Draft PWS.pdf

PDF 1 MB Posted

Attached to
NAVIFOR N4 Directorate Program’s Support Services Federal contract opportunity
Solicitation number
N3600125RC004FS
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This is a Performance Work Statement (PWS) for contractor service support of Naval Information Forces (NAVIFOR) N4 Directorate Programs, including Collaboration at Sea (CAS), Secret Releasable (SECREL), Combined Enterprise Regional Information Exchange System-Maritime (CENTRIXS-M), and Naval Tool for Interoperability and Risk Assessment (NTIRA) systems.

The PWS outlines requirements for comprehensive IT support services including program management, IT service management, development support, operations/systems support, service desk support, cybersecurity, and network engineering across CONUS and OCONUS locations. Key objectives include maintaining system security and compliance, providing 24/7/365 service desk coverage, implementing DevSecOps practices, managing cloud environments, and supporting fleet operations worldwide. The contract requires various personnel roles from junior to senior levels across multiple disciplines, with some positions requiring TOP SECRET/SCI clearance. The period of performance is five years with a possible six-month extension. The work will be performed primarily at Naval facilities in Suffolk VA, Norfolk VA, Honolulu HI, and other fleet locations, with travel required to international sites for fleet exercises and operations support. The contract will be an Indefinite Delivery/Indefinite Quantity (IDIQ) with firm-fixed price provisions.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

Contractor Service Support of the Coalition and Allied Program’s Collaboration at Sea (CAS), Secret Releasable (SECREL), Combined Enterprise Regional Information Exchange System-Maritime (CENTRIXS-M) Communications Systems and Naval Tool for Interoperability and Risk Assessment (NTIRA)

Support

Navy Information Forces (NAVIFOR)

List of Governing References

a) DOD Instruction 8510.01 of 12

b) DODD 8500.1, Information Assurance, 24 October 2002

c) DODI 8570.1M, Information Assurance (IA) Workforce Improvement Program, 24 January 2012

d) DODI 8500.2, Information Assurance (IA) Implementation, 6 February 2003

e) DOD 5200.1-R, Information Security Program, January 1997

f) SECNAVINST 1543.2, CYBERSPACE/Information Technology Workforce Continuous Learning, 30

November 2012

g) DODI 8510.1, “DOD Information Assurance Certification and Accreditation

h) DODI 8551.1, “Ports, Protocols and Services Management (PPSM)

i) SECNAVINST 5239.3C

j) SECNAVINST 5400.15C

k) DOD 5220.22-M, National Industrial Security Program Operating Manual, 28 February 2006

l) SECNAVINST 5211.5E

m) DOD CIO Memorandum, Updated Guidance on the Acquisition and Use of Commercial Cloud Computing

Services, 15 December 2014

n) E.O. 12333, United States Intelligence Activities

o) DOD Instruction 5200.01 of 21 April 2016

p) DOD Directive 5205.07 of 1 July 2010

q) DOD Directive 5205.8, Access to Classified Cryptographic Information, 20 February 1991

r) DOD Instruction 5205.11 of 6 February 2013

s) DOD Instruction 8320.07, "Implementing the Sharing of Data, Information, and Information Technology

(IT)

t) SECNAVINST S5460.3H (NOTAL)

u) SECNAV M-5239.1 of 1 November 2005

v) SECNAVINST 5239.22

w) DOD Instruction 8115.02 of 30 October 2006

x) National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37, Guide for

Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach, 5 June 2014

y) NIST SP 800-82, Guide to Industrial Control Systems (ICS) Security, May 2015

z) NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, 22

January 2015

aa) CNSSI 1253 Security Categorization and Control Selection for National Security Systems, 27 March 2014

bb) NIST SP 800-53A, Assessing Security and Privacy Controls in Federal Information Systems and

Organizations: Building Effective Assessment Plans, 18 December 2014

cc) DOD Directive 8140.01 of 11 August 2015

dd) SECNAV M-5239.2 of 27 June 2016

ee) DOD Instruction 8500.01 of 14 March 2014

ff) OPNAVINST 5239.1D, 18 Jul 2018, 2 Enclosure (1)

gg) CJCSI 6510.01F, Information Assurance and Computer Network Defense, February 2011

hh) CJCSI 6211.02B, Defense Information System Network Policy, h. Responsibilities and Processes of 31

July 2003

ii) DOD Instruction 8530.01 of 7 March 2016

jj) OPNAVINST F3100.6K (NOTAL)

kk) DOD Instruction 8520.03 of 13 May 2011

ll) SECNAVINST 5510.36A

mm) DOD Instruction 5000.02 of 7 January 2015

nn) DOD Program Manager Guidebook for Integrating the Cybersecurity Risk Management Framework into the System Acquisition Lifecycle, 27 October 2015

oo) 48 CFR 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting

pp) NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Information Systems and

Organizations, June 2015

qq) OPNAVINST 5450.343

rr) OPNAVINST 5450.353

ss) SECNAVINST 5239.20A

tt) SECNAVINST 5510.37

uu) DOD Information Systems Agency Enclave Test and Development

vv) Security Technical Implementation Guide (STIG), Version 1, Release 3, 22 January 2016

ww) Director of Central Intelligence 6-3, Security Policy on Intelligence Information in Automated Systems and Networks

xx) NSTISSP No. 11 Revised, National Policy Governing the Acquisition of Information Assurance (IA) and IA Enabled Information Technology (IT) Products, June 2003

yy) DOD Directive 5000.1, Defense Acquisition System, November 2003

zz) ISO 9000, Quality Management Systems, - Fundamentals and Vocabulary, September 2015

SECTION 1: BACKGROUND AND GENERAL INFORMATION

1.1 GENERAL:

The objective of this effort is to procure a non-personal services contract to provide contractor personnel for the management, support, and operation of the Naval Information Forces (NAVIFOR) N4 Directorate Program’s. The current directorate programs include Collaboration at Sea (CAS), Combined Enterprise Regional Information Exchange System-Maritime (CENTRIXS-M), and Naval Tool for Interoperability (NTIRA). These programs include ensuring seamless integration with other naval and joint systems, adherence to security and compliance standards, meeting performance and availability metrics, and supporting scalability and future enhancements of these programs.

The work, as defined in this PWS is expected to be accomplished by a mixture of professional and technical personnel and key personnel consisting of the contract Labor Categories described throughout the PWS. The contractor shall provide personnel who are fully qualified and competent to perform the full range of tasks described throughout the PWS. The contractor is responsible for ensuring the accuracy of the information contained in the resumes. The Government reserves the right to review all resumes of proposed personnel and reject any candidate that does not meet the qualifications in section 7.

In all parts of this contract the Contractor shall provide services support from within Continental United States (CONUS) and its Outside Continental United States (OCONUS) territory sites to support Fleet customers throughout the world, both afloat and ashore to include: Commander, U.S. Naval Forces Europe, U.S. Naval Forces Africa, U.S. SIXTH Fleet; (CNE-CNA-C6F); Commander U.S. Naval Forces Central Command (COMNAVCENT), U.S. FIFTH Fleet (COMFIFTHFLT), Combined Maritime Forces (CMF, U.S. THIRD Fleet (COMTHIRDFLT); Commander, U.S. SEVENTH Fleet (COMSEVENTHFLT), Commander, U.S. FOURTH Fleet (COMFOURTHFLT); Commander, Naval Information Forces (NAVIFOR), Naval Computer and Telecommunications Area Master Station Pacific (NCTAMSPAC), Naval Computer and Telecommunications Area Master Station Atlantic (NCTAMSLANT), Naval Computer and Telecommunications Station Naples (NCTS Naples); Naval Computer and Telecommunications Station Bahrain (NCTS Bahrain); Network Operations Centers (NOCs) in Norfolk (UARNOC), Hawaii (PRNOC), Naples (ECRNOC) and Bahrain (IORNOC) and all of their component command area of responsibilities, as well as any other sites deemed necessary in support of Fleet operations, to include Fleet Maritime Operation Centers (MOCs). The Contractor shall also provide services support to Program Executive Office for Digital and Enterprise Services (PEO Digital) and Program Executive Office Command, Control, Communications, Computers and Intelligence (PEO C4I) where the Coalition and Allied Program’s Collaboration at Sea (CAS), Secret Releasable (SECREL), Combined Enterprise Regional Information Exchange System-Maritime (CENTRIXS-M) Communications Systems and Naval Tool for Interoperability and Risk Assessment (NTIRA) programs have an interest in the total Navy and its Maritime Partners.

In all parts of this contract the contractor shall foster and support cross-functional teamwork by actively collaborating with various internal and external teams, including Fleet and Regional Commanders, Navy Network Operations Centers (NOCs), coalition partners, and other stakeholders – the total Navy and its Maritime Partners.

CAS is a web-based system used to convey mission essential information to a large group of users with low band-width consumption across an array of non-classified and classified networks. CAS fulfils a requirement to file share, email, and chat with U.S. to U.S. and U.S. to coalition and allied maritime partners via ship to ship, ship to shore, shore to ship, and shore to shore.

CENTRIXS-M and/or coalition secret releasable (SECREL) networks, enclaves and community of interest (COI) systems form the network backbone and global infrastructure for coalition and multinational Command, Control, Communications, Computers, and Intelligence (C4I) interoperability. It provides tactical and operational information sharing between U.S. to U.S and U.S. to coalition maritime partners.

NTIRA is a module-based decision aid tool to facilitate knowledge discovery and management for C5I stakeholders in requirements generation, acquisition management and resource planning. It allows stakeholders to share a working environment among the Fleet, Office of the Chief of Naval Operations (OPNAV), acquisition communities, and component commands to facilitate a common picture of individual platforms mission capabilities and identified shortfalls. This knowledge enables decision makers to select the most capable platform to fill mission need and identifies capability gaps that steers Command, Control, Communications, Computers, Combat Systems, and Intelligence (C5I) Modernization.

In addition to C5I Modernization, NTIRA hosts and collects personnel OPREP-3 situation reports in coordination with US Fleet Force (USFF) N1. In support of NAVIFOR, NTIRA is the primary tool for NAVIFOR N1 manpower budgeting and planning. In support of the Information Warfare (IW) community and the Fleet, NTIRA hosts the Information Warfare Equipment Population Summary/Communication Equipment Population Summary and like solutions allowing that community to obtain and monitor existing C4I and IW capabilities aboard afloat ships and shore commands.

NTIRA development and production servers are cloud based. NTIRA exists on both the Non-secure Internet Protocol Network (NIPRNET) and Secret Internet Protocol Network (SIPRNET) and interfaces with Navy Data Environment (NDE) databases.

Data Rights: All documents and materials, to include the software, source codes of any software, and compile modules produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belongs exclusively to the Government.

These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.

All sections of this contract apply to and support the CENTRIXS, CAS, Coalition, SECREL, and NTIRA programs. These programs whether maintained under the same, new, or additional program names may shift between NAVIFOR Directorates due to Command reorganization. In such cases where there is a reorganization within NAVIFOR, the contractor shall provide the same program services under that NAVIFOR Department. In all sections of this contract, references to non-classified and classified networks and/or enclaves are to include all non-government commercial, unclassified, secret, coalition networks, and community of interest (COI) network systems, clouds, data centers, data lakes, and domains where CAS, CENTRIXS, Coalition, SECREL, and NTIRA programs have an interest. This also encompasses integration with other naval and joint systems, adherence to security and compliance standards, meeting performance and availability metrics, supporting scalability and future enhancements, and modernization of these programs.

CAS, CENTRIXS, Coalition, SECREL, and NTIRA will collectively be referenced as and called program or programs throughout the PWS. Commander, U.S. Naval Forces Europe, U.S. Naval Forces Africa, U.S.

SIXTH Fleet; (CNE-CNA-C6F); Commander U.S. Naval Forces Central Command (COMNAVCENT), U.S. FIFTH Fleet (COMFIFTHFLT), Combined Maritime Forces (CMF, U.S. THIRD Fleet (COMTHIRDFLT); Commander, U.S. SEVENTH Fleet (COMSEVENTHFLT), Commander, U.S.

FOURTH Fleet (COMFOURTHFLT); Commander, Naval Information Forces (NAVIFOR), Naval Computer and Telecommunications Area Master Station Pacific (NCTAMSPAC), Naval Computer and Telecommunications Area Master Station Atlantic (NCTAMSLANT), Naval Computer and Telecommunications Station Naples (NCTS Naples); Naval Computer and Telecommunications Station Bahrain (NCTS Bahrain); Network Operations Centers (NOCs) in Norfolk (UARNOC), Hawaii (PRNOC), Naples (ECRNOC) and Bahrain (IORNOC) and all of their component command area of responsibilities, as well as any other sites deemed necessary in support of Fleet operations, to include Fleet Maritime Operation Centers (MOCs) will collectively be referenced as sites or work sites throughout the

PWS.

1.2 TYPE OF CONTRACT:

The Government intends to award an Indefinite Delivery/Indefinite Quantity contract with Firm-Fixed Price provisions for services. Individual task orders will specify positions and performance locations.

1.3 OVERVIEW OF TASKS:

The contractor shall provide comprehensive support for the program, including:

• Program Management Support

• IT Service Management (ITSM)

• Program Compliance

• Development Support

• Scrum

• DevSecOps

• Web Application Development

• Database Development and Architecture

• Development Compliance

• Operations and Systems Support

• Service Desk Support

• Systems Administration

• Database Administration

• Training

• Data Science

• Technical Writing

• Cybersecurity

• Cyber Hygiene

• Network Engineering Support

• Network Security

• Configuration Management

Programs encompass the provision of IT services, as well as the ownership, operation, and management of IT software, cloud, and on-premise hardware and software systems. The contractor is required to utilize IT service management frameworks and practices, such as those delineated in ISO (9000, 27000, 20000), FitSM, Information Technology Infrastructure Library (ITIL), Control Objectives for Information and Related Technology (COBIT), and Capability Maturity Model Integration (CMMI). These IT service management approaches will be integral to fulfilling the program's mission, policy, and requirements, both for the government and the contractor. Additionally, internal and external operations related to IT services will be assessed based on similar framework practices outlined in the program's ITSM policy.

The program's ITSM policy will adhere to the Department of Defense (DOD) ITSM guidance, as outlined in the DOD Enterprise Service Management Framework (DESMF), serving as a guide for its implementation. The Contractor must utilize the Program ITSM policy to provide, at minimum, biannual assessments of program ITSM policy/plan compliance; the Contractor shall develop a plan and implement ITSM solutions for identified compliance gaps.

The contractor is required to support the programs, which provide services and products across diverse network domains with numerous stakeholders and dependencies spanning various US and foreign agencies, system commands, acquisition command program of records, acquisition command non-program of records and fleet command projects. These programs necessitate collaboration across platforms and capabilities teams to meet the technical and operational requirements of the US Navy and its coalition and allied partners for shore-to-shore, ship-to-ship, shore-to-ship, ship-to-shore, and decision aid to decision aid operations, ensuring end to end services, product and capability wholeness.

The contractor's responsibilities include staying abreast of emerging technologies and industry best practices to adapt to evolving requirements. They must also regularly review program strategies and adjust plans as necessary to align with program lines of effort. With intimate familiarity with the program plan and planning, the contractor is expected to effectively support the program's footprint, maintain alignment with program mission objectives, and deliver value to the US Navy and its coalition and allied partners.

The Contractor shall perform Planned Maintenance System (PMS) maintenance procedures in support of Maintenance and Material Management (3-M) in accordance with COMNAVIFORINST 4790.1A and

OPNAVINST 4790.4F

The contractor is expected to execute these tasks with a high level of professionalism, adherence to industry best practices, and commitment to meeting program objectives and timelines.

1.4 PERIOD OF PERFORMANCE:

The period of performance shall be for a five (5) year ordering period. The resultant contract will also contain FAR 52.217-8, thereby allowing a six (6) month extension if circumstances necessitate this option. The Period of Performance reads as follows:

1.4 LOCATIONS OF PERFORMANCE:

The work to be performed under this contract will be performed at US Government provided facilities in locations as specified in task orders issued under this contract. Contract performance may occur at any of the following sites but not limited to:

a. Naval Information Forces (NAVIFOR), Suffolk, VA

b. U.S. Fleet Forces owned and operated facilities

c. Commander Pacific Fleet owned and operated facilities

d. Naval Computer and Telecommunications Area Master Station Atlantic (NCTAMS LANT)

e. United Atlantic Regional Network Operations Center (UARNOC), Norfolk, VA

f. Naval Computer and Telecommunications Area Master Station Pacific (NCTAMS PAC)

g. Pacific Regional Network Operations Center (PRNOC), Wahiawa, HI

h. Naval Computer and Telecommunications Station San Diego

Period of Performance Base 5-Year Ordering Period

11 September 2025-10 September 2030

FAR 52.217-8 Option 11 September 2030-10 March 2031

i. Naval Surface Warfare Center Panama City

j. Other Continental United States (CONUS) and its Outside Continental United States (OCONUS) territory sites as dictated by the Government.

1.5 HOLIDAYS:

The contractor is generally not required to provide services on these days.

New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day President’s Day Veteran’s Day Memorial Day Thanksgiving Day Juneteenth Day Christmas Day Independence Day

World events, system testing, and other emergent requirements may infrequently require the contractor to provide support on federal holidays and weekends.

1.6 WORK ENVIRONMENT AND HOURS OF OPERATION:

Except as noted above, those contractor personnel identified to work at fleet headquarter like facilities shall provide services in accordance with local command work policies, if none is provided the services shall be between the hours of 0600 and 1600 Monday through Friday with the exception of Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. Contractor personnel may be required to participate in events which will fall outside of normal working hours. When such events occur, the Contractor PM shall ensure individual contractor personnel work hours do not exceed 40 hours per work week.

Contractors may telework as approved by the Government Program Manager, and shall comply with the most restrictive of DOD, DON, or local command policies. Teleworking can be terminated by the government at any time. Remote work is allowed at the approval of the Government Program Manager.

Remote work should be of a rare event, situation, or condition such as convenience for medically diagnosed handicaps, small pool of candidates for specialized work, or the retention of talent that is critical to the program or project as examples. Remote workers need to be self-motivated experts who have shown a history of or assessed as taking on initiatives without direction that benefit and exceed goals. Remote work is for the convenience of the contractor and therefore any cost associated with working offsite will not be done at a cost to the government. The Government Program Manager has the right to terminate remote work in part or full regardless of circumstances.

If contractor personnel are working remotely/teleworking at the convenience or request of the contractor and are required to conduct government-directed travel, the contractor shall use Norfolk, Virginia as the point of origin used for travel pricing unless the cost to the Government is lower from their respective remote/telework location. Telework is for the convenience of the contractor and therefore if the personnel are required to be on-site, these travel costs will not be reimbursed. However, the contractor shall be reimbursed for travel costs incurred when remote workers travel to the primary place of performance at the explicit request of the government.

Those contractor personnel providing services at operation center like facilities, such as the Unified Atlantic Region Network Operations Center (UARNOC), shall provide a combined services coverage of 24/7/365.

When an operation center is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings, the contractor PM shall work with the government PM to mitigate gaps in services coverage. When such events occur, the Contractor PM shall ensure individual contractor personnel work hours do not exceed 40 hours per week. Those contractors in Hawaii shall comply with Hawaii state labor laws. Contractors that work in operation centers usually do not qualify for telework due to the nature of the work. However, there may be situations that are conducive to teleworking, in these cases telework must be approved by the Government Program Manager and shall comply with the most restrictive of DOD, DON, or local command policies.

Those contractor personnel providing services at the Unified Atlantic Region Network Operations Center (UARNOC), and Pacific Region Network Operation Center (PRNOC) shall have TS/SCI clearances.

Work is typically performed in an adequately lighted and climate-controlled office space.

Contractor personnel may be required to conduct local, national and international travel in the performance of the contract. Contractor personnel may be required to perform on afloat units, both in port and at-sea, and at the location of field exercises.

Contractor personnel supporting operations and requirements gathering will be required to perform aboard afloat units and during field exercises. At-sea periods are usually no more than two weeks in duration. When embarked aboard ships or operating in the field, contractor personnel may be exposed to adverse and hazardous conditions. At-sea assignments require physical exertion related to embarking, debarking and transferring to-and-from afloat commands and may include transit on Navy and United States Marine Corps (USMC) fixed, tilt-wing, and rotary-wing aircraft, support craft such as Landing Craft Air Cushioned (LCAC), Landing Craft Utility (LCU), Rigid Hull Inflatable Boats and Tugboats supporting ship/shore and ship/ship personnel movement.

All such assignments require the ability to stand for long periods, walk, climb, bend, crouch, stretch, reach above one’s head and similar movements. Contractor is to ensure all personnel can perform such physical demands.

1.7 CONTRACTING OFFICER’S REPRESENTATIVE (COR):

The (COR) will be identified in the contract. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the Contractor performs the requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the Contractor concerning various aspects of the contract; issue written interpretations of requirements; monitor Contractor's performance and notify both the Contracting Officer and Contractor of any deficiencies; coordinate availability of Government furnished property/training sites, and provide or coordinate site entry of Contractor personnel. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.8 IDENTIFICATION OF CONTRACTOR PERSONNEL:

All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.

SECTION 2: CONTRACTOR TASKING

2.1 PERSONNEL:

The contractor shall provide personnel with the position-dependent experience and certification(s) identified in Section 7.0.

2.2 PROGRAM MANAGEMENT SUPPORT:

The Contractor shall designate a Contractor Program Manager (Contractor PM) who shall be responsible for the performance of the tasking of this Performance Work Statement (PWS). The name of this person and an alternate who shall act for the contractor when the Contractor PM is absent shall be designated in writing to the Contracting Officer (KO) and COR. The Contractor PM or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The Contractor PM shall direct the effort of the contractor personnel and shall report and monitor progress to the Government Program Managers and COR through direct communication and the contract deliverables (Section 11). The Contractor PM designated herein shall not concurrently hold any additional roles or responsibilities, whether within or outside the scope of this contract's execution as noted in Roles and Responsibilities section 6.2 Contractor Program Manager.

• The contractor shall prepare briefings and presentations for up to flag/general officer and SES-level executives.

• The contractor shall provide recommendations on Program Objective Memorandum (POM) preparation and analysis, strategic planning, acquisition planning and support, and proposal preparation and review support.

• The Government and the Contractor shall jointly establish due dates specific to individual work products (ex., reports, course-related material, presentations, analysis, etc.) The Contractor shall provide progress reports on individual work products with assigned due dates in the Weekly Activity Report (Section 6).

• The Contractor shall solicit, receive, input, and maintain the overall Program calendar.

• The Contractor shall generate Weekly Activity Report, Monthly Status Report, Monthly Financial

Report, and Trip Reports (Section 6).

• The Contractor shall coordinate and participate as needed in Naval Command, Control, Communications, Computers, Combat Systems, Intelligence, Surveillance, and Reconnaissance (C5ISR) Modernization Council (NCMC), Multinational Maritime IP Interoperability (M2I2) Steering Group meetings (with participating countries); Allied and Coalition Interoperability Summits, Cross Command and Technical Working group conferences, and other syndicates as required to support the Coalition and Allied Division programs.

• The Contractor shall report on progress of and any deviation from established deadlines of assignments, projects, and tasks. The Contractor shall maintain awareness and participate in planning for achievement of team goals and objectives, research, learn, and apply a wide range of qualitative and/or quantitative methods to identify, assess, analyze and improve effectiveness, efficiency, and work products.

• The Contractor shall communicate recommendations on actions affecting the fleet, programs, system products or progress.

• The Contractor shall be responsible for supervising resources, ongoing projects, and plans for future projects. This includes formulating objectives, collecting requirements, and overseeing project execution, while ensuring strict adherence to schedules, financial allocations, and quality benchmarks. The Contractor shall collaborate closely with project teams, facilitate seamless planning and execution, promptly addressing technical challenges through efficient management of support services. Moreover, ensures the implementation of robust quality assurance processes to validate functionality, support, and security measures.

• The Contractor shall proactively identify, measure and mitigate potential risks, maintain effective communication with stakeholders, and spearhead initiatives for continuous improvement.

Throughout the program's lifecycle the contractor shall remain vigilant in upholding compliance with regulatory standards and security protocols.

2.2.1 INFORMATION TECHNOLOGY SERVICE MANAGEMENT (ITSM) SUPPORT:

It is program policy to have an ITSM framework. The Contractor shall develop and continually improve the program/s ITSM standards, capabilities, and practices to facilitate integration and operational activities, in accordance with the program architecture and policy. The Contractor shall follow ITSM policy approved and signed by the government Program Manager. The program ITSM policy follows closely with the Navy IT Service Management Office (ITSMO) which coordinates and governs the development and execution of a customer-focused, enterprise-wide approach to ITSM that drives improved service quality and interoperability across Navy enterprise networks to support the DON IM/IT strategic goals and efficiency initiatives.

ITSM Support activities include, but are not limited to, the following:

• Adhere to the programs ITSM policy, best practices, standards, and measures.

• Review existing program ITSM documentation and create an ITSM Implementation Plan.

• Make recommendations to existing program ITSM policy and as necessary make recommendations for new ITSM policy to conform with and support DOD Instruction 8440.cc, DOD Enterprise Services Management Framework (DESMF) requirements, and Navy ITSM instructions and guidance.

• Optimize and update processes, procedures, and architecture models to comply with DOD and Navy ITSM guidance.

• Support ITSM best practices through delivery of contract Program Organizational Chart (Section 6).

• Support ITSM best practices through delivery of role and responsibilities (Section 6) for each contract’s position such as a responsibility assignment matrix (RAM) or other equivalent products

• Make recommendations to existing program ITSM policy and as necessary make recommendations for new ITSM processes, such as incident management, change management, configuration management, and risk management. Processes shall be tailored to the specific needs of program(s).

• Support development, execution, and measurement of program incident management, problem management, configuration management, and change management activities.

• Support modernization and integration efforts through the application of ITSM Implementation Roadmaps.

• Conduct readiness analysis and integration planning, perform process capability assessments and recommend improvement measures.

• Support program Continual Service Improvement (CSI) development, execution, and measurement efforts through the iterative improvement of capabilities that enable delivery and management of IT products, services and operations.

• Report performance measures to assess progress against program plans and priorities and make recommendations to refine the performance measures to meet program and project objectives.

2.2.2 PROGRAM COMPLIANCE:

The Contractor shall meet programmatic policies, processes, guidance, quality assurance, and metrics.

The Contractor PM and their Alternate shall sign a letter acknowledging they have read applicable programmatic policies, guidance, quality assurance, metrics, and too acknowledging where to access these documents. The Contractor must support developing, implementing, maintaining, and improving the programmatic policy. The policy shall identify processes, guidance, quality assurance, and metrics. The policy, processes, guidance, quality assurance, and metrics may be one or individual documents, each shall have the Government Division Director, Government PM, and Contractor PM signatures.

2.3 DEVELOPMENT SUPPORT:

The Contractor shall provide Development support within Continental United States (CONUS) and its Outside Continental United States (OCONUS) territory sites to support Fleet customers throughout the world, both afloat and ashore, at all sites as referenced in Section 1. The Contractor shall also provide Development support to Program Executive Office for Digital and Enterprise Services (PEO Digital) and Program Executive Office Command, Control, Communications, Computers and Intelligence (PEO C4I) where the Coalition and Allied Program’s Collaboration at Sea (CAS), Secret Releasable (SECREL), Combined Enterprise Regional Information Exchange System-Maritime (CENTRIXS-M) Communications Systems and Naval Tool for Interoperability and Risk Assessment (NTIRA) programs have an interest.

The Contractor shall establish programmatic processes and procedures by drafting, implementing, and maintaining Development Process Guidance, Development Guidelines, and standardized documents such as Standard Operating Procedures (SOPs), User Guides, Test Plans, Configuration Guides, and Training Plans. SOPs, Development Process Guidance, and Development Guidelines are to be reviewed with the government at least once every contract period of performance for corrections, updates, and modifications to support good operational and developmental practices.

The Contractor shall directly interface with the client related program operations and maintenance across all enclaves, platforms, and cloud environments; validate software versions and configurations; recommend software and hardware upgrades and enhancements; and conduct software development, testing, versioning, and deployment tasks.

The Contractor shall work closely with the Fleet and team members to understand requirements that will drive an analysis and design of quality technical solutions. This requires being involved in every aspect of IT service management, which will require but is not limited to, maintain a working knowledge of internal and external stakeholders and partners to gather requirements, prototype, architect, implement/update solutions, build and execute test plans, perform quality reviews, manage operations, and triage and fix operational issues.

The Contractor shall conduct technical reviews as required to ensure software modifications are meeting customer expectations. When required, the Contractor will participate in gathering, analyzing, and documenting customer requirements.

The Contractor shall provide inputs related to the development of the program project management plans including investigation and analysis for determination of functional and performance requirements, maintenance on developed software and applications coding, project schedules and various planning, training and implementation tasks.

The Contractor shall work with the government on development methodologies to support a waterfall, Agile, DevOps, and/or DevSecOps models for all development efforts. The Contractor is to obtain government approval for development methodologies prior to implementation of new methodologies.

Development shall include but not limited to maintenance, bug fixes, new capabilities, enhancements and additions to the deployed program(s).

The Contractor shall coordinate and conduct Sprint meetings to obtain Government approval to work on recommended software changes and additions to the deployed program(s). Sprint outcomes shall be documented in a Sprint Review Report at the conclusion of each sprint (Section 6).

The development leads shall attend all Sprint review board meetings as a participant to provide recommendations, impacts, and drive decision making to the program and projects as it relates to the development lifecycle.

The development process guidance and development guidelines are to be signed documents by the government and shall be followed within the program.

The Contractor shall ensure all web pages, exports, and other products that support the program have appropriate classification markings in accordance with DOD and DON policy and guidance.

2.3.1 SCRUM:

In support of Agile methodologies and Scrum, the Contractor shall:

• Manage and ensure product teams adhere to Agile software development, Scrum, and DevSecOps methodologies

• Schedule and lead daily stand-up meetings, sprint planning, sprint review, sprint demonstrations, and sprint retrospective meetings

• Assess existing sprint cadence and provide feedback and recommendation for future sprints

• Protect the development team from external interruptions and distractions, enabling them to focus on their work during sprints.

• Identify and resolve any obstacles or impediments that the development team encounters during development to keep the work progressing smoothly to include identifying potential coding, design, and algorithm solutions

• Provide guidance and support to team members, helping them understand and apply Scrum principles and practices.

• Encourage the team to reflect on their processes and implement improvements, fostering a culture of continuous learning.

• Act as a liaison between the development team and stakeholders, ensuring clear and effective communication.

• Identify potential risks and work with the development team to mitigate them.

• Promote collaboration within the development team and with other functional areas involved in the project.

• Monitor and support the team in maintaining high-quality software, including code reviews, testing, and integration.

• Oversee the usage of Scrum-related tools such as task boards, issue trackers, and collaboration platforms.

• Assist in creating and maintaining product backlog by using information gathered from stakeholder meetings, service desk interactions, requirements documents, and other sources

• Continuously refine and adapt the Scrum process to best suit the needs of the project, learning from each sprint.

• Help resolve conflicts and issues within the team or between team members and stakeholders.

• Monitor resource allocation, ensuring the team has the necessary tools and environments to complete tasks efficiently.

2.3.2 DEVSECOPS:

The Contractor shall be fully integrated in the design and implementation of applications’ build, release, deployment, and configuration activities. The Contractor shall manage DevSecOps tools, supporting cloud services, and IT infrastructure needed to support software code and website design. The Contractor shall adopt, develop, and implement automated continuous integration and delivery/deployment (CI/CD) pipelines. Shall use a combination of ITIL (or equivalent ITSM framework that address lifecycle processes) and DevSecOps together for the betterment of lifecycle processes.

The Contractor shall develop and maintain overall program DevSecOps solution(s) to include processes, architecture, toolsets, CI/CD pipelines, containerization strategy, and security solutions.

The Contractor shall provide CI/CD prototypes, architect solutions for potential CI/CD pipelines, implement and/or update solutions to include CI/CD pipelines, orchestrators, and other pipeline toolsets utilizing the Government identified technologies and development environments.

The Contractor shall analyze potential DevSecOps toolsets in terms of best use, best technical solution, compatible with Navy and DOD guidelines and policy, cost, and feasibility for inclusion in program pipelines.

The Contractor shall design, build, and maintain Operating System (OS) level virtualization containers in conjunction with Navy and DOD policy and guidance.

The Contractor shall provide input and guidance on architecture and processes to include build, release, both manual and automated testing, security testing, and deployment.

The Contractor shall manage tools, cloud services, cloud instances, and other IT infrastructure in support of DevSecOps.

The Contractor shall develop a coordinated DevSecOps plan with program ITSM functions and processes as an integral component in the DevSecOps strategy.

2.3.3 WEB APPLICATION DEVELOPMENT:

Cross training of different software/application/web/database developers is encouraged. The Contractor shall perform all development activities within the government designated development environment utilizing baselined environments.

The Contractor shall gather and analyze user requirements, develop new software modules and modify existing software modules following government approval. When critical bugs are identified, modules can be modified outside of the sprint cycle if the change is approved by the Government.

The Contractor shall input all change requests in the requirements management tracking system/s (or other id application tool). The Contractor shall obtain Government approval before starting work on proposed changes. Ensure the Government and other relevant stakeholders are included in sprint planning meetings to approve work and set priorities for proposed items.

The Contractor shall provide business process analysis expertise regarding optimizing utilization and adoption of the software among users. Applications will be developed in a manner that maximizes ease of use for non-technical users and considers software maintainability.

The Contractor shall develop web applications using validated user requirements, providing fully tested and documented web applications and web services. Any applications developed must be compatible in all dependent environments.

The Contractor shall ensure all code is maintained and versioned in the appropriate code repository, labeled according to version for ease of rollback if necessary. Versioning must be reflected throughout the various application modules and numbered according to versioning standard as defined by program policy.

The Contractor shall ensure all code changes should include, at a minimum, meaningful variable and function names, and be properly commented in accordance with software best practices. All code changes should be thoroughly tested within the development environment by the developer prior to being deployed to the test server.

The Contractor shall include release notes for all deployments that are clear to the changes made, as well as step by step instructions for change verification. Upon completing the release notes, the release notes are uploaded into the appropriate release notes folder in the knowledge management database with the document name to include the software version number, date, and document version number.

The Contractor shall create documentation throughout the sprint cycles that results in full end-user and configuration documentation for all software development efforts and product releases. Documentation shall contain all information necessary to document processes, procedures, code artifacts, and/or policies that were implemented in the development work. Documentation to include but not limited to Software Design Documents (SDDs), Database Design Document (DDDs), and User Guides.

The Contractor shall maintain the program application and software baselines to include each individual module. The program baseline includes the software on the various virtual machines which together create the application and baselines for the modules under sustainment.

The Contractor shall, for applicable program(s), utilize US Web Design System (USWDS) as a development style guide.

2.3.3.1 NTIRA APPLICATION DEVELOPMENT:

The Contractor shall create and maintain the product backlogs by using information gathered from stakeholder meetings, service desk interactions, requirements documents, and other sources. The Contractor shall coordinate and conduct sprint planning meetings to obtain Government approval before making changes to the NTIRA baselines. The development leads for individual efforts shall attend all sprint planning meetings to provide recommendations, impacts, and drive decision making for the NTIRA system and products.

The Contractor shall establish and document processes and procedures in support of the Software Development Lifecycle for NTIRA. This includes Standard Operating procedures (SOPs), Development Process Guidance, Development Guidelines, User Guides, Test Plans, Configuration Guides, and Training Plans.

The Contractor shall provide software developers and testers with knowledge and experience working in an Agile development environment to include participation in Scrums and DevSecOps.

The Contractor shall provide software developers with knowledge and experience in web application development to include but not limited to using .NET framework, .NET MVC, IIS, C#, Javascript, HTML, ASP.NET, VB.NET, Bootstrap, Typescript, CSS, JQuery, .NET Entity Framework, JSON, Python, Java, Java JDK, Apache Tomcat, Visual Studio, NetBeans, and Eclipse IDE.

The Contractor shall provide software developers with knowledge and experience to include but not limited to using Git-based repositories to include understanding how to perform pull and merge requests, create development branches, and commits.

The Contractor shall provide software developers with knowledge and experience to include but not limited to developing web services and APIs to include RESTful APIs.

The Contractor shall provide software developers with knowledge and experience to include but not limited to working with PKI authentication to include pulling from and application of data from PKI for use in the web application.

The Contractor shall provide software developers with knowledge and experience to include but not limited to working with writing to and pulling from databases, setting up connection strings, implementing a data layer for web applications, executing stored procedures, and executing data objects via MVC models.

The Contractor shall provide software developers with knowledge and experience in 508 compliance.

The Contractor shall be responsible for the effective management and administration of the code repository to include implementing measures to ensure the reliability and integrity of the code repository, including regular backups, version control best practices, and safeguards data loss or corruption. The code repository shall accurately track and preserve all revisions of the codebase, maintaining consistency and reliability over time. The Contractor shall encourage frequent commits and adherence to branching and merging strategies to minimize conflicts and facilitate code review and collaboration.

The Contractor shall provide product demonstrations. Demonstrations shall consist of live presentations or recorded sessions showcasing any functionality, usability, and features developed. This includes but is not limited to key features, workflows, and user interfaces. The purpose of these demonstrations is to provide the stakeholders with a comprehensive understanding of the developed software, facilitate feedback collection, and ensure alignment with the stakeholder's requirements and expectations.

The Contractor shall conduct demonstrations at agreed-upon intervals (typically following completion of significant milestones or development iterations) and scheduled in advance with government stakeholders.

Stakeholders shall have the opportunity to provide feedback, ask questions, and request modifications or enhancements based on the demonstrated functionality.

The Contractor shall maintain records of all product demonstrations, including dates, attendees, topics covered, and feedback received. Any modifications or action items resulting from the demonstrations shall be documented and incorporated into the project plan or subsequent development activities as appropriate.

The Contractor shall ensure all web pages, exports, and other products on the NTIRA servers have appropriate classification markings in accordance with DOD and DON policy and guidance.

2.3.3.2 WEB APPLICATION TESTING:

Following web application development, the Contractor shall conduct testing to ensure code changes work internally prior to deploying changes to the program production environments.

Testing will be performed on the program test servers located in the government prescribed development environment. The Contractor shall ensure all software changes are run through a government approved code analyzer prior to deployment.

The Contractor creates test scripts and test plans for both manual and automated tests, as applicable.

Test scripts and test plans should be developed utilizing the developer release notes and software change requests in the program requirements management tracking system. Upon completion of testing, the test plans must be uploaded to the appropriate test plan folder in the designated knowledge management database. The document name will include the software version number, date, and document version number.

The Contractor shall maintain the development Virtual Machines (VMs) and test servers so they mirror the configurations and software installations encountered in the deployed versions of the program.

The Contractor shall provide and complete 508 compliance testing and reporting for all program production systems which are not 508 excepted.

2.3.4 DATABASE DEVELOPMENT AND ARCHITECTURE:

The Contractor shall provide Database Development and Architecture support within Continental United States (CONUS) and its Outside Continental United States (OCONUS) territory sites to support Fleet customers throughout the world, both afloat and ashore, at all sites as referenced in Section 1. The Contractor shall also provide Development support to Program Executive Office for Digital and Enterprise Services (PEO Digital) and Program Executive Office Command, Control, Communications, Computers and Intelligence (PEO C4I) where the Coalition and Allied Program’s Collaboration at Sea (CAS), Secret Releasable (SECREL), Combined Enterprise Regional Information Exchange System-Maritime (CENTRIXS-M) Communications Systems and Naval Tool for Interoperability and Risk Assessment (NTIRA) programs have an interest.

The Contractor shall manage, monitor, design, code, and modify database schemas, systems, and procedures.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .