A23 - Attachment B Performance Work Statement 2.12.24.docx
DOCX document 129 KB Posted
- Attached to
- Travel Pay System Federal contract opportunity
- Solicitation number
- HQ042323R0010
- Issued by
- Office of the Secretary of Defense
About this file
This performance work statement (PWS) outlines requirements for an end-to-end technological solution for processing federal travel entitlements and payments for the Department of Defense. The Defense Finance and Accounting Service seeks a solution capable of receiving, computing, and transmitting travel vouchers and supporting documentation for various types of military and civilian travel. The PWS specifies required functionality for voucher processing, accounting and disbursing, reporting, forms and reports generation, interfaces, architecture configuration, security configuration, system internal controls, and deliverables. The period of performance is estimated at a six-month base period and five one-year option periods, with an estimated start date of October 2024. The PWS also outlines quality, program support, locations and travel support, training, and labor category requirements for the contract.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A24 DFAS Travel Pay Questions 2-13-2024.docx | DOCX document | |
| Combined Synopsis- RPF Revised.docx | DOCX document | |
| A23 - Attachment C Pricing Travel Pay 2.9.24.xlsx | XLSX spreadsheet | |
| A24 DFAS Travel Pay Questions 2-9-2024.docx | DOCX document | |
| A23 - Attachment A RFP Instructions and Evaluation 2.13.24.docx | DOCX document | |
| Synopsis.docx | DOCX document | |
| A23 - Attachment A RFP Instructions and Evaluation.docx | DOCX document | |
| A23 - Attachment C Pricing Travel Pay 1.23.24.xlsx | XLSX spreadsheet | |
| A23 - Attachment D Travel Pay DD Form 254.docx | DOCX document | |
| A23 - Attachment E Past Performance Questionaire.doc | DOC document | |
| A23 - Attachment B Performance Work Statement.docx | DOCX document |
Show all 11
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement (PWS) for Travel Pay Processing System
January 4, 2023
Table of Contents
| 1. | Introduction | 3 |
| 2. | Scope | 4 |
| 3. | Governance | 4 |
| 4. | Task 1 – Commercial Technological Solution | 5 |
| 5. | Task 2 – Product Support | 13 |
| 6. | Task 3 – Program Support | 19 |
| 7. | Task 4 - Locations and Travel | 22 |
| 8. | Deliverables | 23 |
| 9. | Quality | 25 |
| 10. | Government Furnished Property/Equipment/Material | 29 |
| 11. | Supplementary Engagement Notices | 30 |
| 12. | Security Requirements | 31 |
| 13. | Installation Entry and Common Access Card (CAC) Requirements | 35 |
| 14. | Training | 35 |
| 15. | Labor Category Descriptions | 38 |
1. Introduction
1.1. Purpose. Defense Finance and Accounting Service (DFAS) seeks an end-to-end technological solution for processing federal travel entitlements and payments. DFAS seeks a solution, which includes, at a minimum, receiving, computing, and transmitting travel vouchers within the travel claim package for military (Active, Reserve, and Guard) and civilian permanent change of station (PCS)/permanent duty travel (PDT), Relocation Income Tax Allowance (RITA), personally procured moves (PPM), temporary change of station (TCS), contingency operations, evacuation entitlements, 1164 local travel, Extended TDY Tax Reimbursement Allowance (ETTRA), casualty/Wounded Warrior travel, funeral travel, invitational travel, and temporary duty (TDY) for the Department of Defense (DoD). Within this document, the travel operations noted above, hereinafter, will be collectively referred to as “PCS/TDY travel.” Vouchers, receipts, and supporting documentation, to include required forms, will collectively be referred to as a “travel claim package”.
1.2. Background. In the mid-1990s, DFAS Indianapolis was selected as the travel pay processing system project management office (PMO) for the DoD Services and Agencies. Services and agencies relying on DFAS for travel pay processing solutions include: DFAS (U.S. Army and Defense Agencies), the U.S. Navy, the U.S. Marine Corps, and the Army Corps of Engineers. DFAS fulfills the responsibilities of the PMO by providing processing software, coordinating and testing system change requests, deploying and implementing software releases, and manning a technical help desk to provide tier 1 support to DFAS customers (Tier 1 support is provided internally by DFAS and is not incorporated into this PWS). Tier 2 support is to be provided by the software vendor and identified in section 6.2 of this PWS.
1.3. Objective. DFAS is looking for the optimal technological solution to process travel entitlements completely, accurately, and timely for DoD travelers or those traveling on behalf of DoD. The desired technological solution must possess the capability to accept both manual data entry and interfaced data (i.e. flat files, XML files, or other system-to-system transfers), compute travel vouchers based on entitlements including applicable federal and state taxes, provide pre- and post-audits of travel claims, enact debt management, and certify payment through an electronic acknowledgement in accordance with federal regulations. The system must produce monthly, quarterly, annual, and ad-hoc federal and state tax statements and reports, employer contribution reports, wage report forms, and social security forms and reports.
The DoD continues to focus on efficiencies in the travel claim entitlement process as seeks to improve auditability and increase work force productivity by ensuring complete, accurate, and timely travel payments and accurate accounting of expenditures. The travel processing solution shall be capable of addressing the travel pay process from entitlement calculations, production of the voucher, system reporting, plus interfacing with automated tools, data repositories, and disbursing systems.
The comprehensive solution must conform to all laws, policies, and regulations as well as security technical implementation guides, manuals, and audit methodology. Product functionality, to include system internal controls, and architecture must comply with DFAS infrastructure requirements meeting the risk management framework doctrine to operate on a DoD network.
1.4. Contract Type. The contract type is firm-fixed price with T&M reimbursable for travel.
1.5. Period of Performance. The Period of Performance will be determined at time of award based on successful contractor’s development and implementation plan presented in the proposal. Estimated Period of Performance is below.
Estimates are:
A six (6) month base period, four (4) one-year options and one (1) six (6) month option period for a total of five (5) years as follows:
Base Period - 10/4/2024 – 3/31/2025 (Estimated development/testing phase) Option Period 1 - 4/1/2025 – 3/31/2026 Option Period 2 - 4/1/2026 – 3/31/2027 Option Period 3 - 4/1/2027 – 3/31/2028 Option Period 4 - 4/1/2028 – 3/31/2029 Option Period 5 - 4/1/2029 – 09/30/2029
*Base award date is estimated and subject to change. All option periods will follow the base award.
The eventual contract will include FAR Clause 52.217-8, Option to extend services for up to an additional six (6) months.
2. Scope
2.1. Scope. DFAS seeks an end-to-end commercial technological solution for processing federal travel entitlements and payments with the ability to customize technology specific to DoD requirements and the travel pay mission. The number of annual transactions range between 95,000 to 100,000 TDY transactions and 300,000 to upwards of 550,000 PCS transactions, which includes the orders, vouchers, and all supporting documentation (e.g. electronically scanned and stored orders, forms, and receipts in a variety of file formats such as PDF or JPEG).
3. Governance
3.1. Travel Legislation, Policies, Regulations, and Instructions. DoD Travel utilizes, but is not limited to, the following legislation, polices, regulations, and instructions:
· Federal Travel Regulation (FTR)
· Joint Travel Regulations (JTR)
· Department of Defense Financial Management Regulation 7000.14 R (DoDFMR)
· Code of Federal Regulations (CFR)
· Defense Transportation Regulations (DTR)
· DoD Instruction 5154.31 – Defense Travel System (DTS)
· Government Travel Charge Card (GTCC) Regulation
· Travel and Transportation Reform Act of 1998
· DFAS-IN Regulation 37-1 Finance and Accounting, Chapter 10: “Travel and Transportation Allowances.”
The contractor is responsible to ensure the end-to-end solution is compliant with all the above legislation, policies, regulations, and instructions.
3.2. Cyber Legislation, Policies, Regulations, and Instructions. DoD cyber laws, policies, regulations, and instructions include, but are not limited to:
· Federal Financial Management Improvement Act of 1996 (FFMIA)
· Federal Information Security Management Act of 2002 (FISMA)
· Financial Information System Control Audit Manual (FISCAM)
· Department of Defense Instruction (DoDI) 8500.01 Cybersecurity
· DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology
· DoDI 8520.02 Public Key Infrastructure (PKI) and Public Key securitEnabling (PKE)
· DoDI 8520.03 Identity Authentication for Information Systems
· DoDI 8580.1 Information Assurance (IA) in the Defense Acquisition System
· National Institute of Standards and Technology (NIST) SP 800-39 Managing Information Security Risk NIST SP 800- 53, Rev. 4 Security and Privacy Controls for Federal Information Systems and Organizations
· Committee on National Security Systems Instruction (CNSSI) 1253 Security Categorization and Control Selection for National Security Systems
· CNSSI 4009 Committee on National Security Systems Glossary
· Federal Information Processing Standards (FIPS) 201-2 Personal Identify Verification of Federal Employees and Contractors
· FIPS 140-2 Security Requirements for Cryptographic Modules
· Directive-Type Memorandum (DTM) 08-006 DoD Implementation of Homeland Security Presidential Directive – 12 (HPSD-12)
· Applicable Security Technical Implementation Guides (STIGs) as noted by the System Manager (SM)
The contractor is responsible to ensure the end-to-end solution is compliant with all the above laws, policies, regulations and instructions.
4. Task 1 – Commercial Technological Solution DFAS seeks an end-to-end commercial technological solution for processing federal travel entitlements and payments with the ability to customize technology specific to DoD requirements and the travel pay mission. The following sub-tasks address the minimum business requirements and product standards.
4.1 Voucher.
Create and compute travel vouchers for military and civilian PCS/TDY according to federal travel laws and regulations. As required by federal tax regulation, create and compute tax reimbursement vouchers as necessitated within travel claim packages.
4.1.1 Provide the ability to accept interfaced data from DFAS-approved travel authorization systems to prepopulate vouchers.
4.1.2 Accept uploaded receipts, user notes, and other supporting documentation in a variety of file formats, such as PDF or JPEG. Required receipts are specified in the travel regulations.
4.1.3 Provide the ability to accept and import interfaced data in a standardized format (web service, flat file, direct insert, or manual file) from SM approved and authorized Government- owned travel voucher systems to automatically submit the voucher and travel claim package through the software.
4.1.4 Route the travel claim package submitted by PCS/TDY travelers through appropriate review, approval, auditing, and payment per the referenced travel pay legislation, polices, regulations, and instructions. Ability to allow/disallow assignment based on given data element (i.e. travel office, claim type, etc.) for a designed user group with specific processing attributes, roles, or privileges.
4.1.5 Calculate the travel entitlements per the legislation, polices, regulations, and instructions, authorization, and voucher for PCS/TDY travel.
4.1.5.1 Permit the submission of voucher adjustments to include supplements, partial payments, and advances. The solution shall make adjustments and recalculate the travel claim package accordingly. Voucher adjustments are automatically resubmitted for appropriate review, approval, auditing, and payment status.
4.1.6 Calculates federal and state taxes, as appropriate, for travelers and provides supporting traveler and employer tax documentation. See section 4.4 for a list of documents.
4.1.7 Compute debt based on the travel claim package, including the ability to process cash collection voucher (CCV), and adjust the debt accordingly to include tax implications on the computed debt. Use any debt, offset calculation, refunds, or subsequent CCV to amend the traveler’s documentation systematically.
4.1.8 Utilize the Defense Table of Official Distances (DTOD) to automatically populate distances between two points within the voucher and use that distance for mileage computations when appropriate.
4.1.9 As required, calculate late interest due to the traveler based on the Travel and Transportation Reform Act of 1998.
4.1.10 Interface with DFAS owned software, such as SmartVoucher, to accept data from Services members submitting a 1351-2 (Travel Voucher).
4.2 Repository, Accounting, and Disbursing. Process accounting functions such as multiple lines of accounting and negative lines of accounting. Provide data elements for disbursing systems to release electronic funds transfer to validated traveler bank accounts. The solution must be Standard Financial Information Structure (SFIS) compliant (DoD7000.14-R, DoDFMR Volume, Chapter 4) and Standard Line of Accounting (SLOA) compliant.
4.2.1 Utilize standardized SM approved and authorized interface formats to transmit and receive data from repository and disbursing systems. Provides flexibility to manipulate standardized formats to meet unique customer requirements.
4.2.2 Produce data files to interface with disbursing, data repository systems and Enterprise Resource Planning (ERP) systems as well as specific interfaces referenced in section 4.5. Coordinate with receiving systems file parameters, fields, headers, and footers, as well as acceptance of data returning to the product.
4.2.3 Produce data files to interface with the Internal Revenue Service, Social Security Administration, other federal agencies, and state revenue offices as required.
4.2.4 Create monthly, quarterly, annual, and ad-hoc logs for/with interfacing systems.
4.2.5 Provide integrated flexibility to temporarily alter electronic funds transfer (EFT) disbursement to check, debit, and/or cash in the event of an emergency.
4.3 Reporting. Produce reports and logs needed for tracking, monitoring, and alerting management for additional action(s).
4.3.1 Produce reports and logs for data management to include, but not limited to, transactional data, error logs or duplicative payments, reworked travel claim packages, debts incurred, system access, aging uncompleted transactions, quantities of transactions based on a specific data element, and end user accountability. Reports and logs are required to be exportable into common formats (e.g. text, Microsoft Excel, PDF). Solution must allow the ability to query and export ad hoc data for reporting.
4.3.2 Store software data, attributes, and artifacts in a central repository within a relational database and support live updates.
4.3.3. As required, DFAS can execute scripts/queries against the travel databases to extract data for Government use.
4.4 Forms and Reports. Populate and produce, at a minimum, the following forms and reports with cumulative data stored within the solution:
· DD 1351-2 Travel Voucher
· DD 1351-2C Travel Voucher Continuation
· DD 1351-3 Statement of Actual Expense
· DFAS Form 9114 PCS and TDY En Route Travel Advance Request
· DFAS Form 9098 Claim for Temporary Lodging Expense
· DFAS-CO Form 62 Employee Repayment Form (WTA Form)
· SF1199A Direct Deposit Form
· Wage and Tax Statement (W2)
· Corrected Wage and Tax Statement (W2-C)
· Employer’s Quarterly Federal Tax Return or Claim for Refund (941)
· Adjusted Employer’s Quarterly Federal Tax Return or Claim for Refund (941-X)
· Transmitter Report of Magnetic Media Filing, Form (6559)
· State tax reports and forms required for state tax reconciliations and deposits
· Local travel (SF 1164)
4.5 Interfaces. Transmit and receive data from interfacing systems through web service, flat files, direct insert (Java Database Connectivity or Open Database Connectivity), and manual file upload in order to receive and send data timely. Systems include data repositories, disbursing systems, debt management systems, vendor pay systems, travel order writing systems, and tax management systems such as DFAS’ SmartVoucher tool, Operational Data Store (ODS), Deployable Disbursing System (DDS), and the Automated Disbursing System (ADS); and DoD systems such as Marine Corp Total Force System (MCTFS), Army Corp of Engineers Financial Management System (CEFMS), Defense Table of Official Distances (DTOD), Multi-host Internet Access Portal (MIAP), Universe of Transactions (Advana), Online Payment Status Tool-Travel (OPST-T), goDocs, myPAY, Master Pin Database, and Defense Manpower Data Center (DMDC). Data transmission recipients may increase or decrease in the dynamic business environment. The Contractor shall be responsible for supporting any data integration and standardization to include Department of the Treasury and the Office of the Under Secretary of Defense Treasury Disbursing and Collections Initiative (Treasury Direct Disbursing).
4.5.1 The Contractor shall provide specifications and collaborative guidance in developing an Interface Strategy Plan, which incorporates the following elements: interface design and architecture, the name of the interfacing system, type of interface, data transmitted, frequency of transmission, file format and parameters, file elements and description, error handling, and security of the file.
4.6 Architecture Configuration. The Contractor shall ensure that the solution is deployed under the below architecture guidance.
4.6.1 Software configuration requirements include the ability to support all of the following scenarios:
1. Stand-alone personal computer non network connected without internet access (that can connect and transfer data when connectivity is restored)
2. Stand-alone personal computer non network connected with internet access (that can connect and transfer data when connectivity is restored)
3. A stand-alone computer within a secured enclave
4. A computer networked via a mid-tier client-server relationship hosted on single server and/or multiple servers.
5. A web application using Internet Information Services (IIS) or Tomcat.
6. Cloud or on-premise server hosted. It should be able to work in any cloud environment and specifically in DFAS Blue Cloud Environment.
4.6.2 The software shall be hosted on-premises or in a cloud hosting environment and support all the configurations noted in 4.6.1. On-premise include within DFAS, Defense Information Systems Agency (DISA), and other DoD installations. Commercial Cloud Service Providers (CCSP) architecture, or Software-as-a-Service, is not authorized.
4.6.3 The standard DFAS stand-alone computer (i.e. desktop or laptop) is currently configured with a Windows 10 Operating System (OS). In the event of a Microsoft OS upgrade, the software shall conform to the DFAS desktop/laptop configuration prior to any subsequent OS upgrades and be tested to ensure compatibility.
4.6.4 Software shall utilize a mid-tier web server to provide web-based access using Apache, Oracle, or Microsoft web middleware software, Azure Web App, or similar cloud-based environment approved by DFAS. Web application software variations require SM and/or Information System Security Manager approval (ISSM).
4.6.5 The software shall function on Microsoft SQL Server 2019 or newer database, Oracle 19C or newer, or type pending government acceptance. DFAS will confirm current version or patch number upon contract award.
4.6.5.1 In the event historical or current data requires conversion or migration the Contractor shall develop an action plan, timeline and code/scripts for conversion or migration to a new structure.
4.6.6 Solution provides predefined and customizable user roles and privileges for toolset access.
4.6.7 Access control is granular with roles to restrict and prevent unauthorized/unneeded access. Access control logs/reports are required to monitor activity.
4.6.8 Due to travel pay processing and the mandated use of DFAS accounting and disbursing systems, as well as other input systems, the software must be able to receive and send interfaces and data through flat files, web services, or other necessary means.
4.6.9 Due to the nature of data processed with the software, the solution shall provide masking of Personally Identifiable Information (PII) to protect the privacy of travelers. Heightened user roles and privileges shall determine concealment and availability of PII, authorized by the SM.
4.7 Security Configuration. Cybersecurity remains the top priority. The Contractor shall ensure the software holds encryption capabilities as well as database encryption to include data in transit and at rest.
4.7.1 The software must be able to run on DFAS Enterprise LAN (ELAN), DFAS Blue Cloud Environment (DBCE) or DoD networks in compliance with DoD Risk Management Framework (RMF) security controls and DISA Security Technical Implementation Guides (STIGs). The Contractor shall ensure the software is configured to avoid any CAT 1-3 STIG violations. The Contractor may request in writing to the DFAS Contracting Officer a waiver to any STIG violation. Waivers for CAT 1 violations will not be granted. The inability to acquire a proper Authority to Operate (ATO) due to failed application security controls or application development STIGs will be considered a breach of the contract, allowing DFAS, at its discretion, to take appropriate next steps up to and including terminating the contract.
4.7.2 The software access to the solution toolset or resulting reports/analytics is required utilizing the smart card / Common Access Card (CAC) and Public Key Infrastructure (PKI) security controls and guidance described in the following items:
· FIPS 140-2 Security Requirements for Cryptographic Modules RFC 5280 Internet X.509 Public Key Infrastructure
· Department of Defense Instruction 8520.02 Public Key Infrastructure (PKI) and Public Key Enabling (PKE)
· Department of Defense Instruction 8520.03 Identity Authentication for Information Systems
· Directive-Type Memorandum (DTM) 08-006 – “DoD Implementation of Homeland Security Presidential Directive - 12 (HSPD-12)”
4.7.3 The software as integrated in the DoD environment must include the following identification and authentication requirements:
· Smart-Card / Common Access Card logon/authentication, which is standard for all DoD systems, including Smart-Card/Common Access Card that provides multi-factor authentication, the sole means to log into an application. Users shall not be prompted to enter a password, and certificate credential information has to be passed in an encrypted format.
· Role or identity-based authentication, including: users are only given access that they are approved for (ability to manage roles), and authentication must trigger an immediate certificate validation and revocation check (must use Online Certificate Status Protocol (OCSP) with alternate of Certificate Revocation Lists (CRL) cache in the event OCSP server is offline). DFAS is moving towards DoD’s mandate to authenticate via Global Federated User Domain (GFUD) and the software will need to be compliant with all mandates once full rollout is complete (date TBD). Software must be compatible with Lightweight Directory Access Protocol (LDAP). Application shall allow the user to use the same credentials to logon to the application as they use to gain entry to the local area network.
4.7.4 Authentication is accomplished through use of a common identification smart-card for federal employees such as, but not limited to, the DoD Common Access Card (CAC), a personal identity verification (PIV) card and Global Federated User Domain (GFUD).
4.7.5 The software’s cryptographic hash and protocol compatibility shall include:
· Minimum SHA256 compatible (on-going secure hash algorithm (SHA) compatibility shall be required to ensure continued functionality as SHA standards advance).
· Minimum of transport layer security (TLS) 1.2 communication and support for digitally signed validation requests/responses for non-repudiation.
· Ability to support leading vendor cryptographic hardware, including Federal Information Processing Standards (FIPS) 140-2 to accelerate digital signing and secure sockets layer (SSL)/TLS operations.
4.7.6 The contractor shall apply security engineering principles to system upgrades and modifications to the extent feasible and provide documentation describing measures in place. Security engineering principles may include, but not limited to:
· Developing layered protections
· Establishing sound security policy, architecture, and controls as the foundation for design
· Incorporating security requirements into the system development life cycle
· Delineating physical and logical security boundaries
· Ensuring that system developers are trained on how to build secure software
· Tailoring security controls to meet organizational and operational needs
· Performing threat modeling to identify use cases, threat agents, attack vectors, and attack patterns as well as compensating controls and design patterns needed to mitigate risk
· Reducing risk to acceptable levels, thus enabling informed risk management decisions
4.8 System Internal Controls. Travel pay processing solution must comply with system internal control legislation, polices, regulations, and instructions. Areas of consideration include: system security, access controls, configuration management, and segregation of duties, contingency plans, business controls, and interfacing systems.
4.8.1 The solution shall contain built-in controls inherent to the product. Internal controls and reporting provide the necessary artifacts for compliance audits, financial audits, systems audits, investigative audits, operational audits, and tax audits. These controls should be documented and provided to the SM for audit purposes.
4.8.2 The Contractor shall plan, design, develop, test, deploy, and sustain system controls and business standards in accordance with the following compliance: Federal Information Security Management Act (FISMA), Financial Information System Control Audit Manual (FISCAM), Risk Management Framework (RMF), Committee on National Security Systems (CNSS), National Institute of Standards and Technology (NIST), and Department of Defense (DoD) Cybersecurity legislation, polices, regulations, instructions, guidance, standards, and Security Technical Implementation Guides (STIGs). The system shall comply with the most recent versions, amendments, or addendums of the statutory and regulatory policy, guidance, or standards.
4.8.3 The Contractor shall provide artifacts that validate the product’s internal controls or compliance with the legislation, polices, regulations, instructions, guidance, and standards above. Artifacts shall include screen shots, system documentation, software test, and small extracts of code. The Contractor shall provide evidence as requested by the SM or ISSM in support of the auditor’s request for substantiating evidence.
5. Task 2 – Product Support
5.1 Installation Support. The Contractor shall provide support during installation, implementation of the product, and during exercised option periods.
5.1.1 Installation support includes, but not limited to:
· Guide DFAS and DoD partners through the installation, patching, and upgrade to the most current secure software version, and standard configuration in the DFAS or DoD environment.
· Ensure that the software operates fully within DFAS or DoD environment and in compliance with all DoD security controls which includes and are not limited to CNSS, NIST, FISCAM, RMF, STIGs, etc.
· Assist with design, implementation, and testing of backup, recovery, and disaster recovery of software and repository data.
· Verify that all core software functions operate correctly and without errors to include starting and stopping the software and accessing all core components of the product.
· Verify and confirm activated and deactivated functionality as required by mission demands.
· Provide any necessary installation programs within the software release package/file to execute the software onto the network and be included in the software release package/file.
5.1.2 Configuration support includes, but not limited to:
· Provide post-configuration professional services support to assist with creation of business rules, best practices, and creation of artifacts (such as a user manual, help functions, etc.) based on DFAS and DoD requirements.
· Verify that all core software functions operates correctly and without errors. Verify new functionality added via configuration support works correctly and without errors.
5.2 Product Changes. Provide for mandated rule changes, system change requests, software error correction, and database recovery/conversions. Deliverables include, but are not limited to, test discrepancy reports (TDR), program trouble reports (PTR), system change requests (SCRs), and software enhancements or modifications.
5.2.1 The Contractor shall incorporate mandated rule/policy changes and system improvements, based on requirements provided by and approved by the SM.
5.2.2 The Contractor shall incorporate system changes as required by the Government and defined in SCRs communicated and approved by the SM.
5.2.3 The Contractor shall correct software errors found by Government users and the Contractor that are approved for correction by the SM. Emergency errors, requiring an immediate field updates, will be determined by the Government. If a software error is determined to be a non- emergency by the Government, the error resolution shall begin and be scheduled for completion in a reasonable timeframe. All changes and corrections, emergency or otherwise, must be approved by the SM and/or ISSM.
5.2.4 Contractor shall program approved SCRs based on requirement(s) provided by the SM, in consultation with the Contractor, to ensure the intent of the change is fully satisfied. The Contractor shall document changes based on Government’s configuration management criteria. The Government follows the agile methodology for releases when determining the rate and efficiency of software changes. The Government will take into account the number and magnitude of potential changes and the rate at which they are released into production. Contractor must obtain DFAS approval for any release that waterfall methodology will be used instead of Agile.
5.2.5 The Contractor shall deliver to the SM at least one copy of the software for any system change. Delivery media shall include File Transfer Protocol (FTP) or CD-ROM in executable form. Unless otherwise instructed, deliverables shall be provided to the SM for release to DoD licensed users. The Government will track and monitor DoD-licensed users and provide updates to the Contractor. In the event a DoD-licensed users requires a CD-ROM, the Contractor shall be instructed by the SM to create a CD-ROM and deliver the licensed user a copy of the software through the appropriate channels. The Contractor shall not provide deliverables to any DFAS customer without explicit direction from the SM.
5.2.6 The Contractor shall support the use of DFAS automated configuration management tools and templates for tracking software changes, as well as utilize standard industry practices for version nomenclature. Contractor shall identify, document, manage and control the integrity of changes to Configuration Items (CI), and provide the list of Configuration Items to the SM. Any potential security impacts will be identified by the contractor and managed with the SM and ISSM. All security flaws and their resolutions will be reported to the SM and ISSM, as well as tracked and managed by the contractor in conjunction with the SM and ISSM.
5.2.7 The Contractor shall use Development tools that allow for release incremental implementation similar to an Agile approach unless the waterfall approach is requested/approved by DFAS. This will include programming the DFAS requested number of SCRs per iteration of the release build(s), branching the code to send DFAS the specified number of changes while the Contractor continues to program and test additional changes.
5.3 Database Structure and Maintenance. The Contractor shall provide design, support, changes, maintenance, and archiving of the database structure.
5.3.1 The Contractor shall assist the Government staff to recover lost or damaged user databases, database updates, conversions, or upgrades. Assistance may consist of technical advice as well as programming, and may be on-site, telephonic, or through other electronic communication means.
5.3.2 In the event historical data requires conversion, the Contractor shall develop an action plan, timeline and code/scripts for conversion to a new structure.
5.3.3 The Contractor shall deliver to the SM at least one copy of the database change for any update. Delivery media shall include File Transfer Protocol (FTP) or CD-ROM in executable form. Unless otherwise instructed, deliverables shall be provided to the SM for release to DoD IATS users. The Government will track and monitor DoD IATS users and provide updates to the Contractor. In the event an IATS user requires a CD-ROM, the Contractor shall be instructed by the SM to create a CD-ROM and deliver to the user a copy of the database schema through the appropriate channels. The Contractor shall not provide deliverables to any DFAS customer without explicit direction from the SM.
5.3.4 The contractor shall deliver to the SM a data dictionary that is updated with each release.
5.4 Software Testing. Provide quality software through multi-phased software testing. Deliverables include, but are not limited to, software enhancements or modifications, software releases, and software testing documentation.
5.4.1 The Contractor shall perform unit testing of the software prior to delivery of the software to the Government. Unit tests shall have screenshots of the proof of test and/or steps outlined describing the action taken to get the given results.
5.4.2 The Contractor shall aid in installation of new software version, a modified database configuration, or a new/modified interface file into an onsite test environment for initial testing on the DoD network.
5.4.3 The Contractor shall participate in Software Integration Test (SIT), and Software Acceptance Tests (SAT) as requested by the Government. Advance notice of scheduled dates and sites will be provided by the SM.
5.4.3.1 The Contractor shall have a similar environment that DFAS has to test the changes on. The data will not be the same but the software supporting the application should be similar.
5.4.4 The Contractor shall provide samples of automated computation results and for legislative rule changes implemented as part of system enhancements. The Government will provide the Contractor with documentation for newly legislated rules including sample manual computations showing expected results under various scenarios expected by the Government reconciling with the Contractor’s automated computation results and legislative rule changes.
5.4.5 Contractor shall perform penetration testing to uncover potential vulnerabilities in the information system resulting from implementation errors, configuration faults, or other operational deployment weaknesses or deficiencies. Testing can include, for example, white, gray, or black box testing to attempt circumventing security features of the system. Testing should be completed with each regularly scheduled release in a controlled environment to simulate and execute adversary actions and in conjunction with any automated and manual code reviews. Testing includes but is not limited to testing of open-ended fields for cross scripting (example SQL injection) and testing of all roles within system to ensure only the defined permissions are presented for each role. Contractor shall provide the test plans and results with the first delivery of the product release to ensure DFAS of the product’s security prior to installing on the DFAS network.
5.5 Software Maintenance. Maintain product configuration and integrity ensuring product performs as required.
5.5.1 The Contractor shall ensure that such software maintenance:
· Enables the software installed to continue to perform as intended.
· Modifies the software while preserving its integrity.
· Includes improvements, implementation, migration, and related activities.
· Addresses defects.
· Improves reliability, performance, or other attributes.
· Addresses security vulnerabilities.
· Enables the solution to run in a DoD environment.
· Diagnoses and corrects latent errors in the code, including fixes to new or preexisting security vulnerabilities.
· Modifies software to improve its functionality or maintainability.
5.5.2 The Contractor shall ensure that software maintenance includes security patches throughout the performance of the contract to include all patches required prior to the start of this contract.
5.5.3 The Contractor shall provide at least one set of maintenance upgrades or patches per year, and no less often than is necessary to adequately ensure the software provides the capabilities above.
5.6 Rates and Updates. The Contractor shall provide systems software releases and rate updates to the SM for use with the solution.
5.6.1 Provide rate updates, including but not limited to, per diem, mileage, lodging (e.g. Integrated Lodging Program), BAH, dislocation allowance, and tax rate update to the Government in a format usable by the software to process travel computations on compatible equipment used by authorized users.
5.7 Documentation and Manuals. The contractor shall provide quality user manuals and help screens that are integrated with the software and that accurately depict system operation. Authorized users shall have access to: software, user manuals, help screens, training materials, screen shots, database definitions and schemas. The SM will track authorized licensed users as stated above. Deliverables include, but are not limited to: software release milestones, user manuals, help screens, training materials, a data dictionary, database definitions and schemas.
5.7.1 The Contractor shall maintain and provide user manuals and an online help screen that documents system operation to include procedures and computation for any and all changes.
5.7.2 The Contractor shall provide user manuals in electronic format and help screens integrated within the software. The contractor shall provide a list of all new or documented changes to help topics.
5.7.3 The Contractor shall document in writing to the SM which PTRs, TDRs, and SCRs are included in any software update of software release. This documentation should also include relevant corresponding screenshots and/or proof of test for PTRs, TDRs and SCRs as well as root cause analysis of PTRs to determine underlying functions that may be affected by changes.
5.7.4 The Contractor shall provide installation procedures for any software or databases update to the SM.
5.7.5 The Contractor shall also be required to participate in and aid in the document creation of solution architecture reviews, testing, acceptance meetings, and software audits.
5.7.6 Configuration Management Plan. The contractor shall provide documentation proving it performs configuration management during system, component or service design, and development. The configuration management process applies to:
1. Documentation developed or used in the lifecycle, including requirements and interface specifications
2. Elements including design libraries
3. Tools including design tools and test tools
4. Technical data including test data;
5. Information on element and system lifecycle processes
5.7.7 Development Tools Documentation. DFAS SM and ISSM will review the development process, standards, tools, and tool options/configurations before first use and annually thereafter to ensure those selected and employed satisfy security requirements. Contractor must follow a documented development process that:
1. Explicitly addresses security requirements
2. Identifies the standards and tools used in the development process
3. Documents the specific tool options and tool configurations used in the development process
4. Documents, manages, and ensures the integrity of changes to the process and/or tools used in development
5.7.8 Security Engineering Design Documentation. The Contractor shall provide security engineering design documentation to the SM and/or ISSM.
6. Task 3 – Program Support
6.1 Product and Customer Service Support. Provide product and customer support via telephone, email, and/or on-site to designated Government staffs.
6.1.1 The Contractor shall provide real-time customer support for its product by providing a phone number and/or email address for product support issues. Response times begin when the Contractor receives a support request from DFAS. The Contractor shall respond according to the Severity Levels described below:
1. Critical
a. Any event or combination of events, which causes a 100% loss of system availability. Response shall be via telephone, e-mail, or on-site, if requested.
b. Expected response time is 30 Minutes
c. Continuous support shall be provided until issue is resolved or DFAS allows delay to the next day.
2. High
a. Any event or multiple events causing a continuous or chronic impact to service.
b. Expected response time is 2 Hours
c. Continuous support shall be provided until issue is resolved or DFAS allows delay to the next day.
3. Medium
a. Any event or multiple event indication with the potential to cause a service impact.
b. Expected response time is 4 Hours
4. Non-Service Affecting
a. A condition having no immediate impact on customer service but requiring maintenance action.
b. Expected response time is Next Business Day
6.1.2 Accept phone calls from designated Government staffs and respond in such a manner as to satisfy the requirements of the caller. Call can be for a variety of reasons including system error analysis, database analysis, operational questions, technical questions, rule interpretations (to clarify as programmed), version installation support, and network problems. Contractor personnel shall be available nine (9) hours per day (8:00 am – 5:00 pm Eastern Standard Time), five (5) days per week, Monday through Friday, excluding Government holidays:
· New Year’s Day
· Martin Luther King Jr Day
· Presidents Day
· Memorial Day
· Juneteenth
· Independence Day
· Labor Day
· Columbus Day
· Veterans Day
· Thanksgiving
· Christmas
6.1.3 Product support shall include 24/7 online access to a self-service web portal containing documentation, how-to guides, best practices, and troubleshooting check lists. Self-service portal shall allow creation of support request tickets and remote communication via email or online collaboration for lower priority issues. However, escalation for higher priority issues resulting in live support staff must be available.
6.1.4 Provide on-site assistance to a user when it is determined by the SM that the situation cannot be resolved telephonically and warrants on-site assistance for a satisfactory resolution. This task shall be performed on an as-needed basis. Unless the Contractor and SM agree that an emergency exists, the Contractor shall be notified one week in advance of travel.
6.1.5 The Contractor shall provide, within seven (7) calendar days, the appropriate documentation for each incident and summarize in an incident report. The SM will review the documentation and maintain incidents in DFAS system tracking tool.
6.2 Helpdesk. DFAS will Provide Tier 1 customer support during business hours (8:00 am – 4:00 pm Eastern Standard Time), known as the IATS helpdesk, to DFAS and off-site customers/users of IATS
6.2.1 The Contractor shall provide Tier 2 and Tier 3 support daily and troubleshoot issues from the DFAS I&T staff until resolution.
· Tier 2 help desk support entails support for product software and hardware.
· Tier 3 helpdesk support entails support to resolve issues that could not be resolved at the tier 1 or tier 2 level involving complex issues related to hardware, software and operating system issues, as well as data and database integrity issues and issues requiring a script to correct.
6.2.2 The Contractor shall provide the appropriate documentation for each incident. The SM will review the documentation and maintain incidents in DFAS system tracking tool.
6.3 Product Training and Education Support. Contractor shall provide on-site and remote product training and education covering product configuration and administration when requested.
6.3.1 The Contractor shall ensure that the software configuration and administration training and education support covers (at a minimum), how to:
· Install, patch, upgrade, configure, and maintain the software and database within the DoD environment, if needed.
· Design and functionality capabilities.
· Leverage vendor and industry best practices to more effectively utilize the toolset. Employ best practices for backup, recovery, and disaster recovery solutions.
6.3.2 The Contractor shall schedule all training, if needed, through the SM. Some, but not all, training may occur prior to the installation and configuration of the software.
6.3.3 The Contractor shall provide system documentation, articles, presentations, and manuals for training and end users.
6.4 Project Management. Contractor shall provide project management support and status updates for the duration of the contract.
6.4.1 Functionality and Design Plan. The Contractor shall provide and keep up-to-date a Functionality and Design Plan for the system that includes the inherent business mechanics of the system. The plan shall contain data calculations, data receipt and transfer, data definitions, and the data process flow within the product.
6.4.2 Upon the discussion and noted system changes within a release, the Contractor shall provide the SM a Product Release Portfolio, which includes a development plan for the release, the task associated with each SCR, a schedule including task dependencies (if any) and duration, configuration impact, any interfacing system impact, potential risk and the response strategy, a test plan and schedule, associated training plans for end users, and documents to be updated.
6.4.3 The Contractor shall submit a monthly progress report to the SM and the COR that summarizes the work completed in the monthly-period and the balance of work effort remaining in the corresponding Product Release Portfolio or Task Support Plan. At a minimum, the report shall contain, the start and end date of each completed task, estimated hours to accomplish the task, and the actual completion date of the task.
6.4.4. An in-progress review (IPR) facilitates a comprehensive communication to discuss issues and concerns by either party. An IPR can be initiated by the SM or Contractor. An IPR may be hosted by meeting in person or by telephone conference or video telephone conference.
6.5 Initial Business/ Project Kick-off Meeting. Within ten (10) workdays following the contract award date, the Contractor shall conduct a project kick-off meeting with the Government team (i.e. Contracting Officer, SM, DoD and DFAS stakeholders, and other appropriate Government personnel). The meeting shall review the goals and objectives of the contract and discuss technical requirements. The Contractor shall develop and submit to the Government for approval, at least one (1) workday in advance, an agenda for the kick-off meeting. The agenda shall include an overview of project tasks, transition issues, security requirements, audit requirements, and other logistical notes. Additionally, the Contractor shall provide the meeting minutes and action items to the Government within seven (7) workdays following the meeting.
6.5.1 Implementation Plan. Following the project kick-off meeting, the Contractor shall provide a system implementation plan identifying the action steps required to implement the system at DFAS and with the DoD customers. This plan shall include specific configurations at DFAS and external sites and within each network, actions required and deliverables for a DFAS authority to operate, a timeline of events, a schedule, resource impact, expected travel expenditures, a communication plan, identified risk, anticipated training for all users, and the planned execution of Phase 1 for parallel processing (section 9.3 Inspection and Acceptance).
6.6 Audit Preparation. In the event the travel pay mission area participates in an internal or external audit of the travel pay mission area, the SM shall provide the Contracting Officer with additional requirements for support from the contractor. The Contractor shall provide additional support after the Contracting Officer has determined the support is within the scope of this PWS. Request includes, but not limited to, system documentation, data extract scripts, ad-hoc system reports, meeting attendance, and authenticated system-verified calculations.
7. Task 4 - Locations and Travel Support the Government staff by means of travel, requested by the SM.
7.1 Performance under this contract shall require travel by Contractor personnel. When domestic (CONUS) and/or overseas travel (OCONUS) is required, the Contractor shall provide for any and all necessary travel arrangements for their personnel. All travel must be coordinated with the SM, submitted to the COR and preapproved by the Contracting Officer prior to travel. Travel costs incurred by contractor personnel on official company business are subject to the limitations outlined in FAR Subpart 31.205-46 Travel Costs and 31.201-3, Determining Reasonableness. Typically, costs are considered reasonable if these costs do not exceed the maximum rates outlined within the Federal Travel Regulations (FTR), Joint Travel Regulations (JTR), and the Standardized Regulation (SR). In addition, costs may be determined reasonable by the Contract Officer, if, in its nature and amount, it does not exceed that which would be incurred by a prudent person in the conduct of competitive business. Any local travel performed by the Contractor during performance shall be considered the cost of doing business and is not eligible for cost reimbursement. Contractor personnel shall not be reimbursed for the cost of passports required for OCONUS travel. Application of general and administrative costs to any travel cost reimbursement requests is prohibited.
7.2 Private Automobile. The use of privately owned conveyance within the continental United States by the traveler will be reimbursed to the Contractor at the mileage rate permitted in accordance with the FTR/JTR/SR and in accordance with FAR Subpart 31.205-46. Authorization for the use of privately owned conveyance shall be requested with travel authorizations submitted to the COR and be pre-approved by the Contracting Officer. Distances between travel locations shall be documented in standard highway mileage guides that could easily be replicated for confirmation. Deviations from distances shown in such standard mileage guides shall be sufficiently documented by the traveler on expense report submissions.
7.3 Car Rental. The Contractor shall be eligible for reimbursement of car rental expenses, exclusive of mileage charges, as authorized when the services are required to be performed outside the normal commuting distance from the Contractor's facilities. Car rental shall be limited to the reasonableness criteria set forth at FAR Subpart 31.201-3.
8. Deliverables
8.1 The Contractor shall prepare and submit the deliverables as identified…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .