Draft PWS JECE Services.pdf
PDF 215 KB Posted
- Attached to
- DA01 - JAG Enterprise Cloud Environment (JECE) Federal contract opportunity
- Solicitation number
- N0018923R0039
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Navy JAG Corps
JAG Enterprise Cloud Environment (JECE)
Phase 4 – Sustainment – Managed Services
1. Scope of contract.
Navy Judge Advocate General's Corps is looking for a solution to support the user administration, security operation, maintenance and support of their Microsoft Azure created IL4 Enclave, the JAG Enterprise Cloud
Environment (JECE).
Design and architecture work was performed by Applied Information Sciences (The vendor) in partnership with
All About the Data (AATD), with subsequent implementation, application design and system integration performed by the same vendor. This “Phase IV” contract serves as the sustainment/management of the previously established cloud environment.
The US Navy Judge Advocate General (JAG) seeks an Agile Contractor that has extensive experience developing and designing complex, secure, web portal presences within Azure Government/DoD. The
Contractor must be an expert at configuring, deploying, and securing Azure Landing Zones in accordance with the Azure Cloud Adoption Framework and have extensive experience obtaining DoD and Navy Authorizations to Operate (ATO).
1.1. Contract overview. This contract is being established to provide managed services and support to the
JAG Enterprise Cloud Environment (JECE), a Cloud enclave within the approved Cloud environment under the auspices of Navy JAG’s selected Cloud broker, Naval Sea Systems Command.
1.2. Contract scope. The following commands and their mission requirements will be supported via this contract:
1.2.1. Office of the Judge Advocate General
1.2.2. Naval Legal Service Command
1.2.3. Office of the Special Trial Counsel (Navy)
2. Period of Performance. The period of performance for this contract for:
Period of Performance
Base Year 12 August 2023 – 11 August 2024
Option I 12 August 2024 – 11 August 2025
Option II 12 August 2025 – 11 August 2026
Option III 12 August 2026 – 11 August 2027
Option IV 12 August 2027 – 11 August 2028
FAR 52.217-6 12 August 2028 – 11 February 2029
3. Place of Performance. This is a virtual engagement. Contractors shall conduct user engagement via existing teleconferencing mediums, Microsoft Teams is preferred, but others solutions are acceptable. Work within
Azure environment shall be via direct login, DOD CAC.
4. Automated Data Processing (ADP) Requirements. Contractor shall provide all required information technology equipment to perform all managed services and support under this contract. Navy JAG representatives shall provide access to the JECE environment, in consultation with Navy JAG’s Cloud broker, NAVSEA, for all managed services and support to be performed under this contract.
5. Common Access Card (CAC)/Public Key Infrastructure (PKI), System Authorization Access Request-
Navy (SAAR-N). Contractor must comply with all United States Government, Department of Defense, and
Department of the Navy requirements with respect to CACs, PKI and SAAR-N in order to establish and maintain access to United States Government facilities and information technology systems.
6. CACs / Local Badges. Contractor must comply with all United States Government, Department of Defense, and Department of the Navy governance with respect to CACs and local badges in order to gain access to
United States Government facilities and information technology systems.
7. Receipt and Acceptance of Deliverables. Contractor must document delivery, receipt, and acceptance of all deliverables under this contract.
8. Tasks. This contract may include all of the following tasks:
8.1. Cybersecurity and compliance. Serve as the ISSO to maintain the RMF and ATO requirements for an IL4
Navy Cloud enclave environment, including audits, checks, ATO package maintenance, cybersecurity compliance, system scans, personnel training for security and access, and system monitoring.
8.2. Cybersecurity and compliance. Maintain the terraform packages used to install and recover Azure IL4
Cloud enclave environment.
8.3. Content Management System. Sustain existing and develop new user-requested features for the content management system, written in Django/Wagtail.
8.4. Dynamics 365 management. Create a “Center of Excellence” to monitor usage of Dynamics 365 modules, ensuring there is a centralized area to monitor alerts, remediation, capacities, utilization, etc.
8.5. Dynamics 365 management. Sustain existing and develop new user-requested features for the Disability
Evaluation System Counsel Program (DESCP) case management system.
8.6. Dynamics 365 management. Sustain existing and develop new user-requested features for the Legal
Assistance (LA) module.
8.7. Dynamics 365 management. Sustain existing and develop new user-requested features for the Recruiting module.
8.8. Dynamics 365 management. Sustain existing and develop new user-requested features for the
Budget/Fiscal Resources module.
8.9. Dynamics 365 management. Sustain existing and develop new user-requested features for the
Investigations module.
8.10. Dynamics 365 management. Sustain existing and develop new user-requested features for the Admiralty module.
8.11. Dynamics 365 management. Sustain existing and develop new user-requested features for the Medical
Care Recovery Unit (MCRU) module.
8.12. Dynamics 365 management. Sustain existing and develop new user-requested features for the Personnel
Claims Unit (PCU) module.
8.13. Dynamics 365 management. Sustain existing and develop new user-requested features for the Tort Claims
Unit (TCU) module, including continued development and sustainment of the Camp Lejeune Justice Act claims management system.
8.13.1. Camp Lejeune Justice Act claims module data migration completion.
8.14. Dynamics 365 development and sustainment. Develop and sustain new user-requested modules and supporting features for any new mission requirements assigned to the Navy JAG Corps that are to be hosted and supported from the JAG Enterprise Cloud Environment (JECE).
8.15. Power BI. Sustain existing and develop new features, applications and reporting utilizing Power BI, including, but not limited to, auto-budgeting, reports, audit logs, security roles, etc.
8.16. Training. Sustain current life-cycle support for all training requirements, including training content and delivery of training to the Navy JAG Corps user base, as well as development and sustainment of all life-cycle support for all training requirements derived from additional features, additional modules and additional functionality developed and sustained throughout JECE.
8.17. Testing and Quality Assurance. Sustain existing and develop and sustain new manual test scripts for all
JECE applications and operations. Sustain existing automated testing, and develop and sustain new automated testing. Sustain existing and develop new user acceptance testing scripts. Facilitate user testing for all JECE applications and operations.
8.18. Managed Services. Sustain and maintain all infrastructure support components of the Navy JAG
Enterprise Cloud Environment (JECE) within the NAVSEA Cloud Brokerage, including close coordination and collaboration with NAVSEA and its support contractors.
8.19. Project Management. Provision of project management support, including weekly updates to JAG leadership, as well as management of milestone delivery schedules and deliverables. Project management will also include continuous assessment and reporting of risk, and risk mitigation, for all JECE operations.
8.20. Project Improvement For Existing Modules: Provision of project improvement support, including weekly updates to JAG leadership, as well as management of milestone delivery schedules and deliverables.
Project will also include continuous assessment and reporting of risk, and risk mitigation, for all JECE operations.
9. Quality Control Plan (QASP). QASPs are expected and will be issued.
9.1. The Quality Control Plan (QCP) shall specify the Contractor’s performance monitoring process and personnel roles.
9.2. The Government requires the Contractor to submit a proposed Quality Control Plan (QCP) within 15 days of contract award.
9.3. The Government considers the successful outcome of the contract to be delivery of the required functionality in a manner that meets JAG performance standards relative to cost, schedule, and technical performance. Technical performance is measured in the areas of deliverables quality, user experience, and system availability.
9.4. The COR will review, for completeness, preliminary or draft products that the Contractor submits, and may return them to the Contractor for correction. Absence of comments by the COR will not relieve the
Contractor of the responsibility for complying with the requirements of this PWS. Final approval and acceptance of products required herein must be by letter of approval and acceptance by the COR. The
Contractor must not construe any letter of acknowledgment of receipt of products as a waiver of review, or as an acknowledgment that a product is in conformance with this work statement. Any approval given during preparation of a product, or approval for shipment must not guarantee the final acceptance of the completed product.
10. Minimum Requirements from the Contractor. This paragraph addresses the minimum requirements which must be satisfied by the contractor:
10.1. Contractor must be qualified and certified as a Top-Tier partner with Microsoft.
10.2. Contractor must currently have advanced specializations in the following areas: Microsoft Cloud
Security; ID and Access Management; Infrastructure and Database migration; Low Code Application
Development; and Microsoft Azure VMware.
10.3. Contractor must currently have its own Azure enclave environment to replicate a GCC-High environment for development requirements identified by the Navy JAG Corps.
10.4. Contractor must have past audit-verifiable and successful experience with assisting current and past
Department of the Navy customers with Cloud-based licensing requirements, including, but not limited to, Dynamics 365, Power BI, and Power Platform.
10.5. Contractor must have current Secret clearances and facility clearances for personnel to support all tasks identified in paragraph 12, above.
10.6. Contractor must have current professional services for managed services support for production maintenance and sustainment, as well as for identification, refinement, storyboarding, pricing, development, configuration and delivery of new requirements as identified by Navy JAG.
11. Government Labor Categories. The government labor categories for this contract are as follows:
Program Manager
Senior Project Manager
Project Manager
Senior Training Lead
Senior Quality Assurance Lead
Quality Assurance Tester
Business Analyst
User Experience Specialist
Senior Cloud Engineer
Cloud Architect
Mid-Cloud Engineer
Jr. Cloud Engineer
Power Platform Architect
Power Platform Senior Developer
Power Platform Mid-Developer
Power Platform Junior Developer
Software Engineer- Senior
Software Engineer-Mid
Software Engineer- Jr
IA Security Specialist- Senior
IA Security Specialist- Mid
Technical Specialist
Organizational Change Manager
Data Architect- Senior
Data Architect-Mid
Data Architect-Junior
12. Additional Personnel Qualifications. This paragraph addresses the minimum additional personnel qualifications which the contractor must satisfy:
12.1. Proven experience integrating Dynamics 365 into and within a GCC-High environment.
12.2. Proven experience operationalizing D365 solutions independent of Office 365.
12.3. Proven experience architecting, building and leading Risk Management Framework (RMF) and Authority to Operate (ATO) compliance efforts through successful issuance of an ATO for a Navy IL4 Cloud enclave.
12.4. Contractor must currently have personnel with Security+, AZ 103 or AZ 104 and CSWF IAM-I for privileged account access for immediate support for operations within the JECE enclave.
12.5. Contractor must currently have personnel with experience utilizing SharePoint virtual machines supporting Dynamics 365 operations.
12.6. Contractor must currently have personnel with Django/Wagtail Content Management System experience.
12.7. Contractor must currently have personnel with experience creating terraform packages as Infrastructure as
Code to establish, maintain and recover Azure enclave environments.
12.8. Contractor must currently have personnel with experience serving as an ISSM, including administration and maintenance of RMF and ATO packages for an IL4 Navy Cloud enclave.
12.9. Contractor must currently have personnel with Power BI experience for administration and maintenance of
Power BI support to all current JECE operations.
12.10. Contractor must currently have personnel with experience with both Power BI and administration and maintenance of data supporting legal services and support.
12.11. Contractor must currently have personnel with experience with both Azure Data Factory and administration, maintenance and migration of systems with data supporting legal services and support.
12.12. Contractor must currently have personnel with experience in Camtasia.
12.13. Contractor must currently have one or more certified SCRUM Masters.
12.14. Contractor must currently have one or more certified personnel in Human Computer Interaction.
12.15. Contractor must currently have one or more certified personnel in Power Platform (PL-900, PL-100, PL-
200, and PL-400).
12.16. Contractor must currently have one or more certified personnel in Azure-900.
12.17. Contractor must currently have one or more personnel with experience creating training material, including, but not limited to, Quick Reference Guides, Training Outlines, User Guides, Videos and On-
Demand Help materials.
13. Security Clearance Required. Have a FACILITIES CLEARANCE. OJAG/NLSC cannot accept a contractor with a clearance if the facility itself has not gone through and attained a facilities clearance. The minimum security clearance required of all contractor personnel is SECRET. There is no expectation that contractor personnel will require a security clearance of TOP SECRET/TS-SCI. Therefore, the contractor must be able to provide individuals (when required at the task order level) with a minimum security clearance of SECRET.
Any contractor personnel proposed to work on any effort shall be eligible for necessary clearances to immediately begin performance at the time of task awards.
14. Service Contract Reporting (SCR) (NMCARS 5237.102-90). Services Contract Reporting (SCR) requirements apply to this contract. The contractor shall report required SCR data fields using the SCR section of the System for Award Management (SAM) at following web address: https://sam.gov/SAM/.
Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year. Contractors may direct questions to the help desk, linked at https://sam.gov/SAM/.
15. METHOD OF PAYMENT:
WIDE AREA WORK FLOW. WAWF table to be provided to FLC.
https://sam.gov/SAM/ https://sam.gov/SAM/
16. CONTRACTING OFFICER REPRESENTITIVE (COR)
Cashia Garland
Technology, Operations, and Plans (CODE 67)
Office of the Judge Advocate General
Washington Navy Yard, DC
Office: 202 685 4425 cashia.k.garland.civ@us.navy.mil
17. ABILITYONE CLOSE-OUT
NAVSUP FLC Norfolk may utilize contractor support through the AbilityOne Program, as needed, to perform contract closeout functions for this acquisition. Information, including business sensitive/confidential or proprietary data, that the offeror/contractor provides to the Government or information already in the possession of the
Government may be viewed and utilized by the AbilityOne Program support contractor personnel during the course of its contract performance. The information that may be made available to the support contractor may include, for example, pricing and technical proposals, historical contract, pricing and performance information, Commercial
Asset Visibility (CAV) reporting information and similar data/information.
By submission of a proposal in response to this solicitation, the offeror/contractor and its subcontractors consent to a release of their business sensitive/confidential or proprietary data to the Government's AbilityOne Program support contractor personnel in order to perform close out services. Prior to the release of any such information to the support contractor, the support contractor will have in place with the Government a Non-Disclosure/Non-Use
Agreement in accordance with the terms of the AbilityOne Program support contract.
Offerors may execute their own Non-Disclosure Agreement with the AbilityOne Program (AbilityOne contact information available from the contracting point of contact). The support contractor must provide copies of the executed agreements to the Contracting Officer and the Contracting Officer's Representative (COR) for the support contract; and the offeror/contractor for this acquisition must provide copies of the executed Agreement to the
Contracting Officer for this acquisition. If the offeror/contractor seeks such a Non-Disclosure Agreement with the
AbilityOne Program support contractor, the Agreement must be executed no later than the date of final delivery under the resulting NAVSUP FLC Norfolk contract.
18. CONTRACTOR UNCLASSIFIED ACCESS TO FEDERALLY CONTROLLED FACILITIES,
SENSITIVE INFORMATION, INFORMATION TECHNOLOGY (IT) SYSTEMS OR PROTECTED
HEALTH INFORMATION
The following shall be inserted in full text in all solicitations and contracts (including commercial acquisitions) which require contractor unclassified access to federally controlled facilities, sensitive information, Information
Technology (IT) systems or protected health information. For commercial acquisitions, this text shall be incorporated into either the SOW or PWS.
The security text does not apply in cases where the contractor/vendor does not have access to Navy Marine
Corps Intranet (NMCI) computers, is not issued a Common Access Card (CAC) and is involved in training or other short term duties of less than 30 days duration that allow for the use of a visitor request. In these cases, the government employee must submit a Visitor Access Request (VAR) to the main gate or applicable processing entity for your facility and assume responsibility to escort those without CAC Credentials.
This local text does not apply to non-United States (U.S.) Nationals (foreign nationals) who are contactor employees performing work overseas. The local text is applicable to the U.S. Nationals living in the U.S. or overseas who are performing work on a Navy contract.
The investigation of a non-U.S. national at a foreign location must be consistent with a National Agency Check with Written Inquiries (NACI), to the extent possible and include a fingerprint check against the Federal Bureau of Investigation (FBI) criminal history database, an FBI investigations file (name check) search and a name check against the terrorist screening database. Also, the above cited reference notes that Foreign Nationals may not be granted CAC credentials until completion of their investigation and not in the interim.
Per Department of Defense Memorandum (DoDM) 5200.2, Department of Defense (DoD) components must initiate and ensure completion of a background investigation before applying the credentialing standards to a mailto:cashia.k.garland.civ@us.navy.mil non-U.S. national at a foreign location. The background investigation must be favorably adjudicated before a
CAC can be issued to a non-U.S. national at a foreign location. The type of background investigation may vary based on standing reciprocity treaties concerning identity assurance and information exchanges that exist between the U.S. and its allies or agency agreements with the host country.
CONTRACTOR UNCLASSIFIED ACCESS TO FEDERALLY CONTROLLED FACILITIES,
SENSITIVE INFORMATION, IT SYSTEMS OR PROTECTED HEALTH INFORMATION
Executive Order 13467, Reforming Processes Related to Suitability for Government Employee, Fitness for
Contractor Employees and Eligibility for Access to Classified National Security Information, Homeland
Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement Federal security standards for Federal employees and contractors. The 5 CFR 32 Part 157 in concert with DoD Manual
1000.13, Vol 1, implements the Federal Standards.
APPLICABILITY
This text applies to all DoD sponsored individuals who require CAC eligibility (or login and P/W if acceptable per contract) for: Physical access to DoD facilities or non-DoD facilities on behalf of DoD; Logical access to information systems (whether on site or remotely); or remote access to DoD networks that use only the CAC logon for user authentication, or access to sensitive and protected information. This applies to the Office of the
Secretary of Defense (OSD), the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the DoD, the Defense
Agencies, the DoD Field Activities and all other organizational entities within the DoD (hereinafter referred to collectively as the "DoD Components").
Each contractor employee providing services at a Navy command under this contract is required to obtain a
DoD CAC. Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.
ACCESS TO FEDERAL FACILITIES
Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command's Security Manager (CSM) upon arrival to the command and shall out-process prior to their departure at the completion of the individual's performance under the contract.
START-UP PERIOD
All contractor resource onboarding documents must be submitted via the prime contractor. The prime contractor shall make all necessary preparations to assume full responsibility for productive performance as of the performance start date.
Definition of "productive":
a. Visit Authorization Request (VAR)
b. Contractor Information Sheet (CIS)
c. FD-258 Fingerprint Card
d. Completed Electronic Investigation (EQIP)
e. All contractor resource(s) must have an active Joint Personnel Adjudication System (JPAS) profile
f. Common Access Card(CAC)
Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services and no reimbursement will be paid by the government for efforts expended during the start-up period.
Note (2): Foreign Nationals are not allowed access to the functional/system side of Enterprise Resource
Planning (ERP).
ACCESS TO DOD INFORMATION TECHNOLOGY (IT) SYSTEM
In Accordance With (IAW) Secretary of the Navy (SECNAV) M-5510.30, contractor employees who require access to Department of the Navy (DoN) or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to sensitive information. Sensitive information includes information protected under the Privacy Act, to include PHI. All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II. IT Levels are determined by the requiring activity's Command Information
System Security Manager (ISSM)/Information Assurance Manager (IAM).
Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) or T5 or T5R equivalent investigation, which is a higher level investigation than the National Agency Check (NAC) with Law and Credit (NACLC)/T3/T3R described below. Due to the privileged system access, an investigation suitable for High Risk national security positions is required. Individuals who have access to system control, monitoring, or administration functions
(e.g. system administrator, database administrator) require training and certification to Information Assurance
(IA) Technical Level 1, and must be trained and certified on the Operating System (OS) or Computing
Environment (CE) they are required to maintain.
Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the contractor employee's duties, such employees shall in-process with the Navy CSM and ISSM/IAM manager upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual's performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy IT resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-N; therefore, the government employee with knowledge of the system/network access required or the Contracting Officers Representative
(COR) shall sign the SAAR-N as the supervisor.
The SAAR-N shall be forwarded to the CSM at least thirty (30) days prior to the individual's start date. Failure to provide the required documentation at least thirty (30) days prior to the individual's start date may result in delaying the individual's start date.
When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Cyber Awareness training, and maintain a current requisite background investigation. The contractor's security representative shall contact the CSM for guidance when reinvestigations are required.
INTERIM ACCESS
The CSM may authorize issuance of a DoD CAC and interim access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.
DENIAL OR TERMINATION OF ACCESS
The potential consequences of any requirement under this clause including denial or termination of physical or system access in no way relieves the contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall plan ahead in processing their employees and subcontractor employees. The contractor shall insert this clause in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally-controlled information system/network and/or to government information, meaning information not authorized for public release.
CONTRACTOR'S SECURITY REPRESENTATIVE
The contractor shall designate an employee to serve as the contractor's security representative. Within three (3) work days after contract award, the contractor shall provide to the requiring activity's Security Manager and the
Contracting Officer, in writing, the name, title, address and phone number for the contractor's security representative. The contractor's security representative shall be the primary point of contact on any security matter. The contractor's security representative shall not be replaced or removed without prior notice to the
Contracting Officer and CSM.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS
FOR CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS OR PERFORMING
SENSITIVE DUTIES
Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Contractor employees under this contract are recognized as
Non-Critical Sensitive [ADP/IT-II] positions when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and PHI, provide support associated with fiduciary duties, or perform duties that have been identified as
National Security Positions. At a minimum, each contractor employee must be a US citizen and have a favorably completed NACLC or T3 or T3R equivalent investigation to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The investigation consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each contractor employee filling a non-critical sensitive or IT-II position is required to complete:
• SF-86 Questionnaire for National Security Positions (or equivalent Office of Personnel Management
(OPM) investigative product)
• Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission
• Original Signed Release Statements
Failure to provide the required documentation at least thirty (30) days prior to the individual's start date shall result in delaying the individual's start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than ten (10) years) throughout the contract performance period. The contractor's security representative shall contact the CSM for guidance when reinvestigations are required.
Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the CSM upon arrival to the command and shall out-process prior to their departure at the completion of the individual's performance under the contract. Employees requiring IT access shall also check-in and check-out with the Navy command's ISSM/IAM. Completion and approval of a SAAR-N form is required for all individuals accessing
Navy IT resources. The SAAR-N shall be forwarded to the Navy CSM at least thirty (30) days prior to the individual's start date. Failure to provide the required documentation at least thirty (30) days prior to the individual's start date shall result in delaying the individual's start date.
The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual Cyber Awareness training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the CSM. The CSM will review the submitted documentation for completeness prior to submitting it to the OPM; Potential suitability or security issues identified may render the contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The CSM will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by
OPM to the DoD Central Adjudication Facility (CAF) for a determination.
If the contractor employee already possesses a current favorably adjudicated investigation, the contractor shall submit a VAR via the JPAS or a hard copy VAR directly from the contractor's security representative. Although the contractor will take JPAS owning role over the contractor employee, the Navy command will take JPAS
"Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract. The contractor shall include the IT position category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee's performance under the contract.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS
FOR CONTRACTORS ASSIGNED TO OR PERFORMING NON-SENSITIVE DUTIES
Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc...) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:
• Must be either a U.S. citizen or a U.S. permanent resident with a minimum of 3 years of legal residency in the U.S. (as required by the Deputy Secretary of Defense DTM 08-006 or its subsequent
DoD Instruction (INST)) and
• Must have a favorably completed NACI or T1 investigation equivalent including a FBI fingerprint check prior to installation access.
To be considered for a favorable trustworthiness determination, the CSR must submit for all employees each of the following:
• SF-85 Questionnaire for Non-Sensitive Positions
• Two FD-258 Applicant Fingerprint Cards (or an electronic fingerprint submission)
• Original Signed Release Statements
The contractor shall ensure each individual employee has a current favorably completed NACI or T1 equivalent investigation, or ensure successful FBI fingerprint results have been gained and investigation has been processed with OPM.
Failure to provide the required documentation at least thirty (30) days prior to the individual's start date may result in delaying the individual's start date.
Consult with your CSM and ISSM/IAM for local policy when IT-III (non-sensitive) access is required for non-
U.S. citizens outside the U.S.
(End of Text)
File details come from the government source that posted it. Updated .