Amendment_01.pdf

PDF 37 KB Posted

Attached to
Role Based Information Security Awareness Training Federal contract opportunity
Solicitation number
PC-16-Q-102
Issued by
Peace Corps

About this file

Amendment 01 and Responses to Questions

View the file

Other files for this federal contract opportunity

Other files attached to Role Based Information Security Awareness Training, newest first.
File Type Posted
Attachment_A_Domestic_Vendor_File_Request_Form.pdf PDF
Q A_01.pdf PDF
RFQ_PC-16-Q-102.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

AMENDMENT OF SOLICITATION NO.: RFQ: PC-16-Q-102

AMENDMENT NO.: 01

EFFECTIVE DATE: September 16, 2016

ISSUED BY:

Office of Acquisitions and Contract Management (OACM) Peace Corps 1111 20th Street, NW Washington, DC 20526

Point of Contact: Shanelle Jackson, Contract Specialist

NAME AND ADDRESS OF RESPONDENTS: To All Responders

Questions and answers to the above numbered Solicitation are as set forth below.

DESCRIPTION OF AMENDMENT

PURPOSE: To clarify the Solicitation requirements by amending Section 2.3 General Requirements and responding to questions submitted under the Solicitation. Unless specifically noted, all specifications remain unchanged.

Amendment:

1. Section 2.3 General Requirements is updated as follows:

The Contractor shall be responsible for providing online information security awareness training that meets all FISMA(Federal Information Security Management Act) requirements. This shall include:

• Number of user licenses – 400

• Allow Peace Corps administrator access to:

o Create other administrators o Assign classes/Shift classes o Add role based users o Modify role based users o Delete role based users o All reporting functions o Tracking

• Web-based course delivery

• Website must be available 24 by 7 to accommodate users worldwide

• Languages: Course should be offered in English and Spanish with the potential for content to be delivered and translated in additional languages.

• Annual awareness component and initial onboarding component

• Must meet FISMA, National Institute of Standards and Technology(NIST), Office Of Personnel

Management (OPM),Health Insurance Portability and Accountability Act (HIPAA), and Federal Risk and Authorization Management Program (FedRAMP) guidelines

• Must have a testing element modifiable for Peace Corps

• Help desk support via telephone and email must be available during standard business hours (9AM to

6:00 PM)

*Note: If a third party hosts the course, then it must be on a FedRAMP certified IaaS or a site with another federal agency Authority To Operate(ATO). The preference is to host the content internally.

Questions:

1. What is the place of performance: Government site or contractor site?

Answer: The product must be delivered as web based modules to be hosted on internal agency LMS resources. If a third party hosts the course, then it must be on a FedRAMP certified IaaS or a site with another federal agency Authority To Operate(ATO). The preference is to host the content internally.

2. What is the total anticipated seat time for all of the Role Based Information Security Awareness Training web-based courses?

Answer: Generally, one course should take no longer than an hour to complete. With a role-based course for 1) IT Admins and Engineers, 2) IT Security Managers, and 3) IT Security Specialists offered, approximately 3 hours total seat time if one individual had to take all.

3. Is there existing Role Based Information Security Awareness Training?

Answer: Yes, for elevated account users only; the 3 courses noted in response 2. do not have existing content.

4. If there is existing Role Based Information Security Awareness Training, what percent needs to be revised?

Answer: 100% (see response 3.)

5. Will the Peace Corps provide subject matter experts to provide the content for the Role Based Information Security Awareness Training, or will the contractor be expected to have subject matter expertise?

Answer: It is expected the contractor will have SMEs to provide the FISMA compliant training content for the 3 courses (or related) noted in response 2.

6. How much overlap is there between content for the various roles (e.g., IT Security Managers vs. IT Administrators and Engineers)?

Answer: Overlap exists, but the content should be tailored to the role it addresses.

7. Does the Role Based Information Security Awareness Training need to work on mobile devices (e.g., smart phones and tablets)?

Answer: This is a not a requirement of the RFQ, however it is acceptable.

8. What are the minimum browser requirements for the Role Based Information Security Awareness Training (e.g., Internet Explorer 8, Chrome 50)?

Answer: IE 11, Chrome 52 (current versions)

9. What level of interactivity is desired for the Role Based Information Security Awareness Training courses?

Answer: Desired – level 3 for most users. However, some users would do well with level 4, while others may do better with level 1 or 2 (varies due to international audiences receiving training; language barriers; various learning techniques).

The levels are defined as follows:

a. Level 1: Passive - The learner is introduced to ideas and conceptual information in a linear format such as a PowerPoint presentation with minimal interactivity.

b. Level 2: Limited Participation - The learner is required to recall more information and makes simple responses to instructional clues.

c. Level 3: Complex Participation - The learner has increased control over the lesson and makes decisions using varying techniques in response to instructional cues and applies complex information to solve a problem or produce results.

d. Level 4: Real-Time Participation - The learner is directly involved in a life-like set of complex cues and responses within a real-time simulated 3D environment.

Learners recall large amounts of information and demonstrate specific tasks with measurable results.

10. If levels 3 or 4 will be required, please describe the types of learner participation that are anticipated (e.g., navigation in a 3D environment, branching text-based scenarios).

Answer: Scenario based options, questions open to more than one way pathway for moving through course depending on response, video or 3-D enhancements where applicable.

11. Is audio narration required for the Role Based Information Security Awareness Training courses?

Answer: No

12. Will the contractor be required to translate the content into other languages? If so, which languages will be required?

Answer: Yes, see the amendment to Section 2.3 General Requirements above.

Will any video be required for the Role Based Information Security Awareness Training courses? If the contractor is expected to create video:

a. Approximately how many minutes of video will need to be created?

b. What type of video will it be (e.g., interviews, animations, promotional video)?

Answer: Video is not required, but would be a welcome enhancement to course content where applicable.

13. Does The Peace Corps have a specific development tool (e.g., Adobe Captivate, Articulate) that the contractor must use to develop the web-based modules?

Answer: No

14. The RFQ mentions tracking of training completions. What does this mean from a learner’s vantage point? Are learner’s informed in some fashion of their progress relative to a “plan” of some kind? If there are learning plans/paths, how are learners assigned to them?

Answer: Currently, we do not have learning pathways (requirements, pre-requisites) identified. We do have a minimum requirement for overall Annual CE credits. Completion indicators are required for learners to tracker their own progress, providing proof of compliancy.

15. The RFQ mentions that the system should support role-based users. Aside from administrators and learners, what other roles are expected? Is there a manager type role that extends restricted administrator privileges to some users? If so, how are users assigned to such a role?

Answer: Roles include CISO, CIO, agency heads, security/system/network engineers, ISSOs, IT Security Specialists, System Owners. Currently, users with restricted privileges are associated with accounts (not necessarily a given ‘role’) and must also complete the already existing Privileged User Training.

16. How are new users added to the system? Is there a presumed integration with another system that tracks employee status information and/or organizational hierarchy details (e.g., HRIS system)?

Answer: Users can be uploaded to the LMS and removed, as needed, with login credentials provided; or, can be integrated with our Active Directory (AD) to provide single sign on.

17. How are users authenticated into the system? Is there a presumed integration with another system to support authentication (e.g., SSO)?

Answer: See response 17.

18. The RFQ mentions reporting capabilities. What reports are required? Are all reports predefined, or is there a presumed “adhoc reporting” capability?

Answer: Reports to include, but not limited to, Status Completion (to include user invitation date, start date, completion date, course status-not started, incomplete, complete, etc), Roster, Course Breakdown Status (status completion but broken down by course). All reports aren’t predefined, and there is a “adhoc reporting” capability presumed.

19. Are there any specific theme/layout specifications for the web application?

Answer: Branded with Peace Corps logo, ideally ‘look and feel’ of Peace Corps.

20. The RFQ mentions this is a worldwide-accessible technology. Are multiple languages supported? Will access be extended to Peace Corps employees operating out of Globally Embargoed Countries (GECs)?

Answer: Yes, multiple languages, also refer to response 12. Yes, Peace Corps has Posts in GECs and training is extended to those staff.

21. The RFQ mentions web-based course delivery. Are all courses presumed to be hosted by the same vendor, or are there courses from 3rd party training providers (e.g., Skillsoft) as well?

Answer: The product must be delivered as web based modules to be hosted on internal agency LMS resources. If a third party hosts the course, then it must be on a FedRAMP

22. Could you provide information regarding how the current Security Awareness Training is administered to users?

Answer: On demand training is administered online; previous annual requirement provided online, through 3rd party.

23. In addition to the requested Learning Management System, will the Peace Corps require hosting services as well? Or will the Learning Management System (and the associated training it will manage) reside on Peace Corps servers?

Answer: The product must be delivered as web based modules to be hosted on internal agency LMS resources. If a third party hosts the course, then it must be on a FedRAMP

24. Will any information (student records, user accounts, etc.) from the current Security Awareness Training need to be migrated to the new System?

Answer: No, data migration is not required.

25. What is the expected seat-time duration of the revised Security Awareness Training?

Answer: See response 2.

26. What is the expected level of interactivity of the revised Security Awareness Training?

Answer: Scenario based options, questions open to more than one pathway for moving through course depending on response, video or 3-D enhancements where applicable (See response 9. and 10.)

27. What is the expected scope of multi-media (e.g., use of audio, video, animation, etc.) for the revised Security Awareness Training?

Answer: Should have the capabilities of including multi-media where applicable.

28. Does the Combined Synopsis/Solicitation under solicitation number PC16Q102 contain requirements similar to a current contract? If possible, please provide the current contract number. Or, is this a new requirement for the government?

Answer: This is considered to be a new requirement.

File details come from the government source that posted it. Updated .