DRAFT DEBOSS PERFORMANCE WORK STATEMENT DRAFT.pdf
PDF 351 KB Posted
- Attached to
- Defense Commissary Agency (DeCA) Enterprise Business Operations Systems Solution (DEBOSS) Federal contract opportunity
- Solicitation number
- 842366358
- Issued by
- Defense Information Systems Agency
About this file
This document is a performance work statement for the Defense Commissary Agency's Enterprise Business Operations Systems Solution contract. The contract requires sustainment support for systems and capabilities purchased under prior contracts, including program management, technical support, maintenance support, help desk support, and customer support. The support covers NCR brand name hardware, software, services, and third-party applications deployed agency-wide. The contractor must maintain environments including development, test, pre-production, production, and disaster recovery sites. The support also includes upgrades, patches, security compliance, and cloud migration assistance. The performance period is a one-year base period starting in January 2024 with four one-year option periods. The contractor must meet response and resolution times for priority levels 1 through 4 and report daily, monthly, and quarterly on support activities. The statement also outlines cybersecurity, testing, maintenance, and help desk requirements the contractor must fulfill.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 1 DEBOSS Hardware and Software.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
Award/Mod Effective Version Date
Award
Contract Number:
Task Order Number:
Contractor Name
1. Contracting Officer’s Representative (COR)
a. Primary COR. See Points of Contact in Contract Administration Data
b. Alternate COR. See Points of Contact in Contract Administration Data
c. Property Administrator:
Name:
Organization: Defense Commissary Agency - Property Accountability Division Logistics Directorate
DoDAAC: HQCAAA
Address: 1300 E. Avenue, Fort Gregg-Adams, VA 23801-1800
Phone Number:
Fax Number:
E-Mail Address:
2. Contract or Task Order Title. Defense Commissary Agency (DeCA) DeCA Enterprise Business Operations Systems Solution (DEBOSS).
3. Background
DeCA operates on average 240 military commissaries worldwide (approximately 3,000 lanes including self-checkouts). Of that total, nearly 180 stores are continental United States (CONUS) locations, including Alaska and Hawaii; with approximately 60 stores in 12 outside continental United States (OCONUS) locations. The total number of commissaries operated globally is subject to change based on the needs of military agencies. Commissaries support approximately 12 million United States military customers (active-duty military, reserve, National Guard), military retirees, and family members. Commissaries are designed and operate similarly to commercial grocery stores. This requirement will ensure continuity of mission critical DeCA operations to include necessary break/fix solutions, patches, updates, and fixes to mitigate security vulnerabilities.
DeCA utilizes commercial products and services whenever possible to support their efforts to attain parity with commercial grocers. In 2015, DeCA awarded the Enterprise Business Solution (EBS) contract to NCR Government Systems, LLC (NCR). Under this contract, DeCA deployed several mission support software solutions (e.g., catalog, ordering and receiving, pricing and promotion, and point of sale). Later in 2015, DeCA awarded the Commissary Automated Resale Transaction System Replacement/Modernization (CARTS R/M) to International Business Machine Corporation. Under the CARTS R/M contract, DeCA deployed point of sale hardware and other supporting equipment under the CARTS R/M. The software and hardware solutions associated with these two contracts is currently installed and operating throughout the Agency’s environment, including store locations, warehouses, data centers, test labs, and other DeCA facilities.
4. Objective
The objectives of this requirement are to obtain sustainment support (program management, technical support, maintenance support, help desk, and customer support) for all systems and capabilities purchase under the CARTS R/M and EBS contracts under the DEBOSS contract. The objective is to have a contractor provide flexibility and services capable to meet current and future DeCA workload, availability, scalability, and modernization requirements, while ensure DeCA mission receives uninterrupted, continuous access to the solution and data. Moreover, all hardware, software and software as a service needs to be maintained, supported, and sustained.
5. Scope
The scope of this effort is to maintain the DeCA systems. Specifically, the DEBOSS effort will support NCR brand name hardware, software, services, and third-party applications fielded as further detailed in Attachment 1 DEBOSS Hardware and Software. These systems include interfaces, hardware and software on various infrastructures and platforms, including VMWare, Microsoft, Linux, Oracle, and SQL. This requirement will procure annual hardware renewal warranty support (hereinafter referred to as “support”) and maintenance for previously purchased proprietary, commercial off-the-shelf, brand-name hardware already integrated within the existing mission partner infrastructure. Furthermore, this contracting effort supports the renewal of annual software support for previously acquired software licenses and subscriptions that are installed on DeCA’s networks located in all sites identified in Appendix 1 and DeCA’s test environments. The DEBOSS environment will include development, test, pre-production, production environments (e.g., store, warehouses, data centers, and other DeCA facilities), DeCA’s mission support activities. The mission support services will provide operational, procedural, and contract management support to assist DeCA throughout the DEBOSS lifecycle. This support will include planning and execution, test and evaluation, and transition of emerging technologies. The support will include program management, project management, and contract management to ensure timely and effective performance.
This contract is intended to ensure that DeCA’s current mission critical business solutions continue to support the Agency’s global operations.
The Government may require surge support during the base or any option period, and surge modifications will be within the scope of the contract and provide increased support for the defined task areas of this PWS. Surge support over the life of the contract will not exceed 10% of the contractor’s total proposed cost/price for the base and all option periods
6. Performance Requirements
6.1 Program Management. The Contractor shall manage and oversee all activities performed by its personnel (including subcontractors and teaming partners, as applicable) and escalate problems or concerns to the Contracting Officer and COR.
6.1.1 The Contractor shall provide operational, procedural, and contract management support to assist DeCA throughout the sustainment of DEBOSS environment.
6.1.2 The Contractor shall provide a Program Management Plan within 30 days after contract award.
The plan will document the contractor’s management approach, operating procedures, staffing approach, and overall Work Breakdown Structure. Staffing Plans regarding resource assignments by task may be required at the task order level.
6.1.3 The Contractor shall develop and deliver release notes on all approved change requests, 30 days prior to release of change to DeCA’s test environment.
6.1.4 The Contractor shall support DeCA’s change management and governance processes by conducting a DEBOSS Configuration Control Boards (CCB), must provide briefings and artifacts using a template approved by the Government. The document shall be provided 2 days prior to CCB monthly.
6.1.5 The Contractor shall support DeCA’s change management and governance processes by producing briefings and artifacts and acting as a subject matter expert (SME) at technical review boards and Change Advisory Board.
6.1.6 The Contractor shall submit a written monthly status report no later than the 5th day of each month to the DEBOSS COR and the Contracting Officer. The monthly status report shall include, at a minimum.
6.1.6.1 Integrated Master Schedule to include all DEBOSS system changes (software, OS, database, and hardware upgrades/technology refresh), and integration and interface development.
6.1.6.2 Work completed, work in progress status, point of contact for open activity, risks, and mitigation strategies (with traceability to incident tickets, as relevant).
6.1.6.3 Help Desk (Tier 2, 3, and 4) status
Number of open tickets (with aging); and incidence closures;
Total tickets and average resolution time;
Number of priority 1 tickets and resolution time; and
Knowledgebase of reoccurring issues (user and system).
6.1.6.4 System (hardware, software, database, and communications) availability statistics`
6.1.6.5 The contractor shall provide Risk Management Framework (RMF) all activities status for the following: Authority To Operate (ATO)s, continuous monitoring, Security Technical
Implementation Guides (STIG) compliance, quarterly STIG review status, Plan Of Action and Milestones (POA&M) status and shall provide external information technology (IT)audit compliance support.
6.1.6.6 Cloud migration support status to include schedule, resources, and critical milestone.
6.1.6.7 The contractor shall provide Payment Card Industry (PCI) compliance status, audit finding tracking and remediation status and Department of Defense Instruction (DoDI) 8140.02 certification and individual training status.
6.1.7 The Contractor shall perform Quarterly Program Management Reviews (QPMRs). The Contractor shall submit a Microsoft PowerPoint presentation that consolidates the Contractor’s activities and program status over the previous quarter. Read ahead materials shall be provided to the DEBOSS COR and Contracting Officer 5 days prior to the scheduled PMR.
6.1.8 The Contractor shall ensure all DEBOSS related Enterprise Architecture viewpoint models are updated at various layers of abstraction based upon changes to DEBOSS.
6.1.9 The Contractor shall participate in DEBOSS related architecture review and governance boards.
6.1.10 The Contractor shall assist in any potential updates to business process mappings for the DEBOSS environment and produce architecture models in Business Process Modeling Notation.
6.1.11 Shall provide a configuration management plan identifying, documenting, and informing how DEBOSS changes are managed throughout the acquisition lifecycle.
6.1.12 The Contractor shall review and update the DEBOSS information system contingency plans and provide DEBOSS support for Disaster Recovery activities on an annual basis.
Table 1: Program Management Deliverables
PWS
Task#
Deliverable Title
Format Due Date Distribution/
Copies Frequency and
Remarks
6.1.2 Program
Management Plan
Word Document
30 days after award Standard Distribution*
Once
6.1.3 Release
Notes
Word Document
30 days prior to event
Standard Distribution
30 days prior to release
6.1.4 Configuration
Control Board
Briefings and artifacts
2 days prior to Meeting
Configuration Control Board attendees
Monthly
6.1.6 Program
Management Monthly Status Report
Contractor- Determined Format
5th Day of the Month
Standard Distribution
Monthly
6.1.7 Quarterly
Program Management Reviews
Microsoft PowerPoint
5 days prior to scheduled QPMR
Standard Distribution
Quarterly
The Contractor shall produce all deliverables for the DeCA Program Manager (PM) and COR in Microsoft (MS) Office 365 format, to include MS Word for written documents, MS PowerPoint for presentations, MS Project for schedules, and MS Excel for spreadsheets
* Standard Distribution - Upon contract award, documents will be distributed in accordance with (IAW) the following: One electronic transmittal letter will be delivered to DITCO Contracting Officer and One electronic copy will be delivered to DeCA COR.
6.2 Technical Team. The contractor shall provide a dedicated technical team; comprised of DEBOSS SME to ensure DEBOSS systems can continue to operate within defined thresholds to support DeCA’s global operations. The team will perform analysis, development, interface management, testing, integration; cloud migration; security, changes required by government mandates, cybersecurity needs, upgrades to licenses, data requests; interfaces, and integration with new solutions, data migration, and support escalated break/fix resolution.
6.2.1 The Contractor shall provide SME for all DEBOSS technical issues, responding to escalated help desk tickets, root cause analysis, DeCA’s change management process and Governance boards, performance concerns, leaderships, and other data calls, forecasting major events within the DEBOSS and DeCA environment, and supporting the migration to new solutions and the cloud.
6.2.2 The Contractor shall maintain current interfaces and create and implement interfaces between the DEBOSS, new DeCA systems, internal and external systems, modify existing interfaces, perform configuration changes, and perform custom code and script changes per new and modified Government directed requirements.
6.2.3 The Contractor shall, for each existing DEBOSS interface, maintain the respective Interface Specification Document (ISD) to include: Systems Resource Flow Matrix (SV-6), Interface
Dataflow Diagram, data field definitions, interface frequency (job scheduling), and communication protocol. For new interfaces, the Contractor shall provide DeCA an ISD that includes all interface specifications, code, external scripts, wrappers, and data dictionaries.
6.2.4 The Contractor shall provide documentation outlining custom code and script changes.
6.2.5 The Contractor shall comply and track all changes to the databases and infrastructure IAW DeCA’s Change Management processes.
6.2.6 The Contractor shall be actively involved in transitioning existing DEBOSS capabilities to new applications. The Contractor shall be responsible for developing and maintaining interfaces;
mapping, cleansing, and migrating data; and sunsetting the DEBOSS application.
6.2.7 The Contractor shall provide two SME instructors that shall lead 2 interactive sessions per year on site or online for the DEBOSS environment. The contractor shall provide pricing for 2 onsite and 2 online classes. There will be 10 Government approved seats per class. The Contractor shall provide the training material in electronic format and recording of the training session upon completion.
Table 2 Technical Team Deliverables
PWS
Task
Deliverable Title
Format Due Date Distribution/
Copies Frequency and
Remarks
6.2.3 Interface
Specification Document
Contractor Determined Format
As any DEBOSS interface changes including additions and deletions occur
Standard Distribution
Based on changes to DEBOSS interfaces
6.2.3 System
Resource Flow Matrix
Contractor Determined Format
As any DEBOSS interface changes including additions and deletions occur
Standard Distribution
Based on changes to DEBOSS interfaces
6.2.3 Interface
Dataflow Diagram
Contractor Determined Format
As any DEBOSS interface changes including additions and deletions occur
Standard Distribution
Based on changes to DEBOSS interfaces
6.2.4 Custom
Code and Script Changes Documentati on
Contractor Determined Format
Upon changes of DEBOSS custom codes and scripts
Standard Distribution
Upon changes of DEBOSS custom codes and scripts
6.2.7 Training Interactive sessions;
training material in electronic format
To be determined by Contract Technical Lead
Standard Distribution
2 times per year
6.3 Cybersecurity Support
6.3.1 The Contractor shall act as the Information System Security Officer. In this role, the Contractor shall:
6.3.1.1 Act as the information security focal point and primary Cybersecurity technical advisor to the Information System Security Manager (ISSM) or Senior Information Security Officer (SISO)/ Authorizing Official for the IT assets.
6.3.1.2 Assist the ISSMs in meeting their duties and responsibilities defined in DoDI 8500.01 and DoDI 8510.01.
6.3.1.3 Ensure DeCA RMF program requirements for these IT assets are properly implemented.
6.3.1.4 Ensure cybersecurity requirements are identified early in the life cycle for system projects.
6.3.1.5 Ensure all Department of Defense (DoD) information system cybersecurity-related documentation is current, remains current for the duration of this contract, and is available in Enterprise Mission Assurance Support Server and accessible to properly authorized individuals.
6.3.1.6 Report all cybersecurity issues in writing directly to the ISSM or SISO/Chief Information Security Officer (CISO).
6.3.1.7 In coordination with the ISSM, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered.
6.3.1.8 Develop and manage required network accreditation artifact documents such as a System Security Plan, system descriptions, system overviews and program repository submissions (e.g., IT POA&M).
6.3.1.9 Provide detailed documentation and artifacts to support the Security Manager (SM)/PM through the creation of POA&Ms for all system vulnerabilities and deficiencies, facilitating remediation activities, and tracking the status of remediation efforts.
6.3.1.10 Ensure cybersecurity inspections, tests and reviews are coordinated and supported by providing artifacts within the deadlines established by the inspection/test/review, providing SME to participate in interviews, addressing and remediating shortfalls as identified and within established timelines.
6.3.1.11 Ensure privileged users of the system complete the necessary technical and cybersecurity training, education, and certification to carry out their cybersecurity duties by DoD Manual (DoDM) 8140.03 and DoDI 8140.02.
6.3.1.12 Verify that security event logs are reviewed by the DEBOSS component’s administrator at the frequency defined by DeCA Manual (DeCAM) 35-31.01.
6.3.1.13 Ensure proper implementation of applicable RMF security controls.
6.3.1.14 Ensure compliance with the DoD vulnerability management program by monitoring affected assets within the Assured Compliance Assessment Solution (ACAS), facilitating remediation efforts on, or before required suspense date(s), and monitoring the remediation status.
6.3.1.15 Provide clear, accurate and timely documentation/information in relation to all vulnerability assessments and security compliance reviews.
6.3.1.16 Provide reports detailing whether assets are affected, total number of assets affected, and patch status to the DeCA Cybersecurity Branch before the deadlines established by the US Cyber Command (USCYBERCOM), per DoDI 8531.01 and DeCAM 35-31.01.
6.3.1.17 Support testing and validation for all patch updates (including DoD mandated security patches) for operating systems, databases, third-party, and embedded software for all certified releases of the DEBOSS component products within 21 days of notification or by the DoD mandated response date published in the notification by USCYBERCOM, whichever comes first.
6.3.1.18 Assist weekly review, document, and resolve all findings identified in vulnerability assessments and security compliance reviews, IAW DoDI 8531.01, DeCAM 35-31.01 and published USCYBERCOM directives.
6.3.1.19 Configure audit logs to meet the current audit requirements (Figure 1 of DeCAM 35-31.01).
6.3.1.20 Maintain audit logs and record findings per DeCAM 31-31.01.
6.3.1.21 Report anomalies identified during audit log reviews or alert notifications to DeCA's incident response team, as appropriate, and address identified anomalies and alert notifications per the guidance and reporting timelines defined by DeCAM 35-31.01 and DeCA Incident Response procedures.
6.3.1.22 Enforce security policies and safeguards on all personnel having access to the information system for which the Contractor is responsible. Recommend the suspension of network access for users not complying with security policies of the system to the SISO/CISO. Immediately notify the user's supervisor of any concern or security violation regarding their system access.
6.3.1.23 Ensure that all system support staff and users have a DeCA standard System Access Request documented in DeCA’s Remedy system that is complete with the following information prior to granting system access: business justification from their supervisor, a background investigation and/or clearance verified by the Security Division for the level of system access requested, and aware of their cybersecurity responsibilities.
6.3.1.24 Develop procedures for and conduct periodic security reviews to enforce password strengths. These reviews shall, at minimum, search for default and weak passwords.
6.3.1.25 The contractor shall assist DeCA in conduct a review of Cybersecurity personnel regarding DEBOSS responsibilities and accounts twice per year IAW DeCAM 35-31.0.
6.3.1.26 Harden systems and software IAW DISA STIGs.
6.3.1.27 Conduct periodic benchmark scans to test products for STIG compliance and apply new STIGs IAW timelines and guidance in DeCAM 35-31.01.
6.3.1.28 Identify, analyze, and remediate any STIG severity Category I, II or III finding that occurs in systems or software IAW DeCAM 35-31.01.
6.3.1.29 Review and update security baseline(s) quarterly IAW DeCAM 35-31.01 and providing status report to DeCA. Document and update deviations from STIGs or other hardening guides as new vulnerability issues are identified.
6.3.2 The Contractor shall deliver cybersecurity requirements that impact DeCA compliance with DoD’s cybersecurity program by submitting evidence for security control and continuous monitoring compliance that impact ATO, vulnerability remediation activities, to include POA&Ms and security patching.
6.3.3 The Contractor shall employ a fully DoD certified Cybersecurity workforce at the start of this contract and maintain 100% compliance throughout the life of the contract. Contractor personnel who do not have the proper and current qualifications shall be denied access to DoD Information Systems for the purpose of performing Cybersecurity functions and tasks.
6.3.4 The Contractor shall provide documentation supporting the cybersecurity workforce certification status of personnel performing cybersecurity workforce functions upon request by the Government.
6.3.5 The Contractor shall comply with DoD 8140 series cybersecurity workforce certification requirements.
6.3.6 The Contractor shall demonstrate expertise, qualification standards, and provide the required Department of Defense certifications per DoDI 8140.01 and DoDM 8140.03.
6.3.7 The Contractor shall provide appropriate certifications based on the cybersecurity roles, positions, and duties that the Contractor performs.
6.3.8 The Contractor shall support development of program management reporting to ensure that status updates include cybersecurity requirements, status of Risk Management Framework activity. activities in support of achieving and maintaining an ATO, continues monitoring annual reviews, security control updates, POA&M remediation activities, ACAS remediation activity, in support of DoD RMF Information Assurance Vulnerability Management remediation activity, to ensure the Contractor stays on track in meeting these requirements.
6.3.9 The Contractor shall ensure DEBOSS complies with Joint Forces Headquarters – Department of Defense Information Network Operations requirements by mandated response dates. The DeCA Cybersecurity Branch or Security Operation Center will forward all Joint Force Headquarters – DoD Information Network (JFHQ-DoDIN) Cyber Tasking Orders that are published. Mandated response dates may vary from one day to several weeks.
6.3.10 The Contractor shall assist DeCA in the generation of all documentation to maintain system authorization under the DoD RMF process.
6.3.11 The Contractor shall assist the DeCA PM in resolving any issues during the security testing and evaluation phase to ensure successful completion of the DoD RMF.
6.3.12 The Contractor shall maintain an expertise in DoD and DeCA system security requirements.
6.3.13 The Contractor shall provide and update software release documentation for all patches, upgrades, and versions delivered to the Government.
6.3.14 The Contractor shall provide cybersecurity support relevant to each of the DEBOSS environments: DeCA’s test environment; Contractor’s test/development environment; DeCA’s Production; DeCA’s Disaster Recovery Site; and all Cloud environments, as necessary.
6.3.15 The Contractor shall, IAW President's Executive Order 14028 on “Improving the Nation's Cybersecurity,” mitigate supply chain risk in the provision of supplies and services to the Government.
6.3.16 The Contractor shall develop and maintain a Cybersecurity Plan to be delivered within 90 days of the contract award to assist DeCA’s cybersecurity efforts to ensure that all cybersecurity and DoD requirements (STIGs, National Institute of Standard Technology (NIST)/Records Management (RM) controls, checklist items and JFHQ-DODIN, USCYBERCOM mandated items, etc.) are implemented for each DEBOSS component.
6.3.17 DeCA’s Endpoint Security Solutions (ESS) solution
6.3.17.1 The Contractor shall ensure the system will comply with DoD requirements for the installation and configuration of DoD’s ESS point products including the ESS Agent, Endpoint Security (e.g., Anti-virus, Intrusion Prevention System (IPS)), and where applicable, Asset Baseline Monitor, Asset Configuration Compliance Module, Policy Auditor, Data Loss
Prevention /Device Control Module, and Rogue System Detection). DeCA will provide the ESS software.
6.3.18 Protected Network Environment
6.3.18.1 The Contractor shall ensure the system, including the Vendor Portal and eCommerce systems, will operate effectively within DeCA’s protected networking environment without direct access to the commercial Internet or NIPRNET unless such access is specifically authorized in the ATO. These systems are accessible from the internet and should be configured into the DeCA Demilitarized Zone.
6.3.19 Authentication (HSPD 12)
6.3.19.1 The Contractor shall ensure that DeCA maintains an authentication approach consistent with HSPD 12 (use of the DoD Common Accesses Card (CAC) for authentication) as well as an alternate approach based upon user ID and password. When DEBOSS uses DeCA’s Active Directory, or credentials contained therein, to authenticate users, the system will interoperate with DeCA’s smart card logon solution and use of DoD certificates on the CAC.
6.3.20 DeCA Remote / Onsite Access
6.3.20.1 The Contractor shall enter into a security memorandum of agreement (MOA) within in 30 days of award of contract with DeCA in support of remote Virtual Private Network (VPN) access to the DeCA network. The MOA will define DeCA’s operational and security requirements for a VPN connection from the Contractor’s primary support location to a gateway server on DeCA’s firewall. Support sessions may be initiated from the gateway server to selected internal sites.
6.3.20.2 The Contractor and all subcontractors shall ensure that a mutually established VPN tunnel between the primary support location and DeCA.
6.3.20.3 The Contractor shall provide hardware that provides users with access to DeCA’s Active Directory environment, contracts will provide DoD-approved smart card readers and middleware with the capability to interoperate with DeCA’s smart card logon solution.
6.3.21 DoD PKI Certificates
6.3.21.1 The Contractor shall ensure all personnel with direct access to a DoD Automated Information System will obtain a Class 4 Public Key Infrastructure (PKI) certificate.
6.3.21.2 The Contractor shall ensure personnel working on-site at DoD facilities or working at non- DoD facilities using GFE will obtain their PKI Class 4 certificate from the DoD Class 4 PKI. The DeCA VPN requires PKI for authentication support staff will obtain DoD approved PKI certificates to access any DoD/DeCA application through the VPN.
6.3.21.3 The Contractor shall ensure personnel who are not eligible for DoD PKI credentials but with a need to access DoD systems or exchange signed/encrypted e-mail with DoD counterparts will acquire PKI credentials from an External Certification Authority vendor.
6.3.21.4 The Contractor shall ensure personnel with access to Government computer systems shall meet DoD 5200.2-R requirements and shall receive a favorable investigation commensurate with their level of access to Government information. This includes designating each Contractor personnel to an IT position category (i.e., IT-I, IT-II, or IT-III) based on their level of access and IAW DeCA criteria. Access to classified information is not required.
6.3.22 Payment Card Industry Data Security Standard (PCI DSS)
6.3.22.1 The Contractor will implement and maintain compliance with PCI DSS requirements, to include maintaining a point-to-point encryption (P2PE) solution approved by and in good standing with the PCI Security Standards Council.
6.3.22.2 The Contractor shall ensure the P2PE solution implemented at DeCA must include Point of Interaction devices that are also part of the P2PE solution approved by the PCI Security Standards Council.
6.3.22.3 The Contractor shall ensure vulnerabilities discovered in support of DeCA’s PCI compliance and impacting DeCA’s ability to maintain compliance (e.g., Authorized Scanning Vendor scans against Internet -facing systems) must be addressed/remediated in an expedited timeframe no later than 10 days of discovery.
Table 3 Cybersecurity Team Deliverables
PWS
Task#
Deliverable Title
Format Due Date Distribution/ Copies
Frequency and Remarks
6.3.3 DoD certified
Cybersecurity workforce
IAW with DeCA Cybersecurity
DoD 8140
Upon Award Program Management Monthly Status Report
Monthly
6.3.16 Cybersecurity
Plan
Contractor Determined Format
90 Days from award of contract
Standard Distribution
Once
6.3.1.
Cybersecurity personnel support
IAW DeCAM 35- 31.0
Twice a year Standard
Twice a year
6.4 Testing and Integration Support. The Contractor shall perform end-to-end testing in support of any change including cybersecurity related updates, system modifications, and cloud migration.
6.4.1 The Contractor shall develop maintain the following test environments:
• Developmental Test and Evaluation Environment (DTE1)
• Developmental Test and Evaluation Environment (DTE2)
• Pre-Production Developmental Testing Environment, and
• Training Environment.
6.4.2 The Contractor shall maintain the-current application baseline to match the DeCA production environment, throughout the life of the contract.
6.4.3 The Contractor shall support and maintain standing Change Request.
6.4.4 The Contractor shall provide hardware and software Test Plan(s) that documents all test cases, strategies, and timelines, roles, and responsibilities, and “Release and Roll-Back Plan” 30 days prior to any testing by DeCA, refer to Table 4 Test and Integration Deliverables for details.
6.4.5 The Contractor shall ensure that DeCA’s test environment reflects the production environment to validate fixes and changes, to include regular patches prior to installing solutions in the production environment. This test environment may or may not be on-premises at DeCA Head Quarters.
6.4.6 The Contractor shall test operating systems, Information Assurance Vulnerability Alerts (IAVAs), and database upgrades in their test environment and identify and mitigate issues prior to delivery to DeCA.
6.4.7 The Contractor shall perform DEBOSS testing and evaluation of all upgrades and patches prior to delivery to the Government to support the Government's internal testing and production release processes and procedures.
6.4.8 Prior to release, the Contractor must provide tools to validate test results which clearly identify the following:
Regression Test Data Generation Performance/Load/Balancing Automated testing to include robotics application Alert Notification Current hardware, software, security / IAVA updates, software, and system configurations for all hardware and end-point systems.
6.4.9 The Contractor shall provide hardware and software Test Plan(s) that documents all test cases, strategies, timelines, roles, and responsibilities, and "Release and Roll Back Plan" prior to any testing by DeCA, refer to Table 4 Test and Integration Deliverables for details.
6.4.10 The contractor shall provide and maintain a Requirements Traceability Matrix (RTM) identifying the Requirement, Requirement Type, Target Release, Actual Release, Status, Component(s), Verification Method(s), and Test Case(s), refer to Table 4 Test and Integration Deliverables for details.
6.4.11 The Contractor shall provide automated testing to include the capability to generate ad hoc and canned Test Reports from the test system/application which will include Test Results prior to delivery to the Government.
6.4.12 The DeCA test environment must be refreshed equivalent to 3 times per year to test new releases and stay in line with the production environment.
6.4.13 Provide, maintain, and replenish digital coupons and promotions.
6.4.14 Provide test cases for patches, changes, modification to existing DEBOSS.
6.4.15 Will interface within the DeCA enclave and they will provide test support for end-to-end testing.
6.4.16 Will interface with current and new applications, feeds, 3rd party solutions, and other future DeCA solutions.
Table 4 – Test and Integration Deliverables
WS
Task#
Deliverable Title
Format Due Date Distribution/Copies Frequency and Remarks
6.4 Test &
Evaluation Master Plan with Key Performance Parameter and Critical Performance Indicators
Contractor Determined Format
30 days prior to testing in DeCA Test Lab (DTL)
Standard Distribution
Prior to each testing in DTL
6.4.9 Acceptance
Test Plan
Contractor Determined Format
2 days prior to initial testing in
DT&E1
Standard Distribution
Prior to initial testing in
DT&E1
6.4.9 Requirements
Definition Plan
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.4.9 Interface
Development Plan
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.4.9 System
Migration Plan
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.4.9 Quality
Assurance Plan
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.4.9 Quality
Assurance Surveillance Plan
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.4.9 Software
Requirements Specification Document
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.4.9
6.4.10
Requirements Traceability Matrix
Contractor Determined Format
14 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
6.5 Maintenance. The Contractor shall provide sustainment and maintenance to include scheduled preventative, troubleshooting and break/fix/repair support for DEBOSS applications, data, interfaces, hardware, and environments: New Development Test Environment, Production-Like Test Environment, Production-Like/ Training Environment, Pre-Production, and Production to ensure the following performance standards are met.
Table 5 - Maintenance Standards Severity Level
Definition Performance Standard
Priority 1 Mission Critical
Disruption to business operations, inability to sell/order groceries, inability to access the system, complete loss of service with no work-around available, issue with critical functional process/task (e.g.: Not in Service, release order, receiving, run wave)
System down, application failure, hardware failure, server center and store, database failure, network outage, 10% Self-Checkout (SCO) or 25% Point of Sale (POS).
Respond – Immediately Resolve – 2 hours
Priority 2 High
Business disruption, issue selling groceries Disruption to back office or front-end operations, prices incorrect at POS, invoices not released on time, transmit orders to Central Distribution Center (CDC), CDC processing orders and picking (Radio Frequency (RF) is out), network or system latency.
20% SCO or 50% POS.
Respond – 30 minutes Resolve – 8 hours
Priority 3 Medium
Minimal business disruption Standard issues and tasks having minimal business impact: Reporting capability is non-functional, User/Passwords, partial task impact.
Respond –2 hours Resolve – 12 hours
Priority 4 Low
No business disruption POS, SCO/ Remote Attendant Program (RAP), Price Checker, HHTs, mobile Point of Sale (mPOS), and Printers.
Respond – 4 hours Resolve – 2 days
** Replacement or Repair
All accessories (e.g., POS, SCO/ RAP, Price Checker, HHTs, mPOS, and Printers).
Respond – 4 hours Replace – 96 hours
Respond Time Objective – Indicates the time between the incident creation and when a representative responds to the designated individual to review the reported issue.
6.4.9
DT&E1
System Integration Test Plan
Contractor Determined Format
30 days prior to testing in DTL
Standard Distribution
Prior to each testing in DTL
Table 5 - Maintenance Standards Severity Level
Definition Performance Standard
Resolve Time Objective – Indicates the time to resolve a problem once DeCA has provided all relevant information to support personnel and all necessary data retrieval has been completed. Non-operational hours of a location and circumstances outside of support personnel’s control are not included in the resolve time metric.
6.5.1 The Contractor shall upgrade applications, interfaces, databases, hardware, external devices, firmware, operating systems, and communications and network protocols for DEBOSS Environment.
6.5.2 The Contractor shall update applications to support technology refreshes, version releases, interoperability with legacy and new solutions (hardware and software) or compliancy requirements with DeCA.
6.5.3 The Contractor shall provide sustainment and maintenance for connected payments, store locations, failover and disaster recovery, payment processing, mobile/e-commerce, all CONUS/OCONUS locations, and expansion to Cloud.
6.5.4 The Contractor shall support all new hardware and accessory purchases, and external as listed in Appendix 1. This support will include migration of applications, and integration with hardware vendors and new solutions.
6.5.5 The Contractor shall maintain all components and system configurations of the DEBOSS environment to include system applications, hardware, software, OS, firmware, communication protocols, in an asset management tool.
6.5.6 The Contractor shall assist DEBOSS Program Management Office during any scheduled shut-down processes to shut-down and restore the DEBOSS environment within the DeCA provided schedule.
6.5.7 The Contractor shall perform shut-down procedures for any impacted DEBOSS environment upon notification by DeCA datacenter within two hours. The Contractor shall restore any impacted DEBOSS environment upon when directed by DeCA datacenter upon resolution within four hours.
6.5.8 The Contractor shall provide communication to the DEBOSS Program Manager Office (PMO) and impacted end users for all shutdowns and once system has been restored within 30 minutes.
6.5.9 The Contractor shall preform decommissioning/sunset activities related to the DEBOSS environment.
6.5.10 The Contractor shall maintain/sustain, troubleshoot, and repair all DEBOSS applications, in all DeCA environments by identifying and implementing code, scripts, wrapper updates to resolve the issues. Any scripts and/or wrappers written outside the base code/application will be provided to DeCA.
6.5.11 The Contractor shall provide a Software Scheduled Maintenance Plan for sites CONUS/OCONUS that identifies the downtime for each site and application, within 30 days of contract award. It will be updated annually or as the environment changes. The DeCA’s downtime policy for DEBOSS applications is no more than 2 hours. Upon DeCA’s approval, the Contractor will perform the tasks within the agreed upon parameters. The plan shall include listing end-of-life software schedule for replacement and DeCA will provide final guidance of required disposition.
6.5.12 The Contractor shall ensure that DEBOSS systems are stable, reliable, and secure IAW the performance metrics.
6.5.13 The Contractor shall ensure the schedule and execution of daily database backups for all DEBOSS databases.
6.5.14 The Contractor shall schedule, execute, and monitor system and instance resources to ensure continuous database operations (database storage, memory, Central Processing Unit, network usage, and Input/Output contention) and automated database jobs. The Contractor shall report job failures daily Monday through Friday each week with nightly checks Sun-Thurs, and re-run jobs upon failure if applicable. System reports are initiated at midnight EST and provided to the Government via email by 0800 Eastern Standard Time (EST) the same day of the report.
6.5.15 The Contractor shall provide DeCA daily Systems Status Reports to include the following information:
• All services
• Jobs
• Data synchronization tasks
• Interfaces
• Applications
• Hardware availability
6.5.16 The Contractor shall provide a Monthly Database Metric Report no later than the 5th day of the month.
6.5.17 The Contractor shall establish and maintain a metrics program to document successes and failures, trends, perform analyses, and brief database performance to the Government. The Government will validate the metrics for acceptance. Any discrepancies to the metrics will be returned to the Contractor for correction and re-submitted to the Government for acceptance within 5 days.
6.5.18 The Contractor shall create, maintain, and enforce preexisting naming standards.
6.5.19 The contractor shall upgrade/migrate the DEBOSS environment to current DoD (Original Equipment Manufacturer (OEM) release level.
6.5.20 The Contractor shall resolve all database corruption issues.
6.5.21 The Contractor shall dispatch a technician upon notification from the PMO to resolve an issue/incident to the site. The technician will conduct a preliminary assessment and provide recommended to resolve the issue to the PMO. During the site visit the technician will conduct an evaluation for preventative maintenance on all onsite DEBOSS equipment. The technician will provide a report no later than 5 days from return from site.
6.5.22 The Contractor shall provide a Hardware Scheduled Maintenance Plan for sites CONUS/OCONUS that identifies the downtime. DeCA’s downtime policy for critical components no more than 24 hours. Upon DeCA’s approval, the Contractor will perform the tasks within the agreed upon parameters. The plan shall include listing end-of-life hardware/equipment schedule for replacement and DeCA will provide final guidance for required disposition of equipment.
6.5.23 The Contractor shall, when performing routine maintenance and sustainment, provide new OEM components.
6.5.24 The Contractor shall provide maintenance for all components, labor, and other materials required to affect on-site repair of hardware.
6.5.25 The Contractor shall comply with DoD, DeCA, and all local disposition requirements, when disposing of retired, damaged, or any decommissioned hardware.
6.5.26 The Contractor shall provide the capability to remotely push and install patches, software updates, application software, and operating system patches and firmware to DEBOSS servers and clients in an efficient, standardized, and repeatable manner. The Contractor must monitor the installation and provide status of all remote application/patch installations within 24 hours.
6.5.27 The Contractor shall deploy and configure enterprise patch management agents on all DEBOSS servers. These agents will report back to the enterprise-reporting server for compliance. Non-compliant systems must be remediated within 3 business days.
6.5.28 The Contractor shall provide software packages for all changes to DEBOSS software which includes desktop and server operating systems patches, application software updates, and new software version releases to the DEBOSS PMO 30 days prior to planned Government testing.
6.5.29 The Contractor shall test software packages in coordination with DeCA Automated Test Center.
Packages shall be tested within 7 days and take no longer than 20 days upon the submission of the Service Request (SRs).
6.5.30 The Contractor shall create a Production Change Notice (PCN) following completion of successful environment testing in accordance with guidance in DeCA Change Management policy/procedures.
6.5.31 The Contractor shall ensure scheduled software package deployments will occur within approved downtime windows per software maintenance plan.
6.5.32 The Contractor shall create a software package installation report following the unsuccessful completion of a software Package PCN. This report must be delivered within 3 days after unsuccessful completion and submitted to the PMO or designated POC for disposition action.
The report will include:
Progress %
Remediated Computer Count
Applicable Computer Count
Source Severity
Source ID
Download Size
Name
Source Release Date
Mean Time to Remediate.
6.5.33 The Contractor shall review all Microsoft releases for operating system security updates and create/submit a software package for all Government approved release to DeCA Automated Test Center for testing within 3 days.
6.5.34 The Contractors shall review IAVA to determine scope of vulnerability impact and remediate all affected DEBOSS systems. The Contractors shall develop, test, and begin deployment within 30 days of notification for all IAVAs.
6.5.35 The Contractor is responsible for maintaining 100 % data accuracy and integrity across all DEBOSS environment and downstream systems in real time.
Table 6 – Maintenance Deliverables
Task#
Deliverable Title Format Due Date Distribution/ Copies
Frequency and Remarks
6.5.11 Software
Scheduled Maintenance Plan
Contractor Format
Scheduled Down Time
Standard Distribution
Provide in anticipation of
DEBOSS
downtime
6.5.21 Incident Reports
(IRs), or Problem Reports (PRs)
Contractor Format
5-days after technician returns from site
Standard
Monthly
6.5.15 System Reports Contractor
Format
0800 EST
Same Day of the Report
Standard Distribution
Daily
6.5.16 Monthly Database
Metric Report
Contractor Format
5th Day of the Month
Standard Distribution
Monthly
6.5.22 Hardware
Scheduled Maintenance Plan
Contractor Format
Scheduled Down Time
Standard Distribution
Provide in anticipation of
DEBOSS
downtime
6.5.30 Production
Change Notice
Contractor Format
Completion of successful environment testing
Standard Distribution
Completion of successful environment testing
6.5.32 Software Package
Installation Report
Contractor Format
Unsuccessful completion of a software package production change
Standard Distribution
3 days of unsuccessful completion of a software package production change
6.5.33 Software Package Contractor
Format
Within 3 days of a Microsoft Release
Standard Distribution
Within 3 days of a Microsoft Release
6.6 Cloud Migration and Support. The Contractor shall provide ongoing cloud management services to include migration of DEBOSS applications to the contractor’s cloud, a DeCA cloud, or a third-party cloud.
6.6.1 The contractor shall support FEDRAMP certification process for any DEBOSS application to include documentation.
6.6.2 The Contractor shall support migration of applications to the cloud support – on-going migration, sustain and future DECA solution, including data migration for any future DECA cloud base solution, application cloud viability.
6.7 End User Support
6.7.1 Help Desk Tier 2 and Above
6.7.1.1 The Contractor shall provide support personnel that are United States citizens unless otherwise stated herein, fluent in the English language, and will hold required security clearances based on access to DeCA networks and resources.
6.7.1.2 The Contractor shall ensure each contractor employee (including any subcontractor or agent) will be designated to an IT position category (i.e., IT-I, IT-II, or IT-III) based on level of access IAW DeCA criteria. Access to classified information is not required. Foreign National are permitted Level I access only with command sponsorship and submission of DD 254. Only US citizens are allowed Level II and above.
6.7.1.3 The Contractor shall resolve database SRs within 1 business day.
6.7.1.4 The Contractor shall retain ownership of the incidents received from DeCA’s Global Support Center through confirmation of resolution.
6.7.1.5 The Contractor shall document current incident status within DeCA’s BMC Remedy suite.
6.7.1.6 The Contractor shall resolve each ticket within the parameters outlined in Table 7 DeCA’s Help Desk Support.
6.7.1.7 The Contractor shall monitor all data services, jobs, data synchronizations, and interfaces, applications, and hardware 24 hours per day, 7 days per week and notify the DEBOSS PM of any failures within 30 min and provide plan to resolve within 1 hour of occurrence.
6.7.1.8 The Contractor shall provide daily system status (Daily Stand-Up)) reporting to include the following:
• All incident tickets
• Helpdesk generated events
• Current preliminary analysis status
• Tracking status for each open incident
• Incident opening and closing interactions
6.7.1.9 The Contractor shall update the DEBOSS PM hourly and set up a Microsoft Teams meeting to support to resolution for all critical and high priority incidents.
6.7.1.10 The Contractor shall provide support planning and oversight, ensuring that the appropriate processes, procedures, and resources are in place to support DeCA’s maintenance and support requirements.
6.7.1.11 The Contractor shall work with internal organizations to identify and document lifecycle management issues such as call handling procedures, escalation procedures, spare parts requirements, security procedures, and other policies or procedures necessary to perform this contract.
6.7.1.12 The Contractor shall document and communicate DeCA-specific maintenance requirements, as appropriate, to NCR maintenance organizations.
6.7.1.13 The Contractor shall facilitate root cause analysis for any widespread or significant issues that impact DeCA solution operations.
6.7.1.14 The Contractor shall resolve all Help Desk issues consistent with the Service Level Objective resolution times established in the Table 7 below. Additionally, the Contractor shall conduct problem trend analysis, address root cause analysis of escalated issues, and create solution knowledge generation for all support levels. The Contractor shall prioritize (Table 7) resolution as early into the support process as possible and identifying systemic issues for early resolution.
6.7.1.15 The Contractor shall provide DeCA After-Action Report (AAR) for all incidents within 3 days of incident resolution. (Formal AAR Template).
6.7.1.16 The Contractor shall resolve or remediate request or recurring SRs, IRs, or PRs averaging 50 per month and provide monthly report on all resolution/remediation efforts from the previous month due on the 10th day of each month.
Table 7 Help Desk Performance Standards Priority Definition/Criteria Software
Response Threshold
Hardware Response Threshold
P1 MISSION
ESSENTIAL
(CRITICAL)
Complete loss of service in a production system with no workaround available.
Functional tasks cannot be completed or data integrity at risk.
Failures that prevent a DeCA store from selling/ordering groceries, or a business unit from performing critical functions for DeCA business.
Response: 15 minutes
CONUS
Resolution: 6 hours
OCONUS
Resolution: 24 hours
Respond –…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .