O__M_-_DRAFT_SOW_09102014.pdf

PDF 167 KB Posted

Attached to
FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
Solicitation number
HSFE30-15-S-0001
Issued by
Federal Emergency Management Agency Mitigation Section

View the file

Other files for this federal contract opportunity

Other files attached to FEMA INFORMATION TECHNOLOGY INDUSTRY DAY, newest first.
File Type Posted
FBO15.pdf PDF
FBO13_(002).pdf PDF
FBO12.pdf PDF
FBO11.pdf PDF
FBO10.pdf PDF
FBO9.pdf PDF
FBO8a.pdf PDF
FBO7replacement_(003).pdf PDF
FBO7_2272017.pdf PDF
FBO6_12202016.pdf PDF
FBO5b_(003).pdf PDF
FBO3_8APR16.pdf PDF
PWS6b-Assessment_and_Authorization_Support_v5.pdf PDF
PWS6d-Emerging_Technology_and_Modernization_Support_v5.pdf PDF
PWS6a-Information_System_Security_Officer_v5.pdf PDF
PWSAPPLICATIONENGINEERING.pdf PDF
PWSOperations_and_Maintenance.pdf PDF
FBO.pdf PDF
PWS6c-Security_Operations_Center_Support_v5.pdf PDF
ITOCIrevised5_(3).pdf PDF
OCISecurity5.pdf PDF
IT_Security.pdf PDF
Application_Development.pdf PDF
Mission_Needs.pdf PDF
Program_Management_Oversight.pdf PDF
QAIVV.pdf PDF
Hardware.pdf PDF
General_or_No_Category.pdf PDF
IT_Industry_Day_Roster_-_December_05_2014.pdf PDF
FEMA_IT_Industry_Day_Final_141205.pdf PDF
FEMA_BPA_Draft__Version_12__4__2014_(3).pdf PDF
Security_Operations_Center_Support.pdf PDF
PMO_Contract_SOO-Draft_(2).pdf PDF
Application_Development_Engineering_and_Sustainment_Draft_SOW.pdf PDF
Information_System_Security_Officer_Draft_SOW.pdf PDF
Emerging_Technology_and_Modernization_Support_Draft_SOW.pdf PDF
FEMA_BPA_Hardware_Software_Draft.pdf PDF
REQUIREMENTS _ESTIMATES _AND_SCOPE_(RES).pdf PDF
Assessment_and_Authorization_Support_Draft_SOW.pdf PDF
OCIO_Procurement_Diagram.pdf PDF
FlyerIndustryDay.pdf PDF
Phased_Contract_Award_Approach_Flyer.pdf PDF
Socioeconomic_Disadvantage_Concerns_Flyer.pdf PDF
FEMA_Information_Technology_Industry_Day_Agenda.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Procurement Sensitive

U.S. Department of Homeland Security/Federal Emergency Management Agency

Department of Homeland Security Federal Emergency Management Agency

(FEMA)

Operations and Maintenance (O&M)

Indefinite Delivery, Indefinite Quantity Statement of Work

September 11th, 2014

STATEMENT OF WORK

A. Project Title: Information Technology Operations and Maintenance Services.

B. Background

1. The Federal Emergency Management Agency’s (FEMA) mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other man-made disasters. FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, protections, response, recovery and mitigation. FEMA has developed a suite of information systems to meet this mission and provides users a responsive array of information services. The suite of information systems, services, and applications are provided in Appendix A. FEMA’s enterprise information technology (IT) systems shall be operated and maintained at the highest level of performance and reliability twenty-four (24) hours a day, seven (7) days a week.

2. The work under this acquisition falls under the auspices of the FEMA Chief

Information Officer (CIO). The CIO’s mission is “to enhance and maintain information technology infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across

FEMA’s divisional and regional lines.” The CIO’s vision is to modernize the

FEMA OCIO to “deliver world-class secure Information Technology guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders nationwide.” The CIO’s objective of the short, middle and long term modernization efforts are to transform IT services into a best-of-class, enterprise focused, efficient and well-managed environment. This environment shall be implemented with the flexibility required to support the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.

3. The current FEMA IT environment is a combination of new and old technologies, architectures, platforms and tools that includes a wide variety of

PC-based, client server, web-based and service-oriented components. These systems have been implemented by FEMA using a variety of service providers under a vast array of oversight and governance conditions. These systems represent a broad spectrum of effectiveness to the DHS, FEMA and OCIO mission.

4. FEMA’s OCIO modernization is defined as the evolution of all IT services and support. This will be achieved by utilizing a comprehensive approach and strategy; supporting the FEMA strategic plan; developing a common operating framework; supporting a secure implementation of enterprise applications and services that support the mission. The modernization effort shall provide enterprise level solutions that will support business needs necessary for the immediate requirements in support of the FEMA mission.

C. Scope

1. Currently, FEMA is obtaining IT operations and maintenance (O&M) services through multiple contracted integrators. The objectives of this acquisition are to consolidate six contracts into one contract, transition existing services within 60 days of task order award, ensure accurate and timely invoicing, and obtain superior O&M services. The contractors shall provide a reliable, stable, and secure operating environment that is aligned with the FEMA enterprise infrastructure

2. The primary operations locations are the Mount Weather Emergency Operations

Center (MWEOC), FEMA Headquarters and other sites located in the National

Capital Region. Additional locations include FEMA Regional offices, FEMA

National Processing Service Centers (NPSCs), FEMA’s Brooke Road facility, the

National Emergency Training Center (NETC), Long Term Recovery Centers

(LTROs), Logistics Centers, Mobile Disaster Recovery Centers (MDRCs), Distribution Centers, and Joint Field Offices (JFOs), Center for Domestic

Preparedness (CDP) and other permanent or temporary facilities located in the

United States and Territories.

3. The scope of this contract also includes contractor support to FEMA’s technical staff for operations, maintenance and monitoring of FEMA’s networks, systems and applications of the Agency’s environment. The contractor will support the

FEMA systems and technical environment.

4. There are six (6) service categories that support this requirement and they are as follows: System Operations and Maintenance; System Sustainment; Network

Operations Support; Hardware Installation; Telecommunications service support and Help Desk Support.

D. Applicable Documents / Constraints

1. Homeland Security Enterprise Architecture. The contractor shall comply with the

FEMA Enterprise Architecture so that all technology investment decisions are in line with the standard set forth to support the FEMA mission.

2. Section 508 of the Rehabilitation Act, as amended by the Workforce Investment

Act of 1998 (P.L. 105-220). This Act requires that when Federal agencies develop, procure, maintain, or use electronic and information technology, they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities shall have equal access to and use of information and data that is comparable to that enjoyed by non-disabled

Federal employees and members of the public.

a. All Electronic and Information Technology (EIT) deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable standards have been identified:

1) 36 CFR 1194.21 - Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including but not limited to

GOTS and COTS software. In addition, this standard is to be applied to

Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some Web based applications as described within 36 CFR 1194.22.

2) 36 CFR 1194.22 - Web-based Intranet and Internet Information and

Applications, applies to all Web-based deliverables, including documentation and reports procured or developed under this work statement. When any Web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then -1194.21

Software- standards also apply to fulfill functional performance criteria.

3) 36 CFR 1194.23 - Telecommunications Products, applies to all telecommunications products including end-user interfaces such as telephones and non-end-user interfaces such as switches, circuits, etc.

that are procured, developed or used by the Federal Government.

4) 36 CFR 1194.24 - Video and Multimedia Products, applies to all video and multimedia products that are procured or developed under this work statement. Any video or multimedia presentation shall also comply with the software standards (1194.21) when the presentation is through the use of a Web or Software application interface having user controls available.

5) 36 CFR 1194.25 - Self Contained, Closed Products, applies to all EIT products such as printers, copiers, fax machines, kiosks, etc. that are procured or developed under this work statement.

6) 36 CFR 1194.31 - Functional Performance Criteria applies to all EIT deliverables regardless of delivery method. All EIT deliverable shall use technical standards, regardless of technology, to fulfill the functional performance criteria.

7) 36 CFR 1194.41 - Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required -1194.31 Functional

Performance Criteria-, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and

Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.

b. Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the Contracting Officer’ Representative (COR) and determination will be made in accordance with DHS MD 4010.2. DHS has identified the following exceptions that may apply:

1) 36 CFR 1194.2(b) - (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a

Government solicitation. Agencies cannot claim a product as a whole is not commercially available because no product in the marketplace meets all the standards. If products are commercially available that meets some but not all of the standards, the agency shall procure the product that best meets the standards.

2) When applying this standard, all procurements of EIT shall have documentation of market research that identify a list of products or services that first meet the agency business needs, and from that list of products or services, an analysis that the selected product met more of the accessibility requirements than the non-selected products as required by FAR 39.2. Any selection of a product or service that meets less accessibility standards due to a significant difficulty or expense shall only be permitted under an undue burden claim and requires approval from the DHS Office on Accessible Systems and Technology

(OAST) in accordance with DHS MD 4010.2.

3) 36 CFR 1194.3(b) - Incidental to Contract, all EIT that is exclusively owned and used by the contractor to fulfill this work statement does not require compliance with Section 508. This exception does not apply to any EIT deliverable, service or item that will be used by any Federal employee(s) or member(s) of the public. This exception only applies to those contractors assigned to fulfill the obligations of this work statement and for the purposes of this requirement, are not considered members of the public.

E. SPECIFIC TASKS

1. Task 1: The contractor shall provide superior System Operations and

Maintenance support.

a. This support includes maintenance, modification and configuration of software systems or components to correct faults, improve performance or other attributes; adapt to a changed environment or maintenance activities focused on anticipated problems, or preventive maintenance.

b. Operations of high availability environments with implemented disaster recovery techniques and proactive monitoring.

c. These support activities may include the development of procedures, specification and standards to achieve and support a stable systems environment, conduct data analysis, and perform reviews to assess issues and offer recommendations.

d. The contractor shall operate and maintain at the highest level of performance and reliability twenty-four (24) hours a day, seven (7) days a week.

e. Support activities may include coordinating and managing production deployments following FEMA’s Change and

Configuration Management procedures.

f. Provide support of hardware, software, application and database installation, integration, maintenance and optimization.

g. Service Oriented Architecture (SOA) Production support and monitoring.

h. Provide support of a virtualized platform in FEMA and DHS datacenters.

i. Provide Windows/Linux system administration to include monitoring, optimization, and disaster recovery.

2. Task 2: The contractor shall provide superior System Sustainment support.

a. This support includes processes, procedures, people, material, and information required to support, maintain, and operate FEMA systems.

b. This support includes sustaining engineering, availability engineering, capacity planning, data management, configuration management, training, survivability, environment, and protection of critical program information, information technology security, supportability and interoperability functions of custom developed applications, Commercial Off-the-Shelf (COTS) products and

Government Off-the-Shelf (GOTS) products.

c. The contractor shall operate and maintain at the highest level of performance and reliability twenty-four (24) hours a day, seven (7) days a week.

3. Task 3: The contractor shall provide superior Network Operations Support.

a. Services shall include:

1. Network monitoring and support

2. Change and configuration management

3. Teleconferencing support

4. Capacity planning support

5. Supportability and interoperability functions

6. Technology refresh for the FEMA network assets include:

a. National Network Operations Center (NOC)

b. Local area networks and wide area networks

c. Private Branch Exchange (PBX) systems for voice communications via FEMA’s integrated network

d. Public network and Federal Telephone Systems (FTS)

e. Joint Field Offices (JFO’s) and/or mobile units to be added quickly to the architecture via landlines or satellite communications

f. Video Teleconferencing, (VTC)

g. Satellite

h. The FEMA Intranet / Internet

i. The National Warning System (NAWAS) and

Emergency Alert System (EAS)

j. DHS

7. Support for centralized operations, monitoring, failure and intrusion detection, and restoration of FEMA’s nationwide telecommunications and network systems, including video teleconferencing operations for FEMA senior-level management, federal, state, and local partners and other

DHS components.

8. Services shall be supported twenty-four (24) hours a day, seven (7) days a week.

4. Task 4: The contractor shall provide superior Hardware Installation, Maintenance and Operations Support.

a. Support for the installation and support of Agency hardware and software systems including CPUs, memory, storage and other ancillary/peripheral devices, and includes, but is not limited to, maintenance, upgrades, reconfiguration, moves/adds/changes, troubleshooting, repair, correction of faults, performance improvements or other attributes, adaptation to a changing environment, anticipation of problems, and performance of preventive maintenance.

b. The contractor shall meet the performance standard (acceptable quality level) by responding to inquiries and informing customers of the expected repair time within 2 hours of the call, during normal business hours.

5. Task 5: The contractor shall provide superior Help Desk Support.

a. The contractor shall provide in-person and phone-based technical and end-user support for end-users systems (desktops, laptops, tablet PC’s, and other peripheral devices) through the FEMA

Enterprise Service Desk, JFO IT Surge Support, for end-user personal computers, ancillary devices, printers, and office automation software to correct faults, improve performance or other attributes, adapt to a changing environment or maintenance activities focused on anticipated problems, and preventive maintenance.

b. The contractor shall meet the performance standard (acceptable quality level) by receiving a favorable response on at least 98% of customer satisfaction inquiries.

6. Task 6: The contractor shall provide superior Telecommunications Management

Support.

a. The contractor shall demonstrate experience and knowledge in

Program Management, Project Management and telecommunications support. The contractor will show experience in other functional areas including acquisition, business and enterprise planning, budgeting, cyber security, and training. This knowledge and experience will enhance the contractor’s ability to provide support in program/project management, operations support, systems engineering and lifecycle management, and the evolving technologies lab for the MSC, iFEMA, and Workforce

Transformation programs as detailed below.

b. Mobility Service Center: The contractor shall support FEMA in its core Mobility Services business to include: identifying business needs, acquiring wireless, wire line, and satellite technologies to meet those needs, and managing these technologies from financial, contractual, and operational perspectives

c. Enterprise Mobility Environment for FEMA (iFEMA) program:

The contractor shall support the infrastructure, hardware, software, and services required to support and sustain how FEMA’s workforce utilizes mobile devices, corporate data, and applications to perform business tasks and to fulfill FEMA’s mobility strategic mission

d. Systems hosting: Utilizing Information Technology

Infrastructure Library (ITIL) best practices (found here:

http://www.itil-officialsite.com/) for IT service management, the contractor shall provide voice and data support throughout the DHS

Systems Lifecycle including tiered systems engineering, hosting, application development and website maintenance, Network

Inventory and Optimization System (NIOS), systems operations and maintenance, performance monitoring, integration services, and support of major enterprise disaster assistance modules.

e. Program Management: Responsible for planning, directing, and coordinating activities for all technology and business unit projects within a program supporting the FEMA mission, the contractor shall manage, track, and coordinate projects at a program level and milestones at the project level. Assigned to the team by the program manager, these projects include, but are not limited to, conducting baseline inventories, streamlining processes and procedures, the utilization and maintenance of the current billing and invoicing system used by FEMA, and participation in work groups to improve customer satisfaction and efficiencies resulting in possible cost savings.

f. The contractor shall meet the performance standard (acceptable customer satisfaction inquiries.

7. Task 7: The contractor shall participate in “Transition in” and “Transition out” activities that shall not exceed 60 days.

a. For the “Transition out” activities, the contractor shall provide a

Transition Out Plan that at a minimum discusses the strategy for the following topics: service transition, billing transition, our process training, account hand over, employee credential deactivation (both electronic and badging) http://www.itil-officialsite.com/

8. Task 8: The contractor shall comply with the Homeland Security Enterprise

Architecture requirements (HLS EA).

a. All solutions and services shall meet approved HLS EA policies, standards, and procedures.

b. All developed solutions and requirements shall be compliant with the HLS EA.

c. All IT hardware and software shall be compliant with the HLS EA

Technical Reference Model Standards and Products Profile.

d. All data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the DHS

Enterprise Data Management Office for review and insertion into the DHS Data Reference Model.

e. In compliance with the Office of Management and Budget (OMB) mandates, all network hardware shall be IPv6 compatible without modification, upgrade, or replacement.

9. Task 9: The contractor shall comply with and provide deliverables in accordance with technical and functional performance criteria mentioned in these applicable documents / constraints:

a. Section 508 of the Rehabilitation Act, as amended by the Workforce

Investment Act of 1998 (P.L. 105-220);

b. 36 CFR 1194.21

c. 36 CFR 1194.21

d. 36 CFR 1194.22

e. 36 CFR 1194.23

f. 36 CFR 1194.24

g. 36 CFR 1194.25

h. 36 CFR 1194.31

i. 36 CFR 1194.41

10. Task 10: FEMA supports hundreds of servers, systems and solutions that provide mission and general services support. The contractor shall provide superior technical support and database management to include all information systems and applications listed in Appendix A.

a. In addition to the services listed in Appendix A, the contract may include support for future applications, systems, solutions and technology services that are implemented to support the Agency mission or that provide general support services to the Agency.

b. The contractor shall meet the performance standard (acceptable quality level) by ensuring system database availability meets or exceeds 99% up time.

11. Task 11: The contractor shall provide key personnel.

a. Key personnel shall be specified in each Task Order issued under this contract. The contractor shall provide a list of key personnel and the resume of each employee. The key personnel shall be assigned for the duration of this requirement.

b. Prior to removing, replacing, or diverting any of the specified individuals, the contractor shall obtain approval from the

Contracting Officer and Contracting Officer’s Technical

Representative and shall submit justification (including proposed substitutions) in detail to allow for an evaluation of the impact relative to the Task Order.

c. The contractor shall submit to the COR all proposed substitutions at least thirty (30) days in advance. The request shall contain a complete resume for the proposed substitute, who shall have at least equal ability and qualifications, and received approval from the COR.

d. The government retains the right, at its discretion, to interview all proposed replacements of key personnel. No changes shall be made by the contractor without the written consent of the

Contracting Officer.

12. Task 12: The Contractor shall provide for and fund all training for its staff necessary to perform the services stated in this SOW and Task Orders.

a. The Contractor shall provide refresher training to keep its staff current.

b. The Contractor shall include in its proposal a plan to provide training to meet this requirement.

c. FEMA will only fund FEMA-specific training.

d. The contractor shall meet the performance standard (acceptable customer satisfaction inquiries

F. DELIVERABLES AND DELIVERY SCHEDULE

1. The contractor shall provide satisfactory Monthly Progress Reports

a. The contractor shall submit a Monthly Progress Report by the 21st of each month following the monthly reporting period. The suspense date of the report shall be the same as the date used for invoicing by the primary contractor.

b. Any and all subcontractor/consultant data will be current through the “as of” date of the report

c. The report shall be unclassified.

d. The report shall be e-mailed to the CO, COR and Technical Monitor(s).

e. The performance standard (acceptable quality level) of a satisfactory

Report is The Monthly Progress Report is delivered on time and contains the required technical and expenditure data.

f. At a minimum, the Report shall consist of the following data

1) Technical data

a) Discuss efforts performed during the reporting period.

b) Discuss the status of any assigned deliverables. This will include the Contract Data Requirements List (CDRL) reference, deliverable title, date due and date delivered.

c) Identify any problems encountered (technical/schedule/cost) and resolutions.

d) Specifically note if there are any unresolved problems/issues at the end of the reporting period.

2) Expenditure data

a) Provide current and cumulative expenditures of both hours and dollars. Illustrate expenditures separately by Task Order and the amount funded as well as compute a funding balance.

b) Provide line graphs illustrating expenditures of both hours and dollars. These graphs shall demonstrate planned expenditures as well as funding levels.

c) Provide the names of all personnel charging to the Task Order.

Organize the data by contract labor category and illustrate both current and cumulative hours charged for each person. Reveal separate uncompensated hours and total time to account for hours worked.

d) Reflect the total expenditures compared to those invoiced for the same period and describe any variances.

3) The above detail information shall be provided for current contract period Task Orders only. Information required by paragraph F.1 shall also be provided for each previous Task Order so as to provide a summary for the Task Order.

2. The contractor shall provide a Final Report for each contract period.

a. The Final Report shall include a cumulative list of all deliverable and the technical and expenditure data outlined above for the Monthly Progress

Reports

b. The report shall be unclassified.

c. The report shall be e-mailed to the CO, COR and Technical Monitor(s).

d. The Report shall be submitting within 15 business days of the end of the performance period

e. The performance standard (acceptable quality level) of a satisfactory

Report is The Monthly Progress Report is delivered on time and contains the required technical and expenditure data.

3. The contractor shall provide an Annual Plan of Action and Milestones (POA&M and Staffing Plan)

a. The contractor shall develop a (POA&M) for each work area within the

Statement of Work (SOW) and/or as identified by the Task Order.

b. The POA&M is due within twenty-one (21) calendar days after the Task

Order award, Exercise of Option, Technical Instruction Issuance, and/or

Modification to the Technical Instruction or the Task Order which affect the

Level of Effort or dollar ceilings.

c. While contractor format is acceptable, with the COR’s and Contracting

Officer’s, the following information, as a minimum, will appear in each

POA&M.

1) Task Order Statement of Work

a) Date POA&M prepared (and revision number if applicable)

b) Work Area

c) POA&M applicable period of performance

d) Work summary to include a listing of planned deliverables

e) Estimated Man-Years required for the period to include subcontractors

f) Names of personnel to be assigned and estimated Level of Effort stated in terms of man-years.

d. The report shall be unclassified.

e. The report shall be e-mailed to the CO, COR and Technical Monitor(s).

f. The performance standard (acceptable quality level) of a satisfactory

Report is The POA&M Staffing Plan is delivered on time and contains accurate required data.

4. The contractor shall participate in formal and informal In Progress Reviews

(IPRs) of work being performed

a. Formal reviews will be scheduled by the Government and will be conducted in Governmental spaces. At the time the review is scheduled, the

Government will communicate the specific purpose of the review and advise the contractor as to the desired content of the presentation.

b. The contractor shall provide copies of slides to be presented to all attendees.

c. An initial IPR will be conducted within sixty (60) days of the Task Order award date and will follow an agenda agreed to by the COR. Subsequent

IPRs will be conducted approximately every ninety (90) days thereafter unless waived by the Government

d. The performance standard (acceptable quality level) of a satisfactory

Report is: The IPR is conducted within 60 days of a Task Order award;

subsequent IPRs are conducted approximately every 90 days.

5. The contractor shall participate in Task Prioritization Meetings with individual

Task Area Points of Contact.

a. The purpose of these meetings is to convey the Government’s technical program schedules and priorities and to identify corresponding task priorities for this order.

b. The COR and/or the Alternate COR (A-COR) may attend these meetings.

c. Results of these meetings will be included in the Monthly Progress Report.

6. The contractor shall provide bi-weekly Earned Value Management (EVM) reports

a. The date for the first submission will be confirmed by the COR upon Task

Order award.

b. The COR will also identify the specific projects to be reported.

c. Cumulative hours by subtask are a minimum requirement; cumulative hours by task and by employee are desired. The Government will provide the format for this report at the time of award and confirm the required submission date for the first report.

d. The purpose of the report is to provide EVM variables that feed directly into the Project schedule.

e. The Government, at its discretion, may hold validation sessions with the contractor to review actual hours submitted in the bi-weekly reports with the hours reported in the Monthly Progress Report.

f. The EVM report shall be e-mailed provided to the COR, Government Task

Area Managers (for their respective project) and the CO.

g. The report shall be unclassified.

h. The performance standard (acceptable quality level) of a satisfactory

Report is: The EVM Report is delivered bi-weekly and contains accurate required data.

G. GOVERNMENT FURNISHED EQUIPMENT AND INFORMATION.

FEMA will provide necessary equipment to accomplish the functions described within this SOW. This includes, but is not limited to laptops, desk phones, printers, office supplies, etc. Contractors shall be responsible for any items issued to him/her from FEMA and will be issued a hand receipt for stated items. All items are subject to inventory based on the Government’s discretion and can be requested to be returned at any time. Additionally, FEMA will provide the contractor with all necessary information to perform all services described in this SOW.

H. PLACE OF PERFORMANCE

1. Services shall be performed at the following locations:

a. FEMA MWEOC: Mt. Weather, Virginia 20135

b. FEMA NPSC: Winchester, VA

c. FEMA Brooke Road Facility: Winchester, VA

d. FEMA NPSC: Hyattsville, MD

e. FEMA NPSC: Denton, Texas

f. JFOs/DFOs/MDRCs: US and territories

g. FEMA HQ: Washington, DC

h. FEMA CDP: Anniston, AL

i. FEMA USFA: Emmitsburg, MD

I. PERIOD OF PERFORMANCE

1. The indefinite-delivery indefinite-quantity contract awarded will have a period of performance of 1 year from date of award plus 4 1-year options periods.

J. TRAVEL

1. All contractor travel, other than local, shall be approved in advance by the COR.

Contractor travel expenses will be reimbursed in accordance with the allowable travel costs specified in the Federal Travel Regulations.

K. CONTRACTOR PERSONNEL REQUIREMENT

1. Contractor personnel performing under the terms of this contract and any resulting task order shall identify themselves as a Contractor in all communications, oral or written, while performing services under this contract.

At no time shall the Contractor personnel assigned to this contract represent themselves as a FEMA employee or an official representative of FEMA.

Additionally, reference to or use of the Contractor personnel’s affiliation with

FEMA for reasons not associated with specific performance under this contract is strictly prohibited. Contractor personnel shall not include DHS/FEMA logos, emblems, project/program nomenclature, or contact information on their business cards; rather, the employee’s corporate business cards shall be used.

The following is the required signature block template to be used by Contractor personnel assigned a FEMA e-mail account:

• Employee Name

• Employee Company, Employee Title

• Contractor Support to “Name of FEMA Office or Program”

• Phone Number

• E-mail address

L. SECURITY:

1. GENERAL

a. Department of Homeland Security Acquisition Regulation (HSAR) clause

3052.204-71 requires that contractor personnel requiring unescorted access to government facilities, access to sensitive information, or access to government information technology (IT) resources are required to have a favorably adjudicated background investigation prior to commencing work on this contract.

b. Department of Homeland Security (DHS) policy requires a favorably adjudicated background investigation prior to commencing work on this contract for all contractor personnel who require recurring access to government facilities or access to sensitive information, or access to government IT resources.

c. Contractor employees will be given a suitability determination unless this requirement is waived under Departmental procedures. Requirements for suitability determination are defined in paragraph 3.0.

2. ADDITIONAL INFORMATION FOR CLASSIFIED CONTRACTS:

a. Performance of this contract requires the Contractor to gain access to classified National Security Information (includes documents and material).

Classified information is Government information which requires protection in accordance with Executive Order 12958, National Security Information (NSI) as amended and supplemental directives.

b. The Contractor shall abide by the requirements set forth in the DD Form 254, Contract Security Classification Specification, an attachment to the contract, and the National Industrial Security Program Operating Manual (NISPOM) for protection of classified information at its cleared facility, if applicable, as directed by the Defense Security Service. If the Contractor is required to have access to classified information at a DHS or other Government Facility, it shall abide by the requirements set forth by the agency.

3. GENERAL REQUIREMENT:

a. The Contractor shall ensure these instructions are expressly incorporated into any and all subcontracts or subordinate agreements issued in support of this contract.

4. CONTRACTOR PERSONNEL

a. EMPLOYMENT ELIGIBILITY

1. To comply with the requirements HSAR Clause 3052.204-71, and

Department policy, the contractor shall complete the following forms for applicable personnel who will be performing work under this contract as indicated:

• Standard Form (SF) 85P, “Questionnaire for Public Trust Positions”

• FD-258 fingerprint cards

• DHS Form 11000-6, “Conditional Access to Sensitive but Unclassified

Information Non-Disclosure Agreement”. Required of all applicable contractor personnel.

• DHS Form 11000-9, “Disclosure and Authorization Pertaining to

Consumer Reports Pursuant to the Fair Credit Reporting Act (FCRA)”

b. CONTINUED ELIGIBILITY

1. The Contracting Officer may require the contractor to prohibit individuals from working on contracts if the government deems their initial or continued employment contrary to the public interest for any reason, including, but not limited to, carelessness, and insubordination, incompetence, or security concerns.

c. TERMINATION

1. The DHS Security Office shall be notified of all terminations/resignations within five (5) days of occurrence. The Contractor shall return to the

Contracting Officer Representative (COR) all DHS issued identification cards and building passes that have either expired or have been collected from terminated employees. If an identification card or building pass is not available to be returned, a report shall be submitted to the

COR, referencing the pass or card number, name of individual to who it was issued and the last known location and disposition of the pass or card.

d. SUITABILITY DETERMINATION

1. DHS may, as it deems appropriate, authorize and grant a favorable entry on duty (EOD) decision based on preliminary suitability checks.

The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of the full investigation. The granting of a favorable EOD decision shall not be considered as assurance that a full employment suitability authorization will follow. A favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude, or bar DHS from withdrawing or terminating access government facilities or information, at any time during the term of the contract. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable

EOD decision or suitability determination by the Security Office.

2. Contract employees waiting for an EOD decision may begin work on the contract provided they do not access sensitive Government information.

Limited access to Government buildings is allowable prior to the EOD decision if the Contractor is escorted by a Government employee. This limited access is to allow Contractors to attend briefings, non-recurring meetings and begin transition work.

e. BACKGROUND INVESTIGATIONS

1. Contract employees (to include applicants, temporaries, part-time and replacement employees) under the contract, requiring access to sensitive information, shall undergo a position sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigations will be processed through the DHS Security Office. Prospective Contractor employees shall submit the following completed forms to the DHS

Security Office. The Standard Form 85P will be completed electronically, through the Office of Personnel Management’s e-QIP

SYSTEM. The completed forms shall be given to the DHS Security

Office no less than thirty (30) days before the start date of the contract or thirty (30) days prior to entry on duty of any contract employees:

a) Standard Form 85P, “Questionnaire for Public Trust Positions”

b) FD Form 258, “Fingerprint Card” (2 copies)

c) DHS Form 11000-6 “Conditional Access To Sensitive But

Unclassified Information Non-Disclosure Agreement”

d) DHS Form 11000-9, “Disclosure and Authorization Pertaining to

Consumer Reports Pursuant to the Fair Credit Reporting Act”

2. Only complete packages will be accepted by the DHS Security Office.

Specific instructions on submission of packages will be provided upon award of the contract.

3. Be advised that unless an applicant requiring access to sensitive information has resided in the US for three of the past five years, the

Government may not be able to complete a satisfactory background investigation.

4. Non-U.S. citizens shall not be authorized to access or assist in the development, operation, management or maintenance of Department IT systems under the contract, unless a waiver has been granted by the

Head of the Component or designee, with the concurrence of both the

Department’s Chief Security Officer (CSO) and the Chief Information

Officer (CIO) or their designees. Within DHS Headquarters, the waiver may be granted only with the approval of both the CSO and the CIO or their designees. In order for a waiver to be granted:

a) The individual must be a legal permanent resident of the U. S. or a citizen of Ireland, Israel, the Republic of the Philippines, or any nation on the Allied Nations List maintained by the Department of

State;

b) There shall be a compelling reason for using this individual as opposed to a U. S. citizen; and

c) The waiver shall be in the best interest of the Government.

f. INFORMATION TECHNOLOGY SECURITY CLEARANCE

1. When sensitive government information is processed on Department telecommunications and automated information systems, the Contractor shall provide for the administrative control of sensitive data being processed. Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level. Some positions will require the individual have an active minimum background investigation level of BI and individuals must be cleared to

High Risk Public Trust and/or National Security Level Top Secret.

2. Contractors who fail to comply with Department security policy are subject to having their access to Department IT systems and facilities terminated, whether or not the failure results in criminal prosecution.

Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g., Privacy Act).

3. Contractor access will be terminated for unauthorized use. The contractor agrees to hold and save DHS harmless from any unauthorized use and agrees not to request additional time or money under the contract for any delays resulting from unauthorized use or access.

5. SECURITY MANAGEMENT

a. The contractor shall appoint a senior official to act as a Security Officer. The individual shall work collaboratively with the DHS Security Officer through the

COR on all security matters, to include physical, personnel, and protection of all sensitive documents/material handled by the Contractor.

b. The COR and DHS Security Office will have the right to inspect procedures, methods and facilities utilized by the Contractor to comply with the security requirements under this contract. Should the COR or DHS Security Office determine that the Contractor is not in compliance with the security requirements of the contract, the Contracting Officer shall notify the

Contractor, in writing, of the appropriate action the contractor must take to rectify any non-compliance with the contract security requirements.

6. INFORMATION TECHNOLOGY SECURITY TRAINING AND OVERSIGHT

a. All Contractor employees using Government automated systems or processing Government sensitive data shall be required to receive Security

Awareness Training. This training will be provided by the appropriate component Agency of DHS.

b. Contractors involved with management, use, or operation of any IT systems that handle sensitive information within or under the supervision of the department, shall receive periodic training at least annually in security awareness, and accepted security practices and systems rules of behavior.

Department contractors, with significant security responsibilities, shall receive specialized training specific to their security responsibilities annually. The level of training shall commensurate with the individual’s duties and responsibilities and is intended to promote a consistent understanding of the principles and concepts of telecommunications and IT systems security.

c. All personnel who access Government information systems will be continually evaluated while performing these duties. Supervisors should be aware of any unusual or inappropriate behaviors by personnel accessing systems. Any unauthorized access, sharing of passwords, or other questionable security procedures should be reported to the local Security Office or Information

System Security Officer (ISSO).

d. Before receiving access to IT resources under this contract the individual must receive a security briefing, which the Contracting Officer’s

Representative (COR) will arrange, and complete any nondisclosure agreement furnished by DHS.

7. SECURITY CERTIFICATION AND ACCREDIDATION

a. FEMA shall provide personnel with the appropriate clearance levels to support the security certification and accreditation processes under this

Agreement in accordance with DHS MD 4300A, DHS Sensitive Systems

Policy and Handbook. During all System Development Life Cycle (SDLC) phases of FEMA systems, FEMA personnel shall develop documentation and provide any required information for all levels of classification in support of the certification/accreditation process. In addition, all security certification and accreditation will be performed using the DHS certification and accreditation process, methodology and tools.

Appendix A: FEMA’s Suite of Information Systems, Services, and Applications

1. The complete list of the primary systems and services are as follows:

o End-User Support Systems (Active Directory, Microsoft Exchange, Microsoft

SharePoint, etc.)

o FEMA Intranet and Internet o Web Content Management o Test and Development Lab (TDL) o Oracle DBMS, Microsoft SQL Server, MongoDB, CouchDB o Operational Data Store (ODS) o Oracle RMAN/OSB o RAC Clustered environments o Virtual Databases o Oracle 10g and higher o SharepPlex/Goldengate o Data Guard o Advanced Replication o Oracle Grid o Oracle Enterprise Manager o New Database technology in Cloud environments o Microsoft Windows, UNIX, Linux o Service Oriented Architecture o EMC Storage Arrays, and Virtual Environments o CISCO Devices o HP Insight Manager o NetIQ App Manager o Sybase PowerBuilder o BMC Remedy Product Suite o What’s Up Gold Product Suite o Microsoft System Center Server Management o Microsoft PowerShell o Cloud Management Technologies o PVCS Version Manager and Tracker o ArcServe Backup o Web Servers - - IIS, Apache, TomCat o Manhattan Assoc Warehouse Management and Trading Partner products o IBM COGNOS Business Intelligence Suite o JBoss Application Server o Software AG’s webMethods Integration Broker

2. The complete list of the primary enterprise applications are as follows Automated Acquisition Management System

AAMS

ACCPAC ACCPAC

Automated Construction Estimating System ACE

Automated Disaster Deployment ADD

Individual Assistance Admin Admin IA

Assisted Firefighters Grant AFG (External & Internal)

NEMIS Assistance Client - web application ASTC Web

Citizen Corp CCORP

Credit Card Transaction Management System CCTMS

Community Information System CIS (External & Internal)

Customer Satisfaction Analysis Section CSAS (Wincati)

Disaster Assistance Center DAC Admin

Disaster Assistance Center DAC Call Center at DC2 (Replaced

Denton Call Center)

Disaster Assistance Center DAC Call Center (Mt. Weather)

Disaster Assistance Center DAC Public

Direct Assistance, Replacement Assistance

Consideration

DARAC

Documents Management and Records Tracking

System

DMARTS IATAC

Deployment Tracking System DTS (replacing ADD)

Electronic Certification & Approval Processing

System eCAPS

Electronic Grants System eGRANTS

Environmental-Historic Preservation EHP - EMIS (Internal Only)

Emergency Management Information

Management System

EMIMS

Emergency Management Mission Integrated

Environment

EMMIE (External & Internal)

FEMA Access Management System FAMS Disasteraid

Hazard Mitigation Grant Program HMGP

Individual Assistance Processing Server IA Processing Server

Integrated Financial Management Information

System

IFMIS

Inspection Management Web IM Web

Incident Management Coordination Assessment and Determination

IMCAD (External & Internal)

Integrated Public Alert and Warning System IPAWS/SOA

Integrated Report Management Application IRMA

Java Address Correction Service JACS

Java Auto Determination Events JADE

Logistics Information Management System LIMS

Logistics Supply Chain Management System LSCMS

Mitigation Grant Program MT eGrants (External & Internal)

Non-Disaster Grants ND Grants (External & Internal)

National Emergency Family Registry and Child

Locator System

NEFRLS (External & Internal)

National Emergency Management Information NEMIS

System

NEMIS Access Control NACS

NCP Virtual Desktop NCP-VD

National Emergency Management Information

System Client

NEMIS Client

NEMIS to IFMIS Transfer Service

National Fire Incident Reporting System NFIRS

National Fire Incident Reporting System NFIRS Reporting

National Shelter System NSS (External Only)

Office of Chief Counsel OCC Filemaker

Payment and Recording System PARS SF269 / SF425

Rental Resources under ASTC Rental Resources

SOA Financial System SFS

SOA Transport System STS

Total Asset Visibility TAV

Individual Assistance State Export

TRIM Context, Document Management System TRIM

Viewstar Viewstar

A. Project Title: Information Technology Operations and Maintenance Services.
B. Background
C. Scope
G. GOVERNMENT FURNISHED EQUIPMENT AND INFORMATION.
FEMA will provide necessary equipment to accomplish the functions described within this SOW. This includes, but is not limited to laptops, desk phones, printers, office supplies, etc. Contractors shall be responsible for any items issued to him/her ...
I. PERIOD OF PERFORMANCE
1. The indefinite-delivery indefinite-quantity contract awarded will have a period of performance of 1 year from date of award plus 4 1-year options periods.
1. GENERAL
2. ADDITIONAL INFORMATION FOR CLASSIFIED CONTRACTS:
3. GENERAL REQUIREMENT:
4. CONTRACTOR PERSONNEL
5. SECURITY MANAGEMENT
6. INFORMATION TECHNOLOGY SECURITY TRAINING AND OVERSIGHT
7. SECURITY CERTIFICATION AND ACCREDIDATION

Appendix A: FEMA’s Suite of Information Systems, Services, and Applications

File details come from the government source that posted it. Updated .