DCD IT Admin Contract PWS (DRAFT).docx
DOCX document 118 KB Posted
- Attached to
- Request for Information - IT Administration Contract for AFRL Federal contract opportunity
- Solicitation number
- FA865225R0002
About this file
This is a Performance Work Statement (PWS) for an Indefinite Delivery Indefinite Quantity (IDIQ) contract supporting the Air Force Research Laboratory (AFRL) Digital Capabilities Directorate's IT administration services. The contract will provide comprehensive IT support across multiple technical domains, including infrastructure network management, software development, cybersecurity, cloud services, systems engineering, and IT service management. The base period is 12 months with four one-year options, and the contract will be administered via a Firm Fixed Price Contract Line Item Number (CLIN) with additional Other Direct Costs (ODC) and Travel CLINs.
Key performance areas include supporting enterprise IT programs like Enterprise Business Systems (EBS), Digital Laboratory Environment (DLE), Air Force Research and Development Mission Infrastructure (AFRDMI), and ServiceNow. The contractor will be responsible for tasks such as network design, software development, cybersecurity compliance, cloud migration, system integration, training, and portfolio management. Performance metrics are detailed in a Services Summary matrix covering areas like sustainment, help desk support, software development, cybersecurity, and program management. The contract requires personnel with expertise in various technical domains and the ability to support classified environments up to Top Secret/Sensitive Compartmented Information (TS/SCI) levels.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions_and_Answers_FA865225R0002.docx | DOCX document | |
| Questions_and_Answers_FA865225R0002.docx | DOCX document | |
| Questions_and_Answers_FA865225R0002.docx | DOCX document | |
| Questions_and_Answers_FA865225R0002.docx | DOCX document | |
| Questions and Answers_FA865225R0002.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement for
DIGITAL CAPABILITIES DIRECTORATE
IT ADMINISTRATION
Indefinite Delivery Indefinite Quantity (IDIQ)
In Support Of
Air Force Research Laboratory
4 Aug 2025
AFRL/PKI
Air Force Materiel Command
Table of Contents
| 1. | Introduction | 2 |
| 2. | General Requirements | 3 |
| 2.1. Non-Personal Services | 3 | |
| 2.2. Inherently Governmental Functions | 3 | |
| 2.3. Ethics | 3 | |
| 2.4. Data Rights | 3 | |
| 3. | Task Order Management | 4 |
| 3.1. Period of Performance and Contract Structure | 4 | |
| 3.3. Integration of Effort | 6 | |
| 3.4. Quality of Support | 6 | |
| 3.5. Contractor Facilities for Task Order Management | 7 | |
| 3.6. Management of Personnel | 7 | |
| 3.7. Business Management | 9 | |
| 4. | Performance Requirements | 9 |
| 4.1 Description of Services | 10 | |
| 4.2. Deliverables | 18 | |
| 4.3. Certification Requirements | 19 | |
| 5. | Quality Assurance | 20 |
| 5.1. Government Inspection | 21 | |
| 5.2. Contracting Officer’s Representative (COR) | 21 | |
| 5.3. Administrative Records | 21 | |
| 5.4. Quality Control | 21 | |
| 5.5. Performance Evaluation | 21 | |
| 6. | Services Summary (SS) | 22 |
| 7. | Contract Security | 24 |
| 7.1. Non-Disclosure Agreements | 24 | |
| 7.2. Information Access | 25 | |
| 7.3. Physical Security | 25 | |
| 7.4. Operational Security (OPSEC) | 26 | |
| 7.5. Communications Security (COMSEC) | 26 | |
| 7.6. Security Clearances | 27 | |
| 7.7. In/Out Processing | 27 | |
| 7.8. Security Administration | 27 | |
| 7.9. Science and Technology (S&T) Protection | 28 |
Introduction This IDIQ Performance Work Statement (PWS) describes the general and representative Contractor knowledge, experience and capabilities required in support of the Air Force Research Laboratory (AFRL) Digital Capabilities Directorate (IZ) Program Offices (PO). The scope of this PWS includes the management and technical support for IZ’s continued development, modernization, implementation, and sustainment of IZ Information Technology (IT) capabilities/applications to support the IZ program office and all AFRL technical directorates (TDs) and other customers. The Digital Capabilities Directorate’s mission is to provide overarching requirements to streamline activities, integrate business information, provide crucial insights, and promote collaboration across the AFRL enterprise.
General Requirements
2.1. NON-PERSONAL SERVICES
The Government shall neither supervise Contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances shall the Government assign tasks to or prepare work schedules for individual Contractor employees. The Contractor shall manage its employees and guard against any actions that are of the nature of personal services or give the perception of personal services. If the Contractor believes that any actions constitute or are perceived to constitute personal services or are outside the scope of this task order, the Contractor shall notify the Contracting Officer (CO) immediately.
2.2. INHERENTLY GOVERNMENTAL FUNCTIONS
The Contractor shall not perform any inherently governmental functions (as defined by FAR Subpart 7.5). All decisions relative to programs supported by the Contractor shall be the sole responsibility of the Government.
The Contractor shall not counsel, mentor, make judgment and/or discretionary decisions or perform any other activities related to supervision of Government personnel.
If the Contractor believes that any actions constitute or are perceived to constitute inherently Governmental functions, the Contractor shall notify the CO immediately.
2.3. ETHICS
The Contractor will be highly visible to the entire acquisition community as a result of providing assistance to the Government. Consequently, the Contractor shall present an unblemished appearance in regard to ethics, discretion, and protection of information, including the guidelines for electronic mail use listed in AFMAN 33-152, AFI 33-322 Records Management, and Internet use of AFI 35-107 Public Web and Social Communications.
2.4. DATA RIGHTS
The Government shall retain unlimited rights to all data and deliverables developed at Government expense. At any time and per the Government request, any records, documents, and associated papers shall be available for review.
2.5. PROGRAM SCOPE
The contractor will support AFRL/IZ enterprise IT programs that enable the critical AFRL scientific and engineering missions. Below is a list of existing enterprise services provided by AFRL/IZ:
Enterprise Business Systems (EBS) Enterprise Business Systems (EBS) is a business mission system proving the IT that facilitates the implementation of the AFRL centralized business processes that embodies RDT&E of the activities across AFRL. EBS leverages COTS IT tools & applications to complete the transformation of business functions in AF S&T management. The mission of EBS is to provide and sustain IT solutions to support AFRL enterprise business processes.
Key Interfaces for EBS include PMRT (CCaRs) (Program Management Resource Tools), JOCAS II (Job Order Cost Accounting System), ConData (Contracting Data), AFNet Active Directory, SAM.gov, URED (Unified Research and Engineering Database), GAFS (Financial Data), PBES (Budget Data), and EMASS.
Digital Laboratory Environment (DLE) The Digital Laboratory Environment (DLE) is a secure, cloud-hosted IL-5 environment which provides users with access to S&T digital tools. DLE enables enterprise-wide collaboration, as well as rapid on-ramp of mission partners outside of AFRL, within the DoD, industry, and academia. It is hosted on AWS Gov Cloud and can be accessed from NIPR, DREN, and commercial internet through a standard web browser.
DLE provides modern digital S&T tools such as: collaborative software development, project planning, tracking, MBSE, MS&A, mathematics, specialty engineering, data filing, and sharing tools. Tools available with DLE include, but are not limited to, collaboration tools such as Jira, Confluence, Discourse, and Overleaf; SW Factory and CI/CD tools such as GitLab/Gitlab Ultimate, Jenkins, Artifactory, and SonarQube; and MBSE and MS&A tools such as ANSYS, MagicDraw (Cameo), MATLAB, and Teamwork Cloud.
Air Force Research and Development Mission Infrastructure (AFRDMI) The Air Force Research and Development Mission Infrastructure (AFRDMI) is a hardware and software platform that provides secure compute, network, and storage capabilities for classified RDT&E activities. This platform's four zones (two in each of two classifications) each have an Authority to Operate (ATO) from the Air Force Intelligence Community (IC).
AFRDMI offers two distinct environments:
Zone B: The "Anything Goes" Sandbox: This isolated environment allows for maximum flexibility. Researchers can experiment with virtually any software or hardware, analyze classified data, and develop cutting-edge tools without the constraints of strict security protocols.
Zone A: The Operational Test Environment: As projects mature, users can transition to Zone A, which offers SIPR and JWICS connectivity. This enables greater access to operational data and systems, fostering collaboration with customers and partners.
Together the platform and its ATOs establish approved environments where Scientists and Engineers can perform R&D to rapidly develop and test applications using curated or real-time classified data.
S-VISION
S-VISION is a secure, isolated Secret network enabling AFRL users and external partners to collaborate using approved software and hardware for research, development, test, and evaluation (RDT&E). S-VISION is a secure and collaborative networking solution intended for AFRL users and their partners, focusing on easing the deployment and usage of approved software and hardware within a Secret network environment. This system was designed to enable AFRL's research, development, test, and evaluation (RDT&E) activities.
ServiceNow ServiceNow is a comprehensive cloud-based platform designed to assist enterprise organizations in improving their operational efficiencies. It does this by providing a suite of tools and features that enable the streamlining and automation of routine work tasks across a wide range of business processes. This automation is achieved through the use of advanced AI-driven technology, making it easier for businesses to manage and optimize their workflows. ServiceNow's primary focus lies in three main areas: IT service management (ITSM), IT operations management (ITOM), and IT business management (ITBM). These areas cover various aspects of an enterprise's technology infrastructure and management, ensuring that all operations run smoothly, efficiently, and with minimal human intervention.
Other Programs as Defined The Digital Capabilities Directorate anticipates the transition of additional software programs into the Delivered Products and Services Portfolio throughout the lifespan of this contract vehicle, as well as the need for exploratory efforts to identify potential future software offerings. These programs may encompass a broad technical scope, including, but not limited to the development of new software applications, modernization of legacy systems, and ongoing maintenance and support of existing applications. As pilot programs are matured and identified for transition, additional task orders may be awarded for these programs and other emerging technologies as needed to support the evolving mission and objectives of the Digital Capabilities Directorate. These task orders may require specific technical expertise and certifications related to the performance requirements listed below.
Task Order Management
3.1. PERIOD OF PERFORMANCE AND CONTRACT STRUCTURE
Performance is 12 months with four one-year options. The DCD IT Administration contract will support digital programs across the Directorate, with task orders being awarded for each program. The contract will be administered via a Firm Fixed Price CLIN. An ODC CLIN and a Travel CLIN will be included for program support to include optional purchase of software licenses and hardware. FAR 52.217-08 is included in this contract.
3.2. TRANSITION PLANNING
The transition period is from the task start date and will last no more than 30 days.
The Contractor shall submit applications to obtain Contractor identification badges, security clearances in accordance with (IAW) DD Form 254, as required, Internet and e-mail connectivity, etc.
Kick-off Meeting. The Contractor shall schedule a kick-off meeting with the CO, PM and COR within 10 calendar days of task order award. The CO will coordinate and confirm the date, time and location of the kick-off meeting. Notification shall be provided at least 5 calendar days prior to the scheduled meeting.
In addition to the clause “Continuity of Services” (FAR 52.237-3), Contractor agrees to give support to and cooperate with any successor that may be designated prior to the expiration of this contract. Phase-in assistance to a successor Contractor may be required during the final 60 days of this contract.
3.3. INTEGRATION OF EFFORT
The Contractor shall be responsive to task requirements, to the requirements of task order management and to the provision of programmatic data to the Program Management Officer (PMO). The Contractor shall employ methods and systems which will maximize the capacity to monitor and provide program management of complex tasking across this diverse organization. The Contractor shall provide monthly status of program supported and tasks performed to the Program Office.
3.4. QUALITY OF SUPPORT
The Contractor shall provide the necessary resources and infrastructure to manage and administer this task order. The Contractor shall provide appropriate, flexible, and dynamic support in response to mission demands and changes in technology and technical requirements.
The Contractor shall accomplish the assigned work by employing and utilizing qualified personnel with the appropriate combination of education, training and experience; matching personnel skills to the work required; and ensuring the labor categories, labor rates and man-hours utilized in the performance meet contract requirements.
Qualified personnel are defined as meeting or exceeding the stated qualification requirements in the educational and experience labor categories table(s). Additionally, the Contractor shall provide qualified replacement/substitute personnel which meet or exceed the same standards.
The Contractor shall identify and implement its approach for providing and ensuring quality throughout its solution to meet the requirements of the PWS via the Contractor’s Quality Management Plan (QMP). The QMP shall describe the application of the appropriate methodology (i.e., quality control and/or quality assurance) for accomplishing performance requirements. The QMP shall describe how the appropriate methodology fulfills the Government’s requirements. The Government has the right to require revisions of the QMP should the QMP have major failures affecting the quality of the services required at any time during performance. Quality Management Plan (CDRL A013)
3.5. CONTRACTOR FACILITIES FOR TASK ORDER MANAGEMENT
The Contractor will be provided on-base office space for the purpose of direct program execution. On-base space and equipment will be provided, as defined by Task Order.
3.6. MANAGEMENT OF PERSONNEL
3.6.1 Workforce Stability. The Contractor shall maintain a stable workforce while minimizing turnover and managing their personnel in such a way as to minimize the impact of any turnover and/or disruption to the customer and/or mission. The Contractor shall ensure continuation of services during personnel absences due to sickness, leave, and voluntary or involuntary termination from employment such that there is no negative impact to the Government mission schedule. Once the Contractor knows an employee is leaving and will no longer support a task, the Contractor shall provide written documentation to the COR within 1 calendar day of the employee advising the Contractor of his/her intent to leave. In the case of a no-notice departure, the Contractor shall immediately inform the COR. This written notification shall include the date and time the position will be vacant, anticipated replacement date, and management action, if needed, to ensure task mission remains on schedule toward completion. A position shall not remain vacant for more than three (3) calendar weeks.
3.6.3 Removal of Personnel at Government Request. In addition to the remedies for poor performance, the Government may request removal (permanent or temporary) of personnel for security, safety, or health reasons, upon discovery of fraudulent credentials or qualifications.
3.6.4 Contractor Identification in the Government Workplace. All Contractor employees shall wear company picture identification badges and/or lanyards to distinguish themselves from Government employees. All Contractor employees shall prominently identify their workstations as a Contractor workstation with their company name. When conversing with Government employees during business meetings, over the telephone, or via electronic mail, Contractor employees shall identify themselves as Contractor employees and who they are employed by to avoid sensitive topics that Government employees should not discuss with Contractors. Contractors shall identify themselves on any attendance sheet or any coordination documents. Electronic mail signature blocks shall identify their company affiliation. Contractor badges shall be worn when Contractor employees are at Government installations or when on temporary duty (TDY) at another location. Government-issued badges, identification cards, passes, and vehicle registration media are U.S. Government property to be accounted for, protected, and returned to the Government the next business day when no longer required.
3.6.5 Access to Worksite. In events such as a base shutdown due to severe weather or security issues (ex/September 11, 2001), IAW FAR Clause 52.249-14, Excusable Delays, in Section I of the contract, the Contractor will work with the Government to determine payment terms, and any payments will be subject to (CO) approval. For official Major Command (MAJCOM) family days, or holidays granted by Executive Order, the Government is not liable for the Contractor’s costs incurred for work at the locale affected by the shutdown on other than Firm Fixed Price (FFP) contracts. In all cases, if Government personnel are not available in a Government facility to oversee Contractor activities, Contractor personnel shall leave the premises. The contractor is expected to work at an off-site location.
3.6.8 Location and Hours of Work. Accomplishment of this PWS requires work to be performed at Government, Prime Contractor, or Subcontractor facilities unless otherwise approved by the CO. The primary location of work is Government facilities, as specified by PWS. The primary work location for baseline support is Wright-Patterson Air Force Base, OH. The alternate work location is contractor facilities, as specified by the CO. Travel to other Government or Contractor facilities may be required.
For baseline support, core hours of work are from 0900 to 1500 daily EST. All employees are expected to be available during core hours. Alternate Work Schedule (AWS) may be available, as approved by the COR, contingent upon no degradation in mission accomplishment and/or customer service. Short-term situations may make performance in excess of 8 hours per day, 40 hours per week necessary on occasion. The Contractor must ensure that they can provide for this type of contingency. Contractors may be required to work outside of the normal duty hours indicated above.
Hours for individual sub-tasks may be further specified by PWS and may or may not fall within the work schedule described above.
3.6.9 Legal Holidays. Federal law (5 U.S.C. 6103) establishes public holidays for Federal employees, published by the Office of Personnel Management (OPM), and will be observed under this contract. The Contractor’s employees are not required to perform services on legal holidays and/or the day of Government observation if legal holiday falls on the weekend.
3.6.10 Temporary Duty (TDY)/Travel. The Contractor may be required to travel using commercial air, Government air, and other conventional modes. Travel arrangements will be based on individual tasks, and the cost of travel will be directly reimbursed from task funding. All Continental United States (CONUS) travel requires prior approval by the COR. All Outside the Continental United States (OCONUS) travel requires prior approval by the CO.
3.6.11 Government Furnished Property, Equipment, Material, Information, or Services. Contractors will be provided Government Furnished Property (GFE) laptops, Common Access Cards (CACs), and access to Government facilities to complete tasks.
3.6.12 Emergency Support. The Contractor shall provide on-call support to respond to and resolve unplanned system outages to preserve systems (i.e. if building heating and cooling shuts down unexpectedly). This includes outages that occur outside of normal business hours, including evenings, weekends, and holidays. The Contractor shall acknowledge and begin working on a reported unplanned outage within four hours of notification. Notification may be provided via phone, email, or designated monitoring system alerts. The Contractor shall provide status updates to the designated Government Point of Contact (POC) every four hours until the outage is resolved. Emergency support requirements will be identified on a per task order basis.
3.7. BUSINESS MANAGEMENT
The Contractor shall establish efficient and effective processes and assign appropriate resources to effectively administer this task order. The Contractor shall implement and maintain a management structure that can effectively manage a diverse workload across multiple organizations within this task order. The structure shall include the ability to respond to requirements across the full range of potential workloads and shall provide the flexibility to support both long-term stable tasks, and short-notice short-duration tasks. The management structure shall provide the capability to rapidly reassign personnel as well as assign personnel to multiple, sometimes diverse tasks, where the Contractor and Government deem such action to be appropriate. Duties include but are not limited to responding to Government requests for contractual action in a timely fashion; having a single point of contact between the Government and Contractor personnel assigned at the appropriate levels to effectively manage the required tasks; assigning work effort; and maintaining proper and accurate time keeping and cost accounting records of personnel assigned to work on the requirement.
Individual project personnel shall be made available within two (2) weeks of the award.
The Contractor shall manage work distribution to ensure there is no Organizational Conflicts of Interest (OCI), in accordance with FAR Subpart 9.5 as supplemented.
Performance Requirements The Contractor shall maintain baseline IT support staff for the Digital Capabilities Directorate to support AFRL's digital transformation. This support will improve collaboration and execution of AFRL programs, projects, and deliverables through technical expertise. The baseline IT support staff will possess broad expertise as outlined in paragraph 4.1 below.
The Contractor shall provide specialized IT and cybersecurity personnel to the Digital Capabilities Directorate for individual task orders, executed via task-specific supplemental PWS documents. These task orders are anticipated to be agile, long-term efforts to sustain IT capabilities that accelerate research, experimentation, and innovation. These task orders require high-quality expertise to support and collaborate with AFRL teams to solve pressing digital challenges and develop practical, scalable, and secure systems.
4.1 Description of Services
The Contractor shall provide qualified personnel with expertise in the following areas:
1.1.1. Infrastructure
Network Management & Design: The Contractor shall provide comprehensive network management and design services, including the installation, configuration, maintenance, monitoring, and optimization of network devices such as routers, switches, firewalls, load balancers, and intrusion detection/prevention systems. This includes implementing and managing network security measures, ensuring network performance and availability, and designing and implementing new network solutions to meet evolving organizational needs. The contractor shall also provide support for network troubleshooting, performance analysis, and capacity planning.
Infrastructure Cabling: The Contractor shall install, maintain, and troubleshoot all network cabling infrastructure, including fiber optic and copper cables, ensuring proper labeling, testing, and certification to meet industry standards and best practices. For items outside the Contractor’s scope of control, the Contractor is responsible for coordinating with external entities (i.e., 88 ABW) to complete the work.
Data Center Hosting: The Contractor shall manage and maintain data center operations, ensuring the availability, reliability, and security of the physical environment, including power distribution, cooling systems, environmental monitoring, and physical security. This also includes disaster recovery planning and implementation.
Servers (physical and virtual): The Contractor shall provide comprehensive support for both physical and virtual servers, encompassing installation, configuration, maintenance, patching, performance monitoring, troubleshooting, and security hardening. This includes managing server operating systems, hardware, and software, as well as ensuring high availability and disaster recovery capabilities.
Storage & Backups: The Contractor shall implement and manage data storage and backup solutions, ensuring data integrity, availability, and recoverability. This includes designing and implementing backup and recovery strategies, managing storage capacity, and ensuring data security and compliance with relevant regulations.
Hardware (installation, configuration, maintenance): The Contractor shall install, configure, and maintain all IT hardware, including desktops, laptops, printers, peripherals, and other related equipment, to include fit/finish items to include cabale management and removal of excess hardware. This encompasses asset management, inventory control, and the secure disposal of outdated hardware according to established procedures.
Workstation/Printer/Peripheral Life-Cycle Support: The Contractor shall manage the entire lifecycle of workstations, printers, and peripherals, from deployment to maintenance, repair, and disposal. This includes installing and configuring operating systems, software applications, and drivers, as well as providing end-user support and troubleshooting assistance.
Mobile Computing (secure access to organizational resources): The Contractor shall provide support for mobile devices, including smartphones and tablets, ensuring secure access to organizational resources through the implementation and management of mobile device management (MDM) solutions, security policies, and end-user support.
Telephone Installation: The Contractor shall install and maintain telephone systems and equipment, including traditional PBX systems, VoIP systems, and associated hardware. This includes configuring call routing, voicemail systems, and other telephone features to meet organizational communication needs.
Conference Facility Support (A/V and video conferencing): The Contractor shall provide technical support for conference facilities, including the setup, operation, and maintenance of audio-visual equipment, video conferencing systems, and other presentation technologies. This includes troubleshooting technical issues and ensuring the smooth and reliable operation of conference room technology.
Voice Communication System Support (VoIP and traditional): The Contractor shall maintain and support voice communication systems, including both VoIP and traditional phone systems, ensuring high quality and reliability. This includes troubleshooting system issues, managing user accounts, and implementing necessary updates and upgrades.
Video Conferencing: The Contractor shall provide comprehensive support for video conferencing systems, including hardware, software, and network connectivity. This includes setting up and configuring video conferencing equipment, managing user accounts, and providing end-user training and support to ensure effective communication and collaboration.
Remote Access and Virtual Private Network (VPN) Management: The Contractor shall implement and manage secure remote access solutions, including Virtual Private Networks (VPNs), to allow authorized users to connect to the organizational networks remotely. This includes configuring VPN servers, managing user access, and ensuring the security of remote connections.
1.1.2. Software and Applications
Operating System Support: The Contractor shall provide comprehensive support for operating systems on servers and workstations, including installation, configuration, patching, performance monitoring, troubleshooting, and security hardening. This encompasses managing operating system security, user accounts, and software updates.
Software (installation, configuration, maintenance): The Contractor shall install, configure, and maintain all software applications, ensuring compatibility with operating systems and hardware, and managing software licenses. This includes providing end-user support and troubleshooting software issues.
Software License Management: The Contractor shall manage all software licenses, ensuring compliance with licensing agreements and optimizing software costs. This includes tracking license usage, renewing licenses, and maintaining accurate records of software licenses.
Sustainment Applications: The Contractor shall provide ongoing support and maintenance for existing applications, including bug fixes, performance tuning, security updates, and enhancements. This includes working with application vendors to resolve issues and ensure application stability and performance.
Application Support & Monitoring: The Contractor shall monitor application performance, troubleshoot issues, and provide support to end-users, ensuring application availability and optimal performance. This includes identifying and resolving performance bottlenecks, diagnosing and resolving application errors, and proactively addressing potential issues.
Visualization: The Contractor shall design and develop data visualizations, including charts, graphs, dashboards, and interactive reports, to support data analysis and reporting, using visualization tools and techniques to effectively communicate data insights to stakeholders.
1.1.3. Software Development and Integration
Agile Development: The Contractor shall utilize agile development methodologies, such as Scrum or Kanban, to manage software development projects, embracing principles of iterative development, continuous integration, and continuous delivery. This includes conducting sprint planning, daily stand-up meetings, sprint reviews, and sprint retrospectives.
Systems Integration: The Contractor shall integrate various software components, systems, and platforms, including cloud-based services, to create cohesive and interoperable solutions. This includes developing and implementing integration strategies, managing interfaces between systems, and ensuring data consistency and integrity across different platforms. Expertise in cloud platforms (including but not limited to Amazon Web Services, Azure, and Google Cloud Platform), cloud security, and cloud migration is required.
Software Engineering and Architecture: The Contractor shall apply software engineering principles and best practices to design, develop, maintain high-quality, scalable, and maintainable software solutions. This includes developing reusable, modular, and testable code, using version control systems, and adhering to coding standards. The contractor shall be proficient in various programming languages (including, but not limited to, Python), operating systems (including, but not limited to, Linux), and development tools. Familiarity with tools enabling effective collaboration, cross-disciplined teams, containers, virtual machines, etc., is required.
Domain and Active Directory Management: The Contractor shall manage and maintain the Active Directory and domain infrastructure, including user accounts, group policies, and domain controllers. This includes ensuring the security and integrity of the directory service, managing user access, and troubleshooting directory-related issues.
1.1.4. Data Management
Data Warehousing/Data Lakes: The Contractor shall design, implement, and manage data warehouses and data lakes, enabling the organization to store, process, and analyze large volumes of data from various sources. This includes data modeling, ETL (Extract, Transform, Load) processes, data quality management, and performance optimization.
Database Architecture and Administration: The Contractor shall design, implement, and administer databases, ensuring data integrity, security, and availability. This includes database design, installation, configuration, performance tuning, backup and recovery, security management, and expertise in various database technologies, including relational and NoSQL databases.
Data Engineering, Analytics, and Science: The Contractor shall develop and implement data pipelines, perform data analysis, and develop data-driven insights. This includes data cleansing, transformation, aggregation, and statistical modeling. The contractor shall be proficient in using data analysis tools and techniques to extract meaningful insights from data.
Archival, Retrieval, Sharing, and Publishing: The Contractor shall develop and implement processes for archiving, retrieving, sharing, and publishing data, ensuring data accessibility, security, and compliance with relevant regulations. This includes developing data governance policies, implementing access control mechanisms, and establishing data retention schedules.
Analysis and Reporting: The Contractor shall generate reports and analyses based on data, providing insights to support decision-making. This includes developing dashboards, reports, and visualizations to communicate data effectively to stakeholders.
Data Migration: The Contractor shall plan and execute data migration projects, ensuring data integrity and minimizing disruption to business operations. This includes data mapping, data validation, and data transfer between different systems and platforms.
1.1.5. Security
Cybersecurity (including Defensive Cyber Operations (DCO) infrastructure support): The Contractor shall implement and maintain security measures to protect organizational data and systems from cyber threats, including implementing firewalls, intrusion detection/prevention systems, security information and event management (SIEM) systems, and other security tools. The Contractor shall also provide support for Defensive Cyber Operations (DCO) infrastructure, including managing and administering security platforms, systems, applications, and tools.
COMSEC Inventory Management: The Contractor shall manage and maintain COMSEC (Communications Security) equipment and materials, ensuring compliance with all applicable regulations and policies. This includes inventory control, key management, and secure storage and handling of COMSEC materials.
Software Vulnerability Testing: The Contractor shall conduct regular software vulnerability testing to identify and remediate security vulnerabilities in software applications, using automated tools and manual techniques to assess and mitigate potential risks.
Software Container Vulnerability Testing: The Contractor shall conduct security vulnerability testing specifically for software containers, assessing container images and configurations for vulnerabilities and implementing necessary security measures to protect containerized applications.
Multifactor Authentication Implementation and Integration: The Contractor shall implement and integrate multifactor authentication (MFA) solutions to enhance security and protect against unauthorized access. This includes configuring MFA for various systems and applications and providing user support for MFA enrollment and usage.
Identity Lifecycle Management and Federation: The Contractor shall implement and manage identity lifecycle management and federation solutions, streamlining user access management and enabling secure access to resources across different organizations. This includes managing user identities, provisioning access, and implementing single sign-on (SSO) capabilities.
Equipment Accountability/Asset Discovery, Inventory Management, and Tracking: The Contractor shall maintain accurate records of all IT assets, including hardware and software, through comprehensive asset discovery, inventory management, and tracking processes. This includes identifying and classifying assets, tracking their location and lifecycle status, and ensuring accountability for all IT resources.
1.1.6. Cybersecurity Enhancements
Authority to Operate (ATO) support: The Contractor shall provide expert and comprehensive Risk Management Framework (RMF) support services to facilitate and maintain accreditation for [System Name] by the Authorizing Official (AO), with the primary objective being the timely and successful completion of the accreditation process, leading to an Authority to Operate (ATO). This support shall encompass all phases of the RMF lifecycle, as defined in NIST Special Publication 800-37, Revision 2, and DoD Instruction 8510.01, and shall include, but not be limited to: assisting in system categorization (CNSSI 1253 and AFRL policies); supporting security control selection and implementation; conducting thorough security control assessments (NIST SP 800-53A) including vulnerability scanning, penetration testing (if required), documentation review, reviewing system configurations, and examining audit logs; developing and maintaining a complete and accurate accreditation package (SSP, SAR, POA&M, and other supporting documentation); developing, maintaining, and tracking POA&Ms; supporting continuous monitoring activities; collaborating with system owners, Information System Security Managers (ISSMs), and other stakeholders to ensure effective RMF implementation; and serving as a technical point of contact for the AO and their representatives, providing accreditation status updates and addressing questions and concerns.
Cybersecurity Risk Management: The Contractor shall implement a cybersecurity risk management framework to identify, assess, and mitigate cybersecurity risks. This includes conducting risk assessments, developing risk mitigation plans, and implementing security controls to reduce risk.
Security Engineering and Compliance: The Contractor shall apply security engineering principles and best practices to design, develop, and implement secure systems, adhering to relevant security standards and frameworks such as NIST SP 800-160, NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
System Security Engineering: The Contractor shall perform System Security Engineering (SSE) activities throughout the system lifecycle. This includes conducting security requirements analysis, designing secure architectures, implementing security controls, and performing security testing and validation using tools like STIGs (Security Technical Implementation Guides).
Multi-level Security: The Contractor shall design and implement systems that support multi-level security requirements, up to the Top Secret/Sensitive Compartmented Information (TS/SCI) level. This includes implementing access control mechanisms, data encryption, and other security measures to protect classified information.
1.1.7. Cloud
IaaS, PaaS, and Cloud Management: The Contractor shall manage cloud resources and services, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). This includes provisioning and configuring cloud resources, managing cloud security, monitoring cloud performance, and optimizing cloud costs.
Cloud Migration: The Contractor shall plan and execute cloud migration projects, migrating applications and data from on-premises systems to cloud platforms. This includes assessing migration feasibility, developing migration plans, and executing migrations with minimal disruption to business operations.
Cloud Hosting and Infrastructure: The Contractor shall design and implement cloud hosting solutions, leveraging cloud platforms to host applications and data. This includes selecting appropriate cloud services, configuring cloud infrastructure, and ensuring the security and availability of cloud-hosted resources.
1.1.8. IT Service Management
Service/Helpdesk: The Contractor shall provide end-user support through a consolidated service desk, utilizing ITIL (Information Technology Infrastructure Library) principles and best practices. This includes incident management, problem management, change management, and request fulfillment. This includes the use of triggers, dashboards, and data pushes to monitor performance of ticket reports and queues.
Accounts Management: The Contractor shall manage user accounts and access permissions, ensuring that users have appropriate access to organizational resources. This includes creating and managing user accounts, assigning roles and permissions, and enforcing password policies.
Workflow Automation and Process Improvement: The Contractor shall identify opportunities for workflow automation and process improvement, leveraging automation tools and techniques to streamline IT processes and improve efficiency. This includes designing and implementing automated workflows, integrating systems, and optimizing processes for optimal performance.
Knowledge Management and Continuity: The Contractor shall implement and maintain a knowledge management system to capture, organize, and share IT knowledge and best practices, ensuring continuity of operations and facilitating knowledge transfer within the organization. This includes developing knowledge articles, FAQs, and other documentation to support IT staff and end-users.
Customer Experience and Feedback Management: The Contractor shall implement a system for proactively managing customer experience and feedback. This includes collecting and analyzing user feedback through user satisfaction surveys and reporting on customer satisfaction metrics to continuously improve service delivery. This feedback will be used to identify areas for improvement and implement changes to enhance the user experience.
1.1.9. Governance and Compliance
Records Management: The Contractor shall develop and implement records management policies and procedures, ensuring compliance with legal and regulatory requirements. This includes classifying, storing, retrieving, and disposing of records according to established guidelines.
Compliance Support: The Contractor shall ensure compliance with relevant regulations and standards, such as NIST, HIPAA, and PCI DSS. This includes conducting compliance assessments, implementing security controls, maintaining documentation to demonstrate compliance, and analyzing and complying with applicable privacy governance, including conducting privacy impact analyses.
Configuration Management: The Contractor shall maintain accurate records of system configurations, tracking changes and ensuring consistency across systems. This includes using configuration management tools and processes to manage software versions, configurations, and deployments.
DLA Disposition Services (DLADS): The Contractor shall manage the disposal of IT equipment through the Defense Logistics Agency Disposition Services (DLADS), ensuring compliance with environmental regulations and security protocols. This includes preparing equipment for disposal, coordinating with DLADS, and maintaining appropriate documentation.
Financial Improvement and Audit Readiness (FIAR) Compliance: The Contractor shall maintain system logs, data, and documentation required for financial feeder systems that are subject to annual Financial Improvement and Audit Readiness (FIAR) reviews. This includes ensuring data accuracy, completeness, and traceability and providing support to auditors during FIAR reviews.
DoD and DAF IT Portfolio Management Compliance: The Contractor shall prepare and maintain documentation to demonstrate compliance with Department of Defense (DoD) and Department of the Air Force (DAF) IT portfolio management requirements. This includes documenting IT investments, systems, and services and providing reports and metrics to demonstrate compliance.
Clinger Cohen Compliance: The Contractor shall prepare and maintain documentation to demonstrate compliance with the Clinger-Cohen Act, which requires federal agencies to implement effective IT management practices. This includes documenting IT investments, systems, and processes and demonstrating compliance with IT management standards and guidelines.
FISMA Compliance: The Contractor shall prepare and maintain documentation to demonstrate compliance with the Federal Information Security Management Act (FISMA), which requires federal agencies to implement information security programs to protect federal information and information systems. This includes developing and implementing security plans, conducting security assessments, and maintaining documentation to demonstrate compliance.
1.1.10. Systems Engineering and Modernization
Systems Engineering: The Contractor shall apply systems engineering principles and methodologies to design, develop, and implement complex IT systems. This includes requirements analysis, system architecture design, system integration, and system testing.
Enterprise Modernization: The Contractor shall modernize legacy IT systems, migrating to newer technologies and platforms to improve performance, security, and efficiency. This includes assessing legacy systems, developing modernization plans, and implementing modernization projects.
Cross Domain Solutions: The Contractor shall develop and implement solutions for secure data sharing across different security domains. This includes implementing cross-domain guards and other security mechanisms to ensure that data is shared securely and in compliance with security policies.
Technical Documentation Development: The Contractor shall develop and maintain comprehensive technical documentation for all IT systems and applications, including system architecture diagrams, user manuals, troubleshooting guides, and other relevant documentation.
1.1.11. Portfolio Management
Strategic Portfolio Management and Road Mapping: The Contractor shall develop and maintain a strategic IT portfolio management plan and roadmap, aligning IT investments with organizational goals and priorities. This includes identifying and prioritizing IT projects, developing investment strategies, and creating a roadmap for future IT development.
Budget Tracking and Cost Optimization: The Contractor shall track IT budgets, monitor IT spending, and identify opportunities for cost optimization. This includes developing budget forecasts, analyzing IT costs, and recommending cost-saving measures.
KPI/Performance Metrics Development and Tracking: The Contractor shall develop and track key performance indicators (KPIs) and performance metrics to measure the effectiveness and efficiency of IT services. This includes defining KPIs, collecting performance data, and generating reports to track progress and identify areas for improvement.
Asset Discovery, Inventory Management, and Tracking: The Contractor shall utilize automated tools and processes to discover, inventory, manage, and track all IT assets, including hardware and software. This ensures accurate and up-to-date information on IT resources, facilitating efficient management and lifecycle tracking.
1.1.12. Testing
Comprehensive Testing: The Contractor shall provide comprehensive testing support throughout the system lifecycle, including developing test plans, executing test cases, and documenting test results. The Contractor shall utilize automated testing tools and techniques and implement a Continuous Integration/Continuous Deployment (CI/CD) pipeline to automate the build, test, and deployment process.
1.1.13. Training
Training: The Contractor shall provide training to the user community on the use of IT systems and applications. This includes developing training materials, conducting training sessions (CBT, in-person, virtual, or classroom), and providing ongoing support to end-users.
User Experience Analysis: The Contractor shall conduct user experience (UX) analysis to understand user needs and preferences, informing the design and development of user-friendly and effective IT systems and applications. This includes conducting user research, usability testing, and analyzing user feedback to improve the user experience.
1.1.14. Program and Financial Management
The Contractor shall perform program management activities necessary to maintain control of resources, provide proactive communication across the program, and project level teams. Program management activities include managing the systems engineering technical baseline through requirements management, configuration and change management, risk management, and certification and accreditation management. The contractor is responsible for monitoring and reporting program activities and progress in terms of cost, schedule, and performance. The contractor shall ensure appropriate metrics are used and documented as part of the cost, schedule, and performance reporting and exercise continuous risk mitigation and issue resolution activities.
The Contractor shall integrate government and contractor processes to support periodic AFRL reporting, milestone decisions, risk management, configuration and change management and budgeting activities. Risk Management Plan (CDRL A011), Configuration Management Plan (CDRL A012) The Contractor shall manage and support system design planning (including design assumptions and specifications), development, test, deployment and operations. The Contractor shall manage the work at a detailed level commensurate with the scope and criticality of the project.
4.2. Deliverables
The Contractor shall provide deliverable(s) in a format mutually agreed upon by the Government and the Contractor. Additional deliverables may be added at the sub-task level. If a deliverable due date falls on a weekend or holiday, the Contractor shall submit the deliverable on the last workday prior to the due date.
Program Support. The Contractor shall designate a qualified Task Lead who will serve as the single point of contact and be responsible for the overall management and execution of the work performed under this contract. The Task Lead shall possess demonstrated experience in (relevant areas of expertise, e.g., IT program management, systems engineering, cybersecurity). Monthly Status Report (CDRL A001) Contractor’s Personnel Roster (CDRL A002) Technical Reports. The Contractor shall prepare technical reports as directed by the Government per sub-task. Materials may include reports for analysis, study, performance, monitoring, products and services related to IT Services programs, projects and deliverables. Technical Report (CDRL A003) Miscellaneous Reports. The Contractor shall prepare miscellaneous reports or presentation materials for weekly and ad-hoc meetings with the Government. Materials may include meeting agendas and minutes, presentation charts, system environment status, cybersecurity findings/mitigations, incident reports, etc. Miscellaneous Report (CDRL A004) Software Development Reports. The Contractor shall prepare reports related to the development, testing, and release of software products.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .