SETA Enterprise Content Management Work Order SOO 05262009.pdf

PDF 70 KB Posted

Attached to
Systems Engineering and Technical Assistance (SETA) Federal contract opportunity
Solicitation number
HSFEHQ-09-R-1960A
Issued by
Federal Emergency Management Agency Information Technology Section

About this file

SETA Task Order 01 SOO

View the file

Other files for this federal contract opportunity

Other files attached to Systems Engineering and Technical Assistance (SETA), newest first.
File Type Posted
SETA Multi-Step Advisory 07082009.pdf PDF
SETA Multi-Step Advisory.pdf PDF
Summary of Questions and Responses from FEMA SETA Pre-Solicitation Conference June 16 2009.pdf PDF
_SOA_FEMA ITD SETA IDIQ SOW 06302009.pdf PDF
SETA Multi-Step Advisory 07062009.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Draft

Systems Engineering and Technical Assistance (SETA) Work Order Indefinite Delivery, Indefinite Quantity

FEMA Document and Enterprise Content Management Services

1. INTRODUCTION

1.1 Background

In recent years, FEMA has implemented a variety of enterprise services in the areas of documents management, records management, content management and business process management to provide mission and business support to the Agency. These implementations have occurred as a set of disparate investments without an overarching strategy and legacy solution consolidation plan. At present that Agency has various solutions, in some cases duplicative solutions that support the same set of services.

The purpose of this effort is to assess and evaluate the current solution set, define the target solution set and implement new capabilities and define the approach to migrate capabilities to the target environment.

It is recognized that no single solution is able to satisfy all the requirements of the Agency. The definition of the target set of solutions for enterprise document and content management system will provide FEMA with critical technology that will assist the agency to more effectively manage its important structured, semi-structured and unstructured documents and information, such as text documents, spreadsheets, graphical presentations and images, photographs, XML components, multimedia files including audio and video files, and e-mail messages.

1.2 Purpose

The purpose of this work order is to identify and assess the current document management. Enterprise content management and business process management capabilities within FEMA, to determine and define an enterprise -wide set of solutions that will form the core services in support of these domains. A goal of this effort is to reduce, consolidate and architect a solution based on the defined set of requirements using commercial off the shelf (COTS) software and hardware solutions

2. SCOPE

Working with the FEMA Information Technology Directorate, assess the current set of solutions, recommend a target solution set and implement a set of business services on this solution. This will include document management, enterprise content management and business process and workflow management. This may include scanning, indexing, searching and retrieval capabilities.

July 6, 2009 SETA Enterprise Content Management Work Order SOO 05262009

3. OBJECTIVES

3.1. Document Current State FEMA Document Management, Enterprise Content Management, Business Process Management Architecture and Processes

• Ascertain and document current “as-is” (baseline) solutions and processes.

• Assess the functional capabilities, solutions standards, platform stability and maturity and identify deficiencies and opportunities.

• Provide discovery results of FEMA’s baseline Document Management /

Enterprise Content Management Architecture and Processes in a file format compatible for import into FEMA’s Composite EA Model and Repository.

3.2. Define Target Document Management/Enterprise Content Management Architecture Requirements

• Conduct target requirements analysis in coordination from FEMA Information Technology Directorate and Agency mission and business support organizations..

• Collect, define, and validate functional and non-functional requirements, including enterprise architecture and security.

• Target Architecture shall include requirements, as a minimum, for the following:

o Enterprise document and content management o Business process management o Implementation of workflow solutions o Document scanning o Optical Character Recognition (OCR) with the ability to convert scanned

PDFs into searchable text o Metadata structure and dictionary o Integration with FEMA Business Process Management Suite o Management Consoles and Dashboards for reporting and alerts o Records Management o Graphic Image Management o Electronic Forms Development/Processing o Governance

• Development of target architecture must include the recognition of the installed based of solutions and technologies already in place to support these functions

• Baseline the project schedule, cost, and scope and update security Certification and Accreditation (C&A) documentation, as needed.

• Provide results of Target Requirements Analysis in a file format compatible for import into FEMA’s Composite EA Model and Repository.

3.3. Architect and Design Document Management / Enterprise Content Management System

• Transform the requirements into comprehensive, logical, and detailed architectural design using commercial off the shelf software and hardware to guide development and implementation.

• Review plans with appropriate FEMA Subject Matters Experts and

July 6, 2009 stakeholders to validate the design.

• Provide appropriate documentation for Department of Homeland Security

Systems Engineering Life Cycle and Enterprise Architecture Decision processes in conjunction with Chief Enterprise Architect.

3.4. Implement Electronic Contracts Administration Document Management/ Content Management Pilot Project

• If tasked, implement Electronic Contracts Administration Document Management/Content Management system architecture for FEMA’s Management Directorate Acquisition Management Division Acquisition Operations Branch. This pilot project will be used to prove the feasibility of the proposed solution as a Document Management/Content Management System for FEMA.

o FEMA’s Management Directorate Acquisition Management Division Acquisition Operations Branch documents are contained in a central location and can be described as follows:

Room Dimensions: 31’ x 15’

• Primary Composition: Burroughs Aisle-Saver

Shelving System (MA100) (http://www.borroughs.com/products/aislesaver.aspx

• 24 Total Double Carriages, 2 Total Single Carriages, 75% Capacity

• Per Carriage Dimensions: 6 Shelves (40”width x 11.5” depth x 11” height)

Secondary Composition: 15 Lateral File Cabinets, Single Drawer (32” width x 16” depth x 13” height), 30% Capacity

• Estimated No. of Audio\Video Files: 100

• Estimated No. of File Folders: 9,000

• File Folders Composition: Letter Size 90%, Legal

Size 10%, Loose 80%, Stapled 20%, One-Sided 80%, Two-Sided 20%, Non-Graphical 95%, Graphical 5% o Users of the Electronic Contracts Administration Document Management/Content Management Pilot Project include, at peak times, approximately 300 staff members of the Division Acquisition Operations Branch and approximately 1,500 Contracting Officer Technical Representatives.

o All Acquisition Operations Branch documents (described in paragraph above) shall be scanned.

Scanning will occur at FEMA Offices in Washington DC Convert existing pdf and other electronic file formats to searchable pdf files

• Conduct unit testing throughout development

• Conduct configuration management

• Develop all required IT Security documentation leading to an approved C&A documentation package in conjunction with FEMA Chief Information Security Officer.

July 6, 2009 http://www.borroughs.com/products/aislesaver.aspx

3.5 Provide Training and Support

• Develop and provide training materials and technical documentation in the English language.

• Provide conference and meeting rooms, as necessary, to discuss Document Management/Enterprise Content Management issues

3.6 Analyze Enterprise Network and Voice Program Effect

• The emergence of this new capability will lead to an increase in electronic transfer of large files and personnel communications across the organization.

If tasked, the contractor shall provide expertise and engineering assistance to assess impact to the FEMA IT Network, Voice and\or Wireless Domains. The assessment may include:

o Provide wireless system engineering advice and technical assistance in support of the FEMA Enterprise and disaster response network environments o Engineering and technical assistance in the implementation of wireless systems solutions o Engineering and technical assistance in the implementation of wireless cellular and Inmarsat satellite solutions o Voice systems planning, analysis, design, development, testing, integration, and installation associated with a nationwide voice network o Voice system & network design engineering using engineering Computer Aided Design; hardware development o Simulation and modeling in support of voice systems design and analysis o Network capacity assessment and planning

3.7 Analyze FEMA IT Video Domain Impact

• The emergence of this new capability will lead to an increase in video teleconferences (video & content) across the organization. If tasked, shall provide expertise and engineering assistance to assess impact to the FEMA IT Video Domain. The assessment may include:

o Provide video system engineering advice and technical assistance in support of the FEMA Enterprise o Engineering and technical assistance in the implementation of video systems solutions o Video systems planning, analysis, design, development, testing, integration, and installation associated with a nationwide video network o Video system & network design engineering using engineering Computer Aided Design; hardware development o Simulation and modeling in support of video systems design and analysis o Network capacity assessment and planning related to video

July 6, 2009

4. POST AWARD REPORTS AND DELIVERBABLES

• Written reports as required by the Work Order and approved by the Contracting Officer’s Technical Representative (COTR).

• Security System Plan (SSP)

• C & A documentation and updates, as required

• Project Task Schedule five days after Task Initiation.

• Weekly Status Activities Report showing progress and accomplishments of past week (Thursday through Wednesday) and planned activities for next week, each Thursday at close of business, no later than 5:30 pm Eastern Time.

• Weekly project cost and budget reports including staff burn rate.

• Meeting minutes, as required.

• Support the development of professionally designed, written and produced educational materials explaining the FEMA Document and Enterprise Content Management System.

5. PERIOD OF PERFORMANCE

The period of performance for this Work Order shall be for a base period of four (4) months with four annual renewable options for the duration of the Work Order. The Government will consider and evaluate an alternate contractor-proposed period of performance.

6. CONSTRAINTS

The Contractor will be required to provide professional technical services resulting in deliverables related to the program’s needs as described in this Work Order. The contractor is advised that the Government will normally have a minimum of five (5) business days to review and provide comments on all deliverables produced under the task order that results from this competition and that upon receipt of the Government’s comments or suggested changes, the contractor shall have a minimum of 3 work days to revise their deliverables to address the Government’s comments or suggested changes.

The contractor is further advised that there may be situations requiring shorter time frames to revise documents based upon the Government’s review. Such situations will be communicated to the contractor by the Contracting Officer’s Technical Representative (COTR). The contractor may be required to provide an expedited re-work of deliverables to address the Government’s comments or suggested changes to contract deliverables.

While the Work Packages outline the work products and deliverable requirements, the following constraints are highlighted:

• The contractor shall ensure that all systems and items are in compliance with

Section 508 standards and exceptions as delineated in the DHS Systems Engineering Life Cycle, and all other applicable requirements & processes.

• As applicable, contractor shall assure that all proposed or implemented information systems and products supporting enterprise-wide records management are in conformity with DOD 5015.2 certification requirements.

July 6, 2009

• The contractor shall follow IT configuration management procedures by maintaining a commercially available software configuration management system as approved and owned by FEMA.

• The contractor shall ensure that required documentation is in accordance with all DHS/FEMA Directives that apply. Documentation also has to be consistent and matured with the expectation of a Capability Maturity Model Integration (CMMI) Level 3 organization. Where documentation is not present for systems, it has to be created and maintained to reflect the current state of the applicable application and its touch points.

• The contractor shall work with Government personnel as an integrated project team (IPT) to accomplish the assigned work requirements under this contract, and with contract staff who are involved with information technology support throughout other components of FEMA.

• The contractor shall become proficient with and maintain an understanding of DHS/FEMA security policies and procedures and EA to assure that all deliverables meet these requirements.

7. Security Requirements

7.1 Security Management

The contractor shall appoint a senior official to act as a Security Officer. The individual shall work collaboratively with the FEMA IT Security Branch through the COTR on all security matters, to include physical, personnel, and protection of all sensitive documents/material handled by the Contractor.

The COTR and FEMA Security Office will have the right to inspect procedures, methods and facilities utilized by the Contractor to comply with the security requirements under this contract. Should the COTR or FEMA Security Office determine that the Contractor is not in compliance with the security requirements of the contract, the Contracting Officer shall notify the Contractor, in writing, of the appropriate action the contractor must take to rectify any non-compliance with the contract security requirements.

7.2. Information Technology Security Clearance

When sensitive government information is processed on Department telecommunications and automated information systems, the Contractor shall provide for the administrative control of sensitive data being processed and adhere to the procedures governing such data as outlined in “DHS IT Security Program – Publication DHS MD 4300.Pub.” Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level.

Contractors who fail to comply with Department security policy are subject to having their access to Department IT systems and facilities terminated, whether or not the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g. Privacy Act).

7.3. Information Technology Security Oversight and Training

July 6, 2009

• All statements of work and contract vehicles shall identify and document the specific security requirements for IT services and operations required of the contractor.

• Contractor IT services and operations must adhere to all DHS and FEMA IT security policies.

• Requirements shall address how sensitive information is to be handled and protected at the contractor’s site, including any information stored, processed, or transmitted using the contractor’s computer systems, the background investigation and/or clearances required, and the facility security required.

• FEMA IT Security Branch shall conduct reviews to ensure that the IT security requirements are included within the contract language, are implemented and enforced.

• Security deficiencies in any outsourced operation shall require creation of a program-level Plan of Action & Milestones (POA&M).

• All personnel who access Department information systems will be continually evaluated while performing these duties. Supervisors should be aware of any unusual or inappropriate behaviors by personnel accessing systems.

• Each Major Application or General Support System must have an ISSO assigned unless excepted, mitigated, or waived by the FEMA CISO.

• Any unauthorized access, sharing of passwords, or other questionable security procedures should be reported to the local Security Officer or Information System Security Officer (ISSO) of the application of system.

• Contractors involved with management, use, or operation of any IT systems that handle sensitive information within or under the supervision of the Department, shall receive periodic training at least annually in security awareness and accepted security practices and systems rules of behavior. Department Contractors, with significant security responsibilities, shall receive specialized training specific to their security responsibilities annually. The level of training shall be commensurate with the individual’s duties and responsibilities and is intended to promote a consistent understanding of the principles and concepts of telecommunications and IT systems security. This training will be provided by

FEMA.

• On behalf of the Program Manager and system owner, the contractor shall ensure the security documentation required for certification and accreditation (C&A) is properly prepared and completed in accordance with the DHS 4300A Sensitive Systems Policy. All documentation will be completed using the Department’s tools, Risk Management System (RMS) and Trusted Agent FISMA (TAF). The PM and/or the system owner will ensure an ISSO is stood up to support the IT system built by the contracted element. All efforts will be coordinated with the FEMA Chief Information Security Officer (CISO). At the direction of the CISO, all documentation will be submitted to the IT Security Branch for review and approval. ITSB will review IT Security documentation and ensure it meets acceptance criteria prior to testing. Acceptance will be based upon the below following the DHS 4300 Security Artifacts Criteria. Upon approval, the ITSB will schedule and perform the ST&E and other associated documentation necessary for an Authority to Operate.

July 6, 2009

SBU Artifacts NSS Artifacts Criteria

1. FIPS 199 Assessment SSAA Paragraph 6.4 Level of Effort Determination

1 Information Types are defined for the system 2 Security Categorization is provided 3 Example: Workbook is completed

2. Risk Assessment SSAA Paragraph 2.3 Threat Description

4 Addresses Threats and Vulnerabilities to the system 5 System Specific Results of the risk assessment not a “plan” that says risk assessment will be conducted

3. System Security Plan

(SSP)

System Security Authorization Agreement (SSAA)

6 Defines security controls 7 Defined system boundary 8 Identifies ISSO and System Owner 9 Follows RMS Template format for C&A projects initiated after April 11, 2005

4. Contingency Plan SSAA Appendix L - Contingency Plan

10 System specific backup and recovery procedures are provided 11 Identifies alternate or off-site storage facility 12 Identifies names and contact information of team members 13 Identifies names and contact information of vendors, including alternate and off-site vendor POCs Identifies a recovery strategy

5. Privacy Threshold / Impact Assessment (PTA/PIA)

PTA / PIA 14 Statement that PIA is not applicable or 15 Does not require signature now 16 Example: Workbook is completed

6. E-Authentication E-Authentication 17 Statement that E-auth is not applicable or 18 E-authentication Level identified (1,2,3,4) 19 Example: Workbook is completed

7. Controls Testing (ST&E) Plan

SSAA Appendix H - Security Test and Evaluation Plan and Procedures

20 System specific test procedures 21 Identifies tools used

8. Contingency Plan Test Results

Contingency Plan Test Results

22 Data back-up is tested 23 Data recovery is tested

9. Security Assessment Report

SSAA Appendix P Security Test and Evaluation Report

10. Accreditation Letter

(ATO)

Accreditation Letter 24 Signed by DAA or other non-contractor designee 25 Dated 26 Identifies correct system

11. Self Assessment (NIST

SP 800-26)

Self Assessment 27 CISO review and approval.

July 6, 2009

File details come from the government source that posted it. Updated .