2023.07.07 IGC_RFI_Atch 1 PWS.pdf

PDF 463 KB Posted

Attached to
INTEGRATED DATA ENVIRONMENT & GLOBAL TRANSPORTATION NETWORK CONVERGENCE (IGC) Federal contract opportunity
Solicitation number
TRANSCOM23D015
Issued by
Department of Defense United States Transportation Command

About this file

This performance work statement outlines the required software development and operations support services for the Integrated Data Environment & Global Transportation Network Convergence system. Key details include:

  • The contractor shall provide agile software development support, migrate the system from a waterfall to agile methodology, and migrate it from on-premise hosting to Amazon Web Services GovCloud.

  • Tasks include contract management, software development, production application support, exercise support, risk management framework support, cloud migration support, and global operations center training support.

  • The performance period is from October 2024 to September 2029 with option periods extending to September 2029. The contractor shall perform work on-site at Scott Air Force Base and remotely as required.

  • The contractor shall follow an agile scrum methodology and continuous integration/delivery practices to implement capabilities, changes, and defect fixes. Quality standards require 95% of committed work be deployed with 95% free of defects.

  • The contractor shall provide software, documentation, and other deliverables specified in the tables and migrate the system, data, and applications to the AWS GovCloud environment.

View the file

Other files for this federal contract opportunity

Other files attached to INTEGRATED DATA ENVIRONMENT & GLOBAL TRANSPORTATION NETWORK CONVERGENCE (IGC), newest first.
File Type Posted
2023.07.12 IGC_RFI_Rev1.pdf PDF
2023.07.07 IGC_RFI.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Program Executive Office USTRANSCOM (PEO-T)

Performance Work Statement (PWS)

For

Integrated Data Environment &

Global Transportation Network Convergence (IGC)

07 July 2023

PWS Revision Log

Version Date Summary of Changes v1 07 July 2023 Draft, Published with Request for Information

Table of Contents

1 Description of Services

1.1 Background

1.2 Objective

1.3 Scope

1.4 References

1.5 Performance Requirements

1.5.1 Task Area 1: Contract Level and Task Order Management (Fixed Firm Price [FFP])

(FY24-FY29 T-OPS)

1.5.2 Task Area 2: Software Development Support [FFP] (FY25-FY29 T-OPS)

1.5.3 Task Area 3: Monitoring and Production Application Support [FFP] (FY25-FY29 T-

OPS)

1.5.4 Task Area 4: CCMD Exercise Support [LH] (FY25-FY29 JTEEP O&M)

1.5.5 Task Area 5: RMF Support [FFP] (FY25-FY29 T-OPS)

1.5.6 Task Area 6: Cloud Migration Support [LH] (Priced Optional Task) (FY25-FY29 T-

OPS)

1.5.7 Task Area 7: Global Operations Center and Training Support [FFP] (FY25-FY29 T-

OPS)

1.6 Delivery Schedule

1.6.1 Warranty

1.6.2 Inspection

1.6.3 Final Acceptance

2 Performance Standards 3 Government Furnished Equipment (GFE), Government Provided Software (GPS), and

Government Furnished Information (GFI)

3.1 Use of Government-Furnished Computers

3.1.1 Privately Owned Computers

3.1.2 Information Services

3.1.3 Access to Government Services

3.1.4 Official Business

3.2 GFI

3.3 Secret Internet Protocol Router Network (SIPRNET)

3.4 Property Accountability

4 General Information

4.1 Place of Performance

4.2 Account Management

4.3 Section 508 Accessibility

4.4 Travel and Other Direct Costs (ODC) (Time and Materials [T&M], Priced-Separately) 30

4.4.1 Travel

4.4.2 ODC Requirements

4.5 Period of Performance (POP)

4.6 Specialized Skills Required

4.7 Velocity

4.8 Latent Defects

4.9 Identification of Security, Cyberspace Workforce Management, and Non-Disclosure

Requirements

4.10 Quality Assurance

4.11 Standards

5 Security

5.1 Physical, Personnel, Information, Antiterrorism/Force Protection and Industrial

5.2 OPSEC

5.3 Operations Security Requirements

5.4 Countermeasures to Unauthorized Disclosure of Critical Information

5.5 Security Regulation Compliance

6 USTRANSCOM Cybersecurity Incident Reporting

6.1 Operationally Critical Support

6.2 Cybersecurity Incident Reporting

6.3 Cybersecurity Incident Reporting Timelines

6.4 Mandatory Reporting Data

6.5 Incident Reporting Coordination

6.6 Confidentiality and Non-Attribution Statement

Appendix A: List of Government Furnished Information Appendix B: Acronyms

1 Description of Services

1.1 Background

The United States Transportation Command (USTRANSCOM) provides global air, land, and sea transportation for the Department of Defense (DoD), both in times of peace and war through its Transportation Component Commands (TCCs): Air Mobility Command (AMC); Surface Deployment and Distribution Command (SDDC); and Military Sealift Command.

USTRANSCOM provides synchronized transportation, distribution, and maintenance, which makes possible projecting and maintaining national power where needed with the greatest speed and agility, the highest efficiency and most reliable level of trust and accuracy.

Integrated Data Environment & Global Transportation Network Convergence (IGC) is the DoD system of record for In-transit Visibility (ITV) and for Asset Visibility (AV). The enabling ITV capabilities provide customers the ability to track the identity, status, and locations of DoD unit and non-unit cargo and passengers, leveraging data provided by the military Services, commercial carriers, the Defense Logistics Agency (DLA), USTRANSCOM, and USTRANSCOM's components. IGC integrates that data and makes it available to the user, including historical data. The enabling AV capabilities provide global visibility of assets in nearly all classes of supply, which are organized by categories: In-Storage, In-Transit, and Asset Visibility. Utilizing IGC, USTRANSCOM optimizes the effectiveness and efficiency of the DoD logistics pipeline in support of the users, Military Services, Combatant Commands (CCMDs), and subordinate Joint force commands including Joint Task Forces (JTFs).

1.2 Objective

The objective of this requirement is to provide software development support and expertise for IGC. This includes all software code and associated components and integrations. Software development support shall include any phase of the Software Development Lifecycle (SDLC), including concept development, planning, requirements elicitation and analysis, systems design and development, coding and testing, deployment, implementation, integration, troubleshooting, security posture, documentation, and software application maintenance. Responsibilities include managing the code baseline, the hosted environment, and system interfaces. The code baseline may change as a result of user preference, latent defects, change requests, security requirements, or updates to Commercial Off The Shelf (COTS) products used by the system. Additionally, the contractor shall provide production support to include troubleshooting and resolving user problems as well as identifying opportunities to improve the system. Overall, software development support shall include all aspects of the SDLC necessary to sustain and modify the system baseline. The contractor shall work closely with other members of the team to include Government Product Owners, engineers, security, and end-users.

1.3 Scope

The contractor shall provide agile software development support for IGC, support transition from a Waterfall to Agile SDLC methodology, and support migration from a Defense Information Systems Agency (DISA) Defense Enterprise Computing Center (DECC) to an Amazon Web Services (AWS) GovCloud hosting environment. The contractor shall provide solution consulting and programming to: (1) implement new system capabilities; (2) implement change requests; (3) sustain deployed capabilities by rapidly troubleshooting and repairing software issues (i.e., correct software defects); (4) provide technical expertise to ensure high availability of the application to meet the USTRANSCOM mission; (5) receive and respond to problems reported by system users (i.e. correct incidents); and (6) improve the system’s security posture.

The contractor shall provide support in achieving the discipline of Development/Security/Operations (DevSecOps). This support shall include expertise with project management and reporting, business requirements analysis and specification development, design analysis, web service development, software integration, data conversion, testing, release management, technical support, and documentation to support program processes and requirements.

Further, the contractor shall provide Operations and Maintenance (O&M) support. The contractor shall manage IGC, which currently resides in two DISA DECCs for development, test, non-production, and production.

The Government may require surge support during the base or any option period. Surge modifications will be within the scope of the contract.

1.4 References

All references to including electronic libraries can be found in Attachment 1_References.

1.5 Performance Requirements

The contractor shall use a Government owned Application Lifecycle Management (ALM) tool (e.g., Jira) to effectively manage and execute the Agile Scrum methodology to analyze requirements, decompose large requirements into logical sub artifacts, create user stories level artifacts and technical specifications (i.e., Epics or large features must be decomposed into user stories), coordinate with the appropriate subject matter experts (both technical and functional) to receive approved acceptance criteria for Epic/Task/Subtask level artifacts, set Story Points and establish a waterline, develop and test software, create test scripts and implement User Acceptance Testing (UAT), and keep artifact statuses updated (artifacts are the method for identifying a change with software which will be deployed into Production). To maintain predicable velocity, the developers shall complete the artifacts they commit to in each software sprint, and team members are encouraged to collaborate towards requirements completion. User stories and design documentation shall be maintained within the government provided ALM tool. The technical release documentation shall document all changes and procedures necessary to promote a release into production.

The Government will assign requirements to the contractor for fulfillment in via the Government provided ALM tool. Each assigned requirement will have one or more associated artifacts.

The software development sprints are defined by the Government, are planned as four weeks in length, and result in software releases.

1.5.1 Task Area 1: Contract Level and Task Order Management (Fixed Firm Price

[FFP]) (FY24-FY29 T-OPS)

The contractor shall provide the planning, direction, coordination, and control necessary to accomplish all requirements in this PWS. The contractor shall designate key personnel responsible for the cost, schedule, and technical performance for the contract and shall serve as a primary Point of Contact for both management and technical matters. In addition, the contractor shall participate in Program Management Reviews where the status of the work and associated deliverables are reviewed in the context of the business processes supported by the system.

The contractor shall provide support by preparing documents such as required briefings, point papers and meeting minutes related to status of the performance of this PWS.

The contractor shall provide support in the specific areas outlined below in this PWS. The contractor shall work with the IGC Program Office, process owners/stakeholders, Federal and DoD Government representatives, and other contractors to accomplish required tasks.

Government personnel will make all decisions regarding Government requirements or Government actions and the contractor’s representative will submit required evaluations and recommendations to the Contracting Officer Representative (COR) and/or Contracting Officer (KO) for further action.

Deliverables:

Task Order Management Plan (TOMP) The contractor shall prepare a TOMP describing the technical approach, organizational resources, and management controls to be employed to meet requirements.

Product Roadmap The contractor shall maintain a product roadmap to plan out new system capabilities, functionality changes, system maintenance, and/or product upgrades.

The product roadmap shall include current sprint, sprint+1, and sprint+2 at a minimum.

The contractor shall collaborate with the Government Product Owner to obtain the Government’s priority on software features and product updates.

1.5.1.1 Contractor Transition Phase In (Priced Optional CLIN) (FY24)

This is an optional task that will be exercised at time of award if the awardee is other than the incumbent contractor. The phase-in period shall be conducted during the first month of performance. During this period, the incoming contractor will be provided transitional training and work side-by-side with or shadow the outgoing contractor on processes and procedures for performance of day-to-day duties, and specific deliverables. This effort is not functional in nature but is to familiarize the incoming Contractor with the USTRANSCOM work environment as it relates to the requirements of the PWS. This period is also for obtaining access to the software development tools, program tools, and development plans and procedures. The contractor shall be authorized access to Government facilities at Scott Air Force Base (SAFB) if necessary to provide contractor personnel familiarization with existing equipment, reporting, scheduling, and procedures. Many of the phase-in period tasks will be conducted over the Microsoft TEAMS application. The contractor shall provide representation from all contract task areas for this period. At the end of the transition period, the contractor shall assume responsibility for all PWS tasks.

1.5.1.2 Kick-Off Meeting (KOM)

The contractor shall attend a KOM with all partners to establish a baseline of understanding after the contract award at a location to be determined by the COR within 10 business days of contract start. Participants will include Program Manager (PM), Government Technical Lead, KO, COR, and other key contractor personnel and Government staff. At the KOM, the contractor shall present the details of its intended approach and approximated project schedule for review and approval by the COR. The KOM will serve to resolve strategic questions, refine goals, define success, and explore the biggest challenges and breakthrough opportunities for the Government.

This will be the beginning of a dialogue between the Government and the contractor to ensure successful execution of this contract by the contractor. The contractor shall coordinate the agenda for the KOM and include, as a minimum, the following:

Introduction of management and technical teams Presentation of management plans and reports, technical issues, resolutions, and mitigation strategies Establishment of common understanding of the contract Other relevant items may be introduced at the discretion of the contractor and/or the

Government

Deliverables:

KOM Agenda KOM Briefing Materials KOM Action Item Lists KOM Minutes

1.5.1.3 Monthly Status Report (MSR)

The contractor shall provide a MSR that includes by task the financial, performance, system availability, and schedule status. The MSR will include proposed changes to the schedule as detailed in the TOMP as well as property accountability, technical accomplishments, issues and risks, and planned activities for the next reporting period. Any issue requiring Government response or action shall be brought to the Government’s attention immediately upon identification, and status captured in monthly reports.

This report will contain the calls and artifacts received and the actions taken during the reporting period. It shall correlate actions taken to other tasks or solutions that address resolving the reason for the artifact. Since the artifacts are assigned via the Government ALM tool, and the contractor will enter results into the Government ALM tool, metrics associated with the responsiveness, quantity, and duration of the artifacts will be extracted directly from the Government ALM tool.

The status report shall include a cumulative tally of all artifacts assigned to the most recently completed release that have not been previously reported. This tally shall include the release identifier, total number of artifacts assigned to a release per category, the category (e.g., established within the ALM tool such as Requirement, Change Request (CR), Defect), and a total sum of total artifacts across all categories. Further, the report shall contain a sum of artifacts (per category and overall total) that were planned for each sprint (i.e., above the waterline after sprint planning using story points), as well as the sum of artifacts that are accepted in UAT (per category and overall total) and placed into production with the scheduled release. The bottom of the table shall include totals for each column. A notional example is provided below:

Table 1: Notional Example

Release Waterline Deployed

CR Defect Requirement Total CR Defect Requirement Total

10.3 17 4 9 30 17 5 7 29

10.3.1 3 3 3 3

10.4 22 9 4 35 22 9 4 35

Totals 39 16 13 68 39 17 11 67

The MSR is due to the Government no later than the 10th business day of each month. The MSR format will be agreed upon by the COR and the contractor and shall contain, but not limited to, the following information:

Activities conducted and results Deliverable Status Travel data, to include name of traveler, trip location and purpose, estimated and actual travel costs, and dates of travel Meetings attended with a summary of relevant items discussed Proposed activities Risk assessment and mitigation recommendations Open issues Actual and projected cost expenditures Labor hours/costs by task and labor category Key personnel changes System availability and outages Security Summary analysis and assessment results Contractor Furnished Equipment (CFE) Information Assurance (IA) compliance verification Quality assurance and Configuration Management (CM) Key Performance and Capacity Metrics Analysis Task Status for the Reporting Period Production Support Tickets, Metrics, and Reports Number of total production support tickets, the status, listed in order of oldest to newest, average age of ticket Available data storage space (available versus used and ninety (90)-day rolling trend) System Operator Actions by Shift Feed Statistics Rolling thirty (30)-day Trend Charts (Production Support) Number and Processing Time for Query Reports Numbers of Business Objects (BOBJ) Users and Queries Numbers of Web Service Customers and Queries Numbers of COGNOS Users and Queries Software Versioning, Lifecycle, and Licensing Rolling 12-month Data Storage Capacity Projection Sustainment Summary – Provides a listing and status of all Sustainment Releases, Analysis Tasks, Site Configuration Change Notifications, External System Testing, and Emergency Releases

Incidence Report (IR)/CR Report – Provides a summary of all IGC IRs/CRs that are not closed and corresponding states; it shall include 13-week trend charts

Deliverable:

Monthly Status Report (MSR)

1.5.1.4 Weekly Status & Planning Meeting

The contractor shall participate in weekly status and planning meetings as directed by the Government. The contractor shall provide a weekly Task Area Status Report (TASR) that lists the accomplishments of the reporting period by each active task/project area, and provide schedule updates. Focus areas are:

Current Sprint o Tasks and Schedule Updates o Operations and Site Configuration o Security o Blocking Issues

Planning Sprint +1 o Requirements Management o Planning Next Sprint

Administrative o Upcoming calendar events o Pertinent issues as agreed upon by the Government

The TASR is due to the Government by Wednesday of each week.

Deliverable:

Task Area Status Report (TASR)

1.5.1.5 Employment Status Report

The contractor shall provide an employee status report containing names and labor categories of personnel supporting each major task. The report shall be provided within twenty (20) business days after contract award and within five business days after changes in personnel occur.

Deliverable:

Employment Status Report Employment Status Report Updates

1.5.1.6 Service Contract Reporting

The contractor shall report in the System for Award Management (SAM):

1. The total dollar amount invoiced for services performed during the previous Government fiscal year under the contract;

2. The prime contractor direct labor hours expended on the services performed during the previous Government fiscal year; and

3. If applicable Tier 1 subcontract number, including DUNS number/Unique Entity Identifier (UEI) and name, and the number of subcontractor direct labor hours expended under the contract.

Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30.

1.5.1.7 Contractor Transition Phase Out (Priced Optional CLIN) (FY29)

Prior to contract expiration, or in the event of a different contractor winning a follow-on contract, the contractor shall provide, at a minimum, all materials and support necessary to accomplish a seamless and expeditious transition of the tasks identified in this PWS to the incoming contractor. The contractor shall include electronic copies of the following: all in-progress working files, Concept of Operation (CONOPS) procedures, and final phase out meeting with Government, incumbent, and the new Contractor. The contractor shall support a formal contract closeout process, to include documentation of lessons learned throughout the life of the contract.

All deliverables shall be provided forty-five (45) business days before the end of the contract period of performance.

Deliverables:

Transition Plan In-Progress Working Files Concept of Operations (CONOPS) Procedures Lessons Learned

1.5.2 Task Area 2: Software Development Support [FFP] (FY25-FY29 T-OPS)

The contractor shall provide two scrum teams with software developers equal to six Full Time Equivalents (FTE) on each team. This task includes responding to requirements generated by the Government through change requests, program, security, production support, or trouble reporting mechanisms. ALM artifacts are the method for identifying software changes, which will be deployed into the Production environment. The contractor shall properly record user stories, associated acceptance criteria, issues, and software solutions to create a knowledge base within the Government’s ALM tool. The contractor shall use the Agile Scrum Framework to execute extreme programming (xP) practices such as test driven development, refactoring, and continuous integration; when completing artifacts to include: requirements elicitation and decomposition, completion of user stories and specifications, software development, security code scans, unit testing, integration testing, and UAT. The contractor shall use a microservices architecture for new code, and decouple monolithic legacy code when appropriate (e.g., failure isolation, multiple rates of change, simplify external dependencies) for long-term usability and scalability of the application. Additionally, the contractor shall automate testing, security updates, configuration management, the software build process, etc. necessary to achieve Continuous Integration/Continuous Delivery (CI/CD).

Deliverables:

Software. The primary deliverable of this task is software code, system configurations, database schemas, etc. resulting from this task. All software code, system configurations, database schemas, etc. associated with this contract shall be the property of the Government and shall not contain any company proprietary markings, logos, or any distribution restrictions. Software code shall be installed on the Government’s Staging and Production servers and provided as a tagged code segment via the Government managed code repository and/or delivered on other mutually agreed upon format.

Release Documentation. As a minimum, this shall include a work plan with recurring updates, static code scans (e.g., Fortify, SonarQube, TruffleHog), release test plan with results, UAT plan with test scripts, and minor mod checklists (i.e., release notes), which include all artifacts with associated descriptions and solutions, and deployment instructions.

Updated Project Documents. Documentation sufficient to install, operate, and maintain the system shall be provided and maintained. These documents shall include updates to the product roadmap, COTS products, training manuals, user manuals, system installation procedures, and any supporting documents necessary for the Government to sustain the system.

Updated System Documents, Security Documents, and White Papers. All solution changes shall be documented as user stories, technical specifications and/or diagrams, interface control documents, system configuration documents, and/or Department of Defense Architecture Framework (DODAF) architectural artifacts. Additionally, documentation will be generated and maintained to support Static Code Analysis, the Risk Management Framework (RMF), DISA Security Technical Implementation Guides (STIGs), DODI 8530.01, and the DOD Cloud Computing Security Requirements Guide.

1.5.2.1 Agile Software Development Support

The contractor shall respond to ALM artifacts to change the system, as prioritized and assigned by the Government Product Owner. The contractor shall participate in and/or lead the Scrum process and other meetings to define, build, test, document, and deploy updates to the system baseline. The contractor shall ensure ample lead-time for understanding and responding to unique change requests. The planning for requested functionality may include the contractor’s recommendations to minimize rework and cost. If a change is beyond the contractor’s capacity to complete within one sprint, the contractor shall decompose the Epic and/or Features into smaller user stories; and update the schedule (i.e., product roadmap). Complex tasks may require additional planning before coding. These tasks are assigned to a sprint for development of a specification prior to the implementation sprint. The contractor shall work with subject matter experts to create, and receive approval on, user stories and associated acceptance criteria, functional specifications and/or technical specifications. The contractor shall support UAT for releases to ensure proposed changes are acceptable to users; and, when required, host release reviews for functional users to illustrate system changes. The contractor shall assist with minor mod checklists (i.e., release notes); and shall provide necessary support to maintain and document the security posture of the application as required by the RMF or applicable DOD accreditation process.

1.5.2.2 Software Defect Support

The contractor shall immediately respond to escalated production support issues that cause work stoppage or operational problems with the system and ensure the Production system operates without interruption to functional users. Software defects that result in a work stoppage or impact to business operations shall result in an unplanned software Hot Fix. Correcting defects identified through production support that do not result in a work stoppage shall be prioritized and assigned to current sprint or a future sprint by the Government depending on the impact to business operations. The contractor shall assist the production support activity in identifying the root cause of production support malfunctions and creating ALM artifacts (i.e., software code changes) to permanently resolve or prevent them. The contractor shall input all actions taken to resolve artifacts into the Government ALM tool. The contractor shall coordinate with production support to ensure minimal rework and downtime during software changes, and to ensure the production support activity understands planned system changes.

1.5.2.3 COTS Support

The contractor shall provide support services for changes in COTS products to include patches (e.g., application, operating system, database), upgrades, and/or migration to newer technologies.

This will involve analyzing the system for incompatibilities and deprecated features; and includes keeping 3rd Party Libraries up-to-date. Once prioritized by the Government, the contractor shall refactor the necessary code to ensure continued system stability. The refactoring shall be assigned to sprint(s) and follow the Agile SDLC process for integration and testing of refactored code.

1.5.2.4 Deployment Pipeline Support

Once IGC is migrated and operational in an Unclassified (planned for March 2025) and Classified (planned for August 2025) Government Cloud (GovCloud), the contractor shall provide expertise required to operate and maintain the Development, Test, and Production environments to reliably and efficiently compile, build, and deploy code. This shall include maintaining virtual machines and components, such as servers, memory, firewalls, load balancers, and storage (i.e., databases). Additionally, the contractor shall maintain and update the Ports, Protocols, and Services (PPS) information. This shall include ports for internal and external traffic as well as the source and destination IP Addresses information. Air Force Department of Defense (AF-DOD) approved PPS worksheet will be used; available on the PPS Management at https://intelshare.intelink.gov/sites/ppsm.

1.5.2.5 Static Application Security Testing (SAST) Support

The contractor shall run static code scans on the entire application using a Government approved code scan tool(s) (e.g., Fortify, SonarQube, TruffleHog) to prevent security vulnerabilities from being deployed into the production environment. The contractor shall analyze code scan results and remediate findings or provide rationale on false positives.

1.5.2.6 DOD Security Requirements Guides (SRGs) and STIGs Compliance Support

The contractor shall register with the DISA STIG library https://cyber.mil/stigs/ to receive notifications for updates to ensure the application and supporting application technology (e.g., operating system, database, servers) complies with the most up-to-date version of the DOD SRGs and Application Security and Development STIGs. The contractor shall remediate any non-compliant checklist items. The contractor shall enter open STIG findings, along with fix actions, into the Government ALM tool.

1.5.3 Task Area 3: Monitoring and Production Application Support [FFP] (FY25-FY29

T-OPS)

This task includes monitoring and troubleshooting production applications; and responding to incidents that are generated by system users. Production support tickets shall be generated within the Government ALM tool. Production support tickets are the method for tracking and resolving incidents (i.e., specific issues), as well as processing user account requests. Incidents may involve generating software defect artifacts (i.e., for systemic problems requiring code changes);

which will be prioritized by the Government. The contractor shall document incidents and systemic problems for accurate reporting, metrics, and to provide a knowledge base within the

Government ALM tool. The contractor shall be responsible for ensuring the description and resolution for incidents they resolve are documented clearly.

Deliverables:

System Performance Report. This report shall contain all open tickets listed in order of priority starting with highest priority, and further sorted such that the earliest ticket of a given priority is at the top for that priority grouping. This report shall contain the ticket #, priority, associated tickets, descriptions, corrective action, date opened and closed with the user, as well as trend and other pertinent data. It shall correlate actions taken to other tasks or solutions that resolved similar tickets. If the contractor has detected a trend, this report shall include a brief summary of the trend, associated tickets, pertinent distribution of causes, and recommended corrective action to prevent similar troubles. The contractor shall use their expertise to recommend changes to software code, queries, data validations, etc. The Government will review these recommendations and provide guidance when appropriate. Since the production support tickets are managed via the Government ALM tool, metrics associated with responsiveness, quantity, and duration of tickets shall be extracted directly from the ALM tool and summarized in the report.

Cyber Intrusion Incident Report. This report shall provide details identifying the root cause, impacts, and actions taken to resolve and prevent the vulnerabilities. The Initial Cyber Intrusion Incident Report is due within four hours of the event. The Cyber Intrusion Incident Report Update is due within twenty-four (24) hours of the event.

Operations Report. This report shall be generated using the Government ALM tool and provide updates on all tickets opened, updated, or closed during the previous 24 hours.

Tickets include, but are not limited to, alert/alarm information and corrective actions, reach back support and contact, outage and availability details, maintenance Authorized Service Interruption (ASI) details, feed processing outage details, and any event that required manual or automated recovery actions to eliminate or reduce impact to the customer. This report shall be e-mailed daily (Sun-Sat) at 0600 to the Government Operations Manager.

1.5.3.1 Monitoring Support

The contractor shall provide twenty-four hours a day, seven days a week support to monitor current health, performance statistics, recent errors, full logs, and key metrics. The contractor shall ensure the system is working normally; and report and resolve any breaches, security attacks, degradations, outages, or anomalies in activity. The contractor shall use log collection, monitoring, and analysis to understand the relationship between network, infrastructure, servers, application framework, data feeds health, data feed latency, databases, reference data, and user behavior to gain a comprehensive view across all activity, across all sources, servers, and locations. In the event of a Cyber incident or intrusion, the contractor shall conform to the policy outlined in the IGC Incident Response Plan. The contractor shall report any detected cyber intrusions. Cyber incidents shall be documented in a Cyber Intrusion Incident Report. The incident report shall document and report loss/compromise, suspected compromise, suspicious contact, or activity involving systems accredited to process classified information. It may be used as a preliminary response to supplement national reporting requirements and provide a resource to document initial or first response to a Cyber incident.

1.5.3.2 Production Support

The contractor shall respond to and resolve operational problems with the IGC system and tool suite. This task includes responding to incidents, analyzing and correcting specific incidents, creating software development artifacts (e.g., Jira tickets) for systemic problems requiring code changes, and following escalated tickets to resolution. Typical incidents to be resolved under this task include database updates for specific records with incorrect data, which involves determining the cause of the issue, correcting the database, and determining whether a permanent code fix is necessary.

This task also includes resolving COTS related issues, system interface issues, and system access arissues. The contractor shall coordinate with commercial vendors and other Government service providers to provide hardware, interface and software support.

The contractor shall coordinate with the DISA DECC Operational Support Team (OST), Help Desks, TRANSCOM DOD Information Networks (DODIN) Operations Center (TDOC), and other External Organizations (EOs) as required to coordinate resolution of issues. The contractor shall establish processes to handle cross-notifications between DLA, USTRANSCOM, source systems, DISA, and other EOs.

1.5.3.3 Production Support Analysis

The contractor shall analyze problems and solutions to detect and report trends and “worst actor” features and/or processes. These recommendations shall consider the simplest solutions first. For example, a trend in user errors for entering data might be solved by adding help text or changing data validations. On the other hand, recurring errors may require changes to functionality or the database. The contractor’s expertise must be sufficient to support such analysis and to provide concise, actionable recommendations. For complex recommendations, the contractor may have to collaborate with the Government or other contractor personnel to create change specifications.

Support analysis may also result in recommending changes to system documentation or training material.

1.5.3.4 Cybersecurity Analysis

The contractor shall monitor and analyze Information Assurance Vulnerability Management (IAVM) Notices, USTRANSCOM Security Notifications, United States Computer Emergency Readiness Team (US-CERT), and vendor security advisories. The contractor shall determine system impact, identify mitigating factors, and provide recommendations to the Government regarding potential courses of action. The contractor’s recommendations shall be compliant with DOD security requirements and industry best security practices. The contractor shall ensure that cybersecurity remediation, patch deployments, and other significant security activities are considered in the Product Roadmap.

1.5.3.5 Cybersecurity Service Provider (CSSP) Support

The contractor shall provide Host Based Security System (HBSS) and Assured Compliance Assessment Solution (ACAS) scans weekly; and shall participate in one Continuity of Operations (COOP) exercise (i.e., Intrusion Assessment or Incident Response) annually.

1.5.3.6 Interoperability Certification Support

The contractor shall ensure IGC maintains interoperability certification by the Joint

Interoperability Test Command (JITC) in accordance with Chairman Joint Chiefs of Staff (CJCS) Instruction 5123.01H. All documentation delivered also must meet recommendations and guidelines defined in DOD Instruction 8330.01. The contractor shall comply with the most current version of each reference. The contractor shall review and provide inputs (if applicable) to the IGC DODAF artifacts provided by the USTRANSCOM enterprise architecture team and review the Enhanced Information Support Plan (e-ISP).

1.5.3.7 On-Site Platform/Infrastructure Support

Until IGC is migrated to GovCloud, the contractor shall provide System Administration (SA), Application Administration, and Database Administration (DBA) support focusing on architecting, deploying, maintaining and documenting IGC infrastructure in the current on-premise environment (i.e., DISA DECC). Examples of activities include: supporting the IGC infrastructure, promoting software deployments, security patching, incident and problem management, monitoring resource usage, application performance, and managing all system accounts.

The contractor shall provide technical input during DECC hardware services Operating System (OS) patches, upgrades, and technical refreshes. The contractor shall provide technical input, schedule de-confliction, and perform regression testing of COTS and IGC product baselines. The contractor shall coordinate with affected EOs, and impacted provider and consumer systems. The contractor shall perform COTS and IGC product baselines regression testing on the equipment, and data migration and testing. This position shall maintain a current Secret Clearance (See Section 5), with a current T-5 background investigation, and current IAT I or IAT II certification (See Table 4).

Once IGC is migrated to GovCloud, the Government will descope this subtask via contract modification.

1.5.3.8 COTS Patching and Upgrades

The contractor shall provide patching and upgrade support for COTS products hosted at the DISA DECC as prioritized by the Government; and assist with COTS replacements if required by the Government.

1.5.3.9 SAP Business Objects (BOBJ) Support

The contractor shall support the operations of the BOBJ applications within IGC. This includes administration, performance tuning, adding users, granting permissions, configuration, account management, performance troubleshooting/ monitoring, performing restores, auditing and clearing logs, and monitoring space and capacity.

1.5.3.10 IBM COGNOS Support

The contractor shall support the operations of the COGNOS applications within IGC. This includes administration, cube support, mash-up support, performance tuning, adding users, granting permissions, configuration, account management, performance troubleshooting/ monitoring, performing restores, auditing and clearing logs, and monitoring space and capacity.

At a minimum, the contractor shall provide individual(s) with the following qualifications to perform this subtask:

IBM Certified Administrator – COGNOS BI (Exam COG-622) with three (3) years’ experience

1.5.3.11 Teradata Hardware Technical Refreshes

The contractor shall support hardware technical refreshes of IGC Teradata hardware. The contractor shall provide technical input, installation of the COTS and IGC product baselines on the equipment, data migration and testing. The contractor shall coordinate with affected EOs, including the DECCs.

1.5.4 Task Area 4: CCMD Exercise Support [LH] (FY25-FY29 JTEEP O&M)

The contractor shall provide support equal to 0.75 FTE to provide an exercise capability on the classified environment that emulates the operational environment. Data for this exercise capability uses simulated data provided by exercise systems. This capability enables IGC to participate in USTRANSCOM-supported exercises. The contractor shall provide on-site Exercise Controller Support for pre-exercise planning, exercise data loading, exercise execution and post-exercise review activities.

The contractor Exercise Controller, in coordination with the Government, shall activate required exercise feeds to support specific exercise requirements. Tasks include incorporating required production data; maintaining/updating exercise specific reference data; providing exercise setup, start, stop, save, and message archive; monitoring exercise feed status and purging exercise related data; coordination with exercise data providers; and establishing user account permissions to access exercise data on an individual exercise basis.

The contractor shall provide on-site Exercise Controller staff during normal working hours, 0800 until 1700 Central Time Monday through Friday, excluding holidays, during exercises. In exercise windows, the Exercise Controller will support during normal business hours and hand off to Production Support during non-business hours to support exercise tasks. The Exercise controller will be on call 24/7, during exercise windows, in support of issues the Production Support can not resolve. The Exercise Controllers shall be located at the government facility (SAFB or the Alternate Operating Facility) and will utilize Government owned office space and equipment/workstations. Exercise duration is typically six to 14 calendar days for up to eight planned Joint Staff (JS) and CCMD funded exercises a fiscal year some of which may run concurrently. The contractor shall be able to support up to two simultaneous exercises.

Additionally, the contractor shall participate in the development and testing of DESS-produced support data. The contractor shall support two DESS Thread Tests per fiscal year and document event test results by reporting results to the USTRANSCOM-J37 DESS Program Manager.

1.5.5 Task Area 5: RMF Support [FFP] (FY25-FY29 T-OPS)

The contractor shall provide support equal to one FTE responsible for creating and maintaining System Security Assessment and Authorization documentation for RMF security authorization.

The contractor shall develop documentation in accordance with (IAW) DOD Instructions

8500.01 and 8510.01, and National Institute of Standards and Technology (NIST) SP 800-18 and SP 800-53a. In addition, the contractor shall support existing system security documentation to facilitate security authorization in accordance with DOD RMF.

Along with the System Security Plan (SSP), the contractor shall submit a plan and timeline to create any missing cybersecurity supporting artifacts IAW Attachment 2_Compelling Evidence Standards. The contractor shall participate in IGC assess and authorize (A&A) activities. The contractor shall manage and update existing system security documentation developed to facilitate IGC security authorization IAW RMF procedures. The contractor shall conduct security certification activities as required to maintain current authorization and support follow-on authorizations.

The government will be responsible for providing policy requirements associated with the program, while the developer will be responsible for building and incorporating the language into the required artifacts.

Deliverables:

SSP & Plan for Cybersecurity Support Artifacts The contractor shall develop an SSP IAW DOD Instructions 8500.01 and 8510.01, and NIST Special Publication (SP) 800-18 and SP 800-53a. The SSP will be a formal document that provides an overview of the security requirements for the system and describes the security controls in place or plans for meeting those requirements. The information gathered in paragraph 1.5.5.1 will be included in the SSP as it becomes available so that IGC remains continuously up to date.

1.5.5.1 Cybersecurity Planning Support

The contractor shall perform Assessment and Authorization and Risk Management activities to maintain system authorization and support follow-on activities. The contractor shall ensure compliance by providing documentation of applicable RMF Controls, Assessment Procedures (APs), and Control Correlation Identifiers (CCIs). This may involve coordination with the Government, and other Government appointed contractors, such as System Administration, Security Engineer, Information System Security Manager, Information System Security Officer, and Functional Subject Matter Expert teams.

Additionally, the contractor shall provide the required compelling evidence to demonstrate compliance with the requirements of the APs or CCIs, such as screen shots, audit logs, messages, completed forms, signed letters or other documentation, etc. Acceptable compelling evidence per requirements, APs, and CCIs are documented in Attachment 2_Compelling Evidence Standards.

After contract award, the Government will provide the contractor a list of the current controls, APs, and CCIs relevant to the IGC system. The contractor shall contribute artifacts to demonstrate compliance with the requirements of the APs or CCIs. Some of the security controls within each control family may be inherited from the hosting environment or a third party provider.

Artifacts may include, but are not limited to:

Logical Diagram Network Diagram Data Flows (PPS) External Interfaces Type of Data Exchange Firewall Rules Firewall Rule Log Authenticated Scans Protection Mechanism(s) Hardware and Software Inventory Lists Memorandums of Agreement/Understanding (MOA/MOU), Service Level Agreements

(SLA), Interface Control Agreement (ICD)

Acceptable Use Policy PPS information. The contractor shall provide ports for internal and external traffic and source and destination Internet Protocol (IP) Addresses information. The contractor shall use the DISA approved PPS worksheet.

Risk Analysis and Assessment Report. Relating to the system applicable Information Assurance Vulnerability Assessments and any other reported vulnerability

IA Topology Static Code Analysis Reports Incident Reports

1.5.6 Task Area 6: Cloud Migration Support [LH] (Priced Optional Task) (FY25-FY29

T-OPS)

The contractor shall migrate IGC from its on-site hosting environment (i.e., DISA DECC) into GovCloud to utilize cloud computing for the Development, Test, and Production environments.

USTRANSCOM's TRANSCOM Cloud Optimal DevSecOps Ecosystem (TCODE) (i.e., cloud platform as a service) is currently hosted within AWS GovCloud, but that may change in the future. The contractor shall utilize USTRANSCOM enterprise capabilities (e.g., TCODE) and cloud native services (e.g., AWS CSOs) when available. The current estimate for this effort is 30 months beginning 1 October 2024, however, this is an optional task as the start date may change.

The contractor shall provide pricing for this optional task per contract period.

Deliverables:

Cloud Architecture Application Migration Strategy Application Deployment Blueprints Cloud Migration After Action Report (AAR)

1.5.6.1 Design Cloud Migration Architecture

The contractor shall provide a loosely coupled architecture while leveraging native cloud services (e.g., Elastic Load Balancing, Auto Scaling, Relational Database Services, RedShift, Diode, etc.) that can be easily ported (e.g., AWS to Azure). The proposed cloud architecture shall include operating system instances, storage, network topology, and Government-specific security controls. The contractor shall take into consideration a microservices-based architecture, stateless application, serverless computing, containerization, automated application and infrastructure deployment, automated scaling, high availability, and cost optimization. The contractor shall ensure the cloud architecture enables software deployments from the Development environment through the Production environment. The contractor shall document scaling procedures for operational scenarios that would necessitate a change in compute or storage for up to 14,000 concurrent NIPR users and up to 150 concurrent SIPR users. The contractor shall develop the proposed cloud architecture in coordination with the appointed Government Technical Subject Matter Experts to attain final Government approval.

1.5.6.2 Develop Application Migration Strategy

The contractor shall develop a detailed application migration strategy, which will include the target environment, migration approach, data migration plan, resource plans from both the Government and contractor, timelines, dependency diagram, risks/issues, estimated costs, test strategies, and Government-specific security controls. The contractor shall ensure the migration plan identifies and remediates gaps or discrepancies between the current and end state environment, if applicable. The contractor shall develop the application migration strategy in coordination with the appointed Government Technical Subject Matter Experts to attain final Government approval.

1.5.6.3 Application Refactoring Support

The contractor shall perform any necessary refactoring so the application works effectively and efficiently in the cloud. The contractor shall consider a service-oriented architecture, the number of running instances to allow dynamic scaling, and dynamic-cloud capabilities.

1.5.6.4 Build Cloud Enclave Environments

The contractor shall adopt the operating procedures and DevSecOps tool chain managed and maintained by the Government to sustain, support, and operate IGC in the GovCloud (e.g., TCODE).

1.5.6.4.1 Build Development Environment

The contractor shall download the applicable Software Development Kits (SDKs) and become familiar with the GovCloud (e.g., TCODE) services, procedures, and technologies. The contractor shall establish, configure, and validate a development environment for the application within the GovCloud to ensure the environment can support development activities (i.e., Develop, Build, Deploy, Test).

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .