RFI_Incident Mgmt System_FINAL.pdf
PDF 187 KB Posted
- Attached to
- Incident Management Software Federal contract opportunity
- Solicitation number
- PUR250022
- Issued by
- National Transportation Safety Board
About this file
This is a Request for Information (RFI) from the National Transportation Safety Board (NTSB) seeking information about Commercial Off-the-Shelf (COTS) Incident Management System (IMS) and Case Management System (CMS) software solutions. The NTSB requires a cloud-based, web-enabled Software as a Service (SaaS) or Platform as a Service solution that can provide centralized, secure incident management for their 24/7 Response Operations Center (ROC) and Transportation Disaster Assistance (TDA) division.
The solution must be FedRAMP authorized (or willing to obtain authorization within 24 months), support 250 simultaneous users, and include capabilities such as real-time notifications via SMS/email, dashboard access with role-based permissions, document management, calendar integration, and mobile applications for both Android and iOS. Key technical requirements include multi-tenant SaaS architecture, integration with directory services, and compliance with FISMA Moderate security controls. Responses are due by February 3, 2025, at 4:00 PM ET, with a 15-page limit for technical responses. Questions must be submitted by January 24, 2025. The NAICS code is 513210 (Software Publishers) with a size standard of $47.0M.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| NTSB Responses to Questions_RFI.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
REQUEST FOR INFORMATION (RFI)
Commercial Off the Shelf (COTS) Incident Management System (IMS) & Case
Management System (CMS)
Request for Information, Incident Management System, Page 1 of 6
Description
The National Transportation Safety Board (NTSB) Acquisition Division (CFO-30) is seeking information from interested parties with the capability to provide a Software as a Service or Platform as a Service (COTS) Incident Management System (IMS) with the capability to also provide functionality as a Case Management System (CMS). The proposed solution shall be Software as a Service (SaaS), or solution hosted in an environment that meets the current federal security requirements.
THIS IS A REQUEST FOR INFORMATION (RFI) ONLY. This RFI is issued solely for information and planning purposes – it does not constitute a Request for Proposal (RFP) or a promise to issue an RFP in the future.
This request for information does not commit the Government to contract for any supply or service whatsoever. Further, the NTSB is not at this time seeking proposals and will not accept unsolicited proposals. Responders are advised that the U.S. Government will not pay for any information or administrative costs incurred in response to this RFI; all costs associated with responding to this RFI will be solely at the interested party’s expense. Not responding to this RFI does not preclude participation in any future RFP, if any is issued. If a solicitation is released, it will be synopsized on the Contract Opportunities page on the System for Award Management at SAM.gov. It is the responsibility of the potential offerors to monitor this site for additional information pertaining to this requirement.
BACKGROUND:
The National Transportation Safety Board (NTSB) is a Federal agency mandated by Congress to investigate all aviation accidents and selected accidents/incidents in other modes of transportation and report the results of those investigations.
In support of this mission, the NTSB runs a 24-hour 7 day a week Response Operations Center (ROC). The NTSB’s ROC is seeking a cloud-based, web-enabled , software capable of providing a centralized, secure, and integrated incident management system designed to manage incidents, accidents, and events. The agency requires an efficient means of disseminating information with and among investigative participants.
The NTSB currently operates a centralized information dashboard for gathering real time investigative data. The NTSB has a continued need to further utilize a solution that will disseminate accurate and timely information to the intended audiences as soon as the information is generated with auditing capabilities, real-time notification via short messaging services (SMS) texting, email and other forms of messaging for both the ROC mission and the Transportation Disaster Assistance (TDA) mission.
The NTSB’s Transportation Disaster Assistance (TDA) division coordinates the disaster response resources of federal, state, local, and volunteer agencies. TDA Specialists work closely with these agencies and the transportation carrier to address the needs of disaster victims and their families. TDA provides information to family members following accidents. While on scene, TDA Specialists conduct briefings and provide updates on the investigation to family members. Once the on-scene phase of the investigation is over, TDA serves as the primary resource for information for family members as the investigation proceeds. TDA staff use a variety of applications and tools to manage these investigation activities.
Request for Information, Incident Management System, Page 2 of 6
The desidred outcomes of this RFI are for the NTSB to:
• Identify potential sources that offer COTS Software as a Service or Platform as a Service that could satisfy the NTSB’s requirements;
• Learn more about what needs can and cannot be met with existing market offerings;
• Determine the approximate cost of acquiring, implementing, and maintaining the solution(s);
• Learn about the technology and staff resources that may be required to implement and support the solution; and,
• Inform future budget planning.
Statement of Objectives
The NTSB’s ROC is seeking a cloud-based, web-enabled software as a service (SaaS) solution capable of providing a centralized, secure, and integrated incident management system designed to manage information during the launch of incidents, accidents, and events. The software shall include the ability to process information for mission/tasking, situation reporting, significant events, and incident action planning.
Scope of Work:
The NTSB ROC staff must be able to use the software to track, view, and print reports with the above information. The contractor shall provide professional services which are specialized in nature and focused on configuration and technical support for the software technology. The software shall be able to interface with the NTSB’s current emergency notification system to send SMS text, email messages, and voicemail messages to an individual or Outlook Active Directory group simultaneously through multiple types of devices (Android or Apple devices, email, and voicemail). The software shall be able to function for a minimum of 250 users simultaneously.
• Ability to process information for mission/tasking, situation reporting, significant events, and incident action planning create and send SMS text, email messages, and voicemail messages to an individual, groups, and external entities.
• Ability for recipient to respond back to messages with options to join telecoms.
• Ability to get overall notification results and create reports.
• Ability to provide status board access/ dashboard with limited read/write only functions to select users.
• Ability to allow simultaneous data entry, deletion and closeouts with the ability to identify who made the entry, deletion and/or closeout, time stamp the action and create a timeline of all actions.
• Ability for a select group of users to update all users’ contact data.
• Ability for select group of users to create and store prerecorded messages (i.e., accident/incident background information).
• Ability to allow limited (read only) to others depending on the nature of the event.
• Ability to allow employees to self-register their individual profiles and update contact information.
Request for Information, Incident Management System, Page 3 of 6
• Ability to access system via any web-based connection (browser or internet connected device) with appropriate user authentication and security controls. The software shall have the capability to independently continue services in the event NTSB’s IT infrastructure is compromised.
• Ability to allow the NTSB to provide portal access to outside originations who are not operating the same software/solution.
• Ability to map locations and addresses in the system.
• Chatroom instant messaging capability Between internal and external entities,
• Ability to create and update forms and templates
• Ability to provide an instant messaging system that does not maintain a permanent record of the messages.
• Ability to create and print after actions reports.
• Ability to be compatible with web-based emergency notification system using SMS, landline, cell phones and emails to contact individuals 24-hours 7-days per week.
• Ability to create an internal flag/warning system that is user specific before data is shared or emailed.
• Ability to receive alerts from, receive data from, send alerts to and send data to an in-house application which provides an Open API interface.
• 24/7 tech support available by telephone
• Ability to attach multiple file types to a case in different areas of the record (i.e., POC, photos, letters, PDF, spreadsheets, Word documents, etc.)
• Ability to notify family members via email or SMS of upcoming board events and manage RSVPs
The Case Management System (CMS) requires:
• The solution must be able to send emails from within the CMS and automatically associate TDA-generated emails with the case and quickly associate incoming emails with a case and with the TDA case manager.
• The solution shall provide auto-notification to TDA staff of case assignment/pick-up via email or notification to all users’ dashboard to avoid duplication of effort. The notification shall include case number identifier, keys number identifier, Investigator in Charge (IIC), number of fatal and injured, and accident date.
• Access to TDA dashboard via iPhone and/or authorized agency hardware. A mobile app for the android and iPhone is desired.
• Autogenerate notifications to family members from templates within the system vs. creating Outlook emails separately for each point of contact (POC).
• Ability for family members to input contact info via update request forms or email sent to a designated email address.
• The proposed solution must have a calendar capability for notification and tracking purposes.
• Upon entry of a case in the system, automatically create a calendar reminder, eleven months after the date of the accident, prompting the case manager to reach out to the IIC for a one-year investigative update.
o Select a random time of day for which those reminders would be set.
o Ensure that the reminder does not flag the “appointment” as “busy” in the case manager’s calendar.
Request for Information, Incident Management System, Page 4 of 6 o Include a standard 15-minute reminder alarm.
• The CMS shall be able to integrate with in-house developed applications using REST APIs and or
OpenAPI.
• The CMS shall have the ability to be managed by the TDA staff for basic edits such as field changes, dashboard views, etc. without intervention by the vendor.
• One of the main tasks of this system is the ability to track people associated with the case, their relationship to those involved in the accident, track correspondence with these people, and to quickly associate documents/comments with a person (or a subgroup of people).
Technical Requirements
• Software shall be available as a true Multi-Tenant Software as a Service (SaaS). The SaaS shall host the data and application in the cloud enabling users with internet connected mobile devices like iPad and iPhone to communicate and obtain real-time updates from the incident management solution. The SaaS ability is critical to the NTSB, as it allows for continued workflow and transmittal of vital real-time investigative information.
• Ability to collaborate and share data with outside entities to include other emergency response agencies and/or public health departments in real-time. This feature is only possible if the solution is a true Multi-Tenant SaaS in which single instance of software and its supporting infrastructure serves multiple agencies. This ability will allow the NTSB to communicate and gather vital information from various entities and agencies during launches investigations in a more effective and efficient manner. The unique real time collaboration tool is essential to the future workflow of the NTSB’s ROC. This will allow the NTSB to effectively collaborate with mission essential entities and allow greater information sharing with increased accuracy and reduced redundancy and delays.
• Ability to integrate with a Directory Services ( MS Active Directory, Okta, Azure Entra ID).
• Software shall have a mobile application that will work on Apple or Android OS.
Security Requirements
• All cloud services must be FedRAMP authorized and shall meet all Federal FISMA guidelines and
NTSB IT policies for the protection of privacy of unclassified data. If not FedRAMP authorized, potential offerors shall indicate if they are willing to obtain FedRAMP authorization within 24 months of contract award.
• FedRAMP Requirements - Before any cloud solution, including software-as-a-service (SaaS) applications can be used by a federal agency, they must first achieve FedRAMP Authorization to Operate (ATO). Established as a program in 2012 and codified into law in 2022, FedRAMP provides a standardized approach to security and risk assessment for cloud technologies and federal agencies, helping promote the adoption of secure cloud services across the government.
The system must comply with a baseline (low, moderate or high) that aligns with the sensitivity of data handled in that system. The majority of SaaS solutions serving government agencies will handle or process data that meets the FIPS 199 criteria for a moderate impact level, meaning those systems would handle Controlled Unclassified Information (CUI), or government data that is not publicly available. For those systems, this means strict compliance with 323 security baseline controls spanning 18 NIST 800-53 (Rev. 5) control families.
• Non-FedRAMP options - In-progress of receiving a FedRAMP authorization.
• Current Network Security Requirements - The Federal Information Security Management Act
(FISMA) is a piece of United States legislation, enacted as part of the Electronic Government Act https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final https://kirkpatrickprice.com/audit/fisma/
Request for Information, Incident Management System, Page 5 of 6 of 2002. FISMA’s intent is to protect government information and assets from unauthorized access, use, disclosure, disruption, modification, or destruction of information and information systems. FISMA is the law; NIST Special Publication 800-53, Security Controls for Federal Information Systems and Organizations, is the standard that contains the individual security controls required to comply with FISMA. NTSB network (part of GSS) is a FISMA Moderate compliance.
Accessibility Requirements Section 508 of the Rehabilitation Act requires Federal agencies to make their electronic and information technology accessible to people with disabilities. This applies to all Federal agencies when they develop, procure, maintain, or use electronic and information technology.
All electronic and information Technology (EIT) procured through this contract must meet the applicable accessibility standards specified in 36 CFR1194.2, unless an agency exception to this requirement exists.
The standards define Electronic and Information Technology, in part, as “any equipment or interconnected system or subsystem of equipment that is used in the creation, conversion, or duplication of data or information.” The standards define the type of technology covered and set forth provisions that establish a minimum level of accessibility. The application section of the standards (1194.2) outlines the scope and coverage of the standards. The standards cover the full range of electronic and information technologies in the Federal sector, including those used for communication, duplication, computing, storage, presentation, control, transport and production. This includes computers, software, networks, peripherals and other types of electronic office equipment.
Web Hosting Requirements Software as a Service (SaaS). SaaS is application software hosted on the cloud and used over an Internet connection by a web browser, mobile app or thin client. The SaaS provider is responsible for operating, managing, and maintaining the software and the infrastructure on which it runs. The customer simply creates an account, pays a fee and gets to work.
1. Responses
Interested parties are requested to respond to this RFI.
Written responses in a PDF compatible format are due no later February 3, 2025, at 4:00 PM/Eastern Time (ET). Responses shall be submitted via e-mail only to P. Matt Hazlinsky at matt.hazlinsky@ntsb.gov.
Proprietary information, if any, should be minimized and MUST BE CLEARLY MARKED. To aid the Government, please segregate proprietary information. Please be advised that all submissions become Government property and will not be returned.
Section 1 of the response shall provide administrative information, and shall include the following as a minimum:
Organization Name, mailing address, physical address (if different from mailing address), phone number, fax number, and e-mail of designated point of contact. Include your Unique Entity Identifier (UEI) from your System for Award Management (SAM) registration, if you are currently registered.
https://nvd.nist.gov/800-53
Request for Information, Incident Management System, Page 6 of 6
Tailored capability statements addressing the particulars of this effort, with appropriate documentation supporting claims of organizational, staff and software capability. If significant subcontracting or teaming is anticipated to deliver technical capability, organizations should address the administrative and management structure of such arrangements.
Business type (large business, small business, small, disadvantaged business, 8(a)-certified small, disadvantaged business, HUBZone small business, woman-owned small business, very small business, veteran-owned small business, service-disabled veteran-owned small business), based upon North American Industry Classification System (NAICS) code 513210, Software Publishers, size standard $47.0M. Please refer to Federal Acquisition Regulation (FAR) Part 19 for additional detailed information on Small Business Size Standards.
The number of pages in Section 1 of the response will not be counted towards the 15-page limitation. The 15-page limitation applies only to Section 2 of the response.
Section 2 of the response shall address the capabilities of the SaaS to satisfy the requirements listed in the Background and Scope of Work paragraphs of the RFI. Responders are requested to indicate if there is information that is not clear or could otherwise be improved upon to perform the requirements of the contract to industry standards.
2. Questions
Questions regarding this announcement shall be submitted in writing by e-mail to the Contracting Officer at matt.hazlinsky@ntsb.gov. Verbal questions will NOT be accepted. Questions will be answered by posting answers to the selected Government point of entry; accordingly, questions shall NOT contain proprietary or classified information. The Government does not guarantee that questions received after January 24, 2025, at 4:00 PM/ET will be answered.
Summary
THIS IS A REQUEST FOR INFORMATION (RFI) ONLY to identify parties that can provide a COTS Incident Management solution capable of tracking investigation cases and report on all activities associated with disaster victims and their family members. The information provided in the RFI is subject to change and is not binding on the Government. NTSB has not made a commitment to procure any of the items discussed, and release of this RFI should not be construed as such a commitment or as authorization to incur cost for which reimbursement would be required or sought. All submissions become Government property and will not be returned.
| Description |
| The Case Management System (CMS) requires: |
| Technical Requirements |
| Security Requirements |
| 1. Responses |
File details come from the government source that posted it. Updated .