Statement_of_Work_QA.pdf

PDF 166 KB Posted

Attached to
Quality Assurance IT Support Federal contract opportunity
Solicitation number
HSFEHQ-11-R-0019
Issued by
Federal Emergency Management Agency Information Technology Section

About this file

State of Work

View the file

Other files for this federal contract opportunity

Other files attached to Quality Assurance IT Support, newest first.
File Type Posted
FBO Notice.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FEMA Quality Assurance (QA) Services Indefinite Delivery, Indefinite Quantity Statement of Work

Department of Homeland Security (DHS) Federal Emergency Management Agency

(FEMA)

Quality Assurance

(QA)

Indefinite Delivery, Indefinite Quantity Statement of Work

September 1, 2011

1. Background

2. Purpose

3. Scope

4. Functions Performed in Support of this Contract Effort

5. Task Order Deliverables

6. Task Order Reporting

7. Task Order Prioritization

8. Placement of Additional Task Order

9. Period of Performance

10. Place of Performance

11. Hours of Operation:

12. Travel

13. Key Personnel

14. Security

15. Government-Furnished Equipment and Information

16. DHS Enterprise Architecture Compliance

17. Accessibility Requirements (Section 508)

18. Training of Contractor Staff

19. QA Standards Applicable to Task Orders

1. Background

The Federal Emergency Management Agency’s (FEMA) mission is to reduce the loss of life and property and protect communities nationwide from all hazards, including natural disasters, acts of terrorism, and other man-made disasters. FEMA leads and supports the nation in a risk-based, comprehensive emergency management system of preparedness, protections, response, recovery and mitigation. FEMA has developed a suite of information systems to meet this mission and provides users a responsive array of information services. FEMA’s enterprise information technology (IT) systems are operated and maintained at the highest level of performance and reliability twenty-four

(24) hours a day, seven (7) days a week.

The work under this acquisition falls under the auspices of the Federal Emergency Management Agency (FEMA) Office of Chief Information Officer (OCIO). The CIO’s mission is “to enhance and maintain Information Technology infrastructure; develop and enhance key systems to support operating programs; increase efficiencies and cooperation across FEMA’s divisional and regional lines.” The CIO’s vision is to modernize the FEMA IT to “deliver world-class secure Information Technology guidance, products, and services to meet the needs of FEMA’s emergency managers and stakeholders nationwide.” The CIO’s objective of the short, middle and long term modernization efforts is to transform the information technology services into a best-of-class, enterprise focused, efficient and well-managed environment. This environment must be implemented with the flexibility required to support the evolving mission of FEMA and to support the surge requirements necessary to support emergency situations as they occur.

The current FEMA information technology environment is an amalgam of new and old technologies, architectures, platforms and tools that includes a wide variety of PC-based, client server, web-based and service-oriented (SOA) components. These systems have been implemented by FEMA using a variety of service providers under various oversight and governance conditions. Meeting FEMA IT services and support goals will be achieved by utilizing a comprehensive approach and strategy that is consistent with both the Department and Agency strategy. Major components of these strategies include data center consolidation, implementation of enterprise network services, implementation of technology standards, consistent application of security services and configurations and to leverage current technologies to provide services to citizens and other government components.

The Office of the Chief Information Officer (OCIO), Mission Systems Bureau of the Federal Emergency Management Agency (FEMA) has instituted the Quality Assurance (QA) Independent Verification and Validation (IV&V) Branch. IV&V’s mission supports FEMA’s mission by implementing quality assurance for IT systems and services that are reliable and responsive to the needs of stakeholders and ensures compliance to standards by using best practices of independent testing, configuration management, requirements management and risk management services throughout DHS\FEMA Systems Engineering Life Cycle (SELC).

2. Purpose

The Federal Emergency Management Agency (FEMA) OCIO, Quality Assurance IV&V Branch (OCIO- QA) is tasked with providing complete Quality Assurance support to all FEMA systems, to include applications, LANs, COTS, Hardware, WEB, COM, GOT and WAN, during all phases of the System Engineering Life cycle (SELC). The term SELC encompasses all forms of System Lifecycle within FEMA, encompassing the Software Engineering Lifecycle (SELC), Software Development Lifecycle, (SDLC) and/or System Development Lifecycle (SDLC). FEMA requires a full range of technical assistance services and support to meet these mission requirements.

Software Quality Assurance (SQA) is a key part of the entire software development process, which includes, but is not limited to: processes such as requirements management, source code control, change management, software/applications/system testing, IV&V, configuration management, release management and risk management.

The purpose of this acquisition is to procure a comprehensive set of services that can be provided by the Quality Assurance (QA) Section in support of the full life cycle of systems and software development, system operations and maintenance, and system sustainment for FEMA IT and its customers.

3. Scope The contractor shall provide the full range of technical support and assistance required by FEMA for conducting quality assurance activities relating to its information technology systems and infrastructure.

FEMA is in the process of restructuring and developing documented repeatable processes in order to obtain CMMI Level 3 certification. The contractor shall provide support, as directed, to QA staff, project managers and customers in the following process areas:

3.1. Establish Quality Assurance /Program Management

3.1.1. Maintain and update the baseline documentation sets for projects. As well as requirements, design, and development artifacts, these documents should contain program costs, schedules and performance objectives.

3.1.2. Develop quality assurance guidance documents and templates, including quality assurance checklists that foster continuous improvement

3.1.3. Ensure that system development teams adhere to Quality Assurance Surveillance plans.

3.1.4. Support the FEMA Chief Information Officer in establishing and maintaining quality assurance documents in support of all FEMA IT initiatives.

3.1.5. Provide processes and tools to evaluate how proposed IT initiatives support the agency’s goals and objectives.

3.1.6. Manage an enterprise-wide performance measurement program that monitors the cost-schedule performance of IT projects as well as their contribution to the FEMA mission.

3.1.7. Assist FEMA in selecting IT projects that contribute the greatest benefit to the FEMA mission. Analyze and report on project issues such as cost, technical trade-offs, and schedule dependencies.

3.1.8. Prepare charters and procedures for the technical committees needed for effective IT program management, including:

3.1.8.1.Technical Review Committee to assess projects for their compliance with the FEMA technical architecture and to make enterprise-wide decisions regarding hardware and software product selection.

3.1.8.2.The contractor shall support this committee with product research and proof-of-concept testing of candidate technologies.

3.1.8.3.Interface Control Working Group to define the standards of data exchange and inter-operability among FEMA systems

3.2. Support Requirements Management and Requirements Definition

3.2.1. Establish requirements management processes to ensure that FEMA develops the “right system” that fulfills the user’s mission requirements.

3.2.2. Establish procedures to manage and track requirements throughout the entire lifecycle of a project.

3.2.3. Establish procedures to trace and manage Test Cases based on defined requirements Develop templates for a project-level requirements management plan that defines the minimal elements needed to ensure adequate control of requirements changes throughout the development lifecycle.

3.3. Establish Configuration Management processes

3.3.1. Implement, manage and oversee a coordinated FEMA configuration management process.

3.3.2. Develop standardized templates for configuration management plans, release management plans and related documentation that define government, contractor and user responsibilities.

3.3.3. Establish appropriate controls for the movement of software to the test and production environments.

3.3.4. Develop the procedures and then support the daily conduct of a FEMA-level Configuration Control Board.

3.3.5. Conduct configuration audits to confirm that system configurations are consistent with technical documentation.

3.4. Institute Risk Management

3.4.1. Apply risk management processes and procedures to support risk management controls for software applications and systems throughout the FEMA SELC.

3.4.2. Evaluate the existing FEMA risk management processes, align these processes in the program and project level with best practices and integrate with other areas such as configuration management, requirements management and project management.

3.4.3. Identify key business risks and determine if the proper internal controls and processes are in place to reduce risks to acceptable levels.

3.4.4. Support investigations and risk-management studies to perform technical analysis in order to find solutions to critical problems in the technical implementation of projects.

3.4.5. Conduct trend analysis, process analysis, and requirements analysis for IT projects within the FEMA.

3.5. Perform Validation and Verification/Test Management

3.5.1. Provide software application testing, test result analysis and assistance in determining whether the developed application meets the documented requirements from the program office.

3.5.2. Perform functional, performance and regression testing activities.

3.5.3. Prepare and execute automated test scripts using GFE HP test tools.

3.5.4. Conduct tests to ensure Section 508 compliance using the DHS-approved tool suite.

3.5.5. Identify performance and functional usability issues with applications. Document these problems for review by the affected program office.

3.5.6. Prepare standardized test reports and analyses for all testing operations.

3.5.7. Provide the technical support required to operate and maintain the Consolidated Test Facility (integrated testing and IV&V testing environments)

4. Functions Performed in Support of this Contract Effort

The QA, IVV Branch under the direction of the FEMA CIO will be responsible for the management and execution of Task Orders issued against the IDIQ contract for the performance of some or all of the following functions listed. This list is not all-inclusive, but it is a representative of the functions that could be performed under the resulting contract:

4.1. Quality Assurance/Program Management

Performance-based management links investment planning with the systematic use of select feedback to manage projects and processes. Successful performance-based management depends upon the effective use of performance measures. The contractor shall provide assistance in the following areas:

4.1.1. Linking IT Projects to Agency Goals and Objectives

The contractor will assist in building partnerships with program offices and functional areas to define projects that contribute to the overall agency’s goals and objectives.

4.1.2. Developing Performance Measures

The contractor shall assist in developing meaningful performance measures. These shall include more than just cost, timeliness and quality. The performance measures must include measurements of the achievement of goals and usability for which the system was developed in terms of identifiable improvements in the quality and delivery of the organization’s services and products.

4.1.3. Establishing a Baseline to Compare Future Performance

The contractor shall use the performance measures established to measure and establish the baseline. The establishment of a baseline in terms of quality and delivery of products will enable later management of the performance measurement program to determine their progress.

4.1.4. Selecting IT Projects with the Greatest Value

The contractor shall assist in the development and application of cost benefit analysis studies. These studies will then be used to determine the best use of resources to facilitate the optimal gain toward accomplishing the agency mission.

4.1.5. Collecting Performance Data

The contractor shall assist in the collection of costs, timeliness, and quality performance data measures. The data will also include analysis that measures the strategic gains toward the overall mission of the agency.

4.1.6. Analyzing Results

The contractor shall assist in the analysis of the results to provide feedback to FEMA on the expected result versus the actual result. This analysis will look at all performance measures and consist of an analysis of what the data showed. Analysis of data in this instance is more than just using the objective data, but also incorporating subjective data of the users in terms of usefulness and effectiveness of the system.

4.2. Requirements Management

Requirements Management is the SELC component that ensures FEMA develops the “right system” that fulfills the user’s mission specifications. The Contractor shall be proficient with IBM Rational RequisitePro for Requirements Management. The contractor shall provide full system life-cycle requirements management support to include, but not limited to:

4.2.1. Evaluate and make recommendations on the project’s process and procedures for managing requirements.

4.2.2. Working as part of the Integrated Project Team (IPT) to verify that system requirements are well-defined, understood, documented, and testable with IV&V Test Section existing HQ Quality Center testing solution.

4.2.3. Verify that software requirements can be traced through design, code and test phases to verify that the system performs as defined by FEMA IT customers.

4.2.4. Verify that requirements are under formal configuration management control.

4.2.5. Validate that the relationships between each software requirement and its system requirement are correct.

4.2.6. Providing expertise in developing a Requirements Management Plan outlining the minimal elements needed.

4.2.7. Perform functions to establish and implement requirements control processes;

assisting in defining the specifications for government, contractor, and user responsibilities.

4.2.8. Establishment of procedures and methods to manage and track the requirements throughout the life-cycle of the product.

4.2.9. Assist in the creation of Requirements Traceability Matrices

4.2.10. Performing reviews and required coordination to identify technical and operational issues and such as requirements definition, architecture and policy compliance and engineering guideline development or compliance assessments.

4.2.11. Recommending opportunities for resolving issues in requirements, data, applications and infrastructure elements.

4.2.12. Analyzing and reporting impacts on issues such as costs, engineering trade-offs, return on investment, schedule dependencies and technically feasible alternatives and solutions.

4.2.13. The contractor shall assist in the training and dissemination of all new/revised QA documents, templates, and procedures, as applicable, to FEMA project teams to foster and ensure an enterprise wide approach to quality management.

4.3. Configuration Management (CM)

Configuration Management is the SELC component that ensures control of the baseline and an understanding of each system as currently fielded/developed. CM is vital to effective SELC product assurance and control. CM activities are the means through which program and functional managers control the integrity and continuity of the design, engineering, and cost trade off decisions. Support shall include:

4.3.1 Identifying functional and physical characteristics of selected system components during the system’s life-cycle.

4.3.2 Assisting in controlling changes to those characteristics.

4.3.3 Recording and report change processing and implementation status.

Configuration Management support shall address hardware and computer software configuration items (HWCI/CSCI), engineering changes, interfaces to internal and external system components, system documentation, and FEMA architectural aspects.

Under this task area the contractor shall propose design and assist in implement templates for:

4.3.4 Minimal elements of a Configuration Management Plan

Describe the configuration control process, specifying government, contractor and user responsibilities. The plan shall include the establishment of:

4.3.5 Configuration Control Board (CCB)

The plan should include the establishing of the CCB composition, procedures and participate in the management of the CCB.

4.3.6 Technical Review Committee (TRC)

Establishing TRC composition, procedures and participate in the management of the

TRC.

4.3.7 Interface Control Working Group (ICWG)

Establishing the ICWG composition, procedures and participate in the management of the

ICWG.

4.3.8 Configuration Audits (CA)

Conducting CA to include functional (FCA), physical (PCA) and all other audits designed to confirm that system configurations are consistent with technical documentation.

4.3.9 Configuration Management Implementation

The contractor shall implement the CM process in accordance with the approved FEMA CM plan. The contractor will collect problem reports, coordinate and schedule the CCB, TRC, and ICWG. Provide information packets, present issues/recommendations to the groups, maintain the baseline and provide reports and status, as coordinated and in agreement with FEMA.

4.4 Risk Management Support

4.4.1 Identify, characterize, and assess threats and documenting risk throughout the system’s lifecycle, through the use of risk identification methods and the application of (e.g. DHS, FEMA IEEE, PMI), search for and identify potential issues and concerns which could impact the overall success of projects. Methods to identify risks may include; monitoring project activities, examining artifacts and documentation, observing, interviewing, polling, surveying, participating in discussions and meetings, conduction focus sessions, and applying DHS and FEMA oversight guidelines.

4.4.2 Assess the vulnerability of critical systems and evaluate the measured risk and constraints. Transform risk items into information that can be used to aid decision-making and to validate risk information, using risk analysis. Risk analysis involves classification and prioritization of risk items, providing recommendation for mitigating and measuring risk items, and reviewing risk item information.

4.4.3 Verify/determine risk classification by performing root cause analysis to determine risk class. Risk classes are usually a higher level of abstraction derived from individual risk items. Risk impact is a description f the anticipated consequences of a risk event occurring.

4.4.4 Verify/determine risk probability by considering the likelihood of the risk occurrence.

4.4.5 Verify/determine risk timeframe as the period of time within which the risk is expected to occur expressed in terms of short-term, medium-term, or long-term.

The determination of risk timeframe is a subjective, qualitative process which considers the criticality of internal and external project factors within the specific context of the project.

4.4.6 Verify/determine the risk exposure derived from the risk attributes of impact and probability, used in conjunction with timeframe to prioritize risks for mitigation and escalation. Determine risk exposure for each risk from the intersection of that risk’s impact and probability.

4.4.7 Verify/determine risk severity of the importance of the risk based upon 1) potential impact of the risk on a project, 2) the probability of occurrence, and 3) the risk timeframe.

4.4.8 Develop recommended mitigations and/or contingencies and action to mitigate identified risks as mitigation is a response to a risk, designed to reduce or eliminate the probability and /or impact of the risk. Identify, develop and implement risk management processes to mitigate risk. If no mitigation actions are available, the risk may be accepted. Accepting the consequences of the risk even can be active (e.g. developing a contingency plan to be executed if the risk event occurs), or acceptance can be passive (e.g. taking no action, allowing the risk event to occur, and accepting the resulting consequences).

Develop risk management plan and processes to be integrate with FEMA SELC.

4.4.9 Track and control mitigation actions to insure that steps of the risk management process are being followed and, as a result, risks are being mitigated and contingency plans are followed as necessary. Risk tracking and control involves the oversight and tracking of risk mitigation and contingency action plan execution, re-assessment of risks, reporting risk status, and recording risk information changes.

4.4.10 Conduct post implementation reviews and audits. The type and scope of the reviews and audits will be determined by ongoing analysis of risk management plans and activities, identification of high probability risks, confirmation of risk mitigation plans of high impact risks, project closeout, and validation of implementation of approved systems changes and verification of documented system baselines.

4.5 Test Management Support

The contractor shall provide FEMA the full range of System Development and Technical Assistance.

4.5.1System Technical Support To include requirements, analyses, design, definition, cost analysis, development planning, performance assessments, documentation, testing, evaluation, quality assurance, configuration management, inventory management and control, integration and operations management of command, control, communication, display, information, sensor and other systems. Support shall include:

4.5.1.1 Performing technical requirements studies/tradeoffs analysis.

4.5.2Review Products and Services for Technology Insertion

The contractor shall assist in the review and testing of new technologies and applications.

The reviews may be in the form of table-top-reviews, proof-of-concept demonstrations, prototype activities or pilot tests. The results of these shall be in the form or written reports describing functionality, ease of implementation/integration and compatibility with FEMA systems or programs, cost benefit analysis and risk analysis.

4.5.3Performing operation and maintenance of installed equipment as designated

4.5.4Prepare and execute automated test scripts using available GFE Test tools (HP Quality and Performance Center).

4.5.5Develop Functional/Performance test scripts

4.5.6Execute test scripts

4.5.7Troubleshoot IV&V environment issues

4.5.8Document and report test results and recommendations.

4.5.9Ensure efforts and testing for 508 compliance using the DHS approved tool suite.

DHS 508 development and testing includes but is not limited to; Hiawatha Software tool suite (AccRepair), JAWS and Adobe Common-Look

4.6 System/Software Administration Support

The contractor shall provide FEMA the full range of System Administration and Technical Assistance to assist with consolidate test facility and QA applications within the environment. This includes personnel with in-depth knowledge of the following:

4.6.1Computer and Communications Hardware Systems Support To include requirements analyses, engineering studies, trade-off analyses, performance assessments, front-end interface design, definition, modeling, documentation, testing, evaluation, quality assurance, system optimization, configuration management, system integration, installation and operations management of digital stored program computer and communication hardware.

4.6.1.1Network Management and System Management.

4.6.1.2Performance Center server/environment administration

4.6.1.3Quality Center server/environment administration

4.6.1.4System/User administration/management, to include in-depth knowledge of MS Active Directory

5. Task Order Deliverables Task Orders issued against the IDIQ contract could result in any of the following deliverables. This list is not all-inclusive, but it is a representative of the deliverables that could be developed or modified under the resulting contract:

5.1 Resumes of Key personnel shall be part of the Contractor’s proposal in response to the Request for Proposal (RFP), Task Order submissions and requested changes in personnel.

5.2 IT Software Development Lifecycle (SDLC) Support Plan

5.3 Quality Assurance Plan (QAP)

5.4 Quality Assurance Surveillance Plan for IT Projects(QASP)

5.5 Requirements Management Plan (RMP)

5.6 Configuration Management Plan (CMP)

5.7 Performance Measurement Plan (PMP)

5.8 Release Management Plan (RelMP)

5.9 IT Project Post Implementation Review Report (PPIRR)

5.9.2 System Software Technical Support as needed to maintain QA environment

5.9.3 QA System Administration Configuration Designs

5.9.3.1 Requirements and base configuration for each system (as different from the FEMA standard)

5.9.3.2 System dependencies

5.9.3.3 System Maintenance plan

5.9.4 Test plan and Usability plan for test tasking

5.9.4.1 Automated test scripts

5.9.4.2 Test report

5.9.4.2.1 Recommendations

5.9.4.2.2 Risks

5.9.4.3 Meeting agendas and minutes for QA initiated meetings

5.9.4.4 Detailed issues log

5.10 Periodic status reports. Reporting period will be agreed upon jointly between COTR and the successful contractor. At minimum, the frequency shall not be less than weekly. Specific deliverables and their delivery shall be identified within the Task Order document.

6. Task Order Reporting

The contractor shall submit a Monthly Progress Report by the 21st of each month following the monthly reporting period. The suspense date of the report will be the same as those used for invoicing by the primary contractor. Any and all subcontractor / consultant data will be current through the “as of” date of the report.

The report will be unclassified. E-mail submission is encouraged. The specific format will be approved by the Task Order Manager (TOM) and the Contract Specialist. The following information will be provided as a minimum:

6.1. Task Order Activities

6.1.1. Activities performed during the reporting period

6.1.2. Status of any assigned deliverables. This will include the Contract Data Requirements List (CDRL) reference, deliverable title, date due and date delivered

6.1.3. Identify any problems encountered (technical/schedule/cost) and resolutions

6.1.4. Note if there are any unresolved problems/issues at the end of the reporting period.

6.2. Expenditure Data

6.2.1. Provide current and cumulative expenditures of both hours and dollars; illustrate expenditures separately by Task Order and the amount funded as well as compute a funding balance

6.2.2. Provide line graphs illustrating expenditures of both hours and dollars. These graphs will demonstrate planned expenditures as well as funding levels

6.2.3. Provide the names of all personnel charging to the Task Order. Organize the data by contract labor category and illustrate both current and cumulative hours charged for each person. Reveal separate uncompensated hours and total time to account for hours worked (if applicable)

6.2.4. Total expenditures will be compared to those invoiced for the same period and differences explained

The above detail information will be provided for current contract period Task Orders only. The report will be distributed as indicated on individual Task Orders.

7. Task Order Prioritization

The contractor shall participate in periodic Task Order Review Meetings with individual Task Area Points of Contact (POC). The purpose of these meetings is to convey the Government’s technical program schedules and priorities and to identify corresponding task priorities for this order. Results of these meetings will be included in the Monthly Progress Report.

8. Placement of Additional Task Order

8.1 During the period of performance of this contract, the contractor will be given the opportunity to perform each future Task Order. For each Task Order, a Task Order Proposal Request will be issued to the contractor that contains:

8.1.1 Clear statement of the requirements

8.1.2 Expectations regarding the schedule and completion of Task Order activities

8.1.3 Reasonable response period

8.1.4 Disclosure of the significant factors and sub factors, including cost or price, that FEMA will consider in evaluating proposals, and their relative importance

8.2 The contractor’s Task Order proposal will be evaluated and discussions may be conducted as needed. Based upon its evaluation, FEMA will award a Task Order.

Contractor proposals shall include at a minimum, the following:

8.2.1 Proposed cost estimate for customer specific Test support requests 14 days after requirements submission.

8.2.2 Understanding of Requirements

8.2.3 Draft schedule

8.2.3.1 Amount of time required

8.2.3.2 Number of personnel needed

8.2.4 Type of personnel needed (skill set required)

8.2.5 ROM cost proposal, based on written requirements statement generated by the customer

8.2.6 Additional tools needed (if any); to include a justification for why the tools are required

8.2.7 Qualified key staff support on a per task basis as required to complete tasks 10 business days after contract award for Systems Hardware specialists 15 business days after contract award for all other staff support specialist

9. Period of Performance

The period of performance will be five (5) years, which consists of one (1) twelve (12) month base period and four (4) one (1) year option periods.

The period of performance for each task will be defined in each Task Order awarded under this contract. The government may exercise an option to extend the Period of Performance beyond the contract award to compensate for non-availability of the systems’ test environment.

10. Place of Performance

The activities under this contract may be required to be performed in any of the fifty United States or territories. The activities and services under this contract will be performed at the locations specified in each individual Task Order.

It is anticipated that the primary government facilities of performance for the activities under this contract will occur at:

FEMA Brooke Road Facility 188 Brooke Road Winchester VA. 22603

FEMA Information Technology Division Federal Emergency Management Agency 300 D Street SW Washington, DC 20472

FEMA Mt. Weather Emergency Operations Center 19844 Blue Ridge Mountain Road Mt. Weather, Virginia 20135

FEMA currently has a number of other locations within the Washington metropolitan areas. When specific needs arise, activities under this contract may need to be performed in those locations.

The activities under the scope of this contract may also be required to occur at other FEMA locations. This may include:

FEMA Regional Offices Region I – Boston Region II – New York Region III – Philadelphia Region IV – Atlanta Region V – Chicago Region VI – Denton Region VII – Kansas City Region VIII – Denver

Region IX – Oakland Region X – Bothell

FEMA National Processing Service Center (NPSC) Denton, TX

Hyattsville, MD Winchester, VA

Work will be performed at FEMA sites and contractor sites as deemed necessary by the PM. FEMA sites may be anywhere in the United States and its territories. Local travel and TDY travel expenses within scope of the Government Joint Travel Regulations are authorized but must be pre-approved by the COTR.

11. Hours of Operation:

Duty hours are typically 0800 to 1700 each day. Core business hours are from 0900 to 1500 daily, an 8 hour workday may be agreed upon in writing by the vendor and the COTR. However due to the nature of FEMA disaster operations and IT systems delivery schedules, non-normal hours of operation and weekend work is possible.

12. Travel

All contractor travel other must be approved in advance by the COTR. Contractor travel expenses within scope of the Government Joint Travel Regulations (JTR) will be reimbursed in accordance with the JTR allowable travel costs. Overtime will be subjected to COTR and CO approval.

13. Key Personnel

The use of foreign nationals (those not U.S. citizens, including those individuals with Lawful Permanent Residence) on any Task Order is not permitted. All key and assigned support staff shall be U.S. citizens.

Key personnel will be specified in each Task Order issued under this contract. Prior to removing, replacing, or diverting any of the specified individuals, the Contractor shall notify the Contracting Officer and Contracting Officer’s Technical Representative 30 days prior to any action related to the performance of key personnel and shall submit justification (including proposed substitutions) in detail to allow for an evaluation of the impact relative to the Task Order. A transition period of no less than one week and no more than two weeks is acceptable.

Key expert level personnel shall be, at a minimum, IT Infrastructure Library (ITIL) certified or trained (if applicable) in their stated field; i.e., Release and Control Practitioner and or ITIL v3 Certification.

Key testing personnel shall have expert knowledge(prolonged or intensed experience through practice and education) in the use of Hewlett-Packard/Mercury Inc., Loadrunner, WinRunner, Quality Center, Performance Center, Quick Test Pro and Business Availability Suite.

Key configuration Management personnel shall have expert knowledge in the use of the IBM Rational Suite of software; Requisite Pro, Clear Case and Clear Quest software and CMMI 3 certification.

Key 508 personnel shall have senior level expertise in the use of the Hiawatha Software tool suite, especially AccRepair

Key System/Software Technical Support personnel shall have senior level expertise in two or more categories (see section 4.5).

The Government also retains the right, at its discretion, to interview all proposed replacements of key personnel. No diversion shall be made by the Contractor without the written consent of the Contracting Officer; provided, that the Contracting Officer may ratify in writing the change and such ratification shall constitute the consent of the Contracting Officer required by this clause.

14. Security

The contractor shall comply with the Department of Homeland Security’s (DHS) technical, management, and operational security controls to ensure that the Government’s security requirements are met. DHS 4300A policy guide will be used for Sensitive Systems and DHS 4300B policy guide will be used for National Security Systems.

1. Contractor Eligibility, Continued Eligibility and Termination The Contractor shall provide the appropriate levels of clearance to maintain the classified and unclassified systems. The Contractor will ensure that each employee and potential employee provide their name, and social security number for verification. If the number is not valid, then the employee will not be authorized to work on the contract until it is resolved.

Subject to existing law, regulations and / or other provisions of this contract, illegal or undocumented aliens shall not be employed by the Contractor to perform on this contract. The Contractor shall ensure this provision is expressly incorporated into any and all subcontracts or subordinate agreements issued in support of this contract.

The Department of Homeland Security (DHS) and the Federal Emergency Management Agency (FEMA) reserves the right to deny and / or restrict entrance to Government facilities, prohibit employees from assigned work under the contract, deny and/or restrict handling of sensitive documents/material to any Contractor employee who DHS determines to present a risk of compromising classified and/or sensitive Government information.

The Contractor shall report to the FEMA Security Office any and all adverse information brought to their attention concerning employees performing under this contract. The report shall include the employee’s name and social security number, along with the adverse information being reported. Termination of employment of an employee does not obviate the requirement to submit this report. Reports based on rumor or innuendo shall not be submitted to the DHS Security Office.

The Contractor shall notify the FEMA Security Office of all terminations / resignations of contractor personnel on this contract within five (5) days of occurrence. The Contractor shall return to the Contracting Officer’s Technical Representative (COTR) all DHS and / or FEMA issued identification cards and building passes that have either expired or have been collected from terminated employees. If an identification card or building pass is not available to be returned, a report shall be submitted to the COTR, referencing the pass or card number, name of individual to whom it was issued, and the last known location and disposition of the pass or card.

2. Contractor Security Management

The Contractor shall appoint a senior official to act as a Security Officer. The individual shall work collaboratively with the FEMA Security Officer through the COTR on all security matters, to include physical, personnel, and protection of all sensitive documents/material handled by the Contractor.

The COTR and FEMA Security Office will have the right to inspect procedures, methods and facilities utilized by the Contractor to comply with the security requirements under this contract. Should the COTR or DHS Security Office determine that the Contractor is not in compliance with the security requirements of the contract, the Contracting Officer shall notify the Contractor, in writing, of the appropriate action the Contractor must take to rectify any non-compliance with the contract security requirements.

3. Suitability Determination

FEMA will exercise full control over granting, denying, withholding or terminating unescorted Government facility and / or access to or handling of sensitive Government information to contractor employees based upon the results of a background investigation. FEMA may, as it deems appropriate, authorize and grant a favorable Entry on Duty (EOD) decision based on preliminary suitability checks. The favorable EOD decision would allow the employees to commence work temporarily prior to the completion of a full investigation.

Granting of a favorable EOD decision shall not be considered as assurance that full employment suitability authorization will follow.

A favorable EOD decision or a full employment suitability determination shall in no way prevent, preclude or bar DHS from withdrawal of or terminating access to Government facilities or information, at any time during the term of the contract.

Contractor employees shall not be allowed unescorted access to a Government facility without a favorable EOD decision or suitability determination by the Security Office.

Contract employees waiting for an EOD decision may begin work on the contract provided they do not access sensitive Government information. Limited access to Government buildings is allowable prior to the EOD decision, if the Contractor is escorted by a Government employee. This limited access allows contractors to attend briefings, non-recurring meetings and begin transition work.

4. Background Investigations

Contract employees (to include applicants, temporaries, part-time and replacement employees) under the contract, in addition to possessing a granted personnel security clearance, shall undergo a position sensitivity analysis based on the duties each individual will perform under the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted for suitability screening purposes. All background investigations will be processed through the FEMA Security Office. Prospective Contractor employees shall submit the following completed forms to the DHS Security Office. The Standard Form 85P will be completed electronically, through the Office of Personnel Management’s e-QIP System. The completed forms must be given to the FEMA Security Office no less than thirty (30) days before the start of the contract or thirty (30) days prior to entry on duty of any employees, whether a replacement, addition, subcontractor employee or contractor:

1. Standard Form 85P, “Questionnaire for Public Trust Positions”

2. FD Form 258, “Fingerprint Card” (2 copies)

3. Conditional Access to Sensitive But Unclassified Information Non-

Disclosure Agreement

4. Disclosure and Authorization Pertaining to Consumer Reports

Pursuant to the Fair Credit Reporting Act

Only complete packages will be accepted by the FEMA Security Office. Specific instructions on submission of packages will be provided upon award of the contract.

Due to the applications and systems that may be tested, the contractor staff must hold clearances at a Secret level and must be United States citizens.

Contractor personnel will adhere to FEMA leased/owned facility site security requirements and may be required to have agency escort while in the test bed sites and operational facilities. FEMA reserves the right to limit the number of personnel allowed in agency owned testing sites and operational facilities.

Unless an applicant requiring access to sensitive information has resided in the United States for three (3) of the past five (5) years, the Government may not be able to complete a satisfactory background investigation. In such cases, FEMA retains the right to deem an applicant as ineligible due to insufficient background information.

The use of Non-U.S. citizens, including Lawful Permanent Residents (LPRs), is not permitted in the performance of this contract for any position that involves access to or development of any FEMA Information Technology (IT) systems.

FEMA will consider only U.S. Citizens for employment on this contract. . By signing this contract, the Contractor agrees to this restriction.

5. Information Technology Security

When sensitive Government information is processed using Government telecommunications and automated information systems, the Contractor shall provide for the administrative control of sensitive data being processed and adhere to the procedures governing such data as outlined in the “DHS IT Security Program – Publication DHS MD 4300.Pub.” Contractor personnel must have favorably adjudicated background investigations commensurate with the defined sensitivity level.

Contractors who fail to comply with the Government’s security policy are subject to having their access to Government IT systems and facilities terminated, regardless if the failure results in criminal prosecution. Any person who improperly discloses sensitive information is subject to criminal and civil penalties and sanctions under a variety of laws (e.g. Privacy Act).

All Contractor employees using Government automated systems or processing Government sensitive data shall be required to receive Security Awareness Training. This training will be provided by FEMA.

Contractors involved with management, use, or operation of any IT systems that handle sensitive information within or under the supervision of the department, shall receive periodic training at least annually in security awareness, and accepted security practices and systems rules of behavior. Department contractors, with significant security responsibilities, shall receive specialized training specific to their security responsibilities annually. The level of training shall commensurate with the individual’s duties and responsibilities and is intended to promote a consistent understanding of the principles and concepts of telecommunications and IT systems security.

All personnel who access Government information systems will be continually evaluated while performing these duties. Supervisors should be aware of any unusual or inappropriate behaviors by personnel accessing systems. Any unauthorized access, sharing of passwords, or other questionable security procedures should be reported to the local Security Office or Information System Security Officer (ISSO).

15. Government-Furnished Equipment and Information

In support of the activities of this contract, the government shall provide the contract with the following:

1. Copies of the applicable FEMA documentation, policies and guidelines

2. A primary FEMA point of contact for each Task Order

3. Timely access to subject matter experts, technical experts, database administrators, system administrators, and other appropriate resources as necessary

4. The necessary equipment to accomplish the activities under this contract. This includes, but is not limited to; laptops, desk phones, printers, office supplies, etc.

5. The individual to whom government property is assigned will be responsible for any items issued to them from FEMA and will be issued a hand receipt for stated items

6. All items are subject to inventory based on the Government’s discretion, and can be requested to be returned at any time

7. FEMA will provide the contractor will all necessary information to perform all services described in this SOW.

16. DHS Enterprise Architecture Compliance

All activities support and solutions provided under this contract shall meet DHS Enterprise Architecture policies, standards, and procedures. Specifically, the contractor shall comply with the following Homeland Security Enterprise Architecture (HLS EA) requirements:

1. All developed solutions and requirements shall be compliant with the HLS EA

2. All IT hardware or software shall be compliant with the HLS EA Technical

Reference Model (TRM) Standards and Products Profile

3. All data assets, information exchanges and data standards, whether adopted or developed, shall be submitted to the DHS Enterprise Data Management Office (EDMO) for review and insertion into the DHS Data Reference Model

4. In compliance with Office of Management and Budget (OMB) mandates, all network hardware shall be IPv6 compatible without modification, upgrade, or replacement.

5. All Information Technology assets being developed, procured, or acquired shall be IPv6 capable.

17. Accessibility Requirements (Section 508)

Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use electronic and information technology, they must ensure that it is accessible to people with disabilities. Federal employees and members of the public who have disabilities must have equal access to and use of information and data that is comparable to that enjoyed by non-disabled Federal employees and members of the public.

All Electronic and Information Technology (EIT) deliverables within this work statement shall comply with the applicable technical and functional performance criteria of Section 508 unless exempt. Specifically, the following applicable standards have been identified:

1. 36 CFR 1194.21 – Software Applications and Operating Systems, applies to all EIT software applications and operating systems procured or developed under this work statement including, but not limited to, GOTS and COTS software. In addition, this standard is to be applied to Web-based applications when needed to fulfill the functional performance criteria. This standard also applies to some web-based applications as described within 36 CFR 1194.22.

2. 36 CFR 1194.22 – Web-based Intranet and Internet Information and Applications, applies to all web-based deliverables, including documentation and reports procured or developed under this work statement. When any web application uses a dynamic (non-static) interface, embeds custom user control(s), embeds video or multimedia, uses proprietary or technical approaches such as, but not limited to, Flash or Asynchronous JavaScript and XML (AJAX) then “1194.21 Software” standards also apply to fulfill functional performance criteria.

3. 36 CFR 1194.23 – Telecommunications Products, applies to all telecommunications products including end-user interfaces such as telephones and non end-user interfaces such as switches, circuits, etc. that are procured, developed or used by the Federal Government.

4. 36 CFR 1194.24 – Video and Multimedia Products, applies to all video and multimedia products that are procured or developed under this work statement. Any video or multimedia presentation shall also comply with the software standards (1194.21) when the presentation is through the use of a web or software application interface having user controls available.

5. 36 CFR 1194.31 – Functional Performance Criteria applies to all EIT deliverables regardless of delivery method. All EIT deliverables shall use technical standards, regardless of technology, to fulfill the functional performance criteria.

6. 36 CFR 1194.41 – Information Documentation and Support, applies to all documents, reports, as well as help and support services. To ensure that documents and reports fulfill the required “1194.31 Functional Performance Criteria”, they shall comply with the technical standard associated with Web-based Intranet and Internet Information and Applications at a minimum. In addition, any help or support provided in this work statement that offer telephone support, such as, but not limited to, a help desk shall have the ability to transmit and receive messages using TTY.

Exceptions for this work statement have been determined by DHS and only the exceptions described herein may be applied. Any request for additional exceptions shall be sent to the COTR and determination will be made in accordance with DHS MD

4010.2. DHS has identified the following exceptions that may apply:

1. 36 CFR 1194.2(b) – (COTS/GOTS products), When procuring a product, each agency shall procure products which comply with the provisions in this part when such products are available in the commercial marketplace or when such products are developed in response to a Government solicitation. Agencies cannot claim a product as a whole if not commercially available because not all products in the marketplace meet every standard.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .