Drafted PWS_W9124J-25-R-BCFM.pdf
PDF 334 KB Posted
- Attached to
- Base Realignment and Closure Financial Module (BRAC FM) Federal contract opportunity
- Solicitation number
- W9124J-25-R-BCFM
About this file
This Performance Work Statement (PWS) details a non-personal services contract for the Army's Base Realignment and Closure Financial Module (BRAC FM) system. The contract requires a contractor to maintain and update the BRAC FM, a web-based application hosted on the Azure cloud that manages automated funds requests for the BRAC program, and maintain the public-facing BRAC website. The primary objectives include updating system functionality, ensuring compliance with information assurance and security standards, and providing technical support for the BRAC Division.
The contract is structured as a firm fixed-price agreement with a base year and four optional 12-month extension years, running from June 2025 to June 2030. Key requirements include modifying the BRAC FM to facilitate funds distribution, updating Army Management Structure Code data, performing monthly execution data updates, and maintaining comprehensive system documentation. The contractor must ensure system compliance with DoD and Army IT regulations, perform regular security vulnerability assessments, and provide monthly progress reports. Contractor personnel must have specific technical qualifications, including bachelor's degrees, proficiency in various Microsoft technologies, and certifications in information assurance and system administration.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSN_W9124J25RBCFM_3.31.25.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
Base Realignment and Closure Financial Module (BRAC FM)
Part 1
General Information
1. General: This is a non-personal services contract for the Headquarters, Department of the Army (HQDA), Deputy Chief of Staff (DCS), G-9, Base Realignment and Closure (BRAC) office. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.
1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to maintain and provide functionality for the BRAC Financial Module (FM) and to maintain the public-facing BRAC website as defined in this Performance Work Statement except for those items specified as government furnished property and services. The contractor shall perform to the standards in this contract.
1.2 Background: The BRAC FM (AITR #DA05452) is a web-based application hosted on the ALTESS Azure cArmy cloud on NIPRNET. It is a central repository for coordinating and managing automated requests to issue or return funds (i.e. funds requests) in support of BRAC program requirements. BRAC FM provides the BRAC Division, Army Commands (at the installation level), and US Army Corps of Engineers (USACE) the ability to initiate and submit automated funds requests to the BRAC Division Resource Management Branch (RMB). The RMB then reviews, validates, and transmits the funds requests to the Army Budget Office (ABO) for final approval and funds distribution (or withdrawal). BRAC FM is the only web-based application available to the BRAC Division to manage funds requests. The current hardware and software configuration for the BRAC FM are as follows:
• Windows 2012 datacenter, SQL server 2014, IIS 8.5 for the IaaS environment.
• Certificates required: DoD approved 8570 Baseline Certification. IA Technical
Level II (GSEC or Security+ CE or SSCP or CCNA-Security) and CE/OS Certificate.
1.3 Objectives: To update and maintain the BRAC FM System and maintain BRAC’s public website. Updates and maintenance will be in accordance with G9 website standards- and American Disability Act complaint, section 508.
1.4 Scope: The Contractor shall provide non-personal services to include personnel, management, labor, materials, equipment, and other services, that are necessary to perform all operation and maintenance functions to support the BRAC FM, including-management, technical, and analytical support services as set forth in this PWS. The contractor will also enhance and maintain and update the BRAC public web site.
1.5 Period of Performance: The period of performance shall be for one (1) Base Year of
12 months and four (4) 12-months option years. However, the Government reserves the right to extend the term of the contract in accordance with (IAW) Federal Acquisition Regulation (FAR) clause 52.217-8, Option to Extend Services. The Period of Performance reads as follows:
Phase In (1 month): 30 Jun 2025 – 30 July 2025 Base Year (11 months): 31 July 2025 – 30 Jun 2026 Option Year 1: 01 July 2026 – 30 Jun 2027 Option Year 2 01 July 2027 – 30 Jun 2028 Option Year 3: 01 July 2028 – 30 Jun 2029 Option Year 4: 01 July 2029 – 30 May 2030 Phase Out: (1 month): 31 May 2030 – 30 June 2030 FAR 52.217-8 (6 months): 01 July 2030 – 30 Dec 2030
1.6 General Information
1.6.1 Quality Control: The contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services in accordance with FAR 52.246-4, Inspection of Services-Fixed Price. The contractor’s quality control program is the means by which he assures himself that his work complies with the requirements of the contract. The QC Plan will be included in the original proposal. After acceptance of the quality control plan the contractor shall receive the contracting officer’s acceptance in writing of any proposed change to his QC system.
1.6.2 Quality Assurance: The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s). This is an internal government surveillance plan and will not be shared with the contractor.
1.6.3 Recognized Holidays: The contractor is not required to perform services on the following holidays:
New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day President’s Day Veteran’s Day Memorial Day Thanksgiving Day Juneteenth Day Christmas Day Independence Day
1.6.4 Hours of Operation: The contractor is responsible for being responsive to Government, between the hours of 8:00A.M. to 5:00P.M Eastern Standard Time (EST)
Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. For other than firm fixed price contracts, the contractor will not be reimbursed when the government facility is closed for the above reasons. The Contractor shall at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.
1.6.5 Place of Performance: The preponderance of the work under this contract may be accomplished off-site and will generally not be under direct Government supervision. However, in order to assure responsiveness to the BRAC FM, the contractor shall be prepared to provide onsite support, when necessary, for this effort. When onsite support is required the primary place of performance for this effort is in G-9 offices located within the Pentagon. When such performance is required, the COR will facilitate proper access to the Pentagon, subject to all security requirements, and designate the necessary office space and equipment for contractor employee use.
1.6.6 Type of Contract: The government will award a Firm Fixed Price (FFP) contract.
1.6.7. Security Requirements:
1.6.7.1. This is an unclassified contract. There are no requirements for Contractor employee to have access to classified Government information in the performance of this contract effort.
1.6.7.2. When required by the Government representative, if contractor personnel are required to provide full-time support on-site at secure Government facilities or attend meetings, a valid, interim or final Secret eligibility and access must be posted in the Defense Information System for Security (DISS) to gain access.
1.6.8. Personal Identity Verification (PIV).
1.6.8.1. The Contractor and its employees shall comply with PIV procedures implemented by Homeland Security Presidential Directive-12 (HSPD-12), Federal Information Processing Standards Publication (FIPS PUB) Number 201-1, Office of Management and Budget (OMB) Guidance M-05-24 and DCS, G-9.
1.6.8.2. The Contractor shall insert clause 52.204-9, as required by FAR 4.1303, in all subcontracts when the Subcontractor is required to have physical access to a Federally controlled facility or access to a Federally controlled information system.
1.6.8.3. In accordance with HSPD-12, OMB M-05-24 and FIPS 201-1, unless a previous favorable background investigation has been completed in the last ten (10) years, all contractor employees will be the subject of a background investigation conducted by the Government.
1.6.8.4. No contractor employee shall commence work until an appropriate personnel security questionnaire (PSQ) paperwork has been submitted to the Office of Personnel Management (OPM). Contractor employees not meeting the minimum PIV requirements of HSPD-12 and FIPS Pub 201-1 shall be the subject of a National Crime Information Center (NCIC) check prior to beginning work in addition to the submission of the PSQ to
OPM.
1.6.8.5 Non-US citizens will not be used in the performance of this contract unless the provisions of Army Regulation 25-2, Information Assurance have been fully completed and approval has been granted by the Government for the non-US citizen to perform the required support.
1.6.9. Visit Notifications.
1.6.9.1. If the Contractor has previously been granted a facility clearance (FCL) through Defense Counterintelligence and Security Agency DCSA, the Facility Security Officer (FSO) shall submit visit notifications via DISS.
1.6.9.2. If the Contractor is not cleared through DCSA, the Contractor shall submit a signed visit request on company letterhead stationery through the Government COR at least a week before visit. The request shall include the full name (last, first, middle), date of birth (MM/DD/YYYY), place of birth (city, state, country), citizenship, type of last investigation and date last investigation was completed, if any and shall be the subject of a National Crime Information Center (NCIC) check prior to beginning work.
1.6.10. All Contractor employees fulfilling the requirements of this contract are required to read and sign a Nondisclosure Statement prior to beginning work. Performance of this contract may require Contractor employees to access data and information proprietary to the Government agency or of such a nature that its dissemination or use, other than in performance of this contract, would be adverse to the interest of the Government and/or other persons or corporate entities to whom duties to protect private information may be owed. The Contractor shall educate its employees regarding the restrictions imposed by FAR 9.505-4 so that they will not use or disclose proprietary information or data generated or acquired in the performance of this contract except as provided herein.
1.6.11. All Contractor employees shall read all applicable security regulations, guidance and briefings, to be provided by the Government. Contractor personnel shall familiarize themselves with the Government’s regulations and policies and site-specific regulations regarding access to sensitive materials, computer facility/IT network access, issue of access credentials, etc., which shall be provided by the Government, as required.
1.6.12. Physical Security: The majority of work will be performed outside Government facilities at worksite(s) of the contractor’s choosing. In the event that the Contractor employee is required to work in a Government facility, including the Pentagon, the Contractor employee shall be responsible for safeguarding all Government property provided for contractor use, including any access credential issued to the employee. At the close of each work period, Government facilities, equipment, and materials shall be secured.
1.6.13. Access Credentials. The Contractor shall establish and implement methods of making sure all access credentials (Common Access Card (CAC); DD Form 1466, DoD Building Pass) issued to the Contractor employee by the Government are not lost or misplaced and are not used by unauthorized persons. No access credentials issued to the Contractor by the Government shall be duplicated.
1.6.13.1. The Contractor shall develop procedures covering access credentials that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued access credentials to Contractor employees who no longer require access to Government information systems or Government facilities. Failure of the Contractor to ensure Government issued access credentials are returned to the Government can result in delayed payment by the Government.
1.6.13.2. In the event access credentials are lost or damaged, the Contractor employee shall immediately notify the COR who will notify DCS G-9 Security of the loss or damage and request re-issue of the credential.
1.6.13.3. Multiple occurrences of lost or damaged access credentials by Contractor employees will be reported to the Contracting Officer. When the replacement of access credentials is performed by the Government, the total cost of re-issuing the credential(s) shall be deducted from the monthly payment due the Contractor.
1.6.13.4. The Contractor shall prohibit the use of Government issued access credentials by any persons other than the Contractor employee to whom the credential is issued. The Contractor shall prohibit the opening of secure or locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the DCS G-9 Security Office.
1.6.14 Identification of Contractor Employees. All Contractor employees attending meetings, answering Government telephones and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. Contractor employees shall also ensure that all documents or reports produced are suitably marked as Contractor products or that Contractor participation is appropriately disclosed. Contractor employees with assigned duties requiring on-site performance shall meet the requirements to obtain a Department of Defense building pass. Contractor employees requiring use of Government information systems or facilities must meet the criteria required to obtain a Common Access Card and building specific identification badge requirements/specifications.
1.6.15. Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with FAR Subpart 42.5. The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, will meet periodically, quarterly as a minimum, with the contractor to review the contractor's performance. At these meetings the contracting officer will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
1.6.16 Contracting Officer Representative (COR): The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies; coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.
1.6.17 Key Personnel: The following personnel are considered key personnel by the government: Program Manager, System Administrator, and Information System Security Officer. The contractor shall provide a program manager who shall be responsible for the performance of the work. The name of this person and an alternate who shall act for the contractor when the manager is absent shall be designated in writing to the contracting officer and COR. The program manager or alternate shall have full authority to act for the contractor on all contract matters relating to daily operation of this contract. The contract manager or alternate shall be available between 8:00 a.m. to 5:00p.m EST Monday thru Friday except Federal holidays or when the government facility is closed for administrative reasons. Contracting officer and COR are to be notified of any changes in Key Personnel within 24 hours of change. Qualifications of key personnel are as follows:
Program Manager: Must have a minimum of 10 years’ experience in managing information technology projects, contracts, funds, and resources. Must have in-depth knowledge and understanding of the Army’s BRAC program, its complex program and management structure, and systems. Exercises a broad range of sound project management principles and judgment in analyzing unique problems and issues specific to developing, managing, and implementing financial management and management information systems. Identifies strengths and weaknesses and develops recommendations for improvement through the application of project management techniques and technology. Must have a comprehensive knowledge of the financial laws, policies, and regulations that govern the Army BRAC accounts. Must have an expert knowledge of analytical and evaluative methods and techniques, to include qualitative and quantitative analysis, conduct comprehensive studies, and develop assessments, recommendations, and position statements. Must have the skills and ability to develop and present complex presentations. Must have excellent written and oral communication, analysis, and interpersonal relationship skills.
Minimum Education Requirement: Bachelor of Arts or Bachelor of Science degree from an accredited university or other equivalent degree program experience and possess Project Management Professional (PMP) Certification.
1.6.18 The Government will provide contractor personnel a Government-hosted e-mail account with address alias or directory entry including word “contractor” in the address/directory. The email will be used for official business under this contract and the contractor will ensure that all email include a signature block indicating their contractor status, e.g. “Smith, Bob (Contractor) with the full company name.
1.6.18.1. System Administrator: At least one Contractor employee shall obtain and maintain the training necessary to perform server administrator tasks and stay current with emerging administrator requirements (see 5.2). Upon award, the Contractor shall have obtained the necessary certifications and requirements in order to have access to the network and servers that BRAC FM and the BRAC website utilize. The Contractor shall maintain the necessary certification and requirements throughout the life of the contract.
1.6.18.2. Information System Security Officer (ISSO): The Contractor shall assume the role of ISSO. Upon award, the Contractor shall follow the requirements of DoD 8570.01- M, Information Assurance (IA) Workforce Improvement Program and maintain compliance throughout the life of the contract. The Contractor shall work with designated personnel in the DCS, G-9 Information Technology Directorate to ensure BRAC FM maintains compliance with all required tests and updates in support of the certification and accreditation of BRAC FM. The Contractor shall perform annual tests on BRAC FM such as the Contingency Test, Disaster Recovery and Security Control Test, Annual Security Controls Testing and Annual Security Review. The Contractor shall serve as an Installation System Security Officer providing support to the BRAC Program Manager in support of the DoD Risk Management Framework (RMF) Authorization Process, to include completing registration and update efforts within the Enterprise Mission Assurance Support Service (eMASS) system, in support of Army Portfolio Management Solution (APMS) system updates, and in regard to updates to the BRAC Business System Architecture documentation.
1.6.19 Contractor Travel: Contractor personnel will not be required to travel.
1.6.20 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in the FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may require other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the
OCI.
1.6.21. PHASE-IN /PHASE-OUT PERIOD: To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the Contractor shall have personnel on board, during the thirty (30) day phase-in/ phase-out periods. During the phase in period, the Contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date. The Government intends to allow 30 days for phase-in / phase-out. The phase-in / phase-out period shall be in accordance with Section I, FAR 52.237-3, Continuity of Services. This period is intended for the establishment of operations and infrastructure in preparation for full contract performance and to minimize any decreases in productivity and to prevent possible negative impacts. The Contractor shall have all “Key Personnel”, as referenced in 1.6.18, ready for full performance within 3 days of Date of Award. The Contractor shall be familiar with the performance requirements summary (Technical Exhibit 1) in order to commence full performance of services on the contract start date.
1.6.22. ANTI-TERRORISM AND OPERATIONS SECURITY REQUIREMENTS
1.6.22.1. AT Level I Training. All Contractor employees, to include subcontractor employees, requiring access to Army installations, facilities and controlled access areas shall complete AT Level I awareness training within 30 calendar days after contract start date, and annually after. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the contracting officer, if a COR is not assigned, within 15 calendar days after completion of training by all employees and subcontractor personnel. https://jkodirect.jten.mil Course #
JS-US007-14.
1.6.22.2 iWATCH Training. The Contractor and all associated sub-contractors shall brief all employees on the local iWATCH program (training standards provided by the requiring activity ATO). This local developed training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 calendar days of contract award and within 15 calendar days of new employees commencing performance with the results reported to the COR NLT 45 calendar days after contract award. COR will provide training slide deck.
1.6.223.3 Contractor Employees Who Require Access to Government Information Systems. All contractor employees with access to a government info system must be registered in the ATCTS (Army Training Certification Tracking System) at commencement of services and must successfully complete the DOD Information Assurance Awareness prior to access to the IS and then annually thereafter.
1.6.22.4 For Task orders that Require OPSEC Training. Per AR 530-1, Operations Security, new Contractor employees must complete Level I OPSEC training within 30 calendar days of their reporting for duty. All Contractor employees must complete annual OPSEC awareness training. and adhere to organization’s security program.
https://securityawareness.usalearning.gov/opsec/index.htm
1.6.22.5 For information assurance (IA)/information technology (IT) certification. Per DoD 8570.01-M, DFARS 252.239.7001 and AR 25-2, the Contractor employees supporting IA/IT functions shall be appropriately certified upon contract award. The baseline certification as stipulated in DoD 8570.01-M shall be completed upon contract award.
1.6.22.6 Threat Awareness Reporting Program. Threat Awareness Reporting Program.
For all contractors with security clearances. Per AR 381-12 Threat Awareness and Reporting Program (TARP), contractor employees must receive annual TARP training (https://learn.atis.army.mil/ .
1.6.22.7 For contractors requiring Common Access Card (CAC). Before CAC issuance, the contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.
1.6.23 Data Rights (If applicable): The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials shall not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property https://securityawareness.usalearning.gov/opsec/index.htm of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.6.23.1 Any database and software developed as part of this contract becomes the property of the U.S. Government, and the U.S. Government retains the rights to all intellectual property (e.g. Patentable items and copyrighted materials) purchased or developed through this effort. The Contractor shall make available to the U.S.
Government draft and final copies of all publications based on the work performed under this contract in hard and electronic format as defined by the Government. All products, source code and scripts produced, and their associated work papers are to be considered the property of the U.S. Government. The Contractor shall provide all products, source code, software and documentation developed in accordance with this contract and integral to the continued operation and full-functionality of any program or system to the DCS G-9 upon request. All hardware and software purchased under this contract is the property of the Government and shall be turned over to the Government no later than the end date of this contract. All licenses shall be in the Government’s name and the licenses’ terms cannot violate federal law or regulation.
1.6.23.3 The Contractor’s firm and the non-key personnel assigned to work these contract tasks shall have recent and/or current working experience with DoD real policies, practices, and procedures. The work associated with this contract is highly complex in nature. The work is advanced in nature and does not lend itself to Contractor personnel that are wholly unfamiliar with the topic. As such, it is recommended that Subject Matter Experts (SME) assigned to work these tasks shall have a minimum of three (3) years of work experience with DoD real property lifecycle management. SMEs are not considered key personnel but work directly with Contract Manager and Real Property Analysis Data Lead in support of day-to-day contract management and customer support (e.g., ad hoc queries, trend analysis, quality assurance / quality control). The Contractor shall assign a Contract Manager to oversee execution of work.
1.6.23.4 All Contractor employees shall be functionally proficient in Microsoft Word, Microsoft Excel, Microsoft Power BI, Microsoft PowerPoint, Microsoft Visio, Microsoft Outlook, Microsoft Access, Adobe Acrobat and Internet Explorer (or a comparable internet browser application).
1.6.23.5 The specific Contractor employees who will directly support BRAC FM system operations shall collectively be functionally proficient, at the least, in Microsoft SQL Server, Microsoft SQL Server SQL Server Reporting Services (SSRS), Microsoft Visual Studio, Microsoft Internet Information Services (IIS), Microsoft .NET Framework, Business Objects Crystal Reports Developer Edition, Data Dynamics ActiveReports, Aspose.Slides for .NET, Websites Screenshot DLL.
1.6.23.6 All key and non-key personnel shall have a bachelor's degree from an accredited college or university due to the extensive analytical requirements of the contract tasks.
Work experience is not a replacement for a completed bachelor’s degree. Additional qualifications are required for key personnel as noted in the key personnel table in section 1.6.19.
1.6.24 SECTION 508 COMPLIANCE. IAW FAR 39.2, BRAC shall be compliant with Section 508, an amendment to the United States Workforce Rehabilitation Act of 1973.
The Contractor shall ensure all BRAC applications are accessible to people with disabilities and that current and future requirements to maintain compliance with Section 508 are met.
PART 2
DEFINITIONS & ACRONYMS
2. DEFINITIONS AND ACRONYMS:
2.1. DEFINITIONS:
2.1.1. AUTHORITIVE DATA SOURCE (ADS). An ADS is a recognized or official data production source with a designated mission statement or source/product to publish reliable and accurate data for subsequent use by users. An ADS may be the functional combination of multiple or separate data sources and provides enterprise-accepted and trusted information for reuse, analysis, and aggregation, which ultimately leads to accurate choices, rapid decisions, and a wealth of knowledge. Once a proposed source is certified by the Army Data Council as authoritative, it is registered in the ADS Registry so users can determine which of many sources containing information is authoritative and ensures the user of the most accurate, timely, trusted data.
2.1.2.AUDITABLE SOURCE SYSTEM. An auditable source system is one where information is first recorded from the original documents and/or business process.
Auditable source documents substantiate the integrity of the data being used.
2.1.3.CONTRACTOR. A supplier or vendor having a contract to provide specific supplies or services to the government. The term used in this contract refers to the prime.
2.1.4.CONTRACTING OFFICER. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. Note: The only individual who can legally bind the government.
2.1.5. CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S. Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations.
This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.6. DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.
2.1.7. DELIVERABLE. Anything that can be physically or electronically delivered but may include non-physical things such as meeting minutes.
2.1.8. KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.9 GOVERNMENT-FURNISHED PROPERTY (GFP) OR GOVERNMENT
PROPERTY. Property in the possession of, or directly acquired by, the Government and subsequently made available to the Contractor.
2.1.10. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
2.1.11. QUALITY ASSURANCE. The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
2.1.12. QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.
2.1.13. QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.
2.1.14. SUBCONTRACTOR. One that enters into a contract with a prime contractor.
The Government does not have privity of contract with the subcontractor.
2.1.15. WORKDAY. The number of hours per day the Contractor provides services in accordance with the contract.
2.1.16. WORK WEEK. Is defined as Monday through Friday, unless specified otherwise.
2.2. ACRONYMS:
ABO Army Budget Office ACL Access Control List AFARS Army Federal Acquisition Regulation Supplement AMSCO Army Management Structure Code APMS Army Portfolio Management System AR Army Regulation BRAC Base Realignment and Closure BRAC FM Base Realignment and Closure Financial Module CAC Common Access Card CFR Code of Federal Regulations CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTS Commercial Off the Shelf DA Department of the Army DAIM Department Analysis Information Memorandum
DCS, G-9 Deputy Chief of Staff, G-9 DB Database DFARS Defense Federal Acquisition Regulation Supplement DFAS Defense Finance and Accounting Service DOD Department of Defense EBS Enterprise Business System eMASS Enterprise Mission Assurance Support Service FAR Federal Acquisition Regulation FCS Funds Control System FISMA Federal Information Security Management Act FIPS Pub Federal Information processing Standards Publication FSC Federal Service Code GFEBS General Fund Enterprise Business System HSPD Homeland Security Presidential Directive IAW In Accordance With IATO Interim Authority to Operate ITI Information Technology Infrastructure KO Contracting Officer NCIC National Crime Information Center NLT Not Later Than OCI Organizational Conflict of Interest O&M Operations & Maintenance OMB Office of Management and Budget OPM Office of Personnel Management PIPO Phase In/Phase Out PIV Personal Identity Verification POC Point of Contact PRS Performance Requirements Summary PSQ Personnel Security Questionnaire PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Program RMF Risk Management Framework SQL Structured Query Language TE Technical Exhibit UIC Unit Identification Code USACE United States Army Corps of Engineers WAWF Wide Area Workflow- a secure Web-based system for electronic invoicing, receipt and acceptance.
XML Extensible Markup Language
PART 3
GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
3. GOVERNMENT FURNISHED ITEMS AND SERVICES:
3.1 Government Property.
3.1.1 Government Furnished Property (GFP): The Government will provide two computers under this contract, as they must use GFP to access government systems. The GFP will have a current HQDA network operating system image including the Microsoft Office suite installed and a CAC reader to allow for VPN access. Within five (5) business days of contract award, the contractor shall provide a list of all personnel on the contract that will (1) require a GFP, (2) require access to the network, and (3) who will require server access (requires a separate token). The Contractor shall be responsible for the safekeeping of all GFP. The Contractor shall reimburse the Government for any loss or damage of GFP.
3.1.2 The Contractor shall be responsible for ensuring updates occur on the GFE in order to keep the laptops current on the HQDA enterprise network. Updates will be obtained via VPN connection to the HQDA Network for a minimum of 4-6 hours per connection to ensure updates are completed.
3.1.2.1. The Contractor shall return GFE upon termination/expiration of the contract.
3.1.2.2. The COR will hand receipt all GFE to Contractor. The COR will monitor and control all GFE tracking by conducting a semi-annual inventory and periodic visual inspections.
3.1.3 Government Furnished Software Packages. The Government will provide the production web hosting equipment necessary to support the system requirements under this contract. The following major commercial software packages may be available for contractor use:
• SQL Server 2014
3.1.4 Government Furnished Credentials: The contractor shall submit a consolidated package with all completed paperwork required for all contractors requiring CAC cards, network access and/or server access within five (5) business days of contract award.
PART 4
CONTRACTOR FURNISHED ITEMS AND SERVICES
4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES:
4.1 General: The Contractor shall furnish all supplies, equipment, facilities, and services required to perform work under this contract that are not listed under Part 3 of this PWS.
PART 5
SPECIFIC TASKS
5. Specific Tasks: Under no circumstances shall the term “assist” imply personal services; nor shall the terms “analysis” or “assess” imply that the Contractor shall have any responsibility to make an actual judgment or recommendation on the issues/items involved. For tasks detailed below, the Contractor shall maintain detailed task job aids in Microsoft Word with step-by-step instructions explaining the steps needed to complete the task. It should be noted that the level of effort for this requirement is subject to change and may be increased/decreased at the discretion of Army leadership.
5.1. Basic Services. The contractor shall provide services to support the DCS, G9 BRAC FM and the BRAC website.
5.2. BRAC Financial Module (BRAC FM)
5.2.1 The Contractor shall modify and update the existing BRAC FM to facilitate distribution of BRAC funds. The contractor shall modify and update BRAC FM tables and migrate, if required, the BRAC FM reporting function. Modifications shall be IAW BRAC Resource Management and Army Budgeting Office (ABO) policies.
5.2.2 The Contractor shall update BRAC FM Army Management Structure Code (AMSCO) data, on as needed basis. This update will be provided by ABO and/or the Defense Finance and Accounting Service (DFAS) – Indiana (IN). Updates shall be completed NLT twenty-four (24) hours/one working day of receiving the data.
5.2.3 The Contractor shall update, on a monthly basis, the information comprising BRAC execution data. The update will include coordination with representatives from ABO, DFAS-IN, and the ABO, assembling revised information from corporate sources and action officers, and entering the information into BRAC FM. This update shall be performed within ten (10) days from receiving the data from ABO.
5.2.4 The Contractor shall respond to telephonic requests for assistance from the BRAC Division, Army Commands, ABO, USACE, IMCOM installations and IMCOM HQ in the functionality and use of the BRAC FM. As required, the Contractor shall provide a written response to requests for assistance, requests for ad hoc reports or for other data analysis not otherwise available.
5.2.5 The Contractor shall update all BRAC FM functional and technical documentation to include all DoD Information Assurance Certification and Accreditation Process (DIACAP) related documentation.
5.2.6 The Contractor shall maintain and update, when necessary, BRAC FM’s Risk Management Framework (RMF) status. Contractor must meet Federal Information Security Modernization Act (FISMA) requirements. Contractor shall support requirements of Army Portfolio Management Solution (APMS).
5.2.6 Reporting Requirements:
5.2.6.1 Monthly Progress Reports. The Contractor shall submit monthly progress reports to the COR or Contracting Officer if the COR is not available. The monthly reports shall include an accurate, up-to-date account of all work performed by specific tasks for the reporting period; planned work to be accomplished by specific tasks during the subsequent reporting period; and any outstanding issues that need to be addressed by the Contractor and/or the Government.
5.2.6.2 The Contractor shall deliver, maintain, and assist in developing the followingsystem documentation (updated annually)
5.2.7 The Contractor shall deliver, maintain, and assist in developing the following documents that are provided for the Contractor team and BRAC FM PM’s office to ensure programmatic continuity:
5.2.7.1. Bi-annual update of the Standard Operating Procedures (SOPs) (updated annually for each component)
5.2.7.2. Annual update of the continuity books and key task job aids for each BRAC FM component and major event (updated annually)
5.2.8 Systems Support, Software and Data Management: The Contractor shall provide systems administration support for BRAC FM. The Contractor shall ensure that BRAC FM servers and business systems are configured and maintained in compliance with DoD and Army IT regulations to ensure confidentiality, integrity, and availability. The Contractor shall ensure the systems are configured in compliance with current network protocols so DCS, G-9 staff, and users are able to utilize the DCS, G-9 business systems to accurately plan and support requirements.
5.2.8.1. System Administration. The Contractor shall maintain BRAC FM virtual/cloud services and software components on the network and ensure business applications are reliable, available, maintainable, and responsive to user requirements 95% of the time during business hours daily.
5.2.8.2. The Contractor shall ensure business applications meet the specified security and vulnerability standards by applying all required software patches, system updates, and upgrading software versions. The Contractor shall maintain BRAC FM, through system testing and implementation, to support recurring information assurance vulnerability management (IAVM) and computing environment security patches as determined by DCS, G-9, JSP, CYBERCOM, or DISA, needed to fully support the business processes to include monthly information assurance vulnerability alerts (IAVAs) or published security technical implementation guides (STIGs).
5.2.8.3. The Contractor shall perform quarterly server configuration for application installation, software installation, upgrades and IAVA patch management. The Contractor shall be required to configure servers as needed to update STIGs.
5.2.8.4. The Contractor shall perform quarterly requirements analysis on server resource requirements including processors and random-access memory (RAM) storage requirements and coordinate requirements with business application support teams and JSP. The Contractor shall perform requirements analysis prior to a technical refresh cycle and as needed when there are system enhancements or changes to the system.
5.2.8.5. The Contractor shall perform weekly reviews to the software log files (transactions between servers) for potential problems and security issues.
5.2.8.6. The Contractor shall support vulnerability alert processes IAW DoD 8500.01 for maintaining information system certification and accreditation (C&A) on the Army network every three (3) years unless a major change is made to the system. The Contractor shall perform the following tasks: create and organize documentation required to comply with hosting environment requirements; and address any vulnerabilities;
execute security readiness review (SRR) scripts and address any vulnerabilities. The Contractor shall provide the Government with a monthly Security Vulnerabilities report, which shall be stored on the government network.
5.2.8.7. The Contractor shall create and manage BRAC FM user accounts and provide technical assistance to system end users, and support teams for other DCS, G-9 business systems.
5.2.8.8. The Contractor shall maintain the following system documentation and shall no less than annually complete: contingency plans; network diagrams; and software system configuration requirements and technical documentation to include code, algorithms, application program interfaces (APIs) and user manuals.
5.2.8.9. The Contractor shall report all system downtimes that are not a part of regular scheduled outages immediately (within one hour during business hours) to the COR/Program Manager including when a system fails to provide or perform its primary function. The Contractor shall have all mission support systems that are mission assurance category III (MAC III) operating within three (3) to five (5) business days IAW DoDI 8500.01 The Contractor shall submit a system’s outage report to the COR/Program Manager outlining duration and remedy.
5.2.8.10. The Contractor shall coordinate security patch implementation and software upgrades to maintain IAVM compliance, report compliance to the Pentagon Computer Incident Response Team (PENTCIRT) and address vulnerabilities identified in the network scans completed by JSP. The Contractor shall submit a monthly technical report on all critical and high vulnerabilities to the PM. The report shall be stored on the government network.
5.2.8.11. The Contractor shall ensure all system administration activities will support compliance with DoD and Army regulations.
5.2.8.12. The Contractor shall work with the staff from the DCS, G-9 business applications to maintain compliance with the requirements imposed by the Army. DCS, G-9 servers and business systems are configured and maintained in compliance with DoD and Army IT regulations to ensure confidentiality, integrity and availability.
5.2.8.13. The Contractor shall ensure the systems are configured in compliance with current JSP and Defense Information Systems Agency (DISA) network protocols so that DCS, G-9 staff, and users are able to utilize the DCS, G-9 business systems to accurately plan and support installation management requirements.
5.2.8.14. The Contractor shall communicate all scheduled system outages to system users with 24 hours minimum notice.
5.2.8.15. The Federal Information Security Management Act (FISMA) requires that all systems on DoD networks operate with valid network authorizations (ATO/IATOs) to complete Annual Contingency Tests, Security Controls Test, and Annual Security Reviews. To ensure BRAC remains FISMA compliant, the Contractor shall execute the requisite Annual Security Review, Contingency Test, and Security Control Test with the accompanying Memorandums for Record for signature by the Government PM. These reviews include the annual update of the BRAC FM Contingency Operations Plan, Information Assurance Vulnerability Management Plan, and Incident Response Plan. The Contractor shall maintain all FISMA documents on the government network. The Contractor shall complete and submit of all FISMA requirements to DCS G9 Information Technology Directorate () prior to mandated suspense date.
5.2.8.16. The Contractor shall ensure that the BRAC FM system remains compliant with the OSD Business Enterprise Architecture (BEA) Acquire-to-Retire Process. The Contractor shall perform an annual analysis of the BEA business processes, data structure, data elements, requirements definition and data mapping in support of the consolidation of Army-wide real property and related data from source systems.
5.2.8.17. The Contractor shall complete all technical documentation and system documentation for BRAC server certification and approval by the Government Program Manager annually. The Contractor shall ensure BRAC FM server accreditation is completed in accordance with guidelines set forth by the DoD Risk Management Framework (DoDI 8510.01). The Contractor shall complete the requisite documentation for RMF compliance. The Contractor shall stay current on eMASS training requirements to perform security control assessments within eMASS. The Contractor operating in the capacity of the ISSO will be designated, per appointment memo, as one of the BRAC FM’s ISSOs.
5.2.9. The Contractor shall provide support for HQDA strategic briefs for senior leader review. The Contractor shall provide data extracts and commander’s comments in support of the HQDA senior leader strategic briefs/processes.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .