Attachment 1 Performance Work Statement.pdf
PDF 290 KB Posted
- Attached to
- Help Desk IT Operations, and Information Assurance Services Federal contract opportunity
- Solicitation number
- W9124J-21-R-HELP
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 2 Sources Sought.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Help Desk, IT Operations, and Cybersecurity Services
Period of Performance: 10 May 2021 – 09 May 2022
1.0 General.
This Performance Work Statement (PWS) supports a non-personal services contract to provide Help Desk, Network Operations, Network Engineering, and Cybersecurity Support for US Army North. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who in turn is responsible to the Government.
1.1 Description of Services.
The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform network support as defined in this Performance Work Statement except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS. In general, the requirement consists of four (4) areas: Three (3) Information Technology Information Library (ITIL)®-aligned (or equivalent) Tiers: Tier 1 - Service Desk / Help Desk; Tier 2 – Network Operations; Tier 3 - Technical Management; and Cybersecurity Program Management.
NOTE: For each of the applicable area of service described below, there will be Government employees with similar skill sets, who will be operating under government supervision and assigned to the task areas. These employees will not be integrated within the contractor employees. The contractor employees requested for these services will support the Government employees during surges, afterhours and/or on extended exercises. It is the intent of the contractor to provide additional contracted employees to ensure these areas meet the Government’s needs.
The first ARNORTH requirement is for an ITIL®-aligned (or equivalent), Tier 1 Service Desk / Help Desk. The Tier 1 Help Desk provides local desktop support to approximately 900 users operating approximately 1,200 NIPRNET Computers, , 65 multi-function devices, and various other endpoints. The Help Desk provides telephonic support to approximately 300 forward stationed users at various locations throughout the United States. The contractor shall provide capability so that the Help Desk can operate 13 hours a day during duty days and 8 hours a day on Saturdays. The Contractor shall support surge requirements of 24 hours a day, 7 days a week during key exercises or real world events with either supplemental staffing or government coordinated overtime solutions.
The second ARNORTH requirement is for an ITIL®-aligned (or equivalent), Tier 2 Network Operations.
The Tier 2 Operations monitors and maintains the ARNORTH Non-Secure IP Router Network (NIPRNET), a tactical Secure IP Router Network (SIPRNET), and any cloud-based instances using government-provided tools. Tier 2 also provides technical reporting functions in accordance with applicable Standing Operating Procedures (SOP) and Knowledge Management (KM) plans. The government will provide one COR dedicated to Tier 2 Operations. The contractor shall provide capability so that the Tier 2 Desk can operate 11.5 hours a day during normal duty days. The Contractor shall support surge requirements of 24 hours a day, 7 days a week during key exercises or real world events with either supplemental staffing or government coordinated overtime solutions.
The third ARNORTH requirement is for an ITIL®-aligned (or equivalent) Tier 3 Technical Management during normal duty days. The Tier 3 Technical Management Team provides configuration and life cycle management of the NIPRNET, tactical SIPRNET, and cloud services, as well as planning and fielding new IT initiatives. The contractor shall provide capability so that the Tier 3 Desk can operate 11.5 hours a day during normal duty days (Monday-Friday less Federal holidays). Contractor employees shall have a broad technical understanding of the relationships of computer hardware, software, and information systems in a premises, hybrid, private cloud, and public cloud environments. The knowledge required includes, but is not limited to, virtual environment, operating systems, programming techniques, databases, Infrastructure as a Service (IaaS), Platform as a Service (PaaS), Software as a Service (SaaS), wired and wireless networking, and software functionality. The Contractor shall support surge requirements of 24 hours a day, 7 days a week during key exercises or real world events with either supplemental staffing or government coordinated overtime solutions.
The fourth ARNORTH requirement is for a Cybersecurity (CS) support operation during normal duty days. Contractor employees shall have a broad technical understanding of cybersecurity in premises, hybrid, private cloud, and public cloud environments, as well as the Risk Management Framework (RMF) and Enterprise Mission Assurance Support Services (eMASS) processes. The contractor shall provide the ability to operate the Cybersecurity Desk 11.5 hours a day during normal duty days (Monday- Friday less Federal holidays). The Contractor shall support surge requirements of 24 hours a day, 7 days a week during key exercises or real world events with either supplemental staffing or government coordinated overtime solutions.
Contractor and sub-contractor employees shall have a broad technical understanding of the information technology (IT) relationships to execute Cybersecurity and network security processes and programs.
Contractor employees shall be able to detect and take immediate corrective action for network vulnerabilities and intrusions. The Contractor shall support surge requirements of 24 hours a day, 7 days a week during key exercises or real world events with either supplemental staffing or government coordinated overtime solutions.
1.2 Background.
US Army North is the Army Service Component Command (ASCC) to US Northern Command (NORTHCOM), and must be capable to stand up and deploy multiple task forces in the event of natural or man-made disasters. The Army North Information Technology Directorate, known as the “G-6,” provides Help Desk/Service Desk, daily operations management, technical management services, and cybersecurity support for the Command. US Army North controls its own NIPRNET and provides all planning and support, to include all required RMF/ATO processes. The Fort Sam Houston (FSH) Network Enterprise Center (NEC) owns the SIPRNET; however, there is a cooperative arrangement in which Army North provides certain SIPRNET planning and administrative functions, to include maintaining the Tenant Security Plan (TSP), planning new SIPRNET connections, and coordinating for the Authority to Connect (ATC) for new and changed SIPRNET instances.
The Command conducts two major National Level Exercises, as well as communications exercises, certification exercises and conference support both locally and throughout the U.S. Northern Command (USNORTHCOM) Area of Responsibility (AOR). During training and contingency operations, all tiers and cybersecurity may be required to support operations on a 24 x 7 basis. The Command uses a planning factor of 28 days per year (4 weeks) for the conduct of 24 x 7 operations.
1.3 Objectives.
The services described in this PWS will support the Command in its mission to provide an ITIL®-aligned (or equivalent) technical support for command and control of forces in day-to-day, training, and contingency operations.
1.4 Scope.
The services described in this PWS will support the Command in its mission to provide an ITIL®-aligned (or equivalent) Tier 1, 2, and 3 Service Desk operations, as well as cybersecurity support, for command and control of forces in day-to-day, training, and contingency operations.
1.5 Period of Performance.
The period of performance shall be for one (1) Base Year of 12 months and two (2) 12-month option years. The Period of Performance reads as follows:
Base Year, 01 May 2021 – 30 April 2022 Option Year 1, 01 May 2022 – 30 April 2023 Option Year 2, 01 May 2023 – 30 April 2024
1.6 General Information.
1.6.1 Quality Control. Quality Control is the responsibility of the contractor. The contractor is responsible for the delivery of quality services/supplies to the Government (see FAR 52.246-4, Inspection of Services-Fixed Price). The Contractor shall develop, implement and maintain an effective Quality Control System which includes a written Quality Control Plan (QCP). The QCP shall implement standardized procedure/methodology for monitoring and documenting contract performance to ensure all contract requirements are met. The Contractors’ QCP shall contain a systematic approach to monitor operations to ensure acceptable services/products are provided to the Government. The QCP, as a minimum, shall address continuous process improvement; procedures for scheduling, conducting and documentation of inspection; discrepancy identification and correction; corrective action procedures to include procedures for addressing Government discovered non-conformances; procedures for root cause analysis to identify the root cause and root cause corrective action to prevent re-occurrence of discrepancies; procedures for trend analysis; procedures for collecting and addressing customer feedback/complaints. The contractor shall upon request provide to the Government their quality control documentation. After acceptance of the quality control plan the contractor shall receive the Contracting Officer’s acceptance in writing of any proposed change to their QC system
1.6.2 Quality Assurance. The government shall evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is a Government only document primarily focused on what the Government must do to assure that the contractor has performed in accordance with the requirements of the contract.
1.6.3 Federal Government Holidays. The Contractor is not required to perform services on the following Government recognized holidays unless mission requirements identified in the PWS dictate otherwise.
New Year’s Day 1st day of January Martin Luther King Jr.'s Birthday 3rd Monday of January Presidents Day 3rd Monday of February Memorial Day Last Monday of May Independence Day 4th day of July Labor Day 1st Monday of September Columbus Day 2nd Monday of October Veterans Day 11th day of November Thanksgiving Day 4th Thursday of November Christmas Day 25th day of December Other Federal Holidays as directed by the President
1.6.4 Hours of Operation. The contractor shall perform as required in this PWS.
1.6.5 Place of Performance. The vast majority of the work to be performed under this contract shall be performed in the US Army North Headquarters, Fort Sam Houston, Texas, with some work at remote locations within the United States.
1.6.6 Type of Contract. Firm Fixed Price.
1.6.7 Security Requirements. Contractor personnel (to include subcontractors) performing work under this contract shall have clearances as specified by this PWS, and must maintain the level of security required for the life of the contract. The security requirements are in accordance with DD Form 254, Department of Defense Contract Security Classification Specification.
1.6.7.1 Physical Security. The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
1.6.7.2 Operations Security.
The Contractor shall be responsible for the security of all Service member information. Neither the Contractor nor any of its contract service providers shall disclose or cause to disseminate any information concerning operations of military activities. Such action(s) could result in violation of the contract and possible legal actions Contracted personnel shall not discuss their work on ARNORTH requirements in public or over unprotected or unencrypted communications. The Contractor shall not post to company websites (including Social Networking sites), publications, newsletters or other media any images, data or information on ARNORTH facilities, personnel, equipment, and/or classified or controlled unclassified information. When in doubt, the Contractor shall coordinate any company press releases related to this contract through the COR. Because observation of execution of contract services may reveal Critical Information, specific restrictions are needed to preclude unintentional release of this information to unauthorized parties. Consequently, contractor personnel shall not disclose to unauthorized third parties any images, data or information, or observed events that may reveal ARNORTH's personnel, equipment, and/or classified/unclassified control information.
1.6.7.3 Key Control. The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.
NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer.
1.6.8 Classified Information requirements.
1.6.8.1 The contractor will require access to TOP SECRET information, and will have NO safeguarding capability. The contractor will have access to COMSEC information and CUI information. The contractor will also require access to Security/Program Classification Guide(s) (SCG) and the SIPRNET. In performing this contract, the contractor will have access to classified information only at the Government Activity.
1.6.8.2 Classified COMSEC material is not releasable to contractor employees who have not received a FINAL clearance at the appropriate security level. COMSEC access shall be IAW DoD 5220.22-M, chapter 9, section 4, AR 380-40 and Additional Security Guidelines for COMSEC, Appendix B. When access is required at Government facilities, contractor personnel shall adhere to COMSEC rules and regulations as mandated by Command policy and procedures.
1.6.8.3 Secret Internet Protocol Network (SIPRNET) access required. All contractors granted SIPRNET access shall be aware that NATO classified material resides on the SIPRNET and they are not authorized to access, download, or to disseminate any NATO or other special access data (i.e. intelligence, COMSEC, etc.) outside the execution of the defined contract requirements and without the guidance and written permission of the KO. All contractors shall read the NATO Central Registry awareness briefing located at: https://secureweb.hqda.pentagon.mil/cusr/forms.aspx prior to being issued a SIPRNET account. This briefing does not authorize NATO access, and is solely for the purpose of awareness.
1.6.9 Other Security Requirements.
1.6.9.1 Access and general protection/security policy and procedures. Contractor and all associated sub-contractors employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204- 9, Personal Identity Verification of Contractor Personnel) as directed by DOD, HQDA and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.
1.6.9.2 Handling or access to classified information. Contractor shall comply with FAR 52.204- 2, Security Requirements. This clause involves access to information classified “Confidential,” “Secret,” or “Top Secret” and requires contractors to comply with— (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DoD 5220.22-M); (2) any revisions to DOD 5220.22-M, notice of which has been furnished to the contractor
1.6.9.3 For contractors requiring Common Access Card (CAC). Before CAC issuance, the contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.
1.6.9.4 For contractors that do not require CAC, but require access to a DoD facility or installation.
Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.
1.6.9.5 Army Training Certification Tracking System (ATCTS) registration for contractor employees who require access to government information systems. All contractor employees with access to a government info system shall be registered in the ATCTS (Army Training Certification Tracking System) at commencement of services, and shall successfully complete the DOD Cybersecurity Awareness prior to access to the IS and then annually thereafter.
1.6.9.6 Cybersecurity (CS)/Information Technology (IT) training. All contractor employees and associated sub-contractor employees shall complete the DoD Cybersecurity awareness training before issuance of network access and annually thereafter. All contractor employees working CS/IT functions shall comply with DoD and Army training requirements in DoDD 8570.01, DoD 8570.01-M and AR 25-2 within six months of appointment to CS/IT functions. The contractor shall submit to the COR certificates of completion for each affected contractor employee and subcontractor employee within 45 calendar days after completion of training.
1.6.9.7 Cybersecurity (CS)/Information Technology (IT) certification. Per DoD 8570.01-M, DFARS
252.239.7001 and AR 25-2, the contractor employees supporting CS/IT functions shall be appropriately certified upon the start of performance. The baseline certification as stipulated in DoD 8570.01-M shall be completed upon the start of performance.
1.6.9.8 Other Security training. All contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete Anti-terrorism (AT) Level I awareness training; Threat Awareness and Reporting System (TARP) Training; Operations Security (OPSEC) Level 1 training, and Information Security (INFOSEC) training within 30 calendar days after contract start date or effective date of incorporation of this requirement into the contract, whichever is applicable. The contractor shall submit to the COR certificates of completion for each affected contractor employee and subcontractor employee within 45 calendar days after completion of training by all employees and subcontractor personnel. The COR will provide the most current web link for the training
1.6.10 Post Award Conference/Periodic Progress Meetings. The Contractor shall attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5, Post Award Orientation. The Contracting Officer, COR, and other Government personnel, as appropriate, will meet periodically, quarterly as a minimum, with the contractor to review the contractor's performance. At these meetings the Contracting Officer will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government. The Contractor shall provide a written summary of the meeting within 10 working days.
1.6.11 Contracting Officer Representative (COR). The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance;
maintain written and oral communications with the Contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, and specifications; monitor Contractor's performance and notify both the Contracting Officer and Contractor of any deficiencies; coordinate availability of government furnished property; and facilitate site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.
1.6.12 Key Personnel.
Contractor shall provide a Contract Manager, Alternate Contract Manager, Tier 1/Help Desk Task Lead, Tier 2/Operations Task Lead, Tier 3/Technical Management Task Lead, and a Cybersecurity Task Lead.
A Task Lead may also serve as the Contract Manager or Alternate Contract Manager. The Contractor shall provide the résumé of the Contract Manager, Alternate Contract Manager, and Task Leads to the KO. The Contract Manager or Alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The Contractor shall designate the Manager, Alternate, and Task Leads by name in writing to the contracting officer and lead COR. The Task Leads shall provide performance coordination and management in their particular areas. The Contract Manager or Alternate shall:
Have full authority to act for the contractor on all contract matters relating to performance.
Be available 7:00 am to 5:00 pm (central time), Monday thru Friday, except Federal holidays or when the government facility is closed for administrative reasons.
Be available by telephone at all times in case of emergencies Provide performance coordination and management.
Work staffing, certification, and security issues, to include:
Ensuring Contractor employees have required clearances and certifications.
Coordinating shift, surge, and on call support schedules with the COR.
Attending the COR’s recurring and ad-hoc status meetings
The Task Lead shall work in the Government location and shall be responsible for day-to-day management of contract performance. The specific required skills are as follows:
1.6.12.1 Tier 1 / Help Desk Task Lead. The contractor shall be able to provide senior level technical direction and engineering knowledge for IT support activities to include:
The contractor shall be able to perform system-level configuration of products including determination of hardware, OS, and other platform specifications.
The contractor shall be able to provide assistance and oversight for all information systems operations activities, including computer configuration, operations, data entry, data control, LAN/MAN/WAN administration and operations support, operating systems programming, system security policy procedures, and/or web strategy and operations.
The contractor shall have the ability to supervise all contract personnel engaged in the operation and support of network users, including all communications equipment on various platforms in large scale or multi- shift operations. Contract lead’s resume shall reflect a minimum of 6 years’ supervisory experience.
The contractor shall monitor and respond to hardware, software, and wired/wireless network problems through routine testing and analysis of all elements of the network facilities (including power, software, communications machinery, lines, modems, and terminals). Standard response procedures include identification of a problem, notification of appropriate personnel, complete troubleshooting or replacement procedures, and ensuring that notification of the appropriate personnel that the system(s) or equipment has returned to normal operations The contractor shall utilize software and hardware tools and identifies and diagnose complex problems and factors affecting network performance.
The contractor shall support a variety of IT systems and deploy commercial of the shelf (COTS) and Government off the shelf (GOTS) technologies including Microsoft, Linux, networking NSA Type 1 encryption devices, VOIP, email, video teleconferencing, and common desktop productivity tools.
The contractor shall support a variety of SaaS offerings including productivity suites such as Microsoft Office 365 or Google G Suite; and Cloud storage such as Microsoft OneDrive or Google Cloud.
The contractor shall meet DoD 8570.01-M IAT Level I requirements and shall have the following minimal education and experience metrics: 10 or more years of experience in IT customer support;
knowledge of computer systems administration; Comp TIA Security Certification (or equivalent);
Top Secret Security Clearance.
The contractor shall be able to use the latest versions of the following: Microsoft Operating Systems; Microsoft Office; Microsoft SharePoint; .NET; MS SQL Server; MS Active Directory Administration.
1.6.12.2 Tier 2 / Operations Task Lead. The contractor shall be able to provide senior level technical direction and engineering knowledge for communications activities including planning, designing, developing, testing, installing and maintaining large communications networks. Additionally, the contractor shall be able to assist in a variety of functional areas to include contract related logistical functions and assisting in exercise support functions. Some of these task activities, and specific skill sets that the contractor shall have include:
The contractor shall be required to monitor complex technical control facility hardware and software, either on-premises or cloud-based. They shall be able to interface with other IT technical personnel, users, and vendor support service groups to ensure escalation to a point of problem resolution is reached during outages or periods of degraded system performance.
The contractor shall be able to direct compilation of records and reports concerning network operations and maintenance, troubleshoot network performance issues, analyze network traffic, and provide capacity planning solutions The contractor shall manage the support of network communications, including LAN/MAN/WAN systems in support of large-scale systems projects.
The contractor shall be able to perform system-level configuration of products including determination of software, hardware, OS, and other platform specifications, either with on-premises equipment or IaaS/PaaS/SaaS cloud components.
The contractor shall be able to provide assistance and oversight for all information systems operations activities, including computer and telecommunications/communications operations, data entry, data control, LAN/MAN/WAN administration and operations support, Wi-Fi (IEEE 802.11) management and support, operating systems programming, system security policy procedures, and cloud operations.
The contractor shall have the ability to supervise all contract personnel engaged in the operation and support of network facilities, including all communications equipment on various platforms in large scale or multi-shift operations. Contract lead’s resume shall reflect a minimum of 6 years’ supervisory experience.
The contractor shall monitor and respond to NIPRNET and SIPRNET hardware, software, network, and cloud platform problems through routine testing and analysis of all elements of the network facilities (including power, software, communications machinery, lines, modems, and terminals). Standard response procedures include identification of a problem, notification of appropriate personnel, complete troubleshooting or replacement procedures, and ensuring that notification of the appropriate personnel that the system(s) or equipment has returned to normal operations The contractor shall utilize software and hardware tools and identify/diagnose complex problems and factors affecting network performance.
The contractor personnel shall support a variety of IT systems and deploy commercial of the shelf (COTS) and Government off the shelf (GOTS) technologies including Microsoft, Linux, networking NSA Type 1 encryption devices, VOIP, email, video teleconferencing, and common desktop productivity tools.
The contractor shall have detailed understanding of VMware Virtualization Technology with a proven track record of operating a VMware environment for more than 3years The contractor shall have a detailed understanding of the configuration, management, and use of security information and event management (SIEM) software, to include properly reacting to SIEM events.
The contractor shall also be able to manage the system vulnerability identification and resolution process in order to support network accreditation process. Additionally, minimum of 5 years of firsthand experience operating network security devices to include Cisco integrated services routers
(ISR).
The contractor shall meet shall meet DoD 8570.01-M IAT Level II requirements and shall have the following minimal education and experience metrics: Bachelor’s degree in a related IT field;
Knowledge of Computer Systems Administration; Comp TIA Security Certification (or equivalent);
Top Secret Security Clearance The contractor shall be able to use the latest versions of the following: Microsoft Operating Systems; Microsoft Office; Microsoft SharePoint; .NET; MS SQL Server; VMWARE, VCenter, ESX
5.0 and Above; MS active Directory Admin; Cisco products to include but not limited to 3560 switches, routers, and ASA firewalls and intrusion prevention systems (IPS).
1.6.12.3 Tier 3 / Technical Management Task Lead. The contractor shall be able to provide senior level technical direction, engineering knowledge, and planning for IT network support activities. The contractor shall have the ability to perform two core functions. The first core competency shall include supervising complex operations that involve two or more additional functional areas such as, but not limited to, network operations, systems security, systems software support, and production support activities. Second, the contractor shall perform a variety of systems engineering, maintenance, and testing tasks and activities that are broad in nature and are concerned with major systems design, integration, and implementation, including personnel, hardware, software, budgetary, and support facilities and/or equipment. Some of these task activities, and specific skill sets that the contractor shall have include:
The contractor shall be able to provide technical guidance for directing and monitoring NIPRNET and SIPRNET information system operations to include designing, building, and implementing network systems. Additionally, they shall provide quality control review and the evaluation of new and existing software products.
The contractor shall be able to provide technical guidance for directing and monitoring IaaS, PaaS, and SaaS implementation and operations.
The contractor shall be required to monitor complex technical control facility hardware and software. Contractor shall be able to interface with other IT technical personnel, users, and vendor support service groups to ensure escalation to a point of problem resolution is reached during outages or periods of degraded system performance.
The contractor shall be able to direct compilation of records and reports concerning network operations and maintenance, troubleshoot network performance issues, analyze network traffic, and provide capacity planning solutions.
The contractor shall manage testing, installation, and support of network communications, including LAN/MAN/WAN systems in support of large-scale systems projects.
The contractor shall be able to perform system-level design and configuration of products including determination of software, hardware, OS, and other platform specifications for on-premises, IaaS, PaaS, and SaaS implementations.
The contractor shall be able to provide assistance and oversight for all NIPRNET and SIPRNET information systems operations activities, including computer and telecommunications/ communications operations, data entry, data control, LAN/MAN/WAN administration and operations support, operating systems programming, system security policy procedures, and/or web strategy and operations.
The contractor shall have the ability to supervise all contract personnel engaged in the operation and support of network facilities, including all communications equipment on various platforms in large scale or multi-shift operations. Contract lead’s resume shall reflect a minimum of 6 years’ supervisory experience.
The contractor shall monitor and respond to hardware, software, network, and cloud problems through routine testing and analysis of all elements of the network facilities (including power, software, communications machinery, lines, modems, and terminals). Standard response procedures include identification of a problem, notification of appropriate personnel, complete troubleshooting or replacement procedures, and ensuring that notification of the appropriate personnel that the system(s) or equipment has returned to normal operations The contractor shall utilize software and hardware tools and identify/diagnose complex problems and factors affecting network performance. Additionally, the contractor shall troubleshoot network systems when necessary and make improvements to the network. Improvements should focus on reliability, streamlining, and reducing outage or downtime of equipment, systems, and networks.
The contractor personnel shall support a variety of IT systems and deploy commercial of the shelf (COTS) and Government off the shelf (GOTS) technologies including Microsoft, Linux, networking NSA Type 1 encryption devices, VOIP, email, video teleconferencing, and common desktop productivity tools. Additionally, the contractor shall be familiar with elements, infrastructure, and service capabilities of the Defense Information Systems Agency (DISA). The contractor shall have a minimum of 10 years of system administrator experience to include the operation of Microsoft Server Systems to include Exchange, SharePoint and SQL Server.
The contractor shall have detailed understanding of VMware Virtualization Technology with a proven track record of operating a VMware environment for more than 3 years.
The contractor shall have a detailed understanding of the configuration, management, and use of security information and event management (SIEM) software, to include properly reacting to SIEM events.
The contractor shall also be able to manage the system vulnerability identification and resolution process in order to support network accreditation process. Additionally, contractor shall have a minimum of 5 years of firsthand experience operating network security devices to include Cisco Integrated Services Routers (ISR).
The contractor shall also have extensive router and switch management experience of least 5 years The contractor shall meet shall meet DoD 8570.01-M IAT Level II requirements and shall have the following minimal education and experience metrics: Bachelor’s degree in a related IT field;
Knowledge of Computer Systems Administration; Comp TIA Security+ Certification (or equivalent);
Top Secret security clearance with SSBI.
The contractor shall be able to use the latest version of the following: Microsoft Operating Systems; Microsoft Office; Microsoft SharePoint; .NET; MS SQL Server; VMWARE, VCenter, ESX
5.0 and Above; MS active Directory Admin; SAN Storage, Cisco products to include but not limited to 3560 switches, routers, and ASA Firewalls and intrusion prevention systems (IPS).
1.6.12.4 Cybersecurity Task Lead. The contractor shall be able to provide senior level technical direction and engineering knowledge for IT support activities to include
The contractor shall have a current Certified Information Systems Security Professional (CISSP) certification.
The contractor shall be able to manage the system vulnerability identification and resolution process in order to support network accreditation process.
The contractor shall be able to manage the ARNORTH Host Based Security System (HBSS) enterprise configurations following the guidance in the DISA HBSS Tier 3 Operations Tactics, Techniques, and Procedures guide.
The contractor shall be able to assist the government P-ISSM to manage the Risk Management Framework (RMF) process using the eMASS Portal, to include RMF process for on-premises, IaaS, PaaS, and SaaS employments. Currently US Army North manages the RMF/ATO process for the ARNORTH NIPRNET as well as the DOD DSCA Automated Support System (DDASS), as well as the ATC process for ARNORTH connections to the NEC SIPRNET. However, the number and types of required ATO and ATC may increase during the course of this contract.
The contractor shall have a detailed understanding of the configuration, management, and use of security information and event management (SIEM) software, to include properly reacting to SIEM events.
The contractor shall have the ability to supervise all contract personnel engaged in the operation and support of Cybersecurity and cyber security activities. Contract lead’s resume shall reflect a minimum of 6 years’ supervisory experience.
The contractor shall meet DoD 8570.01-M IAM Level II requirements and shall have the following minimal education and experience metrics: Bachelor’s degree in a related IT field; 10 or more years of experience in the information assurance/cyber security field; Knowledge of Computer Systems Administration; Comp TIA Security Certification (or equivalent); Top Secret Security Clearance.
1.6.13 Identification of Contractor Employees. All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They shall also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.
1.6.14 Supervision of Contractor Employees. The Government will not exercise any supervision or control over Contractor or subcontractor employees while performing work under the contract. Such employees shall be accountable solely to the Contractor, not the Government. The Contractor, in turn, shall be accountable to the Government for Contractor or subcontractor employees.
1.6.15 Other Direct Costs. This category includes travel and other expenses associated with visits to ARNORTH subordinate facilities.
1.6.16 Data Rights. The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials shall not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.6.17 Organizational Conflict of Interest. Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.
1.6.18 Phase In. To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the Contractor shall have personnel on board, during the 20-day phase in period.
During the phase in period, the Contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date.
1.6.19 Sub-Contracting. The contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement. The prime contractor shall manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. The prime contractor shall submit subcontracting plan (IAW FAR part 19.9) to the Contracting Officer (KO) for approval.
Contractors shall not add subcontractors without approval from the KO. Contractors are responsible for filing subcontract reports in the electronic Subcontracting Reporting System (eSRS). Prime/ Higher Tier subcontractors must inform their subcontractor to enter their reports in eSRS under the flow down requirement. Contractors shall provide a notification e-mail address in the report for the federal government agency.
2.0 Definitions, Acronyms, and References
2.1 Definitions.
Contract administrator. The official government representative delegated authority by the contracting officer to administer a contract. This individual is normally a member of the appropriate contracting/procurement career field and advises on all technical contractual matters.
Contractor. A supplier or vendor awarded a contract to provide specific supplies or services to the government. The term used in this contract refers to the prime.
Contracting officer. A person with authority to enter into, administer, and/or terminate contracts, and make related determinations and findings on behalf of the government. Note: the only individual who can legally bind the government.
Contracting Officer's Representative (COR). An employee of the U.S. government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does not have authority to change the terms and conditions of the contract.
Defective service. A service output that does not meet the standard of performance associated with the performance work statement.
Deliverable. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.
Government-Furnished Property (GFP) or Government Property (GP). Property in the possession of, or directly acquired by, the government and subsequently made available to the contractor.
Key Personnel. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the key personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
Physical security. Actions that prevent the loss or damage of government property.
Quality Assurance. The government procedures to verify that services being performed by the contractor are acceptable in accordance with established standards and requirements of this contract.
Quality Assurance Specialist. An official government representative concerned with matters pertaining to the contract administration process and quality assurance/quality control. Acts as technical advisor to the contracting officer in these areas.
Quality Assurance Surveillance Plan (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
Quality Control. All necessary measures taken by the contractor to assure that the quality of an end product or service shall meet contract requirements.
Subcontractor. One that enters into a contract with a prime contractor. The government does not have privity of contract with the subcontractor.
Tier 1 Services. The first point of contact for information technology incidents and service requests from end users; often called the Help Desk or Service Desk. Appropriately categorize, prioritize and solve incidents, or escalate incidents and service requests which Tier I cannot resolve. Properly configure user computers or other personal IT devices; provide account access as required.
Tier 2 Services. Operate a Network Operations Center (NOC) to monitor and maintain the network.
Troubleshoot and resolve incidents escalated from Tier 1. Escalate incidents and service requests which Tier 2 cannot resolve. When required, expand NOC operations into a Joint Network Operations Control Center (JNCC), operating in accordance with Joint Publication 6.0.
Tier 3 Services. Provide technical planning and management of the IT network. Troubleshoot and resolve incidents escalated from Tier 2.
Work day. The number and range of hours per day the contractor provides services in accordance with the contract. Work week. Monday through Friday, except for federal holidays unless specified otherwise.
2.2 Acronyms.
ACAS Assured Compliance Assessment Solution AD Active Directory AGM Army Gold Master AO Authorizing Official AOR Area of Responsibility AR Army Regulation ARNORTH US Army North ASCC Army Service Component Command
ATC Authority to Connect ATCTS Army Training Certification Tracking System ATO Authority to Operate CAC Common Access Card CAN Campus Area Network CISSP Certified Information Systems Security Professional CMR Contract Manpower Reporting CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTS Commercial-Off-the-Shelf CR Conference Room CS Cybersecurity CST Central Standard Time DA Department of the Army DCE Defense Coordinating Element DD254 Department of Defense Contract Security Requirement List DDASS DOD DSCA Automated Support System DISA Defense Information Systems Agency DNS Domain Name Server DOD Department of Defense FAR Federal Acquisition Regulation GAL Global Address List HBSS Host Based Security System IA Information Assurance IaaS Infrastructure as a Service IAM IA Managerial IAT IA Technical IAVA IA Vulnerability Assessment IDS Intrusion Detection System ISSM Information System Security Manager ISSO Information System Security Officer IAVA IA Vulnerability Assessment IT Information Technology ITAM IT Asset Management ITIL Information Technology Information Library JNCC Joint NetOps Control Center KM Knowledge Management KO Contracting Officer NIPRNET Non-Secure IP Router network NMS Network Management System NORTHCOM Northern Command OCONUS Outside Continental United States (includes Alaska and Hawaii)
OPSEC Operations Security OS Operating System OWA Outlook Web Access PaaS Platform as a Service POC Point of Contact POP Period of Performance PPS Ports, Protocols, and Security PRS Performance Requirements Summary PWS Performance Work Statement
QA Quality Assurance QAP Quality Assurance Program QASP Quality…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .