USCA19BPAC1010_v2.pdf
PDF 28 KB Posted
- Attached to
- PPS Client Case Management BPA Federal contract opportunity
- Solicitation number
- USCA19R0062
- Issued by
- The Judicial Branch
About this file
BPA Call USCA19BPAC1010 v2
View the file
Other files for this federal contract opportunity
Show all 22
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ORDER FOR SUPPLIES OR SERVICES
IMPORTANT: Mark all packages and papers with contract and/or order numbers.
1. DATE OF ORDER 2. CONTRACT NO. (If any) 6. SHIP TO:
Office of Probation and Pretrial Services Administrative Office of the United States Courts One Columbus Circle, N.E.
Suite 4-300 Washington, DC 20544-0001
3. ORDER NO.
USCA19BPAC1010
4. REQUISITION/REFERENCE NO.
Manish Patel, 202-502-3258 Procurement Management Division Administrative Office of the United States Courts One Columbus Circle, N.E.
Suite 3-250 Washington, DC 20544-0001
5. ISSUING OFFICE (Address correspondence to)
7. TO:
8. TYPE OF ORDER
a. PURCHASE
REFERENCE YOUR: ____________
Please furnish the following on the terms and conditions specified on both sides of this order and on the attached sheet, if any, including delivery as indicated.
X b. DELIVERY -- Except for billing instructions on the reverse, this delivery order is subject to instructions contained on this side only of this form and is issued subject to the terms and conditions of the above-numbered contract.
9. ACCOUNTING AND APPROPRIATION DATA 10. REQUISITIONING OFFICE
11. NOT USED 12. F.O.B. POINT
14. GOVERNMENT B/L NO. 15. DELIVER TO F.O.B. POINT ON
OR BEFORE (Date)
16. DISCOUNT TERMS13. PLACE OF
a. INSPECTION b. ACCEPTANCE
17. SCHEDULE
CLIN NO.
(a)
SUPPLIES OR SERVICES
(b)
QUANTITY
ORDERED
(c) UNIT (d)
UNIT PRICE
(e)
AMOUNT
(f)
QUANTITY
ACCEPTED
(g)
See Lines
SEE BILLING
INSTRUCTIONS
ON
REVERSE
18. SHIPPING POINT 19. GROSS SHIPPING WEIGHT 20. INVOICE NO.
$0.00 17(h) TOT.
(Cont.
pages)
21. MAIL INVOICE TO:
a. NAME Office of Probation and Pretrial Services
b. STREET ADDRESS(or P.O. Box) Administrative Office of the United States Courts, One Columbus Circle, N.E., Suite 4-300
c. CITY Washington
d. STATE
DC
e. ZIP CODE 20544-0001
$0.00
17(i)
GRAND
TOTAL
22. UNITED STATES OF AMERICA BY (Signature)
23. NAME (Typed)
Manish Patel
TITLE: CONTRACTING/ORDERING OFFICER
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION NOT USABLE
OPTIONAL FORM 347 (REV. 02/2012)
Prescribed by GSA/FAR 48 CFR 53.213(f)
USCA19BPAC1010 - Page 1 of 8
Supplies or Services and Prices/Costs
CLIN NO. Supplies or Services Quantity Unit of Issue Unit Price Extended Amount
0001 Provide Operations and Maintenance Support in accordance with section 2.0 in C-1 Requirements.
(Firm Fixed Price)
1 Month $0.00 $0.00
CLIN NO. Supplies or Services Quantity Unit of Issue Unit Price Extended Amount
0002 Provide Cybersecurity services in accordance with section 3.0 in C-1 Requirements. (Firm Fixed
Price)
1 Month $0.00 $0.00
Descriptions/Specifications/Statement of Work
C-1 Requirements
1.0 Scope
This BPA Call is for the operations and maintenance support, including cybersecurity, of the Probation and Pre-trial Services Client Case Management (PPS CCM) Initial Operating Capablity (IOC) deployment of up to 1,000 unique users (with approximately one quarter concurrently).
2.0 Task 1: Operations and Maintenance
Operations and Maintenance (O&M) support shall include maintaining the systems and software availability and recovery, help desk support, development, maintenance and enhancement support.
2.1 Systems Software Availability and Recovery
The contractor’s solution shall require a FedRamp compliant environment that meets the following minimum availability and recovery thresholds. Availability is calculated by taking the available service less the number of planned and unplanned service outages divided by the available service less the planned service outage.
• FedRamp Cloud Availability – 99.6%, Threshold
• Recovery Point Objective (RPO) – 4 hours, Threshold
• Recovery Time Objective (RTO) – 12 hours, Threshold
The contractor shall develop an operations framework to maintain and sustain operations to include a Continu-ous Product Improvement (CPI) process to collect metrics on operations support and provide recommendations to the Government to improve efficiencies and resolve bottlenecks. The contractor shall collaborate with the Government to finalize operations procedures, roles and responsibilities.
2.2 Help Desk Support
The contractor shall work with the AO operations support staff (including contractors) to resolve issues and ser-vice requests. The Government’s Enterprise Operations Center (EOC) National Support Desk (NSD) provides 24/7 Tier 1 support to all users. Tier 1 support serves as the user’s single point of contact for all incident and service request submissions related to the Judiciary’s national systems. Their objective is to resolve known in-cidents on the first contact. The EOC-NSD performs the following tasks:
• Log, document, classify, and resolve known incidents to restore a failed IT service as quickly as possible
USCA19BPAC1010 - Page 2 of 8
• Log document, classify, and communicate all service requests as quickly as possible
• Serve as the single point of contact for the users and keep users informed about the status of their incident or service request statuses through the ticketing system or phone call
• Ensure users issues are successfully resolved and their resolutions are correctly logged in the EOC-NSD Service Management system
• Escalate incidents to the appropriate support tier when necessary or when a documented solution is not available or cannot be applied
• Collect all the necessary information to assist in resolving incidents or service requests
• Communicate and document progress and resolution in the EOC-NSD Service management system to keep users up-to-date on incident or service request statuses
• Process Modification (Change) Requests (MRs) and keep users informed about their statuses at agreed upon intervals.
The contractor shall provide prompt correction of all Tier 2 and 3 incidents and service requests escalated from Tier 1 that the Government’s EOC-NSD (NSD) cannot resolve inclusive of glitches, aberrations and errors in the application programming; and/or documentation about which the contractor is either informed by the Gov-ernment or otherwise becomes aware.
The contractor shall provide support to end users between 6:00 AM EST – 8:00 PM EST, Monday through Thursday, 6:00 AM EST – 5:00 PM EST on Fridays, 8:00 AM EST – 4:00 PM EST on Sundays excluding Government holidays, and remotely for on-call after hour support (including Saturdays and Government holi-days). The contractor shall provide the Government visibility into the contractor’s service management system via direct access or an integration/bridge to the Government’s Service Management system (currently HEAT), which is the system of record for all service tickets. The contractor shall also establish a knowledge base system to support all Tiers and users.
2.3 Development, Maintenance, and Enhancement Support
The contractor shall provide development, maintenance, and enhancement (DME) support to include:
• Implementing patches, modifications, improved or enhanced functionalities;
• Providing specialized reports as requested and in accordance with PPS specifications; and
• Correcting any non-warranty issues, glitches, aberrations or errors.
2.4 Operational Artifacts
The contractor shall be responsible for the production and maintenance of all operational artifacts required to maintain operations to include:
• SaaS Cloud Services ConOps;
• SaaS Service Management and Operational Management Guide;
• Service Level Agreement(s)
• Service Delivery Report
3.0 Task 2: Cybersecurity
The contractor shall provide cybersecurity support for the solution, in coordination with the Government’s Se-curity Operations Center (SOC) and Enterprise Operations Center (EOC). This includes providing methods for authorized government privileged users to access performance and operational information directly and in real time to support security and operational performance monitoring. The contractor shall provide automatic monit-oring of resource utilization and events (to include failures and degradation of service) via web interface and documented application programming interfaces (APIs) that are intuitive and easy to use. These APIs must have online documentation that is readily discoverable, including example code, as demonstrated by publicly access-ible web URL.
3.1 Continuous Monitoring
The contractor shall be responsible for the continuous monitoring and reporting to the Government ISO or sys-
USCA19BPAC1010 - Page 3 of 8 tem ISSOs for all assets to include, but not limited to, the patch and vulnerability status of all assets. The con-tractor shall perform vulnerability scanning a minimum of every 30 days with reporting provided by an industry standard solution. The contractor shall implement audit logging and provide reports utilizing an industry stand-ard solution. The contractor shall utilize an industrystandard Host Intrusion Prevention system (HIPS) and provide reporting as necessary. The contractor shall ensure the logging, patching, anti-virus, anti-malware, and HIPS subsystems are installed and functioning on all assets by providing inventory reports.
The contractor shall prepare security reports detailing all assets and all missing patches or out of configura-tion weaknesses.
The contractor shall mitigate High/Critical vulnerabilities within 30 days from the date vulnerabilities are form-ally identified. The contractor shall mitigate Moderate vulnerabilities within 90 days and Low vulnerabilities within 180 days.
The contractor shall engage the Government for the pre-release security assessment and validation of releases prior to going live in production.
3.2 Security Artifacts
The contractor shall be responsible for the production and maintenance of all FedRamp and JISF required arti-facts, maintaining a robust and verifiable continuous monitoring program. The contractor shall track, via the Government's Global Risk Compliance (CSAM) tool, all security artifacts, vulnerabilities, assessments, Plan of Action and Milestones (POA&Ms), and resulting weaknesses.
The contractor shall document each external interface via an Interconnection Security Agreement prepared by the contractor’s cybersecurity staff. An external interface is one that the system connecting to the PPS CCMS is not owned and operated by the Government's Case Management Systems Office and security documentation, system security plans, POA&Ms, and all required artifactsshall be stored in the CSAM.
4.0 Meetings
4.1 Kick-off Meeting
The contractor shall participate in a kick-off meeting with the Government within ten business days after the award date or other mutually agreed upon timeframe. The kick-off meeting will be held at the Government’s fa-cility in Washington, DC.
The meeting is intended to:
- Initiate the communication process between the Government and contractor by introducing key task parti-cipants and discussing roles and responsibilities.
- To ensure the Contractor has a full understanding of the objectives and requirements.
4.2 Other Meetings
The contractor shall participate in other facilitated meetings (e.g., planning, reviews, demonstrations etc.) as re-quired and necessary with the Governement to ensure the successful delivery and execution of the requirements.
Applicable Clauses
F-1 Deliverables
The contractor shall submit electronic copies of document deliverables to the COR and other government staff, as necessary, via email unless otherwise directed by the COR. All deliverables submitted in electronic format shall be free of any known computer virus or defects. If a virus or defect is found, the deliverable will not be ac-cepted. The replacement file shall be provided within two (2) business days after notification of the presence of a virus.
Deliverables are as follows:
Deliverable Description Task Frequency
USCA19BPAC1010 - Page 4 of 8
FedRamp Accredidation Package
All FedRamp security doc-umentation for the Solution required by the AO to com-plete a risk assessment of the system relative to NIST and JISF controls. Required documents include:
- System Security Plan
- Security Assessment Plan
- Security Assessment Re-port
- Continuous Monitoring Scorecard and Plan
- Plan of Actions and Mile-stone Report
- Security Control Imple-mentation Worksheet
2 Update as required for any substantive change in the system.
Invoices Fully itemized invoice for services provided during a given month.
All Monthly
Knowledge Base System
(KBS)
A system that is generated and utilizes knowledge from different sources, data and information. It provides a summary of in-formation for efficient ac-cess for system users to search through knowledge base content for articles and other resources.This KBS should aid in solving problems, especially com-plex ones, by utilizing arti-ficial intelligence concepts.
The KBS should be used in problem-solving proced-ures and to support human learning, decision making and actions.
1 Within 30 days of Award.
Update as required.
Progress Status report Detailed report describing accomplishments, risks, is-sues, plans, labor hours, ODCs etc.
All Monthly
SaaS Cloud Services Con- Ops
Detailed description of the Solution from concept to operations. The document should define the necessary operational and quality control processes and pro-cedures to validate and im-plement, operate and main-tain the system to include, but not limited to, configur-ation management, integra-
1 Update as required.
USCA19BPAC1010 - Page 5 of 8 tion, test and validation.
SaaS Service Management and Operational Manage-ment Guide
Describes the operations roles and responsibilities and standard procedures that will be used for monit-oring, patching, updating, user account management, monitoring, and incident management. The incident management procedures shall also detail the issue resolution process to ensure the timely resolution of all reported issues and incid-ents based on severity and priority. The document should also include the pro-cesses and procedures to support continuity of oper-ations and disaster recov-ery.
1 Update as required.
Service Desk Ticket Ana-lysis
Analysis of historical ser-vice desk trouble tickets that provides insight into causes and frequency, and provides recommendations for corrective action, or to examine trends and correct conditions for causes.
1 Monthly. Format agreed to after award.
Service Delivery Report Report showing cloud ser-vice delivery metrics in-cluding planned and un-planned outages and per-formance relative to prom-ised SLAs. The Offeror shall provide cloud-service usage reports for the entire contract, by account, and by specific user or tenant organizations.
The Report shall include details on the data gathered and the methodology used to establish the reported metrics.
The Contractor must provide prompt notification and follow up reporting on all service incidents and problems reported.
1 Monthly. Format agreed to after award.
USCA19BPAC1010 - Page 6 of 8
F-2 Place of Performance and Hours of Operation
The primary place of performance shall be at contractor facility within the Continental United States (CONUS).
Hours of operation are in accordance with those stated in section 2.2 under Task 1 - Operations and Mainteance of C-1 Requirements.
F-3 Period of Performance
The period of performance is for twelve months starting with deployment of the IOC for up to 1,000 users.
H-1 Key Personnel
The following position is considered key personnel by the government under this BPA call pursuant to clause 2-65 Key Personnel in base agreement. The required skills, experience, and qualifications are described below.
These positions must be filled by contractor personnel. Subcontractor personnel are not permitted to serve as key personnel.
IT Operations Manager (Labor Category Level - Senior) Oversees and directs the day-to-day activities of (IT) operations, ensuring that systems, services, and infrastruc-ture work reliably and securely. Lead teams that develop and implement networks and servers, respond to user help desk requests, and monitor system stability and performance. Provides guidance and leadership to the IT operations teams and technicians, but also directly supports end users by handling escalations, resolving user is-sues, and monitoring the performance of business-critical systems to proactively prevent delays and outages and quickly resolve ongoing issues.
Experience: Minimum of six (6) years of experience management of large scale, complex systems. Experience wth ITIL and ITSM.
Education: Bachelor’s degree in related field.
H-2 Government Furnished Equipment
The Government will furnish to contractor employees performing work on government premises on-site office space, furniture, telephone service (for official government business only), and other necessary equipment and supplies applicable to performing the requirements set forth in this BPA Call. For contractor personnel working off government premises, the Government will be provide the applicable equipment and software to perform the requirements outlined in this BPA Call. The contractor shall be responsible for proper utilization and safeguard-ing of all Government property provided for contractor use. Contractor employees must immediately report damage, theft, or loss of Government property to the COR.
H-3 Key Performance Indicators
The contractor shall be responsible for meeting the key performance indicators (KPI) stated below. The table below provides a description of the KPI, the acceptable standard, and the Government's method of measure-ment.
Name Description Measurement Standard AQL Measurement Frequency
Response Time Number of seconds it takes for a transaction to be completed from the initial user input and the system's response
Number of seconds it takes for a transaction to be completed from the initial user input and the system's response
<0.5 seconds to <0.1 seconds
100% of the time. Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report
USCA19BPAC1010 - Page 7 of 8 back to the user.
Does not include communication with external sys-tems processing.
back to the user.
Data Availability Data availability to all instances of the system within the prescribed period.
Number of seconds it to view and access data once the transac-tion has com-pleted.
<0.5 seconds to <0.1 seconds
100% of the time. Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report
System Availabil-ity
System Opera-tional Availability (Ao) threshold to assess the total time the system is capable of being used.
Ao is calculated by taking the available service less the number of planned and un-planned service outages divided by the available service less the planned service outage
>=99.6% given network availabil-ity >= the SLA for the network
100% of the time Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report
Recovery Point Objective (RPO)
The allowable time data must be recovered from backups in the event of a failure.
Number of hours in data loss after a failure.
4 hours 100% of the time Immediately upon restoration of ser-vice and included in Monthly Sum-mary via Service Delivery Report
Recovery Time Objective (RTO)
Allowable time service must be restored in the event of a failure.
Number of hours the system is re-stored after a fail-ure.
12 hours 100% of the time Immediately upon restoration of ser-vice and included in Monthly Sum-mary via Service Delivery Report
Scheduled Down-time
Minimize the number of sched-uled downtime per month.
Number of hours scheduled down-time per month
3 hours 100% of the time Weekly/Monthly Summary via On-line Service Dash-board and Service Delivery Report
Security Controls The Contractor’s Solution shall provide the re-quisite security as indicated in the Objectives.
JISF, FedRamp Security Controls, CJI Assessments
Meets all security requirements as indicated in the Objectives
100% currency and adherence
Monthly Sum-mary delivered with Service De-livery Report
Security Vulner-abilities
The Contractor's Solution shall en-sure the timely resolution to all reported security vulnerabilities.
Rate at which vul-nerabilities are re-solved as docu-mented in POAMs
7 days for zero-day patches; 30 days for High/ Criticals; 90 for Moderates; 180 for Lows
100% of the time Monthly Sum-mary delivered with Service De-livery Report
USCA19BPAC1010 - Page 8 of 8
File details come from the government source that posted it.