Sol_140G0223Q0095.pdf
PDF 744 KB Posted
- Attached to
- 7A--SCIENTIFIC SOFTWARE SYSTEM DESIGN, DEVELOPMENT, AN Federal contract opportunity
- Solicitation number
- 140G0223Q0095
About this file
This is a combined synopsis/solicitation issued by the Department of the Interior US Geological Survey Office of Acquisitions and Grants seeking scientific software system design, development, and maintenance services. The services include research and development on the DYFI system, software development and maintenance of the DYFI system, response to significant earthquakes, collaboration with ShakeMap developers, and supporting data requests. The period of performance is from September 2023 to September 2028 consisting of a base period and up to four option periods, with an additional optional six-month extension. This is a small business set-aside soliciting firm-fixed-price quotations due by September 7, 2023. The solicitation incorporates various FAR clauses and references applicable federal acquisition regulations.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Sol_140G0223Q0095_Amd_0001.pdf | ||
| B08_Price_Schedule.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
140G0223Q0095
1. REQUEST NO.
5a. ISSUED BY
NAME
a. NAME
c. STREET ADDRESS
d. CITY
10. PLEASE FURNISH QUOTATIONS TO
THE ISSUING OFFICE IN BLOCK 5a ON
OR BEFORE CLOSE OF BUSINESS (Date)
2. DATE ISSUED 3. REQUISITION/PURCHASE REQUEST NO. 4. CERT. FOR NAT. DEF.
UNDER BDSA REG. 2
AND/OR DMS REG.1
RATING
6. DELIVERY BY (Date)
7. DELIVERY
9. DESTINATION
a. NAME OF CONSIGNEE
b. STREET ADDRESS
PAGE OF PAGES
5b. FOR INFORMATION CALL: (No collect calls)
TELEPHONE NUMBER
AREA CODE NUMBER
8. TO:
b. COMPANY
e. STATE f. ZIP CODE
c. CITY
d. STATE e. ZIP CODE
IMPORTANT: This is a request for information, and quotations furnished are not offers. If you are unable to quote, please so indicate on this form and return it to the address in Block 5a. This request does not commit the Government to pay any costs incurred in the preparation of the submission of this quotation or to contract for supplies or services. Supplies are of domestic origin unless otherwise indicated by quoter. Any representations and/or certifications attached to this Request for Quotations must be completed by the quoter.
11. SCHEDULE (Include applicable Federal, State and local taxes)
THIS RFQ
REQUEST FOR QUOTATION
(THIS IS NOT AN ORDER)
IS IS NOT A SMALL BUSINESS SET ASIDEX
08/24/2023 0040571616
1 40
PO BOX 25046
204 DENVER FEDERAL CENTER
DENVER CO 80225-0046
USGS OAG DENVER ACQUISITION BRANCH
USGS Geologic Hazards Team
MS 966
Box 25046 Denver Federal Center
Denver
CO 80225
303 236-9329Cheryl Theeke
09/07/2023 1400 ED
FOB DESTINATION
OTHER
(See Schedule)X
ITEM NO.
(a)
SUPPLIES/SERVICES
(b)
QUANTITY
(c)
UNIT
(d)
UNIT PRICE
(e)
AMOUNT
(f)
(I) This is a combined synopsis/solicitation for commercial items prepared in accordance with the format in FAR Subpart 12.6, as supplemented with additional information included in this notice.
This announcement constitutes the only solicitation; quotes are being requested and a separate written solicitation will not be issued.
(II) This combined synopsis/solicitation is issued as a request for quotation (RFQ). Submit written quotes on RFQ Number 140G0223Q0095. This combined synopsis/solicitation will utilize the policies contained in the Federal Acquisition Regulations (FAR) Part 12 in conjunction with the policies and procedures for solicitation evaluation and award prescribed in FAR Part 13, Continued ...
12. DISCOUNT FOR PROMPT PAYMENT
a. 10 CALENDAR DAYS (%) b. 20 CALENDAR DAYS (%) c. 30 CALENDAR DAYS (%) d. CALENDAR DAYS
NUMBER PERCENTAGE
NOTE: Additional provisions and representations
13. NAME AND ADDRESS OF QUOTER
b. STREET ADDRESS
c. COUNTY
d. CITY e. STATE f. ZIP CODE
14. SIGNATURE OF PERSON AUTHORIZED TO
SIGN QUOTATION
16. SIGNER
a. NAME (Type or print)
c. TITLE (Type or print)
a. NAME OF QUOTER
AREA CODE
NUMBER
15. DATE OF QUOTATION
b. TELEPHONE are are not attached
AUTHORIZED FOR LOCAL REPRODUCTION
Previous edition not usable
STANDARD FORM 18 (REV. 6-95)
Prescribed by GSA - FAR (48 CFR) 53.215-1(a)
ITEM NO. SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
NAME OF OFFEROR OR CONTRACTOR
2 40
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140G0223Q0095
Simplified Acquisition Procedures, as appropriate for this acquisition.
(III) The combined synopsis/solicitation document and incorporated provisions and clauses are those in effect through Federal Acquisition Circular
2023-05.
(IV) This combined synopsis/solicitation is a small business set-aside. The associated NAICS code is 541511 - Custom Computer Programming
Services. The small business size standard is
$34.0M.
(V) This combined solicitation/synopsis is for purchase of the following commercial service(s):
CLIN NO. 00010 - BASE PERIOD (September 22, 2023 through September 21, 2024)
Scientific Software System Design, Development, and Maintenance (Refer to CLIN below for more information).
CLIN NO. 00020 - BASE PERIOD (September 22, 2023 through September 21, 2024)
TRAVEL - This is a Not To Exceed (NTE) CLIN
(Refer to CLIN below for more information).
CLIN NO. 00100 - OPTION PERIOD ONE (September 22, 2024 through September 21, 2025)
Scientific Software System Design, Development, and Maintenance (Refer to CLIN below for more information).
CLIN NO. 00110 - OPTION PERIOD ONE (September 22, 2024 through September 21, 2025)
TRAVEL - This is a Not To Exceed (NTE) CLIN
(Refer to CLIN below for more information).
CLIN NO. 00200 - OPTION PERIOD TWO (September 22, 2025 through September 21, 2026)
Scientific Software System Design, Development, and Maintenance (Refer to CLIN below for more information).
CLIN NO. 00210 - OPTION PERIOD TWO (September 22, 2025 through September 21, 2026)
TRAVEL - This is a Not To Exceed (NTE) CLIN
(Refer to CLIN below for more information).
CLIN NO. 00300 - OPTION PERIOD THREE (September
Continued ...
NSN 7540-01-152-8067 OPTIONAL FORM 336 (4-86)
3 40
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140G0223Q0095
22, 2026 through September 21, 2027)
Scientific Software System Design, Development, and Maintenance (Refer to CLIN below for more information).
CLIN NO. 00310 - OPTION PERIOD THREE (September
22, 2026 through September 21, 2027)
TRAVEL - This is a Not To Exceed (NTE) CLIN
(Refer to CLIN below for more information).
CLIN NO. 00400 - OPTION PERIOD FOUR (September
22, 2027 through September 21, 2028)
Scientific Software System Design, Development, and Maintenance (Refer to CLIN below for more information).
CLIN NO. 00410 - OPTION PERIOD FOUR (September
22, 2027 through September 21, 2028)
TRAVEL - This is a Not To Exceed (NTE) CLIN
(Refer to CLIN below for more information).
CLIN NO. 00500 - 6-Month Extension under FAR
52.217-8 Option to Extend Services, if utilized by the Government (September 22, 2028 through
March 21, 2029)
Scientific Software System Design, Development, and Maintenance (Refer to CLIN below for more information).
CLIN NO. 00510 - 6-Month Extension under FAR
52.217-8 Option to Extend Services, if utilized by the Government (September 22, 2028 through
March 21, 2029)
TRAVEL - This is a Not To Exceed (NTE) CLIN
(Refer to CLIN below for more information).
(VI) Refer to the attached Statement of Work for the description of the service(s).
(VII) Dates and place(s) of delivery and acceptance and FOB point do not apply to this solicitation.
(VIII) FAR 52.212-1, Instructions to Offerors -
Commercial Products and Commercial Services (Mar
2023), applies to this acquisition.
(IX) FAR 52.212-2, Evaluation - Commercial
Products and Commercial Services (Nov 2021), applies to this acquisition. Award will be made to that offeror whose offer, conforming to the
4 40
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140G0223Q0095 solicitation, will be most advantageous to the
Government, price and other factors considered.
Refer to the attached Basis for Award for
Evaluation Factors.
(X) The offeror shall submit a completed copy of the provision at FAR 52.212-3, Offeror
Representations and Certifications - Commercial
Products and Commercial Services (Dec 2022), with its quote. An offeror shall complete only paragraph (b) of this provision if the offeror has completed the annual representations and certifications electronically at www.sam.gov. If an offeror has not completed the annual representations and certifications electronically at the SAM website, the offeror shall complete only paragraphs (c) through (m) of this provision.
(XI) The clause at FAR 52.212-4, Contract Terms and Conditions - Commercial Products and
Commercial Services (Dec 2022), applies to this acquisition. Please see attached Terms and
Conditions for more information.
(XII) The clause at FAR 52.212-5, Contract Terms and Conditions Required to Implement Statutes or
Executive Orders - Commercial Products and
Commercial Services (Jun 2023) applies to this acquisition.
(XIII) The following clauses are also applicable to this acquisition: Please see Clauses and
Provisions attachment.
(XIV) Defense Priorities and Allocations System
(DPAS) and assigned rating does not apply.
(XV) The Government intends to award a single, firm-fixed-price purchase order, with options, resulting from this combined synopsis/solicitation. Questions about this combined synopsis/solicitation shall be emailed to ctheeke@usgs.gov NLT 5:00PM EDT on August 30, 2023 to allow time for government response before solicitation closing. Questions after this deadline may not be answered. Quotations are required to be received in the contracting office no later than 2:00PM EDT on September 7, 2023.
Quotations shall be emailed to ctheeke@usgs.gov.
Offerors shall hold pricing for the Government for 30 days.
5 40
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140G0223Q0095
(XVI) Any questions regarding this combined synopsis/solicitation shall be directed to Cheryl
Theeke at ctheeke@usgs.gov.
Period of Performance: 09/22/2023 to 09/21/2028
00010 BASE PERIOD (September 22, 2023 through September
21, 2024)
Scientific Software System Design, Development, and Maintenance - Services, non-personal, to provide all plant, equipment, labor, supervision, and materials (unless otherwise provided herein) necessary to provide research and development on the DYFI system in accordance with the attached
Performance Work Statement.
Period of Performance: 09/22/2023 to 09/21/2024
00020 BASE PERIOD (September 22, 2023 through September
21, 2024) - TRAVEL
This is a NTE CLIN. All travel is to be handled in accordance with Federal travel regulations.
Period of Performance: 09/22/2023 to 09/21/2024
00100 OPTION PERIOD ONE (September 22, 2024 through
September 21, 2025)
Scientific Software System Design, Development, and Maintenance - Services, non-personal, to provide all plant, equipment, labor, supervision, and materials (unless otherwise provided herein) necessary to provide research and development on the DYFI system in accordance with the attached
Performance Work Statement.
(Option Line Item)
Period of Performance: 09/22/2024 to 09/21/2025
00110 OPTION PERIOD ONE (September 22, 2024 through
September 21, 2025) - TRAVEL
This is a NTE CLIN. All travel is to be handled in accordance with Federal travel regulations.
6 40
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140G0223Q0095
(Option Line Item)
Period of Performance: 09/22/2024 to 09/21/2025
00200 OPTION PERIOD TWO (September 22, 2025 through
September 21, 2026)
Scientific Software System Design, Development, and Maintenance - Services, non-personal, to provide all plant, equipment, labor, supervision, and materials (unless otherwise provided herein) necessary to provide research and development on the DYFI system in accordance with the attached
Performance Work Statement.
(Option Line Item)
Period of Performance: 09/22/2025 to 09/21/2026
00210 OPTION PERIOD TWO (September 22, 2025 through
September 21, 2026) - TRAVEL
This is a NTE CLIN. All travel is to be handled in accordance with Federal travel regulations.
(Option Line Item)
Period of Performance: 09/22/2025 to 09/21/2026
00300 OPTION PERIOD THREE (September 22, 2026 through
September 21, 2027)
Scientific Software System Design, Development, and Maintenance - Services, non-personal, to provide all plant, equipment, labor, supervision, and materials (unless otherwise provided herein) necessary to provide research and development on the DYFI system in accordance with the attached
Performance Work Statement.
(Option Line Item)
Period of Performance: 09/22/2026 to 09/21/2027
00310 OPTION PERIOD THREE (September 22, 2026 through
September 21, 2027) - TRAVEL
This is a NTE CLIN. All travel is to be handled in accordance with Federal travel regulations.
(Option Line Item)
Period of Performance: 09/22/2026 to 09/21/2027
7 40
CONTINUATION SHEET
REFERENCE NO. OF DOCUMENT BEING CONTINUED PAGE OF
(A) (B) (C) (D) (E) (F)
140G0223Q0095
00400 OPTION PERIOD FOUR (September 22, 2027 through
September 21, 2028)
Scientific Software System Design, Development, and Maintenance - Services, non-personal, to provide all plant, equipment, labor, supervision, and materials (unless otherwise provided herein) necessary to provide research and development on the DYFI system in accordance with the attached
Performance Work Statement.
(Option Line Item)
Period of Performance: 09/22/2027 to 09/21/2028
00410 OPTION PERIOD FOUR (September 22, 2027 through
September 21, 2028) - TRAVEL
This is a NTE CLIN. All travel is to be handled in accordance with Federal travel regulations.
(Option Line Item)
Period of Performance: 09/22/2027 to 09/21/2028
00500 6-Month Extension under FAR 52.217-8 Option to
Extend Services, if utilized by the Government
(September 22, 2028 through March 21, 2029)
Scientific Software System Design, Development, and Maintenance - Services, non-personal, to provide all plant, equipment, labor, supervision, and materials (unless otherwise provided herein) necessary to provide research and development on the DYFI system in accordance with the attached
Performance Work Statement.
(Option Line Item)
Period of Performance: 09/22/2028 to 03/21/2029
00510 6-Month Extension under FAR 52.217-8 Option to
Extend Services, if utilized by the Government
(September 22, 2028 through March 21, 2029)
TRAVEL - This is a NTE CLIN. All travel is to be handled in accordance with Federal travel regulations.
(Option Line Item)
Period of Performance: 09/22/2028 to 03/21/2029
Contract Specialist: Cheryl Theeke, Email:
ctheeke@usgs.gov
CONTINUATION SHEET REFERENCE NO. OF DOCUMENT BEING CONTINUED
PAGE OF PAGES
TABLE OF CONTENTS
PERFORMANCE WORK STATEMENT
FISMA – Information Technology Security Requirements Summary Section 508 Compliance
COMMERCIAL CLAUSES
52.204-21 Basic Safeguarding of Covered Contractor Information Systems. (Nov 2021) 52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders - Commercial Products and Commercial Services (JUN 2023) 52.217-8 Option to Extend Services (NOV 1999) 52.217-9 Option to Extend the Term of the Contract (MAR 2000) 52.222-49 Service Contract Labor Standards-Place of Performance Unknown. (MAY 2014) 52.252-2 Clauses Incorporated by Reference (Feb 1998) GS0339 Green Acquisition (JUL 2018) GS0725 Demonstration of Satisfactory Operation (JUL 2001) GS0925 Unscheduled Closures – Fixed Price (MAR 2003) GS1131 Unilateral Deobligation of Unexpended Funds (MAY 2013) GS1332 Contractor’s Representative (JUL 2001) GS1338 Notice to the Government of Delays (JUL 2001) GS1348 Accident Reporting (APR 2003) GS1364 Availability of IT Security Standards, Guides, and Other Publications (AUG 2022) GS1417 Use of Government Computers (SEP 2018) Electronic Invoicing and Payment Requirements - Invoice Processing Platform (IPP) (APR 2013) .. 33 SECURITY REQUIREMENTS: FACILITY ACCESS and INFORMATION TECHNOLOGY
(AUG 2016)
PROVISIONS
52.252-1 Solicitation Provisions Incorporated by Reference (FEB 1998)
BASIS FOR AWARD
Question Cutoff Quotation Submission
PERFORMANCE WORK STATEMENT
BACKGROUND
The Advanced National Seismic System National (ANSS) centered at the USGS National Earthquake Information Center, Golden CO has the unique mandate to produce rapid earthquake information products for all significant earthquakes. These information products now include automatic shaking intensity maps (ShakeMaps), reported macroseismic intensity maps ("Did You Feel It?") and estimated losses (PAGER). The focus of this effort will be on the DYFI system, and its interaction with the USGS Earthquake Program (EP) web pages. DYFI is the U.S. Government’s premiere citizen-science portal for earthquakes, and USGS EP web pages are one of its most accessed.
This information is given to state, federal, and international emergency management and civil defense agencies; groups operating critical public facilities such as dams, power plants, and railroads; government public information channels; national and international news media; scientific groups and private citizens. To ensure the quality and the relevance of earthquake information, new research and development, modified and additional products, as well as technological advances in data acquisition, computations, and processing, must be continually developed and adapted to routine use. New research results must be peer-reviewed and disseminated via peer-reviewed literature and presented at scientific meetings.
SCOPE OF WORK
The contractor shall provide services for the design, development, implementation, maintenance, and operation of several ANSS real-time product related processing systems, primarily the DYFI system. The work shall involve system technological upgrades, independent design and implementation of new subsystems, modification to existing codes, and earthquake response operations. Routine testing prior to operation, and continued calibration based on operational knowledge gained will be used to improve responsiveness of the systems to customer needs and USGS objectives. As the DYFI data are widely used for scientific analyses, the data must be made accessible via state-of-the-art protocols, yet the contractor must interact with and accommodate specialized requests via database queries.
Outcomes include:
• Programming of scientific algorithms and modifications to existing scientific modules that compute macroseismic intensity, their uncertainties, and related data and web products.
• DYFI software development to include: a) Implementation and maintenance of DYFI system in the USGS cloud environment, consistent with EP cloud strategies, b) continue ensuring robustness, speed, & redundancy with software and hardware improvements, including acquisition, triggering, and web delivery, and c) Interact and advice international collaborators on comparable global systems.
• Implement new subsystem for accommodating new earthquake early warning post-DYFI follow-up questionnaire, currently in peer review.
• Response: DYFI response for all earthquakes globally & nationwide that have significant felt reports. Post-earthquake response includes customer service, data processing, and making these data available and responding to inquiries. Aid in specific earthquake response issues as requested by COR.
• As DYFI is integrated heavily with USGS ShakeMap, collaborate with ShakeMap developers for robust delivery of DYFI data within ShakeMap, and aid in response to significant earthquakes nationwide and globally, as needed.
• Supporting the wide range of media, government, scientists’ data requests and inquiries.
Provide support for scientific technical users of data from above systems with complex database queries and improvements to web and GIS DYFI data portals.
Interact with and respond to queries with users and other developers to improve data availability.
• Enhance DYFI user experience, both in terms of contributing citizen-science data, viewing data online and via mobile devices and accessing data for varied purposes.
• Provide operational and bug fixes both proactively and as requested by users or the COR.
• Writing user and programmer documentation via ApiDocs, GitHub and the likes.
• For new research and developments, contribute to and lead efforts on peer-review scientific publications and presentations at scientific meetings.
• Modifying existing systems to accommodate changing technologies and data conventions (e.g., web standards, product format upgrades, and seismic data exchange conventions).
• Maintain an awareness of current macroseismic data collection methodologies and operations via journal reviews, attending and presenting at scientific meetings and workshops, and via Real-time Shaking and Impact team meetings.
QUALITY ASSURANCE SURVEILLANCE PLAN
Required Service Standard Acceptable Level of
Quality Method of
Surveillance Upkeep, cloud porting, and new R&D on of the "Did You Feel It?" (DYFI) software; continued product improvements, including implement-ation of new EEW post- DYFI questionnaire
Standard programming with best practices will be required (e.g., code status updates, Git-hub source control & documentation; con-tinuous integration)
Releases of new versions of DYFI software are checked into the USGS DYFI repository (GitHub).
Software will be checked in by team members & checked against previous systems or earthquakes.
Software components unit & regression tested to validate functionality.
System performance, USGS Fundamental Scientific Practices (FSP), code & data releases standards adhered to.
Response to significant earthquakes; quality assurance & review of online DYFI products;
revise as needed.
Adherence to existing USGS earthquake program web product standards & delivery methods.
Web-based products will be timely, of high quality, & consistent with USGS ANSS post-earthquake product standards.
Review by real-time products and event coordinators.
Support for data requests by scientific, technical, and general inquiries. Use feedback to make improvements to web, GIS DYFI data portals & user Interface
Provides professional & timely response to DYFI user inquiries as requested by project lead, or in direct response to users’ inquiries.
Comprehensive response to inquiries, carbon copied to COR (as desired), project Lead & are archived.
Project lead and COR will review user feedback as well as USGS and DYFI customers for satisfaction to data requests & overall DYFI system performance.
Documentation of software updates in GitHub or USGS standard repository.
Documentation fully describes new functionality & nature of revised information pro-ducts. Adherence to existing USGS web and FSP.
Documentation will be checked & quality assured to be consistent with USGS reporting, online presentation, & FSP.
Web-based pro-ducts will be timely, of high quality, & consistent with USGS ANSS post-earth-quake product standards.
Documentation will be reviewed by COR & products coordinator, web manager, or via internal review. Review of data & products by real-time products & event coordinators as well as by feedback from developers and scientists.
Contributes to or leads peer-reviewed publications and presents R&D results at scientific advancements at meetings
Publications and report are to standards of peer-review journals and meeting expectations
Adherence FSP via internal and external peer review.
Peer-reviewed content satisfies reviewer and publication standards.
FISMA – Information Technology Security Requirements Summary
COTS
Hardware or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
1 N/A Background Investigations. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”
Hardware or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
2 N/A
Contractor will have access to Privacy Act System of Records - Work under this contract will involve design, development or operation of (access to) system(s) of records containing personal information protected by the Privacy Act (5 U.S.C. Section 552a).
Non-disclosure Agreement. Prior to receiving access to USGS computers, contractor employees shall be required to sign nondisclosure or other system security agreements, depending on the systems to be used and level of access granted.
Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:
• User Access to USGS IT Systems known to contain sensitive or proprietary data
• IT Support services (greater than user access)
• Development or Maintenance of Custom
Applications
• On-site contractor support and management of IT system
• Off-site contractor Oversight and Management of IT System
• IT Security Services
Privacy Act System: [Identify covered system(s) to which the contractor may have access]
Work to be performed: [Summarize nature of the contractor's use of such records, such as]
• User-level access to system containing protected records
• Operation or maintenance of Privacy Act
System of records or computers hosting such system
• Design or modification of a Privacy Act system of records]
The contractor is not required or permitted to respond to requests for Privacy Act data or to make decisions about releases of data under the Act. Contractor shall ensure its employees are instructed to safeguard against improper use or release of such data and advise them that violation of the Act may involve criminal or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
penalties. The contractor will comply with FAR clause 52.224-2, Privacy Act, incorporated herein by reference and with DOI Privacy Act regulations at 43 CFR 2, Subpart D
3 N/A Training. The Contractor shall perform in accordance with clause “Security Requirements:
Facility Access and Information Technology” - Contractor employees must successfully complete DOI’s end-user computer security awareness training prior to being granted access to DOI data or being issued a user account.
Training must be renewed annually. Additionally, the contract employees must sign a Statement of Responsibility (SOR) that states they have read the appropriate Rules of Behavior and other applicable Information security policies.
4 N/A Personnel Changes. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology” - The contractor must notify the COR immediately when an employee working on a DOI system is reassigned or leaves the contractor’s employ.
Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:
• User Access to USGS IT Systems known to contain sensitive or proprietary data
• IT Support services (greater than user access)
• Development or Maintenance of Custom
Applications *
• On-site contractor support and management of IT system
• Off-site contractor Oversight and Management of IT
System
• IT Security Services *
*May not be applicable for off-site performance.
5 N/A Contractor Location. The Contractor shall or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
Requirements: Facility Access and Information Technology.”
Applies whenever any contractor employee has unsupervised access to a USGS system (even if only basic network, internet or email or will develop custom applications) such as:
• User Access to USGS IT Systems known to contain sensitive or proprietary data
• IT Support services (greater than user access)
• Development or Maintenance of Custom
Applications
• On-site contractor support and management of IT system
• Off-site contractor Oversight and Management of IT
System
• IT Security Services
No portion of the services to be performed hereunder may be performed outside the United States without the express written permission of the Contracting Officer.
If services are proposed to be performed abroad, the Contractor shall provide an acceptable security plan that addresses mitigation of problems related to communication, control, and protecting the confidentiality, integrity, and availability of IT systems and information.
A Security Plan Template is available upon request from the Contracting Officer.
6 N/A N/A Applicable Standards. The Contractor shall
Requirements: Facility Access and Information Technology” - Contractor must follow the DOI System Development Life Cycle (SDLC), NIST SP 800-64 and the DOI SDLC Security Integration Guide.
7 N/A Asset Valuation-Security Categorization:
The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”
User Access to USGS IT Systems – The Government is responsible for security categorization on USGS systems to which the Contractor may have access https://insight.usgs.gov/aei/offices/oa/oag/AOP/guidefordevelopingsecurityplans.pdf or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
under this contract.
IT Support Services greater than
User-Level Services Choose one:
The Government is responsible for security categorization on USGS systems to which the Contractor may have access under this contract.
- The Government has defined the [insert name of system to be developed, operated or maintained by the contractor] to be a [Major Application], [Minor Application] or [General support system] as defined in OMB Circular A-130, Appendix III and NIST SP800-53.
The following risk and sensitivity levels have been assigned based on the FIPS 199 and the NIST SP 800- 60.
Mission impact:
Data sensitivity:
Risk level:
Bureau/departmental/national criticality:
Off-Site Oversight and Management of IT System- The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.
IT Security Services - Applies only if the purpose of the contract includes obtaining asset valuation services.
The Contractor shall use the FIPS 199 and the NIST SP 800- 60 to determine information types and security categorization based on mission impact, data sensitivity, risk level, and bureau / departmental / national criticality for Contractor-owned and operated systems used to provide services under this contract. Solicitations must include either the complete publication or a reference to public facilities, such as a website or office, where it may be accessed.
The Government shall be granted unlimited rights in software or data produced hereunder as
Select either COTS or custom software language as applicable. If both apply, identify software/data
Property Rights.
1. For Federal Supply Schedule orders or orders under an existing contract, rights to software acquired hereunder are set forth in the basic contract.
2. For open market contracts, the
Government's rights in software delivered hereunder shall be as described in software developer's commercial software license or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
described in FAR clause 52.227-17, Rights in Data—Special Works, incorporated by reference herein.
deliverables governed by each clause.
agreement or the clause FAR 52.227-19, Commercial Computer Software- Restricted Rights, whichever is greater.
9 N/A Independent Verification and Validation (IV&V). The Government is responsible for independent software verification and validation prior to being moved into production.
On-Site Contractor Support and Management of IT System Choose one:
Software will be independently verified and validated by the Government or another selected contractor prior to being moved into production.
Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide
Off-Site Contractor Operation and
Management of IT System-Contractor will ensure that independent verification and validation is performed on software deployed on contractor managed systems containing USGS data, in accordance with DOI SDLC Security Integration Guide
IT Security Service - Applies only if the purpose of the contract includes obtaining IV&V services.
or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
10 N/A Applies if the purpose of the contract includes obtaining C&A services.
Certification & Accreditation.
User Access to USGS IT Systems or IT Supports Services (Greater than User Access Certification and Accreditation on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.
Development or Maintenance of Custom Applications The contractor will perform Certification and Accreditation (C&A) services on the application developed or maintained hereunder prior to going into production. The application must be re-accredited every three years or whenever there is a major change that affects security. C&A documents will be provided to the COR in both hard copy and electronic forms. The contractor must follow NIST SP 800-37, 800-18, 800-30, 800-60, 800-53A, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment.
NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/ FIPS documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the Contracting Officer. The government reserves the right to conduct the ST&E using either Government personnel or an independent contractor. The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.
On-Site Contractor Support and Management of IT System or Off-Site Contractor Operation and Management of IT System The Contractor must maintain systems that are compliant with NIST SP 800-18, 800-30, 800-37, 800-53A, 800-60, Federal Information Processing Standard (FIPS) 199 and 200, the associated DOI guides/templates, the DOI Security Test & Evaluation (ST&E) Guide, and the DOI Privacy Impact Assessment. As required by the above, Major Applications and General Support Systems shall be certified and accredited (C&A) prior to going into production and re-accredited every three years or whenever there is a major change that affects security. C&A documents will be provided to the COR in both hard copy and electronic forms.
NIST documents are available on the internet at http://csrc.nist.gov/publications/nistpubs/. The contractor may request copies of DOI documents by contacting the Contracting Officer. The government will reserve the right to conduct the ST&E, using either Government personnel or an independent contractor. The contractor will take immediate and timely action to correct or mitigate any weaknesses discovered as necessary to bring the application or system into compliance with the above requirement.
or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
11 N/A for COTS
HW & SW,
User Access to
USGS IT
Systems (other than IT services), IT Support Services (User Level or greater access)
N/A Internet Logon Banner. The Contractor shall perform in accordance with clause “Security Requirements: Facility Access and Information Technology.”
Development or Maintenance of Custom Applications OR On-Site Contractor Support and Management of IT System OR Off-site Contractor Oversight and Management of IT System- Web-based applications developed or maintained under this contract must contain a USGS approved logon banner:
https://portal.doi.net/CIO/ITPMgmt/Documents/IT Standards/IT Security/DOI Security Control Standards (based on NIST SP 800-53 Revision 3)/Access Control v1.4.pdf
12 N/A Incident Reporting. The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” - The contractor must report computer security incidents affecting DOI data or systems in accordance with the DOI Computer Incident Response Guide.
13 Quality Control. All software or hardware purchased must be free of malicious code such as viruses, Trojan horse programs, worms, spyware, etc. Validation of this must be written into the contract.
14 N/A N/A Self-Assessment. The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” - The contractor must conduct an annual self-assessment in accordance with annual DOI guidance on all information systems in production.
https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf https://portal.doi.net/CIO/ITPMgmt/Documents/IT%20Standards/IT%20Security/DOI%20Security%20Control%20Standards%20(based%20on%20NIST%20SP%20800-53%20Revision%203)/Access%20Control%20v1.4.pdf or Software
Development or Maintenance of Custom Applications
Outsourced IT Services or On-site Support
Requirements herein are incorporated as part the Statement of Work/ Performance Work Statement:
15 N/A Vulnerability Analysis. Vulnerability Analysis on USGS systems to which the Contractor may have access under this contract will be conducted by the Government or another of its contractors.
16 N/A Logon Banner. Contractor employees who access DOI information systems must acknowledge a government-approved legal warning banner prior to logging on to the system. This includes contractor owned information systems hosting DOI data.
17 N/A Security Controls.
The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology” – The Contractor shall ensure compliance with the security control requirements of the current version of NIST SP 800-53, Rev.1, which are applicable to the security categorization of the data or system. FIPS 199 and the NIST SP 800- 60 will be used to determine information types and security categorizations.
18 N/A N/A Contingency Plan.
The Contractor shall perform in accordance with contract clause “Security Requirements: Facility Access and Information Technology.”
For IT Support Services: The Contractor shall submit a contingency plan in accordance with NIST SP 800-34 and DOI IT Systems Contingency Plan Guide.
Section 508 Compliance
CT Accessibility Requirements Statement per the Revised Section 508 of the Rehabilitation Act
Did You Feel It? (DYFI?) support - Department of the Interior - US Geological Survey
General Exceptions - Software
Technical Criteria:
• E207.1 General - Where components of ICT are software and transmit information or have a user interface, such components shall conform to E207 and the requirements in Chapter 5
• E207.2 WCAG Conformance - User interface components, as well as the content of platforms and applications, shall conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).
• E207.2.1 Word Substitution - When Applying WCAG to Non-Web Software For non-Web software, wherever the term “Web page” or “page” appears in WCAG 2.0 Level A and AA Success Criteria and Conformance Requirements, the term “software” shall be substituted for the terms “Web page” and “page”. In addition, in Success Criterion in 1.4.2, the phrase “in software” shall be substituted for the phrase “on a Web page.”
• E207.3 Complete Process for Non-Web Software - Where non-Web software requires multiple steps to accomplish an activity, all software related to the activity to be accomplished shall conform to WCAG 2.0 as specified in E207.2.
Exceptions:
• E501.1 Scope - Where Web applications do not have access to platform accessibility services and do not include components that have access to platform accessibility services, they shall not be required to conform to 502 or 503 provided that they conform to Level A and Level AA Success Criteria and Conformance Requirements in WCAG 2.0 (incorporated by reference, see 702.10.1).
Functional Performance Criteria:
• 301.1 Scope - The requirements of Chapter 3 shall apply to ICT where required by 508 Chapter 2 (Scoping Requirements), 255 Chapter 2 (Scoping Requirements), and where otherwise referenced in any other chapter of the Revised 508 Standards or Revised 255 Guidelines.
• 302.1 Without Vision - Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.
• 302.2 With Limited Vision - Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.
• 302.3 Without Perception of Color - Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.
• 302.4 Without Hearing - Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.
• 302.5 With Limited Hearing - Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.
• 302.6 Without Speech - Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.
• 302.7 With Limited Manipulation - Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.
• 302.8 With Limited Reach and Strength - Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.
• 302.9 With Limited Language, Cognitive, and Learning Abilities - ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.
http://app.buyaccessible.gov/ict-accessibility#e207_1__e207_2__e207_2_1__e207_3 http://app.buyaccessible.gov/ict-accessibility#e207_1__e207_2__e207_2_1__e207_3 http://app.buyaccessible.gov/ict-accessibility#e207_1__e207_2__e207_2_1__e207_3 http://app.buyaccessible.gov/ict-accessibility#e207_1__e207_2__e207_2_1__e207_3 http://app.buyaccessible.gov/ict-accessibility#e501_1_scope_exception https://buyaccessible.gov/ict-accessibility#e301_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1 https://buyaccessible.gov/ict-accessibility#e302_1
COMMERCIAL CLAUSES
52.204-21 Basic Safeguarding of Covered Contractor Information Systems. (Nov 2021)
(a) Definitions. As used in this clause—
Covered contractor information system means an information system that is owned or operated by a contractor that processes, stores, or transmits Federal contract information.
Federal contract information means information, not intended for public release, that is provided by or generated for the Government under a contract to develop or deliver a product or service to the Government, but not including information provided by the Government to the public (such as on public websites) or simple transactional information, such as necessary to process payments.
Information means any communication or representation of knowledge such as facts, data, or opinions, in any medium or form, including textual, numerical, graphic, cartographic, narrative, or audiovisual (Committee on National Security Systems Instruction (CNSSI) 4009).
Information system means a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information (44 U.S.C. 3502).
Safeguarding means measures or controls that are prescribed to protect information systems.
(b) Safeguarding requirements and procedures.
(1) The Contractor shall apply the following basic safeguarding requirements and procedures to protect covered contractor information systems. Requirements and procedures for basic safeguarding of covered contractor information systems shall include, at a minimum, the following security controls:
(i) Limit information system access to authorized users, processes acting on behalf of authorized users, or devices (including other information systems).
(ii) Limit information system access to the types of transactions and functions that authorized users are permitted to execute.
(iii) Verify and control/limit connections to and use of external information systems.
(iv) Control information posted or processed on publicly accessible information systems.
(v) Identify information system users, processes acting on behalf of users, or devices.
(vi) Authenticate (or verify) the identities of those users, processes, or devices, as a prerequisite to allowing access to organizational information systems.
(vii) Sanitize or destroy information system media containing Federal Contract Information before disposal or release for reuse.
(viii) Limit physical access to organizational information systems, equipment, http://uscode.house.gov/browse.xhtml;jsessionid=114A3287C7B3359E597506A31FC855B3 and the respective operating environments to authorized individuals.
(ix) Escort visitors and monitor visitor activity; maintain audit logs of physical access; and control and manage physical access devices.
(x) Monitor, control, and protect organizational communications (i.e., information transmitted or received by organizational information systems) at the external boundaries and key internal boundaries of the information systems.
(xi) Implement subnetworks for publicly accessible system components that are physically or logically separated from internal networks.
(xii) Identify, report, and correct information and information system flaws in a timely manner.
(xiii) Provide protection from malicious code at appropriate locations within organizational information systems.
(xiv) Update malicious code protection mechanisms when new releases are available.
(xv) Perform periodic scans of the information system and real-time scans of files from external sources as files are downloaded, opened, or executed.
(2) Other requirements. This clause does not relieve the Contractor of any other specific safeguarding requirements specified by Federal agencies and departments relating to covered contractor information systems generally or other Federal safeguarding requirements for controlled unclassified information (CUI) as established by Executive Order 13556.
(c) Subcontracts. The Contractor shall include the substance of this clause, including this paragraph (c), in subcontracts under this contract (including subcontracts for the acquisition of commercial products or commercial services, other than commercially available off-the-shelf items), in which the subcontractor may have Federal contract information residing in or transiting through its information system.
52.212-5 Contract Terms and Conditions Required to Implement Statutes or Executive Orders - Commercial Products and Commercial Services (JUN 2023)
(a) The Contractor shall comply with the following Federal Acquisition Regulation (FAR) clauses, which are incorporated in this contract by reference, to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
(1) 52.203-19, Prohibition on Requiring Certain Internal Confidentiality Agreements or Statements (JAN 2017) (section 743 of Division E, Title VII, of the Consolidated and Further Continuing Appropriations Act, 2015 (Pub. L. 113-235) and its successor provisions in subsequent appropriations acts (and as extended in continuing resolutions)).
(2) 52.204-23, Prohibition on Contracting for Hardware, Software, and Services Developed or Provided by Kaspersky Lab and Other Covered Entities (NOV 2021) (Section 1634 of Pub. L. 115-91).
(3) 52.204-25, Prohibition on Contracting for Certain Telecommunications and Video Surveillance Services or Equipment. (NOV 2021) (Section 889(a)(1)(A) of Pub. L. 115- 232).
(4) 52.209-10, Prohibition on Contracting with Inverted Domestic Corporations (NOV
2015).
(5) 52.232-40, Providing Accelerated Payments to Small Business Subcontractors (MAR 2023) (31 U.S.C. 3903 and 10 U.S.C. 3801).
https://www.acquisition.gov/far/52.203-19#FAR_52_203_19 https://www.acquisition.gov/far/52.204-23#FAR_52_204_23 https://www.acquisition.gov/far/52.204-25#FAR_52_204_25 https://www.acquisition.gov/far/52.209-10#FAR_52_209_10 https://www.acquisition.gov/far/52.232-40#FAR_52_232_40 https://www.govinfo.gov/link/uscode/31/3903 https://www.govinfo.gov/link/uscode/10/3801
(6) 52.233-3, Protest After Award (AUG 1996) (31 U.S.C. 3553).
(7) 52.233-4, Applicable Law for Breach of Contract Claim (OCT 2004) (Public Laws 108-77 and 108-78 (19 U.S.C. 3805 note)).
(b) The Contractor shall comply with the FAR clauses in this paragraph (b) that the Contracting Officer has indicated as being incorporated in this contract by reference to implement provisions of law or Executive orders applicable to acquisitions of commercial products and commercial services:
☒ (1) 52.203-6, Restrictions on…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .