04 LSJ_Adjudicated post CRB review (3) (1)_Redacted.pdf

PDF 660 KB Posted

Attached to
OSGS Information Systems Security Engineering and Sustainment Services Federal contract opportunity
Solicitation number
1332KP20FNEEG0017
Issued by
Department of Commerce National Oceanic and Atmospheric Administration

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Version 1.0

Source Selection Information – see FAR 2.101 and 3.104

LIMITED SOURCE JUSTIFICATION

FOR AN ORDER/BPA EXCEEDING

THE SIMPLIFIED ACQUISITION THRESHOLD

(AUTHORITY: FAR 8.405‐6)

This acquisition is conducted under the authority of the Multiple Award Schedule Program.

1. Agency and contracting activity. Department of Commerce, NOAA Acquisition and Grants Office (AGO), Satellite and Information Acquisition Division (SIAD) and National Environmental Satellite, Data, and Information Service (NESDIS).

2. Nature and/or description of the action being approved.

This is a limited sources justification for a follow‐on to provide continued security and sustainment engineering to NESDIS Office of Satellite and Ground Services (OSGS). It will be a Time and Materials (T&M) order against the current contractor’s (iCES Corporation) GSA schedule contract #GS‐35F‐438AA .

Vendor address: iCES Corporation, 8229 Boone Boulevard, Suite 800 Vienna, VA. 22182

3. Description of the supplies or services required to meet the agency’s needs (including the estimated value).

Under their various OSGS Security Engineering Support and Plan of Actions and Milestones (POA&M)/SSA tasks on the GSA ESM BPA, iCES provided general security engineering support to a wide variety of NESDIS systems as requested [including Earth System Prediction Capability (ESPC)/Environmental Satellite Processing and Distribution Services (ESPDS)/NPP Data Exploitation (NDE), Jason/NOAA Jason Ground System (NJGS), Polar‐orbiting Operational Environmental Satellites (POES), Geostationary Operational Environmental Satellites (GOES), and Satellite Controller Communications System (SCCS)]. Some examples are listed below. This general security engineering support to NESDIS systems will be continued under the PROJECT #7: Security Engineering/Implementation task of this proposed requirement.

Continued general security engineering support examples:

● Participate in ESPDS Release Telemetry Interference Monitoring (TIM) to ensure that enterprise security initiatives are addressed as early as possible and in priority order as defined by Assistant Chief Information Officer ‐ Satellites (ACIO‐S). Work with other OSGS contractors to identify and address gaps in the transition process for Operations to take over scanning of ESPDS. Performed initial analysis of the Japanese Space Agency (JAXA) provided software for the Global Change Observation Mission‐Water (GCOM‐W1) Processing and Distribution System (GPDS). Review and vote on Change Requests for the ESPDS Change Control Board. Coordinate with ACIO‐S and NOAA Office of the Chief Information Officer (OCIO) Point of Contact (POCs) regarding the Online Certificate Status Protocol (OCSP) change issue that resulted in ESPDS data outage. Facilitate discussions with stakeholders including Solers, the ESPDS Project Management Office (PMO), and the ESPC Information Systems Security Officer (ISSO).

● Work with Satellite Controller Communications System (SCCS) team to draft responses to questions and comments raised by ACIO‐S and Office of Satellite and Product Operations (OSPO). Review the SCCS Performance Work Statement (PWS) and provide recommended IT Security changes.

Source Selection Information – see FAR 2.101 and 3.104

● Participate in requirements meetings with the NJGS PMO and contract vendor, and provide security input, security requirements, and security standards for the NGJS refresh project. Participate as NJGS Technical Refresh Review Board member at the NJGS Technical Refresh System Requirements Review (SRR), and submit four Request for Actions (RFAs) to address security requirements concerns. Resolve NJSG Tech Refresh applicability of Enterprise Security initiatives. Review updates to NJSG Tech Refresh System Requirements.

● Work with GOES PMO and contactor to provide artifact to close out Milestones of GOES POA&M.

Reviewed the requirements document for the Sensor Processing System (SPS) Hardware and Software Refresh task of the Modernization project and provided comments for the Security section. Work with the GOES PMO and provided artifacts for early closure of some milestones.

Generated a Draft Implementation POA&M for the SPS refresh. Participate in GOES LEDS‐II status meetings to ensure that the project is on schedule to meet GOES POA&M Milestones.

Continued targeted security engineering support examples:

● Contribute to security reviews and evaluations of RFIMS proposals and completed integration of Security tasks into the two awarded Integrated Master Schedules (IMSs). Complete and submit the Risk Management Framework (RMF) process for both RFIMS IMS awards to the requirements team.

Reviewed and provided comments on the Systems Engineering Management Plan (SEMP), Configuration Management Plan (CMP), and Integrated Master Schedule (IMS). Provide input on integrating the Secure Software Development Life Cycle (SSDLC) into each of the proposed RFIMS Integrated Milestone Schedules.

● Develop the Project Charter and conduct weekly HSPD‐12 Working Group meetings. Establish Test Lab at Contractor Facility to test solutions and prototypes. Develop detail Implementation Plans in coordination with OSPO and Submitted HSPD‐12 FIPS200 Tailoring documentation.

● Work with ACIO‐S to refine the process and forms for Alt Tokens. Purchase keyboards with smart card readers and Alt Token stock. Research and test alternative Alt Token solutions for Red Hat Enterprise Linux (RHEL) middleware compatibility. Investigate migrating RHEL Jump Boxes to Windows to implement 2FA. Ensure the HSPD‐12 solution for ESPC is coordinated and integrated with ESPC Active Directory, ESPDS HSPD‐12 solution, Virtual Private Network (VPN) implementation, and ESPC Continuity Of Operations (COOP). Conducted walkthroughs for SAB and Helpdesk Areas, produced “AS‐IS” baselines, and identified remaining work.

● Lead efforts to transition COSMIC from a custom designed system to support a single partner satellite to PAAN a system to provide a NOAA standardized service to support multiple partner satellites. Design and implement the new architecture for PAAN. Work with stakeholders to add the PAZ, KOMPSAT, and SCATSAT satellites to PAAN.

In addition, under its GSA ESM BPA, iCES provided security engineering support for targeted tasks to a number of systems (including COSMIC/PAAN/KOMPSAT/PAZ/SCATSAT, RFIMS, ESPC/ESPDS, and METOP).

Some examples are listed below. This targeted security engineering support will be continued under “PROJECT #1: SCATSAT Security Engineering” and “PROJECT #2: PAAN Security Engineering” for Constellation Observing System for Meteorology, Ionosphere, and Climate (COSMIC)/Partner Antenna Access Network (PAAN)/Korea Multi‐Purpose Satellite (KOMPSAT)/PAZ/Scatterometer Satellite (SCATSAT);

“PROJECT #3: Independent Scientific Advisory Board (ISAB)‐12 Phase IV‐b Implementation”, “PROJECT #4:

ISAB‐12 Phase V Implementation”; “PROJECT #5: RHEL to Windows Migration” for ESPC/ESPDS; and “PROJECT #8: Radio Frequency Interference Monitoring System (RFIMS) Network and Security Support” for RFIMS. While “PROJECT #6: Space Weather Follow‐On (SWFO) Security Engineering Support” is for a new satellite, it is a continuation of the security engineering support that iCES has provided to many other satellites (POES, GOES, COSMIC, KOMPSAT, PAZ, SCATSAT, Jason‐3, etc.) and is only listed as a separate Project to separate out its funding source.

Continued general security engineering support examples:

● Participate in ESPDS Release TIMs to ensure that enterprise security initiatives are addressed as early as possible and in priority order as defined by Assistant Chief Information Officer ‐ Satellites (ACIO‐S). Work with other OSGS contractors to identify and address gaps in the transition process for Operations to take over scanning of ESPDS. Performed initial analysis of the Japanese Space Agency (JAXA) provided software for the Global Change Observation Mission‐Water (GCOM‐W1) Processing and Distribution System (GPDS). Review and vote on Change Requests for the ESPDS Change Control Board. Coordinate with ACIO‐S and NOAA Office of the Chief Information Officer (OCIO) Point of Contact (POCs) regarding the Online Certificate Status Protocol (OCSP) change issue that resulted in ESPDS data outage. Facilitate discussions with stakeholders including Solers, the ESPDS Project Management Office (PMO), and the ESPC Information Systems Security Officer (ISSO).

● Work with Satellite Controller Communications System (SCCS) team to draft responses to questions and comments raised by ACIO‐S and Office of Satellite and Product Operations (OSPO). Review the SCCS Performance Work Statement (PWS) and provide recommended IT Security changes.

● Participate in requirements meetings with the NJGS PMO and contract vendor, and provide security input, security requirements, and security standards for the NGJS refresh project. Participate as NJGS Technical Refresh Review Board member at the NJGS Technical Refresh System Requirements Review (SRR), and submit four Request for Actions (RFAs) to address security requirements concerns. Resolve NJSG Tech Refresh applicability of Enterprise Security initiatives. Review updates to NJSG Tech Refresh System Requirements.

● Work with GOES PMO and contactor to provide artifact to close out Milestones of GOES POA&M.

Reviewed the requirements document for the Sensor Processing System (SPS) Hardware and Software Refresh task of the Modernization project and provided comments for the Security section. Work with the GOES PMO and provided artifacts for early closure of some milestones.

Generated a Draft Implementation POA&M for the SPS refresh. Participate in GOES LEDS‐II status meetings to ensure that the project is on schedule to meet GOES POA&M Milestones.

Continued targeted security engineering support examples:

● Contribute to security reviews and evaluations of RFIMS proposals and completed integration of Security tasks into the two awarded Integrated Master Schedules (IMSs). Complete and submit the Risk Management Framework (RMF) process for both RFIMS IMS awards to the requirements team.

Reviewed and provided comments on the Systems Engineering Management Plan (SEMP), Configuration Management Plan (CMP), and Integrated Master Schedule (IMS). Provide input on integrating the Secure Software Development Life Cycle (SSDLC) into each of the proposed RFIMS Integrated Milestone Schedules.

● Develop the Project Charter and conduct weekly HSPD‐12 Working Group meetings. Establish Test Lab at Contractor Facility to test solutions and prototypes. Develop detail Implementation Plans in coordination with OSPO and Submitted HSPD‐12 FIPS200 Tailoring documentation.

● Work with ACIO‐S to refine the process and forms for Alt Tokens. Purchase keyboards with smart card readers and Alt Token stock. Research and test alternative Alt Token solutions for RHEL middleware compatibility. Investigate migrating RHEL Jump Boxes to Windows to implement 2FA.

Ensure the HSPD‐12 solution for ESPC is coordinated and integrated with ESPC Active Directory, ESPDS HSPD‐12 solution, Virtual Private Network (VPN) implementation, and ESPC Continuity Of Operations (COOP). Conducted walkthroughs for SAB and Helpdesk Areas, produced “AS‐IS” baselines, and identified remaining work.

● Lead efforts to transition COSMIC from a custom designed system to support a single partner satellite to PAAN a system to provide a NOAA standardized service to support multiple partner satellites. Design and implement the new architecture for PAAN. Work with stakeholders to add the PAZ, KOMPSAT, and SCATSAT satellites to PAAN.

The Option Period will be a continuation of services and may include the execution of new tasks as provided in the optional project.

Base period value:

Option period:

Total Estimated value:

The Follow‐on Order is planned with a base year of 20 January 2020 to 19 January 2021 and an option period of 20 January 2021 to 19 September 2021.

4. Authority and supporting rationale. The following circumstance justifies limiting the source as supported below:

Logical Follow‐on under the authority of FAR 8.405‐6(a)(1)(i)(C) – In the interest of economy and efficiency, the new work is a logical follow‐on to an original Federal Supply Schedule (FSS) BPA (GSA ESM #GS35F438AA‐01150118) . The original BPA was placed in accordance with the applicable FSS ordering procedures in FAR 8.4. The original BPA was not previously issued under sole‐source or limited sources procedures.

This is a logical follow‐on because this proposed requirement is a continuation of the tasks that the contractor started on their GSA ESM BPA as iCES continues to sustain legacy systems, plan for future systems and implement security engineering initiatives as described in Section 3 above. . The GSA ESM BPA has reached its estimated value and the new sustainment contract (Operations, Maintenance and Support or OMS) which this requirement would fall under, won’t be in place until the second quarter of fiscal year 2021. As such, the need for the security sustainment of NESDIS projects and two NOAA systems with personnel familiar with them and deeply knowledgeable of the next steps and design implementation details given the tight timeframes requires this limited sources procurement.

Award of this proposed requirement directly to iCES is efficient and makes economic sense because a new competitive acquisition will cause a delay of at least six months (new contractor to be brought up to speed), and introduce an unacceptable risk of not getting the appropriate skills and expertise to complete the general and targeted security engineering requirements. Continuing the security engineering initiatives with the incumbent Contractor eliminates this possible delay and risk.. Additionally, awarding to the incumbent has the benefit of avoiding duplicative costs by having the same contractor continue performing the work.

If the proposed requirement is not awarded to iCES, there are significant impacts to NOAA on the following fronts:

a) ESPC compliance with Homeland Security Presidential Directive (HSPD)‐12 will remain low when most systems are already compliant. HSPD‐12 compliance is tracked at the DOC and NOAA levels and reported to OMB and Congress.

b) The PAAN architecture to be implemented provides one system through which International Partners can provide NESDIS with their satellite data and can allow the Partners to control their respective satellites through the Fairbanks Command and Data Acquisition Station (FCDAS). Delaying implementation would hamper getting additional Partners and new Commercial Satellite data into NESDIS, impacting the NESDIS mission to provide global and timely weather data.

c) The SCATSAT project requires security documentation updates prior to the upcoming Security Controls Assessment (SCA). This is critical for the PAAN system to maintain its authorization.

Without the security documentation updates, operations and data flows of the SCATSAT and the PAAN system may be interrupted causing damage to our relationships with the Partners.

5. Determination by the ordering activity contracting officer that the order represents the best value consistent with FAR 8.404(d).

The Contractor currently supports NOAA in various tasks under the current GSA ESM Order. The incumbent has been performing well and no issues have arisen related to their deliverables. The Contracting Officer will review the Contractor’s proposed rates for the Follow‐on Order to ensure they are in accordance with the labor rates included in their GSA Schedule and perform price analysis by comparing their proposed rates to historical data in previous awards. The Contracting Officer will also request additional discounts/price reductions before award consistent with FAR 8.404(d). Based on this information, the contracting officer determines that the order represents the best value consistent with FAR 8.404(d).

6. Market research conducted among schedule holders (or reason market research was not conducted).

On or around August 2019, the Contracting Officer and the Program Office searched SAM.gov, reviewed NOAALink, reviewed GSA, and interviewed knowledgeable Government Subject Matter Experts (most notably Sam Assi, the IT Security Architect). It was determined that no other vendors have the subject matter expertise to adequately do the work. Additionally, NOAALink’s core contracts, which expire in September 2020, does not allow issuance of task orders with a period of performance that extends past their expiration date. A waiver to procure this proposed requirement outside of the NOAALink Program was approved by , IT Services Branch Chief, Strategic Sourcing Acquisition Division (SSAD), on October 1, 2019. In addition, it is not anticipated that the NOAALink follow‐on contract will be awarded before the required start date for this effort.The Government intends to award to iCES via its GSA Schedule IT 70 contract (GS‐35F‐438AA).

7. Any other facts supporting the justification.

No additional information.

8. Actions, if any, the agency may take to remove or overcome any barriers that led to the restricted consideration before any subsequent acquisition for supplies and services is made.

Any future sustainment engineering requirements will be transitioned into the Operations, Maintenance, and Sustainment (OMS) contract, which is expected to be in place by January 2021. The OMS contract is being procured using full and open competition. It will not be set aside for small business but will provide opportunities for subcontracting.

9. Technical/Requirements Representative Certification.

I certify that this requirement constitutes the Government’s minimum needs and the supporting data provided herein is accurate and complete to the best of my knowledge and belief.

File details come from the government source that posted it. Updated .