USCA19BPAC1010.pdf

PDF 27 KB Posted

Attached to
PPS Client Case Management BPA Federal contract opportunity
Solicitation number
USCA19R0062
Issued by
The Judicial Branch

About this file

BPA Call - USCA19BPAC1010 Operations and Maintenance

View the file

Other files for this federal contract opportunity

Other files attached to PPS Client Case Management BPA, newest first.
File Type Posted
USCA19R0062_Q&A_Clarifications.docx DOCX document
USCA19R0062-0002.pdf PDF
USCA19R0062_-_Summary_of_Changes.docx DOCX document
USCA19BPAC1010_v2.pdf PDF
Attachment_1_-_PPS_Security_and_Privacy_v2.pdf PDF
Attachment_4_-_RTM_for_IOC_v2.xlsx XLSX spreadsheet
USCA19R0062_Questions_and_Answers.docx DOCX document
Attachment_A_-_BPA_Pricing_v2.xlsx XLSX spreadsheet
Attachment_B_-_Requirements_Traceability_Matrix_v2.xlsx XLSX spreadsheet
USCA19BPAC1009_v2.pdf PDF
Attachment_C_-_Past_Performance_Questionnaire_v2.docx DOCX document
USCA19R0062-0001.pdf PDF
Attachment_A_-_BPA_Pricing.xlsx XLSX spreadsheet
Attachment_B_-_Requirements_Traceability_Matrix.xlsx XLSX spreadsheet
Attachment_D_-_Demonstrations.docx DOCX document
Attachment_C_-_Past_Performance_Questionnaire.docx DOCX document
Attachment_2_-_Current_PPS_Portfolio_Interfaces.xlsx XLSX spreadsheet
USCA19BPAC1009.pdf PDF
Attachment_1_-_PPS_Security_and_Privacy.pdf PDF
Attachment_3_-_PPS-CCMS_Roadmap.pdf PDF
USCA19R0062.pdf PDF
Attachment_4_-_RTM_for_IOC.xlsx XLSX spreadsheet
Show all 22

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ORDER FOR SUPPLIES OR SERVICES

IMPORTANT: Mark all packages and papers with contract and/or order numbers.

1. DATE OF ORDER 2. CONTRACT NO. (If any) 6. SHIP TO:

Office of Probation and Pretrial Services Administrative Office of the United States Courts One Columbus Circle, N.E.

Suite 4-300 Washington, DC 20544-0001

3. ORDER NO.

USCA19BPAC1010

4. REQUISITION/REFERENCE NO.

Manish Patel, 202-502-3258 Procurement Management Division Administrative Office of the United States Courts One Columbus Circle, N.E.

Suite 3-250 Washington, DC 20544-0001

5. ISSUING OFFICE (Address correspondence to)

7. TO:

8. TYPE OF ORDER

a. PURCHASE

REFERENCE YOUR: ____________

Please furnish the following on the terms and conditions specified on both sides of this order and on the attached sheet, if any, including delivery as indicated.

X b. DELIVERY -- Except for billing instructions on the reverse, this delivery order is subject to instructions contained on this side only of this form and is issued subject to the terms and conditions of the above-numbered contract.

9. ACCOUNTING AND APPROPRIATION DATA 10. REQUISITIONING OFFICE

11. NOT USED 12. F.O.B. POINT

14. GOVERNMENT B/L NO. 15. DELIVER TO F.O.B. POINT ON

OR BEFORE (Date)

16. DISCOUNT TERMS13. PLACE OF

a. INSPECTION b. ACCEPTANCE

17. SCHEDULE

CLIN NO.

(a)

SUPPLIES OR SERVICES

(b)

QUANTITY

ORDERED

(c) UNIT (d)

UNIT PRICE

(e)

AMOUNT

(f)

QUANTITY

ACCEPTED

(g)

See Lines

SEE BILLING

INSTRUCTIONS

ON

REVERSE

18. SHIPPING POINT 19. GROSS SHIPPING WEIGHT 20. INVOICE NO.

$0.00 17(h) TOT.

(Cont.

pages)

21. MAIL INVOICE TO:

a. NAME Office of Probation and Pretrial Services

b. STREET ADDRESS(or P.O. Box) Administrative Office of the United States Courts, One Columbus Circle, N.E., Suite 4-300

c. CITY Washington

d. STATE

DC

e. ZIP CODE 20544-0001

$0.00

17(i)

GRAND

TOTAL

22. UNITED STATES OF AMERICA BY (Signature)

23. NAME (Typed)

Manish Patel

TITLE: CONTRACTING/ORDERING OFFICER

AUTHORIZED FOR LOCAL REPRODUCTION

PREVIOUS EDITION NOT USABLE

OPTIONAL FORM 347 (REV. 02/2012)

Prescribed by GSA/FAR 48 CFR 53.213(f)

USCA19BPAC1010 - Page 1 of 8

Supplies or Services and Prices/Costs

CLIN NO. Supplies or Services Quantity Unit of Issue Unit Price Extended Amount

0001 Provide Operations and Maintenance Support in accordance with section 2.0 in C-1 Requirements.

(Firm Fixed Price)

1 Month $0.00 $0.00

CLIN NO. Supplies or Services Quantity Unit of Issue Unit Price Extended Amount

0002 Provide Cybersecurity services in accordance with section 3.0 in C-1 Requirements. (Firm Fixed

Price)

1 Month $0.00 $0.00

Descriptions/Specifications/Statement of Work

C-1 Requirements

1.0 Scope

This BPA Call is for the operations and maintenance support, including cybersecurity, of the Probation and Pre-trial Services Client Case Management (PPS CCM) Initial Operating Capablity (IOC) deployment of up to 1,000 users.

2.0 Task 1: Operations and Maintenance

Operations and Maintenance (O&M) support shall include maintaining the systems and software availability and recovery, help desk support, development, maintenance and enhancement support.

2.1 Systems Software Availability and Recovery

The contractor’s solution shall require a FedRamp High environment that meets the following minimum avail-ability and recovery thresholds. Availability is calculated by taking the available service less the number of planned and unplanned service outages divided by the available service less the planned service outage.

• FedRamp Cloud Availability – 99.6%, Threshold

• Recovery Point Objective (RPO) – 4 hours, Threshold

• Recovery Time Objective (RTO) – 12 hours, Threshold

The contractor shall develop an operations framework to maintain and sustain operations to include a Continu-ous Product Improvement (CPI) process to collect metrics on operations support and provide recommendations to the Government to improve efficiencies and resolve bottlenecks. The contractor shall collaborate with the Government to finalize operations procedures, roles and responsibilities.

2.2 Help Desk Support

The contractor shall work with the AO operations support staff (including contractors) to resolve issues and ser-vice requests. The Government’s Enterprise Operations Center (EOC) National Support Desk (NSD) provides 24/7 Tier 1 support to all users. Tier 1 support serves as the user’s single point of contact for all incident and service request submissions related to the Judiciary’s national systems. Their objective is to resolve known in-cidents on the first contact. The EOC-NSD performs the following tasks:

• Log, document, classify, and resolve known incidents to restore a failed IT service as quickly as possible

USCA19BPAC1010 - Page 2 of 8

• Log document, classify, and communicate all service requests as quickly as possible

• Serve as the single point of contact for the users and keep users informed about the status of their incident or service request statuses through the ticketing system or phone call

• Ensure users issues are successfully resolved and their resolutions are correctly logged in the EOC-NSD Service Management system

• Escalate incidents to the appropriate support tier when necessary or when a documented solution is not available or cannot be applied

• Collect all the necessary information to assist in resolving incidents or service requests

• Communicate and document progress and resolution in the EOC-NSD Service management system to keep users up-to-date on incident or service request statuses

• Process Modification (Change) Requests (MRs) and keep users informed about their statuses at agreed upon intervals.

The contractor shall provide prompt correction of all Tier 2 and 3 incidents and service requests escalated from Tier 1 that the Government’s EOC-NSD (NSD) cannot resolve inclusive of glitches, aberrations and errors in the application programming; and/or documentation about which the contractor is either informed by the Gov-ernment or otherwise becomes aware.

The contractor shall provide support to end users between 6:00 AM EST – 8:00 PM EST, Monday through Thursday, 6:00 AM EST – 5:00 PM EST on Fridays, 8:00 AM EST – 4:00 PM EST on Sundays excluding Government holidays, and remotely for on-call after hour support (including Government holidays). The con-tractor shall provide the Government visibility into the contractor’s service management system via direct ac-cess or an integration/bridge to the Government’s Service Management system (currently HEAT), which is the system of record for all service tickets. The contractor shall also establish a knowledge base system to support all Tiers and users.

2.3 Development, Maintenance, and Enhancement Support

The contractor shall provide development, maintenance, and enhancement (DME) support to include:

• Implementing patches, modifications, improved or enhanced functionalities;

• Providing specialized reports as requested and in accordance with PPS specifications; and

• Correcting any non-warranty issues, glitches, aberrations or errors.

2.4 Operational Artifacts

The contractor shall be responsible for the production and maintenance of all operational artifacts required to maintain operations to include:

• SaaS Cloud Services ConOps;

• SaaS Service Management and Operational Management Guide;

• Service Level Agreement(s)

• Service Delivery Report

3.0 Task 2: Cybersecurity

The contractor shall provide cybersecurity support for the solution, in coordination with the Government’s Se-curity Operations Center (SOC) and Enterprise Operations Center (EOC). This includes providing methods for authorized government privileged users to access performance and operational information directly and in real time to support security and operational performance monitoring. The contractor shall provide automatic monit-oring of resource utilization and events (to include failures and degradation of service) via web interface and documented application programming interfaces (APIs) that are intuitive and easy to use. These APIs must have online documentation that is readily discoverable, including example code, as demonstrated by publicly access-ible web URL.

3.1 Continuous Monitoring

The contractor shall be responsible for the continuous monitoring and reporting to the Government ISO or sys-

USCA19BPAC1010 - Page 3 of 8 tem ISSOs for all assets to include, but not limited to, the patch and vulnerability status of all assets. The con-tractor shall perform vulnerability scanning a minimum of every 30 days with reporting to the Enterprise Vul-nerability Scanning system. The contractor shall log to the Enterprise solution and ensure the logging, patching, anti-virus, and HIPS (if required) subsystems are installed and functioning on all assets.

The contractor shall prepare security reports detailing all assets and all missing patches or out of configura-tion weaknesses.

The contractor shall mitigate High/Critical vulnerabilities within 30 days from the date vulnerabilities are form-ally identified. The contractor shall mitigate Moderate vulnerabilities within 90 days and Low vulnerabilities within 180 days.

The contractor shall engage the Government for the pre-release security assessment and validation of releases prior to going live in production.

3.2 Security Artifacts

The contractor shall be responsible for the production and maintenance of all FedRamp and JISF required arti-facts, maintaining a robust and verifiable continuous monitoring program. The contractor shall track, via the Government's Global Risk Compliance (CSAM) tool, all security artifacts, vulnerabilities, assessments, Plan of Action and Milestones (POA&Ms), and resulting weaknesses.

The contractor shall document each external interface via an Interconnection Security Agreement prepared by the contractor’s cybersecurity staff. An external interface is one that the system connecting to the PPS CCMS is not owned and operated by the Government's Case Management Systems Office and security documentation, system security plans, POA&Ms, and all required artifactsshall be stored in the CSAM.

4.0 Meetings

4.1 Kick-off Meeting

The contractor shall participate in a kick-off meeting with the Government within ten business days after the award date or other mutually agreed upon timeframe. The kick-off meeting will be held at the Government’s fa-cility in Washington, DC.

The meeting is intended to:

- Initiate the communication process between the Government and contractor by introducing key task parti-cipants and discussing roles and responsibilities.

- To ensure the Contractor has a full understanding of the objectives and requirements.

4.2 Other Meetings

The contractor shall participate in other facilitated meetings (e.g., planning, reviews, demonstrations etc.) as re-quired and necessary with the Governement to ensure the successful delivery and execution of the requirements.

Applicable Clauses

F-1 Deliverables

The contractor shall submit electronic copies of document deliverables to the COR and other government staff, as necessary, via email unless otherwise directed by the COR. All deliverables submitted in electronic format shall be free of any known computer virus or defects. If a virus or defect is found, the deliverable will not be ac-cepted. The replacement file shall be provided within two (2) business days after notification of the presence of a virus.

Deliverables are as follows:

Deliverable Description Task Frequency FedRamp Accredidation Package

All FedRamp security doc-umentation for the Solution

2 Update as required for any substantive change in the

USCA19BPAC1010 - Page 4 of 8 required by the AO to com-plete a risk assessment of the system relative to NIST and JISF controls. Required documents include:

- System Security Plan

- Security Assessment Plan

- Security Assessment Re-port

- Continuous Monitoring Scorecard and Plan

- Plan of Actions and Mile-stone Report

- Security Control Imple-mentation Worksheet system.

Invoices Fully itemized invoice for services provided during a given month.

All Monthly

Knowledge Base System

(KBS)

A system that is generated and utilizes knowledge from different sources, data and information. It provides a summary of in-formation for efficient ac-cess for system users to search through knowledge base content for articles and other resources.This KBS should aid in solving problems, especially com-plex ones, by utilizing arti-ficial intelligence concepts.

The KBS should be used in problem-solving proced-ures and to support human learning, decision making and actions.

1 Within 30 days of Award.

Update as required.

Progress Status report Detailed report describing accomplishments, risks, is-sues, plans, labor hours, ODCs etc.

All Monthly

SaaS Cloud Services Con- Ops

Detailed description of the Solution from concept to operations. The document should define the necessary operational and quality control processes and pro-cedures to validate and im-plement, operate and main-tain the system to include, but not limited to, configur-ation management, integra-tion, test and validation.

1 Update as required.

SaaS Service Management Describes the operations 1 Update as required.

USCA19BPAC1010 - Page 5 of 8 and Operational Manage-ment Guide roles and responsibilities and standard procedures that will be used for monit-oring, patching, updating, user account management, monitoring, and incident management. The incident management procedures shall also detail the issue resolution process to ensure the timely resolution of all reported issues and incid-ents based on severity and priority. The document should also include the pro-cesses and procedures to support continuity of oper-ations and disaster recov-ery.

Service Desk Ticket Ana-lysis

Analysis of historical ser-vice desk trouble tickets that provides insight into causes and frequency, and provides recommendations for corrective action, or to examine trends and correct conditions for causes.

1 Monthly. Format agreed to after award.

Service Delivery Report Report showing cloud ser-vice delivery metrics in-cluding planned and un-planned outages and per-formance relative to prom-ised SLAs. The Offeror shall provide cloud-service usage reports for the entire contract, by account, and by specific user or tenant organizations.

The Report shall include details on the data gathered and the methodology used to establish the reported metrics.

The Contractor must provide prompt notification and follow up reporting on all service incidents and problems reported.

1 Monthly. Format agreed to after award.

F-2 Place of Performance and Hours of Operation

USCA19BPAC1010 - Page 6 of 8

The primary place of performance shall be at contractor facility within the Continental United States (CONUS).

Hours of operation are in accordance with those stated in section 2.2 under Task 1 - Operations and Mainteance of C-1 Requirements.

F-3 Period of Performance

The period of performance is for twelve months starting with deployment of the IOC for up to 1,000 users.

H-1 Key Personnel

The following position is considered key personnel by the government under this BPA call pursuant to clause 2-65 Key Personnel in base agreement. The required skills, experience, and qualifications are described below.

These positions must be filled by contractor personnel. Subcontractor personnel are not permitted to serve as key personnel.

IT Operations Manager (Labor Category Level - Senior) Oversees and directs the day-to-day activities of (IT) operations, ensuring that systems, services, and infrastruc-ture work reliably and securely. Lead teams that develop and implement networks and servers, respond to user help desk requests, and monitor system stability and performance. Provides guidance and leadership to the IT operations teams and technicians, but also directly supports end users by handling escalations, resolving user is-sues, and monitoring the performance of business-critical systems to proactively prevent delays and outages and quickly resolve ongoing issues.

Experience: Minimum of six (6) years of experience management of large scale, complex systems. Experience wth ITIL and ITSM.

Education: Bachelor’s degree in related field.

H-2 Government Furnished Equipment

The Government will furnish to contractor employees performing work on government premises on-site office space, furniture, telephone service (for official government business only), and other necessary equipment and supplies applicable to performing the requirements set forth in this BPA Call. For contractor personnel working off government premises, the Government will be provide the applicable equipment and software to perform the requirements outlined in this BPA Call. The contractor shall be responsible for proper utilization and safeguard-ing of all Government property provided for contractor use. Contractor employees must immediately report damage, theft, or loss of Government property to the COR.

H-3 Key Performance Indicators

The contractor shall be responsible for meeting the key performance indicators (KPI) stated below. The table below provides a description of the KPI, the acceptable standard, and the Government's method of measure-ment.

Name Description Measurement Standard AQL Measurement Frequency

Response Time Number of seconds it takes for a transaction to be completed from the initial user input and the system's response back to the user.

Number of seconds it takes for a transaction to be completed from the initial user input and the system's response back to the user.

<0.5 seconds to <0.1 seconds

100% of the time. Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report

USCA19BPAC1010 - Page 7 of 8

Does not include communication with external sys-tems processing.

Data Availability Data availability to all instances of the system within the prescribed period.

Number of seconds it to view and access data once the transac-tion has com-pleted.

<0.5 seconds to <0.1 seconds

100% of the time. Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report

System Availabil-ity

System Opera-tional Availability (Ao) threshold to assess the total time the system is capable of being used.

Ao is calculated by taking the available service less the number of planned and un-planned service outages divided by the available service less the planned service outage

>=99.6% given network availabil-ity >= the SLA for the network

100% of the time Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report

Recovery Point Objective (RPO)

The allowable time data must be recovered from backups in the event of a failure.

Number of hours in data loss after a failure.

4 hours 100% of the time Immediately upon restoration of ser-vice and included in Monthly Sum-mary via Service Delivery Report

Recovery Time Objective (RTO)

Allowable time service must be restored in the event of a failure.

Number of hours the system is re-stored after a fail-ure.

12 hours 100% of the time Immediately upon restoration of ser-vice and included in Monthly Sum-mary via Service Delivery Report

Scheduled Down-time

Minimize the number of sched-uled downtime per month.

Number of hours scheduled down-time per month

3 hours 100% of the time Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report

Security Controls The Contractor’s Solution shall provide the re-quisite security as indicated in the Objectives.

JISF, FedRamp Security Controls, CJI Assessments

Meets all security requirements as indicated in the Objectives

100% currency and adherence

Monthly Sum-mary delivered with Service De-livery Report

Security Vulner-abilities

The Contractor's Solution shall en-sure the timely resolution to all reported security vulnerabilities.

Rate at which vul-nerabilities are re-solved as docu-mented in POAMs

7 days for zero-day patches; 30 days for High/ Criticals; 90 for Moderates; 180 for Lows

100% of the time Monthly Sum-mary delivered with Service De-livery Report

USCA19BPAC1010 - Page 8 of 8

File details come from the government source that posted it.