within three business days of detection.

Performance Standards and Acceptable Quality Levels (AQL) Objective 2, System Security and Protection

Performance Standard and Related Task
AQL
Inspection Method
Incentives*

* Unless specified otherwise, possible ratings are as follows: exceptional, very good, satisfactory, marginal, or unsatisfactory, per FAR 42.1503, Table 42-1, and “Evaluation Ratings Definitions”.

Task 3, General Security Controls, PWS 2.2.1 Zero deviation from the PWS.

Draft: 25 business days after post-award conference Final: Five business days after receipt of written feedback

No more than 2% of all activities shall not perform as established.
Monthly Sample
N/A

Task 4, SIS Authentication, PWS 2.2.2 Zero deviation from the PWS.

25 business days after post-award conference

No more than 2% of all activities shall not perform as established.
Monthly Sample
N/A

Task 5, Incident Reporting, PWS 2.2.3 Zero deviation from the PWS.

25 business days after post-award conference

No more than 3% of all activities shall not perform as established.
Monthly Sample
N/A

Task 6, Media Protection (Policy), PWS 2.2.4 Zero deviation from the PWS.

Draft: 25 business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 7, Media Protection (Access), PWS 2.2.5 Zero deviation from the PWS.

20 business days after post-award conference

No more than 3% of all activities shall not perform as established.
Monthly Sample
N/A

Task 8, Media Protection (Sanitization), PWS 2.2.6 Zero deviation from the PWS.

20 business days after post-award conference

No more than 3% of all activities shall not perform as established.
Monthly Sample
N/A

Task 9, Maintenance, PWS 2.2.7 Zero deviation from the PWS.

Draft: 25 business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 10, Physical & Environmental Protection (Policy), PWS 2.2.8 Zero deviation from the PWS.

Draft: 25 business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 11, Physical & Environmental Protection (Practices), PWS 2.2.9 Zero deviation from the PWS.

Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 12, Security Policy, PWS 2.2.10 Zero deviation from the PWS.

Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 13, Personal Security, PWS 2.2.11 Zero deviation from the PWS.

Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 14, Risk Assessment, PWS 2.2.12 Zero deviation from the PWS.

Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting.

Monthly Sample
N/A

Task 15, System and Services Acquisition, PWS 2.2.13 Zero deviation from the PWS.

25 business days after post-award conference

No more than 3% of all activities shall not perform as established.
Initial review upon deliverable; then quarterly
N/A

Task 16, System and Communication Protection, PWS 2.2.14 Zero deviation from the PWS.

Draft: Ten business days after post-award conference Final: Five business days after receipt of written feedback Draft: 80% correct.

Final: 100% correct, except for possible errors in grammar/formatting

Initial review upon deliverable; then twice yearly
N/A

Task 17, System & Information Integrity, PWS 2.2.15 Zero deviation from the PWS.

20 business days after post-award conference

No more than 2% of all activities shall not perform as established.
Monthly Sample
N/A

2.3 Objective 3, Compatibility, Data Migration, and Reporting Provide compatibility, data migration, and data analysis, usage, and reporting functionality.

2.3.1 Task #18, Compatibility—The Contractor’s SIS shall:

2.3.1.1 Be compatible with mobile device operating systems, browsers, and interfaces for data exchange to include, but not limited to, the latest versions of Apple iOS, Chrome OS, and Android OS.

2.3.1.2 Be compatible with modern desktop web browsers, including Google Chrome, Safari, Microsoft Internet Explorer, Microsoft Edge, and Mozilla Firefox.

2.3.1.3 Increase or decrease the available hardware and software resources, as needed, to support periods of unpredictable high and low usage.

2.3.2 Task #19, Data Migration—If data migration is required, the Contractor shall:

2.3.2.1 Provide a draft data migration plan to move approximately 450-550 gigabytes of data from the existing system. Finalize the plan based on written feedback from DoDEA. Note: Exact information about the data migration will be determined post-award.

2.3.2.2 Migrate the data in accordance with the final plan.

2.3.3 Task #20, Analysis, Usage, and Reporting—The Contractor’s SIS shall:

2.3.3.1 Provide database connections or Application Programming Interfaces (API) for pulling large sets of data and connecting to application servers (i.e., reporting tools).

1) Create and maintain protocols to enable the creation and consumption of Representational State Transfer (REST) APIs and connections that are not limited to relational databases.

2) Provide developer documentation for database connections or APIs including but not limited to data dictionary, models, import mapping, etc.

3) Ensure the secure exchange data files of any size and types including but not limited to (1) CSV, PDF, TXT, JSON, HTML, XML and (2) to DoDEA-internal or external sources based on settings set by DoDEA-approved security roles.

4) Receive and send files to or from authorized external business partners manually and/or predicated to an automated schedule.

5) View and download the originating file content.

6) Track details—success or failure—of receiving and sending files.

2.3.3.2 Incorporate external data sources (e.g., third-party vendors, census data, etc.) and link to data model(s) to include but not limited to Single Sign-On (SSO) and direct connections to educations resources such as Benchmark, HMH, SAT, PSAT, ACT, SRI, BAS, AP, CAS, ASFAB, AAPPL, CoGAT, WIDA, ACCESS.

2.3.3.3 Share and sync (auto-populate) roster information securely across applications and synch student and teacher roster accounts data interchange standard and framework (e.g., Ed-Fi and IMS).

2.3.3.4 Provide dashboards to present key performance indicators (KPI) and recommended metrics for DoDEA hierarchical organizational levels, student academics, and DoDEA educational specialists.

2.3.3.5 Transfer assessment results from other sources back into the SIS and associate the data to the appropriate identifier such as student, school, parent/sponsor, course, schedule, etc., in a secure manner so as not to impede PII/PHI.

2.3.3.6 Provide front-end module for scheduling routine data tasks, procedures, and imports and user ability to review task results and choose data points for results output.

2.3.3.7 Provide a business rule engine that allows users to incorporate field validation, data cleansing, and identify violating records for reporting.

2.3.3.8 Enable DoDEA-defined users to track various attribute (e.g., student name) changes for all entities (e.g., student, school, courses, etc.). User shall be able to define which attributes will be tracked.

2.3.3.9 Provide documented procedures to classify or tag each PII, PHI, sensitive, or other protected criteria data element for export control, user access, and/or editing restrictions.

2.3.3.10 Provide an accessible log of actual routing and physical destination of data exchange.

2.3.3.11 Display a DoDEA-defined warning for users attempting to download or export PII/PHI or fields marked for classification.

2.3.3.12 Provide a public-facing component or viewing method to display non-sensitive, non-PII/PHI data elements in a preformatted structure by organizational level such as, but not limited to: school lunch menus, school calendar to include highlighted events, administration announcements and operational items, extracurricular activities, courses offered by school, etc., as well as within the entire course catalog, course description, academic requirements of the organization, and school contact information.

2.3.3.13 Enable DoDEA-defined users to print and save reports including student withdrawal form that includes fields such as but not limited to current classes, grades, attendance, and fees owed, etc.

2.3.3.14 Provide the following:

1) Ability to calculate results of included data by sum, count, difference and display the data in a viewable report format as well as exportable format to include but not limited to CSV, TXT.

2) Mechanism to store saved queries, filters, forms, and reports based on access permission level(s), organizational level, user or user groups.

3) Ability to allow users to share queries or reports with individuals or groups of users as well as different organizational levels.

4) Multiple format options to download query results and reports to include but not limited to HTML, CSV, Word, TXT, PDF, etc.

2.3.3.15 Provide the following reporting functionality:

1) Provide real-time process for reporting high-quality data (i.e., accurate, valid, completeness, reliable, relevant, consistent, unique, and timely) via a “single source of truth”.

2) Provide data/information aligned to the Common Education Data Standards (CEDS).

3) Enable DoDEA-defined users to download aggregated reports and charts in sharable format including code snippet for embedding results into another system or presentations.

4) Enable DoDEA-defined users to create ad-hoc queries including those with multiple tables without requiring technical skill such as SQL or coding.

5) Enable DoDEA-defined users to create reports and automate export of data based on existing saved queries or using standard data filtering programming code such as SQL.

6) Provide ad-hoc query function that may include such features as a drag-and-drop feature that allows users to a generate form and report layout for media screen, support printing and/or exported to a Microsoft Office suite product.

7) Enable DoDEA-defined users to request creation of database objects that utilize data from multiple data tables or sources.

8) Enable DoDEA-defined users to create custom fields for the purpose of grouping and tracking specific entities.

9) Enable DoDEA-defined users to (1) select, group and aggregate data based on user-defined criteria, (2) select, create groups/snapshots and limit access to data based on user-defined criteria, and (3) manage, assign or enable user-defined fields with datatypes to include but not limited to Boolean, text/varchar, numeric, date.

Performance Standards and Acceptable Quality Levels (AQL) Objective 3, Compatibility, Data Migration, and Reporting

Performance Standard and Related Task
AQL
Inspection Method
Incentives*

* Unless specified otherwise, possible ratings are as follows: exceptional, very good, satisfactory, marginal, or unsatisfactory, per FAR 42.1503, Table 42-1, and “Evaluation Ratings Definitions”.

Task 18, Compatibility, PWS 2.3.1 Zero deviation from the PWS.

20 business days after post-award conference

No more than 5% of all activities shall not perform as established.
Random Sample
N/A

Task 19, Data Migration, PWS 2.3.2 Zero deviation from the PWS.

25 business days after post-award conference

No more than 5% of all activities shall not perform as established.
Random Sample
N/A

Task 20, Analysis, Usage, and Reporting, PWS 2.3.3 Zero deviation from the PWS.

40 business days after post-award conference

No more than 5% of all activities shall not perform as established.
Monthly Sample
N/A

2.4 Objective 4, General System Functionality— The Contractor shall provide the following:

1) Comprehensive student information…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .