P03- SOW (Attachment A.).pdf

PDF 241 KB Posted

Attached to
Quark Publishing Platform Production System (License) Federal contract opportunity
Solicitation number
12FPC224Q0072
Issued by
Department of Agriculture Under Secretary for Farm Production and Conservation

About this file

This document is a Statement of Work (SOW) for the renewal of Quark licenses and maintenance for the USDA's Farm Production and Conservation (FPAC) Business Center Information Solutions Division. The Quark platform is used to author, edit, release, and maintain Conservation Practice Documents for the National Handbook of Conservation Practices.

The SOW details the Quark footprint, including the Quark Publishing Platform production system with 1000 named user licenses, as well as the Quark Author web-based content creation software. It outlines the license and maintenance renewal requirements, with a base period of 09/30/2024 - 09/29/2025 and an optional one-year extension. Pricing must be provided as line-item data within 10 days of award or software activation. The contractor must also provide software attestation forms and meet FedRAMP Moderate Baseline or higher certification requirements for the cloud-hosted application.

View the file

Other files for this federal contract opportunity

Other files attached to Quark Publishing Platform Production System (License), newest first.
File Type Posted
P06- FAR 13.501 BN (Quark) (Redacted).pdf PDF
S01 - 12FPC224Q0072 (Quark)(30AUG2024).pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work Quark License and Maintenance Renewal

Background

In 2018, the FPAC Business Center (FPAC-BC) was formed within the FPAC Mission Area to centralize operations with divisions for acquisition and procurement, budget, financial management, grants and agreements, human resources, information solutions, management services, performance accountability and risk, economics and policy analysis, environmental activities, appeals and litigation, customer experience, homeland security, and external affairs.

The FPAC-BC Information Solutions Division (ISD) realigned the information technology delivery functions from FSA, NRCS, and RMA to a single organization. The FPAC ISD primary customers include FSA headquarters and field employees, NRCS headquarters and field employees, RMA headquarters employees and approved insurance providers, and FPAC Business Center employees.

The Nationalizing Conservation Practice Standards Documents (CPD) Project, commissioned in 2012, is a multi-year development and implementation rollout effort. The three main components of this project are nationalizing Conservation Practice Documents (CPD), implementing a quality assurance process, and developing the Conservation Practice Documents-Document Management System (CPD-DMS). Supplemental activities include the associated revisions to Handbook GM 450, Part 401, Subpart B, and to Chapter 1 of the (National Handbook of Conservation Practices (NHCP). Other tasks include revisions to the Electronic Field Office Guide (eFOTG) and development of the Conservation Practice Data Entry System (CPDES).

The Quark publishing platform manages and automates the creation, processing, and publishing of content. The Quark authoring application is a web-based content creation tool, which together with the Quark publishing platform, allows for streamlining and automation of content generation and review/feedback loop involved in creating, previewing, publishing, and reusing content. Quark has been integrated in the EDM platform and has the following Quark footprint:

Quark Publishing Platform - Production System Quark Publishing Platform manages and automates the creation, processing, and publishing of content. The modules of Quark Publishing Platform work together to automatically enable the assembly of content for different audiences, and publication and media types creating an end-to-end publishing workflow that speeds time-to-market, improves customer satisfaction and lowers cost.

Quark Publishing Platform server connections Access to the Quark platform is controlled through server connections. These connections permit users to be part of the management and automation of the creation, processing and publishing of content, as described above, while the platform manages the audit and governance of their activities. 1000 connections are provided with the CLIENT base platform.

licensing, further connections are required above this.

Quark Author Named User License Quark Author is Web-based content creation software that, together with Quark Publishing Platform, enables the streamlining and automation of high-value customer communications, The intuitive online authoring experience means subject matter experts – wherever they are – can rapidly create, preview, publish and reuse content.

At the USDA, the Quark Publishing and Authoring Platform is being used to author, edit, release and maintain Conservation Practice Documents (CPD) such as Implementation Requirements, Operations & Maintenance (O&M), and Specifications documents. The platform also provides for the Quality assurance (QA) review process workflow involving the national, state and area staff, while allowing the capture of the Review Feedback and Response History. The 34 Conservation Practice Standards (CPS) and supporting CPDs are worked on each year to maintain the 5-year revision schedule required by policy. When finalized, the standards are published to the NHCP, making them available for public use.

The Quark toolset is used by the National Practice Discipline leads and their teams, Quality assurance teams, State Conservation Engineers, State Engineering Staff, Area Engineering Staff, State Resource Conservationists and their staff, Centers staff.

Objectives FPAC will renew Quark licenses and maintenance as a base award with one (1) option year.

Delivery

• Electronic Delivery of Licenses: SM.FPAC.BC.SDT.LICENSEMANAGEMENT@USDA.GOV

Delivery Dates

Base Period 09/30/2024 – 09/29/2025 Option Year One (1) 09/30/2025 – 09/29/2026

Requirements:

Line Item Product QTY 1 Annual Maintenance Renewal for Quark Publishing Platform Production

System with 1000 Named Users, QXP Server & Subrenderers, Quark Author Web Edition. Managed Service 30 days.

1. Software Line-Item Pricing Deliverable

In accordance with Office of Management and Budget Memorandum M-16-12, Category Management Policy 16-1: Improving the Acquisition and Management of Information Technology: Software Licensing, USDA must maintain an inventory of its software licenses, including pricing data. The contractor shall provide line-item pricing data on all software licenses provided to USDA at award and/or during performance of the contract/order.

Deliverable Submitted to: Due Date:

Software Line Item Pricing Contracting Officer’s

Representative Within 10 Days of Award, or Within 10 Days of Software Activation for Licenses Provided After Award Date

THE REMAINDER OF THIS PAGE INTENTIONALLY LEFT BLANK

mailto:%3cSM.FPAC.BC.SDT.LICENSEMANAGEMENT@USDA.GOV

SPECIAL IT REQUIREMENTS

Cyber-Security Supply Chain Risk Management (C-SCRM)

See Attachment A (USDA Cyber Supply Chain Risk Management (C-SCRM) Contract Language – Version 1.0).

Sections 2, 4, 5 and 6 are incorporated by reference.

Data Rights Data collected, generated or managed The Contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this task. The Contractor shall also protect all unclassified Government data, equipment, etc., by treating information as sensitive business, confidential information, controlling and limiting access to the information, and ensuring the data and equipment are secured within their facility.

To the extent required to carry out a program of inspection to safeguard against threats and hazards to the security, integrity, and confidentiality of Government data, the Contractor will afford the Government access to the Contractor's or other external organization’s facilities, installations, technical capabilities, operations, documentation, records, and databases. The Contractor will cooperate with Federal agencies and their officially credentialed representatives during official inspections or investigations concerning the protection of USDA information.

Cooperation may include providing relevant documentation showing proof of compliance with federal and agency requirements, and rendering other assistance as deemed necessary.

Privacy Act The Contractor Agrees To –

• Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies— o The systems of records; and o The design, development, or operation work that the contractor is to perform;

• Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act;

and

• Include this clause, including this paragraph, in all subcontracts awarded under this contract, which requires the design, development, or operation of such a system of records.

• In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.

• Definitions of the clause:

o “Operation of a system of records,” as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.

o “Record,” as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person’s name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.

Confidentiality and Non-Disclosure Any USDA proprietary information, data, and/or equipment that the Contractor has been granted access by USDA to perform work under this order, will be returned to the USDA when no longer required to perform work under this order. The public release of USDA proprietary information must be authorized in writing by the Contracting Officer.

The component parts of this effort and reports are expected to contain highly sensitive information that may act as a guide for hostile entities to cause harm to the Department’s critical infrastructure. Any such information made available in any format shall be used only for the purpose of carrying out the provisions of this agreement. Such information shall not be divulged or made known in any manner to any person.

The Contractor shall immediately notify the Contractor Program Manager, the Contractor on-site Manager, the COR, the Government TPM and the Contracting Officer upon discovery of any inadvertent disclosures of information. The Contractor shall not retain any information regarding vulnerabilities, to include summaries, the actual vulnerability report, etc., at the end of the task order. All information arising from this task, both hard copy and electronic, shall be returned to the COR and Government TPM at task completion.

The Contractor must agree that:

• The draft and final deliverables and all associated working papers and other materials deemed relevant by the

USDA TPMs that have been generated by the Contractor in the performance of this task order are the property of the U.S. Government and must be submitted to the USDA TPMs at the conclusion of the tasks.

• All documents produced for this project are the property of the U.S. Government and cannot be reproduced or retained by the Contractor. All appropriate project documentation will be given to the Government TPM during and at the end of this contract. The Contractor will release no information. Any request for information relating to this Statement of Work presented to the Contractor must be submitted in writing to the USDA TPMs and the CO, who in turn will 12.3 under assignment of this contract.

Sensitive Information Storage and Disclosure Sensitive information, data, and/or equipment will be disclosed only to authorize personnel on a Need-To-Know basis. The holder shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment will be returned to Government control; destroyed; or held until otherwise directed. Destruction of items shall be accomplished by tearing into small parts; burning; shredding or other method that precludes the reconstruction of the material.

Work on this contract may require that personnel have access to Privacy Information. Personnel shall adhere to the Privacy Act, Title 5 of the U. S. Code, Section 552a and applicable agency rules and regulations.

The Contractor Program Manager shall ensure that all contract personnel take the required USDA Security Awareness and Rules of Behavior Training.

Release of Information No USDA data shall be divulged to any unauthorized person, for any purpose. Therefore, the Contractor shall clear with the Contracting Officer any public release of any information. Information includes news stories, articles, sales and marketing information, advertisements, etc. All requests for public release of information shall be submitted via email to the COR and Government Technical Program Manager (TPM) and the Contracting Officer and addressed to:

United States Department of Agriculture Office of Communications (OC) 1400 Independence Avenue, SW Washington, DC 20250

The Contracting Officer shall submit the Contractor’s Request for Press Release to the Office of Communications for approval. The Contractor shall not release any information to the public without official OC approval from the Contracting Officer.

Return of Data Data and information developed, entered, and processed under this contract shall be considered Government property. All data and/or materials provided to the contractor to accomplish individual deliverables, or data generated as a result of accomplishing individual deliverables, shall be returned to the Government or destroyed at the end of each applicable deliverable, unless the contractor specifically requests and receives approval from the COR to maintain copies of this data. The Contractor is responsible for distributing data and/or materials given to members of the contractor’s team. None of this data will be released to any other Government organization or other organizations of individuals without the express written approval of USDA unless otherwise specified.

Privacy

Privacy Act Notification (Apr 1984)

The Contractor will be required to design, develop, or operate a system of records on individuals, to accomplish an agency function subject to the Privacy Act of 1974, Public Law 93-579, December 31, 1974 (5 U.S.C. 552a) and applicable agency regulations. Violation of the Act may involve the imposition of criminal penalties.

Privacy Act (Apr 1984)

(a) The Contractor agrees to:

(1) Comply with the Privacy Act of 1974 (the Act) and the agency rules and regulations issued under the Act in the design, development, or operation of any system of records on individuals to accomplish an agency function when the contract specifically identifies-

• The systems of records; and

• The design, development, or operation work that the contractor is to perform.

(2) Include the Privacy Act notification contained in this contract in every solicitation and resulting subcontract and in every subcontract awarded without a solicitation, when the work statement in the proposed subcontract requires the redesign, development, or operation of a system of records on individuals that is subject to the Act; and

(3) Include this clause, including this paragraph (3), in all subcontracts awarded under this contract which requires the design, development, or operation of such a system of records.

(b) In the event of violations of the Act, a civil action may be brought against the agency involved when the violation concerns the design, development, or operation of a system of records on individuals to accomplish an agency function, and criminal penalties may be imposed upon the officers or employees of the agency when the violation concerns the operation of a system of records on individuals to accomplish an agency function. For purposes of the Act, when the contract is for the operation of a system of records on individuals to accomplish an agency function, the Contractor is considered to be an employee of the agency.

(c)(1) "Operation of a system of records," as used in this clause, means performance of any of the activities associated with maintaining the system of records, including the collection, use, and dissemination of records.

(2) "Record," as used in this clause, means any item, collection, or grouping of information about an individual that is maintained by an agency, including, but not limited to, education, financial transactions, medical history, and criminal or employment history and that contains the person's name, or the identifying number, symbol, or other identifying particular assigned to the individual, such as a fingerprint or voiceprint or a photograph.

(3) "System of records on individuals," as used in this clause, means a group of any records under the control of any agency from which information is retrieved by the name of the individual or by some identifying number, symbol, or other identifying particular assigned to the individual.

PRIVACY TRAINING (JAN 2017)

(a) Definition. As used in this clause, "personally identifiable information" means information that can be used to distinguish or trace an individual's identity, either alone or when combined with other information that is linked or linkable to a specific individual. (See Office of Management and Budget (OMB) Circular A-130, Managing Federal Information as a Strategic Resource).

(b) The Contractor shall ensure that initial privacy training, and annual privacy training thereafter, is completed by contractor employees who-

(1) Have access to a system of records;

(2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information on behalf of an agency; or

(3) Design, develop, maintain, or operate a system of records (see also FAR subpart 24.3 and 39.105).

(c) Privacy Training:

(1) Privacy training shall address the key elements necessary for ensuring the safeguarding of personally identifiable information or a system of records. The training shall be role-based, provide foundational as well as more advanced levels of training, and have measures in place to test the knowledge level of users. At a minimum, the privacy training shall cover- (i) The provisions of the Privacy Act of 1974 ( 5 U.S.C. 552a), including penalties for violations of the Act;

(2) The appropriate handling and safeguarding of personally identifiable information;

(3) The authorized and official use of a system of records or any other personally identifiable information;

(4) The restriction on the use of unauthorized equipment to create, collect, use, process, store, maintain, disseminate, disclose, dispose or otherwise access personally identifiable information.

(5) The prohibition against the unauthorized use of a system of records or unauthorized disclosure, access, handling, or use of personally identifiable information; and

(6) The procedures to be followed in the event of a suspected or confirmed breach of a system of records or the unauthorized disclosure, access, handling, or use of personally identifiable information (see OMB guidance for Preparing for and Responding to a Breach of Personally Identifiable Information).

(7) Completion of an agency-developed or agency-conducted training course shall be deemed to satisfy these elements.

(d) The Contractor shall maintain and, upon request, provide documentation of completion of privacy training to the Contracting Officer.

(e) The Contractor shall not allow any employee access to a system of records, or permit any employee to create, collect, use, process, store, maintain, disseminate, disclose, dispose or otherwise handle personally identifiable information, or to design, develop, maintain, or operate a system of records unless the employee has completed privacy training, as required by this clause.

(f) The substance of this clause, including this paragraph (f), shall be included in all subcontracts under this contract, when subcontractor employees will-

(1) Have access to a system of records;

(2) Create, collect, use, process, store, maintain, disseminate, disclose, dispose, or otherwise handle personally identifiable information; or

(3) Design, develop, maintain, or operate a system of records.

Resources: Federal Acquisition Regulations (FAR) Privacy Act provisions (Subparts 24.1 and 24.2) and include the specified contract clauses (52.224 Parts 52.224-1 and 52.224-2) Alternate I (JAN 2017). As prescribed in 24.302(b), if the agency specifies that only its agency-provided training is acceptable, substitute the following paragraph (c) for paragraph (c) of the basic clause:

(g) The contracting agency will provide initial privacy training, and annual privacy training thereafter, to Contractor employees for the duration of this contract.

Compliance With Internet Protocol Version 6 (IPv6) In Acquiring Information Technology Any system, hardware, software, firmware or networked component (voice, video or data) developed, procured or acquired in support or performance of this contract must be capable of transmitting, receiving, processing, forwarding and storing digital information across system boundaries utilizing system packets that are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 500-267) and corresponding declarations of conformance defined in the USGv6 Test Program. In addition, this system must maintain interoperability with IPv4 systems and provide at least the same level of performance and reliability capabilities of IPv4 products:

• Specifically, any new IP product or system developed, acquired, or produced must:

o Interoperate with both IPv6 and IPv4 systems and products, and o Have available contractor/vendor IPv6 technical support for development and implementation and fielded product management.

• As IPv6 evolves, the Contractor commits to upgrading or providing an appropriate migration path for each item developed, delivered or utilized at no additional cost to the Government.

• The Contractor must provide technical support for both IPv4 and IPv6.

• Any system or software must be able to operate on networks supporting IPv4, IPv6 or one that supports both.

• Any product whose non-compliance is discovered and made known to the Contractor within one year after acceptance must be upgraded, modified or replaced to bring it into compliance at no additional cost to the Government.

Section 508 Requirements E201.1 Scope ICT that is procured, developed, maintained, or used by agencies shall conform to the Revised 508 Standards.

E205.1 General Electronic content shall comply with E205.

E205.2 Public Facing Electronic content that is public facing shall conform to the accessibility requirements specified in E205.4.

E205.3 Agency Official Communication Electronic content that is not public facing shall conform to the accessibility requirements specified in E205.4 when such content constitutes official business and is communicated by an agency through one or more of the following:

A. An emergency notification;

B. An initial or final decision adjudicating an administrative claim or proceeding;

C. An internal or external program or policy announcement;

D. A notice of benefits, program eligibility, employment opportunity, or personnel action;

E. A formal acknowledgement of receipt;

F. A survey questionnaire;

G. A template or form;

H. Educational or training materials; or I. Intranet content designed as a Web page.

E205.4 Accessibility Standard (WCAG 2.0) - Electronic content shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (Incorporated by reference, see 702.10.1).

E206.1 General. Where components of ICT are hardware and transmit information or have a user interface, such components shall conform to the requirements in Chapter 4.

E208.1 General Where an agency provides support documentation or services for ICT, such documentation and services shall conform to the requirements in Chapter 6.

E301 General

E301.1 Scope. The requirements of Chapter 3 shall apply to ICT where required by 508 Chapter 2 (Scoping Requirements), 255 Chapter 2 (Scoping Requirements), and where otherwise referenced in any other chapter of the Revised 508 Standards or Revised 255 Guidelines.

E302 Functional Performance Criteria

302.1 Without Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.

302.2 With Limited Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.

302.3 Without Perception of Color. Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.

302.4 Without Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.

302.5 With Limited Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.

302.6 Without Speech. Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.

302.7 With Limited Manipulation. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.

302.8 With Limited Reach and Strength. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.

302.9 With Limited Language, Cognitive, and Learning Abilities. ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.

503.1 General Applications shall conform to 503.

603.1 General. ICT support services including, but not limited to, help desks, call centers, training services, and automated self-service technical support, shall conform to 603.

603.2 Information on Accessibility and Compatibility Features. ICT support services shall include information on the accessibility and compatibility features required by 602.2.

603.3 Accommodation of Communication Needs. Support services shall be provided directly to the user or through a referral to a point of contact. Such ICT support services shall accommodate the communication needs of individuals with disabilities.

Software Line Item Data The contractor shall provide line item pricing data on all software licenses provided to USDA at award and/or during performance of the contract/order by completing the Software License Line Item Data form found at https://forms.office.com/Pages/ResponsePage.aspx?id=5zZb7e4BvE6GfuA8-g1Gl2SXbFM93shIsb61_oKTJ09UMFhHRU5UWllPS0o4RE9ZTTVDVFRUWEM0NS4u. The form shall be completed within 10 days of award or 10 days of activation for licenses provided after the award date.

Software Attestation Requirement The Contractor shall provide completed Attestation Forms for all software components delivered under this contract.

This requirement applies to both custom-developed software and third-party software integrated into the final deliverables. The Contractor must submit the completed Attestation Forms at the following milestones:

• Prior to contract award.

• With each major software update or release.

• Upon request by the Contracting Officer.

The Contractor must submit the attestation to all of the following:

• Online at https://softwaresecurity.cisa.gov/software and associate USDA with the submittal.

https://forms.office.com/Pages/ResponsePage.aspx?id=5zZb7e4BvE6GfuA8-g1Gl2SXbFM93shIsb61_oKTJ09UMFhHRU5UWllPS0o4RE9ZTTVDVFRUWEM0NS4u https://forms.office.com/Pages/ResponsePage.aspx?id=5zZb7e4BvE6GfuA8-g1Gl2SXbFM93shIsb61_oKTJ09UMFhHRU5UWllPS0o4RE9ZTTVDVFRUWEM0NS4u https://softwaresecurity.cisa.gov/software

• And send an email to FY24VendorAttestations@usda.gov with the signed attestation form with a copy (cc) to the CO when complete.

The Contractor is responsible for ensuring the accuracy and completeness of the Software Attestation Forms. Any discrepancies or issues identified in the attestation must be promptly addressed and resolved by the Contractor at no additional cost to the Government. The Government reserves the right to validate the submitted Software Attestation Forms and request additional documentation or evidence to verify compliance. The Contractor shall cooperate fully and provide any requested information within ten (10) business days of the request. Failure to submit the completed Software Attestation Forms in accordance with the requirements outlined herein may result in failure to receive a contract, withholding of payments, termination of the contract for default, or other remedies as deemed appropriate by the Government.

FedRAMP Certification A cloud-hosted application for the Federal Government shall be managed at the FedRAMP Moderate Baseline or higher and shall include details on:

• Number of users of the application.

• Handling and implementing change requests.

• Patching and completing security updates.

• Meeting service level agreements. Offeror should include what service levels (such as availability) they were required to meet and if they were unable to meet them.

• Handling and correcting trouble tickets, incidents, and problem.

• Transitioning data and services to a cloud-hosted Software-as-a Service for a Federal Government at

FedRAMP Moderate Baseline or higher.

• Meeting and maintaining cybersecurity authorizations and accreditations at FedRAMP Moderate baseline or higher.

THE REMAINDER OF THIS PAGE INTENTIONALLY LEFT BLANK

mailto:FY24VendorAttestations@usda.gov

SPECIAL IT REQUIREMENTS
Cyber-Security Supply Chain Risk Management (C-SCRM)
Data Rights
Privacy
Compliance With Internet Protocol Version 6 (IPv6) In Acquiring Information Technology
Section 508 Requirements
Software Line Item Data
Software Attestation Requirement
FedRAMP Certification

File details come from the government source that posted it. Updated .