Amend_No_1-RFP-NIH-NICHD-DIPHR-2018-6.pdf

PDF 105 KB Posted

Attached to
Multiple Study Data Coordinating Centers for DIPHR Federal contract opportunity
Solicitation number
NIH-NICHD-DIPHR-2018-6
Issued by
Department of Health and Human Services National Institutes of Health

About this file

Amendment of Draft Solicitation RFP-NIH-NICHD-DIPHR-2018-6

View the file

Other files for this federal contract opportunity

Other files attached to Multiple Study Data Coordinating Centers for DIPHR, newest first.
File Type Posted
Amend_No_2-RFP-2018-6_DIPHR_DCC..pdf PDF
Amend_No_1-RFP-2018-6_DIPHR_DCC_.pdf PDF
Request_for_Proposal_NIH-NICHD-DIPHR-2018-6_.pdf PDF
https://www.fbo.gov/spg/HHS/NIH/OoA/RFP-NIH-NICHD-DIPHR-2018-6/listing.html HTML file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV 10-83)

PREVIOUS EDITION NOT USABLE Prescribed by GSA FAR (48 CFR) 53.214(a)

AMENDMENT OF DRAFT SOLICITATION/MODIFICATION OF CONTRACT

1. CONTRACT ID CODE

PAGE

OF PAGES

2. AMENDMENT/MODIFICATION NO.

3. EFFECTIVE DATE

May 30, 2018

4. REQUISITION/PURCHASE REQ. NO

N/A

5. PROJECT NO. (if applicable)

6. ISSUED BY CODE

7. ADMINISTERED BY (If other than Item 5)

CODE

Office of Acquisitions NICHD Contracts Management Branch Eunice Kennedy Shriver National Institute of Child Health and Human Development National Institutes of Health

6710B ROCKLEDGE DRIVE

BETHESDA, MD 20892-7000

8. NAME AND ADDRESS OF CONTRACTOR (No., street, city, county, State and ZIP Code)

TO ALL POTENTIAL OFFERORS

9A. AMENDMENT OF DRAFT SOLICITATION NO.

RFP-NIH-NICHD-DIPHR-2018-6

9B. DATED (SEE ITEM 11)

May 4, 2018

10A. MODIFICATION OF CONTRACT/ORDER NO.

CODE

FACILITY CODE

10B. DATED (SEE ITEM 13)

11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF DRAFT SOLICITATIONS

[] The above numbered draft solicitation is amended as set forth in item 14.

12. ACCOUNTING AND APPROPRIATION DATA (if required)

13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS,

IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.

A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE CONTRACT

ORDER NO. IN ITEM 10A.

B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(b).

C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:

D. OTHER (Specify type of modification and authority)

E. IMPORTANT: Contractor _ is not, __ is required to sign this document and return ____ copies to the issuing office.

14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)

Purpose: To amend DRAFT SOLICITATION RFP-NIH-NICHD-DIPHR-2018-6 to provide answers to questions

See continuation pages for Amendment

Except as provided herein, all terms and conditions of the document referenced in item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.

15A. NAME AND TITLE OF SIGNER (Type or print)

16A. NAME AND TITLE OF CONTRACTING OFFICER

Theresa Koomson, Contracting Officer NICHD Contracts Management Branch

15B. CONTRACTOR/OFFEROR

BY ______________________________________________

(Signature of person authorized to sign)

15C. DATE SIGNED

16B. UNITED STATES OF AMERICA

BY

_______________/S/________________

(Signature of Contracting Officer)

16C. DATE SIGNED

05/30/2018

AMENDMENT NO.: 001

CONTINUATION PAGE Page 2 of 12

As a result of this Amendment the following answers are provided below:

Question 1:

In several places in the SOW (e.g., Attachment 3, section III.A.1 “For all web-based systems, it must be open source systems” and “Open-source systems are required”) you require the use of open source software. However, you cite CTDB and Redcap as examples of open source platforms. Open source software is “software with source code that anyone can inspect, modify, and enhance” and neither CTDB nor Redcap meet this definition. We’d appreciate if you could provide your definition of open source software in the RFP, so that we correctly address the requirement. Based on those examples, we think that you are asking for software that was developed with Government funding but, if so, please note that such requirement would place most offerors in an unfair competitive disadvantage. This is because only the Government contractors/grantees who developed the software (e.g., Vanderbilt University for Redcap or EMMES for Advantage EDC) have access to them.

Response:

Apologies for the confusing language. The SOW in the official solicitation will be revised to clarify that the requirement is to develop a state-of-the-art, efficient, reliable, secure and responsive web-based data coordination and management system(s) within the framework of or integrated with a NIH-hosted (i.e., NICHD Clinical Trials Database or REDCap) or commercially-available application such as but not limited to ClinCapture, OpenClinica, EpiCollect5, etc. Offeror will indicate in its response which commercially-available or NIH-hosted application or applications will be used and provide a reasoned explanation of the choice. The explanation will address, at least, the technical suitability of the selected application and associated costs. See Section III. A. 1. of the SOW.

Question 2:

Also in Attachment 3, section III.A.1 (and other places throughout the SOWs), you require that forms be somehow converted so that they can be imported into an open source platform. Although some data collection systems (e.g., OpenClincia, which is truly open source) can create forms from an imported Excel file, in most systems forms are not “imported” but configured in the same system through point-and-click process. As a consequence, in order to be able to provide an accurate technical approach to address this requirement, we need to know which open source system you want to import the forms into, whether it has this capability and, if so, the specifications for the file containing the form attributes.

Response:

The SOW in the official solicitation will be revised to clarify that data collection instruments and information required to access, use and modify data management systems must be delivered to the NICHD COR within 30 days of the end of each task order (see III. A. 4).

Question 3:

In Attachment 3, section III.A.6 you require that “The system shall have the capacity for providing automated mailings for the study sites”. Do you mean that uses who belong to the sites should be able to use the system to prepare and send mailings to the participants, or do you mean that contractor’s users should be able to use the system to send mailings to the site users and/or participants? Please, clarify.

Response:

The SOW in the official solicitation will be revised to clarify the requirement (see III. A. 1. o.). The system should support the ability of study site research staff and DCC staff to generate automatic contacts with participants including, for example, email or text reminders to complete questionnaires or reminders of upcoming study visit appointments.

NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV 10-83)

PREVIOUS EDITION NOT USABLE Prescribed by GSA

CONTINUATION PAGE Page 3 of 12

Question 4:

Task Order 1 SOW. Since this study has already started, please clarify if a specimen tracking system needs to be provided by the offeror or if one is already in use and will continue being used.

Response:

The biospecimen tracking system is an existing component of the NICHD Clinical Trials Database system.

Question 5:

We were hoping you could clarify one of the Technical Requirements (SOW – IDIQ Section III.A. Data Systems and Technology) on page 112 of the PDF. The requirements states that, “For all web-based systems, it must be open source systems; anyforms created using proprietary software must be converted or provide converted instruments or importing into an open source platform (e.g., CTDB, Redcap). Open-source systems are required.”

• Could the Government please clarify its definition of what it would consider Open-Source? We have spoken with REDCap and they have made clear that the Consortium version of their software is not Open-Source – I have also attached a screenshot from their website where they make a similar statement.

• According to the REDCap consortium page NICHD currently has a REDCap platform setup. REDCap will not license its platform to Consulting Firms, so the only feasible way is for NICHD to obtain the license directly from REDCap and then the Contractors can work with the platform. Will Contractors be able to use the source code for this platform to setup the EDC for this DCC?

• Does the government consider systems that are essentially GOTS (developed via government funding, but not licensed) as Open-Source?

• If CTDB is open-source, could you please direct us to the location where we can download the source-code for analysis? Or could you provide me a POC for that system who can assist with this request?

Response:

The official solicitation will be revised to remove the language regarding “open source”, and to clarify that the requirement is to develop a state-of-the-art, efficient, reliable, secure and responsive web-based data coordination and management system(s) within the framework of or integrated with a NIH-hosted (i.e., NICHD Clinical Trials Database or REDCap) or commercially-available application such as but not limited to ClinCapture, OpenClinica, EpiCollect5, etc. Offeror will indicate in its response which commercially-available or NIH-hosted application or applications will be used and provide a reasoned explanation of the choice. The explanation will address, at least, the technical suitability of the selected application and associated costs. See Section III. A. 1. of the SOW. The website for the NICHD CTBD is: https://ctdb.nichd.nih.gov/ctdb/

Question 6:

Please clarify the Government’s expectation for “open-source” platforms. Is the requirement for a platform that is maintained as publicly available open-source code-base? Or is the requirement for a platform that utilizes software and technologies that do not have recurring licensing cost for continued use and maintenance and are not dependent upon a third-party to deliver updates, enhancements, and fixes?

Response:

The official solicitation will be revised to remove the language regarding “open source”, and to clarify that the requirement is to develop a state-of-the-art, efficient, reliable, secure and responsive web-based data coordination and https://ctdb.nichd.nih.gov/ctdb/

CONTINUATION PAGE Page 4 of 12 management system(s) within the framework of or integrated with a NIH-hosted (i.e., NICHD Clinical Trials Database or REDCap) or commercially-available application such as but not limited to ClinCapture, OpenClinica, EpiCollect5, etc. Offeror will indicate in its response which commercially-available or NIH-hosted application or applications will be used and provide a reasoned explanation of the choice. The explanation will address, at least, the technical suitability of the selected application and associated costs. See Section III. A. 1. of the SOW.

Question 7:

We request that the Government clarify the following for Offerors.

• How many and which clinical data collection systems are in current use in the Intramural research program

NICHD?

• Are any of those systems in use open source?

• Will the continued use or support of these systems be in scope of this solicitation?

• What is the Government’s end goal for how many and which Intramural research data systems will need to be supported?

Response:

The official solicitation will be revised to remove the language regarding “open source”, and to clarify that the requirement is to develop a state-of-the-art, efficient, reliable, secure and responsive web-based data coordination and management system(s) within the framework of or integrated with a NIH-hosted (i.e., NICHD Clinical Trials Database or REDCap) or commercially-available application such as but not limited to ClinCapture, OpenClinica, EpiCollect5, etc. Offeror will indicate in its response which commercially-available or NIH-hosted application or applications will be used and provide a reasoned explanation of the choice. The explanation will address, at least, the technical suitability of the selected application and associated costs. See Section III. A. 1. of the SOW.

NICHD currently uses the Clinical Trials Database, and we are in the process of adopting REDCap. These applications are not open source but would be NIH-hosted and available at no cost to NICHD intramural investigators.

The successful offeror would be granted access (at no cost) to the NICHD-hosted CTDB (or REDCap) to perform the work of the contract. Other data collection systems currently in use in NICHD DIPHR include in-house proprietary systems developed by external contractors, which would not satisfy the requirements of this solicitation.

The Government does not have a goal specifically related to the number of EDC systems, but the proposed system(s) would need to support data collection and monitoring for multiple concurrent studies (as many as eight to ten concurrent, ongoing initiatives during any given year). It is anticipated that the smallest number of systems to support the largest number of studies would be desirable for efficiency and cost considerations.

Question 8:

REDCap is cited as an open-source example throughout the scopes of work in the RFP. Per published FAQs and correspondence with Vanderbilt, REDCap is not a publicly available open-source code-base to any organizations outside of the REDCap Consortium, and only non-profit research institutions are eligible to join the consortium. In the event that continued use and maintenance of REDCap is within the scope of this solicitation, we have the following questions:

• Does the NICHD DIPHR currently use or have future plans to adopt REDCap?

NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV 10-83)

PREVIOUS EDITION NOT USABLE Prescribed by GSA

CONTINUATION PAGE Page 5 of 12

• If so, does the NICHD DIPHR have or plan to use an instance of REDCap that is installed on Government servers?

• Could the successful offeror obtain access to the instance of REDCap used by NICHD DIPHR for the purpose of developing electronic case report forms?

Response:

The official solicitation will be revised to remove the language regarding “open source”, and to clarify the requirement (see Section III. A. 1. of the SOW). NICHD DIPHR is in the process of establishing an instance of REDCap to be supported by NIH servers. Access to the NICDH DIPHR instance of REDCap and/or CTDB would be provided to the successful offeror (at no cost) to perform the work of the task order, including developing case report forms.

Question 9:

In the event that continued use and maintenance of CTDB is within the scope of this solicitation, we have the following questions:

• Though not indicated as such in the published FAQs, is CTDB available as an open source product to for-profit companies?

• Does CTDB have an application programming interface (API) for systems integration and exchange of data and metadata with other systems?

• Can the successful offeror obtain access to the Government’s instance of CTDB to develop electronic case report forms?

Response:

First, the official solicitation will be revised to remove the language regarding “open source”, and to clarify the requirement (please see III. A. 1 in the revised draft RFP). Once the contract is awarded, the successful offeror would be granted access to CTDB (at no cost) to perform the tasks delineated in the SOW, including generating case report forms. CTDB does not have an API for systems integration and exchange of data/metadata with other systems.

Metadata standards are incorporated into the system during the creation of data collection forms and items.

Question 10:

Are REDcap and CTDB both to be considered as “open source” for this RFP?

Response:

The official solicitation will be revised to remove the language regarding “open source”, and to clarify the requirement (please see III. A. 1. of the revised draft RFP). REDCap and CTDB are not open source but would be NIH-hosted and access would be granted to the successful offeror (at no cost) to perform the work of the task order.

Question 11:

Are the Task Orders (listed as sample Task Orders in draft) distinctively separate from the proposal for the Data Coordinating Center bid in support of 8-10 annual studies?

CONTINUATION PAGE Page 6 of 12

Response:

No, the task orders (and samples) represent a subset of the up to 8-10 studies that would be supported by the DCC

IDIQ.

Question 12:

Is laboratory support and collection and management of biospecimens separate from the Data Coordinating Center bid proposal and a part of each anticipated task order?

The DCC is responsible for developing and implementing a system for tracking biospecimens, but the clinical sites collect the biospecimens and a separate contract will procure laboratory services for analyzing and storing the biospecimens.

Question 13:

Is CTDB the only acceptable open source system for this task order?

Response:

Data collection in the CTDB electronic data capture system will already be in place prior to the award of this task order. While it is conceivable that an offeror may propose to migrate the data collection system to another application that meets the requirements of the SOW, it is anticipated that this may not be an efficient or cost-effective effort.

Question 14:

How many clinical sites should we anticipate will support this study?

Response:

There is a single clinical site involved in this study.

Question 15:

Is transfer of data to an open source system at the end of the study sufficient to satisfy the open source requirement?

Response:

Consistent with the requirements of the IDIQ, the Data Coordinating Center will be expected to develop a state-of-the-art, efficient, reliable, secure, and responsive web-based data coordination and management system within the framework of or integrated with a NIH-hosted (e.g., NICHD Clinical Trials Database or REDCap) or commercially available application, such as but not limited to ClinCapture, OpenClinica, EpiCollect5, or similar products. Near the end of each task order, the DCC will be expected to plan and execute an orderly, secure, complete transfer of all study materials to the NICHD COR to enable study continuity and reproducibility, including but not limited to all data, metadata, datasets, official documentation, and information technology assets.

Question 16:

One of the task order requirements is to build a tracking system to maintain participant contact information and use it to engage participants and construct a geolocation database. Will the Data Coordinating Center be in direct contact with participants or will this tracking system be used only by clinical site(s)?

NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV 10-83)

PREVIOUS EDITION NOT USABLE Prescribed by GSA

CONTINUATION PAGE Page 7 of 12

This has not been decided and will be determined following award of the Task Order in collaboration among DIPHR investigators, Data Coordinating Center personnel, and the Clinical Site(s). However, the Data Coordinating Center should be prepared to take on the role of direct contact with participants should a decision be made to have Data Coordinating Center personnel assume this role.

Question 17:

Should vendors assume that participants will have their own internet-connected devices in order to login to RAPPER?

Yes.

Question 18:

Is DICOM format compatible with PACS ?

DICOMS (raw acquired MRI images not suitable for analyses without conversion) are stored on PACs system at our imaging center. Users (certainly not outside data coordinating centers) are not allowed to have access to the imaging center’s PACs due to PHI of every individual scanned at the center. Eyetracking data has nothing to do with DICOMS or PACS.

Question 19:

What is the size of each image?

A DICOM (fMRI for PEAs) is ~1.5 GB per subject. We don’t know the size of the eyetracking data, as this data collection has not started and it depends on the performance of the child. Eyetracking data are .txt files and do not need special handling.

Question 20:

What is the number of images per visit?

Response:

During a functional scan a 3D image of the brain is take every 2 seconds during a scan, so those files, per subject, are 4D files (3D image over time), we assess other time of scan that are not functional, so the number of images per scan varies. DICOMs contain all of these and need to be converted, so the number of images per subject in fMRI is meaningless. Eyetracking does not assess images.

Question 21:

Will the various Task Orders be awarded once the IDIQ contracts are awarded or are these just sample TOs?

Response:

It is anticipated that Task Order 1, Task Order 2 and Task Order 3 will be awarded concurrently with the IDIQ contracts. The sample task orders are anticipated for future award.

CONTINUATION PAGE Page 8 of 12

Question 22:

In Attachment 1, page 2 it states in the block that there are “. . . four (3) . . .” sections in the Business Proposal. I think it should be three sections.

Response:

This is a typo. There are only three (3) sections in the Business Proposal not four (4). This will be corrected in the official solicitation.

Question 23:

In Attachment 11 the points add up to 115 instead of 100.

Response:

Each of the Technical Evaluation Criteria for this acquisition has a total score of 100 points. This will be corrected in the official solicitation.

Question 24:

Attachment 1, section II.B. Page limitations: Because the SOW of Task Order 1 is very similar to the SOW of Sample Task Orders 1A and 1B, we would normally describe our technical approach under Task Order 1 and we would then cross-reference it under the sample task orders. Therefore, we would not use the 10 pages for 1A and 1B but we would appreciate if we could use them for Task Order 1. In other words, we would prefer to have a 30-page limit for the combination of Task Order 1, Sample Task Order 1A and Sample Task Order 1B. The same comment applies to Task Order 2 and Sample Task Orders 2A to 2E (i.e., 60 pages total), and for Task Order 3 and Sample Task Orders 3A to 3C (40 pages total).

Response:

Variations in the page limitations for the individual task orders are acceptable; however, the technical proposal shall not exceed 150 pages total.

Question 25:

Please, clarify if Data Sharing Plan and the Human Subjects section do not count towards the 150 pages technical proposal page limitation.

Response:

The page limitation for the Technical Proposal shall not exceed 150 pages exclusive of the Data Sharing Plan and the Human Subjects section.

Question 26:

Attachment 1, Section II.B, Page Limitations, p.3, lists documents exempted from the 150-page count. Please confirm that the all following Technical Proposal Attachments listed in Section J, Technical Proposal Attachments, p. 56, will also be exempt from the Technical Proposal’s 150-page limitation:

• Technical Proposal Cost Summary

• Summary of Related Activities

• Protection of Human Subject Assurance Identification/IRB Certification/Declaration of Exemption, OMB Form No. 0990-0263

• HHS Section 508 Product Assessment Template

NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV 10-83)

PREVIOUS EDITION NOT USABLE Prescribed by GSA

CONTINUATION PAGE Page 9 of 12

None of the Technical Proposal Attachments listed in Section J are included in the page limitations specified in Attachment 1.

Question 27:

Attachment 11, IDIQ Evaluation Criteria, p. 5, IV, Experience and Qualifications of the Organization. This appears to be the same as criterion III on p.4. Please confirm and update the Evaluation Criteria.

The criteria for Experience and Qualifications of the Organization are listed twice. This error will be corrected in the official solicitation.

Question 28:

For budget consistency across offerors, please provide specific budget period calendar dates (start and end dates) for each of the following:

• Task Order 1 – Sprouts Baseline/Age 3 Assessment

Response: Estimated period of performance is September 25, 2018 – September 24, 2021

• Task Order 1A – Sprouts Baseline/Age 4 Assessment

Response: Estimated period of performance is September 25, 2021 – September 24, 2024

• Task Order 1B – Sprouts Baseline/Age 5 Assessment

Response: Estimated period of performance is September 25, 2024 – September 24, 2027

• Task Order 2 – Preparation and Training

Response: Estimated period of performance is September 25, 2018 – June 24, 2019

• Task Order 2A – Recruitment and Implementation (Stage 1)

Response: Estimated period of performance is June 25, 2019 – June 24, 2020

• Task Order 2B – Recruitment and Implementation (Stage 2) (Phase 1)

Response: Estimated period of performance is June 25, 2020 – June 24, 2021

CONTINUATION PAGE Page 10 of 12

• Task Order 2C – Recruitment and Implementation (Stage 2) (Phase 2)

Response: Estimated period of performance is June 25, 2021 – June 24, 2022

• Task Order 2D – Recruitment and Implementation (Stage 2) (Phase 3)

Response: Estimated period of performance is June 25, 2022 – December 24, 2022

• Task Order 2E – Data Finalization and Documentation

Response: Estimated period of performance is December 25, 2022 – September 24, 2023

• Task Order 3 – Start-Up and Recruitment of First Subcohort

Response: Estimated period of performance is September 25, 2018 – January 24, 2020

• Task Order 3A – Recruitment of the Second Subcohort and Follow-Up

Response: Estimated period of performance is January 25, 2020 – October 24, 2020

• Task Order 3B – Recruitment of the Third Subcohort and Assessment

Response: Estimated period of performance is October 25, 2020 – September 24, 2021

• Task Order 3C – Completion of Follow-Up Assessments and Data Close-Out

Response: Estimated period of performance is September 25, 2021 – October 24, 2022

Question 29:

On p. 30 of the RFP, what is the PII Confidentiality Impact Level? It is unmarked.

The PII Confidentiality Impact Level has been determined to be Moderate.

Question 30:

A significant number of evaluation points in the Technical Proposal seem to be dedicated to organizational experience and qualifications. Would the government consider expanding the page limits to allow for an organizational experience section?

Response:

Variations in the page limitations for the individual task orders are acceptable; however, the technical proposal shall not exceed 150 pages total.

Question 31:

Attachment 11 includes two sections to evaluate Experience and Qualifications of the Organization. Should vendors assume this element will be evaluated twice?

NSN 7540-01-152-8070 30-105 STANDARD FORM 30 (REV 10-83)

PREVIOUS EDITION NOT USABLE Prescribed by GSA

CONTINUATION PAGE Page 11 of 12

No, this is a typo and will be corrected in the official solicitation.

Question 32:

We were not able to find SECTION K - REPRESENTATIONS, CERTIFICATIONS, AND OTHER STATEMENTS OF OFFERORS in Section J-LIST OF ATTACHMENTS of the subject DIPHR RFP.

Response:

The Reps and Certs template will be included in the official solicitation.

Question 33:

On p. 74, section C, SA&A Package Deliverables, the RFP states that an Independent Assessment of security and privacy controls is due 90 days after the contract award, but then in the next paragraph, it states that the POA&M (which is a deliverable from the independent assessment) is due 30 days after contract award. These timelines are in conflict since the first one has to occur before the second one. Could the Government amend the second deadline to greater than 90 days so the independent assessment can be completed and a POA&M can be created from it or otherwise clarify the desired timeline for these activities?

Response:

The POA&M deliverable can be extended to 90 days after the contract award.

Question 34:

On p. 75, section E, Reporting and Continuous Monitoring, there are paragraphs relating to Asset Management, Configuration Management, Vulnerability Management that all state a requirement to use SCAP-compliant automated tools for monitoring and scanning. Will the Government amend this requirement to allow offeror utilization of implemented tools that are not fully SCAP-compliant, but that perform materially the same functionality and can provide the same reporting capability as SCAP-compliant tools?

Response:

Government will not amend this requirement. Without the requirement we have no standard by which to measure the proposed solution.

Question 35:

On p. 40, section 5 Desktops, Laptops, and Other Computing Devices Required for Use by the Contractor, item c states the following: “Maintain the latest operating system patch release and anti-virus software definitions within 15 days.”

With regard to applying operating system patches, we believe that 15 days is an insufficient timeframe to allow for testing necessary to ensure no disruption to business operations or security of information. Would it be possible to remove the requirement of 15 days for patches to desktops/laptops and replace that language with something consistent to RFP ?

p. 75 in the paragraph on Patching and Vulnerability Remediation? That language states “in an expedited manner, within vendor and agency specified timelines”.

CONTINUATION PAGE Page 12 of 12

The requirement can be adjusted to the NICHD requirement of 30 days.

Question 36:

On p. 9, section C, E-Authentication Questionnaire, the RFP references NIST SP 800-63 rev 2, but that publication was superceded by rev 3 in June 2017. Should this requirement be updated to rev 3 or do you still wish to require adherence to rev 2?

Also, the term “Threshold Analysis” doesn’t exist in either rev 2 or rev 3 of NIST SP 800-63, so will the Government provide a specific questionnaire related to an authentication risk assessment to which the awardee may respond?

Yes, NIH is currently utilizing NIST SP 800-63 rev 2 to fulfill this requirement. NIH refers to the NIST SP 800-63 rev 2 document as E-Authentication Threshold Analysis.

AMENDMENT OF DRAFT SOLICITATION/MODIFICATION OF CONTRACT
BETHESDA, MD 20892-7000

File details come from the government source that posted it.