Attachment_3_Task_Order_001.pdf

PDF 666 KB Posted

Attached to
Transportation Security Administration Assessment Platform (TAP) Federal contract opportunity
Solicitation number
HSTS01-15-R-HRM015
Issued by
Department of Homeland Security Transportation Security Administration

About this file

Attachment 3

View the file

Other files for this federal contract opportunity

Other files attached to Transportation Security Administration Assessment Platform (TAP), newest first.
File Type Posted
Amendment_A00004.pdf PDF
Amendment_A00004_Attachment_1_TAP_Contract_Pricing.xls XLS spreadsheet
HSTS01-15-R-HRM015_Vendor_Questions_and_TSA_Responses_from_the_Information_Technology_Industry_Day.pdf PDF
Amendment_A00003.pdf PDF
Attachment_10_TSA-DHS_EA_Compliance_Language.pdf PDF
RFP_HSTS01-15-R-HRM015_Vendor_Clarification_Questions_and_TSA_Responses.pdf PDF
HSTS01-15-R-HRM015_A00002.pdf PDF
SF-30_HSTS01-15-R-HRM015__A00002.pdf PDF
Attachment_12_Airport_Locations_With_Zipcodes.pdf PDF
Attachment_13_Information_Assurance_Requirements_TSA_IT_Govt_Acquisitions.pdf PDF
Attachment_11_TSAs_Organizational_Assessment_Services_Item_Writing_Guidelines.pdf PDF
Amendment_A00002_Attachment_1_TAP_Contract_Pricing.xls XLS spreadsheet
HSTS01-15-R-HRM015_A00001.pdf PDF
Attachment_1_CATS_Contract_Pricing.xls XLS spreadsheet
Attachment_6_-_CATS_Contractor_Status_Review_Template.pptx PPTX presentation
Attachment_8_DHS_4300A_Sensitive_Systems_Handbook.pdf PDF
Attachment_4__Past_Performance_Questionnaire.docx DOCX document
Attachment_5_Non-Disclosure_Agreement.pdf PDF
HSTS01-15-R-HRM015.pdf PDF
Attachment_7_TSA_Core_Competencies.pdf PDF
Attachment_9_Award_Term_Plan.pdf PDF
Show all 21

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOURCE SELECTION SENSITIVE INFORMATION

FOR OFFICIAL USE ONLY

CATALOG OF ASSESSMENTS AND TESTING

SYSTEM (CATS) HSTS01-15-D-HRM015

TASK ORDER 001 (HSTS01-15-J-HRMTBD) –

Phase In Activities, Certification and Accreditation, and Program Management Services/Deliverables

Contents

1 Pricing Schedule

2 Background

3 Scope of Work

3.1 Objective

4 SPECIFIC REQUIREMENTS/TASKS

4.1 System Requirements

4.2 Test Item and Structure

4.3 Administrative Requirements

4.4 Reporting Requirements

4.5 Assessment Library

4.6 Implementation

4.7 Hosting, Maintenance, and Support

4.8 Project Management, Quality Control, and System Integration

4.9 Data and Records Requirements

4.10 Personally Identifiable Information (PII) and Privacy Incident Response

4.11 Meetings

5 DELIVERABLES

6 TRAVEL

7 PLACE OF PERFORMANCE

8 PERSONNEL AND FACILITIES

9 INFORMATION ASSURANCE

9.1 Controls

9.2 General Security Responsibilities for Contract Performance

9.3 Configuration Management (Hardware/Software)

9.4 Risk Management Framework

9.5 Contingency Planning

9.6 Program Performance

9.7 Federal Risk and Authorization Management Program (FedRAMP)

9.8 Information Assurance (IA) Policy

9.9 Data Stored/Processed at Contractor Site

9.10 Remote Access

9.11 Interconnection Security Agreement (ISA)

9.12 SBU Data Privacy and Protection

9.13 Disposition of Government Resources

9.14 Special Considerations and Circumstances (If Applicable)

10 ACCESSIBILITY REQUIREMENTS (SECTION 508)

10.1 Section 508 Applicable EIT Accessibility Standards

10.2 Section 508 Applicable Exceptions

10.3 Section 508 Compliance Requirements

1 Pricing Schedule

*Offerors shall insert Unit Prices and Total Prices consistent with pricing included on

Attachment 1 “CATS Contract Pricing”

CLIN

DESCRIPTION UNIT

OF

ISSUE

UNIT

PRICE*

QTY TOTAL*

0001 Steady-state Program Management Services (incl.

key personnel; production of all data, reports, and manuals not elsewhere separately priced;

proctor/administrator and system training; and all other recurring contract/program management support)

MO $_______ 4 $_______

0002 Phase-in Activities (i.e. employee vetting, obtaining additional software licenses, initial User

Acceptance Testing, Quality Control Plan, Project

Status Reviews)

JB $_______ 1 $_______

0003 Certification and Accreditation JB $_______ 1 $_______

0004 Data Management Plan EA $_______ 1 $_______

0005 Project Management Plan EA $_______ 1 $_______

0006 System Integration Plan EA $_______ 1 $_______

The total TO Firm Fixed Price is $______________.

2 Background

The Transportation Security Administration (TSA), Office of Human Capital (OHC), Organizational Assessment Services (OAS) Branch, is responsible for developing, implementing and analyzing assessments for selection, promotion, and certification for occupations within the agency in order to ensure that TSA candidates and employees possess the knowledge, skills, abilities, and competencies necessary to carry out assigned duties.

On November 19, 2001, the Aviation and Transportation Security Act (ATSA) established the existence of Transportation Security Administration (TSA), as well as performance criteria for

Transportation Security Screeners, now known as Transportation Security Officers (TSO). In accordance with ATSA requirements, TSOs are held accountable for their technical knowledge, as well as their ability to use that knowledge to perform the essential functions of the Security

Officer Job. The Employee Assessment Management System (EAMS) is the tool TSA currently uses to assess job knowledge. These assessments are comprised of questions drawn from TSA’s

Standard Operating Procedures guidance, training curriculum, and other relevant materials.

These tests vary depending on the specific function performed by a TSO and are typically scored as pass/fail.

The Catalog of Assessments and Testing System (CATS) will be used by TSA, Office of Human

Capital (OHC) to evaluate candidates and incumbents within a variety of positions including

Transportation Security Officers (TSOs); Screening Partnership Program (SPP) screeners;

Federal Air Marshals (FAMs); management, administrative, and professional (MAP) positions;

and executive positions. These positions will be in a variety of business, technical, and security operations-related disciplines at the entry-level, team lead, first-line supervisor, manager, and executive levels.

3 Scope of Work

TSA has a requirement to acquire a proven automated testing platform to test, evaluate, and track assessments; a self-service scheduling system that can be loaded with TSA and/or contractor-established test sites and available times; the ability to load TSA’s assessments onto the platform; and the ability to load and/or integrate with third party assessments.

The CATS shall be Commercial-off-the-Shelf (COTS) technology which must seamlessly integrate and interface with all TSA hiring systems (Government furnished and third-party) and the LMS. The CATS shall be capable of utilizing test content from TSA-developed assessments, the CATS provider’s library of assessments, and off-the-shelf and custom developed assessments from third-party sources. The system will have the ability to create and edit assessments and shall have sufficient bandwidth allowing for system response time that does not negatively impact the user experience and scalable storage capability to meet TSA’s testing storage needs.

The system will have the capability for OHC to author and revise tests and test items, administer tests, analyze test results, and generate reports. The system will also be used to assist with delivering initial certification and recertification assessments for TSA positions. The system will be capable of administering tests in an ‘offline’ or alternative environment (e.g., paper and pencil format, using scannable answer sheets, etc.) that is accessible by all sites as needed.

This Task Order (TO) Statement of Work (SOW) establishes phase-in activities for the CATS.

Phase-in Activities to include:

Obtaining software licenses

Initial User Acceptance Testing (UAT)

Security Authorization to Operate (ATO) to include Certification and Accreditation

(C&A) of CATS.

3.1 Objective

The objective of this requirement is for the TSA to acquire a qualified Contractor to provide: a proven automated testing platform to test (online and offline), evaluate, and track assessments;

access to a library of commercially available assessments that are professionally developed and validated; Contractor expertise to identify and recommend assessments as necessary; custom developed and validated assessments; Contractor-managed tests sites; a self-service scheduling system that can be loaded with TSA and/or Contractor-established test sites and available times;

the ability to load TSA’s assessments onto the platform; and the ability to load and/or integrate with third-party assessments. It is the goal of this contract to establish a unified platform capable of managing all TSA assessments that can be integrated with TSA’s Hiring (Government furnished and third-party) and LMS. The integration with the LMS and upload of TSA-owned test content shall be prioritized to support TSA certification testing.

4 SPECIFIC REQUIREMENTS/TASKS

4.1 System Requirements

Any licenses procured for the CATS and during the life of the Contract shall be procured on behalf of TSA, assigned to TSA and transferred to TSA. The Contractor shall procure all licenses for government use purposes to the maximum extent practicable.

4.1.1 The system shall:

4.1.1.1 Along with all TSA data, be stored on a physically segregated server from all other entities, both federal and non-federal and meets the requirements of the

Certification and Accreditation (C&A). An exception to this subparagraph will be considered on a case-by-case basis (e.g. service provider has a testing system

TSA already uses currently in place).

4.1.1.2 Have COTS technology.

4.1.1.3 Have the capability to seamlessly and securely integrate/interface and exchange structured data via web services with TSA or other Contractor hosted

Government systems, to include TSA’s Hiring (Government furnished and third-party) and LMS, including:

4.1.1.3.1 Provide a scheduled daily automated transmission of structured CATS data to the Integrated Hiring Solution (IHS).

4.1.1.3.2 Provide a scheduled daily automated transmission of structured CATS data to the LMS.

4.1.1.3.3 Provide a scheduled daily automated transmission of structured CATS data to the Recruiting and Hiring System (R&H).

4.1.1.3.4 Maintain security and encryption standards per Section 4.1.2 and

Section 8 of this SOW while data is “at rest”, or “in motion”.

4.1.1.3.5 With the Government’s prior approval; develop/implement and maintain additional manual/automated data transmissions and/or data exchanges in response to enterprise architecture changes, system usability issues, or physical/technology security considerations during the lifecycle of the project.

4.1.2 The Contractor shall:

4.1.2.1 Transform and load legacy assessment data provided by TSA into the CATS database. The Contractor shall load all candidate and employee data from the previous two full calendar years and shall load data for all TSO CBT results for failed assessments from 2009 to current.

4.1.2.2 Develop a Scale Test Plan, and validate that the legacy data has been loaded correctly into the CATS database.

4.1.2.3 Maintain the system, provide technical support, and resolve technical issues.

The Contractor shall not exceed four late responses per calendar year and the

Contractor shall not exceed two business days to respond to either phone call or email from TSA.

4.1.2.4 Be required to maintain data controls and protections as required by the

Privacy Act of 1974, as amended, and title 49, Code of Federal Regulations

(CFR) part 1520, as well as all applicable Department of Homeland Security

(DHS) and TSA information security requirements. Further information can be found at http://www.dhs.gov/dhs-security-and-training-requirements-contractors.

4.1.2.5 Encrypt all sensitive data transmitted outside system boundaries using Federal http://www.dhs.gov/dhs-security-and-training-requirements-contractors http://www.dhs.gov/dhs-security-and-training-requirements-contractors

Information Processing Standard (FIPS) 140-2 validated cryptographic modules, and algorithms compliant with FIPS 197 (Advanced Encryption Standard (AES)

256).

4.2 Test Item and Structure

4.2.1 The system shall have the functionality to:

4.2.1.1 Allow a variety of test item formats (e.g., multiple-choice, multiple-response, matching, ranking, audio and video, etc.).

4.2.1.2 Present test items as one item per screen and multiple items per screen.

4.2.1.3 Present the item stem as well as the item response options on one screen with the capability to display the item stem on multiple pages with the associated items for appropriate item types.

4.2.1.4 Enable, or disable, a display of the test time remaining and show a progress bar.

4.2.1.5 Randomize the order of test items.

4.2.1.6 Offer computer-adaptive testing.

4.2.1.7 Present instruction screens to allow for learning system navigation after the candidate logs onto the system and provide one for two sample test items for each of the item types contained in the test. For TSA developed tests, TSA will provide sample items; for third-party or COTS test content, TSA will use published test instructions.

4.2.1.8 At the beginning of each assessment or test battery, require test-takers to acknowledge a confidentiality agreement stating that they will not share information about the assessment or test items.

4.2.1.9 Display question number (i.e., the number of the question to which the test taker is currently responding) and total number of questions in the assessment

(e.g., question 33 of 50).

4.2.1.10 Permit or restrict the ability to allow test-takers to navigate back to previous questions.

4.2.1.11 Permit or restrict the ability to allow test-takers to skip test questions.

4.2.1.12 Permit or restrict the ability to allow test-takers to mark questions for later review.

4.2.1.13 Permit or restrict the ability to allow test-takers to search for items missing a response.

4.2.1.14 Require a response to all questions before test taker can exit the assessment.

4.2.1.15 Provide automatic enforcement of per assessment time limits and total assessment session time limits, and allow these time limits to be extended by an administrator to provide a reasonable accommodation on a per test taker basis when approved. Total assessment session duration varies depending on assessments selected for inclusion.

4.2.1.16 Allow supplemental test materials (e.g., simulated emails, memos, documents) to be presented to the candidate.

4.2.1.17 Allow individual tests to be presented as a test battery with assessments being provided in a fixed order within each battery.

4.2.1.18 Randomly assign test items to test takers based on content domain (e.g.

random number form generation, random question generation, serial form generation).

4.2.1.19 Present test takers with an exit survey, to be approved or provided by TSA, upon conclusion of each assessment or test battery.

4.2.2 Authoring Requirements

4.2.2.1 The Contractor shall provide a system with the capability that allows TSA to create, edit, upload and approve multiple assessments. CATS shall be capable of providing the following:

4.2.2.1.1 Contractor support for uploading and formatting multiple assessments provided by TSA in a mutually agreed upon format.

4.2.2.1.2 Customizable multi-author environment.

4.2.2.1.3 Tracking authors.

4.2.2.1.4 Tracking edits (e.g., version control, author).

4.2.2.1.5 Randomization of assessment questions and answer options within assessment.

4.2.2.1.6 Moving/Re-Sequencing test questions (manually and/or automated).

4.2.2.1.7 Allowing designated TSA role-based users to author instructions that test takers review before, during, and after a test.

4.2.2.1.8 Allowing designated TSA role-based users to determine what feedback test takers see upon test completion, to include but not be limited to pass/fail, raw score, percent correct.

4.2.2.1.9 Using the standard copy/paste functions to enter test content.

4.2.2.1.10 Linking assessment items to topic areas/learning objectives.

4.2.3 Item Banking

4.2.3.1 The Contractor shall provide a system with item banking capability that allows

TSA to securely store and retrieve TSA-provided test items. CATS shall provide the following capabilities for designated TSA role-based users and Contractor support to:

4.2.3.1.1 Upload newly created test items to the item bank.

4.2.3.1.2 Maintain historical items in the item bank.

4.2.3.1.3 Provide the ability to copy or up-version items.

4.2.3.1.4 Ensure that items cannot be automatically written over once the test is finalized.

4.2.3.1.5 Allow users to manually select items from the item bank to be used in test generation based on the psychometric characteristics of items

(e.g., item difficulty, item discrimination, item total correlation, number of times item has been included in a test, number of response options for the item, date item was created, and author).

4.2.3.1.6 Randomly assign test items from an item bank based on the psychometric characteristics of items (as specified in 4.2.3.1.5) to single or multiple assessments.

4.2.3.1.7 Display a list of all of the tests that have used that item for each item in the item bank.

4.2.3.1.8 Provide the ability to run aggregated item-statistic reports for each individual item across all tests.

4.3 Administrative Requirements

4.3.1 Scheduling. The system shall:

4.3.1.1 Have web-based automated registration, scheduling, and score reporting service, interface and transfer data bi-directionally with all TSA Hiring

(Government furnished and third-party) Systems and the LMS.

4.3.1.2 Update list and assign test batteries to test-takers as updates are made in TSA’s hiring systems and LMS.

4.3.1.3 Permit TSA test-takers to self-register and schedule testing session(s), and when needed schedule the session at a Contractor-managed test site, or a TSA-managed test site.

4.3.1.4 Allow test-takers the capability to schedule during TSA defined scheduling periods and cancel/reschedule test sessions (in accordance with TSA business rules that will be established or modified post contract award. Business rules will govern number of cancellations allowed, late arrivals, lifetime failures, etc.).

4.3.1.5 Allow test-takers to view test session appointment information, including date, time, and address.

4.3.1.6 Allow simultaneous file viewing by multiple authorized users.

4.3.1.7 Allow multiple test-takers to concurrently register for and schedule assessments.

4.3.1.8 Automatically confirm the candidate(s) scheduled test session, with TSA approved email and/or text message content via a non-responder or unattended email/text address, within one (1) hour of scheduling an assessment. The confirmation email/text shall include the test date and time, location, and test site requirements (e.g. the IDs needed for identification, length of test, etc.). The reminder email/text shall also include instructions for canceling or rescheduling the test session.

4.3.1.9 Allow TSA to make revisions to the notification messages to test takers as needed. Requested changes shall be completed within five (5) business days of the request.

4.3.1.10 Have the capability for the system to notify test-takers of changes to scheduled test sessions.

4.3.1.11 Send a TSA approved reminder email/text to the candidate within 48 – 72 hours prior to the scheduled test session. The reminder email/text shall include the test date and time, test site location, and test site requirements as described above (in subparagraph number 4.3.1.7). The reminder email/text shall also include instructions for canceling or rescheduling the test session.

4.3.1.12 Allow test-takers with disabilities the option to request reasonable accommodation (in accordance with the Americans with Disabilities Act (ADA)) prior to or at the time of scheduling a test. The system shall also allow test-takers to cancel a request for an accommodation. The system shall automate notification to TSA and provide TSA with the ability to approve or disapprove an accommodation.

4.4 Reporting Requirements

The Contractor shall provide a system that can store, report, and transfer information on multiple assessments.

4.4.1 The system shall have the capability to:

4.4.1.1 Be scalable to accommodate multiple assessments and the size of the TSA workforce.

4.4.1.2 Generate TSA approved reports on several thousand cases (e.g., test results for thousands of test takers) at one time.

4.4.1.3 Generate TSA approved reports that reflect item choice data for each test taker to include the correct answer and overall score.

4.4.1.4 Conduct psychometric analyses (e.g., item-level analysis, test-level analysis, etc.) to determine how well tests and test items perform.

4.4.1.5 Support customized reports production (e.g., reference missed, question missed, competency level performance).

4.4.1.6 Report on item banking content across tests.

4.4.1.7 Generate real-time TSA approved predefined reports; TSA approved aggregate reports for subsets of data; and TSA approved ad hoc reports based on pre-existing data elements captured in the system (e.g., time-based reporting/comparisons, such as quarter to quarter, year to year; results by airport).

4.4.1.8 Upload and transfer candidate assessment results automatically into the TSA hiring systems within 12 hours of assessment completion. The content of the data transferred will be determined after contract award (e.g., pass/fail status, percentile based on established test norms, raw score, etc.).

4.4.1.9 Provide designated TSA employees access to pull reports and data as necessary.

4.4.1.10 Provide the capability to export data and reports in a generic file format such as raw data in delimited ASCII format or other agreed-upon formats.

4.4.1.11 Encrypt all sensitive data transmitted outside system boundaries using FIPS

140-2 validated cryptographic modules, and algorithms compliant with FIPS 197

(AES 256).

4.4.1.12 Enable TSA access to current and historical assessment results, to be determined after award of contract based on TSA business rules. The

Government may require the Contractor to turn specific candidate scores on or off within two (2) business days of notification. TSA can request that the

Contractor turn on or off specific candidate scores when necessary.

4.4.1.13 Capture test administration data including but not limited to responses, item latencies, assessment start time, and assessment end time.

4.4.1.14 Store assessment and test data and results, in compliance with TSA’s requirements for the safeguarding of Personally Identifiable Information (PII) and SSI, through the end of the contract.

4.5 Assessment Library

4.5.1 The Contractor shall provide TSA with continuous, electronic access to the list of tests and assessments included in their Assessment Library along with a brief description of the test/assessment including but not limited to:

4.5.1.1 Constructs and/or competencies that the test was designed to measure.

4.5.1.2 Test format (e.g., multiple choice, video based simulation, computer adaptive).

4.5.1.3 Test administration method (e.g., proctored, un-proctored).

4.5.1.4 Test length (e.g., number of items, number of scenarios or events if a simulation) and the amount of time allowed to complete the test (for untimed tests the average time to complete the test).

4.5.1.5 Purpose of the test, if available.

4.5.1.6 Pricing.

4.5.2 Upon request from authorized TSA personnel the Contractor shall provide the Test Manual or

Technical Report that fully describes the development and validation of the test, the psychometric properties of the test (e.g., reliability and validity information), and definitions of the constructs and/or competencies that the test was designed to measure.

4.5.3 Upon request from authorized TSA personnel, the Contractor shall assist TSA in locating third-party assessments. Once located, the Contractor shall provide TSA with a brief description of the test and an overview of its psychometric properties.

4.5.4 Once TSA has selected and implemented an assessment from the assessment library, the

Contractor shall ensure that assessment remains in the library for use throughout the life of the contract.

4.6 Implementation

4.6.1 User Acceptance Testing (UAT).

4.6.1.1 Provide TSA the opportunity to review and conduct Initial UAT of the assessment automation, scheduling system, and the ability to pull appropriate reports, when assessments are uploaded into the system, after system integration, before and after initial production, when changes are made, prior to each testing period, and after any substantial upgrades to the system. Initial

UAT will be conducted by the Government with assistance from the Contractor.

The Contractor shall provide test plan scripts to be used by TSA as it conducts initial UAT, and the test plan scripts shall cover all required functionality. The

TSA initial UAT will be conducted at the TSA Headquarters (HQ) test lab located at 601 S 12th Street, Arlington, VA 20598. The TSA test lab will interface with the vendor’s test environment over a secure Internet connection.

4.6.2 Support TSA to achieve full operational capability of CATS including Authorization to Operate

(ATO) within six months from the date of contract award.

4.6.3 Develop an implementation plan for deploying the approved CATS online and offline systems.

This implementation plan shall contain a timeline for operational deployment of the technical requirements listed above, and include the following:

4.6.3.1 Set-up user profiles.

4.6.3.2 Customizations per technical requirements.

4.6.3.3 Operational testing.

4.6.3.4 UAT of the operational system within the TSA environment.

4.6.3.5 Testing of interfaces and/or integrations with other systems.

4.6.3.6 Transfer of initial data in a mutually agreed-upon format.

4.6.3.7 Training for all user levels.

4.6.3.8 User guides for all user levels.

4.6.3.9 Roll-out.

4.7 Hosting, Maintenance, and Support

4.7.1 System Monitoring/Maintenance. The Contractor shall:

4.7.1.1 Provide maintenance and support for all systems and interfaces to include system administration, system upgrades, support for process changes, and system integrations. Schedule all anticipated system maintenance to include dates and durations in a Schedule Maintenance Plan report to the PM/COR. The plans should include and not be limited to:

4.7.1.1.1 Remote maintenance service to address routine system upgrades, unscheduled and emergency outages/technical difficulties.

4.7.1.1.2 Customer support based on user role.

4.7.1.1.3 Timeframes for responses to user questions and issues, including escalation criteria for unresolved issues and problems.

4.7.1.1.4 Support availability Monday through Saturday and Sunday as agreed upon by TSA and Contractor.

4.7.1.1.5 Additional system enhancements as requested by TSA.

4.7.1.1.6 Timeframes for downtime necessary to implement system upgrades, enhancements, and maintenance as mutually agreed upon by TSA and the Contractor.

4.7.1.2 Check the validity of data being transmitted and the authorization of both sending and receiving systems to transmit said data. This shall include details on each data transaction type in the interface to include all fields, data types, identifiers, reference codes, recurrence/frequency, format, and associated

“messaging” (file transfer auditing).

4.7.1.3 Comply with TSA’s Security C&A requirements and Federal privacy regulations, including but not limited to the submission of all required security documentation.

4.7.1.4 Comply with all applicable TSA security requirements as specified in this SOW.

4.7.1.5 Provide a Failure Recovery protocol in case of emergency stoppages of the assessment session, power failures, and computer failure.

4.7.1.6 Comply with TSA’s IT enterprise architecture standards and processes, and submission of all required documentation.

4.7.1.7 Make minor edits such as name changes, typos missed in the review process, or other errors in the automated systems within 5 business days of the notification by the Government. Any errors found in the production version of the automated assessments shall be corrected within 48 hours of notification or detection by either TSA or the Contractor.

4.7.1.8 The Contractor shall provide a Privacy Management Plan that describes the

Contractor’s technical approach regarding the protection and security of all

Privacy Act-protected information or other PII that is stored, reported, or transferred using the Contractor’s systems and processes. This Privacy

Management Plan shall include at a minimum the following information:

4.7.1.8.1 All privacy policies and practices currently followed by the Contractor.

4.7.1.8.2 Privacy policies and practices to be implemented by the Contractor to properly safeguard and protect all Privacy Act-protected information and PII to mitigate privacy risks, including technical and physical security measures.

4.7.1.8.3 IT measures and controls to be deployed in the system to mitigate privacy risks and protect unauthorized access to the information contained in CATS.

4.7.1.8.4 Compliance and evaluation measures, including auditing measures. Self

-assessment and other mechanisms (both IT-based and physical), to be deployed to protect all Privacy Act Information and PII contained in

CATS and/or maintained in paper or electronic format at Contractor’s site(s).

4.7.1.8.5 Compliance with TSA Records Management, Privacy, SSI, and IT security requirements.

4.7.1.9 The Contractor shall have the capability to provide enhancements to the system when requested by TSA due to changing needs. When requests for enhancements are submitted by the TSA Contracting Officer (CO) to the

Contractor, receipt of the request shall be acknowledged within two (2) business days and a detailed technical solution and timeline shall be provided by the Contractor within ten (10) business days to the CO. The Contractor’s enhancements shall not include any changes required as a result of upgrades/changes and “bug fixes” performed by the Contractor to the core system. The Contractor’s System Enhancements may include but are not limited to:

4.7.1.9.1 Short-term Application Enhancements.

4.7.1.9.2 Adding or updating System Capabilities.

4.7.1.9.3 Adding or updating user roles and reporting options.

4.7.1.9.4 System and Database Tuning (not to include DHS/TSA C&A or IT security requirements).

4.7.1.9.5 A weekly report describing progress of System Enhancement(s), and resolutions when changes are made or as requested by TSA.

4.8 Project Management, Quality Control, and System Integration

4.8.1 The system shall have the capability to seamlessly integrate with all TSA’s hiring systems

(Government furnished and third-party), including the Candidate Dashboard and Airport

Assessor systems. Currently TSA’s hiring system is administered under the HRAccess contract and hosted on an Oracle platform. (The Required Interface Documentation (ICD) will be provided after contract award).

4.8.2 The system shall have the capability to seamlessly integrate with TSA’s LMS. (The required ICD will be provided after contract award).

4.8.3 The draft Project Management Plan shall include a project timeline describing the tasks and activities that will be accomplished. The draft Project Management Plan shall be due at the Post

Award Kickoff meeting. TSA will provide the Contractor with review comments within 10 business days after the draft Project Management Plan is received. The Final Project

Management Plan shall be provided to the COR within 10 business days from the date the review comments were submitted to the Contractor.

4.8.4 The draft System Integration Plan shall include a systems integration timeline describing the tasks and activities that will be accomplished. The Contractor shall provide a draft System

Integration Plan to the COR within 10 business days after the Post-award Kickoff Meeting. TSA will provide the Contractor with review comments within 10 business days after the draft

Systems Integration Plan is received. The final System Integration Plan shall be provided to the

COR within 10 business days from the date the review comments were submitted to the

Contractor.

4.8.5 The purpose of the Post-Award Kickoff Meetings, when required, is to discuss technical and contracting objectives of task order(s) and to review the Contractor’s draft Project Management

Plan and the draft System Integration Plan.

4.8.6 Quality Control Plan (QCP). The Contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this SOW. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s quality control program is the means by which the work complies with the requirements of the contract. The Contractor shall provide a draft QCP with its Quote. A final QCP is due 10 calendar days after the Post Award Meeting that will be scheduled by the CO. After receipt of the QCP, the Contractor shall obtain the COR’s acceptance in writing of any proposed change to the QCP system.

4.8.7 The Contractor shall immediately report to TSA any information regarding testing incidents and inappropriate practices engaged by Contractor personnel.

4.8.7.1 Maintain incident reports for any test administration anomalies (e.g., power outages, fire drills, technical issues, medical issues, etc.).

4.8.7.2 Receive, document and evaluate test taker complaints/concerns/incidents and provide documentation to the Government to determine if a test taker should be allowed to re-test based on the outcome of the findings (e.g., technical issues, fire drills, power outages); and take appropriate corrective actions to reschedule impacted test takers in a timely manner.

4.8.7.3 Monitor, maintain, and review incidents reported and provide reports to TSA

OHC on trends or areas of concern and determine the appropriate actions necessary based on the established TSA OHC business rules.

4.8.8 The system shall:

4.8.8.1 Be compliant, unless granted a waiver in writing by TSA, with the National

Information Exchange Model (NIEM) on all interface messages.

4.8.8.2 Have the ability to implement, integrate, and interface with other Federal

Human Resource IT systems.

4.8.8.3 Be able to transfer data between CATS and other systems, and shall be capable of providing the following:

4.8.8.3.1 Automated data transfers.

4.8.8.3.2 Data transfer to third-party software application (Excel, SPSS) for analysis.

4.8.8.3.3 The ability to access and transfer assessment data, including raw and scored data, in real-time and 24/7, with the exception of predetermined downtime due to scheduled system maintenance.

4.8.8.3.4 Transfer complete assessment results to all TSA’s Hiring (Government furnished and third-party) and LMS.

4.9 Data and Records Requirements

4.9.1 The Contractor shall submit a Data Management Plan (DMP) to TSA Enterprise Data

Management (EDM) within 60 days of the start of the project. The TSA EDM team will provide a template for the data management plan and the Contractor shall submit in accordance with the template provided. The EDM team will review the DMP for completeness and to ensure that it is in alignment with DHS guidelines. The template will be provided at the Post-award Kickoff

Meeting. The DMP includes conceptual and logical data models along with a data asset profile.

Any data exchanges with other DHS Components shall adhere to DHS data exchange standards using the NIEM. All required artifacts will be provided to the TSA EDM project team. The EDM team will review the DMP for its completeness and make sure it is in alignment with DHS guidelines.

4.9.2 As part of the necessary data structure, the Contractor shall provide an ERD to explain the business relationships to TSA through graphically and textually detailing the data that is stored per each database and system/application. The preferred format for the ERD is CA Erwin;

however other formats, such as Visio, DLL, database scripts or format specified by TSA EDM project team shall be accepted. All additional known data models (e.g., Logical Data Model

(LDM), Conceptual Data Model (CDM), Physical Data Model (PDM), Data Flow Diagrams (DFD)) depicting TSA-specific data are required. Referential integrity also needs to be addressed for all parent/child or primary key/foreign key relationships within these models.

Note: The following definitions pertain to the previous paragraphs:

a. An ERD is a diagram used to identify the topics of interest (entities) and their connections to each other

(relationships).

b. An LDM in systems engineering is a representation of an organization’s data, organized in terms of entities and relationships and is independent of any particular data management technology.

c. A CDM is a high-level model that is considered a useful first step in documenting and describing the fundamental nature of the organization’s data. It serves as the foundation for providing a common vocabulary and for understanding the overall structure of data, and for normalizing data access to support improved information sharing. In a CDM, fundamental things of significance to the business organization are represented. A CDM usually includes data objects and the corresponding core relationships in terms of the business user.

d. A PDM is a representation of a data asset design which takes into account the facilities and constraints of a given database management system (DBMS). It is typically derived from a logical data model, though it may be reverse-engineered from a given database implementation.

e. The PDM can usually be used to calculate storage estimates and may include specific storage allocation details for a given database system. There is no sharp dividing line between a CDM and an

LDM. Similarly, there is no sharp dividing line between an LDM and a PDM. Depending on the developers and their requirements, details may appear in one model or the other. Each model should be constructed down to the level of detail that makes the model useful to the intended audience.’

f. A DFD is a diagram depicting the flow of data from the source to the target systems, showing all interactions made in between. Referential integrity is a database concept that ensures that relationships between tables remain consistent. When one table has a foreign key to another table, the concept of referential integrity states that you may not add a record to the table that contains the foreign key unless there is a corresponding record in the linked table.

g. These definitions have been defined through the ‘DHS Enterprise Data Management – Data Modeling

Methodology Guidelines’ found on the DHS Connect DMWG Portal which can be found at:

http://dhsconnect.dhs.gov/org/comp/mgmt/cio/oat/Pages/DataManagementWorkingGroup.aspx

4.10 Personally Identifiable Information (PII) and Privacy Incident Response

See Section III, Clause 25, entitled “5200.224.003 Security of Systems Handling Personally Identifiable

Information and Privacy Incident Response (Aug 2013)”

4.11 Meetings

4.11.1 The Contractor shall attend, either in person or by video teleconference, a Post-award

Conference/Kickoff Meeting with the CO, COR, and PM within seven (7) business days after the

Contractors performing work on this contract have passed TSA Personnel Security suitability determination. The Post-award Conference/Kickoff Meeting will be held at the Government’s facility, located at TSA HQ, 701 12th Street, Arlington, VA.

4.11.2 The Government anticipates that the majority of meetings will be conducted via telephone, unless otherwise specified in individual Task Orders. In-person meetings or video conference will be held at TSA HQ, as necessary, by the OHC Program Office. Meeting topics shall include but are not limited to discussions on assessment recommendations, system integration, and other topics relating to the contract.

4.11.3 Intermittent Project Status Reviews

4.11.3.1 At the sole discretion of the Government and as specified in individual Task

Orders, intermittent project status reviews may be conducted on an informal basis (by telephone or teleconference) or in person at TSA HQ.

http://dhsconnect.dhs.gov/org/comp/mgmt/cio/oat/Pages/DataManagementWorkingGroup.aspx

4.11.4 Monthly Program Management Reviews

4.11.4.1 The Government will require regularly scheduled program management reviews, monthly and either in person at TSA headquarters, 701 12th Street, Arlington, VA 20598 or via conference call. During the program management reviews, TSA will review the progress of the program, identify any risks, issues, or concerns, and provide feedback on the Contractor’s progress and performance. The Contractor shall be required to provide written data and verbal presentations as to the financial status of the CATS program, any identified risks, issues, or concerns (and their mitigation or its plans for their mitigation), the number and kinds of assessments administered, and the number and type of Help Desk requests received, resolved, and pending

5 TRAVEL

Contractor travel may be required to support this requirement. All travel required by the Government outside of a 50 mile local commuting area(s) from the Contractor’s site will be reimbursed to the

Contractor in accordance with the Federal Travel Regulations. The Contractor shall be responsible for obtaining COR approval (electronic mail is acceptable) for all reimbursable travel in advance of each travel event.

The TSA COR must approve the Contractor’s travel requirements in advance. The Contractor’s contract manager/program manager or alternate shall submit the travel request no later than five days prior to travel to allow for review and approval by the TSA COR. If travel is required for short suspense requirements and the travel request cannot be submitted at least five days prior to travel, verbal authorization shall be obtained from the TSA COR as soon as possible. The TSA COR shall follow up with a written approval within 48 hours of verbal authorization.

To be considered for reimbursement, travel requests must contain:

• The purpose and destination of the trip.

• The date(s) and time(s) of travel.

• Estimated cost of travel.

• Traveler’s name and position title.

6 PLACE OF PERFORMANCE

With the exception of assessment test proctoring as specified herein, performance of this contract shall be conducted primarily at the Contractor’s site. Occasional site visits to TSA HQ, 701 12th street, Arlington, Virginia 20598, may be necessary and at no additional cost to the Government.

TSA reserves the right to visit and/or conduct random and announced/unannounced quality assurance inspections at Contractor facilities (specifically Contractor-established test facilities).

7 PERSONNEL AND FACILITIES

The Contractor shall provide all of the personnel, operational resources and facilities, and functional management processes necessary to execute the requirements of the SOW. Before performing work under this contract, the Contractor personnel must be deemed suitable by TSA Personnel Security and are required to sign a non-disclosure agreement.

8 INFORMATION ASSURANCE

8.1 Controls

8.1.1 The Contractor shall comply with DHS and TSA technical, management and operational security controls to ensure that the Government's security requirements are met. These controls are described in DHS PD 4300A and TSA MD 1400 series security policy documents and are based on the NIST Special Publication (SP) 800-53 standards.

8.2 General Security Responsibilities for Contract Performance

8.2.1 The Contractor shall ensure that its employees follow all policies and procedures governing physical, environmental, and information security described in the various TSA regulations pertaining thereto, good business practices, and the specifications, directives, and manuals for conducting work to generate the products as required by this contract. Personnel will be responsible for the physical security of their area and government furnished equipment (GFE) issued to them under the provisions of the contract.

8.2.2 All Contractor employees shall receive initial TSA IT Security Awareness Training within 60 days of assignment to the contract.

8.2.3 Refresher training must be completed annually thereafter.

8.2.4 Role-Based training for contract employees individuals with Significant Security Responsibility

(SSR), whose job proficiency is required for overall network security within TSA, will be in accordance with DHS and TSA policy.

8.2.5 Individuals with SSR will have a documented individual training and education plan, which will ensure currency with position skills requirements, with the first course to be accomplished within 90 days of employment or change of position. The individual training plan will be refreshed annually or immediately after a change in the individual’s position or related position description requirements.

8.2.6 The education and training will meet standards established by NIST and set forth in DHS and TSA security policy.

8.2.7 Evidence of training provided to personnel will be available upon request of the DHS IT Security

Training Office, or during DHS/TSA onsite validation visits performed on a periodic basis.

8.3 Configuration Management (Hardware/Software)

8.3.1 Hardware or software configuration changes shall be in accordance with the DHS Information

Security Performance Plan (current year and any updates thereafter), the DHS Continuous

Diagnostics and Mitigation (CDM) Program to include dashboard reporting requirements and

TSA’s Configuration Management policy. The TSA Chief Information Security Officer (CISO)/

Information Assurance and Cyber Security Division (IAD) must be informed of and involved in all configuration changes to the TSA IT environment including systems, software, infrastructure architecture, infrastructure assets, and end user assets. The TSA IAD will approve any request for change prior to any development activity occurring for that change and will define the security requirements for the requested change.

8.3.2 The Contractor shall ensure all application or configuration patches and/or Request for Change

(RFC) have approval by the Technical Discussion Forum (TDF), and Systems Configuration

Control Board (SCCB) and lab regression testing prior to controlled change release under the security policy document, TSA MD 1400.3 and TSA Information Assurance Handbook, unless immediate risk requires immediate intervention. Approval for immediate intervention

(emergency change) requires approval of the TSA CISO, SCCB co-chairs, and the appropriate

Operations Manager, at a minimum.

8.3.3 The Contractor shall ensure all sites impacted by patching are compliant within 14 calendar days of change approval and release.

8.3.4 The acquisition of COTS Information Assurance (IA) and IA-enabled IT products (to be used on systems entering, processing, storing, displaying, or transmitting “sensitive information”) shall be limited to those products that have been evaluated and validated, as appropriate, in accordance with the following:

8.3.4.1 The NIST FIPS validation program.

8.3.4.2 The National Security Agency (NSA)/ NIST National Information Assurance

Partnership (NIAP) Evaluation and Validation Program.

8.3.4.3 The International Common Criteria for Information Security Technology

Evaluation Mutual Recognition Agreement.

8.3.5 U.S. Government Configuration Board (USGCB) and DHS Configuration Guidance.

8.3.5.1 The provider of IT shall certify applications are fully functional and operate correctly as intended on systems using the USGCB and in accordance with DHS and TSA guidance.

8.3.5.1.1 USGCB Guidelines: http://usgcb.nist.gov/usgcb_content.html

8.3.5.1.2 DHS Sensitive Systems Configuration Guidance:

http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx

8.3.5.2 The standard installation, operation, maintenance, updates and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. The IT should also use the Windows Installer Service for installation to the default “program files” directory and should be able to silently install and uninstall.

8.3.5.3 Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.

8.3.6 The Contractor shall establish processes and procedures for continuous monitoring of

Contractor systems that contain TSA data by ensuring all such devices are monitored by, and report to, the TSA Security Operations Center (SOC).

8.4 Risk Management Framework

8.4.1 The Security Authorization and Ongoing Authorization Process in accordance with NIST SP 800-

37 and SP 800-137 (current versions) is a requirement for all TSA IT systems, including general support systems (e.g., standard TSA desktop, general network infrastructure, electronic mail, etc.), major applications and development systems (if connected to the operational network or processing, storing, or transmitting government data). These processes are documented in the

NIST Risk Management Framework. Ongoing Authorization is part of Step 6 “Monitoring” of the

Risk Management Framework. All NIST and DIACAP guidance are publicly available; TSA and

DHS security policy is disclosed upon contract award.

http://usgcb.nist.gov/usgcb_content.html http://dhsconnect.dhs.gov/org/comp/mgmt/cio/iso/Pages/sscg.aspx

8.4.2 A written ATO granted by the TSA Authorizing Official (AO) is required prior to processing operational data or connecting to any TSA network. The Contractor shall provide all necessary system information for the security authorization effort.

8.4.3 TSA will assign a security category to each IT system compliant with the requirements of FIPS

199 and assign security controls to those systems consistent with FIPS 200.

8.4.4 Unless the AO specifically states otherwise for an individual system, the duration of any

Accreditation will be dependent on the FIPS 199 rating and overall residual risk of the system;

the length can span up to 36 months.

8.4.5 The Security Authorization Package contains documentation required for Security

Authorizations and Ongoing Authorization. The package shall contain the following security documentation: 1) Security Assessment Report (SAR) 2) Security Plan (SP) or System Security

Authorization Agreement (SSAA), 3) Contingency Plan (CP), 4) Contingency Plan Test Results, 5)

FIPS 199 Security Categorization, 6) Privacy Threshold Analysis (PTA), 7) E-Authentication, 8)

Security Assessment Plan (SAP), 9) ATO Letter, 10) Plan of Action and Milestones (POA&M), and

11) Ongoing Authorization Artifacts as required by the DHS Ongoing Authorization Methodology

(current version). The SA package shall document the specific procedures, training, and accountability measures in place for systems that process PII. All security compliance documents will be reviewed and approved by the CISO and the IAD, and accepted by the CO upon creation and after any subsequent changes, before they go into effect.

8.5 Contingency Planning

8.5.1 The Contractor shall develop and maintain a Contingency Plan (CP) upon contract award to include a Continuity of Operation Plan (COOP), to address circumstances whereby normal operations are disrupted.

8.5.2 The Contractor shall ensure that contingency plans are consistent with template provided in the

DHS Information Assurance Compliance System Tool. If access has not been provided initially, the Contractor shall use the DHS 4300A Sensitive System Handbook, Attachment 8, IT

Contingency Plan Template.

8.5.3 The Contractor shall identify and train all TSA personnel involved with COOP efforts in the procedures and logistics of the disaster recovery and business continuity plans.

8.5.4 The Contractor shall ensure the availability of critical resources and facilitate the COOP in an emergency situation.

8.5.5 The Contractor will test their CP annually.

8.5.6 The Contractor shall record, track, and correct any CP deficiency and any deficiency correction that cannot be accomplished within…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .