S02 - Attachment 1 - PWS.docx
DOCX document 133 KB Posted
- Attached to
- Library Services Federal contract opportunity
- Solicitation number
- 36C77622R0068
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| S02 - Solicitation Synopsis FINAL - Library Services.docx | DOCX document | |
| S02 - Attachment 3 - QASP.docx | DOCX document | |
| S02 - Attachment 2 - PAST PERFORMANCE.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Library Services HIG22-3
PWS
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS (VA)
VETERANS HEALTH ADMINISTRATION (VHA)
OFFICE OF HEALTH INFORMATICS (OHI)
Health Information Governance’s (HIG) Library Network Office (LNO) Library Services
HIG22-3
Date: November 4, 2021 PWS Version Number: 0.10
Table of Contents
| 1.0 | BACKGROUND | 2 |
| 2.0 | Applicable Documents | 3 |
| 3.0 | SCOPE OF WORK | 6 |
| 3.1 | CHANGES TO THE PWS | 6 |
| 4.0 | PERFORMANCE DETAILS | 6 |
| 4.1 | PERFORMANCE PERIOD | 6 |
| 4.2 | PLACE OF PERFORMANCE | 7 |
| 4.3 | TRAVEL | 7 |
| 4.4 | NON-DISCLOSURE AGREEMENTS AND CONFLICTS OF INTEREST | 7 |
| 5.0 | SPECIFIC TASKS AND DELIVERABLES | 8 |
| 5.1 | Support for Knowledge-Based Resources: | 8 |
| 5.1.1 | Task 1 Administer Remote Access Platforms | 8 |
| 5.1.2 | Task 2 Administer Serials Solutions (A-to-Z Title List): | 9 |
| 5.1.3 | Task 3 Administer National Library of Medicine (NLM) Linkout: | 10 |
| 5.1.4 | Task 4 Provide Web Services: | 10 |
| 5.1.5 | Task 5 Comparison Chart: | 10 |
| 5.1.6 | Task 6 Training: | 11 |
| 5.1.7 | Task 7 REPORTING REQUIREMENTS: | 11 |
| 6.0 | GENERAL REQUIREMENTS | 12 |
| 6.1 | PERFORMANCE METRICS | 13 |
| 6.2 | ENTERPRISE AND IT FRAMEWORK | 24 |
| 6.3 | SECURITY AND PRIVACY REQUIREMENTS | 26 |
| 6.3.1 | POSITION/TASK RISK DESIGNATION LEVEL(S) | 26 |
| 6.3.2 | CONTRACTOR PERSONNEL SECURITY REQUIREMENTS | 27 |
| 6.4 | METHOD AND DISTRIBUTION OF DELIVERABLES | 29 |
| 6.5 | FACILITY/RESOURCE PROVISIONS | 29 |
| 6.6 | GOVERNMENT FURNISHED PROPERTY | 30 |
| ADDENDUM A – ADDITIONAL VA REQUIREMENTS, CONSOLIDATED | 30 | |
| ADDENDUM B – VA INFORMATION AND INFORMATION SYSTEM SECURITY/PRIVACY LANGUAGE | 37 |
BACKGROUND
The Veterans Health Administration (VHA) Office of Health Informatics (OHI) Health Information Governance’s (HIG) Library Network Office (LNO) supports the VA Library Network (VALNET) library professionals and staff with centralized services, policies and procedures, staff development opportunities, and assistance with local library issues. Throughout the VA, LNO serves as an advocate for the importance of knowledge-based resources to the provision of quality healthcare. The LNO provides a core collection of nationally funded, authoritative information resources to all VA staff, available both on-site at a VA medical center, or from home. The LNO is seeking contractor support to manage statistics/data about VALNET and the knowledge-based resource accounts for VHA and the 153 medical centers.
The Veterans Affairs Library Network (VALNET) is a health sciences library network of national significance. VALNET librarians provide knowledge-based information for clinical and management decision-making, research, and education to enhance the quality of care for Veterans enrolled in the VA Health Care System. VALNET serves a diverse group of users, including Veteran inpatients and outpatients, their families, and caregivers; VA staff and employees; and students and trainees in affiliated teaching programs.
LinkOut is a service of PubMed that allows a library to link directly from PubMed to other sources of information. This makes it easy for users to access relevant full text articles and other online resources. LinkOut facilitates the link and makes local journal holdings available full-text to a library’s patrons. Users at these institutions see their institutions logo within the PubMed search result (if the journal is held at that institution) and can access the full-text. All links are specially assigned to specific database records. When accessing a link through LinkOut, no additional searching should be necessary to access the relevant resource that has been linked to the record.
Applicable Documents In the performance of the tasks associated with this PWS, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541, “Federal Information Security Management Act (FISMA) of 2002”
2. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”
3. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and Contractors,” August 2013
4. 10 U.S.C. § 2224, "Defense Information Assurance Program"
5. Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Development (CMMI-DEV), Version 1.3 November 2010; and Carnegie Mellon Software Engineering Institute, Capability Maturity Model® Integration for Acquisition (CMMI-ACQ), Version 1.3 November 2010
6. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
7. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
8. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, http://www.va.gov/vapubs/
9. VA Handbook 0710, Personnel Security and Suitability Security Program, May 2, 2016, http://www.va.gov/vapubs
10. VA Directive and Handbook 6102, “Internet/Intranet Services,” July 15, 2008
11. 36 C.F.R. Part 1194 “Electronic and Information Technology Accessibility Standards,” July 1, 2003
12. Office of Management and Budget (OMB) Circular A-130, “Managing Federal Information as a Strategic Resource,” July 28, 2016
13. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed Services (CHAMPUS)”
14. An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, October 2008
15. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998
16. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
17. VA Directive 6500, “Managing Information Security Risk: VA Information Security Program,” September 20, 2012
18. VA Handbook 6500, “Risk Management Framework for VA Information Systems – Tier 3: VA Information Security Program,” March 10, 2015
19. VA Handbook 6500.1, “Electronic Media Sanitization,” November 03, 2008
20. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI)”, July 28, 2016 (http://www1.va.gov/vapubs/)
21. VA Handbook 6500.3, “Assessment, Authorization, And Continuous Monitoring of VA Information Systems,” February 3, 2014
22. VA Handbook 6500.5, “Incorporating Security and Privacy in System Development Lifecycle”, March 22, 2010
23. VA Handbook 6500.6, “Contract Security,” March 12, 2010
24. VA Handbook 6500.8, “Information System Contingency Planning”, April 6, 2011
25. Office of Information and Technology (OI&T) ProPath Process Methodology (Transitioning to Process Asset Library (PAL) (reference process maps at http://www.va.gov/PROPATH/Maps.asp and templates at http://www.va.gov/PROPATH/Templates.asp). NOTE: In the event of a conflict, OI&T ProPath (PAL) takes precedence over other processes or methodologies.
26. One-VA Technical Reference Model (TRM) (reference at http://www.va.gov/trm/TRMHomePage.asp)
27. National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, “Recommended Security Controls for Federal Information Systems and Organizations” (http://csrc.nist.gov/publications/PubsSPs.html)
28. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
29. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
30. VA Directive 6300, Records and Information Management, February 26, 2009
31. VA Handbook, 6300.1, Records Management Procedures, March 24, 2010
32. OMB Memorandum, “Transition to IPv6”, September 28, 2010
33. VA Directive 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, October 26, 2015
34. VA Handbook 0735, Homeland Security Presidential Directive 12 (HSPD-12) Program, March 24, 2014
35. OMB Memorandum M-06-18, Acquisition of Products and Services for Implementation of HSPD-12, June 30, 2006
36. OMB Memorandum 05-24, Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, August 5, 2005
37. OMB memorandum M-11-11, “Continued Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors, February 3, 2011
38. OMB Memorandum, Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation, May 23, 2008
39. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011
40. NIST SP 800-116, A Recommendation for the Use of Personal Identity Verification (PIV) Credentials in Physical Access Control Systems, November 20, 2008
41. OMB Memorandum M-07-16, Safeguarding Against and Responding to the Breach of Personally Identifiable Information, May 22, 2007
42. NIST SP 800-63-2, Electronic Authentication Guideline, August 2013
43. NIST SP 800-157, Guidelines for Derived PIV Credentials, December 2014
44. NIST SP 800-164, Guidelines on Hardware-Rooted Security in Mobile Devices (Draft), October 2012
45. Draft National Institute of Standards and Technology Interagency Report (NISTIR) 7981 Mobile, PIV, and Authentication, March 2014
46. VA Memorandum, VAIQ #7100147, Continued Implementation of Homeland Security Presidential Directive 12 (HSPD-12), April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
47. VA Memorandum, VAIQ # 7011145, VA Identity Management Policy, June 28, 2010 (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
48. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
49. Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0, Federal Interagency Technical Reference Architectures, Department of Homeland Security, October 1, 2013, https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf
50. OMB Memorandum M-08-05, “Implementation of Trusted Internet Connections (TIC), November 20, 2007
51. OMB Memorandum M-08-23, Securing the Federal Government’s Domain Name System Infrastructure, August 22, 2008
52. VA Memorandum, VAIQ #7497987, Compliance – Electronic Product Environmental Assessment Tool (EPEAT) – IT Electronic Equipment, August 11, 2014 (reference Document Libraries, EPEAT/Green Purchasing Section, https://www.voa.va.gov/documentlistpublic.aspx?NodeID=552)
53. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
54. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
55. Executive Order 13693, “Planning for Federal Sustainability in the Next Decade”, dated March 19, 2015
56. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001
57. VA Directive 0058, “VA Green Purchasing Program”, July 19, 2013
58. VA Handbook 0058, “VA Green Purchasing Program”, July 19, 2013
59. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote Access”, January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
60. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
61. VA Memorandum, “Implementation of Federal Personal Identity Verification (PIV) Credentials for Federal and Contractor Access to VA IT Systems”, (VAIQ# 7614373) July 9, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
62. VA Memorandum “Mandatory Use of PIV Multifactor Authentication to VA Information System” (VAIQ# 7613595), June 30, 2015, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
63. VA Memorandum “Mandatory Use of PIV Multifactor Authentication for Users with Elevated Privileges” (VAIQ# 7613597), June 30, 2015; https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
64. “Veteran Focused Integration Process (VIP) Guide 1.0”, December, 2015, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
65. “VIP Release Process Guide”, Version 1.4, May 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4411
66. “POLARIS User Guide”, Version 1.2, February 2016, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4412
SCOPE OF WORK
The Contractor shall provide management of knowledge-based resources and related tools for 153 medical centers. LNO maintains a core collection of online knowledge-based resources that are available to VA staff 24X7 from any computer with Internet access. The contractor shall provide assistance to LNO in the management of these knowledge-based resources which includes approximately 7,000 online journal titles, 10,000 online books and over 35 databases. Work on the resources includes troubleshooting online access, maintenance of remote access through remote access platforms, and maintenance of resource accounts (SerialsSolutions) for each medical center and LNO. Contractor shall also maintain and update the following 4 websites;
Desktop Library VA Library Network (VALNET) VA Central Office Library Library Network Office
CHANGES TO THE PWS
Any changes to this PWS shall be authorized and approved only through written correspondence from the Contracting Officer (CO). A copy of each change shall be kept in a project folder along with all other products of the project. Costs incurred by the Contractor through the actions or authorizations of parties other than the CO shall be borne by the Contractor.
PERFORMANCE DETAILS
The following describes the performance details associated with this contract.
PERFORMANCE PERIOD
The performance period shall be twelve (12) months from date of award, with four (4) twelve (12) month option periods.
Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).
There are eleven (11) Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, four are set by date:
| New Year's Day | January 1 |
| Juneteenth | June 19 |
| Independence Day | July 4 |
| Veterans Day | November 11 |
| Christmas Day | December 25 |
If any of the above falls on a Saturday, then Friday shall be observed as a holiday. Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
| Martin Luther King's Birthday | Third Monday in January |
| Washington's Birthday | Third Monday in February |
| Memorial Day | Last Monday in May |
| Labor Day | First Monday in September |
| Columbus Day | Second Monday in October |
| Thanksgiving | Fourth Thursday in November |
PLACE OF PERFORMANCE
Due to the COVID-19 Pandemic, Tasks under this PWS are to initially be performed remotely. Once it has been determined for the facility to reopen, government office space is available at 810 Vermont Ave, Washinton DC, and limited to one personnel. It is expected that, from that point, the contractor will have an in-person presence three days a week on site, with the remainder of the work week performed remotely.
TRAVEL
The Government does not anticipate travel during the base and option years. Local travel within a 50-mile radius from the Contractor’s facility is considered the cost of doing business and will not be reimbursed. This includes travel, subsistence, and associated labor charges for travel time. Travel performed for personal convenience and daily travel to and from work at the Contractor’s facility will not be reimbursed:
NON-DISCLOSURE AGREEMENTS AND CONFLICTS OF INTEREST
Due to the procurement-sensitive nature of the deliverables produced by this effort, Contractors (both at the prime and sub-contractor level at all tiers) shall be required to execute Non-disclosure/Conflict of Interest Agreements.
Pursuant to Veterans Affairs Acquisition Regulation (VAAR) 852.209-70, Organizational Conflicts of Interest, the Contractor shall also provide an additional statement with its offer(s) which describes, in a concise manner, all relevant facts concerning any past, present, or currently planned interest (financial, contractual, organizational, or otherwise) or actual or potential organizational conflicts of interest relating to the services to be provided under this solicitation. The Contractor shall also provide statements with its offer(s) containing the same information for any consultants and sub-contractors identified in its proposal and which shall provide services under the solicitation.
The Contractor may also provide the CO relevant facts which show how the Contractor’s organizational and/or management system or other actions would avoid or mitigate any actual or potential organizational conflicts of interest. The presentation of any such information intended to reflect the Contractor’s attempts and/or plans to mitigate any actual or potential organizational conflicts of interest does not in and of itself, however, guarantee that the CO shall approve any such mitigation attempts/plans.
Nondisclosure or misrepresentation of actual or potential organizational conflicts of interest at the time of the offer or arising as a result of a modification to the contract, may result in the termination of the contract at no expense to the Government.
SPECIFIC TASKS AND DELIVERABLES
The Government will have ten (10) business days to review each deliverable and provide feedback/comments. The contractor shall have five (5) business days to incorporate feedback/comments and make appropriate revisions. The contractor shall provide the revised version of each deliverable to the COR and VA PM. The PM will review and determine final acceptance by the Government. The PM will notify the contractor of final acceptance within five (5) business days.
The contractor shall ensure that all documentation and deliverables are stored on appropriate VA servers within one week of their completion. The contractor shall use the designated telecommunications tool for all pertinent conference calls, and the VA Exchange server for all pertinent email.
If for any reason, any deliverable cannot be delivered in the time schedule, the contractor shall provide a written explanation to the PM, COR and CO as soon as late deliverable is anticipated and no less than three working days prior to scheduled delivery. This written transmittal shall include a firm commitment of when the work shall be completed. This notice to the CO shall cite the reasons for the delay, and the impact on the overall project. The CO will then review the facts and issue a response in accordance with applicable regulations. The Contractor shall perform the following:
TASKS:
Support for Knowledge-Based Resources:
Manages online knowledge-based information resources:
Contractor shall serve as the administrator for over 35-50 online databases, plus 25-30 accounts that encompass 20,000-30,000 online books and over 7,000 online journals. Work includes ensuring accuracy of the internet protocol (IP) range information for each medical center (153 sites), other VA facilities (Vet Centers, Community Based Outpatient Clinics, etc.) and Virtual Private Network (VPN) accounts. Work includes posting new resources on the VHA National Desktop Library, informing field library staff and webmasters of new and changed uniform resource locators (url) used to access to resources, serving as an intermediary between VHA staff and vendors for access issues, troubleshooting issues and if not resolved elevating issues to the publisher. The LNO is to be included on all communications between the contractor and publishers.
1.1.1 Task 1 Administer Remote Access Platforms
Athens or LibLynx is a remote authentication service used by the LNO that provides a single username and password that allows access to online resources when the user is not on the VA network. The contractor shall manage the remote access platform web-based accounts for every VA medical center (153 accounts). In doing so, the contractor activates and deactivates library online resources purchased nationally as well as those purchased at a local or VISN level. As part of the functionality of the tool, the contractor creates usernames/passwords when required for individual staff access (currently over 21,000 accounts), correct remote access password issues (estimated 150 per month), provide solutions to access issues (estimated 150 per month), ensure the listing of resources in the individual remote access accounts are up to date (estimated 50 changes/year). The contractor will audit/review the 4 websites controlled by LNO for accuracy, currency, broken links, etc. The contractor will attend weekly resource conference calls to provide verbal updates and progress on remote access issues.
The Library Network Office is in the process of transitioning the remote access platform from Athens to LibLynx.
Deliverable:
A. Provide a usage report for national resources and medical center libraries, to be included as a part of monthly report outlined in Task 7 below.
Task 2 Administer Serials Solutions (A-to-Z Title List):
Serials Solutions is a commercial online resource tool used by the VHA Library Network Office. This management tool provides a single point of entry to e-resources owned by VA Libraries. The A-to-Z title list, e-resource portal, Journal Linker, title searching, and subject browsing features provide a variety of options for access of online journals and books, all from Web pages that are branded and localized to match the look and feel of a library’s web site. Serials Solutions 360 Core, a companion tool used by the LNO, helps simplify online resource management tasks using web-based tools.
The contractor shall manage individual Serials Solutions database administrative accounts for every VA medical Center (153 sites). The contractor shall update national resources (online books, journals and databases) for each account, as well as local and VISN level resources which vary for every medical center (estimated 93 per month); provide individualized branding for each of the 153 accounts, adding the name of the site and other pertinent information to each VA account. troubleshoot incorrect links, customize holding statements (estimated 90 per month). The contractor will update Serial Solutions with VA staff changes. and generate individual and national usage reports.).
Deliverable:
A. Provide a usage report for medical center libraries, to be included as a part of monthly report outlined in Task 7 below.
5.1.3 Task 3 Administer National Library of Medicine (NLM) LinkOut:
The contractor will manage the National Library of Medicine Linkout accounts for every VA medical Center library, ensuring the accuracy of the date transfer and troubleshooting any access issues. Accuracy of the data transfer is to be accomplished by conducting a PubMed search on a random sampling of unique journal titles subscribed to by the medical center. This is to be performed on 5 Library of Medicine LinkOut accounts a month. The contractor will turn on and off the LinkOut Outside Tool as library staff come and go.
Deliverable:
A. Provide a report on the LinkOut account activity and sample results, to be included as a part of monthly report outlined in Task 7 below.
1. Task 4 Provide Web Services:
The contractor shall serve as the coordinator for 4 websites (VHA National Desktop Library, LNO, VALNET Intranet and VACO Library Intranet) which requires knowledge of TeamSite and SharePoint Designer. The coordinator shall be responsible for creating new pages, updating content (to be provided by Library Network Office staff) and fixing any broken links. The contractor will Modify/Create/Post documents and images on web (estimated 5 documents per month), post Hotline agendas and recordings, update the calendar on the Training page, add the recordings and slides/handouts to the Training page, and attend weekly Library Network Office (LNO) conference calls to provide verbal updates and progress on deliverables.
Deliverable:
A. Provide a report on webpages reviewed for currency and accuracy, to be included as a part of monthly report outlined in Task 7 below.
Task 5 Comparison Chart:
The VALNET comparison chart provides a wide variety of information about VA libraries including data on staffing, space, services, equipment, resources, and more. This site also houses the VALNET Staff Directory and the Library Annual Statistical Report. The contractor shall update the VALNET comparison chart as changes are reported to the Library Network Office. This includes changes to data and information related to each medical center and the VALNET staff directory.
Deliverable:
A. Provide a report of changes made to the VALNET Comparison Chart over the course of the month, to be included as a part of monthly report outlined in Task 7 below.
Task 6 Training:
The contractor shall serve as technical support and backup for Knowledge Nook. Training sessions are held twice a month via WebEx, Teams or other platform. The contractor shall attend the practice sessions to troubleshoot as necessary. The contractor will attend the Knowledge Nook sessions to record the meeting, monitor chat and, and respond to questions/ backup the LNO training facilitator.
Deliverable:
A. Provide a report of training sessions attended, to be included as a part of monthly report outlined in Task 7 below.
Task 7 REPORTING REQUIREMENTS:
The Contractor shall provide the COR with Monthly Progress Reports in electronic form in Microsoft Word and Project formats. The report shall include detailed instructions/explanations for each required data element, to ensure that data is accurate and consistent. These reports shall reflect data as of the last day of the preceding Month.
The Monthly Progress Reports shall cover all work completed during the reporting period and work planned for the subsequent reporting period. The report shall also identify any problems that arose and a description of how the problems were resolved. If problems have not been completely resolved, the Contractor shall provide an explanation including their plan and timeframe for resolving the issue. It is expected that the Contractor will keep in communication with VA accordingly so that issues that arise are transparent to both parties to prevent escalation of outstanding issues. The Monthly progress report shall include progress on all preceding deliverables:
1) Remote Access Platform Issues
2) Serials Solutions issues reported and resolved.
3) LinkOUT issues reported and resolved.
4) Website updates.
5) Comparison chart updates
6) Training updates
GENERAL REQUIREMENTS
The Government shall hold a Post Award Orientation Conference (PAOC) for the Contractor with SIM BA advisory groups comprised of key stakeholders and Subject Matter Experts (SMEs), PMs, and the COR. The Government shall schedule the PAOC to be held within 10 calendar days after the award or as agreed upon between the COR and Contractor.
Quality Control (QC): The Contractor shall develop and maintain an effective QC program to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s QC program is the means by which he assures himself his work complies with the requirements of the contract. As a minimum, the Contractor shall develop QC procedures addressing the areas identified in the “Performance Metrics Table” defined in the contract. After acceptance of the QC plan, the Contractor shall receive the CO’s acceptance in writing of any proposed change to his QC system.
Quality Assurance (QA): The Government shall evaluate the Contractor’s performance in accordance with the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government shall do to ensure the Contractor has performed in accordance with the performance standards. It defines how the performance standards shall be applied, the frequency of surveillance, and the minimum acceptable defect rates. Quality standards and the QASP shall be outlined in the PWS. The table below provides a sample of standards and descriptions the Government may use.
PERFORMANCE METRICS
The table below defines the Performance Standards and Acceptable Levels of Performance associated with this effort.
| Required Service/Task |
| Performance Standard |
| Acceptable Quality Level |
| Method of Surveillance |
| Incentive (Positive and/or |
Negative)
| Administer Remote Access Platforms (See PWS Section 5.1.1) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables (see 5.1.1A-G) |
| Zero instances where significant errors or omissions were identified (see note 1) |
| 100% Inspection |
| Firm-Fixed Price (FFP). The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government. (see note 2) |
| Administer Serials Solutions (A-to-Z Title List) (See PWS Section 5.1.2) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables (see 5.1.2A-D) |
| Zero instances where significant errors or omissions were identified (see note 1) |
| 100% Inspection |
| FFP. The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government. (see note 2) |
| Administer National Library of Medicine (NLM) Linkout (See PWS Section 5.1.3) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables (see 5.1.3A,B) |
| Zero instances where significant errors or omissions were identified (see note 1) |
| 100% Inspection |
| FFP. The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government. (see note 2) |
| Provide Web Services (See PWS Section 5.1.4) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables (see 5.1.4A-F) |
| Zero instances where significant errors or omissions were identified (See Note 1) |
| 100% Inspection |
| FFP. The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government |
(See Note 2)
| Comparison Chart (See PWS Section 5.1.5) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables (see 5.1.5A) |
| Zero instances where significant errors or omissions were identified (See Note 1) |
| 100% Inspection |
| FFP. The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government |
(See Note 2)
| Training (See PWS Section 5.1.6) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables (see 5.1.6A,B) |
| Zero instances where significant errors or omissions were identified (See Note 1) |
| 100% Inspection |
| FFP. The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government |
(See Note 2)
| Reporting Requirements (See PWS Section 5.1.7) |
| Consolidated Monthly Report. The report shall include progress on all Tasks/Deliverables for PWS section 5.1.1 – 5.1.7 and any optional tasks that may have been exercised |
| Zero instances where significant errors or omissions were identified (See Note 1) |
| 100% Inspection |
| FFP. The PM and COR shall review and accept deliverables. Contractor shall re-accomplish products found to be unacceptable within five (5) business days. Contractor shall receive payment once deliverable is accepted by the Government |
(See Note 2)
* Note 1: Significant errors or omissions are defined as deliverables not meeting the intent of the task and the work considered to be within scope of this contract.
** Note 2: Continued repetitive errors may result in an unacceptable rating on performance report to be used as part of the evaluation criteria on future competitions.
Types of Surveillance:
1. Random sampling: Appropriate for frequently recurring tasks. Evaluate randomly selected samples of the lot to determine the acceptability of the entire lot (random inspection guide, method of surveillance, lot size, sample size, performance requirement, sampling procedure, and inspection procedure).
2. One hundred percent inspection: Appropriate for tasks that occur infrequently. Inspect and evaluate performance each time task is performed.
3. Periodic surveillance: Evaluation of samples selected on other than a 100 percent or statistically random basis (such as monthly, quarterly, or semi-annually).
ENTERPRISE AND IT FRAMEWORK
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with the VA Technical Reference Model (TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. The VA TRM, which includes the Standards Profile and Product List, serves as technology roadmap and tool for supporting Office of Information and Technology (OIT). Architecture and Engineering Services (AES) has overall responsibility for the VA TRM.
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are PIV-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), http://www.ea.oit.va.gov/VA_EA/VAEA_TechnicalArchitecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, http://www.techstrategies.oit.va.gov/enterprise_dp.asp. The Contractor shall ensure all Contractor delivered applications and systems are compliant with VA Identity Management Policy (VAIQ# 7011145), Continued Implementation of Homeland Security Presidential Directive 12 (VAIQ#7100147), and VA IAM enterprise identity management requirements (IAM Identity Management Business Requirements Guidance document), located at https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514. The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with NIST Special Publication 800-63, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of Personal Identity Verification (PIV) and/or Common Access Card (CAC), as determined by the business need. Assertion based authentication must include a SAML implementation. Additional assertion implementations, besides the required SAML assertion, may be provided if they are compliant with NIST 800-63 guidelines. Trust based authentication must include authentication/account binding based on trusted HTTP headers. The Contractor solution shall conform to the specific Identity and Access Management PIV requirements are set forth in OMB Memoranda M-04-04 (http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy04/m04-04.pdf), M-05-24 (http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-24.pdf), M-11-11 (http://www.whitehouse.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf), National Institute of Standards and Technology (NIST) Federal Information Processing Standard (FIPS) 201-2, and supporting NIST Special Publications.
The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directive issued by the Office of Management and Budget (OMB) on September 28, 2010 (https://cio.gov/wp-content/uploads/downloads/2012/09/Transition-to-IPv6.pdf) & (http://www.cybertelecom.org/dns/ipv6usg.htm). IPv6 technology, in accordance with the USGv6: A Technical Infrastructure for USGv6 Adoption (http://www.nist.gov/itl/antd/usgv6.cfm) and the NIST SP 800 series applicable compliance (http://csrc.nist.gov/publications/PubsSPs.html), shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 users, including all internal infrastructure and applications shall communicate using native IPv6 operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services, in addition to OMB/VA memoranda, can be found at https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (http://www.whitehouse.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://www.fedramp.gov/files/2015/04/TIC_Ref_Arch_v2-0_2013.pdf.
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 7 (64bit), Internet Explorer 11 and Microsoft Office 2010. In preparation for the future VA standard configuration update, end user solutions shall also be compatible with Office 2013 and Windows 8.1. However, Office 2013 and Windows 8.1 are not the VA standard yet and are currently not approved for use on the VA Network, but are in-process for future approval by OI&T. Upon the release approval of Office 2013 and Windows 8.1 individually as the VA standard, Office 2013 and Windows 8.1 will supersede Office 2010 and Windows 7 respectively. Applications delivered to the VA and intended to be deployed to Windows 7 workstations shall be delivered as a signed .msi package and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by the VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) specific to the particular client operating system being used.
The Contractor shall support VA efforts IAW the Veteran Focused Integration Process (VIP). VIP is a Lean-Agile framework that services the interest of Veterans through the efficient streamlining of activities that occur within the enterprise. The VIP Guide can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371. The VIP framework creates an environment delivering more frequent releases through a deeper application of Agile practices. In parallel with a single integrated release process, VIP will increase cross-organizational and business stakeholder engagement, provide greater visibility into projects, increase Agile adoption and institute a predictive delivery cadence. VIP is now the single authoritative process that IT projects must follow to ensure development and delivery of IT products.
The contractor shall utilize VA approved tools for the creation, update, and storage of BA artifacts. Some of the tools currently being utilized are RSA, System Architect, Tableau, and SharePoint.
SECURITY AND PRIVACY REQUIREMENTS
POSITION/TASK RISK DESIGNATION LEVEL(S)
| Position Sensitivity |
| Background Investigation (in accordance with Department of Veterans Affairs 0710 Handbook, “Personnel Suitability and Security Program,” Appendix A) |
| Low / Tier 1 |
| Tier 1 / National Agency Check with Written Inquiries (NACI) A Tier 1/NACI is conducted by OPM and covers a 5-year period. It consists of a review of records contained in the OPM Security Investigations Index (SII) and the DOD Defense Central Investigations Index (DCII), Federal Bureau of Investigation (FBI) name check, FBI fingerprint check, and written inquiries to previous employers and references listed on the application for employment. In VA it is used for Non-sensitive or Low Risk positions. |
| Moderate / Tier 2 |
| Tier 2 / Moderate Background Investigation (MBI) A Tier 2/MBI is conducted by OPM and covers a 5-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check], a credit report covering a period of 5 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, law enforcement check; and a verification of the educational degree. |
| High / Tier 4 |
| Tier 4 / Background Investigation (BI) A Tier 4/BI is conducted by OPM and covers a 10-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check report], a credit report covering a period of 10 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, spouse, neighbors, supervisor, co-workers; court records, law enforcement check, and a verification of the educational degree. |
The position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:
Position Sensitivity and Background Investigation Requirements by Task
| Task Number |
| Tier1 / Low / NACI |
| Tier 2 / Moderate / MBI |
| Tier 4 / High / BI |
| 5.1.1 |
| |X| |
| |_| |
| |_| |
| 5.1.2 |
| |X| |
| |_| |
| |_| |
| 5.1.3 |
| |X| |
| |_| |
| |_| |
| 5.1.4 |
| |X| |
| |_| |
| |_| |
| 5.1.5 |
| |X| |
| |_| |
| |_| |
| 5.1.6 |
| |X| |
| |_| |
| |_| |
| 5.1.7 |
| |X| |
| |_| |
| |_| |
The Tasks identified above, and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.
CONTRACTOR PERSONNEL SECURITY REQUIREMENTS
Contractor Responsibilities:
1. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak, and understand the English language.
1. The Contractor shall bear the expense of obtaining background investigations.
Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations. The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 6.2 Tasks), etc. The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.
1. The Contractor should coordinate the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized.
c. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:
1) Optional Form 306
2) Self-Certification of Continuous Service
3) VA Form 0710
4) Completed Security and Investigations Center (SIC) Fingerprint Request Form The Contractor personnel shall submit all required information related to their background investigations (completion of the investigation documents (SF85, SF85P, or SF 86) utilizing the Office of Personnel Management’s (OPM) Electronic Questionnaire for Investigations Processing (e-QIP) after receiving an email notification from the Security and Investigation Center (SIC).
The Contractor employee shall certify and release the e-QIP document, print, and sign the signature pages, and send them encrypted to the COR for electronic submission to the SIC. These documents shall be submitted to the COR within 3 business days of receipt of the e-QIP notification email. (Note: OPM is moving towards a “click to sign” process. If click to sign is used, the Contractor employee should notify the COR within 3 business days that documents were signed via eQIP).
1. The Contractor shall be responsible for the actions of all personnel provided to work for VA under this contract. If damages arise from work performed by Contractor provided personnel, under the auspices of this contract, the Contractor shall be responsible for all resources necessary to remedy the incident.
1. A Contractor may be granted unescorted access to VA facilities and/or access to VA Information Technology resources (network and/or protected data) with a favorably adjudicated Special Agreement Check (SAC), training delineated in VA Handbook 6500.6 (Appendix C, Section 9), and, the signed “Contractor Rules of Behavior.” However, the Contractor will be responsible for the actions of the Contractor personnel they provide to perform work for VA. The investigative history for Contractor personnel working under this contract must be maintained in the database of the Office of Personnel Management (OPM).
1. The Contractor, when notified of an unfavorably adjudicated background investigation on a Contractor employee as determined by the Government, shall withdraw the employee from consideration in working under the contract.
Failure to comply with the Contractor personnel security investigative requirements may result in loss of physical and/or logical access to VA facilities and systems by Contractor and Subcontractor employees and/or termination of the contract for default.
Identity Credential Holders must follow all HSPD-12 policies and procedures as well as use and protect their assigned identity credentials in accordance with VA policies and procedures, displaying their badges at all times, and returning the identity credentials upon termination of their relationship with VA.
Contractor shall provide up to date staff rosters of all personnel to include their role descriptions.
METHOD AND DISTRIBUTION OF DELIVERABLES
The Contractor shall deliver documentation in electronic format, unless otherwise directed in Section B of the solicitation/contract. Acceptable electronic media include files compatible with the following applications: MS Word 2010, MS Excel/2010, MS PowerPoint 2010, MS Project 2010, MS Access 2010, MS Visio 2010, AutoCAD 2010, and Adobe Portable Document Format (PDF).
FACILITY/RESOURCE PROVISIONS
The Government will provide office space, telephone service and system access when authorized contract staff work at a Government location as required in order to accomplish the Tasks associated with this PWS. All procedural guides, reference materials, and program documentation for the project and other Government applications will also be provided on an as-needed basis.
The Contractor shall request other Government documentation deemed pertinent to the work accomplishment directly from the Government officials with whom the Contractor has contact. The Contractor shall consider the COR as the final source for needed Government documentation when the Contractor fails to secure the documents by other means. The Contractor is expected to use common knowledge and resourcefulness in securing all other reference materials, standard industry publications, and related materials that are pertinent to the work.
VA may provide remote access to VA specific systems/network in accordance with VA Handbook 6500, which requires the use of a VA approved method to connect external equipment/systems to VA’s network. Citrix Access Gateway (CAG) is the current and only VA approved method for remote access users when using or manipulating VA information for official VA Business. VA permits CAG remote access through approved Personally Owned Equipment (POE) and Other Equipment (OE) provided the equipment meets all applicable 6500 Handbook requirements for POE/OE. All the security controls required for Government furnished equipment (GFE) must be utilized in approved POE or OE. The Contractor shall provide proof to the COR for review and approval that their POE or OE meets the VA Handbook 6500 requirements and VA Handbook 6500.6 Appendix C, herein incorporated as Addendum B, before use. CAG authorized users shall not be permitted to copy, print, or save any VA information accessed via CAG at any time. VA prohibits remote access to VA’s network from non-North Atlantic Treaty Organization (NATO) countries. The exception to this is countries where VA has approved operations established (e.g. Philippines and South Korea).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .