PWS 832117964 CMRS-draft final v1.docx

DOCX document 7 MB Posted

Attached to
DoD CMRS Development and Sustainment Federal contract opportunity
Solicitation number
832117964
Issued by
Defense Information Systems Agency

View the file

Other files for this federal contract opportunity

Other files attached to DoD CMRS Development and Sustainment, newest first.
File Type Posted
832117964 CMRS_sources sought v5.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

as of April 28, 2021

Award/Mod Effective
Version Date

Contract Number:

Task Order Number:

Contractor Name

Tracking Number:

Follow-on to Previous Contract and Task Order Number:
HC1028-17-A-0010 / HC1028-18-F-0597

1. Contracting Officer’s Representative (COR).

a. Primary COR.

Name:

Organization:

Department of Defense Activity Address Code (DODAAC):

Address:

Phone Number:

E-Mail Address:

b. Alternate COR.

Name:

Organization:

DODAAC:

Address:

Phone Number:

E-Mail Address:

c. Property Administrator.

Name:

Organization:

DODAAC:

Address:

Phone Number:

E-Mail Address:

2. Contract or Task Order Title. Department of Defense Continuous Monitoring and Risk Scoring (CMRS) Development and Sustainment

3. Background. CMRS is chartered through National Defense Authorization Acts (NDAA) since 2011. Most recently, the 2019 NDAA requires a “Department-wide automated information security continuous monitoring capability.” CMRS is currently supported under the Defense Information Systems Agency (DISA) Software Development Blanket Purchase Agreement (BPA) HC1028-17-A-0010/HC1028-18-F-0597.

CMRS is a suite of Government off-the-shelf (GOTS) based software solution creating global and organizational views of inventory, compliance, vulnerability, and risk by enabling visualization of raw data and by applying threat and vulnerability-based scoring algorithms. The vision for CMRS is to integrate data from Department of Defense (DoD) Enterprise Cyber Security applications and tools using data standards to provide near-real time risk visualization, automated configuration management (CM) analysis, and continuous monitoring capabilities that enable net defense and provide risk awareness information. The functionality of CMRS is to assess and measure the risk state of DoD Information Technology (IT) systems in accordance with Enterprise security controls such as software/hardware inventory, Security Technical Implementation Guide (STIG) and patch compliance, anti-virus configurations, and directive compliance. CMRS hosts DoD security information of workstations, servers, and network devices in a central repository.

4. Objectives: The primary objectives of this PWS are:

a. Develop, sustain, maintain, and integrate the operational capabilities of CMRS on the Microsoft .NET framework, and CMRS NextGen on the Big Data Platform (BDP).

b. Develop, sustain, integrate, and maintain new capabilities for the CMRS application.

c. Implement new analytics, data, and platform component alignment with operational requirements and maximize capabilities.

The CMRS, contractor must be able to develop new capabilities based on open source technologies as well as integrate Government Off-The-Shelf (GOTS), Commercial Off-The-Shelf (COTS) and/or third-party developed components. Additionally, the contractor shall update the CMRS applications to ingest DoD security information of workstations and servers, network infrastructure, networked user support devices, Internet of Things (IOT), Platform Information Technology (PIT), mobile devices, Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) connected to DoD network, into the existing central repository.

More specifically, the objective of this PWS is to provide DISA with requirements management, development, application level support and sustainment, data integration, engineering, market research, test and evaluation (T&E), and Assessment and Authorization (A&A) of the CMRS program. The effort is necessary to acquire the resources needed for the development, sustainment, maintenance, and the continued support of CMRS on the Microsoft .NET framework, and CMRS NextGen on the Big Data Platform (BDP). This includes engineering for creating design artifacts, integration guides, user guides, system policies/procedures, technical assessments, technical recommendations, and performance metrics. This effort focuses on the support needed for the development, sustainment, and maintenance of CMRS, and will require collaboration and integration with the vendors responsible for other phases of the change management lifecycle, particularly with respect to the BDP, testing / Independent Verification and Validation (IV&V), pilots, change management, cyber security, hosting, operations, and maintenance phases.

5. Scope: The contractor shall be responsible for providing programmatic, technical, engineering, and integration support for the continued, development, enhancement, integration, deployment, and sustainment of CMRS. This includes program and project management, software development and maintenance, requirements management, cyber security analysis, cybersecurity analysis, Assessment and Authorization (A&A) support, integration of COTS/GOTS products and services, quality assurance/system evaluation, validation and verification (V&V), installation support, training, documentation, operations support, content generation, and system performance analysis to sustain, improve and expand CMRS capabilities (e.g. generation of the IAVM policies, FRAGO 6 policies, and other content to support cybersecurity scorecard and operational ad-hoc requirements (like ACAS compliance).

The contractor shall provide the necessary support in each of the Task Areas listed below, providing the services, capabilities, and deliverables of this PWS. Efforts shall provide benefits to extend system life, reduce life cycle costs (or provide the best return on investment), leverage technology advancements, and improve the capacity, capability, reliability and robustness to meet program life requirements.

The Government may require surge support during the base or any option period, and surge modifications will be within the scope of the contract and provide increased support for the defined task areas of this PWS. Surge support over the life of the contract will not exceed 50% of the contractor’s total proposed price for the base and all option periods, excluding any six-month extension of services pursuant to FAR 52.217-8.

Relevant ENCORE III Performance Areas:

· Performance Area 2 - Integrated Solutions Management

· Performance Area 5 - Requirements Analysis

· Performance Area 8 - Custom Application Development

· Performance Area 9 - Product Integration

· Performance Area 10 - Test and Evaluation (T&E)

· Performance Area 12 – Network Support

· Performance Area 13 – Cyber Security Assessment, Authorization, and Implementation

· Performance Area 16 – Web Services

· Performance Area 17 – Operations Support

· Performance Area 18 – IT Support Services

1. Performance Requirements.

0. Task Area 1 - Contract Level and TO Management Support

0. Integration Management Control Planning. Contractor shall provide the technical and functional activities for integration of all tasks specified within this PWS. Contractor shall include productivity and management methods such as quality assurance, progress/status reporting, and program reviews when performing the task order requirements. Monthly status reports, Management Plan, Briefing Materials, and all other reports shall be accurate and free of errors in representing the current state of the contract in terms of costs, schedules, and performance. This standard applies to all sub-tasks within Section 6. Contractor shall provide the centralized administrative, clerical, documentation, and related functions to meet the task order requirements. The contractor shall provide the technical and functional activities for effective and efficient program management of the tasks within this PWS.

0. Task Order Management. The contractor shall prepare a Task Order Management Plan (TOMP), upon award as part of contract kick-off describing the technical approach, organizational resources, and management controls (i.e. program planning, financial reporting, quality assurance, quality control, strategic and operational planning, progress/status reporting, and program reviews.) to be employed to meet the performance and schedule requirements throughout contract execution. The TOMP, at a minimum, shall address or include the following: organization, resources, personnel management, management structure/control, execution plan, labor execution plan, quality assurance/control plan, contract management plan, implementation plan, risk management, and SME support. The following positions have historically led the functional areas of the contract and are considered key personnel for the Government: 1) The Task Order (TO) program manager; 2) The A&A lead; 3) The Tier II/Tier III support lead; 4) development team leads for related CMRS platforms (currently .NET/NextGen) and 5) system administrator lead. The contractor shall limit turnover in key personnel to 10% or less. The TOMP shall also include a Transition Implementation Plan (TIP), outlining activities, and timeline required for the contractor to transition support services identified in this PWS to a new contractor. The TOMP shall be updated throughout the performance of this task to reflect changes and to further define program criteria and milestones. All modifications to the TOMP shall be submitted to the Government for approval before execution. In addition, it shall detail the coordinated interaction between system development and integration activities as well as the maintenance and security compliance of existing and developing capabilities.

As part of the TOMP, the contractor shall establish a comprehensive risk management process that includes identification, evaluation, and mitigation of risks associated with schedule, technical, and performance. Additionally, the team shall develop a risk matrix to track project risks (such as schedule, cost, program, and engineering) that may be revealed during the project and will decide upon initial action and communication plans that will help ensure successful issue resolution and project execution. The risk matrix will be maintained and delivered to the Government as part of the weekly update. The contractor shall tailor their risk assessments in accordance with the DoD Risk, Issue, and Opportunity Management Guide for Defense Acquisition Program where it applicable.

The Contractor shall provide risk tracking. This shall include:

· Establishing and maintaining a program specific risk management tool. The tool shall list all open and historical risks associated with the effort

· Gathering and documenting mitigation strategies and approaches for each risk in the system

· Identifying, documenting and monitoring program management risks, as well as coordinating with business and technical representatives to gather and capture those risks in the risk management system

· Creating reports that outline program risks

The contractor shall use DevForce, DoD Enterprise Portal Service (DEPS), or similar tools specified by the Government to store draft and final versions of contract artifacts and deliverables. This includes deliverables outlined in the PWS, briefings, requirements, design documents, source code, test cases, configuration management artifacts, and other program and contract-level documentation.

Prior to completion of each performance period within this Task Order, the Contractor shall provide a formal report outlining lessons learned. This report shall include recommendations for improving the engineering and administrative processes and policies for future activities.

Deliverable(s)

(1) TOMP and updates

(2) Risk Matrix

(3) Formal Lessons Learned Report

0.0.2. Program Reporting

6.1.3.1 Integrated Master Schedule (IMS). The contractor shall provide the Government with an event driven IMS. The contractor shall use Microsoft Project or similar software designated by the Government for developing and maintaining the schedule. The contractor shall review, and identify any dependencies or interrelationships between the TO and other program efforts and significant dates. The contractor shall prepare and maintain an IMS for the overall Task Order to include schedules for each subtask and the level of effort (LOE) for task completion. The IMS shall address dependencies, risks, key milestone events, critical path activities, and delivery dates. The schedule will also outline all resources assigned to individual tasks and the LOE for each task’s completion. The contractor shall coordinate with the appropriate Government Functional Leads and assess the risks identified in the schedule and recommendation for program resolution. The schedules shall be developed and base-lined in collaboration with the Government schedule team.

The base-lined schedule shall not be modified without the Government CMRS Program Manager (PM) approval. The schedule shall be coupled with weekly management control meetings to ensure all organizations and activities underway are coordinated and support the objectives of the overall program. The contractor shall submit an updated IMS to the Government CMRS PM on a weekly basis.

Deliverable(s)

(4) Weekly IMS

6.1.3.2 Work Breakdown Structure (WBS). The contractor shall analyze and decompose the scope in this PWS and provide a WBS, per project or development effort, and corresponding WBS Dictionary. The WBS shall be the structure for communication for this TO and be the common link that unifies the planning, scheduling, budgeting, contracting and performance reporting. The WBS shall provide clear traceability of work efforts and end products. The WBS shall be no less than three levels, and its baseline shall be established at an Integrated Baseline Review (IBR) conducted within 30 calendar days of contract award.

Deliverable(s)

(5) WBS

6.1.3.3 Monthly Status Reports (MSR). The contractor shall submit MSRs that include financial, performance, schedule, and Other Direct Costs (ODCs) status including proposed changes and deviation from the planned schedule, technical accomplishments, issues and risks, and planned activities for the next reporting period. Any issues requiring Government response or action shall be identified to the Government immediately and status captured in the MSR. An inventory of all program assets shall also be included in the MSR to include servers, laptops, network equipment, external hard drives, server certificates with expiration dates, and hardware and software licenses with expiration dates.

The initial MSR shall include the projected deliverables planned by month, group by work categories (e.g. development, testing, Tier III, A&A, etc.) for the period of performance. In each subsequent report, the contractor shall show the original planned projections by month, actual work performed (deliverable), and an updated projection of the remaining deliveries across the period of performance (POP). The contractor shall identify any differences from the previous projection for the period the report covers and explain how that difference affects the projection for work yet to be accomplished.

The MSR will contain notifications of key personnel changes, to include changes in assignment or status of key personnel. The MSR will contain metrics for both monthly and year-to-date key personnel turnover. Key personnel are: 1) The contract program manager; 2) The A&A lead; 3) The Tier III support lead; and 4) development team leads for related CMRS platforms (currently .NET and NextGen) 5) system administrator lead. Any issues requiring Government response or action shall be identified to the Government immediately and status captured in the MSR.

Deliverable(s)

(6) MSR

6.1.3.4 Integrated Product Team (IPT) Weekly Status Reports. The contractor shall host a weekly IPT meeting with the objective to synchronize and de-conflict the activities from representatives from appropriate functional disciplines (both in and outside of the CMRS program) to meet CMRS objectives, identify and resolve issues, and make sound and timely recommendations to facilitate decision making. The IPT functional disciplines shall include cyber security, A&A, hosting provider, testing team (both development and IV&V (Independent Verification and Validation), Tier III, configuration management, and development teams. The contractor shall capture the outcomes of the weekly IPT and submit the summary as the Weekly Status Report outlining the progress of current and future tasks with completion status, as well as identifying any issues and risks, dependencies, engineering updates that require Government interaction for resolution and/or impact agreed upon delivery. At a minimum, the update shall outline what work has been performed, what problems have been encountered that may impact schedule, potential solutions for any problems, and projected tasks for the next week. The update shall also include metrics on the program’s performance with regard to capabilities provided to the customer and the outcome from those capabilities. The Weekly Status Report shall include minutes from the IPT, proposed updates to the CMRS project on Management Information Decision Support (MIDS) system, and any other program updates applicable to Cyber Directorate management.

Deliverable(s)

(7) Weekly Status Report

(8) Weekly MIDS Updates

0. Meetings. The Contractor shall coordinate meetings with Government representatives and their stakeholders to discuss the status of the project. The Contractor shall conduct meetings weekly, bi-weekly, and monthly to support the program. The Contractor shall prepare and distribute the meeting agenda, briefing materials, meeting minutes, and action items. Meeting locations may vary. If hosting at the Contractors facility, the Contractor shall provide appropriate meeting audio/visual and audio teleconferencing capabilities. If hosting at the Governments facility, the Contractor shall leverage DISA Collaboration Services, Microsoft Teams/Stream or other Government-approved delivery media for remote presentation, electronic white board, and chat. The Contractor shall produce meeting agendas, briefing materials, minutes of all meetings, including synopsis of technical discussions, and track the status of all action items.

The contractor shall continuously interface and coordinate with CMRS dependent/interfacing programs, parallel research & development efforts, other programs’ working groups, and the operational community to ensure continuity of current operations and synchronization of future initiatives and requirements. Such dependent/interfacing programs and organizations include, but are not limited to, Information Security Continuous Monitoring (ISCM), Secure Configuration Management (SCM), Endpoint Security Solutions (ESS)/Host Based Security System (HBSS), Assured Compliance Assessment Solution (ACAS), ACEM, Tychon, Comply to Connect (C2C), Operational Attribute Management System (OAM) , Asset Publishing Service (APS), Cyber Operational Attribute Management System (COAMS), Digital Policy Management System (DPMS), Information Assurance Vulnerability Management (IAVM), Enterprise Mission Assurance Support Service (eMASS), DISA Operations, United States Cyber Command (USCYBERCOM), DoD Chief Information Officer (CIO), Joint Forces Headquarters-DODIN (JFHQ-DODIN), Defense Health Agency (DHS), Army Research Lab, Governance Risk and Compliance Project solution(s), and Risk Management Knowledgebase to name a few.

The contractor shall capture, and compose minutes, or provide annotations to official minutes, if they are provided by other entities, for all meetings where CMRS is represented involving organizations outside the CMRS Program Management Office (PMO) e.g. Meetings with DoD CIO, USCYBERCOM, JFHQ-DODIN, Combatant Commands, Services, Agencies, Field Agencies and/or DISA Operations. The minutes shall be distributed by email to the CMRS PMO and saved to the CMRS DEPS portal.

6.1.4.1 Kick-Off Meeting. A Kick-off meeting shall be conducted no later than 10 business days after the contract award, and after execution of subsequent option periods. This meeting will be between the Government and the contractor and will be the venue to facilitate a successful execution of this contract, including transition activities. The Contractor shall prepare presentations that provide updates to the technical and management approach including current and Other Direct Costs (ODC’s), schedule, and performance data. The Kick-off meeting agenda shall include the following:

· Introducing the management and technical teams

· Presenting the Draft Management and Engineering Plans

· Common understanding of contract

· Common understanding of technical direction

· Presentation of all Task Order deliverables to include proposed formats and reporting methods

· Transition Plan of the current activities being performed for CMRS and sustainment Other relevant items may be introduced at this meeting.

6.1.4.2 Technical Exchange Meetings. After a Kick-off meeting is held, the contractor shall conduct Technical Exchange Meetings (TEM) on a weekly basis at the primary Government location. In addition, the Contractor shall prepare a presentation that provides updates to the technical and management approach including current and projected schedule and performance data. The TEM agenda shall include, at a minimum, the following:

· Plans and Accomplishments

· Issues, Risks and Mitigation Strategies

· Action Item Review

· Other relevant items may be introduced at the discretion of the Contractor and/or the Government

The Contractor shall produce minutes of all TEM meetings, including a synopsis of the technical discussion and a list of open/closed action items, to the COR.

6.1.4.3 CMRS Monthly Working Group Meeting. The contractor shall host a Monthly Working Group Meeting to engage the CMRS user community and discuss all CMRS related “Hot Topics” (e.g. CMRS General Announcements, Operational Status and Issues, Orders Related to CMRS and/or Publishing, Publishing trends, enhancements, resources, access control, and/or user questions). The CMRS Monthly Working Group shall take place on the 4th Thursday of every month. The meeting agenda and briefing material drafts will be due 3 business days prior to meeting, and finalized 1 day prior. The CMRS Monthly Working Group meetings are to be recorded and uploaded to the CMRS KM page (along with the associated slide deck) to the CMRS KM page within 48 hours of the meetings conclusion.

Deliverable(s)

(9) Kick-Off Meeting

(10) Technical Exchange Meetings

(11) Meeting Agendas

(12) Briefing Materials

(13) Minutes meetings

(14) Action Item Tracking Report

(15) CMRS Monthly Working Group Meeting

0. Transition. As part of the TOMP and upon contract award, the winning contractor shall work with the incumbent contractor to create and execute a Transition Implementation Plan (TIP) to transfer, in coordination with the incumbents:

0. The TIP shall include a description and catalog of Government Furnished Property (GFP), Government Furnished Information (GFI), (i.e., all configuration items), source code, system architectures, system access controls, build scripts and plans, test scripts and other program artifacts

0. Roles and responsibilities in any Government-managed forum currently supported by the incumbents

0. “Left seat – right seat” functional/knowledge transition to minimize impact to the program

The Government will facilitate the execution of the TIP to ensure continuity of all current activities supported by the incumbent. Three months before the end of the contract, the contractor shall update the TIP to support the transition to a follow-on team for review by the Government.

Deliverable(s)

(16) TIP and Updates

0. Strategic Planning and Analysis. The Contractor shall review program strategies and brainstorming and documenting alternative strategies and approaches for addressing program/project technical, financial, and schedule challenges. The Contractor shall conduct research regarding various aspects of proposed strategies and alternatives, providing summaries of findings. Where applicable as defined by the Program Manager and/or the COR, the Contractor shall identify and apply a variety of process analysis approaches to determine impact of complex issues. When alternative strategies and approaches are required, the Contractor shall provide a composite list of all alternatives considered, and a detailed summary of cost, schedule, and performance risks and benefits of each. Following COR approval of selected strategies, the Contractor shall document, track, and promulgate outcomes. The contractor shall pilot, prototype, and execute scalability testing for proposed solutions as directed by the Program Manager and/or the COR.

The Contractor shall provide the following:

· Develop draft mission and vision statements, subsequent goal delineation and provide recommendations for building operational plans that specify measurable outcomes to include capital outlay planning efforts in a consolidated strategic planning process which enables the Government to prioritize project initiatives.

· Review requests for information received from senior leadership and other related programs and projects as well as requirements to present program status at formal and informal meetings. The Contractor shall gather data, conduct research, and create draft responses to these requests. This data may include technical, business, requirements, financial, schedule, or strategic data or concepts. The Contractor shall ensure that thorough records are retained of all requests and responses, whether written or oral.

0. Metrics. The contractor shall collect, aggregate, and report CMRS Monthly Performance system and user Metrics. The metrics are currently saved to MIDS and DEPS.

Deliverable(s)

(17) Monthly Metrics Report

0. Policy Review and Update. The Contractor shall provide technical and programmatic reviews of existing DoD processes, policies, doctrine, directives, regulations, and implementation of instructions, to include Concept of Operations (CONOPS) and Tactics, Techniques, and Procedures (TTPs). The Contractor shall record specific policy updates and implementation recommendations.

Deliverable(s)

(18) Policy Review Findings and Recommendations Report(s)

0. Technical Writing and Graphic Design. The Contractor shall provide technical writing and graphic design services. The Contractor shall ensure that all program and project documents communicate the intended message clearly and concisely, are free of typographical errors, spelling errors, grammatical errors and errors of logic. The writing will reflect a logical organizational structure, contain paragraph, page, section, and chapter numbers, as appropriate to allow reviewers to accurately identify and cite specific text in written documents. The writing must contain tables of contents and indexes, as appropriate to the size and complexity of the document, are created in a manner that avoids excessive printing costs or unnecessarily large electronic files, and are stored in a location that is easily retrievable by the Government team.

The Contractor shall coordinate with technical and management teams to identify needs for creation, editing, review, and promulgation of both formal and informal program and project documents. The Contractor shall review and edit existing documents to prepare them for final delivery, publication, or dissemination. The Contractor shall provide detailed technical editing in redline form to allow original authors the option to accept/reject the recommended changes. The Contractor may, on occasion, be required to provide hardcopy edits.

The Contractor shall conduct document review meetings to coordinate the review and input of multiple reviewers. The Contractor shall maintain an official set of notes (electronic or hard copy) at these meetings and shall deliver a final, compiled, updated document to meeting attendees.

The Contractor shall coordinate with technical and management teams to gather and compile data to create new technical documents. The Contractor shall propose an outline to the document owner, and based on feedback shall create, incrementally, annotated outline, initial draft, final draft, and final documents.

The Contractor shall review and provide input to documents created by other teams, Contractor progress reports, management plans, program plans, policy documents, information requests, leadership documents, functional/business documents, and technical documents. The Contractor shall provide detailed comments on all documents reviewed, outlining issues and providing specific, actionable, corrective recommendations.

The Contractor shall produce professional illustrations of systems and processes.

0. Asset Management. The Contractor shall provide asset inventory and asset tracking services for all Government Furnished Property (GFP) to be reported quarterly. Any interim GFP changes shall be reported to the Government in the Monthly Status Report (MSR). The Quarterly Equipment Inventory Report (QEIR) shall include:

· Make/Model of equipment, Manufacturer, and Serial Number (if applicable) for all hardware and software

· Physical location to include Building, Room, and Rack identification

· Ownership to include hand receipt data consistent with Defense Property Accountability System (DPAS)

· A description of how the equipment is being utilized

· Contract Management aspects to include: Leases, Maintenance Agreements, Service Contracts, and Warranties

· Financial aspects to include Cost and Depreciation Specialized and Government proprietary resources and equipment needed will be provided. The specialized equipment may be GFP or purchased as Other Direct Costs (ODCs) at the Government’s discretion.

The Contractor shall return all equipment to the Government’s facility once the equipment is no longer a viable asset in CMRS; or in support of CMRS development, operations, or maintenance. The DISA designated Property Team will dispose of the equipment as necessary.

Deliverable(s)

(19) Interim GFP Updates (MSR)

(20) Quarterly Equipment Inventory Report

0. Hardware and Software Installations, Configuration, and Sustainment. The Contractor shall provide all hardware and software procurements, installations and configurations for all CMRS system enclaves located at DISAs Joint Interoperability Test Command Lab (Ft. Meade, MD), DISA Ecosystem, Acropolis, DISA BDP, and Continuity of Operations Plan (COOP) facilities. The Government will maintain ownership of all procured hardware and software. Sustainment shall include, at a minimum, all necessary hardware and software maintenance, licenses, data rights, subscriptions and warranties & plans, or other reoccurring products and requirements for the continued operations of the CMRS infrastructure.

The Contractor shall identify and recommend hardware which is no longer required (e.g. end-of-life or no longer meets technical requirements.). The Contractor shall coordinate the return of all equipment to DISA. The Contractor shall be responsible for returning all GFP when no longer needed/authorized (e.g., end of contract or end-of-life.). All hardware and software will be tracked consistent with the DPAS requirements. All procurements will be approved by the COR prior to commencement. The Contractor shall provide the COR with a materials list and at least three (3) quotes for all procurements. Monthly invoices to the Government for any ODCs (hardware/software) shall include a copy of the Contractors actual invoice for the procured items.

0. Life-Cycle Sustainment Outcome Metrics Data Reporting. The Contractor shall recommend, maintain, and report on capability performance and methods of collecting and reporting sustainment outcome metrics that consist of but are not limited to, Material Availability, Operational Availability, Material Reliability, and Ownership Cost.

Deliverable(s)

(21) Life-Cycle Sustainment Outcome Metrics Data Reporting

0. Life-Cycle Sustainment Plan (LCSP). The Contractor shall provide an LCSP addressing the maintenance concept including when to execute required sustainment tasks; regarding product categories related to logistics, and key enablers such as diagnostics and prognostics. The LCSP shall be tailored to meet project needs. The LCSP is an evolutionary document begun during the Materiel Solution Analysis Phase as a strategic framework for ensuring sustainment at minimal lifecycle cost. It will evolves into an execution plan for how sustainment is applied, measured, managed, assessed, and reported after system fielding.

Deliverable(s)

(22) Life-Cycle Sustainment Plan (LCSP)

0. Product Life-Cycle Management (PLCM). Product Life-Cycle Management, as outlined in DoD Instruction 5000.02, is an integrated, information driven approach to all aspects of a product’s life from its design inception, through its manufacture, deployment and maintenance, and culminating in its removal from service and final disposal. For this effort, the Contractor shall develop and provide an appropriate PLCM Supportability Strategy for the implemented capability. This strategy shall consist of, at a minimum, a Life-Cycle Sustainment Plan; a Risk Management Plan; a Disposal Plan; Life-Cycle Sustainment Outcome Metrics; Life-cycle Certification and Accreditation Plan; and a document identifying the Sustainment Readiness Levels that would correlate to the Technology Readiness Levels (TRL) applied throughout this effort. The Contractor shall update the PLCM plans annually and reference lessons learned and approved configuration changes.

Deliverable(s)

(23) Product Life-Cycle Management Plan (PLCMP)

0. Technology Refresh (TR) Strategy. The Contractor shall develop a comprehensive TR strategy to include a combination of processes, tools, and the necessary Information Technology (IT) infrastructure so the Government can program resources to implement while minimizing risks to product availability and mission success. TR shall be projected across the expected life-cycle of the product, not just the period of performance of this task order.

Deliverable(s)

(24) Technology Refresh Plan (TRP)

0. Contractor Furnished Equipment. Contractor Furnished Equipment (CFE) employed for remote access to a Government network shall meet or exceed equivalent GFP cyber security computing requirements. The contractor shall ensure that all CFE (hardware and software) employed to access these environments meet the following minimum Government cyber security requirements and provide periodic certification of compliance as a pre-requisite to being granted network access.

1. Use of personally owned systems is prohibited;

1. Operating systems and applications shall be configured for compliance with the applicable STIGs, consistent with the purpose of the equipment (i.e. development and test equipment may relax STIG requirements if required to enable testing and software development);

1. DoD approved anti-virus and anti-spyware software shall be installed and signatures shall be configured to automatically update on a daily basis;

1. DoD approved host-level firewall shall be utilized and configured to permit traffic by exception only, dropping all other traffic. If the host-level firewall provides intrusion detection or prevention, the signatures or rules shall be updated at the same intervals as the anti-virus software;

1. Computers shall be Information Assurance Vulnerability Management (IAVM) compliant;

1. Computers shall be scanned with the currently approved DoD scanner solution at a minimum of every 7 calendar days. All vulnerabilities shall be remediated and reported to the cognizant Information Security System Manager (ISSM);

1. Contractor employees shall possess a current Government issued Common Access Card (CAC) and install Government certified CAC readers; and

1. Verification of compliance with these requirements shall be provided to an appointed Government representative on a monthly basis.

Deliverables – Task 6.1 through Subtask 6.1.16:

PWS Task#
Identifier
Deliverable Title
Format
Due Date
Distribution/Copies
Frequency and Remarks
6.1.2
A001
TOMP and updates
Contractor-Determined Format delivered in MS Word
1) Draft – Due upon delivery of the Contractor’s proposal

(2) Final – 10 business days after receive comments from the COR

(3) Updates, as necessary, after notification from COR

Standard Distribution*
Draft – Post Award, at proposal

Final – 10 business days from COR comments

6.1.2
A002
Risk Matrix
Government Determined Format
Initial – 30 calendar days after contract award
Standard Distribution*
Updates – weekly w/quad and monthly w/MSR
6.1.2
A003
Formal Lessons Learned Report
Government Determined Format
10 business days prior to end of PoP for the base year;

Reports will be due 10 business days prior to each option period if the options are exercised

Standard Distribution*
Annually
6.1.3.1
A004
Weekly IMS
MS Project
(1) Draft – 10 business days after contract award

(2) Final – 10 business days after receive comments from COR

(3) Updates, as necessary, after notification from the COR

Standard Distribution*
Draft – 10 business days post Award

Final – 10 business days from COR comments Weekly thereafter

6.1.3.2
A005
WBS
MS Project
(1) Draft – 10 business days after contract award

(2) Final – 10 business days after receive comments from the COR

(3) Updates, as necessary, after notification from the COR

Standard Distribution*
Draft – 10 business days post Award

Final – 10 business days from COR comments

6.1.3.3
A006
MSR
Contractor-Determined Format delivered in MS Word or PowerPoint
10th business day of the month for the previous month’s activities. The previous month is defined as the first day of the month through the last day of the month.
Standard Distribution*
Monthly
6.1.3.4
A007
IPT Weekly Status Report
Contractor-Determined Format
Friday by Close of Business (defined as 5:00 pm ETD)
Standard Distribution*
Weekly
6.1.3.4
A008
Weekly MIDS Updates
Contractor-Determined Format
Friday by Close of Business (defined as 5:00 pm ETD)
Standard Distribution*
Weekly
6.1.4
A009
Kick-Off Meeting
Contractor-Determined Format
No later than 10 business days after the contract award
Standard Distribution*
Within 10 business days after the contract award
6.1.4
A010
Technical Exchange Meetings
Contractor-Determined Format
Weekly after a Kick-off meeting is held
Standard Distribution*
Weekly after a Kick-off meeting is held
6.1.4
A011
Meeting Agendas
Contractor-Determined Format
Draft – 3 business days prior to meeting

Final – 1 business day prior

Standard Distribution*
Draft – 3 business days prior to meeting

Final – 1 business day prior to meeting

6.1.4
A012
Briefing Materials
Contractor-Determined Format
Draft – 3 business days prior to meeting

Final – 1 business day prior

Standard Distribution*
Draft – 3 business days prior to meeting

Final – 1 business day prior to meeting

6.1.4
A013
Meeting Minutes
Contractor-Determined Format
Draft – 2 business days after the meeting

Final – 2 business days after receive comments from the COR (or their designated representative)

Standard Distribution*
Draft – 2 business days after the meeting

Final – 2 business days from COR comments

6.1.4
A014
Action Item Tracking Report
Contractor-Determined Format
Draft – 2 business days after the initial meeting

Updates – 2 business days after received comments from the COR (or their designated representative)

Standard Distribution*
Draft – 2 business days after the meeting

Final – 2 business days from COR comments

6.1.4
A015
CMRS Monthly Working Group Meeting
Contractor-Determined Format
4Th Thursday of every month

Meeting Agenda Draft – 3 business days prior to meeting Final – 1 business day prior Briefing Materials Draft – 3 business days prior to meeting Final – 1 business day prior

4Th Thursday of every month

6.1.5
A016
TIP and Updates
Contractor-Determined Format delivered in MS Word
Draft – 10 business days after contract award

Final – 10 business days after comments are received from the COR Draft – 120 calendar days prior to end of contract Final – 10 business days after comments are received from the COR

Standard Distribution*
Draft – 10 business days Post Award & 120 calendar days before contract end,

Finals – 10 business days from COR comments

6.1.7
A017
Monthly Metrics Report
Contractor-Determined Format
Due the 2nd Friday of each month
Standard Distribution*
Monthly
6.1.8
A018
Policy Review Findings and Recommendations Report(s)
Contractor-Determined Format
5 business days following a request in writing from the COR
Standard Distribution*
5 business days from COR request
6.1.10
A019
Interim GFP Updates (MSR)
Contractor-Determined Format
Monthly, included in MSR
Standard Distribution*
Monthly
6.1.10
A020
Quarterly Equipment Inventory Report
Government Determined Format
Quarterly
Standard Distribution*
Quarterly
6.1.12
A021
Life-Cycle Sustainment Outcome Metrics Data Reporting
Government Determined Format
Draft – 10 business days after a written request is received from the COR

Final – 10 business days after comments are received from COR Updates –When a written request is received from the COR.

Standard Distribution*
Draft – 10 business days from COR request

Final – 10 business days after COR comments Updates –When a written request is received from the COR.

6.1.13
A022
Life-Cycle Sustainment Plan (LCSP)
Government Determined Format
Draft – 10 business days after a written request is received from the COR

Final – 10 business days after comments are received from COR Updates –When a written request is received from the COR.

Standard Distribution*
Upon Government request
6.1.14
A023
Product Life-Cycle Management Plan (PLCMP)
Government Determined Format
Draft – 10 business days after a written request is received from the COR

Final – 10 business days after comments are received from the COR Updates – When a written request received from the COR

Standard Distribution*
Draft – 10 business days from COR request

Final – 10 business days after COR comments

6.1.15
A024
Technology RefreshPlan (TRP)
Government Determined Format
Draft – 10 business days after a written request is received from the COR

Final – 10 business days after comments are received from the COR Updates – When a written request is received

Standard Distribution*
Draft – 10 business days from COR request

Final – 10 business days after COR comments

*Standard Distribution: 1 copy of the transmittal letter without the deliverable to the Contracting Officer; 1 copy of the transmittal letter with the deliverable to the Primary COR.

0. Task Area 2 - Software Engineering and Development

1. System Overview. The CMRS efforts are separated into two efforts and platforms: (a) the development and sustainment of the baseline for the .NET version of CMRS, and (b) the development and sustainment of CMRS NextGen on BDP (“CMRS NextGen”), with both platforms having instances on DoD Unclassified and Secret networks. The contractor shall maintain and develop against requirements for both CMRS .NET and CMRS NextGen.

See Appendix H - CMRS Overview additional information.

Operational Environments.

a. CMRS .NET: CMRS .NET is hosted in Government approved data centers (i.e. DISA Ecosystem, Cloud offerings, Centaur Operations, and Acropolis), and utilizes the Microsoft technologies .NET, Internet Information Services (IIS), and SQL Server. CMRS is tightly integrated into the SCM portfolio of capabilities, and currently ingests data DoD /DISA Endpoint Security Solution (ESS) e.g. ESS/HBSS, ACAS, ACEM, Tychon. During the course of the contract described in the PWS, it will be updated to ingest data from C2C, and/or any new DoD enterprise endpoint tools that may become systems of record using the architecture and data flow as described in the following appendices:

· Appendix A - CMRS .NET and System Views

Dependencies Note: CMRS .NET has 1 Secret Internet Protocol Router Network instance and 4 Non-Secure Internet Protocol Router Network (NIPRNet) instances that distribute the published data across physical boundaries (subject to change):

· Alpha – All other endpoint data

· Bravo – Army endpoint data

· Charlie – Air Force endpoint data

· Echo – Navy endpoint data

c. CMRS NextGen: CMRS NextGen leverages data, tools and capabilities on DISA’s Big Data Platform (BDP). The contractor shall be responsible for developing analytics on DISA’s BDP platform. See the following appendices for additional information:

· Appendix C - Big Data Platform

· Appendix J – BDP Data Elements

d. CMRS Pilot/Testing Efforts: The contractor shall utilize CMRS .NET and CMRS NextGen to support improvement efforts or to test new functionalities of Government-approved pilot programs. For pilot/testing efforts the contractor shall supply staff, coordinating and contract support by providing CMRS data, logs, best practices, scoring models, decision-aids, and/or other content requested by the Government. At a minimum, the purpose of such pilots will be to ensure the pilot software can successfully ingest, process, and output the data in the required formats. (i.e. Software normalization, risk scoring, and/or others tools related to the scope of the project). The data that the contractor shall present back to the Government will be highlighted in a separate Government requirements document.

Examples can include:

· Data Ingest: Must be capable of ingesting endpoints data format Extensible Markup Language (XML), comma-separated values (CSV), Structured Query Language (SQL), JavaScript Object Notation (JSON), Assessment Summary Results/ Assessment Results Format (ARF/ASR), STIX/TAXI II or similar formats).

· Risk score algorithm: The algorithms will be both viewable and modifiable through the GUI and it should be able to compute risk scores based on vulnerabilities, threats, likelihood, and impact data.

· SW Normalization: Must be capable of counting software products and hardware products enabling accurate counts for all endpoints discovered via DoD ESS endpoint sensors worldwide for DoD Software/Hardware Inventory/ Licensing reporting.

· Data Output: The data displayed should provide an intuitive, dashboard-style interface to quickly assess cyber risk scores or software products at multiple levels of granularity and perform simple drill-downs to individual assets based on organization’s roles and attributes access control and output data in a standardized format as requested by the Government (XML, CVS, etc.).

As determined by the Government.

Deliverable(s)

(25) CMRS Pilot Testing and Reports (i.e. Software normalization, risk scoring and/or other future pilots/testing efforts)

1. System Requirements.

The following operational drivers provide the framework and guidance to the CMRS capabilities.

· Information Security Continuous Monitoring (ISCM): ISCM is defined as maintaining on-going awareness of information security, vulnerabilities, and threats to support organizational risk management decisions. ISCM is established to collect information in accordance with pre-established metrics, utilizing information readily available, in part, through implemented security controls. Organizational officials collect and analyze the data regularly to manage risk as appropriate for each organizational tier. Subsequently, determinations are made from an organizational perspective on whether to conduct mitigation activities or to reject, transfer, or accept risk. CMRS is the authoritative DoD continuous monitoring system, and receives guidance from ISCM. Additional information on ISCM can be found at http://nvlpubsnistgov/nistpubs/Legacy/SP/nistspecialpublication800-137pdf.

· Continuous Diagnostics and Mitigation (CDM): The CDM Readiness and Planning Guide for Asset-Based CDM Security Capabilities provides the following core elements for continuous monitoring solution (https://www.cisa.gov/cdm):

· Hardware Asset Management (HWAM)

· Software Asset Management (SWAM)

· Configuration Settings Management (CSM)

· Vulnerability Management (VUL)

· SCM: CMRS ingests data from the SCM portfolio of tools. These tools help facilitate Information System Monitoring as part of the DoD’s Continuous Monitoring Strategy – supporting the initial data sets of assets, system configurations, and vulnerabilities. Appendix B - SCM Dependencies illustrates CMRS’ dependencies on the SCM tool set.

· Big Data: CMRS NextGen reside on the DISA BDP, and leverages their datasets to build analytics. CMRS also shares analytics with other BDP programs, analysts, and data scientists.

1. Current System Functionality

· Asset Management: Asset management tools help maintain inventory of software and hardware within the organization.

The contractor shall:

· Sustain, maintain, and enhance a device hardware inventory within CMRS to include workstations and servers, network infrastructure, networked user support devices, Internet of Things (IOT), Platform Information Technology (PIT), mobile devices, Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) connected to DoD network.

· Sustain and maintain, and enhance a device software inventory within CMRS.

· Configuration Compliance: CM tools allow administrators to monitor settings and changes to settings. The contractor shall:

· Sustain and maintain, and enhance tools to enable the assessment of secure configuration compliance of CMRS devices.

· Include status of what DoD endpoint sensor modules and versions are deployed on devices across the DoD

· Report STIG compliance.

· Patching Compliance: The number of vulnerabilities discovered and patches developed to address those vulnerabilities continues to grow, making manual patching of systems and system components an increasingly crucial task.

The contractor shall:

· Sustain and maintain, and enhance tools in CMRS that identify and report vulnerabilities in a coordinated, organization-centric manner using DoD enterprise endpoint sensors and policy based analytics in CMRS using custom eXtensible Configuration Checklist Description format (XCCDF) documents.

· Sustain and maintain, and enhance tools that automate the implementation, assessment, and continuous monitoring of vulnerability controls.

Based on the basics and operational drivers above, the contractor shall enhance, evolve and integrate CMRS capabilities in concert with the following foundational requirements (F1-F14).

· F1 - Ability to assess employment of DoD mitigation and data collection capabilities

· Central aggregation…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .