S02-Attachment 1-PWS-Final.pdf

PDF 512 KB Posted

Attached to
DA01--PACT Act- Find Representative Tools (VA-24-00084565) Federal contract opportunity
Solicitation number
36C10B24Q0612
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

This document is a Performance Work Statement (PWS) for a Department of Veterans Affairs (VA) contract opportunity titled "DA01--PACT Act- Find Representative Tools (VA-24-00084565)". The PWS seeks contractor support to help VA migrate Veteran and Power of Attorney (PoA) experiences from the legacy Stakeholder Enterprise Portal (SEP) product and eBenefits platform to VA.gov. The key objectives are to make it easier, safer, faster, and accessible for Veterans and their appointed representatives to create, view, and update PoA relationships, and to explore ways VA.gov can better support Veterans who choose to interact through a VSO-like pathway. The contract will be a firm-fixed price with a 12-month base period, and the work will be performed through agile 2-week sprints with defined deliverables. The government will provide some government-furnished equipment, including laptops, to support the work. The solicitation indicates this is a sole-source opportunity for a Service-Disabled Veteran-Owned Small Business (SDVOSB) or Veteran-Owned Small Business (VOSB).

View the file

Other files for this federal contract opportunity

Other files attached to DA01--PACT Act- Find Representative Tools (VA-24-00084565), newest first.
File Type Posted
S02 - RFQ Find a Rep-Final.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

DEPARTMENT OF VETERANS AFFAIRS

VA Office of the Chief Technology Officer

Find-a-Rep Follow-on

Date: 7/12/2024

VA-24-00084565

PWS Version Number: 1.0

1.0 BACKGROUND

1.1 MISSION OF THE REQUESTING BUSINESS OFFICE

In 2017, the Department of Veterans Affairs (VA) Office of the Chief Technology Officer (OCTO) partnered with VA Central Office and all three VA Administrations to identify a vision statement for enhancing VA’s digital presence for Veterans. That vision is known as the Digital Modernization Vision and is supported by a group of VA executives known as the Digital Modernization Council. This council is chaired by the CTO.

The VA Digital Modernization Vision defined in July 2017:

VA will deliver self-service tools on par with top private sector companies and will have the best online experience in the Federal Government. Every digital service will be customized to the individual using it. Interacting with VA digital services will feel like navigating TurboTax, not filling out a form.

The work described in this PWS directly supports VA OCTO. VA OCTO has three North Star goals:

1/ Increase the usage and throughput of VA services 2/ Decrease the time Veterans spend waiting for an outcome 3/ Increase the quality and reliability of VA services

1.2 PROBLEM WE ARE TRYING TO SOLVE

Today, Veterans rely on Veteran Service Organizations (VSOs) and law offices using a legacy platform (eBenefits) to assign Power of Attorney (PoA) for help in applying for, appealing, and managing benefits. VA needs to create a suite of products, powered by new systems like Lighthouse, to serve Veterans who wish to appoint someone with PoA, to serve the people assigned PoA with the ability to accept or reject the assignment, and support the deprecation of the legacy system used to take those actions.

1.3 EXISTING RELEVANT DOCUMENTATION

Lighthouse has a set of existing services/Application Programming Interface (API) which power transactions on VA.gov and elsewhere, documentation for which can be found here:

https://developer.va.gov/explore

Information about the form Veterans use to appoint Power of Attorney can be found here: About

VA Form 21-22 | Veterans Affairs

Information about the legacy product Stakeholder Enterprise Portal (SEP) built on top of the https://developer.va.gov/explore https://www.va.gov/find-forms/about-form-21-22/ legacy platform (eBenefits), which previously enabled people assigned PoA to accept that power, can be found here: About Stakeholder Enterprise Portal - SEP (va.gov)

2.0 APPLICABLE DOCUMENTS

In the performance of the tasks associated with this Performance Work Statement, the Contractor shall comply with the following:

1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”

2. “Federal Information Security Modernization Act of 2014”

3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security

Requirements for Cryptographic Modules”

4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and

Information Systems,” February 2004

5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and

Information Systems,” March 2006

6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and

Contractors,” August 2013

7. 10 U.S.C. § 2224, "Defense Information Assurance Program"

8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”

9. Public Law 109-461, Veterans Benefits, Health Care, and Information Technology

Act of 2006, Title IX, Information Security Matters

10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”

11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm

12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm

13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5, 2019

14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and

Guidelines,” January 18, 2017

15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal

Information as a Strategic Resource,” July 28, 2016

16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed

Services (CHAMPUS)”

17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the

Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008

18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017

19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004

20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021

21. VA Handbook 6500, “Risk Management Framework for VA Information Systems

VA Information Security Program,” February 24, 2021 https://www.sep.va.gov/maintenance.html https://www.va.gov/vapubs/index.cfm https://www.va.gov/vapubs/index.cfm http://www.va.gov/vapubs http://www.va.gov/vapubs

22. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019

23. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010

24. VA Handbook 6500.6, “Contract Security,” March 12, 2010

25. VA Handbook 6500.8, “Information System Contingency Planning,” April 6, 2011

26. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018

27. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017

28. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference Process

Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp

29. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)

30. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014

31. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015

32. VA Handbook 6510, “VA Identity and Access Management,” January 15, 2016

33. VA Directive and Handbook 6513, “Secure External Connections,” October 12,

34. VA Directive 6300, “Records and Information Management,” September 21, 2018

35. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010

36. NIST SP 800-37 Rev 2, “Risk Management Framework for Information Systems and

Organizations: A System Life Cycle Approach for Security and Privacy,” December

37. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)

38. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015

39. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” March 24, 2014

40. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005

41. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019

42. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008

43. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)

44. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018 https://www.va.gov/process/ https://www.va.gov/process/maps.asp https://www.va.gov/process/artifacts.asp https://www.va.gov/trm/TRMHomePage.aspx https://arch.idmanagement.gov/#what-is-the-ficam-architecture

45. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020

46. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014

47. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile Devices

(Draft),” October 2012

48. Draft National Institute of Standards and Technology Interagency Report (NISTIR)

7981, “Mobile, PIV, and Authentication,” March 2014

49. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland

Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

50. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)

51. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896

52. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents

53. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019

54. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008

55. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007

56. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005

57. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018

58. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August 2, 2001

59. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013

60. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013

61. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote

Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

62. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103

63. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371

64. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28

65. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

66. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020

67. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol

Version 6 (IPv6),” November 19, 2020

68. Social Security Number (SSN) Fraud Prevention Act of 2017

69. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23, 2018 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://www.cisa.gov/publication/tic-30-core-guidance-documents https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28 https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946

3.0 SCOPE OF WORK

3.1 OVERVIEW OF WORK

OCTO is seeking contractor support to help VA migrate Veteran and PoA experiences from the legacy SEP product and eBenefits platform, to VA.gov. There is an expectation of collaboration with other development teams, both internal and external to OCTO possibly including but not limited to digital solutions powered by Lighthouse APIs and APIs owned by OIT on behalf of the Office of the General Counsel. This work will include the research, design, implementation, testing, security, deployment, and support of a suite of services, as well as the capability to conduct technical spikes and assessments and ensure high levels of accessibility compliance.

The Find a Representative and Accredited Reps teams may be asked to assist with conducting research and developing tools and features on each teams’ roadmaps and to detail team members to other VA teams.

3.2 DEVELOPMENT METHODOLOGY AND WORKING PRINCIPLES

The Contractor’s support and solutions shall follow the practices described in the Digital Services Playbook (https://playbook.cio.gov). The Contractor shall be familiar with the concepts in each play and implement them in its approaches and support. The Contractor shall deliver modern digital services that use DevOps techniques that embrace Continuous Integration / Continuous Delivery (CI/CD). The Contractor shall deliver secure and tested modern web application designs using automated testing frameworks.

The Contractor shall provide VA with teams that shall deliver viable, digital solutions in support of VA’s strategic mission and objectives. Specifically, the Contractor shall:

1. Deliver high-quality, functional products that are measured by user feedback from surveys, research, etc.

2. Follow the practices described in the “Digital Services Playbook” (https://playbook.cio.gov).

3. Be agile. Incorporate Agile methodologies and ceremonies into work, such as (but not limited to) sprint planning, daily scrum, sprint review, sprint retrospective, backlog grooming, and estimating activities.

4. Actively involve users in the design of all solutions. Incorporate best practices for modern user research and usability testing, such as (but not limited to) creating user personas, problem space definitions, affinity maps, user flow diagrams, wireframes, information architecture diagrams, design prototypes, user research plans, conversation guides, and user research synthesis.

5. Maintain a consistent look, feel, and voice across user-facing sites and services.

Incorporate best practices defined in the VA Design System and VA Content Style Guide (https://design.va.gov/).

https://playbook.cio.gov/ https://playbook.cio.gov/ https://design.va.gov/

6. Personalize solutions for the individual or team using the product (https://www.whitehouse.gov/briefing-room/presidential-actions/2021/12/13/executive-order-on-transforming-federal-customer-experience-and-service-delivery-to-rebuild-trust-in-government/, https://www.whitehouse.gov/wp-content/uploads/2018/06/s280.pdf)

7. Optimize web applications for mobile-first operation, with all solutions being equally available on both mobile and desktop whenever possible. Incorporate robust accessibility principles into design, development and testing for all web applications to deliver high-quality digital experiences to users of assistive devices.

8. Protect user information with best-in-class security, given the constraints of the environment.

9. Use DevOps techniques of CI/CD across all environments including, at a minimum, development, staging, and production. (http://github.com/department-of-veterans-affairs/va.gov-team/tree/master/platform/engineering/)

10. Use automated testing frameworks to create unit tests, integration tests, functional/black box tests, and load tests (or their equivalents as applicable) to test 100% of functionality delivered. Strive for compliance with Test Driven Development practices.

11. Ensure configuration and sensitive data, including data the VA defines as sensitive, are not present in source code, and are stored in encrypted credential management systems.

12. Deliver all code not containing configuration or sensitive data to an open source repository per Office of Management and Budget Guidance M-16-21.

13. Cultivate a positive, trusting, and cooperative working relationship with the Government and all other vendors supporting this work.

4.0 OBJECTIVES

The Contractor shall provide VA with 2-week iterations of agile software delivery. The agile delivery Iterations shall be supported by multi-disciplinary teams with appropriate skillsets to support the following services: product and delivery management, systems architecture/infrastructure, systems security, systems monitoring, software development, shared front-end and other code libraries, shared tooling, support services, user research, user experience strategy, information architecture, interaction and visual design, content writing, DevSecOps, data analytics, and platform operations and management.

Before each 2-week iteration, during iteration/sprint planning and continuously throughout the period of performance, the contractor shall propose a “definition of done” for the upcoming sprint which details the specific work items and deliverables to be completed during the sprint and shall gain approval on each “definition of done” from the product owner and COR prior to the start of each sprint. The “definition of done” defined during sprint planning will be informed by a continuously prioritized backlog of work items towards the goals and outcomes listed in the PWS. The contractor’s invoice for that sprint will be certified when the definition of done has been approved by the PO and COR. Any item(s) that were initially included in the definition of https://www.whitehouse.gov/briefing-room/presidential-actions/2021/12/13/executive-order-on-transforming-federal-customer-experience-and-service-delivery-to-rebuild-trust-in-government/ https://www.whitehouse.gov/briefing-room/presidential-actions/2021/12/13/executive-order-on-transforming-federal-customer-experience-and-service-delivery-to-rebuild-trust-in-government/ https://www.whitehouse.gov/briefing-room/presidential-actions/2021/12/13/executive-order-on-transforming-federal-customer-experience-and-service-delivery-to-rebuild-trust-in-government/ https://www.whitehouse.gov/wp-content/uploads/2018/06/s280.pdf http://github.com/department-of-veterans-affairs/va.gov-team/tree/master/platform/engineering/ http://github.com/department-of-veterans-affairs/va.gov-team/tree/master/platform/engineering/ done, but not delivered, must be discussed with the PO/COR to ensure their removal from the definition of done was appropriate and justified, prior to the invoice being certified.

4.1 PRODUCT VISION

• Make it easier, safer, faster, and accessible for Veterans and people whom they assign PoA, to create, view, and update their PoA relationships.

• Explore new ways that VA.gov can better support Veterans who choose to interact with VA through a VSO-like pathway.

• The digitized 21-22 application form remains up-to-date with changes to the associated paper form within maximum 1 year of release (target between 0-6 months)

4.2 DESIRED USER OUTCOMES

Throughout the period of performance, the Contractor shall provide a repeatable process for delivery of iterations of agile software development in support of the objectives below, via a backlog of user stories prioritized by the Government. During Sprint Planning, Sprint goals are established by the Product Owner, and the Contractor and Product Owner agree on the Definition of Done. Sprints will be accepted when the Definition of Done determined during Sprint Planning are accepted by the VA Product Owner and COR. Any exceptions must be approved by the Product Owner in advance of the Sprint being accepted.

• The primary outcome desired is to deliver a fast, easy, accessible, and safe experience for Veterans

• Find an accredited representative and assign PoA

• Easily verify if they have an existing accredited representative across their digital VA experience, both within the Find a Representative tool and elsewhere, such as in their VA.gov profile.

• Report outdated representative contact information and unethical or predatory behavior.

Beyond the above, the outcomes we want to achieve use an Objectives and Key Results structure. The following table contains a sample description of the relevant near-term key results and their associated OCTO objectives.

Objective Key Result

Our digital experiences are the best way to access VA health care and benefits

• CSAT for our web products have increased by 5 points

• All new products have a faster transaction time than those they replaced

• No transactions accepted by our products have a fatal error

Our platforms are the best way to deliver products at VA

• Our platforms power twice as many interactions compared to last year

4.3 DESIRED BUSINESS OUTCOMES

• Facilitate and support claim automation initiatives and processes aimed at reducing the amount of time it takes to render decisions and deliver benefits

• Expedite the deprecation of the legacy eBenefits platform and legacy SEP product by delivering replacement services

• Ensure the status of a user’s form or evidence submission is clearly communicated, and that zero fatal submission errors are silent to the user or go unresolved by the submission technology.

4.4 OUTCOMES WE WANT TO AVOID

• Users submitting a form receive a success message but the data never reaches the next system

• Users attempting to submit a form encounter errors that prevent form submission

4.5 POTENTIAL MINIMUM VIABLE PRODUCT FEATURES AND EPICS

• Veterans can view any authorized representative on file and submit a request for representation

• Veterans can gain a comprehensive understanding of the role VSO attorneys and accredited representatives play in the claims and decision review processes

• Veterans can view a list of local recognized VSOs, attorneys, and claims agents and search/filter by things like state/territory, zip code, organization name, and other criteria

• Veterans can view the VA’s official list of VA-recognized organizations and VA-accredited individuals and search/filter by state/territory, zip code, name, and potentially other criteria

• Veterans can submit a request to appoint a VSO as their Representative

• Per 38 USC 5901: Prohibition against acting as claims agent or attorney, Veterans can report individuals who act as an accredited representative without authorization and/or view final discipline decisions on accredited representatives

• Delivery of SEP replacement services such as enabling representatives to complete and submit a disability claim, upload supporting documents, add or change a Veteran’s dependents on a Veteran’s behalf, and/or view claims status information.

5.0 PERFORMANCE DETAILS

5.1 PERIOD OF PERFORMANCE (POP) AND BUDGET ESTIMATE

The Period of Performance (PoP) shall be one 12-month Base Period.

5.2 TRANSITION SUPPORT (OPTIONAL TASK)

https://uscode.house.gov/view.xhtml?req=granuleid:USC-prelim-title38-section5901&num=0&edition=prelim#sourcecredit

Transition of a product to a new contractor or the Government is sometimes necessary. It is critical to the continued functionality of OCTO products that all contractors are diligent in transitions between teams to ensure there is no disruption in Veteran services. The most important factors in these transitions are the availability of well written documentation and good faith communications. This optional task shall be for a period of up to 30 days, if exercised by the Government. The Contractor must submit a Transition Support Package within (7) days upon optional task exercise. The Transition Support Package shall consist of at least the following, and is critical to the successful transition in OCTO, and must be available in the relevant GithHub repository:

1. All documentation

2. All access to the platform (if applicable) and anything interacting with the platform or application, for which the incoming vendor will require access

3. All relevant information necessary for Developer onboarding – interaction with 3rd party tools, downstream services, application interactions outside va.gov

In consult with the relevant OCTO Product Owner and COR, the Contractor shall create a list of all relevant stakeholders both inside OCTO, across VA, and outside VA (if relevant). The contractor shall ensure frank and open communication between all staff of the exiting and incoming contractors. At a minimum the outgoing contractor shall ensure the incoming contractor has access to the following:

1. Product documentation including product outlines/briefings, objectives and key results (OKRs), roadmaps and active epics/stories, stakeholder landscape maps, decision records, and analytics

2. Developer documentation including READMEs, set-up instructions, diagrams, relevant databases and services.

3. Design documentation including prototypes, user research reports, design decisions for products in production, early designs for incomplete products, content strategy, and records of interactions with the collaboration cycle.

4. Access to accounts for third-party products such as tooling or SaaS products that will be taken over by the new team.

Although not exhaustive, the following are typical interactions which the contractor shall support during transition:

1. A handoff coordination meeting between the leads of the incoming and outgoing teams

2. Community of Practice specific orientations to the available documentation allowing the outgoing team to ask questions

3. Conversations about the stakeholder landscape and typical communication patterns

4. Demonstrations of specific functionality in the application

5. Any routine steps that the contractor currently performs to observe and maintain the health of a system (production or otherwise) must be documented and reviewed with the government.

Deliverable:

A. Transition Support Package

5.3 CONTRACT TYPE

The effort shall be proposed on a Firm Fixed Price (FFP) basis.

5.4 KEY PERSONNEL

Senior Product Manager, shall provide significant expertise in the following:

• Set a clear vision for the product, aligning it with both user needs and business goals.

• Define a strategic roadmap, balancing short-term wins with long-term innovation.

• Efficiently manage the product development lifecycle, ensuring timely delivery of features. This involves coordinating cross-functional teams, prioritizing tasks, and maintaining a high standard of quality.

• Continuously gather user feedback and monitor product metrics. Use this to make informed decisions, adapting the product strategy as needed to meet evolving user requirements and trends in user satisfaction and other product success metrics.

Senior Engineering Lead, shall provide significant expertise in the following:

• Support a development team with the skills and expertise to successfully deliver and support products using the mix of technologies needed for the project, including Ruby on Rails and React and Amazon Web Services (AWS).

• Adheres to modern software development practices including documentation, testing, and monitoring.

• Makes sure engineering decisions are architecturally sound.

Senior Designer / User Researcher, shall provide significant expertise in the following:

• Provide human-centered design and research deliverables that align with standards set by VA.gov

• Collaborate with engineers to ensure design deliverables are achievable with any uncovered technical restraints

• Ensure staffing can support continuous and simultaneous research on both teams, both evaluative and generative research efforts

• Mentors human-centered designers and researchers as needed to support quality and timely deliverables

• Ensures UI visual designers are properly staffed to the program, depending on project needs

• Provide meaningful hands-on contributions to design and research in support of the project

Additional Information

SCRUM teams will be considered acceptable when they can effectively work. This may include some resources that are staffed, but not cleared. This will be case by case and worked with the COR. For the initial team to be deemed ready to work, all members of the team will have a Personal Security Adjudication Center letter in order to obtain access to working tools such as

GitHub and Slack that do not require VA network access. Access to Amazon Web Services requires an Electronic Questionnaires for Investigations Processing release date.

5.5 KICKOFF MEETING

The Contractor shall hold a kickoff meeting within 10 days after task order award. The Contractor shall present, for review and approval by the Government, at a minimum the details of the intended approach, work plan, and onboarding plan. The Contractor shall specify dates, locations (can be virtual), agenda (shall be provided to all attendees at least five calendar days prior to the meeting), and meeting minutes (shall be provided to all attendees within three calendar days after the meeting). The Contractor shall invite the Contracting Officer, Contract Specialist, COR and the VA Program Manager/Product Owner.

6.0 QUALITY ASSURANCE SURVEILLANCE PLAN (QASP)

6.1 PRODUCT SPECIFIC OBJECTIVES AND KEY RESULTS

The Government is open to discussion with the vendor about appropriate QASP metrics for this task order after award.

6.2 RECURRING DELIVERABLES

Delivery and Monitoring Report and Roster: The Contractor shall provide a single monthly report, detailing and providing links to all stories, epics and other work completed. This includes a plain language description of all work accepted by the Government Product Owner and COR at the end of each sprint. This report shall include, in plain language, additional details about the project status, sprint team velocity, sprint team goal completion, and highlight project risks. The report shall also highlight and provide links to key infrastructure and application monitoring data. The report shall also include details with links to documentation for any critical incidents or outage events that resulted in service outages or significant service degradations. The Contractor shall attach or provide links to postmortem documentation for all critical incidents or outage events. Should there not be any reported incidents during the reporting period, a link to the relevant monitoring tools is sufficient. The specific data points and format of this monthly report shall be determined by the Contractor in collaboration with the VA Program Manager/Product Owner and COR. Lastly, the Contractor shall submit a roster to the COR that includes the Status of Government Furnished Equipment (GFE) for all GFE all staff, as applicable.

7.0 DATA AND OPEN SOURCE REQUIREMENTS

The Government shall receive Unlimited Rights to data first produced in performance of this contract in accordance with FAR 52.227-14, “Rights In Data-General” (MAY 2014). This includes all rights to source code and any and all documentation created in support thereof.

License rights in any Commercial Computer Software shall be governed by FAR 52.227-19, “Commercial Computer Software License” (DEC 2007). Any data delivered shall be submitted and protected in accordance with VA handbook 6500.

VA intends that the software delivered under this task order will be publicly posted without restriction. To the extent that the Contractor(s) seeks to incorporate into the software delivered under this task order any software that was not first produced in the performance of this task order, VA encourages the Contractor(s) to incorporate either software that is in the public domain, or free and open source software that qualifies under the Open Source Definition promulgated by the Open Source Initiative. In any event, the Contractor(s) must promptly disclose to VA in writing, and list in the documentation, any software incorporated in the delivered software that is subject to a license fee.

8.0 OTHER ADMINISTRATIVE ITEMS

8.1 PLACE OF PERFORMANCE

Efforts under this task order can be performed at any location within the United States. All work locations must be able to accommodate the Hours of Work specified in Section 8.4.

8.2 TRAVEL

Travel is expected for yearly in-person planning meetings and/or to support user research sessions. The travel is expected 2 times in the 12 month POP, for the full team, to a location within the Continental United States. Travel costs shall be included in the contractor’s Firm Fixed Price.

8.3 HOURS OF WORK

The contractor shall set their own work hours. However, contractors may be required to attend meetings with Government personnel between standard east coast work hours (typically 9am – 5pm ET). Additionally, monitoring and production support will be required between 7am – 8pm

ET.

9.0 GENERAL REQUIREMENTS

9.1 ENTERPRISE AND IT FRAMEWORK

9.1.1 VA TECHNICAL REFERENCE MODEL

The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OI&T Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OI&T. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.

9.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT

(FICAM)

The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in the VA Handbook 6510 and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0

The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.

The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-04-04, M-05-24, M-11-11, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-04-04, M-05-24, and M-11-11 can be found at:

https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf, https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf, and https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.

The Contractor shall ensure all Contractor delivered applications and systems support:

1. Automated provisioning and are able to use enterprise provisioning service.

2. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number

[ICN]).

4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.

5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.

6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.

7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA

Enterprise Design Patterns.

8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.

https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy04/m04-04.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-24.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/memoranda/2011/m11-11.pdf

9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.

10. Role Based Access Control.

11. Auditing and reporting capabilities.

12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.

The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.

9.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)

The Contractor solution shall support the latest Internet Protocol Version 6 (IPv6) based upon the directives issued by the Office of Management and Budget (OMB) on August 2, 2005 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05- 22.pdf) and September 28, 2010 (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf).

IPv6 technology, in accordance with the USGv6 Profile, NIST Special Publication (SP) 500-267 (https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf), the Technical Infrastructure for USGv6 Adoption (https://www.nist.gov/programs-projects/usgv6-program), and the NIST SP 800 series applicable compliance (https://csrc.nist.gov/publications/sp ) shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and/or dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g. web, email, DNS, ISP services, etc.) shall support native IPv6 and/or dual stack (IPv6/ IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and/or dual stack (IPv6/ IPv4) operations. Guidance and support of improved methodologies which ensure interoperability with legacy protocol and services in dual stack solutions, in addition to OMB/VA memoranda, can be found at: https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282.

9.1.4 TRUSTED INTERNET CONNECTION (TIC)

The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M08-05 mandating Trusted Internet Connections (TIC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08- 05.pdf), M08-23 mandating Domain Name System Security (NSSEC) (https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08- 23.pdf), and shall comply with the Trusted Internet Connections (TIC) Reference Architecture Document, Version 2.0 https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf.

9.1.5 STANDARD COMPUTER CONFIGURATION

The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Internet Explorer 11 and Office 365 ProPlus. Applications delivered to VA and intended to be deployed https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2005/m05-22.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/egov_docs/transition-to-ipv6.pdf https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication500-267.pdf https://csrc.nist.gov/publications/sp https://www.voa.va.gov/documentlistpublic.aspx?NodeID=282 https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-05.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://obamawhitehouse.archives.gov/sites/default/files/omb/assets/omb/memoranda/fy2008/m08-23.pdf https://www.dhs.gov/sites/default/files/publications/TIC_Ref_Arch_v2.2_2017.pdf to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using System Center Configuration Manager (SCCM) VA’s current desktop application deployment tool.

Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.

9.1.6 PROCESS ASSET LIBRARY (PAL)

The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section 6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf . The main PAL can be accessed at www.va.gov/process.

9.1.7 AUTHORITATIVE DATA SOURCES

The VA Enterprise Architecture Repository (VEAR) is one component within the overall Enterprise Architecture (EA) that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:

1. Interfacing with VA’s Master Veteran Index (MVI) to provision identity attributes, if the solution relies on VA user identities. MVI is the authoritative source for VA user identity data.

2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.

3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data.

ECMS is the authoritative source for VA procurement actions data.

https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf http://www.va.gov/process

4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.

5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.

6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active-duty military service data. VADIR is the authoritative source for Qualifying Active- Duty military service in VA.

9.1.8 SECURITY AND PRIVACY REQUIREMENTS

9.1.8.1 POSITION/TASK RISK DESIGNATION LEVEL(S)

Position Sensitivity

Background Investigation (in accordance with Department of Veterans Affairs 0710 Handbook, “Personnel Suitability and Security Program,” Appendix A)

Low / Tier 1 Tier 1 / National Agency Check with Written Inquiries (NACI) A Tier 1/NACI is conducted by OPM and covers a 5-year period. It consists of a review of records contained in the OPM Security Investigations Index (SII) and the DOD Defense Central Investigations Index (DCII), Federal Bureau of Investigation (FBI) name check, FBI fingerprint check, and written inquiries to previous employers and references listed on the application for employment. In VA it is used for Non-sensitive or Low Risk positions.

Moderate / Tier 2

Tier 2 / Moderate Background Investigation (MBI) A Tier 2/MBI is conducted by OPM and covers a 5-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check], a credit report covering a period of 5 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, law enforcement check; and a verification of the educational degree.

High / Tier 4 Tier 4 / Background Investigation (BI) A Tier 4/BI is conducted by OPM and covers a 10-year period. It consists of a review of National Agency Check (NAC) records [OPM Security Investigations Index (SII), DOD Defense Central Investigations Index (DCII), FBI name check, and a FBI fingerprint check report], a credit report covering a period of 10 years, written inquiries to previous employers and references listed on the application for employment; an interview with the subject, spouse, neighbors, supervisor, co-workers; court records, law enforcement check, and a verification of the educational degree.

The position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the Performance Work Statement are:

Position Sensitivity and Background Investigation Requirements by Task

Task Number Tier1 / Low / NACI Tier 2 / Moderate / MBI Tier 4 / High / BI

All Tasks The Tasks identified above and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will be working. The submitted Contractor Staff Roster must indicate the required Background Investigation Level for each Contractor individual based upon the tasks the Contractor individual will be working, in accordance with their submitted proposal.

9.1.9 CONTRACTOR PERSONNEL SECURITY REQUIREMENTS

9.1.10 Contractor Responsibilities:

a. The Contractor shall prescreen all personnel requiring access to the computer systems to ensure they maintain the appropriate Background Investigation, and are able to read, write, speak and understand the English language.

b. The Contractor shall bear the expense of obtaining background investigations. Within 3 business days after award, the Contractor shall provide a roster of Contractor and Subcontractor employees to the COR to begin their background investigations in accordance with the ProPath template.

The Contractor Staff Roster shall contain the Contractor’s Full Name, Date of Birth, Place of Birth, individual background investigation level requirement (based upon Section 7.0 Tasks), etc.

The Contractor shall submit full Social Security Numbers either within the Contractor Staff Roster or under separate cover to the COR. The Contractor Staff Roster shall be updated and provided to VA within 1 day of any changes in employee status, training certification completion status, Background Investigation level status, additions/removal of employees, etc. throughout the Period of Performance. The Contractor Staff Roster shall remain a historical document indicating all past information and the Contractor shall indicate in the Comment field, employees no longer supporting this contract. The preferred method to send the Contractor Staff Roster or Social Security Number is by encrypted e-mail. If unable to send encrypted e-mail, other methods which comply with FIPS 140-2 are to encrypt the file, use a secure fax, or use a traceable mail service.

c. The Contractor should coordinate the location of the nearest VA fingerprinting office through the COR. Only electronic fingerprints are authorized.

d. The Contractor shall ensure the following required forms are submitted to the COR within 5 days after contract award:

1) For a Tier 1/Low Risk designation:

a) OF-306

b) DVA Memorandum – Electronic Fingerprints

2) For Tier 2/Moderate or Tier 4/High Risk designation:

a) OF-306

b) VA Form 0710

c) DVA Memorandum – Electronic Fingerprints

e. The Contractor personnel shall submit all required information…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .