SOW for solicitation 123A9420Q0015.pdf
PDF 347 KB Posted
- Attached to
- Two automated immunohistochemistry stainers, Windows 10-compatible Federal contract opportunity
- Solicitation number
- 123A9420Q0015
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Combined Synopsis-Solicitation - 123A9420Q0015.pdf | ||
| Clauses for beta.sam.gov posting - 123A9420Q0015.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
STATEMENT OF WORK
for Automated Immunohistochemistry Stainer
Background
The Food Safety and Inspection Service (FSIS), a public health regulatory agency of the U.S.
Department of Agriculture (USDA), protects consumers by ensuring that meat, poultry, and egg products are safe, wholesome, and accurately labeled. The FSIS Eastern Lab (EL) is a regulatory laboratory analyzing meat, poultry, Siluriformes, and egg products to ensure that the food supply is protected from adulteration. The EL is located at Russell Research Center, 950 College Station Road, Athens, GA 30605. We require replacement of our current automated immunohistochemistry (immuno) stainers for doing specialized antibody/antigen staining. The existing immuno stainers are 13 years old and are not Windows 10 compatible.
For this reason we are in need of 2 new automated immuno stainers. In addition, the legacy versions of the Microsoft Windows operating system and must be upgraded to Windows 10 or replaced to eliminate unacceptable security risks to the USDA information technology enterprise.
Objective/Scope
The objective for the purchasing of the Windows 10-compatible automated immunohistochemistry stainers is to replace obsolete equipment and software, to modernize the hardware and software to meet current security standards, and to modernize the technologies used to support histological testing methods.
Requirements
The laboratory requires two (2) new automated immuno stainers.
1. The automated immuno stainers must:
a. Have a fully open system that does not require using a propietary or specified reagent.
b. Have an integrated 2D barcode scanner.
c. Stain a minimum of 36 slides per run.
d. Have dimensions no larger than 76 x 67 x 58 centimeters in order to fit in our limited benchtop space.
e. Separate hazardous and non-hazardous waste.
f. Have a permanent dispenser probe and not use detachable pipette tips.
g. Have a pipette dispense accuracy of 99% for the total dispense volume.
h. Include slide and reagent bar code and label printing capability with high-resolution and high-content 1D and 2D barcodes and alphanumeric printing.
i. Include a Windows 10 instrument controller with Windows 10 compatible instrument control software.
2. A one-year service plan shall include:
a. 24-hour repair service will be available.
b. Response and repair work must be completed within three working days of the service call being placed with the contractor.
c. A one-year warranty on service and parts at no cost.
d. A contractor guarantee of the availability of repair parts for a minimum period of five years beyond the installation date.
e. A complete report detailing all repair work and current instrument status will be provided to the lab immediately following any repairs and prior to the service technician leaving the lab.
The instrument shall be installed and all factory published specifications for functionality demonstrated upon installation. The warranty service shall include telephone support for hardware and software. Maintenance/repair services shall be provided during normal working hours, 8:00 am to 4:30 pm, local time, Monday through Friday, excluding Federal Holidays.
LEGAL HOLIDAYS (DEC 2008)
(a)The Federal Government observes the following days as holidays.
New Year’s Day January 1st* Martin Luther King’s Birthday Third Monday in January Presidents’ Day Third Monday in February Memorial Day Last Monday in May Independence Day July 4th* Labor Day First Monday in September Columbus Day Second Monday in October Veterans’ Day November 11th Thanksgiving Day Fourth Thursday in November Christmas Day December 25th*
*If the date falls on a Saturday, the Government holiday is the preceding Friday. If the date falls on a Sunday, the Government holiday is the following Monday.
(b) In addition to the days designated above as holidays, the Government may observe additional days in accordance with 5 USC 6103.
Data system:
As part of the requirement, the vendor shall provide responses to the “Questions for Vendors Concerning Windows 10 Instrument Controllers” in order or approval to be obtained for introduction of new vendor IT equipment into the FSIS Enterprise and for evaluation. If the proposed edition and/or version of Microsoft Windows 10 is disapproved by the Government, the vendor will be notified.
General Requirements:
COMMONLY ACCEPTED SECURITY CONFIGURATIONS FOR WINDOWS
OPERATING SYSTEMS (DECEMBER 2016)
By delivering applications under this contract/order, the Contractor certifies that such applications are fully functional and operate correctly as intended on systems using the United States Government Configuration Baseline (USGCB) and comply with E-authentication and other Federal mandates such as LincPass. This includes Microsoft Edge (IE 11), Mozilla FireFox 49.0.2 and higher configured to operate on Windows 10, Windows Server 2012, and higher, as well as latest versions of Android OS and iOS for mobile devices.
The standard installation, operation, maintenance, updates, and/or patching of software shall not alter the configuration settings from the approved USGCB configuration. If a configuration change is necessary, the contractor will supply the actual configuration change, and the business reason for that deviation; the complete list of USGCB configurations can be supplied by FSIS security. The information technology system should also utilize (where appropriate) the Windows Installer Service for installation of the default program files directory and should be able to silently install and uninstall.
Applications designed for normal end users shall run in the standard user context without elevated system administration privileges.
COMPLIANCE WITH INTERNET PROTOCOL VERSION 6 (IPv6) IN ACQUIRING INFORMATION TECHNOLOGY (IPv6) (November 2016)
(a) Any system, hardware, software, firmware or networked component (voice, video or data) developed, procured or acquired in support or performance of this contract shall be capable of transmitting, receiving, processing, forwarding and storing digital information across system boundaries utilizing system packets that are formatted in accordance with commercial standards of Internet Protocol (IP) version 6 (IPv6) as set forth in the USGv6 Profile (NIST Special Publication 500-267) and corresponding declarations of conformance defined in the USGv6 Test Program. In addition, this system shall maintain interoperability with IPv4 systems and provide at least the same level of performance and reliability capabilities of IPv4 products:
(b)Specifically, any new IP product or system developed, acquired, or produced must:
(1) Interoperate with both IPv6 and IPv4 systems and products, and
(2) Have available contractor/vendor IPv6 technical support for development and implementation and fielded product management.
(c) As IPv6 evolves, the Contractor commits to upgrading or providing an appropriate migration path for each item developed, delivered or utilized at no additional cost to the Government.
(d) The Contractor shall provide technical support for both IPv4 and IPv6.
(e) Any system or software must be able to operate on networks supporting IPv4, IPv6 or one that supports both.
(f) Any product whose non-compliance is discovered and made known to the Contractor within one year after acceptance shall be upgraded, modified or replaced to bring it into compliance at no additional cost to the Government.
The instrument shall come with the software for data acquisition, processing and reporting, and the appropriate computer and required accessories should be included.
Specific Requirements:
Software:
1. Instrument control software mustallow for separate programmable runs per individual slide.
2. Instrument control software must allow for selection all slides, specified range of slides, or individual slides for label and/or barcode printing.
3. The instrument should have an automated method setup capability to allow less experienced operators to create functional methods.
4. The instrument controller must account for local Daylight Savings Time rules in the U.S. time zones.
Computer system requirements:
1. The instrument controller must have at least one current generation quad core (e.g.
Intel core i5 or better) processor running at a clock speed of 2.33 GHz or faster.
2. The instrument controller must have at least 16 gigabytes (GB) of random access memory (RAM) with an expansion capability to at least 32 GB.
3. The instrument controller must have at an internal CD/DVD ±R/RW Drive
4. The instrument controller must have a 22 inch or larger flat screen monitor, keyboard, and mouse
5. The instrument controller must have a solid state drive of at least 500 GB storage capacity on which the operating system and instrument control/data acquisition software are installed.
6. The instrument controller must have at second solid state drive in a RAID 1 configuration with a working capacity of at least 500 GB, or solid state drive mirroring capability (for automated data back-ups).
7. The instrument controller must have at least 2 USB 3.x ports out of a total of at least 6 USB ports.
Training:
1. Onsite operator training provided at the FSIS Eastern Laboratory, Athens, GA covering:
a) The use of hardware and its maintenance
b) The use of software for starting, running the instrument, and data processing
2. Training must be for up to 8 people.
Deliverables
DELIVERABLES/MILESTONES (JAN 2014)
The Contractor shall adhere to the following schedule and deliverable requirements.
Item Deliverable Name Due Date No. of Copies
Format Addressee
1 The contractor shall deliver two automated immuno stainer instruments that meet the above listed specifications, including all equipment, software, essential documents, and licenses.
Receipt at Eastern Laboratory no earlier than 30 days following the contract award date and no later than 60 days after the contract award date.
NA NA USDA FSIS OPHS
Eastern Laboratory Attn: Chrissy Brown 950 College Station Road Athens, GA 30605
2 Installation performed by a factory trained field service engineer.
Within two weeks of delivery of the instrument.
NA NA NA
3 Initial configuration of the system.
At time of installation.
NA NA NA
4 Demonstration of system specifications upon installation.
At time of installation.
NA NA USDA FSIS OPHS
Eastern Laboratory Attn: Chrissy Brown 950 College Station Road Athens, GA 30605
5 Physical copies of (1) software installation media and (2) the qualified system controller image.
At time of installation.
1 of each
DVD or Solid state USB drive
USDA FSIS OPHS
Eastern Laboratory Attn: Chrissy Brown 950 College Station Road Athens, GA 30605
6 Copies of system management and user manual(s).
At time of installation.
2 Electronic PDF file and paper formats
USDA FSIS OPHS
Eastern Laboratory Attn: Chrissy Brown 950 College Station Road Athens, GA 30605
7 User Training At time of installation.
NA Demonstr ation
USDA FSIS OPHS
Eastern Laboratory Attn: Chrissy Brown 950 College Station Road Athens, GA 30605
8 Software Line Item Pricing (if applicable) (see Software License Line Item Data (May 2018) clause (below).
Within 10 Days of Award, or Within 10 Days of Software Activation for Licenses Provided After Award Date
1 Electronic PDF file
Contracting Officer’s Representative
Performance Indicators and Standards
Performance Indicators Standards for Acceptable Performance Delivery of automated immuno stainer instruments and associated components
Instrument is received with no apparent damage and with all contracted components.
Installation and Configuration
Instrument meets manufacturer specifications for installation and operational qualification.
Sensitivity and specificity demonstration
Instruments meets or exceeds sensitivity and specificity specifications identified above in this document and those of the manufacturer.
Software installation media and system image
Installation software and system image are provided in one of the specified formats.
Management and user manual(s).
Manuals are provided in the specified formats.
User Training. Training delivered per specified requirements
Government Furnished Information or Other Resources. None
Inspections and Acceptance.
1 Inspection: The Government will review 100 percent of the deliverables.
2 Acceptance Criteria: In accordance with Section 5, Performance Indicators & Standards.
3 Written Acceptance or Rejection of Deliverables by the Government: The
Contracting Officer or Contracting Officer's Representative (COR) will provide written notice of acceptance or rejection to the Contractor within 45 days of the end of the contract period.
Reporting Requirements. The contractor shall provide to the Eastern Laboratory contact the name(s) of all contractor personnel who will be working on site NLT 2 business days prior to the initial visit.
ORGANIZATIONAL CONFLICT OF INTEREST AND LIMITATION ON FUTURE CONTRACTING
(SEPT 2008)
The following provisions are in accordance with FAR Part 9.5:
a. The U.S. Department of Agriculture (USDA), Food Safety and Inspection Service (FSIS), including any echelon or sub-echelon activity of the USDA, will not consider the Contractor, its successor-in-interest, assignee, or affiliates as a prime source of supply for, nor allow it to be a subcontractor or consultant to a supplier for, any follow-on procurement of a system, subsystem, or major component thereof, including training related thereto for which the Contractor provides technical support services, analyses, system design and evaluation or other types of assistance ordered under this contract action. For examples of a follow-on procurement, see FAR Part 9.508. These examples are not all-inclusive, but are intended to help the Contracting Officer (CO) apply the general rules in FAR Part
9.505 to individual situations.
b. The above restrictions shall be included in all subcontracts, teaming arrangements, and other agreements calling for performance of work related to this contract action, unless exempted in writing by the CO.
c. To prevent unfair competitive advantage in the procurement of any similar federal support services which are the subject of this contract action, the contractor agrees that, until award of a contract action for by FSIS for any of these services it: (1) shall not disclose any information concerning the work under this contract action, including technology developed or findings and conclusions rendered by the Contractor in performing this contract action, to any prospective Contractor; and (2) shall not render any services of any kind related to this procurement to any prospective Contractor.
d. If, under the scope of this contract action, the Contractor is required to prepare a SOW or to design or develop specifications/requirements which are to be incorporated or used in a solicitation for future acquisition of a system, subsystem, or major component thereof relating to the subject matter of this contract action, the USDA, including any echelon or sub-echelon activity, will not consider the Contractor, its successor-in-interest, assignee, or affiliates as a prime source of supply for, nor allow it to be a subcontractor or consultant to a supplier for the procurement of the system, subsystem, or major component thereof. The Contractor, subcontractors and consultants at any tier have an affirmative duty to disclose to the CO actual, potential or apparent conflicts whenever there is reason to believe such exist or will exist.
e. The restrictions and provisions of paragraph (d), above, shall be in effect for a period of two years from the performance completion date of this contract action. At any time subsequent to the effective date of this contract action, the Government may either modify the restrictions of paragraphs (c), and (d), or waive the restrictions entirely if it is determined to be in the best interests of the Government.
The restrictions contained herein do not limit the restrictions delineated in FAR Part 9.5.
CONTRACTING OFFICER (JAN 2012)
The Contracting Officer (CO) has the overall responsibility for the administration of this contract. The CO alone, without delegation, is authorized to take actions on behalf of the Government to amend, modify or deviate from the contract terms, conditions, requirements, specifications, details and/or delivery schedules; issue task orders against the contract; make final decisions on disputed deductions from contract payments for nonperformance, or unsatisfactory performance; terminate the contract for convenience or default; and issue final decisions regarding contract questions or matters under dispute. However, the CO may delegate certain other responsibilities to the Contracting Officer’s Representative (COR). All delegated duties will be specified in writing by a COR Appointment and Delegation Notice.
DESIGNATION OF CONTRACTING OFFICER’S REPRESENTATIVE (JAN 2012)
The Contracting Officer hereby designates as the Contracting Officer’s Representative (COR):
[TO BE DESIGNATED UPON AWARD]
The COR shall be responsible for administering the performance of work under this contract. In no event, however, will any understanding, agreement, modification, change order, or other matter deviating from the terms of this contract be effective or binding upon the Government unless formalized by proper contractual documents executed by the Contracting Officer prior to completion of the contract.
The Contracting Officer shall be informed as soon as possible of any actions or inactions by the Contractor or the Government which will change the required delivery or completion times stated in the contract, and the contract shall be modified accordingly.
On all matters that pertain to the contract terms, the contractor shall communicate with the Contracting Officer. Whenever, in the opinion of the Contractor, the COR requests effort outside the scope of the contract, the contractor shall so advise the COR. If the COR persists and there still exists a disagreement as to proper contractual coverage, the Contracting Officer shall be notified immediately, preferably in writing if time permits. Proceeding with work without proper contractual coverage may result in nonpayment or necessitate submittal of a contract claim.
The COR shall be responsible for initiating the Contractor Performance Assessment Report (CPAR) for awards over the simplified acquisition threshold of $150K to document contractor’s performance during the period of performance 14 days after completion of services or delivery of goods.
UNAUTHORIZED PERFORMANCE OF SERVICES (MAY 2011)
(a) No personal services shall be performed under this contract. No Contractor employee will be directly supervised by the Government. All individual employee assignments, and daily work direction, shall be given by the applicable employee supervisor. If the Contractor believes any Government action or communication has been given that would create a personal services relationship between the Government and any Contractor employee, the Contractor shall promptly notify the Contracting Officer of this communication or action.
(b) The Contractor shall not perform any inherently Government actions under this contract. No Contractor employee shall hold him or herself out to be a Government employee, agent, or representative. No Contractor employee shall state orally or in writing at any time that he or she is acting on behalf of the Government. In all communications with third parties in connection with this contract, Contractor employees shall identify themselves as Contractor employees and specify the name of the company for which they work.
(c) The Contractor shall ensure that all of its employees working on this contract are informed of the substance of this clause. Nothing in this clause shall limit the Government's rights in any way under any other provision of the contract, including those related to the Government's right to inspect and accept the services to be performed under this contract. The substance of this clause shall be included in all subcontracts at any tier.
REPRESENTATIONS, CERTIFICATIONS AND OTHER STATEMENTS OF OFFEROR (FEB 2007)
In accordance with FAR 15.204-1(b), the completed and submitted “Representations, Certifications, and Other Statements of Offeror”, are incorporated by reference in this resulting contract.
Section 508 – Accessibility of Information and Communications Technology
(a) This SOW is subject to Section 508 of the Rehabilitation Act of 1973 (29 U.S.C. 794d) as amended by the Workforce Investment Act of 1998 (P.L. 105-220). Specifically, subsection 508(a)(1) requires that when the Federal Government procures Information and Communications Technology (ICT)1, the ICT must allow Federal employees and members of the public with disabilities comparable access to and use of information and data provided to Federal employees and members of the public without disabilities.
(b) The ICT accessibility standards as 36 CFR Part 1194 were developed by the Architectural and Transportation Barriers Compliance Board (also known as the Access Board) and apply to contracts, task orders, and indefinite quantity contracts on or after June 25, 2001.
(c) Each Information and Communications Technology (ICT) product or service furnished under this contract shall comply with the Information and Communications Technology Accessibility Standards (36 CFR 1194), as specified in the contract, at a minimum. If the Contracting Officer determines any furnished product or service is not in compliance with the contract, the Contracting Officer will promptly inform the Contractor in writing. The Contractor shall, without charge to the Government, repair or replace the non-compliant products or services within a period of time specified by the Government in writing. If such repair or replacement is not completed within the time specified, the Government shall have the following recourses:
1) Cancellation of the contract, delivery, or task order, purchase or line item without termination liabilities; or
2) In the case of custom Information and Communications Technology (ICT) being developed by a contractor for the Government, the Government shall have the right to have any necessary changes made or repairs performed by itself or by another firm for the non-compliant ICT, with the contractor liable for reimbursement to the Government for any expenses incurred thereby.
(d) The contractor must ensure that all ICT products and services that are less than fully compliant with the accessibility standards are provided pursuant to extensive market research and are the most current compliant products or services available to satisfy the contract requirements.
(e) For every ICT product or service accepted under this contract by the Government that does not comply with 36 CFR 1194, the contractor shall, at the discretion of the Government, make every effort to replace or upgrade it with a compliant equivalent product or service, if commercially available and cost neutral, on either a contract specified refresh cycle for the product or service, or on a contract effective option/renewal date, whichever shall occur first.
Section 508 Compliance The Vendor and any Software Application shall comply with the standards, policies, and procedures below. In the event of conflicts between the referenced documents and this SOW, the SOW shall take precedence.
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
1 Please note that the term Information and Communications Technology (ICT) is synonymous with Electronic and Information Technology (EIT), the previously used term. The term ICT will be used to meet international standards after the release of the Section 508 Refresh.
3) http://www.access-board.gov/sec508/508standards.htm (Section 508 standards)
4) FAR 39.2 (Section 508)
5) http://www.ocio.usda.gov/document/departmental-regulation-4030-001 (USDA standards, policies, and procedures for Section 508)
In addition, all contract deliverables are subject to these standards.
All web content or communications materials produced, regardless of format (text, audio, video, etc.), must conform to the applicable Section 508 standards to allow Federal employees and members of the public with disabilities comparable access to and use of information and data provided to Federal employees and members of the public without disabilities. All contractors (including sub-contractors) and consultants responsible for preparing or posting content must comply with the applicable Section 508 accessibility standards and, where applicable, those set forth in the referenced policy or standards document above. Remediation of any materials that do not comply with the applicable provisions of 36 CFR Part 1194 as set forth in the SOW shall be the responsibility of the contractor or consultant.
The following Section 508 provisions apply to the products and/or services identified in this SOW:
• 36 CFR Part 1194.21 provisions a-l
• 36 CFR Part 1194.22 provisions a-p
• 36 CFR Part 1194.23 provisions a-k[4]
• 36 CFR Part 1194.24 provisions a-e
• 36 CFR Part 1194.25 provisions a-j[4]
• 36 CFR Part 1194.26 provisions a-d
• 36 CFR Part 1194.31 provisions a-f
• 36 CFR Part 1194.41 provisions a-c
The following Section 508 provisions apply for software development material identified in this
SOW:
For software development, software applications, and operating systems the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
a. 36 CFR Part 1194.21 provisions a-l
b. 36 CFR Part 1194.31 provisions a-f
c. 36 CFR Part 1194.41 provisions a-c
For web-based applications (intranet, internet information and applications, 16 rules), the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
a. 36 CFR Part 1194.21 provisions a-l
b. 36 CFR Part 1194.22 provisions a-p
c. 36 CFR Part 1194.31 provisions a-f
d. 36 CFR Part 1194.41 provisions a-c
For telecommunication products and services the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards) http://www.access-board.gov/sec508/508standards.htm http://www.ocio.usda.gov/document/departmental-regulation-4030-001
a. 36 CFR Part 1194.23 provisions a-k
b. 36 CFR Part 1194.31 provisions a-f
c. 36 CFR Part 1194.41 provisions a-c
For video and multimedia applications (including training materials), the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
a. 36 CFR Part 1194.24 provisions a-e
b. 36 CFR Part 1194.31 provisions a-f
c. 36 CFR Part 1194.41 provisions a-c
For self-contained and closed products, the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
a. 36 CFR Part 1194.21 provisions a-l
b. 36 CFR Part 1194.25 provisions a-j
c. 36 CFR Part 1194.31 provisions a-f
d. 36 CFR Part 1194.41 provisions a-c
For desktop and portable computers, the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
a. 36 CFR Part 1194.21 provisions a-l
b. 36 CFR Part 1194.26 provisions a-d
c. 36 CFR Part 1194.31 provisions a-f
d. 36 CFR Part 1194.41 provisions a-c
For help desk and other support services, the Contractor shall comply with the following standards, policies, and procedures:
Section 508 Accessibility Standards
1) 29 U.S.C. 794d (Rehabilitation Act as amended)
2) 36 CFR 1194 (Section 508 standards)
a. 36 CFR Part 1194.31 provisions a-f
b. 36 CFR Part 1194.41 provisions a-c
If the help desk or other support services include training, Contractor must also comply with the following standards, policies, and procedures in addition to 36 CFR Part 1194.31 provisions a-f and 36 CFR Part 1194.41 provisions a-c:
a. 36 CFR Part 1194.21 provisions a-l (installable and web-based training)
b. 36 CFR Part 1194.22 provisions a-p (web-based software)
All Information and Communications Technology (ICT) subject to the 36 CFR 1194 standards will have a Section 508 usability and acceptance test where Section 508 compliance will be validated.
This test must be administered by a Federal Section 508 Testing Center.
All maintenance for Information and Communications Technology that requires upgrades, modifications, installations, and purchases will adhere to the Section 508 standards and 36 CFR 1194.
POST-AWARD ADMINISTRATION AND MONITORING OF SECTION 508 COMPLIANCE
ACCESSIBILITY OF ELECTRONIC AND INFORMATION TECHNOLOGY ACCESSIBILITY (MAY
2015) The Section 508 Plan/Remediation Plan and any modifications to the Plan must be submitted for approval to the Office of the Chief Information Officer (OCIO) or the Department OCIO when the proposed requirement is for, or includes, the acquisition of EIT products and services that are subject to Section 508 conformance provisions as required by departmental and federal requirements. Any exception must be documented and approved by OCIO.
ACCESS TO SENSITIVE INFORMATION (FEB 2007)
(a) As used in this clause, “sensitive information” refers to information that a contractor has developed at private expense, or that the Government has generated that qualifies for an exception to the Freedom of Information Act, which is not currently in the public domain, and which may embody trade secrets or commercial or financial information, and which may be sensitive or privileged.
(b) To assist the U. S. Department of Agriculture (USDA), Food Safety and Inspection Service (FSIS) in accomplishing management activities and administrative functions, the Contractor shall provide the services specified elsewhere in this contract.
(c) If performing this contract entails access to sensitive information, as defined above, the Contractor agrees to -
(1) Utilize any sensitive information coming into its possession only for the purposes of performing the services specified in this contract, and not to improve its own competitive position in another procurement action.
(2) Safeguard sensitive information coming into its possession from unauthorized use and disclosure.
(3) Allow access to sensitive information only to those employees that need it to perform services under this contract.
(4) Preclude access and disclosure of sensitive information to persons and entities outside of the Contractor’s organization.
(5) Train employees who may require access to sensitive information about their obligations to utilize it only to perform the services specified in this contract and to safeguard it from unauthorized use and disclosure.
(6) Obtain a written affirmation from each employee that he/she has received and will comply with training on the authorized uses and mandatory protections of sensitive information needed in performing this contract.
(7) Administer a monitoring process to ensure that employees comply with all reasonable security procedures, report any breaches to the Contracting Officer, and implement any necessary corrective actions.
(d) The nature of the work on this contract may subject the Contractor and its employees to a variety of laws and regulations relating to ethics, conflicts of interest, corruption, and other criminal or civil matters relating to the award and administration of government contracts.
Recognizing that this contract establishes a high standard of accountability and trust, the Government will carefully review the Contractor’s performance in relation to the mandates and restrictions found in these laws and regulations. Unauthorized uses or disclosures of sensitive information may result in termination of this contract for default, or in debarment of the Contractor for serious misconduct affecting present responsibility as a government contractor.
(e) The Contractor shall include the substance of this clause, including this paragraph (e);
suitably modified to reflect the relationship of the parties, in all subcontracts that may involve access to sensitive information.
INFORMATION TECHNOLOGY SYSTEMS SECURITY (SEPT 2013)
The activities covered under by this contract shall require the Contractor’s access to Federal Automated Information System or systems, as well as the implementation of new systems. The Offeror’s proposal must include:
(1) A detailed outline (commensurate with the size and complexity of the Statement of Work) of its present and proposed information technology systems security program.
The response must demonstrate that it complies with the security requirements of the SOW, the Federal Information Security Management Act of 2002 (FISMA, Public Law 107-347, 44 U.S.C. 3531-3536); Office of Management and Budget (OMB) Circular A-130, Appendix III “Security of Federal Automated Information Systems” (http://www.whitehouse.gov/omb/circulars_a130_a130appendix_iii) and an acknowledgement of its understanding of the security requirements of the SOW.
(2) A signed copy of the USDA FSIS IT Rules of Behavior shall be included with the Offeror’s proposal.
INFORMATION TECHNOLOGY SYSTEMS SECURITY CONTRACT REQUIREMENTS (JAN 2012)
The contractor shall establish and implement appropriate administrative, technical and physical safeguards to ensure the security and confidentiality of sensitive Government information, data, and/or equipment.
The contractor shall comply with IT systems security and/or privacy specifications set forth in FSIS and USDA directives, policy, and procedures; the Computer Security Act of 1987; Office of Management and Budget (OMB) Circular A-130; and the Federal Information Security Management Act of 2002 (FISMA).
Pursuant to FSIS policy, the contractor shall be responsible for assuring that each contractor employee who requires routine unaccompanied physical access to a Federally-controlled facility and/or unaccompanied access to a Federally-controlled information system, including an FSIS-issued computer, completes Computer Security Awareness training prior to performing any work under this contract.
The contractor is required to maintain a listing of all individuals who have completed Computer Security Awareness training and submit this listing to the COR with a copy to the Contracting Officer within ten (10) calendar days of an individual starting work on this contract.”
ADDITIONAL PRIVACY ACT REQUIREMENTS (JAN 2012)
For contracts that are awarded with Federal Acquisition Regulations (FAR) and Agriculture Acquisition Regulations (AGAR) concerning the Privacy Act, Food Safety and Inspection Service (FSIS) requests that contractor employees complete Privacy Act training. Contractor employees may take the course at any place of their choice. An acceptable course is one that covers the basics of the Privacy Act. A certificate that shows completion of training is to be provided to the Contracting Officer’s Representative (COR).
Contractor employees are to complete at least one Privacy Act training course within thirty days after contract award and at least once each year thereafter. USDA offers free Privacy Act training for contractor employees that have a current contract. Contractor employees must be assigned to a current contract that is subject to the Privacy Act to receive the free training. The Contracting Officer (CO) and/or COR can be contacted for further information on procedures for Privacy Act training.
SCIENTIFIC INTERGRITY TRAINING (APR 2017)
In accordance with the United States Department of Agriculture (USDA) Department Regulation 1074-001 for contracts that are awarded in accordance with Federal Acquisition Regulations (FAR) and Agriculture Acquisition Regulations (AGAR), the FSIS requests that contractor employees complete at least one Scientific Integrity training course within ninety (90) days after contract award.
Contractor employees must be assigned to a current FSIS contract to receive the free training.
Contractor employees may take the course at any place of their choice. An acceptable course is one that issued to the contractor employee through the USDA AgLearn training system. A certificate issued by AgLearn showing completion of training is to be provided to the Contracting Officer’s Representative (COR). The COR and/or Contracting Officer (CO) can be contacted for further information on procedures for Scientific Integrity training.
RULES OF BEHAVIOR FOR PRIVILEGED USERS (FEB 2006)
Food Safety and Inspection Service (FSIS) Information Technology (IT) Security
Rules of Behavior for Privileged Users Version 1.0
February 10, 2006
Introduction
Purpose The intent of the FSIS Rules of Behavior (ROB) for Privileged Users is to recognize the additional responsibilities associated with special access to, and/or privileges associated with, computer resources within the Department or its offices/bureaus/components. The ROB for Privileged Users are in addition to the Computer System User IT Security General ROB to which all DOJ users are subject. The identification of these responsibilities originates in OMB A-130 and is included in the FSIS IT Security Standards.
“Privileged User” defined:
A privileged user is someone authorized access to departmental/office/bureau/component computer resources when that access provides the capability to alter the properties, behavior or control of the information system/network. It includes, but is not limited to, any of the following types of access:
a. “Super user,” “root,” or equivalent access, such as access to the control functions of the information system/network, administration of user accounts, etc.
b. Access to change control parameters (e.g., routing tables, path priorities, addresses) of routers, multiplexers, and other key information system/network equipment or software.
c. Ability and authority to control and change program files, and other users’ access to data.
d. Direct access to operating system level functions (also called unmediated access) that would permit system controls to be bypassed or changed.
e. Access and authority for installing, configuring, monitoring or troubleshooting the security monitoring functions of information systems/networks (e.g., network/system analyzers;
intrusion detection software; firewalls) or in performance of cyber/network operations.
Who is covered by these rules?
These rules extend to all privileged users (FSIS employees and contractors) who use any computing resources that support the mission and functions of the Food Safety and Inspection Service. All privileged users will review and provide signature or electronic verification to these rules annually, or upon change of assigned responsibilities, whichever occurs first.
What are the penalties for Noncompliance?
Compliance with these rules will be enforced through sanctions commensurate with the level of infraction. Actions may include a verbal or written warning, removal of system access for a specific period of time, reassignment to other duties, or termination, depending on the severity of the violation.
In addition, activities that lead to or cause the disclosure of classified information may result in criminal prosecution under the U.S. Code, Title 18, Section 798, and other applicable statutes.
Responsibilities Complying Privileged Users will:
1. Understand that it is their responsibility to comply with all security measures necessary to prevent the unauthorized disclosure, modification, or destruction of information; follow appropriate system security policies, guidelines and procedures
2. Agree to the FSIS General Rules of Behavior.
3. Minimize exposure and risk by utilizing a separate account to perform privileged functions from general user functions.
4. Not establish or reset any account utilizing the same password for more than one account, and will not provide the user name and password at the same time through the same medium.
5. Grant read or write authority no higher than is granted to him/her (e.g., a component level user administrator shall not assign department level access to another user administrator).
6. Access application programs only for the purpose of creating or maintaining files.
7. Not make modifications to system configurations that could impact availability or security of the system without the approval of the Change Control Board and/or change management process.
8. Not perform general user activities under the same account (user name and password) due to the security requirement for separation of duties.
9. Protect all passwords from unauthorized disclosure.
10. Not share accounts with another privileged user.
11. Make the system available at any time to the SAISO for inspection and review of audit logs.
12. Grant only read-only access to audit files to the Security Auditor; grant access to general system information only if a need-to-know is established and authorization is received from the ISSO.
13. Make the computer(s) available for periodic reviews of the security configuration by independent testers
14. Make changes to system configuration as directed to meet Vulnerability and Patch Management requirements.
15. Immediately record and report any security incidents to the ISSPM.
I acknowledge and understand the responsibilities associated with my role as a Privileged User, and I will comply with the February 10, 2006, Privileged User Rules of Behavior. The Statement of acknowledgement can be provided via email.
Typed Name
Questions for Vendors Concerning Windows 10 Instrument Controllers
20 Feb 2020 – Frank Niagro – 706-546-2370 – ferank.niagro@usda.gov
Instructions to Vendor: Any delivered computer must have the Windows 10 or a Linux desktop operating system. Please answer the following questions concerning any proposed Windows 10 instrument controller proposals.
1. Will a Microsoft Windows-based computer be required for operation of the instrument, data storage, data processing, or data analysis/reporting?
1.a. If a Windows-based computer is required, will it be provided as part of the instrument deliverables?
1.a.(1) If not provided, the instrument control and data acquisition/processing/analysis software must run on a USDA-FSIS USGCB standard image notebook computer (currently a HP x360 notebook PC). Will the software run on a USDA-FSIS USGCB standard image computer?
1.a.(2) If the computer is provided with the instrument, please answer the following questions.
2. Will the Windows 10 controller be externally attached (i.e., a connected PC) or embedded in the instrument?
2. a. If externally connected, what will be the make and model of the PC hardware?
2. b. If externally connected, what will be the connection interface to the instrument (e.g., RS-232 via cable with DB-25 connector and standard pin-outs)?
3. What (a) edition and (b) version of Windows 10 will be installed on the delivered controller?
4. What instrument-related software will be installed on the Windows 10 controller? (provide software name and version for each)
Software Name Software Version or Build
5. Will the Windows 10 controller meet the requirements of Section 508 of the Americans With Disabilities Act? (ADA – See the https://www.section508.gov web site for details)
6. Will the Windows 10 controller be compliant with the US Government Configuration Baseline?
(USGCB – see the https://csrc.nist.gov/projects/united-states-government-configuration-baseline web site for details)
7. Can the Windows 10 controller be connected to the USDA-FSIS network without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
8. Can the Windows 10 controller be joined to the USDA-FSIS Active Directory domain without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
https://www.section508.gov/ https://csrc.nist.gov/projects/united-states-government-configuration-baseline
9. Can the Windows 10 controller be renamed according to the USDA-FSIS computer naming convention without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
10. Can the Symantec Endpoint Protection (SEP - https://www.symantec.com/products/endpoint) anti-malware application be installed and operational on the Windows 10 controller without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
11. Can the LabWare LIMS-ELN software application (https://www.labware.com) be installed and operational on the Windows 10 controller without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
12. Will the Windows 10 controller be provided free of bloatware and other software that is not needed for instrument control, data analysis, or other user functions?
13. Will a PDF viewer application be installed on the Windows 10 controller?
13. a. If a PDF viewer application is needed/installed on the Windows 10 controller for viewing instrument manuals, output files, or other documents needed for instrument operation or maintenance, will it be Adobe Acrobat Reader DC?
14. Will any Microsoft Office applications (e.g., Excel) be installed on the Windows 10 controller?
14. a. If a Microsoft Office application will be installed on the Windows 10 controller PC, will the software version be Office 365 or Office 16?
15. Can the Windows 10 controller PC be connected to the USDA-FSIS network and scanned for security vulnerabilities without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
16. Can the Windows 10 controller PC be connected to the USDA-FSIS network and scanned for installed software without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
17. Can the NovaStor (https://www.novastor.com/) backup software be used to perform automated backup of instrument data across a connected network without invalidating the instrument manufacturer’s IQ and OQ, or other support for the instrument and controller?
18. What are the formats (e.g., relational database, Excel file, text file, Portable Document File, etc.)
for storage of (a) instrument run data and (b) result data?
19. Does the instrument conform to the Analytical Information Markup Language (AniML) standard (https://animl.org/)?
20. What computer peripheral types (e.g., LCD display, printer) will be provided with the deliverables?
Peripheral Type Make Model https://www.symantec.com/products/endpoint https://www.labware.com/ https://www.novastor.com/ https://animl.org/
| Performance Indicators and Standards |
| Inspections and Acceptance. |
| Reporting Requirements. The contractor shall provide to the Eastern Laboratory contact the name(s) of all contractor personnel who will be working on site NLT 2 business days prior to the initial visit. |
| Section 508 – Accessibility of Information and Communications Technology |
| Section 508 Compliance |
| Introduction |
| Purpose |
Responsibilities
File details come from the government source that posted it. Updated .