Performance Work Statement Passive RFID.docx

DOCX document 136 KB Posted

Attached to
Automated Inventory Management Using Passive Radiofrequency Identification Federal contract opportunity
Solicitation number
36C10B22R0016
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

View the file

Other files for this federal contract opportunity

Other files attached to Automated Inventory Management Using Passive Radiofrequency Identification, newest first.
File Type Posted
Request for Information - Passive RFID.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Automated Inventory Management Using Passive Radiofrequency Identification

VA-22-00058687

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Veteran Health Administration Veteran Integrated Service Network 21 (VISN 21)

Automated Inventory Management Using Passive Radiofrequency Identification

Date: 3/29/2022

TAC- VA-22-00058687

PWS Version Number: 1.0

Contents

1.0BACKGROUND4
2.0APPLICABLE DOCUMENTS4
3.0SCOPE OF WORK7
4.0PERFORMANCE DETAILS7
4.1PERFORMANCE PERIOD8
4.2PLACE OF PERFORMANCE8
4.3TRAVEL9
5.0SPECIFIC TASKS AND DELIVERABLES9
5.1PROJECT MANAGEMENT9
5.1.1CONTRACTOR PROJECT MANAGEMENT PLAN9
5.1.2REPORTING REQUIREMENTS10
5.2IMPLEMENTATION AND EXPANSION10
5.2.1COMPATIBILITY REQUIREMENTS10
5.3SITE ASSESSMENT11
5.4DESIGN11
5.4.1TIME STAMP11
5.4.2WIRELESS TECHNOLOGY11
5.4.3HARDWARE AND SERVER DESIGN DOCUMENT12
5.5HARDWARE PROVISIONING AND CONFIGURATION12
5.5.1INSTALLATION AND CONFIGURATION13
5.6SOFTWARE PROVISIONING AND CONFIGURATION13
5.6.1HARDWARE-SPECIFIC SOFTWARE13
5.6.2USER INTERFACE PROVISIONING AND CONFIGURATION14
5.6.3INFOR® LBI SOFTWARE CONFIGURATION15
5.7PROFESSIONAL SERVICES15
5.7.1ASSET TAGGING15
5.7.2SYSTEM ADMINISTRATION16
5.7.3PROFESSIONAL SERVICE HOURS16
5.8ACCEPTANCE TESTING16
5.8.1PHASE 1: PERFORMANCE TESTING16
5.8.2PHASE 2: USER ACCEPTANCE TESTING16
5.9TRANSITION PLANNING18
5.10TRAINING REQUIREMENTS18
5.11WARRANTY SERVICES19
6.0GENERAL REQUIREMENTS19
6.1ENTERPRISE AND IT FRAMEWORK19
6.1.1VA TECHNICAL REFERENCE MODEL20
6.1.2FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT20
6.1.3INTERNET PROTOCOL VERSION 621
6.1.4TRUSTED INTERNET CONNECTION (TIC)22
6.1.5STANDARD COMPUTER CONFIGURATION22
6.1.6VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT PLAN (PLM)22
6.1.7PROCESS ASSET LIBRARY (PAL)23
6.1.8AUTHORITATIVE DATA SOURCES23
6.1.9SOCIAL SECURITY NUMBER (SSN) REDUCTION24
6.2SECURITY AND PRIVACY REQUIREMENTS25
6.2.1POSITION/TASK RISK DESIGNATION LEVEL(S)25
6.2.2CONTRACTOR PERSONNEL SECURITY REQUIREMENTS26
6.3METHOD AND DISTRIBUTION OF DELIVERABLES28
6.4PERFORMANCE METRICS28
6.5FACILITY/RESOURCE PROVISIONS29
6.6GOVERNMENT FURNISHED PROPERTY30
6.7SHIPMENT OF HARDWARE OR EQUIPMENT30
AADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED33
A1.0CYBER AND INFORMATION SECURITY REQUIREMENTS FOR VA IT SERVICES33
A2.0VA ENTERPRISE ARCHITECTURE COMPLIANCE33
A2.1CONTRACTOR PERSONNEL SECURITY REQUIREMENTS34
A3.0NOTICE OF FEDERAL ACCESSIBILITY LAW AFFECTING ALL ELECTRONIC AND INFORMATION TECHNOLOGY PROCUREMENTS (SECTION 508)34
A3.1CONTRACTOR PERSONNEL SECURITY REQUIREMENTS34
A3.2EQUIVALENT FACILITATION35
A3.3COMPATIBILITY WITH ASSISTIVE TECHNOLOGY35
A3.4ACCEPTANCE AND ACCEPTANCE TESTING35
A4.0PHYSICAL SECURITY AND SAFETY REQUIREMENTS36
A5.0CONFIDENTIALITY AND NON-DISCLOSURE36
A6.0INFORMATION TECHNOLOGY USING ENERGY-EFFICIENT PRODUCTS38
BADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE40
B1.GENERAL40
B2.ACCESS TO VA INFORMATION AND VA INFORMATION SYSTEMS40
B3.VA INFORMATION CUSTODIAL LANGUAGE41
B4.INFORMATION SYSTEM DESIGN AND DEVELOPMENT43
B5.SECURITY INCIDENT INVESTIGATION45
B6.LIQUIDATED DAMAGES FOR DATA BREACH46
B7.SECURITY CONTROLS COMPLIANCE TESTING47
B8.TRAINING48

BACKGROUND

The mission of the Department of Veterans Affairs (VA), Veteran Integrated Service Network 21 (VISN 21) is to provide benefits and services to Veterans of the United States. In meeting these goals, VISN 21 strives to provide high quality, effective, and efficient Information Technology (IT) services to those responsible for providing care to the Veterans at the point-of-care as well as throughout all the points of the Veterans’ health care in an effective, timely and compassionate manner.

VISN 21 currently uses CenTrak® proprietary active radiofrequency identification (active RFID) real time locating systems (RTLS) to track asset, staff, and patient locations. CenTrak® Active Asset Tracking (AT) deployed at VISN 21 Health Care Systems (HCS) is supplemented with the Infor® Location Based Intelligence (LBI) user interface (UI). The hardware and software are designed for locating assets in real time at a zonal, room-level, and within-room level accuracy.

Currently, however, active (i.e., battery powered) CenTrak® asset tracking (AT) only provides coverage for a portion of VISN 21’s assets due to the trade-off between tag size, maintenance cost (e.g., battery management), and the ability to locate assets in real time. However, it is not necessary to locate in real time the majority of non-expendable (NX) equipment at medical centers. Therefore, VISN 21 is seeking a passive (i.e., non-powered) RFID solution to complement CenTrak® active AT in locating non-expendable equipment not suitable for use with active RFID tags.

APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”

2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements For Cryptographic Modules”

3. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

4. 10 U.S.C. § 2224, "Defense Information Assurance Program"

5. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010

6. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

7. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

8. VA Directive 0710, “Personnel Suitability and Security Program,” June 4, 2010, http://www.va.gov/vapubs/

9. VA Handbook 0710, Personnel Suitability and Security Program, September 10, 2004, http://www.va.gov/vapubs

10. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008

11. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003

12. Office of Management and Budget (OMB) Circular A-130, “Management of Federal Information Resources,” November 28, 2000

13. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

14. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008

15. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998

16. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

17. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012

18. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015

19. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008

20. VA Handbook 6500.2, “Management of Data Breaches Involving Sensitive Personal Information (SPI)”, January 6, 2012

21. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring Of VA Information Systems,” February 3, 2014

22. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle” March 22, 2010

23. VA Handbook 6500.6, “Contract Security,” March 12, 2010

24. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011

25. Project Management Accountability System (PMAS) portal (reference https://www.voa.va.gov/pmas/)

26. OI&T ProPath Process Methodology (reference process maps at http://www.va.gov/PROPATH/Maps.asp and templates at http://www.va.gov/PROPATH/Templates.asp NOTE: In the event of a conflict, OI&T ProPath takes precedence over other processes or methodologies.

27. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.asp)

28. National Institute Standards and Technology (NIST) Special Publications (SP)

29. VA Directive 6508, VA Privacy Impact Assessment, October 3, 2008

30. VA Directive 6300, Records and Information Management, February 26, 2009

31. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010

32. OMB Memorandum, “Transition to IPv6”, September 28, 2010

33. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, February 17, 2011

34. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 20, 2014

35. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006

36. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005

37. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011

38. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008

39. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011

40. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008

41. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007

42. NIST SP 800-63-2, Electronic Authentication Guideline, August 2013

43. Draft NIST Special Publication 800-157, Guidelines for Derived PIV Credentials, March 2014

44. NIST Special Publication 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012

45. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014

46. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

47. VA Memorandum, VAIQ # 7011145, VA Identity Management Policy, June 28, 2010 (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

48. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

49. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf

50. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007

51. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008

52. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)

53. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

54. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

55. Executive Order 13514, “Federal Leadership in Environmental, Energy, and Economic Performance,” October 5, 2009

56. Executive Order 13423, “Strengthening Federal Environmental, Energy, and Transportation Management,” January 24, 2007

57. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

58. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013

59. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013

60. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

61. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

62. VA Directive 6071, Project Management Accountability System (PMAS), February 20, 2013

63. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

64. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

65. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

SCOPE OF WORK

The Contractor shall provide the professional services, hardware, and software required by individual Task Orders (TOs) for the implementation of a radiofrequency-based asset tagging system at VISN 21 Health Care Systems.

PERFORMANCE DETAILS

This is an Indefinite Delivery/Indefinite Quantity (IDIQ) contract. Individual TOs shall be issued on a Firm Fixed Price (FFP) basis.

The Contractor shall provide and/or acquire the services, hardware, and software required by individual TOs pursuant to the general requirements specified below.

PERFORMANCE PERIOD

The ordering period shall be three (3) years from the date of award. The period of performance (PoP) for any task order may go up to 16 months beyond the last day of the ordering period. Each TO will have its own PoP.

Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).

There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's DayJanuary 1
JuneteenthJune 19
Independence DayJuly 4
Veterans DayNovember 11
Christmas DayDecember 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's BirthdayThird Monday in January
Washington's BirthdayThird Monday in February
Memorial DayLast Monday in May
Labor DayFirst Monday in September
Columbus DaySecond Monday in October
ThanksgivingFourth Thursday in November

PLACE OF PERFORMANCE

The place of performance shall be identified in individual Task Orders within VISN 21. The list of current VISN 21 Health Care Systems and their addresses are given in Table 1.

ID
Name
Address
570
Central California Health Care System (CCHCS)
2615 E. Clinton Ave. Fresno, CA 93703-2286
612
Northern California Health Care System (NNHCS)
10535 Hospital Way Mather, CA 95655
640
Palo Alto Health Care System (PAHCS)
3801 Miranda Ave. Palo Alto, CA 94304
654
Sierra Nevada Health Care System (SNHCS)
975 Kirman Avenue Reno, NV 89502
662
San Francisco Health Care System (SFHCS)
4150 Clement St. San Francisco, CA 94121
593
North Las Vegas Health Care System (NLVHCS)
6900 N. Pecos Road North Las Vegas, NV 89086
459
Pacific Islands Health Care System (PIHCS)
459 Patterson Road Honolulu, HI 96819

Table 1: VISN 21 Health Care Systems

TRAVEL

The Government anticipates travel under this effort to perform the tasks associated with the effort. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.

The total estimated number of trips in support of the program related meetings for this effort will be dependent on each Task Order.

SPECIFIC TASKS AND DELIVERABLES

Individual TO(s) may encompass more than one functional area listed below. Functional area details are described to provide greater insight into the complexity and uniqueness of some potential TO requirements covered by this Performance Work Statement (PWS). Functional area requirements are not mutually exclusive, and an individual TO requirements may fall within multiple functional areas.

PROJECT MANAGEMENT

CONTRACTOR PROJECT MANAGEMENT PLAN

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline and tools to be used in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine, and ad hoc requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated with approval from the Government. The Contractor shall update and maintain the CPMP throughout the period of performance.

Deliverable:

A. Contractor Project Management Plan

REPORTING REQUIREMENTS

The Contractor shall provide the COR with Monthly Progress Reports (MPR) in electronic format. The MPR shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including a plan and timeframe for resolving the issue. The Contractor shall monitor performance against the CPMP and report all deviations. The Contractor shall communicate with the Government any potential issues that may arise. The MPR reports shall reflect progress as of the last day of the preceding month.

Deliverable:

A. Monthly Progress Report

Implementation and expansion

COMPATIBILITY REQUIREMENTS

Due to the existing implementation of CenTrak® active RTLS and Infor® LBI at VISN 21 Medical Centers and CBOCs, the following requirements apply to all specific tasks and deliverables in this PWS:

· The Contractor shall propose a hardware solution that is compatible with Infor® LBI. Location and asset data from the proposed passive RFID system must be transmissible to Infor LBI® and conform to the CenTrak® and Infor® Data Standards.

· The Contractor shall propose a software interface that is compatible with CenTrak® hardware and software for asset tracking. The proposed software and user interfaces must be able to accept CenTrak® location data.

· The Contractor shall propose a solution that is compatible with CenTrak® and Infor® data architecture.

The requirements above ensure that there is possible cross-talks between the passive and active asset management systems at VISN 21. In addition, VA VISN 21 requires that:

· The Contractor shall provide proof as an authorized reseller or distributor for the original equipment manufacturer (OEM) and remain an authorized reseller or distributor for the duration of the POP.

· The Contractor shall provide proof as an authorized reseller or distributor for the original software manufacturer of the user interfaces.

Site Assessment The Contractor shall perform a detailed site assessment at the site(s) identified in individual TOs to provide a full scope of requirements for site needs. A VAMC or CBOC in a different city shall be considered a different site for site assessment purposes. The Contractor shall coordinate with the COR and site POCs to schedule site assessments. The Contractor shall conduct a pre-assessment conference call at least two (2) weeks in advance of the site assessment. The Contractor shall coordinate the call with the COR to ensure attendance by facility stakeholders and subcontractor(s).

The Contractor shall provide a Site Assessment Report that outlines all requirements and line items per site to include hardware, software and services. Line items shall be listed in the format of the price cost schedule with the description of the item, quantity, cost per unit, and CLIN number. The Assessment Report shall include narrative and diagrams where appropriate to demonstrate understanding of the project goals. The assessment shall include a timeline for the entire project lifecycle with the following milestones defined as a minimum:

1. Equipment installation schedule

2. Limited installation capability demonstration

3. Equipment installation completion

4. User acceptance testing

5. User training

Milestones may be based on TO award date. The limited installation capability demonstration is defined to be a technical feasibility report in which the steps required for complete equipment installation is detailed for each task order.

Deliverables A. Site Assessment Report Design

Time Stamp The Contractor shall ensure all applications synchronize with internal VA site time standard. The synchronization of time on this network is critical in every aspect of managing, securing, planning, and debugging as it involves determining when an event occurred.

Wireless Technology The Contractor shall utilize the existing Wi-Fi infrastructure at each facility for the implementation of the technology. The Contractor shall notify the Government when known existing Wi-Fi infrastructure at each facility is not available or is insufficient and supplemental technologies will be required where Wi-Fi is not available or insufficient to achieve the resolution objectives of the applications.

Hardware and Server Design Document The Contractor shall ensure there is a Hardware and Server Design Document (HSDD) for every site. The Contractor shall update the HSDD throughout the remaining implementation so that it remains current with the existing design. The HSDD shall include:

1. Proposed changes, corrections and/or updates to the VA-provided maps and Engineering Space Files as noted during the Contractor’s site validation.

2. Proposed location for installation of hardware.

3. The Contractor shall provide a draft of the server configuration and architecture that shall be configured and optimized to meet the needs of the facility. This draft documentation shall include a diagram that lays out the server requirements at each location along with expected bandwidth utilization for the WAN links, expected application latency requirements, server specification (including power, BTUs, and network connections).

4. The Contractor shall provide the specification for the number of tags that can be supported per server.

Deliverables

A. Hardware and Server Design Document (HSDD)

Hardware Provisioning and Configuration The Contractor shall provide all necessary hardware components delivered to sites as specified in the Hardware and Server Design Document (HSDD) and ordered at the task order level. The hardware provided shall be compatible with VISN 21’s existing interface software and additional proposed interface software. Hardware components shall include, but not limited to, handheld RFID scanners, passive RFID tags, infrastructure components. Wireless hardware proposed shall be FIPS-compliant.

The Contractor shall coordinate with the COR and site POCs to schedule delivery and receive written or e-mail COR concurrence is required to ship hardware. The Contractor shall provide a copy of the signed Facility Receiving Report to the COR once components are delivered. The Contractor shall submit a copy of the signed Facility Receiving Reports for each site. The Facility Receiving Report shall contain:

1. Confirmation of the order and delivery of the components

2. Reconciliation (if any) of what was planned to be delivered versus what was delivered. Details of where items were delivered, what time they were delivered, and who from the Government received them.

Deliverable A. Facility Receiving Report

Installation and Configuration The Contractor shall install all hardware components delivered to sites. The Contractor shall coordinate with the COR and site POCs to schedule installation.

The Contractor shall ensure that hardware installed and configured do not interfere with other wireless technologies in the same environment. In the event of interference, the Contractor shall propose a plan for resolution of interference to the Government.

The Contractor shall install supporting hardware and components to blend in (or not be visible at all) with the general surface treatments of the facility. The Contractor shall install components to have minimal impact on the business operations of the facility and meet applicable infection control and health and safety requirements such as Joint Commission and local Infection Control Risk Assessment (ICRA) findings and standards. Hardware installation shall occur during normal business hours. This may include use of containment units for any above the ceiling work.

When installation of an infrastructure device requires a data connection, the Contractor shall use existing data connections whenever possible. If a new data connection and cabling is required, the Contractor shall provide the cabling and the cabling services.

The Contractor shall provide rendered maps of installed infrastructure device locations (i.e., “as-built drawings”).

Deliverable A. Infrastructure Device Maps

Software Provisioning and Configuration

Hardware-Specific Software The Contractor shall provide and install all necessary software compatible with the proposed hardware (i.e., middleware). The Government will provide virtual servers. If a virtual server platform is not feasible, the Contractor shall provision compatible physical servers for software installation. The Contractor shall provide a Software Installation Report. This Report shall include:

1) A list of all servers configured

2) Software and licenses that are installed on each server

3) Software validations

4) Server data architecture diagram

Deliverable A. Software Installation Report

User Interface Provisioning and Configuration The User Interface (UI) shall be a web-based UI and include at minimum the following capabilities:

1. Web-based UI

2. Display individual item information to allow users to uniquely identify individual assets

3. Displays facility assets in a list view; assets may be searched by asset number (identifier), asset type, asset model, asset manufacturer, or tag ID

4. Display facility assets in a map view; asset location shall be displayed on a facility floorplan in a pictographic method

5. Asset information may be exported from the system in an excel format

6. Access past year of asset location history (capability may be developed)

7. Fully customizable business rules

8. Asset egress alerts (capability may be developed as designated by VA)

9. Report generation and integration with Microsoft® Power BI

The UI shall be capable of interfacing with the following automated inventory management system / computerized inventory and maintenance management systems (CMMS):

1. VA Automated Engineering Management System/Medical Equipment Reporting System (AEMS-MERS)

2. IBM Maximo® Enterprise Asset Management System (Maximo EAM)

3. Nuvolo©

The interface for data exchange between the UI and VA AEMS-MERS/Maximo®/Nuvolo© shall at least be bidirectional and have at least the following capabilities:

1. Provide the UI and VA-AEMS/MERS and Maximo AEM the ability to identify a unique asset using a combination of unique asset ID and facility number.

2. Update the UI at least once every 24 hours.

3. Allow the UI shall display individual asset information from VA-AEMS/MERS and Maximo AEM to allow user to unique identify individual assets.

4. Provide designated users the capability to adjust the periodicity of bidirectional updates.

5. Post inventory date and time to VA-AEMS/MERS and Maximo AEM

6. Have the option to be run on demand

7. Update the UI with space creation from VA-AEMS/MERS and Maximo AEM

8. Update the UI when an asset has been decommissioned in VA-AEMS/MERS and Maximo AEM

9. Stop sending location/inventory date updates to VA-AEMS/MERS and Maximo AEM when assets are marked as decommissioned in the UI.

Infor® LBI Software Configuration VISN 21 currently uses Infor® LBI as a UI for active RFID-based asset tracking. To streamline clinical and operational workflow, compatibility with Infor® LBI is required for all proposed hardware, software, and user interfaces. Therefore, if the proposed UI is not Infor® LBI, the Contractor shall provide configuration services for integrating the proposed passive RFDI system interfaces with Infor LBI®. The Contractor must maintain a current Reseller Agreement with Infor® for all tasks requiring Infor® LBI software installation, configuration, and maintenance.

Per hardware design changes and/or VA reconfiguration requirements, the Contractor shall update rendered maps in Infor® LBI application. Naming shall conform to data standards as outlined in the RTLS Enterprise Data Architecture (EDA) Standards Workbook. Configuration changes shall be scoped during the site assessment at each facility.

Professional Services

Asset Tagging The Contractor shall provision all hardware and software required for tagging and commissioning of assets, including passive RFID tags. The Contractor shall create and provide a Tagging and Commissioning Plan for sites prior to beginning the tagging process for review and approval by the Government. Once approved, this plan shall be integrated into the CPMP. This Plan shall include:

1. Identification of all Asset Groups and Assets to be tagged.

2. A schedule during normal business hours (not to interrupt business operations) to tag and commission all assets.

3. Guidance and instructions on tag placement (unless provided by the Government).

4. Method for quality control of tag placement and commissioned data.

5. Method for taking corrective actions on misplaced tags, defective tags, assets that cannot be located, incorrect information in the database, and other errors that can occur during the tagging and commissioning process.

6. Documentation to allow the Government to perform the tagging and commissioning process.

Upon COR approval of the Tagging and Commissioning Plan, the Contractor shall execute and report on tagging and commissioning operations weekly with the COR either through email or status calls, and in the Monthly Progress Reports.

Deliverable A. Tagging and Commissioning Plan B. Tagging and Commissioning Instruction System Administration The Contractor shall provide Database and System Administration services during the implementation and warranty period. The System Administration Services shall include:

1. Perform periodic system health checks on servers and databases, including monitoring application logs

2. Security compliance and remediation of application related vulnerabilities

3. Apply Monthly OS security patches provided by VA OIT

4. Troubleshoot connectivity issues

5. Troubleshoot startup/shutdown server and application issues

6. Implement software updates and upgrades

Professional Services Hours The Contractor shall provide service hours as requested by the Government for all tasks associated with:

1. System and software configuration and administration

2. Software and hardware compliance with VA standards

3. Workflow solutions and implementation

4. Project planning and management

5. Analytics and business intelligence

Acceptance testing The Contractor shall create and provide an Acceptance Test Plan that includes two phases. A single Acceptance Test Plan is required to define testing methodology for all TOs. The Contractor shall not execute testing on any TO until the Government approves the Acceptance Test Plan.

Deliverable A. Acceptance Test Plan

Phase 1: Performance Testing The Contractor shall perform testing on the system and/or system enhancements to certify Proof of Performance to include room-level location accuracy of 95%. The Contractor shall test and verify that all system functions and specification requirements are met and operational, and no unwanted effects, such as signal distortion or interference with other facility devices are present. The Contractor shall provide VA with a copy of the performance test plan methodology and test results.

If the system does not meet requirements and additional remediation hardware is required, the Contractor shall provide a list that outlines additional requirements per site to include hardware, software, and service in the Facility Remediation Hardware Report.

The Contractor shall provide the Final Hardware Deployment Document (FHDD). The FHDD shall include complete hardware configuration, including any additional hardware purchased under this contract. This document shall be in the format of a .pdf floor map layout and in a table excel spreadsheet format. This document shall include the final quantity and location of hardware identified in the Hardware Design Document that was installed to meet the goals of the applications being deployed at each facility. The information provided shall include the Hardware Unique Identification Device #, Hardware Serial Number, and Building, Floor, and Room number where it was installed.

Deliverables:

A. Performance Test Plan B. Facility Remediation Hardware Report C. Final Hardware Deployment Document

Phase 2: User Acceptance Testing The Contractor shall schedule an acceptance test date and provide VA 30 days written notice prior to the date the acceptance test is expected to begin. The notification of the acceptance test shall include the expected length (in time) of the test(s). The Contractor shall provide certified/qualified personnel to assist VA with performing this testing. The Contractor shall provide VA with a copy of the acceptance test plan methodology and test results. At the Government’s discretion, the test results may be accepted without meeting the above location accuracy requirements.

At a minimum, the Acceptance Test Report shall provide a rating of location accuracy for each of the locations within scope to the smallest division requested (e.g., bay accuracy – room accuracy – area accuracy – floor accuracy – building accuracy). The report shall be in an excel format and provide the tag ID, location, division, and accuracy rating (does or does not meet defined requirements). The overall location accuracies shall be calculated and displayed respectively in the report. The proposed format of the Acceptance Test Report shall be included in the Acceptance Test Plan.

Deliverables:

A. User Acceptance Test Plan B. Facility Acceptance Test Report Transition Planning The Contractor shall develop a Transition Plan for sites after implementation. The Transition Plans shall include a detailed procedure to transition all duties to Government staff by the end of this contract in the form of a RACI matrix. The Contractor shall submit a Transition Plan that addresses transitioning daily operational oversight of the system of at each facility including all hardware and software as well as maintenance, repair and configuration management procedures. Once the Transition Plans are approved by the Government, the Contractor shall execute those plans.

The Contractor shall provide User and Technical Manuals that shall include all components of the system.

1. Two (2) copies of operator's instruction manuals per facility

2. Two (2) copies of complete technical service manuals including detailed troubleshooting guides, necessary diagnostic software, service keys, schematic diagrams, and parts lists per facility

Deliverables:

A. Transition Plan B. User and Technical Manuals

Training Requirements The Contractor shall develop and provide a Training Plan and deliver onsite or remote training, workshop, and consulting services as designated by VA. The Contractor shall provide multiple offerings for each user interface and software to be used. The Contractor shall provide training at the request of the COR. The Contractor shall provide certified/qualified personnel and conduct both on-site and remote training sessions for:

1. Biomedical Engineering technical trainings for asset tracking

2. Application training for inventory managers

3. Inventory management training for asset tracking

4. Non-technical user and administrator training for asset tracking

The Contractor shall perform up to 8-hours of training within a 24-hour period. The contractor can break-up training events in blocks during each workday to accommodate different shifts.

The Contractor shall submit a Training Plan for each training for review and approval by the COR. The Training Plan shall include, at a minimum:

1. Training locations, training dates, and training times

2. Format, method and / or delivery of training (e.g. onsite, web based)

3. Training audience (e.g. technical repair, system user, system administrator)

4. Instructor profile and content information

The Contractor shall also provide Training Material and Schedules for each training event and complete those events in accordance with the approved Training Plan. Once each Training Event is completed, the Contractor shall provide the following:

1. Facility-specific list of the attendees for each training session

2. The Contractor staff that conducted the training

Deliverables:

A. Training Plan B. Training Material and Schedules C. List of Attendees Warranty Services All new equipment, hardware, and services performed under each TO shall be covered under the manufacturer’s warranty and shall include all parts and labor and technical support for one (1) year following acceptance by VA. The Contractor shall perform all maintenance during the system warranty period. The Contractor shall oversee all sub-Contractor support, maintenance, and warranties. Service Maintenance Agreements (SMA) for hardware and software provided under each TO shall be included respectively during the warranty period. The Contractor shall provide Database and System Administration services during the warranty period. The Contractor shall provide additional provision warranty and SMA as required by the Government beyond the 1-year warranty period. The Contractor shall provide a Warranty Status Report, detailing hardware and software specifications and warranty end dates, in accordance with the start of each warranty period.

VA staff members will handle initial trouble calls from end users. Issues, which cannot be resolved by VA staff, will be referred to the Contractor by VA technical support staff. The Contractor shall provide methods for requesting technical support from the Contractor including telephone and e-mail. The Help Desk shall be staffed from 8am to 5pm MDT. The help desk shall respond to calls within 2 hours after receiving the initial call. The Contractor shall coordinate with the VA POC to schedule on-site service; service shall be completed within 15 business days of the reported incident.

Deliverable:

A. Warranty Status Report

GENERAL REQUIREMENTS

ENTERPRISE AND IT FRAMEWORK

VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.

STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT (PLM)

The Contractor shall support VA efforts IAW the updated Veteran Focused Integration Process (VIP) and Product Line Management (PLM). The major focus of the new VIP is on Governance and Reporting and is less prescriptive, with a focus on outcomes and continuous delivery of value. Product Line Management (PLM) is a framework that focuses on delivering functional products that provide the highest priority work to customers while delivering simplified, reliable, and practical solutions to the business, medical staff, and our Veterans. The VIP Guide is a companion guide to the PLM Playbook and can be found at: https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 and the PLM Playbook can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946. The PLM Playbook pivots from project-centric to product-centric delivery and contains descriptive practices that focuses on outcomes. The PLM Playbook contains a set of “plays” that implement Development, Security, and Operations (DevSecOps) principles and processes such as automated development, continuous integration/continuous delivery, and release on demand. The PLM Playbook details how product lines implement Lean-Agile principles, methods, practices, and techniques through levels of maturity. VIP and PLM are the authoritative processes that IT projects must follow to ensure development and delivery of IT products.

PROCESS ASSET LIBRARY (PAL)

The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.

AUTHORITATIVE DATA SOURCES

The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:

1. Interfacing with VA’s Master Person Index (MPI) (formerly the Master Veteran Index (MVI)) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .