QAs__6-22-16.docx
DOCX document 21 KB Posted
- Attached to
- CRADA Builder Software Tool Federal contract opportunity
- Solicitation number
- SB1341-16-RQ-0293
About this file
Questions and Responses
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| syn_sol_6-22-16.docx | DOCX document | |
| CRADA_Builder_SOO_6-21-16_GG.doc | DOC document | |
| QAs__6-10-16.docx | DOCX document | |
| syn_sol_6-10-16.docx | DOCX document | |
| CRADA_Builder_SOO_6-10-16.doc | DOC document | |
| SB1341-16-RQ-0293.pdf | ||
| CRADA_Builder_SOO_4-4-16.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SB1341-16-RQ-0293 Questions Log:
1. According to Solicitation # SB1341-16-RQ-0293. The following will be used to evaluate quotations (IT Security (Pass/Fail). Should you please instruct us where can we obtain an IT Security clearance. Your help is greatly appreciated.
Answer: IT Security Pass/Fail criteria have been removed from the RFQ.
2. The Government indicated evaluation will be based on ATO letter or 'that they have passed an independent security audit'. Our firm received and was certified based on an independent security audit performed by the American Association for Laboratory Accreditation (A2LA) in connection with our accreditation as a FedRAMP Third Party Assessment Organization (3PAO). Does this audit meet the NIST IT Security Pass/Fail requirement?
Answer: IT Security Pass/Fail criteria have been removed from the RFQ.
3. Is this a follow-on requirement? If so, could you please provide the incumbent contract number for this opportunity? If not, is this a new requirement?
Answer: This is a new requirement.
4. I do have one quick question regarding the NIST CRADA requirement. In the solicitation it requires an Authorization to Operate (ATO) letter from a government agency for security purposes to certify that the contractor meets all FIPS requirements. We have not had a requirement for this type of thing in the past and have done work for the Department of Commerce. However it does state that you will accept an independent security audit. We have no issue with that but would like to get a recommended source (company) that you would suggest we use. We fully understand the FIPS and all of the issues regarding security so having an audit isn't of concern but would like to have it done by a firm that NIST recognizes.
Answer: IT Security Pass/Fail criteria have been removed from the RFQ.
5. How many agencies will be using this tool?
Answer: At present time we will be including up to six agencies in this tool. Based on future interest and availability of funds we may expand to a maximum of 11 agencies under additional Statements of Objectives.
6. Could you please provide number of users per agency or total number of users for this tool?
Answer: Users per agency will vary based on agency structure. Some agencies have very small offices and will only have 2-3 users in the system. Other agencies may have upwards of 40 users.
7. Was the tool by NIH the RFP mentioned (http://www.ott.nih.gov/cradas ) developed internally or externally? If external, could you please share the name of the vendor who built this tool?
Answer: The tool by NIH was developed internally.
8. Is there a preference for on premise solution or can we propose a cloud based solution that is FedRAMP certified?
Answer: NIST requires that the final tool to be hosted from the federallabs.org facility.
9. Is federallabs.org maintained by a contractor today? If yes, could you please share the name and the contract number?
Answer: Federallabs.org is currently maintained by Total Technology Inc. under contract SB1341-13-CQ-0002.
10. We are requesting clarification to the statement that “the final tool shall be hosted on the FLC’s federallabs.org website” (found on page 1 of the SB1341-1-RQ-0293.pdf document). Does this mean NIST is open to a tool that is (more than one answer is acceptable)
| a. accessible from the federallabs.org website and has the same look and feel as the federallabs.org website |
| b. accessible from the federallabs.org website and has a unique look and feel to designate a look specific to the CRADA tool? |
| c. hosted from your facility |
| d. hosted from the federallabs.org facility (if not hosted internally) |
| e. hosted from the contractor’s facility |
Answer: NIST requires that the final tool to be hosted from the federallabs.org facility. NIST prefers the tool to have the same look and feel as the federallabs.org website and related tools but this is not a requirement.
11. Is NIST open to a Commercial off-the-shelf (COTS) solution, with out of the box functionality, that simply requires configuration versus a solution built from custom code?
Answer: Yes, we are open to configured COTS solutions that meet all of the requirements.
12. Does NIST have a preference for an on premise solution, a hosted solution, a cloud solution, or any of the above?
Answer: NIST requires that the tool to be hosted from the federallabs.org facility.
13. Reference: Combined Synopsis/Solicitation, page 3, Para 1: Do cover letter and Table of Contents (TOC) count towards the 10 pages limit for Volume I – Technical Submissions?
Answer: No.
14. Is there an incumbent currently performing the work? If Yes, who is the incumbent? What is the incumbent’s contract number?
Answer: There is no incumbent contract for this requirement. This is a new requirement.
15. Is the incumbent eligible to bid?
Answer: There is no incumbent contract for this requirement. This is a new requirement.
16. Reference: SOO, page 6, Place of Performance: Where is the current development, test and production environment hosted?
Answer: There is no current development, test and production environment for this tool as it is a new requirement.
17. Reference: SOO, page 6, Place of Performance: Can the development and test environment be hosted at Contractor’s facilities or at a Cloud Service Provider (CSP)?
Answer: Development and test environments can be hosted at the Contractor’s facilities as long as the final tool can be hosted on the federallabs.org website.
18. Reference: SOO, page 7, General Information/IT requirements: What is the current authentication mechanism? Is the aim to maintain the same authentication mechanism and expand it to other agencies?
Answer: Currently, the NIH CRADA Builder tool uses SiteMinder SSO for authentication. The aim would be to use the same mechanism provided that it meets other agencies’ security needs.
19. Reference: SOO, page 4, Task 2.a: The tool must support up to 6 agencies. Can you provide the list of agencies?
Answer: The list is tentative and will be confirmed prior to contract issuance; currently the six agencies are the Department of Commerce, the Department of Homeland Security, the US Department of Agriculture, the Department of Energy, the Environmental Protection Agency, and the Department of Veterans Affairs.
20. Reference: SOO, page 2, Section 4.1, Background: The current NIH CRADA tool supports agreements related to the clinical domain. Will the scope of the new CRADA Builder tool be limited to the clinical domain or will it be expended? If the scope is expended, to which domains?
Answer: All research scopes, both clinical and non-clinical R&D, will need to be included in the final tool.
21. Reference: SOO, page 6, Government-Furnished Properties, Data and Information: How many legal clauses (rough order of magnitude) need to be inserted in the CRADA Builder Tool to support all agencies?
Answer: On average, each agency’s standard agreement template contains approximately 50-80 clauses.
22. Q1. Looking at the CRADA tool that NIH built, it looks like a custom solution. Is the government interested in extending NIH solution (with similar underlying architecture) to address all the labs NIST deals with, or can we present a COTS solution on cloud?
Answer: NIST is open to configured COTS solutions that meet all of the requirements.
23. Since labs listed under FLC are all over the country, will the government provide access to stakeholders in these labs via a remote connection or members of the consortium work out of a DC office?
Answer: The lead agency contacts are all located in the DC area.
24. Do you have expert on source code that we can talk to? A few issues:
There are quite a few tools that need to be installed and configured. The main ones are:
PHP
Apache Drush Drupal MySQL
It would help to know which versions of these tools are required, otherwise we will just install the latest.
Answer: PHP v5.3.3, Apache v2.4.18, Drush v6.2.0, Drupal v7.43, MySQL v5.5.38
The "install-crada-site.sh" script has call to clone a git repository at "github.com/CBIIT/CRADA". We are getting a 404 error when attempting to access the site. The script also indicates that an account (username/password) is needed for access.
Answer: Currently source code in github is in a private repository (no public access). Responders will need to change the .zip script to clone from their new git repository once created.
It may be that you have provided all of the source code in the two zip files and we might not need to clone it from the git repository. In which case we would need instructions on how to assemble the two zips. It may be that we just need to replace the "all" folder in zip1 with the one in zip2.
It is common for web sites like this to have an "index.php" page that serves as the launch page for the site. I don't see one, and I don't see another obvious launch page. We need to know the URL or page to access the site once it is deployed.
Answer: Drupal is different than PHP. CRADA is a submodule in Drupal. You can find the landing folder default/modules/crada in the source zip file.
25. My organization would like to respond to the CRADA solicitation; however, in the technical volume 1 section there is a requirement that requests that responders produce a ATO letter from their government customers. Unfortunately, our customers whom we've provided C&A support to their systems are in the intelligence community. Due to the classified nature of their mission systems they would not sign off on a letter stating that we've C&A'd their systems to achieve ATO. Are there other means by which potential vendors can prove that we can C&A government systems for ATO?
Answer: IT Security Pass/Fail criteria have been removed from the RFQ.
26. IT Security requirement. Since the application will be hosted by FLC's federallabs.org, why do we need an ATO letter?
Answer: IT Security Pass/Fail criteria have been removed from the RFQ.
27. Will NIST provide development tier environment?
Answer: No.
28. Will NIST provide government-furnished laptops/desktops?
Answer: No.
29. Our software developers are reviewing the codes provided and believe that they are missing two files from the code base.
They are:
crada_helper_functions.js current_document.js Answer: These files will be emailed to all vendors who previously requested the source code by close of business 6/10/2016. If you have not received an email by COB on 6/10/2016, please send an email requesting the additional files to Wendy.Paulo@nist.gov. The files will also be available to any additional company that requests the code according to the instructions in the solicitation.
30. Does NIST prefer an Open Source or COTS solution?
Answer: NIST does not have a preference between Open Source or a COTS Solution.
31. Will NIST follow the same technical architecture as NIH deployment?
Answer: Yes, we prefer that the additional agencies’ modules follow the same technical architecture as the NIH deployment.
32. Does NIST expect the current contractor (Total Technology) at the federallabs.org facility to be involved in implementing the final solution? Will Total Technology (or the current contract holder) be responsible for maintaining this system after implementation is complete?
Answer: The holder of the main FLC contract, which includes maintenance of the federallabs.org website, at the time of implementation will be involved in implementing the final solution and maintaining the system after implementation is complete.
33. What team within NIST is running this project? Do we have a technical point of contact?
Answer: A technical point of contact will be provided at the time of contract award.
34. Who was the contractor for NIH’s deployment?
Answer: The tool by NIH was developed internally.
35. We were going to engage NIH independently to sign NDAs or whatever is needed to see how they operate. Would that be a problem?
Answer: This is a NIST procurement. We cannot dictate communications with other government agencies. All official communication regarding this procurement is from NIST.
36. I wanted to let you know that I did receive this email with the attachments, but we still had problems. Once we changed the extension of the files you sent to “.html” we were able to see the javascript, but we cannot create a new document because it is missing another Javascript file (new_document.js). Can you send us that file?
Answer: These files will be emailed to all vendors who previously requested the source code by close of business 6/23/2016. If you have not received an email by COB on 6/23/2016, please send an email requesting the additional files to Wendy.Paulo@nist.gov. The files will also be available to any additional company that requests the code according to the instructions in the solicitation.
37. We downloaded the two files, changed the extension and added them to our CRADA deployment. We are able to access more functionality now. However, we are now getting error messages indicating that we are missing two other files:
../default/modules/crada/new_document.js ../default/modules/crada/list_documents.js Answer: These files will be emailed to all vendors who previously requested the source code by close of business 6/23/2016. If you have not received an email by COB on 6/23/2016, please send an email requesting the additional files to Wendy.Paulo@nist.gov. The files will also be available to any additional company that requests the code according to the instructions in the solicitation.
37. Would it be possible to offer an extension of a week for this proposal?
Answer: The request for proposals has been extended to Wednesday, July 6, 2016.
File details come from the government source that posted it. Updated .