Attachment 1 - Statement of Work.pdf

PDF 3 MB Posted

Attached to
Purchase of 2 Multi-Functional Devices Federal contract opportunity
Solicitation number
SP7000-25-Q-1016
Issued by
Defense Logistics Agency

About this file

This Statement of Work details the Defense Logistics Agency's requirements for two color multifunctional printers for the 25th Fighter Squadron in Korea. The devices must meet specific technical requirements including: Trade Agreement Act compliance, support for Windows 11/MacOS 13 or higher, 120VAC power, minimum 45 pages per minute print speed, four paper trays with 100-sheet minimum capacity, 1200x1200 DPI print resolution, 5GB minimum memory, 10,000 monthly impression volume, and two NIPR smartcard readers.

The SOW outlines comprehensive specifications for network functionality (IPv4/IPv6 support), security requirements (DISA STIG compliance), and services including delivery to Osan Air Base in Pyeongtaek City, Korea. The contractor must provide manufacturer's warranty, implementation documentation, and submit reports through WAWF. Testing requirements specify that devices must be delivered to DLA Information Operations in New Cumberland, PA within 5 business days of award for a 20-day testing period. The contractor must resolve any non-compliance issues within 14 calendar days or testing will be suspended.

View the file

Other files for this federal contract opportunity

Other files attached to Purchase of 2 Multi-Functional Devices, newest first.
File Type Posted
Attachment 2 - Salient Characteristics.pdf PDF
Attachment 3 - Delivery Schedule.pdf PDF
SP7000-25-Q-1016.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Attachment 1 Statement of Work (SOW) Version 23.1

I. OVERVIEW

A. The Defense Logistics Agency (DLA) seeks to purchase Two (2) Printers for 25th Fighter Squadron Korea. Specific details are found in sections II and III.

B. The services associated with the devices sought are delivery (Section IV), manufacturer’s warranty

(Section V), reports (Section VII), network functionality (Section IX), and network security (Section X).

II. DEVICE CONFIGURATIONS

A. All devices shall meet the following requirements:

1. Equipment shall be Trade Agreement Act (TAA) compliant and manufactured new (not rebuilt, refurbished or remanufactured). New means composed of previously unused components, whether manufactured from virgin material, recovered material in the form of raw material, or materials and by-products generated from, and reused within, an original manufacturing process;

provided that the supplies meet contract requirements, including but not limited to, performance, reliability, and life expectancy.

2. Support Microsoft Windows 11 or higher and MacOS 13 or higher desktop operating system and Microsoft Server 2016 or higher server operating systems.

3. Delivered with up-to-date software/firmware and drivers, with 32-bit and 64-bit architecture driver support.

4. Capable of operating using 120VAC +/- 10% 60Hz.

5. Include a printed or digital (via compact disc (CD) or download link) operator’s manual, in English, for each device.

6. Scan and send in PDF format.

7. Scanner Surface Size: Accommodates letter (8 ½ x 11”) and legal paper (8 ½ x 14”)

8. Print Rate: Up to 45 Pages Per Minute or greater

9. Four (4) Paper Trays [100 Sheet Minimum Multi-purpose/Tray] -Tray 1 – letter, legal, executive, statement, 3 x 5 in, 4 x 6 in, 5 x 7 in, 5 x 8 in, 12 x 18 in, envelopes (No. 9, No. 10, Monarch)

- Tray 2 – letter, legal, executive, statement, 5 x 7 in, 5 x 8 in, 8.5 in x 13 in

- Tray 3 – letter, legal, executive, statement, 5 x 7 in, 5 x 8 in, 8.5 x 13 in

- Tray 4 – letter, legal, executive, statement, 5 x 7 in, 5 x 8 in, 8.5 x 13 in

10. Print resolution of at least 1,200 x 1,200 DPI.

11. Memory: Minimum 5 GB

12. Recommended monthly print volume: 10,000 impressions.

13. SmartCard Reader: 2 NIPR Smartcard readers

B. Contractors shall provide original equipment manufacturer (OEM) specification sheets and proposed configuration details specifically describing how the devices shall be configured to meet all requirements (for example, additional paper trays and finishers that will be included) with proposal to the Contracting Officer.

C. As part of its proposal, Contractor shall provide Letter(s) of Supply from the manufacturer as proof that they are an authorized dealer for all devices provided.

III. PURCHASE SPECIFICATIONS:

A. Two (2) Color Multifunctional Printers with NIPR Smartcard Readers - Minimum 45 pages per minute. Capable of 120VAC +/- 10% 60Hz. Networkable Color Multifunctional Printers. With Scan, Copy, Print and CAC Capabilities

IV. DELIVERY

Ship to:

FB5294 51 LRS LGRDDC

CP 011 82 505 784 5085

OSAN AB BLDG 824 SINJANG DONG

PYEONGTAEK CITY, KOREA, REPUBLIC OF

VII. REPORTS

A. The Contractor shall provide the following report:

1. Delivery Report (Appendix #1), as referenced in Section IV.A.2, which shall contain an accurate listing of all devices under contract (model, serial number, location). This report shall be submitted to the DLA POC.

VIII. INVOICING

A. Invoice shall be submitted via Wide Area Work Flow (WAWF) and shall be submitted in United States Dollars. The following website provides additional information regarding WAWF including information for “vendors getting started” with the system:

https://wawf.eb.mil/xhtml/unauth/help/help.xhtml.

IX. NETWORK FUNCTIONALITY

A. The Contractor shall provide devices that shall operate on and coexist on a network supporting all of the following:

1. Internet Protocol Version 4 (IPv4),

2. Internet Protocol Version 6 (IPv6),

3. A hybrid of IPv4 and IPv6.

B. The Contractor shall provide documentation and support to DLA for STIG compliant network configurations based on agency hardware/software (see section X.A. below).

X. NETWORK SECURITY

A. The Contractor shall provide devices that can be configured to comply with the current Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) titled Multifunction Device and Network Printer STIG (latest version and release), available at:

https://cyber.mil/.

B. All devices shall support Simple Network Management Protocol (SNMP) version 3 (v3). Versions 1 and 2 (SNMPv1/SNMPv2) shall be disabled.

C. All hard drives that are put into service within Federal agencies shall remain in their custody. In the instance where a device is removed by the Contractor, all hard drives, whether internal, external, or otherwise, shall remain in possession of the Government and not be removed with the device.

D. Contractors shall monitor industry standard vulnerability sites (e.g. http://nvd.nist.gov/, https://www.us-cert.gov/ncas/alerts, http://oval.mitre.org/) and take appropriate actions if their equipment is subject to a known vulnerability. When vulnerabilities are identified by the Contractor, DLA or its customers, the Contractor shall provide remediation for distribution to all installed equipment in accordance with USCYBERCOM TASKORD regulations unless a different time period is directed by USCYBERCOM via DLA. The TASKORD is Controlled Unclassified Information (CUI). The following is authorized to be quoted from the TASKORD for reference:

1. Assured Compliance Assessment Solution (ACAS) assigns severity scores of critical, high, medium and low to plug-in findings.

a. Critical findings reflect discovery of a common vulnerability and exposure (CVE) that poses significant risk to the confidentiality, integrity, and availability of DODIN Networks. Actions to mitigate or remediate critical vulnerabilities shall be initiated upon discover with the goal of mitigation/remediation within seven (7) calendar days.

b. Findings with a severity score of high shall be addressed in the same manner as vulnerabilities addressed via Information Assurance Vulnerability Alert (IAVA) directives and mitigated or remediated within twenty-one (21) calendar days of discovery.

c. Findings with severity scores of medium and low shall be addressed in accordance with local Approving Official (AO), Information System Security Manager (ISSM), or Information System Security Officer (ISSO) guidance until further notice.

d. In all instances, DOD components shall consider exposure to threat, mission impact, sensitivity of data, and current mitigating security controls when prioritizing implementation of fix actions.

E. In the event remediation cannot be achieved within the mandated timeline, the Contractor shall provide a Plan of Action and Milestones and receive approval thereof by the Customer’s agency Authorizing Official or designee for risk acceptance.

F. All Printers shall be International Organization for Standardization (ISO)/International Electrotechnical Commission (IEC) 15408 (Common Criteria) certified IAW CNSSP-11 using the National Information Assurance Partnership (NIAP) approved criteria or equivalent.

1. A device shall be acceptable if it is included on both the NIAP CCEVS Product Compliant List (https://www.niap-ccevs.org/Product/) and the Common Criteria Portal Certified Products list (http://www.commoncriteriaportal.org/products/).

2. All devices shall have current ISO/IEC 15408 certification and recertification, if applicable, before the Contractor can schedule lab time for testing. See section XI F. Guidance for Common Criteria Maintenance and Reevaluation is available at: https://www.niap-ccevs.org/documents and guidance/ ccevs/ scheme-pub-6.pdf

G. All devices shall be capable of obtaining accreditation through the Risk Management Framework (RMF) for DOD Information Technology (IT). As part of this, the Contractor agrees to provide all requested information and work in good faith with DLA so the DLA customers can expeditiously obtain RMF accreditation prior to device delivery and installation. The Contractor shall also provide devices for vulnerability and STIG testing to DLA or customer’s site at no cost to the Government. The Contractor further agrees that if the proposed device(s) does not obtain RMF accreditation, the contractor shall remove the device(s). Information regarding RMF is found in Risk Management Framework (RMF) for

DOD Information Technology (IT) Instruction 8510.1 dated 12 March 2014:

http://www.dtic.mil/whs/directives/corres/pdf/851001 2014.pdf. In order to maintain RMF and STIG compliance, devices are required to be delivered with the most up-to-date firmware, as outlined in section II.A.10.

H. At time of delivery, the Contractor shall:

1. Supply a SMARTCARD Public Key Infrastructure (PKI) Solution which is compliant with DODI

8520.03 and NIST FIPS 201 (PIV) standards. The contractor shall provide card readers that shall read and process all approved CAC and PIV cards. The Contractor shall maintain compliance with DOD-wide SMARTCARD and DOD PKI standards and support all approved physical cards.

2. Ensure that CAC authentication is available for scanning, printing and copying and shall be:

a. Capable of digitally signing emails using the senders DOD PKI Certificate(s).

b. Capable of encrypting emails using the receivers DOD PKI Certificate(s).

c. Capable of scan-to-file on networked devices.

d. In compliance with Homeland Security Presidential Directive-12 (HSPD-12).

I. The Contractor shall produce certificates of compliance, if requested.

XI. TESTING

A. All devices proposed in response to the contract shall be tested for compliance with Network Security as defined in section X after award. The Contractor shall deliver the devices for each Volume Band series, under each Functional Area, to DLA Information Operations J67E located at 430 Mifflin Avenue, Building 430, New Cumberland, PA 17070, for testing, at no cost to the government. Delivery coordination shall take place within five (5) business days of contract award. The MFD Configuration Manager can be reached at (717) 265-3131.

B. The estimated time for DLA testing is twenty (20) business days per device. Testing and approval shall be performed by the DLA Information Operations EMS Division in conjunction with the Contractor’s assistance. The Contractor shall provide onsite engineering assistance and other support necessary to configure, setup, and test the equipment as needed at no additional cost to the Government.

1. DLA tests devices to meet DOD RMF and STIG Compliance when applicable. If all devices pass the preliminary testing process, DLA shall submit a compliance memorandum to the Contractor informing them that the devices have passed the preliminary testing process. DLA reserves the right to offer devices to Customers after all devices in a particular category (MFD/printer/scanner) from all Contractors have been tested. In some cases, prior to being added to the DLA customer’s network, additional certification procedures and testing shall be required prior to risk acceptance.

If required by DLA, the Contractor shall deliver test devices to the DLA customer prior to proceeding with installation. DLA shall exercise due diligence to assist with technical mitigation and resolve any questions and/or concerns raised by that agency during the testing review process.

2. If the devices do not pass any of the testing procedures for any reason, DLA shall not proceed with installation of said devices at the customer locations and DLA shall terminate the contract.

C. A device shall not be tested if it does not meet the specification as outlined in sections II and III.

D. The devices shall be delivered with all required accessories, software, firmware, etc. Output paper handling accessories are not tested and shall not be delivered to the lab.

E. Approved devices previously submitted to DLA for testing are not required to be re-tested.

F. The Contractor shall deliver the devices for each model series, to DLA Information Operations J67E located at 430 Mifflin Avenue, Building 430, New Cumberland, PA 17071, for testing, at no cost to the government. Delivery coordination shall take place within five (5) business days of contract award.

G. The Contractor shall resolve non-compliance issues as quickly as possible. If the issues cannot be resolved within fourteen (14) calendar days, the test shall be suspended. After the non-compliance issues are resolved by the Contractor, the suspended session shall be scheduled when lab time is next available. If requested by DLA, the Contractor shall remove their devices from the lab to avoid delaying the next scheduled test at no additional cost to the Government.

H. For all devices tested and placed on the DLA contract, the Contractor shall collaborate with the DLA Configuration Manager to develop the testing results package. The Contractor shall develop the device Implementation Guide. The Implementation Guide shall provide step-by-step instructions and screenshots to configure the devices in accordance with the testing results. Government acceptance of the Implementation Guide is at the discretion of the DLA EMS Division.

I. The security requirements set forth in this SOW are minimum device specifications and have been identified as the basic requirements common across Government agencies. These are the minimum security requirements applicable to all devices awarded under this contract. Each ordering activity may have its own hardware/software acceptance processes. All devices shall be subject to ordering activity hardware/software evaluation processes at the order level. If the device fails a security evaluation, the Contractor may select a different technology or mitigate the failed controls to fulfill this requirement.

The Contractor shall be available to meet with the information technology (IT) and security personnel at a mutually convenient time during the evaluation process and shall identify a mutually acceptable solution. The Contractor shall provide the necessary equipment or expertise to complete security testing and integration into the existing environment. At the order level, the customer agency may require the Contractor to ship devices to a specific location for testing at time of order award.

J. If, during the life of the contract, a requirement in section IX and X is changed, updated or revised, the Contractor shall comply with the most current version of the requirement.

K. The Contractor shall remove all hardware from the DLA test lab within fourteen (14) calendar days upon notification of test completion at no additional cost to the Government.

XII. SUPPLY CHAIN RISK MANAGEMENT

A. As part of its proposal, the Contractor shall provide written documentation demonstrating how the integrity and security of all equipment, components thereof, repair parts and consumables it will provide and/or use in performing this contract will meet the standards set forth in National Institute of Standards and Technology (NIST) Special Publication 800-161. This documentation shall clearly demonstrate how the Contractor is taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services DLA receives through this contract. Additionally, this documentation shall provide specific details of what—

1. Policies the Contractor has in place to prevent both (a) the use of counterfeit or altered equipment, components thereof, consumables and parts and (b) their introduction into the Contractor’s supply chain;

2. Security procedures the Contractor uses to track the chain of custody of equipment, components thereof, consumables and parts, to include while this material is in storage and in transit; and

3. Steps the Contractor takes to ensure the integrity and authenticity of equipment, components thereof, repair parts and consumables to prevent tampering so they will perform according to specifications without additional unwanted functionality.

B. The Contractor shall continuously meet the standards of NIST Special Publication 800-161 while taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services provided through this contract.

Upon request, the Contractor shall provide written documentation meeting all requirements set forth in part A, above.

XIII. INSTALLATION SECURITY REQUIREMENTS

A. The Contractor shall comply with all Federal, DoD and local rules and regulations to obtain Government installation access in order to meet all response times identified within the PWS.

B. The Contractor shall comply with Government base access requirements as set forth in the base/ command regulations.

C. The Contractor shall be responsible for any and all fees associated with the application process and/or enrollment to access any installation or facility.

XIV. GENERAL CONDITIONS

A. The Contractor shall assign a single point of contact (POC) to coordinate with the Contracting Officer in all aspects of this contract within three (3) business days of receipt of the order. The Contractor shall provide its assigned POC’s name, title, business address, phone number and email address to the Contracting Officer.

B. The Contractor shall comply with the Section 508 accessibility requirements. By submission of its offer, the Contractor affirms that its Electronic Information Technology (EIT) supplies and services are accessible as outlined in the law, the standard, and FAR Subpart 39.2. The Contractor shall submit their completed Voluntary Product Accessible Template (VPAT®) or the provided VPAT document (Appendix #4) with their proposal.

C. Device make/models must be included on the NIAP CCEVS Product Compliant List (https://www.niap-ccevs.org/Product/).

XV. APPENDICES

A. Appendix #1: Delivery Report

B. Appendix #2: VPAT® Template

File details come from the government source that posted it. Updated .