PWS - AI prototypes - RFI Draft v2.docx

DOCX document 136 KB Posted

Attached to
R499--Artificial Intelligence Pilot Teams (VA-24-00064764) Federal contract opportunity
Solicitation number
36C10B24Q0429
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This document is a Performance Work Statement (PWS) for the Department of Veterans Affairs (VA) Office of the Chief Artificial Intelligence Officer (OCAIO) to support Artificial Intelligence (AI) Pilot Teams. The PWS describes the VA's vision to be a national leader in responsible use of AI to reduce healthcare provider burnout, improve Veteran and VA employee experience, and provide higher quality care for Veterans. The key objectives are to develop a deep understanding of user problems, determine where AI-enabled approaches are appropriate, design and develop AI-enabled solutions, integrate the solutions with existing VA systems, and monitor performance. The work may include conducting user research, prioritizing problems to solve, developing prototypes and minimum viable products, conducting AI model research, and creating educational materials. The contract will be a 12-month base period with a 12-month option period, on a Time and Materials and Firm Fixed Price basis. The PWS also details security, privacy, and other administrative requirements. The VA has issued a Request for Information (RFI) seeking industry feedback on the PWS and proposed contract structure.

View the file

Other files for this federal contract opportunity

Other files attached to R499--Artificial Intelligence Pilot Teams (VA-24-00064764), newest first.
File Type Posted
36C10B24Q0429 0002.docx DOCX document
36C10B24Q0429 0001_1.docx DOCX document
36C10B24Q0429 0001.docx DOCX document
36C10B24Q0429.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Artificial Intelligence Pilot Teams

VA-24-00064764

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

VA Office of the Chief Technology Officer

Office of the Chief Artificial Intelligence Officer

Artificial Intelligence Pilot Teams

Date: 4-16-2024

VA-24-00064764

PWS Version Number: 0.1

BACKGROUND

Mission of the requesting business office The Office of the CTO (OCTO) serves the Department of Veterans Affairs Office of Information Technology’s (VA OIT) mission to deliver world-class IT products and services to VA and Veterans. OCTO works closely with core program portfolios across VA to examine the short and long-term needs of the Department, and to identify and fill gaps in VA’s technology portfolio. OCTO takes an approach to problem-solving, teamwork, and leadership that is built on agile development and results in ongoing improvement.

DESCRIPTION OF THE SPACE

OCTO now serves a dual purpose as the VA Office of the Chief Artificial Intelligence Officer (OCAIO). The mission of OCAIO is to deliver world-class AI-enabled IT products and services to VA and Veterans in a 1) purposely, 2) effective and safe, 3) secure and private, 4) fair and equitable, 5) transparent and explainable, and 6) accountable and monitored fashion. These six pillars comprise the VA Framework for Trustworthy AI.

Existing relevant documentation

· AI-enabled tools in production at VA must be consistent with the VA Trustworthy AI Framework.

APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”

4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and Information Systems,” March 2006

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

9. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology Act of 2006, Title IX, Information Security Matters

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm

13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5, 2019

14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017

15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016

16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”

17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021 VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021

21. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019

22. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010

23. VA Handbook 6500.6, “Contract Security,” March 12, 2010

24. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011

25. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

26. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

27. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

28. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

29. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

30. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

31. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016

32. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017

33. VA Directive 6300, “Records and Information Management,” September 21, 2018

34. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

35. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

36. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

37. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

38. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014

39. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

40. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

41. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

42. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)

43. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018

44. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

45. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

46. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices (Draft),” October 2012

47. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014

48. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

49. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

50. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

51. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

52. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

53. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

54. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

55. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

56. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018

57. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

58. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013

59. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013

60. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

61. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

62. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

63. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

64. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

65. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

66. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol Version 6 (IPv6),” November 19, 2020

67. Social Security Number (SSN) Fraud Prevention Act of 2017

68. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018

69. Executive Order 13960, Promoting the Use of Trustworthy Artificial Intelligence in the Federal Government, December 03, 2020

70. Executive Order 14110, Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence, October 30, 2023

71. OMB Memorandum M-24-10, Advancing Governance, Innovation, and Risk Management for Agency Use of Artificial Intelligence, March 28, 2024

SCOPE OF WORK

Product vision AI instituted in a responsible manner has enormous potential to benefit Veterans, VA healthcare providers, and VA employees. Our vision is for VA to be a national leader in responsible use of AI to reduce healthcare provider burnout, improve Veteran and VA employee experience, and provide higher quality care for Veterans.

Desired user outcomes Example user outcomes are as follows:

1. Reducing healthcare provider burnout

a. Time spent on clinical documentation decreases from X to Y.

b. Time spent on clinical documentation after hours (“pajama time”) decreases from X to Y.

c. Veteran satisfaction with clinical encounters increases from X to Y.

d. % of providers experiencing symptoms of burnout decreases from X to Y.

2. Improving Veteran and VA Employee experience

e. Time spent per specific administrative task decreases from X to Y.

f. Employee satisfaction increases from X to Y.

g. Accuracy in completed specific administrative task increases from X to Y.

h. Number of days needed for Veteran to receive response to Ask VA query decreases from X to Y.

3. Better care for Veterans

i. Adherence to evidence-based clinical guidelines increases from X to Y.

j. Backlog of Community Care records to be summarized and/or ingested into VA electronic health record decreases from X to Y.

Desired business outcomes Example outcomes for some of the problem focus areas described above are as follows:

1. Reducing healthcare provider burnout

a. Turnover of healthcare providers reduces from X to Y due to reduced levels of burnout.

b. Access to care for Veterans increases due to increased provider capacity, evidenced by reduced appointment wait time from X to Y.

2. Improving Veteran and VA Employee experience

a. Time spent per specific administrative task decreases from X to Y.

b. Employee satisfaction increases from X to Y; employee turnover reduces from X to Y.

c. Accuracy in completed specific administrative task increases from X to Y.

d. Number of manual interventions needed per benefits claims decision decreases from X to Y.

3. Better care for Veterans

a. Adherence to evidence-based clinical guidelines increases from X to Y.

Outcomes we want to avoid

We aim to avoid the following outcomes:

1. Deploying AI without a clear purpose or meaningful outcome.

2. Deploying AI that poses unnecessary or unacceptable risk to Veterans or VA employees.

3. Deploying solutions that are not adopted by end users given lack of workflow integration.

Overview of work The Contractor shall support a variety of initiatives related to the focus areas for problems to solve in section 3.1-3.3 above. In general, VA requires contractor support with prioritizing, designing, and executing AI-enabled pilot projects raised by stakeholders across VA. Work to be completed may include, but is not limited to:

· Developing deep understanding of user problems and potential areas for impact. Potentially conducting interviews with stakeholders, surveys, and observational research to gain insights about user perspectives, needs, problems, behaviors.

· Assist VA in prioritizing amongst problems to solve and assisting VA in determining where to invest effort in piloting.

· Assisting VA in determining whether an AI-enabled approach to specific problems is appropriate, and if applicable, which specific Machine Learning (ML)-based approaches could be leveraged. Providing input to VA stakeholders about where AI-enabled approaches may and may not be appropriate.

· Setting measurable goals and supporting metrics collection. Developing deep understanding of relevant data available.

· Developing solution prototypes and minimum viable products for testing with users.

· Developing and releasing solutions to production for live pilots with users.

· Where applicable, conducting research with VA stakeholders to develop machine learning models to support their use cases.

· Where applicable, conducting research with VA stakeholders to engineer prompts for large language model (LLM)-based tools to support their use cases.

· Creating user-facing educational and training materials on the AI-enabled solutions developed.

· Integrating third party and/or homegrown AI-enabled solutions with existing VA systems, including but, not limited to, VistA/CPRS, Oracle Health, Ask VA, VA Chatbot, employee-facing customer support interfaces, employee-facing benefits adjudication interfaces.

· Monitoring performance of solutions developed.

· Collecting user feedback on solutions developed and iterating upon solutions accordingly.

· Ensuring solutions are consistent with VA Trustworthy AI Framework.

Transition Support (Optional Task 1) Transition of a product to a new contractor or the Government is sometimes necessary. It is critical to the continued functionality of OCTO products that all contractors are diligent in transitions between teams to ensure there is no disruption in Veteran services. The most important factors in these transitions are the availability of well written documentation and good faith communications. This optional task shall be for a period of up to 60 days, if exercised by the Government. The Contractor must submit a Transition Support Package within (7) days upon optional task exercise. The Transition Support Package shall consist of at least the following, and is critical to the successful transition in OCTO, and must be available in the relevant GithHub repository:

1. All documentation

2. All access to the platform (if applicable) and anything interacting with the platform or application, for which the incoming vendor will require access

3. All relevant information necessary for Developer onboarding – interaction with 3rd party tools, downstream services, application interactions outside va.gov In consult with the relevant OCTO Product Owner and COR, the Contractor shall create a list of all relevant stakeholders both inside OCTO, across VA, and outside VA (if relevant). The contractor shall ensure frank and open communication between all staff of the exiting and incoming contractors. At a minimum the outgoing contractor shall ensure the incoming contractor has access to the following:

1. Product documentation including product outlines/briefings, objectives and key results (OKRs), roadmaps and active epics/stories, stakeholder landscape maps, decision records, and analytics

2. Developer documentation including READMEs, set-up instructions, diagrams, relevant databases and services.

3. Design documentation including prototypes, user research reports, design decisions for products in production, early designs for incomplete products, content strategy, and records of interactions with the collaboration cycle.

4. Access to accounts for third-party products such as tooling or SaaS products that will be taken over by the new team.

Although not exhaustive, the following are typical interactions which the contractor shall support during transition:

1. A handoff coordination meeting between the leads of the incoming and outgoing teams

2. Community of Practice specific orientations to the available documentation allowing the outgoing team to ask questions

3. Conversations about the stakeholder landscape and typical communication patterns

4. Demonstrations of specific functionality in the application

Deliverable:

A. Transition Support Package

ADDITIONAL PRODUCT AND DEVELOPMENT SUPPORT (OPTIONAL TASK 2)

The optional tasks will be used to provide increased capacity to deliver features related to Artificial Intelligence Pilot Teams as described in this PWS. Upon execution of this optional task, the Contractor shall provide additional feature and product development support. These optional tasks may be exercised for a quantity of additional support not to exceed the limit set forth in the Price Schedule in both the Base Period and the Option Period. The specific scope of functionality to be delivered for each optional task exercise will be agreed to by the VA Program Manager/Product Owner and Contracting Officer’s Representative (COR) prior to exercise of the optional tasks by the CO based on current business priorities. The Contractor shall provide a proposal for the requested support including by a Level of Effort (LOE) made up of the required level of resources with appropriate technical skill sets, limited to the Labor Categories included in Attachment A. Prior to each exercise of this Optional Task, the Contractor shall provide a short description of what work will be completed, a list of all deliverables, and a schedule for implementation including milestones for delivery and associated milestone payments. The Government will review and agree to the proposal, after which a modification will be made to the contract adding the proposal, providing funding, and reducing the available ceiling on the line item accordingly.

Development methodology and working principles The Contractor’s support and solutions shall follow the practices described in the Digital Services Playbook (https://playbook.cio.gov). The Contractor shall be familiar with the concepts in each play and implement them in its approaches and support. The Contractor shall deliver modern digital services that use DevOps techniques that embrace Continuous Integration / Continuous Delivery (CI/CD). The Contractor shall deliver secure and tested modern web application designs using automated testing frameworks.

The Contractor shall provide VA with teams that shall deliver viable, digital solutions in support of VA’s strategic mission and objectives. Specifically, the Contractor shall:

1. Deliver high-quality, functional products that are measured by user feedback from surveys, research, etc.

2. Follow the practices described in the “Digital Services Playbook” (https://playbook.cio.gov).

3. Be agile. Incorporate Agile methodologies and ceremonies into work, such as (but not limited to) sprint planning, daily scrum, sprint review, sprint retrospective, backlog grooming, and estimating activities.

4. Actively involve users in the design of all solutions. Incorporate best practices for modern user research and usability testing, such as (but not limited to) creating user personas, problem space definitions, affinity maps, user flow diagrams, wireframes, information architecture diagrams, design prototypes, user research plans, conversation guides, and user research synthesis.

5. Maintain a consistent look, feel, and voice across user facing sites and services. Incorporate best practices defined in the VA Design System and VA Content Style Guide (https://design.va.gov/).

6. Personalize solutions for the individual or team using the product (https://www.whitehouse.gov/briefing-room/presidential-actions/2021/12/13/executive-order-on-transforming-federal-customer-experience-and-service-delivery-to-rebuild-trust-in-government/, https://www.whitehouse.gov/wp-content/uploads/2018/06/s280.pdf)

7. Optimize web applications for mobile-first operation, with all solutions being equally available on both mobile and desktop whenever possible. Incorporate robust accessibility principles into design, development and testing for all web applications to deliver high-quality digital experiences to users of assistive devices.

8. Protect user information with best-in-class security, given the constraints of the environment.

9. Use DevOps techniques of CI/CD across all environments including, at a minimum, development, staging, and production. (http://github.com/department-of-veterans-affairs/va.gov-team/tree/master/platform/engineering/)

10. Use automated testing frameworks to create unit tests, integration tests, functional/black box tests, and load tests (or their equivalents as applicable) to test 100% of functionality delivered. Strive for compliance with Test Driven Development practices.

11. Ensure configuration and sensitive data, including data the VA defines as sensitive, are not present in source code, and are stored in encrypted credential management systems.

12. Deliver all code not containing configuration or sensitive data to an open source repository per Office of Management and Budget Guidance M-16-21.

13. Cultivate a positive, trusting, and cooperative working relationship with the Government and all other vendors supporting this work.

PERFORMANCE DETAILS

Period of performance (PoP) and budget estimate The Period of Performance (PoP) shall be one (1) 12-month Base Period, with one (1) 12-month Option Period, and two Optional Tasks.

0. Place of performance Efforts under this task order can be performed at any location within the United States. All work locations must be able to accommodate the Hours of Work specified in Section 7.3.

Travel Travel shall be reimbursed on a Time & Materials basis in accordance with the Federal Travel Regulations and requires advanced concurrence by the COR. Contractor travel within the local commuting area will not be reimbursed.

While the Government cannot accurately estimate the amount of travel to an extent it can be firm fixed price, the following was used as the basis for the Government’s cost estimate: Travel is expected for a yearly in-person planning meeting during the Base Period and Option Period, including the full contract team, within the Continental United States for a period of approximately 3 days.

Hours of work The contractor shall set their own work hours within the following parameters: contractors may be required to attend meetings with Government personnel between standard east coast work hours (typically 9am – 5pm ET) monitoring and production support will be required between 7am – 8pm ET.

Contract type The effort shall be proposed on a Time and Materials (T&M) basis and Firm Fixed Price (FFP) basis. All labor shall be FFP per sprint while all travel shall be on a T&M basis.

The Anticipated LoE for this Task Order is 11 full time equivalents.

Key personnel Senior Product Manager

· Experience with developing product requirements documents, product roadmaps, and associated artifacts, including proven experience in leading cross-functional teams and driving product development from concept to launch.

· Experience performing research, developing a deep understanding of the customer, working with and eliciting information from diverse groups of stakeholders and developing clear technical, actionable requirements.

· Experience launching products leveraging artificial intelligence, to include generative AI and large language models.

· Ability to effectively articulate a product vision and strategy.

· Preferred: Strong understanding of health IT data privacy and security practices.

· Preferred: Experience developing Veteran-facing and/or employee-facing products for VA.

Engineering lead

· Experience building end-to-end data science solutions, including operationalizing models.

· Experience in designing overarching GenAI system architecture.

· Strong proficiency in Python, R, SQL, and experience with libraries/frameworks such as PyTorch, TensorFlow, and Scikit-learn.

· Experience with cloud and modern data science tools and platforms such as Databricks MLFlow and Azure ML.

· Ability to guide and manage an engineering team effectively.

· Preferred: Strong understanding of health IT data privacy and security practices.

· Preferred: Experience developing Veteran-facing and/or employee-facing products for VA.

Senior data analyst, healthcare

· Data management experience; knowledgeable in database rules, writing queries, and relational database creation and management (create, query, relate)

· Experience in the development of algorithms leveraging R, Python, or SQL/NoSQL

· Experience with deriving insights from unstructured and structured healthcare data, and ability to effectively communicate those insights to stakeholders and clinical leaders.

· Experience working with healthcare terminology standards, e.g. ICD-10, CPT, LOINC, RxNorm, SNOMED.

· Preferred: Experience working with healthcare data from VHA.

Additional Information

SCRUM teams will be considered acceptable when they can effectively work. This may include some resources that are staffed, but not cleared. This will be case by case and worked with the COR. For the initial team to be deemed ready to work, all members of the team will have a Personal Security Adjudication Center letter in order to obtain access to working tools such as GitHub and Slack that do not require VA network access. Access to Amazon Web Services requires an Electronic Questionnaires for Investigations Processing release date.

Kickoff meeting The Contractor shall hold a kickoff meeting within 10 days after task order award. The Contractor shall present, for review and approval by the Government, at a minimum the details of the intended approach, work plan, and onboarding plan. The Contractor shall specify dates, locations (can be virtual), agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the Contracting Officer, Contract Specialist, COR and the VA Program Manager/Product Owner.

Quality Assurance Surveillance Plan (QASP) Product specific objectives and key results The Government is open to discussion with the vendor about appropriate QASP metrics for this task order after award.

Recurring deliverables Delivery and Monitoring Report and Roster: The Contractor shall provide a single monthly report, detailing and providing links to all stories, epics and other work completed. This includes a plain language description of all work accepted by the Government Product Owner and COR at the end of each sprint. This report shall include, in plain language, additional details about the project status, sprint team velocity, sprint team goal completion, and highlight project risks. The report shall also highlight and provide links to key infrastructure and application monitoring data. The report shall also include details with links to documentation for any critical incidents or outage events that resulted in service outages or significant service degradations. The Contractor shall attach or provide links to postmortem documentation for all critical incidents or outage events. Should there not be any reported incidents during the reporting period, a link to the relevant monitoring tools is sufficient. The specific data points and format of this monthly report shall be determined by the Contractor in collaboration with the VA Program Manager/Product Owner and COR. Lastly, the Contractor shall submit a roster to the COR that includes the Status of Government Furnished Equipment (GFE) for all GFE all staff, as applicable.

Data and Open Source Requirements The Government shall receive Unlimited Rights to data first produced in performance of this contract in accordance with FAR 52.227-14, “Rights In Data-General” (MAY 2014). This includes all rights to source code and any and all documentation created in support thereof. License rights in any Commercial Computer Software shall be governed by FAR 52.227-19, “Commercial Computer Software License” (DEC 2007). Any data delivered shall be submitted and protected in accordance with VA handbook 6500.

VA intends that the software delivered under this task order will be publicly posted without restriction. To the extent that the Contractor(s) seeks to incorporate into the software delivered under this task order any software that was not first produced in the performance of this task order, VA encourages the Contractor(s) to incorporate either software that is in the public domain, or free and open source software that qualifies under the Open Source Definition promulgated by the Open Source Initiative. In any event, the Contractor(s) must promptly disclose to VA in writing, and list in the documentation, any software incorporated in the delivered software that is subject to a license fee.

Other Administrative Items

GENERAL REQUIREMENTS

ENTERPRISE AND IT FRAMEWORK

VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19-17 can be found at: https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.

STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE MANAGEMENT (PLM)

The Contractor shall support VA efforts IAW the updated Veteran Focused Integration Process (VIP) and Product Line Management (PLM). The major focus of the new VIP is on Governance and Reporting and is less prescriptive, with a focus on outcomes and continuous delivery of value. Product Line Management (PLM) is a framework that focuses on delivering functional products that provide the highest priority work to customers while delivering simplified, reliable, and practical solutions to the business, medical staff, and our Veterans. The VIP Guide is a companion guide to the PLM Playbook and can be found at: https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 and the PLM Playbook can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946. The PLM Playbook pivots from project-centric to product-centric delivery and contains descriptive practices that focuses on outcomes. The PLM Playbook contains a set of “plays” that implement Development, Security, and Operations (DevSecOps) principles and processes such as automated development, continuous integration/continuous delivery, and release on demand. The PLM Playbook details how product lines implement Lean-Agile principles, methods, practices, and techniques through levels of maturity. VIP and PLM are the authoritative processes that IT projects must follow to ensure development and delivery of IT products.

PROCESS ASSET LIBRARY (PAL)

The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.

AUTHORITATIVE DATA SOURCES

The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:

1. Interfacing with VA’s Master Person Index (MPI) (formerly the Master Veteran Index (MVI)) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.

3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.

4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.

5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.

6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying Active Duty military service in VA.

SOCIAL SECURITY NUMBER (SSN) REDUCTION

The Contractor solution shall support the Social Security Number (SSN) Fraud Prevention Act (FPA) of 2017 which prohibits the inclusion of SSNs on any document sent by mail. The Contractor support shall also be performed in accordance with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates VA to discontinue using SSNs to identify individuals in all VA information systems as the Primary Identifier. The Contractor shall ensure that any new IT solution discontinues the use of SSN as the Primary Identifier to replace the SSN with the ICN in all VA information systems for all individuals. The Contractor shall ensure that all Contractor delivered applications and systems integrate with the VA Master Person Index (MPI) for identity traits to include the use of the ICN as the Primary Identifier. The Contractor solution may only use a Social Security Number to identify an individual in an information system if and only if the use of such number is required to obtain information VA requires from an information system that is not under the jurisdiction of VA.

SOFTWARE AND LICENSING REQUIREMENTS

The Contractor shall be responsible for the provision of all software licenses and any associated licensing maintenance required for any development, delivery, integration, operation, and/or maintenance associated with its proposed application(s), software products, software solution, and/or system including, but not limited to, any and all application(s), software and/or software products that comprise, are a part of, or integrate with the Contractor’s proposed application(s), software products, software solution, and/or system for the life of any resulting contract.

SECURITY AND PRIVACY REQUIREMENTS

It has been determined that protected health information may be disclosed or accessed and a signed Business Associate Agreement (BAA) shall be required. The Contractor shall adhere to the requirements set forth within the BAA, referenced in Section D of the contract, and shall comply with VA Directive 6066.

POSITION/TASK RISK DESIGNATION LEVEL(S)

In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity, and the level of background investigation commensurate with the required level of access for tasks within the PWS. All tasks are considered Tier 2 / Moderate Risk unless otherwise specified in the table below.

Position Sensitivity and Background Investigation Requirements by Task

Task Number
Tier 1/ Low Risk
Tier 2 / Moderate Risk
Tier 4 / High Risk
Across all tasks
☐
☐
☒

The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

Contractor Responsibilities:

1. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak, and understand the English language.

Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the PAL template artifact. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

1. The Contractor should coordinate with the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized. The Contractor shall bring their completed Security and Investigations Center (SIC) Fingerprint request form with them (see paragraph d.4. below) when getting fingerprints taken.

b. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) Optional Form 306

2) Self-Certification of Continuous Service

3) VA Form 0710

4) Completed SIC Fingerprint Request Form The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).

The Contractor employee shall certify and release the e-QIP document, print, and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via e-QIP).

1. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. In the event that damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.

1. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), completed training delineated in VA Handbook 6500.6 (Appendix C, Section 9), signed “Contractor Rules of Behavior”, and with a valid, operational PIV credential for PIV-only logical access to VA’s network. A PIV card credential can be issued once your SAC has been favorably adjudicated and your background investigation has been scheduled by OPM. However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of OPM.

1. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.

Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.

Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures,…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .