Attachment 0002-Performance Work Statement_Task Order 01_Castle Keep.pdf
PDF 340 KB Posted
- Attached to
- Castle Keep Implementation and Sustainment Federal contract opportunity
- Solicitation number
- W52P1J-22-R-0049
View the file
Other files for this federal contract opportunity
Show all 17
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Defensive Cyberspace Operations (DCO)
Castle Keep Implementation Task Order 01
7 June 2022
CASTLE KEEP (CK)
TASK ORDER 01 - PERFORMANCE WORK
STATEMENT (PWS)
1. General
1.1. SCOPE
No change to Base PWS.
1.2. Background
1.3. Contract Management.
1.4. Period of Performance.
The Period of Performance for Task Order 01 will be twelve (12) months in length.
1.5. Place of Performance.
1.6. Travel.
As designated, travel shall be used to satisfy the requirements of this Task Order. Travel is an Other Direct Cost (ODC). ODC’s are on a cost-reimbursable basis. Travel shall be in coordination with the Government and rates should be comparable to the Joint Travel Regulation (JTR) and reimbursable as outlined in the Federal Acquisition Regulations (FAR) Part 31.205-46.
1.6.1. Contractor/subcontractor personnel shall be required to travel to Government Sites for program support to include CONUS and OCONUS sites. Based on Government direction, the contractor may be required to travel within the National Capital Region; travel is expected to be required once per quarter and require 2-4 contractor personnel to participate in coordination efforts with other stakeholders.
1.6.2. All travel requires Government approval/authorization and notification to the COR/KO. The contractor shall perform temporary duty (TDY) non-local travel (both CONUS and OCONUS), as required by the contract and as stated in individual task orders during the performance of this PWS. Individual task orders will clearly define known requirements. The contractor shall submit all travel requests, security clearance information and need-to-know certification to the Government COR for review and KO for approval, at least two (2) weeks prior to the start date of the required travel.
Emergency (last minute) travel requirements shall be coordinated as above by telephone or fax, if necessary. All travel costs shall be charged to the reimbursable Travel CLIN and contractor shall verify sufficient funds are loaded in that CLIN when requesting approvals. All allowable costs will be in accordance with Joint Travel Regulation (JTR) and reimbursable as outlined in the Federal Acquisition Regulations (FAR) Part 31.205-46.
1.6.3. Travel to other government facilities or other contractor facilities may be required. The government will monitor each travel event. The contractor will manage the funds allocated for travel on each awarded Task Order.
1.6.4. Anticipated Travel: All TDY supports the coordination and communication of system requirements in support of CASTLE KEEP. Majority of travel is to the Pentagon to meet with the customer monthly/quarterly and periodically to Charlottesville, VA to the National Ground Intelligence Center (NGIC) to conduct technical exchanges with the Army Commercial Cloud Service Provider (AC2SP).
CONUS and OCONUS travel may be required for training and deployment of the system. However, the extent of travel will be identified in the individual task orders.
1.7. Security.
1.8. Type of Contract.
1.9. Quality Assurance.
1.10. Hours of Operation.
1.11. Staffing Requirements.
1.12. Government Networks and Communications Infrastructure.
1.13. Inherently Governmental Functions.
1.14. Conflict of Interest.
1.15. Personal Services.
1.16 Inspection and Acceptance.
2. APPLICABLE DOCUMENTS
3. REQUIREMENTS
The Government requires the following services in support of the continued development, fielding, and accreditation of its fully automated SSO management tool providing the ability to conduct continuing reviews of SCI security programs including oversight and evaluations. The Contractor shall incrementally deliver capabilities enabling the management of, and conduct training programs for SCI security officials. The resulting system shall store, share, audit and query all associated records and reports. The contractor shall support the development, testing, accreditation, fielding, and sustainment of the CASTLE KEEP Initial Operational Capability (IOC) in FY22 and Full Operational Capability (FOC) in FY23.
IOC is defined as the following:
Release of Increment 1 baseline production environment on JWICS within the Army MI Cloud provided virtual private cloud architecture.
Release of Increment 1 baseline application software accessible by the Army SSO community personnel on JWICS for operational use; incremental delivery of application software workflow and capabilities as directed by the Government.
An Authority to Operate (ATO) for the production environment and application software is issued by the Department of the Army (Intelligence) – Information Management (DAMI-IM) Authorizing Official.
Limited connectivity with external information management systems; data is primarily input by the Army SSO community and not fully ingested nor shared with external data systems.
FOC is defined as the following:
Release of required Increment 1 baseline production on JWICS with the Army MI Cloud provided virtual private cloud architecture.
Release of all Increment 1 baseline application software accessible by the Army SSO community personnel on JWICS for operational use; full delivery of application software workflow and capabilities as directed by the Government for user management, physical security, personnel security, and information security workflows.
An ATO for the production environment and application software is issued by the DAMI- IM Authorizing Official.
Connectivity and data ingestion with designated external information management systems.
3.1. Specific Performance Requirements. Below are the system performance requirements for CASTLE KEEP. The contractor shall ensure that all the performance requirements are traceable to the final product baseline, and that the product baseline is tested and acceptable to the Government prior to the ATO decision.
3.1.1. Amazon C2S Cloud. CASTLE KEEP resides on the Amazon C2S cloud on JWICS, using standard IC ITE components to include the Accumulo database from the Apache Software Foundation as the basic building blocks for configuration of the system. The contractor shall use approved cloud services and applications to support more advancement in operations with Elastic Map Reduce (EMR), AWS autoscaling, and / or containerization with EMR to support multi-region balancing that would enhance resiliency (COOP) and long-term Army or potentially DoD user growth.
3.1.2. Accuracy and Validity. The data brought into the system shall be certified and tracked to the individual user to ensure correctness and pedigree of data. The system must not alter the original data placed in the data store but will need to manipulate copies of the data for indexing, tracking, and oversight purposes. The system shall conform to 500-27 Audit.xml technical requirements.
3.1.3. Timing. The system upon deployment shall achieve an online and availability rate of 98%.. The response time for transactions or queries should be comparable to existing Amazon C2S, Accumulo, and JWICS systems of comparable size and scope.
3.1.4. Capacity Limits. The system shall support over 2,100 different SCIF/TSCIFs that are located on Government installations and at Army contractor facilities. The system shall support approximately 5,000 users, of which approximately half will access the system daily. The total data storage requirement be approximately four terabytes and the throughput will be approximately 50,000 transactions per day. Additionally, the system shall be able to store personnel security records for approximately 1.2 million personnel. The vendor shall use a government directed technical collaboration environment as a means for managing configuration documentation and storage of CASTLE KEEP’s technical and acquisition documentation. The contractor shall provide Government access to their configuration and storage system.
3.1.5. Software Environment. For CASTLE KEEP, the contractor shall use the
Java programming language for all major components, but will be permitted to compliment these primary areas where suitable with additional scripting languages (e.g. JavaScript Object Notation (JSON), Linux shell, etc.) that may enhance user experience, setup and/or maintenance procedures. The contractor shall ensure that primary areas for the technical solution will utilize the AWS framework with core services including EC2 for computing power along with EBS and S3 actively used data storage, Glacier for system recovery back-ups, and Cloud Watch for resource monitoring. All systems shall be required to comply with Army Cloud Adoption policies that may require integration, consideration for further software packages or services as the platform continues to mature.
Additional services and third-party Amazon extensions may be proposed by the contractor to the Army but would be an option to be considered by the Government. The contractor shall ensure code will be written in Java to allow cross-platform data sharing in accordance with DNI and DOD standards.
3.1.6. Failure Contingencies. Current practices are primarily hardcopy in nature with paper files kept at each location. Hardcopy files will be kept until the system has fully transitioned to operational status. Once all of the hardcopy data has been migrated to CASTLE KEEP, the requirement for paper files will be removed. Since CASTLE KEEP will reside on Amazon Web Services, the need for backup and Continuity of Operations (COOP) is not necessary; it is inherent in the Amazon architecture. The only concern will be inadvertent loss of data, so to minimize data loss there will be a periodic (daily or weekly) cold backup of all data into C2S components, which will ensure that no critical data will be lost.
3.1.7. Design Considerations. The system will leverage the DNI lead IC ITE C2S platform. The Government sponsor within the JWICS domain oversees this AWS based cloud with the capability to provide systems with the necessary infrastructure components for computing power and data storage, along with security boundaries. Additional corresponding elements are to be leveraged from the IC ITE and Army G-2 provided service portfolios to support user authentication, information security management, audit, and monitoring.
Selection of the C2S platform drives consistency with the broader IC ITE initiative. Continued growth and standard enforcement will reduce the burden for long-term operation of this capability from equipment management through information assurance (IA) such that each responsibility may be aligned and delivered as layers in compliance with common standards.
3.1.8. System Functions. Key system capabilities will involve information consolidation, single point portal access available to all SSO personnel, workflow process management, audit traceability, and reporting (both standard reoccurring and ad-hoc). While workflow is a core component of the system, it is truly through oversight that it becomes empowered through centralization and reporting of key SSO functions - to include supporting documentation - to uphold adherence to strict security standards across all sites and personnel. The system itself will support up to 5000 individual users in total, with concurrent usage of up to 500 users. Availability for system users must be 24 hours a day, 7 days a week throughout the entirety of the year. Standard reoccurring scheduled maintenance windows with advance notice will be provided to the user community. While users may have access to the system around the clock, operations and maintenance along with trouble support staff dedicated to the system may be centralized and available for response within 48 hours of any incident occurrence.
3.1.9. Configuration Management. The contractor shall adhere to established software development standards and guidelines as prescribed by a minimum level 3 Capability Maturity Model (CMM), a minimum level 3 Capability Maturity Model Integration (CMMI), Institute of Electrical and Electronics Engineers (IEEE), and International Organization for Standardization (ISO). The contractor shall follow industry best practice configuration and change management policies developed in accordance with CMMI, IEEE and ISO; including creating and managing the CASTLE KEEP software, and managing baseline libraries. The contractor shall develop and maintain a Configuration Management Plan (CDRL A0007) for the duration of the contractor’s software development and integration efforts under the resulting contract.
3.1.9.1. The contractor shall develop, test and integrate software utilizing CMMI or equivalent practices, processes and services. The contractor shall maintain and track the status of each requirement using use a government directed technical collaboration environment through release, updating software baselines after reviews and/or testing and releasing updated baselines to the field.
3.1.9.2. The contractor shall use a government directed technical collaboration environment to create/update/maintain release packages in accordance with industry best practice configuration and change management policies and procedures. The contractor shall perform or participate in periodic and scheduled audits of the software baselines to verify that they conform to the documentation that defines them. The contractor shall establish and use a standard source code repository for source code management in accordance with industry best practices. The contractor shall also provide notification of implemented changes to the initiator of the change request/problem report and to the users of the system.
3.1.9.3. The contractor shall create, update, and maintain release packages for each block or version release in accordance with industry best practices.
3.1.9.4. The contractor shall maintain application/program records, such as preparation, update, coordination, and maintaining system, user, and process documentation. The contractor shall provide support to HQDA G-2 project personnel to meet their process and documentation needs in accordance with organizational policies and standards. The contractor shall provide support in the development of templates for all required process support documentation including charts and reports as required.
3.1.10. Personnel Qualifications:
3.2. The overall objective of this effort is to achieve program goals established by the Government for the Contractor to provide comprehensive information technology support for software development, software sustainment, system accreditation, system integration with the Army MI Cloud on the JWICS network utilizing Amazon Web Services (AWS), and system sustainment and maintenance. The Government will define specific requirements for required services in a Task Order PWS.
3.2.1. Objective 1: Software Development. The Contractor shall provide comprehensive information technology support continued development of the CASTLE KEEP system. The required support includes, but is not limited to the following:
3.2.1.1. The Contractor shall develop, test, and integrate software enhancements as identified/validated by the SSO. These activities include, but are not limited to the following:
JWICS Test, Integration, and Production environments NIPR Development and Test environments Commercial Cloud
Hosted on the Army MI Cloud, National Ground Intelligence Center (NGIC)
Cloud tools provided by Amazon Web Services (AWS) Database Management Query and Reports Workflow Management
Account Management Training Support
3.2.1.2. The Contractor shall utilize the following tools for all software development, deployment, and integration. Additional tools may be employed once validated and approved for use by the SSO.
Java Language Load Balancing (Distribution of traffic across instances) Apache Web (Frontend angular web application) Jboss EAP (Backend REST services, Application Server) Apache Accumulo/Zookeeper (Database) Postgres (User Management System) Message Queuing
Hadoop Storage FIPS 140-2 Compliant Encryption Auto Scaling (System Capacity Adjustment) 500-27 Compliant Auditing Role Based Access Management
3.2.1.3. Functional Area System Functions. The contractor shall integrate software enhancements as identified and validated by the Government for system functionality for the Functional Area Systems. Before validation of a new enhancement, the contractor shall provide an assessment to the Government for the cost, labor categories, labor hours, scope, and performance for the new enhancement to the Government. Prior to the beginning of work on new enhancements, the Government will approve and prioritize all new requirements through the Change Configuration Board
(CCB).
3.2.1.4. New Functional Area System Functions. The contractor shall integrate software enhancements as identified and validated by the Government for system functionality for newly identified requirements.
Before validation of a new enhancement, the contractor shall provide an assessment for the cost, scope, and level of performance for the new enhancement to the Government. Prior to the beginning of work on new enhancements, the Government will approve and prioritize all new requirements through the CCB.
3.2.2. Objective 2: System Testing and Fielding. The Contractor shall support the IOC and FOC implementation of the application for testing with the army SSO and designated testers to review user interface and workflow functionality and confirm system requirements and concept of operations before fielding across the Army. The contractor shall support Army wide implementation and assist in identifying and resolving system issues to minimize impact to SSO daily operations.
3.2.2.1. IOC and FOC. The contractor shall support IOC and FOC implementation with HQDA G-2 SSO and designated users on JWICS prior to fielding across the Army. The contractor shall monitor use during IOC implementation and will identify and report to the Government all new requirements and/or issues to maintain or enhance system functionality for FOC; new requirements will be approved and prioritize by the government through the CCB process before any work can begin by the contractor.
3.2.2.2. System Testing with HQDA G-2 SSO. The contractor shall test and validate the CASTLE KEEP application and environment software prior to fielding on JWICS in a production environment to ensure system functionality and integrity.
3.2.2.3. System Fielding. Upon completion of application testing, the contractor shall support system fielding across the army SSO community based on the fielding plan by the Army. System fielding may require the contractor to travel, train, and familiarize the system to Army components. The Government will identify and prioritize the units to begin using CASTLE KEEP. The contractor will assist with establishing accounts, allowing access to training materials, and provide support to ensure the system is operational for all Army components.
3.2.2.4. Training Support. The contractor shall provide new
equipment training to system users for fielding. This includes at a minimum, but is not limited to, system overview, system management, user management, workflow functionality, additional functionality as identified the Government.
3.2.2.5. Technical Guide and Quick Start Guide. The contractor shall maintain a Technical Guide and Quick Start Guide easily accessible in CASTLE KEEP for Army SSO personnel.
3.2.2.6. Sustainment. The contractor shall provide sustainment support for IOC and FOC capabilities and ramp up to provide Tier 1 through Tier 3 support as required.
Tier Level Description
Tier I Contractor has initial contact with the customer, has basic technical knowledge of products and processes supported, gathers customer information, determines the underlying issue through analysis and attempts to resolve the issue efficiently and effectively. If the Tier I is not able to resolve an issue, a tracking ticket may be opened and the issue is escalated to the appropriate Tier II contact.
Tier II Contractor has more experience and technical knowledge of products and processes supported and can address and resolve more complex issues. Contractor analyzes and attempts to resolve the issues efficiently and effectively. If the Tier II is not able to resolve an issue it is escalated to the appropriate Tier III contact.
Tier III Contractor has specialized experience and technical knowledge of the product or process supported and is able to analyze and resolve difficult and complex IT issues. Contractor resolves the specific IT issue or calls upon industry or outside certified IT support to resolve the issue.
3.2.3. Objective 3: CASTLE KEEP Accreditation Support. The Contractor shall provide comprehensive information technology support required to achieve and maintain system accreditation on JWICS (Authority to Operate). The contractor shall coordinate accreditation activities with the CASTLE KEEP Information System Security Manager (ISSM) and designated Government Security Control Assessor (SCA) to ensure the system and enhancements are incorporated into the Risk Management Framework (RMF) artifacts to achieve and maintain an Authority to Operate (ATO) on JWICS (CDRL A0008)
3.2.3.1. The contractor shall provide senior-level Information Technology / Cyber Security support to ensure CASTLE KEEP compliance with Federal, DoD, Department of the Army (DA) and Joint Security Implementation Guide (JSIG) Cybersecurity / Information Assurance policies. Ensuring the rigorous application of cybersecurity security/information assurance policies, principles, and practices.
3.2.3.2. The Contractor shall perform technical, analytical, and advisory functions pertinent to the CASTLE KEEP system, ensuring it is in compliance with higher authority cyber security policies and guidelines.
3.2.3.3. The Contractor shall conduct threat and vulnerability assessments to access risks and determine effective corrective measures;
reviewing and evaluating the security impact of system changes. The contractor shall maintain and update system security controls and ensure they are in compliance with higher authority cyber security requirements.
3.2.3.4. The Contractor shall be responsible for the development of accreditation documentation and the Risk Management Program for CASTLE KEEP. The Contractor shall coordinate with Government SMEs to ensure Authority to Operate (ATO) submission packages are complete
(CDRL A0016).
3.2.3.5. The Contractor shall be responsible for effectively coordinating Assessment and Authorization (A&A) activities associated with the CASTLE KEEP system to meet ATO milestone timeline requirements.
3.2.4. Objective 4: Software Assurance. The Contractor shall provide comprehensive information technology support required to ensure the CASTLE KEEP system remains current with applicable cyber security vulnerability alerts, developing patches and bug fixes as required. The contractor shall provide services including the creation of design specifications, systems engineering, and software maintenance of dataset and web-based applications.
3.2.4.1. Environmental Maintenance. The contractor shall maintain a development and test environment within the AC2SP Unclassified Commercial Cloud Service and a test, and production environment within the AC2SP Commercial Cloud Service environment on JWICS. The development environment will allow for sufficient release management, code repository, issue/requirements management, build automation, unit testing, and other functions typical of a mature software development effort.
The contractor shall document the baseline development environment, configuration control and audit (physical configuration audit/functional configuration audit) within the first thirty (30) days of the contract award and at the end of the performance period. The contractor shall design, implement, and maintain the development environment with the ability to develop multiple versions of software in an agile or other software development methodology.
3.2.4.2. Database Ingestion, Export, and Application Performance. The contractor shall maintain data ingestion, data normalization, and indexing infrastructure as necessary. The contractor shall recommend and implement (if approved by the Government) cost-effective solutions to maintain acceptable performance as CASTLE KEEP data volume and usage increases. The primary database for CASTLE KEEP is Accumulo.
3.2.4.3. Software Maintenance. The contractor shall provide software maintenance support through patch releases to correct defects against the operations system, maintain application security posture, and resolve performance issues for all system capabilities. The contractor shall provide a plan on how to maintain CASTLE KEEP. The plan shall address logistical support for the lifecycle of the tool. The contractor shall support the change control process for the validation and prioritization of software maintenance.
3.2.4.4. Functional Area System. The contractor shall maintain and support system functionality at a minimum for the following areas and any system enhancements/changes approved by the government.
3.2.4.4.1. Physical Security/Facilities Security Information.
3.2.4.4.2. Personnel Security Information.
3.2.4.4.3. Equipment Tracking Information.
3.2.4.4.4. SSO Training Information.
3.3.4.4.5. Oversight/Reporting/Metrics for Management of SSO
Functions.
3.3.4.4.6. User Management.
3.3.4.4.6. Input and Output. Data will be entered into the systems by various methods to include manual input by users, electronic interface with other systems, electronic forms and files, fillable forms, a: electornic interface, digitized electronic forms, or through fillable forms that are generated by CASTLE KEEP
3.2.5. Objective 5: External Data Integration. The contractor shall support external data integration with system identified by the Government.
Initially, the following external systems have been identified for consideration and integration:
Joint Personnel Adjudication System (JPAS)/Defense Information
System for Security (DISS), DMDC, NIPR Special Access Security Officer (SASO), DIA, JWICS Army Centralized Contracts and Security Portal (ACCS), Army, NIPR
SCATTERED CASTLES, IC, JWICS
3.2.6. Objective 6: DoD Intelligence Community Elements. The Government may require code sharing with other DoD IC elements.
3.3. Deliverables. The following types of deliverables may be required in subsequent work orders. These deliverables shall be delivered to the COR as a hard copy and electronic data files in the formats that are the current Industry standard for the following programs: Microsoft Word, Microsoft Excel, Adobe Acrobat, and AutoCAD. Specific Deliverable requirements and delivery schedule will be identified by the Government on each task order.
3.3.1. Post Award Conference/Periodic Progress Meetings. (CDRL A0002, A0003, A0005) The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with the Federal Acquisition Regulation (FAR) Part 42.5. The KO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance. At these meetings, the KO will apprise the contractor of how the Government views the contractor's performance and the contractor shall apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues and document in writing minutes of all meetings.
These meetings shall be at no additional cost to the Government.
3.3.2. Technical Information Exchange Meetings (TIEM). (CDRL A0002, A0003, A0005) Technical Information Exchange Meetings (TIEM) may be held during the period of performance. The Government will approve the TIEM frequency. TIEMs shall be scheduled to ensure that the Government is able to review progress and task completion at various times during the period of performance. The TIEM meeting/s shall be no longer than total of three hours and shall be held between the Contractor employee(s), Program Manager and/or Project Manager, Government technical POC, and the COR. Technical discussion between the Contractor employee(s) and the Government technical point of contact (POC) may occur informally. These TIEMs shall include, but not be limited to demonstrations by the Contractor of task completion, review of progress, and clarifications of requirements.
3.3.3. Product Demonstrations. (CDRL A0002, A0003, A0005) Product Demonstrations may be held during the period of performance. The Government will approve the Product Demonstration frequency, typically associating these events with product/code deliveries. Product Demonstrations shall be scheduled to ensure that the Government is able to review progress and assess system functionality at various times during the period of performance.
The Product Demonstrations meeting/s shall be no longer than total of three hours and shall be held between the Contractor employee(s), Program Manager and/or Project Manager, Government technical POC, and the COR.
3.3.4. Monthly Progress Report (MPR) (CDRL A0001). The Contractor shall prepare and deliver a Progress Report. The frequency of the Progress Report shall be determined in each individual Task Order and shall be based on factors such as project duration and complexity. The PR shall outline deliverables submitted, problems encountered, and schedule deviations.
3.3.5. Integrated Master Schedule (IMS) (CDRL A0004). The IMS shall be provided to the Government at the Post Award Conference (PAC) for each Task Order. The Government will review the presented materials to verify if they adequately address project specific plans and processes as defined in the Task Order PWS, that the project schedule is complete, accurate and realistic, and that any action items have been captured and assigned to a responsible party with a suspense date for closure.
3.3.6. Draft Project Schedule (CDRL A0004). The Contractor shall submit a draft project schedule for each Task Order. The Draft Project schedule shall be submitted no later than fifteen (15) calendar days after Task Order award and delivered in the current industry standard of Microsoft Word or Adobe Acrobat X (PDF) format to the KO, CS and the COR via electronic mail. The Draft Project schedule shall to include, as a minimum, the following information:
Requirements Validation In Progress Reviews Equipment and Material Procurement Installation Testing
3.3.7. Program Management Plan (CDRL A0011). The Program
Management Plan shall be prepared by the Contractor as a deliverable for specific Task Orders and will be identified in individual Task Orders. The plan shall provide technical, management, schedule, and cost data. It provides current information which is used to describe the approach, resources and needs of the contractor to perform the effort.
3.3.8. Software Test Plan and Test Description (CDRL A0008, A0009). The Test and Acceptance Plan shall be prepared by the Contractor as a deliverable for specific Task Orders and will be identified in individual Task Orders. This plan shall provide a description of the recommended acceptance testing procedures and processes associated with verifying that all Task Order requirements have been satisfied. The Contractor’s Test and Acceptance Plan will be approved by the Government prior to the start of work. This plan shall be completed no later than fifteen (15) calendar days after Task Order award and delivered in the current industry standard of Microsoft Word or Adobe Acrobat X (PDF) format to the KO, CS and the COR via electronic mail.
3.3.9. Software Test Report (CDRL A0010). The Software Test Report shall be prepared by the Contractor as a deliverable for specific Task Orders and will be identified in individual Task Orders. This report shall provide the result of all acceptance testing conducted by the Contractor in support of the associated Task Order. This plan shall be completed no later than fifteen (15) calendar days after test completion and delivered in the current industry standard of Microsoft Word or Adobe Acrobat X (PDF) format to the KO, CS and the COR via electronic mail.
3.3.10. Computer Software Product (CDRL A0006). The contractor shall provide the software source code for CASTLE KEEP Tool system.
3.3.11. Software Documentation (CDRLA0013, A0014, A0015, A0017, A0018, A0019, A0020, A0021, A0022, A0023, A0024, A0025, A0026). The contractor shall provide software documentation for the CASTLE KEEP Tool system.
4. GOVERNMENT RESPONSIBILITIES.
5.0. CONSTRAINTS
5.1. Contractor Employees Who Require Access to Government Information Systems.
5.2. Information Assurance, Antiterrorism, Operational Security, Physical Security
Requirements.
5.3. Physical Security
5.4. Intellectual Property
5.5. Government – Contractor Relationships.
5.6. Facilities and Specialized Handling
5.7. Government Furnished Property and Services
5.8. Contractor Furnished Items and Responsibilities
APPENDIX A: DEFINITIONS
CONTRACTOR. A supplier or vendor awarded a contract or task order to provide specific supplies or service to the Government. The term used in this task order refers to the prime contractor.
CONTRACTING OFFICER (KO). A person with authority to enter into, administer, and or terminate contracts and/or task orders, and make related determinations and findings on behalf of the Government. Note: The only individual who can legally bind the Government.
CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S.
Government appointed by the Contracting Officer to administer the task order. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the contractor as long as that direction is within the scope of the task order, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the task order.
DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.
DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.
KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a task order by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
OVERTIME. A change in mission requirements or work load that requires increased level of effort satisfied through the current staffing working additional hours.
PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
QUALITY ASSURANCE. The Government procedures to verify that services being performed by the contractor are performed according to acceptable standards.
QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
QUALITY CONTROL. All necessary measures taken by the contractor to assure that the quality of an end product or service shall meet contract requirements.
SUBCONTRACTOR. One that enters into a contract with a prime contractor. The Government does not have privet of contract with the subcontractor.
WORK DAY. The number of hours per day the contractor provides services in accordance with the task order.
Appendix B: ACRONYMS
AC2SP Army Commercial Cloud Service Provider ACCS Army Centralized Contracts and Security Portal ATO Authority to Operate AWS Amazon Web Services ATCTS Army Training Certification Tracking System C2S Commercial Cloud Services CDS Cross-Domain Solution CMR Contractor Manpower Reporting CMRS Contractor Manpower Reporting System COOP Continuity of Operations COR Contract Office Representative DAMI-IM Department of the Army Intelligence – Information Management DISS Defense Information System for Security DNI Director of National Intelligence DoD Department of Defense DoDM Department of Defense Manual EAP Emergency Action Plan eCMR Electronic Contractor Manpower Reporting FOC Full Operational Capability FSC Federal Service Code IA Information Assurance IC ITE Intelligence Community Information Technology Enterprise IDS Intrusion Detection System INSCOM Intelligence and Security Command IOC Initial Operational Capability IP Intellectual Property KO Contracting Office JPAS Joint Personnel Adjudication System JWICS Joint Worldwide Intelligence Communication System NCR National Capital Region NIPR Non-security Internet Protocol Router NVESD Night Vision Electronic Sensors Directorate OCI Organizational Conflict of Interest OMA Operations and Maintenance Appropriations PWS Performance Work Statement QASP Quality Assurance Surveillance Plan QCP Quality Control Plan QRB Quick Response Branch RDT&E Research, Development, Testing and Evaluation RMF Risk Management Framework SASO Special Access Security Office SAV Staff Assistance Visit SCI Sensitive Compartmented Information SCIF Sensitive Compartmented Information Facility SIPR Secret Internet Protocol Router
SOP Standard Operating Procedure SPPD Special Products and Prototyping Division SSO Special Security Office/Officer SSR Special Security Representative SWA Secure Work Area TM Technical Manager TSCIF Tactical Sensitive Compartmented Information Facility TSWA Temporary Secure Work Area UIC Unit Identification Code
Appendix C: Contract Data Requirements List
Data Item
CDRL
Acronym
Title of Data Item
DID
Para
Deliverable
Quality Control Plan N/A 1.9.1
A0001 CPSMR CONTRACTORS PROGRESS STATUS AND MANAGEMENT
REPORT
DI-MGMT-80227 3.3.4
A0002 PRESENTATION MATERIAL DI-ADMN-81373 3.3.1,
3.3.2, 3.3.3
A0003 CONFERENCE AGENDA DI-ADMN-81249B 3.3.1,
3.3.2, 3.3.3
A0004 IPMR INTEGRATED PROGRAM MANAGEMENT REPORT DI-MGMT-81861 3.3.5,
3.3.6
A0005 CONFERENCE MINUTES DI-ADMN-81250B 3.3.1,
3.3.2, 3.3.3
A0006 CSP COMPUTER SOFTWARE PRODUCT DI-IPSC-81488 3.3.10
A0007 CMP CONTRACTOR'S CONFIGURATION MANAGEMENT PLAN DI-CMAN-80858B 3.1.9
A0008 STD SOFTWARE TEST DESCIPTION DI-IPSC-81439A 3.3.8
A0009 STP SOFTWARE TEST PLAN DI-IPSC-81438A 3.3.8
A0010 STR SOFTWARE TEST REPORT DI-IPSC-81440A 3.3.9
A0011 PROGRAM MANAGEMENT PLAN DI-MGMT-81797 3.3.7
A0012 ORGANIZATIONAL CONFLICT OF INTEREST (OCI) PLAN DI-ADMIN-ECO-
1.13
A0013 COMPUTER PROGRAM END ITEM DOCUMENTATION DI-IPSC-80590B 3.3.11
A0014 SDD SOFTWARE DESIGN DESCRIPTION DI-IPSC-81435A 3.3.11
A0015 SUM SOFTWARE USER MANUAL DI-IPSC-81443A 3.3.11
A0016 DOD INFORMATION ASSURANCE CERTIFICATION AND
ACCREDIATION PROCES AND RISK MANAGEMENT
FRAMEWORK DELIVERABLE DATA
DI-MGMT-82000 3.2.3.4
A0017 SDP Software Development Plan DI-IPSC-81427B 3.3.11
A0018 SIP Software Installation Plan DI-IPSC-81428A 3.3.11
A0019 SSDD System/Subsystem Design Description DI-IPSC-81432A 3.3.11
A0020 SRS Software Requirements Specification DI-IPSC-81433A 3.3.11
A0021 DBDD Database Design Description DI-IPSC-81437A 3.3.11
A0022 SVD Software Version Description DI-IPSC-81442A 3.3.11
A0023 Software Documentation DI-IPSC-81756 3.3.11
A0024 Software Build Plan DI-IPSC-82167 3.3.11
A0025 SDPDD Software Development Process Description Document DI-IPSC-82208 3.3.11
A0026 DAL Data Accession List DI-MGMT-81453B 3.3.11
File details come from the government source that posted it. Updated .