Attachment 2_Technical Exhibit.pdf

PDF 192 KB Posted

Attached to
FTC TETRIX Education Robotics Support Federal contract opportunity
Solicitation number
HE125425QE059
Issued by
Department of Defense Education Activity

About this file

This Technical Exhibit details rigorous technical requirements for a Department of Defense Education Activity (DoDEA) education technology contract, specifically focusing on software, cloud services, cybersecurity, and system integration standards. The document outlines comprehensive requirements including:

Key technical specifications mandate FedRAMP Level 2 compliance, compatibility with Windows 11 and Chrome/Edge browsers, minimum hardware specifications (4GB RAM, 100GB storage), and robust data management capabilities. Cybersecurity requirements are extensive, including compliance with DoD cybersecurity directives, providing security patches within five business days, protecting against cyberattacks, implementing single sign-on capabilities, ensuring US-based data centers, encrypting data in transit and at rest, and mandating that all contractor personnel accessing data be US citizens. The contractor must support industry-standard data rostering, provide automated user account creation, support secure data integration using REST APIs or SFTP, and maintain comprehensive data protection and backup protocols.

View the file

Other files for this federal contract opportunity

Other files attached to FTC TETRIX Education Robotics Support, newest first.
File Type Posted
25QE059 AMD1_Attachment 5 - JA_Brandname_TETRIX Robotics_Redacted.pdf PDF
25QE059_AMD1_REV_Att3_IDIQ Items List.xlsx XLSX spreadsheet
25QE059 AMD1_Attachment 4_QA.pdf PDF
25QE059 AMD1_SF30_2025.07.23.pdf PDF
Solicitation - HE125425QE059.pdf PDF
Attachment 1_PWS.pdf PDF
Attachment 3_IDIQ Items List.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HE125425QE059_Attachment 2

Technical Exhibit - TECHNICAL REQUIREMENTS

The Contractor shall comply with the applicable technical requirements detailed below.

1.1 Software and Cloud Security Requirements—The Contractor shall:

1.1.1 Ensure all online resources, cloud-based services and instructional software meet Department of

Defense (DoD) and DoDEA cybersecurity requirements as defined below. Note: Software, cloud services and associated websites are rigorously tested to ensure no security risks are posed to DoDEA infrastructure and its users.

1.1.2 Complete the Cloud Services questionnaire that was submitted as part of the proposal submission and provide copies of and/or access to any software listed in the proposed solution.

1.1.3 Ensure its content accessible from the web is compatible with the following browser platforms:

Google Chrome, and Edge. Ensure that any applicable STIGs are implemented.

1.1.4 Provide a plan of actions and milestones (POA&M) to mitigate any cybersecurity findings resulting from non-compliant and/or vulnerable components in 30 calendar days of written notification from DoDEA.

1.1.5 Be able to meet Federal Risk and Authorization Management Program (FedRAMP) Level 2 standards for all proposed software/digital resources and ensure that any third-party resources that are part of its proposed solution also meet the FedRAMP Level 2 standard. For more information on FedRAMP, see the following URL: www.fedramp.gov. Participate, if required, in interviews and deep system architecture inspections.

Per DoD policy for cloud-based services, DoDEA conducts a supplemental series of validations, which closely mirror the FedRAMP Internet Cloud vetting processes. Contractor participation/cooperation is normally required to complete this process.

On a case-by-case basis, DoDEA may honor requests to waive the FedRAMP Level 2 requirement.

1.2 System Requirements—The Contractor shall:

1.2.1 Provide, per Section 1.1 (above), any software installed and/or accessed in or by a DoDEA system, network whether stand-alone or web-based, is compatible with the standards cited herein.

1.2.2 Provide minimum desktop/server system technical specifications, reference architectures, networking specifications and diagrams, and applicable systems configuration documentation for the proposed solution.

1.2.3 Provide software that is compatible with the following minimum baseline:

Specifications Minimum Memory 4 GB

Hard Drive 100 GB

Processor Intel® Core™ i5-8365U Processor 8th Generation (up to 4.1GHz, 6MB cache) equivalent or better (Must show benchmark/passmark scores)

Video Graphics Integrated Intel HD Graphics 620 (1920x1080) equivalent or better Operating System Windows 11

Browser Environment Chrome, Edge, Edge Chromium

1.2.4 Provide software that is completely functional on a standard DoDEA desktop without the need or requirement for administrative-level user rights and/or permissions or the requirement to use or insert external media to execute the software.

1.2.5 Provide software that does not require modifications to folder permissions while executing.

1.2.6 Provide, if applicable, software packages that support unattended installation methods used by enterprise software packaging and deployment systems.

DoDEA currently distributes software packages via Microsoft’s System Center Configuration

Manager (SCCM) and Microsoft Intune.

All older 16-bit software are automatically denied.

1.3 Data Management Requirements—The Contractor shall:

1.3.1 Provide a mechanism for batch administration and automation of routine data management tasks via flat file import, or representational state transfer (REST) based web service application programming interfaces (APIs). The mechanism shall provision and manage data objects within the Contractor’s system, including but not limited to organizational structures, student accounts, staff accounts, courses, and class rosters.

1.3.2 Provide all necessary documentation and assets to facilitate batch administration and automation of routine data management tasks, including but not limited to roster template files (i.e., comma separated value templates); data element/field definitions documentation; data interchange formats and schemas (XML/ JSON); and/or data dictionaries for the purpose of mapping organizational student information system (SIS) data to the Contractor’s required input formats.

1.3.3 Provide a single point of contact to support DoDEA in performing the required data integration activities within the Contractor’s system.

1.3.4 Configure DoDEA enterprise within its system and/or databases as the appropriate organizational entity (i.e., region, district, school) upon a request in writing from the contracting officer’s representative (COR). Note: DoDEA’s organization hierarchy consists of the following: one system, three regions, nine districts, 62 communities, and 161 schools, including the K-12 virtual school programs.

1.3.5 Participate in a technical meeting with DoDEA within ten business days after award for the purposes of preparing for onboarding of new services and initial configuration of administrator-level accounts.

1.3.6 Ensure the transfer of any Sensitive, Confidential data including but not limited to PII data be transferred in a secure means meeting any requirements set by DoDEA’s Chief Information Security Officer (CISO).

1.4 DoDEA Software License Keys: The Contractor shall provide (1) license keys and electronic downloads for software required under this Contract to the COR and (2) software directly to DoDEA schools, districts, or regions only if explicitly required to do so in the contract or in writing by the COR.

1.5 Cybersecurity Supporting Elements/Requirements and Scalability—The Contractor shall:

1.5.1 Comply with the same Federal law and DoD policies and guidance to which DoDEA is subject that include but are not limited to the cybersecurity requirements defined in the following documents:

DoD Directive (DoDD) 8500.01E, Information Assurance, be found at the following URL:

https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pdf.

DoD Security Technical Implementation Guidance (STIG), which may be found at the following URL: https://public.cyber.mil/stigs/downloads/.

DoD Risk Management Framework (DODRMF) per DoD Instruction 8510.01, which may be found at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf?ver=2019- 02-26-101520-3004.5.2.

1.5.2 Provide security patches/upgrades to include third-party applications in response to public-released security vulnerabilities associated with its software solution. Provide a POA&M for any security vulnerabilities within five business days of discovery. Software upgrades/patches shall be included in the licensing cost and be performed at the least disruptive times as determined by DoDEA in writing. Note: Any exception to this requirement must be approved in advance and in writing by DoDEA’s Chief Information Officer (CIO) or designated official.

1.5.3 Protect DoDEA data against all cyberattacks, notifying DoDEA within 72 hours of an identified and confirmed breach/intrusion.

1.5.4 Perform security incident investigations upon identification of an event or at the request of DoDEA.

1.5.5 Address all information assurance vulnerability messages (IAVM) in the defined timelines to include IA vulnerability alerts (IAVA), IA vulnerability bulletins (IAVB), and technical advisories

(TA).

1.5.6 User passwords must not be readable by anyone having access to the system.

1.5.7 Ensure any portion of its solution that involves Internet access by DoDEA students complies with the relevant requirements of the Children's Internet Protection Act, Public Law 106-554, § 1(a)(4) [Div. B, Title XVII, § 1701], Dec. 21, 2000, 114 Stat. 2763, 2763A-335. All Contractor personnel that have access or may potentially have access to DoDEA data in any form shall be US citizens. Note: If its solution does not involve Internet access by DoDEA students, please ensure the following are included:

1) Maintaining system security IAW the latest versions of the (1) DoD Cloud Computing Security

Requirements Guide, (2) Family Educational Rights and Privacy Act (FERPA), and (3) Protection of Pupil Rights Amendment (PPRA).

2) Providing a solution robust enough to serve the needs of a large community of learners dispersed across the world using a variety of bandwidths and scalable to meet future growth, both in terms of instruction and the number of users. In addition, provided solutions shall be applicable to the digital learning environment of the DoDEA Virtual School.

3) Ensuring Contractor staff who have access to DoDEA’s student, teacher and/or staff personally identifiable information take the DoD Privacy Act/Personally Identifiable Information (PA and

PPI/PII) training before gaining access to the data and yearly thereafter. Provide copies of the certificates to the COR which can be audited at any time by the CISO or his/her designee.

1.6 Program and System Integration—The Contractor’s solution shall:

1.6.1 Provide Single Sign-On (SSO) Capabilities / Platform which (1) integrates with an Industry Standard

SSO login solution. (ClassLink, Google, Azure, etc.); (2) supports Oauth 2.0, Security Assertions Markup Language (SAML) for integration with Azure, or Google; and (3) authenticates using Azure Active Directory (AD) or Google AD. Authenticates using Azure Active Directory (AD) or Google

AD.

1.6.2. Support industry-standard data rostering standards via ClassLink and standard data formats such as OneRoster.

1.6.3. Ensure that data storage, handling, and security meet the following minimum standards:

1) DoDEA’s information and data shall be secured in data center located in the United States.

2) The system, including its server(s) and network devices, shall be in an environmentally controlled and secure facility under controlled circumstances (e.g., using authorized personnel access lists, ID cards, entry logs, etc.).

3) All Contractor personnel that have access or may potentially have access to DoDEA data in any form shall be US citizens, including any third-party penetration (PEN)/security testers.

4) All data transit shall be secured with Transport Layer Security (TLS) encryption.

5) All data at rest shall be secured with Advanced Encryption Standard (AES)-256 encryption.

1.6.4 Ensure that data integration includes the following:

1) Automated industry standard form of data integration using Representational State Transfer

Application Program Interface (RESTful API), Learning Tools Interoperability (LTI), or Secure File Transfer Protocol (SFTP) data sets (ClassLink, OneRoster, etc.).

2) Encryption of DoDEA’s data at rest to include unique encryption keys for each customer on systems hosting multiple customers.

3) Notification of DoDEA in writing within 72 hours of any changes made to corporate policies for data protection.

4) Use of only masked student data in a non-production environment.

5) Integration scheduling that meets DoDEA’s required timeframes.

6) Provision of fully automated data uploads per Agency schedule(s) and Agency requirements.

7) Support of SFTP capabilities using a single set of login credentials.

8) Provision of a single data set of DoDEA information. Note: The Contractor’s solution shall support DoDEA at all levels: school, community, district, region, and HQ.

9) Maintenance of a backup and restore plan for DoDEA data in the event of a disaster.

10) Provision of detailed feedback of what caused errors if an integration transmission results in errors.

1.6.5 System Features—The system shall:

1) Allow user accounts to be created automatically based on a file provided by DoDEA either nightly or on another pre-determined scheduled feed.

2) Allow DoDEA to be able to choose the format of user login identification, e.g., an email address, and be able to create manual accounts, if needed.

3) Require the user—for manually created accounts—to reset the password on the user’s initial login or, upon request, a password reset.

(End of Exhibit)

File details come from the government source that posted it. Updated .