Attachment_I_PERFORMANCE_WORK_STATEMENT.docx
DOCX document 73 KB Posted
- Attached to
- HMS IT Maintenance Bridge Sole Sourced Federal contract opportunity
- Solicitation number
- N0018918HMSMS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| COMBINED_SYNOP-SOLI_FINAL2.docx | DOCX document | |
| Attachment_II_GFP.xlsx | XLSX spreadsheet | |
| Attachment_III_CAP_FFP.doc | DOC document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Terminology and Acronyms utilized herein are further defined in Attachment VI.
1.0. INTRODUCTION. The Navy Bloodborne Infection Management Center (NBIMC) supports clinical patient management through inpatient and outpatient care at field, hospital, and branch clinic locations worldwide. NBIMC, under direction of the Bureau of Medicine and Surgery located at the Naval Support Activity (NSA), Bethesda MD serves as the oversight branch for the management, administration, and development of policy concerning force screening for Human Immunodeficiency Virus (HIV) and Recruit hepatitis screenings. NBIMC operates a system called HIV Management Service (HMS) that maintains interoperability with the Composite Health Care System (CHCS), SNAP Automated Medical System, (SAMS), DoD Theater Medical Information Program (TMIP);
Headquarters level activities, Medical Readiness Reporting System (MRRS) and the current testing contractor system(s) in use.
1.1. HMS is a Certified and Accredited distributed Internet application with the database and database application residing on a central, dedicated network of servers providing client/server support to selected users. HMS user’s access HMS servers and applications from workstations by way of NIPRNET via the WRNMMC/NSA local area network (LAN) using HTTPS. HMS is not directly interfaced to other external systems. Selected data sources provide data for loading/updating the HMS database through uploading of encrypted data files to the HMS Network.
HMS Object Overview is depicted in Attachment III "Diagram 1.1 HMS OBJECT OVERVIEW"
1.1.1 HMS uses Microsoft SQL Server Relational Database Management System (RDBMS). HMS is a set of application modules, accessed by menus, that contain User Interface screens and application business logic distributed to both clients and centralized servers to manage access to and update of database tables related to particular categories of environmental and health data. The following applications comprise the HMS System:
· HMS Application v.1.2
· HMSLoader Subsystem v.1.0.1
· HML 1.05.1 – HIV Management Loader
· HML-HMS Interface Application v.2.0
HMS is a custom built application that performs three basic functions: Process test orders, report test results, and patient administration. The HMS system accepts, stores, and processes testing data from various DoD information systems. These systems are the Navy and Coast Guard Composite Health Care System (CHCS), MRRS (Medical Readiness Reporting System), and SAMS (Shipboard Non-Tactical Automated Data Processing Program Automated Medical System). Test data is also submitted through NBIMC HMSLoader system which is a web application provided to users that need to order additional test(s) that cannot be ordered through the systems previously mentioned, and as a backup in the event one of the listed systems has an outage. The test orders are sent to a contracted laboratory; and thereafter, the results are received and processed into HMS and reported back to the original test submitter.
HMSLoader Sub System: The HIV Management System Loader (HMSLoader), a component of HMS, is a web-base application that accepts test orders from users around the world. HMSLoader is also used to order additional or supplemental tests other than HIV tests.The HMSLoader application also accepts test orders from the Shipboard Non-Tactical ADP Program (SNAP) Automated Medical System (SAMS). The orders are submitted via an encrypted file extracted by the SAMS system. HMSLoader is a Visual Basic application that allows entry and subsequent processing of blood specimen demographic information for test orders. It is designed to provide services to the NBIMC user community by combining a Microsoft Internet Explorer (IE) interface along with Internet access. By using a secure web-based architecture (Hypertext Transfer Protocol Secure [HTTPS] exclusively). It is a distributed Internet application composed of client access portion and application logic/processing portion. The client portion is implemented using HTML-based forms deployed using Microsoft IE 5.5 (or higher). All client/server communications are performed using HTTPS.
HIV Management Loader (HML): HML is the component of the HIV Management Service (HMS). HML’s key responsibility is to manage data transactions and provide a central data repository for storage and reporting to authorized sites. HML consists of three services, which work together to send orders and receive results between CHCS sites and the contractor laboratory; transform data from HL7 messages to XML and vice versa; and store, process and validate orders and results, and to also to support HML. One is a service to extract HMSLoader Orders, and the other is to submit results into the HMS system. The HML system is a component of HMS and is designed to process all test orders and results from all of the relevant DoD systems and the contractor laboratory.
1.1.2. Upon contract award the Contractor shall ensure that computer system data processing for HMS shall be maintained in accordance with DoD 8510.01 and DOD 8500 series instructions for Sensitive MAC II level systems at all level times; A DoD Information Technology Security Certification and Accreditation Process (DIACAP) is required for HMS and will be renewed every three years. A three-year DIACAP renewal will be required and will be pursued by the Government prior to the expiration of the Authority to Operate (ATO)/Interim Authority to Operate. Data management under this contract is Sensitive But Unclassified (SBU) and must have the appropriate compliance with the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and Privacy laws.
1.1.2.1. Within 30 days of contract award the contractor shall begin the process of ensuring the HMS system meets the DIACAP requirements and preparing documentation. The contractor shall complete all documentation as updates are required and as directed by the Information Assurance Officer (IAO) and Certification and Accreditation Team. The contractor shall note, this process will be repeated at least once during the life of this contract.
1.1.3. The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all Government data, to ensure the confidentiality, integrity, and availability of Government data.
1.1.4. Health Insurance Portability and Accountability Act (HIPAA). The contractor shall comply with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (P.L. 104-191) requirements, as well as the Department of Defense (DoD) 6025.18-R, "DoD Health Information Privacy Regulation," December , 2009. This includes the Standards for Electronic Transactions, the Standards for Privacy of Individually Identifiable Health Information and the Security Standards. The contractor shall also comply with all Applicable HIPAA-related rules and regulations as they are published and defined. Refer to inclusion of Business Associate Agreement within Section H Special Contract Requirements.
1.1.5. Data Use Agreement (DUA)/Data Sharing Agreement (DSA). Upon award the contractor shall sign a Data Use Agreement (DAU)/ Data Sharing Agreement (DSA) Attachment A) to ensure that PHI is used appropriately and is not disclosed to unauthorized individuals or organizations. Contractors "accessing, retrieving, maintaining or collecting" individual identifying information on behalf of any DoD Component must comply with the requirements of HIPAA Privacy Rule, DoD 6025.18-R C8, DoD 5400.11-R and DoD Directive 5400.11 as if they were a DoD employee.
1.1.6. Systems of Record. The contractor shall assist the Government in completing a Privacy Act System of Records Notice for collections of records where information in identifiable form is retrieved in order to meet the requirements of 5 U.S.C. 552a, the Privacy Act of 1974 . The contractor will also comply with the requirements in Office of Management and Budget (OMB) Circular A-130 , in the DoD Directive 5400.11, “DoD Privacy Program,” May 8, 2007, and in the DoD 5400.11-R, “Department of Defense Privacy Program,” May 14, 2007.
1.1.7. Privacy Impact Assessment. The contractor shall assist in the completion of a Privacy Impact Assessment (PIA) for the Navy AIS (HMS) that maintains protected health information (PHI) or individually identifiable Information (III) on Active duty members and beneficiaries that retrieves such III through the use of personal identifiers. The PIA will be prepared according to the DoD PIA format, which is specified in the “DoD Privacy Impact Assessment (PIA) Guidance,” dated February 12, 2009.
1.1.8. The Contractor shall support obtaining certification and accreditation of Navy AISs (HMS). This task will consist of process support, analysis support, coordination support, security certification test support, and security documentation support.
a) Process Support. The contractor shall assist the Government in the implementation of the DIACAP. The contractor shall recommend process tailoring as provided for in the DIACAP, participate in process activities, and document the results of those activities.
b) Analysis Support. The contractor shall perform analyses to validate established security requirements and to recommend additional security requirements. The contractor shall analyze through testing the adequacy of the required protective features, assess residual risk, and assist in determining the readiness of the system for accreditation. For detected vulnerabilities that could preclude accreditation, the contractor shall recommend human procedures, software configuration parameters, system changes, or combinations thereof to mitigate the risk with the vulnerability.
c) Coordination Support. As directed by Government, the contractor shall coordinate with or participate in meetings with the Government to keep them informed on system security matters, address specific security issues, and obtain guidance. The contractor shall participate in meetings with other organizations as directed by the Government.
d) Security Certification Test Support. In addition to the testing performed for Analysis Support, the contractor shall support the formal Security Test and Evaluation (ST&E) of the Navy HMS System being evaluated. This support shall include pre-test preparations, participation in the tests, and analysis of the results. This testing will be performed bi-annually by the Government and as directed by senior organizations.
e) Security Documentation Support. The contractor shall document the results of the DIACAP process activities and contractor technical or coordination activity. The contractor shall prepare the System Security Authorization Agreement (SSAA) (with all required appendices), and other supporting documentation. The DIACAP documents will be kept up to date as system changes occur (i.e. software, hardware, ports and protocols etc..,).
f) Independent Verification & Validation (IV&V) Support. In addition to other testing performed, the contractor shall support the Independent Verification & Validation (IV&V) Security Test of the Navy HMS System being evaluated. This support shall include pre-test preparations, participation in the tests, and analysis of the results. This testing will be performed bi-annually by the Government and as directed by senior organizations.
1.2 SCOPE OF WORK. The Contractor shall provide qualified personnel to perform all service necessary to maintain the NBIMC HMS. The contractor shall provide qualified personnel to perform all maintenance and duties that include, but are not limited to the following:
· Project Management
· Network administration
· Information Assurance and System security
· System Administration
· Database administration
· Data Transmission Troubleshooting
· Data Load Application
· HMS Application Monitoring
· HML Application
· HMS-HML Interface Application
· HMSLoader User Administration
· Technical Writing, Documentation Analysis, Review and Update
1.2.1. Contractor employees shall ensure HMS component (HMS, HMSL, HML, CHCS, MRRS) connectivity is maintained, applications work and customer reports are provided within established time frames. The Contractor can expect to process 10,000 patient records per day, download multiple (approximately 6-8) master files weekly from headquarter level sources and conduct troubleshooting routines to resolve errors daily from information assurance alerts, security documentation or network logs.
1.2.2. Perform information assurance and security management through continuous improvement analysis; as well as, troubleshooting issues (errors & outages, etc.), conducting testing, performing training, maintaining logs (network, security, application, occurrences, trouble tickets, schedule change requests, etc), and documenting preparation techniques.
1.2.3. Perform testing, prepare test plans, prepare attendant documentation and conduct on and off-site training to ensure operations proceed according to prescribed procedures and processes.
1.2.4. The Contract shall provide personnel in following labor categories:
1 - Project Manager 1 - Technical Writer / Configuration Manager 1 – Documentation Specialist 1 - Computer Software Engineer (System and Application software developer) 1 – Database Administrator 1 – Data Analyst 2 - Server Application / Computer System Administrator 1 - Network System/Data Communication Analyst 1 - Information Assurance and System security
1.3 CONTRACT PERSONNEL. The Government will not exercise any supervision or control over Contractor employee performing services under this Performance Work Statement (PWS); such employees shall be accountable solely to the Contractor who, in turn, is responsible to the Government.
1.3.1. The Contractor shall furnish qualified personnel to assure satisfactory performance of the services required by the PWS. The Contractor shall use full-time employees, on site at NBIMC.
1.3.2. Within the time frames specified by the government, Contractor employees shall complete and maintain all requirements set forth for conduct and performance on-site at NSA Bethesda. The government expectation is contractor personnel shall participate in and complete staff education and training requirements as set forth in this DON guidance (weekly, monthly, semi-annual and annual time frames or when directed by DoN/DoD.
1.3.3. The Contractor shall provide personnel with working knowledge of and hands on work experience in performing requirements within the PWS. As a minimum, senior level Contractor employees shall have work experience with the following software/systems/protocols and Government guidelines contained within this PWS.
1.3.3.1. The contractor shall provide personnel with current skill sets to perform the tasks outlined in the statement of work. Due to the evolving nature of the Information Technology industry, the government requires the skill level of the staff to remain current with technology. The government expects the contractor to provide qualified substitutes for any employee involved in off-site training required to maintain competency to work under this contract.
1.3.4. The Contractor shall provide personnel during normal duty hours Monday through Saturday, exclusive of Federal Holidays. Normal duty hours are between 0630 to 1700. The contractor shall ensure coverage is maintained by personnel with Data Management and System Operations skill sets during the core working hours daily. All work shall be performed at Naval Support Activity, Navy Bloodborne Infection Management Center, Bethesda, MD. On occasion, Contactor personnel duty work hours may shift to accommodate performing routine and non-routine maintenance procedures during alternate shift duty hours (on a bi-monthly basis) such as upgrading applications(s) and server methodologies, and/or aligning procedures to coincide with NSA Bethesda, DoN and/or DoD policy initiatives. The contractor shall not perform services in excess of 40 hours per week for each position. Contractor will provide coverage during duty hours and have replacement coverage available. Government will allow a 24-hour window for replacement coverage to be provided by contractor.
1.3.5. The Contractor shall ensure equipment (business policy switches, servers, firewall and network) operations is documented and supported within the DoD common operating environment. Contractor personnel shall ensure documentation reflects actual events, occurrences, and accurately augments operating policies and procedures.
1.3.6. The Contractor shall ensure that employees providing services under this contract are able to read, write, and speak English fluently to communicate clearly and effectively.
1.3.7. The Contractor shall provide employee(s) toll free telephonic access to Contractor facilities when on-site at NSA Bethesda or other sites determined by the Contractor and the government to complete services.
1.3.8. It is essential that continuity of services be maintained to the maximum degree possible; hence, substitution of Contractor employees shall be kept to the absolute minimum necessary to perform the services required and to provide adequate substitute personnel. All substitute personnel must meet the personnel qualifications as set forth in the contract, to include applicable training and certifications to support all technologies deployed at NBIMC as described within the PWS.
1.3.9 All contractor provided personnel shall be required to provide on/off site training to the authorized user community.
1.4 SECURITY REQUIREMENTS. Computer system data processing and management under this contract is Sensitive But Unclassified (SBU) and must have the appropriate compliance with requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Security Requirements for HMS can be located within the DoD Publications; DoD 52001-R, DoD 5200.2-R, DoD 5200.08-R, and DIRECTIVE 8510.01, 8500.1 and 8500.2 Information Assurance (IA) which can all be accessed electronically at the following web address: http://www.dtic.mil/whs/directives/index.html .
1.4.1. The IS/networks involved in the operation of DoD systems of records shall be safeguarded through the use of a mixture of administrative, procedural, physical, communications, emanations, computer and personnel security measures that together achieve the same requisite level of security established for DoD IS/networks for the protection of information referred to as “Sensitive Information.”
1.4.2. DOD 8510.01 CERTIFIED AND ACCREDITATED security requirements are found in the Department of Defense Directive (DODD) 8500.01E (Information Assurance) and Department of Defense Instruction (DoDI) 8500.2 (Information Assurance Implementation).
1.4.3. Personnel Security. The tasks required under this requirement meet the criteria for an IT-II position designation, therefore, the Contractor must possess a DISCO, DONCAF or DOHA favorably adjudicated National Agency Check with Local Checks (NACLC) prior to period of performance start date. The Contractor must possess a "SECRET" clearance for all performing staff and have met all the security requirements for an approved ADP/IT-II position.
1.4.3.5.1. Facility Clearance
The contractor must meet eligibility requirements for access at the level required for “Secret” Information. At the time of award, the contractor shall furnish a completed DD 254. See Attachment I.
1.5 INFORMATION ASSURANCE. The information assurance Contractor personnel must have at least three (3) to five (5) years experience at the engineering level. The Contractor provided personnel must be available to ensure full functional and multi-tasking support. Upon award, the Contractor shall furnish to the Contracting Officer Representative (COR) documentation verifying this information assurance , operating system, computing and network environment experience and certifications IAW DoD 8570, and DoDI 8570.01-M.
a) The Contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. The Contractor shall meet the applicable information assurance certification requirements, including—
(1) DoD-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8570-01-M; and
(2) Appropriate operating system and network environment certifications for information assurance technical positions in accordance with DoD 8570.01-M.
(3) Upon request by the Government, the Contractor shall provide documentation supporting the information assurance certification status of personnel performing information assurance functions.
(4) Contractor personnel who do not have proper and current certifications shall be denied access to DoD information systems for the purpose of performing information assurance functions.
(5) The Contractor must have the required staff to maintain the contract, with the required IA certifications and experience upon contract start. All new hires’ thereafter, qualification periods begin the date they start in the position (i.e., they must obtain the appropriate certification within 6 months of hire date).
1.5.1. The contractor shall provide personnel with current skill sets to perform the tasks outlined in the statement of work. Due to the evolving nature of the IT industry, the government requires the skill level of the staff to remain current with technology. The government expects the contractor to provide qualified substitutes for any employee involved in off-site training required to maintain competency to work under this contract. The contractor shall pay for the cost of training courses for their employees for appropriate certifications or to gain competencies in new technologies that may be deployed at NBIMC.
1.5.1.1 CERTIFICATION REQUIREMENTS. All contract personnel on-site with privileged access are considered IAT II and must have a Security Plus certification. In addition, at least one member of the on-site contract personnel team will have the baseline certification required for each area of expertise (i.e. operating system (OS) and computing/ network environments (CE/NE) represented. The baseline certifications for OS and CE/NE are listed below in accordance with NBIMC set requirements; Navy Medicine DoD 8570-1M and SECNAV M-5329.2 IAWF improvement program implementation guide; however, higher certifications are acceptable:
| Certification |
| IAT Level II |
| OS/CE/NE |
| MCTS |
| X |
| OS |
| MCITP |
| X |
| CE/NE |
| MCTS.NET |
| X |
| CE |
| MCDBA |
| X |
| CE |
| CCNP |
| X |
| NE |
| JUNIPER Networks IDP |
| X |
| NE |
| CISSP |
| X |
| OS/CE/NE |
1.6 Continuous training/education is required for these positions as technology and standards are changing. The contractor is responsible for maintaining updated certifications for personnel and HMS in relation to the certifications identified within this Performance Work Statement.
1.7 Configuration Management Team or CCB . Project Manager shall be responsible to the Government CCB Chairperson (Task Order Manager) for:
Overall responsibility for all CM activities related to the project
Ensuring approval for any issues requiring additional scope, time, or cost
Identification of CIs
All communication of CM activities to project stakeholders
Participation in CCB meetings
Re-baselining, as required, any items affected by CM changes The Project Manager will also submit weekly reports, to include configuration status, every Friday. These reports will consist of the following information as part of the configuration status section (DASHBOARD ROLL-UP):
1) Change requests
a. Aging - How long change requests have been open
b. Distribution - number of change requests submitted by owner/group
c. Trending - what area(s) are approved changes occurring in
2) Version Control
a. Software
b. Hardware
c. Data
d. Documentation
3) Build Reporting
a. Files
b. CI relationships
c. Incorporated Changes
4) Audits
a. Physical Configuration
b. Functional Configuration
Lead Engineers
All identified CIs will be assigned to a Lead Engineer. The assigned Lead Engineer shall be responsible for:
Designating a focus group to develop the change request
Ensure all change requests comply with organizational templates and standards prior to the CCB
Documentation Specialist (Identification of CIs)
The Project Manager will assign a CI name and the CI will be entered into the CMDB in an "initiate" status. The CI will then be assigned to an engineer focus group (development team or NA's & SA's). Each member of a CIs focus group could have the ability to access the CI through Clear Quest, make changes and edits, and enter the CI back into the Clear Quest with a description of the change/edit annotated in the CMDB log.
Testing shall be conducted for all software, System or Network changes by the focus group in order to validate any changes made. The Lead Engineer assigned to manage the focus group is responsible for ensuring that testing has been conducted, changes are entered into the CMDB log, and that all changes/edits are saved properly into the CMDB. The Lead Engineer is also responsible for assigning new version numbers and CMDB status for any changes made by his/her assigned focus group.
The Lead Engineer, CM, and Project Manager will work together to ensure these relationships are fully understood. The Lead Engineer and CM will then be responsible for illustrating these relationships and co-dependencies in the CMDB to ensure a full understanding of each CI and how they relate to one another.
Any configuration changes which are identified by the project team or stakeholders must be captured in a configuration change request (CCR) and submitted to the CCB. The CCB will review, analyze, and approve/deny the request based on the impact, scope, time, and cost of the proposed change.
If the change is approved, the project requirements will be re-baselined (if necessary) and all changes will be communicated to the project team and stakeholders by the Project Manager. Denied CCRs through CQ may be re-submitted with additional or new information for re-consideration by the CCB.
1.8 RIGHTS TO TECHNICAL DATA AND SOFTWARE. All data and computer software developed under this contract belongs exclusively to the Government with unlimited rights as defined in DFARS 252.227-7013, “Rights in Technical Data and Computer Software” (Oct 1988). All employees will be expected to sign a Non-Disclosure Agreement (NDA) as part of their check-in process at contract award.
1.9 GOVERNMENT RESOURCES. The Government will provide, without cost, office space, and functional equipment to perform work at the NSA Bethesda.
1.9.1 The Government will provide general maintenance plan specifications for equipment and HMS documentation/instructions for Contractor use.
1.9.2 The Government will provide a test system (to mirror the operational system to troubleshoot issues) on site at NSA Bethesda and/or at other designated DoD test sites for Contractor provided operations. The contractor will ensure that all available equipment is used in the test system. The test system should be set up so that it mirrors the production system to maximum extent practicable using new or used equipment removed from the production system. The contractor shall note this requirement is dependent upon having available funding and equipment.
1.9.3 The contractor will be required to travel to other locations in support of the tasks described in the statement of work. All arrangements will be agreed upon in advance between the contractor and the Government. The government will pay for all required travel and per diem cost for travel on behalf of the government. All travel arrangements shall comply with the Federal Travel Regulations.
1.9.4 Equipment. The government will provide a cellular telephone or blackberry to designated contract personnel to receive after hour alerts. All hardware , software, firmware purchases or upgrades to the HMS system will be at the expense of the government.
2.0 UPON CONTRACT END. Upon completion or termination of this contract, all computer programs and copies generated and/or provided to the Contractor under this contract shall be audited for accuracy, availability, and provided to the government within five (5) calendar days of contract end.
3.0 INTRUSION MANAGEMENT SERVICES. The Contractor shall provide a Network System/Data Communication Analyst to perform Intrusion Management Services including but not limited to the following:
· Provide daily on-site network monitoring and firewall management [Monday through Friday (0630-1700 hours).
· Provide twenty-four (24) hours, seven (7) days per week, and 365 days per year sensor alerts and notify NBIMC Staff within two hours in the event of outages, or service disruptions.
· Conduct on-site trend analysis daily.
· Participate in network design reviews and provide advice to the Government regarding the impact of proposed changes on firewalls, IDS and other network security policy and/or practices.
· Perform Asset Management.
· Implement Fault Management.
· Perform System Audit Log Monitoring daily.
· Ensure File Integrity Monitoring daily.
· Document daily events within eight (8) to twelve (12) hours of occurrence.
· Suggest, recommend, and document methods of reducing vulnerabilities as it relates to intrusion detection trends. (weekly)
· Create new and administer existing firewall rules for NBIMC applications in accordance with NBIMC firewall modification process, noting the specific mapping of ports in and out. (daily)
· Manage current configuration and participate in design planning for firewall changes. (weekly)
· Validate ports daily on each server that are identified as requiring filtering through a firewall.
· Establish access control lists, that control which inside systems can establish connections to external networks and which external networks can connect to the NBIMC network. (daily)
· Establish all ports and protocols in use in the DMZ and provide firewall rules to support devices in the DMZ zones. (daily)
· Administer all switches, VPN devices and monitoring systems established in the DMZ. (daily)
· Perform Vulnerability Assessments at least quarterly, using tools such as Retina, WSUS and Gold Disk to determine locations within the network that might be vulnerable to attack from internal or external sources. (provide report of findings to Government).
· Analyze firewall, intrusion detection logs and network vulnerability assessments on a daily basis and provided results to Government.
· Ensure the system’s management application for alert activation, administration and management requires authentication using username and password.
· Contractor shall provide security services to the maximum extent possible via standard security protocols (e.g., Secure Sockets Layer, Transport Layer Security, and secure/Multipurpose Internet Mail Extensions) and shall use algorithms and key strengths as defined in DoD Policy.
3.0.1 SYSTEM AFTER HOURS ON-CALL MONITORING. The contractor shall monitor the HIV Management service (HMS) system twenty-four (24) hours, seven (7) days per week, and 365 days per year via Government Furnished Equipment (GFE), and contactor personnel shall report onsite if required for issues that cannot be corrected remotely. NBIMC staff will be notified within two hours in the event of outages, or service disruptions. The notifications will be sent via telephone notices or email alerts to the Government Furnished Property (GFP) provided to the contractor (as listed in Attachment VIII). The notification will be provided by WRNMMC operation personnel, NBIMC personnel or email notification alerts.
3.1 The Contractor shall provide a System Administration to at a minimum performs the following:
Anti-Virus, Patching , and Scripting Administration
· Assist with the planning, design, research and acquisition of new or upgraded hardware and software systems; maintain current knowledge of hardware, software and network technology and recommends modifications as necessary.
· Manage systems for update protection for the latest virus/worm signature. Perform daily scans and create an emergency policy during a virus outbreak attack, secluding subnet, isolating the infection in a small controlled area.
· Perform weekly scans using the Retina scanner, or other approved scanner, domain wide, to ensure compliance via Interim Authority to Operate/Information Assurance Vulnerability Alerts (IATO/IAVA) standards, providing remediation when vulnerability is found from regular patching, registry fix or complete reformat of the affected systems and ensure Computer Tasking Order (CTO) requirements. Submit weekly vulnerability findings and mitigation reports after scanning of domain/network devices etc.
· Updoad Retina scans into VRAM or other designated application as required.
· Manage the updates for the Domain Naming System (DNS) black hole lists mandated by the IATO/IAVA as a DOD standard, preventing users accessing any non-approved websites considered harmful in computer operations.
· Apply patches Daily, Weekly or when CTO, IAVA/IAVA(B), or IAVA(T) information is distributed or received.
· After normal working hours, the Contractor shall provide sensor alert action via remote monitoring and notification.
3.2 As a minimum, Contractor employees shall have the ability and skill to maintain, network, application and information assurance software, system(s), and security protocols in the following areas:
· Juniper Netscreen Firewalls
· Netscreen Security Manager
· CISCO Router protocols
· CISCO Switches protocols
· Database Management Services
· Oracle 9i
· Configuration Management
· VPN Deployment (hardware, software)
· Network Management
· Server Management
· IT Desktop Support
4.0 The Contractor shall furnish personnel within the following functional areas with a combination of skill sets and understanding of the below technologies:
a) DEVELOPMENT & GRAPHIC:
· Rational Suite Analyst Studio
· C++
· Visio 2003 (or current version)
· Microsoft Message Queue
· VBScript
· Visual Basic using Business Objects
· Microsoft Visual SourceSafe
· VISUAL C++
· .Net
· ASP.Net
· XML
· JAVA
· JAVASCRIPT
· HTML
· SQL
b) FIREWALL MANAGEMENT/NETWORK MONITORING:
· Fast Ethernet
· TCP/IP
· Network Engineering
· Intrusion Detection and Prevention
· Firewall VPN Security
· Juniper Netscreen and Pix firewalls IDS/IPS monitoring, administration and alerts
· Netscreen Securtiy Manager (NSM)
· Forensics tools
· Penetration Testing tools
· Vulnerability Assessment Tools
· The Host Based Security System (HBSS)
· Secure Socket Layer (SSL)
· Hypertext Transfer Protocol (HTTP)
· Hypertext Transfer Protocol Secure (HTTPS)
c) OPERATING & DESKTOP:
· Microsoft Operating System w/IIS, Transaction Server
· Windows NT/2000/2003 (or current version)
· Microsoft Windows XP Desktop (or current version)
· Microsoft SQL 2000/2005 (or current version)
· Other Microsoft Windows current version
d) OTHER:
· Project Management
· Configuration Management Protocol & Guidelines
· Requirements Analysis & Mapping
· Technical Writing
· HIPPA Guidelines
· DON Guidelines
· Intrusion Detection System Protocol & Guidelines
· Rational Suite (Clear Quest)
· Solar Winds Orion (or current version)
· VMWare OS
· Symantec AntiVirus Backup Exec
· SSH Tactia
· Crystal Reports XI (or current version)
· Visual SourceSafe 2005 (or current version)
· Red Hat Linux
· HL7 data format Messaging
· HP TRIM (or other Records Management software application)
4.0.1 The Contractor shall provide COTS solutions that are IPv6 capable. An IPv6 capable system or product shall be capable of receiving, processing, transmitting and forwarding IPv6 packets and/or interfacing with other systems and protocols in a manner similar to that of IPv4. Specific criteria to be deemed IPv6 capable are:
– Conformance to the DoD Information Technology Standards Registry (DISR) developed DoD IPv6 Standards Profile. Systems being developed, procured or acquired shall comply with the Global Information Grid Architecture and DISR standard IPv6 Capable definition. An IPv6 Capable system must meet the IPv6 base requirements defined in the “DoD IPv6 Standards Profile v2.0” dated August 1, 2007 available from the DISR.
– Maintenance of interoperability with IPv4. Systems being developed, procured or acquired shall maintain interoperability with IPv4 systems/capabilities. Systems should implement IPv4/IPv6dual-stack and should also be built to determine which protocol layer to use depending on the destination host it is attempting to communicate with or establish a socket with. If either protocol is possible, systems should employ IPv6.
– Evidence of a migration path and commitment to upgrade all applications and product features to IPv6 by June 2008.
– Availability of contractor/vendor IPv6 technical support for system development, implementation and management.
– DoD IPv6 security guidelines, standards, and solutions shall be utilized and adhered to when available. Currently, DoD IPv6 Information Assurance (IA) guidance is available from the DoD IPv6 Transition Office (DITO).
4.1 The Government reserves the right to update and/or modify this list per requirements set forth by DoD or other authorizing agencies with at least fifteen (15) working days notice. The Contractor in conjunction with NBIMC shall implement a schedule according to revised requirements and the expertise of employees available within five (5) working days of such notice.
4.2 The contractor shall keep the government informed on all technical or administrative activities associated with this effort through proactive communication and through monthly status reports. The contractor shall also provide coordination with the COR for all required tasks under this contract to include training requirements, software upgrades/enhancements, and hardware repair of all major computer applications/system.
5.0 PROJECT MANAGEMENT
The Project Manager is responsible for ensuring that the Project Team completes the project. The Project Manager develops the Project Plan with the team and manages the team’s performance of project tasks. It is also the responsibility of the Project Manager to secure acceptance and approval of deliverables from the Government. The Project Manager is responsible for communication, including status reporting, risk management, escalation of issues that cannot be resolved in the team, and, in general, making sure the project is delivered in budget, on schedule, and within scope.
5.1 PROGRAM MANAGEMENT PLAN. The contractor shall provide a Project Manager which at a minimum performs the following:
The Contractor shall maintain throughout the period of performance, a Program Management Plan (PMP) that will be a continuous medium of technical direction.
5.1.1 The PMP metrics shall be developed by the contractor, then coordinated with and approved by the Government before they are integrated into the PMP. The COR shall have 10 working days to review, comment and approve and/or disapprove the plan upon submission. If the COR finds deficiencies in any portion of the plan, the Contractor shall have ten (10) working days to revise the plan and correct the deficiencies. This review and correction process will continue until the Program Management Plan is approved in writing by the COR. The contractor may add additional areas to the PMP after coordination and approval from the Government. The contractor shall keep the PMP up-to-date, and shall be prepared to brief any PMP content to the Government on short notice, generally within 24 hours.
5.1.2 The PMP shall include the following:
· Provide a dashboard to track every aspect of the project; systems, network; security; documentation and all other processes and/or deliverables to include completion dates.
· Status of current action items, any system change requests, procedures or other issues impacting operations (weekly)
· Findings (as events occur)
· Project transition processes, Transition Plan updates, and schedule
· Process management and control
· Contractor organizational structure
· Key deliverables
· Monitoring mechanisms including program metrics
· Recommendations to improve Service
· Status, assurance and evidence of all documentation updates.
· Status, assurance and evidence of all of Source Code information changes, edits, updates and cataloging in visual source safe.
· Status, assurance and evidence that the proper documentation of all current system, application and account passwords have been submitted to the Government. (No system, application passwords should be changed without Government Authorization.
5.2 The contractor shall immediately notify the Government and shall prepare reports (incident, occurrence, events, etc.) the day of the event for any and all issues that delay or impact daily production; reports will include stating the problem, all troubleshooting efforts, findings, analysis, testing, recommendations and corrective actions performed. If findings require developer intervention, then the contractor shall prepare a schedule change request document for further approval and action.
5.3 The contractor shall prepare daily maintenance logs that include, all work performed, patches, upgrades installed, or incidents encountered. Report findings using the help desk reporting, trouble ticket or system change request methods in use (Rational Studio Suites).
5.3.2 The contractor shall confirm that the IS/networks are locked down prior to initiating testing. Any re-configuration or change in the system will require a re-base lining of the system and documentation of system changes. Vulnerabilities that have been identified must be mitigated according to the timeline identified by the Government Representative.
5.3.3 All word processing/briefing slides shall be in MS Office 2007 formats (or current version).
5.3.4 All technical drawings shall be in Visio version 2007 (or current version).
5.4 The contractor shall collaborate with existing contract technical staff to ensure all component updates meet the DoD Defense Information Infrastructure, Common Operating Environment (DII/COE) and are compatible with established component software in use. Ensure application changes are documented and have proper versioning control. Contractor personnel can expect to work with other agency personnel (government and contractor); senior manager; and expert engineers.
5.5 Throughout the life of the resultant contract, the Contractor shall collaborate with other user communities to: (a) perform system re-engineering, testing, integration, installation and deployment of components; (b) document and implement system component integration into the existing HMS; and (c) update existing integration, network and technical documents relative to components within the HMS documentation library.”
5.6 The contractor shall maintain user administration accounts, role-based security requirements and audit use for authorized and unauthorized access according to established protocol.
5.7 The contractor shall prepare test plans when new testing is required, or processes are implemented.
5.8 The contractor shall prepare and submit to NBIMC for approval, Management plans when system downtime is required due to testing, new implementation, patching etc..,
6.0 The contractor shall provide employees in the designated labor categories listed in Section 1.2.4 to perform the tasking/duties described in the following section.
6.1 HMS DATABASE MAINTENANCE. The contractor shall provide qualified employees to perform the task listed in Sections 6.1.1 through 6.7 in the follow labor categories:
Computer Programmer
Computer Software Engineer (Application)
Computer Software Engineer (System Software)
Computer System Analyst
Database Administrator
6.1.1 The qualified employees listed in section 6.1 will at a minimum complete the following daily tasks:
· HMS receives data imported from external systems by way of secure file transfer protocols. These protocols consist of Hypertext Transfer Protocol-secure (HTTPS) and Secure Socket Layer (SSL), Data Encryption Standards (DES) encryption, Triple-DES encryption, a Secure File Gateway, a Business to Business Gateway (B2B), utilize SFTP and VPN, and zipped password protected e-mail files. It thereby allows NBIMC to retain control of all patient identifiable information to minimize unauthorized disclosures and comply with Health Insurance Portability and Accountability Act (HIPAA) of 1996. The contractor shall ensure data files are processed through manual and automated methods.
· Ensure HMS compatibility with legacy systems including WIN 2000, WIN 2003, .Net or current protocols;
· Document system changes and deliver report logs to NBIMC bi-weekly;
· Troubleshoot and maintain concurrent connections with internal/external sites transmitting data to and from the database components (HMS, HML, HMSLoader, etc.);
· Ensure data receipt and integrity from data loads;
· Audit and monitor stored procedures to monitor activity according to protocol;
· Establish proxy server system where applicable;
· Implement encrypted email transmission service(s) utilizing approved DoD protocol (i.e. PKI/VPN/SQL);
· Add Positive Message alert function to components;
· Setup automated archival process and policy in SQL;
· Convert data tier. (i.e. XML, HL7);
· Integrate CHCS processes to ensure compatibility and interoperability with HMS components;
· Perform database back-ups, performance tuning and general maintenance;
· Establish automated result reporting via secure compact disk and Web applications.
· Manage the SQL server 2005/2008 databases.
· Analyze and coordinate data collection for performance
· Responsible for data quality, identifies, manages and executes efforts to maintain data integrity. Ensures coordination between various data entities to produce a quality data source
· Contractor shall correct application deficiencies and bugs as they are identified or occur.
· Perform adhoc database queries to assist staff with unknown or new requirements
· Create new or modify existing Crystal Reports
· Establish, Modify and Implement or troubleshoot HL7 data format messages transmission problems or errors.
· Implement, troubleshoot or modify HL7 message format listener service for transmissions to new and existing sites.
6.2.1 The contractor shall manage manual backend processes. At a minimum the contractor shall:
· Check daily submission of deficient barcode
· Check system for new raw HL7 messages received
· Check and release HL7 messages not automatically processed through HML subsystem
· Identify details on data file.
6.2.2 The contractor shall integrate the system with external systems that are secured on multiple levels:
· Communication level, by using Application Programmable Interfaces (APIs) over a secure medium (e.g. HTTPS)
· Source identity level, by allowing API requests only from configured IPs
· Message level authentication by including security credentials inside the message
6.3 HMS WEB INTERFACE MAINTENANCE.
6.3.1 Update Help features (at least quarterly) within individual HMS modules to include but not limited to: 1) Frequently Asked Questions (FAQS); 2) Context sensitive Tool Tips when mousing over fields and buttons; quick guides, operating procedures; and 3) Definitions directory;
6.3.1.1 Maintain Help module and expand feature to include system updates and system general usage tips.
6.3.1.2 Enhance help desk submission features for users.
6.3.1.3 Maintain and implement system change requests approved by NBIMC.
6.3.1.4 Maintain and modify HMS web component to include trouble ticket template access.
6.3.1.5 Perform general maintenance and troubleshooting of HMS web architectural modules.
6.3.1.6 Maintain, Update and modify the NBIMC HMS private website. Provide feasible technology options that will improve day-to-day operations.
6.4 HMSLOADER MAINTENANCE.
6.4.1 Includes maintaining operational functionality and troubleshooting issues on legacy HMSLoader system while simultaneously re-engineering to meet common operating environment requirements.
6.4.2 Review and update existing requirements, changes or corrections weekly; as evaluated against actual operational performance logs, reports and system enhancements.
6.4.3 Implement features to return HIV results to submitting activities and insert system change request findings according to configuration control board direction; and update existing logical mock-up to reflect updated requirements. The contractor shall prepare a scheduled event plan for task completion within agreed upon timelines.
6.4.4 Ensure HMS interoperability with SAMS, TIMPO, CHCS, MRRS and other authorized systems. Each system operates a bi-directional interface with HMS components. Specific criteria are found in the Interface Control Documents, to be provided at time of award, and other DoD/DON policy (see Section C-5).
6.4.5 Perform general maintenance and troubleshooting.
6.5 HIV MANAGEMENT LOADER (HML) MAINTENANCE.
6.5.1 Includes maintaining and improving operational functionality and troubleshooting issues for software components, directories while simultaneously re-engineering to correct defects and meet operating environment requirements.
6.5.2 Review and update monthly existing requirements as evaluated against actual operational performance logs, reports and system enhancements.
6.5.3 Implement features to process orders and results; return result reports to submitting activities, HMS and other agency systems; implement system change requests according to design specifications; and update existing logical mock-up to reflect updated requirements. The Contractor shall complete within 180 days of contract start.
6.5.4 Ensure interoperability occurs with SAMS, TIMPO, CHCS, Reserves and other systems.
6.5.5 Perform general maintenance and troubleshooting.
6.6 HMS REGISTRATION SITE MAINTENANCE.
6.6.1 Includes maintaining and improving operational functionality of the site and all modules to include and troubleshooting issues for software…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.