Performance Work Statement Passive RFID.docx
DOCX document 136 KB Posted
- Attached to
- Automated Inventory Management Using Passive Radiofrequency Identification Federal contract opportunity
- Solicitation number
- 36C10B22R0016
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Request for Information - Passive RFID.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Automated Inventory Management Using Passive Radiofrequency Identification
VA-22-00058687
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Veteran Health Administration Veteran Integrated Service Network 21 (VISN 21)
Automated Inventory Management Using Passive Radiofrequency Identification
Date: 3/29/2022
TAC- VA-22-00058687
PWS Version Number: 1.0
Contents
| 1.0 | BACKGROUND | 4 |
| 2.0 | APPLICABLE DOCUMENTS | 4 |
| 3.0 | SCOPE OF WORK | 7 |
| 4.0 | PERFORMANCE DETAILS | 7 |
| 4.1 | PERFORMANCE PERIOD | 8 |
| 4.2 | PLACE OF PERFORMANCE | 8 |
| 4.3 | TRAVEL | 9 |
| 5.0 | SPECIFIC TASKS AND DELIVERABLES | 9 |
| 5.1 | PROJECT MANAGEMENT | 9 |
| 5.1.1 | CONTRACTOR PROJECT MANAGEMENT PLAN | 9 |
| 5.1.2 | REPORTING REQUIREMENTS | 10 |
| 5.2 | IMPLEMENTATION AND EXPANSION | 10 |
| 5.2.1 | COMPATIBILITY REQUIREMENTS | 10 |
| 5.3 | SITE ASSESSMENT | 11 |
| 5.4 | DESIGN | 11 |
| 5.4.1 | TIME STAMP | 11 |
| 5.4.2 | WIRELESS TECHNOLOGY | 11 |
| 5.4.3 | HARDWARE AND SERVER DESIGN DOCUMENT | 12 |
| 5.5 | HARDWARE PROVISIONING AND CONFIGURATION | 12 |
| 5.5.1 | INSTALLATION AND CONFIGURATION | 13 |
| 5.6 | SOFTWARE PROVISIONING AND CONFIGURATION | 13 |
| 5.6.1 | HARDWARE-SPECIFIC SOFTWARE | 13 |
| 5.6.2 | USER INTERFACE PROVISIONING AND CONFIGURATION | 14 |
| 5.6.3 | INFOR® LBI SOFTWARE CONFIGURATION | 15 |
| 5.7 | PROFESSIONAL SERVICES | 15 |
| 5.7.1 | ASSET TAGGING | 15 |
| 5.7.2 | SYSTEM ADMINISTRATION | 16 |
| 5.7.3 | PROFESSIONAL SERVICE HOURS | 16 |
| 5.8 | ACCEPTANCE TESTING | 16 |
| 5.8.1 | PHASE 1: PERFORMANCE TESTING | 16 |
| 5.8.2 | PHASE 2: USER ACCEPTANCE TESTING | 16 |
| 5.9 | TRANSITION PLANNING | 18 |
| 5.10 | TRAINING REQUIREMENTS | 18 |
| 5.11 | WARRANTY SERVICES | 19 |
| 6.0 | GENERAL REQUIREMENTS | 19 |
| 6.1 | ENTERPRISE AND IT FRAMEWORK | 19 |
| 6.1.1 | VA TECHNICAL REFERENCE MODEL | 20 |
| 6.1.2 | FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT | 20 |
| 6.1.3 | INTERNET PROTOCOL VERSION 6 | 21 |
| 6.1.4 | TRUSTED INTERNET CONNECTION (TIC) | 22 |
| 6.1.5 | STANDARD COMPUTER CONFIGURATION | 22 |
| 6.1.6 | VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT PLAN (PLM) | 22 |
| 6.1.7 | PROCESS ASSET LIBRARY (PAL) | 23 |
| 6.1.8 | AUTHORITATIVE DATA SOURCES | 23 |
| 6.1.9 | SOCIAL SECURITY NUMBER (SSN) REDUCTION | 24 |
| 6.2 | SECURITY AND PRIVACY REQUIREMENTS | 25 |
| 6.2.1 | POSITION/TASK RISK DESIGNATION LEVEL(S) | 25 |
| 6.2.2 | CONTRACTOR PERSONNEL SECURITY REQUIREMENTS | 26 |
| 6.3 | METHOD AND DISTRIBUTION OF DELIVERABLES | 28 |
| 6.4 | PERFORMANCE METRICS | 28 |
| 6.5 | FACILITY/RESOURCE PROVISIONS | 29 |
| 6.6 | GOVERNMENT FURNISHED PROPERTY | 30 |
| 6.7 | SHIPMENT OF HARDWARE OR EQUIPMENT | 30 |
| A | ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED | 33 |
| A1.0 | CYBER AND INFORMATION SECURITY REQUIREMENTS FOR VA IT SERVICES | 33 |
| A2.0 | VA ENTERPRISE ARCHITECTURE COMPLIANCE | 33 |
| A2.1 | CONTRACTOR PERSONNEL SECURITY REQUIREMENTS | 34 |
| A3.0 | NOTICE OF FEDERAL ACCESSIBILITY LAW AFFECTING ALL ELECTRONIC AND INFORMATION TECHNOLOGY PROCUREMENTS (SECTION 508) | 34 |
| A3.1 | CONTRACTOR PERSONNEL SECURITY REQUIREMENTS | 34 |
| A3.2 | EQUIVALENT FACILITATION | 35 |
| A3.3 | COMPATIBILITY WITH ASSISTIVE TECHNOLOGY | 35 |
| A3.4 | ACCEPTANCE AND ACCEPTANCE TESTING | 35 |
| A4.0 | PHYSICAL SECURITY AND SAFETY REQUIREMENTS | 36 |
| A5.0 | CONFIDENTIALITY AND NON-DISCLOSURE | 36 |
| A6.0 | INFORMATION TECHNOLOGY USING ENERGY-EFFICIENT PRODUCTS | 38 |
| B | ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE | 40 |
| B1. | GENERAL | 40 |
| B2. | ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS | 40 |
| B3. | VA INFORMATION CUSTODIAL LANGUAGE | 41 |
| B4. | INFORMATION SYSTEM DESIGN AND DEVELOPMENT | 43 |
| B5. | SECURITY INCIDENT INVESTIGATION | 45 |
| B6. | LIQUIDATED DAMAGES FOR DATA BREACH | 46 |
| B7. | SECURITY CONTROLS COMPLIANCE TESTING | 47 |
| B8. | TRAINING | 48 |
BACKGROUND
The mission of the Department of Veterans Affairs (VA), Veteran Integrated Service Network 21 (VISN 21) is to provide benefits and services to Veterans of the United States. In meeting these goals, VISN 21 strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner.
VISN 21 currently uses CenTrak® proprietary active radiofrequency identification (active RFID) real time locating systems (RTLS) to track asset, staff, and patient locations. CenTrak® Active Asset Tracking (AT) deployed at VISN 21 Health Care Systems (HCS) is supplemented with the Infor® Location Based Intelligence (LBI) user interface (UI). The hardware and software are designed for locating assets in real time at a zonal, room-level, and within-room level accuracy.
Currently, however, active (i.e., battery powered) CenTrak® asset tracking (AT) only provides coverage for a portion of VISN 21’s assets due to the trade-off between tag size, maintenance cost (e.g., battery management), and the ability to locate assets in real time. However, it is not necessary to locate in real time the majority of non-expendable (NX) equipment at medical centers. Therefore, VISN 21 is seeking a passive (i.e., non-powered) RFID solution to complement CenTrak® active AT in locating non-expendable equipment not suitable for use with active RFID tags.
APPLICABLE DOCUMENTS
In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”
2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”
3. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
4. 10 U.S.C. § 2224, "Defense Information Assurance Program"
5. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
6. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
7. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
8. VA Directive 0710, “Personnel Suitability and Security Program,” June 4, 2010, http://www.va.gov/vapubs/
9. VA Handbook 0710, Personnel Suitability and Security Program, September 10, 2004, http://www.va.gov/vapubs
10. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
11. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003
12. Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources,” November 28, 2000
13. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
14. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
15. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998
16. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
17. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012
18. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015
19. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
20. VA Handbook 6500.2, “Management of Data Breaches Involving Sensitive Personal Information (SPI)”, January 6, 2012
21. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA Information Systems,” February 3, 2014
22. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle” March 22, 2010
23. VA Handbook 6500.6, “Contract Security,” March 12, 2010
24. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011
25. Project Management Accountability System (PMAS) portal (reference https://www.voa.va.gov/pmas/)
26. OI&T ProPath Process Methodology (reference process maps at http://www.va.gov/PROPATH/Maps.asp and templates at http://www.va.gov/PROPATH/Templates.asp NOTE: In the event of a conflict, OI&T ProPath takes precedence over other processes or methodologies.
27. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.asp)
28. National Institute Standards and Technology (NIST) Special Publications (SP)
29. VA Directive 6508, VA Privacy Impact Assessment, October 3, 2008
30. VA Directive 6300, Records and Information Management, February 26, 2009
31. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
32. OMB Memorandum, “Transition to IPv6”, September 28, 2010
33. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, February 17, 2011
34. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 20, 2014
35. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
36. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
37. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011
38. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
39. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
40. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008
41. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
42. NIST SP 800-63-2, Electronic Authentication Guideline, August 2013
43. Draft NIST Special Publication 800-157, Guidelines for Derived PIV Credentials, March 2014
44. NIST Special Publication 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012
45. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
46. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
47. VA Memorandum, VAIQ # 7011145, VA Identity Management Policy, June 28, 2010 (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
48. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
49. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf
50. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
51. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008
52. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
53. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
54. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
55. Executive Order 13514, “Federal Leadership in Environmental, Energy, and Economic Performance,” October 5, 2009
56. Executive Order 13423, “Strengthening Federal Environmental, Energy, and Transportation Management,” January 24, 2007
57. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
58. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
59. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
60. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
61. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
62. VA Directive 6071, Project Management Accountability System (PMAS), February 20, 2013
63. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
64. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
65. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
SCOPE OF WORK
The Contractor shall provide the professional services, hardware, and software required by individual Task Orders (TOs) for the implementation of a radiofrequency-based asset tagging system at VISN 21 Health Care Systems.
PERFORMANCE DETAILS
This is an Indefinite Delivery/Indefinite Quantity (IDIQ) contract. Individual TOs shall be issued on a Firm Fixed Price (FFP) basis.
The Contractor shall provide and/or acquire the services, hardware, and software required by individual TOs pursuant to the general requirements specified below.
PERFORMANCE PERIOD
The ordering period shall be three (3) years from the date of award. The period of performance (PoP) for any task order may go up to 16 months beyond the last day of the ordering period. Each TO will have its own PoP.
Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).
There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
| New Year's Day | January 1 | |
| Juneteenth | June 19 | |
| Independence Day | July 4 | |
| Veterans Day | November 11 | |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January | |||
| Washington's Birthday | Third Monday in February | |||
| Memorial Day | Last Monday in May | |||
| Labor Day | First Monday in September | |||
| Columbus Day | Second Monday in October | |||
| Thanksgiving | Fourth Thursday in November |
PLACE OF PERFORMANCE
The place of performance shall be identified in individual Task Orders within VISN 21. The list of current VISN 21 Health Care Systems and their addresses are given in Table 1.
| ID |
| Name |
| Address |
| 570 |
| Central California Health Care System (CCHCS) |
| 2615 E. Clinton Ave. Fresno, CA 93703-2286 |
| 612 |
| Northern California Health Care System (NNHCS) |
| 10535 Hospital Way Mather, CA 95655 |
| 640 |
| Palo Alto Health Care System (PAHCS) |
| 3801 Miranda Ave. Palo Alto, CA 94304 |
| 654 |
| Sierra Nevada Health Care System (SNHCS) |
| 975 Kirman Avenue Reno, NV 89502 |
| 662 |
| San Francisco Health Care System (SFHCS) |
| 4150 Clement St. San Francisco, CA 94121 |
| 593 |
| North Las Vegas Health Care System (NLVHCS) |
| 6900 N. Pecos Road North Las Vegas, NV 89086 |
| 459 |
| Pacific Islands Health Care System (PIHCS) |
| 459 Patterson Road Honolulu, HI 96819 |
Table 1: VISN 21 Health Care Systems
TRAVEL
The Government anticipates travel under this effort to perform the tasks associated with the effort. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.
The total estimated number of trips in support of the program related meetings for this effort will be dependent on each Task Order.
SPECIFIC TASKS AND DELIVERABLES
Individual TO(s) may encompass more than one functional area listed below. Functional area details are described to provide greater insight into the complexity and uniqueness of some potential TO requirements covered by this Performance Work Statement (PWS). Functional area requirements are not mutually exclusive, and an individual TO requirements may fall within multiple functional areas.
PROJECT MANAGEMENT
CONTRACTOR PROJECT MANAGEMENT PLAN
The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated with approval from the Government. The Contractor shall update and maintain the CPMP throughout the period of performance.
Deliverable:
A. Contractor Project Management Plan
REPORTING REQUIREMENTS
The Contractor shall provide the COR with Monthly Progress Reports (MPR) in electronic format. The MPR shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including a plan and timeframe for resolving the issue. The Contractor shall monitor performance against the CPMP and report all deviations. The Contractor shall communicate with the Government any potential issues that may arise. The MPR reports shall reflect progress as of the last day of the preceding month.
Deliverable:
A. Monthly Progress Report
Implementation and expansion
COMPATIBILITY REQUIREMENTS
Due to the existing implementation of CenTrak® active RTLS and Infor® LBI at VISN 21 Medical Centers and CBOCs, the following requirements apply to all specific tasks and deliverables in this PWS:
· The Contractor shall propose a hardware solution that is compatible with Infor® LBI. Location and asset data from the proposed passive RFID system must be transmissible to Infor LBI® and conform to the CenTrak® and Infor® Data Standards.
· The Contractor shall propose a software interface that is compatible with CenTrak® hardware and software for asset tracking. The proposed software and user interfaces must be able to accept CenTrak® location data.
· The Contractor shall propose a solution that is compatible with CenTrak® and Infor® data architecture.
The requirements above ensure that there is possible cross-talks between the passive and active asset management systems at VISN 21. In addition, VA VISN 21 requires that:
· The Contractor shall provide proof as an authorized reseller or distributor for the original equipment manufacturer (OEM) and remain an authorized reseller or distributor for the duration of the POP.
· The Contractor shall provide proof as an authorized reseller or distributor for the original software manufacturer of the user interfaces.
Site Assessment The Contractor shall perform a detailed site assessment at the site(s) identified in individual TOs to provide a full scope of requirements for site needs. A VAMC or CBOC in a different city shall be considered a different site for site assessment purposes. The Contractor shall coordinate with the COR and site POCs to schedule site assessments. The Contractor shall conduct a pre-assessment conference call at least two (2) weeks in advance of the site assessment. The Contractor shall coordinate the call with the COR to ensure attendance by facility stakeholders and subcontractor(s).
The Contractor shall provide a Site Assessment Report that outlines all requirements and line items per site to include hardware, software and services. Line items shall be listed in the format of the price cost schedule with the description of the item, quantity, cost per unit, and CLIN number. The Assessment Report shall include narrative and diagrams where appropriate to demonstrate understanding of the project goals. The assessment shall include a timeline for the entire project lifecycle with the following milestones defined as a minimum:
1. Equipment installation schedule
2. Limited installation capability demonstration
3. Equipment installation completion
4. User acceptance testing
5. User training
Milestones may be based on TO award date. The limited installation capability demonstration is defined to be a technical feasibility report in which the steps required for complete equipment installation is detailed for each task order.
Deliverables A. Site Assessment Report Design
Time Stamp The Contractor shall ensure all applications synchronize with internal VA site time standard. The synchronization of time on this network is critical in every aspect of managing, securing, planning, and debugging as it involves determining when an event occurred.
Wireless Technology The Contractor shall utilize the existing Wi-Fi infrastructure at each facility for the implementation of the technology. The Contractor shall notify the Government when known existing Wi-Fi infrastructure at each facility is not available or is insufficient and supplemental technologies will be required where Wi-Fi is not available or insufficient to achieve the resolution objectives of the applications.
Hardware and Server Design Document The Contractor shall ensure there is a Hardware and Server Design Document (HSDD) for every site. The Contractor shall update the HSDD throughout the remaining implementation so that it remains current with the existing design. The HSDD shall include:
1. Proposed changes, corrections and/or updates to the VA-provided maps and Engineering Space Files as noted during the Contractor’s site validation.
2. Proposed location for installation of hardware.
3. The Contractor shall provide a draft of the server configuration and architecture that shall be configured and optimized to meet the needs of the facility. This draft documentation shall include a diagram that lays out the server requirements at each location along with expected bandwidth utilization for the WAN links, expected application latency requirements, server specification (including power, BTUs, and network connections).
4. The Contractor shall provide the specification for the number of tags that can be supported per server.
Deliverables
A. Hardware and Server Design Document (HSDD)
Hardware Provisioning and Configuration The Contractor shall provide all necessary hardware components delivered to sites as specified in the Hardware and Server Design Document (HSDD) and ordered at the task order level. The hardware provided shall be compatible with VISN 21’s existing interface software and additional proposed interface software. Hardware components shall include, but not limited to, handheld RFID scanners, passive RFID tags, infrastructure components. Wireless hardware proposed shall be FIPS-compliant.
The Contractor shall coordinate with the COR and site POCs to schedule delivery and receive written or e-mail COR concurrence is required to ship hardware. The Contractor shall provide a copy of the signed Facility Receiving Report to the COR once components are delivered. The Contractor shall submit a copy of the signed Facility Receiving Reports for each site. The Facility Receiving Report shall contain:
1. Confirmation of the order and delivery of the components
2. Reconciliation (if any) of what was planned to be delivered versus what was delivered. Details of where items were delivered, what time they were delivered, and who from the Government received them.
Deliverable A. Facility Receiving Report
Installation and Configuration The Contractor shall install all hardware components delivered to sites. The Contractor shall coordinate with the COR and site POCs to schedule installation.
The Contractor shall ensure that hardware installed and configured do not interfere with other wireless technologies in the same environment. In the event of interference, the Contractor shall propose a plan for resolution of interference to the Government.
The Contractor shall install supporting hardware and components to blend in (or not be visible at all) with the general surface treatments of the facility. The Contractor shall install components to have minimal impact on the business operations of the facility and meet applicable infection control and health and safety requirements such as Joint Commission and local Infection Control Risk Assessment (ICRA) findings and standards. Hardware installation shall occur during normal business hours. This may include use of containment units for any above the ceiling work.
When installation of an infrastructure device requires a data connection, the Contractor shall use existing data connections whenever possible. If a new data connection and cabling is required, the Contractor shall provide the cabling and the cabling services.
The Contractor shall provide rendered maps of installed infrastructure device locations (i.e., “as-built drawings”).
Deliverable A. Infrastructure Device Maps
Software Provisioning and Configuration
Hardware-Specific Software The Contractor shall provide and install all necessary software compatible with the proposed hardware (i.e., middleware). The Government will provide virtual servers. If a virtual server platform is not feasible, the Contractor shall provision compatible physical servers for software installation. The Contractor shall provide a Software Installation Report. This Report shall include:
1) A list of all servers configured
2) Software and licenses that are installed on each server
3) Software validations
4) Server data architecture diagram
Deliverable A. Software Installation Report
User Interface Provisioning and Configuration The User Interface (UI) shall be a web-based UI and include at minimum the following capabilities:
1. Web-based UI
2. Display individual item information to allow users to uniquely identify individual assets
3. Displays facility assets in a list view; assets may be searched by asset number (identifier), asset type, asset model, asset manufacturer, or tag ID
4. Display facility assets in a map view; asset location shall be displayed on a facility floorplan in a pictographic method
5. Asset information may be exported from the system in an excel format
6. Access past year of asset location history (capability may be developed)
7. Fully customizable business rules
8. Asset egress alerts (capability may be developed as designated by VA)
9. Report generation and integration with Microsoft® Power BI
The UI shall be capable of interfacing with the following automated inventory management system / computerized inventory and maintenance management systems (CMMS):
1. VA Automated Engineering Management System/Medical Equipment Reporting System (AEMS-MERS)
2. IBM Maximo® Enterprise Asset Management System (Maximo EAM)
3. Nuvolo©
The interface for data exchange between the UI and VA AEMS-MERS/Maximo®/Nuvolo© shall at least be bidirectional and have at least the following capabilities:
1. Provide the UI and VA-AEMS/MERS and Maximo AEM the ability to identify a unique asset using a combination of unique asset ID and facility number.
2. Update the UI at least once every 24 hours.
3. Allow the UI shall display individual asset information from VA-AEMS/MERS and Maximo AEM to allow user to unique identify individual assets.
4. Provide designated users the capability to adjust the periodicity of bidirectional updates.
5. Post inventory date and time to VA-AEMS/MERS and Maximo AEM
6. Have the option to be run on demand
7. Update the UI with space creation from VA-AEMS/MERS and Maximo AEM
8. Update the UI when an asset has been decommissioned in VA-AEMS/MERS and Maximo AEM
9. Stop sending location/inventory date updates to VA-AEMS/MERS and Maximo AEM when assets are marked as decommissioned in the UI.
Infor® LBI Software Configuration VISN 21 currently uses Infor® LBI as a UI for active RFID-based asset tracking. To streamline clinical and operational workflow, compatibility with Infor® LBI is required for all proposed hardware, software, and user interfaces. Therefore, if the proposed UI is not Infor® LBI, the Contractor shall provide configuration services for integrating the proposed passive RFDI system interfaces with Infor LBI®. The Contractor must maintain a current Reseller Agreement with Infor® for all tasks requiring Infor® LBI software installation, configuration, and maintenance.
Per hardware design changes and/or VA reconfiguration requirements, the Contractor shall update rendered maps in Infor® LBI application. Naming shall conform to data standards as outlined in the RTLS Enterprise Data Architecture (EDA) Standards Workbook. Configuration changes shall be scoped during the site assessment at each facility.
Professional Services
Asset Tagging The Contractor shall provision all hardware and software required for tagging and commissioning of assets, including passive RFID tags. The Contractor shall create and provide a Tagging and Commissioning Plan for sites prior to beginning the tagging process for review and approval by the Government. Once approved, this plan shall be integrated into the CPMP. This Plan shall include:
1. Identification of all Asset Groups and Assets to be tagged.
2. A schedule during normal business hours (not to interrupt business operations) to tag and commission all assets.
3. Guidance and instructions on tag placement (unless provided by the Government).
4. Method for quality control of tag placement and commissioned data.
5. Method for taking corrective actions on misplaced tags, defective tags, assets that cannot be located, incorrect information in the database, and other errors that can occur during the tagging and commissioning process.
6. Documentation to allow the Government to perform the tagging and commissioning process.
Upon COR approval of the Tagging and Commissioning Plan, the Contractor shall execute and report on tagging and commissioning operations weekly with the COR either through email or status calls, and in the Monthly Progress Reports.
Deliverable A. Tagging and Commissioning Plan B. Tagging and Commissioning Instruction System Administration The Contractor shall provide Database and System Administration services during the implementation and warranty period. The System Administration Services shall include:
1. Perform periodic system health checks on servers and databases, including monitoring application logs
2. Security compliance and remediation of application related vulnerabilities
3. Apply Monthly OS security patches provided by VA OIT
4. Troubleshoot connectivity issues
5. Troubleshoot startup/shutdown server and application issues
6. Implement software updates and upgrades
Professional Services Hours The Contractor shall provide service hours as requested by the Government for all tasks associated with:
1. System and software configuration and administration
2. Software and hardware compliance with VA standards
3. Workflow solutions and implementation
4. Project planning and management
5. Analytics and business intelligence
Acceptance testing The Contractor shall create and provide an Acceptance Test Plan that includes two phases. A single Acceptance Test Plan is required to define testing methodology for all TOs. The Contractor shall not execute testing on any TO until the Government approves the Acceptance Test Plan.
Deliverable A. Acceptance Test Plan
Phase 1: Performance Testing The Contractor shall perform testing on the system and/or system enhancements to certify Proof of Performance to include room-level location accuracy of 95%. The Contractor shall test and verify that all system functions and specification requirements are met and operational, and no unwanted effects, such as signal distortion or interference with other facility devices are present. The Contractor shall provide VA with a copy of the performance test plan methodology and test results.
If the system does not meet requirements and additional remediation hardware is required, the Contractor shall provide a list that outlines additional requirements per site to include hardware, software, and service in the Facility Remediation Hardware Report.
The Contractor shall provide the Final Hardware Deployment Document (FHDD). The FHDD shall include complete hardware configuration, including any additional hardware purchased under this contract. This document shall be in the format of a .pdf floor map layout and in a table excel spreadsheet format. This document shall include the final quantity and location of hardware identified in the Hardware Design Document that was installed to meet the goals of the applications being deployed at each facility. The information provided shall include the Hardware Unique Identification Device #, Hardware Serial Number, and Building, Floor, and Room number where it was installed.
Deliverables:
A. Performance Test Plan B. Facility Remediation Hardware Report C. Final Hardware Deployment Document
Phase 2: User Acceptance Testing The Contractor shall schedule an acceptance test date and provide VA 30 days written notice prior to the date the acceptance test is expected to begin. The notification of the acceptance test shall include the expected length (in time) of the test(s). The Contractor shall provide certified/qualified personnel to assist VA with performing this testing. The Contractor shall provide VA with a copy of the acceptance test plan methodology and test results. At the Government’s discretion, the test results may be accepted without meeting the above location accuracy requirements.
At a minimum, the Acceptance Test Report shall provide a rating of location accuracy for each of the locations within scope to the smallest division requested (e.g., bay accuracy – room accuracy – area accuracy – floor accuracy – building accuracy). The report shall be in an excel format and provide the tag ID, location, division, and accuracy rating (does or does not meet defined requirements). The overall location accuracies shall be calculated and displayed respectively in the report. The proposed format of the Acceptance Test Report shall be included in the Acceptance Test Plan.
Deliverables:
A. User Acceptance Test Plan B. Facility Acceptance Test Report Transition Planning The Contractor shall develop a Transition Plan for sites after implementation. The Transition Plans shall include a detailed procedure to transition all duties to Government staff by the end of this contract in the form of a RACI matrix. The Contractor shall submit a Transition Plan that addresses transitioning daily operational oversight of the system of at each facility including all hardware and software as well as maintenance, repair and configuration management procedures. Once the Transition Plans are approved by the Government, the Contractor shall execute those plans.
The Contractor shall provide User and Technical Manuals that shall include all components of the system.
1. Two (2) copies of operator's instruction manuals per facility
2. Two (2) copies of complete technical service manuals including detailed troubleshooting guides, necessary diagnostic software, service keys, schematic diagrams, and parts lists per facility
Deliverables:
A. Transition Plan B. User and Technical Manuals
Training Requirements The Contractor shall develop and provide a Training Plan and deliver onsite or remote training, workshop, and consulting services as designated by VA. The Contractor shall provide multiple offerings for each user interface and software to be used. The Contractor shall provide training at the request of the COR. The Contractor shall provide certified/qualified personnel and conduct both on-site and remote training sessions for:
1. Biomedical Engineering technical trainings for asset tracking
2. Application training for inventory managers
3. Inventory management training for asset tracking
4. Non-technical user and administrator training for asset tracking
The Contractor shall perform up to 8-hours of training within a 24-hour period. The contractor can break-up training events in blocks during each workday to accommodate different shifts.
The Contractor shall submit a Training Plan for each training for review and approval by the COR. The Training Plan shall include, at a minimum:
1. Training locations, training dates, and training times
2. Format, method and / or delivery of training (e.g. onsite, web based)
3. Training audience (e.g. technical repair, system user, system administrator)
4. Instructor profile and content information
The Contractor shall also provide Training Material and Schedules for each training event and complete those events in accordance with the approved Training Plan. Once each Training Event is completed, the Contractor shall provide the following:
1. Facility-specific list of the attendees for each training session
2. The Contractor staff that conducted the training
Deliverables:
A. Training Plan B. Training Material and Schedules C. List of Attendees Warranty Services All new equipment, hardware, and services performed under each TO shall be covered under the manufacturer’s warranty and shall include all parts and labor and technical support for one (1) year following acceptance by VA. The Contractor shall perform all maintenance during the system warranty period. The Contractor shall oversee all sub-Contractor support, maintenance, and warranties. Service Maintenance Agreements (SMA) for hardware and software provided under each TO shall be included respectively during the warranty period. The Contractor shall provide Database and System Administration services during the warranty period. The Contractor shall provide additional provision warranty and SMA as required by the Government beyond the 1-year warranty period. The Contractor shall provide a Warranty Status Report, detailing hardware and software specifications and warranty end dates, in accordance with the start of each warranty period.
VA staff members will handle initial trouble calls from end users. Issues, which cannot be resolved by VA staff, will be referred to the Contractor by VA technical support staff. The Contractor shall provide methods for requesting technical support from the Contractor including telephone and e-mail. The Help Desk shall be staffed from 8am to 5pm MDT. The help desk shall respond to calls within 2 hours after receiving the initial call. The Contractor shall coordinate with the VA POC to schedule on-site service; service shall be completed within 15 business days of the reported incident.
Deliverable:
A. Warranty Status Report
GENERAL REQUIREMENTS
ENTERPRISE AND IT FRAMEWORK
VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.
FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.
TRUSTED INTERNET CONNECTION (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.
STANDARD COMPUTER CONFIGURATION
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT (PLM)
The Contractor shall support VA efforts IAW the updated Veteran Focused Integration Process (VIP) and Product Line Management (PLM). The major focus of the new VIP is on Governance and Reporting and is less prescriptive, with a focus on outcomes and continuous delivery of value. Product Line Management (PLM) is a framework that focuses on delivering functional products that provide the highest priority work to customers while delivering simplified, reliable, and practical solutions to the business, medical staff, and our Veterans. The VIP Guide is a companion guide to the PLM Playbook and can be found at: https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 and the PLM Playbook can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946. The PLM Playbook pivots from project-centric to product-centric delivery and contains descriptive practices that focuses on outcomes. The PLM Playbook contains a set of “plays” that implement Development, Security, and Operations (DevSecOps) principles and processes such as automated development, continuous integration/continuous delivery, and release on demand. The PLM Playbook details how product lines implement Lean-Agile principles, methods, practices, and techniques through levels of maturity. VIP and PLM are the authoritative processes that IT projects must follow to ensure development and delivery of IT products.
PROCESS ASSET LIBRARY (PAL)
The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.
AUTHORITATIVE DATA SOURCES
The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:
1. Interfacing with VA’s Master Person Index (MPI) (formerly the Master Veteran Index (MVI)) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .