Attach L-11 - EITS SOO (A0005).docx
DOCX document 2 MB Posted
- Attached to
- MDA IT Operations & Engineering Solutions (MIOES) - CANCELED Federal contract opportunity
- Solicitation number
- HQ0857-MIOES-ZA
- Issued by
- DOD Missile Defense Agency
View the file
Other files for this federal contract opportunity
Show all 50
MDA IT Operations & Engineering Solutions (MIOES) - CANCELED has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
By submitting a proposal for Task Order 3000, EITS, the Offeror agrees to furnish all services and items upon which the prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule if this Task Order offer is accepted by the Government anytime from award of the contract resulting from H95001-15-R-0001 through 180 calendar days thereafter.
Period of Performance
| Start date: | Contract Award Notification plus 180 calendar days |
| Duration: | 4.5 year base |
Contract Type This is a cost-plus-incentive-fee (CPIF) task order. The Offeror shall propose a target cost and target fee. The target cost is inclusive of all cost elements, including labor, material, and other direct costs (ODCs). The minimum fee shall be 3% of target cost. The maximum fee shall be 15% of target cost. The share ratio above target cost is 60 (Government)/40 (Contractor). The share ratio below target cost is 40 (Government)/60 (Contractor).
The Offeror’s proposed target fee percentage shall not exceed the fee percentages as proposed on Attachment L-16: Cost / Price Workbook 3, WS3-3: Fee Structure Table.
Payments for all contract line item numbers (CLINs) will be made in accordance with FAR 52.216-7, Allowable Cost and Payment. Payments and the fee payable under the task order are subject to adjustments in accordance with FAR 52.216.10, Incentive Fee, and performance assessments conducted in accordance with the IRES Performance Evaluation and Incentive Plan (Attachment J6).
In addition to adjustments authorized in accordance with FAR 52.216-10(d), adjustment of the target cost due to a variance in the actual cost incurred when compared to the Government’s plug number (GPN) for other direct costs (ODC) may be considered if actual ODC costs exceed +/- 15%. The adjustment will only be made by the amount the actual cost incurred exceeds the +/- 15% threshold; no adjustments to fee will be made.
CLIN Structure
| CLIN |
| Supplies / Services |
| Type |
| QTY |
| Unit |
| Amount |
| 0001 | ||
| Services / Solutions | ||
| CPIF | ||
| 54 | ||
| Month | ||
| Target Cost: | * | |
| Target Fee: | * | |
| Total Target Cost + Fee | * | |
| Minimum Fee: | * | |
| Maximum Fee: | * |
Share Ratio Above Target (Gov/Cont): 60/40 Share Ratio Below Target (Gov/Cont): 40/60
| 0002 |
| Expensed CAP IT Hardware |
| Cost |
| 54 |
| Combo |
| Target Cost *, ** |
| 0003 |
| Expensed CAP IT Software |
| Cost |
| 54 |
| Combo |
| Target Cost *, ** |
| 0090 |
| Data |
| FFP |
| 1 |
| Lot |
| Not Separately Priced (NSP) |
| 0091 |
| CAP Delivery / CDRL |
| FFP |
| 1 |
| Lot |
| NSP |
| * | Cost Price Workbook 3, WS3-6: TO 3000 Prop |
| ** | Fee, if proposed, will be incorporated into the target profit on CLIN 0001. These CLINs are for funding and invoicing only; the contractor’s work breakdown structure must associate the purchase of all other direct costs (including the CAP under these CLINs) with the activity accomplished. |
WARNING – This document contains information that may be exempt from mandatory disclosure under the Freedom of Information Act
H95001-15-R-0001-0005 Attachment L-11
FOR OFFICIAL USE ONLY
Sep 1, 2016 FOR OFFICIAL USE ONLY
IRES
Integrated Research & Development for Enterprise Solutions
Attachment L11:
Enterprise Information Technology Services (EITS) Statement of Objectives (SOO)
WARNING – This document contains information that may be exempt from mandatory disclosure under the Freedom of Information Act
Table of Contents
| 1.0 | Vision and Purpose Statement | 1 |
| 1.1 | Vision | 1 |
| 1.2 | Purpose | 1 |
| 1.3 | Goals for 2020 and Beyond | 2 |
| 1.3.1 | Goal 1: Deliver Agile IT That Enables Mission Success | 2 |
| 1.3.2 | Goal 2: Cyber Compliance – Build the MDA Information Environment | 2 |
| 1.3.3 | Goal 3: Sustainment | 3 |
| 2.0 | Background | 4 |
| 2.1 | Predecessor Task Orders | 4 |
| 2.2 | Organization Background | 4 |
| 2.2.1 | Chief Information Officer (CIO) | 4 |
| 3.0 | Scope | 5 |
| 4.0 | Service Summary Items | 7 |
| 5.0 | Statement of Objectives and Outcomes | 7 |
| 5.1 | Task Order Administration | 9 |
| 5.1.1 Description | 9 | |
| 5.1.2 | Outcomes | 9 |
| 5.1.3 | Desired Attributes | 9 |
| 5.1.4 | Constraints | 9 |
| 5.2 | Portfolio Management Services | 10 |
| 5.2.1 | Description | 10 |
| 5.2.2 | Outcomes | 10 |
| 5.2.3 | Desired Attributes | 12 |
| 5.2.4 | Constraints | 12 |
| 5.3 | Cybersecurity Services | 12 |
| 5.3.1 | Description | 12 |
| 5.3.2 | Outcomes | 12 |
| 5.3.3 | Desired Attributes | 13 |
| 5.3.4 | Constraints | 13 |
| 5.4 | Data Center Services | 14 |
| 5.4.1 | Description | 14 |
| 5.4.2 | Outcomes | 14 |
| 5.4.3 | Desired Attributes | 15 |
| 5.4.4 | Constraints | 15 |
| 5.5 | Customer Support Services | 16 |
| 5.5.1 | Description | 16 |
| 5.5.2 | Outcomes | 16 |
| 5.5.3 | Desired Attributes | 16 |
| 5.5.4 | Constraints | 17 |
| 5.6 | Network Administration | 17 |
| 5.6.1 | Description | 17 |
| 5.6.2 | Outcomes | 18 |
| 5.6.3 | Desired Attributes | 18 |
| 5.6.4 | Constraints | 19 |
| 5.7 | Application Administration | 19 |
| 5.7.1 | Description | 19 |
| 5.7.2 | Outcomes | 19 |
| 5.7.3 | Desired Attributes | 20 |
| 5.7.4 | Constraints | 20 |
| 5.8 | Telephony Services | 20 |
| 5.8.1 | Description | 20 |
| 5.8.2 | Outcomes | 21 |
| 5.8.3 | Desired Attributes | 21 |
| 5.8.4 | Constraints | 21 |
| 5.9 | IT Solutions and Sustainment Engineering Services | 21 |
| 5.9.1 | Description | 21 |
| 5.9.2 | Outcomes | 22 |
| 5.9.3 | Desired Attributes | 23 |
| 5.9.4 | Constraints | 23 |
| 6.0 | Deliverables | 23 |
| 6.1 | CDRL Identification | 23 |
| 6.2 | CDRL Tailoring | 25 |
| 6.3 | Milestones | 25 |
| 7.0 | Government Furnished Equipment (GFE) / Government Furnished Information (GFI) | 25 |
| 8.0 | Special Requirements | 26 |
| 9.0 | Applicable Directives / Regulations | 27 |
| 10.0 | Contractor Developed PWS | 27 |
| 11.0 | Contractor-proposed Service Summary Item Table | 29 |
| TO 3000 Exhibit C | 29 | |
| Enclosures | 30 | |
| (FOUO) Enclosure 1: Workload Data | 30 | |
| (FOUO) Enclosure 2: Enterprise Applications | 30 | |
| (FOUO) Enclosure 3: Responsibility Matrix | 30 | |
| (FOUO) Enclosure 4: MDA Application and Technical Services Portfolio | 30 | |
| Enclosure 5: Service Catalog Table with Average Requests | 30 | |
| Enclosure 6: EITS Key Performance Indicators | 30 | |
| Enclosure 7: Application Versions | 30 |
Enterprise Information Technology Services Vision
| 1.0 | Vision and Purpose Statement |
| 1.1 | Vision |
The MDA vision for delivery of all MDA information management / information technology (IM/IT) services is to have an adaptive organization that assures the confidentiality, integrity, and availability of MDA-controlled unclassified and classified information following the DoD Risk Management Framework (RMF) and to achieve improvements in service delivery and cost containment while delivering customer-focused services based upon IT Service Management (ITSM) principles and the Information Technology Infrastructure Library (ITIL) methodologies.
MDA IT Services provides a set of core functions operating in an Enterprise context delivering processing, storage, and transport of information, human interaction, systems and network management, information dissemination management, and information assurance. These functions must be fully integrated and interoperable with one another in order to achieve overall success across the MDA Information Environment (MIE) consisting of three functional environments: mission, test, and general services.
1.2 Purpose
This task order will provide the MDA with Enterprise (agency-wide) IT capabilities 1) supporting Ballistic Missile Defense System (BMDS) Research, Development, Test, and Evaluation (RDT&E) requirements, 2) providing MDA administrative and business requirements, and 3) enabling BMDS mission support tasks for deployed systems. The CIO has oversight and provides assistance and support for all three IT environments to ensure compliance with the regulatory requirements.
The office of the Chief Information Officer (CIO) is responsible for ensuring that IM/IT are acquired and that information resources are managed and protected for the MDA in a manner that meets the requirements of legislation, regulations, and directives which include, but are not limited to, the Clinger-Cohen Act of 1996, the Paperwork Reduction Act of 1995, the E-Government Act, the Federal Information Security Management Act (FISMA) of 2002, the President’s Management Agenda, the DoD 8500 policy framework, DoD Directive 8000.1, National Security Agency information assurance policies, and the priorities established by the Director, MDA.
The MDA Enterprise Information Environment Mission Area (EIEMA) and Business Mission Areas (BMA) are Department of Defense Architecture Framework (DoDAF) and Joint Information Environment (JIE) compliant; they provide processing, storage, and transport of information; systems and network management; information dissemination management; and cybersecurity functions. The CIO provides MDA with secure classified and unclassified information technology systems; data centers; operations and monitoring centers; telecommunications; local and wide-area network infrastructure; and customer services to meet both DoD and MDA requirements of high availability, disaster recovery and continuity of operations. The CIO also provides support to the Warfighter Mission Area and the Defense Intelligence Mission Area for various components located within the MDA core sites. Components such as the Joint Functional Component Command- Integrated Missile Defense and the Intelligence Support Center represent two of the groups in these mission areas supported within the IRES contract.
1.3 Goals for 2020 and Beyond
MDA adheres to the DoD Unified Capabilities Operational Framework and has tied together multiple mission areas into an integrated framework. This integrated framework facilitates Joint Information Environment (JIE) efficiencies without sacrificing the ability to meet the special purpose information technology requirements of the development and test enclaves which support the timely BMDS development and fielding schedules. MDA data centers are registered with the DoD CIO as Special Purpose Processing Nodes (SPPNs). MDA’s SPPNs support unique requirements (e.g., RDT&E enclaves residing on the Defense Research and Engineering Network (DREN)) that have varying levels of security, access requirements, development requirements, and security controls in accordance with DISA “Enclave Test and Development Security Technical Implementation Guide” (STIG) Zones A through D. MDA follows the JIE standards to the maximum extent possible to facilitate information sharing. MDA’s capabilities-based acquisition model demands collaboration services across multiple government and contractor sites that are interconnected via the DREN infrastructure and the Department of Defense Information Network (DoDIN). This network infrastructure is highly integrated, supporting the wide range of scientific, research, missile defense development, business operations, and day-to-day collaboration required to bring the BMDS from concept to reality.
1.3.1 Goal 1: Deliver Agile IT That Enables Mission Success
IT Services must continually improve processes supporting end-to-end service delivery (i.e., requirements management, service design, release and change management, service transition, and governance functions including technical integration, configuration control, and data management) to increase the organizational agility to meet the demands of the missile defense community. A key element of this goal is integration with MDA’s system engineering process.
1.3.2 Goal 2: Cyber Compliance – Build the MDA Information Environment The Department of Defense (DoD) vision of the JIE is a secure joint information environment comprised of shared IT infrastructure, Enterprise services, and a single security architecture to achieve full spectrum superiority, improve mission effectiveness, increase security, and realize IT efficiencies. The task order must establish a foundation that aligns the MIE to DoD expectations for a SPPN that provides a shared, secure missile defense test and development cloud infrastructure to support the missile defense community’s RDT&E needs employing a single security architecture actively monitored for compliance by the MDA Computer Emergency Response Team (CERT).
| 1.3.3 | Goal 3: Sustainment |
| 1.3.3.1 | Refresh Technologies at a Pace That Continuously Improves Compliance and Service Delivery |
Provide technology refreshment strategies and roadmaps, including data center-specific roadmaps, to ensure technology-parity with the Joint Information Environment while avoiding the cost pitfalls of having to achieve that homogeneity through a vendor monopoly. IT Services will sustain current capabilities while increasing service delivery and complying with DoD guidance.
1.3.3.2 Technology Watchlist
Exploit and integrate new technologies into the supporting infrastructure to improve service effectiveness and efficiency over the next five years. The Technology Watchlist section describes emerging and maturing technology areas that have the potential to improve service effectiveness and efficiency over the next five years. They are listed in a relative order of maturity.
1.3.3.2.1 Cloud Services
The MDA has already begun to field cloud elements and will continue to monitor this technology for changes in direction and to identify integration opportunities. The maturation of these technologies and the integration of the resulting capabilities are key components to achieving the MDA goals of improving IT Service Delivery and cyber compliance. Services based on a cloud delivery model provide opportunities for moving towards ubiquitous mission domain support wherever possible.
1.3.3.2.2 Software Defined Data Center
Evolution to a software-defined data center (SDDC), utilizing technologies to virtualize the compute, storage, and network components of the data center provides flexibility for improved mission effectiveness. SDDC technology is a key element in reaching MDA’s sustainment goal.
1.3.3.2.3 Business Analytics
Improve business intelligence and data analytics by strategically provisioning and employing technologies for searching, mining, storing, securing, and conducting data analytics on large, disparate data sets. Providing data analytic capabilities to MDA mission partners is essential to modern warfare. The integration of the resulting capabilities is a key component to achieving our service delivery goal. This technology can provide predictive analysis to improve mission effectiveness.
1.3.3.2.4 Mobile Technologies
Leverage mobile technologies to enable ubiquitous information access allowing users to perform their duties and improve their situational awareness from any location.
1.3.3.2.5 Cybersecurity Technologies
Strategically plan for and employ the latest, best technology to preserve and protect critical BMDS program information throughout its lifecycle.
2.0 Background
NOTE: This information is provided as an aid to offerors; it is not intended to direct or influence the proposed solutions or contractor-developed performance work statement submitted in response to this SOO.
2.1 Predecessor Task Orders
Task orders let on the JRDC that are considered predecessor task orders to this SOO include:
· 8402, MDA IT Services and Logistics (excluding task 3, and tasks 100 and above)
· 7402, MDA IT Services and Logistics (excluding task 3, and tasks 100 and above)
· 6402, MDA IT Services and Logistics (excluding task 3, and tasks 100 and above)
2.2 Organization Background
The MDA is comprised of four Program Executives responsible for the execution of the BMDS program (Program Executive for Programs and Integration, Program Executive for C4ISR, Program Executive for Aegis BMD, and Program Executive for Advanced Technology) and six Program Directors responsible for the functional activities supporting the RDT&E mission (Director for Engineering, Director for Test, Director for International Affairs, Director for Acquisition, Deputy Director and Director MDIOC, and Director for Operations). In addition to the above, the MDA is also supported by a Command Group Staff that includes: General Counsel; Chief of Staff; Quality, Safety and Mission Assurance; Equal Opportunity and Diversity; Public Affairs; Internal Review; Chief Information Officer; Independent Test Readiness Review Team; and Small Business Advisor. All organizational entities leverage the CIO for Information Technology and Information Management functions.
2.2.1 Chief Information Officer (CIO)
The CIO has adopted ITIL as the framework for organizing IT processes and services, and training the Information Technology workforce to meet an ITSM construct. Accordingly, IC has established five staff functions to manage the Infrastructure Integration and Event Support, Information Management, and Information Technology Operations and Cybersecurity capabilities:
1) IC Staff – Information Management and Technology Operations
2) ICM – Infrastructure Integration and Event Support
a. ICME – Infrastructure, Event Support
b. DACJ – Contracts and Acquisition
c. DOB – Financial Management
d. DOHC – Human Resources – West
e. PA – Protocol / Public Affairs
f. DEI – Security
g. DPL – Integrated Logistics Support
3) ICV – Information and Computer Network Defense (CND)
a. ICVA – IA Certification and Accreditation
b. ICVI – BMDS IA Management
c. ICVC – Computer Network Defense
4) ICT – Information Management and Technology Operations
a. ICTP – IT Policy Planning and Portfolio
b. ICTO – Enterprise Operations and Engineering
c. ICTT – Unified Communications
d. ICTA – IT Networks and Systems
e. ICTM – Information Management
5) Regional IT Support
a. IC-NCR
b. IC-HSV
c. IC-DAHL
d. IC-KAFB
e. IC-COS These five staff functions manage the IT/IM enterprise to ensure compliance with federal mandates, DoD policies, and compliance reporting in order to field Enterprise compliant information technology solutions, manage information, and to operate and defend our networks and information. The synergy achieved by the relationship between these functions results in the Network Operations (NetOps) desired effects of assured system and network availability, assured information protection, and reliable information delivery.
| 3.0 | Scope |
| 3.1 | This task order will support the Missile Defense Agency (MDA) Chief Information Officer (CIO) mission to ensure that MDAs IT Enterprise services and resources are administered, acquired, managed, and operated in compliance with the goals and directives of existing statutes and DOD regulations and the priorities set by the MDA Director and CIO. |
| 3.2 | This task order will provide effective, efficient, secure, and reliable information network services used in critical DoD and MDA communications and information processing utilizing the ITIL framework and methodologies and a well-defined set of Role Based Administration (RBA) categories and responsibilities. |
| 3.3 | This task order will administer two major data centers, one in Huntsville (HSV), AL and the other in Colorado Springs (COS), CO. Both data centers provide a mix of classified and unclassified IT services, with each providing disaster recovery and continuity of operations (DR/COOP) for critical services to the other. |
| 3.4 | This task order will administer the MDA administrative and general services (ADMIN/Genser) defined as MDAs Enterprise unclassified and classified networks, research, development, test and evaluation (RDT&E) network, Facilities Infrastructure LAN (FILAN) and network IT elements (routers, switches, firewalls and gateways), workstations, servers and peripherals to include but not limited to 4 Metropolitan Area Networks (MANs), 21 Local Area Networks (LANs), approximately 156 remote sites, as many as 300 unique MDA-sponsored mission systems or enclaves, and numerous standalone configurations; MDA IT connections to the Secure Internet Protocol Router Network (SIPRNet) and Joint Worldwide Intelligence Community System (JWICS) networks; 8,000 MDA Users, roughly 23,000 user accounts, 13,000 messaging accounts, 2,500 Blackberry users, 1,250 production servers, print servers and 1,000 network printers, connectivity to over 300 Video TeleConference (VTC) nodes, classified and unclassified telephony services, IT and O&M support for the National Capital Region (Ft. Belvoir, Suffolk, Crystal Square 4, Lockport); Huntsville (Von Braun Complex, Building 7319 Missile Assembly Building, Building 5201); Colorado Springs (MDIOC); Dahlgren (David M. Altwegg Complex); Alaska (Building 10441 Joint Base Elmendorf/Richardson and Ft. Greely Buildings 663 and 652 (SLA with GM for 2 cable plant personnel assisting GMB and DDW on Missile Defense Complex as tasked)); Kirtland AFB Building 20200; Vandenberg AFB Building 6510; Kauai (Pacific Missile Range Facility) AAMDTC and as contracted by DTR for Buildings 327/328/155/DART; Romania (Deveselu) - no responsibility after 28 Feb 2016; Poland (new site) - pick up initial responsibility upon site activation in 3QFY16 and hold until turn over to Navy in 2018. MDA ground and flight tests often require travel to remote locations. |
| 3.5 | This task order will leverage and expand capacity in MDA Data Centers to accommodate the rapid provisioning of customer requirements in a cloud-based, dynamic enterprise architecture. EITS will employ a streamlined System Development Lifecycle methodology to deliver Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) solutions with supporting IT Financial Management technical processes to maximize the speed and efficiency by which EITS is able to delivery new and improved capabilities. |
| 4.0 | Service Summary Items |
In accordance with the IRES Performance Evaluation and Incentive Plan, Service Summary Items (SSIs) 1 through 4 are common [required] on all task orders and will be assessed at the contract level (i.e., all task orders will receive the same rating – one fail all fail model).
SSI 5 (through n) [Technical Performance] captures the specific task order Service Summary Items deemed essential to successful execution of the task order (note: To be developed / defined using the performance measures proposed by the contractor.) Exhibit 1 defines the SSIs applicable to this task order.
5.0 Statement of Objectives and Outcomes
Eight major lines of service will be used as the basis for describing the requirements of this SOO; while these eight service areas are provided for an understanding of CIO services and desired outcomes, they are not meant to drive a contractor work breakdown structure (WBS). Offerors are encouraged to develop their own WBS that demonstrates innovative approaches to most advantageously satisfy the government’s requirements.
Outcomes are task order requirements that must be captured in the Contractor Performance Work Statement (CPWS). Thresholds which identify a specific performance level must also be incorporated into the CPWS. Desired attributes are both quantifiable and non-quantifiable performance goals/objectives that the Government would like to achieve, and are provided as assistance in developing proposal/CPWS performance thresholds and service summary items. Constraints are limitations on the contractor’s technical or management approach/solution. The contractor's approach/solution must comply with the constraints. Government identified thresholds for EITS performance can be found in Enclosure 6, EITS Key Performance Indicators.
All activities conducted on this task order must adhere to the special requirements identified in the contract-level SOO (Contract Attachment J-1). In the event of a conflict between Section 5.0 of the SOO and the CPWS, Section 5.0 of the SOO takes precedence.
Exhibit 1. SSIs and Weights Applicable to This Task Order
| SSI # |
| Title |
| Description |
| Performance Threshold |
UNACCEPABLE
Performance Threshold
ACCEPTABLE
Performance Threshold
OBJECTIVE
| Weight |
| Assessment Method |
| SSI 1 |
| Integration |
| Task order activities / requirements are coordinated / deconflicted with other task orders to meet negotiated schedules. Contract / Task order schedules provides a realistic performance baseline that allows for early identification and mitigation of risk. |
| The integrated master schedule (IMS) is not resource loaded and critical path does not identify external task order or contract dependencies. |
| The IMS is resource loaded but critical path does not identify external task order or contract dependencies. |
| The IMS is resource loaded and critical path identifies external task order and contract dependencies |
| 10% |
10 QPI
EVM Program Analyst: review of the task order schedule(s) and the IMS.
| QPI Score = 0 |
| QPI Score = 5 |
| QPI Score = 10 |
| SSI 2 |
| Small Business Utilization |
| On track to meet or exceed all goals established in the Small Business (SB) Participation and Commitment Plan. |
| Contractor fails to meet the SB goal in the SB Participation and Commitment Plan. |
| Contractor meets the SB goal, and meets greater than 25% but less than 50% of the SB subcategory goals in the SB Participation and Commitment Plan. |
| Contractor meets the SB goal and meets 50% or more of the SB subcategory goals in the SB Participation and Commitment Plan. |
| 5% |
5 QPI
COR: Review of Task Order 2000 – CDRL C012
| QPI Score = 0 |
| QPI Score = 2.5 |
| QPI Score = 5 |
| SSI 3 |
| Customer Satisfaction |
| ‘Customer’ is defined as any service provider or user of the products and services delivered under the task order. |
| Customer surveys result in product and service rating of 1.5 or less out of a possible 5.0. |
| Customer surveys result in product and service rating greater than 1.5 but less than 4.0 out of a possible 5.0. |
| Customer surveys result in product and service rating of 4.0 or higher out of a possible 5.0. |
| 5% |
COR: Customer Survey: twice annually prior to performance evaluations (mid and final)
| QPI Score = 0 |
| QPI Score = 2.5 |
| QPI Score = 5 |
| SSI 4 |
| CDRL, Proposal and Milestone Timeliness |
| CDRLs, proposals and milestones are delivered / accomplished in accordance with the agreed to timeline and specifications. |
| 85% or less of CDRLs proposals, and milestones are delivered or accomplished in accordance with agreed to time line and in accordance with SF1423, Data item Description (DID) and /or request for proposal specifications. |
| Greater than 85% but less than 95% of CDRLs proposals, and milestones are delivered or accomplished in accordance with agreed to time line and in accordance with SF1423, DID, and / or request for proposal specifications. |
| 95% or more of CDRLs proposals, and milestones are delivered or accomplished in accordance with agreed to time line and in accordance with SF1423, DID, and / or request for proposal specifications. |
| 5% |
Data manager: 100% Inspection: CDRL / Proposal delivery / milestone accomplishment record.
| QPI Score = 0 |
| QPI Score = 2.5 |
| QPI Score = 5 |
| SSI 5 – SSI n |
| Technical Performance 5 – n |
| * to be specified in the Task Order Service Summary Item Table. |
| * |
| * |
| * |
| 75% |
75 QPI
| Sep 1, 2016 | FOR OFFICIAL USE ONLY | Page 8 |
| 5.1 | Task Order Administration |
5.1.1 Description
Successfully integrate and coordinate all activity necessary to efficiently execute the task order.
| 5.1.2 | Outcomes |
| 5.1.2.1 | An Integrated Program Management Report (IPMR) that contains data for measuring cost and schedule performance for the Enterprise Information Technology Services task order. The Enterprise Information Technology Services IPMR required formats are: |
· Format 1 defines cost and schedule performance data by product oriented Work Breakdown Structure (WBS). Format 1 data will be provided at WBS level 4.
· Format 2 defines cost and schedule performance data by the contractor's organizational structure (e.g., Functional or Integrated Product Team (IPT)).
· Format 3 defines changes to the Performance Measurement Baseline (PMB).
· Format 4 defines staffing forecasts.
· Format 5 is a narrative report used to provide the required analysis of data contained in Formats 1-4 and 6.
· Format 6 defines and contains the contractors Integrated Master Schedule (IMS).
· Format 7 defines the time-phased historical and forecast cost submission.
CDRL C001: TO 3000: Integrated Program Management Report
5.1.2.2 Delivery of the contractor acquired property (CAP) for the EITS task order.
CDRL C002: TO 3000: Interim Government Property Inventory Report
5.1.2.3 Quarterly EITS task order management report consisting of significant accomplishments, issues, concerns, risks, and self-assessment of technical performance.
CDRL C003: TO 3000: Task Order Status Report MILESTONE: Initial Baseline Review
| 5.1.2.4 | Delivery of task order modification proposals. [Note: costs associated with future task order modification proposals should not be proposed in response to this SOO statement and should not be included in the Task Order Administration algorithm requested under Subfactor 1a. This SOO statement is for future cost collection purposes, if modification proposal preparation costs are a direct charge to the contract.] |
| 5.1.3 | Desired Attributes |
a. Situational awareness of task order activities.
b. Frequent and open communication.
5.1.4 Constraints
None.
| 5.2 | Portfolio Management Services |
| 5.2.1 | Description |
Provide IT portfolio management focusing on the portfolio of services delivered by the MDA/CIO for use in the execution of daily operations supporting the MDA. Specific functions within this objective include: Requirements Management, Service Level Reporting, Service Metrics, Governance (Change, Configuration, and Release Management), Licensing, Technology Refresh, Enterprise Architecture, IT Service Management (ITSM), and the development, management, and reporting of performance metrics. Outputs of Portfolio Management Services will provide data used in the development of external Agency reports (i.e., CPIC, investment capital forecasting) and aid the MDA/CIO in coordinating with internal MDA customers on existing and future services/capabilities.
| 5.2.2 | Outcomes |
| 5.2.2.1 | A requirements management and requirements engagement methodology that facilitates an integrated requirements review process that enables an ability to ensure the most effective and efficient utilization of existing infrastructure, provides transparency into the requirements pipeline allowing informed prioritization of activities to manage demand on Enterprise IT Services. Assume approximately 20-25 emerging requirement per month. |
CDRL C010: Operational Support Documents: Capacity Management Plan
| 5.2.2.2 | Execute using standards-based processes that integrate requirements management, design lifecycle, implementation/change management and configuration management across disparate technical architectures. |
| 5.2.2.3 | Transparent IT Service Economics leveraging a constantly improving Service Portfolio (Service Catalog, Service Pipeline, etc.) that describes Services in a manner meaningful to the MDA IT User Community and supports ease of IT Service ordering, provisioning, and costing which enables accurate and timely updates of Service Level Agreements and chargeback/showback reporting for each customer organization relevant to standard and fee-for-service IT requirements. |
CDRL C008: Operational Support Documents: MDA CIO Service Portfolio CDRL C011: Quarterly Reports: [Insert Document Title]: [Insert FYQ] CDRL C012: Operational Support Documents: MDA CIO Service Pipeline CDRL C013: Chargeback Showback Metrics: [Insert Month Ending]
5.2.2.4 Oversight and governance of key processes that ensure continuous improvement in evolving an Enterprise IT Organization with a true service orientation that aligns with the MDA Organization and Mission; demonstrating IT cost control wherever possible, improving the quality of end-to-end IT services, improving agility in responding to business and mission needs, focused on customer results and recommending prioritization of actions and IT expenditures based on business and mission priorities.
CDRL C007: Operational Support Documents: MDA Enterprise Strategic Plan
5.2.2.5 Accurate system, segment, or enterprise DoDAF representations of all EITS managed networks, systems, and applications supporting the needs of the Agency and BMDS, tailored to the form, fit, and function required to accurately represent Enterprise IT service support to the key lines of business within MDA.
CDRL C005: Engineering Documentation CDRL C006: Operational Support Documents: [Insert Document Title] (assume 14-20 annually)
| 5.2.2.6 | Execution of the program-wide standards-based change, configuration, and release management processes across disparate work activities affecting the Enterprise networks. |
| 5.2.2.7 | Conformance with program-wide Configuration Management/System Engineering Processes to ensure attributes of various systems that lead to an integrated technical baseline. |
| 5.2.2.8 | Efficient use and management of commercial-off-the-shelf software and hardware licensing and maintenance agreements enabling reductions in Agency operating expenses for IT software and equipment. |
| 5.2.2.8.1 | Fully compliant licensing for all software products and services. |
| 5.2.2.8.2 | Efficiencies in software licensing. |
CDRL C004: Software Accountability and Maintenance Report
| 5.2.2.8.3 | Efficiencies in hardware maintenance contracts. |
| 5.2.2.9 | An integrated approach to operating the government’s IT investments that provides for the continuous identification, selection, control, life-cycle management, and evaluation of the IT investments in a structured process resulting in a systematic method maximizing the return of IT investments. |
CDRL C009: Operational Support Documents: Technology Refresh Plan
| 5.2.2.10 | Optimization of processes (both manual and automated) across the Enterprise into an integrated environment that is responsive to change and supportive of the delivery of Enterprise IT services to MDA RDT&E elements and functions. |
| 5.2.2.11 | Implementation and execution of online (e.g., digital dashboard) forward schedule of change demonstrating positive change and configuration control to ensure the continuous delivery of situational awareness for all IRES managed systems and services. |
| 5.2.3 | Desired Attributes |
a. Achieve measurable efficiencies in IT service delivery.
b. Performance measures that demonstrate efficiencies in the delivery of product and services.
c. Identification and tracking of cost control initiatives implemented at the portfolio level.
d. Reliable lifecycle management and capacity planning projections that can be used for management decisions.
e. Realistic performance baselines that facilitates early identification and mitigation of risk; baseline integrity is maintained and changes are fully documented.
f. Relevant, accurate architecture documentation compliant with DoDAF v. 2.x.
g. Accurate data supporting fee-for-service chargeback to customers.
| 5.2.4 | Constraints |
| 5.2.4.1 | Comply with CIO boards, processes, and procedures. |
| 5.2.4.2 | Service Level Agreements are ratified between government customers and the government’s IT Policy Planning and Portfolio management office (MDA/ICTP). |
| 5.3 | Cybersecurity Services |
| 5.3.1 | Description |
Provide cybersecurity services including the execution of the MDA’s Tier 2 Certified Network Defense Service Provider (CNDSP), referred to as the MDA Computer Emergency Response Team (CERT). Responsibilities of the CERT include the protection, detection, response and sustainment of CNDSP program requirements across subordinate Tier 3 enclaves. Included in the cybersecurity services objective are the functions of boundary protection, Tier 3 cybersecurity, vulnerability management, and Cross-Domain Solutions (CDS). CDS activities encompass the design, development, implementation, accreditation, and sustainment of dataguard solutions necessary to enable cross-domain interoperability that support information sharing for operations, testing, exercises, experiments, wargames, and training. Cybersecurity operations also include the development/update of Risk Management Framework documentation supporting the certification and accreditation process.
| 5.3.2 | Outcomes |
| 5.3.2.1 | Continued certification of the MDA CERT as a Tier 2 CNDSP. Assume 12 coordinated cybersecurity penetration tests per year on network enclaves varying is size between 50 and 500 devices; government will specify specific enclave. |
| 5.3.2.2 | Manage Enterprise-wide cybersecurity architecture; incorporating ADMIN/Genser, RDT&E, and mission support systems. |
CDRL C015: [Insert System Name]: Certification and Accreditation Documentation (assume 15 to 20 annually)
5.3.2.3 A cyber incident handling process that: (1) maintains a robust detection capability; (2) ensures the timely reporting of cyber incidents; (3) effectively contains events and incidents and isolate information systems to minimize any damage or impact to the MIE; (4) safely acquires and preserves the integrity of cyber incident data; (5) ensures the effective coordination and communication of cyber incident information through appropriate channels; (6) provides an effective and comprehensive response; (7) identifies lessons learned to help improve infrastructure component protection strategies; and (8) understands patterns of activity and trends to characterize the threat and direct protective and defensive strategies.
CDRL C014: Cyber Incident Handling Process: [FY]
| 5.3.2.4 | Controlled flows of information into and out of the internal network enclaves and protection from malicious insiders, external entities with malicious intent, intentional or inadvertent denial of service attacks, and unauthorized access or disclosure of sensitive information. |
| 5.3.2.5 | Delivery of compliant IT Security Services that enables continuous assessment of current risk posture and provides actionable recommendations that improve the computer network defense of the Data Center Infrastructure in compliance with DoD regulations and Information Security Standards. |
| 5.3.2.6 | Automated access or transfer of information between two or more differing security domains (i.e., CDS) for the timely sharing of authorized information critical to the success of the BMDS mission. |
| 5.3.2.7 | Standards-based approach to providing integrated cybersecurity that incorporates risk across all mission areas and achieves efficiencies in mission execution. |
| 5.3.2.8 | Cybersecurity metrics that assist MDA organizations: (1) verify that security controls are in place and compliant; (2) identify strengths and weaknesses in security posture; (3) show trends and forecasts to better prepare the organization to handle future incidents; (4) raise the level of security awareness within the organization; and (5) facilitate strategic decision making by government management. |
| 5.3.3 | Desired Attributes |
a. Escalation of cyber-attack awareness within five minutes of identification.
b. Continued certification of the MDA CERT as a Tier 2 CNDSP.
c. Continuous updates of POA&M for all systems/enclaves with timely mitigation for all Category 1 findings.
d. Verified, validated, and approved cross domain solutions for use in BMDS mission support and testing.
| 5.3.4 | Constraints |
| 5.3.4.1 | The MDA CERT must ensure continuity of its protection, detection, response and sustainment of MDA networks through the use of split-based operations housed in both the MDIOC (Colorado Springs, CO) and the Von Braun Complex (Huntsville, AL). |
| 5.3.4.2 | Maintain compliance, readiness, and ability to pass external cybersecurity evaluations and inspections. |
| 5.3.4.3 | Cybersecurity services will be conducted using the Defense Information Systems Agency provided Assured Compliance Assessment Solution (ACAS) and Host Based Security System (HBSS). |
| 5.4 | Data Center Services |
| 5.4.1 | Description |
Provide data center capabilities that incorporate all of the characteristics of Cloud Computing (on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service) in the following service models: Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) through a Community Cloud deployment model supporting the Research, Development, and Testing of current and future BMDS capabilities. Data Center Services includes the provisioning and management of consolidated storage infrastructure, centralized backup and restore, and situational awareness of all delivered IT services. Data Center Services also provides data management services to subscribed MDA customers as well as the configuration management of floor space and rack elevation assignments through a contractor-defined reservation process. Data Center Services oversees authorized maintenance activities, configuration freeze control/Mission Assurance, and the coordination of environment control and management functions to include capacity planning and requirements forecasting of facility infrastructure needs.
| 5.4.2 | Outcomes |
| 5.4.2.1 | Consolidated and centralized network and compute solutions capable of rapidly delivering secure IT resources supporting multiple tenants concurrently supporting BMDS test and development as well as production IT Services in support of MDA missions. |
| 5.4.2.2 | Delivery of virtualized computing resources as a service that enables user self-service ordering capability for test and development environments that can be ordered, by authorized users, online and rapidly provisioned via automated and semi-automated backend systems. MDA IT consumers should be able to acquire virtualized computing resources for short or long term durations. The Data Center Service should package hosting, networking, security, and connectivity together as a service and be integrated with portfolio management processes enabling chargeback/showback in Service Level Agreements and support the delivery of capability to the respective Operations and Sustainment Community. Assume 60 to 96 requests per year. |
| 5.4.2.3 | Mature private cloud services for RDT&E and business operations functions, employing all the key principles of cloud. |
| 5.4.2.4 | Economies of scale for the MDA Enterprise through: (1) increased productivity with fewer technical staff; (2) reduced spending on technology infrastructure; (3) streamlined processes; (4) reduced capital investments; (5) improved workforce accessibility; (6) rapid provisioning of IT service requests; (7) license reduction; and (8) improved flexibility. |
| 5.4.2.5 | A Data Management Plan to include a data governance framework, logical data architecture and data dictionary and the ability to demonstrate an approach to coherently manage data as a program wide asset that can provide a Business Intelligence capability for analytical and reporting purposes to be mined for relevant prime contractor and Government program management decision-making. |
CDRL C018: Operational Support Documents: Data Management Plan
| 5.4.2.6 | Sophisticated capabilities for Data Center Infrastructure Management which provides access to accurate, real-time information about critical systems in the Data Centers. Provide total network services to include monitoring bandwidth and ensuring secure IP transport from data centers to major MDA locations. |
| 5.4.2.7 | Realization of the DoD goal to obtain efficiencies while maintaining mission effectiveness through Data Center Consolidation to achieve the effective and optimized use of the MDA’s approved Special Purpose Processing Node (SPPN) Data Centers, increased security, reduced attack surface, single security architecture, continuous monitoring IAW DODI 8510, consistent IT architecture, consolidated IT investment to gain Enterprise-level efficiencies and a simplified, standardized and centralized IT Infrastructure capable of supporting the various mission domains within the MDA. |
| 5.4.2.8 | Compliant asset tracking capability to track assets within the data centers from initial receipt to final disposition and maintain an auditable inventory of managed property and assets. |
| 5.4.3 | Desired Attributes |
a. Tiered, self-service provisioning of compute resources for test and development
b. Server availability: 99.99%
c. Operating system and network provisioning within 5 days of request
d. Integration of provisioning with financial management subsystems for chargeback
e. Consistent, 100% auditable asset tracking reporting capability, tied to procurement subsystems
5.4.4 Constraints
Data Center services to be provided from MDA data centers in Huntsville and Colorado Springs.
| 5.5 | Customer Support Services |
| 5.5.1 | Description |
Provide customer support services inclusive of service desk operations, touch-labor client support, COMSEC account management, print services, conference room A/V maintenance, client application software, conference and event support, and employee equipment moves at the MDIOC.
| 5.5.2 | Outcomes |
| 5.5.2.1 | Standardized, integrated processes providing comprehensive access into work performed by the IT services organization with cognizance of all activities impacting the delivery of IT, R&D, and MDIOC facility capabilities; functions as the single entry-point for customer requirements and assistance. |
| 5.5.2.2 | Knowledge base maintenance and development enabling first call resolution. |
| 5.5.2.3 | Tier-0 knowledge articles enabling customer self-help capabilities. |
| 5.5.2.4 | Managed customer experience lifecycle ensuring that all requests are handled in accordance with incident response and service level objectives with communication out to customers with defined service level expectations. |
| 5.5.2.5 | Standards-based approach to providing client support management, maintenance, and sustainment across all mission areas to achieve efficiencies in mission execution. |
| 5.5.2.6 | MDA COMSEC accounts maintained and managed through the receipt, destruction, and accountability of both electronic and hard copy keying material. |
| 5.5.2.7 | Enterprise-wide print solutions for both classified and unclassified network environments monitored continually to prevent outage or disruption of services. |
| 5.5.2.8 | Managed and maintained non-VTC conference room audio/visual equipment. |
| 5.5.2.9 | Consistent configuration management, accountability, and sustainment using automated tools and services providing accurate baselines of all deployed client systems. |
| 5.5.2.10 | Technology support services to remote locations and significant MDA events executed at a high priority based on mission requirements. |
| 5.5.2.11 | Accurate IT asset (hardware and software) accountability with traceability to the using customer. |
| 5.5.3 | Desired Attributes |
a. Incident Response (Mean Time to Repair (MTTR)): Critical, 6 hours; High, 1 Day; Medium, 2 Days; Low, 3 Days
b. Maintain continuous 100% inventory of all Controlled Cryptographic Item (CCI) and keying material with no loss or compromise
c. Asset records (for property and portfolio purposes) maintained accurate to 98%
| 5.5.4 | Constraints |
| 5.5.4.1 | MDA COMSEC account management is subject to NSA policy and annual audits are expected from NSA for all four accounts across MDA. |
| 5.5.4.2 | COMSEC material and associated database maintained in accordance with NSA/CSS Policy Manual 3-16 and NSTISSI 4005. |
| 5.5.4.3 | Incident Response (Mean Time to Repair (MTTR)): Critical, 1 Day; High, 2 Days; Medium, 3 Days; Low, 4 Days. Incident severity definitions: |
| 5.5.4.3.1 | Critical designates the loss of a critical service or component that has large user impact and/or impact to a mission critical asset of a current MDA/Combatant Commander (CCMD) activity (test, exercise, or operational). |
| 5.5.4.3.2 | High is the loss or degradation of a service/component impacting a single functional area or effort. Although affecting, this level of severity does not prevent scheduled test, exercise, or operational activities from proceeding. |
| 5.5.4.3.3 | Medium is the loss or degradation of a service/component with isolated or no user impact. |
| 5.5.4.3.4 | Low is the loss or degradation of a service/component has impact to a single user and/or with no major impact. |
| 5.5.4.4 | Support to Agency Executives is expected 12 hours per day, Monday through Friday, with escalation and recall of staff in support of critical and high priority IT events during off hours. Response times of less than thirty (30) minutes to initial contact, and 4 hours until final repair completion. This time includes any necessary prior Government coordination for any repair. Designated Executive list is estimated to be 90 individuals distributed as follows: NCR-35, HSV-35, DHL-10, other-10. |
| 5.5.4.5 | COMSEC Service Level Agreements: Colorado Springs (1 FTE), Huntsville (2 FTE), and Alaska (1 FTE) |
| 5.6 | Network Administration |
| 5.6.1 | Description |
EITS Network Administration Services provides design and technical management service in support of the MDA Unclassified and Classified Network Transport Services (UNET & CNET) that provide connectivity between MDA organizations and between MDA and the greater DoD community through Department of Defense Information Network (DoDIN) Service Delivery Points. EITS Network Administrations Services provides comprehensive management and technical support for MDA WAN, MAN, and LAN communications and data distribution to MDA’s principal sites, major sites, and all authorized remote site locations. Network Administration Services provides management of the WAN and MAN telecommunications common carrier product interfaces and coordinates with long-haul and local exchange carriers and services providers to ensure network reliability is maintained in support of Agency missions. Network Administration Services provides cable plant management and network distribution in all LAN environment locations (reference GFI, para. 7) as well as the distribution of precision timing and video cable circuits. Network Administration Services manages the interfaces to external DoD networks and all network enclaves supported by the common transport services and enforces network security controls IAW DoD policy and standards.
| 5.6.2 | Outcomes |
| 5.6.2.1 | Network normalization to reduce, standardize, and consolidate MDA’s current system of disparate networks, processing, and storage infrastructures, which are difficult to protect and defend. |
| 5.6.2.2 | Effective deployment and use of Enterprise architectures to enforce common standards, policies and management processes enabling proactive defense of networks and data. |
| 5.6.2.3 | Network architecture that is aligned with DoD’s Strategy for Implementing the Joint Information Environment; Network Administration Services improves upon the MDA’s established Single Security Architecture which collapses network security boundaries and reduces the Agency’s external attack surface; enables improved containment and reaction to cyber-attack, and standardized management, operational and technical security controls of the network supporting Administrative and General Systems as well as supporting RDT&E connectivity requirements. |
| 5.6.2.4 | Accurate IT asset tracking of associated hardware and software supporting O&M, Capital Planning and Investment Control for recapitalization planning, Service Level Agreement derivation, and chargeback/showback reporting. |
| 5.6.2.5 | Reliable technical baseline of the networks and associated interfaces. |
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .