S02 Final RFQ 36C10A24Q0124 7.23.24.pdf
PDF 2 MB Posted
- Attached to
- DA01--Vocera Premier Plus Support Services Federal contract opportunity
- Solicitation number
- 36C10A24Q0124
About this file
This document is a Request for Quotation (RFQ) for Vocera Premier Plus Support Services from the Department of Veterans Affairs (VA) Technology Acquisition Center.
The VA seeks a contractor to provide a systematic delivery of best practices in the use, maintenance, and on-going design support of the Vocera communication system at the Fayetteville VA Coastal Healthcare System. The services include Vocera data and device management, software management, deployment optimization, training and orientation, reporting, Vocera Engage administration, and user satisfaction. The base period is 1 year from August 1, 2024 to July 31, 2025, with four 1-year option periods. Pricing is fixed-price, with quantities not separately priced. The set-aside is for small businesses. Quotes are due July 29, 2024 by 2:00PM EST. The award will be made to the lowest-priced, technically-acceptable offeror.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| S03 JA Redacted_Redacted.pdf | ||
| S06 Amended RFQ 0001 36C10A24Q0124 8.8.24.pdf | ||
| S06 36C10A24Q0124 0001.pdf | ||
| 36C10A24Q0124_3.docx | DOCX document | |
| 36C10A24Q0124_1.docx | DOCX document | |
| P03 Brand Name JA_Vocera Premier Plus Support Redacted_Redacted.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PAGE 1 OF 101 1. REQUISITION NO.
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NO. 5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
a. NAME b. TELEPHONE NO. (No Collect Calls) 8. OFFER DUE DATE/LOCAL
TIME
9. ISSUED BY CODE 10. THIS ACQUISITION IS UNRESTRICTED OR SET ASIDE: % FOR:
SMALL BUSINESS
HUBZONE SMALL
BUSINESS
SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
WOMEN-OWNED SMALL BUSINESS
(WOSB) ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
8(A)
NAICS:
SIZE STANDARD:
11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
12. DISCOUNT TERMS
13a. THIS CONTRACT IS A
RATED ORDER UNDER
DPAS (15 CFR 700)
13b. RATING
14. METHOD OF SOLICITATION
RFQ IFB RFP
15. DELIVER TO CODE 16. ADMINISTERED BY CODE
17a. CONTRACTOR/OFFEROR CODE FACILITY CODE 18a. PAYMENT WILL BE MADE BY CODE
TELEPHONE NO. UEI: EFT:
PHONE: FAX:
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT SUCH ADDRESS IN OFFER
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a UNLESS BLOCK BELOW IS CHECKED
SEE ADDENDUM
19. 20. 21. 22. 23. 24.
ITEM NO. SCHEDULE OF SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
(Use Reverse and/or Attach Additional Sheets as Necessary)
25. ACCOUNTING AND APPROPRIATION DATA 26. TOTAL AWARD AMOUNT (For Govt. Use Only)
27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1, 52.212-4. FAR 52.212-3 AND 52.212-5 ARE ATTACHED. ADDENDA ARE ARE NOT ATTACHED.
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN _______________ 29. AWARD OF CONTRACT: REF. ___________________________________ OFFER COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND DATED ________________________________. YOUR OFFER ON SOLICITATION DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY (BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED SET FORTH HEREIN IS ACCEPTED AS TO ITEMS:
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a. UNITED STATES OF AMERICA (SIGNATURE OF CONTRACTING OFFICER)
30b. NAME AND TITLE OF SIGNER (TYPE OR PRINT) 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER (TYPE OR PRINT) 31c. DATE SIGNED
AUTHORIZED FOR LOCAL REPRODUCTION (REV. NOV 2021)
PREVIOUS EDITION IS NOT USABLE Prescribed by GSA - FAR (48 CFR) 53.212
7. FOR SOLICITATION
INFORMATION CALL:
STANDARD FORM 1449
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL PRODUCTS AND COMMERCIAL SERVICES
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, & 30
565-24-3-096-0050
36C10A24Q0124 7/25/2024
Daniel Renna, Contract Specialist 848 377 5048 7/29/2024
2:00PM EST
Department of Veterans Affairs Technology Acquisition Center Procurement Service G 23 Christopher Way Eatontown NJ 07724
X 100
X
541519
150 EMP
N/A
X
See Schedule
Procurement Service G
Eatontown NJ 07724
Department of Veteran Affairs
Financial Services Center PO Box 149971 Austin TX 78714-8971
(877) 353-9791
Title: Vocera Premier Plus Support Services
See Section B.1 for Schedule of Supplies and Services
See CONTINUATION Page
565-3640160-096-824100-3131 010024101 x x
Lori L. Walker
Request For Quotation: 36C10A24Q0124
SECTION B - CONTINUATION OF SF 1449
B.1 SCHEDULE OF SUPPLIES AND SERVICES
BASE PERIOD
Vocera Premier Plus Support Services
Inspection/Acceptance: Destination
Period of Performance: August 1, 2024 through July 31, 2025
IFCAP Purchase Order #: TBD
ARM SN: 179808
Primary Point of Contact: To be provided at award
Product Service Code (PSC): DA01
19. ITEM
NO.
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23. UNIT
PRICE
24.
AMOUNT
0001 Vocera Premier Plus Support Services Upgrade (Annual)
Part #240-01405
POP: 8/01/2024- 7/31/2025
PSC: DA01
1 EA $
0002 Yearly Vocera User Satisfaction Survey
In Accordance With (IAW) Performance Work Statement (PWS) paragraph 5.0.
PSC: DA01
1 EA Not Separately Priced (NSP)
NSP
0003 Contractor Staff Roster
IAW PWS paragraph 6.2.2.
PSC: DA01
1 EA NSP NSP
0004 Monthly Government Furnished Equipment (GFE) Status Report
IAW PWS paragraph 6.6.
PSC: DA01
12 MO NSP NSP
Total Amount Base Period: $
OPTION PERIOD 1: Option for an additional 12-months of Support IAW FAR 52.217-9, “Option to Extend the Term of the Contract”
Vocera Premier Plus Support Services
Inspection/Acceptance: Destination
Period of Performance: August 1, 2025 through July 31, 2026
IFCAP Purchase Order #: TBD
ARM SN: TBD
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23. UNIT
PRICE
24.
AMOUNT
1001 Vocera Premier Plus Support Services Upgrade (Annual)
Part #240-01405
POP: 8/01/2025- 7/31/2026
1002 Yearly Vocera User Satisfaction
IAW PWS paragraph 5.0.
PSC: DA01
1 EA NSP NSP
1003 Contractor Staff Roster
IAW PWS paragraph 6.2.2.
PSC: DA01
1 EA NSP NSP
1004 Monthly GFE Status Report
IAW PWS paragraph 6.6.
PSC: DA01
12 MO NSP NSP
Total Amount Option Period 1: $
OPTION PERIOD 2: Option for an additional 12-months of Support IAW FAR 52.217-9, “Option to Extend the Term of the Contract”
Inspection/Acceptance: Destination
Period of Performance: August 1, 2026 through July 31, 2027
IFCAP Obligation Number: TBD
ARM SN: TBD
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23. UNIT
PRICE
24.
AMOUNT
2001 Vocera Premier Plus Support Services Upgrade (Annual)
Part #240-01405
POP: 8/01/2026- 7/31/2027
2002 Yearly Vocera User Satisfaction
IAW PWS paragraph 5.0.
PSC: DA01
1 EA NSP NSP
2003 Contractor Staff Roster
IAW PWS paragraph 6.2.2.
PSC: DA01
1 EA NSP NSP
2004 Monthly GFE Status Report
IAW PWS paragraph 6.6.
PSC: DA01
12 MO NSP NSP
Total Amount Option Period 2: $
OPTION PERIOD 3: Option for an additional 12-months of Support IAW FAR 52.217-9, “Option to Extend the Term of the Contract”
Vocera Premier Plus Support Services
Inspection/Acceptance: Destination
Period of Performance: August 1, 2027 through July 31, 2028
IFCAP Obligation Number: TBD
ARM SN: TBD
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23. UNIT
PRICE
24.
AMOUNT
3001 Vocera Premier Plus Support Services Upgrade (Annual)
Part #240-01405
POP: 8/01/2027- 7/31/2028
3002 Yearly Vocera User Satisfaction
IAW PWS paragraph 5.0.
PSC: DA01
1 EA NSP NSP
3003 Contractor Staff Roster
IAW PWS paragraph 6.2.2.
PSC: DA01
1 EA NSP NSP
3004 Monthly GFE Status Report
IAW PWS paragraph 6.6.
PSC: DA01
12 MO NSP NSP
Total Amount Option Period 3: $
OPTION PERIOD 4: Option for an additional 12-months of Support IAW FAR 52.217-9, “Option to Extend the Term of the Contract”
Vocera Premier Plus Support Services
Inspection/Acceptance: Destination
Period of Performance: August 1, 2028 through July 31, 2029
IFCAP Obligation Number: TBD
ARM SN: TBD
GOVERNING LAW CLAUSE
Federal law and regulations, including the Federal Acquisition Regulations (FAR), shall govern this Contract/Order. Commercial license agreements may be made a part of this Contract/Order but only if both parties expressly make them an addendum hereto, as permitted by FAR 12.212. If the commercial license agreement is not made an addendum, it shall not apply, govern, be a part of or have any effect whatsoever on the Contract/Order; this includes, but is not limited to, any agreement embedded in the computer software (clickwrap), any agreement that is otherwise delivered with or provided to the Government with the commercial computer software or documentation (shrinkwrap), or any other license agreement otherwise referred to in any document. If a commercial license agreement is made an addendum, only those provisions addressing
20. SCHEDULE OF
SUPPLIES/SERVICES
21.
QTY
22.
UNIT
23. UNIT
PRICE
24.
AMOUNT
4001 Vocera Premier Plus Support Services Upgrade (Annual)
Part #240-01405
POP: 8/01/2028- 7/31/2029
4002 Yearly Vocera User Satisfaction
IAW PWS paragraph 5.0.
PSC: DA01
1 EA NSP NSP
4003 Contractor Staff Roster
IAW PWS paragraph 6.2.2.
PSC: DA01
1 EA NSP NSP
4004 Monthly Government Furnished Equipment (GFE) Status Report
IAW PWS paragraph 6.6.
PSC: DA01
12 MO NSP NSP
Total Amount Option Period 4: $ Total Amount Base and All Options: $ data rights regarding the Government’s use, duplication and disclosure of data (e.g., restricted computer software) are included and made a part of this Contract/Order, and only to the extent that those provisions are not duplicative or inconsistent with Federal law, Federal regulation, the incorporated FAR clauses and the provisions of this Contract/Order; those provisions in the commercial license agreement that do not address data rights regarding the Government’s use, duplication and disclosure of data shall not be included or made a part of the Contract/Order. Federal law and regulation including, without limitation, the Contract Disputes Act (41 U.S.C. § 7101 et seq.), the Anti-Deficiency Act (31 U.S.C. § 1341 et seq.), the Competition in Contracting Act (41 U.S.C. § 3301 et seq.), the Prompt Payment Act (31 U.S.C. § 3901 et seq.), Contracts for Data Processing or Maintenance (38 USC § 5725), and FAR clauses 52.212-4, 52.227-14, 52.227-19 shall supersede, control, and render ineffective any inconsistent, conflicting, or duplicative provision in any commercial license agreement. In the event of conflict between this clause and any provision in the Contract/Order or the commercial license agreement or elsewhere, the terms of this clause shall prevail. The Contractor shall deliver to the Government all data first produced under this Contract/Order with unlimited rights as defined by FAR 52.227-14. Claims of patent or copyright infringement brought against the Government as a party shall be defended by the U.S.
Department of Justice (DOJ) in accordance with 28 U.S.C. § 516; at the discretion of DOJ, the Contractor may be allowed reasonable participation in the defense of the litigation. Any additional changes to the Contract/Order must be made by modification (Standard Form 30) and shall only be made by a warranted Contracting Officer. Nothing in this Contract/Order or any commercial license agreement shall be construed as a waiver of sovereign immunity.
SOFTWARE LICENSE, MAINTENANCE AND TECHNICAL SUPPORT:
(1). Definitions.
a) Licensee. The term “licensee” shall mean the U.S. Department of Veterans Affairs (“VA”) and is synonymous with “Government.”
b) Licensor. The term “licensor” shall mean the Contractor having the necessary license or ownership rights to deliver license, software maintenance and support of the computer software being acquired.
The term “Contractor” is the party identified in Block 17a on the SF1449. If the Contractor is a reseller and not the Licensor, the Contractor remains responsible for performance under this Contract/Order.
c) Software. The term “software” shall mean the licensed computer software product(s) cited in the Schedule of Supplies/Services.
d) Maintenance. The term “maintenance” is the process of enhancing and optimizing software, as well as remedying defects. It shall include all new fixes, patches, releases, updates, versions and upgrades, as further defined below.
e) Technical Support. The term “technical support” refers to the range of services providing assistance for the software via the telephone, email, a website or otherwise.
f) Release or Update. The term “release” or “update” are terms that refer to a revision of software that contains defect corrections, minor enhancements, or improvements of the software’s functionality. This is usually designated by a change in the number to the right of the decimal point (e.g., from Version 5.3 to 5.4). An example of an update is the addition of new hardware.
g) Version or Upgrade. The term “version” or “upgrade” are terms that refer to a revision of software that contains new or improved functionality. This is usually designated by a change in the number to the left of the decimal point (e.g., from Version 5.4 to 6).
(2). Software License.
a) Unless otherwise stated in the Schedule of Supplies/Services, the Performance Work Statement or Product Description, the software license provided to the Government is a perpetual, nonexclusive license to use the software.
b) The Government may use the software in a networked environment.
c) Any dispute regarding the license grant or usage limitations shall be resolved in accordance with the Disputes Clause incorporated in FAR 52.212-4(d).
d) All limitations of software usage are expressly stated in the Schedule of Supplies/Services and the Performance Work Statement/Product Description.
(3). Software Maintenance and Technical Support.
a) If the Government desires to continue software maintenance and support beyond the period of performance identified in this Contract/Order, the Government will issue a separate contract or order for maintenance and support. Conversely, if a contract or order for continuing software maintenance and technical support is not received, the Contractor is neither authorized nor permitted to renew any of the previously furnished services.
b) The Contractor shall provide software support services, which includes periodic updates, enhancements and corrections to the software, and reasonable technical support, all of which are customarily provided by the Contractor to its commercial customers to cause the software to perform according to its specifications, documentation or demonstrated claims.
c) Any telephone support provided by Contractor shall be at no additional cost.
d) The Contractor shall provide all maintenance services in a timely manner in accordance with the Contractor’s customary practice or as defined in the Performance Work Statement or Product Description. However, prolonged delay (exceeding 2 business days) in resolving software problems will be noted in the Government’s various past performance records on the Contractor (e.g., www.cpars.gov).
e) If the Government allows the maintenance and support to lapse and subsequently wishes to reinstate it, any reinstatement fee charged shall not exceed the amounts that would have been charged if the Government had not allowed the subscription to lapse.
(4). Disabling Software Code.
The Government requires delivery of computer software that does not contain any code that will, upon the occurrence or the nonoccurrence of any event, disable the software. Such code includes but is not limited to a computer virus, restrictive key, node lock, time-out, or other function, whether implemented by electronic, mechanical, or other means, which limits or hinders the use or access to any computer software based on residency on a specific hardware configuration, frequency of duration of use, or other limiting criteria. If any such disabling code is present, the Contractor agrees to indemnify the Government for all damages suffered as a result of a disabling caused by such code, and the contractor agrees to remove such code upon the Government’s request at no extra cost to the Government. Inability of the Contractor to remove the disabling software code will be considered an inexcusable delay and a material breach of contract, and the Government may exercise its right to terminate for cause. In addition, the Government is permitted to remove the code as it deems appropriate and charge the Contractor for consideration for the time and effort expended in removing the code.
(5). Manuals and Publications.
Upon Government request, the Contractor shall furnish the most current version of the user manual and publications for all products/services provided under this Contract/Order at no additional cost.
B.2 CONTRACT ADMINISTRATION DATA
1. Contract Administration: All contract administration matters will be handled by the following individuals:
a. CONTRACTOR: To be determined
b. GOVERNMENT: Contracting Officer 36C10A See Block 31b.
Technology Acquisition Center – Procurement Service G
Eatontown NJ 07724
2. CONTRACTOR REMITTANCE ADDRESS: All payments by the Government to the contractor will be made in accordance with:
[X] 52.232-33, Payment by Electronic Funds Transfer—System For Award Management, or
[] 52.232-36, Payment by Third Party
3. INVOICES: Invoices shall be submitted in arrears:
a. Quarterly []
b. Semi-Annually []
c. Other [X] Upon receipt and acceptance.
4. GOVERNMENT INVOICE ADDRESS: All Invoices from the contractor shall be submitted electronically in accordance with VAAR Clause 852.232-72 Electronic Submission of Payment Requests.
See website at: http://www.fsc.va.gov/einvoice.asp
ACKNOWLEDGMENT OF AMENDMENTS: The offeror acknowledges receipt of amendments to the Solicitation numbered and dated as follows:
AMENDMENT NO DATE
B.3 ACCOUNTING AND APPROPRIATION DATA
Funds in the amount of $TBD are obligated on IFCAP Purchase Order Number TBD to fund CLINs 0001-0004. The contractor shall reference the IFCAP Purchase Order Number and CLIN/SLIN on each invoice submitted for payment.
B.4 PERFORMANCE WORK STATEMENT
PERFORMANCE WORK STATEMENT (PWS)
DEPARTMENT OF VETERANS AFFAIRS
Veterans Health Administration Fayetteville VA Coastal Healthcare System
Date: 07/17/2024
VA-24-00086577
PWS Version Number: 1.0
1.0 BACKGROUND
The Department of Veterans Affairs (VA) Veterans Health Administration Fayetteville VA Coastal Healthcare System has a requirement for continued Vocera Premier Plus Support Services (only maintenance and support) for VA-owned Vocera badge devices.
Vocera badge devices are Federal Information Processing Standards 140-2 compliant and dual-band for distribution to nursing staff and clinical support services for communication within the patient care team. The Vocera badges allow for hands free communication (voice/messaging) between the clinical care team and nursing staff to coordinate patient care. These services consist of the management of the Vocera system currently deployed across the Fayetteville enterprise. Vocera Premier Plus Support Service requires premier level technical support and maintenance of the system. Vocera Premier Plus Support Services are a comprehensive and systematic delivery of best practices in the use, maintenance, and on-going design support of the Vocera communication system
2.0 APPLICABLE DOCUMENTS
In the performance of the tasks associated with this PWS, the Contractor shall comply with the following:
1. 44 U.S.C. § 3541-3549, “Federal Information Security Management Act (FISMA) of 2002”
2. “Federal Information Security Modernization Act of 2014”
3. Federal Information Processing Standards (FIPS) Publication 140-2, “Security Requirements for Cryptographic Modules”
4. FIPS Pub 199. “Standards for Security Categorization of Federal Information and Information Systems,” February 2004
5. FIPS Pub 200, “Minimum Security Requirements for Federal Information and
Information Systems,” March 2006
6. FIPS Pub 201-2, “Personal Identity Verification of Federal Employees and
Contractors,” August 2013
7. 10 U.S.C. § 2224, “Defense Information Assurance Program”
8. 5 U.S.C. § 552a, as amended, “The Privacy Act of 1974”
9. Public Law 109-461, Veterans Benefits, Health Care, and Information
Technology Act of 2006, Title IX, Information Security Matters
10. 42 U.S.C. § 2000d “Title VI of the Civil Rights Act of 1964”
11. VA Directive 0710, “Personnel Security and Suitability Program,” June 4, 2010, https://www.va.gov/vapubs/index.cfm
12. VA Handbook 0710, “Personnel Security and Suitability Program,” May 2, 2016, https://www.va.gov/vapubs/index.cfm
13. VA Directive and Handbook 6102, “Internet/Intranet Services,” August 5,
14. 36 C.F.R. Part 1194 “Information and Communication Technology Standards and Guidelines,” January 18, 2017
15. Office of Management and Budget (OMB) Circular A-130, “Managing Federal
Information as a Strategic Resource,” July 28, 2016
16. 32 C.F.R. Part 199, “Civilian Health and Medical Program of the Uniformed
Services (CHAMPUS)”
17. NIST SP 800-66 Rev. 1, “An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule,” October 2008
18. Sections 504 and 508 of the Rehabilitation Act (29 U.S.C. § 794d), as amended, January 18, 2017
19. Homeland Security Presidential Directive (12) (HSPD-12), August 27, 2004
20. VA Directive 6500, “VA Cybersecurity Program,” February 24, 2021
VA Handbook 6500, “Risk Management Framework for VA Information Systems VA Information Security Program,” February 24, 2021
21. VA Handbook 6500.2, “Management of Breaches Involving Sensitive Personal Information (SPI),” March 12, 2019
22. VA Handbook 6500.5, “Incorporating Security and Privacy into the System Development Lifecycle,” March 22, 2010
23. VA Handbook 6500.6, “Contract Security,” March 12, 2010
24. VA Handbook 6500.8, “Information System Contingency Planning,” April 6,
25. VA Handbook 6500.10, “Mobile Device Security Policy,” February 15, 2018
26. VA Handbook 6500.11, “VA Firewall Configuration,” August 22, 2017
27. OIT Process Asset Library (PAL), https://www.va.gov/process/ . Reference
Process Maps at https://www.va.gov/process/maps.asp and Artifact templates at https://www.va.gov/process/artifacts.asp
28. One-VA Technical Reference Model (TRM) (reference at https://www.va.gov/trm/TRMHomePage.aspx)
29. VA Directive 6508, “Implementation of Privacy Threshold Analysis and Privacy Impact Assessment,” October 15, 2014
30. VA Handbook 6508.1, “Procedures for Privacy Threshold Analysis and Privacy Impact Assessment,” July 30, 2015
31. VA Handbook 6510, “VA Identity and Access Management,” January 15,
32. VA Directive and Handbook 6513, “Secure External Connections,” October 12, 2017
33. VA Directive 6300, “Records and Information Management,” September 21,
34. VA Handbook, 6300.1, “Records Management Procedures,“ March 24, 2010
35. NIST SP 800-37 Rev 2, “Risk Management Framework for Information
Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” December 2018
36. NIST SP 800-53 Rev. 5, “Security and Privacy Controls for Federal Information Systems and Organizations,” September 23, 2020 (includes updates as of 12/10/2020)
37. VA Directive 0735, “Homeland Security Presidential Directive 12 (HSPD-12) Program,” October 26, 2015
38. VA Handbook 0735, “Homeland Security Presidential Directive 12 (HSPD-
12) Program,” March 24, 2014
39. OMB Memorandum 05-24, “Implementation of Homeland Security Presidential Directive (HSPD) 12 – Policy for a Common Identification Standard for Federal Employees and Contractors,” August 5, 2005
40. OMB Memorandum M-19-17, “Enabling Mission Delivery Through Improved Identity, Credential, and Access Management,” May 21, 2019
41. OMB Memorandum, “Guidance for Homeland Security Presidential Directive (HSPD) 12 Implementation,” May 23, 2008
42. Federal Identity, Credential, and Access Management (FICAM) Roadmap and Implementation Guidance, December 2, 2011, (NOTE: Part A of the FICAM Roadmap and Implementation Guidance, v2.0, was replaced in 2015 with an updated Architecture (https://arch.idmanagement.gov/#what-is-the-ficam-architecture)
43. NIST SP 800-116 Rev 1, “Guidelines for the Use of Personal Identity Verification (PIV) Credentials in Facility Access,“ June 2018
44. NIST SP 800-63-3, 800-63A, 800-63B, 800-63C, “Digital Identity Guidelines,” updated March 02, 2020
45. NIST SP 800-157, “Guidelines for Derived PIV Credentials,” December 2014
46. NIST SP 800-164, “Guidelines on Hardware-Rooted Security in Mobile
Devices (Draft),” October 2012
47. Draft National Institute of Standards and Technology Interagency Report
(NISTIR) 7981, “Mobile, PIV, and Authentication,” March 2014
48. VA Memorandum, VAIQ #7100147, “Continued Implementation of Homeland
Security Presidential Directive 12 (HSPD-12),” April 29, 2011 (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
49. IAM Identity Management Business Requirements Guidance document, May 2013, (reference Enterprise Architecture Section, PIV/IAM (reference https://www.voa.va.gov/documentlistpublic.aspx?NodeID=514)
50. VA Memorandum “Personal Identity Verification (PIV) Logical Access Policy Clarification,” July 17, 2019, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896
51. Trusted Internet Connections (TIC) 3.0 Core Guidance Documents, https://www.cisa.gov/publication/tic-30-core-guidance-documents
52. OMB Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative,” September 12, 2019
53. OMB Memorandum M-08-23, “Securing the Federal Government’s Domain Name System Infrastructure,” August 22, 2008
54. Sections 524 and 525 of the Energy Independence and Security Act of 2007, (Public Law 110–140), December 19, 2007
55. Section 104 of the Energy Policy Act of 2005, (Public Law 109–58), August 8, 2005
56. Executive Order 13834, “Efficient Federal Operations,” dated May 17, 2018
57. Executive Order 13221, “Energy-Efficient Standby Power Devices,” August
2, 2001
58. VA Directive 0058, “VA Green Purchasing Program,” July 19, 2013
59. VA Handbook 0058, “VA Green Purchasing Program,” July 19, 2013
60. Office of Information Security (OIS) VAIQ #7424808 Memorandum, “Remote
Access,” January 15, 2014, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
61. Clinger-Cohen Act of 1996, 40 U.S.C. §11101 and §11103
62. “Veteran Focused Integration Process (VIP) Guide 4.0,” January 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371
63. VA Memorandum “Proper Use of Email and Other Messaging Services,” January 2, 2018, https://www.voa.va.gov/DocumentListPublic.aspx?NodeId=28
64. “DevSecOps Product Line Management Playbook” version 2.0, May 2021, https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946
65. NIST SP 500-267B Revision 1, “USGv6 Profile,” November 2020
66. OMB Memorandum M-21-07, “Completing the Transition to Internet Protocol
Version 6 (IPv6),” November 19, 2020
67. Social Security Number (SSN) Fraud Prevention Act of 2017
68. Section 240 of the Consolidated Appropriations Act (CAA) 2018, March 23,
3.0 SCOPE OF WORK
The Contractor shall provide a systematic delivery of best practices in the use, maintenance, and on-going design support of the Vocera communication system. The contractor shall provide: Vocera Data and Device Management, Vocera Software Management, Vocera Deployment Optimization, Vocera Training and Orientation Management, Vocera Report Management, Vocera Engage Administration, Vocera Engage Monitoring, Vocera Engage Deployment Optimization, Vocera Engage Training and Orientation Management, Vocera Engage Issue Escalation Management and Vocera End User Satisfaction. All necessary software updates and patches are required to maintain the equipment to the Original Equipment Manufacturer (OEM) normal operating specifications. Included in the scope of work is unlimited technical and clinical telephone support from an OEM-trained specialist.
4.0 PERFORMANCE DETAILS
4.1 PERFORMANCE PERIOD
The Period of Performance shall be one 12-month base period from August 1, 2024 to July 31, 2025 with four 12-month options.The overall PoP shall not exceed 60 months.
Any work at the Government site shall not take place on Federal holidays or weekends unless directed by the Contracting Officer (CO).
There are 11 Federal holidays set by law (USC Title 5 Section 6103) that VA follows:
Under current definitions, five are set by date:
New Year's Day January 1 Juneteenth June 19 Independence Day July 4 Veterans Day November 11 Christmas Day December 25
If any of the above falls on a Saturday, then Friday shall be observed as a holiday.
Similarly, if one falls on a Sunday, then Monday shall be observed as a holiday.
The other six are set by a day of the week and month:
Martin Luther King's Birthday Third Monday in January Washington's Birthday Third Monday in February Memorial Day Last Monday in May Labor Day First Monday in September Columbus Day Second Monday in October Thanksgiving Fourth Thursday in November
4.2 PLACE OF PERFORMANCE
Tasks under this PWS shall be performed in VA facilities located in Fayetteville, NC VA Coastal Healthcare System, including the Coastal clinics. Work may be performed at remote locations with prior concurrence from the Contracting Officer’s Representative
(COR).
4.3 TRAVEL
The Government anticipates travel under this effort to perform the tasks associated with the effort, as well as to attend program-related meetings or conferences throughout the PoP. Include all estimated travel costs in your firm-fixed price line items. These costs will not be directly reimbursed by the Government.
The total estimated number of trips in support of the program related meetings for this effort is three per quarter. Anticipated locations include the following, estimated at one business day in duration:
Brunswick County VA Clinic 18 Doctors Circle, Suite 2 Supply, NC 28462-4089
Cumberland County VA Clinic 7300 South Raeford Road Fayetteville, NC 28304-6162
Goldsboro VA Clinic 2610 Hospital Road Goldsboro, NC 27534-9423
Hamlet VA Clinic 100 Jefferson Street Hamlet, NC 28345-3100
Jacksonville 2 VA Clinic 306 Brynn Marr Road Jacksonville, NC 28546-7023
Jacksonville 3 VA Clinic 4 Josh Court
Jacksonville, NC 28546-5253
Jacksonville VA Clinic 4006 Henderson Drive Jacksonville, NC 28546-0055
Lee County VA Clinic 3112 Tramway Road Sanford, NC 27330-7142
Robeson County VA Clinic 139 Three Hunts Drive Pembroke, NC 28372-6800
Wilmington VA Clinic 1705 Gardner Road Wilmington, NC 28405-8873
5.0 SPECIFIC TASKS AND DELIVERABLES
Contractor shall provide the following:
Vocera Data and Device Management
Establish, update, and maintain processes for submitting data and device changes to Vocera database.
Add/delete/update users, groups and address book entries as requested by using departments.
Export user, group and address book information for review by using departments for accuracy and currency (every six months).
Maintain device management data. Develop, update and maintain processes for changes in badge ownership, ordering new equipment, troubleshooting equipment, repairing equipment, requesting and processing Return Merchandise Authorizations (RMA), reporting damage and budget trends, maintaining spares pool, coaching on replacement budget planning, training users and leadership on device management best practices, scheduling reports, and aiding with finding lost equipment.
Vocera Software Management
Apply Vocera service packs and hot fixes.
Conduct system health analysis (every six months).
Vocera Deployment Optimization
Refine deployment call flows to improve usability of the Vocera system.
Provide Vocera workflow optimization assistance for existing Vocera deployed nursing units / departments. Assistance needed for configuration changes involving units / departments not already designed and implemented when the Vocera Systems Administrator Service begins.
Conduct rounds on each unit to coach staff, learn workflow, uncover issues, resolve issues and develop relationships.
Vocera Training and Orientation Management
Develop, update, and deliver training for new employee orientation for Vocera users.
Establish process for on-boarding of new Vocera users.
Establish process for reviewing Vocera reports to identify and coach users experiencing less than optimal performance.
Maintain training materials and make easily available to staff for self-review and refresher.
Maintain at least a 10% Super User population across all units and shifts;
providing training to keep the Super User population competent and constant.
Provide upgrade training for changes in functionality affecting end users.
Vocera Issue Escalation Management
Develop, update and maintain process for end users to report Vocera issues.
Address and resolve issues regarding Vocera equipment, database, and users.
Escalate issues regarding network or servers to the appropriate Customer contact.
Escalate issues with the Vocera product to Vocera Technical Support.
Track and trend Vocera issues to institute process improvements where possible to reduce issue escalations.
Follow up with issue reporter to provide update status and resolution.
Vocera Report Management
Set up scheduled reports as requested by end user unit leaders.
Provide consultation to units regarding the reports available.
Review reports and provide consultation to end user units, network staff and other key support staff and stakeholders regarding actions needed to optimize Vocera system and user performance. (Monthly)
Vocera Engage Administration
The Vocera Systems Administrator shall provide the following services:
Vocera Engage Monitoring
Monitor the Engage for any issues.
Escalate identified issues, as appropriate, to Vocera Technical Support.
Vocera Engage Deployment Optimization
Provide guidance to Customer as relates to the Engage workflow improvement.
o Integration workflow optimization assistance for existing integrations into existing nursing units / departments.
Provide support for engaging Vocera Professional Services for Customer requested configuration changes.
Vocera Engage Training and Orientation Management
Develop and deliver training for new employee orientation for Vocera
Staff Assignment and Alarm-to-Device users.
o Super User class size not to exceed 12 staff members;
o Basic End User class size not to exceed eight staff members.
Provide upgrade training for changes in functionality affecting end uses.
Vocera Engage Issue Escalation Management
Develop process for end users to report Vocera Engage issues and concerns.
Manage escalated Vocera Engage issues with Vocera Technical Support.
Track and trend Vocera issues to institute process improvements where possible to reduce issues escalations.
Follow up with issue reporter to provide update status and resolution.
Vocera End User Satisfaction
Develop Vocera User Satisfaction Survey.
Survey using departments once a year to collect formal feedback and quantifiable measures of satisfaction.
Facilitate user group meetings to discuss Vocera issues, lessons learned and process improvements. (Monthly)
Deliverable:
Yearly Vocera User Satisfaction Survey
Vocera administrator will not be responsible for troubleshooting or maintaining hardware infrastructure, including servers, server operating systems, server security certification processes work, network, integration of Vocera to any third party components, configuration and/or adjustment to network controllers/settings, and the private branch exchange (PBX). Vocera administrator will be responsible for being the liaison between the end users and biomed/Office of Information & Technology (OI&T) to provide information needed for troubleshooting purposes and submitting Vocera technical support tickets.
The contractor shall provide technical and professional onsite or remote service support to successfully deploy hardware/software upgrade of Vocera platform across the Fayetteville VA enterprise. In addition, the contractor shall provide any hardware components needed for full upgrade of the Vocera platform/system at all Fayetteville VA sites.
Should future expansion to new medical center sites be required, direction will be provided by the Contracting Officer via modification to the contract.
6.0 GENERAL REQUIREMENTS
6.1 ENTERPRISE AND IT FRAMEWORK
6.1.1 VA TECHNICAL REFERENCE MODEL
The Contractor shall support the VA enterprise management framework. In association with the framework, the Contractor shall comply with OIT Technical Reference Model (VA TRM). The VA TRM is one component within the overall Enterprise Architecture (EA) that establishes a common vocabulary and structure for describing the information technology used to develop, operate, and maintain enterprise applications. Moreover, the VA TRM, which includes the Standards Profile and Product List, serves as a technology roadmap and tool for supporting OIT. Architecture & Engineering Services (AES) has overall responsibility for the VA TRM.
6.1.2 FEDERAL IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT (FICAM)
The Contractor shall ensure Commercial Off-The-Shelf (COTS) product(s), software configuration and customization, and/or new software are Personal Identity Verification (PIV) card-enabled by accepting HSPD-12 PIV credentials using VA Enterprise Technical Architecture (ETA), https://www.ea.oit.va.gov/EAOIT/VA_EA/Enterprise_Technical_Architecture.asp, and VA Identity and Access Management (IAM) approved enterprise design and integration patterns, https://www.oit.va.gov/library/recurring/edp/index.cfm. The Contractor shall ensure all Contractor delivered applications and systems comply with the VA Identity, Credential, and Access Management policies and guidelines set forth in VA Handbook 6510 VA Identity and Access Management, VA Handbook 0735 Homeland Security Presidential Directive 12 (HSPD-12) Program, and align with the Federal Identity, Credential, and Access Management Roadmap and Implementation Guidance v2.0.
The Contractor shall ensure all Contractor delivered applications and systems provide user authentication services compliant with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-63-3, VA Handbook 6500 Appendix F, “VA System Security Controls”, and VA IAM enterprise requirements for direct, assertion based authentication, and/or trust based authentication, as determined by the design and integration patterns. Direct authentication at a minimum must include Public Key Infrastructure (PKI) based authentication supportive of PIV card and/or Common Access Card (CAC), as determined by the business need.
The Contractor shall ensure all Contractor delivered applications and systems conform to the specific Identity and Access Management PIV requirements set forth in the Office of Management and Budget (OMB) Memoranda M-05-24, M-19-17, and NIST Federal Information Processing Standard (FIPS) 201-2. OMB Memoranda M-05-24 and M-19- 17 can be found at:
https://www.whitehouse.gov/sites/whitehouse.gov/files/omb/memoranda/2005/m05- 24.pdf, and https://www.whitehouse.gov/wp-content/uploads/2019/05/M-19-17.pdf respectively. Contractor delivered applications and systems shall be on the FIPS 201-2 Approved Product List (APL). If the Contractor delivered application and system is not on the APL, the Contractor shall be responsible for taking the application and system through the FIPS 201 Evaluation Program.
The Contractor shall ensure all Contractor delivered applications and systems support:
1. Automated provisioning and are able to use enterprise provisioning service.
2. Interfacing with VA’s Master Person Index (MPI) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
3. The VA defined unique identity (Secure Identifier [SEC ID] / Integrated Control Number [ICN]).
4. Multiple authenticators for a given identity and authenticators at every Authenticator Assurance Level (AAL) appropriate for the solution.
5. Identity proofing for each Identity Assurance Level (IAL) appropriate for the solution.
6. Federation for each Federation Assurance Level (FAL) appropriate for the solution, if applicable.
7. Two-factor authentication (2FA) through an applicable design pattern as outlined in VA Enterprise Design Patterns.
8. A Security Assertion Markup Language (SAML) implementation if the solution relies on assertion-based authentication. Additional assertion implementations, besides the required SAML assertion, may be provided as long as they are compliant with NIST SP 800-63-3 guidelines.
9. Authentication/account binding based on trusted Hypertext Transfer Protocol (HTTP) headers if the solution relies on Trust based authentication.
10. Role Based Access Control.
11. Auditing and reporting capabilities.
12. Compliance with VIEWS 00155984, PIV Logical Access Policy Clarification https://www.voa.va.gov/DocumentView.aspx?DocumentID=4896.
The required Assurance Levels for this specific effort are Identity Assurance Level 3, Authenticator Assurance Level 3, and Federation Assurance Level 3.
6.1.3 INTERNET PROTOCOL VERSION 6 (IPV6)
The Contractor solution shall support Internet Protocol Version 6 (IPv6) based upon the memo issued by the Office of Management and Budget (OMB) on November 19, 2020 (https://www.whitehouse.gov/wp-content/uploads/2020/11/M-21-07.pdf). IPv6 technology, in accordance with the USGv6 Program (https://www.nist.gov/programs-projects/usgv6-program/usgv6-revision-1), NIST Special Publication (SP) 500-267B Revision 1 “USGv6 Profile” (https://doi.org/10.6028/NIST.SP.500-267Br1), and NIST SP 800-119 “Guidelines for the Secure Deployment of IPv6” (https://doi.org/10.6028/NIST.SP.800-119), compliance shall be included in all IT infrastructures, application designs, application development, operational systems and sub-systems, and their integration. In addition to the above requirements, all devices shall support native IPv6 and dual stack (IPv6 / IPv4) connectivity without additional memory or other resources being provided by the Government, so that they can function in a mixed environment. All public/external facing servers and services (e.g.
web, email, DNS, ISP services, etc.) shall support native IPv6 and dual stack (IPv6 / IPv4) users and all internal infrastructure and applications shall communicate using native IPv6 and dual stack (IPv6 / IPv4) operations.
6.1.4 TRUSTED INTERNET CONNECTION (TIC)
The Contractor solution shall meet the requirements outlined in Office of Management and Budget Memorandum M-19-26, “Update to the Trusted Internet Connections (TIC) Initiative“ (https://www.whitehouse.gov/wp-content/uploads/2019/09/M-19-26.pdf), VA Directive 6513 “Secure External Connections”, and shall comply with the TIC 3.0 Core Guidance Documents, including all Volumes and TIC Use Cases, found at the Cybersecurity & Infrastructure Security Agency (CISA) (https://www.cisa.gov/publication/tic-30-core-guidance-documents). Any deviations must be approved by the VA TIC 3.0 Working Group at vaoisesatic30team@va.gov.
6.1.5 STANDARD COMPUTER CONFIGURATION
The Contractor IT end user solution that is developed for use on standard VA computers shall be compatible with and be supported on the standard VA operating system, currently Windows 10 (64bit), Edge (Chromium based), and 365 Apps for enterprise. Applications delivered to VA and intended to be deployed to Windows 10 workstations shall be delivered as a signed .msi package with switches for silent and unattended installation and updates shall be delivered in signed .msp file formats for easy deployment using Microsoft Endpoint Configuration Manager (CM) VA’s current desktop application deployment tool. Signing of the software code shall be through a vendor provided certificate that is trusted by VA using a code signing authority such as Verizon/Cybertrust or Symantec/VeriSign. The Contractor shall also ensure and certify that their solution functions as expected when used from a standard VA computer, with non-admin, standard user rights that have been configured using the United States Government Configuration Baseline (USGCB) and Defense Information Systems Agency (DISA) Secure Technical Implementation Guide (STIG) specific to the particular client operating system being used.
6.1.6 VETERAN FOCUSED INTEGRATION PROCESS (VIP) AND PRODUCT LINE
MANAGEMENT (PLM)
The Contractor shall support VA efforts IAW the updated Veteran Focused Integration Process (VIP) and Product Line Management (PLM). The major focus of the new VIP is on Governance and Reporting and is less prescriptive, with a focus on outcomes and continuous delivery of value. Product Line Management (PLM) is a framework that focuses on delivering functional products that provide the highest priority work to customers while delivering simplified, reliable, and practical solutions to the business, medical staff, and our Veterans. The VIP Guide is a companion guide to the PLM Playbook and can be found at:
https://www.voa.va.gov/DocumentView.aspx?DocumentID=4371 and the PLM Playbook can be found at https://www.voa.va.gov/DocumentView.aspx?DocumentID=4946. The PLM Playbook pivots from project-centric to product-centric delivery and contains descriptive practices that focuses on outcomes. The PLM Playbook contains a set of “plays” that implement Development, Security, and Operations (DevSecOps) principles and processes such as automated development, continuous integration/continuous delivery, and release on demand. The PLM Playbook details how product lines implement Lean-Agile principles, methods, practices, and techniques through levels of maturity. VIP and PLM are the authoritative processes that IT projects must follow to ensure development and delivery of IT products.
6.1.7 PROCESS ASSET LIBRARY (PAL)
The Contractor shall perform their duties consistent with the processes defined in the OIT Process Asset Library (PAL). The PAL scope includes the full spectrum of OIT functions and activities, such as VIP project management, operations, service delivery, communications, acquisition, and resource management. PAL serves as an authoritative and informative repository of searchable processes, activities or tasks, roles, artifacts, tools and applicable standards and guides to assist the OIT workforce, Government and Contractor personnel. The Contractor shall follow the PAL processes to ensure compliance with policies and regulations and to meet VA quality standards. The PAL includes the contractor onboarding process consistent with Section
6.2.2 and can be found at https://www.va.gov/PROCESS/artifacts/maps/process_CONB_ext.pdf. The main PAL can be accessed at www.va.gov/process.
6.1.8 AUTHORITATIVE DATA SOURCES
The VA Enterprise Architecture Repository (VEAR) is one component within the overall EA that establishes the common framework for data taxonomy for describing the data architecture used to develop, operate, and maintain enterprise applications. The Contractor shall comply with the department’s Authoritative Data Source (ADS) requirement that VA systems, services, and processes throughout the enterprise shall access VA data solely through official VA ADSs where applicable, see below. The
Information Classes which compose each ADS are located in the VEAR, in the Data & Information domain. The Contractor shall ensure that all delivered applications and system solutions support:
1. Interfacing with VA’s Master Person Index (MPI) (formerly the Master Veteran Index (MVI)) to provision identity attributes, if the solution relies on VA user identities. MPI is the authoritative source for VA user identity data.
2. Interfacing with Capital Asset Inventory (CAI) to conduct real property record management actions, if the solution relies on real property records data. CAI is the authoritative source for VA real property record management data.
3. Interfacing with electronic Contract Management System (eCMS) for access to contract, contract line item, purchase requisition, offering vendor and vendor, and solicitation information above the micro-purchase threshold, if the solution relies on procurement data. ECMS is the authoritative source for VA procurement actions data.
4. Interfacing with HRSmart Human Resources Information System to conduct personnel action processing, on-boarding, benefits management, and compensation management, if the solution relies on personnel data. HRSmart is the authoritative source for VA personnel information data.
5. Interfacing with Vet360 to access personal contact information, if the solution relies on VA Veteran personal contact information data. Vet360 is the authoritative source for VA Veteran Personal Contact Data.
6. Interfacing with VA/Department of Defense (DoD) Identity Repository (VADIR) for determining eligibility for VA benefits under Title 38, if the solution relies on qualifying active duty military service data. VADIR is the authoritative source for Qualifying Active Duty military service in VA.
6.1.9 SOCIAL SECURITY NUMBER (SSN) REDUCTION
The Contractor solution shall support the Social Security Number (SSN) Fraud Prevention Act (FPA) of 2017 which prohibits the inclusion of SSNs on any document sent by mail. The Contractor support shall also be performed in accordance with Section 240 of the Consolidated Appropriations Act (CAA) 2018, enacted March 23, 2018, which mandates VA to discontinue using SSNs to identify individuals in all VA information systems as the Primary Identifier. The Contractor shall ensure that any new IT solution discontinues the use of SSN as the Primary Identifier to replace the SSN with the ICN in all VA information systems for all individuals. The Contractor shall ensure that all Contractor delivered applications and systems integrate with the VA Master Person Index (MPI) for identity traits to include the use of the ICN as the Primary Identifier. The Contractor solution may only use a Social Security Number to identify an individual in an information system if and only if the use of such number is required to obtain information VA requires from an information system that is not under the jurisdiction of VA.
6.1.10 SOFTWARE AND LICENSING REQUIREMENTS
The Contractor shall be responsible for the provision of all software licenses and any associated licensing maintenance required for any development, delivery, integration, operation, and/or maintenance associated with its proposed application(s), software products, software solution, and/or system including, but not limited to, any and all application(s), software and/or software products that comprise, are a part of, or integrate with the Contractor’s proposed application(s), software products, software solution, and/or system for the life of any resulting contract.
6.2 SECURITY AND PRIVACY REQUIREMENTS
It has been determined that protected health information may be disclosed or accessed, and a signed Business Associate Agreement (BAA) shall be required. The Contractor shall adhere to the requirements set forth within the BAA, referenced in Section D of the contract, and shall comply with VA Directive 6066.
6.2.1 POSITION/TASK RISK DESIGNATION LEVEL(S)
In accordance with VA Handbook 0710, Personnel Security and Suitability Program, the position sensitivity and the level of background investigation commensurate with the required level of access for the following tasks within the PWS are:
Position Sensitivity and Background Investigation Requirements by Task
Task Number Tier1 / Low Risk Tier 2 / Moderate
Risk Tier 4 / High Risk
5.0
The Tasks identified above and the resulting Position Sensitivity and Background Investigation requirements identify, in effect, the Background Investigation requirements for Contractor individuals, based upon the tasks the particular Contractor individual will…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .