Cancer_Genomics_Cloud_Pilots_BAA _13_Jan_2014.docx

DOCX document 239 KB Posted

Attached to
Cancer Genomics Cloud Pilots Federal contract opportunity
Solicitation number
N01CO42400-80
Issued by
Department of Health and Human Services National Institutes of Health

About this file

Cancer Genomics Cloud Pilots BAA 13 Jan 2014

View the file

Other files for this federal contract opportunity

Other files attached to Cancer Genomics Cloud Pilots, newest first.
File Type Posted
AMENDED_Cancer_Genomics_Cloud_Pilots_BAA_19_Feb_2014.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Broad Agency Announcement (BAA) for Cancer Genomics Cloud Pilots

BAA#: N01CO42400-80

13 Jan 2014

Contents

PART I: OVERVIEW3
PART II: FULL TEXT OF ANNOUNCEMENT5
I.FUNDING OPPORTUNITY DESCRIPTION5
A.Introduction/Background5
B.Project Description/Scope6
C.Project Structure6
D.Research and Technical Objectives7
E.Schedule/Milestones10
F.Reporting Requirements and Deliverables11
G.Government-Furnished Property (Equipment/Information/Data)17
H.Intellectual Property/Data Rights18
I.Security Requirements18
J.Institutional Responsibility Regarding Investigator Conflicts of Interest23
II.AWARD INFORMATION23
A.Awards23
III.ELIGIBILITY INFORMATION24
A.Eligible Applicants24
B.Procurement Integrity, Standards of Conduct, Ethical Considerations and Organizational Conflicts of Interest (OCIs)25
C.Other Eligibility Requirements25
IV.APPLICATION AND SUBMISSION INFORMATION26
A.General Proposal Information26
B.Volume 1: Technical Volume27
C.Volume 2 - Business Volume37
V.APPLICATION REVIEW INFORMATION42
A.Evaluation Criteria42
A.Evaluation of Options46
B.Review and Selection Process46
VI.AWARD ADMINISTRATION INFORMATION47
A.Notices to Offerors47
B.Administrative and National Policy Requirements47
C.Reporting48
VII.OTHER INFORMATION48
A.Frequently Asked Questions (FAQs)48
B.Pre-Proposal Conference48
C.Submission Checklist49

PART I: OVERVIEW

· Federal Agency Name: National Cancer Institute, National Institutes Of Health, Department of Health & Human Services

· Funding Opportunity Title: Cancer Genomics Cloud Pilots

· Announcement Type: Initial Broad Agency Announcement (BAA)

· Funding Opportunity Number: N01CO42400-80

· Dates

· Posting Date: January 13, 2014

· Frequently Asked Questions (FAQ’s) resulting from the Pre-Proposal Conference held on January 6, 2014, as well as from this BAA will be posted on a weekly basis at the following website: http://cbiit.nci.nih.gov/ncip/nci-cancer-genomics-cloud-pilots.

· Proposal Due Date: February 27, 2014, 4:00 PM local time

· Anticipated Individual Awards: NCI estimates that up to three (3) cost type contracts may be issued. Awards are anticipated to be made on or about September 12, 2014. The total period of performance proposed shall be comprised of a base period and options and shall not exceed twenty-four (24) months.

· Small Business Set-Aside: No

· Total Funding Available for Award: The aggregate total cost (direct and indirect costs combined) for all combined awards is anticipated to be $20,000,000. The total costs for each award may vary depending upon the scope and capacity of the technical objectives of each award. All funding is subject to change due to government discretion and availability.

· Types of Instruments that May be Awarded: The Government is considering multiple cost-reimbursement and/or cost-plus-fixed-fee contract awards. As such, any Offeror selected for negotiations must demonstrate, prior to award, that its accounting system is adequate for administering a cost-type contract. The amount of funding made available under this BAA will depend on the quality of the proposals received and the availability of funds. The Government reserves the right to select for negotiation all, some, one, or none of the proposals received in response to this BAA, as well as to make awards without discussions with Offerors. The Government also reserves the right to conduct discussions if it is later determined to be necessary. Additionally, the Government reserves the right to accept proposals in their entirety or to select only portions of proposals for award. In the event the NCI desires to award only portions of a proposal, negotiations may be opened with that Offeror. Grant awards will NOT be made under this BAA.

· BAA Email: ncicloud@mail.nih.gov All email communications regarding this BAA should be addressed to ncicloud@mail.nih.gov to ensure timely exchange of information.

· Contracting Officer: Lynne Darby, lynne.darby2@nih.gov, 301-846-1114

· Administrative Point of Contact: Scott Keasey, scott.keasey@nih.gov, 301-846-1115

· Technical POC: Anthony Kerlavage, anthony.kerlavage@nih.gov, 240.276.5190

· Proposal Submissions Mailing Address:

All proposals must be submitted in hard copy.

If mailed through the U.S. Postal Service, proposals must be addressed as follows:

Victoria Cunningham National Cancer Institute (NCI) Office of Acquisitions 9609 Medical Center Drive, Room 1E566, MSC 9705 Bethesda, Maryland 20892-9705240-276-5440

If hand-delivered or delivered by an overnight service, proposals must be addressed as follows:

Victoria Cunningham National Cancer Institute (NCI) Office of Acquisitions 9609 Medical Center Drive, Room 1E566, MSC 9705 Rockville, Maryland 20850-9705 240-276-5440

· BAA Solicitation Website: http://fbo.gov, http://grants.nih.gov/grants/guide NCI BAAs are posted on the Federal Business Opportunities (FBO) website (http://www.fbo.gov/) and the NIH Guide for Grants and Contracts website (http://grants.nih.gov/grants/guide). Amendments to this BAA, if any, will be posted to the websites listed above when they occur. Interested parties are encouraged to periodically check these websites for updates and amendments. Potential Offerors are cautioned that the ONLY controlling document for this acquisition is the formal BAA and any subsequent amendments posted via FBO.gov.

· Letter of Intent: For planning purposes, the Government requests all potential Offerors intending to propose to this BAA submit an email with the subject line: “Letter of Intent”, to ncicloud@mail.nih.gov no later than January 27, 2014. In your message please indicate the following information:

· Organization name

· Organization address

· Organization telephone number

· Name and contact information of the Principal Investigator and Business Point of Contact.

PART II: FULL TEXT OF ANNOUNCEMENT

FUNDING OPPORTUNITY DESCRIPTION

The following information is for those wishing to submit a proposal to this BAA. All responsible Offerors are invited to submit a proposal in accordance with the requirements of this BAA. This BAA is being issued, and any resultant selection will be made, using procedures under Federal Acquisition Regulation (FAR) 35.016. Any negotiations and/or awards will use procedures under FAR 15.4. Proposals received as a result of this BAA shall be evaluated in accordance with evaluation criteria specified herein through a peer review process.

A. Introduction/Background

The National Cancer Informatics Program (NCIP) supports NCI research initiatives through sustaining a multidisciplinary community of biomedical researchers, informaticists, and developers dedicated to improving informatics practices in the study of cancer and the translation of that knowledge into improved clinical interventions. The NCIP seeks to ensure that the cancer research community including NCI-designated cancer centers, the upcoming National Cancer Trials Network (NCTN), Specialized Programs of Research Excellence (SPORES), and individual scientists working in both intramural and extramural laboratories, have the necessary informatics capabilities to carry out their missions. To accomplish its goals, the NCIP engages in fostering community-driven open development of informatics capabilities designed to support specific research needs and providing access to well-described data collections to facilitate integrative cancer research. A critical element of the program is to maintain and extend informatics infrastructure and standards to improve interoperability among disparate information systems. The program also encourages collaborative relationships among researchers and provides training for the next generation of biomedical investigators to use informatics capabilities to accelerate biological discovery and clinical application.

The growth of large-scale DNA sequence data for cancer research and its routine use in translational science is rapidly out-stripping the required computational capacity for storage, processing, network transmission, and analysis. Groups ranging in size from single laboratories and investigators to large multi-institutional consortia are generating large-scale data at an exponential pace. The ability to access and analyze genomic data and associated clinical annotations collected from various studies is critical to accelerating research and making new discoveries.

Presently, investigators mine genomics data by locating and downloading data stored at a variety of locations, including project-specific repositories (e.g., The Cancer Genome Atlas (TCGA) and Therapeutically Applicable Research to Generate Effective Treatments (TARGET) Data Coordinating Centers, the Cancer Genomics Hub (CG-Hub), the National Center for Biomedical Informatics Sequence Read Archive (NCBI SRA), and/or International Cancer Genome Consortium (ICGC) repositories), often adding their own local data. They then compute over these data on local hardware using computational tools, many of which are locally developed and rapidly changing. This model has been successful for many years, but is becoming untenable given the enormous growth of biomedical data since the advent of large-scale scientific programs such as the Cancer Genome Atlas (TCGA) and Therapeutically Applicable Research to Generate Effective Treatments (TARGET) that use next generation sequencing technology. At its projected completion in 2014, it is expected that TCGA will generate approximately 2.5 Petabytes (PB) of data. The difficulties that are caused by such scale are three-fold:

1.Maintaining local copies of data at this scale is not cost effective and will continue to increase in cost as the data is growing faster than Kryder’s Law
2.Providing computational capacity to analyze the data is similarly constrained
3.Electronic transfer of data at this scale is not practical.

With regard to the final point, the 2.5 PB expected TCGA core data set would require weeks to months to download even if the organization that is transferring the data has access to point-to-point 10 Gigabit networks. Evidence from other NCI programs, as well as the results of a request for community input sent to all NCI grantees and intramural researchers indicates that with less than 0.5 PB of TCGA data available, much of the NCI-supported research community is already computationally limited by financial constraints and IT (network, storage, and computing) issues that exceed the capacity of individual investigators and most institutions.

Wider access to data and computational infrastructure utilizing new technological capabilities could potentially address these needs as well as offer an additional avenue for dynamic community engagement in biomedical research. Hence there is a critical need to support the exploration of alternate models to better facilitate broad-scale sharing and analysis of genomics datasets.

B. Project Description/Scope

The purpose of this BAA is to support the development of a new model for computational analysis of biological data that has the potential to address the challenges described above. This model (which has been articulated recently in a series of NCI Precision Medicine Workshops and publications by experts in the field of biomedical informatics) involves the creation of a set of data repositories with co-located computational capacity and an Application Programming Interface (API) that provides security and data access for developers of analytic tools. In this model, applications are brought to the data, rather than bringing the data to the applications. Such a “Cancer Genomics Cloud” has the potential to democratize access to NCI-generated genomic data and provide a more cost-effective way to provide computational support to the cancer research community.

Towards this end, the NCI seeks to sponsor the development of multiple Cancer Genomics Cloud Pilots that will be available for use and testing by the scientific community as part of a competitive evaluation that will include technical benchmarking and cost analysis. If successful, the NCI will consult with the cancer research community and relevant oversight committee(s) to define, and potentially construct, a production version of one or more of the pilot clouds, or a successor design informed by the results of the pilot evaluations. In spirit, and by design, this new initiative will be the first step toward the establishment of a full Cancer Knowledge Commons, along the lines called for in the National Academy report on Precision Medicine, and will be coordinated with The National Institutes of Health’s Big Data to Knowledge (BD2K) initiative and other relevant activities in large-scale data analysis.

C. Project Structure

The Government anticipates award of up to three contracts in association with this BAA. Contracts for this acquisition will initially be awarded for a base period of six (6) months. The expectation for the base period will be to deliver an initial design and development. All deliverables required in this period are defined under post-award requirements contained herein. The deliverables due during the base period will be evaluated and based on this evaluation options may be exercised for a nine (9) month Option Period 1. Deliverables required during Option Period 1 are defined under post-award requirements, contained herein. In Option Period 1, awardees must complete their hosted instance of a Cancer Genomics Cloud Pilot that meets the Technical Objectives and the requirements in their proposed Statement of Work. Upon successful completion of Option Period 1, Option Period 2 may be exercised. During this final nine (9) month period, awardees must complete the IT-SA&A process, after which NCI will evaluate the pilots and conduct a public evaluation of the implementations.

Contract Period
Duration
Scope of Work
Base Period
6 months
Initial Design and Development
Option Period 1
9 months
Completion of Design, Development and Implementation
Option Period 2
9 months
Operation and Evaluation

D. Research and Technical Objectives

The primary Research and Technical Objective (RTO) of the Cancer Genomics Cloud Pilot is to drive solutions to support the design, implementation, and documentation of a new model for computational analysis and sharing of very large biological data sets as well as learn about unforeseen obstacles. The ultimate goal is democratizing access to NCI-generated genomic data sets as well as providing sustainable computational support to the cancer research community.

Pilot solutions are to overcome current data access limitations by bringing applications to the data rather than bringing the data to the applications. The models’ proposed could use commoditized cloud providers, private cloud providers, specialized hardware, and/or specialized configurations of commoditized hardware. The resulting pilots will enable authorized access to key NCI data sets as well as computing resources (i.e., storage, servers, high capacity networks). Key anticipated outcomes and benefits include the ability to:

· Enhance access to NCI-generated cancer data and tools;

· Take advantage of increases in compute efficiency and scalability;

· Accelerate bioinformatics tool development;

· Serve researchers with limited or no high-performance computing access;

· Better assess and optimize hardware needs and costs for future production system(s).

It is not in the scope of these Research and Technical Objectives to serve as a “data coordinating center” for NCI datasets. Activities such as file processing, quality control, data harmonization (such as sequence realignments), and general provision of download and transfer services for these datasets will be provided by other dedicated solicitations/awards..

The technical objectives for this BAA are described below:

1. Core Data and Use Cases

Successful Cancer Genomics Cloud Pilot solutions must host a common core data set from The Cancer Genome Atlas (TCGA) project. This core data set must include: 1) All TCGA DNA-Seq binary alignment (BAM) files; 2) All TCGA RNA-Seq FASTQ and BAM files; 3) All TCGA SNP array (.cel) files; 3) Somatic and germline mutation calls for each sample (.vcf and .maf files); and 4) All TCGA clinical data. In addition, to promote diversity across the Cloud Pilots must include at least one additional TCGA data set. A complete description of all TCGA data types and their access is available at https://tcga-data.nci.nih.gov/tcga/tcgaDataType.jsp.

The TCGA data is currently stored at two specialized data centers, the Cancer Genomics Hub (CGHub) for lower level sequence data and associated metadata and the Data Coordination Center (DCC) for all other datatypes. CGHub (https://cghub.ucsc.edu) is a secure repository at the University of California Santa Cruz for storing, cataloging and accessing lower levels of sequence data such as sequences and alignments (i.e., BAM and FASTQ files), where they can be accessed by the research community. All of the TCGA sequence data on CGHub are under Controlled Access, meaning that user certification is required. Metadata are the exception, which are Open Access. All other genomic data (e.g., SNP6, array gene expression, methylation, sequence variant data) and all clinical data generated by TCGA are housed at the TCGA DCC. Both the Open Access and Controlled Access data stored in the DCC are accessible to the community through the TCGA Data Portal (https://tcga-data.nci.nih.gov/). More information on the Open and Controlled Access data from TCGA is available at: https://tcga-data.nci.nih.gov/tcga/tcgaAccessTiers.jsp. Successful solutions are expected to operate in a collaborative environment with the current TCGA data centers and any future TCGA data center for obtaining the required data.

The stated formats for the core data sets are minimum requirements. Solutions with innovative storage formats to support specialized compute-optimized needs are encouraged.

The core mutation call data will be provided by the TCGA data centers. Solutions with additional mutation call methods that run these methods on the core TCGA sequencing data, provide resulting data through their cloud instance, and provide the methods to the TCGA data centers for re-use are encouraged, but not required.

To facilitate community input about the data types and analyses that should be prioritized for the Cancer Genomic Cloud Pilots, NCI has conducted a Request for Information (RFI), implemented as a portal for community comment at http://ncicloud.ideascale.com. Through this portal, individuals have commented and voted on use cases and data types they deem critical for the pilots. Use of this information is encouraged, but not required in the development of proposed solutions.

2. Architecture

A key technical objective is the exploration of alternative models to better facilitate broad-scale sharing and analysis of genomic data sets. As such, the NCI does not anticipate placing substantive proscriptions on the architecture that is utilized to develop the Cloud Pilots. The only requirement is that NCI must be able to replicate the design using technology and services that are available on the standard commercial market (i.e. there are standard terms under which the service is offered to the Government or the public).

3. Computational Services

Cancer Genomics Cloud Pilots must provide end users with access to significant compute capacity to support the large-scale analytical capabilities anticipated for the core data set. Importantly, solutions should consider support for diverse types of large-scale computing. Examples of computing modalities may include, but are not limited to big-graph analysis and large-scale statistical analysis.

A key technical objective of the Cancer Genomics Cloud Pilots is a highly usable application programming interface (API) that is accessible by the technical members of the research community. The interface must support services for data access as well as direct analysis and computation against the data store. A set of core services – such as security, logging, and entitlements - must be jointly established by the Cloud Pilot awardees and implemented in each Cloud Pilot. The ability to initiate and terminate compute services capable of accessing a data store through programmatic interfaces is an important feature.

In addition to supporting analysis over core data sets described herein, Cloud Pilots must also provide users the ability to access cloud resources for the analysis of their own private data in conjunction with hosted data through the API(s).

4. Analysis Capabilities

Cancer Genomics Cloud Pilot solutions must provide a set of query and analysis tools and/or workflows that will be utilized for their pilot implementation. In addition, awardees will be expected to work collaboratively to identify a common subset that will be implemented across all of the pilot implementations. Each pilot team must also implement analysis capabilities specific to the additional data type(s) and/or their expertise hosted in their cloud instance. The analysis capabilities implemented must use the same API provided for community use. In addition to the query and analysis capabilities implemented, each Cloud Pilot must support users’ ability to securely run their own tools on the hosted cloud data using the API(s). Clouds must therefore support tools developed in diverse coding languages. It is encouraged, but not required to review community input at http://ncicloud.ideascale.com for priority use cases to support.

5. Access and Security

The Cloud Pilots will be considered federal electronic information systems and as such, must meet the relevant federal regulations. This includes adopting and implementing the policies, procedures, controls, and standards of the HHS Information Security Program to ensure the integrity, confidentiality, and availability of Federal Information and the Federal Information system. The HHS Information Security Program is outlined in the HHS Information Security Program Policy, which is available on the HHS Office of the Chief Information Officer’s (OCIO) Website, http://www.hhs.gov/ocio/index.html. This policy is in accordance with the Federal Information Security Management Act (FISMA).

The core data set defined for the pilots are categorized as Federal Information Management Security (FISMA) Low. However, additional data types incorporated by individual pilots may elevate security requirements to FISMA moderate. Solutions must plan the system controls accordingly taking into consideration a Moderate categorization. The security requirements for these pilot implementations include, but are not limited to, preparation of an IT Security Plan, IT Risk Assessment, FIPS 199 Assessment, and performance of security control testing and evaluation. The awardees will be responsible for attaining the Authority To Operate (ATO) from the relevant security officer.

Protection of data in the Cancer Genomics Cloud Pilots must be consistent with that established for these data in the NCI CGHub, the TCGA DCC and any future data coordinating center. Proposed solutions must address the requirement for pilot teams to attain the status of a Trusted Partner and maintain all restricted data within a controlled environment. The current NIH policy requires authentication of user access with the NIH authentication services for approved users, complying with systems security requirements, and implementing contingency procedures for incidents related to data management.

Additionally, proposed solutions must demonstrate an understanding of FedRAMP requirements (http://www.fedramp.gov) and describe an approach for achieving compliance in the event of a production implementation.

6. Scalability and Extensibility

Solutions must demonstrate knowledge and understanding of the current and future data size, complexity and computational capacity needs and plan the pilots accordingly. For the purpose of these Research and Technical Objectives, assume a starting core dataset size of 2.5 PB and compute services in the range of 1000-5000 nodes. Solutions should consider increases in the range of 10- to 100-fold. As part of any design, solutions should provide an assessment of operational costs for the proposed pilot including a projection of costs for the proposed scale-up that meets the anticipated future needs.

The proposed design should describe how the system could be extended - without major refactoring - to support other data types beyond the core plus additional data sets scoped for the pilot implementations.

7. Data Standards

To support a long term goal of interoperability among the clouds and computations that span one or more clouds, it is important that data in the Cancer Genomic Cloud Pilots be represented using standard formats, data elements, and vocabularies. Proposals must describe how teams will work collaboratively with one another, with the TCGA data coordinating centers, and with the NCI staff to define the appropriate standards for raw and processed data that will be commonly applied across these resources. For each pilot, the information model must be described, discoverable and reusable to ensure that the community has shared understanding of the meaning of data to develop and share analytical tools.

8. Other Considerations

Cancer Genomics Cloud Pilot solutions must demonstrate how they will work collaboratively with one another, and with the NCI staff in designing, building and evaluating the Cloud Pilots. Although not required, additional features above and beyond the needs described within this Research and Technical Objectives are encouraged. These considerations should be based on demonstrable community need, either from the RFI or other reliable sources, and be able to be implemented with best value to the government.

E. Schedule/Milestones

The awardee must provide for and maintain effective communications with any subcontractors, the Contracting Officer’s Representative (COR) and the Contracting Officer (CO) as necessary to implement their proposed SOW, including periodic teleconferences, as indicated below, with the COR and CO to discuss technical aspects of ongoing activities, anticipated problems, obstacles, proposed approaches to solve problems, and overcome challenges. The contractor must plan for the following meetings:

· Post award Contract Initiation Meeting (virtual);

· Monthly meeting (virtual);

· Regular on-site meetings at contractor facilities with the COR and such other experts as needed by the COR to assess progress;

· Quarterly on-site meetings at the NCI facilities;

· Ad hoc meetings as required.

For proposal preparation purposes Offerors should assume 10 instances of travel to various meetings at NCI Shady Grove, Rockville, MD, 20850.

F. Reporting Requirements and Deliverables

1. Submission of Reports

Format of Cover page: All reports shall be submitted in Contractor format, but include a cover page containing the following information:

· Contract Number and Project Title

· Title of Report

· Period of Performance Being Reported

· Contractor’s Name and Address

· Author(s)

· Date of Submission

· Delivery Address

Type and Number of Copies:

· Electronic Copy to COR and Contracting Officer

· 1 Original Hard Copy to Contracting Officer

2. Technical Progress Reports

a. Monthly Progress Report

This report shall include a description of the activities during the reporting period and the activities planned for the ensuing reporting period. The first reporting period consists of the first full month of performance plus any fractional part of the initial month. Thereafter, the reporting period shall consist of each calendar month. Reports are due on or before the 10th calendar day of the month.

In addition, the contractor shall provide monthly Earned Value Reporting. The Earned Value Reporting requirements for the purposes of this acquisition shall be similar to, but will NOT require compliance with, ANSI/EIA Standard 748, OMB Circular A-11, FAR 34.2, and HHSAR 334.2. The Contractor shall provide, as part of the Monthly Progress Report, monthly Earned Value Reports after the issuance of the contract award. Earned Value Reporting requirements shall be applied to subcontractors using the same rules as applied to the prime contractor.

The Monthly Earned Value Reports shall include analysis and reporting comprising the following elements:

1. Budget at Completion (BAC)

2. Budgeted Cost for Work Performed (BCWP – also known as Earned Value (EV))

3. Actual Cost for Work Performed (ACWP)

4. Budgeted Cost for Work Scheduled (BCWS – also known as Planned Value (PV))

5. Estimate at Completion (EAC)

6. Schedule Variance (SV)

7. Cost Variance (CV)

8. Schedule Efficiency (SPI)

9. Cost Efficiency (CPI)

Current period values and cumulative values for data, variances, efficiencies, indices, and forecasts shall be provided in numerical format showing values AND in graphical format showing trends. Causal analysis shall be conducted on any variances. Each month a summary of variance causes for that reporting period and variance causes to date shall be provided. The summary shall include a breakdown of causes that identifies:

· Size of the variance by cause (some variances may have multiple causes)

· Corrective actions either taken or recommended in reaction to the variance

· Success or expected success of any corrective actions

· Recommended changes to the project that might prevent the causes, mitigate the impacts, and/or provide remediation in terms of each variance.

b. Period of Performance Completion Report

This report is to include a summation of the work performed and the results obtained for the each contract period of performance. This report shall be in sufficient detail to describe comprehensively the results achieved.

c. Final Project Completion Report

This report is to include a summation of the work performed and the results obtained for the entire contract period of performance. This report shall be in sufficient detail to describe comprehensively the results achieved. The Contractor shall submit, with the Final Report, a summary (not to exceed 250 words) of salient results achieved during the performance of the contract.

d. Source Code and Binaries

Unless otherwise specified, the Contractor shall deliver to the Government, per the delivery schedule, all source code and binaries developed, modified, and/or enhanced under any resultant contract.

e. HHS Enterprise Performance Life Cycle (EPLC) Requirements The Offeror will provide the following deliverables in compliance with the EPLC requirements. The Offeror will be provided reporting templates at the time of finalization of the Statement of Work. These deliverables will be submitted as per the negotiated delivery schedule.

i. Requirements Document

ii. Use Case Definition Document

iii. Design Plan

iv. Project Implementation Plan –The plan must include a Risk Management Plan and a Communications Plan.

v. Project Schedule

vi. Test Plan

vii. Test Report

f. User and Implementation Documentation In addition to the hosted instance, the selected teams must deliver sufficient documentation of the prototype to support end-users and administrators of the system and to allow independent implementation of the final prototype.

3. Additional Technical Deliverables and Reporting Requirements

a. Operations Metrics Plan

A Contactor-created plan that includes the description of metrics that will be collected during the Operations and Evaluations Period for assessing usage, performance, uptime, and other relevant metrics. The Government will evaluate and approve this plan to be utilized for the Metrics Reports.

b. Metrics Report

The Offeror must provide periodic reports of the metrics collected in accordance with the delivery schedule.

c. Hosted Cancer Cloud Prototype

Selected Offerors will instantiate the hosted instance of a Cancer Genomics Cloud prototype as a deliverable such that it meets the requirements detailed in the Research and Technical Objectives section of this BAA and the proposed Statement of Work. Delivery must include a report summarizing the content and technical features of the system (as defined in the proposed Statement of Work) and administrator-level access for the Contracting Officer’s Representative.

d. Operational Costs Report

The selected Offerors must provide an assessment of operational costs including a projection of cost for scaled-up infrastructure as outlined in the technical objectives in this BAA as well as the proposed Statement of Work. The report must take into consideration and describe scalability and extensibility plans for which the costs have been estimated.

e. Evaluation Plan

This deliverable must outline plans that include community engagement as described in the Offeror’s proposed Technical Volume.

f. Trusted Partner Status Certificate

The certificate for attaining a NIH Trusted Partner Status in order to be able to redistribute any controlled data sets.

g. Transition Plan

Offerors must plan and implement an orderly and efficient transition to a subsequent contractor or to the Government, by the expiration date of the contract, including a comprehensive inventory of all the data and resources and the transfer all other relevant equipment, databases, software applications, SOP’s, algorithms, technologies and other resources generated and/or purchased under this contract.

4. Other Reports and Deliverables

Other Reports and Deliverables may be required as outlined below. This may include special reports required by regulation or policy and interim deliverables, and/or documentation, etc. These will be finalized in the Statement of Work during negotiations.

a. Information Security and Physical Access Reporting Requirements

i. Roster of Employees Requiring Suitability Investigations This report requires submission of a roster, by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under the contract who will develop, have the ability to access, or host and/or maintain a Federal information system(s). The roster shall be submitted to the Contracting Officer's Representative (COR), with a copy to the Contracting Officer, within 14 calendar days of the effective date of any contract. Reporting New and Departing Employees will be provided thereafter along with each Monthly Status Report.

ii. Employees Non-disclosure Agreements Each employee, including subcontractors, having access to non-public Department information under this acquisition shall complete the Commitment to Protect Non-Public Information – Contractor Employee Agreement. A copy of each signed and witnessed Non-Disclosure agreement shall be submitted to the COR and CO prior to performing any work under this acquisition.

iii. Online Security Awareness Training Any contractor employees having access to: (1) Federal information or a Federal information system or (2) personally identifiable information (PII), shall complete the NIH Information Security Awareness Training course at http://irtsectraining.nih.gov/publicUser.aspx before performing any work under contract. Thereafter, contractor employees having access to the information identified above shall complete an annual NIH-specified refresher course during the life of any contract. Awardees shall also ensure subcontractor compliance with this training requirement.

b. IT Security Assessment and Accreditation (IT-SA&A) In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, awardees will be required to submit written proof to the Contracting Officer that an IT-SA&A was performed as per the delivery schedule. Awardees will be required to perform an annual security control assessment and provide to the Contracting Officer verification that the IT-SA&A remains valid. The following deliverables follow from the SA&A process.

i. IT Security Plan (IT-SP) In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, awardees will be required to submit the IT-SP as per the delivery schedule. The IT-SP shall be consistent with, and further detail the approach to, IT security contained in the Offeror’s proposal. The IT-SP shall describe the processes and procedures that the awardee will follow to ensure appropriate security of IT resources that are developed, processed, or used under this contract. If the IT-SP only applies to a portion of the contract, the Contractor shall specify those parts of the contract to which the IT-SP applies.

The Contractor shall review and update the IT-SP in accordance with NIST SP 800-26, Security Self-Assessment Guide for Information Technology Systems and FIPS 200, on an annual basis.

ii. IT Risk Assessment (IT-RA) In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, awardees will be required to submit the IT-RA as per the delivery schedule. The IT-RA shall be consistent, in form and content, with NIST SP 800-30, Risk Management Guide for Information Technology Systems, and any additions or augmentations described in the HHS-OCIO Information Systems Security and Privacy Policy. Awardees will be required to update the IT-RA on an annual basis.

iii. FIPS 199 Assessment In accordance with HHSAR Clause 352.239-72, Security Requirements For Federal Information Technology Resources, awardees will be required to submit a FIPS 199 Assessment as per the delivery schedule. The FIPS 199 Assessment shall be consistent with the cited NIST standard.

iv. Privacy Impact Assessment (PIA) Titles II and III of the E-Government Act of 2002 require that agencies evaluate systems that collect personally identifiable information (PII) to determine that the privacy of this information is adequately protected. The mechanism by which agencies perform this assessment is a privacy impact assessment (PIA).

v. E-Authentication Threshold Analysis/Risk Assessment

vi. IT Contingency Plan

vii. IT Contingency Plan Test and Results Analysis

viii. IT Security Control Assessment Testing and Evaluation Report (SAR)

ix. Plan of Actions and Milestones (POA&M)

x. Authority to Operate Letter (NCI-ATO)

c. Section 508 Report Awardees will be required to submit an annual Section 508 report. The Section 508 Report Template and Instructions for completing the report are available at: http://www.hhs.gov/od under "Vendor Information and Documents."

5. Delivery Schedule

Delivery of other reports and deliverables will be proposed by the Offerors in their technical proposal. These will be finalized with awardees during negotiations.

Deliverable Name
BAA Section
Submission Requirement
Monthly Progress Report
F.2.a.
Deliver 10 calendar days after completion of the month.
Period of Performance Completion Report
F.2.b.
Deliver on the last day of the contract period. The report for the Option Period 2 can be combined with the Project Completion Report.
Final Project Completion Report
F.2.c.
Deliver by the final day of completion of contact
Source Code and Binaries
F.2.d.
Code developed as part of this contract must be managed in a publicly-available source code repository
Requirements Document
F.2.e.i.
Deliver initial document within 30 calendar days of contract award; updated monthly through the end of Option Period 1.
Use Case Definition Document
F.2.e.ii.
Deliver initial document within 30 calendar days of contract award; updated monthly through the end of Option Period 1.
Design Plan
F.2.e.iii.
Deliver initial document within 90 calendar days of contract award; updated monthly through the end of Option Period 1.
Project Implementation Plan
F.2.e.iv.
Deliver initial document within 30 calendar days of exercise of Option Period 1; updates with the Monthly Progress Report
Project Schedule
F.2.e.v.
Deliver initial schedule within 30 calendar days of initial contract award and updates with Monthly Progress Report
Test Plan
F.2.e.vi.
Deliver initial document within 30 calendar days of contract award; updated monthly through the end of Option Period 1.
Test Report
F.2.e.vii.
Deliver with Monthly Progress Report in both Option Periods
User and Implementation Documentation
F.2.f.
Deliver initial document 45 calendar days prior to the end of Option Period 1; updated monthly through the end of Option Period 2.
Operations Metrics Plan
F.3.a.
Deliver initial document with the first Monthly Report in Option Period 1, updated monthly through the end of Option Period 1.
Metrics Report
F.3.b.
Deliver weekly in Option Period 2
Hosted Cancer Cloud Prototype
F.3.c.
Deliver no less than 45 calendar days prior to the end of Option Period 1.
Operational Costs Report
F.3.d.
Deliver initial document no less than 60 calendar days prior to the end of Option Period 1; updated through the end of Option Period 2.
Evaluation Plan
F.3.e.
Deliver initial plan within the proposal and Final as attachment to the Implementation Plan
Trusted Partner Status Certificate
F.3.f.
Deliver within the Base Period.
Transition Plan
F.3.g.
Deliver initial document with the first monthly report of Option Period 2, updated as needed through the end of the contract.
Roster of Employees Requiring Suitability Investigations
F.4.a.i.
Deliver initial document within14 calendar days of the effective date of any contract and updates to new and departing employees with each Monthly Progress Report.
Employees Non-disclosure Agreements
F.4.a.ii.
Deliver with the first Monthly Progress Report; updates as needed with the Monthly Progress Report.
Online Security Awareness Training
F.4.a.iii.
Provide certification of training completion for all staff with the first Monthly Progress Report.
IT Security Plan (IT-SP)
F.4.b.i.
Deliver initial document with the SOW and revised within 30 calendar days of award; update as required during contract period.
IT Risk Assessment (IT-RA)
F.4.b.ii.
Deliver initial document within 90 calendar days of contract award; updated as needed throughout the contract
FIPS 199 Assessment
F.4.b.iii.
Deliver initial document with the SOW and final within 30 calendar days of award.
Privacy Impact Assessment
F.4.b.iv.
Deliver no later than 60 calendar days from award.
E-Authentication Threshold Analysis/Risk Assessment
F.4.b.v.
Deliver no later than 60 calendar days from award.
IT Contingency Plan
F.4.b.vi.
Deliver initial document with the first monthly report; update as needed though the end of Option 1.
IT Contingency Plan Test and Results Analysis
F.4.b.vii.
Deliver with final ATO.
IT Security Control Assessment Testing and Evaluation Report (SAR)
F.4.b.viii.
Deliver with final ATO.
Plan of Actions and Milestones POA&M
F.4.b.ix.
Deliver with final ATO.
Authority to Operate Letter (NCI-ATO)
F.4.b.x.
Deliver no later than 90 calendar days from the start of Option Period 2.
Section 508 Report
F.4.c.
Deliver initial report within 30 calendar days of initial launch of pilot and then provide updates as attachments to the Monthly Progress Reports.

G. Government-Furnished Property (Equipment/Information/Data)

It is expected that Government property will be required by awardees during contract performance. A list of this property will be included in any Contract as needed or required at time of award.

Pre-award data: To aid the Offerors in evaluating the data types required for this BAA, instructions for how to obtain exemplar data available through pubic websites are provided in the Technical Proposal Instructions. This section includes instructions for obtaining 1) Exemplar DNA-Seq, FASTQ, and binary alignment (BAM) files, (whole genome sequence and whole exome sequence); 2) Exemplar RNA-Seq BAM files; 3) Exemplar SNP array .cel files; 3) Exemplar somatic and germline mutation calls (.vcf and .maf files ); and 4) TCGA clinical data.

Post-award data: Awardees will be directed to obtain data from cgHUB (for sequence data) and the TCGA Data Coordinating Center (for all other TCGA data types). Awardees will be required to obtain authorization to access the protected TCGA data and– government staff will assist with achieving this in a timely manner. Given the extreme volume of data, awardees will be directed to begin transferring data immediately upon award. As new data is made available through these sources, awardees will be required to get data updates regularly throughout the project. Awardees will be required to achieve Trusted Partner status during the course of the project in order to make the data available to community during Option period 2.

H. Intellectual Property/Data Rights

The prime contractor must meet the intellectual property requirements of this BAA, as outlined in the Research and Technical Objectives. These are non-negotiable; therefore it is critical that the Offeror has the ability to meet these requirements prior to award (see Other Eligibility Requirements Section III.C.)

All data, documentation and software delivered under any resulting contract will be delivered with unlimited rights as set forth in FAR 52.227-14 for the Government. All software developed under this BAA must be released under an approved non-viral open source license in accordance with FAR 52.227-17. To clarify, the software must be released under an Open Source Initiative-approved, non-viral, open source license. See http://opensource.org/licenses

Inventions are the result of intellectual input which cannot be determined in advance. While Bayh-Doyle may not apply to inventions under these anticipated contracts, FAR 52.227-11 clearly documents the rights and obligations of the Contractor and Government with respect to inventions.

To the extent that an Offeror intends to use or include commercial products in its designs, the products must be available both to the Government and the public through standard commercial terms.

I. Security Requirements

This acquisition requires all awardees to:

· Develop, have the ability to access or host and/or maintain Federal information and/or Federal information system(s).

· Access, or use, Personally Identifiable Information (PII), including instances of remote access to or physical removal of such information beyond agency premises or control.

· Have regular or prolonged physical access to a “Federally-controlled facility,” as defined in FAR Subpart 2.1.

Awardees and any subcontractors performing under any contracts resultant from this BAA shall comply with the following requirements:

1. Information Type

Mission Based Information:
Health Care Research and Practitioner Education Information

2. Security Categories and Levels

ConfidentialityLevel:[ ] Low[X] Moderate[ ] High
IntegrityLevel:[ ] Low[X] Moderate[ ] High
AvailabilityLevel:[X] Low[ ] Moderate[ ] High
OverallLevel:[ ] Low[X] Moderate[ ] High

3. Position Sensitivity Designations

The following sensitivity level(s), clearance type(s), and investigation requirements apply to this contract:

Level 5: Public Trust - Moderate Risk. Contractor/subcontractor employees assigned to Level 5 positions with no previous investigation and approval shall undergo a Suitability Determination and a Minimum Background Investigation (MBI), or a Limited Background Investigation (LBI).

Awardees will be required to submit a roster by name, position, e-mail address, phone number and responsibility, of all staff (including subcontractor staff) working under this acquisition where the Contractor will develop, have the ability to access, or host and/or maintain a federal information system(s). The roster shall be submitted to the COR, with a copy to the Contracting Officer, within 14 calendar days of the effective date of this contract. Any revisions to the roster as a result of staffing changes shall be submitted within 15 calendar days of the change. The Contracting Officer will notify Awardees of the appropriate level of investigation required for each staff member. An electronic template, "Roster of Employees Requiring Suitability Investigations," is available for contractor use at:

https://ocio.nih.gov/aboutus/publicinfosecurity/acquisition/Documents/SuitabilityRoster_10-15-12.xlsx

Suitability Investigations are required for contractors who will need access to NIH information systems and/or to NIH physical space. However, contractors who do not need access to NIH physical space will not need an NIH ID Badge. Each contract employee needing a suitability investigation will be contacted via email by the NIH Office of Personnel Security and Access Control (DPSAC) within 30 days. The DPSAC email message will contain instructions regarding fingerprinting as well as links to the electronic forms contract employees must complete.

Additional information can be found at the following website:

http://idbadge.nih.gov/background/index.asp

Awardees and any subcontractor employees will be required to comply with the conditions established for their designated position sensitivity level prior to performing any work under any resultant contract.

4. Information Security Training

a. Mandatory Training All employees having access to (1) Federal information or a Federal information system or (2) personally identifiable information, shall complete the NIH Information Security Awareness Training course at http://irtsectraining.nih.gov/ before performing any work under this contract. Thereafter, employees having access to the information identified above shall complete an annual NIH-specified refresher course during the life of this contract. The Contractor shall also ensure subcontractor compliance with this training requirement.

b. Role-based Training HHS requires role-based training when responsibilities associated with a given role or position, could, upon execution, have the potential to adversely impact the security posture of one or more HHS systems. Read further guidance at: Secure One HHS Memorandum on Role-Based Training Requirement“ For additional information see the following: https://ocio.nih.gov/aboutus/publicinfosecurity/securitytraining/Pages/rolebasedtraining.aspx

The Contractor shall maintain a list of all information security training completed by each contractor/subcontractor employee working under this contract. The list shall be provided to the COR and/or Contracting Officer upon request.

c…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .