A11 DRAFT PWS DJMS.pdf
PDF 589 KB Posted
- Attached to
- Defense Joint Military Pay System Support Services Federal contract opportunity
- Solicitation number
- HQ042302082025
- Issued by
- Defense Finance and Accounting Service
About this file
This is a Performance Work Statement (PWS) for Defense Joint Military Pay System (DJMS) support services, issued by the Defense Finance and Accounting Services (DFAS). The contractor will provide technical support for operating and maintaining DJMS, which manages over 2 million payroll accounts for military personnel across Air Force, Army, Navy, and service academies. The system includes both Active Component (AC) and Reserve Component (RC) subsystems, containing approximately 121,308 and 62,217 function points respectively, with most code written in COBOL.
The PWS outlines seven key tasks: Contract Program Management, Requirements Management & Analysis, Technical Design Activities, Configuration Management, Development of Code, Testing Support, and Security Management. The period of performance is one base year plus four 12-month options, with work to be performed 100% remotely/telework. The contract type will be a mix of Firm-Fixed Price (FFP) and Labor Hour (LH). Key personnel requirements include Applications Programmers (Senior and Intermediate), Data Security (Senior), and Project Manager (Advanced) positions. The estimated workload includes approximately 15 system releases per year with an average of two System Change Requests per release, and roughly 500 Production Support calls and 20 data queries annually. The contractor must maintain appropriate security clearances and complete mandatory training requirements.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| A11 RFI Pricing Spreadsheet 2.21.25 v2.xlsx | XLSX spreadsheet | |
| A11 RFI Pricing Spreadsheet 2.21.25.xlsx | XLSX spreadsheet | |
| A11 Notice of Sources Sought.pdf | ||
| A11 RFI Pricing Spreadsheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
Defense Joint Military Pay System Support (DJMS)
PART 1
GENERAL INFORMATION
1. GENERAL
1.1 Background: Defense Finance and Accounting Services - Information & Technology (DFAS I&T) is responsible for the provision of information and technology services, to include: planning, developing architectures, designing, building, operating and maintaining essential DFAS infrastructure systems, providing software engineering services in accordance with DFAS standard methods and procedures, and establishing and managing the DFAS Enterprise Information Infrastructure architecture and engineering environment. This procurement is to obtain I&T support services to assist with the operation and maintenance of the Defense Joint Military Pay Systems (DJMS) system. DJMS is comprised of the following sub-systems:
Defense Joint Military Pay System Defense Joint Military Pay System Production Support Defense Joint Military Pay System Information Assurance/Security
Defense Joint Military Pay System (DJMS): The Defense Joint Military Pay Systems (DJMS) is a system and includes both the Active Component (AC) and the Reserve Component (RC). The AC component contains approximately 121,308 function points and an estimated 8000 modules containing 5,015,885 lines of code (80% COBOL) and 344,971 lines of Job Control Language (JCL). The RC component contains approximately 62,217 function points and is comprised of an estimated 1200 modules containing 834,590 lines of codes (80% COBOL) and approximately 202,371 lines of JCL (Lines of code are not including comments and blank lines). Modules are written in assembler, COBOL, FOCUS, code for micro and mid-tier computers, IBM and third party vendor utility software. DJMS-AC and DJMS-RC operate in an IBM mainframe environment.
DJMS establishes, maintains, and manages over two million payroll accounts for military personnel of the Air Force (AC and RC), Air Force Academy cadets, Army (AC and RC), Military Academy cadets, Navy (AC), Naval Academy midshipmen, and Junior ROTC instructors for the Air Force, Army, and Marine Corps. The AIS also produces payroll files for electronic transmittal to the Federal Reserve Bank system, Leave and Earning Statements for all members, and maintains tax information and produces W-2s for all services supported. DJMS produces and maintains accounting information and creates management, budget execution, and accounting reports for all levels of Government. It interfaces with numerous federal and state Government computing systems nationwide, providing tax, allotment, bond, and military retirement information. Major interfaces are also required with the Air Force, Army, and Navy personnel, accounting, and disbursing systems.
Defense Joint Military Pay System Production Support: Reference DJMS above; DJMS Production Support is provided for both components – active and reserve. The system runs on computers at DISA Mechanicsburg. Technical staff is responsible for the establishment and maintenance of over 40 production and test platforms. This support is provided 24 hours per day, 5 days a week, with on-call support on weekends (See Hours of Operation, Section 1.6).
Defense Joint Military Pay System Information Assurance/Security: Core security and information assurance is provided for both DJMS-AC and DJMS-RC. The Account Manger oversees security of the systems through ensuring correct user access, conducting regular checks, protecting the data, and providing information to auditors as directed.
(See Part 4 for more details).
1.2 Objective: The objective of this Performance Work Statement (PWS) is to define the tasks necessary to obtain the technical information and technology support services needed to assist in the operation, programming, implementation, and maintenance of the Defense Joint Military Pay System (DJMS).
1.3 Scope: The contractor shall provide all necessary personnel, management, administrative, and technical services to meet the requirements and tasks outlined in this PWS for the DJMS system. The software and non-software support services to be acquired fall within the general areas of implementing change requests to the system and performing routine system maintenance as a supplemental resource to the existing government-led DJMS IT team. The Government has identified a total of 7 Specific Tasks (See Part 4) that must be completed to ensure the success of this requirement.
Task 1: Contract Program Management Task 2: Requirements Management & Analysis Task 3: Technical Design Activities Task 4: Configuration Management Task 5: Development of Code Task 6: Testing Support Task 7: Security Management
1.4 Period of Performance: The anticipated period of performance shall consist of one (1)
Base Year of 12-months and four (4) 12-month Option Years.
1.5 Recognized Holidays: Contractors are not expected to perform on federally recognized holidays to include but not limited to:
New Year’s Day Labor Day Martin Luther King Jr. Birthday Columbus Day President’s Day Veterans Day Memorial Day Thanksgiving Day Juneteenth Christmas Day Independence Day
1.6 Hours of Operation: The contractor shall conduct business between the core hours of
0630 – 1700 hours Monday thru Friday Eastern Time except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within the PWS when the Government facility is not closed for any of the above reasons. The stability and continuity of the workforce is essential. The contractor is required to provide after hours and on-call support in the event of system failures.
1.7 On Call: On-call means a contractor employee shall be available to answer and respond to telephone calls after normal work hours due to production job problems and provide consultation in critical situations that are not during normal business hours.
1.8 Place of Performance: The work to be performed under this Task Order (TO) is anticipated to be 100% telework/remote.
Collaboration tools such as phone conference lines and Microsoft Teams will be used for initial orientations and regular status meetings. Arrangements will be made for contract staff to receive a DFAS laptop through shipping and CAC cards can be obtained at any RAPIDS location.
1.9 Type of Contract: The contract type is anticipated to be a mix of Firm-Fixed Price (FFP) and Labor Hour (LH).
1.10 Travel: The Government does not anticipate any travel at this time.
1.11 Relocation Costs: Relocation costs and travel costs incident to relocation are not allowable and will not be reimbursed hereunder.
1.12 Identification of Contractor Employees: All contractor personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties shall identify themselves as contractors to avoid creating an impression, they are Government officials. Contractor personnel shall ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. The Common Access Card (CAC) used for building entrance, computer access, and other situations will identify the individual as a contractor.
1.13 Post Award Conference/Periodic Progress Meetings: The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The CO, COR, Government Project Manager (PM) and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings, the CO will apprise the contractor of how the Government views the contractor's performance and the contractor shall apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues.
These meetings shall be at no additional cost to the Government.
1.14 Contracting Officer Representative (COR): The COR is the primary point of contact for the contractor. The COR shall interface with DFAS Information and Technology (IT) Point of Contact (POC) as well as the appropriate DFAS Site Force Protection Office POC to maintain internal monthly system updating to DoD compliance. To identify Site Force Protection Officers at each DFAS location consult the Agency Force Protection ePortal Page.
The COR is responsible for monitoring all technical aspects of the award and assisting in contract administration. COR duties include:
Ensure contractor performs the technical requirements of the award.
Perform inspections necessary in connection with contract performance.
Maintain written and oral communications with the contractor concerning technical aspects of the award.
Monitor contractor’s performance and notifies both the CO and contractor of any deficiencies.
Coordinate availability of Government furnished property and site entry of contractor personnel.
A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.
Knowledge Transfer Plan: Whenever there is a transition in support personnel, the current contractor shall be required to transition specific systems knowledge to the replacing labor resources. This transition period will be no longer than 120 days from the end of the current period of performance. Actual transition time will be determined by
DFAS.
Contractor shall work cooperatively with the replacement resources to transfer knowledge. In addition, a system configuration audit will be performed to ensure all configurable items have been captured and are in repositories identified in the Software Life Cycle process.
1.15 Quality Control: The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s quality control program is the means by which they assure themselves that the work complies with the requirement of the Task Order (TO). The program should take into consideration the Task (See Part 4) and Performance Requirements Summary (PRS) of the PWS.
1.16 Quality Assurance Plan: The government shall evaluate the contractor’s performance under this TO in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance and the minimum acceptable level of support.
1.17 Data Rights: The DJMS requirement will utilize current data and software that is owned by the government. Although the contractor shall be given access to, and the ability to use, the existing code, documentation, and data, DFAS will retain its intellectual property rights to the data and code.
DFAS intends that all data, software, and documentation delivered by the contractor in performance of this TO will be owned by DFAS. This data, software, and documentation includes, but is not limited to, data, documents, graphics, code, plans, reports, schedules, schemas, metadata, architecture designs, and the like; additionally, all new open source software created by the contractor and forks or branches of current open source software where the contractor has made a modification; and all new tooling, scripting configuration management, infrastructure as code, or any other final changes or edits to successfully deploy or operate the software.
The government requires “Unlimited Data Rights” to all data produced by the contractor in the performance of this TO. DFARS Provisions and Clauses 252.227-7013, 252.227- 7016, 252.227-7017, 252-227-7030, and 252-227-7037 are applicable to performance under this TO.
1.18 Organizational Conflict of Interest: Contractor personnel performing work under this TO may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The contractor shall notify the CO immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the CO to avoid or mitigate any such OCI. The contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the CO and in the event the CO unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the CO may affect other remedies as he or she deems necessary, including prohibiting the contractor from participation in subsequent Call Order requirements which may be affected by the OCI.
1.19 Monthly Status Reports: The prime contractor official representative shall submit a monthly status update to the COR, no later than the 10th day of the following month, identifying the initial and annual mandatory training status of all contractor personnel.
This report can be integrated with the regularly scheduled Monthly Status Reports and made available to the COR as a deliverable item on the TO.
1.20 DevSecOps: Is not applicable at this time, as the contractor shall be working with other
Government programmers and will not be responsible for software elements as named deliverables.
1.21 Agile Methodology: The contractor shall work in a team-based Agile environment. The
Product Owner will specify high-level requirements/ capabilities to the Agile team. As in typical Scrum-based Agile processes, the Agency Product Owner will work together with the team to develop and estimate user stories and establish acceptance criteria. These acceptance criteria shall specify expected functionality for a user story, as well as any non-functional requirements that must be met in the development of the story. The Agency Product Owner, supported by subject matter experts and business analysts, will determine whether or not acceptance criteria have been satisfied.
1.22 Section 508 Compliance:
208 Support Documentation and Services:
E208.1 General. Where an agency provides support documentation or services for ICT, such documentation and services shall conform to the requirements in Chapter 6.
302 Functional Performance Criteria:
302.1 Without Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that does not require user vision.
302.2 With Limited Vision. Where a visual mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited vision.
302.3 Without Perception of Color. Where a visual mode of operation is provided, ICT shall provide at least one visual mode of operation that does not require user perception of color.
302.4 Without Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that does not require user hearing.
302.5 With Limited Hearing. Where an audible mode of operation is provided, ICT shall provide at least one mode of operation that enables users to make use of limited hearing.
302.6 Without Speech. Where speech is used for input, control, or operation, ICT shall provide at least one mode of operation that does not require user speech.
302.7 With Limited Manipulation. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that does not require fine motor control or simultaneous manual operations.
302.8 With Limited Reach and Strength. Where a manual mode of operation is provided, ICT shall provide at least one mode of operation that is operable with limited reach and limited strength.
302.9 With Limited Language, Cognitive, and Learning Abilities. ICT shall provide features making its use by individuals with limited cognitive, language, and learning abilities simpler and easier.
602 Support Documentation:
602.1 General. Documentation that supports the use of ICT shall conform to 602.
603 Support Services:
603.1 General. ICT support services including, but not limited to, help desks, call centers, training services, and automated self-service technical support, shall conform to 603.
PART 2
SECURITY REQUIREMENTS
2. SECURITY REQUIREMENTS:
General Requirements. Contractor personnel must meet the following conditions of employment.
1. Must be a U.S Citizen or National
2. Registered for Selective Service (males born after 12-31-1959). A Status Information Letter is required for any male born after 12-31-1959 that is not registered with Selective Service.
3. This is a national security position which requires a favorable fitness review and background investigation as a condition of employment. Failure to maintain security eligibility may result in termination.
Personnel Security Investigation (PSI) Requirements. Contractor personnel working on this contract will require a favorably adjudicated Tier 3, or equivalent Noncritical-Sensitive (formerly IT-II) or higher level Investigation granting National Security eligibility. Contractor personnel must also have current enrollment (within 5 years) in the Continuous Vetting program, in accordance with Trusted Workforce 2.0 standards. No access to classified information is required. IAW standard DFAS Personnel Security policy, ALL incoming contractors must submit a new set of fingerprints (taken within the last 30 days)*.
Contractor/Contractor personnel must apply for fingerprint appointment immediately (the next business day) upon award date. The contractor/contractor personnel shall submit the Contractor Request for Investigation (CRI) (DFAS Form 9035) immediately (the next business day) of providing fingerprints. It is the contractor’s responsibility to ensure its contractor and subcontractor employees timely obtain and submit fingerprints; but tips can be found at this URL:
https://dfas.mil/careers/security/87. A Declaration for Federal Employment (OF-306) should then be submitted to the Contracting Officer Representative (COR), who will submit this form along with a Contractor Request for Investigation (CRI) (DFAS Form 9035) to DFAS Personnel Security as soon as possible, but not less than fifteen (15) calendar days prior to the intended start date. DFAS Personnel Security will review all submitted documentation to validate whether contractor personnel meet personnel security requirements to perform work on the contract or if a new background investigation is required.
*New fingerprints are not required if any of the following apply:
1. The person has been fingerprinted for the Defense Counterintelligence and Security Agency
(DCSA) within the past 30 days.
2. The person is currently undergoing a background investigation, or reinvestigation, by DCSA or any other Federal agency.
3. The person has a background investigation currently being adjudicated by the DCSA
Adjudication and Vetting Services (DCSA AVS) or another AVS.
4. The person has been favorably adjudicated within the past 30 days by the DCSA AVS or a
AVS from any other Federal agency: or
5. The person is coming directly from another DoD agency, with no break in service. This includes any of the military branches as well as the U.S. Coast Guard; however, service members in an inactive reserve status are not included.
6. The DFAS Personnel Security Office otherwise determines that no new fingerprints are required.
Regulatory Requirements. Contractor personnel shall follow the security and training requirements in DoDM 5200.01, Volumes 1-3, “DoD Information Security Program,” DoDI, 5200.48, “Controlled Unclassified Information,” DFAS 2000.1-I, “Force Protection Mission,” DFAS 5200.1-I, “Information Security Program,” DFAS 5200.8-I, “Physical Security Program,” and DFAS 5200.10-I, “Counter Insider Threat Program.” Contractor personnel shall follow all host security requirements in accordance with Part 117 of Title 32, Code of Federal Regulations;
paragraph 117.16. The following clauses also apply to this contract: DFARS 252.225-7043, FAR 52.222-50, FAR 52.204-2 and DFARS 252.204-7012. The contractor shall immediately report any occurrences of violation of stated regulations to the DFAS Manager of the area to which they are assigned, Contracting Officer (CO), COR, Director, Force Protection, and the DFAS Personnel Security Office.
DFAS Personnel Security Incident Reporting Requirements, the National Industrial Security Program and Due Process as it Relates to DFAS Contractor Personnel. The National Industrial Security Program (NISP) is a partnership between the federal government and private industry to safeguard classified information and CUI.
Executive Order 12829, as amended, "National Industrial Security Program", further amended by Section 6 of E.O. 13691, was established to achieve cost savings and to ensure that industry safeguards the classified information with which it is entrusted while performing work on contracts, programs, bids, or research and development efforts while working for United States Government.
It is important to note that personnel employed as contractors for DFAS are not covered under the National Industrial Security Program (NISP) and are exempt from the provisions of 5 C.F.R. 731.
This means that DFAS contractor personnel involved in an incident that potentially violates one or more of the National Security Adjudicative Guidelines found at https://www.dni.gov/files/NCSC/documents/Regulations/SEAD-4-Adjudicative-Guidelines- U.pdf , are not entitled to Due Process rights normally afforded to federal civilian employees and those personnel covered under NISP; more specifically, DFAS Personnel Security may suspend or revoke their access to DFAS IT systems, sensitive information and/or DFAS facilities.
Incident Reporting Requirements.
In all cases, whenever a DFAS contractor displays conduct, or is involved in any incident, which is in violation of any of the thirteen National Security Adjudicative Guidelines*, the contractor must immediately report the incident to the contractor company Security Office/Facility Security Officer, the DFAS Manager of the area to which they are assigned, the CO, the COR, the Director, Force Protection, and the DFAS Personnel Security Office. Reporting to DFAS Personnel Security may be made by phone to (317) 212-7888, by email to dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil, or, in the case of personnel physically located at DFAS Indianapolis Center, in person to the DFAS Personnel Security Office located on the third floor center hallway at Column 320T.
All incidents will be investigated by DFAS Personnel Security and, depending on the date of the subject’s most recent investigation, may need to have an updated background investigation initiated. Those that do not require a new investigation will have all relevant information regarding the incident forwarded to the DCSA AVS for review and re-adjudication.
*The thirteen National Security Adjudicative Guidelines are:
1. GUIDELINE A: Allegiance to the United States
2. GUIDELINE B: Foreign Influence
3. GUIDELINE C: Foreign Preference
4. GUIDELINE D: Sexual Behavior
5. GUIDELINE E: Personal Conduct
6. GUIDELINE F: Financial Considerations
7. GUIDELINE G: Alcohol Consumption
8. GUIDELINE H: Drug Involvement and Substance Misuse
9. GUIDELINE I: Psychological Conditions
10. GUIDELINE J: Criminal Conduct
11. GUIDELINE K: Handling Protected Information
12. GUIDELINE L: Outside Activities
13. GUIDELINE M: Use of Information Technology
Some Examples of Incidents That Require Reporting to DFAS Personnel Security:
a) An arrest for any criminal offense, not including minor traffic violations, by any law enforcement agency. This DOES include the traffic offenses of Driving Under the Influence of Alcohol or Drugs, and Reckless Driving.
b) Violation of any court order.
c) Civil judgements.
d) Delinquencies on any debt for 180 days or longer.
e) Federal, State or Local tax issues or delinquencies.
f) Delinquencies on any Federal debt (including Federal Student Loans and Federally backed home mortgage loans).
g) Child Support delinquencies.
h) Filing for Chapter 7 or Chapter 13 bankruptcy in any Federal Bankruptcy Court.
i) Foreign Travel.
j) Marriage or Cohabitation with a Foreign National (person from a foreign country).
k) Having a close personal friendship with a Foreign National with regularly occurring contact.
l) Ownership of property or financial accounts in a foreign country; and
m) Being approached by a person know to be, or suspected to be, working as an agent of a foreign government or terrorist organization, or any other person, who seeks any information about DFAS, the Department of Defense, or the U.S. Government, especially if the person offers money or something of value to the contractor employee.
It should be noted that person’s delinquent on Federal debt of any kind may not obtain or maintain favorable personnel security adjudication or be considered for a contractor position with DFAS unless they can provide documentary proof that a payment plan has been established with the government agency to whom the debt is owed, and that regularly recurring payments are being made. Contractor personnel who cannot obtain and maintain a favorable personnel security adjudication may not have access to the government data, facility, and equipment required under the contract.
NOTE: This list does not cover every potential incident or offense; any incident in which a contractor is involved, and a question exists as to whether it should be reported, should report the incident to DFAS Personnel Security, who will then determine if further action is warranted.
Failure to report an incident is, in and of itself, an incident involving personal conduct, and may, in some cases, be more serious than the original incident.
Foreign Travel by DFAS Contractor Personnel.
Official and Unofficial (Personal) Travel: Official U.S. Government Business: persons employed as contractor employees with DFAS, to include those with Noncritical Sensitive (formerly IT-II) access, Critical Sensitive (formerly IT-I) access, access to critical program information (related to Research, Development, Test, and Evaluation), sensitive compartmented information, and/or special access program information, in accordance with DoD Directive 5240.06, are required to complete a DFAS Form 9133, Notification of Foreign Travel, not less than 30 calendar days prior to the scheduled travel.
One copy shall be sent the DFAS Personnel Security group box at dfas.indianapolis-in.zh.mbx.dfas-inhrsecurity@mail.mil and one copy shall be turned into the Site Force Protection Office of the DFAS site where they are stationed. Site Force Protection POC information:
https://dfasportal.dfas.mil/ddss/force_protection/Pages/SiteSpecificForceProtectionSecurityServic es.aspx
Upon receipt of the completed Form 9133, the Site Force Protection Office will contact the contractor employee to validate training, complete the country/theater clearance package, as required, and schedule a Foreign Travel briefing. Immediately prior to travel, contractor employees will check with the State Department at https://travel.state.gov/content/travel/en/traveladvisories/traveladvisories.html.html for any travel advisories for the country or region being traveled to and take the appropriate steps to ensure their safety for any location covered by a travel advisory or warning.
Security Education and Training. Contractor personnel shall receive initial, continuous and refresher security education training in accordance with DoDM 5200.01, Volume 3, “DoD Information Security Program – Protection of Classified Information,” DoDI 5200.48, DFAS 2000.1-I, DFAS 5200.1-I, DFAS 5200.8-I, and DFAS 5200.10-I. Contractor personnel shall also complete all required contractor training requirements identified in this SOW/PWS.
Access To, Accountability For, and Safeguarding of Controlled Unclassified Information (CUI). The DFAS manager of the requiring office will determine what CUI contractor personnel are given access to. CUI may not be disclosed to contractor personnel unless required for contract performance. Contractor personnel shall safeguard CUI in accordance with DoDI
5200.48 and DFAS 5200.1-I. The sponsoring DFAS activity will provide storage capability for all CUI required for contract performance. Contractor personnel must monitor CUI for aggregation and compilation based on the potential to generate classified information. Contractor personnel must report the potential classification of aggregated or compiled CUI to the DFAS Manager of the area to which they are assigned, the CO, the COR, and the Director, Force Protection.
Installation Entry and Common Access Card (CAC) Requirements. The Contractor shall comply with established security procedures for entering government installations and facilities. Contractor employees shall be required to obtain and wear identification (ID) badges that will permit access into the facility.
Contractors shall work with the assigned DFAS COR/Mission Partner Account Sponsor (MPAS) to obtain a CAC using Mission Partner Identity Credential Account Management (MP ICAM). Under no circumstances will a CAC be issued to any person unless that person has been cleared by the DFAS Personnel Security Office to work on the contract.
All CACs and badges issued to Contractor personnel are Government property and must be returned to the assigned DFAS COR/MPAS upon departure from the program or at the conclusion of the contract, whichever comes first. CACs can also be mailed in or turned into RAPIDS locations. Contractors whose CAC is lost or stolen must report the loss as soon as possible to the assigned DFAS COR/MPAS and present documentation that the CAC is missing and describing the circumstances under which the loss occurred. The assigned DFAS COR/MPAS will follow agency CAC procedures to issue a new CAC.
Contractors’ must not share their CACs and passwords with any other staff members. The assigned DFAS COR/MPAS will report any violation or suspected violation to the Contracting Officer and DFAS MP ICAM Account Security Manager (MPASM). Any violators will be temporarily or permanently removed from the project. If a Contractor has a CAC issued from another agency, that CAC must be revoked and returned before issuance of a new CAC.
Training.
DoD Mandatory Contractor Personnel Training Requirements: The contractor shall direct that its employees performing under this contract complete the annual mandatory training in accordance with the DoD mandate identified for each training module.
Contractor personnel working at a DFAS site who require a Common Access Card (CAC), or contractor personnel working remote via VPN, need to complete the following training modules within 30 days after receipt of CAC, (note for Cyber Awareness Challenge Module 003, completion of this module is required prior to requesting a new DFAS network or VPN account), as a precondition for continued attendance and/or network access.
In addition, these modules shall be completed annually to retain accessibility. Noncompliance will negatively impact contract performance and lead to the loss of CAC and/or network access for contractor personnel.
Continuity of Operations and Crisis Management Organization. Contractor personnel will take the training through the DFAS Portal upon receipt of Network access.
Cyber Awareness Challenge. Completion of this module is required prior to requesting a new DFAS network or VPN account. For contractor personnel unable to access the DFAS Portal, the same training is available at:
https://public.cyber.mil/training/cyber-awareness-challenge/
Upon completion of the training Contractor personnel shall maintain a copy of the training certificate in PDF, submit a copy to the COR, attached to the request for network access as proof of completion.
Keeping DFAS Safe: Physical Security, Information Security, Personnel Security, CBRNE, Counterintelligence and Operations Security. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
Level I Antiterrorism Awareness Training. All contractor personnel shall take this training.
For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:
https://jkodirect.jten.mil/Atlas2/page/login/Login.jsf
All other contractor personnel shall take the training through the DFAS Portal upon receipt of network access.
Privacy Act (PA) and Personally Identifiable Information (PII). Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
Records Management. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
Insider Threat (InT) Awareness Training. Contractor personnel shall take the training through the DFAS Portal upon receipt of Network access.
DoD Mandatory Controlled Unclassified Information (CUI) Training. All contractor personnel shall take this CUI training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:
https://securityawareness.usalearning.gov/cui/index.html
All other contractor personnel will take the training through the DFAS Portal upon receipt of network access.
Unauthorized Disclosure of Classified Information and CUI. All contractor personnel shall take this training. For contractor personnel who will not require or receive access to the DFAS Portal, this training is available at:
https://securityawareness.usalearning.gov/disclosure/index.html
All other contractor personnel will take the training through the DFAS Portal upon receipt of network access.
NOTE: This list of training requirements is subject to change.
Training Time. The average estimated time for completion of each training module is approximately one hour or less. The Keeping DFAS Safe: Physical Security, Information Security, and Personnel Security training module will take approximately 90 minutes to complete.
Training Methods:
Network Training. Network training through the DFAS Portal is the required method for those Contractor personnel who have an existing DFAS network account. Web-based Training. All contractor personnel are required to take the following web-based training: Cyber Awareness Challenge (When system/network access is required), Level I Antiterrorism Awareness Training, DoD Mandatory Controlled Unclassified Information Training, and Unauthorized Disclosure of Classified Information and CUI. If an individual does not have network access through the DFAS Portal, they can complete the training through a DoD authorized Web source. All other contractor personnel shall take the training through the DFAS Portal upon receipt of DFAS network access. The contractor personnel shall retain a PDF copy of the “Certificate of Completion” or a “screen shot” with the date of the completion of the training. The COR will maintain a file for proof of completion. Contractor personnel who do not require network access but require unescorted access into a DFAS facility shall receive applicable security training through the site Force Protection Office. To identify Site Force Protection Officers at each DFAS location consult the Agency Force Protection Portal Page:
https://dfasportal.dfas.mil/ddss/force_protection/Pages/SiteSpecificForceProtectionSecurityServic es.aspx
The prime contractor official representative shall provide the COR with a group list of its personnel requiring completion of the training. The COR will submit the ‘group list’ to the Site Force Protection Officer to schedule training. As a reminder, the prime contractor official representative shall submit this group list of names within 30 days after contract award. Requests for individual training shall be justified in writing and submitted to the COR for evaluation.
Special arrangements will be determined by the Site Force Protection Officer, other training Module POCs and the COR.
Interaction with Contractor Personnel. The COR shall forward questions or concerns directly to the prime contractor official representative who is directly responsible for managing its own employees/subcontractor personnel.
The prime contractor official representative shall coordinate with the COR a training schedule without causing undue delays to contract performance.
The prime contractor official representative (including subcontractor’s personnel when applicable) shall provide the COR, within 30 days after contract award/exercise of an option, a written report identifying:
- Contractor employees required to take the training
- Contractor employees who have completed the training
- Contractor employees who are delinquent
Contractor personnel shall direct their training questions or concerns to their contractor management chain and/or company representative.
Monthly Training Status Reports. The prime contractor official representative shall submit a monthly status update to the COR, identifying the initial and annual training status of all contractor personnel.
Training Point of Contact (POC). The COR is the POC for the Contractor. The Contractor shall provide regular training updates to the COR and keep an updated registry to assure employees who come on board at any time in the contract life have completed all required training.
PART 3
GOVERNMENT FURNISHED EQUIPMENT
3. GOVERNMENT FURNISHED EQUIPMENT:
3.1 Government Furnished Equipment: Laptops shall be furnished by DFAS and shipped to the remote working locations of those fulfilling the activity of the contract. All software resident on the computers required to complete the tasks will be made available to the contractor after Desktop Management Initiative (DMI) and Cyber Security Service Contractor (CSSP) approval. Only DFAS Government furnished equipment shall be connected to the DFAS Enterprise Local Area Network (ELAN). The contractor shall be fully responsible for maintaining the inventory, providing physical security, and returning the equipment and materials to the Government in the same condition in which they were received, after completion of the period of performance.
Desktop Management Initiative (DMI) is the DFAS Standard for software/hardware. All computers connected at DFAS sites must be configured under DMI.
The Government shall provide the access network connection, via the Cisco AnyConnect Virtual Private Network for any personnel not working at the DFAS site.
The contractor shall be responsible for safeguarding all Government equipment, information and property provided for contractor use. At the close of business each workday, Government equipment and materials shall be secured.
3.2 DFAS IT Policy Concerning Contractor Furnished Equipment (CFE): The contractor shall ensure personally owned workstations, laptop computers, software, and printers, including computers connected remotely will not be connected to the DFAS Enterprise Local Area Network (ELAN). This prohibition is a security requirement to protect the ELAN from the spread of malicious logic (viruses and Trojan Horse programs) and to protect sensitive but unclassified (SBU) information from being compromised.
PART 4
SPECIFIC TASKS
4.0 SPECIFIC TASKS:
The contractor shall perform the work identified below and obtain the results identified in the outcome column of the attached Performance Requirements Summary (PRS) which is attached as exhibit 1 and fully incorporated herein. It sets forth how the contractor’s activities will be monitored and measured. The tasks required are organized into the following system lifecycle categories: requirements development, technical design, configuration management, technical design activities, development of code, testing, and implementation activities. Each category of work has specific detailed tasks that set forth the results the contractor must accomplish and the performance measures for each. A more general description of the work required to be performed and expectations governing how that work will be performed are provided below.
The following tasks apply to contractor support for both DJMS-AC and DJMS-RC:
4.1 Task 1: Contract Program Management
The contractor shall track hours worked on various projects. The tracking and updating of the above information shall be captured in a Staffing Matrix and detailed in individual project milestone charts. The contractor shall also prepare a monthly Staffing Matrix to include each contractor performing under this T.O. The Staffing Matrix shall highlight any changes from the previous report. The Staffing Matrix shall list the Contractor’s Name, Subcontractor, Start Date, Stop Date and any other information agreed to by the Government and the contractor.
The contractor shall prepare and deliver a weekly Status Report to the COR. The contractor shall report by project/system that details the system, Government team leader, Contractor(s) assigned, summary of activities for the week, progress, problems encountered and solutions to the problems.
4.1.1 Performance and Cost Report
The contractor shall prepare and deliver on a monthly basis a Performance and Cost Report and a Summary Project Status Report to the COR no later than the 5th workday of the month. The contractor shall maintain and report in accordance with (IAW) the Government’s instructions the following: the current status of this T.O.; relevant information regarding problem areas and course of action taken in their resolution; potential problems anticipated; significant activities, work progress, and T.O. costs; metrics, and cost data; forecasts;
analyses; and software reuse progress metrics. The metrics shall focus on how the contractor performance rates against the acceptable level of performance (ALP) set forth in the PRS for the work performed by the contractor. The contractor shall report status and cost in accordance with the Government-approved Work Breakdown Structure (WBS).
A soft copy of the Performance and Cost Report (not including Travel attachments) shall be attached to the contractor’s invoice. Upon the expiration of the period of performance, the contractor is responsible for submitting the final invoice within sixty days of the end of the period of performance.
4.1.2 Management Reviews (MRs)
The contractor shall prepare and provide Management Reviews (MRs) to identify and address progress, problems, and other pertinent information. The Government may require these Management Reviews intermittently in order to address pertinent issues. The contractor shall identify all Subcontractors and address progress, problems, and other pertinent, detailed information. If required, the contractor shall ensure the following topics are available for discussion at the MR: the management of T.O. activities, scheduling, costs, and technical status.
4.2 Task 2: Requirements Management & Analysis
4.2.1 Agile Development Support
The contractor shall support the Agile software development life cycle for DJMS when requested by working with stakeholders from the system user community and the Military Pay Office (PMO) in the DFAS Enterprise Solutions & Standards (ESS) organization or from the DJMS System Management Office Participate in Agile ceremonies (e.g. scrum, backlog, and retrospective meetings).
4.2.2 Data Searches and Queries
The contractor shall perform stand-alone and multiple searches to gather data needed within established timeframes. Searches consists of reviewing requirement (query to obtain data from system or create transactions) and perform analysis of how to execute requirement, program code to obtain requirement, unit test and systems test or program test, obtain approval to proceed and send to production for execution. The contractor shall ensure data reports were provided to the customer within the established timeframe.
4.2.3 ROM Analysis
The contractor shall develop rough order of magnitude (ROM) analysis by reviewing proposed software changes and perform analysis of effort needed to process the requirement and develop a rough order of magnitude for performing the work necessary. The contractor shall develop a ROM consisting of proposed changes and will reflect hours for programmers, tester, test support and project management.
4.2.4 Functional Analysis
The contractor shall analyze and review (when requested) the Functional Description document(s) drafted by DJMS organizations for an SCR in order to provide feedback and seek clarification on items within the document that may impact the ability of the technical development team to perform their technical duties
The contractor shall write system change specification and perform an analysis of the Functional Description, the relationship between sub-system and programs, examine configuration items for impact of this change, write addendum if necessary and based on review, write system change specification document.
The contractor shall ensure system change specification document is created and loaded into project repository. Focus of analysis will be on the inputs (tasks that provide raw data to DJMS from DJMS users (Control files, MAPS), outputs (data created by DJMS for external sources (IRS, SSA), internal files (data maintained and used by DJMS (MMPA, LES), external interface files (maintained by external systems and read by DJMS (treasury, returned checks)), and tables rates (look up data).
As part of developing system change specifications, the contractor shall review current schedules and timelines for dependencies and review the impact assessment and time needed to complete in the schedule. The contractor shall update schedules and related estimates of effort and time as required. This includes updating and tracking the configuration management tool and the individual configuration items estimated hours and assigned resource are updated in the database.
The contractor shall attend the system requirement review meetings of the system changes requirements, system change specifications and provide their analysis and input. The contractor shall ensure all issues are addressed.
4.2.5 Internal Agency Requests
The contractor shall provide information and data to respond to various ‘what if’ scenarios and perform research activities on different systems. Perform detailed analysis, document it, and communicate it to internal DFAS customer community. Write file searches or programs to obtain needed data if applicable or use staging database for queries. The contractor shall perform research to generate the requested data provided to the customer that addresses the request while meeting suspense date.
The contractor shall process platform/mainframe enhancement requests by programming and testing of system upgrade or enhancements. This includes testing to ensure that the identified change works and does not change system output. Contractor shall also research how changes impact system output and respond to appropriate party with the result and/or analysis.
4.2.6 Resolve Inquiries
The contractor shall respond to calls, emails and messages in a timely manner.
Upon receiving questions and inquires, the contractor shall determine what the issue is and categorize the inquiry accordingly in the system designated by DFAS for such data. Contractor shall ensure email and messages are timely checked and emails categorized and logged.
In analyzing said inquires, the contractor shall review the system where all such issues are logged to see if similar prior issues exist. Contractor shall research the issue to determine a solution. Inquiries that pertain to security access or other system issues will be referred to DJMS ISSM/ ISSO or DISA Mechanicsburg for resolution. When the solution requires a coding change, contractor shall refer the matter to the Business Analyst for PTR development. Contractor shall strive to resolve the inquiry at the lowest level and in the shortest time possible and ensure the log is closed out with applicable data.
4.2.7 Audit Support & Compliance Support
When requested by an auditor to provide data, the contractor shall research and gather such data. The contractor shall examine internal controls to verify they are working properly and when required, test the internal controls to ensure compliance of system.
4.2.8 Analyzing ABENDs
The contractor shall analyze Abnormal Ending (ABEND) conditions. In performing such task, the contractor shall examine cause(s) of an ABEND in production, analyze and identify a solution for the ABEND. Thereafter, the contractor shall obtain coordination from the Business Analyst and production support for their selected solution. The solution identified by the contractor must resolve the ABEND following a detailed analysis of the causes of the ABEND condition.
4.3 Task 3: Technical Design Activities
4.3.1 Technical Analysis
The contactor shall provide sound technical analysis and designs to achieve requirements identified in SCRs. The contractor shall utilize the requirement impacts and functional analysis of each change request to perform research that establishes the scope of changes necessary to the technical architecture of the DJMS to implement the change. These changes will be formally documented in a DJMS Technical Analysis document.
4.3.2 Testing Analysis
The contractor shall provide support and guidance to analyze testing activities.
The contractor shall utilize the requirement impacts and functional analysis of each change request to perform…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .