Attachment_A_-_CDS_Statement_of_Objectives.pdf
PDF 1 MB Posted
- Attached to
- Customer and Data Services in support of FIMAs Risk MAP program Federal contract opportunity
- Solicitation number
- HSFE60-17-R-0003
About this file
CDS Statement of Objectives
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_B_-_Established_Contract_Rates_5.18.17.xlsx | XLSX spreadsheet | |
| CDS_Attachment_G_-Revised_May_18.xlsx | XLSX spreadsheet | |
| CDS_RFP_Questions_and_Answers_5.19.17.xlsx | XLSX spreadsheet | |
| Attachment_F_-_CDS-PTS_Conflict_of_Interest_Analysis.xlsx | XLSX spreadsheet | |
| Attachment_B_-_Established_Contract_Rates.xlsx | XLSX spreadsheet | |
| Attachment_J_-_CDS_Transition_Out_Plan.pdf | ||
| Attachment_H_-_Past_Performance_Questionnaire_and_Client_Authorization.pdf | ||
| Attachment_G_-_CDS_Price_Evaluation_Worksheet_.xlsx | XLSX spreadsheet | |
| Attachment_E_-_DHS_Official_Seal_Approval.pdf | ||
| Attachment_C_-_CDS_GFE_Inventory_January_2017.xlsx | XLSX spreadsheet | |
| HSFE60-17-R-0003.pdf | ||
| Attachment_D_-_DOL_Wage_Determinations.pdf | ||
| Attachment_I_-_CDS_Technical_Quantitative_Analysis_Spreadsheet.xlsx | XLSX spreadsheet |
Show all 13
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
FOR OFFICIAL USE ONLY
Federal Emergency Management Agency Risk Management Directorate
Statement of Objectives Customer & Data Services
HSFE60-17-R-0003/ATTACHMENT A
April 19, 2017
Table of Contents
I. DESCRIPTION AND PURPOSE
II. FEMA STRATEGIC GOALS
III. FIMA MISSION
IV. PROGRAM DESCRIPTIONS
V. RISK MAP ENTERPRISE ACQUISITION STRATEGY
VI. UNIVERSAL OBJECTIVES
VII. CUSTOMER AND DATA SERVICES VISION & OBJECTIVES
VIII. ASSUMPTIONS AND CONSTRAINTS
IX. SECURITY REQUIREMENTS
X. DHS ENTERPRISE ARCHITECTURE COMPLIANCE
XI. DELIVERABLES AND MILESTONE SCHEDULE
XII. GOVERNMENT FURNISHED EQUIPMENT
XIII. KEY PERSONNEL
XIV. DETAILED SYSTEMS LIST
XV. DEFINITIONS
ATTACHMENT 1 – CDS REQUIREMENTS TRACEABILITY MATRIX (RTM)
I. DESCRIPTION AND PURPOSE
The Federal Insurance and Mitigation Administration (FIMA) is a component of the Federal Emergency Management Agency (FEMA) within the Department of Homeland Security (DHS), which operates the Risk Management Directorate (RMD) and the National Flood Insurance Program (NFIP). This Statement of Objectives (SOO) supports the Risk Mapping, Assessment, and Planning’s (Risk MAP) Customer and Data Services (CDS) program.
The FEMA Risk Management Directorate implements several programs including the Risk MAP Program, the National Dam Safety Program, the Levee Safety Program, the Natural Hazards Risk Assessment Program, the Building Sciences Program, National Earthquake Hazards Reduction Program (NEHRP) and the NFIP Actuarial Sciences Program.
The vision for Risk MAP is to deliver quality data that increases public awareness and leads to action that reduces risk to life and property. Risk MAP assesses flood hazards and flood risk in support of the NFIP and delivers flood hazard and risk products to local governments, the real estate and lending industries, and other stakeholders.
FEMA’s NFIP has been offering flood insurance coverage to homeowners, renters and businesses as protection against flood losses for over 40 years. In return, local governments provide commitment to sound floodplain management and related flood disaster mitigation efforts. In addition to offering flood insurance, the duties of the NFIP include identifying communities’ flood risks, mapping and publishing Flood Insurance Rate Maps of those risks, helping communities meet floodplain management requirements, and communicating the benefits of flood insurance protection so that more Americans are reimbursed for flood damage through the insurance mechanism, rather than through Federal disaster assistance funds.
FEMA’s flood products are one of the essential tools for flood hazard mitigation in the United States. These maps are used an estimated 20 million times annually in the private and public sectors, in the following ways:
• Lending institutions and insurance companies use them to determine who needs flood insurance and to determine flood insurance rates.
• Community planning officials, land developers, and engineers use them for designing and siting new buildings and infrastructure to be safe from flooding.
• States and communities use them for hazard mitigation planning and emergency management.
• Federal agencies use them when implementing Executive Order 11988, Floodplain Management and the Federal Flood Risk Management Standard.
FEMA’s flood insurance policies are sold through licensed insurance agents either through their affiliated Write-Your-Own (WYO) Insurance Companies or through the NFIP Direct Servicing Agent (DSA); the premium rates, coverages, and rules are determined by FEMA. By law, flood insurance is required of borrowers as a condition of making, increasing, extending, or renewing loans from federally regulated or insured lending institutions for improved real property in identified Special Flood Hazard Areas.
FIMA has recently embarked on taking an Administration-wide view of procurements in an effort to identify common requirements across FIMA that can be procured through a single contract. The intent of this initiative is to realize efficiencies across FIMA by increasing co-ordination and reducing duplication of operations. The purpose of this SOO is to obtain contracted support for the CDS program, which involves work related to: IT systems maintenance and operations; data management; maintaining full operational capability and relevance through data interoperability; and data distribution; support for IT and data business requirements; support for Customer Experience initiatives; and expert professional contact center operations support for the FEMA Map Information eXchange (FMIX), and potentially, one additional facility. The CDS provider will support Risk MAP operations and the changes necessary to continue to improve the FIMA Risk Management vision.
Since the political and technological environments are continuing to evolve, this initiative will require the continuous review of existing systems and operations in meeting the objectives outlined below. FEMA’s goal with this SOO is to receive offeror proposed Technical Solutions that are: proven; efficient; easy to implement and effective, while also not programmatically disruptive; and cost effective. In light of constant funding constraints, most maintenance activities will be incremental.
II. FEMA STRATEGIC GOALS
The 2014-2018 FEMA Strategic Plan reflects objectives the Agency will accomplish to provide the best possible support to the American people before, during, and after disasters. It sets forth the strategies FEMA will employ to accomplish the objectives and also establishes measurable outcomes to achieve. This CDS contract will support operations and maintenance needed to retain full operational capability and remain relevant as FEMA and Risk Management focus on resolving challenges with interoperability, customer experience, data management, and cycle time for system and application fixes, in support of FEMA’s five strategic priorities.
The Strategic Plan provides a strategic lens to focus FEMA's efforts and guide the allocation of resources over the next four years. The FEMA Strategic Plan also supports the Department of Homeland Security's Strategic Plan for Fiscal Years (FY) 2014-2018 Mission 5 of Strengthen national preparedness and resilience.
FEMA’s Five Strategic Priorities:
• Priority 1: Be survivor-centric in mission and program delivery
• Priority 2: Become an expeditionary organization
• Priority 3: Posture and build capability for catastrophic disasters
• Priority 4: Enable disaster risk reduction nationally
• Priority 5: Strengthen FEMA’s organizational foundation https://www.fema.gov/media-library/assets/documents/96981 http://www.dhs.gov/sites/default/files/publications/FY14-18%20Strategic%20Plan.PDF http://www.dhs.gov/sites/default/files/publications/FY14-18%20Strategic%20Plan.PDF
FEMA's Two Strategic Imperatives:
• A whole community approach to emergency management
• Foster innovation and learning
III. FIMA MISSION
The mission of FIMA is to create safer communities by reducing loss of life and property; enable individuals to recover more rapidly from floods and other disasters; and lessen the financial impact of disasters on the Nation. This is accomplished through three primary objectives:
• Analyze Risk – Determining the impact of natural hazards that lead to effective strategies for reducing risk.
• Reduce Risk – Reducing or eliminating long-term risk from hazards on the existing built environment and future construction.
• Insure for Flood Risk – Reducing the impact of floods on the Nation by providing flood insurance.
IV. PROGRAM DESCRIPTIONS
FEMA’s FIMA operates the NFIP, which was created by an Act of Congress in 1968. The NFIP makes flood insurance available to residents and businesses of participating communities that commit to sound flood plain management practices. The primary tool for identifying the flood hazard is a flood map. The NFIP established the flood mapping program which was expanded in 2003 with the Flood Map Modernization effort. In order to leverage the successes of Map Modernization and further enhance the usability and value of flood hazard mapping, FEMA developed the Risk MAP program in 2009. Risk MAP combines flood hazard mapping, risk assessment tools and Hazard Mitigation Planning into one seamless program. The intent of this integrated Risk MAP program is to encourage beneficial partnerships and innovative uses of flood hazard and risk assessment data in order to maximize flood loss reduction.
The objectives of Risk MAP are:
• Assess Nation’s flood risk and use this information to increase public awareness of risk. This consistent, quantitative flood risk assessment will be used to track progress toward reducing flood risk and to target resources.
• Increase public awareness of risk from natural hazards and establish a baseline of local knowledge and understanding of risk management concepts.
• Ensure 80 percent of the Nation’s flood hazards are current – the flood hazard data are new, have been updated, or deemed still valid.
• Provide updated flood hazard data for 100 percent of the populated coastal areas in the
Nation. This data originates as part of the work required within the Production and Technical Services (PTS) contract, but the CDS contract is responsible for housing it.
o Evaluate levee status information to ensure the appropriate flood hazards are depicted on Digital Flood Insurance Rate Maps for counties with levees, including those impacted by expiring Provisionally Accredited Levee status.
• Continue to meet statutory requirements of the NFIP through assessing on a watershed basis, the need to revise and update all floodplain areas and flood risk zones identified, delineated, or established.
The goals of Risk MAP include:
• Goal 1: Address gaps in flood hazard data to form a solid foundation for flood risk assessments, floodplain management, and actuarial soundness of the NFIP.
• Goal 2: Ensure that a measurable increase of the public’s awareness and understanding of risk management results in a measurable reduction of current and future vulnerability to flooding.
• Goal 3: Lead and support states, local and tribal communities to effectively engage in risk-based mitigation planning resulting in sustainable actions that reduce or eliminate risks to life and property from natural hazards.
• Goal 4: Provide an enhanced digital platform that improves management of limited Risk MAP resources, stewards information produced by Risk MAP, and improves communication and sharing of risk data and related products to all levels of government and the public.
• Goal 5: Align Risk Analysis programs and develop synergies to enhance decision-making capabilities through effective risk communication and management.
Risk MAP is designed to support communities with their implementation of another element of the NFIP-- floodplain management. If communities participate in the NFIP by actively managing their flood risk, flood insurance will be available to their citizens. Flood insurance helps communities and individuals financially recover from floods. The NFIP sells and administers Standard Flood Insurance Policies in two ways:
1. Through an arrangement with private Write Your Own (WYO) insurance companies (under authority of 44 CFR Section 62.23); and
2. Through a contract with an entity that directly sells and services NFIP policies, the NFIP
Direct Servicing Agent (DSA).
Since 1983, the Write Your Own (WYO) Program has become the primary vehicle for delivering and servicing flood insurance with participating insurance companies, who write nearly 80% of the NFIP’s policies in their own names. The Government bears the underwriting risk for WYO issued policies, and for the policies issued by the DSA.
V. RISK MAP ENTERPRISE ACQUISITION STRATEGY
Between 2008 and 2014, FEMA crafted an acquisition strategy to optimize stakeholder acceptance; deliver results using an enabling vision; ensure needed flexibility and adaptability exists; facilitate smooth and seamless transition; and provide innovation with problem solving capabilities to meet the challenges facing Risk MAP program and related NFIP programs. This strategy involved a restructuring of the business model where a National Service Provider provided program management, customer service and many other services required to run the overall effort. The approach currently includes establishing separate contracts to provide five groupings of services:
• Program Management (PM)
• Customer & Data Services (CDS)
• Production and Technical Services (PTS)
• Community Engagement and Risk Communication (CERC)
• Letter of Map Amendment (MT-1)
The current CDS support contract is expiring and a new provider must be acquired. This acquisition is for the CDS provider only; PTS, PM, CERC and MT-1 providers are not a part of this acquisition.
VI. UNIVERSAL OBJECTIVES
While each program area will have separate contract(s), the success or failure of the RMD will hinge on the interaction and cooperation of all contractors working as a team to ensure the smooth, seamless flow of information to all stakeholders and partners, both internal and external, and a comprehensive, coordinated approach to provide information and services to customers at all levels. A failure by a single contractor at any level may lead to Risk Management program failure. It is the responsibility of all contractors to participate as team members with all other contractors. To this end, FEMA has established Universal Objectives for all Risk Management contractors.
Universal Objectives
Universal Objective A: Leverage technology, relationships, and mutual interests across the public and private sectors to improve project delivery, data interoperability, consistency and effectiveness in order to increase risk awareness, leading to citizens and communities taking mitigation action to substantially reduce risk to life and property and increase the Nation’s resilience to natural hazards.
Universal Objective B: Provide a high level of cooperation and integration across all FIMA contractors, ensuring seamless and integrated program delivery and advance the ability for FIMA to easily exchange data across the Enterprise. Support the Customer Experience strategy of offering an informed, relevant and unified servicing approach for all FIMA stakeholders. Offer subject matter expertise as required (e.g. business requirements, training development, authors, committees, etc.).
Universal Objective C: Implement sound program management practices to enable reliable and efficient operations, support of FIMA Governance structures, and forward-thinking innovation throughout the NFIP program.
Universal Objective D: Promote integration with FIMA, FEMA, DHS, and Other Federal Agencies’ programs.
VII. CUSTOMER AND DATA SERVICES VISION & OBJECTIVES
Vision
FIMA’s vision for CDS is to improve the Customer Experience for its constituents by providing solutions that address constituent’s decision-making needs in a seamless and integrated manner. This vision entails proactive maintenance of existing systems and applications to ensure they conform to evolving business processes and changes in inputs (e.g., source data) and thus remain easy-to-use, thereby improving the quality of service offered to constituents. Focus areas along this path include working with FEMA’s Office of the Chief Information Officer (OCIO) and other partners on accessibility and interoperability of data.
Objectives
Objective 1: Operate and Maintain Risk MAP non-IT solutions
• The Map Service Center (MSC), Engineering Library, Letter Of Map Change Clearing
House (LOMC Clearing House) comprise Risk MAP’s non-IT solutions. Together the MSC and Engineering Library manage the physical and digital maintenance of archived legacy flood hazard mapping data and the distribution of digital and paper maps as required. The LOMC Clearinghouse is a central hub that performs the administrative functions related to receiving LOMC requests, and distributing the LOMC requests to the PTS contractors for review and processing requiring significant manual labor. All three solutions blend physical and IT components. This Objective excludes the IT applications and systems associated with these three solutions because they are addressed within Objective 4.
o Operate and maintain the MSC and Engineering Library.
o Operate the Letter Of Map Change Clearing House (LOMC Clearing House). FEMA receives more than 30,000 LOMC requests per year from communities, engineers, surveyors, and homeowners using the MT-1 and MT-2 application forms. Due to the current economic conditions, an increasing population, and FEMA’s initiative to conduct a large scale update of the nation’s flood maps, the volume of LOMC requests are expected to trend in the same manner as it has historically. Both digital (eLOMA) and paper requests are supported by the LOMC Clearing House.
o Respond to any types of requests for data from internal and external customers.
Manage digital and paper mapping data.
o Continue to support physical distribution of Risk Management products on a limited basis to communities. Provide professional services to fulfill external data requests for supporting documentation and support Freedom of Information Act requests.
o Collect fees for Letters of Map Change, distribution of products through the MSC, and distribution of engineering library materials through external data requests.
Objective 2: Operate and Maintain a Stakeholder-facing Contact Center
• Operate a Contact Center to respond to stakeholder inquiries regarding the NFIP, Risk MAP, and as needed, other Risk Management programs, as well as providing technical and system support that continues services currently provided.
• The call center shall offer Tier 0, Tier 1, Tier 2, and Tier 3 levels of service.
• All systems must efficiently track users and caller behavior to support analysis and continuous improvement of usability and customer experience.
• Additional duties include participation in quarterly call center coordination meetings, attending the National Flood Conference, providing agent referrals; providing back-up support for inquiries into the NFIP training contract; phone support in the event of a flooding event; and assisting with loss history requests, and disputed information on the loss history reports.
• Operation of the call center shall accommodate surge service requirements.
• Be prepared to plan and execute, no later than February of 2019, the consolidation of two contact centers into a single contact center. The plan for combining the two contact centers should not threaten continuity of services but should complete the combination in an expedient manner.
• Operate, maintain, and fix existing Contact Center processes and supporting technology to reduce operational costs and maintain relevance to broader FIMA contact center strategy.
Anticipated fixes and business process improvements include, but are not limited to: better integrating call center and web content management; and improved dissemination of analytics summarizing policy, process, and customer experience insights gained as a result of normal Contact Center operations.
Objective 3: Manage all Risk Management Data in an Integrated, Comprehensive Manner
• Minimize data duplication, identify authoritative sources, ensure data credibility, and meet the needs of internal and external program stakeholders.
• Provide continuity of data management services currently provided and implement solutions that improve program data management and reduce costs.
• Ensure Risk Management data is readily accessible to all stakeholders for use in existing workflows including, but not limited to:
o Disaster response analytics, o Supporting mitigation actions and planning, o Mitigation planning for agencies and communities, and o Flood risk identification and communication.
• Maintain a full suite of data governance processes and documentation to support integrated data repositories.
• Maintain risk management data repository to ensure data and products are accurate, comprehensive, complete, available, accessible and updateable to support program goals, support decision-making, and comply with records management, OCIO, PII, and cyber security requirements as directed by DHS and FEMA. Examples of this data include, but are not limited to:
o Program management data, o Project management data, o Engineering, o Modeling, and o Geospatial (e.g. LiDAR, imagery, topography).
• Ensure Risk Management data is able to support FEMA, FIMA, Risk Management and stakeholder strategic planning goals and objectives and meet industry standards and best practices for data management, geospatial information and digital products.
o While initiatives may run in parallel, FIMA’s current approach is to focus first on data collection and clean-up, then dissemination and display, and finally, data analysis.
• The Data Management System must accept and exchange Risk Management Program data, products and deliverables among FEMA, Risk Management providers and other mapping partners.
• Monitor, analyze, and improve the quality of mapping and management data, including archived data, as identified in various program analyses (e.g., TMAC and GAO findings).
• Provide professional services to fulfill external data requests for supporting documentation and support Freedom of Information Act requests.
• Collect, account for and maintain records of all fees associated with the Risk Management Program.
• Provide technical support to monitor currency of web content and coordinate updates of content from a variety of sources for posting to FEMA.gov or other relevant websites.
• Provide data management, access, and related disaster support services that support Risk Management and FEMA objectives during large disasters and times of critical need.
• Implementation of all Technical Solutions involving management of data will be in consultation with the OCIO and the OCTO.
Objective 4: Operate, Maintain, and Maximize Risk Management IT to Retain Relevance and Full Operational Capability
• Operate and maintain existing Risk Management IT Systems, Applications, Datasets, and
Infrastructure (excluding hardware discussed in Objective 5), which manage all aspects of map production, flood risk communications, flood map product dissemination and exchange, and hazard mitigation planning. Capabilities and services delivered by the existing systems and applications include, but are not limited to: collection and exchange of mapping data;
planning and management of the map production process’ cost, quality, schedule, scope, and purchases; modification, amendment, revision, display, exchange, and dissemination of digital and paper maps; digitization of paper maps; data management quality control;
collection of hazard mitigation plans and management of the mitigation plan review process;
communication and knowledge management; geospatial data quality review, dissemination, and analysis; and collection of data for program performance metrics.
• To continue delivering full operational capability, Risk Management IT Systems, Applications, Datasets, and Infrastructure will require incremental changes. A few examples of anticipated fixes include:
o Continued upkeep of user account management processes and tools to safeguard the data stored within each system and application, in compliance with DHS/FEMA IT security policies.
o Resolution of issues with alignment of architecture among existing systems’ and applications’ data that inhibit interoperability, data exchange, and end-to-end management of map production and amendment processes.
o Maintenance of data quality by facilitating robust quality planning, review and revision.
o Support interoperability of existing systems and usability of data by ensuring data is geospatially compatible, data transfer is efficient, and architecture is reliable to support mission needs for FEMA, FIMA and Risk Management.
• Deliver the ability to prototype and test complex fixes addressing multiple business requirements, when requested, to demonstrate efficacy of required end state.
• Ensure systems and applications conform to Risk Management business requirements including program coordination, planning, collaboration, and information sharing and exchange among FEMA HQ, regions, states, tribes, and communities (e.g. existing RMD SharePoint Portal).
• Decrease cycle time and improve the quality, customer experience and effectiveness of end products while realizing cost efficiencies when deploying releases that maintain or fix systems and applications in accordance with DHS/FEMA IT security requirements
• Maintain HQ and regional operational relevance by compiling, synthesize, and responding to HQ, regional, and FEMA/FIMA stakeholder requests for fixes and maintenance to data, applications, and systems.
• Provide an effective platform for effective internal communication and coordination for Risk Management initiatives across FEMA staff, contractors, and, on a limited basis, partners.
• Act as a SME in the development of business requirements and in assessing the alignment of those requirements with existing systems.
• Provide recommendations balancing quality, efficiency and cost in the scoping of interoperable solutions that meet FEMA enterprise architecture requirements in an environment of continuous user engagement.
• Translate existing business requirements developed by, or in coordination with, other Risk Management providers to fix systems currently in operation and maintenance.
• Leverage existing investments in systems, programs, and data to deliver solutions that meet stakeholders’ mission and needs.
• On a limited, case-by-case basis, assume responsibility for hosting, operating, and maintaining applications developed by other providers as work arounds. Use a transparent and predictable process to scope, plan, and execute the transition and ongoing operations and maintenance, including security scanning and patching, without jeopardizing existing Authority to Operate (ATO).
• Monitor user behavior for Risk Management systems and applications to identify fixes needed to deliver full operational capability, especially in the areas that impact customer experience (e.g., usability, accessibility and relevance to mission needs). System adjustments will be implemented in accordance with those goals and standards.
• Implement the operational elements of any Risk Management IT system in the operations/maintenance phase.
Table below contains the systems currently managed by CDS. More information about these systems and applications is available in Section XV on FIMA websites and in the Virtual Library for this acquisition.
System Includes following:
Mapping Information Platform Mapping Information Platform
MIP Ad-Hoc Reporting System National Flood Hazard Layer Services Preliminary FEMA Map Products
DFIRM Verification Tool Online Letters of Map Change eLOMA Flood Risk Studies Engineering Library (FRiSEL) Mitigation Planning Portal State GeoSpatial Data Coordination Contacts Database cHECk-RAS*
RASPLOT*
HAZUS*
Metaman Map Service Center Map Service Center (MSC) Project Planning and Purchasing Portal (P4) Coordinated Needs Management System (CNMS) Mitigation Action Tracker (MAT)
HAZUS-MH
Status of Map Change Requests FIRMette Desktop Risk Management Directorate (RMD) SharePoint Portal HAZUS SharePoint PhaseWare Check-RAS Information Website LOMA Flash Tutorial Website Floodmaps File eXchange Risk MAP Progress Tracker Data.gov Metadata Harvester State Contact FEMA Software Help Flood Hazard Determination Notice on the Web FileTrail Case File Access System (CFAS)
LYRIS
* Software available for download that is hosted on the Mapping Information Platform General Support System
Objective 5: Provide Co-locating IT Hosting Capabilities and Support the Management of FEMA systems in DHS/FEMA approved Hosting Environments
• Reduce program hosting and systems costs, and gain operational efficiencies by co-locating in a single, DHS-approved data center, the MIP and the MSC. The MIP is currently hosted by Hewlett Packard at DHS’s DC2 facility in Clarksville, Virginia. The MSC is currently hosted by IBM at the Navy’s Allegany Ballistics Laboratory Federal Data Center (ABL) in Allegany, West Virginia. Bandwidth in and out of DC2 is provided by DHS OneNet. While some data efficiencies could be garnered by consolidation of some aspects of the MIP and MSC, the primary objective is to co-locate the two systems rather than merge the two systems. The target data center must meet all FEMA and DHS IT security requirements and may be owned by either the government or a contractor and, similarly, be operated by either the government or a contractor. Further, the target data center must have the capabilities to enable the other objectives of this SOO. (Contract expiration dates are given in the Transition-out Plan).
• FIMA’s strategy is to leverage service-based IT delivery models rather than provide contractors with GFE. The target data center should support this strategy, recognizing that Risk MAP does currently provide CDS GFE that is not yet at end-of-life. As part of the co-location migration, consider the target infrastructure needed to realize FIMA’s vision.
• Present a plan for migration that does not threaten continuity of services but does obtain Authority to Operate (ATO) the systems in an expedient manner.
• Manage and maintain Service Level Agreements for Risk MAP production environment(s).
Provide data center hosting services as needed, consistent with DHS guidance and program needs.
• Ensure all systems comply with standard operational requirements related to system backup, failover, and recovery without compromising information security.
• Balance operational cost for continuous uptime and disaster recovery with service level especially for the MIP and MSC systems which possess FIPS199 classification of Moderate.
Objective 6: Collaborate with FIMA Leadership to Apply Customer Experience Corrections
• This objective spans all CDS objectives since Customer Experience affects all internal and external stakeholder-facing aspects of CDS, such as supporting regional efforts, providing flood data to property owners and developers, and providing NFHL data to NFIP stakeholders.
• Assess performance of existing applications to determine corrective actions that improve the customer experience.
• Collaborate with the Customer Experience governance team(s) to organize corrective actions into initiatives to help FIMA achieve its Customer Experience vision. Leverage techniques such as Design Thinking to enrich the initiative development process.
• Work with FIMA leadership to determine sequencing and implementation plans for specific initiatives.
• Monitor and report out on progress towards customer experience initiatives being delivered through all CDS objectives.
Objective 7: Manage Risk Management IT Operations, Data, and Systems to Support the Achievement of the Risk MAP Program
• Provide program management services to support the scope of CDS to include either creating or contributing to the maintenance of artifacts, including but not limited to: 1) System documentation (e.g., business use cases, system diagrams, data dictionaries, data quality plans, crosswalks, SOPs); 2) Artifacts required by DHS/FEMA Systems Engineering Life Cycle; 3) and maintenance of new and existing systems’ ATO.
• Provide process and programmatic change management services for the scope of the CDS contract that are integrated with the work of other providers supporting FIMA and sensitive to customers’ workload and varying degrees of engagement with Risk Management programs and Risk MAP systems.
• Contribute to or develop communications about operational status of Risk Management systems and applications including system updates or maintenance.
• Engage stakeholders to support a productive user experience and mutual understanding of Risk Management systems, applications, and data.
• As required by FEMA, attend conferences, meetings, and events to support system and application demonstrations, gather information about the user experience, and increase awareness of technology and data used to support the Risk Management mission.
• Continuously improve upon development and delivery of training and outreach through assessment of training effectiveness to support stakeholder and system users understanding of Risk Management systems, applications, and data. Training will support simultaneous and asynchronous learning in a cost effective manner.
• As required by FEMA, manage one or more user groups (e.g., FEMA IT Risk MAP Systems Team, HAZUS Users Group) which act as liaisons and integrators between Risk Management IT users and FEMA Headquarters.
• Liaise with other Risk Management provider staff as appropriate to determine and co-ordinate the implementation of necessary program changes.
• Provide subject matter expertise on existing Risk Management IT in support of strategic planning initiatives.
• Create a multi-year plan for proactively managing the life of Risk Management programs’ systems and applications as appropriate for the proposed infrastructure, supplemented by an Annual Technology Refresh Implementation Plan.
Objective 8: Operate and Maintain Risk Assessment Data and Tools
• Maintain the Hazards United States – Multi-Hazard (HAZUS-MH) software and associated national data sets and provide an appropriate level of end user support consistent with CDS objectives.
• Maintain relevance of HAZUS as a tool to increase the understanding of risk at the community level.
• Maintain the HAZUS software in accordance with the November 2016 HAZUS Strategic Plan.
• Explore innovative solutions with the FEMA OCTO for future HAZUS development to achieve faster runs, better ease of use, Application Programing Interface (API), and use of emerging datasets such as First Order Approximation data. Recommend options that would improve the flexibility of data exchange workflow between HAZUS and other products as necessary.
VIII. ASSUMPTIONS AND CONSTRAINTS
Universal Objectives Overarching Assumptions and Constraints
• All activities align with DHS/FEMA strategic goals and constraints.
• All contractors will work together with FEMA to develop program goals and shared metrics that demonstrate the Risk Management program goals are achieved.
• Outreach activities are coordinated, integrated, and consistent with Risk Management messaging throughout the Risk Management program including appropriate advisory focus groups.
• The offeror’s proposed Technical Solution should leverage existing FIMA investments and resources, are cost effective, and demonstrate a sound return on investment (ROI).
• The offeror’s Technical Solution should maintain data interoperability and consistency of operations across FIMA and with other FIMA stakeholders where appropriate and feasible.
• The offeror’s Technical Solution should meet these goals and objectives must address important federal mandates and business drivers, including, but not limited to: the Government Paperwork Elimination Act; the Government Information Security Reform Act;
the Clinger-Cohen Act; the Government Performance and Results Act; the Federal Records Act; the Computer Security Act; the Freedom of Information Act; the Disabilities Act;
Section 508 of the Rehabilitation Act; the Disaster Mitigation Act of 2000; the National Flood Insurance Reform Act of 1994;the Stafford Act; the Flood Disaster Protection Act of 1973, the Housing and Urban Development Act of 1969; the Privacy Act of 1974, as amended, the E-Government Act of 2002, as appropriate, as well as other laws and regulations specific to FEMA.
• The offeror’s proposed Technical Solution must comply with all statutes and demonstrate working knowledge of applicable regulations, policies, guidelines, and specifications that affect the NFIP, the mission of the Department of Homeland Security, and related multi-hazard programs including risk assessment in a pre- and post- disaster environment.
• The offeror’s proposed Technical Solution must demonstrate the flexibility to accommodate a changing environment as the roles and mission of the Risk Management Directorate evolves. In addition, the solutions may recommend changes to improve efficiency and effectiveness of Risk Management program functions and management.
• Data security and privacy issues are a major focus of the federal government's information technology efforts. All activities must be compliant with the Government Information Security Reform Act, OMB policies, and FEMA and the Department of Homeland Security requirements.
• Information technology (IT) systems must be coordinated with and comply with FEMA and Department of Homeland Security (DHS) enterprise architecture requirements.
CDS Objectives Overarching Assumptions and Constraints
General
• The offeror’s proposed Technical Solution must ensure continuity of operations so that there is minimal impact on existing programs.
• The offeror’s proposed Technical Solution must consider operation and maintenance of multi-hazard capabilities and services.
• Per the Asset Inventory, detailed in the Virtual Library, there is some non-GFE at ABL and DC2 e.g. IBM V7000 200Tb SAN that stores the MIP production data, that will either need to be replaced, substituted or acquired.
• Information pertaining to the majority of the existing facility leases and contracts is provided within the incumbent contractor’s Transition-out Plan. The only facility not included in this Transition-out Plan is DC2. As a result, this facility’s contract information is listed below:
o Location: HP Enterprise Services, LLC, DHS Data Center 2, Clarksville, VA
23927 o Primary Facility Purpose: IT Hosting o Lease Expiration: 6/26/17 o Landlord Notification Requirements: TBD o Maximum Months Extension: 3 remaining option years o Hp Customer Service Advocate for
FEMA: PaulVanderVoort@associates.hq.dhs.gov.
o Contract COR: Eugene.Luke@dhs.fema.gov
• The NFIP and Risk MAP program must be agile in order to be sustainable. Funding is dependent upon the NFIP premiums and year-by-year appropriations. Currently, there is no guarantee that these Programs continue to be funded, or even authorized, from year to year.
• All communities must be able to access Risk MAP products and intermediate data deliverables.
• The CDS contractor will support rapid issue resolution requests, such as requests and demands from Congress.
• The offeror’s proposed Technical Solution should address existing capabilities, including:
o Incorporating user and business requirements including all aspects of regional operations requirements.
o Building upon the progress made during Risk MAP and other Mitigation programs.
o E-commerce approach to services such as fee collection.
o Change management.
o Maintaining relevance of capabilities and services to FIMA’s mission.
o Supporting communications with the OCIO on FIMA’s IT Architecture guidance for Risk Management systems and applications.
• The Engineering Library receives the following approximate monthly requests:
o 135 internal data requests (IDRs);
o 151 external data requests (EDRs); and o 5-10 Freedom of Information Act requests.
Data, Security & IT
• Where security protocol allows, FEMA will maintain a Virtual Library for offerors of detailed materials about CDS operations and systems as well as evolving initiatives such as Customer Experience.
• If cloud services are proposed, the offeror’s Technical Solution shall provide an option that is FedRAMP certified for FIPS 199 Moderate or above, provides a government-only environment, and it will require approval from the FEMA and DHS CIOs.
o Data stored in cloud environments should be stored and exchanged in open standard, machine-readable formats to ensure compatibility with FEMA’s future needs and target enterprise architecture.
o Single Sign-On Integration: Cloud vendors must be able to integrate with FEMA’s Identity, Credentialing, and Access Management capabilities to provide PIV-enabled access to services.
o Any proposed activity will require consultation with the OCIO and the Office of Chief Technology Office (OCTO).
mailto:PaulVanderVoort@associates.hq.dhs.gov mailto:Eugene.Luke@dhs.fema.gov
• Contractors must comply with all DHS/FEMA IT requirements, including, but not limited to:
o Data center policy.
o Enterprise Architecture.
o IT systems security standards.
o Enterprise Architecture target for geospatial information infrastructure requirements.
o Section 508 compliance.
• Upon request, contracts must provide current copies of all IT system security documentation.
• All solutions must include a Data Quality Plan using the DHS Data Quality Planning Guidance and template.
• The offeror’s proposed Technical Solution must include utilization of IT best practices for collecting and documenting user and stakeholder requirements in a collaborative and iterative manner and can support evolving system needs.
• Contractors must use established IT life cycle management methodologies which includes third party validation and participation from users. Usability expertise applies to customer and data services objectives to ensure all aspects of the Risk MAP program are simple and straightforward for the public.
• DHS OneNet intranet services are available at DC2 and may be available for use at other approved data centers.
• All Sensitive But Unclassified (SBU) information shall be handled in accordance with all applicable FEMA policies and DHS MD 11042.1, Safeguarding Sensitive But Unclassified (For Official Use Only) Information.
• A contractor information system security plan is required when DHS sensitive data will be handled/ processed at a contractor’s facility or on contractor equipment.
• The offeror’s proposed Technical Solution must determine the need for use of National Information Exchange Model (NIEM) for data feeds and information exchanges as a means of improving the quality of information exchanged and minimizing the number of separate data feeds and information exchange developed.
• The DHS Systems Engineering Lifecycle (SELC) or comparable FEMA version of the DHS SELC shall be incorporated into the offeror’s proposed Technical Solution.
• Enterprise Licenses may be available through DHS and FEMA, and must always be investigated as part of the solution and task orders.
• The Engineering Library is nearly 100% digital with respect to back-up data and most maps. There are some older miscellaneous materials that may need to be physically provided for in small storage space. Further there is a small need for micro fiche reading capability.
• Connection to FEMA’s Mt. Weather facility is required. There will be iterative coordination with Mt. Weather and the OCIO in order to accomplish the required connections and pass necessary certification and accreditation for the systems discussed in this SOO.
• Prototype solutions may be requested by the program to demonstrate design efficacy before initiating work on complex maintenance activities and non-material enhancements to existing systems and applications..
• The Risk Management Directorate is currently engaged in developing a 10 Year Strategic
Plan for the Directorate and therefore the Risk MAP Program. Inputs such as the TMAC recommendations for FEMA are being considered as part of the planning process. The resulting Strategic Plan will likely require the Directorate to modify or extend the portfolio of risk management products and services it offers to stakeholders as it seeks to refine its understanding of existing terrain and further develop its hazard analysis acumen. There may therefore be data collection, storage and dissemination maintenance needs in order for CDS to remain relevant to Risk Management. Since the Strategic Plan is under development, no specific guidance can be given at this time regarding storage and access requirements of any new data.
• It is noted in this SOO and Virtual Library documentation that significant quantities of data and large data files, such as LiDAR and coastal analyses, reside within FIMA and parts, or all, of such data, in addition to other types of hazard data, may need to be stored by the CDS contractor at some point during the period of performance of the CDS contract in a way that follows security standards and policies.
• At a minimum, the process of accepting responsibility for hosting, operating, and maintaining applications developed by other providers should account for: 1) transfer of complete technical requirements documentation, existing user manuals and outreach materials, GFE requirements, software and license information, and business knowledge required to operate and maintain the application (e.g., reporting requirements); 2) transfer of operational understanding (e.g., data refresh rates, system operations and middleware/OS configurations, existing maintenance records and build deployments); 3) certification and accreditation process requirements (e.g., updates to system-level documentation); and 4) a clearly defined cutover process to include testing procedures and concurrence on readiness. The full process must comply with DHS/FEMA IT security standards and policies.
• Comply with all information sharing and privacy related guidance, statues, and procedures regardless of information collection tools to include proper reporting of suspected and confirmed privacy related incidents and the development of appropriate privacy compliance documentation.
• All proposed maintenance and operations activities, to include fixes to maintain full operational capability, must account for FEMA’s Guidelines and Standards for Flood Risk Analysis and Mapping (https://www.fema.gov/guidelines-and-standards-flood-risk-analysis-and-mapping)
LOMC
• The current fee collection tools used are Pay.gov for credit cards and OTCnet for checks and money orders (deposited twice a week into the U.S. Treasury account at a local Bank of America branch).
• Fees are collected for Letters of Map Change and distribution of engineering library materials through external data requests.
MIP
• The MIP is designed to support 75 users per day and up to 50 concurrent users.
• The MIP availability should be consistent with system FIPS 199 classification as
Moderate.
• The MIP and MSC together house over 100TB of production data.
https://www.fema.gov/guidelines-and-standards-flood-risk-analysis-and-mapping https://www.fema.gov/guidelines-and-standards-flood-risk-analysis-and-mapping
• The same security requirements are required for the Development and Test environments as the MIP and MSC data center production environment.
Contact Centers
• The consolidated call center shall be located in the Washington, DC Metropolitan Area in commercial space within 25 miles of FEMA HQs at 500 C Street, SW, Washington, DC.
• The contractor may propose the designated standard hours of operation.
• The consolidated call center could see a potential increase of 12,600 calls per month.
FMIX
• The FMIX offers Tier 0 self-service options, Tier 1 general inquiries services, Tier 2 technical assistance for Risk MAP IT systems in addition to handling Tier 3 technical calls that require the assistance of the IT developers.
• MIP Help Desk support is provided Monday through Friday. Peak periods occur during normal mitigation planning periods.
• The FMIX receives approximately 11,000 mapping inquiry and map change request calls in addition to approximately 1,000 emails and 1,000 live chats per month. The FMIX staff also performs MT1 processing to balance their workload.
• Current FMIX call center operators possess degrees related to the fields of hydrography, geography, environmental, etc, as well as possess a Certified Floodplain Manager certification.
• The current CMS product used is Avaya; this is not a mandatory system, nor is this product standardized across FEMA call centers.
IX. SECURITY REQUIREMENTS
SECURITY REQUIREMENTS AND ORGANIZATIONAL CONFLICTS OF INTEREST
Personnel accessing DHS and/or FEMA worksites will require security in-processing, including clearance in accordance with Homeland Security Presidential Directive 12. (This statement covers all security requirements we will have on this project)
The Contractor may be exposed to nonpublic or otherwise sensitive information subject to restricted use and disclosure. Accordingly, all personnel assigned to the project must sign a nondisclosure agreement as prescribed by the Contracting Officer. Furthermore, the assessment’s findings, analytical conclusions, and recommendations, shall be restricted from disclosure to persons not specifically affiliated with the project unless otherwise approved by the Contracting Officer.
If access to government information technology (IT) systems is necessary, federal, DHS, and/or local IT security requirements must be followed.
In accordance with FAR 9.505-1, a Contractor that provides systems engineering and technical direction for a system but does not have overall contractual responsibility for its development, its integration, assembly, and checkout, or its production shall not be awarded a contract to supply the system or any of its major components; or be a subcontractor or consultant to a supplier of the system or any of its major components.
Security Management All statements of work and contract vehicles shall identify and document the specific security requirements for IT services and operations required of the contractor
Contractor IT services and operations must adhere to all DHS and FEMA IT security policies.
Requirements shall address how sensitive information is to be handled and protected at the contractor’s site, including any information stored, processed, or transmitted using the contractor’s computer systems, the background investigation and/or clearances required, and the facility security required.
FEMA IT Security Branch shall conduct reviews to ensure that the IT security requirements are included within the contract language, are implemented and enforced.
Security deficiencies in any outsourced operation shall require creation of a program-level
POA&M.
All…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .