PWSAPPLICATIONENGINEERING.pdf

PDF 320 KB Posted

Attached to
FEMA INFORMATION TECHNOLOGY INDUSTRY DAY Federal contract opportunity
Solicitation number
HSFE30-15-S-0001
Issued by
Federal Emergency Management Agency Mitigation Section

About this file

PWS APPLICATION ENGINEERING

View the file

Other files for this federal contract opportunity

Other files attached to FEMA INFORMATION TECHNOLOGY INDUSTRY DAY, newest first.
File Type Posted
FBO15.pdf PDF
FBO13_(002).pdf PDF
FBO12.pdf PDF
FBO11.pdf PDF
FBO10.pdf PDF
FBO9.pdf PDF
FBO8a.pdf PDF
FBO7replacement_(003).pdf PDF
FBO7_2272017.pdf PDF
FBO6_12202016.pdf PDF
FBO5b_(003).pdf PDF
FBO3_8APR16.pdf PDF
PWS6b-Assessment_and_Authorization_Support_v5.pdf PDF
PWS6d-Emerging_Technology_and_Modernization_Support_v5.pdf PDF
PWS6a-Information_System_Security_Officer_v5.pdf PDF
PWSOperations_and_Maintenance.pdf PDF
FBO.pdf PDF
PWS6c-Security_Operations_Center_Support_v5.pdf PDF
ITOCIrevised5_(3).pdf PDF
OCISecurity5.pdf PDF
Program_Management_Oversight.pdf PDF
IT_Security.pdf PDF
Application_Development.pdf PDF
Mission_Needs.pdf PDF
QAIVV.pdf PDF
Hardware.pdf PDF
General_or_No_Category.pdf PDF
IT_Industry_Day_Roster_-_December_05_2014.pdf PDF
FEMA_IT_Industry_Day_Final_141205.pdf PDF
FEMA_BPA_Draft__Version_12__4__2014_(3).pdf PDF
O__M_-_DRAFT_SOW_09102014.pdf PDF
PMO_Contract_SOO-Draft_(2).pdf PDF
Application_Development_Engineering_and_Sustainment_Draft_SOW.pdf PDF
Security_Operations_Center_Support.pdf PDF
Information_System_Security_Officer_Draft_SOW.pdf PDF
Emerging_Technology_and_Modernization_Support_Draft_SOW.pdf PDF
FEMA_BPA_Hardware_Software_Draft.pdf PDF
REQUIREMENTS _ESTIMATES _AND_SCOPE_(RES).pdf PDF
Assessment_and_Authorization_Support_Draft_SOW.pdf PDF
FlyerIndustryDay.pdf PDF
Phased_Contract_Award_Approach_Flyer.pdf PDF
Socioeconomic_Disadvantage_Concerns_Flyer.pdf PDF
OCIO_Procurement_Diagram.pdf PDF
FEMA_Information_Technology_Industry_Day_Agenda.pdf PDF
Show all 44

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT – PROCUREMENT SENSITIVE – DRAFT – PROCUREMENT SENSITIVE

DO NOT RELEASE

SOURCE SELECTON INFORMATION

SEE FAR 3.104

PROCUREMENT SENSITIVE

FOR OFFICIAL USE ONLY

Table of Contents 1 1 GENERAL .............................................................................................................................................. 4 2

1.1 Introduction ..................................................................................................................................... 4 3

1.2 Background ..................................................................................................................................... 5 4

1.3 Objective ......................................................................................................................................... 5 5

1.4 Applicable Documents ................................................................................................................... 6 6

1.5 Scope ............................................................................................................................................... 7 7

2 SPECIFIC TASKS AND REQUIREMENTS ............................................................................................ 8 8

2.1 Task 1 – Program Management ..................................................................................................... 8 9

2.1.1 Hardware Procurement .......................................................................................................... 10 10

2.1.2 Risk Management ................................................................................................................... 10 11

2.1.3 Configuration Management ................................................................................................... 11 12

2.1.4 Task Order Project Management .......................................................................................... 11 13

2.1.5 Facilitation of Product Reviews ............................................................................................ 12 14

2.1.6 Status Reporting .................................................................................................................... 12 15

2.2 Task 2 – Enterprise Architecture Development ......................................................................... 12 16

2.3 Task 3 – Data Architecture Development ................................................................................... 13 17

2.4 Task 4 – Applications Development............................................................................................ 13 18

2.4.1 Requirements Review ............................................................................................................ 14 19

2.4.2 Applications Design ............................................................................................................... 14 20

2.4.3 Agile Development Methodology Customizations .............................................................. 15 21

2.4.4 Applications Implementation ................................................................................................ 16 22

2.4.5 Developmental Testing, Integration, and Evaluation .......................................................... 17 23

2.4.6 Applications Documentation................................................................................................. 18 24

2.4.7 Applications Installation Support ......................................................................................... 18 25

2.4.8 Applications Delivery ............................................................................................................. 18 26

2.4.9 Post-Deployment Support ..................................................................................................... 18 27

2.4.10 Service Management Review ................................................................................................ 19 28

2.5 Task 5 – Training .......................................................................................................................... 19 29

2.6 Task 6 – Exit Transition ................................................................................................................ 20 30

3 CONTRACTOR RESOURCES ............................................................................................................. 20 31

3.1 Qualified Personnel ...................................................................................................................... 20 32

3.2 Continuity of Support ................................................................................................................... 20 33

3.3 Key Personnel ............................................................................................................................... 20 34

3.4 Project Manager ............................................................................................................................ 21 35

3.5 Employee Identification ............................................................................................................... 21 36

3.6 Employee Conduct ....................................................................................................................... 22 37

3.7 Removing Employees for Misconduct or Security Reasons .................................................... 22 38

4 OTHER APPLICABLE CONDITIONS .................................................................................................. 22 39

4.1 Period of Performance ................................................................................................................. 22 40

4.2 PLACE OF PERFORMANCE ........................................................................................................ 22 41

4.3 HOURS OF OPERATION .............................................................................................................. 22 42

4.4 TRAVEL ......................................................................................................................................... 23 43

4.5 SECURITY ..................................................................................................................................... 23 44

4.5.1 Continued Eligibility .............................................................................................................. 23 45

4.5.2 Termination ............................................................................................................................ 23 46

4.5.3 Suitability Determination ....................................................................................................... 24 47

4.5.4 Background Investigation ..................................................................................................... 24 48

4.6 PERIOD OF PERFORMANCE ....................................................................................................... 25 49

4.6.1 Access to Classified and Confidential Unclassified Information ....................................... 25 50

4.7 Information Technology Security Clearance .............................................................................. 25 51

4.8 Security of Deliverables ............................................................................................................... 25 52

4.9 Information Technology Security Training and Oversight ........................................................ 26 53

4.10 Post-AWARD CONFERENCE ....................................................................................................... 26 54

4.11 PROJECT PLAN ............................................................................................................................ 26 55

4.12 BUSINESS CONTINUITY PLAN .................................................................................................... 26 56

4.12.1 Individual BCPs ...................................................................................................................... 27 57

4.13 PROGRESS REPORTS ................................................................................................................. 27 58

4.14 PROGRESS MEETINGS ................................................................................................................ 28 59

4.15 GENERAL REPORT REQUIREMENTS ........................................................................................ 28 60

4.16 PROTECTION OF INFORMATION ................................................................................................ 28 61

4.17 Suspected Loss of Compromise of SPII [Breach] ..................................................................... 30 62

4.18 SECTION 508 COMPLIANCE ........................................................................................................ 32 63

5 GOVERNMENT/CONTRACTOR -FURNISHED RESOURCES ........................................................... 33 64 6 CONTRACTOR -FURNISHED PROPERTY ......................................................................................... 34 65

SOURCE SELECTON INFORMATION

SEE FAR 3.104

7 GOVERNMENT ACCEPTANCE PERIOD ............................................................................................ 34 66

7.1 Contracting Officer Right to Reject or Require Correction ....................................................... 35 67

7.2 Review and Comment Period Duration ....................................................................................... 35 68

7.3 Other Review Time Periods and Schedules ............................................................................... 35 69

8 Deliverables ......................................................................................................................................... 35 70 9 INVOICING PROCEDURES ................................................................................................................. 37 71 Appendix A Acronyms........................................................................................................................... 38 72

1 GENERAL 75

1.1 Introduction 76

The mission of the Federal Emergency Management Agency (FEMA) is “to support our citizens 77 and first responders to ensure that as a nation we work together to build, sustain and improve our 78 capability to prepare for, protect against, respond to, recover from, and mitigate all hazards.” For 79 35 years, FEMA’s mission has consistently been to lead America to prepare for, prevent, respond 80 to, and recover from disasters with a vision of “A Nation Prepared.” 81 The mission of the FEMA Office of the Chief Information Officer (OCIO) is to enhance and 82 maintain information technology (IT) infrastructure, develop and enhance key systems to support 83 operating programs, and increase efficiencies and cooperation across FEMA’s divisional and 84 regional lines. To support the FEMA mission, the OCIO is providing the leadership to enable the 85 entire FEMA enterprise, including the OCIO organization, to better manage and execute its IT 86 portfolio, programs, and projects. 87 The OCIO is transforming the FEMA IT environment through a series of enterprise-wide 88 enhancements, including IT project management, requirements, best practice systems 89 development processes, IT security, operations and maintenance, and IT quality assurance. This 90 transformation is being accomplished to enhance and maintain the enterprise technology 91 infrastructure, develop and enhance key systems to support operating programs, and increase 92 efficiencies and cooperation across FEMA divisional and regional lines. 93 FEMA IT projects, infrastructure, and operations will be managed and executed with a 94 standardized approach that leverages all possible enterprise-wide acquisition efficiencies, utilizes 95 a common best-practice approach to project management, and provides for the more efficient 96 integration of systems and use of resources. 97 The FEMA transformation approach will focus on high performance execution with skilled 98 teams collaborating across functional areas to include requirements, development, operations and 99 maintenance, quality assurance, and security. High performing, cross functional, collaborating 100 teams will execute using rapid application development approaches such as Agile 101 methodologies. FEMA will adapt the Department of Homeland Security Systems Engineering 102 Life Cycle (DHS SELC) as it transforms and mature its policies and guidelines and expects 103 Contractors to rapidly evolve. Critical success factors will include: 104

• High productivity with resultant high quality work 105

• Collaboration and cooperation with across functional areas with a teaming approach 106

• Technical skills and expertise to be innovative and solve problems 107

• Efficient use of team resources that maximizes productivity. 108

To ensure successful deployment of mission capabilities, FEMA expects Contractors to provide 109 technical methods, techniques, and concepts that are innovative, practical, cost-effective and 110 meet the evolving needs and requirements that result from FEMA’s operational users. 111

SOURCE SELECTON INFORMATION

SEE FAR 3.104

1.2 Background 112

FEMA has an inventory of 200 authorized IT systems. These were built to address mission 113 needs, often disaster-driven, without an enterprise architecture in place. There are many 114 duplications of data and activity, with limited use of common web services. Many of the user 115 interfaces are difficult to use, and transferring data between systems often requires manual 116 intervention. FEMA has additional unmet business needs, currently documented in 14 business 117 cases. 118 FEMA is committed to modernizing its IT systems. To accomplish this, FEMA has started 119 developing an enterprise architecture and has initiated programs of governance for data. FEMA’s 120 goal is to complete these initiatives and to create, through innovation, a transformed organization 121 in which IT services are delivered through state-of-the-art, service-enabled applications. These 122 updated applications are intended to: 123

• Stabilize and integrate IT access across the Agency 124

• Provide comprehensive emergency management support, including but not limited to 125 preparedness, training, mitigation, response, and recovery 126

• Protect the emergency management infrastructure and information assets against loss or 127 compromise 128

• Enhance the Homeland Security information infrastructure by enabling the sharing of 129 mission-critical information where and when it is needed, regardless of organizational 130 boundary 131

• Effectively leverage existing information assets to address emerging mission requirements 132 quickly 133

• Operate at Capability Maturity Model Integration (CMMI) Development Level 3 134

• Support the effective analysis, assessment, and selection of appropriate solutions, products, 135 and technologies to support the enterprise 136

• Optimize return on all IT applications expenditures 137

• Implement proper project management practices and reporting procedures in adherence to 138 established best practices (e.g., Project Management Body of Knowledge [PMBOK]) 139 FEMA’s desired outcome is to transform the organization so that resources are optimized and the 140 mission is more efficiently and effectively accomplished. For the period 2015 through 2019, 141 FEMA priorities are primarily to strengthen IT governance and cybersecurity, to modernize 142 infrastructure and systems, to eliminate redundancies, and to enhance support for data-driven 143 analytics. 144

1.3 Objective 145

The primary objective of this acquisition is to establish a single-award Indefinite Delivery/ 146 Indefinite Quantity (IDIQ) contract for Applications Engineering services that will enable 147 FEMA, through the OCIO, to accomplish its mission to “develop and enhance key systems to 148 support operating programs; increase efficiencies and cooperation across FEMA’s divisional and 149 regional lines.” 150 The task orders issued under the IDIQ will be designed to acquire Applications Engineering 151 (AE) services and will be written against five functional areas: Program Management (PM), 152 Enterprise Architecture Development, Data Architecture Development, Applications 153 Development, and Training. Requirements include enterprise engineering, applications 154 development, systems integration, testing, deployment, and post deployment support services. 155 The desired and necessary outcome is to identify a highly qualified and capable Contractor team 156 that: 157

• Has experience and expertise with a variety of application development approaches as 158 described herein. 159

• Can apply those various approaches to different scenarios, as described by a unique set of 160 work packages, each containing unique requirements, desired behaviors, required labor 161 categories, and relevant skill sets. 162

• Demonstrates understanding, knowledge, and ability to accomplish the evolution of 163 applications pursuant to the FEMA OCIO’s vision and efforts to create an agile enterprise 164 that is responsive to the dynamic mission requirements facing FEMA. 165

• Demonstrates that they can embrace a series of diverse architectures within which work is 166 currently accomplished, and help drive toward those strategic capabilities that FEMA must 167 create. 168

• Can accelerate the forward motion to build and employ an effective, practical, and usable 169 service-oriented architecture (SOA). 170

• Can migrate the legacy applications to a modernized architecture while effectively 171 servicing our current customers who depend upon legacy applications that must continue 172 to exist and be reliable and responsive until migrated to the evolving, web-based, service-173 oriented architecture environment. 174

1.4 Applicable Documents 175

The Contractor shall comply with the requirements set forth in the most current versions of the 176 following documents, including those that supersede versions that were current at the time of 177 award. The Contractor shall also comply with any future legislation, guideline, or policy in 178 accordance with its provisions. 179

1. DHS Acquisition Directive D-102-01 180

2. DHS Guidebook 102-01-103-01, Systems Engineering Lifecycle Guidebook 181

3. Government Accountability Office, Schedule Assessment Guide 182

4. 44 U.S.C. § 3551, “Federal Information Security Modernization Act of 2014” 183

5. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the 184

Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998 185

6. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974” 186

SOURCE SELECTON INFORMATION

SEE FAR 3.104

7. Office of Management and Budget A-130, Management of Federal Information 187 Resources, Appendix III, Security of Federal Automated Information Resources 188

8. Office of Management and Budget A-123, Management's Responsibility for Internal 189 Control 190

9. Office of Management and Budget A-127, Financial Management Systems 191

10. FEMA, FEMA Strategic Plan 2014–2018, 2014 192

11. FEMA, IT Modernization Plan and Actionable Target Architecture, 27 March 2015 193

12. FEMA, Actionable Architecture Volume II – Target Architecture, 27 March 2015 194

13. FEMA, Volume III – Enterprise Actionable Architecture – Baseline, 3 December 2014 195

14. Federal Enterprise Architecture, Consolidated Reference Model Document Version 2.3, 196

Office of the President, October 2007 197

15. Federal Enterprise Architecture, Practice Guidance, Office of the President, October 198

2007 199

16. Federal Enterprise Architecture, Consolidated Reference Model Document Federal 200

Enterprise Architecture Framework Version 2, Office of the President, 29 January 2013 201

17. National Institute for Standards and Testing (NIST) 500-235, Structured Testing: A 202

Testing Methodology Using the Cyclomatic Complexity Metric, 01 August 1996 203

18. FEMA Program Management Office Standard Operating Procedures, TBD 204

19. FEMA Risk Management Plan 205

20. FEMA Configuration Management Plan 206

1.5 Scope 207

The scope of this effort includes all systems engineering development performed to meet 208 requirements provided by FEMA, including network analysis, network modernization, 209 requirements review, requirements analysis, interface definition, enterprise architecture 210 definition, applications design, applications development, systems integration, developmental 211 testing, user acceptance testing, training, deployment, and post deployment support. The work 212 will be performed in conformance to the DHS Systems Engineering Lifecycle (SELC), evolving 213 FEMA applications development policies and guidance, and the FEMA Configuration 214 Management plan, in coordination with FEMA Quality Assurance personnel and support staff. 215 Some of the work will be performed at the Top Secret level. The Contractor must be capable of 216 supporting Top Secret level development, including producing and operating in accordance with 217 a System Security Plan (SSP). 218 The Contractor must be capable of managing task orders employing waterfall, Rapid 219 Development, DevOps, and/or Agile software development methodologies as specified per task 220 order. The Contractor shall manage risk in conformance to the guidelines provided by the FEMA 221

Risk Management Plan. The Contractor must be capable of operating in accordance with CMMI 222 Level 3 project management practices. 223 The Contractor must be execute with high performance, cross functional teams able to employ 224 efficient development methodologies to deliver FEMA mission capabilities. 225 The Contractor must be capable of performing studies, developing recommendations, and 226 implementing improvements to mature the data architecture in conformance with FEA guidelines 227 (see Applicable Documents 14, 15 and 16 in Section 1.4). This shall include, as needed, updating 228 the Conceptual Data Model (CDM), the Logical Data Model (LDM), and the Physical Data 229 Models (PDM). 230 During the period of performance and at the end of the contract, the Contractor shall deliver to 231 FEMA Operations and Maintenance (O&M) personnel all source code and associated artifacts 232 required to maintain applications developed by the Contractor. All applications developed under 233 this contract, and all customization files, source code, designs, and other artifacts associated with 234 applications developed under this contract, shall be property of the U.S. Government. 235

2 SPECIFIC TASKS AND REQUIREMENTS 236

2.1 Task 1 – Program Management 237

The Contractor will be expected to plan, execute, and manage the work described in this 238 Statement of Work (SOW) employing industry best practices for project and program 239 management according to standards and methodologies published by the Project Management 240 Institute or equivalent industry practices. 241 FEMA shall be represented by its Contracting Officer (CO) and the FEMA PMO. The 242 Contractor shall accept direction from FEMA PMO staff, specifically including PMO staff 243 employed by FEMA contractors, as directed by FEMA. The Contractor shall accept requests for 244 information from FEMA PMO staff, specifically including PMO staff employed by FEMA 245 contractors, as requests for information from FEMA. Failure to comply fully and proactively 246 with requests for information, or other direction, from PMO staff, specifically including PMO 247 staff employed by FEMA contractors, will be regarded as failure to comply with direction from 248 FEMA. Preference will be given to respondents that include explicit plans for compliance with 249 FEMA direction, as described here, in the project management portions of their contract 250 proposals. 251 The Contractor shall provide program management support to accomplish the administrative, 252 managerial, logistical, integration and financial aspects specified in individual task orders. The 253 Contractor shall assign a full-time, dedicated Program Manager (PM) who shall ensure 254 compliance with all the Task Order (TO) requirements and be the primary Contractor point-of-255 contact for the work to be performed. The Contractor shall continuously monitor the 256 performance of this contract, and all subcontracts, to provide DHS with a timely assessment, per 257 the Contract Service Level Agreements (SLA), of program progress, risks, issues, and proposed 258 resolutions. The PM shall have sufficient corporate authority to direct, execute, and control all 259 elements of the Contractor’s work program and to ensure that all necessary management, 260 analysis, business, contracts, engineering, implementation, and maintenance personnel resources 261

SOURCE SELECTON INFORMATION

SEE FAR 3.104

are available and sufficient, both in numbers and qualifications, to successfully perform all 262 required tasks. The PM shall be subject to the Key Personnel provisions of Section 3.3. 263 At a minimum, the PM shall have the following responsibilities: 264

1. Manage execution of all task orders placed under this contract 265

2. Manage the efforts and access authorization of any subcontractor that the Contractor 266 assigns to a task order placed under this Contract 267

3. Perform other program management duties that are necessary for the successful 268 completion of task orders and the satisfaction of overall contract requirements 269

4. Serve as the principal interface for all matters relating to the execution of this SOW 270 between the Contractor’s project team and the Contractor’s corporation; between the 271 Contractor’s project team and the Government PM and the PMO staff, and between the 272 Contractor’s project team and associated contractors and subcontractors for all matters 273 relating to the execution of this SOW 274

5. Ensure the timeliness and quality of deliverables so that all information and data for each 275 task order are accurate and complete in accordance with the SOW 276

The Contractor shall establish a project team responsible for executing the total effort required 277 by this SOW. This organization shall exhibit clear lines of authority, responsibility, and 278 accountability of project authority among all organizational elements including Government, 279 FEMA Contractor, and all subcontractors. The Contractor shall describe its management 280 approach to accomplishing the required work for each Government task order issued under the 281 Contract in a Task Order Management Plan (TOMP). The Contractor shall provide the TOMP 282 within thirty (30) days of contract award. 283 The Contractor shall perform an Earned Value Management (EVM) tracking using a system 284 conforming to the American National Standards Institute/Electronic Industry Association 285 (ANSI/EIA) Standard 748-A, Earned Value Management Systems. For Agile development 286 projects the Contractor shall utilize Agile EVM. 287 The Contractor shall submit twelve (12) monthly Earned Value Reports: three Contract 288 Performance Report (CPR) Formats 1, 3, and 5, and the Contract Funds Status Report (CFSR). 289 The Contractor shall transmit Earned Value Management System (EVMS) data documenting all 290 activities performed on the Contract to FEMA monthly, in an ANSI Accredited Standards 291 Committee (ASC) X12 format agreed to by FEMA. 292 The Contractor shall follow the DHS Systems Engineering Lifecycle (SELC) (DHS Instruction 293 Manual 102-01-001 Acquisition Management Instruction/Guidebook Appendix B System 294 Engineering Life Cycle). SELC activities shall be customized for each task order in accordance 295 with the recommendations provided in DHS Guidebook, 102-01-103-01, Systems Engineering 296 Life Cycle Guidebook. This shall include following tailored versions of the SELC applying to 297 Agile Development, Rapid Applications Development, or DevOps Continuous Integration 298 methodologies as specified by the task order. The Contractor shall perform the lifecycle activities 299 specified for the task order, including organizing and facilitating the gate reviews specified for 300 the task order. 301 If specified in the task order, the Contractor shall develop applications at the Top Secret level. 302 This shall include operating in accordance with a System Security Plan (SSP). 303 The Contractor shall consult with FEMA security personnel on all matters of task execution, 304 including development, configuration management, risk analysis and developmental testing, to 305 ensure that applications produced under this contract render robust and technologically current 306 protection against interference with Government services, unauthorized access to Government 307 systems and unauthorized access to information under government stewardship, in place and in 308 transit. As stated in other portions of this contract, the Contractor shall include FEMA security 309 personnel in reviews of all products, including task execution plans, designs, source code, test 310 plans, test results and documentation, and shall respond appropriately to review comments 311 developed by FEMA security personnel. 312 The Contractor shall perform the following program management activities, described in detail 313 in the subsections to follow: 314

1. Hardware Procurement 315

2. Risk Management 316

3. Configuration Management 317

4. Task Order Project Management 318

5. Facilitation of Product Reviews 319

6. Status Reporting 320

2.1.1 Hardware Procurement 321

The Contractor shall operate using Government Owned Contractor Operated equipment, which 322 shall be operated on Government premises or shall be delivered to the Government at the end of 323 the contract. 324 The Contractor shall develop a design to support development activities and review it with 325 FEMA, including PMO and O&M personnel. This design shall include details of where the 326 equipment will be located and how and when it will be installed. This design shall include 327 Government-owned equipment to be operated on Contractor premises, such as desktop 328 computers. It may also include Government-owned equipment to be operated on Government 329 premises, such as platform-as-a-service (PAAS) cloud servers. On approval of the design, the 330 Contractor will purchase the equipment and deliver it in accordance with the approved plan. 331 The Contractor will design and procure other Government-owned equipment when required by 332 the task order. The Contractor will also supply Contractor-owned workstations, and associated 333 infrastructure, at the Contractor site sufficient to support internal Contractor operations. 334

2.1.2 Risk Management 335

The Contractor shall conduct continuing risk identification and assessment activities to identify 336 any risks that may affect the Contractor’s ability to meet its technical cost and schedule 337 objectives. The Contractor shall inform the Government Program/Project Manager immediately 338

SOURCE SELECTON INFORMATION

SEE FAR 3.104

upon identifying risks and shall address those risks and necessary mitigation strategies in the 339 next scheduled status meeting and in the Monthly Status Reports and Briefings. The Contractor 340 shall understand and utilize the risk management processes noted in the FEMA Risk 341 Management Plan. 342

2.1.3 Configuration Management 343

The Contractor shall follow the FEMA Configuration Management Plan and utilize the FEMA 344 common suite of software tools for configuration management, requirements management, and 345 problem reporting. The Contractor may propose updates to the FEMA Configuration 346 Management Plan and common suite of software tools in its response, but shall conform to the 347 FEMA Configuration Management Plan and tools if these proposed updates are not 348 implemented. 349 FEMA will store requirements information in the FEMA requirements management system, and 350 will facilitate access for the (Applications Engineering) Contractor. The Contractor shall 351 identify, per the task order, design and test information for each requirement to be added to the 352 FEMA requirements management system. 353

2.1.4 Task Order Project Management 354

The Contractor shall establish a technical approach, organize resources, and establish and 355 execute management controls to ensure that cost, technical, and schedule requirements of each 356 task order are met. 357 The Contractor shall implement procedures to monitor technical, cost, and schedule performance 358 for each task order. The Contractor shall establish metrics for assessing and reporting task status 359 that will enable the Contractor to detect and predict deviations from the planned or required 360 performance (cost, technical, or schedule) in time to take corrective action. For tasks requiring 361 source code development, the metrics shall include summary static analysis measurements such 362 as cyclomatic complexity, essential complexity, and nesting depth, to be agreed to between 363 FEMA and the Contractor. 364 As designated by FEMA in the TO, the Contractor shall create a Project Management Plan 365 (PMP) describing the scope, approach, schedule, work breakdown structure (WBS), resources, 366 quality assurance, and management controls necessary to meet contract performance, schedule, 367 and cost requirements. The PMP shall describe the Contractor’s project organization, including 368 all lines of authority and reporting relationships, and further describe monitoring procedures, 369 metrics, and corrective action procedures to be used to manage the project. PMPs will be 370 consistent in approach and format unless otherwise agreed to by FEMA. 371 The Contractor shall design and implement corrective action procedures to prevent, circumvent, 372 or mitigate the impact of deviations from planned or required performance. 373 The Contractor shall provide schedule information to the FEMA Project Manager in FEMA 374 specified format to enable task order schedule integration with the FEMA Integrated Master 375 Schedule. 376

2.1.5 Facilitation of Product Reviews 377

The Contractor shall facilitate SELC phase gate reviews as specified by FEMA, including users, 378 requirements developers, quality assurance personnel, security personnel, O&M personnel and 379 others as specified by FEMA. The Contractor shall create gate review updates summarizing the 380 Contractor’s capability development progress and deliver those updates. The Contractor shall 381 participate in each gate review, shall present the Contractor’s progress to the FEMA Lead 382 Technical Authority conducting the review, and address any deficiencies or risks identified in the 383 reviews. The gate reviews shall include all, or a subset, of the following, depending on the scope 384 of the task order and SELC tailoring: 385

• System Definition Review (SDR) 386

• Critical Design Review (CDR) 387

• Integration Readiness Review (IRR) 388

• Test Readiness Review (TRR) 389

• Production Readiness Review (PRR) 390

• Operational Test Readiness Review (OTRR) 391

• Operational Readiness Review (ORR) 392

2.1.6 Status Reporting 393

The Contractor shall prepare and deliver periodic TO Status Reports consisting of a summary of 394 activities, performance and investment metrics and trends, and the status of the contract. Status 395 Reports shall be delivered to the PMO and the CO. Detailed Status Report deliverable 396 requirements and schedules will be provided in individual task orders. 397 The plans and status reports shall be delivered in the required format within the schedule 398 established in the task order, shall conform to FEMA quality guidelines, and shall be accepted by 399 the CO. 400 The Contractor shall prepare and deliver a Monthly Status Report and prepare a monthly status 401 briefing. The Contractor shall attend a Monthly Status Review to be held on the second Tuesday 402 of each month or at the discretion of the Government Program Manager. This Monthly Status 403 Report shall report status and metrics for all task orders in progress. 404 The Contractor shall utilize an existing FEMA Online Project Repository, or develop, deploy, 405 and maintain an Online Project Repository (e.g., a SharePoint site) that allows the Contractor, 406 sub-contractor, Government Program Manager, Government PMO, and other government 407 contractor personnel to track the project schedule, assess status and risks, schedule events, and 408 review documents and deliverables. The Contractor shall maintain this repository throughout the 409 period of performance. The repository shall include a browser-accessible dashboard that reports 410 the status of the program and all program projects. 411

2.2 Task 2 – Enterprise Architecture Development 412

The FEMA Enterprise Architecture (EA) comprises three products: the Baseline Architecture, 413 the Target Architecture, and the IT Modernization Plan (See Applicable Documents 11, 12, and 414 13 in Section 1.4). The Actionable Enterprise Target Architecture is further divided into seven 415 reference architectures: Performance, Business, Data, Application, Security, Infrastructure, and 416

SOURCE SELECTON INFORMATION

SEE FAR 3.104

Technical. Although these architectures can be characterized as 80 percent mature in terms of 417 their depth, breadth, and alignment of content and their satisfaction of four recognized 418 architecture quality measures (completeness, correctness, usability, and utility), not all seven 419 reference architectures are currently at the same level of maturity. 420 The Contractor shall perform studies, develop recommendations, and implement improvements 421 to mature the EA when tasked to do so by FEMA. The Contractor shall conform to the Federal 422 Enterprise Architecture (FEA) standards identified in Applicable Documents 14, 15, and 16 (see 423 Section 1.4, Applicable Documents) when doing this work. The Contractor shall facilitate and 424 document review of these products by FEMA personnel, including QA personnel, security 425 personnel, and requirements personnel. 426

2.3 Task 3 – Data Architecture Development 427

The Contractor shall perform studies, develop recommendations, and implement improvements 428 to mature the data architecture when tasked to do so by FEMA. This shall include, as needed, 429 updating the Conceptual Data Model (CDM) to accurately present data relevant to FEMA core 430 business processes, updating the Logical Data Model (LDM) to normalize data access across 431 diverse FEMA applications, and updating Physical Data Models (PDM) to portray how the data 432 is stored in individual applications. When tasked to do so, the Contractor shall develop and 433 implement recommendations for storing FEMA data in NoSQL, NewSQL, RDBMS, columnar, 434 or graph databases so as to facilitate data collection, access, and analysis efficiently to meet 435 FEMA goals and priorities. The Contractor shall facilitate and document review of these 436 products by FEMA personnel, including QA personnel, security personnel and requirements 437 development personnel. 438 The Contractor shall perform studies, develop recommendations and implement improvements to 439 support an enterprise data warehouse if tasked to do so by FEMA. This shall include, as needed, 440 sizing a data warehouse, developing the hardware architecture for a data warehouse, developing 441 software to extract, transform and load (ETL) data from FEMA applications data stores into a 442 data warehouse, developing software to perform analysis on data stored in a data warehouse, or 443 developing applications to produce reports on data warehouse content. The Contractor shall 444 facilitate and document review of these products by FEMA personnel, including QA personnel, 445 Security personnel and Requirements development personnel. 446

2.4 Task 4 – Applications Development 447

The contractor shall build or update FEMA applications as specified in the FEMA requirements 448 control system, when directed to do so by task order. The Contractor shall provide services in the 449 following categories of Applications Development: 450

• Requirements Review 451

• Applications Design 452

• Applications Implementation 453

• Developmental Testing 454

• Applications Documentation 455

• Applications Installation 456

• Applications Delivery 457

• Service Management Reviews 458

These Applications Development services will be defined in the subsections to follow. 459 The levels of detail and products of each service activity will be specified by FEMA on a per-460 task-order basis. Small changes to existing systems may be specified with a single stated 461 requirement, and design may consist of stating which existing module is to be updated. 462 Construction of new, complex systems may be specified with large numbers of requirements, 463 and the design may be documented in a formal software design document. 464

2.4.1 Requirements Review 465

The Contractor shall participate in reviews of FEMA requirements, providing informed 466 engineering judgement concerning the clarity, measurability, completeness, internal consistency, 467 and testability of the requirements. The Contractor shall confirm that the requirements include 468 appropriate specifications for volume and load performance. The Contractor shall review 469 requirements for consistency with and impact to other FEMA applications when tasked to do so. 470 The Contractor shall advise FEMA of the impact of the proposed requirements on the FEMA 471 Enterprise Architecture, including the Performance Architecture, the Business Architecture, the 472 CDM, and the LDM, as described in Applicable Documents 11, 12, and 13 (see Section 1.4, 473 Applicable Documents). 474

2.4.2 Applications Design 475

The Contractor shall develop designs for construction of software systems, or modifications of 476 existing software systems, to satisfy FEMA requirements. Where possible, the Contractor shall 477 make use of off-the-shelf components such as web servers, workflow systems, and enterprise 478 middleware servers to reduce custom software design effort. 479 The Contractor shall design the application in conformance with the Application Architecture 480 and other components of the EA, supporting SOA wherever applicable and efficient. The 481 Contractor shall use the maximum practical number of existing FEMA and DHS services to 482 support the application, and shall design the application so as to make functions that are usable in 483 other applications available as services. 484 The Contractor designs shall identify the infrastructures to be used to support the application, 485 including platform and OS. 486 The design shall be decomposed into components, to the point that qualified software developers 487 can code the components or configure them in a workflow system. The Contractor shall specify 488 the languages to be used to code any custom software components included in the design. 489 Unless specified otherwise by FEMA, user interfaces produced under this contract shall be 490 developed in accordance with Section 508 of the Rehabilitation Act (29 U.S.C. § 794 d), as 491 amended by the Workforce Investment Act of 1998 (P.L. 105 - 220), August 7, 1998. 492 http://www.section508.gov/Section-508-Of-The-Rehabilitation-Act

SOURCE SELECTON INFORMATION

SEE FAR 3.104

Designs produced under this contract shall only include components that are identified in the 493 DHS Technical Reference Model (TRM) at the time of deployment. Designs with components 494 not in the TRM shall include a justification and proposed schedule for adding components to the 495 TRM prior to deployment. These schedules shall be subject to FEMA review and approval, as 496 shall be any other aspect of applications design. 497 For each task order, unless specified otherwise by FEMA, the Contractor shall work with the 498 FEMA Project Manager to provide information to ensure a complete requirements traceability 499 matrix mapping design components to requirements, to confirm that there are design elements 500 included to satisfy every requirement. This traceability matrix will be controlled by FEMA 501 requirements definition personnel and design information will be stored in it through 502 collaboration with FEMA requirements definition personnel. 503 When directed by FEMA, the Contractor shall produce operable user interface screens that 504 provide the user interface portion of required functionality, but do not provide other functionality 505 such as database access or archive search. Depending on the task order scope, these operable 506 screens may be all of the user interface or only a representative part. These operable screens will 507 be reviewed during the design phase with FEMA Requirements personnel and user 508 representatives, and will also be included in any gateway design reviews defined in the SDLC 509 applied to the task order. 510 The Contractor shall facilitate a critical design review (CDR) that includes QA personnel, 511 requirements personnel, O&M personnel, security personnel, FEMA enterprise architects, and 512 FEMA PMO personnel. The design review shall include samples of the documentation to be 513 produced for configurations of off-the-shelf software included in the design, such as XML 514 configuration files, configuration scripts, or graphical flowcharts. For custom software 515 components, the design review shall include source code standards to be applied and the plan for 516 ensuring that they are followed, as discussed in the Application Implementation subsection 517 below. The design review shall also include software designs, operable user interface screens 518 developed during design (if any), developmental test plans, including unit test plans, and the 519 static and dynamic analysis tools to be used to measure source code security, source code 520 maintainability, and web site security, as discussed in the Developmental Test and Evaluation 521 subsection below. 522

2.4.3 Agile Development Methodology Customizations 523

For task orders to be executed using Agile methodology, the Contractor shall be responsible for 524 all activities prescribed in the DHS SELC customized for Agile development, including but not 525 limited to: 526

• Collaborating with FEMA requirements personnel to define epics, stories and Agile 527 process tasks 528

• Estimating schedule and risk for epics, stories and Agile process tasks 529

• Defining a schedule of sprints to implement the epics, stories and Agile process tasks 530

• Defining tests to confirm that Agile process tasks have been completed 531

• Completing the Agile process tasks 532

• Facilitating daily scrum sessions to monitor progress towards completing the Agile 533 process tasks 534

• Confirming task completion by test execution 535

• Tracking and reporting technical debt, including Code Hygiene debt and Architectural 536 debt. 537 The Contractor shall include FEMA PMO personnel and any other personnel identified by 538 FEMA in daily scrum sessions. 539 Unless stated otherwise in the task order, the activities identified here are in addition to, but not 540 duplicative, of other development activities identified in the SOW. 541

2.4.4 Applications Implementation 542

For designs that include custom software, the Contractor shall identify a coding standard 543 approved by FEMA prior to the start of coding. This standard may be a program-wide standard 544 applied to all tasks, with customizations for the task being executed. The coding standard shall 545 include, at a minimum, the following specifications: 546

1. A policy for controlling cyclomatic complexity. This policy should be consistent with the 547 NIST policy of limiting cyclomatic complexities to a value between 10 and 15. This 548 policy may include use of a static analysis tool to measure cyclomatic complexity and 549 nesting depth, threshold values that trigger a manual inspection, and a waiver policy for 550 cases in which the automatically measured cyclomatic complexity is not representative of 551 the accessibility of code logic. 552

2. A policy for ensuring that all variable names are composed of words or names that would 553 be readily understood by code maintenance personnel. This policy may authorize the use 554 of single-letter names for loop counter variables and temporary pointers. 555

3. Procedures negotiated with FEMA Quality Assurance to enforce the code standard. These 556 procedures may include sampling analyses. 557

The Contractor shall perform the following applications implementation activities: 558

1. Configure off-the-shelf software components to perform the functions specified in the 559 application design, proceeding so as to produce the configuration documentation 560 specified in the application design. 561

2. Execute unit tests, as discussed in the Developmental Testing, Integration, and Evaluation 562 (DT&E) subsection below, to confirm that the configurations produced above perform 563 the functions specified in the application design. 564

3. Produce custom software components to perform the functions specified in the 565 application design, in accordance with coding standards specified for the task. 566

4. Execute unit tests, as discussed in the DT&E subsection, to confirm that the custom 567 software components produced above perform the functions specified in the application 568 design. 569

SOURCE SELECTON INFORMATION

SEE FAR 3.104

5. Execute Continuous Integration tests, as described in the DT&E subsection, to confirm 570 that the source code components and configurations produced above support the 571 functions specified in the application design when integrated into the delivered 572 application. These tests shall include static and dynamic tests of source code security, 573 source code maintainability, and web site security, using off-the-shelf static and dynamic 574 analysis tools to confirm that custom software components produced above are secure 575 and maintainable. 576

2.4.5 Developmental Testing, Integration, and Evaluation 577

Unless…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .