Attachment A- Performance Work Statement 16 JUL 25.pdf
PDF 368 KB Posted
- Attached to
- Avaya Phone Switch Maintenance Federal contract opportunity
- Solicitation number
- HT940625QAvay
- Issued by
- Defense Health Agency
About this file
This Performance Work Statement (PWS) details a non-personal services contract for LAN-LINE phone switch services and maintenance for the Navy Medical Readiness Training Command (NMRTC) in Beaufort, SC. The contractor will provide an Avaya Call Manager (CM) 10.2 PBX package, configure and install system components, and deliver Tier 1 system maintenance with 24/7 coverage and 4-hour parts access for disaster recovery. The system includes 9 G450's supporting 192 analog phones, 192 Digital Communication Protocol (DCP) phones, and multiple VOIP channels, with capacity for over 1,000 IP Phones and three servers (Sonexis, Avaya Messaging R11, and CAIRS).
The contract has a base period from 30 September 2025 to 29 September 2026, with four option years extending through 29 September 2030 and a final 6-month option period ending 31 March 2031. The system upgrade will enable Naval Hospital Beaufort to be compliant with Defense Health Agency (DHA) and Defense Information Systems Agency (DISA) requirements. The PWS specifies detailed technical requirements for installation, configuration, training, emergency services, and cybersecurity measures, with the work to be performed at NMRTC Beaufort, Marine Corps Air Station Beaufort, and Marine Corps Recruit Depot Parris Island.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment C- Combined Synopsis - Alliance Technology Group LLC.pdf | ||
| Attachment B- Authorized Reseller_Agreement.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DHA PWS Template V13
November 16, 2021
Department of Defense Defense Health Agency
Performance Work Statement
Navy Medical Readiness Training Command (NMRTC) Beaufort, SC
Date: 14 July 2025
November 16, 2021
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide LAN-LINE phone switch services and maintenance for Navy Medical Readiness Training Command (NMRTC) BEAUFORT.
1.1.1 Description of Service/Introduction: The Government requires LAN-LINE phone switch services, installation and maintenance for Navy Medical Readiness Training Command (NMRTC) Beaufort, SC. The contractor shall provide the Avaya Call Manager (CM) 10.2 PBX package, configure and install all components outlined in Attachment 1. The Contractor shall also provide Tier 1 system maintenance with 24/7 coverage and 4-hour parts access for disaster recovery for the AVAYA CM10.2 PBX system. The switch has 9 G450’s with each service 192 analog phones, 192 Digital Communication Protocol (DCP) phones, and multiple VOIP channels, collectively accommodating over 1000 IP Phones with room for expansion. The CM10.2 PBX shall be capable of supporting up to 3,700 phones, with approximately 1,000 currently in use, and 3 servers, to include: Sonexis, which uses 100 ports for conference calls, Avaya Messaging R11 that provide virtual/e-faxing and voicemail to email services, and CAIRS provides call data and call accounting server/services. The CM10.2 allows Naval Hospital Beaufort the ability to be compliant with Defense Health Agency (DHA) and Defense Information Systems Agency (DISA) requirements.
Attachment 1
Product Code Item Description Qty
CM 10.2 Upgrade - Avaya Hardware and Software w/ Fax
Licenses
185446 AVAYA COMMUNICATIONS SOLUTION 1
184846 CALL MANAGEMENT SYSTEM MODEL 1
232256 SUPPORT ADVANTAGE REPORTING MODEL 1
232280 SUPPORT ADVANTAGE SELF SERVICE MODEL 1
265021 AVAYA AURA EXPERIENCE PORTAL MODEL 1
232258 SUPPORT ADVANTAGE MESSAGING MODEL 1
351679 SA PREFER SUPT AVAYA MSG R11 FAX 2 PORT 3YR AN PREPD 3
351685 SA PREFER SUPT AVAYA MSG R11 FX SECURE ADD ON 2PT
3YR AN PREPD
403220 AVAYA MESSAGING MODEL NEW 1
407997 AVAYA MESSAGING R11 FAX 2 PORT LIC:DS,SR 3
407998 AVAYA MESSAGING R11 FAX SECURE ADD ON 2 PORT
LIC:DS,SR
185840 CM MODEL ADDITIONS 1
405362641 POWER CORD USA 12
700519870 ASP 110 DELL R360 MIDRANGE SERVER ASBCE 3
November 16, 2021
384961 ASP MODEL NEW MODEL 1
434496 ASP 130 R6 REDHAT ENTERPRISE LINUX LIC:DS 3
700519836 ASP 130 DELL R660 HYPERVISOR A1 SERVER BUNDLE 1
700519839 ASP 130 DELL R660 HYPERVISOR A31 SERVER BUNDLE 2
232282 SUPPORT ADVANTAGE MODEL 1
345403 SA PREFER SUPT ASP 130 R6 RHEL 3YR AN 3
232282 SUPPORT ADVANTAGE MODEL 1
255853 SA ON-SITE 24X7 SUPT APPL MEDIUM SRV R2-D 3YR AN
PREPD
256196 SA ON-SITE 24X7 SUPT APPL LARGE SRV R2-D 3YR AN
PREPD
400244 SA RLS MGMT SURVEY ASSIST EACH APPLICATION SERVER 1
CM 10.2 Upgrade - Avaya Subscription Licenses and Support
230193 SA ON-SITE 24X7 CM MED GTWY 3YMO 9
253615 SA PREF ADS SAL GTWY SFTW ONLY TRK 2
266226 UTILITY MAINT AV CONF PHONES HW 1
434845 UC ESSENTIALS LIC FIXED SUBS ADJ LP 304
434846 UC ADVANCED LIC FIXED SUBS ADJ LP 1102
283332 SA LOCAL ADVANTAGE 3YMO 1406
405787 AXP BASIC LICENSE FIXED SUBS ADJ LP (CC Basic Licenses, To be removed from quote if customer seeks procurement of T-Metrics solution)
CM 10.2 Upgrade - Windows Licenses
500-
DG7GMGF0D5RK
Microsoft Windows Server 2022 Standard - 16 Core License Pack - Perpetual Microsoft Corporation CSP - DG7GMGF0D5RK 0005 3 $1,132.71 $3,398.13 Note: This order requires a custom domain which will be used to create your user accounts and email address to manage your licenses. Please provide a custom domain at the time of ordering following this format:
XXXcustomername.onmicrosoft.com. Do not use spac Microsoft Corporation CSP - CSP-Domain-New Note: To associate your licenses with an existing domain, please notify Carahsoft and a link will be provided to you. Microsoft Corporation CSP-CSP-Domain-Exist
CM 10.2 Upgrade - Post Award Site Survey
System Engineer Alliance Services - Site Survey, 2 Systems Engineers 32 Travel Travel and Expenses 2
CM 10.2 Upgrade - Alliance Professional Services Alliance - INSTL Specific tasks for project completion include: 1
November 16, 2021
- Participate on Customer Kick-Off Meeting and follow-up system design meetings, as appropriate
- Physical installation of up to (2) Physical servers
- Upgrade System Manager to R10.2 on a new Physical server
- Upgrade Session Manager to R10.2 on a new Physical server
- Upgrade Communication Manager to R10.2 on a new Physical server
- Update the settings files for the IP stations to register to the new Communication Manager
- Update firmware on the G4xx Media Gateways
- Register all Gateways to the new Communication Manager
- Installation, integration and translation of a High Availability SBC solution
- Includes (2) SBC and (1) EMS
- Installation, integration and translation of a Simplex CMS on a new Physical Server
- Integration and translation of up to (15) Call Center Agents
- Translations of a SIP integration with T-Metrics (Optional, no additional cost)
- Upgrade of Officelinx Messaging R10.8 to the latest version of Avaya Messaging on a new Physical server
- This is a Single Server Solution
- This is a JITC configured solution
- Configuration of Avaya Messaging for Advanced Inbound and Outbound faxing
- The Business Partner or customer is responsible for providing the SR140 Brooktrout licensing
- Customer/Business Partner to provide Windows Installed Servers
- Onsite Administration Training for Communication, System and Session Manager (Up to 2 consecutive days; no more than 6 hours a day)
- Onsite rack of a server for Compunetix
- Provide onsite support for the Compunetix engineer to get them remote access
- Onsite First Day of Service Support (Up to 4 hours)
CM 10.2 Upgrade - Alliance IA Services for Avaya Servers
PROJ-MGMT Project Management 90 IA Services Scans - STIG compliance scan 19.5 IA Services Scans - Vulnerability scan 19.5 IA Services Create checklist - Created from Avaya documentation 26 IA Services Create checklist - RHEL 8 80 IA Services Apply STIGs & create checklists - Windows Server 10 IA Services Apply STIGs & create checklists - Vmware ESXi / KVM 16
November 16, 2021
IA Services Apply STIGs & create checklists - Vmware / KVM VM 22 IA Services Create POA&M 52
Compunetix Conference Manager v5 RCM15000-V ConferenceManager5V Server Bundle - includes Vmware. Application
Software, RMM, SIP Key
SQLBASE2019 Microsoft SQL Server 1 SCMJITCSYS ConferenceManager5v JITC License Key (per system) *Requires
Blast Dial, SQL Standard, Encryption (ports12-199)
SCMJITC001 1 port - JITC License Key (per port) *Requires SCMJITCSYS 96 CM5V-001-AS ConnectNow+ System Annual Subscription (per port) 96 SCMEBCSYS-AS Emergency and Blast Dial Conferencing License Key (per system) -
Annual Subscription
CM5V-SRTP-AS ConferenceManager5v Encryption License - SRTP and TLS (per audio port), v15.0 and v16.0 - Annual Subscription
EXCPSERVER1U12 12 Month Service Agreement - Point of Sale and Renewals - For 1U server. (Covers hardware and software repair, plus software subscription; invoiced at point of sale)
SONO8PRO Covers up to 8 hours (per day) of dedicated onsite engineering support for install, during regular business hours
00-Cost Travel and Expenses for Installation 1 00-Cost Estimated Ground Freight (SC 29902) 1
CAIRS Call Accounting Telephone Management System: Up to
1,500 Ports
CNET-CAS-4 CAIRS Call Accounting System for CM10 1 SQL-2022 Microsoft SQL Server 2022 Standard 1 LABOR Installation & Training 56 DB-Con Database Conversion (Small) 1 Car Car 7 PD Per Diem 7 Travel Travel 1 Server-A Web Server with STIG Service 1 TS-1 Buffer Box CNET-Beaufort Base Year 1
CAIRS VoIP Discovery E911: Up to 1,500 Ports VoIP-D CAIRS VoIP Discovery 1500 LABOR Installation & Training 56 DB-Con Database Conversion (Small) 1 Car Car 7 PD Per Diem 7 CNET-Beaufort-VD Base Year 1
November 16, 2021
1.1.2 Background: Contract GS-35F0156V/Order # N6890822F0008 is the current contract under which the Government is receiving service and maintenance for the existing Call Manager (CM) system. The existing CM is a component of Avaya’s Communication Hardware and Software that processes calls, including making, routing, and terminating them. It also manages accounting and statistical collections, establishing signal connections between call endpoints, and providing telephony services to more than 900 end users. CM also interacts with other services such as multimedia conferencing (phone bridge), contact/call centers, and response systems.
1.1.3 Scope: The contractor shall provide AVAYA communication hardware and software to process calls. Configure and provide Call manager 10.2, Avaya Messaging R11, G450 media gateway, and SONEXIS call conferencing support and maintenance as well as performing to the standards in this PWS. The contractor shall provide services to include software updates and patching as required to maintain the system functionality, as well as inform the Command and Points of Contact listed in section 4.0 of necessary hardware, software, and/or system component updates and upgrades to ensure minimal downtime and reliability of equipment and services.
1.1.4 Objectives: To configure and install all components to Avaya CM 10.2 package and provide tier 1 system maintenance with 24/7 coverage and 4-hour parts access for disaster recovery for the AVAYA CM10.2 PBX system at Naval Hospital Beaufort. The Call Manager 10.2 (CM10.2) allows Naval Hospital Beaufort the ability to be compliant with Defense Health Agency (DHA) and Defense Information Systems Agency (DISA) requirements.
1.1.5 Period of Performance (PoP): The contractor shall begin services per the Performance Work Statement on 30 September 2025. The Period of Performance has a Base Period of 30 September 2025 – 29 September 2026, 4 Option Years and 1, 6-month Option Period.
Base Year: 30 September 2025 – 29 September 2026 Option Year 1: 30 September 2026 – 29 September 2027 Option Year 2: 30 September 2027 – 29 September 2028 Option Year 3: 30 September 2028 – 29 September 2029 Option Year 4: 30 September 2029 – 29 September 2030 Option Period 5: 30 September 2030 – 31 March 2031
1.2 Administrative Specifications
1.2.1 Place of Performance: The work shall be performed at NMRTC Beaufort, Marine Corps Air Station Beaufort and Marine Corps Recruit Depot Parris Island.
1.2.2 Recognized Federal Holidays: The vendor will not be required to provide service and/or maintenance on recognized federal Holidays or presidential executive orders unless deemed an emergency. (Reference paragraph 2.4.1 Major Outages).
1.2.3 Hours of Operation: The contractor is responsible for conducting business Monday thru Friday 0700 – 1600, except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, Presidential Executive Orders or similar Government directed facility closings. The contractor must, at all times maintain an adequate
November 16, 2021 workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.2.4 Contracting Officer Representative (COR): The COR will be identified by COR Appointment Letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements; including Government drawings; designs; specifications; monitor Contractor's performance and notify both the Contracting Officer and Contractor of any deficiencies;
coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the contract.
1.3 Key Personnel (Contractor): The contractor shall provide a contract manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the CO. The contract manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be available between 7:00 a.m. to 4:00 p.m., Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons. Qualifications for all key personnel are listed below: Must have knowledgeable insight on all aspect of our current phone switch system.
1.4 Security
1.4.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM
5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.4.2 Follow the DHA Personnel Security Office guidelines for submittal of security clearances.
Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security Office can be reached at (703) 275-6038.
1.5 Contractor Identification. Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as
November 16, 2021 contractor support personnel in all forms of communication with all entities with whom DHA/Deputy Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.
Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
1.5.1 Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order.
Contractor personnel shall make their contractor status known during introductions.
1.5.2 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.5.3 Contractor personnel performing services in a contractor capacity in a government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the Government understands that the person is contractor support personnel.
If a company’s Identification Badge is not readily available, the contractor will be required to stop at the Materials Management Department located on the 1st floor and sign the visitors log and pick up and wear a VISITOR’S BADGE. The contractor will be required to return to Materials Management to sign out of the log and return visitor’s badge upon completion.
2.0 SPECIFIC TASKS
2.1 Installation & Configuration – Contracting personnel shall install, configure, and integrate all new systems, software, and components relating to Avaya Communications Solutions under this contract Physical Installation shall include up to 3 new servers, an upgraded System Manager, Communication Manager, and firmware to include data migration from the current system to the new Call Manager 10.2. The current ESNA system shall be uninstalled and replaced with the new Avaya Messaging R11 server with all ports and licenses installed for voicemail, faxing, virtual faxing, and automated attendant lines. ESNA database is to be migrated to the new Avaya Messaging R11 server. All servers will be replaced with the new servers and updated operating systems. The current VeraSmart Call Auditing system (CALERO) will be replaced with the installation and configuration of CAIRS Call Accounting Telephone Management System.
Sonexis Call Conferencing Manager will be replaced with an upgrade Conference Manager 5V bundle which includes VMWare, Application Software, RMM, and SIP Keys.
November 16, 2021
2.2 Site Surveys & Information Assurance Pre-Installation – All contracting personnel will be expected to coordinate with Naval Hospital Beaufort for planning a site survey with the vendor to determine precise locations of equipment, assessing the network infrastructure, assessing the accessibility, and identifying potential obstacles that may cause any complications with STIG Compliancy. The contracting personnel is expected to perform vulnerability scans, create a checklist, and apply STIGS to Windows Servers, VMWare ESXi, and VMWare virtual machines.
These STIGS will be applied before the servers are shipped to Naval Hospital Beaufort.
2.3 Education & Training – Contracting personnel shall perform Onsite Administration Training for Communication, System and Session Manager for up to 2 consecutive days for no more than 6 hours a day. This training shall include all Call Manager components, CAIRS Call Accounting Systems, and CAIRS VOIP Discovery and E911 services for at a minimum two (2) Government personnel. Additionally, the Contractor shall be subject matter experts (SME) to ensure all specific training objectives are met
2.3.1 Specific Training Objectives: The goal is to (a) achieve comprehensive training and proficiency in all systems, including the new CAIRS and Avaya Messaging systems, thereby eliminating reliance on Avaya for Tier 1 Support at the medical station and (b) complete Onsite Administration Training for Communication, System and Session Manager.
2.4 Emergency Services. On occasion, services may be required to support an activation or exercise of contingency plans outside the normal duty hours.
2.4.1 Major Outages – A major outage is defined as a complete system failure that has occurred, preventing all inbound and outbound calls and faxes (not due to power outages), and a server malfunction is hindering service to where Avaya technicians will be required for resolution. Upon receipt of notification, the contractor's technician must call and speak directly with the Naval Hospital Beaufort’s Communications Officer. If after hours, the Command Duty Officer (CDO).
The contractor must provide the estimated time of arrival to the site and if after hours request the CDO contact the Head of the Information Technology Department, so the technician may obtain access to the Naval Hospital's Telephone Switch Room.
2.4.2 When a major outage is not cleared and/or no status report is given to Naval Hospital Beaufort after four (4) hours, Naval Hospital Beaufort will escalate problem to the contractor supervisor. At the completion of repairs for major outages and/or minor problems, Naval Hospital Beaufort's Communications Officer will be notified and provided written documentation as to the measures that were taken by the technician to complete the repair.
2.4.3 Contractor will provide direct contact information (phone numbers and/or email) for 24/7 coverage upon award of the contract, to include contractor supervisor. To allow access for repairs/maintenance the contractor will provide a list of all technicians' names that require access to Naval Hospital Beaufort. This information (contact information/list of technicians) must be kept current. Personnel not on the list will be denied access at no cost to the Government.
November 16, 2021
2.4.4 Upon gaining access to the Naval Hospital, gaining access to the telephone switch room may take upwards of an hour for Naval Hospital Staff to be contacted and report. As such, this delay will not be deemed a customers' failure to provide access.
2.4.5 Service level provided will be by the contractor selected to perform the work. Naval Hospital Beaufort reserves the right at any time to have a technician who is either not compatible with Naval Hospital Beaufort's environment, or who is not providing the level of service expected replaced by the Contractor.
2.4.6 Government Specific Task. Naval Hospital Beaufort performs network security scans daily. The scan identifies software security vulnerabilities. Example: Naval Hospital will provide the contractor a report listing the existing software security vulnerabilities needing remediating monthly. After receipt of the report the contractor shall provide written documentation approving the Naval Hospital's installation of the software security patches and/or a report stating reasons why the necessary updates are not possible in the monthly report. Any problems located by the Contractor that the Contractor deems not covered under this maintenance contract will be discussed with Naval Hospital Beaufort's representative and/or the Head of the Information Technology Department.
2.5 Contractor Travel: The contractor shall travel to the worksite for installation of the CM10 system and to conduct onsite training. The contractor shall access the Joint Travel Regulations website, https://www.travel.dod.mil/Policy Regulations/Joint-Travel-Regulations/ to review travel and regulatory guidance.
2.6 Quality Assurance (QA): The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
2.7 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.
2.7.1 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
2.8 GOVERNMENT-FURNISHED PROPERTY AND SERVICES.
2.8.1 Government Responsibility for Damage: The Government shall not be responsible, in any way, for damage to the Contractor employees’ personal belongings brought onto the site.
https://www.travel.dod.mil/Policy
November 16, 2021
2.8.2 Telephones: Government telephone facilities will be made available to the Contractor for official business use only. This includes contacting manufacturers, suppliers, and Government users.
2.9 CONTRACTOR-FURNISHED ITEMS AND SERVICES
2.9.1 Responsibility: Contractor shall furnish all supplies, materials, repair or replacement parts, tools, equipment, software upgrading and labor necessary to efficiently and acceptably perform the requirements of this contract.
2.9.2 Damages: The Contractor shall protect all facilities from damage caused by the Contractor and shall repair, at no additional cost to the Government, all damages caused by the Contractor’s activities. During performance of services, Contractor shall keep Navy Medical Readiness Training Command (NMRTC) site safe, neat, clean, and orderly. Contractor shall be responsible for all means, methods, techniques, sequences, and procedures of the service.
November 16, 2021
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE
PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D- Services)
2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R- Services)
2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the Government’s plan.
2.2 Acronyms:
AIS Automated Information System
APL Approved Products List APL
AQL Acceptable Quality Level
ARRT Acquisition Requirements Roadmap Tool
ATO Authority to Operate
B2B Business-2-Business
CAC Common Access Card
CAP Cloud Access Point
November 16, 2021
CCEVS Common Criteria Cybersecurity Evaluation and Validation Scheme
CDI Covered Defense Information
CE Computer Environment
CDRL Contract Data Requirement List
CIO Chief Information Officer
CJCSM Chairman of the Joint Chiefs of Staff Manual
CMMC Cybersecurity Maturity Model Certification
CMR Contractor Manpower Reporting
CNSSI Committee on National Security Systems Instruction
CO Contracting Officer(s)
CONUS Continental United States (excludes Alaska and Hawaii)
COR Contracting Officer Representative
COTR Contracting Officer's Technical Representative
CSP Cloud Service Provider
CSSP Cyber Security Service Provider
CUI Controlled Unclassified Information
DAD-A Deputy Assistant Director for Acquisition
DC3 DoD Cyber Crime Center
DD Form 254 Department of Defense Contract Security Requirement List (if applicable)
DB Design-Build
DBB Design-Bid-Build
DFARS Defense Federal Acquisition Regulation Supplement
DHA Defense Health Agency
DISA Defense Information System Agency
DoD Department of Defense
DoDD Department of Defense Directive
DoDI Department of Defense Instruction
DSAs Data Sharing Agreements
November 16, 2021
DSAA Data Sharing Agreement Application
DMZ Demilitarized Zone
DoDM Department of Defense Manual
DPCLO DHA Privacy and Civil Liberties Office
DUA Data Use Agreement eMSM Enhanced Multi-Service Markets
EULA End User License Agreement
EVM Earned Value Management
FAR Federal Acquisition Regulation
FCI Federal contract information
FE Facilities Enterprise
FedRAMP Federal Risk Authorization and Management Program
FISMA Federal Information Security Modernization Act
FRCS Facility Related Control Systems
FSO Facilities Security Officer
HA Health Affairs
HIPAA Health Insurance Portability and Accountability Act
HCA Head of the Contracting Activity
HIT Health Information Technology
IGCE Independent Government Cost Estimate
IA Information Assurance
IO Initial Outfitting
I/O In/Out Processing Portal
IPv Internet Protocol Version
IS Information System
ISP Internet Service Provider
IT Information Technology
ISCM Information Security Continuous Monitoring
November 16, 2021
IV&V Independent Verification & Validation
MedCOI Medical Community of Interest
MHS Military Health System
MIL-STD Military Standard
MTFs Military Treatment Facilities
NCR National Capitol Region
NDA Non-Disclosure Agreement
NIAP National Information Assurance Partnership
NIST National Institute of Standards and Technology
OCONUS Outside Continental United States (includes Alaska and Hawaii)
ODC Other Direct Costs
OPM Office of Personal Management
OSD Office of the Secretary of Defense
P-ATO Personal Authorization to Operate
P&R Personnel and Readiness
PGI Procedures, Guidance and Information
PDT Project Delivery Team
PHI Protected Health Information
PII Personally Identifiable Information
PIT Platform Information Technology
PK Public Key
PKI Public Key Infrastructure
POA&M Plan of Action and Milestones
POC Point of Contact
PMO Program Management Office
PoP Period of Performance
PP Personal Property
PPSM Ports, Protocols, and Services Management
November 16, 2021
PRS Performance Requirements Summary
PSP Personnel Security Program
PWS Performance Work Statement
QA Quality Assurance
QAP Quality Assurance Program
QASP Quality Assurance Surveillance Plan
QC Quality Control
QCP Quality Control Plan
RFP Request for Proposal
RFQ Request for Quotation
RMF Risk Management Framework
SP Special Publication
SPRS Supplier Performance Risk System
SRM Sustainment, Restoration and Modernization
SRG Security Requirements Guides
STIG Security Technical Implementation Guides
TOS Terms of Service
US United States
UFC Unified Facilities Criteria
VPN Virtual Private Network
XML Extensible Markup Language
November 16, 2021
PART 3
3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:
3.1 Services: The Government:
☐ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Government Furnished Services required in support of this contract/task orders.
These Services are:
Naval Hospital Beaufort performs network security scans on a daily basis. The scan identifies software security vulnerabilities. Naval Hospital Beaufort will provide the contractor a report listing the existing software security vulnerabilities needing remediating on a monthly basis. After receipt of the report the contractor shall provide written documentation approving Naval Hospital's installation of the software security patches and/or a report stating reasons why the necessary updates are not possible in the monthly report. Any problems located by the contractor that the contractor deems not covered under this maintenance contract will be discussed with Naval Hospital Beaufort's representative and/or the Head of the Information Technology Department.
3.2 Facilities: The Government:
X Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Facilities in support of this contract/task orders. The Government provided Facilities are described below:
3.3 Utilities: The Government:
X Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is Not Applicable.
November 16, 2021
☐ WILL provide Utilities in support of this contract/task orders. The Government provided Utilities are described below:
3.4 Equipment: The Government:
X Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Equipment in support of this contract/task orders. The Government provided Equipment is described below:
3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application
The contractor shall be responsible for obtaining and maintaining access, training, and successful operation of the PIEE/GFP Module application for the entirety of the contract/task order PoP. The PIEE GFP Module application is located at the following website: https://wawf.eb.mil/piee-landing/. Access to PIEE/GFP Module application training materials and in-depth information applicable to the contractor’s responsibilities regarding GFP can be found at the following website: https://dodprocurementtoolbox.com/.
Contracting Office Responsibilities:
The Contracting Officer’s Representative (COR) shall ensure close coordination and validation of the GFP items with DHA Accountable Property Officer prior to uploading the GFP Attachment into the PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Officer’s Representative’s (COR) responsibility to prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.
The COR will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the Contracting Office and requested within the PIEE/GFP Module system.
Contractor Responsibilities:
A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete, and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their https://wawf.eb.mil/piee-landing/ https://wawf.eb.mil/piee-landing/ https://dodprocurementtoolbox.com/
November 16, 2021 contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.
The contractor shall report semi-annually 100% inventories, reconciliations, and final disposition of GFP provided by the government. Final invoices will not be paid pending GFP reconciliation.
Contractors shall be aware of and ensure compliance with applicable FAR Part 45, DFARS 245 and 252.245, Defense Pricing and Contracting Policies, Procurement Integrated Enterprise Environment Standards, DHA Administrative Instruction 094 and DHA Guidance.
3.5 Materials: The Government:
X Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ IS providing Materials in support of this contract/task orders. The Government-provided Materials are described below:
November 16, 2021
PART 4
4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES
4.1 Services: The Contractor:
X Will NOT provide Contractor Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☐ WILL provide Contractor Furnished Services required in support of this contract/task orders.
These Services are described below:
4.2 General: The contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.
4.3 Secret Facility Clearance: The contractor shall possess and maintain a SECRET facility clearance from the Defense Security Service. The contractor’s employees, performing work in support of this contract shall have been granted a SECRET security clearance from the Defense Industrial Security Clearance Office. N/A
4.4 Materials: The contractor shall provide all supplies, parts and tools necessary to perform communication capabilities as defined in this Performance Work Statement (PWS).
4.5 Equipment: The contractor shall provide all necessary equipment to maintain the AVAYA phone switch located within NMRTC BEAUFORT.
4.6 Facilities: The contractor shall meet with the Information Technology Department located at NMRTC Beaufort at 1 Pinckney BLVD, Beaufort Sc 29902 to conduct any requirements under this PWS.
November 16, 2021
PART 5
5.0 SPECIFIC TASKS
5.1 Special Qualifications: N/A
5.1.1 When using education/certification in conjunction with labor categories, the COR in coordination with the CO must establish a review process of contractor personnel to ensure labor category requirements are met. The vendor must provide personnel who are skilled, qualified, and certified to install, configure, maintain, and troubleshoot the requested system upgrades to the
CM10.1.
November 16, 2021
PART 6
6.0 INFORMATION TECHNOLOGY & SECURITY
6.1 All work under this contract is unclassified.
6.2 The TIER 1 or TIER 2 levels and position sensitivity designation for positions under this contract is: (Requirement must be checked in order to be a requirement for this PWS.)
6.2.1 TIER II: Non-critical sensitive position.
63 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements: N/A
6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office (DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data. After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.
6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.
6.4 Training
6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements: N/A
6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoDM 8140.03. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.
6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoDM 8140.03, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001.
6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoDM 8140.03.
November 16, 2021
6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by DoD 8570.01–M.
6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.
6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.
6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.
6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor IS: Reserved.
6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800-171), in accordance with DFARS clause 252.204-7012.
6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800-171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment Methodology requirement flows down to subcontractors.
6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)
6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.
6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.
6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.
6.5.4 Cybersecurity Maturity Model Certification (CMMC) (When applicable): The CMMC (DFARS clause 252.204-7021) builds upon the NIST SP 800-171 DoD Assessment Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and https://www.sprs.csd.disa.mil/
November 16, 2021
DoD Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk. The CMMC requirement flows down to subcontractors.
6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization (3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.
6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.
6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.
6.5.8 Cyber Incident Reporting Requirement
6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:
6.5.8.1.1 Conduct a review for evidence of compromise of covered defense information, including, but not limited to, identifying compromised computers, servers, specific data, and user accounts. This review shall also include analyzing covered contractor information system(s) that were part of the cyber incident, as well as other IS on the contractor’s network(s), that may have been accessed as a result of the incident in order to identify compromised covered defense information, or that affect the contractor’s ability to provide operationally critical support; and
6.5.8.1.2 In accordance with DFARS clause 252.204-7012, rapidly report (within 72 hours) cyber incidents involving DoD CUI to DoD Cyber Crime Center (DC3) via https://www.cmmcab.org/ https://www.fedramp.gov/
November 16, 2021 https://dibnet.dod.mil/portal/intranet/. In the event of a cybersecurity incident involving a CUI- Specific breach (i.e., PII/PHI), the contractor, in addition to reporting to the DC3, shall follow the incident reporting guidance prescribed in the TRICARE Operations Manual, Chapter 1, Section 5, “Compliance with Federal Statutes” at https://manuals.health.mil/
6.5.8.2 Cyber incident report: The cyber incident report shall be treated as information created by or for DoD and shall include, at a minimum, the required elements as prescribed at the https://dibnet.dod.mil/portal/intranet/.
6.5.8.3 Medium assurance certificate requirement: In order to report cyber incidents in accordance with this clause, the contractor or subcontractor shall have or acquire a DoD-approved medium assurance certificate to report cyber incidents. For information on obtaining a DoD-approved medium assurance certificate, see https://public.cyber.mil/
6.5.9 Malicious software: When the contractor or subcontractors discover and isolate malicious software in connection with a reported cyber incident, submit the malicious software to DC3 in accordance with instructions provided by DC3 or the Contracting Officer. Do not send the malicious software to the Contracting Officer.
6.5.10 Media preservation and protection: When a contractor discovers a cyber incident has occurred, the contractor shall preserve and protect images of all known affected IS and all relevant monitoring/packet capture data for at least 90 days from the submission of the cyber incident report to allow DoD to request the media or decline interest.
6.5.11 Access to additional information or equipment necessary for forensic analysis: Upon request by DoD, the contractor shall provide DoD with access to additional information or equipment that is necessary to conduct a forensic analysis.
6.5.12 Cyber incident damage assessment activities: If DoD elects to conduct a damage assessment, the CO will request that the contractor provide all of the damage assessment information gathered in accordance with paragraph (e) of DFARS clause 252.204-7012.
6.5.13 Apply other IS security measures when the contractor reasonably determines that IS security measures may be required to provide adequate security in a dynamic environment or to accommodate special circumstances (e.g., HIPAA) and any individual, isolated, or temporary deficiencies based on an assessed risk or vulnerability. These measures may be addressed in a system security plan.
6.5.14 The contractor shall maintain within the US or US territories all Government data that is not physically located on DoD premises, unless the contractor receives written notification from the CO to use another location, in accordance with DFARS 239.7602-2(a).
6.5.15. The contractor shall mitigate supply chain risk to the government by complying with DFARS 252.239-7018 and only utilizing unified capability equipment identified on the DODIN Unified Capabilities Approved Products List (https://aplits.disa.mil/processAPList), unless granted a waiver in accordance with DODI 8100.04, DOD Unified Capabilities (UC).
https://dibnet.dod.mil/portal/intranet/ https://manuals.health.mil/ https://public.cyber.mil/ https://aplits.disa.mil/processAPList
November 16, 2021
6.6 Risk Management Framework (RMF) for DoD IT: All IS, Platform Information Technology (PIT) and IT Services or Products under this requirement, that receive, transmit, store, or process nonpublic government data must be accredited in accordance with DoDI…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .