Attachment A - Statement of Work.pdf

PDF 1 MB Posted

Attached to
Professional, Administrative, Computational, and Engineering Services contract (PACE V) Federal contract opportunity
Solicitation number
80GRC020R0010
Issued by
National Aeronautics and Space Administration Glenn Research Center

About this file

This statement of work outlines the information technology services required by the National Aeronautics and Space Administration Glenn Research Center through the Professional, Administrative, Computational, and Engineering Services contract (PACE V). Key services include applications development and support, communications support, computing infrastructure and platform services, cybersecurity, end-user support, information management, and IT management functions. Specific requirements span areas such as application hosting and development, multimedia engineering, scientific and engineering applications support, data center management, server administration, storage administration, test facility IT support, identity management, and cybersecurity engineering. The contractor must provide skilled resources and project management across these diverse IT domains to support the Glenn Research Center's diverse programs, projects, and institutional activities.

View the file

Other files for this federal contract opportunity

Other files attached to Professional, Administrative, Computational, and Engineering Services contract (PACE V), newest first.
File Type Posted
Additional Questions and Answers for 80GRC020R0010 Amendment 04.pdf PDF
80GRC020R0010 Amendment 04.pdf PDF
Additional Questions and Answers for PACE V RFP 80GRC020R0010.pdf PDF
80GRC020R0010 Amendment 03.pdf PDF
80GRC020R0010 Amendment 02.pdf PDF
Attachment M - Historical Other Direct Costs updated.xlsx XLSX spreadsheet
Attachment C - Historical WYE and ODC by Work Area updated.pdf PDF
Attachment B - Pricing Spreadsheet MS Excel Workbook Template updated.xlsx XLSX spreadsheet
Questions and Answers for 80GRC020R0010.pdf PDF
Attachment K - Historical Labor Category Descriptions Updated.pdf PDF
80GRC020R0010 Amendment 01.pdf PDF
Attachment TS - 2 PACE V Technical Scenario 2.pdf PDF
80GRC020R0010 Rquest for Proposals (RFP).pdf PDF
Attachment K - Historical Labor Category Descriptions.pdf PDF
Attachment I - Past Performance Questionnaire.doc DOC document
Attachment IS - 2 PACE V Innovation Scenario 2.pdf PDF
Attachment E - E(d) GRC Baseline Template.xlsx XLSX spreadsheet
Attachment E - E(e) GRC Headcount Template.xlsx XLSX spreadsheet
Attachment IS - 1 PACE V Innovation Scenario 1.pdf PDF
Attachment E - E(b) GRC 533 Template.xlsx XLSX spreadsheet
Attachment M - Historical Other Direct Costs.xlsx XLSX spreadsheet
Attachment L - Cognizant Audit Office Template.xlsx XLSX spreadsheet
Attachment J - Sample Work Orders.pdf PDF
Attachment P - Government Furnished Property.xlsx XLSX spreadsheet
Attachment D - IT Master Plan 2020.pdf PDF
Attachment TS - 1 PACE V Technical Scenario 1.pdf PDF
Attachment H - Client Authorization Letter (CAL).doc DOC document
Attachment E - E(c) GRC Accounting Calendar Template.xlsx XLSX spreadsheet
Attachment B - Pricing Spreadsheet MS Excel Workbook Template.xlsx XLSX spreadsheet
Attachment N - Data Center Information.xlsx XLSX spreadsheet
Attachment Q - Large File Transfer User Guide.pdf PDF
Attachment C - Historical WYE and ODC by Work Area.pdf PDF
Attachment E - E(a) GRC 533 Supplemental Cost Report Template.xlsx XLSX spreadsheet
Attachment O - ITS-HBK_2810_ 06_2B.pdf PDF
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

80GRC020R0010

Statement of Work

GLENN RESEARCH CENTER

PROFESSIONAL, ADMINISTRATIVE, COMPUTATIONAL, AND ENGINEERING

SERVICES CONTRACT – V (PACE V)

1. INTRODUCTION 7

1.1. GOALS AND OBJECTIVES 7

1.2. TRANSFORMATION AND INNOVATION 8

1.3. REMOTE WORK AND TELEWORK 9

1.4. SCOPE 9

2. MANAGEMENT AND ADMINISTRATION 10

2.1. HEALTH AND SAFETY 10

2.2. WORK AUTHORIZATION 10

2.3. RESOURCES MANAGEMENT 11

2.4. RISK MANAGEMENT 11

2.5. PROPERTY MANAGEMENT 11

2.6. RECORDS MANAGEMENT 12

2.7. MISSION SUPPORT - PURCHASING 12

2.8. CONFIGURATION MANAGEMENT 13

2.9. QUALITY MANAGEMENT AND CONTROL 14

2.10. PROJECT / SYSTEM INTEGRATION 14

3. INFORMATION SERVICES 14

3.1. APPLICATIONS 15

3.1.1. WEB AND NATIVE APPLICATION SERVICES 16

3.1.1.1. APPLICATION MONITORING AND ADMINISTRATION 16

3.1.1.2. WEB APPLICATION GOVERNANCE 17

3.1.1.3. APPLICATION PORTFOLIO MANAGEMENT 17

3.1.1.4. SOFTWARE LIFE-CYCLE MANAGEMENT 17

3.1.1.5. WEB SITE DEVELOPMENT AND MAINTENANCE 18

3.1.1.6. WEB AND APPLICATIONS GRAPHIC DESIGN 19

3.1.1.7. WEB SITE HOSTING AS A SERVICE 19

3.1.1.8. CUSTOM APPLICATIONS DEVELOPMENT 20

3.1.1.9. GOVERNMENT AND COMMERCIAL APPLICATION DELIVERY 21

3.1.1.10. APPLICATION MODERNIZATION 22

3.1.2. BUSINESS MANAGEMENT APPLICATIONS 22

3.1.2.1. ELECTRONIC WORKFLOW DEVELOPMENT AND BUSINESS PROCESS AUTOMATION (BPA) 22

3.1.3. INFRASTRUCTURE APPLICATIONS 22

3.1.3.1. USABILITY AND SECTION 508 COMPLIANCE 22

3.1.3.2. DATABASE ADMINISTRATION 23

3.1.3.3. ELECTRONIC AUTHENTICATION AND LAUNCHPAD 23

3.1.3.4. SUPPORT FOR OFFICE OF PROTECTIVE SERVICES (OPS) SYSTEMS 24

3.1.4. SCIENCE AND ENGINEERING APPLICATIONS 24

3.1.4.1. SCIENTIFIC APPLICATIONS AND SERVICES SUPPORT 24

3.2. COMMUNICATIONS 24

3.2.1. MEDIA SERVICES 24

3.2.1.1. VIDEO CONFERENCING AND COLLABORATION FACILITY SUPPORT 24

3.2.1.2. MULTIMEDIA ENGINEERING, INSTALLATION, AND MAINTENANCE 25

3.2.1.3. MULTIMEDIA MAINTENANCE AND REPAIR 25

3.2.2. HIGHLY SPECIALIZED IT COMMUNICATIONS 26

3.2.2.1. ADVANCED NETWORKING AND COMMUNICATIONS 26

3.2.2.2. SPACE COMMUNICATIONS 26

3.2.2.3. NASA SPACE DELAY/DISRUPTION TOLERANT NETWORK (DTN) READINESS PROJECT 27

3.2.2.4. UNMANNED AIRCRAFT SYSTEMS (UAS) IN THE NAS/NEXTGEN SUPPORT 27

3.3. COMPUTING 27

3.3.1. IT FACILITIES MANAGEMENT 27

3.3.1.1. DATA CENTER MANAGEMENT 28

3.3.1.2. DELIVER INFRASTRUCTURE AND PLATFORM AS A SERVICE (IAAS AND PAAS) 28

3.3.1.3. SERVER, STORAGE, AND IT FACILITY PERFORMANCE MONITORING 29

3.3.2. HIGH-PERFORMANCE COMPUTING 30

3.3.2.1. HIGH PERFORMANCE COMPUTING 30

3.3.3. STORAGE 30

3.3.3.1. STORAGE ADMINISTRATION 30

3.3.4. HIGHLY SPECIALIZED IT COMPUTING 31

3.3.4.1. TEST FACILITY SUPPORT 31

3.3.4.2. EMBEDDED COMPUTING 31

3.4. CYBERSECURITY 32

3.4.1. IDENTIFY 33

3.4.1.1. INFORMATION SYSTEM SECURITY OFFICIAL (ISSO) SUPPORT 33

3.4.1.2. PROGRAM PROTECTION (ASSESSMENT AND AUTHORIZATION MANAGEMENT, CONSULTING, AND AUDITING

SERVICES) 33

3.4.1.3. INFORMATION PROTECTION 34

3.4.2. PROTECT 34

3.4.2.1. CYBERSECURITY ARCHITECTURE, ENGINEERING, AND TECHNICAL STANDARDS 35

3.4.2.2. IDENTITY, CREDENTIALING, ACCESS, AND EMERGENCY MANAGEMENT 36

3.4.2.3. NASA ACCESS MANAGEMENT SYSTEM (NAMS) 36

3.4.2.4. CYBERSECURITY ENGINEERING 36

3.4.2.5. CONSULTATION AND OUTREACH 36

3.4.2.6. ORGANIZATIONAL COMPUTER SECURITY OFFICIAL SUPPORT 37

3.4.2.7. INFORMATION TECHNOLOGY SECURITY AWARENESS AND TRAINING 37

3.4.2.8. OFFICE OF CYBERSECURITY SERVICES (OCSS) 37

3.4.3. DETECT 37

3.4.3.1. CYBERSECURITY MANAGEMENT AND OPERATIONS 38

3.4.3.2. TRAFFIC CAPTURING AND ANALYSIS 38

3.4.3.3. VULNERABILITY AND DISCOVERY SCANNING 38

3.4.3.4. CONSOLIDATED LOGGING 38

3.4.3.5. WEB SITE AND APPLICATION SECURITY 39

3.4.3.6. DATA LOSS PREVENTION (DLP) 39

3.4.4. RESPOND 40

3.4.4.1. CYBERSECURITY INCIDENT RESPONSE 40

3.5. END-USER 40

3.5.1. COLLABORATION 40

3.5.1.1. COLLABORATIVE TOOLS 41

3.5.1.2. MANAGEMENT OF TOOLSETS 41

3.5.1.3. TOOL ANALYSIS AND ADOPTION 41

3.5.1.4. SOCIAL NETWORKING 41

3.5.1.5. DOCUMENT MANAGEMENT 41

3.5.1.6. ELECTRONIC DOCUMENT MANAGEMENT 42

3.5.2. MESSAGING AND DIRECTORY 42

3.5.2.1. NASA ENTERPRISE DIRECTORY SUPPORT (NED) 42

3.5.2.2. NASA LIST SERVER SUPPORT 42

3.5.3. SUPPORT 43

3.5.3.1. NASA ENTERPRISE ACCOUNT MANAGEMENT 43

3.5.3.2. MOBILE MANAGEMENT SERVICES 43

3.5.3.3. ENGINEERING AND DESIGN ENVIRONMENT SYSTEMS ADMINISTRATION SUPPORT 43

3.5.3.4. USER ASSISTANCE TEAM CENTER 44

3.5.3.5. ENHANCED END-USER SYSTEMS AND ADMINISTRATION SUPPORT 45

3.6. INFORMATION MANAGEMENT 45

3.6.1. DATA GOVERNANCE 45

3.6.1.1. TAXONOMY DISCOVERY AND FORMULATION 45

3.6.2. RECORDS MANAGEMENT 45

3.6.2.1. ELECTRONIC RECORDS MANAGEMENT 45

3.6.2.2. KNOWLEDGE MANAGEMENT 46

3.6.2.2.1. KNOWLEDGE TOOL SUPPORT 46

3.6.3. SCIENTIFIC AND TECHNICAL INFORMATION 46

3.6.3.1. SCIENTIFIC AND TECHNICAL PUBLISHING SUPPORT 46

3.6.4. UNIFIED DATA LIFE-CYCLE 46

3.6.4.1. DATA MANAGEMENT SYSTEM (DMS) 46

3.6.4.2. DOCUMENT AND DATA SCANNING 47

3.6.4.3. MULTIMEDIA REPOSITORY MANAGEMENT 47

3.6.5. SOFTWARE AND SERVICES 47

3.6.5.1. INTEROPERABLE CODE AND DATA UTILITIES AND SERVICES 47

3.6.5.2. DATA MANAGEMENT SERVICE 47

3.6.5.3. DATA WORKFLOW AND PROVENANCE SERVICE 47

3.6.5.4. DATA LIFECYCLE SERVICE 47

3.6.5.5. DATA INTEGRATION SERVICE 47

3.6.6. DATA SCIENCE TECHNOLOGIES AND SERVICES 48

3.6.6.1. DATA SCIENCE AND MANAGEMENT SUPPORT 48

3.7. IT MANAGEMENT AND GOVERNANCE 48

3.7.1. PROJECT AND PORTFOLIO MANAGEMENT 48

3.7.1.1. INTEGRATION OFFICE AND PROJECT MANAGEMENT SUPPORT 48

3.7.1.2. INFORMATION SYSTEMS ENGINEERING AND INSTALLATION 49

3.7.1.3. DATA CALL SUPPORT 49

3.7.2. POLICY AND PROCESS MANAGEMENT 49

3.7.2.1. MAINTAIN IT POLICIES AND PROCEDURES 49

3.7.3. VENDOR AND AGREEMENT MANAGEMENT 50

3.7.3.1. CONFIGURATION MANAGEMENT OF IT ASSETS AND INFORMATION 50

3.7.3.2. IT VENDOR AND AGREEMENT MANAGEMENT 50

3.7.3.3. SERVE AND MANAGE APPLICATION LICENSES 50

3.7.4. IT INVESTMENT MANAGEMENT 51

3.7.4.1. CAPITAL PLANNING AND INVESTMENT CONTROL (CPIC) 51

3.7.4.1.1. EXHIBIT 300 SUPPORT 51

3.7.4.1.2. IT CAPITAL INVESTMENT REVIEW (ITCIR) 52

3.7.4.1.3. IT PLANNING SUPPORT 52

3.7.4.1.4. MONITOR IT PURCHASE REQUESTS (PR) 52

3.7.4.1.5. MONITOR AND AUDIT BANK CARD PURCHASE OF IT PRODUCTS 52

3.7.5. IT GOVERNANCE 52

3.7.5.1. PLANNING AND INTEGRATION 52

3.7.5.2. IT GOVERNANCE SUPPORT 53

3.7.6. INFORMATION TECHNOLOGY ARCHITECTURE 53

3.7.6.1. ENTERPRISE ARCHITECTURE 53

3.7.6.2. ENTERPRISE ARCHITECTURE DEVELOPMENT, TECHNOLOGY RESEARCH AND INFUSION 54

3.7.6.3. ENTERPRISE ARCHITECTURE AND IT PORTFOLIO MANAGEMENT INTEGRATION 54

3.7.6.4. EA AND CTO-IT REVIEW SUPPORT 55

3.7.7. STAKEHOLDER AND CUSTOMER MANAGEMENT 55

3.7.7.1. TRAINING SUPPORT FOR IT SYSTEMS AND ENVIRONMENTS 55

3.7.7.2. CONSULTING AND OUTREACH 55

APPENDIX A: CONFIGURATION MANAGEMENT 56

APPENDIX B: CUSTOM APPLICATIONS DEVELOPMENT EXAMPLES 57

APPENDIX C: DATABASE ADMINISTRATION 62

APPENDIX D: SCIENTIFIC APPLICATIONS AND SERVICES SUPPORT 63

APPENDIX E: VIDEO CONFERENCING AND COLLABORATION FACILITY SUPPORT 64

APPENDIX F: DATA CENTER MANAGEMENT 65

APPENDIX G: SERVER ADMINISTRATION 67

APPENDIX H: HIGH PERFORMANCE COMPUTING 68

APPENDIX I: TEST FACILITY SUPPORT 70

APPENDIX J: CYBERSECURITY AWARENESS AND TRAINING 73

APPENDIX K: OFFICE OF CYBERSECURITY SERVICES 74

APPENDIX L: CYBERSECURITY MANAGEMENT AND OPERATIONS 75

APPENDIX M: ENGINEERING AND DESIGN ENVIRONMENT SYSTEMS ADMINISTRATION SUPPORT 76

APPENDIX N: USER ASSISTANCE TEAM 84

APPENDIX O: ENHANCED END-USER SYSTEMS ADMINISTRATION SUPPORT 85

APPENDIX P: ENHANCED END-USER SYSTEMS AND ADMINISTRATION SUPPORT QUALIFICATIONS 87

APPENDIX Q: ANTICIPATED CYBERSECURITY SERVICES MOVING TO ENTERPRISE CONTRACT 89

1. Introduction

1.1. Goals and Objectives

Since its establishment, the National Aeronautics and Space Administration (NASA) (also referred to as the Government or the Agency) has continued to evolve as a result of changing missions and priorities. Similarly, NASA’s Information Technology (IT) infrastructure is evolving toward a level of maturity that will allow it to successfully change NASA’s existing IT environment into a seamless and truly integrated IT architecture. NASA recognizes that effectively and efficiently creating, researching, managing, preserving, protecting, and disseminating the information required to achieve the objectives of space exploration, as well as other NASA missions, is vital to its mission success.

The nature of NASA’s program implementation model requires extensive cross-Center collaboration that is vital to the planning, design, and development of mission-related capabilities and technology in the future. Therefore, NASA requires a seamless technical IT infrastructure to ensure interoperability both within programs and across Centers and facilities.

The goal of this contract is to continue to provide the highest quality information technology solutions to customers of the NASA Glenn Research Center, anticipating and responding to changes in the Center’s requirements for IT across institutional, programmatic, research, engineering, and facilities while ensuring continued alignment with the Agency’s missions.

As the Agency continues to identify efficiencies in the delivery of services through enterprise contracts and solutions providers, PACE V will demonstrate extreme flexibility in adjusting for the influx and effluence of enterprise services while continuing to focus on services and solutions that are unique to the Glenn Research Center.

PACE V will also address the rapid evolution in information technology in capabilities such as Artificial Intelligence, Machine Learning, Data Analytics, Cloud Services, and Cybersecurity throughout the life of the contract. As capabilities mature, so must our ability to embrace and exploit new solutions made possible by their maturation.

Towards meeting these goals, the following objectives have been identified:

Leverage a shared pool of local and enterprise resources and expertise to deliver modern, efficient, and cost-effective solutions.

Optimize the use of common processes across all work orders and work areas of the contract, employing industry standards and best practices. For example, Software Development, Revision Control, Source Code Repository, Issue Tracking, Configuration Control, and Change Management.

Provide solutions that align, support, and integrate with Agency OCIO programmatic strategies, goals, and objectives.

Provide cost-effective surge support to adjust to peaks and valleys of service demand, funding, and technology.

Proactively maintain awareness of technology trends and facilitate innovation and ideation across all work areas.

Regularly identify, surface, and propose innovation and modernization opportunities based on sound business analyses.

Partner with the GRC community through a well-structured customer relationship management model that seeks to understand their business and offer well-integrated solutions in close coordination with the OCIO.

Maintain awareness of Agency IT initiatives that present opportunities for GRC to more fully leverage the expertise available through the PACE contract.

The Government will retain a set of key authorities that encompass the overall service strategy and service design related to Enterprise and Center-specific IT services. The Government will also retain authority for all demand management, governance, and approval functions associated with the PACE V Contract.

1.2. Transformation and Innovation

GRC has been slow to adopt the modern and innovative technologies currently transforming the IT industry and referenced in the Goals and Objectives section of this document. While pockets of expertise exist across the Agency and here at GRC, a wholesale modernization of processes, tools, frameworks, and infrastructure has not occurred. We are seeking a partner that will help GRC modernize its digital services and solutions and then stay abreast of the state of the industry so that as transformational opportunities present themselves, they can be strategically pursued. NASA is expecting a partner that will identify and fully leverage currently available best practices while implementing modern processes and technologies to achieve the objectives referenced throughout this document.

NASA has begun a digital transformation that is expected to surface best practices and strategic opportunities from across the Agency in support of its mission. Our partner will help GRC showcase its strengths while fully embracing enterprise solutions and services to drive efficiencies.

Applications. GRC has a long history of providing best-of-breed enterprise applications, including eRoom, the award-winning NETS (NASA Environmental Tracking System), and AMLS (the Agency Mailing List Service). Agency digital transformation initiatives may result in some applications continuing to be provisioned locally, others moving to the cloud, still others being decommissioned, and some local best-of-breed local applications might be extended to the enterprise.

Data Center. GRC’s robust and modern data center offers a full range of infrastructure-as-a-service and platform-as-a-service offerings. With a state-of-the-art virtual machine ecosystem, the data center provides cost effective application hosting and information repository services. As NASA’s evolution toward cloud and hybrid solutions continues, our partner will assist GRC in fully understanding the opportunity space, analyzing utilization options, developing business cases, and maintaining the Center’s strategic roadmap for data center services.

Cybersecurity. Through years of thought leadership and robust technical service delivery, GRC has established itself as a Center of excellence in Cybersecurity.

Together with its contracting partners, GRC has managed the Agency IT Security and Awareness Training Center, developed and maintained NASA’s Identity, Credential, and Access Management architecture and provided Cybersecurity Engineering leadership.

This recognized leadership culminated in the selection of GRC as the location for the Agency’s Office of CyberSecurity Services (OCSS) last year. OCSS is in a period of tremendous growth and opportunity and requires a partner capable of delivering quality personnel and solutions in this critically important and highly competitive field.

Other areas of digital transformation being heavily exploited across industry but less so at NASA include Artificial Intelligence, Machine Learning, Data Analytics and Data Science in general.

Opportunities for the application of these technologies are abundant across GRC.

To summarize, GRC requires a partner to continue the transformation that has already begun and accelerate modernization activities that have languished for too long. As evidenced by the details of this statement of work, GRC’s IT requirements are as diverse as its mission. The details of what is required in support of each work area are often unavailable or not fully articulated. Nevertheless, the theme of innovation and modernization is common.

The Contractor shall assist NASA in the continued modernization of its current service delivery model to one which more fully embraces and exploits the transformational technologies discussed above and those that have yet to emerge as mainstream IT. This requirement is reinforced and described in more detail throughout this statement of work.

1.3. Remote Work and Telework

GRC is highly interested in partnering with a Contractor that leverages a remote-worker approach, when appropriate, while maintaining its ability to deliver timely and excellent IT services.

While the majority of PACE V services require onsite personnel, a Contractor that embraces a remote-worker approach can enhance NASA’s opportunities to attract the best industry talent and support the Agency in reducing its carbon footprint. Opportunities for remote work service delivery exist throughout the scope of this Statement of Work and will be clarified in work orders when appropriate.

With the right tools and a flexible schedule, employees can work anytime and from anywhere.

This enables increased flexibility and productivity within the workforce and can lead to higher morale and reduced turnover.

The Contractor shall:

Develop, implement, and maintain remote workforce capabilities to enhance the quality and excellence of IT service delivery while reducing the footprint required of a completely onsite workforce.

Implement remote work as directed or in situations when remote work can deliver service quality and excellence that meets or exceeds that of onsite work.

Propose solutions based on a remote workforce in situations where remote work best meet the requirements of the Government.

Allow for the liberal use of telework when authorized by the Government.

1.4. Scope

This Statement of Work defines the requirements for technical tasks to assist the GRC in meeting the objectives of its research, development, engineering, and institutional support activities. These requirements include, but are not limited to, technical tasks (defined in Section

3) in the IT areas of Applications, Communications, Computing, CyberSecurity, End-User, Information Management, and IT Management and Governance.

The IT Services outlined in this Statement of Work support the diverse programs, projects and institutional activities across GRC’s scope of involvement in the NASA Mission. IT Services delivered through PACE enable GRC to execute NASA’s mission from a variety of NASA locations, with primary services delivered by Glenn Research Center at Lewis Field and Plum Brook Station. Specific work locations will be defined in each work order.

The Contractor shall comply with all applicable Federal, NASA, and GRC policies and procedures.

2. Management and Administration

As the business of provisioning information technology has matured, it has become increasingly important that OCIO proposals, project reviews, informational and decisional presentations, and executive presentations are professionally developed, based on sound business value, and ensure that the OCIO is represented in the best possible light. This includes, but is not limited to, professionally accredited Project Managers, Business Analysts, and Technical Writers.

The Contractor shall provide the management and administrative functions required to satisfy the requirements of this contract. The Contractor shall submit a Management Plan that defines how the Contractor will manage their day-to-day operations and provide cost-effective project management and business analysis oversight across all deliverables.

The Contractor shall assist with the consolidation and potential migration of elements of PACE to applicable Agency enterprise contracts. The Contractor shall assist with the consolidation and potential migration of IT services from other GRC contracts into PACE.

The Contractor shall obtain security clearances as required for work on this contract. As a result of the nature of the work, the Contractor shall accommodate nonstandard working shifts as defined by specific tasks.

2.1. Health and Safety

The Contractor shall submit a detailed safety and occupational health plan within thirty (30) calendars days after award in accordance with NPR 8715.3 and Section H of the solicitation.

This plan, as approved by the Contracting Officer, will be incorporated into the contract.

2.2. Work Authorization

The Government will use a combination of defined core work areas and IDIQ task orders to authorize work under this contract. The Contractor shall familiarize itself with and utilize the NASA GRC provided Work Management System (WMS) for processing core work and IDIQ task orders. The tasks will specify requirements, schedules, deliverables, and required skills.

The “authority to proceed” process will be managed through the WMS provided by NASA GRC.

The Contractor shall ensure that its internal work management and tracking systems integrates with OCIO processes for the purpose of receiving work requests and providing order status and tracking information to the Government. The Contractor shall input into the WMS for tracking the costs associated with projects including labor, materials, travel, training and other direct and indirect costs and report this information monthly with the NASA Form 533 Supplemental Reports.

2.3. Resources Management

The Contractor shall create, modify, maintain, and report resources information in accordance with Section G of the solicitation, with the Management Plan, and with other requests for resource data requested by the Government.

The Contractor shall conduct an annual internal contract-wide requirements and resources review. The Contractor shall present the results of this review to the Government and shall include recommendations for current and subsequent fiscal year (FY) contract resource requirements. This internal review shall be completed prior to the annual Capital Planning and Investment Control (CPIC) process.

2.4. Risk Management

The Contractor shall assess, evaluate, document, and manage risks associated with the performance of this contract. The Contractor shall create, modify, maintain, and implement a contract-wide Risk Management Plan per NPR 7120.7 (at the time of this writing, NPR 7120.7 is being revised. Until the revision of NPR 7120.7 version A is approved, NASA Interim Directive NID 7120.99 is effective), NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements, and NPR 2810.1A, Security of Information Technology.

2.5. Property Management

The Contractor shall comply with Government-specified requirements for property management (Sections G and H of the contract) and perform property custodial functions for the Government furnished property per NPR 4200.1, NASA Equipment Management Procedural Requirements, and NPR 4200.2, Equipment Management Manual for Property Custodians. The Contractor shall use a Government specified application as a tool, or set of tools, to administer Government property. In accordance with Section G of the solicitation, the Contractor shall conduct inventories of the physical property.

In addition, the Contractor shall keep a complete listing of all hardware systems and the software/firmware residing on those systems (e.g., operating systems, middleware, and applications), physical location of those systems, and documentation describing the interrelationships between individual systems and facility infrastructure. The Contractor shall provide a tool to establish and maintain an accurate inventory of hardware and software. The system shall be operational at the start of the contract. The system shall be used to provide monthly, quarterly, annual, and multi-year (seven-year projection) reports of hardware and software renewals or replacements.

2.6. Records Management

The Contractor shall maintain records appropriately and administer the disposition of records and non-records in accordance with NASA Records Retention Schedules (NRRS) 1441.1, which has been approved by NASA and the National Archives and Records Administration.

2.7. Mission Support - Purchasing

To fulfill mission and mission support requirements associated with the delivery of IT services, the Contractor shall establish and maintain a Government-approved IT purchasing process.

In accordance with NASA IT Purchasing Guidance, the Contractor shall procure and deliver all IT services, equipment, materials, hardware, software, license renewals and media through an Agency Enterprise Contract when appropriate. IT purchases shall be limited to Core Work Areas and Work Orders and the Contractor shall obtain Government approval for all IT purchases. The Contractor shall comply with NPD 2800.1 (Managing Information Technology) and NPR 2800.2 (Electronic and Information Technology Accessibility) and shall adhere to the evolving guidance provided by the GRC IT purchasing team and approved by the Contracting Officer’s Representative.

Non-Emergency IT Purchases: All items procured via this contract must be associated with a valid System Security Plan (SSP). Before a non-emergency IT purchase is made, the Contractor shall verify that a System Security Plan exists for the item under consideration.

The Contractor shall support NASA’s compliance with Federal Regulations on Supply Chain Risk Management (SCRM), which requires NASA to conduct an assessment of the vulnerability of the IT systems to cyber-espionage and sabotage. The Contractor shall obtain clearance through NASA’s Request for Investigation (RFI) process for items not on the Agency’s Assessed and Cleared List (ACL) prior to purchasing.

The Contractor shall obtain approvals from the System Owner of the system, the Work Order Representative, the Capability Manager of the Work Order, the Work Area Manager of the Work Order, and the GRC OCIO IT Purchase Approver.

Emergency IT Purchases: It is recognized that in the normal process of conducting NASA business, emergent conditions may arise requiring immediate remediation by the Contractor.

When Emergency IT Purchases are required, at least one Government approval shall be obtained. Once the emergency has been mitigated, the Contractor shall notify the System Owner of the system, the Work Order Representative, the Capability Manager of the Work Order, the Work Area Manager of the Work Order, and the GRC OCIO IT Purchase Approver.

Hardware and Software Maintenance and Licensing: The Contractor shall also purchase hardware maintenance agreements and software support contracts associated with the new IT being purchased. When available and appropriate, the Contractor shall purchase software licenses and media from vendors that have Enterprise License Agreements (ELA) already established with NASA.

The Contractor shall be responsible for the renewal of hardware maintenance, software licenses, and software support contracts for the systems specified in this contract, both IT and multimedia. The contractor shall coordinate with NASA’s Enterprise License Management Team (ELMT) prior to procuring any software license or software maintenance. This coordination shall be conducted in accordance with NFS 1807.70 Enterprise License Management Team (ELMT) Program prior to purchasing licenses and maintenance.

The Contractor shall maintain complete purchasing documentation for all items purchased under this contract. The Contractor shall track proofs of purchase for all hardware warranties, software licenses, and software support contracts managed through this contract. The Contractor shall negotiate and establish maintenance agreements and software license renewals with vendors and report the status of this activity. The Contractor shall inform the Government a minimum of 90 days prior to expiration of existing agreements.

As part of the procurement activity, the Contractor shall ensure that its hardware and software inventory are updated. The Contractor shall ensure that maintenance and obsolescence schedules are updated as changes in the hardware and software inventory occur. The Contractor shall ensure additions and deletions are posted to the appropriate property management tool (see Section 2.5) within seven calendar days from the change.

The Contractor shall provide monthly reports on Hardware and Software Maintenance and Licensing, including License Renewal and Maintenance agreement changes, for the hardware and software items maintained in the Contractor-provided property management tool (see Section 2.5).

The Contractor shall track and make available to the Government the status of all individual procurements from purchase request through final purchase order, delivery, and acceptance.

2.8. Configuration Management

The contractor shall perform service asset and configuration management (SACM) functions for PACE-managed environments. The contractor shall prepare, implement, and maintain a SACM Plan within 60 calendar days after contract award.

The contractor shall create new and maintain existing system architecture and as-built drawings for all PACE-managed environments in conformance with GRC drawing standards. When making changes to configuration items, the contractor shall adhere to the GRC Information Technology Change Management Process. The contractor shall provide and use an online Configuration Management Database (CMDB) to identify, maintain, track, and report all PACE-managed configuration items (CIs), including Government-Furnished Equipment (GFE). The Contractor shall update the CMDB with current information after receiving, installing, modifying, relocating, refreshing, or excessing CIs. The Government will have full access rights to all data in the contractor’s CMDB thereby requiring that the design of the database facilitate the export of data to Government CMDBs.

The contractor shall perform SACM functions in coordination with GRC IT configuration management officials and ensure conformance with evolving IT standards and guidelines, such as ITIL V4. The contractor shall conduct a bi-annual audit to verify all configuration items are properly recorded in the CMDB.

The Contractor shall track information in accordance with Appendix A, Configuration Management.

2.9. Quality Management and Control

The Contractor shall document key processes and procedures using GRC-approved International Standards Organization (ISO) formats where required. The Contractor shall be responsible for acquiring and maintaining the skills and expertise necessary to perform the requirements of this contract and maintain currency with relevant and applicable industry trends.

2.10. Project / System Integration

In accordance with NPR 7120.7 and NPR 7150.2, the Contractor shall integrate all multi-disciplinary activities associated with a project. Project development and implementation within this contract often requires contributions from varied technical disciplines. The Contractor shall institute a process that provides a single point of contact (lead) for a particular project as well as help unify all of the varied contributors into a single team. This lead will serve as the primary communications channel to the Government for the implementation of the particular project.

3. Information Services

The Contractor shall perform IT project management, engineering, scientific, technical, administrative, and related tasks issued hereunder by the Contracting Officer (CO), or the CO’s authorized representative. These activities fall into broad categories as outlined below, but need not be limited to the activities noted. Individual task requirements may involve any or all categories of activities.

For each task, the Contractor shall be responsible for estimating costs, establishing budgets, developing a major milestone schedule and monitoring progress against plan. The contractor shall identify, document, and track problems and take appropriate corrective action. These responsibilities are in addition to the execution of the technical requirements.

The majority of the work shall be accomplished onsite in various locations across GRC. Certain tasks may benefit from offsite delivery models (e.g., transactional, short-duration tasks; subject matter expertise reach back). Travel to other locations may be required. Individual work orders will specify the location of the work as well as the availability of Government facilities, laboratories, equipment, and support services.

Work performed under this contract shall be in accordance with established and applicable Federal, Agency and GRC procedures and directives for requirements, standards, specifications, and instructions. GRC reference documentation governing such things is maintained in the GRC Business Management System.

The Government reserves the right to issue work orders for any or all of the scope of work indicated in this SOW. There is no guarantee work orders will be written for all elements. The work requirements are not listed in priority order and no significance should be implied by their relative position in this document. References to GRC include both Glenn Research Center at Lewis Field and Plum Brook Station.

The following definitions apply:

a) Continuous operational coverage is on-site support performed 24-hours-per-day, 7-days-per-week, including holidays.

b) Core hours for coverage are weekdays from 7:00 a.m. until 5:30 p.m., Eastern.

c) Extended business hours are coverage hours that occur outside of core hours.

d) On-call support is support that does not require an individual’s physical presence but they must be reachable via phone or text. In many cases, it is required that personnel be available throughout the "on call support" period to come in to the work location and provide physical support.

e) As-needed support is support that that is not required on a full time or on a routine pre-scheduled basis but is provided upon request.

f) Desk-side support is coverage in which the contractor must be physically present at the customer's work location during a specific event or time.

3.1. Applications

The Contractor shall provide support for all aspects of application development, including management of knowledge and information management systems, Web application development, mobile application development, desktop application development, scientific application development, database system administration, Web server system administration, application development tool system administration, and content management support on the NASA public portal.

The Contractor shall provide customer support, training, account management, and procurement for applications including Digital Solutions (Web and Application) Services; comply with OCIO Production Change Control Process; and adhere to standard OCIO notification processes for all outages of production services.

Applications Policy Compliance: Web Applications developed within this contract shall be developed in compliance with Federal, Agency, and Center required laws and policies including, but not limited NPR 2810.1A, Security of Information Technology NPR 1382.1, NASA Privacy

Procedural Requirements, and NPR 7150.2.

Applications Governance: The GRC Application Governance Board (AGB) has responsibility for the portfolio of applications throughout their entire lifecycle. The AGB prioritizes and adjudicates all resource utilization. The Contractor shall log all service requests into a Government-provided issue tracking tool (currently Jira) and prepare appropriate business case analysis for discussion and decision by the GRC Application Governance Board (AGB). The AGB reviews all service requests to determine their priority and efficacy. The Contractor shall maintain accurate on ongoing status information on all AGB in-process service requests in Government-provided issue tracking tool(s), as requested by the AGB Chairperson. The Contractor shall provide continuous, transparent and accurate application resource utilization (people, equipment, licenses, etc.) to the AGB. The Contractor shall support the AGB as subject matter experts. The Contractor shall abide by the decisions of the AGB. The Contractor shall maintain awareness of available Enterprise Services (for example, those offered via NEST, NICS, and EAST2) to ensure that all application service delivery remains aligned with Agency requirements and best practices.

3.1.1. Web and Native Application Services

The contractor shall support activities associated with developing, operating, and maintaining web services and native application services. Activities include supporting Center and Agency initiatives to enable end users to readily acquire and utilize software tools to accomplish their work.

3.1.1.1. Application Monitoring and Administration

The Contractor shall provide life cycle support of enterprise and business application software in support of client/server and Web applications development. This includes, but is not limited to software development tools, standard application development suites, and configuration management tools. The Contractor shall support business application software distribution on GRC’s domain environment; research hardware and software upgrades. The Contractor shall maintain system and procedures documentation. The Contractor shall provide client/server application development and maintenance support, including migrating applications across environments, coordination with other GRC IT groups on networking, access, and other application-related issues, performance monitoring and tuning of software, and problem diagnosis and resolution.

The Contractor shall provide planning, documentation, and overall support for development, test, and production application environments. The Contractor shall create application sites/instances and migrate between environments.

The Contractor shall ensure all applicable web services leverage transport layer security, and comply with NASA-SPEC-2650.2: TRANSPORT LAYER SECURITY (TLS) SECURITY CONFIGURATION SPECIFICATION (https://etads.nasa.gov/gh-pages/?spec=/ASCS/tls/releases/download/v2.0-final/NASA-SPEC-2650.2-guide.html#_certificates). The Contractor shall support IP access control and Windows user authentication methods. The Contractor shall support Agency designated authentication and authorization methods, including NASA’s Identity, Credentialing, and Access Management (ICAM) and Launchpad. The Contractor shall support Agency and Center sponsored application development and environment initiatives.

The Contractor shall install, support, troubleshoot and maintain the desktop, server, web, and mobile application development suite, which includes, but is not limited to, the following:

ColdFusion, PHP, ERWin data modeling software, GiT, Serena Version Manager and Subversion source control software, Jira, Jira Service Desk, ServiceNow, WordPress, Drupal, and others as recommended by the contractor and defined and approved by the Government.

All software shall be at the vendor’s current version within 6 months of its release unless otherwise determined by the Government. All vulnerabilities must be remediated in accordance with the policies of NPR 2810 and IT Handbook ITS-HBK-2810.04-01A, Security Categorization, Risk Assessment, Vulnerability Scanning, Expedited Patching, and Organizationally Defined Values. Patches and software upgrades shall be researched for their potential to enhance the production environment as well as any risks to the environment and the results provided to the Application Governance Board for evaluation and decision.

The Contractor shall document environment configuration and procedures pertaining to application environments. The Contractor shall provide environment troubleshooting and problem resolution, as necessary and ensure that system functionality is maintained during core and extended business hours.

The Contractor shall track current technologies and trends as they relate to the desktop (native), server, web, and mobile application environment support. The Contractor shall provide recommendations and propose modifications to environment configuration based on analysis of these technologies and trends.

3.1.1.2. Web Application Governance

Web application activities and services shall be tracked and completed in accordance with the tenets of Project Management, in compliance with NASA standards in NPR 7120.7 and NPR

7150.2. Applications shall use ICAM standard access methods and protocols.

The GRC Application Governance Board (AGB) has responsibility for the portfolio of applications. The Contractor shall bring service requests to the GRC Application Governance Board (AGB). The AGB reviews requests to determine their appropriateness for GRC. The Contractor shall support the AGB as a subject matter expert, in areas of application development. The Contractor shall abide by the decisions of the AGB.

3.1.1.3. Application Portfolio Management

The Contractor shall support the development and maintenance of a portfolio of GRC applications and websites. The portfolio will be included in NASA’s portfolio tracking tool, Agency Application Rationalization Tool (AART). This portfolio will identify pertinent characteristics pertaining to the purpose, requester, development, and use of the applications and services provided.

The contractor shall utilize the Agency Application Rationalization Tool (AART) as part of the portfolio management activities. It will be used to track all web sites, web applications, and applications as defined by Agency processes. Information shall be entered in the development phase, updated at least annually, and managed through decommissioning. This system requires registrants to enter information about their websites and verify that they are compliant with NASA polices. The Contractor shall support the AART system at GRC and shall assist users with their registrations and the validation of the content. Additionally, the information shall be monitored to ensure that GRC remains compliant with NASA and Center policies regarding website registration.

The Contractor shall support Agency and Center application portfolio rationalization activities including but not limited to reevaluate applications annually according to a set of established criteria and making disposition recommendations for each (tolerate, invest, migrate, eliminate).

3.1.1.4. Software Life-Cycle Management

NPR 7150.2 identifies the software development and engineering requirements for business and institutional software. In addition, it establishes requirements for the following Classes of software:

Class A Human-Rated Space Software Systems

Class B Non-Human Space-Rated Software Systems or Large-Scale Aeronautics Vehicles

Class C Mission Support Software or Aeronautic Vehicles, or Major Engineering/Research Facility Software

Class D Basic Science/Engineering Design and Research and Technology Software

Class E Design Concept, Research, Technology and General Purpose Software Class F General Purpose Computing, Business and IT Software

The Application Governance Board establishes the Software Classification of new applications in accordance with NPR 7150.2.

The Contractor shall provide full project life-cycle support for digital solution projects. The Contractor shall implement industry best practices to manage the software development lifecycle in accordance with NPR 7150.2 and GRC’s IT Governance practices.

The Contractor shall support project formulation activities including customer consultation, requirements gathering, process improvement, business analysis, solution analysis, and business case development. Solution recommendations shall be based on analysis of available options across COTS and GOTS portfolios, existing solutions, available platforms, and custom development. Recommendations shall be based on sound business case analyses including impact to the environment, ability to meet technical requirements, return on investment, and appropriate cost factors.

The Contractor shall recommend a project management approach based on fit to project.

The Contractor shall provide support for the design, implementation, configuration, testing, operation, maintenance and user support for a centralized version control system. This system will be used for source code, documents and test results. This includes the following tasks:

a) Provide support for a Web-based interface to the version control system

b) Ensure backups of data in the system

c) Add/remove user accounts

d) Setting permissions and roles on user accounts, as needed

e) If possible, integrate the system with any NASA standard provisioning and authentication systems (e.g. eAuth and NAMS) and require PIV authentication

f) Providing reports on system usage including storage space used, list of users, list of projects

3.1.1.5. Web Site Development and Maintenance

The contractor shall support the web sites and web environment of GRC. The primary tool for delivering web sites to GRC is the WordPress Content Management System (CMS). However, the contractor will also be responsible for supporting legacy infrastructure and web sites that are built in in almost any web development language. The Contractor shall ensure web pages are compliant with Federal and Agency Internet policies, including compliance with accessibility requirements. Web design and development activities should align with the tenets of responsive design. Authentication shall use the NASA standard ICAM (Identity Credential and Access Management) infrastructure.

The Contractor shall verify that all software developers have been successfully trained in secure programming techniques. The Contractor shall perform application security analysis and testing according to the verification requirements of an agreed-upon standard, such as the Open Web Application Security Project (OWASP) Application Security Verification Standard (ASVS). For web applications, the Contractor shall ensure that the software shall not include any of the flaws described in the current "OWASP Top Ten Most Critical Web Application Vulnerabilities."

3.1.1.6. Web and Applications Graphic Design

The Contractor shall provide services for electronic creation and manipulation of graphics products that support web application and mobile application development. The graphics development work requires specialized skills for creating and manipulating electronic formats and integrating them into web and mobile applications. The Contractor shall meet all Government and NASA regulations and policies in final products (e.g., NASA Insignia policy;

Section 508 policy).

The Contractor shall interpret, incorporate, and analyze customer requirements to produce analyses, design, review, and layouts for websites and applications.

The Contractor shall produce and update graphics products using appropriate development tools. The Contractor shall develop new content and features utilizing current GRC themes, policies, messages, cybersecurity requirements (NPR 2810.1A, Security of Information Technology (Revalidated with Change 1, dated May 19, 2011), in accordance with NASA policies, and ensuring these are present and consistent in web and mobile applications.

The Contractor shall participate in customer development meetings and other activities as necessary to capture, consolidate, and document design concepts and requirements.

The Contractor shall be responsible for coordinating integration of products and information into websites and applications. The Contractor shall also be responsible for the archiving and data management of all products to facilitate retrieval.

3.1.1.7. Web Site Hosting as a Service

The Contractor shall provide services and support including procurement assistance, installation, repair, upgrades, customer support, preventive maintenance, and user account management for all applications hosted by the Central Web Services Team including those used in the creation of Web content, checking quality and compliance of Web content, indexing and searching Web content, securing Web content, and applications used for providing Web site usage statistics, online calendars, and Web form information mailing.

The Contractor shall operate and maintain a suite of tools for the evaluation and management of the web environment. The suite includes, but is not limited to html validators, link checkers, web analytics tools, and site templates.

The Contractor shall operate and maintain a centrally available web content management systems (CMS), currently WordPress. Services include affinity kits, plug-ins, user management, maintenance of and changes to default configurations, transition of sites to the appropriate location (test, internal, external), and documentation and assistance with site implementations.

The contractor shall support the GRC user community in the use of these tools, respond to questions, and provide training on their use.

The Contractor shall support Web curators and sites on Center’s Web hosting systems and assist curators in gaining access, developing, and deploying their sites.

The Contractor shall provide support for application level service architecture (including security) development, investigation, installation, evaluation, testing and piloting of enhancements, replacements or additions to Web development and maintenance products, and recommend hardware/software/network configuration changes.

3.1.1.8. Custom Applications Development

The Contractor shall provide development, support and maintenance of desktop, server, web, and mobile applications on multiple platforms. The Contractor shall ensure that system functionality is maintained during core and extended business hours. The Contractor shall provide development support as required to maintain the applications and data integrity within those applications and resolve data interface issues. Provide development support to implement modifications per customer requirement changes. Provide support for replacement of applications by the Agency Applications Office (AAO), eGov, and other initiatives including, but not limited to, data analysis, data mapping, data conversion, and documentation. Maintain existing application documentation.

NASA has defined a suite of Application Development Languages, which is maintained in the Applications Program (AP), Applications Program, Handbook Policy Handbook, V1.0 AP-NASA- HDBK-001, Section 4.2 Application Programming (Development) Language Standards. The Contractor shall comply with this policy. The AGB may define additional application development languages aligned with the NASA standards, to improve custom application development at the Center, which the Contractor shall support.

The Contractor shall perform development activities including but not limited to developing schedules, identifying resource requirements, identifying and documenting operational concepts, gathering technical requirements, creating interface designs, developing data models, coding, testing and implementing software per GRC requirements. The Contractor shall also provide configuration management and release support and maintain documentation of these requirements.

Maintaining Legacy Applications. With dozens of applications currently in production, the Contractor shall maintain the legacy ColdFusion application portfolio, development environment, and associated Oracle databases.

New Application Development. The Contractor shall perform new development on a modern…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .