SEC_C._APPENDIX_A_-_Deliverables6162016.pdf

PDF 160 KB Posted

Attached to
DRAFT SOL. MOD 0001 Federal contract opportunity
Solicitation number
TIRNO_16_R_00026
Issued by
Department of the Treasury Internal Revenue Service

About this file

SECTION C- Attachment to Appendices Table- APPENDIX A- Deliverables

View the file

Other files for this federal contract opportunity

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SECTION C: Performance Work Statement

APPENDIX A – DELIVERABLES

Section C.3.1, Portal Service and Program Integration Services Deliverables:

The Contractor shall propose the delivery period/date and the contents for each of the work products designated “Contractor Proposed” required for Portal Service and Program Integration Services. These work products include the following:

PWS Ref. Service Area Deliverable Period Content H.1.4 Portal Service and

Program Integration Services

Program Management Plan including all Sections

Contractor Proposed

Contractor Proposed

H.1.3 Portal Service and Program Integration Services

Operations Management Framework

Contractor Proposed, and updates at as needed for process change or update

Contractor Proposed

C.3.1 Portal Service and Program Integration Services

Integrated Master Schedule

Contractor Proposed

Contractor Proposed

C.3.1 Portal Service and Program Integration Services

QA Measurement Methodology

Contractor Proposed

Contractor Proposed

H.2.3 Portal Service and Program Integration Services

Earned Value Management System (EVMS) Reports

Monthly Contractor Proposed

H.1.8 Portal Service and Program Integration Services

Innovation Plan Contractor Proposed

Contractor Proposed

C.3.1 Portal Service and Program Integration Services

Service Level Objectives (SLO) Report

Monthly Contractor Proposed

C.3.1 Portal Service and Program Integration Services

Privacy/Civil Liberties Impact Assessment

(PCLIA)

ELC Milestone

PCLIA shall demonstrate that program managers, system owners, and developers have consciously incorporated privacy and civil liberties

PWS Ref. Service Area Deliverable Period Content protections throughout the entire life cycle of a system. This involves making certain that privacy and civil liberties protections are built into the system from the beginning when it is less costly and more effective.

Section I Portal Service and Program Integration Services

Section 508 Compliance Update Test Plan

Transition Provide an updated test plan that outlies products and/or services that are tested for compliance with Section 508 and how the test will be conducted.

Section I Portal Service and Program Integration Services

Section 508 Compliance Test Report

Prior to Production

Provide a test report that reflects the results of the Section 508 test plan that was conduct prior to production

Section I Portal Service and Program Integration Services

Accessibility Risk Information

Prior to Production

Provide the risk impact for any unresolved Section 508 provisional failures

Section I Portal Service and Program Integration Services

Accessibility Compliance Approach

Prior to Production

Explain how the contractor or business owner will address Section 508 issues

Section C.3.2, Portal Infrastructure Services Information Available to IRS:

Routine Infrastructure Services information should be made available to the IRS. This information should be considered work products and transient information. Frequency of delivery and minimal required content should be as necessary to satisfy the requirement. The Contractor shall provide sufficient information to provide a full and accurate depiction of the process status in the reporting period.

Automated or online information availability is the preferred access mechanism.

Item No. Information Provided PWS Reference/Content 1 Portal Infrastructure Services

Documentation C.3.2

Section C.3.3, Portal Web Hosting Services Deliverables:

The Contractor will propose the delivery period/date, and the contents for each of the work products designated “Contractor Proposed” required for Portal Web Hosting Services. These work products include the following:

PWS Ref. Service Area Deliverable Period Content C.3.3.2;

C.3.3.3;

C.3.3.4;

C.3.3.6

Portal Web Hosting Services

Portal Web Hosting Services Status Report

Monthly Contractor Proposed;

Capacity Management Status Report;

Incident/Problem Status Updates;

Monitoring Status Reports;

Change Management Status Reports;

Patch Management Status Reports

Section C.3.3, Portal Web Hosting Services Information Available to IRS:

Routine Web Hosting Services information should be made available to the IRS. This information should be considered work products and transient information. Frequency of delivery and minimal required content should be specified in the related Web Hosting process definitions. The Contractor shall provide sufficient information to provide a full and accurate depiction of the process status in the reporting period. Automated or online information availability is the preferred access mechanism.

1 Portal Web Hosting CONOPS C.3.3.1 2 Capacity Management Plan C.3.3.2 3 Throughput Report C.3.3.2 4 Capacity Demand Report C.3.3.2 5 Incident/Problem Management SOP C.3.3.3 6 User Behavior and Usage Analysis C.3.3.4 7 IT Infrastructure usage analysis and metrics C.3.3.4

8 Service utilization analytics and metrics

C.3.3.4

9 Log file data C.3.3.4 10 Monitoring event data C.3.3.4 11 Guide for Application Developers C.3.3.5 12 Change Management SOP C.3.3.6 13 Deployment Process SOP C.3.3.6 14 IEP On-Boarding SOP C.3.3.7 15 IEP On-Boarding Metrics C.3.3.7 16 IEP Service Desk SOP C.3.3.8

Section C.3.4, Security Deliverables

The Contractor shall update security process plans when changes occur and ensure there is a review on at least an annual basis. Examples of scenarios that would prompt updates to security plans include security control assessments, changes in policy or procedure, changes in requirements, process or technology improvements and changes in laws or NIST guidance.

The Contractor shall create and maintain IEP 1.5 Security process documents that capture all aspects of the services provided including regulatory compliance, define the operational metrics and measures used to calculate the Service Level Objectives (SLO), and define status reporting elements and frequencies. These documents are under full project configuration control.

The Contractor will obtain approval from the IRS for changes to security plans thorough the project Change Management process.

PWS Ref. Service

Area Deliverable Period Content

Security Services Process Documents C.3.4.4 Security IEP 1.5 Continuous Monitoring

Plan At least annually

Contractor Proposed

C.3.4.5 Security IEP 1.5 Security Configuration and Change Management Plan

At least annually

Contractor Proposed

C.3.4.6 Security IEP 1.5 Security Audit Plan At least annually

Contractor Proposed

C.3.4.2 Security IEP 1.5 Security Patch Management Plan

At least annually

Contractor Proposed

C.3.4.7 Security IEP 1.5 Security Incident Handling, Monitoring and Response Plan

At least annually

Contractor Proposed

C.3.4.8 Security IEP 1.5 Information System Contingency Plan (ISCP)

At least annually

Contractor Proposed

C.3.4.1 Security IEP 1.5 Security Concept of Operations (Security CONOPS)

At least annually

Contractor Proposed

C.3.4.11 Security IEP 1.5 Access Management Plan (AMP)

At least annually or as needed

Contractor Proposed

No. Service Area

Deliverable Period Content

Plans and Documents Supporting SCA and ASCA Activities C.3.4.5, C.3.4.9, C.3.4.10

Security IEP 1.5 System Security Plan

(SSP)

This document describes the systems management, operational and technical security controls implemented to provide the required level of confidentiality, integrity, and availability.

At least annually

Updates to the approved plan required with changes in NIST or IRS policy, changes in implementation of security controls.

Contractor Proposed

C.3.4.9 Security IEP 1.5 Authorization Boundary Memo.

Document that establishes the system boundary for the SCA process. (Generally considered part of SSP, but usually updated prior to full

SSP.)

At least annually

Contractor Proposed

C.3.4.9 Security IEP 1.5 Interconnection Security Agreements (ISA) The ISA defines the security controls between interconnected systems and authorizes the connection from one information system to other systems outside of the IRS.

At least annually or as needed

Contractor proposed, per requirements in C.3.4.9.

C.3.4.9 Security IEP 1.5 Security Control Assessment (SCA) Test Plan

At least annually

Contractor proposed, per requirements in C.3.4.9.

C.3.4.9 Security IEP 1.5 Security Assessment Report (SAR) Mitigation Plan This deliverable is dependent on the completion of the SAR document with findings from SCA Testing. The SAR document is developed by the IRS Cybersecurity FISMA Certification Program Office (CPO) team.

Annual - TBD days after receipt of SAR

Contractor proposed, per requirements in C.3.4.9.

C.3.4.9 IEP 1.5 Privacy/Civil Liberties Impact Assessment (PCLIA)

When changes are required or annually

Contractor proposed, per requirements in C.3.4.9.

C.3.4.9 Security IEP 1.5 State of Security (SoS) Package

Annually Contractor proposed, per requirements in C.3.4.9.

C.3.4.4 Security FISMA Compliance Reports including, but not limited to, inventory, inventory change log, security configuration compliance reports, personal security, and POA&Ms.

Monthly Contractor proposed, per requirements in C.3.4.4

C.3.4.1 Security IEP 1.5 Information Security Status Package Includes validation of timely delivery and acceptance of FISMA Compliance Reports, Summary of incidents and actions from Weekly Status Report and POA&M status

Monthly Contractor proposed, per requirements in C.3.4.1

Security Reports

Reports should be considered work products and transient information. Frequency of delivery and minimal required content should be specified in the related Security Services Process Documents. The Contractor shall provide sufficient information to provide a full and accurate depiction of the security status in the reporting period. Automated or online status reporting is recommended.

The Contactor should provide consistent and consolidated security reporting that reflects the unique security requirements supported in each portal work stream (PUP, RUP, EUP, TPE etc.) and environments (Dev, Test, EITE, PETE, Prod).

1 IEP 1.5 Weekly Security Status Report 2 IEP 1.5 Security Risk Assessment

(SRA) Mitigation Report

3 IEP 1.5 Incident Response Test Report

• The Contractor shall provide a Weekly Security Status and a monthly Security Status Report for review at monthly Security Program Management Review(PMR).

As part of the IEP 1.5 Weekly Security Status Report the Contractor shall summarize how they followed up on potential incidents and suspicious activity to mitigate risks and prevent breaches.

The Contractor shall submit detailed evidence along with the report that shows the steps they performed to follow-up with each potential incident and suspicious activity. This evidence includes the details of all analysis performed to close SIEM tickets, even if those tickets were not communicated to CSIRC. Examples of the Weekly Security Status reports include: Status of ongoing Security Operation and planned activities, schedule for FISMA Compliance Reports, actions resulting from analytic results, and POA&M status.

− Vulnerability Assessment (Analysis) shall contain the status of vulnerabilities and Contractor’s effort to remediate them through patches or secure configurations − Configuration Compliance Report contains the NIST compliance summary and details for all the servers and devices in the IEP 1.5 environment. It should be easy for the recipient of this report to identify the configuration weaknesses in the environment, particularly critical and high risk weaknesses. Weaknesses should be tracked in the Mitigation Report and mitigated in the same manner as other findings from SCA tests, etc.

− Security Incident Report contains the detailed investigation documentation for each potential/suspected incidents detected and investigated by the Contractor’s security operations team. This includes the details of the analysis performed to close the SIEM ticket escalated from a third party subcontractor to Contractor. (Provided as needed)

− Mitigation Report contains the details of open and closed security findings and mitigations taken to close them.

• IEP 1.5 Security Risk Assessment (SRA) Mitigation Report provides planned mitigation actions necessary to address findings in the Security Risk Assessment (SRA). This deliverable is dependent on the completion of the SRA document. The SRA document is developed by the IRS Security Assessment Services (SAS) team. (per description in Section C.3.4.1) and it is an ad-hoc report. This document is related to Risk Management Framework (RMF) and Cybersecurity's Security Change request process (Managed Service Security Impact Assessment).

• IEP 1.5 Incident Response Test Report details results of the quarterly incident response simulation provided following quarterly test (per description in section C.3.4.7).

Section C.3.5, Portal Application Services Deliverables:

PWS Ref. Service Area Deliverable Period Content C.3.5 Portal

Application Services

Application Migration Plan and Strategy

Contractor Proposed and as updated

Contractor Proposed

C.3.5 Portal Application Services

Integration Test Results As scheduled Contractor Proposed

C.3.5 Portal Application Services

Search Terms report Monthly, and upon request

Contractor Proposed per requirements

C.3.5 Portal Application Services

Search performance metrics and user behavior report

Contractor proposed

Contractor Proposed

C.3.5 Portal Application Services

External Search engine optimization process

Contractor proposed and as updated

Contractor Proposed

C.3.5 Portal Application irs.gov Optimization Plan Contractor proposed and

Services as updated

C.3.5 Portal Application Services

Search Engine Optimization (SEO) Findings and Recommendations

Monthly Contractor Proposed

C.3.5 Portal Application Services irs.gov Web Performance metrics

Contractor Proposed

C.3.5 Portal Application Services irs.gov Web usage metrics and site activity

Contractor Proposed, and on-demand

Contractor Proposed per requirements

C.3.5 Portal Application Services irs.gov Browser and Operating System summary

Every six months

Contractor Proposed per requirements

C.3.5 Portal Application Services

Section C.3.6, Portal Website Help Desk Services Deliverables:

The Contractor will propose the delivery period/date, and the contents for each of the work products designated “Contractor Proposed” required for Website Help Desk Services. These work products include the following:

C.3.6 Portal

Website Help Desk Services

Help Desk CSR Training materials

Contractor Proposed

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Help Desk Escalation Specialist(s) Training materials

Contractor Proposed

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Required Report Templates Contractor Proposed

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Contact Information List Contractor Proposed

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Emergency Contact List Contractor Proposed

Contractor Proposed.

C.3.6 Portal Escalation Users Guide Contractor Contractor Proposed.

Website Help Desk Services

Proposed

C.3.6 Portal Website Help Desk Services

Help Desk SOP Contractor Proposed

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Call Recordings Monthly File(s) containing extract of calls between CSR and a tax payer; .wav format

C.3.6 Portal Website Help Desk Services

Chat Transcript Report Monthly Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Help Desk Report Quality Assurance Process document

Contractor Proposed, and as updated.

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Customer Satisfaction survey results

Quarterly Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Help Desk architecture and design

Contractor Proposed

Contractor Proposed.

C.3.6 Portal Website Help Desk Services

OMB Research Survey package

Quarterly Per requirements

C.3.6 Portal Website Help Desk Services

Post filing Season review package

Annually Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Help Desk metrics and summary

Weekly Per requirements and Contractor Proposed.

C.3.6 Portal Website Help Desk Services

Help Desk Status Report Monthly Status report of Website Help Desk activities, requests, risks, and issues. It will also include the monthly call recordings.

C.3.6 Portal Website Help Desk Services

Classification Report of new irs.gov Help Desk Statistics by Topic

Weekly Per requirement

C.3.6 Portal Website Help Desk Services

Help Desk Service Level Agreement Report

Weekly Per requirement

C.3.6 Portal Website Help Desk Services

Topic and Sub-Topic of all contacts.

Weekly from January 1 to April 30 each year

Per requirement

C.3.6 Portal Website Help Desk Services

Canned Response Usage Report

Bi-weekly during filing season and monthly during non-filing season

Provides a breakdown of Help Desk contacts by folder name and canned response title

C.3.6 Portal Website Help Desk Services

CSR Chat - E-Mail Phone Comments Report

Monthly Extract of all comments that come into the help desk.

This includes all inquiries, not just those that are escalated.

C.3.6 Portal Website Help Desk Services

Backup of all chat, e-mail, and escalation data

Captured monthly, delivered annually

Contractor proposed transfer method

Section C.3.7.2, Initial Transition and Termination of Portal Operations Deliverables:

No. Service Area Deliverable Period Content

C.3.7.2 Initial Transition and Termination of Portal Operations

Stakeholder sign-off of the IEP 1.5 Transition Plan for initial implementation

Contractor proposed

Contractor proposed

C.3.7.2 Initial Transition and Termination of Portal Operations

Stakeholder sign-off of the IEP 1.5 Transition Completion

Contractor proposed

Contractor proposed

C.3.7.2 Initial Transition and Termination

Stakeholder sign-off of Application O&M

After the application

Contractor proposed

No. Service Area Deliverable Period Content of Portal Operations

Transition O&M transition is completed, including all application that Contractor assumes O&M responsibility

Section C.3.7.2, Initial Transition and Termination of Portal Operations Work Products/Reports:

1 IEP 1.5 Transition Plan for initial implementation C.3.7.1

2 IEP 1.5 Weekly Transition Status Report

C.3.7.1

Initial Transition and Termination of Portal Operations

File details come from the government source that posted it. Updated .