Attachment J-A Performance Work Statement.pdf

PDF 641 KB Posted

Attached to
Enterprise Multimedia and Integrated Technical Services (eMITS) Federal contract opportunity
Solicitation number
80TECH22R0001
Issued by
National Aeronautics and Space Administration

About this file

This is a request for proposal for a NASA contract to provide Enterprise Multimedia and Integrated Technical Services. The contractor will be required to provide information technology management, multimedia, communication services, and related services to the NASA Office of Chief Information Officer and NASA Office of Communications at all NASA Centers and facilities. Prospective offerors must submit any contractual or technical questions by June 7th and submit proposals no later than June 30th, 2022. The contractor will be expected to manage areas such as IT, customer collaboration and support, information management, multimedia and communications services, and contract administration. The place of performance will be across all NASA locations.

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Multimedia and Integrated Technical Services (eMITS), newest first.
File Type Posted
Questions and Answers for 80TECH22R0001 - Amendment 03.pdf PDF
Attachment J-C Data Requirements List (DRL) and Data Requirements Descriptions (DRD) - Amendment 03.pdf PDF
eMITS Request For Proposals 80TECH22R0001 - Amendment 03.pdf PDF
eMITS Request For Proposals 80TECH22R0001 - Amendment 02.pdf PDF
LIST OF ATTACHMENTS - Amendment 02.pdf PDF
Attachment J-Q CBA - Amendment 02.pdf PDF
Exhibit 1 eMITS Past Performance Questionnaire (PPQ) - Amendment 02.pdf PDF
Questions and Answers for 80TECH22R0001 - Amendment 02.pdf PDF
Attachment J-P List of Contracts Transitioning to eMITS - Amendment 01.pdf PDF
Questions and Answers for 80TECH22R0001.pdf PDF
Attachment J-B Applicable Documents List - Amendment 01.pdf PDF
Attachment J-Q CBA - Amendment 01.pdf PDF
eMITS Request For Proposals 80TECH22R0001 - Amendment 01.pdf PDF
Attachment J-A Performance Work Statement - Amendment 01.pdf PDF
Attachment J-C Data Requirements List (DRL) and Data Requirements Descriptions (DRD) - Amendment 01.pdf PDF
Attachment J-F Reserved - Amendment 01.pdf PDF
Attachment J-H System Inventory - Amendment 01.pdf PDF
Attachment J-J INSTALLATION-ACCOUNTABLE GOVERNMENT PROPERTY - Amendment 01.pdf PDF
Exhibit 2 Cost Forms - Amendment 01.xlsx XLSX spreadsheet
LIST OF ATTACHMENTS - Amendment 01.pdf PDF
LIST OF ATTACHMENTS.pdf PDF
Attachment J-B Applicable Documents List.pdf PDF
Attachment J-C Data Requirements List (DRL) and Data Requirements Descriptions (DRD).pdf PDF
Enclosure 1 Labor Categories.xlsx XLSX spreadsheet
eMITS RFP Comment Form.xlsx XLSX spreadsheet
eMITS Request For Proposals 80TECH22R0001.pdf PDF
Attachment J-P List of Contracts Transitioning to eMITS.pdf PDF
Exhibit 1 eMITS Past Performance Questionnaire (PPQ).pdf PDF
Exhibit 2 Cost Forms.xlsx XLSX spreadsheet
Enclosure 2 Performance and Award Fee Evaluation Plan.pdf PDF
Enclosure 4 iSite Contractor Onboarding Guide.pdf PDF
Historical Document KIAC Performance Work Statement - P00050.pdf PDF
Historical Document GLTIC Statement of Work.pdf PDF
LP013-C-22-012 Request for Proposal Cover Letter.pdf PDF
Attachment J-D FINANCIAL MANAGEMENT REPORTING REQUIREMENTS.pdf PDF
Attachment J-E DD FORM 254 RFP.pdf PDF
Attachment J-F Personal Identity Verification (PIV) Card Issuance Procedures.pdf PDF
Attachment J-H System Inventory.pdf PDF
Attachment J-I Government Furnished Property.pdf PDF
Attachment J-J INSTALLATION-ACCOUNTABLE GOVERNMENT PROPERTY.pdf PDF
Attachment J-Q CBA.pdf PDF
Enclosure 3 QASP.pdf PDF
Historical Document SRACES_ PERFORMANCE WORK STATEMENT.pdf PDF
Attachment J-O Wage Determination.pdf PDF
Historical Document HQ Information Technology Support Services III - Performance Work Statement.pdf PDF
Historical Document COMIT NNJ16JA52B STATEMENT OF WORK.pdf PDF
Show all 46

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

eMITS – Enterprise Multimedia and Integrated Technical Services Table of Contents

1. INTRODUCTION, GOALS, OBJECTIVES

2. ORDERING AND SERVICES DELIVERY

3. CONTRACT MANAGEMENT AND ADMINISTRATION

3.1 GENERAL

3.2 CONTRACT RISK MANAGEMENT

3.3 ENTERPRISE CONTRACT MANAGEMENT SUPPORT

3.4 INTEGRATION SUPPORT

3.5 OPERATIONS, PROJECT, AND FUNCTION MANAGEMENT

3.6 FINANCIAL RESOURCES MANAGEMENT

3.7 PROPERTY MANAGEMENT

3.8 SAFETY AND HEALTH

3.9 WORK AUTHORIZATION

3.10 QUALITY MANAGEMENT AND CONTROL

3.11 PHYSICAL SECURITY MANAGEMENT

3.12 INFORMATION SECURITY MANAGEMENT

3.13 SECTION 508 COMPLIANCE

3.14 CONTRACT ADMINISTRATION SYSTEM

4. IT MANAGEMENT

4.1 IT POLICY MANAGEMENT

4.2 IT GOVERNANCE AND BOARD MANAGEMENT

4.3 IT STRATEGY MANAGEMENT

4.4 ENTERPRISE ARCHITECTURE SUPPORT SERVICES

4.5 IT SERVICE MANAGEMENT (ITSM)

4.6 CUSTOMER RELATIONSHIP MANAGEMENT (CRM)

4.7 IT PROGRAM/PROJECT MANAGEMENT (PPM)

4.8 PERFORMANCE MANAGEMENT

4.9 IT RISK MANAGEMENT

4.10 CONFIGURATION MANAGEMENT (CM)

4.11 IT BUSINESS AND INVESTMENT MANAGEMENT

4.12 IT ACQUISITION MANAGEMENT (ITAM)

4.13 SOFTWARE LICENSE MANAGEMENT

4.14 PLATFORM AND COE GOVERNANCE

4.15 SCHEDULE MANAGEMENT SUPPORT

5. CUSTOMER COLLABORATION AND SUPPORT SERVICES

5.1 PROVIDE TRIAGE TO CUSTOMERS PROCESSES AND INTEGRATED SOLUTIONS, AS ORDERED

5.2 PROVIDE PROJECT FACILITATION AND SUPPORT, AS ORDERED

6. INFORMATION MANAGEMENT

6.1 IDAS SERVICE LINE SUPPORT

6.2 STRATEGIC RELATIONSHIP MANAGEMENT

6.3 FORMS MANAGEMENT

6.4 RECORDS MANAGEMENT

6.5 DOCUMENT DIGITIZATION AND DATA CONVERSION

6.6 DATA QUALITY AND COMPLIANCE

7. MULTIMEDIA AND COMMUNICATIONS SERVICES

7.1 MULTIMEDIA TECHNOLOGY, PROCESSING, AND ENGINEERING

7.2 ENGINEERING, INSTALLATION AND MAINTENANCE

7.3 MEDIA REPOSITORY MANAGEMENT

7.4 CATALOGING STILL AND MOTION IMAGERY

7.5 PRESERVATION AND MIGRATION

7.6 DIGITAL SIGNAGE

7.7 TECHNOLOGY SUPPORT FOR STRATEGIC COMMUNICATIONS

7.8 MULTIMEDIA MISSION SERVICES

7.9 IMAGERY ACQUISITION, PROCESSING AND DISTRIBUTION

7.10 NASA TELEVISION AND INSTITUTIONAL VIDEO OPERATIONS

7.11 CREATIVE DEVELOPMENT (GRAPHICS, WRITING AND EDITING)

7.12 DIGITAL MEDIA PRODUCTION AND DISTRIBUTION

7.13 FABRICATION, PRINTING AND PHYSICAL PRODUCTION

7.14 EXHIBITION MEDIA DESIGN AND DEVELOPMENT

7.15 MEETING, EVENTS, AND PRESENTATIONS

1. Introduction, Goals, Objectives

1.0 Enterprise Multimedia and Integrated Technical Services (eMITS)

1.1 Introduction and Overview

The National Aeronautics and Space Administration (NASA) Office of Chief Information Officer (OCIO) and Office of Communications (OCOMM) are transitioning to Agency level, or enterprise, contracts for multimedia and technical communications services. The two organizations are consolidating services currently provided by individual contractors at separate field centers with the dual intent of finding synergies and reducing duplication. Although the services themselves are dissimilar, the service solutions and skills required to perform the contracted tasks are similar. All the services employ or pertain to information technology (IT) and other electronic equipment. Further, creating and delivering multimedia and technical communications requires the use of the internet, digital platforms, and IT.

The intent of the eMITS contract is to support customer organizations through a single provider of digital multimedia and technical communications services. The transformation and migration of services to Agency contracts is expected to last at three to four years. As part of this effort, the eMITS contract will eventually provide all services in this Performance Work Statement (PWS) for the OCIO and OCOMM organizations, including all Center and Agency level customers. Not all the services of eMITS will be provided to all customers on the start date of the contract. Initially, a small number of Centers will begin receiving the services in the eMITS PWS at contract start, with other Centers and customers migrating their requirements at later dates. The eMITS contractor will facilitate this effort and effectively and efficiently provide eMITS services to all customers according to schedule. The eMITS contractor will also provide cost effective services from both onsite and remote support approaches to best provide the required eMITS services to all customers.

1.2 Contract Transition

Attachment J-P lists the contracts that have scope expected to transition to eMITS. Note, not all scope of work in these contracts will transition to eMITS, and transition dates may change.

The OCIO is conducting an IT Transformation activity which includes the establishment of a contract strategy that addresses the breath of the OCIO work requirements. Contracts identified in this strategy cover a wide range of work and support services, including cybersecurity and privacy services; internal communication and public communication; networks and computing services; end user services; and application development services. The graphic below represents the plan for Agency-wide IT contracts. It is provided here for information and context only.

1.3 Principle Stakeholders and Places of Performance

The eMITS contract will support and be accessible by all NASA mission directorates and functional organizations and at all NASA Centers and facilities. Customers may be located in any department or at any facility, but the principal stakeholders are OCIO and OCOMM. Goals and Objectives

Figure 1.2-1 Contract Strategy FY21-FY24

The eMITS contractor will be an integral partner in OCIO’s effort to change the way multimedia communications and IT services are delivered across the Agency. The eMITS contractor will not only provide the services contained in this work statement, but also gain and maintain knowledge necessary to integrate the services with the products and services offered across the entire portfolio of OCIO contracts. The intended result is a comprehensive suite of cost-effective, cutting-edge service solutions that will facilitate NASA’s mission.

1.4 Performance Work Statement (PWS) Overview

The principal purpose of this contract is to acquire multimedia and technical communications services and related services for OCIO and OCOMM. The PWS provides for the following:

• Information Technology Management Services – IT Management is characterized by processes that enable the establishment, administration, and measurement of an organization’s IT program. A large portion of the services in this section will support the OCIO’s Strategy Division (Enterprise Business Management Office, Strategy and Architecture Office, Customer Engagement Office), and Operations Division (IT Service Management Office, Enterprise Project Management Office).

• Customer Collaboration and Support Services These services are crucial to OCIO’s and OCOMM’s success in achieving a unified presence and smooth interface with NASA entities bringing requirements for multimedia communications and IT services.

• Information Management Services – Managing the information across the Agency requires the establishment and execution of information management services, including data digitization and conversion, forms management, and records management.

• Multimedia and Communication Services – This broad category includes, but is not limited to, NASA Television; www.nasa.gov; NASA’s social media operations; digital communications support for human spaceflight and science missions; institutional audiovisual support; publishing support; and the foundational work in graphic, visual, electronic and broadcast arts required to achieve NASA’s strategic communications goals. OCOMM sets this strategy and will direct most of these services.

2. Ordering and Services Delivery

Core Performance Work Statement provides detailed performance-based requirements that will be defined in work packages as part of the Annual Work Plan. IDIQ task orders will be issued as performance based, in accordance with NFS 1852.216-80, Task Ordering Procedure, and include more specific performance characteristics (technical, schedule and cost) and deliverable requirements.

The Annual Work Plan is a plan submitted by the Contractor and approved by the Government that details the Contractor’s overall approach to meeting the Government’s requirements. The Annual Work Plan establishes the contract year ceiling for current and anticipated Work Packages. (DRD MA-07) This includes:

• Existing, funded requirements

• Known, funded requirements but not ready to begin

• Known, unfunded requirements (seeking funds)

• Anticipated requirements based on historical data/transactions

The Annual Work Plan is a flexible working document, incorporating changes as needed during the year (with COR/DCOR concurrence, and CO approval) to accommodate emerging mission and customer requirements.

Unknown requirements, when identified, that can be accomplished within an option period can be defined via IDIQ task order.

3. Contract Management and Administration

The Contract Management section includes requirements for program management, financial management, property/inventory management/logistics, Safety, Health and Environmental (SHE) Management, and quality management.

3.1 General

In all service areas of this contract, the Contractor shall:

3.1.1 Ensure the implementation of effective systems engineering, business management, and other quality practices to deliver the services in an efficient and integrated manner and at a sustained high level of success

3.1.2 Implement practices to ensure effective communication of management, technical, quality, financial, and customer satisfaction issues that may arise in the performance of this contract

3.1.3 Ensure the implementation of management practices to proactively pursue process improvements to enhance customer satisfaction and service delivery

3.1.4 Apprise the Contracting Officer (CO), Contracting Officer’s Representative (COR) immediately of any issues that could have an adverse impact on successful performance of the contract requirements

3.1.5 Continually evaluate and implement fiscally responsible, cost effective, innovative, and efficient processes or disciplines for performing the requirements outlined in this PWS.

3.1.6 Follow the most current approved version wherever reference is made in this PWS and in task orders/work packages to specific policies, procedures, directives, work instructions, and other Government documents.

3.1.7 Maintain the ability to obtain security clearances, up to the Top - Secret level, as appropriate for work on this contract. Where required, specific employee security clearance requirements will be defined along with the technical content in work packages or task orders.

3.1.8 Provide all resources (labor, materials, and property) required to perform this contract.

The exceptions to this are the items (materials and property) listed in:

3.1.8.1 Manage Attachment J-H, Systems Inventory.

3.1.8.2 Manage Attachment J-I, List of Government-Furnished Property (GFP)

3.1.8.3 Manage Attachment J-J, Installation-Accountable Government Property (IAGP)

3.1.9 Provide to the Government all deliverables listed in the Attachment J-C, Data Requirements List in electronic form as specified in the individual DRD, unless otherwise directed.

3.1.10 Provide, implement, and maintain the Contract Management Plan in accordance with Data Requirements Document (DRD) MA-01, Contract Management Plan

3.2 Contract Risk Management

The Contractor shall:

3.2.1 Integrate risk management processes into its contract management approach in order to mitigate impacts to cost, schedule, and performance.

3.2.2 Proactively report any risks to cost, schedule, and performance to the COR and customers of the eMITS contract and work with the Government to mitigate any impacts.

3.3 Enterprise Contract Management Support

The Government expectation is that the eMITS contractor will be a solutions partner with the Government and continually seek to implement processes and operational methods that will enhance the provision of services for all customers of this contract, including the OCIO, OCOMM, center OCIO and OCOMM organizations, and their customers. The Contractor shall:

3.3.1 Be aware of and be flexible to the differences in individual center service delivery that currently exists. Prior to this eMITS contract, many of the services herein have been provided on separate center level service contracts with different service delivery requirements and expectations.

3.3.2 Partner and collaborate with center level organizations and customers to ensure the most satisfactory service delivery for each supported organization as is practical and feasible within the enterprise services delivery framework.

3.3.3 Assist each supported organization in integrating into a uniform enterprise service delivery model for services and facilitate change management on this contract while remaining flexible to individual center schedules and processes until such time a more uniform service delivery model for each service can be approved and implemented.

3.3.4 Recommend integrated solutions that span across business strategies, technologies, architecture, platforms, and, when applicable, across other agency and center contracts.

3.3.5 Have a strong understanding of the business processes supported at both the agency and center level, products and services offered and implemented across this contract and associated NASA contracts, and shall recommend solutions that span across those products and services in meeting customer requirements.

3.3.6 Effectively onboard new customers and requirements as center contracts expire or as services are transitioned to the eMITS contract in accordance with Attachment J-P, Center Transition Schedule while continuously seeking cost effective methods of service delivery across the Agency that take advantage of economies of scale and reduce overall costs to the Government.

3.4 Integration Support

The NASA OCIO and OCOMM are transitioning to an Agency framework for delivery of services, although not all services included in this Performance Work Statement (PWS), or those included in other contracts, will be provided in an enterprise manner, at least initially. Currently there are multiple Agency services contracts managed by the OCIO including the Advanced Enterprise Global Information Systems (AEGIS) contract, the NASA End-user Services & Technologies (NEST) Contract, the Enterprise Applications Service Technologies (EAST) 2 contract (or its replacement contract NCAPS), the Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) contract, and other Center level contracts. Additionally, OCOMM will also be working towards an enterprise level contract or contracts for delivery of core OCOMM services (NASA Communications Services (NCS) contract). Many organizations across the OCIO and OCOMM as well as their customer organizations across NASA require support that utilizes the services of more than one, if not all, of these contracts, as well as other associated Agency and local center contractor services, in order for the OCIO and OCOMM to provide a comprehensive service delivery package that will meet the mission of these organizations. In providing the services and support required on the eMITS contract, The Contractor shall:

3.4.1 Continually develop and enhance its knowledge of the services and delivery methods of these associated contracts (see section H.X, Associated Contractor Agreements for a non-exclusive list of associated contracts) and shall provide services as defined in this work statement that are integrated with those associated contracts to the greatest extent possible in order to minimize the burden of integration of service lines by the customer organizations.

3.4.2 Partner and collaborate with associate contractors and establish associate contractor agreements for the effective integration of services with those contractors identified in Section H, Clause H-11 Associate Contractor Agreements.

3.5 Operations, Project, and Function Management

In performance of the broad scope and magnitude of the eMITS contract, the contractor must establish effective and efficient internal processes and procedures in order to manage and deliver the required services while meeting cost, schedule, and performance metrics. (DRD-MA-01, Contract Management Plan). These contractor processes must facilitate service delivery from the contract level, service line level, project level, to the lowest operational support level. In providing the required services of the eMITS contract, The Contractor shall:

3.5.1 Operate and manage designated production systems, ongoing and new projects, and functions and activities required to provide products and services to the customer community in accordance with DRD MA-01, Contract Management Plan.

3.5.2 Create and maintain project plans (DRD MA-09, Project Plans).

3.5.3 Be knowledgeable of industry standard project management tools and implement those approved tools on this contract. The Contractor management shall demonstrate project management expertise by executing operational and development projects and activities per negotiated schedules and budgets.

3.5.4 Integrate appropriate methodologies and procedures into its Program and Project Management processes and shall document those processes in the Project Plans.

3.5.5 Document and demonstrate effective integration across all applicable services within this contract as well as those required of associate contracts in order to provide comprehensive service delivery to customers.

3.5.6 Establish Service Level Agreements] with customers and supported organizations.

3.5.7 Create and maintain processes to support the NASA requirements to report IT spend in support of OMB Data Calls.

3.5.8 Create and report metric performance as directed by contract or work package.

3.5.9 Provide Rough Order of Magnitude (ROM) estimations for anticipated or planned work, in accordance with DRD MA-06, Rough Order of Magnitude, when requested by the Government.

3.5.10 Document Standard Operating Procedures as defined in DRD MA-12, Standard Operating Procedures.

3.5.11 Document Lessons Learned and Corrective Action Reports as directed by the CO or COR; or as deemed internally appropriate by Contractor management and deliver the report to the Government in accordance with DRD MA-14, Lessons Learned and Corrective Action Reports.

3.5.12 Create and maintain the deliverables required to support the NASA Continuous Monitoring process in accordance with NPR 2810.1.

3.5.13 Attend and support key Government-sponsored meetings and forums as required by the government.

3.5.14 Provide and maintain a Continuity of Operations Plan (DRD MA-08, Information Technology Service Continuity Management (SCM) Plan). The COOP shall:

3.5.14.1 Establish Contractor policy and guidance to ensure the execution of the mission essential functions for this contract as identified by the contractor and approved by the Government.

3.5.14.2 Address the situation/event when an emergency in a facility threatens or incapacitates operations and address the relocation of selected personnel and functions of any service provided by this contract.

3.5.14.3 Document the emergency response and recovery process

3.5.14.4 Document potential impacts and mitigations thereto, including contract status of threatened, diminished, or incapacitated, as well as an associated timeline.

3.5.14.5 Address the items in this section at each location in which services are provided and continuity of identified operations must be maintained.

3.6 Financial Resources Management

The Contractor shall:

3.6.1 Provide accurate and timely financial reports in accordance with NASA Policy Directive (NPD) 9501.1, NASA Contractor Financial Management Reporting System, NASA Program Requirement (NPR) 9501.2, NASA Contractor Financial Management Reporting, and NPR 9060.1, Cost Accruals. The Contractor shall deliver:

3.6.1.1 DRD MA-17, Financial Management Report.

3.6.2 Provide ongoing business analysis and respond to Government requests for financial information.

3.6.3 Maintain detail order and invoice records that support Government-performed invoicing (to customer organizations) and allow Government-performed invoice reconciliation.

3.6.4 Provide financial information maintained by the Contractor for use by the Government for budgeting purposes and business case analyses.

3.6.5 Provide financial planning data to support the Government budget process including but not limited to: Planning, Programming, Budgeting, and Execution [PPBE] budget calls, Operating plan budget calls, and special requests for budget impacts.

3.6.6 Maintain an internal accounting system that fully accommodates Government reporting requirements as defined in the DRD MA-17 Financial Management Report

3.6.7 Conduct quarterly accounting reconciliations (planned expenditures versus actual expenditures).

3.6.8 Support a contract-wide requirements/budget review meeting with the Government as defined in DRD MA-21, Contract Management Review. This internal review shall be completed prior to the annual Capital Planning and Investment Control Process (CPIC) (DRD MA-05, IT CPIC) and the annual program planning and budget execution (PPBE) cycle.

3.7 Property Management

The Contractor shall:

3.7.1 Submit for approval a property management plan in accordance with DRD LS-01 – Property Management Plan. The Contractor shall coordinate with each Center or locations’ Property Management Officer to ensure local policies and processes are followed as applicable.

3.7.2 Analyze available property at each location and provide planning and advice to maximize use of available property to support work package and task order requirements.

3.8 Safety and Health

The Contractor shall:

3.8.1 Perform work in accordance with DRD SA-01, Safety and Health Plan, and shall submit and maintain the plan per the Data Requirements List (DRL).

3.8.2 Complete Government provided Safety and Health training, including but not limited to, general online safety training and hazardous materials training, according to agency and individual center policy and depending on the work performed at designated locations.

3.8.3 Establish guidelines for contract personnel regarding emergency medical services and evaluation while they are on international travel in accordance with NASA FAR Supplement 1852.242-78.

3.9 Work Authorization

3.9.1 Work Authorization System.

3.9.2 Work will be authorized per this contract via work packages (DRD MA-07) as well as through the issuance of Indefinite Delivery/Indefinite Quantity task orders.

3.9.3 The Contractor shall operate according to the policies of the agency and its various local facilities. When standard/non-standard business hours are required, the hours will be defined on specific work packages. The Contractor shall ensure coverage of necessary services per requirements.

3.10 Quality Management and Control

The Contractor shall:

3.10.1 Submit a Quality Assurance Management Plan (QAMP) in accordance with DRD QE-01 that specifies the Contractor’s approach to assuring delivery of quality products, material, and services. The Contractor shall also submit a QAMP Quarterly Summary Report in accordance with DRD QE-01.

3.10.2 Ensure all personnel performing work are properly trained, certified, and qualified for assigned work requirements, to include recognition of job hazards for any equipment used. The Contractor shall be responsible for obtaining and maintaining the skills and certifications required on this contract.

3.10.3 Complete requirements in this work statement that meet any and all quality metrics as defined in this work statement, in work packages, or in task orders.

3.10.4 As directed by the Government, provide a plan for metrics development and propose metrics for any area of this contract for approval by the CO/COR.

3.10.5 The Government will standardize requirements metrics for services performed by the contractor at all locations where services are required to be performed, however, the Contractor shall be flexible and perform requirements according to each location’s specific requirements and needs.

3.10.6 Corrective Actions – Contractor shall develop and implement a Corrective Action Plan to address and remedy issues identified by either the Contractor or the Government.

3.11 Physical Security Management

The Contractor shall:

3.11.1 Provide Security Management services including IT-related physical security (not already included in local security contracts), and emergency management.

3.11.2 As it relates to IT-Related Physical Security - Implement a comprehensive security program consistent with NASA, Department of Defense (DoD), and Center-specific regulations and procedures.

3.11.3 Update and maintain (initial, change updates, etc.) to the DD 254, Contract Classification Specification.

3.11.4 The work to be performed under this contract is up to the Secret level.

3.11.5 The contracted personnel must be able to obtain and maintain the requisite clearance level in accordance with NASA policy and procedures for system, data, or facilities to perform assigned duties when performance starts.

3.11.6 All personnel performing on or supporting the eMITS contract must be United States (U.S.) Citizens.

3.11.7 All personnel requiring Secret access under this contract/order shall undergo a favorably adjudicated Tier 3 (T3) Investigation formerly known as a National Agency Check, Local Agency Check and Credit Check or Access National Agency Check and Inquiries as a minimum investigation. The Tier 3 Investigation will be maintained current within 10-years and requests for Secret Periodic Reinvestigations will be initiated by submitting a Tier 3R investigation prior to the 10-year anniversary date of the previous Tier 3 Investigation.

3.11.8 Contract personnel found ineligible by the appropriate central adjudication facility for Secret access will not be allowed to support a NASA contract requiring Secret access.

3.11.9 Visit Access Requests (VAR) shall be processed and verified through the NASA OPS personnel. Visits for contracts/orders are identified as "Other" or "TAD/TDY" and will include the Contract/Order Number and NASA Access level of the contract/order with any additional information. Contractors that do not have access to the OPS personnel may submit visit authorizations by e-mail in a password protected .pdf to the Contracting Officer Representative (COR) or Center Government representative.

3.11.10 Contractor personnel must comply with all local security requirements including entry and exit control for personnel and property at the government facility.

3.11.11 Contractor personnel will be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by Government security personnel. Failure to comply with Government security regulations and requirements will require the company to provide the Government with a written remediation/corrective action plan; furthermore, failure to comply with such requirements can be cause for removal and the contractor will not be able to provide service on this contract.

3.11.12 Contractor personnel with an incident or adverse information report who have had their access to classified information suspended will not be permitted to provide or to fill positions requiring access to classified information on a NASA contract/order.

3.11.13 The Contractor shall not divulge any information, classified or unclassified SBU\CUI, about NASA files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the NASA facility. Identification shall be worn and displayed as required.

3.11.14 NASA retains the right to request removal of contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, clearly conflict with the interest of the Government.

3.11.15 Contractor personnel will generate or handle documents that contain Sensitive But Unclassified (SBU) or Controlled Unclassified Information (CUI) according to NASA policies and procedures. Contractor shall have access to generate and handle classified material only at specified location(s) listed in this PWS. All contractor deliverables shall be marked in accordance NASA policy, procedures, and standards to include Freedom of Information Act Program, unless otherwise directed by the Government. The contractor shall comply with the provisions of the NASA policy for handling classified material and producing deliverables.

3.11.16 The Contractor shall afford the Government access to the contractor's facilities, installations, operations, documentation, databases and personnel used in performance of the contract. Access shall be provided to the extent required to cany out a program of IT inspection (to include vulnerability testing), investigation and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of data or to the function of information technology systems operated on behalf of NASA or NASA partners, and to preserve evidence of computer crime.

3.12 Information Security Management

3.12.1 IT Security Program Management Compliance

The contractor shall

3.12.1.1 Comply with NPR 2810.1, Security of Information and Information Systems.

3.12.1.2 Submit an IT Security Management Program Plan (per DRD MA-03, IT Security Plan) for its unclassified IT resources. This program plan shall describe the policy, processes, and procedures that will be followed to ensure appropriate security of IT resources that are developed, processed, or used under this contract. This plan will address the control of sensitive data housed in Contractor systems.

3.12.1.3 Have an Information Systems Security Officer (ISSO) who is responsible for the Contractor’s systems and serves as a single Point of Contact for NASA.

3.12.1.4 The ISSO shall be responsible for ensuring the development of Cybersecurity plans for resources owned or managed by the Contractor to perform work on this contract.

3.12.1.5 Comply with the Government’s ISM policies and procedures. Examples include Federal Information Security Management Act (FISMA), and National Institute of Standards and Technology (NIST).

3.12.1.6 Perform continuous analysis of industry best practices and trends and inform the Government of changes that could impact or improve the Government’s ISM process.

3.12.1.7 Ensure successful completion of all mandatory annual Cybersecurity Training for all Contractor personnel.

3.12.1.8 Incorporate new projects/programs into the existing security program.

3.12.1.9 Provide regular Information Assurance participation in Line of Business activities including sprint planning sessions, implementation efforts for strategic initiatives, and coordinate of security activities.

3.12.1.10 Work with the NASA OCIO and incumbent Contractors to transfer responsibility for all Cybersecurity requirements for existing information systems that are within the scope of the eMITS contract, from the incumbent contractor to the eMITS contractor. Be responsible for transferring the same responsibilities to any contractor who will be assuming the work, e.g. as a follow-on contractor or alignment due to NASA transformation activities.

3.12.1.11 Provide information security subject matter expertise to all information and systems development teams to provide recommendations on security measures and requirements throughout the contract’s lifecycle.

3.12.1.12 Participate in the development of security program metrics and periodically review existing policies, procedures, and processes against Federal and NASA compliance policies and standards as requested by the customer.

3.12.1.13 Recommend improvements or changes to security policies, standards, operation procedures, technical guidance, and any other security directives, guidance, and procedures as necessary.

3.12.1.14 Assist NASA in providing guidance and in-house training to Center personnel on protection of sensitive information.

3.12.1.15 Track applicable policies and regulations pertaining to information protection.

3.12.1.16 Support routine inspections to ensure the proper disposition and/or sanitization for files and records that contain privacy information, including Personally Identifiable Information

(PII).

3.12.1.17 Provide support for the development of requirements for cybersecurity solutions.

3.12.1.18 Provide process and procedure management for NASA applications.

3.12.1.19 Understand emerging Cybersecurity needs and develop and adapt new processes, procedures, and capabilities in response.

3.12.1.20 Develop, document, and maintain as needed, standard operating procedures for any contract specific implementation of management, operational, and technical Cybersecurity controls.

3.12.1.21 Ensure all employees have the appropriate Level Of Confidence (LOC) prior to gaining access to any system containing NASA data.

3.12.1.22 Comply with the Cybersecurity requirements as defined in NPDs, NPRs, NIDs, Cybersecurity and Privacy Division Handbooks, and NASA Standards as identified in Attachment J-B, Applicable Documents List (ADL), and cited in NFS 1852.204-76, Security Requirements for Unclassified Information Technology Resources.

3.12.1.23 Comply with information protection requirements in accordance with ITS-HBK- 1382.03-01, Privacy Risk Management and NFS 1852.204-76: Collections, PIAs, and SORNs, to ensure compliance with federal regulations and privacy protection requirements.

3.12.1.24 As it relates to Cybersecurity, incorporate appropriate safeguards in accordance with applicable NASA CSPP standards, as noted in 3.12.1.22 above, to ensure availability, integrity, and confidentiality of information and IT resources utilized in performance of this contract. Also, submit all data in accordance with applicable Government standard formats and protocols.

3.12.1.25 Support NASA in the implementation, documentation, and integration of operational and technical Cybersecurity policies, procedures, and control measures in accordance with NASA policies, procedures and other guidelines identified in the Applicable Documents List (ADL) covered by the NFS 1852.204-76.

3.12.1.26 Ensure that systems secure sensitive data, as it is stored or transmitted across the network, complies with Federal Information Processing Standard (FIPS) 140-2, Security Requirements for Cryptographic Modules, and Attachment J-B, Applicable Documents List (ADL), and NFS 1852.204-76,

3.12.1.27 Prepare, submit, and maintain Contractor Account Management documentation to include personnel clearance information, training records, contractor user account information (e.g. user-ids, access, quotas, and requirements)

3.12.1.28 Personnel Security Clearance is required. The work to be performed under this contract is up to the Secret level. Therefore, the company must have personnel and process to maintain the rating for the identified positions. Employee information is sensitive. Provide information reporting annually for personnel screening as required by NPR 2810.1 and NPR

1600.1 on position risk.

3.12.1.29 Ensure that when using NASA IP address space, only NASA-provided external Internet connections shall be used in accordance with Attachment J-B, Applicable Documents List (ADL), and NFS 1852.204-76, Applicable Documents List (ADL) and associated NASA Information Technology Requirements (NITRs).

3.12.1.30 Support a comprehensive Intrusion Detection System (IDS), IPS and Incident Response (IR) capability, in coordination with the NASA Security Operations Center (SOC).

3.12.1.31 Make available logs from any information systems, as requested by the NASA SOC and Cybersecurity Official. Electronic raw log data shall be forwarded to the SOC, in accordance with NASA policies, procedures and guidance.

3.12.1.32 Support NASA incident investigations. This includes providing analysis of the NASA traffic passing through NASA connections to any connections between NASA and its partners, even if they are utilizing NASA address space, including Internet connections.

3.12.1.33 Promptly coordinate Intrusion Detection/Incident Response identification/support on eMITS systems and activities with the NASA SOC, the Center Cybersecurity Official (Center Information Security Officer (CISO), and Incident Response Manager (IRM)).

3.12.1.34 In support of CSPP, utilize NASA’s IT, Compute Services, and CP capabilities to perform the Cybersecurity support functions at all Centers, component facilities and Headquarters, in accordance with item 3.12.21 above.

3.12.1.35 Provide rapid response and mitigation as directed to any vulnerabilities or incidents that might occur. This includes responses to threat notification, Risk Management, network monitoring, centralized database collections, Cybersecurity response tracking and analysis, and forensics in the Cybersecurity Incident Management Environment and provide to the Cybersecurity Official.

3.12.1.36 Establish and maintain information feeds with internal and external technical working groups to include IT and Cybersecurity professional associations, NASA Centers and component facilities, vendors, and national/international industry organizations.

3.12.1.37 For systems eMITS is responsible for: Evaluate, recommend, and test prototypes of Cybersecurity tools, techniques, and in coordination with NASA CSPP.

3.12.1.38 Provide system information to authorized recipients within NASA Cybersecurity officials as requested to support investigations, audits, personnel actions, and legal proceedings.

3.12.1.39 Coordinate with Agency and Center information systems and disaster recovery experts across NASA to verify integration of procedures and planning techniques.

3.12.1.40 Demonstrate compliance with IT information system security requirements by documenting a system security plan (DRD MA-04, Information Technology (IT) Security Plan (SSP) and Reports for systems operated or maintained under this contract.

3.12.1.41 Meet the requirements for security authorization, also known as certification and accreditation (C&A), of these information systems, consistent with FIPS 200 and NIST SP 800- 37 (Rev 1).

3.12.2 Compliance

3.12.2.1 Comply with all Federal and NASA policies and guidance, including NASA Policy Directives (NPD), NASA Procedural Requirements (NPR), NASA Interim Directives (NID), Cybersecurity handbooks, policy decision memoranda (PDM), and NASA standards, related to information security and Cybersecurity.

3.12.2.2 Maintain separation of sensitive IT duties within the contract service areas to limit risks due to insider threats.

3.12.2.3 Be responsible for appropriately protecting NASA information, in electronic or physical form, IAW Federal and NASA policy.

3.12.2.4 Appropriately label documents and media containing sensitive NASA information.

3.12.2.5 Comply with reporting requirements, including security configuration profiles, patch management, hardware inventory, and software inventory.

3.12.2.6 Ensure applications are registered using the designated NASA Application Tracking/Registration system, currently the Agency Application Rationalization Tool.

3.12.2.7 Perform analysis of FISMA, NPR, NIST, or other applicable documents or standards.

3.12.2.8 Ensure all data has been properly removed from non-operational (spare, decommissioned, excessed, etc) IT systems.

3.12.2.9 To meet Patch and Cybersecurity Configuration Management Requirements, address all vulnerabilities of all information systems under the scope of this contract in accordance with NASA policy and guidelines, including any organizationally defined values (ODV) and NASA configuration management standards.

3.12.2.10 The NASA SOC shall lead the Mitigation Action Recommendation (MAR) actions.

The contractor shall receive and mitigate vulnerabilities on reports from multiple sources, including, but not limited to: the NASA SOC, Center vulnerability patch actions issued through the individual Center/NASA Facility action tracking process, and Federal/Agency/Center security assessments (Examples include, but are not limited to: Department of Homeland Security, Agency Network Penetration Test, Web Application Deep Dive, Web Application Security Project, CSPP regularly scheduled network vulnerability scans, Government Accountability Office (GAO) and Office of Inspector General (OIG) audits).

3.12.2.11 Meet the current Agency standard timelines for remediation of vulnerabilities and the creation and management of POA&Ms or requests for RBDs as needed based on the CSPP defined timelines in NASA system of record.

3.12.2.12 Scan all information systems supported under this Contract for vulnerabilities (both credential and non-credentialed) in accordance with the NASA defined schedule and policy, using NASA approved tools and templates.

3.12.2.13 Review vulnerability reports provided from NASA, and other contractors and implement system patching as required. The contractor shall be held accountable for patching of all systems covered by CP managed SSP.

3.12.2.14 Provide scan configuration files and scan reports for all systems with an approved RBD that cannot run NASA approve reporting agent software.

3.12.2.15 Ensure that managed systems are rebooted on a regular basis, as necessary, to ensure patches are fully installed on systems and shall also provide deviation reporting and RBD requests in accordance with NASA policy for approval for mission-essential functions that would be adversely affected.

3.12.2.16 Implement NASA approved ODV and Cybersecurity Standards and Engineering Team (CSET) baseline configurations as documented in Agency policy. Ensure all deviations are documented in NASA system of record.

3.12.2.17 Plan for and implement the full system development lifecycle maintenance and updates of assets and systems, including but not limited to:

3.12.2.18 Near real time asset tracking and reporting (to include configuration management) from procurement to retirement in order to optimize the most accurate Cybersecurity response and analysis.

3.12.2.19 Removal of retired systems from Active Directory, DNS Dynamic Host Configuration Protocol (DHCP) Internet Protocol Address Management (IPAM) (DDI) and pertinent Cybersecurity asset databases.

3.12.2.20 End of Life and End of Support replacement strategy in accordance with NASA policy and requirements.

3.12.2.21 Complete data sanitization for assets in accordance with NASA policy and procedures.

3.12.2.22 Protect all information systems using NASA enterprise defined baseline configurations and other NASA approved tools (including anti-virus and anti-spyware) solutions, which provide automated updates of malware/malicious code detection definitions at least once every 24 hours and automated logging and reporting.

3.12.2.23 Apply appropriate least-privilege access of system in accordance with NASA policy and guidance, as noted in item 18 above.

3.12.2.24 Comply with the Risk Information Security Compliance System (RISCS) and Cybersecurity Enterprise Data Warehouse (ITSEC-EDW) reporting requirements, including security configuration profiles, patch management, hardware inventory, and software inventory.

The CDM tools must be installed for reporting. For systems that cannot install CDM tools, a NASA-approved RBD must be submitted for approval, and the devices must be manually inventoried and reported in accordance with NASA policy and procedures, as noted in item 18 above.

3.12.2.25 Comply with the Risk Information Security Compliance System (RISCS) and Cybersecurity Enterprise Data Warehouse (ITSEC-EDW) reporting requirements, including security configuration profiles, patch management, hardware inventory, and software inventory.

The CDM tools must be installed for reporting. For systems that cannot install CDM tools, a NASA-approved RBD must be submitted for approval, and the devices must be manually inventoried and reported in accordance with NASA policy and procedures, as noted in item 18 above.

3.12.2.26 Ensure the NASA-provided CDM solutions are installed and continue to function properly (based on NASA CSPP) on all supported IT devices and integrated with NASA reporting mechanisms, including RISCS and IT ITSEC-EDW.

3.12.2.27 Configure and maintain operating systems and software on all systems provided under this Contract in accordance with Federal and NASA Cybersecurity configuration policies and guidance. The Contractor shall ensure all applicable IT systems, applications, and services are securely configured based on the security configuration standards defined by CSPP.

3.13 Section 508 Compliance

The contractor shall ensure that all products, platforms, and services delivered as part of this work statement that are Information and Communication Technology (ICT) or contain ICT, must conform to the Revised Section 508 of the Rehabilitation Act Standards, 36 C.F.R. § 1194.1 & Apps. A, C & D. The Standards may be found at Revised 508 Standards and 255 Guidelines (access-board.gov).

The Applicable Chapters for this acquisition are as follows:

508 Chapter 1: Application and Administration

508 Chapter 2: Scoping

Chapter 3: Functional Performance Criteria

Chapter 4: Hardware

Chapter 5: Software

Chapter 6: Support Documentation and Services

Chapter 7: Referenced Standards - WCAG 2.0.

3.14 CONTRACT ADMINISTRATION SYSTEM

The iSite Contract Management Portal (iSite) will be provided by NASA To facilitate contract administration and oversight for this Contract. iSite is a suite of tools which includes configurable workflows, financial reporting, configurable estimates, document repository, and automated notifications among other functions based on NASA managed security controls. More information may be found at the vendor’s website https://www.isitellc.com/icmp/.

NASA and Contractor shall use the provided system for requesting new work, revising existing work, financial planning, reporting, actuals, deliverable submission, technical performance feedback gathering, and serve as the primary system for communicating financial and funding information to include monthly time-phased baseline plans for all work packages. The provided system will allow for the electronic initiation, receiving, review, approval, issuance, and modification of work under this contract.

The following table identifies the Contract Administration roles and responsibilities that the Contractor shall:

Contract Administration Roles and Responsibilities

1. Use iSite to communicate, at a minimum, estimated costs and fee by month, posting actuals, which will inform financial/funding reports, provide technical proposals in response to requests for work, describe labor categories and hours proposed and consumed, and communicate subcontractor costs proposed and consumed during performance of this contract.

2. Access to data contain within the system will be controlled through security group permissions and role-based access.

3. Work with the Government to configure the provided system for this contract as part of contract phase-in and ensure that the system is operational prior to start date this contract.

Please reference attachment J.X Contract Administration Tools & Services (CATS): iSite Contractor On-boarding Guide for more details on the necessary information for iSite system configuration.

4. Within 5 days of contract award, the Contractor shall provide a primary point of contact for iSite efforts.

Table 3.14-1 Contract Administration

4. IT Management

Establishment of policies, continuous monitoring, implementation of controls, establishment of appropriate vetting mechanisms, change management, configuration management, risk management, service management and integration, communication mechanisms, portfolio management, and investment management are some of the key processes and activities that support IT Management

4.1 IT Policy Management

The Contractor shall:

4.1.1 Support the development, implementation, maintenance, and management of the OCIO policy repository (NODIS).

4.1.2 Support Agency Policy Oversight Working Group activities and deliverables.

4.1.3 Support the Agency IT Policy Lead, as point-of-contact, for Master List matters, administer the Master List, and support training classes for Master List custodians

4.1.4 Serve as primary point-of-contact for quality systems master list matters, administer the Master List, and conduct training classes for master list custodians.

4.1.5 Ensure that requested policy information or reviews are provided within schedule guidelines and establish, document, and maintain a process to control the Master List.

4.1.6 Coordinate periodic document reviews as requested.

4.1.7 Review new or revised NASA policy, Center policy, OMB policy, and other policies as required.

4.1.8 Facilitate the drafting of revisions to existing policy and the creation of new policies.

4.1.9 Provide technical assistance in the development of the policy/documentation waivers.

4.1.10 Provide assistance in processing policy and waivers through the Agency and Center processes.’

4.1.11 Review, evaluate, and recommend the disposition of Policy/Documentation change requests (CRs).

4.1.12 Facilitate the development and revision of the policy waiver forms and policy waiver requirements.

4.1.13 Provide weekly management reports of policies and associated actions and CRs.

4.1.14 Maintain a log that includes the status of IT waivers

4.1.15 Support the development, implementation, and maintenance of a streamlined Agency and Center IT policy review process that will facilitate the implementation of and compliance with IT policy across the Agency. The Contractor shall develop IT policy and procedures in compliance with Government, NASA, OCIO, and center policy laws, regulations, and directives.

4.1.16 Develop, implement, and disseminate IT policy and procedures in accordance with NASA OCIO policy directives where controlling. The Contractor shall review, develop, and implement center IT policy and compliance therewith.

4.2 IT…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .