About this file

This document summarizes a solicitation for software developer support services for the Theater Integrated Combat Munitions System. The Air Force seeks to award a firm fixed price contract for a one year base period and three one-year options to One Network Enterprises, Inc. for software configuration, testing, and deployment of operational capabilities. One Network Enterprises, Inc. is currently the only qualified vendor due to their ownership of the proprietary One Network software that powers the TICMS application. The solicitation is located on SAM.gov and interested parties should contact One Network Enterprises, Inc. regarding potential subcontracting opportunities. No response is required from offerors as this is a sole source procurement to the incumbent, One Network Enterprises, Inc.

View the file

Other files for this federal contract opportunity

Other files attached to TICMS - Software Support & Development Solicitation, newest first.
File Type Posted
04 Example RFP Template.xlsx XLSX spreadsheet
03 DD254 Draft.pdf PDF
01 FA821322R3038_Solicitation_10 NOV 2022.pdf PDF
02 CDRLS - EXHIBIT A.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Controlled Un-Classified (CUI) TICMS PWS Oct 2022

PERFORMANCE WORK STATEMENT (PWS)

FOR

Theater Integrated Combat Munitions System (TICMS) & IT System Configuration Services

FOR

AFLCMC/EBH

Hill Air Force Base, Utah

PWS

October 2022

Table of Contents

1.0 INTRODUCTION

1.1 Purpose

1.2 Scope

1.3 Background

2.0 APPLICABLE DOCUMENTS

2.1 Cybersecurity Compliance

3.0 DESCRIPTION OF SERVICES

3.1 Overall Support

3.2 Software Developer

3.3 Quality Assurance

3.4 Program Manager

3.5 System Architect

3.6 Functional Support

3.7 Technical Writer

3.8 General Requirements

3.8.1 Sprint Requirements

3.8.2 NIPRNet / SIPRNet

3.8.3 Source Code Scanning

3.8.4 Code Release Process

3.8.5 TICMS Sub-summation

3.9 Functionality

4.0 PROGRAM MANAGEMENT

4.1 Management of Personnel

4.2 Program Manager

4.3 Technical Lead

4.4 Meeting Attendance

4.5 Schedule

4.6 Hours of Operations / Federal Holidays

5.0 DELIVERABLES

5.1 Weekly Status Review

5.2 Personnel Roster Associated with Billing

5.3 Sprint Cycle / Release

5.3.1 Definitions Associated with JIRA / Confluence

5.4 Quality Assurance Results with Each Release

5.5 Technical Triage Sessions

5.6 Code Scanning Tools

6.0 GENERAL INFORMATION

6.1 Place of Performance

6.2 Period of Performance

6.3 Travel / Other Direct Costs (ODC)

6.4 Non-Personal Services

6.5 Ethics

6.6 Inherently Governmental Functions

6.7 Data Rights

7.0 SAFETY

7.1 Ensuring Adequate COVID-19 Safety Protocols for Federal Contractors (Deviation 2021-O0009, Revision 1) (Oct 2021)

8.0 SECURITY

8.1 Common Access Cards (CAC)

8.2 Non-Disclosure Agreements (NDAs)

8.3 Access

8.4 Security Clearances

8.5 Protection of Information

8.6 Classified Information

8.7 Trustworthiness Determination

8.8 Operations Security (OPSEC)

8.9 Reporting Requirements

9.0 GOVERNMENT QUALITY

9.1 Government Provided Quality Assurance Surveillance Plan (QASP) related to this PWS

9.2 Contractor Performance Assessment Reporting System (CPARS) Applicability

9.3 Quality of Support / Service

9.4 Government Inspection

9.5 Government Point of Contacts (POCs)

10.0 Government Furnished Equipment / Property (GFE / GFP)

10.1 Applicability

11.0 APPENDIX A: Acronyms

12.0 APPENDIX B: Services Summary (SS) Table

13.0 APPENDIX C: Reserved

1.0 INTRODUCTION

1.1 Purpose

This Performance Work Statement (PWS) defines the support required to continue the utilization of software developers and system experts on the One Network Enterprises, Incorporated (One Inc.) proprietary software system relating to the configuration of the Theater Integrated Combat Munitions System (TICMS) software suite to include the TICMS platform and its corresponding database, structure, and tables. The support requires the Contractor to work directly with Government IT System and Munitions Subject Matter Experts (SMEs) to employ agile software delivery methodologies to implement functionalities within the TICMS application. This continued proprietary One Inc./TICMS configuration enables the functions, processes, and procedures necessary to manage the United States Air Force (USAF) stockpile of conventional munitions, class of supply V. This includes, but is not limited to, tactical missiles, strategic missiles (conventional portions), conventional munitions, and Cartridge Actuated Devices/Propellant Actuated Devices (CAD/PAD) stockpiles. The system also manages related munitions composition data, maintenance data documentation, baseline business process optimization, and Operational Safety, Suitability and Effectiveness (OSS&E) programs. Additionally, the software configuration for use in the Secure Internet Protocol Router Internet (SIPRNet) environment will be required within the contract’s scope. All classified development will be performed in Government facilities on Hill Air Force Base. Therefore, Contractor developers will require a Common Access Card (CAC) and SIPRNET access. See Sections 3 and 8 for additional details.

1.2 Scope

The scope identified in this PWS will be completed within a one 1-year base with three 1-year option years. The Contractor will configure, test, and deploy operational capabilities as defined and prioritized by the USAF within the following high-level functionalities which are further elaborated in Section 3.0, Description of Services:

a. Stock Management and Control/Accountability

b. Life Cycle Management

c. Distribution Management

d. Foreign Military Sales (FMS)

e. Maintenance, Serviceability, & Reliability

f. Financial Management o FIAR (Financial Improvement and Audit Readiness) o FISCAM (Federal Information System Controls Audit Manual) o FFMIA (Federal Financial Management Improvement Act)

g. Technical Data Management

h. Data Management and Archival

i. Munitions Command, Control Operations

j. System Roles and Access Controls

k. SIPRNet Enclave Ops

l. OSS&E

m. MIT (Munitions Integrated Tablet) and Disconnected Client

It is expected the Contractor will employ the agile IT development methodology processes and objectives to deliver capability amongst the major functionalities listed at 1.2 above as prioritized by the USAF. The magnitude of the development/changes/configuration will not exceed the proposed Contractor Manpower Equivalents (CMEs) in any one sprint cycle.

Labor categories/skill levels within the Period of Performance (PoP) shall be aligned with the spring cycle. If changes are required, they will be identified to the Contracting Officer Representative (COR) and the COR to the Contracting Officer (CO).

Sprint cycles will be four to six weeks long in duration. It will also account for One Inc. code development, Quality Assurance (QA), and User Acceptance Testing (UAT) by both the TICMS Functional Management Office (FMO) and Contractor and will include Cybersecurity testing and scanning. A minimum of nine (9) total sprint cycles are expected to be completed within one year. However, this may vary depending on the complexity of the tasks and development performed.

As with all agile IT development, detailed backlog features will be implemented for each of the above functional requirements and identified during the planning phase of each developmental sprint. Platform level changes will be considered within the scope of this PWS and within each sprint to accommodate this expectation, design, configuration, and deployment of infrastructure. Platform level changes are defined as similar to the conversion of the primary core of the application from RTVN (Real-Time Value Network) to NEO (One Inc. proprietary AI), or similar type changes. The Contractor shall apply modern commercial, cloud-based architecture, security, design, technologies, services, frameworks, and practices to the fullest extent possible in the technical execution of the functional requirements in the various sprints. Delivery of the full scope of the functional requirements is expected to be executed iteratively over multiple sprint efforts. IT systems are dynamic and always evolving; therefore, it is NOT expected that complete IT development and configuration will be completed within any one individual Period of Performance (POP).

SIPRNet development will begin as appropriate within the total PoP of the contract as determined by the Government in conjunction with the Contractor and TICMS system stability and capability is achieved. Additionally, the Contractor shall continuously adhere to STIGs (Security Technical Implementation Guide) and guidelines within DoD 8570.01- M, Information Assurance Workforce Improvement Program, and all applicable DoD IT and Cybersecurity guidelines. IT Personnel assigned CAC’s will attain appropriate DoD 8570.01-M certifications (Security+).

1.3 Background

The TICMS FMO is located at Hill Air Force Base, Utah, and is aligned under AFLCMC/EBH. The TICMS application is the Accountable Property System of Record (APSR) for all USAF Class V conventional munitions inventory. The proprietary version of the One Inc. software is the backbone of the total capability within the TICMS Class V module.

System configuration and modifications in previous contracting actions were accomplished under several contracts, the most recent being Order # N6426720F0251 for 2.5 years.

Additionally, the Naval Surface Warfare Center (NSWC) released Contract NNG15SD87B, Order # N6426720F0002 for ONE Inc. dated 12 December 2019 for a duration of 5 years for annual system licensing.

The continuing goal of the TICMS FMO is to subsume all Class V munitions IT systems within the TICMS application. TICMS is scheduled to subsume seven munitions IT systems in the following order: IMDB (Integrated Missile Data Base), Tactical Munitions Reporting System (TMRS), Munitions Command and Control (MC2), Reliability Asset Monitoring (RAM), Ammo-Web, SIPRNet Ammo-Web, and Agile Munitions Support Tool (AMST).

Combat Ammunition System (CAS) was the first system to be fully subsumed in February 2020. The Order of subsummation may change by the USG for various reason but will always be coordinated with the vendor in advance.

2.0 APPLICABLE DOCUMENTS

2.1 Cybersecurity Compliance

Cybersecurity compliance is essential to achieve secure contractor-provided deliverables. DoD and Air Force guidance, below, constitute cybersecurity requirements to be complied with by the contractor, and are not intended to be a comprehensive listing. Cybersecurity requirements levied via contract clauses are excluded from the below.

a. DODD 8140.01, Cyberspace Workforce Management (https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/814001p.PDF )

b. DODI 8500.01, Cybersecurity (https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/850001_2014.pd f )

c. DODI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT) (https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001p.pdf )

d. AFI 17-101, Risk Management Framework (RMF) For Air Force Information Technology (IT) (https://static.e-publishing.af.mil/production/1/saf_cn/publication/afi17-101/afi17-101.pdf )

e. AFI 17-130, Cybersecurity Program Management (https://static.e-publishing.af.mil/production/1/saf_cn/publication/afi17-130/afi17-130.pdf )

f. NIST SP 800-53, Security and Privacy Controls for Information Systems and Organizations (https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800- 53r4.pdf )

Per NIST SP 800-53 Configuration Management security control CM-6, Security Technical Implementation Guide (STIG), or an industry best practice compliance process is required for U.S. Government Information Systems. Per the TICMS System Security Plan (SSP) the following STIGs, SRGs, or Center for Internet Security (CIS) benchmarks apply to TICMS. The Contractor shall support the compliance with each applicable STIG, SRG, or CIS. STIGs, SRGs, and CIS’ and their applicability are subject to change. Any changes shall be relayed to the Contractor by the USAF. The following STIGs apply to TICMS to date and require Contractor support:

g. Apache Tomcat Application Sever Security Technical Implementation Guide

h. Application Security and Development Security Technical Implementation Guide

i. Oracle Database Security Technical Implementation Guide or Database SRG

j. Red Hat Enterprise Linux 7 Security Technical Implementation Guide or General

Purpose Operating System Security Requirements Guide or applicable CIS benchmarks

The current link for DISA STIGs can be found at https://public.cyber.mil/stigs/. The Contractor shall monitor this site for newly applicable STIGs and changes to existing STIGs. The Contractor shall register for DISA STIG update notifications using the DISA SRG/STIG Mailing List service currently available at https://public.govdelivery.com/accounts/USDISA/subscriber/new?topic_id=USDISA_181.

3.0 DESCRIPTION OF SERVICES

3.1 Overall Support

The Contractor shall be capable of independently performing all tasks relevant to this PWS.

The Contractor shall have the experience and capability to support the assigned tasks and lead support personnel, including Government IT developers, in these tasks. This will be accomplished by leveraging a dedicated team of software and technical SMEs working in conjunction with Government counterparts that understand and work within the proprietary ONE Inc./TICMS product through incremental deliveries. The Contractor shall ensure the dedicated team working on the TICMS product is stable with minimal personnel turnover.

Changes in personnel must be reflected on the Personnel Roster per Section 5.2.

Implementation of new functionality within TICMS will be documented by the Government and Contractor during the scheduled sprint planning meetings. New functionality can be defined as subsuming current Air Force systems (i.e., IMDB, TMRS, MC2, RAM, Ammo- Web, SIPRNet Ammo-Web, and AMST) as well as maintaining the Contractor’s DoD Core and Industrial platforms. The Contractor shall implement agile software processes to deliver the functional capabilities identified throughout this document, including attachments.

The Contractor shall consider minimum manning and labor categories / grades defined below. A typical workday is eight hours, and a typical work year is no more than 1,880 hours per CME. It is understood by the USG that not all labor categories require a full year’s effort, i.e., a SME systems architect, which may only be forecasted for 125hrs a POP. In those instances, if additional hours are required the vendor will coordinate with the COR and the COR to the CO for contract adjustment as required to tailor in additional hours. The Government will not be available on federal holidays (Section 4.6).

3.2 Software Developer

Applies sound software engineering principles to developing software and systems that are modifiable, efficient, reliable (for the intended purpose), understandable, and fault-tolerant to meet systems requirements. Analyzes system specifications and designs outlined by the Systems Engineer. Reviews user functions, analyzes, designs, and codes detailed programs, models, and diagrams to meet specifications and design requirements. Duties include providing architecture, design and process management, and control input to support software maturity processes.

3.3 Quality Assurance

Develops, modifies, applies, and maintains standards for quality operating methods, processes, systems, and procedures. It also provides coordination and guidance in preparing technical appraisals of programming languages and systems, computational software and related technology, and integrating computers into the overall functions of scientific computation, data acquisition, transmission, and processing functions. Ensures that corrective measures meet acceptable reliability standards. Develops overall operating criteria to ensure implementation of the software quality program according to the project, process, and contract requirements and objectives. Ensures that project and process control documentation complies with requirements, objectives, and/or contract. Reviews software design, change specifications, and plans against contractual and/or process requirements. Reviews include applicable specifications, materials, tools, techniques, and methodologies. Performs or directs verification of software requirement allocations, traceability, and testability.

3.4 Program Manager

Duties include planning, directing, controlling, organizing, and coordinating the work activity of personnel involved in all aspects of this contract; implementing a quality assurance program to ensure services and products conform to applicable standards;

formulating statements of management and technical problems; evaluating proposed computer systems to determine technical feasibility, implementation costs, operation costs, and functional adequacy.

3.5 System Architect

Performs a variety of activities in information systems design, development, and analysis in the maintenance of enterprise-wide systems, encompassing one or more of the following areas of technical expertise: programming, computer application analysis, software development, systems integration, problem reporting, troubleshooting, collecting and reporting performance metrics, testing, verification checks, and related disciplines.

3.6 Functional Support

Duties include analyzing, defining, and documenting functional requirements; reviewing current Government procedures, manuals, regulations, technical manuals, standards, and industry publications that relate to the functional area specialty within the application.

3.7 Technical Writer

Writes in clear and concise language. Such as technical documents, procedure manuals, service manuals, and related technical publications concerned with installing, operating, and maintaining electronic, electrical, mechanical, and other equipment. Includes writing such technical documentation as operational specifications, bulletins, articles, and marketing publications. Acquires or verifies knowledge of the subject by interviewing workers engaged in developing new products and services or in making improvements, observing performance of experiments and methods of production, referring to blueprints, sketches, engineering drawings and notes, trade and engineering journals, rewrites of articles, bulletins, manuals, or similar publications. Assists the Government with the development of Architectural Views (AV), Overhead Views (OV), etc.

3.8 General Requirements

The Contractor shall only use cleared, U.S.-based resources to develop and/or configure TICMS releases. Exceptions are U.S. State Department cleared foreign nationals via export licensing procedures such as the previously utilized DSP-05 050711974, provided by the state department for an earlier contract. Additionally, the Contractor is responsible for maintaining currency of the document throughout the duration of the contract Pop. Failure to maintain an approved State Department Export License/Approval form will result in non-cleared personnel to be temporarily removed from the project until clearance is reestablished.

3.8.1 Sprint Requirements

The Contractor shall continue the configuration of the proprietary One Inc. platform and the TICMS software suite, which the Government will work on with its organic software developers in tandem with One Inc. developers as required and determined by the Government. This effort will be accomplished using an agile sprint methodology to be fully defined and mutually agreed upon between the Government and Contractor within each developmental sprint (i.e., system architecture, requirements definition, configuration, testing, QA, fixes, and deployment).

3.8.2 NIPRNet / SIPRNet

The Contractor shall be required to operate within the DoD Non-classified Internet Protocol Router Network (NIPRNet) environment where the TICMS application is hosted. Key personnel (i.e., Program Managers, developers, and functional support SMEs) will require a Common Access Card (CAC). Additionally, SIPRNet code development expects to begin in Option Year 1. The Contractor will be required to provide at least one senior-level software developer and the corresponding support architecture for work to be performed at Hill Air Force Base under the Government’s monitoring via the COR and/or Program Manager (PM).

The Contractor will be notified of SIPRNet work to start at least 90 days prior. The goal is to perform all classified code development within the Hill Air Force Base secure enclave. The Government will work with the Contractor to meet the CAC and SIPRNet token requirements. The Contractor will also be required to operate within the SIPRNet (Classified) environment on Hill Air Force Base, necessitating a DD Form 254, DoD Contract Security Classification Specification, to be provided by the Government. The Contractor will provide personnel with a minimum of a SECRET clearance for all SIPRNet/classified sprints to work within the classified environment on Hill Air Force Base.

The Government will ensure the Contractor is made aware of all impending security requirement changes, for which the Contractor will be responsible to implement immediately. Only eligible U.S. citizens may apply for and obtain a SECRET clearance. The Contractor shall work with the Government COR/PM to ascertain the total number and type of personnel (i.e., Program Manager, Developer, etc.) required to have and maintain a SECRET clearance throughout the PoP.

3.8.3 Source Code Scanning

The Contractor will, in all instances, provide un-compiled source code to the Government representative (TICMS Cybersecurity) associated with this contracting action for analysis and security scanning (i.e., Checkmarx, Xray, etc.) before the source code is promoted to the Government/DoD Amazon Web Services (AWS) Cloud NIPRNet /SIPRNet production/live environment. The Contractor will utilize the same scanning methodology as the Government prior to code delivery. Code scanning requirements are further outlined in Section 5.6.

3.8.4 Code Release Process

The Contractor shall work with the Government team. The Government will share the scanning results of the to-be-promoted code with the Contractor’s Program Manager and development SMEs, as required. The Contract shall also share their scanning results with the Government. The Government will also share its “eyes-on-source-code” process with the Contractor and accept recommendations for improvement from the Contractor’s functional support and system architecture SMEs. The Government will in no way consider accepting compiled code or executables from the Contractor; only source code can be accepted due to mandatory DoD security requirements. The Contractor shall ensure error-free code delivery to include all associated processes (i.e., hashkeys, configuration files, release notes, etc.)

upon providing code and instructions to the Government.

3.8.5 TICMS Sub-summation

TICMS is scheduled to subsume seven munitions IT systems in the following order: IMDB, TMRS, MC2, RAM, AMMO-WEB, SIPR AMMO-WEB, AMST. The detailed requirements for each system will be defined prior to each sprint cycle. The table below outlines the major functionalities within all seven munitions IT systems. This table does not dictate required functionality in any particular order; sub-functions may or may not be completed together within a major functionality. A sub-function may be developed earlier than others, while other sub-functions are deferred in later sprints or a future PoP. The Government will dictate the order of the tasks at the beginning of each sprint cycle and may agree to recommendations per the Contractor’s assessments of the work to be performed.

3.9 Functionality

MAJOR FUNCTIONALITY SUB-FUNCTIONALITY

3.9.1 STOCK MANAGEMENT FORECASTING (Requirements vs. Mission, Peacetime

Conventional Ammunition Requirements [PCAR]) (AMST) STOCK ALLOCATION (Fair Distribution of Limited Assets)

COMPLETE ROUND ASSEMBLY (Build-Up/Tear Down of missiles, munitions, etc.)

INVENTORY ADJUSTMENT PROCESS TO INCLUDE LOSS

REPORTING FOR ALL SYSTEMS BEING SUBSUMED

(Optimization)

STRATEGIC STRATIFICATION (Requirements vs. Inventory, to include tactical and strategic missiles, over FYDP) (AMMO

WEB)

BACK ORDER REQUISITION MONITORING SYS (BRMS in

FMS)

COMMERCIAL OFF THE SHELF (COTS management and approval)

CONVENTIONAL MUNITIONS RESTRICTED OR

SUSPENDED (CMRS), CURRENTLY WITHIN AMMO-WEB,

WILL INCLUDE TACTICAL AND STRATEGIC MISSILES

REQUIREMENTS AS WELL AS DATA MODEL RDM-

CAD/PAD

SERVICEABLE EXCESS

SUPPLEMENTAL ALLOCATION AUTHORIZATION

REQUEST (SAAR) AND ALL OTHER ALLOCATION

MANAGEMENT TO INCLUDE OOCR PROCESS, ATR,

FORECASTING, ALLOCATION, ETC.

INTERIM HAZARD CLASSIFICATION (Development and Workflow)

CONTRACTOR POSSESSED MUNITIONS (CPM)

MANAGEMENT AND REPORTING

3.9.2 LIFE CYCLE

MANAGEMENT PROCUREMENT DATABASE (AMST)

PRODUCT SUPPORT MANAGEMENT PLAN (PSMP)

WARRANTY

WEAPONS SYSTEM CONFIGURATION MGMT; CONTRACT

DATA REQUIREMENTS LIST (CDRL) MANAGEMENT

SUSTAINING ENGINEERING MANAGEMENT AND

ANALYSIS

JOINT ORDNANCE COMMANDERS GROUP (JOCG)

(AMMO WEB)

3.9.3 DISTRIBUTION

MANAGEMENT

SHIPMENTS AND INTRANSIT TRACKING (Non-origin/Dest) CAPABILITY (Note: Some of this capability is within the current MC2 application and AMMO WEB)

GLOBAL ASSET POSITIONING (GAP) & MUNITION

MOVEMENT PLAN (Note: This capability currently exists in

AMMO-WEB)

3.9.4 FOREIGN MILITARY

SALES (FMS) FMS CASE MANAGEMENT (AFLCMC/EBW & EBH)

(FMS) WARNER ROBINS (AFLCMC/EBW) TACTICAL

MISSILE TECHNICAL COORDINATION GROUP PROJECT

TRACKING (TMTCG)

3.9.5 MAINTENANCE,

SERVICEABILITY &

RELIABILITY

INSPECTION; ALL UP ROUND (AUR) TEST, FAILURE,

REPORTING

AMMO CONDITION REPORTS

MUNITIONS FLIGHT TIME TRACKING

ENVIRONMENTAL CATEGORIES FOR INSPECTION

INTERVAL

SOFTWARE VERSION BY COMPONENT

PREDICTIVE RELIABILITY ASSESSMENT

AFRAT WORKLOAD REQUEST

ELECTRONIC TEMPORARY EXTENSION MANAGEMENT

PROGRAM (ETEMP-CAD/PAD)

3.9.6 FINANCIAL

MANAGEMENT

FIAR COMPLIANCE

MOVING AVERAGE COST (MAC) TOOL

CONTRACTOR POSSESSED MUNITIONS (CPM)

MANAGEMENT AND REPORTING (AMST)

3.9.7 TECHNICAL DATA MGMT TIME COMPLIANCE TECHNICAL ORDER (TCTO)

MUNITION SECURITY CLASSIFICATION GUIDE

TECH ORDERS

3.9.8 DATA MGMT AND

ARCHIVAL FILE STORAGE (Key Supporting Documentation [KSDs])

COMPLETE ROUND/AUR HISTORY LOG

MUNITION HISTORICAL ARCHIVE

MUNITIONS CONFIGURATION CONTROL

CONTEXTUAL SEARCH/KEY SUPPORTING DOC

RETRIEVAL

MASTER DATA MANAGEMENT

TEST INFORMATION PLANNING SYSTEM (TIPS-CAD/PAD)

FURTHER OPTIMIZE IDR TO SOLIDIFY CONTROLLED

INVENTORY ITEM CODE (CIIC) &CIIC GROUPING,

SECURITY RISK CATEGORY (SRC), ETC.

WORLD-WIDE MASO LISTING FOR EACH DEPARTMENT

OF DEFENSE ACTIVITY ADDRESS CODE (DODAAC)

WITHIN SYSTEM

3.9.9 MUNITIONS COMMAND,

CONTROL, & OPERATIONS

AIRCRAFT ALTERNATE MISSION EQUIPMENT (AME)

CONFIGURATION

COMPLETE ROUND ANALYZER (CRA) [CURRENTLY

WITHIN AMST]

FACILITY MASTER DATA MANAGEMENT

INTERNATIONAL ORGANIZATION FOR

STANDARDIZATION (ISO) MGMT

VEHICLE, AEROSPACE GROUND EQUIPMENT,

MUNITIONS MATERIAL HANDLING EQUIPMENT, TEST

SET STATUS

WORKORDER TRACKER AND MANAGEMENT

TRAINING (Personnel, Career Field Education and Training Plan (CFETPs), Certifications)

AIRCRAFT GENERATION & AIR TASKING ORDER (ATO)

DASHBOARD; REAL WORLD/EXERCISE

AMMO VESSEL TRACKER (AVT) TOOL

CALL FORWARD

AIR FORCE STAMP/AFLOAT PREPOSITIONED FLEET

BOOKS

LOGISTICS MODULE SCHEDULE (AMMO WEB)

STANDARD CONFIGURATION LOAD (SCL/WEAPONS)

FUZE SETTING MANAGEMENT

EVENTS LOG

EMERGENCY ACTION CHECKLIST

3.9.10 SYSTEM ROLES &

ACCESS CONTROLS (FISCAM)

AUTOMATED DD 2875 ACCESS & ROLES CONTROL &

WORKFLOW

3RD PARTY (e.g., DEPOT, CONTRACTOR) ACCESS

CONTROLS - SECURE PORTAL

AUTOMATED APSR SYSTEM INTERFACE DATA

VALIDATION PROCESSES

3.9.11 SIPRNET ENCLAVE OPS OPERATIONAL PLAN MUNITIONS SUPPORT

(CLASSIFIED) REQUIREMENTS MANAGEMENT SYSTEM

(RMS) CAD-PAD (CLASSIFIED)

MUNITIONS ALLOCATIONS TO CLASSIFIED LOCATIONS

(CLASSIFIED)

RAM (CLASSIFIED)

3.9.12 OSS&E GATHER DATA ON THE USE OF THE ITEMS WITH BOTH

UNCLASSIFIED AND CLASSIFIED AREAS USE OF:

MAINTENANCE, SERVICEABILITY, AND RELIABILITY

DATA MANAGEMENT AND ARCHIVAL

MUNITIONS COMMAND, CONTROL, AND OPERATIONS

AUTOMATE CALCULATIONS USED IN OSS&E REPORTS

3.9.13 MIT AND

DISCONNECTED CLIENT

INSPECTIONS

ACCOUNTABILITY, BUILDS, SHIPMENTS

MESSAGING/ERRORS

LABELING

ASYNCHRONOUS OPERATIONS

MOVE ORDER ENHANCEMENTS

ERROR HANDLING FRAMEWORK / CLIENT

NOTIFICATIONS

OPERATIONAL LEVEL EXPENDITURES /

RECONFIGURATION OF AURs

TACTIVAL LEVEL OPERATIONS

EQUIPMENT/VEHICLE MANAGEMENT CONFIGURATION

CHECKLIST

SEPARATE PRODUCTION AND TRAINING FOR LOCAL

USER DATABASE

4.0 PROGRAM MANAGEMENT

4.1 Management of Personnel

The Contractor shall establish processes and assign appropriate resources to administer the requirement effectively. Pursuant to 5.2, the Contractor shall provide a list of all personnel performing under this order with each billing cycle.

The Contractor shall assign tasks and maintain proper and accurate time-keeping records of personnel assigned to work on the contract. The Contractor shall maintain a stable workforce while minimizing the impact of any turnover and/or disruptions to the Government and/or mission. The Contractor shall ensure the continuation of services during personnel absences due to sickness, leave, and voluntary or involuntary termination from employment such that there is no negative impact to the Government mission/schedule.

4.2 Program Manager

The Contractor shall assign a SME Program Manager (PM) who will be accountable for overall project execution to the Government; e.g., Cost, Schedule, Performance, Status, and Delivery of Requirements for all tasks and any sprint planning methodology that the Contractor plans to use for implementing and executing the functional needs over the initial base year and the subsequent option years.

4.3 Technical Lead

Additionally, a minimum of one Senior or higher TPM (Technical Program Manager) assigned for the duration will be required. The Contractor shall assign a team of agile software developer SMEs, senior, and journeyman, to execute the functional needs.

4.4 Meeting Attendance

The Contractor shall participate in meetings, reviews, and quality deficiency reporting programs and host meetings and reviews as required by the Government. Examples of these meetings include: Weekly Status Reviews, Executive Meetings, Technical Triage Reviews, etc.

4.5 Schedule

The Contractor shall respond to Government requests for contractual actions promptly;

within five business days. The Contractor shall adhere to all scheduled timelines, milestones, delivery schedules, and administrative requirements that contribute to or affect schedule variance, including scheduled on-time delivery of releases, billing invoices, and action items.

4.6 Hours of Operations / Federal Holidays

Standard workdays are Monday through Friday, except U.S. Federal holidays and other Government-observed days. Hours of operations at Government locations are an eight- or nine-hour shift reflected in a normal industry standard 8-hour day / 40-hour work week schedule.

Federal Holidays:

New Year’s Day Birthday of Martin Luther King, Jr.

Washington’s Birthday Memorial Day Juneteenth National Independence Day Independence Day Labor Day Columbus Day (AKA: Indigenous Peoples Day) Veterans Day

Thanksgiving Day Christmas Day

5.0 DELIVERABLES

Deliverables shall be delivered IAW with this PWS unless otherwise specified by the CO via contract modification or CO letter. Refer to Basic Contract Data Requirements List (CDRL) for standardize/repeating requirements, i.e., monthly billing. Table below is an excerpt from the CDRL list on contract (exhibit A) and Para 12, appendix B “SDS”

CDRL # CDRL Title A001 Funds and Man Hours Expenditure Report A002 Software Version Description* A003 Software Test Description* A004 Software Test Report* *Designates the CDRL as a critical CDRL for evaluation. Evaluations are performed in concert with The SDS at Para 12.0 appendix B as well as Normal industry standards and DoD STIG formatting to be utilized as needed to for example to build out the software test report and other deliverables.

The Government has the inherent right to disapprove any deliverable. Therefore, the Government (CO/COR) will have the right to reject or require correction of any deficiencies found in deliverables. In the event of rejection of any deliverable, the COR, in coordination with the CO, will notify the Contractor in writing/Email of the specific reason why the deliverable was rejected. Rejected deliverables shall be resubmitted to the COR for re-evaluation no later than the COR’s suspense date. The Government must approve/accept final versions of deliverables.

5.1 Weekly Status Review

The Contractor PM shall develop and provide a Weekly Status Review briefing. The Weekly Status Review shall briefly summarize the management and technical progress to date and provide the current information indicated below. The Contractor shall provide within the briefing, at a minimum, the following information:

a. Activities during the reported period, by task and subtask, to include on-going activities, new activities, completed activities, deliverables submitted for that period, and progress to date on all above-mentioned activities

b. Schedule (showing major tasks, milestones, and deliverables with planned and actual start and completion dates for each)

c. Problems and corrective actions taken. Include issues or concerns that may affect project milestones, personnel, and cost resources; and proposed resolutions to address them to include risk mitigation plans.

d. Contractor personnel gains, losses, and staffing status (security clearance, upcoming leave, etc.) that may impact and/or disrupt the Government mission.

e. Government actions required (deliverables awaiting Government approval, etc.)

f. Recommendations for change, modifications, or improvements in task or process

g. Cybersecurity scanning/analysis results to include utilized software versions

5.2 Personnel Roster Associated with Billing

The Contractor shall submit a Personnel Roster to the COR with each billing invoice that reflects personnel aligned to the billing. In addition, the Contractor shall submit a request for an additional roster associated with a specific task being performed at the COR’s request.

The latter is an effort to ensure personnel stability, as discussed in Section 3.1. This requirement may be combined with CDRL A001 if desired.

5.3 Sprint Cycle / Release

Sprint cycles should not deviate from the originally planned schedule determined during the sprint planning meetings. Release dates for sprint cycles will be determined based on the Government’s priorities, and the Contractor’s ability to provide the Government requested capabilities and backlog features. Sprint cycles will be four weeks long in duration and will account for One Inc. code development and Quality Assurance. Not every sprint cycle shall be bundled for a release. The Contractor shall release code, at a minimum, once a quarter unless coordinated or directed differently by the Government. For each release, the vendor will perform Quality Assurance (QA) and security testing. The TICMS FMO shall also perform User Acceptance Testing (UAT) and Cybersecurity testing and scanning to validate the vendors effort. The vendor will remedy any USG found software development errors, also referred to as “bugs”, in the produced code. The vendor will be offered the opportunity to review the FMO UAT results and validate any findings as a Bug or an enhancement. Bugs will be mitigated/resolved at no additional cost to the USG. A minimum of eight total sprint cycles are expected to be completed within a one-year time period, with four weeks dedicated to vendor development and two weeks to vendor QA/Test. One Inc.’s JIRA ticketing system and associated confluence pages will be the single point of input for all of the Government requirements, bugs, and enhancements. JIRA tickets shall only be input by TICMS FMO SMEs with an approved and defined criticality (Low, Medium, High, Critical, or Business Critical). Prioritization of JIRA tickets for each sprint cycle will be discussed and determined during the sprint planning meetings. Patch releases shall be kept at a minimum and only deemed necessary by the FMO if there are mission critical bugs and/or tickets required to prevent the warfighter from work stoppage.

5.3.1 Definitions Associated with JIRA / Confluence

Bug: An error, flaw, or fault in a computer program or system that causes incorrect or unexpected results, or to behave in unintended ways. Bugs will be remedied by the vendor at no additional cost to the USG. The vendor is offered the opportunity to arbitrate with the FMO on any bugs they may deem a category other than “bug” i.e., Enhancement.

Enhancement: Product changes or upgrades that increase software or hardware capabilities beyond original client specifications.

Low Level of Severity: Error occurs which does not jeopardize the workflow of the product.

Error has a low impact. Examples include misalignment of text, misspelling of content, or User Interface (UI) inconsistencies.

Medium Level of Severity: Error occurs resulting in minor loss of functionality or performance of the system. Acceptable workaround is available. Error has a medium to low impact. Examples include sorting not working or UI data display issue.

High Level of Severity: Error occurs resulting in a significant impact to the functionality or performance of the system. Short-term workaround may be available. Error has medium to high impact. High defect means that the user’s business process can function or work around the reported error or deficiency in the earliest possible scheduled release. Examples include UI action not working or system alert functionality not working.

Critical Level of Severity: Entire system is unavailable, or a major component of the system does not function completely. No workaround is available. Major component of the system includes integration and system transaction level functionality. Error has a high impact.

Critical defect means that the user’s business process can no longer continue due to the reported error or deficiency of the product, regardless of what the user attempts to do to remedy the defect and that data can be lost and/or corrupted.

Business Critical Level of Severity: Exceeds the Critical severity level and represents nonfunctional system functionality, specific business processes, or severe system degradation that results in significant manpower demand on program owner or end user. Software vendor will use all commercially reasonable efforts to resolve business critical defects within 24-hours from time of customer notification.

5.4 Quality Assurance Results with Each Release

The Contractor shall develop, implement, and maintain a comprehensive software development QA process. This will include industry-standard scanning software such as XRAY and ACAS as well as the USAF Cloud environments (i.e., amazon web services- DOD) mandatory use of the Government initially provided Checkmarx vulnerability scanning product. In order to align with both the Contractor and Government’s Cybersecurity requirements. The Contractor shall ensure scanning products remain current at their own expense.

In addition, the Contractor shall perform application functionality QA to verify software and external interface functionality. QA testing should be aligned with the Government UAT processes. The Contractor shall ensure customer verification, validation, and approval of any system changes prior to any changes being implemented into the production environment.

Vulnerabilities identified during code security scans shall be mitigated by both the Contractor and the Government prior to deployment. The Government will provide a codebase optimization scanning process with Government provided software scans (i.e., Silverthread, CAST or similar) of the vendor’s baseline code. This periodic scan by the USG expects to determine where significant code complexity interferes with effective and timely inquiries within TICMS. The vendor will utilize the maximum extent possible suggested optimization to provide for overall code efficiencies.

5.5 Technical Triage Sessions

The Contractor shall provide a PM, TPM, Developer, Quality Assurance, System Architect, Functional Support, and a Technical Writer (as necessary) to lead and document technical triage sessions with Government technical SMEs to remedy issues within the application and to gather details of requirements. The Government will determine the frequency of these sessions in conjunction with the Contractor PM. The vendor is expected to notify the USG when/if additional labor categories or skillsets are needed other than the aforementioned.

5.6 Code Scanning Tools

The Contractor shall maintain cybersecurity analysis and scanning software as determined and/or provided by the Government as mentioned in Para 5.4 for not only Quality Assurance rationale but robust Cybersecurity mandated by DOD Standards. All code scanning tools (i.e., Checkmarx, ACAS, and Xray) utilized by the Contractor must be upgraded to the latest version/hotfix to be current and consistent with the Government. The vendor shall be expected to monitor all of the software vendor’s websites to ensure applicable upgrades are in place. A lack of proper upgrades can introduce unnecessary cybersecurity vulnerabilities and delay sprint cycles. It is the responsibility of the Contractor to communicate to the Government if the latest version was not utilized during development/testing.

*Note: Services Summary Table available in Appendix B

6.0 GENERAL INFORMATION

6.1 Place of Performance

The primary place of performance will be at the Contractor location, Dallas Tx, and the TICMS FMO at Hill AFB, Utah.

6.2 Period of Performance

The PoP will be a one 1-year base with three 1-year options.

6.3 Travel / Other Direct Costs (ODC)

The Contractor’s personnel will be expected to travel as needed to meet the Government’s requirements. Travel will be primarily between the individual ONE, Inc. Contractor location, to predominantly the corporate HQ at Dallas, Texas and at times to Hill Air Force Base, Utah. This may change to other U.S. based locations dependent on the Government’s needs (i.e., Robins Air Force Base, Georgia). A post-trip report will be provided by the Contractor within one week of return of travel. ODC costs may be applied, when necessary, to incur non-labor / non-travel costs for supplies or materials with prior approval of the government Program Manager via the COR, the COR will coordinate costs with CO. Standard costs for ODC are certain software upgrade costs, specialized equipment related to cyber security needs, etc. It is not expected for the Contractor to “bid” for travel or ODC costs, as the Government will coordinate with the vendor and ultimately approve the travel to an established location. These funds will be on individual clins with a minimum expected allowance beginning at 20K each, which may be expanded via coordination with USG and Contract mod. The vendor is expected to procure all rates and costs associated with the JTR standard and only exceed JTR rates with COR approval while following standardized Joint Travel Regulation (JTR). The Government will provide for Government deemed adequate travel and ODC funding on a separate CLIN within the contract with no earned fee or profit associated within.

6.4 Non-Personal Services

The Government will neither supervise nor direct Contractor personnel. Under no circumstances shall the Government assign tasks to or prepare work schedules for individual Contractor employees. The Contractor shall manage its employees and guard against any actions that are of the nature of personal services or give the perception of personal services.

If the Contractor believes that any actions constitute or are perceived to constitute personal services, or are outside the scope of this contract, the Contractor shall notify the CO immediately.

6.5 Ethics

The Contractor shall not perform any inherently Governmental functions defined by Federal Acquisition Regulation (FAR) Subpart 7.5, Inherently Government Functions. All TICMS program decisions shall be the sole responsibility of the Government.

The Contractor shall not counsel, mentor, make judgments and/or discretionary decisions, or perform any other activities related to the supervision of Government personnel.

If the Contractor believes that any actions constitute or are perceived to constitute inherently Governmental functions, the Contractor shall notify the CO immediately.

6.6 Inherently Governmental Functions

The Contractor will be highly visible to the entire acquisition community as a result of providing assistance to the Government. The Contractor shall present an unblemished appearance in regard to ethics, discretion, and protection of information.

6.7 Data Rights

The Government shall retain unlimited rights to all data and deliverables developed at the Government’s expense pertaining to the operation of the TICMS system. At any time and per Government request, any records, documents, and associated documentation shall be available for review.

7.0 SAFETY

The Contractor shall comply with all applicable Occupational Safety and Health Administration (OSHA) and Air Force Occupational Safety and Health (AFOSH) standards, technical orders, regulations, and referenced publications both within and outside of the US.

The Contractor shall comply with the highest degree of safety protection where any disagreements exist.

7.1 Ensuring Adequate COVID-19 Safety Protocols for Federal Contractors (Deviation 2021-O0009, Revision 1) (Oct 2021)

This clause implements Executive Order 14042, Ensuring Adequate COVID Safety Protocols for Federal Contractors, dated September 9, 2021 (published in the Federal Register on September 14, 2021, 86 FR 50985).

The Contractor shall comply with all guidance, including guidance conveyed through Frequently Asked Questions, as amended during the performance of this contract, for contractor or subcontractor workplace locations published by the Safer Federal Workforce Task Force (Task Force Guidance) at https:/www.saferfederalworkforce.gov/contractors/.

8.0 SECURITY

The Contractor shall comply with the contract security requirements, the DD Form 254, DoD Contract Security Classification Specification, and security requirements identified in the Federal Register at 84 FR 33201 on July 12, 2019 and as outlined in the following subparagraphs. The Contractor shall pass down tailored security requirements, as stated in the contract and codified in regulations, to all subcontractors.

The Contractor shall safeguard all Government property and controlled forms provided for Contractor use and adhere to the Government property requirements contained in this contract.

8.1 Common Access Cards (CAC)

CACs will be issued, as the Government requires, for entry into specific NIPRNet applications and/or DoD installations. Not all personnel will receive a CAC; only U.S.

Citizens with a Tier 1 security clearance will/may receive CAC’s. SIPRNet tokens will be issued by the Government, when required.

8.2 Non-Disclosure Agreements (NDAs)

IAW FAR 9.505-4(b) the Contractor is responsible for obtaining all non-disclosure agreements with all applicable Government, corporate, supplier, and sub tier Contractors with proprietary, restricted, competition sensitive, or any other restricted (e.g., non-foreign disclosure due to public law) data that will be used or accessed during the execution of this contract.

8.3 Access

The Contractor performing software configuration shall permit the SMEs or other Government authorized representative access to all work areas, records, and data used in the performance of the contracted services. The Contractor shall provide support, and not interfere with the CO, CORs, State, Federal, and other designated personnel in the performance of their official duties. Access shall be provided as soon as possible, but not exceed one workday after the request.

8.4 Security Clearances

The Contractor shall ensure their personnel have appropriate clearances prior to commencing work on this contract unless otherwise approved in writing by the Government. The Government will provide documentation indicating required security levels for all contract personnel, if security levels are required. The Contractor shall also complete visit requests to AFLCMC/EBH (SMO Code HP1MFTKFT), if required by the Government, for each individual that will be performing work on a contract in the Defense Information System for Security (DISS).

8.5 Protection of Information

Protection of unclassified DoD information not approved for public release on non-DoD Information Systems will be protected IAW DoDI 8582.01, Security of Non-DoD Information Systems Processing Unclassified Nonpublic DoD Information. The Contractor shall comply with DFARS 252.204-7012, Safeguarding Covered Information and Cyber Incident Reporting. This subpart applies to contracts and subcontracts requiring safeguarding of unclassified controlled technical information resident on or transiting through contractor unclassified information systems. This subpart does not abrogate any existing contractor physical, personnel, or general administrative security operations governing the protection of unclassified DoD information, nor does it impact the requirements of the National Industrial Security Program.

8.6 Classified Information

The Contractor shall comply with the DD Form 254.

Classified Visits: The Contractor shall process all classified visit requests via the DISS in support of tasks within the DoD. Classified visits outside DoD will required Visit Authorization Letters (VALs) IAW the National Industry Security Program Operation Manual (NISPOM).

8.7 Trustworthiness Determination

Trustworthy determinations are required for access to unclassified government IT systems and routine physical access to a federally-controlled facility. A favorably completed Tier 1 personnel security investigation is required for IT Level III access. The Contractor shall submit personnel security investigative paperwork for trustworthiness determinations IAW FIPS Pub 201-3, Personal Identity Verification (PIV) of Federal Employees and Contractors and DoDM 5200.02_AFMAN 16-1405, Air Force Personnel Security Program, paragraph

3.2. Issuance/retrieval of CACs will be IAW DoDI 5200.46, DoD Investigative and Adjudicative Guidance for Issuing the Common Access Card (CAC) and AFI 36-3026 Volume 2, Common Access Card (CAC). CACs are not transferable to another contract and shall be returned IAW FAR 52.204-9, Personal Identity Verification of Contractor Personnel, AFFARS 5352.242-9000, Contractor Access to Air Force Installations and AFFARS 5352.242-9001, Common Access Cards (CAC) for Contractor Personnel.

8.8 Operations Security (OPSEC)

The purpose of OPSEC is to reduce the vulnerability of USAF/DoD missions to adversary collection and exploitation of critical information. Critical Information is defined as information about USAF missions or activities the adversary needs to achieve their goals.

The Contractor shall ensure compliance with DoDD 5205.02E, DoD Operations Security (OPSEC) Program, DoDM 5205.02, DoD Operations Security (OPSEC) Program Manual, AFI 10-701, Operations Security (OPSEC) and/or other applicable Government security regulations including procedures to protect…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .