SOW CGSC4 DRAFT.pdf
PDF 161 KB Posted
- Attached to
- NOS/OCM Geospatial A-E Support Services Federal contract opportunity
- Solicitation number
- NCNP0000-20-00118
About this file
This document is a sources sought notice from the National Oceanic and Atmospheric Administration seeking statements of capabilities from firms for geospatial data collection services in support of coastal resource management projects. Services required include lidar and imagery data acquisition, thematic mapping, high-resolution topographic and bathymetric product generation, survey and control services, and geospatial services such as data management and software development. Responses are due by 11:00 a.m. ET on December 18, 2019. Evaluation criteria will include professional qualifications, specialized experience, capacity, past performance, and location knowledge. Firms must demonstrate end-to-end capabilities and provide evidence of data collection platforms, processing equipment, personnel, surveying experience, and geographic distribution throughout the United States and its territories. Statements of capabilities are limited to ten pages and must include the firm's DUNS, CAGE code, and small business status.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SOW CGSC4 DRAFT.pdf | ||
| Sources Sought.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
NOAA Office for Coastal Management Coastal Geospatial Services Contract – Statement of Work
Office for Coastal Management
National Ocean Service
National Oceanic and Atmospheric Administration
U.S. Department of Commerce
Coastal Geospatial Services Contract
Statement of Work
DRAFT
October 2019
TABLE OF CONTENTS
1.0. PURPOSE 3
2.0. GENERAL 3
3.0. SCOPE 4
4.0. GENERAL REQUIREMENTS 4
WORK/QC PLAN 4
KICKOFF MEETING 5
QUALITY CONTROL 5
RECORDS AND METADATA 5
IT SECURITY REQUIREMENTS 6
CONTRACTOR COORDINATION 10
KEY PERSONNEL (TASK ORDERS) 10
QUALITY ASSURANCE 10
LAWS, REGULATIONS, PROCEDURES AND PERMITS 11
TRAVEL 11
CONTRACTOR CONFIDENTIALITY 11
CONTRACTOR INNOVATION 11
DELIVERABLES 11
5.0. ACRONYMS 12
https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.1fob9te https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.2et92p0 https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.3dy6vkm https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.4d34og8 https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.17dp8vu https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.26in1rg https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.35nkun2 https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.44sinio https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.2jxsxqh https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.3j2qqm3 https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.4i7ojhp https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.1ci93xb https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.2bn6wsx https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.3as4poj https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.1pxezwc https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.147n2zr https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.23ckvvd https://docs.google.com/document/d/1iS1NAQ-lrCQLNrs95ZMwxQMY8T0kIMaYVURtjn0RzR8/edit#heading=h.4d34og8
1.0. Purpose
The National Oceanic and Atmospheric Administration (NOAA) Office for Coastal Management (OCM), hereinafter referred to as the "Government," requires professional geospatial services, in support of various local, state, and regional coastal resource management needs. OCM’s primary areas of technological expertise include geographic information systems (GIS), remote sensing, habitat mapping, data acquisition, hazards resilience, ecosystem services, and training. In its 25 years of existence the organization has worked with state and other coastal resource managers, academia, non-governmental organizations, and the private sector to address coastal and ocean issues.
Lessons learned and emerging technologies and information developed from these efforts are shared broadly across the coastal resource management community enabling them to address similar problems. In developing products and services for its constituents, OCM collaborates with its state and local partners and private industry to address issues such as hazard mitigation, sea level rise, coastal development, habitat restoration, environmental monitoring, and ocean planning.
OCM’s geographic scope is nationwide, including all coastal and Great Lakes states and island territorial jurisdictions. OCM manages NOAA’s Digital Coast which is an enabling platform of actionable information that provides data, tools, and training used by coastal communities to manage and address their coastal issues. OCM works very closely with each state’s coastal zone management program, local governments, non-government organizations, and other Federal agencies to provide end-to-end solutions to coastal and ocean management issues.
This broad-based contract will serve to allow OCM to meet their mission requirements to support coastal resource managers in their decision-making processes. This contract will be used by OCM, other NOAA line offices, as well as other Federal, State, and local agencies. All data, geospatial products, and training produced through this contract will be made available publicly through the Digital Coast.
2.0. General
Except for those items specifically identified in individual task orders as Government furnished, the contractor, operating as an independent contractor and not as an agent of the Government, shall furnish all facilities, labor, material, and equipment necessary to provide goods and services in accordance with the terms, conditions, and specifications set forth below. The contractor shall plan, schedule, and coordinate performance of all work associated with task orders in accordance with the requirements described in this SOW and those of the individual task orders. During the performance of the work, the contractor shall provide adequate professional supervision and quality control to assure the timeliness, accuracy, quality, completeness, and progress of the work.
Unless specifically stated otherwise, the term "contractor," as used in this SOW and in the contract, shall be interpreted as the prime contractor.
3.0. Scope
Geospatial services are vital in the sustainment and usefulness of the Digital Coast for the coastal community. The services are highly technical in nature and require specialized technical expertise that necessitates seamless, end-to-end capability. To meet such extensive and critical requirements, NOAA requires contractors to demonstrate full capability and capacity to simultaneously accomplish, and quickly react, to multiple tasks throughout the United States, it possessions, and territories. Data collection may be required outside of the U.S. on a case-by-case basis.
Firms must have end-to-end capability to provide all of the below listed services:
1. Lidar and imagery data acquisition using multiple platforms including, but not limited to, aerial, satellite, and unmanned vehicles
2. Thematic mapping (e.g., land use / cover, impervious surfaces, wetland and benthic habitats) including training data/ ancillary data collection and processing, supervised classification (including methods using machine learning and/or deep learning algorithms), quality assurance and editing, and accuracy assessment
3. High-resolution topographic / bathymetric product generation
4. Survey and control services, including, but not limited to, the use and installation of in-situ instrumentation, and airborne Global Positioning Systems (GPS) technology
5. Geospatial Services: geospatial data and map service development, data management, data conversion, data integration, data analysis, data modeling, data visualization, database development, cartographic production, and software application development in support of land use planning; coastal conservation;
coastal hazards; marine planning; water quality; and climate change
6. Geospatial Training
A list of required disciplines that the government considers the minimum requirements for the contract can be found in Attachment A. The contractor shall provide fully loaded rates for each of these disciplines in their cost proposal along with a brief description of their requirements for that position. The contractor may provide a description and cost proposal for other disciplines that they would like to make available for this contract. Other disciplines should be cross-walked to the Attachment A list, if applicable. The contractor shall provide only one rate for each discipline that is applicable to the prime and all of the subcontractors.
4.0. General
4.1. Work/QC Plan
The contractor shall develop a Work/QC plan for each task order, unless otherwise directed in that task order, to guide and monitor the product development and delivery. The Work/QC plan shall include the elements which are critical to the successful completion of that task order. The contractor shall use discretion in evaluating what level of detail will work best for preparing an effective Work/QC plan. At a minimum the plan shall include the following:
• Methods for meeting the specifications of that task order
• Methods for maintaining the quality of data and products delivered under the task order
• Description of methodologies to be used in product/data development
• Description of accuracy assessment methodologies, if applicable
• Methods for ensuring consistency between different analysts, if applicable
• Schedule for deliverables
• Detailed description of tasks
The plan will be reviewed by the government upon receipt from the contractor.
4.2. Kickoff Meeting
The contractor shall attend a kickoff meeting at OCM in Charleston, SC, generally within 30 days of task order award unless otherwise specified. This meeting will serve as an information exchange and planning meeting for future activities such as delivery of government furnished equipment (GFE) and field calibration/verification trips. The contractor shall prepare an agenda for this meeting with input from the government. The contractor shall take notes and prepare and distribute the minutes of the meeting to all attendees.
4.3. Quality Control
Quality control (QC) is essential throughout the entire task order process and is solely the responsibility of the contractor. The contractor's quality control system, shall, at a minimum, be composed of the basic quality system elements from the ANSI/ISO/ ASQC Q9002-1994, Quality Systems - Model for Quality Assurance in Production Installation and Servicing (or later). The Government reserves the right to inspect all contractor processes and documentation to assess the contractor's compliance with and commitment to the basic Quality System.
Acceptance of the final deliverables is contingent upon meeting the requirements stated in the task order. The contractor shall provide the government with documentation that their final product has met the specifications of the task order. The contractor shall document this process and the government shall approve that process prior to task order award. The contractor shall develop a QC plan to ensure that requirements of the contract are met as specified. The contractor shall provide a copy of the Plan to the COTR within fourteen (14) days of contract award date. The QC plan will be reviewed and must be approved by the government within 14 days of receipt from the contractor. The contractor shall update the QC plan and provide an updated copy to the COTR as applicable.
4.4. Metadata
Metadata records shall be formatted as machine-readable, syntactically-valid Extensible Markup Language (XML) files based on international standards. The default encoding for metadata shall be the International Organization for Standardization (ISO) Geographic Metadata Standard. The ISO version currently in effect at NOAA is ISO 19115-2 (2009)10 conceptual model with ISO 19139-2 (2012)11 XML schema.
Required content
The metadata records shall contain any and all elements, including those that are considered optional, applicable to the data or data product. The metadata record shall contain sufficient detail to ensure that the data or data product can be fully understood for future use and for posterity. At a minimum, metadata shall include appropriate information on data collection or lineage, data processing, data quality/assurance, data format, geospatial reference information (such as geodetic model, grid coordinate system), and definitions and descriptions of all observations and parameters delivered.
Documentation of data collection methods shall include instrument used and vehicle/platform (such as aircraft) used along with all pertinent information regarding the instrument and platform (such as last calibration).
Metadata for benthic habitat data shall also include all appropriate information per the Coastal and Marine Ecological Standard (CMECS). Information on CMECS can be found on the FGDC website (https://www.fgdc.gov/standards/projects/FGDC-standards-projects/cmecs-folder/cmecs-index- page)and at https://iocm.noaa.gov/cmecs/index.html.
Delivery
The metadata records shall be delivered free of errors in both content and format. The metadata records will be subject to review and approval prior to final acceptance by the Government.
https://www.fgdc.gov/standards/projects/FGDC-standards-projects/cmecs-folder/cmecs-index-page https://www.fgdc.gov/standards/projects/FGDC-standards-projects/cmecs-folder/cmecs-index-page http://coast.noaa.gov/digitalcoast/publications/cmecs http://coast.noaa.gov/digitalcoast/publications/cmecs http://coast.noaa.gov/digitalcoast/publications/cmecs
4.5. IT Security Requirements
The Contractor is required to meet the DOC IT Security Program Policy (ITSPP) and Commerce Information Technology Requirements (CITRs) (available at: https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce- information-technology-requirements).
The base IDIQ contract is not awarded any services, but serves as a vehicle to order services; therefore will not be using either government owned systems or contractor owned systems.
• For this base IDIQ, the Assessment and Authentication (A&A) requirements of Clause 48 CFR 1352.239- 72 do not apply, and a Security Accreditation Package is not required.
• For this base IDIQ, the contractor will not be accessing US government computers or IT systems for this effort.
• For this base IDIQ, the contractor will not be accessing any information that is not within the public domain for this effort.
The contractor shall provide a description of how they secure their contractor owned equipment being used for this acquisition. To assist the contractor, an IT Security Questionnaire (titled: Information and Information Systems Security Requirements for Acquisitions) will be provide to outline information that should be consider in their response. The contractor can request assistance from the NOS Program Office assigned Information System Security Officer in describing how they secure their equipment.
The IT Security Questionnaire was developed following National Institute of Standards and Technology (NIST) Special Publications (SP) 800-53 Revision 4, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans”.
The government shall evaluate the contractor’s response to the questions and determine the potential contractor’s IT security risk to the Government. If the Government determines the IT Security risk to be acceptable, the Authorizing Official & Co-Authorizing Official will document their acceptance in a risk acceptance memo. The risk acceptance memo is available upon request.
The contractor will not have access to any government owned equipment or be furnished government privileged information. The contractor will be developing and documenting information and images obtained during the performance of this contract.
Each task order will include its own statement of work or equivalent and an Information Security in Acquisitions Checklist. All task orders will also require an IT Security review and assessment to determine what IT Security requirements are applicable.
IT security requirement for the [mobile/web] application/ database/ network operating systems must ensure secure management of user credentials (storing, transmitting, authenticating of user password must be encrypted). If the contractor solutions is using a contractor developed or government furnished [mobile/web] application/ database/ network operating systems, the contractor must:
• The contractor is required to meet the DOC IT Security Program Policy (ITSPP) and Commerce Information Technology Requirements (CITRs) (available at:
https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements). DOC has issued Commerce Information Technology Requirements (CITRs) as policy enhancements to the DOC IT Security Program Policy and carries the same authority as the DOC ITSPP. The DOC ITSPP and DOC CITRs may not specifically identify https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements https://connection.commerce.gov/policy/20140528/it-security-program-policy-and-commerce-information-technology-requirements
[mobile/web] application/ database/ network operating systems, may be applicable and will require contractor to compliance with this requirements. The DOC policies will be provided to the contractor at the start of the project. DOC policies are controlled unclassified information (CUI) and are restricted to only authorize personnel.
• Throughout the lifecycle, the contractor is required to incorporate security requirements. Development lifecycle must take into account the security controls catalogue contained within National Institutes of Standards and Technology’s (NIST) Special Publications 800-53 (SP 800-53).
Revision 4 Security and Privacy Controls for Federal Information Systems and Organizations.
• Organization’s Information System Security Officer (ISSO) will provide guidance to the contractor for identifying security controls, documenting security controls and ongoing continuous monitoring of security controls.
• The contractor must provide their security controls implementation including applicable architecture, diagrams, documentation, standard operating procedures supporting the development and operation of their solution. This documentation will be incorporated by the ISSO into appropriate Federal Information Security Management Act (FISMA) system security boundary.
• This applies to all updates must undergo vulnerability scanning, secure baseline compliance scanning and mitigation of vulnerabilities and provide the appropriate documentation to the government for each update demonstrating this requirement has been met.
Specifically for mobile application, web application and/or software product development, appropriate planning needs to be included during the assessment of needs, requirements, development and testing. Security requirements must be incorporated into the mobile application development lifecycle along with the user functional requirements.
• The developer must select and document secure baseline/ checklist (see National Checklist Program below) for the application/ software being developed to address IT security issues.
• The developer must document any deviations/exceptions from selected secure baseline. This secure baseline best practice must be implemented throughout development of product.
• The developer must perform a full source code review and application code scanning for vulnerabilities must be conducted. Any identified source code review deficiencies or scanner identified vulnerabilities must be mitigated and any other generated supporting documentation including the raw vulnerability scanner reports must be provided. This applies to all source code updates which must undergo a full source code review, full source code scanning and mitigation of vulnerabilities with the appropriate documentation provided to the government for each update demonstrating this security requirement has been met. Source code must be provided to the government for each product update, enhancement and/or security flaw remediation.
• If the solution includes a network operating system (i.e., Windows, Linux, etc) or web server (i.e., Apache, Microsoft IIS, etc) then all components (application, web server and network operating system) must have security checklist implemented and documented. System development lifecycle management of the application, web server and network operating system is expected. The government will provide, upon request, the current secure benchmarks being used for existing technologies to ensure compatibility.
This applies to all updates must undergo vulnerability scanning, secure baseline compliance scanning and mitigation of vulnerabilities with the appropriate documentation provided to the government for each update demonstrating this requirement has been met.
• The developer must ensure the solution doesn’t contain in spyware, malicious software, coding flaws or programming backdoors to circumvent the application functionality or the security of the application as described by the government. The solution must not access data stored on the device or request end user information without following all government (including OMB) requirements. The solution must not transmit stored data from the installed device without clearly notifying, fully describing the required data being transmitted and receiving the government’s approval.
Specifically for database development, appropriate planning needs to be included during the assessment of needs, requirements, development and testing. Security requirements must be incorporated into the database development lifecycle along with the user functional requirements.
• The databases must implement secure baseline\ checklist (see National Checklist Program below) for each database and perform databases vulnerability scanning for vulnerabilities.
• The databases weaknesses as identified from any vulnerability/compliance scanner identified vulnerabilities must be mitigated. Mitigation supporting artifacts must include any generated supporting documentation including raw vulnerability scanner reports and documented security checklist with deviations, if deviations exist, must be provided.
• This applies to all updates must undergo vulnerability scanning, secure baseline compliance scanning and mitigation of vulnerabilities with the appropriate documentation provided to the government for each update demonstrating this requirement has been met.
• If the solution includes a network operating system (i.e., Windows, Linux, etc) then both (database and network operating system) must have security checklist implemented and documented. System development lifecycle management of the database and network operating system is expected.
General security requirements
The contractor must consider IT Security controls throughout the lifecycle of this contract as outlined in NIST Special Publication 800-64 (https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/archive/2008-10-16).
The contractor is required to comply with the Department of Commerce’s Commerce Acquisition Manual’s (CAM) 1337.70 Personnel Security Requirements (http://www.osec.doc.gov/oam/acquistion_management/policy/commerce_acquisition_manual_cam/documents/C AM%201337.70%20-%20Personnel%20Security%20Requirements%20(October%202015).pdf).
The contractor shall provide a description of how they secure their contractor owned equipment being used for this acquisition. To assist the contractor, an IT Security Questionnaire (titled: Information and Information Systems Security Requirements for Acquisitions) will be provide to outline information that should be consider in their response. The contractor can request assistance from the NOS Program Office assigned Information System Security Officer in describing how they secure their equipment.
The IT Security Questionnaire was developed following National Institute of Standards and Technology (NIST) Special Publications (SP) 800-53 Revision 4, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans”. The government shall evaluate the contractor’s response to the questions and determine the potential contractor’s IT security risk to the Government.
If the Government determines the IT Security risk to be acceptable, the Authorizing Official & Co-Authorizing Official will document their acceptance in a risk acceptance memo. The risk acceptance memo is available upon request.
The contractor will not have access to any government owned equipment or be furnished government privileged information. The contractor will be developing and documenting information and images obtained during the performance of this contract.
https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/archive/2008-10-16 http://www.osec.doc.gov/oam/acquistion_management/policy/commerce_acquisition_manual_cam/documents/CAM%201337.70%20-%20Personnel%20Security%20Requirements%20(October%202015).pdf http://www.osec.doc.gov/oam/acquistion_management/policy/commerce_acquisition_manual_cam/documents/CAM%201337.70%20-%20Personnel%20Security%20Requirements%20(October%202015).pdf
All electronic provided information by the contractor must undergo malicious software scanning using a commercial anti-virus and anti-spyware software to ensure the information is free of known malicious software. The contractor must work with the COR prior to sending the information to establish a secure method for transfer. One option could be a file encrypted with a password using a product like WinZip. The contractor must encrypt any sensitive information that will be sent electronically (i.e., email), sensitive information includes but not limited to:
• All information describing the implementation, configuration, settings, etc for solution being developed,
• The source code and database schema,
• The vulnerability scanning, secure baselines scanning, mitigation results,
• The secure baseline deviations,
• Internet Protocol, subnet mask and similar identification.
The contractor includes the necessary product support and supporting documentation for the hardware and/or software that allows the sanitization (following NIST Special Publications 800-88 Guidelines for Media Sanitization, http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf) of the hardware and/or software upon the disposal of the product.
The contractor must provide sufficient document demonstrating the software being provided complies with Office of Management and Budget Memorandum M-07-18 entitled Ensuring New Acquisitions Include Common Security Configurations and the FAR 39.101(d) regulations involving NIST common security configuration checklists including Federal Desktop Core Configuration (FDCC) or United States Government Configuration Baseline (USGCB) initiative. More information is available at National Checklist Program (NCP), (http://checklists.nist.gov), is the U.S. government repository of publicly available security checklists (or benchmarks) that provide detailed low level guidance on setting the security configuration of operating systems and applications.
The contractor must provide sufficient documentation which demonstrates the acquiring information technology has implemented common security configurations. Common security configurations are available from the National Institute of Standards and Technology’s website at http://checklists.nist.gov.
The contractor must ensure that the product being purchased complies with the Homeland Security Presidential Directive 12 (HSPD-12) requirements from FAR 4.1302 stating: (a) In order to comply with FIPS PUB 201, agencies must purchase only approved personal identity verification products and services. (b) Agencies may acquire the approved products and services from the GSA, Federal Supply Schedule 70, Special Item Number (SIN) 132-62, HSPD-12 Product and Service Components, in accordance with ordering procedures outlined in FAR Subpart 8.4.
The contractor must ensure that the product being purchased complies with Internet Protocol Version 6 (IPv6) requirements from FAR part 11.002 requirements which state that unless the agency Chief Information Officer waives the requirement, when acquiring information technology using Internet Protocol, the requirements documents must include reference to the appropriate technical capabilities defined in the USGv6 Profile (NIST Special Publication (SP) 500-267- http://www.nist.gov/itl/antd/usgv6.cfm) and the corresponding declarations of conformance defined in the USGv6 Test Program (http://www-x.antd.nist.gov/usgv6/index.html). To meet this requirement each DOC acquisition of IP protocol technology must express requirements for IPv6 capabilities in terms of the USGv6 Profile (i.e., using the USGV6 Capabilities Check List) and vendors must be required to http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-88r1.pdf http://checklists.nist.gov/ http://checklists.nist.gov/ http://www.nist.gov/itl/antd/usgv6.cfm http://www-x.antd.nist.gov/usgv6/index.html document their product’s support of the requested capabilities through the USGv6 test program (reference http://www.antd.nist.gov/usgv6/) using the USGv6 Suppliers Declaration of Conformity.
The contractor must provide sufficient document demonstrating the software being provided meets the following:
• The standard installation, operation, maintenance, update and/or patching of software shall not alter the configuration settings from the approved FDCC/ USGCB/other secure configuration.
• Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
The contractor must provide all supporting documentation or a reference to obtain the necessary material which describes the security capabilities, the design and development processes and the testing and evaluation procedures used by the product or services being provided for this acquisition. The contractor must provide all supporting documentation or a reference to obtain the necessary material which describes all product or service updates and enhancements as they are implemented. The product or service supporting documentation could be the user and system administrator guides, which is documents the functional properties of the security controls employed to permit the analysis and testing of the security controls.
Disclosure of the information/data, in whole or in part, by the contractor can only be made after the contractor receives prior written approval from the Contracting Officer. Whenever the contractor is uncertain with regard to the proper handling of information/data under the contract, the contractor shall obtain a written determination from the Contracting Officer.
4.6. Contractor Coordination
Communication and coordination between both the contractor and the government is considered vital to the satisfactory accomplishment of each task order. Periodic interaction with government staff must be maintained to ensure clear understanding of the anticipated products and satisfactory progress. The contractor shall provide monthly reports at a minimum discussing the work that had been performed during that reporting period, problems encountered (if any), schedule and deliverable status, and planned work for the next reporting period.
The contractor shall schedule teleconferences after issuance of the monthly reports if there is a need to discuss the progress of each project and any issues that may need to be addressed.
In addition, a bi-yearly meeting, either in person or per teleconference may be scheduled by the government with the contractor to discuss their overall performance on the contract.
4.7. Key Personnel (Task Orders)
The contractor’s Project Manager shall be considered key personnel for the contract (See H.3 of contract).
Additional key personnel may be assigned for individual task orders. The Project Manager shall be the contractor’s single point of contact for general matters concerning the contract. The contractor may assign a task order manager to individual task orders; however, the Project Manager will have the overall responsibility of meeting the requirements of the contract.
4.8. Quality Assurance
The government will review all task order deliverables for quality, accuracy, timeliness, and completeness. The government will assess if satisfactory progress is being made and determine if the task order is on schedule for planned completion. If during the government Quality Assurance (QA) process the deliverables are found to not meet the requirements of the task order, the contractor shall correct the deficiencies and re-deliver the deliverable at no additional cost to the government.
http://www.antd.nist.gov/usgv6/
4.9. Laws, Regulations, Procedures and Permits
The contractor shall comply with all applicable laws, ordinances and regulations and procedures (federal, state, county, city, or otherwise) and shall be responsible for obtaining all necessary permits for work performed under the contract and shall include all costs, if any, of such compliance in the prices quoted in its proposal.
4.10. Travel
The contractor is responsible for the planning, coordination, and funding of travel for its employees in support of the performance of requirements outlined in each task order. The government expects that some travel will be necessary in order to meet the specifications of most task orders; however, it is not mandatory. The contractor shall separately indicate travel expenses in each task order cost proposal.
4.11. Contractor Confidentiality
The contractor shall have access to government data and information during the contract period. The contractor shall not use, for any purpose outside the terms of the contract, proprietary raw data. The contractor shall not distribute processed data and derived products developed for the government in connection with this contract prior to quality review and acceptance by the government.
4.12. Contractor Innovation
The contractor shall remain alert to possible improvements in technical methods and administrative procedures used to provide products under the contract. The contractor shall propose such improvements to the government and obtain concurrence prior to implementing a change.
4.13. Deliverables
Specific deliverables will be outlined in the individual task orders. All deliverables shall meet all applicable international, national and Federal information technology and geographic information standards, particularly those identified by the Federal Geographic Data Committee (FGDC) as supporting the National Spatial Data Infrastructure (NSDI). Product deliveries shall meet defined schedules. All deliverables, including Monthly Reports, shall be submitted using OCM’s Task Order Management and Information System (TOMIS).
5.0. Acronyms
CLIN Contract Line Item Number
DEM Digital Elevation Model
DSM Digital Surface Model
DTM Digital Terrain Model
ETM Enhanced Thematic Mapper
FGDC Federal Geographic Data Committee
GFE Government Furnished Equipment
GIS Geographic Information System
GPS Global Positioning Systems
ISO International Organization for Standardization
LIDAR Light Detection and Ranging
NOAA National Oceanic and Atmospheric Administration
NSDI National Spatial Data Infrastructure
OCM Office for Coastal Management
QA Quality Assurance
QC Quality Control
SOW Statement of Work
TOMIS Task Order Management and Information System
File details come from the government source that posted it. Updated .