Attachment_6_-_Task_Order_6_Statement_of_Work.docx

DOCX document 41 KB Posted

Attached to
Support for Information Technology and Database Applications for NIST Federal contract opportunity
Solicitation number
SB1341-15-RP-0018
Issued by
Department of Commerce National Institute of Standards and Technology

About this file

Attachment 6 Statement of Work for Task Order 6

View the file

Other files for this federal contract opportunity

Other files attached to Support for Information Technology and Database Applications for NIST, newest first.
File Type Posted
Amendment_0001.docx DOCX document
SB1341-15-RP-0018.pdf PDF
Attachment_2_-Task_Order_2_-_Modeling_Voting_and_Medical_Devices_SOW.doc DOC document
Attachment_3_-_Task_Order_3_-_HL7_Validation_Engine_SOW.doc DOC document
Attachment_1-Task_Order_1_-_Lab_Test_Suite_SOW.doc DOC document
Attachment_5_-_Task_Order_5_SOW_SRD31Software.docx DOCX document
Attachment_4_-_Task_Order_4_-_IIS_SME_SOW.doc DOC document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

Task Order 6

TITLE: Continued Development of the System for Project Management LAB REQUESTING SERVICE: Center for Nanoscale Science and Technology (CNST)

I. BACKGROUND INFORMATION

The System for Project Management (SPM) supports the eNIST objective to eliminate paper and to automate manual, labor intensive administrative activities. The project employs cutting-edge web-based technologies in support of NIST. The application was not available as commercial package and therefore needed to be developed in-house. This application automates tasks and decreases the administrative requirements of the technical and support staff, while increasing responsiveness to customers and implementing a secure eNIST paperless environment. As a result, NIST scientists are able to spend more time working in their labs than working at their computers to fulfill administrative requirements. SPM was created to store and track all of NIST’s publications, travel, and project status reports provided to management. Management is able to obtain access to the information it needs easily, and the administrative burden on the technical staff has been decreased. Generation of required paperwork has been automated, removing that responsibility from the NIST support staff. The application also serves as a data warehouse for publications and reports, providing backups of all data stored. Access to the data is provided by user roles; i.e., director/deputy director, group leader, project leader, and staff. Over the years the SPM has been modified to flexibly store and track data associated with a variety of NIST projects independent of the Operating Unit (OU). This task order supports additional enhancements to the web-based application, including program integrity and longevity, improved report formats, and enhancements in data input and data management.

II. SCOPE OF WORK

General Requirements

Type of Work
Percentage
Design, modeling, and technical specification of the IT system components, standards, or software tools
30
Validation of designs, models, and technical specifications against the functional requirements and user needs
10
Application development, testing, integration and maintenance
60

NIST IT Architecture constraints:

· The existing project and publication databases will be retained – modifications to existing schemas will be permitted but NIST approval of all modifications is required before inclusion in technical design

· Java (J2EE) technology using Apache Tomcat Engine and Spring Framework is required for server-side logic processing, database interactions, workflow processing, web-service implementation and report generation

· Client-side development shall favor HTML5 over other available technologies

· Adobe PDF technology is permitted for generation and presentation of standard government forms and report generation

· JavaScript technology is permitted for client-side data validation and user interface automation Validation of the IT system design shall include the review of system design documents as well as the review of system functionality and user interfaces with respective user groups. Validation of data exchange standards (and associated software tools) will include the review of any design documents (models, use case scenarios, et cetera) and testing guidelines.

III. SPECIFIC REQUIREMENTS

The Contractor shall develop and maintain a Project Plan.

The Contractor shall participate in bi-weekly progress review meetings with the Center for Nanoscale Science and Technology (CNST) application users and CNST Technical Point of Contact. The meeting will include the status of on-going tasks. It will also be the forum to discuss outstanding or anticipated issues or problems. Any discrepancies of non-performance will be discussed at each meeting and the Contractor shall provide proposed corrective action measures.

The Contractor shall adhere to the Project Plan developed by the Contractor and revised or updated by the team (the Contractor, Government, and other participants as designated on the Plan). The Plan shall include such things as deliverables, milestones, outputs, staffing, and status reporting. The Contractor and CNST Technical Point of Contact will review soft copy of the updated status of the Project Plan at the scheduled bi-weekly meeting. The Contractor shall update the Project Plan when there are changes or as required by the CNST Technical Point of Contact or the COTR.

The Contractor shall provide the status of actual Contractor performance in relation to the anticipated performance and completion as specified in the Project Plan. Any and all differences between the Contractor’s proposed performance schedule, actual performance and completion dates shall be fully explained and documented in the report. The Contractor must also include documented accomplishments and any potential or identified risk items.

The Contractor shall be responsible for overall project management, including the development and monitoring/updating and submission of the Project Plan; task work plans, detailing specific deliverables, monitoring quality of deliverables, final reports, source code, and documentation.

The overall management plan shall address:

· The flexibility needed to allow for multiple tasking of projects

· Tracking of contract staff and hours within and across individual tasks

· Maintaining running totals of staff and dollar expenditures by task (by hours) and overall project

· Appropriately staffing the project with team members who have extensive knowledge of the existing system and the business processes involved and the new technologies that will be required for this project, and

· Oversight by a Project Manager who will also participate in the technical and planning activities of the project on a regular basis The Contractor shall save source code developed under this task using Subversion version control system located at https://subversion.nist.gov. The source code shall include all project files: configuration files used by Integration Development Environments (IDEs), and files used for the compilation and testing of the software products. Checking code into Subversion and deploying the new code to the production SPM server constitutes “delivery”.

The Contractor must adhere to NIST and DoC IT Security Policies while performing all Requirements of this Statement of Work (SOW). The Contractor shall develop security C&A documentation specific for the application, as required by NIST Special Publication 800-37. Additionally, any software developed must meet minimum mandatory controls as specified for Moderate Impact (Confidentiality and Integrity) systems as specified in NIST Special Publication 800-53, DoC IT Security Program Policy and Minimum Implementation Standards (2005), and NIST policy. The contractor should pay particular attention to SA-8 Security Design Principles. Control: The organization designs and implements the information system using security engineering principles. NIST Special Publication 800-27 provides guidance on engineering principles for information system security. The contractor shall maintain a frequent dialog with the CNST IT Security Officer concerning the appropriate level of security.

Task 1: Migrate production server The Contractor shall migrate the webserver from the existing CNST server to the Office of Information System Management (OISM) Virtual Machine (VM) infrastructure. The Contractor will need to work with OISM’s VM Systems Administrators to accomplish this migration.

The Contractor shall deliver:

· A fully configured and functional development and production web server, which can be demonstrated by accessing and using the website

· Documentation on:

· All setup actions taken to install and configure the web server

· Critical maintenance operations (such as starting and stopping the server)

· Important file locations for code and configuration

· Any timed procedures that run on a regular basis (e.g. cron jobs)

· A system diagram of all important connected systems Task 2: Improve SPM memory usage The Contractor shall eliminate all existing memory leaks from SPM. Automated analytical tools shall be put in place on the development and production systems to easily identify and resolve future memory leaks that may appear.

Memory usage of “Reports” in SPM shall be evaluated with a focus on reducing total memory usage. Since there are many possible solutions, the Contractor shall provide an outline of all feasible solutions and confer with CNST stakeholders to implement the desired solution.

The Contractor shall deliver:

· A report to the CNST Technical Point of Contact proving that no memory leaks exist in SPM, due 7 days after each production environment deployment

· Under the assumption that the server is continually operational for the analyzed duration

· Clearing memory leaks by server restart shall not meet the requirement

· Demonstration that memory usage of normal operation of SPM does not exceed “normal” memory usage of 4 gigabytes of random access memory (RAM)

· Documentation on the method to identify future memory leaks using the tools put in place by the Contractor Task 3: Continuous monitoring and downtime recovery SPM is a critical infrastructure system and uptime is paramount. The Contractor shall implement continuous monitoring mechanisms to inform the CNST Technical Point of Contact when a runtime issue arises. A recommended approach is to use Sentry, or possibly Splunk. Possibilities shall be researched by the Contractor, presented to CNST stakeholders, and implemented if agreed upon by CNST and the Contractor.

The Contractor shall deliver a demonstration of the continuous monitoring abilities of the implemented software.

Task 4: Form updates The Contractor shall update the following forms:

· The “New Staff” form to reflect the appropriate date that a person established a relationship with NIST

· The report for project leaders to include a project timeframe and number of research participants active in a single fiscal year with no double counting

· SPM project plan template (not to be confused with the Project Plan for this Statement of Work) to include data management details for research projects

· Remove the title page from the project report

· Other updates as needed by CNST stakeholders The Contractor shall deliver the following:

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 5: New CNST staff functions The Contractor shall add new staff functions as directed by the CNST Center Office and CNST User Office.

The Contractor shall deliver the following:

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 6: Add OU staff related data fields to research participant data The Contractor shall add data fields to the Research Participant for OU staff (both employees and associates), including the start and end dates, LDAP look-up for office location, and lab occupancy information; and create reports that provide a quick overview of the staffing data, including the number of employees and associates.

The Contractor shall deliver the following:

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 7: Configurable query system The Contractor shall collect requirements from CNST stakeholders to build a configurable query system in order to eliminate the need for new canned reports for every task.

The Contractor shall deliver the following:

· Documentation on the requirements that are collected in order to implement the feature

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 8: Electronic application submission The contractor shall implement an electronic form to collect project information from principal investigators.

The Contractor shall deliver the following:

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 9: Modify routing process The contractor shall work with CNST stakeholders to increase system flexibility in controlling the routing process (with appropriate data modification safety constrains) to increase routing efficiency.

The Contractor shall deliver the following:

· Documentation of the full routing process

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 10: Automate routing of project applications The Contractor shall develop process flows and implement the ability for new and renewal project applications to be routed through the CNST User Office using only the SPM in a paper-free process. The process shall include the ability to track and maintain records of safety training. It shall also include the ability to generate reminders when projects will soon expire and must be renewed, and when associated training must be repeated.

The Contractor shall deliver the following:

· Documentation of developed process flows

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 11: Add NanoFab testimonial form to reporting options The Contractor shall implement an electronic form to collect testimonials from businesses associated with CNST that do not generate published outputs.

The Contractor shall deliver the following:

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 12: Project routing cycle time reports The contractor shall collect requirements and implement a feature to track how long it takes for each step in the project routing and application process. To goal is to monitor the efficiency of application processing.

The Contractor shall deliver the following:

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 13: Project scoring by review committees The contractor shall create an electronic form to collect project scoring by project review committees. The contractor shall also collect requirements and implement analysis tools for the collected project scores.

The Contractor shall deliver the following:

· Documentation of techniques for project score analysis

· Source code for the modifications

· Demonstration of updates to CNST stakeholders

· Output of unit tests, integration tests, and system tests for affected source code Task 14: Kerberos authentication The contractor shall configure Single-Sign-On (SSO) for SPM to integrate with the NIST General Realm (Active Directory domain server). Once implemented, SPM users should not have to enter their user name or password to access SPM. Instead, the SPM will verify the user’s identity using their existing Kerberos credentials.

The Contractor shall deliver the following:

· A document that describes all programs, configuration, and commands involved in setting up the authentication environment

· Demonstration of updates to CNST Technical Point of Contact Task 15: Automated testing The Contractor shall write unit tests, integration tests, and system tests when appropriate for all new code. The Contractor shall write tests for existing sections of code when a bug is discovered or when directed by the CNST Technical Point of Contact. The granularity, complexity, and quantity of appropriate tests shall be specified by the CNST Technical Point of Contact. All tests shall be run just prior to new code deployment to the production system in order to increase source code assuredness and quality.

The Contractor shall deliver a demonstration to the CNST Technical Point of Contact of how to run the tests.

IV. DELIVERABLES

CNST intends to follow the principals of agile software development for this Task Order. For this reason, all deliverable due dates are outlined by the aforementioned Project Plan and updated every two weeks.

In software development, document deliverables can come in many forms. Often, limiting the format to a single type (such as a Microsoft Word document) is too restrictive. The Contractor is encouraged to propose the format of appropriate documentation for deliverables that best suits the technology used. The documentation format must be approved by the CNST Technical Point of Contact.

All software demonstrations shall be electronically summarized and archived. Reviews and corrections to program features and configuration shall also be provided electronically and archived.

The following table outlines deliverables from all preceding tasks.

Task number(s)
Deliverable
Deliverable type
Frequency
1
A fully configured and functional development and production web server
Demonstration
Once
1
All setup actions taken to install and configure the web server
Document
Once
1
Critical maintenance operations (such as starting and stopping the server)
Document
Once
1
Important file locations for code and configuration
Document
Once
1
Any timed procedures that run on a regular basis (e.g. cron jobs)
Document
Once
1
A system diagram of all important connected systems
Document
Once
2
A report to the CNST Technical Point of Contact proving that no memory leaks exist in SPM
Document
7 days after each production environment deployment
2
Memory usage of normal operation of SPM does not exceed “normal” memory usage
Demonstration
7 days after each production environment deployment
2
Method to identify future memory leaks using the tools
Document
Once
3
Continuous monitoring abilities
Demonstration
Once
4, 5, 6, 7, 8, 9, 10, 11, 12, 13
Source code for the modifications
Document
At time of completion or at bi-weekly Project Meeting
4, 5, 6, 7, 8, 9, 10, 11, 12, 13
Demonstration of updates to CNST stakeholders
Demonstration
At time of completion or at bi-weekly Project Meeting
4, 5, 6, 7, 8, 9, 10, 11, 12, 13
Output of unit tests, integration tests, and system tests for affected source code
Document
At time of completion and directly before every production environment modification
7
Requirements that are collected in order to implement the feature
Document
Once, before code implementation
9
Full routing process
Document
Once, before code implementation
10
Developed process flows
Document
Once, before code implementation
13
Techniques for project score analysis
Document
Once, before code implementation
14
All programs, configuration, and commands involved in setting up the authentication environment
Document
Once
15
How to run unit tests, system tests, and integration tests
Demonstration
Once

V. CONTRACTOR’S MINIMUM QUALIFICATIONS

It is expected that this task order will require the work of one contract full time equivalent employee. All contractor personnel working under this task order shall be designated as Key Personnel. All Contractor Key Personnel working under this task order must meet the following minimum qualifications.

Contractor personnel assigned to this Order shall have significant knowledge of the EEEL web-based systems. The Contractor shall have experience and competency in:

· The existing SPM code base

· Java Servlet programming

· Java Spring Framework

· Apache Tomcat Server

· HTML5

· Subversion

· The necessary skill level needed, as defined by the Government, for the work requiring support

· Using the Oracle Relational Database Management Systems (RDBMS) and associated Oracle development and query tools like SQLDeveloper

· Oracle version 10g or newer

· Testing

· Unit testing

· Integration testing

· System testing

· Code quality tools

· Static code analysis

· Dynamic code analysis

· Memory usage analysis

VI. INSPECTION AND ACCEPTANCE

As tasks and deliverables are completed, the Contractor shall submit the deliverables for review by the CNST Technical Point of Contact. The CNST Technical Point of Contact will provide comments on any given deliverable within five business days after the receipt of deliverables. The Contractor shall revise and resubmit the deliverables in accordance with the CNST Technical Point of Contact’s comments and resubmit for review and further comment and approval. All revisions shall be made at no additional cost to the Government.

VII. ESTIMATED LEVEL OF EFFORT

The Government estimates, but does not guarantee, that approximately 2524 contractor hours may be required to perform the requirements of this statement of work. This combines 2087 Project Developer Contractor hours and 437 Project Manager Contractor hours. Estimates are based off of approximations made by the Office of Personnel Management.

VIII. PERIOD OF PERFORMANCE

The period of performance for this task order is for one year from award date.

IX. PLACE OF PERFORMANCE

All work shall be performed on-site at the NIST campus in Gaithersburg, Maryland.

NIST will:

· Provide office space for SPM development

· Provide the Contractor with the appropriate hardware, software, and equipment required for accomplishing day-to-day work requirements

· Provide telephones for the Contractor’s business use only

· Provide systems access and all necessary database and web server permissions, as necessary, to meet the requirements of this task order

X. REPORTING REQUIREMENTS

Report name
Schedule
Project Plan
Within 10 days of order award
Project Plan Meeting
First meeting within 10 days of order award, then once every two weeks throughout the period of performance
Source code
Every two weeks, to be delivered at the Project Plan meeting
Requirements and Deliverables
In accordance with the Project Plan

File details come from the government source that posted it. Updated .