Section 3 - STATEMENT OF WORK AND FUNCTIONAL REQUIREMENTS.xlsx

XLSX spreadsheet 54 KB Posted

Attached to
DIN-PACS III Federal contract opportunity
Solicitation number
SPM2D1-10-R-0011
Issued by
Defense Logistics Agency Troop Support Medical

View the file

Other files for this federal contract opportunity

Other files attached to DIN-PACS III, newest first.
File Type Posted
SPM2D1-10-R-0011-0008.pdf PDF
SF_30_SPM2D1-10-R-0011_0005.pdf PDF
Amendment_0006.pdf PDF
SPM2D1-10-R-0011-0004.pdf PDF
Amendment_0005.pdf PDF
SPM2D1-10-R-0011-0003.pdf PDF
Amendment 0002.pdf PDF
AMEND 0001 - SPM2D1-10-R-0011.pdf PDF
SPM2D1-10-R-0011 - DIN-PACS III SOLICITATION.pdf PDF
DINPACS III Contractor Price book Spreadsheet.xlsx XLSX spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Section 3

TABLE OF CONTENTS
TAB AVENDOR QUALIFICATIONS
TAB BPACS PRODUCT OVERVIEW
TAB CVENDOR CONFIGURATION RESPONSE
TAB DSYSTEM FUNCTIONALITY
TAB ESYSTEM ACCEPTANCE
TAB FSYSTEM RELIABILITY
TAB GSYSTEM MAINTENANCE
TAB HREPAIR PARTS STRATEGY
TAB ISYSTEM DOCUMENTATION AND TRAINING
TAB JDICOM REQUIREMENTS
TAB KTELERADIOLOGY
TAB LSYSTEM SECURITY
VENDOR RESPONSE CODES
CodeDescription
CCurrent product fully complies.
PNot part of current product, but planned in a scheduled release. Vendor shall indicate the time frame when requirement will be available.
OOptional capability that can be provided at an additional charge, either as an optional feature, 3rd party option, or as a special order development.
XRequirement is neither available nor planned by the Vendor.
note: Please add your company name to footer.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB A

TAB A VENDOR QUALIFICATIONS

Please describe:Description
A1Overall company and description of DIN-PACS product line.
A2Does your company have a history with integrating the proposed PACS soution with various Government and commercial RIS? Response should be very specific to CHCS if the vendor has such experience.
A3Company/Product Literature – Please enclose company and product literature which highlights the company’s stability and position in the industry, as well as formal product literature for each item offered.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB B

TAB B PACS PRODUCT OVERVIEW

Please describe:Description
B1Briefly describe sites where the product is installed in an enterprise–distributed radiology environment.
B2Please describe what business partners your solution uses to provide the total solution.
B3Briefly list and describe all sites, in the DoD or VA where your PACS product is installed.
B4Briefly list and describe your commercial client references – minimum of five (5) (i.e. installed base of equipment) – Please include a point of contact and phone number for each listing

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB C

TAB C VENDOR CONFIGURATION RESPONSE

Compliance StatusDescription
C1Network Proposal – If requested at a specific site, the Vendor will be required to assess the capability of the existing hospital network to support the DIN-PACS, and provide recommendations for network upgrades, supplements, etc.. to the Government.
The requested proposal shall identify necessary augmentation or reconfiguration to provide maximum capability of the PACS.
The Vendor may also be required to review PACS network augmentation designs to be installed (at the Government’s request) by a third party, and validate that the proposed PACS will optimally perform over this network.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB D

TAB D SYSTEM FUNCTIONALITY

Compliance StatusDescription
D1A mechanism shall be provided to permit a system administrator to age patient records out of the database (for example, to remove records after twenty-seven years or after the age of majority of the patient).
D2The database shall support, as a minimum, ad hoc queries using search criteria based on the values, or range of values, of Table 1 data items, combined using logical operators, and with the ability to sort results. The purpose of this requirement is to assure that worklist query and administrative report queries can be constructed to support a range of needs.
TABLE 1
DICOM Attribute Name (Searchable Item)DICOM Tag
Patient’s Name(0010, 0010)
Patient ID(0010,0020)
Accession Number(0008,0050)
Requesting Service(0032, 1033)
Requested Procedure Code Sequence(0032, 1064)
Study Time(0008,0030)
Study Date(0008,0020)
Study ID(0020,0010)
Study Description(0008,1030)
Study Status ID(0032,000A)
Study Priority ID(0032,000C)
Interpretation Status ID(4008, 0212)
Modality(0008, 0060)
Body Part(0018, 0015)
Interpretation Diagnosis Code Sequence(4008, 0117)
Institutional Department Name(0008,1040)
Patient’s Institution Residence(0038,0400)
Placer Order Number (DMIS ID)(0040,2016)
D2.1The database must support a direct DICOM Query/Retrieve.
D3Storage System In this document, the term “storage system” refers to on-line storage for rapid access to exams. The basic element of storage and retrieval for the storage system shall be the exam. An “exam” includes both images and associated reports.
D3.1The Vendor shall describe their alternatives for storage systems. In particular, the Vendor should address the scalability of their storage system and the rationale behind their storage system selection, sizing, and architecture. All known limits on capacity of the storage system should be addressed.
D3.2The system shall not store an image in the storage system with non-reversible compression before the diagnosis of the exam of which the image is a part is complete.
D3.3The system shall make an exam available for retrieval by workstations within one minute of its receipt in the storage system.
D3.4The system shall not automatically delete from the storage system an exam until space for new exams is required.
D3.5The system shall select exams for automatic deletion from the storage system in order of priority as follows:
D3.5.1retrieved exams not associated with other exams
D3.5.2retrieved exams associated with exams for which the primary diagnosis is complete
D3.5.3archived exams for which the primary diagnosis is complete
D3.5.4retrieved exams associated with exams for which the primary diagnosis is not complete
D3.5.5archived exams for which the primary diagnosis is not complete.
D3.6The policy for automatic deletion of exams from the storage system shall be re-configurable by the system administrator.
D3.7The storage system shall monitor usage and provide real-time display to authorized administrative level users of usage patterns and statistics.
D3.8The storage system shall remain operational during the service required to correct a failed disk drive.
D3.9the storage system shall provide a means for notifying the system administrator in the event of a failure in the storage system. The use of SNMP for this function is preferred but not required. It is highly desired that this notification be provided automatically by the system (i.e. passive).
D3.10The Storage System shall be completely redundant, and shall support mirroring and hot swappable technology for failsafe operation without interruption.
D3.10.1Vendor shall describe RAID or alternative strategy for redundancy. Shall explain how failover occurs and define whether it is automated or requires IT staff involvement.
D4In this document, the term “archive” refers to storage for long-term access to images.
D4.1The PACS archive must be configurable to allow for the storage of “Lossless” and “Lossy” compressed images
Note: Lossy compressed images must display a notice indicating the use of Lossy Compression for archiving.
D4.2Vendor shall offer various alternative solutions for a PACS archive.
D4.3The archive system shall retrieve exams in response to ad hoc requests from users at workstations.
D4.4The archive system shall monitor usage and provide real-time display of usage patterns and statistics.
D4.5The system shall allow the user to designate for the archive, by modality, a compression algorithm that may include lossy and other configurable parameters to be used in archiving exams for that modality.
D4.6The Vendor shall guarantee that the archive system will be supported with media, spare parts, and service for at least seven years from the acceptance date, or guarantee a replacement strategy at no cost to Government.
D4.7Vendor is encouraged in their proposal to offer various Enterprise Storage Solutions. Vendors shall discuss various enterprise storage solutions being offered.
D5Information System Interface
CHCS will remain the primary site of data entry. The PACS must accept radiology orders, changes and updates to radiology orders, radiology reports/amendments, ADT messages, and Master File updates of radiology procedures, Master File updates of radiology locations, and Master File updates of users.
D5.1The vendor shall be able to accept HL7 messages from CHCS (uni-directional CHCS interface). In the future CHCS may be able to accept messages from the PACS (bi-directional CHCS interface).
D5.2Vendors are expected to support industries Integrating the Healthcare Enterprise (IHE) initiative as it evolves.
D6Image Display Workstations. The PACS shall support a variety of PACS workstations, with a variety of configurations for the primary reading and diagnosis, clinical review, and quality control of radiology studies.
D7Monitors
It is generally assumed that the vendor will respond with LCD flat panel technology display monitors. However, vendors are encouraged to propose alternatives as long as such alternatives are either optional or planned workstation developments, and performance requirements either meet or exceed those defined for LCD flat panel technology.
D7.1All monitors must meet the American Association of Physicist in Medicine (AAPM), Task Group 18 performance recommendations for Medical Displays.
D7.2All monitors must comply with the Video Electronics Standards Association (VESA) flat panel display measurements standards version 2.0
D7.3All monitors must have the capability to be calibrated to the DICOM Grayscale Standard Display Function, Part 14.
D7.4All monitors must comply with ISO 13406-2:201, Ergonomic Requirements for work with Visual Display based on Flat Panels. Part 2: Ergonomic Requirements for Flat Panel Displays (ISO 2001) standards.
D7.5Configuration
D7.5.1Workstation monitors shall display no fewer than 1024 shades of gray (10 bit depth).
D7.5.2Maximum monitor brightness shall be greater than or equal to 500 candela per meter squared (cd/m2) for primary monitors, 400 cd/m2 for secondary monitors and 600 cd/m2 for mammography monitors.
D7.5.3The monitor shall equal to or less than 15% brightness uniformity degradation from the center to the periphery.
D7.5.4he monitor shall have less than 3% nonlinearity from center to periphery.
D7.5.5The monitor shall have less than 2% geometric distrotion for primary monitors and 5% geometric distrotion for secondary monitors from center to periphery.
D7.5.6The electron beam spot size shall vary less than 20% from the center to any corner of a rectangle 1/2" inside the perimeter of the monitor.
D7.5.7The number of defective pixels per million shall not exceed the perameters defined in ISO 13406-2.
D7.5.8Vendor shall provide a description and specifications for the proposed Primary monitors including; Spatial Resolution and Diagonal Screen Dimensions for each of the following:
- Grayscale Flat Panel Monitors
- Color Flat Panel Monitors
D7.5.9Vendor shall provide a description and specifications for the proposed Secondary monitors including; Spatial Resolution and Diagonal Screen Dimensions for each of the following:
- - Grayscale Flat Panel Monitors
- Color Flat Panel Monitors
D7.6Monitor Calibration
D7.6.1Brightness and contrast adjustment range of the monitors shall support matching of the monitor grayscale displays on a workstation to less than 10%.
D7.6.2The three-month drift of monitor brightness and contrast shall be less than 5%.
D7.6.3All monitors will be calibrated in conformance to the performance requirements of the NEMA Standard on Gray-Scale Display Function.
D7.6.4The vendor shall supply a QC procedure and all required images and calibration equipment to assure that the test and calibration requirements in this Section are met.
D7.6.5The monitors viewing angel shall be greater than 140o horizontal and 140o vertical.
D7.6.6The angular performance of the monitor shall not reduce the luminance ratio by more than 30% within the operating ranges of the viewing angles.
D7.6.7The contrast response for any viewing angle shall not be greater than three times the expected limits on axis. (30% for diagnostic displays and 60% for clinical displays)
D7.6.8With their “Notice of Readiness to Inspect”, prior to the start of acceptance testing, Vendors will submit their calibration procedures, calibration data, and any associated log files to the Government or the Government’s representative.
D7.6.9All color monitors must be capable of being calibrated to a consistent color temperature.
D7.7Mammographic Monitors
D7.7.1Monitors used for mammographic displays shall meet regulatory requirements for quality assurance under the Mammography Quality Standards Act (MQSA) (21 CFR 900).
D7.7.2Mammographic monitors shall have no visual pixel defect artifacts.
D8Work Station Performance
D8.1The workstation shall display one 2K x 2.5K x 2byte image filling one monitor in two seconds.
D8.2The workstation shall display all the 512 x 512 x 2 byte images at original resolution to fill a monitor in two seconds.
D8.3The workstation shall meet D.8.1 and D.8.2 for each monitor in an exam filling several monitors.
D8.4The workstation shall display the first 20 results of any query of the system database within two seconds, 95% of the time. Display time is measured from the time the user completes selection of the query (e.g., worklist selection) until the 20th result is visible on the monitor.
D8.5The workstation shall display the report on a selected exam within four seconds of the request, 90% of the time. Display time is measured from the time the user initiates the request (for example, through selection of the exam) until the report is visible on the monitor.
D9Exams, Folders, Worklists, and Queries
D9.1It is desired that a mechanism be provided to permit a user with proper privileges to select images or exams for inclusion into one or more manually created folders for teaching and research purposes.
D10Image Display and Paging
D10.1The workstation shall provide a function to display the entire contents of the DICOM header for a selected image.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB E

TAB E SYSTEM ACCEPTANCE (SEE APPENDIX 5)

Compliance StatusDescription
E1System Acceptance Testing will be conducted in accordance with the Government’s Acceptance Testing (AT) Protocol (or other protocol if mutually agreed upon by both the Government and Contractor); the most current version available at the time of acceptance testing. A copy of the current version of this AT Protocol is available from the Contracting Officer.
E2Other systems or equipment items purchased from this contract, and not covered under the Government’s DIN-PACS AT protocol (e.g. Computed Radiography, Film Digitizers, etc.) may be tested by the Government. Systems will be tested per manufacturer’s commercial testing protocols unless an appropriate Government testing protocol is available. The following is a listing of currently available Government testing protocols for items available for purchase under this contract:
Computed Radiography (CR) Acceptance Testing Protocol.
A copy of the current version of this CR Acceptance Testing Protocol is available from the Contracting Officer.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB F

TAB F SYSTEM RELIABILITY (SEE APPENDIX 6)

Compliance StatusDescription
F1The Vendor will comply with the Government's system reliability requirements per Section H, Paragraph 2 of the Solicitation.
F2The system shall be designed with reasonable redundancy so that no single point of failure can cause a major breakdown of radiology service.
F3The system shall protect against the loss of acquired images and data.
F4If a failure interrupts or disables image acquisition, the system shall provide a means to enter the missed images from the imaging equipment at a later time.
F5Where appropriate to guarantee against loss of image or exam information during acquisition or storage in the PACS in the event of a power failure, the vendor shall supply an Uninteruptable Power Supply (UPS) with sufficient capacity to support the necessary equipment during the operation. This requirement is not intended to require UPS at all locations, only at those locations where a power failure would cause a loss of patient images or information. This requirement is also not intended to require that the system continue to operate for additional acquisitions during the power outage.
F6The system shall maintain a total system uptime of 99% monthly, and individual component uptimes of at least 90% monthly. Percentages will be calculated based on the Principal Period of Maintenance (see Appendix 6, Section 2.4 for calculation).Component and system downtimes will include scheduled and unscheduled outages. Vendors shall document their current experience with their product that would demonstrate to the Government that this requirement can be met. (see Appendix 6 for definitions of uptime and downtime.)

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB G

TAB G SYSTEM MAINTENANCE

Compliance StatusDescription
G1The Vendor will comply with the Government's system maintenance requirements specified in Appendix 6 .
G2Vendor shall offer maintenance service in accordance with the "maintenance scope of work options" specified in Appendix 6, paragraph 3.13.
G3Vendors are encouraged to offer their normal, commercial maintenance service plans (based on their standard commercial maintenance service terms and conditions) in addition to the Government specified service options above.
G4The offered maintenance plans shall specify the level of operations support, including all on-site field engineers, part-time and/or off-site personnel, as well as the hours of coverage.
G5Maintenance and support response time shall be 2 hours or less during the 0800-1700 time period and 2 hours or less during the remainder of the day. Response time is measured from the time the field engineer on call is paged until support personnel are on-site and actively working on the problem.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB H

TAB H REPAIR PARTS STRATEGY

Compliance StatusDescription
H1The vendor shall provide a guarantee that the Government will be able to purchase all required spare parts from the vendor for seven years from the date of final system acceptance.
H2If the Government elects not to upgrade existing systems to new versions (either hardware or software), the vendor shall guarantee that they will continue to provide support for hardware, software and spare parts FOR THE INSTALLED SYSTEM for a minimum of three years after release of the upgrade.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB I

TAB I SYSTEM DOCUMENTATION AND TRAINING

Compliance StatusDescription
I1The Vendor shall meet the Government's Documentation and Training requirements specified herein.
I2With every system purchased, as a minimum, two complete sets of manuals covering the system administration, operation, installation, and maintenance of all system components and explaining the operational concept of the system as a whole shall be provided.
I3If purchased with a particular system, the Vendor is required to provide the following Data Requirements (documentation). Further detail on the required content of this documentation is provided at Appendix 3. Vendors shall provide pricing for the completion and delivery of each of the following Data Requirements with their proposal.
I3.1Special Tools and Test Equipment List - used to identify all nonstandard tools, test equipment, and diagnostic software designed and developed by the manufacturer to perform maintenance, test/calibration, diagnostic/prognostic analysis and other related support of the equipment furnished under this contract and required for testing and successful operation and maintenance.
I3.2Master Parts List - The Contractor shall submit a detailed parts list for each component of the system. Each part, component or module shall be identified by the manufacturer's name and part number. Part identification is to be to the printed circuit board level, with diagram reference.
I3.3List of Spare Parts - The Contractor shall submit a recommended spare parts list sufficient for installation and startup tests, as well as for maintaining each line item for a period of at least 12 months following official Government acceptance.
I3.4List of Supplies - The Contractor shall submit a recommended supply list for each site for start-up and operation of the DIN-PACS system for a 12 month period.
I3.5Installation Plan - The Contractor shall submit an Installation Plan as specified in Appendix 3.
I3.6Drawings and Other Documentation - The Contractor shall submit specified Drawings and Other Documentation per Appendix 3, CDRL AG.
I3.7Status Reports - The Contractor shall submit weekly status reports for Level II and III turnkey efforts on the progress of the turnkey installation, beginning with "Notice to Proceed with Construction" through equipment installation and testing. Turnkey level definitions are included in Appendix 4
I3.8As-Built Drawings - The Contractor shall submit as-built drawings per Appendix 3.
I3.9Training Plan - The Contractor shall submit a training plan per Appendix 3.
I3.10Electronic Security Plan - The Contractor shall submit a security plan for each site for safeguard of medical records. Requirement are specified in Appendix 3.
I3.11GFE DICOM Conformance Statement Analysis - Requirements are specified in Appendix 3.
I3.12A IHE Integration Statement for their proposed system
I3.13Quality Control Plan - The Contractor shall submit a complete QC program specific to each site.
I3.14Crisis Management Plan - The Contractor shall submit a crisis management plan as required for each site to illustrate all steps to be taken by the Contractor to insure clinical capability in case of a system crisis/shutdown (should include scenarios to cover all critical subsystems as well as the entire system overall).
I3.15Maintenance Plan
The contractor shall submit a maintenance plan that includes the following:
1. Scheduled preventive maintenance details and schedule
2. Corrective action/repair program details
3. Database maintenance details
4. Archive maintenance details
5. Repair parts program details
6. Technical support description
7. Telemaintenance support
I3.16System Administration, Operation and Maintenance Manuals
The contractor shall provide a minimum of two complete copies of System Administration, Operator and Service literature for each component of the system.
I3.17Ongoing PACS Training to support existing and newly reporting personnel
The vendor should provide a training solution that is computer based (CBT) for use by the <SITE> training department. CBT should be offered either on standalone compact discs (CD's) or as a local web solution via the MTF intranet."

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB J

TAB J DICOM REQUIREMENTS

Compliance StatusDescription
DICOM Connectivity: DICOM requirements are described in detail in Appendix I. Vendor shall meet all requirements for DICOM connectivity as set forth in Appendix I. Major Requirements headings are listed in this section for Vendor's convenience in describing compliance.
J1Network Interfaces to DICOM Devices
J1.1The PACS vendor shall be responsible for providing all appropriate hardware and software to interface and integrate DICOM conforming devices to the PACS network to at least the minimum DICOM functionality specified in Appendix I.
The PACS vendor shall communicate and work directly with the imaging equipment vendors to ensure seamless integration and interface of the imaging devices to the PACS
J1.2The PACS vendor shall be responsible for communicating with each device vendor to determine and implement DICOM compatibility and connectivity between the device and the PACS.
The PACS vendor must provide the government a written list of any additional specific software and/or hardware upgrades, or licenses, required for successful integration of the PACS (to be purchased by the government separately).
J2The Vendor shall support all DICOM Correction Proposals and Supplements approved six months prior to the issuance of a site specific delivery order.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB K

TAB K TELERADIOLOGY

Compliance StatusDescription
K1Teleradiology. Vendor shall discuss their current and future capabilities. Vendor shall discuss their support of IHE initiatives to develop a standard for sending and receiving DICOM images and reports.
Shall describe the vendor's ability to send/receive images and reports across a wide area network to/from differing medical treatment facilities (MTF) that may or may not have the vendors PACS installed.
K2Vendor shall describe their willingness to work with other PACS vendors within the DoD Medical Healthcare System (MHS) to develop a cooperative solution for teleradiology that meets the government's requirement without proliferating additional equipment to existing sites.
K3Vendors shall discuss their commitment to meeting DICOM Structured Reporting.

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

TAB L

TAB L SYSTEM SECURITY

Compliance StatusDescription
L1General Security Requirements. The Contractor shall establish appropriate administrative, technical, and physical safeguards to protect any and all DoD data, to ensure the confidentiality, integrity, and availability of DoD data. As a minimum, this shall include provisions for personnel security, electronic security and physical security as listed in the sections that follow.
L1.1The Contractor shall comply with all information assurance/information security requirements listed in Appendix 7 in relation to each specific service.
L1.2The contractor shall comply with DoD Directive 5200.2, "DoD Personnel Security Program," DoD Directive 8500.1, "Information Assurance (IA)", DoD Instruction 8500.2, "Information Assurance (IA) Implementation," DoD Instruction 8510.01, "DoD Information Assurance Certification and Accreditation Process (DIACAP)," DoD 8551.1, "Ports, Protocols, and Services," and DoD 8580.02, "DoD Health Information Security Regulation."
L1.3The contractor shall ensure that data which contains Protected Health Information (PHI) is continuously protected from unauthorized access, use, modification, or disclosure. The contractor shall comply with all previously stated requirements for HIPAA, Personnel Security, Electronic Security, and Physical Security.
L2Health Insurance Portability and Accountability Act (HIPAA). Health Insurance Portability and Accountability Act of 1996 (HIPAA) Requirement. The HIPAA standard contract language is mandatory whenever a business associate, (i.e., outside person or agency) creates, receives, maintains, or transmits electronic protected health information (PHI) on behalf of a covered entity. This contract or agreement requires the business associate to:
Note: Additional guidance can be found in DoD 8580.02 -R, Health Information Security Regulation.
L2.1Implement administrative, physical, and technical safeguards that will protect the confidentiality, integrity, and availability of the PHI
L2.2Ensure all agents or subcontractors to whom the business associate provides PHI will also implement reasonable and appropriate safeguards to protect the information.
L2.3Report all security incidents In Accordance With each of the services procedures.
L2.4Authorize termination of the contract if the organization finds that the business associate has violated the terms of the contract.
L3Follow the DoD guidelines for submittal of Information Technology (IT) security background checks and ensure all contractor personnel are designated as IT-I, IT-II, or IT-III where their duties meet the criteria of the position sensitivity designations. Contact the service Program Management Office (PMO) for guidance on the appropriate IT levels for personnel on the contract. Any vendor personnel that will be accessing the PACS while installed on a DoD network will be required to have a National Agency Check (NAC) completed. Typically, this requires an investigation to support a "Public Trust Position" and requires the person(s) to complete and submit a Standard Form 85P (SF 85P), Questionnaire for Public Trust Positions, via the Electronic Personnel Security Questionnaire (EPSQ). Questions relating to SF85Ps and the EPSQ process may be directed to 1-888-282-7682 or online at http://www.dss.mil/index.htm.
L3.1Immediately report to the PMO and deny access to any automated information system (AIS), network, or information if a contractor employee filling a sensitive position receives an unfavorable adjudication, if information that would result in an unfavorable adjudication becomes available, or if directed to do so by the appropriate Service representative for security reasons.
L3.2Ensure that all contractor personnel receive Information Assurance (IA) training before being granted access to DoD AISs.
L4Electronic Security. Contractor systems that are involved in the operation of systems in support of DoD's Health System shall operate in accordance with controlling laws, regulations, and DoD policy. DoD IA Certification and Accreditation (C&A) requirements apply to all DoD and contractor systems that receive, process, display, store or transmit DoD information.
L4.1Certification is the determination of the appropriate level of protection required for an Information System (IS). Certification also includes a comprehensive evaluation of the technical and non-technical security features and countermeasures required for each system.
L4.2Accreditation is the formal approval by DoD to operate the system in a particular security mode using a prescribed set of safeguards at an acceptable level of risk. In addition, accreditation allows a system to operate within the given operational environment with stated interconnections; and with appropriate level of protection for the specified period.
L4.3The contractor shall comply with DIACAP requirements, as specified by DoD that meet appropriate DoD and Service IA and C&A requirements. The contractor shall initiate the process by providing the required documentation necessary to meet Service C&A requirements. The contractor shall make their IS available for C&A testing if required by the Service and initiate the process well in advance of a contract delivery order. The requirements shall be met before the contractor's system is authorized to access DoD data or interconnect with any DoD network that receives, processes, stores, displays or transmits DoD data. Additional Service specific requirements must also be met as stated later in the service specific section. The contractor shall ensure the proper contractor support staff is available to participate in all phases of the C&A process. They include, but are not limited to:
L4.3.1Completing and maintaining all documentation necessary to obtain C&A
L4.3.2Attending and supporting C&A meetings with the Service, as necessary
L4.3.3Support/conducting the vulnerability mitigation process to comply with IA controls listed in DoD 8500.2.
L4.3.4Supporting the C&A Team during system security testing
L4.3.5Contractors must confirm that their systems are locked down prior to initiating C&A testing.
L4.4Vulnerabilities that have been identified by DoD as "must-fix" issues during the C&A process must be mitigated according to the timeline identified by the Service Representative. Checklists are provided for complying with DoD and Service requirements. Reference material, a copy of the Windows Gold Disk, SRRs, and STIGs may be obtained at the Defense Information Systems Agency website: http://iase.disa.mil/stigs/SRR/index.html
L4.5Ports Protocols and Services. Vendors shall follow all current DoD and Service standards and requirements for acceptable Ports, Protocols, and Services. Any requests for exception to using the current DoD and Service Ports, Protocols, and Services standards requires an request for exception sent through the Program Manager to the DAA.
L4.6Public Key Infrastructure and Encryption. Vendors shall follow the DoD and Service standards, policies, and procedures related to the use of Public Key Infrastructure (PKI) certificates for positive authentication. Where interoperable PKI is required for the exchange of unclassified information between DoD and its vendors and contractors, industry partners shall obtain all necessary certificates.
(Are there any known issues with vendors meeting this? Can all major vendors do this?)
Vendors must turn over to DoD all encryption keys for deployed systems, backdoor algorithms, and procedures for their use in remote support. The Vendor must provide a written report detailing all of the above, prior to task order expiration, regardless of modifications or extensions.
L5Physical Security. The contractor shall employ physical security safeguards for IS/Networks involved in processing or storage of DoD Data to prevent the unauthorized access, disclosure, modification, destruction, use, etc., and to otherwise protect the confidentiality and ensure use conforms with DoD and Service regulations. The contractor shall be required to follow all requirements in the DoD's Information Assurance Policy. New DoD and Service policies will be posted to specific websites.
L6Post-Accreditation Reviews & Site Acceptance Testing. PMs will conduct a review of all applicable IA controls and perform validation procedures on those controls as identified in the Site Acceptance Protocols. Auditing all new systems at delivery to ensure all applicable electronic patches are installed on the system before the PMO accepts the product.
L6.1Ensuring vendors acquire, develop, and maintain the Certification & Accreditation (C&A) documentation to ensure both initial and continued compliance with DIACAP requirements as specified by DoD and Service Information Assurance requirements for all contractor systems that receive, process, store, display, or transmit DoD data, or has a physical or logical connections to a DoD certified network.
L6.2An annual IA review shall be conducted that comprehensively evaluates existing policies and processes to ensure procedural consistency and the IS continues to operate in the manner to which it was certified. The annual review process should account for the analysis of projected policy needs, and produce a plan for development or implementation of new policies or processes.
L7VAAR 852.273-75 Security requirements for unclassified information technology resources.
The contractor ans their perssonel shall be subject to the same Federal Laws, regulations, standards and VA policies as VA personnel, reguarding information and information system security. These include, but are not limited to Federal Information Security Management Act (FISMA), Appendix III of OMB Circular A-130, and Guidance and standards, available from the Department of Commerce's National Institute of Standards and Technology (NIST). This also includes the use of common security configurations available from NIST's Web site at: http://www.iprm.oit.va.gov
L8To ensure that appropriate security controls are in place, Contractors must follow the procedures ser forth in "VA information System Security/Privacy Requirements for IT Contracts" located at the following Web site: http://www.iprm.oit.va.gov

&F SPM2D1-10-R-0011

OFFEROR NAME &P of &N

File details come from the government source that posted it. Updated .