53-0005-22 Statement of Work.pdf

PDF 190 KB Posted

Attached to
IT Services (Radar Division) Federal contract opportunity
Solicitation number
N00173-22-RFI-FW05
Issued by
Department of the Navy Secretary of the Navy Office of Naval Research

About this file

This statement of work outlines IT support services required by the Naval Research Laboratory's Radar Division. The contractor shall provide on-site and remote IT support services including implementing security technical implementation guides to harden systems, monitoring networks and security devices for compliance, managing software installations, using group policy objects and Microsoft Endpoint Configuration Manager to maintain compliance and update software, installing and configuring Single Sign On software, managing an Exchange email server and Symantec security software, and assisting with system accreditation. The contractor shall also provide help desk support and maintain documentation for the unclassified and classified networks. The period of performance is 60 months. The contractor must have favorably adjudicated security clearances and visit requests are required for contractor personnel.

This sources sought notice/request for information is to gauge interest in fulfilling IT services requirements for the Naval Research Laboratory's Radar Division. The attached statement of work outlines the minimum technical requirements. Responses to this notice are not binding and do not guarantee an award will be made. The notice intends to determine set-aside possibilities for small businesses. The required response format is in an attached document.

View the file

Other files for this federal contract opportunity

Other files attached to IT Services (Radar Division), newest first.
File Type Posted
53-0012-22_1300988622 SOW.pdf PDF
Radar Division IT SOW 2022_1_31.pdf PDF
IT Personnel Qualification 2022_1_31.pdf PDF
53-0005-22_Level of Effort - Radar IT Services.xlsx XLSX spreadsheet
53-0005-22_IT Personnel Qualification 2021_01_28.pdf PDF
53-0005-22_Radar Division IT SOW 2022_01_28.pdf PDF
53-0005-22_Requirements for On-Site Contractors.docx DOCX document
53-0005-22_Sources Sought Notice - Radar IT Services.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work

Information Technology Support

1.0 Purpose

1.1 The Purpose of this effort is to assist the Naval Research Laboratory’s (NRL) Radar Division (Code 5300) with Information Technology (IT) support for technical and administrative needs.

2.0 General Requirements:

2.1 The Contractor shall have its support team in place and fully functioning at the time of the base contract award or exercise of contract option(s).

2.2 On-site staff is, at a minimum, required on all Government work days between the hours of 0830-1700, at a minimum. Remote support is permitted as long as one person is on site during the core hours

2.3 During this period the contractor will execute the technical requirements of either the base or option of the contract in a manner that provides for high quality, timely support while incorporating the proper mix and the most effective use of personnel.

The Base Requirements for the contract award is to have a Senior Computer Systems Engineer in place at the time of award. The position requirements are listed in Personnel Qualifications.

Option One Requirements for the contract is to have a Senior Computer Network Specialist in place at a minimum within 2 months when this option is exercised. The position requirements are listed in Personnel Qualifications.

Option Two Requirement for the contract is to have a System Administer in place at a minimum within 1 month when this option is exercised. The position requirements are listed in Personnel Qualifications.

The determination to exercise options may be determined at time of award or any time thereafter.

3.0 Tasking

3.1 The Radar Division has approximately 100 Users that operates a crossed a multiple of platforms. The current configuration is approximately as follows:

3.1.1 Systems and their current configuration:

3.1.1.1 Unclass servers 30 Windows, 25 Linux

3.1.1.2 Unclass clients 400 Windows 45 Linux

3.1.1.3 Servers are physical and virtual (Class and Unclass.)

3.1.1.4 Class servers 11 Windows 25 Linux

3.1.1.5 Class clients 15 Windows 15 Linux

3.1.1.6 Sever OS include Windows: 2008 R2, 2012 R2, 2016, 2019, Linux Cent

OS7, AlmaLinux 8

3.1.1.7 Workstations and Laptop OS includes Windows 10 SHB (Window 7

Standalones) Linux CentOS 7, AlmaLinux 8, Debian, and Ubuntu Fedora.

3.1.1.8 Maintaining over 27,000 different software titles and versions.

3.1.1.9 Software running on server: Software non-OS Exchange 2016, SQL

2019, IIS 8, BES/UEM 12.15, BelManage 8, BelSecure 8, SecureDoc 5, Windows Update Service Server, Symantec Endpoint Manager 14.3 RU3, Microsoft Endpoint Configuration Manager 5, TrippLite power management, Xerox print management, FlexNet License Management.

Virtualization Microsoft Hyper-V and VMWare, Visual Studio, Symantec Mail Security for Microsoft Exchange, ACAS Security Center, Tenable Nessus, SpaWar SCC/SCAP, and Veritas System Recovery.

3.2 The contractor shall provide IT support to all Radar Division personnel on Nicenet and

5300 Research Net (Unclassified) systems. The Contractor shall install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked systems. Procedures must be developed and maintained for systems such as set up, startup, shutdown, integration, troubleshooting, and operation. Information Technology professionals will monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results. Network applications and services are supported at different classification levels. Solutions are developed to monitor performance, provide scaling capability, and improve quality of service. Systems are installed, and errors resolved.

Support will be provided in the preparation and testing of DoD and US Government computer and/or network systems for accreditation.

Tasks can include, but not limited to:

3.2.1 Implement Security Technical Implementation Guides (STIGS) to harden Nicenet, and 5300 Research Net (Unclassified) systems, and network equipment per DoD standards. Use DoD approved scanning tools such as Assured Compliance Assessment Solution (ACAS), Nessus and SCC/SCAP for monitoring security of Nicenet and Radar Division’s Unclassified Network to identify and address vulnerabilities to ensure compliance with NRL/DoD Navy regulations.

3.2.2 Monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results on Unclassified Network (NICENET), and Non-Internet connected Enclave.

Develop new solutions to monitor performance, provide scaling capability, and improve quality of service. Monitor and report system compliance.

3.2.3 Manage software installations on Unclassified Network and Non-Internet connected Enclave per DADMS guidelines. Verify software installs comply with the DoD approved list in the DADMS database. System Hardware and Software.

3.2.4 Use Group Policy Objects (GPOs) to maintain STIG compliance and update third party software on all systems in Radar Division Windows Active Directory (AD) domain. In addition Microsoft Endpoint Configuration Manager for supplemental third party software deployment and IAVA updating.

3.2.5 Install/configure/maintain Centrify COTS software to implement Single Sign On (SSO) to Windows, and Linux systems per DoD guidelines.

3.2.6 Manage/update/configure MS Exchange email server for Radar Division users, integrating Exchange with Windows and Linux email users. (Manage and maintain Symantec Mail Security for Microsoft Exchange.)

3.2.6.1 It is expected that email will migrate to Flank Speed during the period of performance of this contract. This requirement will cease at that point.

3.2.6.2 Once external email is discontinued on the lab, an email server on a Non-Internet connected Enclave will be established for communications between Radar Division Personnel.

3.2.6.3 (Manage Symantec Endpoint Protection host based security anti-virus/malware/spyware and firewall.)

3.2.7 Configure and maintain mobile disk encryption of GFE mobile devices such as laptops

3.2.8 The ability to provide Security Engineering design and System Engineering network design via the Enterprise Architecture and the ability to fully integrate both.

3.2.9 Install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked and stand-alone systems.

Maximize reliability, maintainability and availability of IT hardware and associated peripherals. Provide IT technical support for the scientific and administrative users.

3.2.10 Interface with NRL Information Systems Security and implement all required computer security procedures. Interface with the NRL networking group to maintain the Radar Division networking infrastructure.

3.2.11 Assist in the preparation and testing of DoD and US Government computer and/or network systems for accreditation

3.2.12 Install hardware and software upgrades to IT systems in accordance with technical direction from the COR

3.2.13 Perform IT systems hardware and software modifications in accordance with technical direction from the COR.

3.2.14 Maintain computer configuration management systems and databases including hardware component lists, modifications, upgrades and maintenance histories.

3.2.15 Coordinate effectively with IT hardware and software vendor representatives in troubleshooting resources affecting computing.

3.2.16 Ensure proper integration of multiple computer systems and types to the SSD shared computer systems and infrastructure including satisfying both technical and administrative interface requirements in both IT hardware and software.

3.2.17 Perform duties related to Cybersecurity Testing, Evaluation, Validation and Verification of traditional and non-traditional information systems.

3.2.18 Development of Cybersecurity test plans for security testing of DoD/DoN information systems in the unclassified and classified domains IAW National and DOD requirements.

3.2.19 Executing testing procedures to determine an accurate assessment of the representative systems and provide information that will formulate mitigation strategies, risk analysis, and risk-based decisions (RBD).

3.2.20 Manages the daily activities of configuration and operation of systems and performs system capacity analysis and planning. Monitors systems for acceptable performance and user accessibility.

3.2.21 Maintains servers, creates monitoring reports and logs, and ensures functionality of system links

3.2.22 Support the technical areas within information security work related to Cybersecurity

3.2.23 Provide help desk support to Radar Divison personnel and support contractors to resolve computer and software issues in a timely and cordial manner.

3.2.24 Maintain documentation of the Code 5300 NICENET, Non-Internet connected Enclave equipment and software configurations.

3.2.24 Install/update/configure Blackberry Enterprise Server and KNOX software for access to Radar Division email via Blackberry, Samsung and iPhone cell phones.

3.2.25 Manage encryption of GFE mobile. Configure and maintain mobile computing system and disk encryption

3.3 The contractor shall provide IT support to all Radar Division personnel Radar5300SCF (REDNET) systems. The Contractor shall install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked systems. Procedures must be developed and maintained for systems such as set up, startup, shutdown, integration, troubleshooting, and operation. Information Technology professionals will monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results. Network applications and services are supported at different classification levels. Solutions are developed to monitor performance, provide scaling capability, and improve quality of service. Systems are installed, and errors resolved. Support will be provided in the preparation and testing of DoD and US Government computer and/or network systems for accreditation.

Tasks can include, but not limited to:

3.3.1 Implement Security Technical Implementation Guides (STIGS) to harden Radar5300SCF (REDNET (Classified Network)) systems, and network equipment per DoD standards. Use DoD approved scanning tools such as ACAS, Nessus and SCC/SCAP for monitoring security of the CLASSIFED NETWORK to identify and address vulnerabilities to ensure compliance with NRL/DoD Navy regulations.

3.3.2 Monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results on Radar Division Classified Network (REDNET). Develop new solutions to monitor performance, provide scaling capability, and improve quality of service.

Monitor and report system compliance.

3.3.3 Manage software installations on the Classified Network (REDNET).

Verify software installs comply with the DoD approved list in the DADMS database. System Hardware and Software.

3.3.4 Use Group Policy Objects (GPOs) to maintain STIG compliance and update third party software on all systems in Radar Division Windows Active Directory (AD) domain. In addition Microsoft Endpoint Configuration Manager for supplemental third party software deployment and IAVA updating.

3.3.5 Install/configure/maintain Centrify COTS software to implement Single Sign On (SSO) to Windows, and Linux systems per DoD guidelines.

3.3.6 Manage/update/configure MS Exchange email server for Radar Division users on REDNET, integrating Exchange with Windows and Linux email users. (Manage and maintain Symantec Mail Security for Microsoft Exchange.)

3.3.7 Install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked and stand-alone systems. Maximize reliability, maintainability and availability of IT hardware and associated peripherals. Provide IT technical support for the scientific and administrative users.

3.3.8 Interface with NRL Information Systems Security and implement all required computer security procedures. Interface with the NRL networking group to maintain the Radar Division REDNET networking infrastructure.

3.3.9 Assist in the preparation and testing of DoD and US Government computer and/or network systems for accreditation

3.3.10 Install hardware and software upgrades to IT systems in accordance with technical direction from the COR

3.3.11 Perform IT systems hardware and software modifications in accordance with technical direction from the COR.

3.3.12 Maintain computer configuration management systems and databases including hardware component lists, modifications, upgrades and maintenance histories.

3.3.13 Coordinate effectively with IT hardware and software vendor representatives in troubleshooting resources affecting computing.

3.3.14 Ensure proper integration of multiple computer systems and types to the

SSD shared computer systems and infrastructure including satisfying both technical and administrative interface requirements in both IT hardware and software.

3.3.15 Perform duties related to Cybersecurity Testing, Evaluation, Validation and Verification of traditional and non-traditional information systems.

3.3.16 Development of Cybersecurity test plans for security testing of DoD/DoN information systems in the classified domains IAW National and DOD requirements.

3.3.17 Executing testing procedures to determine an accurate assessment of the representative systems and provide information that will formulate mitigation strategies, risk analysis, and risk-based decisions (RBD).

3.3.18 Manages the daily activities of configuration and operation of systems and performs system capacity analysis and planning. Monitors systems for acceptable performance and user accessibility.

3.3.19 Maintains servers, creates monitoring reports and logs, and ensures functionality of system links

3.3.20 Support the technical areas within information security work related to Cybersecurity

3.3.21 Provide help desk support to Radar Davison personnel and support contractors to resolve computer and software issues in a timely and cordial manner.

3.3.22 Maintain documentation of the Code 5300 REDNET equipment and software configurations.

3.0 Deliverables

3.1 Monthly Labor and Financial Status Report

3.1.1 Funding history, showing when and how much money was added to each ACRN for each person on the task, amounts allocated to labor, travel, and material, along with cumulative task funding for labor, travel, and material;

3.1.2 Funding balance for labor and materials in each ACRN and by person at the beginning of the monthly reporting period;

3.1.3 Labor hours and amounts expended for labor and materials in each ACRN and by person during the monthly reporting period;

3.1.4 Funding balance for labor and materials in each ACRN and by person at the end of the monthly reporting period.

3.2 Task Technical Progress Reports

The contractor shall provide a monthly summary report of progress on each task of the contract that includes the following information:

3.2.1 Description of the work accomplished;

3.2.1 Summary of meetings attended;

3.2.1 Plans for next reporting period;

3.2.1 Summary of issues or concerns, if any.

4.0 Period of Performance

The period of performance for this effort is sixty (60) months from date of award

4.1 Performance Requirements

The contractor shall perform the above-stated objectives during NRL Radar Division normal core working hours, generally 8:00 am to 5:30 pm Monday through Friday or during other agreed upon hours, except for Federal holidays. Flexible work hours may be used to ensure that some range of technical services are available during the time specified, taking into account the need for maximum support during NRL core work hours. Deviation from these support hours and any use of telework to meet local support requirements shall be proposed to and coordinated by the Contracting Officer's Representative (COR). NRL may require after hours or weekend efforts, for example but not limited to, support of a scheduled outage or to react to an emergency or security situation. After hours support shall be coordinated between the COR and the local site

Program Manager (PM). The NRL COR shall provide the PM with advance notification and specific needs if known in advance. Contractor personnel shall also investigate, provide recommendations for remedial action, and pursue corrective action in case of emergency situations.

Scheduled leave of contractor personnel shall be coordinated between the NRL COR and the PM to ensure that the necessary support activities are adequately covered. The NRL COR shall be notified promptly of any unscheduled contractor leave.

5.0 Special Requirements

The section describes the special requirements for this effort. The following sub-sections provide details of various considerations on this effort.

5.1 Security

a. Specifically designated contractor personnel assigned to this contract must possess a favorably adjudicated DoD Tier 3 investigation and a final SECRET DoD granted personnel security clearance.

b. The contractor will NOT be required to generate, receive or store CLASSIFIED material at the contractor’s facility.

c. A visit request is required for all personnel assigned to work on this contract. Visit requests must include full name, social security number, contract number and should also state if Government furnished computer equipment will be required.

d. Prime contractor will forward a copy of all subcontracts and task orders, related to this contract, regardless of classification, must be approved in advance, in writing, by the Head of the Naval Research Laboratory’s Information Security and Special Programs.

The prime contractor will coordinate the approval of all subcontracts and task orders with the Contracting Officer’s Representative (COR). The COR will in turn, coordinate the approved paperwork with the Head of NRL’s Information Security and Special Programs.

e. Proprietary, Privacy Act or For Official Use Only Information associated with this contract, must be handled/controlled IAW DoD 5200.01 Vol. 4. Prime contractor will provide the security classification guidance for classified work required under this contract.

f. NATO briefings required. NATO access authorized at SECRET level only. Initial NATO briefings must be within a 5 year scope of the completed investigation. Visit request and a copy of NATO indoctrination must be sent to Code 1231 for all initial NATO briefings, prior to access. NATO briefings date must be within the current year.

Annual refresher briefings for NATO access are required. A copy of the signed annual re-briefings must be forwarded to NRL Code 1231 annually.

g. Foreign Nationals are not authorized to work on this contract.

h. All contractors (including subcontractors) identified in the Statement of Work shall supplement their current security practices by requiring any personnel involved in executing the contract to complete Government-sponsored and administered Operations

Security (OPSEC) training, OPSE-1301 and any OPSEC guidance that may pertain to the project.

i. Contractor personnel performing any function designated as a component of the Cyber Security Work Force (CSWF), and /or having privileged user access to NRL information systems will require background investigations and security clearances commensurate with the access level and security classification of the system being accessed as specified in DON 5239.2M (2009). System Administrators with privileged access may work in the computing, network and/or enclave environments. System Administrators with privileged access shall meet the training and certification requirements for IAT level I at the computing environment (CE), IAT level II at the network environment (NE), and IAT level III for the enclave environment as specified in DON 5239.2M (2009). The submission of a DoD TIER 5 Investigation is required for all System Administrators with privileged access serving in these position.

File details come from the government source that posted it. Updated .