RFQ_2031JW25Q00002 - FINANCIAL MANAGEMENT SYSTEM MAINTENANCE AND SUPPORT.pdf
PDF 902 KB Posted
- Attached to
- Financial Management Systems Maintenance and Support Federal contract opportunity
- Solicitation number
- 2031JW25Q00002
About this file
This document is a Request for Quotation (RFQ) for Financial Management Systems Maintenance and Support services for the Office of the Comptroller of the Currency (OCC). The OCC requires a contractor to perform services for its financial management system, $MART, which includes Oracle PeopleSoft modules for general ledger, accounts payable, accounts receivable, requisitions, purchase orders, asset management, and commitment control. The system also interfaces with other government systems. This will be a small business set-aside contract with a NAICS code of 541519 and a size standard of $15 million. The OCC intends to award a firm-fixed price contract with a base year and four option years. All responsible small businesses may submit a quote in accordance with the solicitation.
View the file
Other files for this federal contract opportunity
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
| �� | ����� | ���� |
| �� | ��� | ������������������ |
| ���������� | �� |
����� !"#$%&#�'��()(*+,))�-./�0.122.�0�3456" "%"&# �7�#�$898#%�&9:%;&<<8;�&=�%!8��6;;8#4>
| A A B,*B*+� | C����������D�*))E)) F�� |
| �D������ | ��D������� |
| ��� | �� | |
| �G���� | ��� | |
| H� | � | � |
| �� | � |
��H�I������
| ��� | |
| ��J������ | �K �� |
| �D��������� | ���� *(L*ML()(,�*M))�2.**L(,L()(,NOP'3��QP2ON RST�UTVVWUX�UYVVZ[\]̂ _̀ abc\_]�dbeef_̂̀ �g_e\d\cbc\_] ��� |
�������������h� ��������������������� I�� �����������J�������h ?��� ��()M*i�(Bj))))(k����
| ��� | ||
| ��������g_e\d\cbc\_]ld_]c̀ bdcl_̀ mǹ �̂_̀ �d_aaǹ d\be�\cnag ������H� | � | � |
�������� ��K������ �* �o-�pqqrsps�tp�upvwxrtr�yxpuz{�|}~�|�~�}�~�}�~�����
�h
| �k����� | ����� |
| �� !"#$%&#�'��()(*+,))�-./�0.122.�0�3456" "%"&# �7�#�$898#%��� | ���������������� |
� ������� �M,
| ��������� | |
| ��� | ������ |
| �� | ������������ ����� |
| ������@ ����� | � |
�����������������k�
����GG��J�������
| ��� | �������������� |
| ������������� | �������C |
| ������������ | ���� �����&9:%;&<<8;�&=�%!8��6;;8#4> � |
| �������������� | ������� | |
| ������ | K | ��������������� |
K������
�I���
| ����J��� | ���� | |
| ������ | �����H���� | ���G�� |
| ������� | ��h���� |
| ����� | ����� |
�)))*������ 8��8�;���������"#�#4"�<�7�#�$898#%�0> %89 ��#��7�"#%8#�#48*))*�����:%"&#��8�;�O������*����������"#�#4"�<�7�#�$98#%�0> %89��#��7�"#%8#�#48����������:%"&#�N"#8�O%89����������&#%"#68��EEER�ZW��W�W�ZW�Y���T���XXYU������X�T�YV���WWXZ�YZ�SWUWZZY��[
� ����D�@ @@ �����NOP'3��QP2ON ����
| ��k� � | � | |
| ��� | �K�������� | � |
���K�����
| � | ���� | |
| � | ��� | �K� |
���K������
J�¡�������� K���
�h���
| ������k������I������k������k� | ������ |
| ����������������������J������ | ����������� |
��R�¢£S�¤��¥�¦§�̈¦S¤��̈ ¤¢S£�¦§§¢̈¥�[�JG¡�������� K��� J���������
� �K� ���R¤�©W�T��©���X[���� ���������� ��������������ª�
| ��� | |
| �� | � |
������k������� �k������I�������k������J������k������k���������
����R§T��£T�X«��ZW�¦�V�[
gcb]mb̀ m�̂_̀ a�¬®�̄̀ n°��±l±²¬±³µ́¶·̧µ¹º¶»�º¼�½gb�¾�̂b̀ �̄¿�d̂ ³̀�ÀÁ�±¬±
� C����
| ����� | � | |
| �� | ��� | |
| ���������JG������������� | ���� | |
| ��� | K����R¤�©W�T��©���X[JG���� | K������� |
�h
| �� | ����H� | ����� |
| �� | K���� | ��� |
������������������k���
| ��� | �K��������� |
| �� | �� |
�D������
| � | �� |
| ��� | �*���� �� |
| � | �� |
| ��� | �+������ |
��/��0112332445#���� �����������06789:;7<5#���� ��������" �0=>;<:5#!�������#!������
?@ABCADC�EFDG�HIIJ�KDLMN�OPOQHOR�SATU
��VWWX����YZ[\]̂�_̀ab�V�c�dY_Ve��������f\̂ âg\ah�iâajk̀ [̂�lmn[̀kn�âo�ia\̂ [̀ â̂ g̀��������dYZ[\]̂�p\̂ �̀q[̀kerWWX����YZ[\]̂�_̀ab�r�c�dY_re��������f\̂ âg\ah�iâajk̀ [̂�lmn[̀k�âo�ia\̂ [̀ â̂ g̀��������dYZ[\]̂�p\̂ �̀q[̀kesWWX����YZ[\]̂�_̀ab�s�c�dY_se��������f\̂ âg\ah�iâaj̀ k̀ [̂�lmn[̀kn�âo�ia\̂ [̀ â̂ g̀��������dYZ[\]̂�p\̂ �̀q[̀ke
��t���� ����
�uv�V�]w�
Request for Quote - Financial Management Systems Maintenance and Support OCC Solicitation No. 2031JW25Q00002
1 GENERAL
The contractor shall furnish all technical, management, supervision, labor, materials, and any other support necessary to provide the services as described in the Statement of Work (SOW). The NAICS code for this requirement is 541519: Other Computer Related Service. This is a Small Business Set-Aside consistent with FAR 19. This solicitation will be conducted with streamlined procedures, in accordance with FAR 12.6 and 13.5 procedures.
2 LINE-ITEM DESCRIPTION
The Contractor shall furnish all management and labor support services necessary to perform technical maintenance and support of the Office of the Comptroller of the Currency’s (OCC) Financial Management (FM) Systems as described in Section II Statement of Work (SOW).
3 PRICING
The contract will be Firm-Fixed-Priced (FFP). Services shall be performed at a fixed price per month basis. The fixed monthly rates specified herein shall include all overhead, fringe benefits, general and administrative expenses, and profit for the successful performance of all specified services. Prices are required for all contract line-item numbers (CLINs). The contract will consist of a base period and four one-year option periods. The option periods will be exercised at the sole discretion of the Government consistent with FAR 52.217-9. The following table shall be used to provide pricing.
SECTION I - SUPPLIES OR SERVICES AND PRICES/COSTS
3.1 PRICING TABLE
CLIN
PERIOD OF
PERFORMANCE
QTY
UNIT
MONTHLY
PRICE
EXTENDED
AMOUNT
Base Year – Maintenance and Support 12/30/2024-12/29/2025
MO
1001 Option Year 1- Maintenance and Support 12/30/2025-12/29/2026
12 MO
2001 Option Year 2-
12/30/2026-12/29/2027
3001 Option Year 3-
12/30/2027-12/29/2028
4001 Option Year 4-
12/30/2028-12/29/2029
TOTAL OF ALL CLINs:
1 BACKGROUND
The Office of the Comptroller of the Currency (OCC) was established in 1863 as a bureau of the Department of the Treasury. It is responsible for regulating and supervising the national banking system. The OCC charters, regulates and examines approximately 769 national banks, 248 federal savings associations, and 49 branches and agencies of foreign banks in the United States. The OCC's nationwide staff of examiners conduct on-site examinations of national banks and provide sustained supervision of bank operations. Its mission is to ensure that national banks and federal savings associations operate in a safe and sound manner, provide fair access to financial services, treat customers fairly, and comply with applicable laws and regulations.
The OCC is a non-appropriated federal financial regulatory bureau of the Department of the Treasury with approximately 3,500 permanent employees. The OCC is headquartered in Washington, DC and has six (6) regional offices, 88 mid-size and trust locations, and 26 large bank locations.
2 PURPOSE
The purpose of this SOW is to request technical support services for the OCC’s Financial Management (FM) Systems. This is a non-personnel services contract. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the contractor who, in turn, is responsible to the Government.
FM Systems include the core financial management system, and $MART, which supports the OCC’s operations. $MART includes Oracle PeopleSoft version 9.2 modules for General Ledger, Accounts Payable, Accounts Receivable, Requisitions, Purchase Orders, Asset Management, and Commitment Control, to include the repair, design, development or update of existing and new interfaces, and custom system functionality. Examples of custom functionality include Expense Reports Online (ERO), Non-Travel Reimbursements (NTR), Event Planning, Investments, $MART security, Invitational Travel, Bank Assessments, Lease Management, Lease Notice to Proceed, 1099 processing, Civil Monetary Penalty (CMP), 1098 processing, and Retiree Billing.
The financial management system also interfaces with other systems and organizations such as PRISM, Citibank’s CitiDirect System, Invoice Processing Platform (IPP), National Finance Center (NFC), System for Award Management (SAM), Pay.gov, Central Accounting Reporting System (CARS), Treasury Information Executive Repository (TIER), Financial Planning and Performance Tool (FPPT), and Integration Hardware Asset Management (IHAM).
SECTION II – STATEMENT OF WORK
3 SCOPE
The contractor shall provide technical services to support Operations and Maintenance (O&M) activities related to FM Systems and its interfaces. These functions include:
• Performing updates, enhancements and code changes, and testing patches and upgrades in all environments.
• Maintaining a stable system thereby minimizing end user disruption
• Supporting end-user requests through System Help Reports (SHR’s)
• Working with OCC Database Administrators (DBAs) to complete upgrades to current versions of PeopleSoft whenever they are available and a decision to upgrade has been made by the OCC COR.
• Implementing and documenting structured and disciplined processes and initiatives as directed and approved by the OCC COR.
• Adhering to Information Technology Services (ITS) operational standards such as configuration management, Systems Development Lifecycle (SDLC) tools and procedures, and development strategies to obtain compliance.
• Supporting other functionality currently in, or integrated with, the Oracle PeopleSoft environment (e.g., Retiree Billing, Travel and Expense Reimbursement, Conference Expense Form, Help Desk, Expense Reports Online (ERO), OCC’s Time and Attendance System (e-TIME)).
• Building and supporting current and new interfaces and data exchanges to internal and external systems or processes
• Accounting and process support for Oracle PeopleSoft Financials/Supply Chain Management (FSCM), integrated custom functionality, and both internal and external interfaces supporting the full range of federal financial management functionality and systems.
• Providing technical and data analytics support for business process improvement initiatives.
• Functional accounting, technical programming, troubleshooting and process support as it relates to Federal financial reporting, data element and validation requirements, and required reporting to the Department of Treasury (e.g., Treasury Information Executive Repository (TIER), Government Wide Treasury Account Symbol (GTAS) Adjusted Trial Balance System, DATA Act, OMB Circular A-136, OMB Circular A-123).
• Provide technical and analytical support for identifying discrepancies between PeopleSoft and internal and external systems i.e., DATA Act, Payroll, Pay.Gov.
• Support any other Government wide or FM strategic initiatives involving or relating to FM systems and data.
4 TASKS
4.1 General
The contractor shall provide technical services to support O&M activities related to FM systems. These functions include:
• Performing analysis of issues and identifying the root cause of FM system problems to correct and avoid them in the future.
• Performing test planning, environment preparation, test execution, and documentation activities as necessary to support OCC’s Disaster Recovery program.
• Monitoring the operations of FM Systems, addressing issues as they arise, and modifying documentation as changes occur in OCC’s infrastructure and data formats from external providers.
• Monitoring daily system assurance reports and addressing data anomalies as they arise.
• Assisting OCC's Financial Management team in addressing edit and validation warnings and errors for month-end reporting to TIER, and DATA Act, and subsequent reporting in GTAS.
• Assisting OCC in efforts to adhere to OMB Circular A-136 executive branch financial reporting requirements.
• Performing testing, reviewing, and documentation activities as necessary to support internal or external reviews and audits (OMB Circular A-123/Audit Findings, CFO Act, FFMIA, FISMA) activities relative to FM Systems.
• Providing end user Help Desk Support on an “as needed” basis to the FM Systems or Accounting teams. The contractor shall provide transaction/reimbursement processing support, which includes assisting end users when they encounter issues when processing transactions in $MART.
• Supporting the Financial Management Systems or Accounting teams in processing adjustment transactions or emergency fixes.
• Assisting the FM Systems or Accounting teams with analysis of data anomalies.
• Providing subject matter expertise on Federal accounting transactions to assist in troubleshooting and resolving transactional issues that occur in the financial system.
• Assisting end users with preparation for the OCC fiscal year-end closing during the period of performance, as well as preparation of the next fiscal year set- up.
• Providing support to the FM Systems or Accounting teams with any issue resolution.related to the $MART financial system.
• Supporting OCC FM team end users in loading high volumes of transactions in an automated fashion (e.g., spreadsheet j o u r n a l - uploads).
• Providing reporting support for nVision (web and client server), PeopleSoft Query, Crystal Reports, SQR Reports, and PeopleSoft Business Intelligence Tools.
• Support Oracle PeopleSoft built-in reports and dashboards as well as developing custom queries for external reporting and dashboard tools.
• Building views and queries for FM Data Warehouse efforts
• Managing system updates as they relate to DATA Act implementation and compliance.
• Monitoring, researching, analyzing, and providing resolution on DATA Act Corrective
Actions.
• Providing end user with TIER/Award file support to ensure timely submission of
Treasury deliverables.
• Provide overall technical and functional support for the responsibilities listed in the
(Section 13.0: Guidance and Related Systems).
In addition, financial data from $MART is used in monthly, quarterly, and annual financial statement and reporting deliverables to OCC management and the Department of Treasury (Treasury). As such, the data and reports contained in and generated by $MART is subject to annual audit by the Treasury’s Office of Inspector General. The contractor must possess a comprehensive knowledge of authoritative guidance and applicable laws and regulations related to Federal financial management currently in place and any enacted throughout the project duration. Section 13.0: Guidance and Related Systems provides a listing of applicable guidance and related systems.
4.2 Financial Systems Operations & Maintenance
The contractor shall provide technical support for updates to the $MART application modules required to address system issues and implement minor enhancements (via the Change Control Board).
The contractor shall provide planning and testing support when OCC DBAs deploy Oracle PeopleSoft / PeopleTools / WebLogic Maintenance Packs, periodic and critical patches and fixes to ensure the system platform remains as current as possible on the Oracle PeopleSoft software. These periodic patches and fixes include the maintenance of the Oracle PeopleSoft platform and hosted application functions.
The appropriate Software Development Life Cycle (SDLC)deliverables must be produced and will be subject to a quality review by the Contracting Officer’s Representative (COR) and maintained in a document repository. The following System Change Requests (SCRs) procedures shall be followed for delivery of enhancement request/fix bundles or upgrade:
• Documentation of the enhancement requirements, upgrade, patch, or system issue, including preparation of the Preliminary Engineering Change Proposal (PECP).
• Seek approval by the $MART Change Control Board to make the change.
4.3 FM System Management Initiatives
The contractor shall support initiatives that have been approved by FM management to improve the overall maintenance of the FM systems. For each identified initiative, the contractor shall develop an advised approach and/or formal plan outlining the objectives, identify resource requirement, and develop an implementation phase. The execution of any resulting activities by the contractor to support and/or implement the initiative shall depend on COR approval, and priority as defined by OCC. These initiatives include:
• $MART Upgrade Analysis and/or Implementation: May include performing a comparison of existing requirements against available software packages on the market today; implementing the upgrade from the current Oracle PeopleSoft product.
• Configuration Management: Updating the existing $MART Configuration Management plan to reflect the Change Control Board procedures. Support and maintenance of change management tools.
• Knowledge Transfer: Transferring knowledge to the FM Systems team on user functionality, programming support, interfaces and upgrades, by maintaining a formal process guide.
• Document Library: Maintaining, updating, and improving the $MART Document Library.
• $MART Homepage: Maintaining, supporting, and improving the $MART Homepage.
• Upgrade Support: Ensuring current Financial Management Systems functionality is compatible with new office products or other software upgrades.
• MS SQL Server Upgrades: Assisting with managing deployment and knowledge transfer with the OCC DBAs and performing system testing prior to implementation, as well as regression and cutover testing on “go-live” weekend.
• Business Process Reengineering: Reviewing functional and system processes and flowcharts to develop more efficient, effective ways to do business.
4.4 FM Systems Interfaces/Interconnections
The contractor shall manage the interfaces/interconnections between FM systems and other systems. This includes:
• Maintaining and monitoring all existing interfaces.
• Establishing new interfaces per OCC requirements.
• Resolving transactional errors stemming from interface malfunctions from OCC responsibilities.
• Assisting in the establishment of formal interface agreements between system owners within and outside of FM that are responsible for the operations of integral and external systems.
• Documenting information to be exchanged over the interface and providing precise technical definitions of interface data flows and protocols.
• Forming strategies for developing, testing, and deploying/redeploying interfaces, including creation of the requirements, design, and testing documentation required.
• Maintaining schedules and resources required to complete the interface management effort.
• Ensuring OCC’s Configuration, Quality, and Risk Management Procedures relevant to interface management are utilized.
4.5 FM Systems Business Analysis
The contractor shall provide support to facilitate system changes. This includes:
• Assisting in the development of Business Process diagrams to articulate changes to the $MART / Oracle PeopleSoft system.
• Supporting OCC’s FM business unit and ITS personnel in the enhancement and/ or redesign of OCC business processes.
• Providing subject matter expertise in both federal accounting and financial systems applications to troubleshoot process and system issues and improve the system via changes, upgrades, and enhancements.
• Providing subject matter expertise in Federal Oracle PeopleSoft technical implementation to make system changes, upgrades, and enhancements.
• Ensuring $MART/ERO and all PeopleSoft Applications are mobile-ready in the OCC environment.
• Developing and maintaining reporting tools for financial data including nVision and Tableau.
• Developing and maintaining changes to support automation and efficiency in OCC processes.
5 TRANSITION PHASE
The overarching objective of the Transition Phase is a low risk and low impact (to end users) transition as the contractor assumes responsibilities from the incumbent contractor.
The services provided under this contract are vital to the OCC’s mission and must continue without interruption or degradation. The transition is the primary body of work immediately after contract award and through the end of the transition phase.
In this phase, the initial set of Service Level Agreements (SLA) and metrics will be introduced, baselined, and reported on during this time period. These items set the foundation for continuing performance assessment. It is anticipated that the contractor performs in a back-up and transitioning role for some time and then transitions to the primary role for the remaining time of the phase. It is OCC’s expectation that the contractor’s subject matter experts (SMEs) are on-site to capture, document, and actively participate in the knowledge transfer process.
In this phase especially, the offeror is free to propose any and all support solutions and services based on industry best-practices and organizational experience to meet OCC’s requirements and ease the transition from the incumbent to the new contractor.
The transition phase shall not exceed sixty (60) calendar days. At the conclusion of the transition period, the contractor shall assume full responsibility of the services requested in this contract.
5.1 Phase Out
The contractor shall submit a service migration plan prior to contract end. The plan shall provide the process and procedures for a 30-day migration (unless directed otherwise) of contractual responsibilities and include procedures for supporting operations and maintenance activities related to FM systems throughout the transfer of operational responsibilities from the contractor’s supervision to another contractor or the Government.
The Plan shall also include details regarding communications and coordination with the new service provider, an approach to ensure a smooth migration. The plan shall also include a complete and full inventory of SDLC artifacts to be transferred to the incoming contractor. The plan shall be submitted within 90 days prior to the end of the base year period of performance. The Transition Plan approved by the CO shall be implemented at the direction of the CO and/or Contracting Officer’s Representative (COR) prior to contract end.
6 DELIVERABLES
The contractor shall ensure that all deliverables, including documents, reports, charts and graphs delivered in electronic format adhere to the accessibility requirements in this SOW.
The contractor shall submit all deliverables to the COR, and COI Contracting Officer n electronic format in accordance with the frequencies stated below.
Section Deliverable Description 5 Transition in Plan 5 days after contract award
5.1 Phase Out Plan 90 days prior to the end of the contract
6.1.1 Applicable SDLC Deliverables One week after completion of task
6.1.2 Problem Reports Subject to Priority as conveyed by COR
6.1.3 Status Reports Monthly (date to be proposed by the
vendor)
6.1.4 Knowledge Transfer Guide 60 days prior to the end of each performance year 8 Evidence of OCC mandatory security and privacy training for each contractor staff working in support of this contract
Prior to network access, and annually
10 Non-Disclosure Agreements for each contractor staff working in support of this contract
Prior to network access
6.1 Deliverable Descriptions
6.1.1 Applicable SDLC Deliverables
The contractor shall deliver applicable SDLC artifacts in support of Tasks 5.0.
6.1.2 Problem Reports
The contractor shall notify the COR via email immediately of any problems that cause an interruption to the end user with no alternate means of completing the work. All other problems will require COR and CO notification within 1 business day of discovery.
6.1.3 Monthly Status Report
The contractor shall provide a status report with the following information monthly:
• Monthly Status Report including work performed in the current month and upcoming month, contract financial status, and risks/open issues.
• Monthly Invoice
6.1.4 Knowledge Transfer Guide
The contractor shall support the development and maintenance of documentation for FM systems. In addition, the contractor shall maintain a current guide which documents processes and procedures essential to the successful operation and maintenance of FM systems as proposed for the tasks in Section 4 of the SOW.
6.2 Format
Software applications currently used by OCC to support office operations include:
• Full Suite of Microsoft 365 Apps for Enterprise Products (i.e., Word, Excel, Power Point, Outlook, Project, Access, and Visio)
All documents shall be delivered in electronic format to the CO and COR. Electronic copies shall be delivered using the Microsoft Office Products or as requested by the COR.
In the event the delivery system is unavailable or not accessible due to a system malfunction, the contractor shall submit all reports in hardcopy format to be followed with an electronically transmitted copy as soon as the electronic mail system becomes available.
6.3 Government Acceptance Period
The COR will review deliverables prior to acceptance or provide the contractor with documented reasons for non-acceptance. In the event of a rejected deliverable, the contractor will be notified in writing by the COR of the specific reasons for rejection. The contractor shall have an opportunity to correct the rejected deliverable and return it in accordance with delivery instructions.
The COR will have five (5) business days to review the deliverable and make comments.
The contractor shall have two (2) business days to make corrections and redeliver it to the COR. Should the OCC fail to complete the review within the review period, the deliverable will be considered accepted, unless a longer review period is mutually agreed upon between both parties.
The contractor shall be responsible for timely delivery to OCC personnel in the agreed upon review chain, at each stage of the review. The contractor shall work with OCC personnel reviewing the deliverables to assure that the established schedule is maintained.
The contractor shall take into account corrections in order to meet delivery requirements.
7 TASK MANAGEMENT
7.1 Personnel Management
7.1.1 Supervision of Employees
The contractor’s employees shall always remain under the contractor’s direct supervision. Although the Government will coordinate directions within the scope of the contract, detailed instruction for the contractor’s employees and supervision shall remain the responsibility of the contractor.
The contractor agrees that this is a non-personal services contract; that for all the purposes of the contract, the contractor is not, nor shall hold himself out to be an agent or partner of, or joint venture with, the Government; and that he shall neither supervise nor accept supervision from Government employees.
7.1.2 Business Hours and Coverage
The contractor shall support all tasks between the hours of 6:00AM – 5:00PM Eastern Time. If contractor determines there exists a need to perform work outside of these hours and/or remotely, prior approval must be sought and granted by the COR.
Further, contractor may be required to provide support outside of normal business hours on an as-needed basis at the Contracting Officer’s Representative’s request.
8 GOVERNMENT FURNISHED INFORMATION SECURITY
Contractor staff requiring access to the OCC’s network shall be issued OCC computers.
The Government will also provide access to all personnel systems, equipment and organizations deemed necessary for the performance of the duties outlined above. All development and management of security artifacts must be performed using Government Furnished Property and Other Resources (this includes OCC computers in the network, VPN access, and mobile.occ.gov).
Government furnished information may take the form of policies, standards, guidelines or technical documentation. The contractor shall protect from loss or unauthorized disclosure any materials or information made available to it during the performance of the contract.
When not in use, written materials that the COR identifies as sensitive or confidential shall be secured in locked receptacles provided by the OCC. The contractor shall provide security levels and controls that are required by regulation and consistent with best government and professional practices. They shall provide a certified security environment where Government data resides is protected while at rest, in motion and in use.
All contractor personnel with access to OCC facilities and/or systems must complete OCC-provided mandatory security and privacy training prior to gaining access to OCC information systems; and completed again each year when OCC launches the training for all contractors and employees. Non-compliance may result in revocation of system access.
9 POST AWARD ORIENTATION
The OCC will have a post-award orientation within five (5) working days after contract award. The post-award orientation will be held at OCC Headquarters in Washington, DC and will serve as the kick-off meeting which will include a discussion of contract requirements, the schedule for the completion of this requirement, and any other pertinent information that the contractor will need to meet the performance requirements of this contract. The contractor’s key personnel shall attend this orientation.
10 NON-DISCLOSURE AGREEMENT
The contractor shall not disclose any information obtained in connection with work under this contract without OCC written authorization. Contractor personnel are prohibited from downloading OCC data, including e-mail attachments of OCC data files, to any contractor media without OCC knowledge and consent. All contractor personnel working under this contract and/or having access to privileged information shall execute the Non- Disclosure Agreement (Attachment 1) supplied by the OCC.
11 PLACE OF PERFORMANCE
Work on this task may be performed on-site at the OCC offices at Constitution Center, 400 7th Street SW, Washington DC, 20219. The Government will furnish working space, required equipment, and access to the current desktop environment, inclusive of Microsoft Office. Work on this task may also be performed off-site at a remote location, with prior approval by the COR.
12 PERSONNEL
Certain skilled and experienced professional and technical personnel are essential for successful accomplishment of the work included in this SOW. The OCC requires the Lead/Manager be designated as Key Personnel.
12.1 Minimum Qualifications
The minimum qualifications for Key Personnel assigned to this requirement are as follows:
1. The Lead/Manager - shall have at least 10 years of current and consecutive experience with Federal accounting concepts and processes and reporting requirements, and technical proficiency in PeopleSoft Federal Financials environment. Current Certified Public Accountant (CPA) license is preferred.
13 GUIDANCE AND RELATED SYSTEMS
Guidance:
• Office of Management and Budget (OMB) Circular A-123, “Management’s Responsibility for
Enterprise Risk Management and Internal Control,” and related appendices
• OMB Circular A-136, “Financial Reporting Requirements”
• Digital Accountability and Transparency Act of 2014 (DATA Act) and related OMB and
Treasury guidance
• Treasury Financial Manual (TFM)
• U.S. Standard General Ledger (USSGL)
• Federal Financial Management Improvement Act (FFMIA)
Related systems:
• Government Wide Treasury Account Symbol (GTAS) Adjusted Trial Balance System
• Central Account Reporting System (CARS)
• Collections Information Repository (CIR)
• Federal Procurement Data System (FPDS)
• Intra-Government Payment and Collection (IPAC)
• Invoice Processing Platform (IPP)
• Pay.gov
• System for Award Management (SAM)
• Treasury Information Executive Repository (TIER)
14 ACCESSIBILITY REQUIREMENTS
Section 508 of the Rehabilitation Act, as amended by the Workforce Investment Act of 1998 (P.L. 105-220) requires that when Federal agencies develop, procure, maintain, or use information and communication technology (ICT), it shall be accessible to people with disabilities. Federal employees and members of the public who have disabilities must have access to, and use of, information and data that is comparable to people without disabilities. As such, the following requirements apply to this solicitation:
1. Products, platforms, and services delivered as part of this work statement that are ICT, or contain ICT, must conform to the Revised 508 Standards, which are located at 36 C.F.R. § 1194.1 & Apps. A, C & D, and available at https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines.
2. E102 / 702.10 – Web Content Accessibility Guidelines (WCAG) 2.0 guidelines success criteria level A & AA are incorporated as a requirement. The referenced WCAG criteria is available at http://www.w3.org/TR/WCAG20/.
3. A completed Accessibility Conformance Report (ACR) found at https://www.itic.org/policy/accessibility/vpat, using Voluntary Product Accessibility Template (VPAT) Revised Section 508 Edition, Version 2.4, is required to assist the Government in determining that the ICT products or services support Section 508 accessibility standards.
• E202 - General Exceptions Authorized by OCC as applicable.
The following items are identified as containing ICT:
• Information, Documentation, and Support
Applicable requirements for electronic documents and/or support services:
• E205 – WCAG Level A & AA Success Criteria
• E302 – Functional Performance Criteria
• E602 – Support Documentation
• E603 – Support Services
Conformance to all 508 standards shall be met unless exception is authorized by the OCC IT Accessibility Program Office.
https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines https://www.access-board.gov/guidelines-and-standards/communications-and-it/about-the-ict-refresh/final-rule/text-of-the-standards-and-guidelines http://www.w3.org/TR/WCAG20/ https://www.itic.org/policy/accessibility/vpat
15 SECURITY AND PRIVACY REQUIREMENTS
All Contractor personnel are required to have a Public Trust security clearance.
The COR and the Office of Security have the right to inspect the procedures, methods, and facilities utilized by the Contractor in complying with the security requirements under this contract. Shall the COR determine that the Contractor is not complying with the security requirements of this purchase order, the Contractor shall be informed by the CO of the proper action to be taken to effect compliance with such requirements.
Departing Contractor personnel shall complete the list of off-boarding activities as identified in the Contractor’s Off-Boarding Tasks, Attachment 1 of the contract. The COR shall receive the completed list of off-boarding activities and the completed TD F 80-
05.5 Documentary Materials Removal/Non-removal Certification for each Contractor personnel.
A. Compliance with Applicable Laws, Regulations, and Standards
• Federal Laws. The contractor and all of its respective subcontractors shall follow and remain compliant at all times with the Federal Acquisition Regulation (FAR), Privacy Act of 1974 (5 U.S.C. 552a - the Act), Federal Information Security Modernization Act of 2014 (Public Law 107-347) (FISMA).
In addition, the contractor is responsible for ensuring individuals supporting the OCC are trained in accordance with FAR clause 24.301, “Privacy Training.” The use of any information that is subject to the Privacy Act will be utilized in full accordance with all rules of conduct as applicable to Privacy Act Information.
• FIPS. The contractor and all of its respective subcontractors shall follow Federal Information Processing Standards (FIPS), National Institute of Standards and Technology (NIST) standards and guidelines, and other laws, mandates, or executive orders pertaining to the protection of sensitive information and information systems.
• Office of the Comptroller of the Currency (OCC) Policies and Procedures. The OCC understands that there are limitations in applying agency-specific policies to systems and environments shared with other organizations or customers. The requirements in this OCC Policies and Procedures subsection applies to all activities specifically performed for the OCC by the contractor (e.g., professional services to develop or customize a component for the OCC). The intent of this section is to require contractor compliance with OCC policies and procedures for those activities, tasks, and deliverables specifically and uniquely performed and/or completed for the OCC by the contractor that is not a typical service or component of the existing contractor system/solution. This section also applies to contractors with access and use of OCC information resources (i.e., OCC network, systems, laptops, other IT equipment, and/or OCC information).
The contractor and all of its respective subcontractors shall comply with all Office of the Comptroller of the Currency (OCC) security and privacy policies and standards in effect at the time of the award of the contract, as well as those requirements that may be added during the contract. The contractor/service provider shall conform to OCC administrative regulations, policies, and procedures, as listed in section [cite corresponding location in contracting document], in accordance with applicable federal laws, Executive Orders, directives, policies, regulations, standards, and guidance. The contractor shall work with OCC internal organizations, as needed, to ensure that policies, procedures, configuration control, and product life-cycle requirements are fulfilled to the satisfaction of OCC ITS.
B. General Requirements
• Location. Information collected, used, stored, maintained, or otherwise processed by the contractor in the performance of this contract shall be accessed, transferred, stored or processed only within the United States. In addition, the maintenance and support operations of the contractor's technology and information must take place, and originate from, within the United States.
• Authorization to Use, Store, or Share Sensitive Information. The contractor shall be responsible for properly protecting all information used, gathered, or developed as a result of work under this contract. The contractor shall also protect all government data, equipment, etc. by treating the information as sensitive. All information gathered or created under this contract shall be considered as Controlled but Unclassified (CUI) information. It is anticipated that this information will be gathered, created, and stored within the primary work location. If contractor personnel must remove any information from the primary work area, they shall protect it to the same extent they would their proprietary data and/or company trade secrets.
• Confidentiality. The contractor agrees to assume responsibility for protecting the confidentiality of government records and data associated with this contract, which are not public information.
• Non-Disclosure Agreement. Each individual who has access to sensitive OCC data and/or the OCC network, systems, applications, laptops, or other OCC information resources that may process, store, or transmit sensitive OCC data under this contract shall execute a Non-Disclosure Agreement before being allowed such access.
• Deliverables. The deliverables in this contract will be considered CUI and shall not be shared with any other organization without prior written approval from the [insert specific OCC role].
C. Security and Privacy Authorization
• Need to Know. Sensitive information, data, and/or equipment will only be disclosed to authorized personnel on a Need-To-Know basis. The Offeror shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected.
• Use of PII. The Offeror shall not use any Personally Identifiable Information (PII), E-mail Groups, Lists, or contract information for any purpose other than those activities necessary to the performance of this contract.
D. Configuration Management
E. Continuous Monitoring
• Compliance Reviews and Audits. The contractor shall permit and support compliance reviews and audits under applicable laws to allow the OCC to meet legal and compliance obligations and shall implement processes that allow visibility into the privacy and security controls employed and their effectiveness. The contractor shall provide the OCC or authorized designated officials with information requested by auditors in a timely manner, consistent with the respective auditor's deadline, in support of security compliance reviews and various annual audits, e.g., FISMA, Financial Statement Audit, A-123, etc.
F. Data Protection
• Data Encryption. Where encryption is required, as specified by the OCC, the contractor shall ensure that encryption is established and maintained for data at rest and in transit for the duration of the contract. The encryption employed shall be equivalent to those approved in Federal Information Processing Standards (FIPS) Publication 140-2 or 140-3.
• Need to Know. Sensitive information, data, and/or equipment will only be disclosed to authorized personnel on a Need-To-Know basis. The contractor shall ensure that appropriate administrative, technical, and physical safeguards are established to ensure the security and confidentiality of this information, data, and/or equipment is properly protected.
• General Use of Controlled Unclassified Information (CUI). The contractor shall not use any CUI or CUI subcategories, including, Personally Identifiable Information (PII) or low-sensitivity PII (e.g., E-mail Groups and Lists), for any purpose other than those activities necessary to the performance of this contract.
• Use of PII Specific to this Contract's Scope of Work. The scope of work for this contract has specific business driven and functional requirements that involve PII. The contractor, contractor employees, and subcontractors must physically secure PII when not in use and/or under the control of an authorized individual, and when in transit to prevent unauthorized access or loss. PII is no longer needed or required to be retained under applicable government records retention policies, it must be destroyed through means that will make the sensitive PII irretrievable. The contractor shall only use PII obtained under this contract for purposes of the contract and shall not collect or use such information for any other purpose without the prior written approval of the contracting officer. At expiration or termination of this contract, the contractor shall turn over all sensitive PII obtained under the contract that is in its possession to the government.
In accordance with OMB M-17-12 Preparing for and Responding to a Breach of
Personally Identifiable Information, the contractor and subcontractor(s) shall:
1. Properly encrypt PII in accordance with OMB Circular A-130 and standards per the
"Data Encryption" subsection above.
2. Complete regular training on how to identify and report a breach;
3. Maintain capabilities to determine what Federal information was or could have been accessed and by whom, construct a timeline of user activity, determine methods and techniques used to access Federal information, and identify the initial attack vector;
4. Allow for an inspection, investigation, forensic analysis, and any other action necessary to assist with responding to a breach;
5. Adhere to notification and reporting requirements specified in Section G. "Incident Response" to effectively report and manage a suspected or confirmed breach as soon as possible (within 1 hour) and without unreasonable delay, consistent with the OCC's Incident Response Plan and US-CERT notification guidelines. Please note that a report of a breach shall not, by itself, be interpreted as evidence that the contractor or its subcontractor failed to provide adequate safeguards for PII.
• Use of Contractor Equipment. Use of contractor-owned laptops or other equipment
(e.g., media storage devices, servers, etc.) to process, transmit, or store OCC information or to access the OCC network or other OCC information resources without OCC's formal approval is prohibited. This restriction does not apply to the use of non-OCC laptops or PCs to use OCC-approved virtual desktop infrastructure to remotely access the OCC network.
G. Incident Notification
• Notification. The contractor must report all information security incidents that potentially or actually cause the compromise of OCC information, even if the contractor believes the security incident may be limited, small, or insignificant with respect to OCC data or systems. The OCC will determine when the contractor's reported security incident requires additional focus and attention.
Within one hour from the time the contractor validates that an information security incident has occurred, the contractor must report the security incident information to the OCC Cyber Defense Center (CDC): Computer.Security@occ.treas.gov, (202) 649-7930, regardless of day or time.
The contractor must provide any supplementary information or reports related to a previously reported incident directly to the OCC CDC with the following text in the subject line of the email: “Supplementary Information/Report related to previously reported incident # [insert number].”
Do NOT include any Sensitive Information in the subject or body of any e-mail. To transmit Sensitive Information, use FIPS 140-2 compliant encryption methods to protect Sensitive Information in attachments to email. Passwords must not be communicated in the same email as the attachment.
When notifying the OCC CDC, copy the Contracting Officer if possible or, if reporting by phone or Contracting Officer's email is not immediately available, contact the Contracting Officer immediately after reporting the incident to the OCC CDC.
• Information, System and Tool Availability. The contractor shall make available any information, systems and tools necessary for the OCC to respond to incidents in a manner consistent with NIST SP 800-61, as amended. In the case of a reported security incident, the contractor shall provide the OCC with access to the contractor's system and/or facilities within 72 hours of the OCC's request.
H. Information Ownership
• Government Access. The government will retain unrestricted rights to government data.
The OCC retains ownership of any user created/loaded data and deliverables (e.g., documents, application, custom code, diagrams, workflows, data sets, etc.) hosted on contractors’ equipment, systems, infrastructure, etc., as well as maintains the right to request full copies of these at any time.
• Removal of OCC Data. The contractor acknowledges the OCC’s exclusive right of ownership of the information and is required to transfer, return, and/or delete all agency data collected, processed, stored or maintained by the contractor on behalf of OCC upon termination of services, and shall provide written certification and supporting documentation attesting to the transfer, return and/or deletion of agency information or data generated, collected, processed, maintained, or stored by the contractor and any subcontractors, per instructions the “Security and Privacy Vendor Deliverables” section
• Documents and Deliverable. The preliminary and final OCC-specific deliverables and all associated working papers are the property of the U.S. Government. The contractor shall not release any information without the consent of the Contracting Officer. All work papers, preliminary and final deliverables must be submitted to the COR at the conclusion of the contract in an acceptable and usable format, which may include the original format.
• eDiscovery. The contractor must ensure data preservation requirements (i.e., halt destruction and maintain data the contractor may not otherwise have to maintain) related litigation holds are met. The contractor shall also ensure that metadata associated with litigation holds are preserved. Metadata is electronically stored information that describes the history, tracking, or management of an electronic document. It is created automatically when a user creates, modifies, accesses, or takes other actions with respect to electronic format.
The contractor shall provide immediate access to all government data and government related data impacting government data for review or scan, or conduct of a forensic evaluation, and physical access to any contractor facility with government data.
I. Information Ownership
• Government Right to Terminate Access. The OCC, at its discretion, may suspend or terminate the access to any systems and/or facilities when an information security incident or other electronic access violation, use or misuse issue gives cause for such action. The suspension or termination may last until such time as OCC determines that the situation has been corrected or no longer exists.
J. Training Requirements
• Security Awareness Training. All contractor personnel with access to OCC data and systems must complete OCC-provided mandatory security and privacy training prior to gaining such access. Non-compliance may result in revocation of system access.
• Role-Based Training. The contractor shall ensure that IT personnel supporting this contract complete eight (8) hours of role-based specialized IT security training on an annual basis. The contractor must identify the IT personnel and their respective IT role1 that they serve in support of this contract. The contractor shall provide the list of List of IT Personnel on this Contract and Respective Role and the Completion Report for Role- Based IT Security Training per directions in the "Security and Privacy Vendor Deliverables" section.
1IT Personnel include systems engineers; software developers; systems security engineers; privacy engineers; system, network, and database administrators; personnel conducting configuration management activities; personnel performing verification and validation activities; personnel with access to system-level software; personnel with contingency planning and incident response duties;
personnel with privacy management responsibilities; personnel with access to personally identifiable information; and system security officers.
K. Supply Chain Risk Management
L. Security and Privacy Vendor Deliverables
Non-Disclosure Agreement (NDA) Deliverables
Section Deliverable Frequency Due Date
IV. B. General Requirements. Non- Disclosure Agreement
Non-Disclosure Agreements for each contractor personnel working in support of this contract Once
Prior to accessing OCC information resources
Removal of Data Deliverables
IV. F. Information Ownership.
Removal of OCC Data
IV. D. Data Protection.
Contractor Equipment
Certification of OCC Data Removal from Contractor’s (including any subcontractors), Possession, Equipment, and/or Environment. Data removal instructions include transfer of information to another party per specific instructions from the CO;
return of information, deliverables, etc., to the CO; and deletion of OCC data from contractor equipment (e.g., laptops and other contractor-owned equipment previously approved by the OCC for this use) using NIST SP 800-88, Guidelines for Media Sanitization, as amended.
Once
NLT 15 days after termination/ expiration of contract
Training Deliverables
IV. H. Training Requirements.
Role-Based Training
List of IT Personnel on this Contract and Respective Role
Initially and as changes occur
Initial: Within…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .