S02 - Attachment 1 - PWS - Cloud-Based Crisis Information Management Software v1.0 3.29.23.pdf

PDF 378 KB Posted

Attached to
DA10--NEW - Cloud Based Crisis Information Management Software (VA-23-00021808) Federal contract opportunity
Solicitation number
36C10A23Q0093
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This performance work statement outlines requirements for a cloud-based crisis information management software solution and managed service. The Department of Veterans Affairs seeks a commercial off-the-shelf web-based platform to exchange information with emergency management partners and support situational awareness. Required capabilities include common operating picture functionality, resource tracking, forms and report generation. The solution must integrate with VA systems and be hosted on the VA Enterprise Cloud. The contractor will implement the software within 45 days, provide training and help desk support, and maintain the system. The base period of performance is through July 2023 with four optional 12-month extensions to enhance platform workflows.

View the file

Other files for this federal contract opportunity

Other files attached to DA10--NEW - Cloud Based Crisis Information Management Software (VA-23-00021808), newest first.
File Type Posted
S06 - Amendment 0002 - 36C10A23Q0093.pdf PDF
S05 - Industry QAs - RFQ 36C10A23Q0093 Amend 02.pdf PDF
36C10A23Q0093 0002_1.docx DOCX document
S05 - Industry QAs - RFQ 36C10A23Q0093 Amend 01.pdf PDF
36C10A23Q0093 0001_1.docx DOCX document
S06 - Amendment 0001 - 36C10A23Q0093.pdf PDF
S02 - Attachment 2 - Video_Virtual Technical Demonstration Scenarios.pdf PDF
36C10A23Q0093_1.docx DOCX document
S02 - RFQ 36C10A23Q0093 3.30.23.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

Office of Operations, Security, and Preparedness Office of Emergency Management and Resilience

Cloud Based Crisis Information Management Software

Date: March 29, 2023 Version Number: 1.0

VA-23-00021808

1.0 BACKGROUND

The Department of Veterans Affairs (VA) is a cabinet level Department of the Federal Government charged with providing benefits and services to the nation’s Veterans and authorized dependents. The Department operates three distinctive business lines:

Healthcare, Benefits, and Memorial Affairs. Of these, the Veterans Health Administration operates the largest integrated healthcare system in the world with over 1,700 medical facilities. The Veterans Benefits Administration provides compensation, pension, insurance, education, and home loan guarantees. The National Cemetery Administration operates over 135 cemeteries across the nation. Overall, VA employs 340,000 employees serving 19 million Veterans.

The Office of Emergency Management and Resilience (OEMR) provides policy and program oversight for the Department’s emergency management, recovery and resiliency, national security, continuity, and intelligence support portfolios in order to ensure the Department can effectively manage consequences associated with crisis, and through resilient capabilities, create the operational environment that will enable the Department to return to a normal state as quickly as possible. The operational arm of OEMR is the VA Integrated Operations Center (VAIOC).

The VAIOC is the Department’s national hub for a common operating picture, information fusion, information dissemination, emergency management planning, and communications in order to facilitate shared situational awareness and operations coordination. In addition, the VAIOC has primary responsibility for identifying, sourcing, deploying and employing VA resources in support of Federal disaster response operations. Information and resource management is a cross cutting capability which supports ongoing operations, senior leader awareness, and decision making. To facilitate the above, the VAIOC gathers, assesses, validates, contextualizes, analyzes and fuses disparate information from multiple sources into a single common operating picture. This information must then be organized, shared, displayed, stored, and archived in a manner which is intuitive, easily accessed, and quickly assimilated by stakeholders at all levels.

VA is a senior member of the Federal disaster response community, operates within the context of the National Incident Management System, and subscribes to the tenets of the Incident Command System. As such, the VAIOC regularly communicates and shares information with interagency partners; primarily, the Federal Emergency Management Agency, the Department of Health and Human Services, the Department of Homeland Security, and other departments and agencies with responsibilities under the National Response Framework. VA requires an interoperable and configurable crisis information management platform which satisfies internal emergency management requirements, and which is capable of exchanging information with Federal disaster response community partners.

In November 2018, VA issued the Cloud First Policy mandating that all new and existing IT solutions be assessed to determine suitability to be offered as an enterprise cloud computing service. The VA Enterprise Cloud (VAEC) was established by the Enterprise

Cloud Solutions Office in 2017, to host cloud computing solutions. The web-based crisis information management software solution shall be implemented and hosted in the VA Enterprise Cloud (VAEC).

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”

4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004

5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and

Information Systems,” March 2006

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and

Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

9. Public Law 109-461, Veterans Benefits, Health Care, and Information

Technology Act of 2006, Title IX, Information Security Matters

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm

13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5,

14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017

15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed

Services (CHAMPUS)”

17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021

21. VA Handbook 6500, “Risk Management Framework for VA Information

Systems VA Information Security Program,” February 24, 2021 https://www.va.gov/vapubs/index.cfm https://www.va.gov/vapubs/index.cfm http://www.va.gov/vapubs http://www.va.gov/vapubs

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019

23. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010

24. VA Handbook 6500.6, “Contract Security,” March 12, 2010

25. VA Handbook 6500.8, “Information System Contingency Planning,” April 6,

26. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

27. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

28. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference

Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

29. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

30. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

31. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

32. VA Handbook 6510, “VA Identity and Access Management,” January 15,

33. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017

34. VA Directive 6300, “Records and Information Management,” September 21,

35. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

36. NIST SP 800-37 Rev 2, “Risk Management Framework for Information

Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018

37. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

38. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

39. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-

12) Program,” March 24, 2014

40. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

41. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

42. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

43. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)

44. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018

45. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

46. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

47. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile

Devices (Draft),” October 2012

48. Draft National Institute of Standards and Technology Interagency Report

(NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014

49. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland

Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

50. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

51. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

52. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

53. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

54. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

55. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

56. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

57. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018

58. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August

2, 2001

59. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013

60. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013

61. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote

Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

63. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

64. VA Memorandum “Proper Use of Email and Other Messaging Services,”

January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

65. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946 https://arch.idmanagement.gov/#what-is-the-ficam-architecture https://arch.idmanagement.gov/#what-is-the-ficam-architecture https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.cisa.gov/publication/tic-30-core-guidance-documents https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

66. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

67. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol

Version 6 (IPv6),” November 19, 2020

68. Social Security Number (SSN) Fraud Prevention Act of 2017

69. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23,

70. VA Enterprise Cloud Technical Reference Guide, Version 1.3 July 2018

3.0 SCOPE OF WORK

All parties hereby acknowledge and understand that the Government’s Schedule of Supplies/Services is comprised of the following documents, without exception:

Attachment 1, Performance Work Statement, Cloud Based Crisis Information Management Software, dated March 9, 2023. Accordingly, regardless of their placement during the negotiation phase of this action (e.g., as an attachment or addenda), and if there are any inconsistencies in the Solicitation or Final Contract, the parties hereby agree that the aforementioned documents are incorporated into the Government’s Schedule of Supplies/Services and therefore, deemed first in the order of precedence as defined by the applicable Federal Acquisition Regulation.

The Contractor shall provide a complete commercial-off-the-shelf (COTS) web-based crisis information management software solution that can be integrated with the Federal, State, and local emergency management community. The Contractor shall perform life-cycle development tasks for the COTS web-based crisis information management software solution. The software solution shall meet the necessary requirements to be deployed as an outside hosted managed service on the VA Enterprise Cloud (VAEC). The Contractor shall also provide administrator and user training, help desk support and maintenance. The Contractor shall complete implementation of the solution and provide production access to VA within 45 business days after contract award.

This solution shall be hosted in a VAEC environment and be fully functional no later than 45 business days after contract award. The 45-day implementation timeframe is dependent on and may be adjusted by the VA due to external dependencies such as Enterprise Security External Change Council (ESECC) approvals and the requirement that the solution has a VA Authority to Operate (ATO). In the event that a VAEC cloud service provider (CSP) has not yet been selected by VA, the Contractor shall recommend a CSP for the solution. The Contractor shall not be responsible for providing or acquiring cloud capacity or server hosting infrastructure for this contract.

VA will furnish VAEC capacity as Government Furnished Equipment (GFE).

4.0 PERFORMANCE DETAILS

4.1 PERFORMANCE PERIOD

The period of performance shall be date of award through July 23, 2024, including implementation and maintenance support, plus four 12-month option periods for continued services and optional tasks for each period of performance that may be exercised to provide additional design, development and implementation to existing software platform workflows and procedures.

Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).

There are eleven Federal holidays set by law (USC Title 5 Section 6103) that VA follows:

Under current definitions, four are set by date:

New Year's Day January 1 Juneteenth June 19 Independence Day July 4 Veterans Day November 11 Christmas Day December 25

If any of the above falls on a Saturday, then Friday shall be observed as a holiday.

Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.

The other six are set by a day of the week and month:

Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November

4.2 PLACE OF PERFORMANCE

Tasks under this PWS shall be performed remotely at Contractor facilities. Note that VA is operating from VA facilities located in VAIOC, Suite 1074 located at VA Central Office at 810 Vermont Ave., NW Washington, DC.

4.3 TRAVEL

The Government anticipates no travel requirements under this effort to perform the tasks associated with the effort. Program development / related meetings or conferences will be conducted virtually.

5.0 SPECIFIC TASKS AND DELIVERABLES

The Contractor shall perform the following:

5.1 PROJECT MANAGEMENT

5.1.1 CONTRACTOR PROJECT MANAGEMENT PLAN

The Contractor shall deliver a Contractor Project Management Plan (CPMP) that lays out the Contractor’s approach, timeline, and tools to be used in execution of the contract. The CPMP should take the form of both a narrative and graphic format that displays the schedule, milestones, risks and resource support. The CPMP shall also include how the Contractor shall coordinate and execute planned, routine and ad hoc data collection reporting requests as identified within the PWS. The initial baseline CPMP shall be concurred upon and updated in accordance with Section B of the contract. The Contractor shall update and maintain the VA PM approved CPMP monthly throughout the PoP.

Deliverable:

A. Contractor Project Management Plan

5.1.2 REPORTING REQUIREMENTS

The Contractor shall provide the COR with monthly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding month

The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. The report shall also include an itemized list of all Information and Communication Technology (ICT) deliverables and their current Section 508 conformance status. The Contractor shall monitor performance against the CPMP and report any deviations. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues.

Deliverable:

A. Monthly Progress Report

5.1.3 TECHNICAL KICKOFF MEETING

The Contractor shall hold a technical kickoff meeting within ten business days after award. The Contractor shall present, for review and approval by the Government, the details of the intended approach, work plan, and project schedule for each effort. The Contractor shall specify dates, locations (can be virtual), agenda (shall be provided to all attendees at least three calendar days prior to the meeting) and meeting minutes with summary report (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the Contracting Officer, CS, Contracting Officer’s Representative (COR) and the VA PM.

Deliverable:

A. Technical Kickoff Meeting B. Technical Kickoff Presentation and Summary Report

5.2 THE CRISIS INFORMATION MANAGEMENT SOFTWARE (BASE AND

OPTION PERIODS)

This solution shall be hosted in a VAEC environment and be fully functional no later than 45 business days after contract award. The 45-day implementation timeframe is dependent on and may be adjusted by the VA due to external dependencies such as Enterprise Security External Change Council (ESECC) approvals and the requirement that the solution has a VA Authority to Operate (ATO). In the event that a VAEC cloud service provider (CSP) has not yet been selected by VA, the Contractor shall recommend a CSP for the solution. The Contractor shall not be responsible for providing or acquiring cloud capacity or server hosting infrastructure for this contract.

VA will furnish VAEC capacity as GFE.

The solution shall support a structured incident command system which aligns with the National Incident Management System. The application shall allow users to exchange crisis information with Federal partners, support the ability to track the status of VA critical infrastructure, facilitate resource management and coordinate internal and external disaster response efforts.

The vendor shall manage the solution in either the VAEC or another cloud environment as agreed to by VA. The application shall be accessible from various client devices through either a thin client interface, such as a web browser (e.g., web-based email), or a program interface. If the application is not hosted on the VAEC, the vendor shall obtain a VA approved Authority to Operate (ATO) in whatever environment the software is hosted in.

5.2.1 GENERAL

The Software shall:

1. Be a commercial-off-the-shelf crisis information management platform based upon emergency management organizational structures and operational processes as referenced in the FEMA National Incident Management System at https://www.fema.gov/national-incident-management-system.

2. Be able to exchange information with multiple instances of emergency management software solutions at the Federal, State, and local levels of Government.

3. Be able to integrate and exchange information in near real-time with other commercial-off-the-shelf cloud-based applications, such as, but not limited to, DHS Common Operating Picture, EM Resource, ArcGIS, and Fusion.

4. Be able to integrate and exchange information with VA’s emergency notification and accountability system and other communications (reports, activations).

5. Provide a scalable incident organization chart reflective of the type of incident and the scope of the emergency.

6. Provide dropdown lists, editable by the user, for objectives and assignments.

7. Be capable of enabling user modified workflows, recovery and planning cycles based upon incident type.

8. Allow for tiered level of access (at least 3 tiers) so that users with appropriate permissions can modify planning steps and timelines.

9. Execute near real-time resource tracking.

10. Provide a user managed resource database able to import information in an industry standard data format, or able to accept manual user input.

11. Provide the ability to capture human and material resources.

12. Provide the ability to import and display comma-separated values (CSV) files.

13. Provide the ability to offer the required functionality within a single view. The view shall be able to present information from diverse sources in a user defined, unified manner.

14. Provide the ability to present mission specific templates once the incident type is identified.

15. Provide the ability to add URL links which point to information outside of the application.

16. Provide the ability to collaborate with other users of the software virtually on maps and reports in a near real-time environment with no delay more than 30 seconds.

Collaborative map functionality to include, at a minimum, inserting points, lines, areas, and text.

17. Provide the ability to manually insert a user and/or system generated tracking number on each incident, sub-incident, or action.

18. Support point to point and group chat with users from within the software application.

19. Be able to generate and send user alerts for specific events such as natural disasters, police emergencies, equipment outages, etc.

20. Provide criteria-based help function.

21. Be able to insert attachments and links to forms, logs, or reports.

https://www.fema.gov/national-incident-management-system

22. Be able to print documents, reports, and graphics from the software application in current VA templates and capture changes from previous reports.

23. Provide the ability to display information and export information to a PDF in a single window on a timed interval.

24. Provide analysis and capture trend displays in forms of charts, graphs, heat maps, etc.

25. Have ability to display activities, operations, situations, and overview of user status, for real-world and exercise scenarios.

26. Be capable of supporting exercises, training, and drills without interfering with real-world information sharing.

27. Provide ability to connect with remote and/or wearable camera systems and display video images and recordings.

28. Generate and transmit reports from within tool using the Department’s email groups and individual email addresses seamlessly without having outside users of the tool need an account to view the report.

29. Have ability to ingest and display external traffic and building camera feeds.

30. Have ability to track, change, and report on VA facility/building structures operational capabilities.

31. Diagram to show how the system would work into VAEC and provide requirements listed above.

A. Systems/application diagram

5.3 PLATFORM WORKFLOWS AND PROCEDURES (BASE AND OPTION

PERIODS)

The Contractor shall collaborate with VA in the design, development, and implementation of platform workflows and procedures. Initial development of procedures and workflows will be conducted in conjunction with the VA. Platform workflows and procedures document should be updated after the exercise of an option period, or if significant changes to the system require updates.

Deliverables:

A. Platform workflows and procedures document including diagrams.

5.3.1 ADMINISTRATIVE FUNCTIONS

The software shall:

1. Provide the ability to account for duty personnel (users of software) last log in, last active user, accountability by individual, group, or other attributes.

2. Provide the ability to manage watch operations and planning with an automatic record of shift plan changes, pass down notes and daily event record keeping processes

3. Provide the ability to create editable contacts lists.

4. Provide the ability to create distribution lists from contact lists.

5. Provide the ability for user accounts to inherit permission from groups.

6. Provide the ability to assign user defined access and permissions ranging from view only to full administrative control of the software application, with intermediate levels of access.

7. Provide the ability to clone user permissions when creating additional users.

5.3.2 STATISTICAL FUNCTIONS

The software shall:

1. Provide the ability to export user defined data for standard data analysis.

2. Provide the ability to execute ad hoc queries against the database and generate reports in various formats such as PDF, and CSV based upon the results of such queries.

3. Provide the ability for data collection of designated data elements.

5.3.3 GEOGRAPHIC INFORMATION SYSTEM (GIS) CAPABILITIES

The software shall:

1. Be interoperable with VA’s existing ArcGIS allowing for bi-directional data flow. VA currently employs ESRI’s ArcGIS as its enterprise-wide GIS solution.

2. Provide the ability to import and process geospatial data from external sources to include Representational State Transfer GIS services and Geographical Really Simple Syndication feeds.

3. Provide the ability to use URL links to external sources.

4. Provide the ability to add maps to forms and reports.

5. Provide the ability to add layers and overlays to maps.

6. Provide the ability to create radii, polygons, arrows, lines, text, and graphics/photos.

7. Provide the ability to manually plot an incident location on a map or add using standard geographic coordinates (such as Latitude/Longitude, Universal Transverse Mercator (UTM), Street Address).

8. Provide the ability to place assets and resources on a map using manual plotting or by using geographic coordinates.

9. Provide the ability to insert standard emergency management symbols.

10. Provide the ability to calculate the perimeter or area of a selected polygon.

11. Provide the ability to perform point to point distance measuring.

12. Provide the ability to access incident information and geospatial data by clicking on the map object.

13. Provide the ability to perform map queries (e.g., list selected data within a user defined geographic area) with exportable results.

14. Generate demographics based on polygons and point features entered in the system.

5.3.4 USER INTERFACE

The software shall:

1. Provide multiple incident dashboards that display selected active incidents with summary information, graphics, and key information

2. Provide senior level viewing capabilities with overview of single, complicated selected activities with roll up and administration specific reports.

3. Provide a dashboard with chronological selection or other user determined analysis and quick display charts of past incidents or other determined criteria.

4. Provide a user-defined, configurable Incident Status Board.

5. Provide the ability to create automated, time stamped reports or exports and static slides for briefings

6. Ability to create custom dashboards based on data (inputted or collected) in the system.

5.3.5 INTERDEPENDENCY ANALYSIS

The software shall:

1. Provide the ability for users to add relationship inputs and outputs to new and currently available assets.

2. Provide a second database specifically to allow tracing of the current operating status of all assets within the software.

3. Provide capability to use the choice of the other database and view a “what-if” mode and run a number of possible scenarios on the current status of all assets without impacting the current live state.

4. Ability to allow users to visualize projected impacts of major events, enable users to project the time within which recovery can be accomplished and plan and monitor the best results to obtain recovery.

5. Ability to automate disabling and recovering of group of assets based on criteria occurring near physical location.

5.3.6 MASS DAILY BRIEFING

1. Provide the capabilities to produce a non-sensitive mass / daily briefing, using current templates and integrating information in the common operating picture.

2. Briefing will be exported and converted to PDF as simply as possible using simple procedures (watch should be able to select which slides and information they want to export and push a “create daily briefing button” which will export the selected information into the applicable format.

3. Button will generate an email and link to the daily report. Examples will be available upon request.

4. Briefing will be available in a web site repository, updated and produced every 24 hours.

5. Briefing will include a final slide with QR code that includes a link to allow additional stakeholders to subscribe to the email and receive the briefing.

6. Procedure should be available for other reports or stakeholders/ partners as needed, especially during rapidly changing situations.

5.4 IMPLEMENTATION AND TRAINING SERVICES (BASE AND OPTION

PERIODS)

5.4.1 IMPLEMENTATION

1. The Contractor shall collaborate with VA in the design, development, and implementation of platform workflows and procedures. Initial development of procedures and workflows will be conducted in conjunction with the VA and completed within 45 business days of contract award.

2. The Contractor shall develop and provide training tools and job aids for workflows, procedures, and other tasks performed in the platform as dictated by the VA. The Contractor shall update and add to training tools and job aids within one week of the implementation and when any new tasks or procedures are identified.

3. The Contractor shall ensure that exported reports match formatting standards as dictated by the VA.

Deliverables:

A. Job Aids

5.4.2 TRAINING

The Contractor shall develop and provide training tools and job aids for workflows, procedures and other tasks performed in the platform as dictated by the VA. The Contractor shall update and add to training tools and job aids within one week of the implementation of any new tasks or procedures.

The Contractor shall provide user and administrator training, delivery of workflow and procedures document. Training shall be classroom-based instructor-led training.

Request two sessions per day, to account for shiftwork (morning and afternoon). Each session will have between two to five attendees and offered three times in the week.

Location of training will be at the VAIOC VA Central Office, 810 Vermont Ave, NW Washington, DC. In the event that there is inclement weather or operations preventing training from being conducted, training will be rescheduled. Contractor shall coordinate with the COR and VA system project manager to schedule training sessions.

The Contractor shall provide self-paced computer-based training and tutorials throughout the period of performance as part of the help, support and development of the system. This training shall be available from delivery of workflow and procedures document and updated to cover new capabilities and/or existing capabilities affected by the new software upgrades throughout the period of performances.

Deliverables:

A. Training Plan B. Training Materials

C. User Guides

5.5 OPERATIONS AND MAINTENANCE (O&M) SERVICES (BASE AND

OPTION PERIODS)

The Contractor shall provide helpdesk support to VAIOC users for all aspects of the crisis information management hosted managed service solution. The help desk support shall be provided via phone, email, and chat accessible for VAIOC users from Monday through Friday between the hours of 7:00AM and 9:00PM Eastern Standard Time excluding federal holidays.

Help desk support shall be available 24/7 during times of national crisis. A national crisis will be defined and established by the VA COR.

The Contractor shall maintain the crisis incident management software in a production ready state. The Contractor shall provide routine maintenance (preventive maintenance to keep the software operational and maintenance needed to address defects) and emergency maintenance (needed when the software functionality is severely limited) support, daily system back-up, and system restoral services. The Contractor shall provide all software releases, upgrades, and patches.

The Contractor shall provide an O&M support plan and O&M reports to VA.

Deliverables:

A. O&M Support Plan B. Operations and Maintenance Reports

5.6 SECURITY AND RISK MANAGEMENT REQUIREMENTS (BASE AND

OPTION PERIODS)

The contractor shall provide an individual assigned duties as the VA System Steward. The System Steward’s responsibilities include, but are not limited to, overseeing system operations, providing expertise on security controls, managing security controls for the system and offering guidance on System Security Plan development. The System Steward shall complete all training requirements mandated by the VA to perform the role of System Steward.

5.7 VA ENTERPRISE CLOUD SPECIFIC REQUIREMENTS (BASE AND

OPTION PERIODS)

5.7.1 ARCHITECTURE AND DESIGN

1. Develop, maintain, and update as needed the solution architecture diagram aligned with the VAEC Technical Reference Architecture as well as the One-VA Enterprise Architecture.

2. Design VAEC hosted solution and address VA identified cloud-readiness gaps.

Deliverables:

A. Solution Architecture Diagram B. Solution Design

5.7.2 PLANNING

1. Develop, maintain, and execute the VAEC Implementation Plan that defines the implementation approach, processes and activities (prior to, during, and after), test strategy, setup and configuration procedure, inventory of IT assets, implementation checklist, risk assessment, key dependencies, and schedule. In the event that a VAEC CSP has not yet been selected by VA, the Contractor shall recommend a CSP.

2. Develop and execute the VAEC Transition Plan, as part of the Implementation Plan, that defines the approach and action plans to prepare VA stakeholders to receive and operate the solution. This includes improving stakeholder engagement, outreach, and communications.

3. Develop and update project’s VIP Deployment and Installation, Back-out, and Rollback Plan that describes the installation, back-out, and rollback approach, processes and activities, dependencies and schedule. The plan shall also include the provisioning and installation procedures for VAEC resources.

4. Determine cloud capacity and workload requirements. VA shall review and approve cloud capacity requirements and provide the VAEC cloud capacity for the solution as

GFE.

Deliverables:

A. VAEC Implementation Plan

5.7.3 BUILD AND DEVELOPMENT

1. Support setup, configuration, and provisioning of the solution in the VAEC environments.

2. Work with VA to provide inputs for establishing VAEC capacity, accounts and privileges. This includes monitoring and tracking the creation, update, and deletion of application user (e.g., developer, systems administrator) accounts, and ensuring cloud capacity requirements are satisfied.

3. Develop necessary artifacts to obtain a VA authority to operate (ATO) for the solution and complete VA Assessment and Authorization (A&A) process. After ATO is achieved, the Contractor shall update and maintain the A&A documentation as required to ensure continued compliance. The Contractor shall monitor, track, and respond to Plan of Action and Milestones (POAM). The Contractor shall provide input to update the VAEC ATO, as needed.

4. Provide information and documentation to support operational and production readiness reviews and go-no-go decisions. The Contractor shall execute corrective actions to address gaps and provide all required data and prepare supporting documents/artifacts for the reviews.

5.7.4 IMPLEMENTATION

1. Implement the solution in the VAEC as defined in VIP Deployment and Installation, Back-out, and Rollback Plan as well as the VAEC Implementation Plan.

2. Provide inputs and documentation for the Post-Implementation Review, within five business days of implementation completion, to review lessons learned and identify improvement opportunities.

3. Provide an Implementation Summary Report that describes implementation results, lessons learned, open issues, corrective action, and improvement opportunities.

Deliverables:

A. Implementation Summary Report

5.7.5 OPERATE AND MAINTAIN

1. Operate and maintain the solution hosted in the VAEC in accordance with the application and VAEC service level agreements (SLAs) and operate the solution in its current environment in parallel as applicable.

2. Utilize VAEC General Support Services (GSS) when available and applicable in order to minimize cloud services costs and optimize operations. The contractor shall use native tools and capabilities of the VAEC environment.

3. Provide for the backup and recovery of information stored by the solution to meet the application and VAEC SLA using native tools and capabilities of the VAEC environment.

5.7.6 MONITOR PERFROMACE AND REPORTING

1. Provide a Quarterly Solution Performance Report that summarizes solution availability, usage, events and incidents, improvement opportunities, risks and issues, status, action plans, and planned and actual resolution timelines.

2. Review all usage of cloud computing services provided by VAEC. The Contractor shall submit and implement Quarterly Resource Utilization Optimization Plans on how to best optimize the environment to reduce the costs associated with resource utilization.

3. Provide a breakdown of all costs by solution, environment, and utilization. The Contractor shall report on utilization of each class of resource as a percentage of provisioned capacity in a Monthly Utilization Report. The Contractor shall, as part of its

Monthly Utilization Report, include the total infrastructure expenditure and total number of request services for Cloud Resource Optimization.

Deliverables:

A. Quarterly Solution Performance Report B. Quarterly Resource Utilization Optimization Plan C. Monthly Utilization Report

5.8 OPTIONAL TASKS

OPTIONAL TASK: ADDITIONAL REQUIREMENT(S) FOR DESIGN, DEVELOPMENT,

AND IMPLEMENTATION OF PLATFORM WORKFLOWS AND PROCEDURES

If exercised by the Government, the contractor shall delivery platform workflows in each period of performance that enhance the capabilities already established under the delivery of this contract. The Contractor shall be responsible for the design, development and implementation of Platform Workflows and Procedures for the additional enhancement(s). The Contractor shall include the enhancement to the existing support being provided in PWS Section 5.4 Implementation and Training Services and PWS Section 5.5 O&M Services (Base and Option Periods). Prior to exercising this optional task, the Contractor shall provide a proposed enhancement project plan that details the scope, benefit, timeline and cost breakdown (within the not to exceed amount established). The Government will review, make recommendations and if accepted may exercise this optional task unilaterally in accordance with the terms of the contract.

Deliverables:

A. Enhancement Job Aids B. Enhancement Workflow Diagrams C. Enhancement O&M Support Plan D. Enhancement O&M Reports

6.0 GENERAL REQUIREMENTS

6.1 ENTERPRISE AND IT FRAMEWORK

6.1.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19- 17 can be found at:

https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp https://www.oit.va.gov/library/recurring/edp/index.cfm https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf

24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05-24.pdf https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1 https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1 https://doi.org/10.6028/NIST.SP.500-267Br1 https://doi.org/10.6028/NIST.SP.800-119 sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g.

web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.

6.1.4 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.

6.1.5 STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE

MANAGEMENT (PLM)

The Contractor shall support VA efforts IAW the updated Veteran Focused Integration Process (VIP) and Product Line Management (PLM). The major focus of the new VIP is on Governance and Reporting and is less prescriptive, with a focus on outcomes and continuous delivery of value.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .