Attachment 1 - IT Enterprise Services Performance Work Statement dated 25 MAY 22.docx

DOCX document 234 KB Posted

Attached to
HQ AFRC Enterprise IT Services Federal contract opportunity
Solicitation number
FA6643-22-R-0002
Issued by
Department of the Air Force Reserve Command

View the file

Other files for this federal contract opportunity

Other files attached to HQ AFRC Enterprise IT Services, newest first.
File Type Posted
Solicitation Amendment FA664322R00020002 SF 30.pdf PDF
Attachment 11 - Addendum to FAR 52.212-1 amendment 2.docx DOCX document
Solicitation Amendment FA664322R00020001 SF 30.pdf PDF
updated Attachment 11 - Addendum to FAR 52.212-1.docx DOCX document
updated Attachment 1 - IT Enterprise Services Performance Work Statement dated 25 MAY 22.docx DOCX document
updated Attachment 12 - Addendum to FAR 52.212-2 .docx DOCX document
updated Attachment 6 - Attach L-03 Present Past Performance Questionaire 7 Dec 2022.docx DOCX document
Corrected security answers.pdf PDF
Industry Questions and Answers 2.pdf PDF
Industry Questions and Answers.pdf PDF
DRAFT RFP AFRC IT Support Services Answers.xlsx XLSX spreadsheet
Solicitation - FA664322R0002.pdf PDF
Solicitation - FA664322R0002.pdf PDF
Attachment 2 - DD Form 254 - FA6643-22-R-0002.pdf PDF
Attachment 5 - FACTS Sheet.docx DOCX document
Attachment 7 - Client Authorization Letter.docx DOCX document
Attachment 9 - Task Order proposal worksheet.xlsx XLSX spreadsheet
Attachment 11 - Addendum to FAR 52.212-1.docx DOCX document
Attachment 3 - Task Order 01 Performance Work Statement.docx DOCX document
Attachment 6 - Present Past Performance Questionaire 23 Sep 2022.docx DOCX document
Attachment 8 - Rate Sheet.xlsx XLSX spreadsheet
Attachment 14 Wage Determinations.zip ZIP file
Attachment 4 - Sample Subcontractor Consent Letter.docx DOCX document
Attachment 13 - Consolidated CDRLs List.docx DOCX document
Solicitation - FA664322R0002.pdf PDF
Attachment 10 - Present Past Performance Questionnaire Request Letter.docx DOCX document
Attachment 12 - Addendum to FAR 52.212-2.docx DOCX document
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

FOR

AIR FORCE RESERVE COMMAND

AFRC Enterprise IT Services

25 MAY 2022

1.0. DESCRIPTION OF SERVICES. This Performance-based Work Statement (PWS) describes the services required by the Directorate of Cyberspace and Technology at Headquarters Air Force Reserve Command (HQ AFRC/A6) to support the planning, operation, sustainment and modernization of the Non-Secure Internet Protocol Router (NIPR) Network and the Secure Internet Protocol Router (SIPR) Network information technology (IT) environments of the Air Force Reserve Command (AFRC), as well as, services necessary for managing IT-related activities within AFRC.

1.1 Scope. Scope includes support for the following services:

· Engineering, support, and sustainment of wired and wireless infrastructure

· Network and cloud operations, to include management of networks, storage, compute, servers, and end user devices

· Management of IT capabilities such as print, PKI/LRA, unified communication, and SharePoint

· Support the development/maintenance of Tier 0 resources, provide Tier 1-2 support, and provide escalation to Tier 3-4, as well as support actions required by Tier 3-4 vendors to resolve issues

· Tier 0 – User self-service (Enabled by AFRC A6 through knowledge base, etc.)

· Tier 1 – Service Desk, Communications Focal Point, Touch Maintenance

· Tier 2 – Backshop/Functional area support – Service configuration/operation, escalated Tier 1 issues

· Tier 3 – HQ AFRC-provided on-site vendor representatives (Residents) or vendor tech support if no on-site vendor presence

· Tier 4 - Escalated issues worked by vendors

· Ensuring cyber security and cyber compliance requirements are met

· Performing enterprise architecture functions such as developing architectural artifacts and mapping processes

· IT program and project management

· Administrative oversight functions for IT equipment accountability, package delivery, and cyber force development

- Modernization and/or innovation recommendations to improve the AFRC IT environment

1.2. Organization. The AFRC organization with primary responsibility for this requirement is HQ AFRC/A6.

1.3. Place of Performance. Primary support is expected at Headquarters Air Force Reserve Command at Robins Air Force Base (AFB) Georgia, Air Reserve Personnel Center (ARPC) at Buckley AFB Colorado, Naval Air Station – Joint Reserve Base (NAS-JRB) Ft Worth Texas , Grissom Air Reserve Base (ARB) Indiana, Westover ARB Massachusetts, March ARB California, Homestead ARB Florida, Youngstown ARB Ohio, Pittsburgh ARS Pennsylvania, Duke Field Florida, Portland International Airport Oregon, Joint Base San Antonio Texas, and the Pentagon in Washington DC. During the life of the contract, support needs may be identified at additional AFRC locations. Specific locations requiring support will be identified in task orders.

1.4. Telework. The contractor will coordinate with the COR and the local Government Leads to approve situational telework IAW AFRC policy. Tasks requiring touch labor or SIPRnet access must be performed on base.

2.0. Required Services. The specific services required by AFRC are identified in paragraphs 2.1 through 2.7 below.

2.1. IT Technical Support Services. AFRC requires technical support services to provide infrastructure support, network operations, and IT capabilities management. Services may be required at HQ AFRC, AFRC host bases, or other AFRC unit locations, as identified in each task order. In general, AFRC supports approximately twenty-five thousand (25,000) users at AFRC host bases and an additional forty-five thousand (45,000) users at AFRC tenant locations, but specific scoping for each service is identified in each applicable services requirement below. Operation hours, holidays, and contingency operations are outlined in PWS paragraphs 5.15 through 5.21.

2.1.1. Infrastructure and Engineering Field Support: HQ AFRC provides AFRC-wide engineering of the overall architecture for HQ AFRC and eleven (11) AFRC host bases on NIPR and SIPR. This includes the Wide Area Network (WAN) architecture supporting AFRC data centers, backbones, cloud initiatives, and mission data traversing the WAN. Support high Temporary Duty (TDY) requirement (estimated to be seventy-five percent (75%)) due to high-level of base project support. In support of this environment, the Contractor shall ensure the following Infrastructure and Engineering Field Support services are accomplished:

· Serve as focal point for AFRC Internet Protocol (IP) space management.

· Serve as focal point for the infrastructure engineering for AFRC.

· Manage technology refresh for the command.

· Make recommendations to the Government for infrastructure upgrades, configurations, efforts at HQ and bases. These include: Core Nodes (CN), Critical Distribution Nodes (CDN), Critical Access Nodes (CAN), Distribution Nodes (DN), and Access Nodes (AN).

· Coordinate, as technical liaison, technical requirements with the Government lead.

· Function as Subject Matter Expert (SME) for NIPR/SIPR network-related IT requirement reviews.

· Function as SME for network Command Cyber Readiness Inspection (CCRI) support.

· Perform on-site Local and Wide Area Network (LAN/WAN) security management functions.

· Function as the SME for Air Force network projects affecting both the HQ and enterprise [e.g., Base Information Transport Infrastructure (BITI), One Base One Network (1B1N), Data Center Optimization Initiative (DCOI), Enclave NIPR Firewall and ASIM Sustainment (ENFAAS), Installation Processing Node (IPN), etc.].

· Coordinate with AF project offices and AF responsible offices for Enterprise projects and programs impacting AFR equities.

· Assist with on-site infrastructure support (e.g., switch and router configuration).

· Provide common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.2. Cyber Transport (CT) Support. Manage/support network infrastructure devices including, but not limited to, TACLANEs (Not an acronym; see glossary pages 87-95), switches, routers, Unified Communications (UC), authentication servers, and commercial internet access devices (wireless access points, modems, wireless routers, etc.). Also included are Voice over Internet Protocol/Voice over Secure Internet Protocol (VoIP/VoSIP) devices.

2.1.2.1. Enterprise CT Support:

Contractor shall ensure the following services are accomplished:

· Provide Enterprise (NIPR and SIPR) LAN/WAN administration, network configuration, infrastructure management for servers, switches, routers, and Uninterruptable Power Supply (UPS)/power requirements.

· Provide administration, network configuration, infrastructure management for AFRC-managed commercial internet infrastructure (examples include switches, routers, modems, and wireless access points).

· Install/coordinate endpoint support for wireless infrastructure and cellular systems.

· Request/coordinate Domain Name Service (DNS) record entries for AFRC Enterprise.

· Design, plan, manage, maintain, and support network-related and UC-related infrastructure.

· Support cloud efforts with network design and technical direction.

· Support development and integration of cloud application and infrastructure services into existing systems.

· Coordinate testing efforts; identify and resolve system integration issues.

· Identify improvements for processes and procedures and introduce automation to improve.

· Configure and maintain system accounts for Enterprise CT functions.

· Establish, configure, administer, and manage authentication/load balancing servers, e.g. F5 Multi-Factor Authentication.

· Monitor security of devices and implement new configurations and/or IOS upgrades for Enterprise devices.

· Monitor and report Enterprise LAN/WAN bandwidth utilization and circuit latency.

· Manage Enterprise CT software configuration management.

· Ensure Enterprise complies with Department of Defense (DoD), Air Force (AF), and applicable commercial standards.

· Plan and execute Enterprise software and hardware upgrades and revisions.

· Conduct system analyses to resolve configuration and equipment problems, e.g. degraded service troubleshooting, root cause analysis, etc.

· Troubleshoot Enterprise hardware, software and network problems to return sites to an operational status.

· Perform equipment installs and assist with vendor-managed installation.

· Serve as focal point for problem resolution for Enterprise CT issues.

· (SIPR) Provide technical advice on encryption strategy/design. Provide subject matter expertise on TACLANE equipment and management software/tools.

· Provide monthly WAN bandwidth utilization and latency reports in accordance with CDRL A001 (D), Monthly Metrics Report, DI-MGMT-81928, PWS Appendix C.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.2.2. HQ AFRC and AFRC Host Base CT Support:

Contractor shall ensure the following services are accomplished:

· Provide the following functions for the respective location (as outlined in each task order)

· Provide NIPR/SIPR LAN administration, network configuration, and infrastructure management for servers, switches, routers, wireless infrastructure, cellular, and UPS/power requirements.

· Provide cabling services for station cables (wall jack to devices), patch cables [patch panel to network equipment, and minor building renovations (ten (10) drops or less)].

· Renovations requiring specialized experience/equipment, e.g. confined spaces, above standard ladder height, are outside the scope of this PWS.

· Manage/Administer/Allocate Internet Protocol (IP) address space, e.g. subnetting, DHCP management.

· Configure and maintain system accounts for CT functions.

· Configure and maintain CT tools, e.g. software, appliances.

· Monitor security of devices and implement new configurations and/or IOS upgrades.

· Establish, configure and maintain access Control Server/Identity Service (currently Identity Service Engine (ISE)).

· Monitor and report LAN bandwidth utilization and circuit latency.

· Install and sustain Unified Communications devices, switches, and network infrastructure (fiber, copper, power, etc.).

· Plan and execute software and hardware upgrades and revisions.

· Conduct system analyses to resolve configuration and equipment problems, e.g. degraded service troubleshooting, root cause analysis, etc.

· Manage and configure local Unified Compute hardware and software.

· Perform Equipment, Supply, and COMSEC Custodian duties, as needed.

· Manage, configure, install, and maintain encryption devices and associated management tools, e.g. TACLANEs, Gem.

· Manage and coordinate local wireless and cellular infrastructure.

· Serve as the local focal point for CT problem resolution.

· Ensure physical security/maintenance of CT hardware (NIPR/SIPR).

· Ensure cyber security compliance for DoD and AF (CCRI).

· Telephony.

· Tier 2 Network Virtualization and Security Platform (NSX) support – resident sets up, main concern is maintenance.

· ARPC specific:

· Maintain Cisco Unified Call Center Express (UCCX) suite capabilities including Agent Desktop maintenance which also includes computer telephony integration (CTI) support.

· Provide Interactive Voice Response (IVR) capability and sustainment using the Cisco or other platforms to include Genesys and Quality Management System.

· Work with the local base telephony authority to resolve and repair communications circuit and digital gateway issues that enter and transverse the ARPC facility.

· Provide monthly WAN bandwidth utilization and latency reports in accordance with CDRL A001 (D), Monthly Metrics Report, DI-MGMT-81928, PWS Appendix C.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.3. Mobile Application Infrastructure Support. AFRC’s user base for mobile applications is approximately seventy-five thousand (75,000) users and twenty thousand (20,000) devices. VMware’s AirWatch and other Mobile Device Management (MDMs) will be used for mobile application deployment and management. In support of this environment, Contractor shall ensure the following Mobile Application Infrastructure Support services are accomplished.

· Deploy, create, configure, and administer cloud provider-related components and cloud-specific operational management tools.

· Support efforts to configure and implement any required cloud integration with other applications, automation monitoring and automated event/ incident remediation wherever possible and appropriate.

· Support innovative cloud-based solutions from the virtualization layer up through the software-defined and cloud management platform stacks.

· Configure, manage, secure, patch, and maintain the mobile application infrastructure servers and capabilities.

· Serve as focal point for mobile user problem resolutions (Tier 2), system issues, security updates, server maintenance, and AFNet issues.

· Make recommendations for the command’s effort for AFRC mobile policies, management, and new mobile technologies.

· Support devices/capabilities AFRC pursues, e.g. Android, Apple, Windows.

· Track user license usage and eliminates unused license usage by coordinating with HQ and base CFPs.

· Minimize services, application, and system unscheduled downtime with ninety-nine percent (99%) availability for the month with no more than seven (7) hours of downtime within Contractor’s control.

· Design/implementation/management of Mobile infrastructure (e.g., BlackBerry Work, BlackBerry Dynamics, AirWatch).

· Identification of issues/problems with Mobile implementations and recommended specific solutions.

· Enterprise Mobility Management for Apple iOS, Android, and Window devices to include Mobile Device Management (MDM) and Mobile App Management (MAM) Mobile Content Management (MCM).

· Manages A6 cell devices, to include validating A6 cell-phone bills and providing to A6 for payment, as well as coordinating A6 cell phone and services contracts through mandatory sources (currently Navy Spiral 3 Blanket Purchase Agreement (BPA).

· Update, patch, and perform systems to maintain compliance, e.g. Server Security Technical Implementation Guide (STIGs), CCRI.

· Engage vendor and outside AF agency support as required.

· Provide MDM and MAM usage statistics in accordance with CDRL A001 (A), Mobile Device Management (MDM) and Mobile Application Management (MAM) statistics, DI-MGMT-81928, PWS Appendix C.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.4. Virtualization Engineering and Management Support. AFRC manages eighteen (18) data centers for twelve (12) locations that incorporate thirty-five (35) VMware suites, approximately one thousand (1,000) virtual servers, supporting virtual desktop services across the Air Force. AFRC also centrally manages the AFRC NIPR/SIPR environment for a user population of approximately twenty-five thousand (25,000) regular users and up to seventy-five thousand (75,000) users during peak times. In support of this environment, Contractor shall ensure the following Virtualization Engineering and Management Support services are accomplished:

· Manage multiple virtual server platforms, virtual servers, and the associated components required to deliver the virtual environment, e.g. Cisco Unified Computing System (UCS), Dell MX7000.

· Manage and secure Virtual Desktop Infrastructures (VDIs) (Zero Clients) and the associated components required to deliver the virtual environment, e.g. Cisco UCS, Dell MX7000.

· Implement and configure virtualized infrastructure and the associated components required to deliver the virtual environment, e.g. Cisco switches, Dell MX7000.

· Manage the variety of application deployment methods including application virtualization, thin applications, Application Volume, and Security Server.

· Support externally facing customers with Security Server for virtual desktops.

· Serve as focal point for AFNet issues and user problem resolution in the virtual suites.

· Provide operational support for applications, systems, or infrastructure.

· Design, implement, and support integrated solutions in support of business demand.

· Work with enterprise architects to ensure the cloud infrastructure architecture is aligned with enterprise architectural standards and strategies.

· Apply architectural standards within the cloud infrastructure operation including operational considerations in cloud infrastructure architecture and design.

· Support efforts to architect and design cloud infrastructure extensions.

· Design and sustain the cloud layer in support of the planned cloud-based services as well as any changes.

· Identify market needs for new products or technologies and/or how current products can be modified or enhanced. Identify ways in which new products and/or modifications or enhancements to current products can be successfully implemented.

· Deploy large scale cloud infrastructure and application services for customers.

· Participate in design and implementation activities with emphasis on supportability, maintainability, scalability, performance, and overall quality.

· Utilize virtualization tools to deliver user-facing capabilities, track utilization and automate delivery of services.

· Offer overall support for virtualized infrastructure environment.

· Provide support across the entire platform stack for innovative cloud-based solutions from the virtualization layer up through the software-defined and cloud management platform stacks.

· Establish and/or manage on-premise and hybrid cloud technologies, e.g., Dell Electromagnetic Compatibility (EMC) VMware & Cisco.

· Apply DoD/AF Cloud strategies to include standards and operational considerations in cloud infrastructure architecture and design.

· Identify issues/problems with cloud implementation and recommend specific solutions.

· Update, patch, and perform systems to maintain compliance, e.g. STIGs, CCRI.

· Engage vendor and outside AF agency support as required.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.5. Directory Services. AFRCs environment supports activities for approximately twenty-five thousand (25,000) regular users and up to seventy-five thousand (75,000) users at peak times on NIPR and three thousand (3,000) users on SIPR. In support of this environment, Contractor shall ensure the following services are accomplished:

· Plan, design, enforce and audit security controls, policies and procedures which safeguard the integrity of and access to data.

· Identify improvements for processes and procedures and introduce automation to improve.

· NIPRNet Responsibilities:

· Establish, support, administer, manage, audit, backup, and protect the following services to include but not limited to:

· Assist AFNet personnel on troubleshooting with any issue with the following representative services:

· Active Directory Domain Services (ADDS)

· Dynamic Host Configuration Protocol (DHCP)

· Distributed File System (DFS)

· Group Policy (GP)

· Domain Name Service (DNS)

· Active Directory Sites and Services (ADSS)

· Active Directory Certificate Services (ADCS)

· Active Directory replication

· SIPRNet Responsibilities:

· Establish, support, administer, manage, audit, backup, and protect the following services to include but not limited to:

· Active Directory Domain Services (ADDS)

· Dynamic Host Configuration Protocol (DHCP)

· Distributed File System (DFS)

· Group Policy (GP)

· Domain Name Service (DNS)

· Active Directory Sites and Services (ADSS)

· Active Directory Certificate Services (ADCS)

· Active Directory replication

· Microsoft System Center Configuration Manager (SCCM)

· Windows Server Update Services (WSUS)

· Perform server maintenance and patching to include server OS updates, security patches, and any other Government required patches.

· Ensure Category-level (CAT) vulnerabilities for each assigned server does not exceed AFRC, Air Force (AF), Defense Information Systems Agency (DISA), or the Department of Defense (DoD) vulnerability thresholds; Must maintain <2.49 Weighted Vulnerability Score (WVS) per each assigned server at least 90% of the time and create/maintain approved Plan Of Action & Milestones (POA&M) for vulnerabilities that cannot be remediated.

· Server administrators will implement AF Maintenance Tasking Orders (MTOs), Time Compliance Network Order (TCNO), and Cyber Control Order (CCO) by established deadlines with ninety-five percent (95%) compliance for MTOs; one hundred percent (100%) compliance for TCNOs and CCOs. All non-compliant MTOs will be corrected or Plan of Action & Milestones (POAM) submitted within five (5) business days of non-compliance.

· Maintain Server Security Technical Implementation Guide (STIG) compliance and any other required information assurance actions.

· Current frequency is to generate and execute STIG compliance checklists quarterly.

· Applies to all system components, e.g., operating systems, databases, browsers, firewalls, installed applications, and add-ins as appropriate.

· Comply with CCRI evaluation criteria:

· Generate reports for CCRI data calls

· Submit STIG compliance checklists

· Computer Network Defense (CND) directives compliance reporting

· Troubleshoot server and network issues impacting the technical environment with Government personnel.

· Both SIPRNet and NIPRNet:

· Maintain Command login script

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.6. Server/System Support. AFRC hosts servers and services supporting the missions at multiple locations. The NIPR and SIPR environments utilize physical servers and a VMware virtual environment with storage and backup capabilities. Representative services include but are not limited to Windows Server and services, Linux Server and services, Print services, DHCP services, Cisco Servers and services, Web services, Database Server and services, and other AF/AFRC Business Systems such as, SAS Viya, Physical Access Control System (PACS), MCS Console. In support of this environment, the Contractor shall ensure the following Server and System Support services are accomplished:

· Provide Subject Matter Expertise (SME) on server operating systems and/or services. This expertise includes operation and maintenance of resources (CPU/RAM/Storage) and/or service, contributing to modernization plans, and contributing to overall architecture.

· Perform support for service issues. Troubleshoot service issues with Government personnel.

· Maintain service, to include but not limited to upgrades, patching to include server OS updates, security patches, and any other Government required patches.

· Maintain applicable Security Technical Implementation Guide (STIG) compliance and any other required information assurance actions.

· Troubleshoot service and network issues impacting the technical environment with Government personnel.

· Ensure NIPR/SIPR CAT vulnerabilities for each assigned server does not exceed AFRC, AF, DISA, or DoD vulnerability thresholds; Must maintain <2.49 Weighted Vulnerability Score (WVS) per each assigned server at least 90% of the time and create/maintain approved Plan Of Action & Milestones (POA&M) for vulnerabilities that cannot be remediated.

· Server administrators will implement AF Maintenance Tasking Orders (MTOs), TCNOs, and CCOs by established deadlines with ninety-five percent (95%) compliance for MTOs; one hundred percent (100%) compliance for TCNOs and CCOs. All non-compliant MTOs will be corrected within five (5) business days from the date of non-compliance.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.7. Server/Infrastructure Monitoring. HQ AFRC provides monitoring support for the core and functional system owners and administrators. Monitoring of mission essential systems and infrastructure provides situational awareness (SA) for the Enterprise. In support of this environment, Contractor shall ensure the following Server and Infrastructure Monitoring services are accomplished:

· Perform persistent daily monitoring activities to the MAJCOM leadership, MCCC, functional system owners, core server/system owners and the entities requiring visibility of the current stability and availability of the Enterprise.

· Manage monitoring capability for all core and non-core systems/servers.

· Serve as focal point for problem resolution and is the primary point of contact for problems relating to AFNet issues and AFNet user issues relating to monitoring of servers, infrastructure, services, etc.

· Coordinate with servers/services owners on monitoring devices, servers and services and the respective thresholds.

· Ensure server/service owners and the operational teams receive their respective alerts accurately; modify as required.

· Coordinate with AFRC HQ scripting/automation SMEs and with server/services owners on developing automated break-fix actions based on monitoring triggers.

· Minimizes services, application, and system unscheduled downtime with ninety-nine percent (99%) availability for the month with no more than seven (7) hours of downtime within Contractor’s control.

· Analyze performance trends to identify degraded performance and proactively generate work orders to resolve issues.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.8. System Integration Support. AFRC is utilizing increased automation for server deployments. Systems Integration includes managing a continuous integration/continuous delivery (CI/CD) environment and managing all servers included in the environment. Systems integration support will work closely with the virtualization environment to assist all HQ AFRC/A6CN and Functional System Administrator (FSA) teams to create and maintain blueprints, templates, configuration artifacts, pipelines, and scripts to enable CI/CD of applications and services. In support of this environment, Contractor shall ensure the following System Integration Support services are accomplished:

· Establish, support, administer, manage, audit, backup, and protect the continuous integration/continuous delivery (CI/CD) environment on both NIPRNet and SIPRNet.

· CI/CD tool e.g., Jenkins, GitLab, Concourse.

· Artifact repository e.g., Nexus, Artifactory, GitLab.

· Source Control Management e.g., Bitbucket, GitLab, GitHub.

· Secrets Manager e.g., Vault, GitLab.

· Configuration Management Tools e.g., Puppet, Chef, Salt, Ansible, PowerShell DSC.

· Help to create and maintain the following tool. Provide familiarization training to users.

· VMWare Blueprints as code for A6CN and FSA server and environment deployment automation.

· Configuration templates for A6CN and FSA server configuration and security hardening.

· CI/CD pipelines as code for A6CN and FSA server deployments.

· Automated tests as code for A6CN and FSA server deployments.

· Perform server maintenance and patching to include server OS updates, security patches, and any other Government required patches.

· Ensure CAT vulnerabilities for each assigned server does not exceed AFRC, AF, DISA, or DoD vulnerability thresholds; Must maintain <2.49 Weighted Vulnerability Score (WVS) per each assigned server at least 90% of the time and create/maintain approved Plan Of Action & Milestones (POA&M) for vulnerabilities that cannot be remediated..

· Server administrators will implement AF Maintenance Tasking Orders (MTOs), TCNOs, and CCOs by established deadlines with ninety-five compliance (95%) compliance for MTOs; one hundred percent (100%) compliance for TCNOs and CCOs. All non-compliant MTOs will be corrected or POAM submitted within five (5) business days from the date of non-compliance.

· Maintain Server Security Technical Implementation Guide (STIG) compliance and any other required information assurance actions.

· Current frequency is to generate and execute STIG compliance checklists quarterly.

· Applies to all system components e.g., operating systems, databases, browsers, firewalls, installed applications, add-ins as appropriate.

· Comply with CCRI evaluation criteria:

· Generate reports for CCRI data calls.

· Submit STIG compliance checklists.

· Computer Network Defense (CND) directives compliance reporting.

· Troubleshoot server and network issues impacting the technical environment with Government personnel.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.9. Enterprise File/Storage Support Services. HQ AFRC supports NIPR/SIPR daily file storage, backup, replication, and restoration process for AFRC. The current user population is approximately seventy-five thousand (75,000) users and approximately two thousand (2,000) virtual servers/appliances/devices. In support of this environment, the Contractor shall ensure the following Enterprise File/Storage Support services are accomplished:

· Resolve problems relating to issues on file storage, backup, replication, restoration, etc.

· Work with users and organizations to standardize file storage directory structures.

· Ensure data is accessible and recoverable.

· Identify improvements for processes, procedures, and introduce automation to improve.

· Participate in design and implementation activities with an emphasis on support, maintenance, scale, performance, and overall quality.

· Support innovative cloud-based solutions from the virtualization layer up through the software-defined and cloud management platform stacks.

· Actively monitor, update, and correct file/storage access permissions.

· Monitor and conduct file/storage backups, replications and restores.

· Coordinate to monitor and execute core and non-core server restores.

· Negligent Disclosure of Classified Information (formerly Classified Message Incident) sanitization.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.10. AFRC Wide Area/I-COOP File Server Storage Support Services: HQ AFRC supports an enterprise Information Continuity of Operations Capability (I-COOP). This service entails assisting host base storage administrators and replicating data between twelve (12) AFRC sites (NIPR) and twelve (12) AFRC sites (SIPR) to support continuity of operations. Representative technologies include PowerMax, Unity/Unity XT, XTreme IO, and Isilon. In support of this environment, the Contractor shall ensure the following AFRC Wide Area/I-COOP File Server Storage Support services are accomplished:

· Serve as a focal point for problem resolution on Dell-EMC Storage File Server Consolidation devices and Information Continuity of Operations Capability (I-COOP) backup monitoring and replication issues.

· Perform system analyses to resolve configuration and equipment problems.

· Coordinate with HQ and base CFPs to schedule hardware and software maintenance and updates to the storage equipment.

· Schedule and execute backups, test, and monitor successful backup replication and recovery operations to ensure successful and optimum performance of data recovery and backup capability.

· Provide Tier 2 and Tier3 support to HQ and bases CFPs on storage, backup, restores, replications, and remediate user-based, system-based, AFNet-based, etc. issues.

· Support all aspects of the I-COOP File Server Consolidation to include: shares creation on the devices, privileges to file share areas, allocation of file share space on base devices.

· Monitor all storage devices for file shares, backup success, recovery success, capacity planning, and recommends expansion of devices as need arises.

· Build virtual servers to support storage monitoring tools.

· Assist in new storage devices and upgrade installs, including configuration of file storage equipment.

· Monitor the day-to-day back-up operations of backup/replication software for AFRC.

· Monitor AFRC Host bases day-to-day back-up operations advise/assist Host base POCs of required actions.

· Provides administration and configuration support for backup software operations.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.11. Enterprise Scripting Support. HQ AFRC uses scripts to automate repetitive services for users and administrators. In support of this environment, the Contractor shall ensure the following Enterprise Scripting Support services are accomplished:

· Establish and execute scripts, plans, and executes strategies to comply with Cyber tasking orders monthly.

· Establish and execute scripts, plans, and executes strategies to remediate vulnerabilities across the estimated twenty-five thousand (25,000) workstations and one thousand (1000) servers in AFRC.

· Educate and facilitate vulnerability management with PMO and non-PMO system owners to include sharing and executing scripts, if requested.

· Design and execute other methods, as required, to facilitate vulnerability management.

· Support scripting and automation for remediation of CCRI issues.

· Identify improvements for processes, procedures and introduce automation to improve.

· Participate in design and implementation activities emphasizing supportability, maintainability, scalability, performance and overall quality.

· Support innovative cloud-based solutions from the virtualization layer up through the software-defined and cloud management platform stacks.

· Implement and maintain thorough vulnerability management programs to include creating/executing scripts (preference to PowerShell) to comply with tasking orders, remediation of client and server vulnerabilities, and general purpose scripts.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.12. Enterprise Compliance Support. The Contractor shall ensure the following services are accomplished:

· Execute scripts, plans and strategies to remediate vulnerabilities across the estimated twenty-five thousand (25,000) workstations and one thousand (1000) servers in AFRC.

· Educate and facilitate vulnerability management with PMO and non-PMO system owners to include sharing and executing scripts, if requested.

· Design and execute other methods, as required, to facilitate vulnerability management.

· Comply with CCRI evaluation criteria [e.g., STIGs and Computer Network Defense (CND) Directives] include these overarching categories:

· Technology. Includes (not inclusive) infrastructure, Assured Compliance Assessment Solution (ACAS) scans, traditional security and wireless.

· CND Directives. US Cyber Command issued directive compliance (e.g., compares network administrative accounts to DoD Directive 8140 certification tracking.

· Contributing Factors. More policy driven similar to self-inspection compliance.

· Establish a near real-time, AFRC-wide comprehensive single screen presentation (e.g., single pane of glass or dashboard) to facilitate CCRI preparedness, situational awareness, remediation actions, better understanding of issues in the operational environment, etc.

· Provide drill-down capabilities in the presentations, to include by-base and by function drill-down capability according to CCRI criteria.

· Establish and maintain visibility and tracking of compliance with CCRI evaluation criteria.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.13. Print Management Support.

Contractor shall ensure the following Print Management services are accomplished:

· Coordinate with bases/tenants and HQ CFP on print server application management.

· Utilize centralized capabilities to manage and enforce compliance of printer configurations across the command.

· Make recommendations for implementing the command’s efforts for overall AFRC print server policies and management.

· Plan and implement enterprise print server management, security, configuration control for AFRCs AFNet print servers.

· Make recommendations on new printer technology for devices, management software/processes, configuration controls and methods.

· Serve as AFRC SME for AFNet configuration changes – ensuring all AFRC servers/devices are compliant with guidance/policies.

· Coordinate with AFNet agencies and vendor support on enterprise issues, troubleshooting, and resolution.

· Serve as AFRC POC for Tier 4 issues and coordinate with AFNet agencies and vendor support as necessary.

· Author and maintain Tier 0 and Tier1 print support SOPs for users/CFP.

· Serve as Tier 2/3 support for print issues and POC for Tier 4 issues.

· Manage print release licenses for HQ and other AFRC host locations.

· Serve as AFRC’s Facsimile (FAX) manager (NIPR Only):

· Manage Fax Over IP (FOIP) licenses.

· Recommend overall AFRC FOIP policies, management and support.

· Implement enterprise FOIP server management, security, configuration control.

· Coordinate, test, document, evaluate and implement new FOIP technology.

· Author and maintain Tier 0 and Tier 1 FOIP support SOPs for users/CFP.

· Serve as Tier 2/3 support for FOIP issues and POC for Tier 4 issues.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.14. Public Key Infrastructure (PKI)/Local Registration Authority (LRA) Support. The PKI/LRA office provides token issuing services for SIPR users and administrative account holders. PKI/LRA support is currently maturing processes using Service Now, PKI software, etc. LRA token issuances are expected to grow as AFNet works to implement role-based admin tokens on NIPR (already implemented on SIPR). LRAs must be on site to issue tokens as part of issuance process. AFRC anticipates that the LRA responsibilities at the host bases is an additional duty and will not require dedicated staff at each location. In support of this environment, the Contractor shall ensure the following PKI/LRA Support services are accomplished:

· Provide physical presence to issue token to users.

· Manage request and delivery of Alternate Tokens.

· Follow and implement processes for Alt Token issuance as governed by the Air Force Public Key Infrastructure (PKI) System Program Office.

· Perform as the Local Registration Authority (LRA) to include issuing software certificates to support organizational email and admin accounts.

· Interface with AFNet organizations and Air Force Directory Services (AFDS), AF PKI Special Program Office (SPO), and others to resolve issues.

· Maintain an LRA database including installing, upgrading and configuring hardware/software used to support the database, performs system/database backups, and patches and applies STIGs to associated LRA hardware and software.

· Complete the AF PKI/LRA Course within 90 calendar days from contract award.

· HQ LRA Only: Provide SME guidance and support to AFRC Host Base LRAs.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.15. Unified Collaboration (Video Teleconferencing (VTC)). The HQ AFRC VTC environment consists of VTC suites using IP-based connectivity. VTC staff coordinates conference room audiovisual setup and/or virtual events (TEAMS/Zoom.gov). Additionally, the VTC hub located at HQ AFRC will provide VTC hosting services to AFRC, AFRC host bases, and AFRC tenants expanding local support to users throughout the command.

2.1.15.1. VTC System Engineering Support. Contractor shall ensure the following services are accomplished:

· Serve as the Video Teleconferencing (VTC) hub manager for VTC hub (located at HQ AFRC) supporting VTC session hosting across AFRC.

· Program and integrate VTC controllers (Currently Crestron) products.

· Schedule, coordinate, and facilitate VTC requests/sessions.

· Maintain VTC Account Database.

· Track, document and brief management on VTC utilization trends.

· Maintain and update web-based VTC schedule.

· Provide access list for room supporting VTC hub infrastructure equipment.

· Provide maintenance and/or troubleshooting support for legacy ISDN issues affecting VTC hub services.

· Maintain inventory control.

· Provide enterprise installation support, technical documentation, ongoing troubleshooting and maintenance, and on-site training support for VTC services.

· Act as enterprise VTC network maintenance focal point; receives and responds to alerts from VTC users/network VTC systems.

· Act as primary POC for VTC system maintenance vendors and coordinates with government representatives for actions requiring a financial commitment

· Coordinate with appropriate vendors for maintenance support.

· Configure systems, communications devices, and peripheral equipment.

· Develop and maintain AFRC VTC Directory.

· Install, configure, and upgrade network hardware/software.

· Develop training materials, and train on-site personnel in the proper use of the VTC-Audio/Visual (A/V) hardware/software.

· Support on-site installations from maintenance vendor.

· Perform safe custodian duties.

· Manage secure key material for classified VTC equipment.

· Integrate VTCs and A/V equipment with third-party communications solutions (e.g., Creston).

· Provide monthly VTC usage reports with a ninety-nine percent (99%) success rate of VTC sessions per month.

· Server administrators will implement AF Maintenance Tasking Orders (MTOs), TCNOs, and CCOs by established deadlines with ninety-five percent (95%) compliance for MTOs; one hundred percent (100%) compliance for TCNOs and CCOs. All non-compliant MTOs will be corrected within five business days.

· Ensure NIPR/SIPR CAT vulnerabilities for each assigned server does not exceed AFRC, AF, DISA, or DoD vulnerability thresholds; Must maintain <2.49 Weighted Vulnerability Score (WVS) per each assigned server at least 90% of the time and create/maintain approved Plan Of Action & Milestones (POA&M) for vulnerabilities that cannot be remediated.

· Authors Standard Operating Procedures for non-traditional collaboration tools such as peer-to-peer conferencing services, e.g. Teams, Zoom, etc.

· Provide the common services as identified in section 2.1.17.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.15.2. VTC Operations Center Presentation Support. The Contractor shall ensure the following Presentation Support services are accomplished:

· Schedule, coordinate, facilitate, and set up VTC requests/sessions both secure and un-Secure.

· Provide Senior-level presentation support for up to twelve (12) HQ AFRC VTC-enabled conference rooms at various locations around the base.

· Coordinate presentation requirements for conference room users, presents PowerPoint and/or other presentation support through use of multimedia systems in these rooms.

· Provide technical support to customers on presentation capabilities and requirements for the conference rooms.

· Assist in scheduling of rooms for presentation support.

· Assist with setup of VTC call sessions on HQ AFRC VTC hub.

· Conduct basic troubleshooting, and coordinate with VTC Operations Chief on any issues which require resolution; includes testing with other AF units.

· Configure systems, multimedia devices and peripheral equipment.

· Support on-site maintenance from vendors.

· Perform minor (Lowest Replaceable Unit (LRU) component) equipment installs and assist with vendor-managed installation.

· Serve as equipment custodian for all installed equipment in up to twelve (12) HQ AFRC VTC-enabled conference rooms.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.15.3. HQ USAF/RE VTC Facilitator Support. The Contractor shall ensure the following services are accomplished:

· Provide video conferencing support to Headquarters United States Air Force, Office of Reserve Affairs (HQ USAF/RE).

· Serve as VTC configuration manager, web developer, and facilitator for HQ USAF/RE.

· Schedule, coordinate, facilitate, and set up VTC requests/sessions, both secure and un-Secure.

· Maintain VTC account information.

· Track, document, and brief management on VTC utilization trends.

· Provide daily VTC availability reports to appropriated agencies.

· Provide installation support, technical documentation, ongoing troubleshooting and maintenance, and on-site training support for desktop VTC services.

· Act as centralized VTC network maintenance focal point for the HQ USAF/RE VTC system, receive and respond to alerts from VTC users/network VTC systems.

· Conduct basic troubleshooting and coordinate with HQ AFRC VTC Operations for maintenance support. Configure VTC systems, related communications devices, and peripheral equipment to include testing with other AF units.

· Install, configure, and upgrade network hardware/software.

· Set up VTC sessions, to include bridging of VTC calls through the AFRC VTC Operations Office at Robins AFB, GA.

· Develop training materials, and train on-site personnel in the proper use of the VTC-A/V hardware/ software.

· Perform on-site installations, configure the hardware and software for the appropriate telecommunications service, and test for connectivity and interoperability.

· Analyze existing requirements and prepare specifications for hardware/software acquisitions and/or upgrades.

· Build specialized interconnecting cables.

· Provide presentation support, as required.

· Provide monthly VTC usage reports.

· Maintain a ninety-nine percent (99%) success rate of VTC sessions per month.

· Provide input to on-site contract manager as required to support deliverables identified in section 2.3.1.

2.1.16. Enterprise Microsoft SharePoint (SP) Support. AFRC hosts an enterprise level SharePoint 2019 farm on SIPR. The SIPR farm currently provides services to internal users, with a potential for an increase in user base. All servers are running Windows server 2019 or higher, the Structured Query Language (SQL) servers are running MS SQL 2019. SQL servers run in high availability mode to provide twenty-four (24) hours-a-day/seven (7) days a week (24/7) access and an uptime of ninety-nine percent (99.99%). Architecture and server support along is part of the Service Level Agreements (SLA) and Governances in place for the SIPR farm. Several custom solutions are deployed in the farm, with the potential for additional Government and commercial solutions. SP team works closely with internal software development team and content managers to facilitate insuring proposed solutions meet farm architecture, engineering, and governance requirements. AFRC uses Infrastructure as a Service (IaaS) and Software as a Service (SaaS). AFRC NIPR SharePoint is hosted on SharePoint Online (SPO). SPO hosts seventy-five thousand (75,000) internal and external AFRC users. SPO Site Support with Tier 0 and Tier 1 level customer support is part of the Service Level Agreements (SLA) and Governances in place for SPO. Troubleshooting and custom development on SPO is provided by AFRC SP Team and site administrators, as agreed upon in the SPO SLA.

2.1.16.1. SharePoint Architecture and Server Support. HQ AFRC is responsible for planning, analysis, design, implementation and upgrades to current and future farm installations. The Contractor will provide ongoing analysis should result in performance tuning for optimal use as the SP usage grows. The Contractor is responsible for daily routine operations and maintenance of SharePoint (SP) servers. Supports and provides Central Administration duties, configuring SharePoint, patching and updating software to include SharePoint and the OS. Contractor shall ensure the following services are accomplished:

· Troubleshoot and resolve Tier 2 and Tier 3 issues with the SharePoint SIPR environment.

· Plan, analyze, design and implement/upgrade to a cloud-based solution.

· Implement, upgrade, and manage the internal and external SharePoint sites (includes 2013 and future upgrades) supporting AFRC and its partners.

· Develop the overall website design and structure, monitor web site functionality, security, and integrity, troubleshoot and resolve problems, review, test, collect and analyze website statistics, evaluate new web applications and provide technical advice to web content providers.

· Analyze AFRC's information architecture, maintain and configure organization taxonomies, site collections, policies, procedures, solutions.

· Coordinate with developers to install, debug, and maintain necessary code of assigned software.

· Coordinate, document, test, validate, and deploy new technology.

· Perform daily Central Admin services.

· Troubleshoot and resolve issues with the SharePoint environment.

· Provide technical solutions and escalated support for technical issues using approved ticketing system.

· Patch and update all software, as required.

· Plan, conduct and oversee the technical aspects of projects; coordinate the efforts of technical support staff in the performance of assigned projects.

· Minimizes services, application, and system unscheduled downtime; Must maintain 99% availability for the month with no more than seven (7) hours of downtime within Contractor’s control.

· Provides configuration control documentation of system changes; on-time delivery at 100% level (monthly).

· Perform server maintenance…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .