C_TFM2_2016-07-30.pdf

PDF 258 KB Posted

Attached to
Traffic Flow Management 2 (TFM2)- Request for Offer-SIR Federal contract opportunity
Solicitation number
DTFAWA-16-R-00010
Issued by
Department of Transportation Federal Aviation Administration Headquarters

About this file

C_TFM2_2016-07-30 (pdf)

View the file

Other files for this federal contract opportunity

Other files attached to Traffic Flow Management 2 (TFM2)- Request for Offer-SIR, newest first.
File Type Posted
L-2B Past Performance Survey Record TFM2 2016-06-10.pdf PDF
J-5.zip ZIP file
G_TFM2_2016-07-11.pdf PDF
B_TFM2_Amend-2_2016-09-22.xlsx XLSX spreadsheet
J-3Z Adaptation Files (2of2).2of2 —
J Attachment List Amend-2_2016-09-22.pdf PDF
TFM2_SIR-RFO_Amendment 003_Industry_Comment_Response_10-31-2016.pdf PDF
J-7 Labor Category Min Qualifications_2016-08-02.pdf PDF
J-2.zip ZIP file
M_TFM2_Amend-2_2016-09-27.pdf PDF
J-4B TFMS Commercial Software List Amend-1 2016-09-08.xlsx XLSX spreadsheet
F_TFM2_Amend-1_2016-08-25.pdf PDF
J6I sample ASDEX airport map PVD.zip ZIP file
L-2B Past Performance Survey Record TFM2 2016-06-10.pdf PDF
L-2C Past Performance Survey TFM2 Amend 1 2016-09-08_markup.pdf PDF
J-9 Task Order TFDM SE Amendment-1.pdf PDF
L-1_size-scope-complexity-summary_Amend-2_2016-09-23.pdf PDF
J5_L03-TMML-CDRL-DID_Amend-2.pdf PDF
I_TFM2_Amend-1_2016-08-23.pdf PDF
L-1_size-scope-complexity-summary_Amend-2_2016-09-23.pdf PDF
J-3 (1 of 2).1 of 2 —
M_TFM2_Amend-2_2016-09-27.pdf PDF
D_TFM2_2016-05-11.pdf PDF
J5_L03-TMML-CDRL-DID_Amend-2.pdf PDF
M_TFM2_Amend-1_2016-09-09.pdf PDF
A_TFM2_2016-08-03.pdf PDF
J-4A TFMS Site Equipment List.xlsx XLSX spreadsheet
H_TFM2_Amend-1_2016-08-25.pdf PDF
L-4 TFM2 Cost-Price Mapping Matrix_Amendment-1_ 2016-08-19.xlsx XLSX spreadsheet
J-4B TFMS Commercial Software List.xlsx XLSX spreadsheet
J-9 Task Order TFDM SE Amendment-1.pdf PDF
J Attachment List Amend-1_2016-09-09.pdf PDF
J-5.E07-SRS-CDRL-DID_Amendment-1.pdf PDF
J-3 (1 of 2).1 of 2 —
B_TFM2_2016-08-02.xlsx XLSX spreadsheet
L-2C Past Performance Survey TFM2 2016-06-10.pdf PDF
E_TFM2_2016-06-16.pdf PDF
J-9 Task Order TFDM SE_2016-06-01.pdf PDF
J-6.zip ZIP file
J-4A TFMS Site Equipment List.xlsx XLSX spreadsheet
J-5.zip ZIP file
J-5.zip ZIP file
I_TFM2_2016-08-02.pdf PDF
J-3 (1 of 2).1 of 2 —
J-8 TFM2 Program WBS 2015-10-22.pdf PDF
E_TFM2_2016-06-16.pdf PDF
L-2A Past Performance References TFM2 2016-06-10.pdf PDF
H_TFM2_2016-07-25.pdf PDF
C_TFM2_2016-07-30.pdf PDF
D_TFM2_2016-05-11.pdf PDF
Show all 50

Traffic Flow Management 2 (TFM2)- Request for Offer-SIR has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TFM-2 SIR DTFAWA-16-R-00010 Section C

PART I: Section C

Statement of Work (SOW) i

TABLE OF CONTENTS

C.1 PROGRAM SCOPE ..............................................................................................................................‐ 1 ‐

C.1.1 BACKGROUND ............................................................................................................................................. ‐ 1 ‐ C.1.2 PURPOSE ................................................................................................................................................... ‐ 2 ‐

C.2 APPLICABLE DOCUMENTS ..................................................................................................................‐ 2 ‐

C.2.1 SECURITY SPECIFIC ....................................................................................................................................... ‐ 2 ‐ C.2.2 TRAINING SPECIFIC ....................................................................................................................................... ‐ 4 ‐ C.2.3 OTHER ........................................................................................................................................................ ‐ 4 ‐

C.3 PROGRAM MANAGEMENT .................................................................................................................‐ 7 ‐

C.3.1 PROGRAM MANAGEMENT ORGANIZATION ....................................................................................................... ‐ 7 ‐ C.3.2 CONTRACT TRANSITION ................................................................................................................................ ‐ 7 ‐ C.3.3 PROGRAM MANAGEMENT PLAN (PMP) .......................................................................................................... ‐ 7 ‐ C.3.4 MEETINGS, REVIEWS, CONFERENCES, AND EVALUATIONS .................................................................................... ‐ 8 ‐

C.3.4.1 General Requirements .................................................................................................................. ‐ 8 ‐ C.3.4.2 Program Management Reviews (PMR) ........................................................................................ ‐ 8 ‐ C.3.4.3 Post‐Award Conference (PAC) ...................................................................................................... ‐ 9 ‐ C.3.4.4 Other Meetings ............................................................................................................................ ‐ 9 ‐

C.3.5 PROGRAM CONTROL .................................................................................................................................. ‐ 10 ‐ C.3.5.1 Contract Work Breakdown Structure (CWBS) ............................................................................ ‐ 10 ‐ C.3.5.2 Earned Value Management System (EVMS) .............................................................................. ‐ 10 ‐ C.3.5.3 Integrated Baseline Review (IBR) ............................................................................................... ‐ 10 ‐ C.3.5.4 Performance Measurement ....................................................................................................... ‐ 11 ‐ C.3.5.5 Quality Assurance (QA) .............................................................................................................. ‐ 11 ‐ C.3.5.6 Configuration Management (CM) .............................................................................................. ‐ 12 ‐

C.4 SECURITY ......................................................................................................................................... ‐ 13 ‐

C.4.1 GENERAL ................................................................................................................................................. ‐ 13 ‐ C.4.2 OPERATIONS SUPPORT ............................................................................................................................... ‐ 14 ‐

C.5 ENGINEERING, DESIGN AND DEVELOPMENT .................................................................................... ‐ 15 ‐

C.5.1 ENGINEERING SERVICES .............................................................................................................................. ‐ 15 ‐ C.5.2 REQUIREMENTS ANALYSIS AND DEVELOPMENT ................................................................................................ ‐ 16 ‐ C.5.3 SYSTEM‐LEVEL DESIGN ............................................................................................................................... ‐ 17 ‐ C.5.4 DETAILED DESIGN ...................................................................................................................................... ‐ 18 ‐ C.5.5 DEVELOPMENT .......................................................................................................................................... ‐ 18 ‐ C.5.6 HUMAN FACTORS ...................................................................................................................................... ‐ 19 ‐

C.6 RESERVED ........................................................................................................................................ ‐ 19 ‐

C.7 TEST & EVALUATION ........................................................................................................................ ‐ 19 ‐

C.7.1 TEST TOOLS .............................................................................................................................................. ‐ 19 ‐ C.7.2 TEST ACTIVITIES ........................................................................................................................................ ‐ 19 ‐

C.7.2.1 WJHTC System Acceptance Test (WSAT) .................................................................................... ‐ 19 ‐ C.7.2.2 Support Government Test Activities ........................................................................................... ‐ 20 ‐ C.7.2.3 Key Site Acceptance Test (KSAT) ................................................................................................ ‐ 20 ‐ C.7.2.4 Site System Acceptance Test (SAT) ............................................................................................. ‐ 20 ‐ C.7.2.5 Development Program Trouble Report Working Group Support ............................................... ‐ 21 ‐ ii

C.8 IMPLEMENTATION ........................................................................................................................... ‐ 21 ‐

C.9 TRAINING ........................................................................................................................................ ‐ 22 ‐

C.9.1 TEST AND EVALUATION TRAINING PROGRAM REQUIREMENTS ............................................................................ ‐ 22 ‐ C.9.2 SYSTEM OPERATIONS TRAINING ................................................................................................................... ‐ 22 ‐ C.9.3 SECOND‐LEVEL ENGINEERING SUPPORT TRAINING ........................................................................................... ‐ 23 ‐ C.9.4 FIRST LEVEL MAINTENANCE AND OPERATIONAL TRAINING ................................................................................. ‐ 23 ‐ C.9.5 TRAINING UPDATES FOR SYSTEM REFRESHES AND UPGRADES............................................................................. ‐ 23 ‐

C.10 OPERATIONS AND MAINTENANCE ................................................................................................... ‐ 23 ‐

C.10.1 FIRST‐LEVEL SUPPORT ........................................................................................................................... ‐ 23 ‐ C.10.1.1 Help Desk ................................................................................................................................... ‐ 24 ‐ C.10.1.2 Daily Service Reviews (DSR)........................................................................................................ ‐ 25 ‐

C.10.2 SECOND‐LEVEL ENGINEERING (SLE) AND SUPPORT ..................................................................................... ‐ 25 ‐ C.10.2.1 SLE Meetings, Reviews, and Workgroups .................................................................................. ‐ 26 ‐ C.10.2.1.1 Operations Reviews ............................................................................................................... ‐ 26 ‐ C.10.2.1.2 SLE Work Request Review (WRR) ......................................................................................... ‐ 26 ‐ C.10.2.1.3 Operations Change Request Meetings................................................................................. ‐ 26 ‐ C.10.2.2 SLE Operations Support .............................................................................................................. ‐ 27 ‐ C.10.2.3 System and Software Support .................................................................................................... ‐ 29 ‐ C.10.2.4 Aeronautical Adaptation Data ................................................................................................... ‐ 31 ‐ C.10.2.5 Root Cause Analysis (RCA) .......................................................................................................... ‐ 32 ‐ C.10.2.6 Disaster Recovery Center (DRC) ................................................................................................. ‐ 32 ‐

C.10.3 LOGISTICS SUPPORT .............................................................................................................................. ‐ 33 ‐ C.10.3.1 Commercial Hardware Maintenance Services ........................................................................... ‐ 33 ‐ C.10.3.2 Commercial Software Maintenance Services ............................................................................. ‐ 34 ‐

C.11 TECHNICAL REFRESH ........................................................................................................................ ‐ 34 ‐

C.11.1 Large Displays .................................................................................................................................... ‐ 35 ‐ C.11.2 TFMS Remote Sites (TRS) .................................................................................................................... ‐ 35 ‐ C.11.3 Production Centers ............................................................................................................................. ‐ 35 ‐

APPENDIX A TFMS PRODUCTS .........................................................................................................................‐ 1 ‐

- 1 -

C.1 PROGRAM SCOPE

C.1.1 Background

The Federal Aviation Administration (FAA) works in cooperation with flight operators and other National Airspace System (NAS) users/customers/clients/stakeholders to predict demand, monitor capacity, and implement Traffic Management Initiatives (TMI) as necessary to ensure the number of active flights does not exceed system capacity while striving to minimize constraint impacts to users/customers/clients.

The Next Generation Air Transportation System (NextGen), http://www.faa.gov/nextgen/, Implementation Plan provides the vision and roadmap for modernizing the NAS to meet future air traffic demands safely and efficiently. The execution of this plan involves research, development and deployment of new Air Traffic Management (ATM) systems, technologies, and decision support tools. The FAA’s Air Traffic Systems Decision Support Programs office is responsible for the development and implementation of Traffic Flow Management (TFM) enhancements and new capabilities to support the safe and efficient movement of aircraft through the NAS.

The Traffic Flow Management System (TFMS) assists Traffic Management personnel with predicting demand, identifying constraints, facilitating information sharing, modeling and collaboration of impact mitigation strategies. The Air Traffic Control System Command Center (ATCSCC) in Warrenton Virginia, provides centralized management of NAS-wide TFM capabilities in coordination with Traffic Management Units (TMU) at all major Air Traffic Control (ATC) facilities and flight operators. TFMS remote sites are also located at other FAA and Government offices. See Section F.5.1 (Places of Performance) for current list of locations.

Near real-time information is shared to maximize the efficient use of available capacity across the entire NAS. The system has a centralized architecture supporting various products and tools, including over 30 user/customer/client/data interfaces, comprised of custom applications running on commercial hardware and software. The TFMS supports Air Traffic operations 24/7/365 and is classified by the FAA as an efficiency-critical system per the NAS Requirements Document.

The TFM Production Center (TPC) at the FAA’s William J. Hughes Technical Center (WJHTC) in New Jersey is comprised of a data center with on-site system management and helpdesk operations, along with labs supporting test and evaluations. The TFMS Disaster Recovery Center (DRC) in northern Virginia serves as a backup with capabilities for operations, test, and training.

On-site technical support is provided at the ATCSCC.

The FAA’s Collaborative Air Traffic Management Technologies (CATMT) investment Work Packages (WP) provide the basis and resources for the bulk of TFM enhancements. As future work is approved and funded, tasking will be added within the scope of this contract through the ordering procedures described in Section G. Major TFMS releases (may include updates to multiple products) are nominally planned for deployment in April and/or October to avoid severe weather season and holiday system change moratoriums (Friday before Thanksgiving through Monday after, and Friday before Christmas through Monday after New Year’s Day). See Section F.4.2 for a TFMS typical release timeline and more information.

- 2 -

C.1.2 Purpose

This Statement of Work (SOW) defines the activities and deliverables required for solution implementation and in-service management of TFMS capabilities under this contract. To minimize duplication of information and configuration management complexity, most of the detailed requirements for delivered products and data items are described in Contract Data Requirements Lists (CDRL) and corresponding Data Item Descriptions (DID).

C.2 APPLICABLE DOCUMENTS

Acronyms and Abbreviations – see Section J-1.

Current system-level requirements Documents– see Section J-2.

Govt. Furnished Information (GFI) – see Section J-3.

Govt. Furnished Equipment/Property (GFE/GFP) – see Section J-4.

Contract Data Requirements Lists (CDRL) and corresponding Data Item Descriptions (DID) – see Section J-5.

Future Requirements Documents – see Section J-6.

The Contractor must adhere to all of the following specifications, standards, instructions, orders, guidelines, handbooks, etc. These documents are incorporated into this contract by reference, to the extent herein, or as specified in the individual Delivery Order(s)/Task Order(s) issued under this contract. The versions of these documents as of the contract award date apply; succeeding revisions shall be substituted or incorporated via administrative modification. In the event of a conflict between this SOW and a referenced document, AMS Clause 3.2.2.3-33, Order of Precedence applies.

C.2.1 Security Specific

Document ID Title Date DOT Order 1351.37 DOT Departmental Cybersecurity Compendium, Supplement to DOT Order 1351.37 Departmental Cybersecurity Policy

06/21/2011

FAA Order 1280.1B Protecting Personally Identifiable Information (PII) 8/16/2011 FAA Order 1370.46 NAS Information Security Incident Detection, Reporting, and Response 9/30/2015

FAA Order 1370.79A Internet Use Policy 10/12/1999 FAA Order 1370.81A Electronic Mail Policy 5/13/2002 FAA Order 1370.82A FAA Information Systems Security Program 9/11/2006 FAA Order 1370.91 Information System Security Patch Management 5/19/2004

- 3 -

Document ID Title Date FAA Order 1370.92A Password and PIN Management Policy 8/6/2010 FAA Order 1370.96 ATO System Access Control 4/15/2007 FAA Order 1370.100 Media Sanitizing and Destruction Policy 10/01/2007 FAA Order 1370.101 ATO Information Security Incident Reporting and

Response Policy 12/31/2007

FAA Order 1370.103 Encryption Policy 11/12/2008 FAA Order 1370.105 Logical Access Control Policy 12/10/2008 FAA Order 1370.107 Rules of Behavior/System Use Policy 06/04/2009 FAA Order 1370.116 Boundary Protection Policy 04/16/2012 FAA Order 1375.1E Information/Data Management 11/16/2011 FAA Order 1600.1E Personnel Security Program 7/25/2005 FAA Order 1600.69B FAA Facility Security Management Program 3/29/2005 FAA Order 1600.72A Contractor and Industrial Security Program 12/28/2005 FAA Order 1600.75 Protecting Sensitive Unclassified Information (SUI) 02/01/2005 FAA-STD-045A National Airspace System (NAS) Open Systems

Interconnection (OSI) Security Architecture Protocols and Mechanisms

3/11/2005

FIPS PUB 199 Standards for Security Categorization of Federal Information and Information Systems

Feb- 2004

FIPS PUB 200 Minimum Security Requirements for Federal Information and Information Systems

Mar- 2006

NIST SP 800-18 Rev1 Guide for Developing Security Plans for Federal Information Systems

Feb-2006

NIST SP 800-30 Rev1 Guide for Conducting Risk Assessments, Sep-2012 NIST SP 800-34 Rev 1 Contingency Planning Guide for Federal Information

Systems May-2010

NIST SP 800-37 Rev 1 Guide for Applying Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach

Feb-2010

NIST SP 800-39 Managing Information Security Risk: Organization, Mission, and Information System View

Mar-2011

NIST SP 800-53 Rev 4 Security and Privacy Controls for Federal Information Systems and Organizations

4/1/2013

NIST SP 800-53A Rev 4 Assessing the Security Controls in Federal Information Systems.

12/18/2014

NIST SP 800-64 Rev 2 Security Considerations in the System Development Lifecycle

Oct-2008

NIST SP 800-60 Vol. I Guide for Mapping Types of Information and Information Systems to Security Categories

Aug-2008

NIST SP 800-60 Vol. II Appendices to Guide for Mapping Types of Information and Information Systems to Security Categories

Aug-2008

NIST SP 800-88 Guidelines for Media Sanitization Dec-2014 NIST SP 800-137 Information Security Continuous Monitoring for Federal

Information Systems and Organizations Sep-2011

- 4 -

C.2.2 Training Specific

FAA Order 3000.22A ATO Outcomes-Based Technical Training 09/12/2014 FAA Order 3000.57 ATO Technical Operations Training and Personnel

Certification Training 07/16/2009

FAA Order 3120.4P Air Traffic Technical Training 10/28/2015 No ID # AJI-2 Training Analysis Guide 03/21/2014 No ID # National Air Traffic Analysis Report Template No date No ID # AJI-2 Instructional Design Guide Jan-2015 No ID # AJI-2 eLearning Media Guide 03/26/2014 No ID # FAA eLMS Content Integration Guide Oct-2009 No ID # FAA eLearning Design and Style Guide Oct-2009 No ID # FAA Section 508 Standards and Guidelines for e-Learning Sep-2008

C.2.3 Other

Document ID Title Date

ANSI/ASQ ISO-9001-

Quality Management Systems: Requirements 2008

ANSI/EIA-748, Rev. C Earned Value Management Systems Mar- 2013 FAA-G-2100H Electronic Equipment, General Requirements 10/22/2001 FAA Order 1000.36 FAA Writing Standards 03/31/2003 FAA Order 1350.14B Records Management 12/24/2013 FAA Order 1700.6C FAA Branding Policy 09/11/2006 FAA Order 1800.66

CHG 3

Configuration Management Policy 03/02/2012

FAA Order 1810.8A FAA William J. Hughes Technical Center’s Test and Evaluation Policy

10/15/2015

FAA Order 1900.47E Air Traffic Control Operational Contingency Plan 4/20/2016 FAA Order 3900.19B Occupational Safety and Health Program 3/8/2006 FAA Order 3900.57A Planning and Execution of Construction and Maintenance

Activities at National Airspace System (NAS) Facilities.

2/25/2015

FAA Order 3900.64 Air Traffic Organization Electrical Safety Program 5/21/2013 FAA Order 4441.16 Acquisition of Telecommunications Systems, Equipment, and Services 02/25/1994

FAA Order 4600.27C Inventory Management Guide 9/4/2015 FAA Order 6000.15G General Maintenance Handbook for National Airspace

System (NAS) Facilities 08/09/2013

FAA Order 6000.30F National Airspace Maintenance Policy 4/22/2013 FAA Order 6030.31G National Airspace System Infrastructure Failure Response 02/25/2016 FAA Order 6030.41H Notification of Facility and Service Interruptions and

Other Significant Events 01/26/2009

FAA Order 6040.15 National Airspace Performance Reporting System

(NAPRS)

11/28/2012

FAA Order 7210.633 Air Traffic Quality Assurance Program 1/30/2012

- 5 -

FAA Order 7930.2Q

CHG 1

Notices to Airmen (NOTAM) 5/26/2016

FAA Order 8040.4A Safety Risk Management Policy 04/30/2012 FAA-STD-019E Lightning and Surge Protection, Grounding, Bonding and

Shielding Requirements for Facilities and Equipment Dec-2005

FAA-STD-025F Preparation of Interface Documentation 11/30/2007 FAA-STD-026A Software Development for the NAS 06/01/2001 FAA-STD-063 XML Namespaces 05/01/2009 FAA-STD-064 Web Service Registration 05/01/2009 FAA-STD-065 Web Service Description Documents 02/26/2010 FAA-STD-066 Web Service Taxonomies 02/26/2010 FAA-STD-070 Preparation of Web service Requirements Documents 07/12/2012 FAA-STD-073 Preparation of JAVA Message Service Description

Documents 01/29/2014

NAS-RD-2013 NAS Requirements Document 08/11/2014 MIL-HDBK-61A Configuration Management Guidance 2/7/2001 NDIA IBR Guide Rev1 Integrated Baseline Review (IBR) Guide Sept- 2010 NFPA 101 Life Safety Code 2015

FAA specifications and interface documents may be obtained from the Federal Aviation Administration, Headquarters Public Inquiry Center APA-230, 800 Independence Avenue, SW, Washington, D.C. 20591, 202-267-3484. Requests should fully identify material desired and cite the solicitation or contract number. A number of these documents may be downloaded from the FAA at http://www.faa.gov/regulations_policies/

Acquisition Management System Policy and Guidelines are in the FAA Acquisition System Toolset (FAST) at http://FAST.faa.gov.

The FAA Work Breakdown Structure (WBS) Version 5.1 may be obtained at the following website:

http://fast.faa.gov/WorkBreakdownStructure.cfm?p_title=Special%20Topics

National Institute of Standards and Technology (NIST) standards may be obtained from the Systems and Software Technology Division, Computer Systems Laboratory, National Institute of Standards and Technology, Gaithersburg, MD 20899 or ordered from the NIST website at http://www.nist.gov/.

Institute of Electrical and Electronics Engineers (IEEE) documents may be obtained from Institute of Electrical and Electronics Engineers-USA, 1828 L Street, NW, Suite 1202 Washington, D.C. 20036- 5104 or ordered from the IEEE website at http://www.ieee.org.

American Society of Mechanical Engineers (ASME) documents may be obtained via the ASME website at http://asme.org/.

Integrated Baseline Review (IBR) guidance is provided in the National Defense Industrial Association (NDIA) IBR Guide.

Copies of federal publications may be obtained from the U. S. Government Printing Office, 710 North Capitol Street, Washington, DC 20401, by calling (202) 512-0132, or through the website http://bookstore.gpo.gov/.

Requests for copies of documents not covered in the preceding paragraphs should be addressed to the Contracting Officer. Requests should fully identify material desired and cite the solicitation or contract number.

- 6 -

- 7 -

C.3 PROGRAM MANAGEMENT

The Contractor must establish and maintain the organization and infrastructure necessary to successfully implement all contract requirements efficiently and effectively for the entire duration of the contract period of performance. This must include planning, coordination, conduct and integration of all aspects of program management, e.g., contract administration, finance, technical management and support, across multiple overlapping development and maintenance tasks within the scope of this SOW. The Contractor must accurately track and report to the Contracting Officer (CO): current status of all work compared to baseline plans;

cost/schedule forecasts; and issue/risk identification/mitigation. The Contractor is solely responsible for the quality and timeliness of all sub-contractor work.

C.3.1 Program Management Organization

The Contractor must assign a dedicated Program Manager (PM) with overall responsibility to organize, plan, schedule, implement, control, analyze and report all elements of the contract.

The PM must have sufficient corporate authority to direct, execute, and control all elements of the work under this contract. The PM, as focal point within the Contractor’s organization, must be capable of effectively presenting and discussing contract activities with the primary Government representatives: Contracting Officer (CO), Contracting Officer’s Representative (COR), and TFMS Program Manager.

C.3.2 Contract Transition

The Contractor must prepare, deliver, and comply with a Government approved Contract Transition Plan in accordance with the related CDRL/DID M07. The contractor must complete all necessary activities in accordance with the Government approved Contract Transition Plan.

This plan must describe the process, details and schedule for providing an orderly transition during the contract’s phase-in and phase-out transition periods stated in Section F.3 Periods of Performance. The Contractor must address all elements of this Statement of Work in the plan.

The objectives of the plan are: to identify and minimize risks of impacts on continuity of operations; maintain communication with staff and affected stakeholders; identify key issues;

and overcome obstacles to transition. The Contractor must perform due diligence to ensure all transition activities are identified, negotiated, and completed during the Transition Period of Performance. The plan must include Government-witnessed verification steps to assess hand-off readiness of TFMS work activities identified in this Statement of Work.

The Contractor must complete transition activities per the dates in Section F.4 (Key Milestones).

C.3.3 Program Management Plan (PMP)

The Contractor must prepare, deliver, maintain and comply with a Government approved Program Management Plan (PMP) in accordance with the related CDRL/DID M01 which covers roles, process and procedure details.

- 8 -

The Contractor must document its risk management process and procedures in the PMP for timely and continuous identification, assessment, tracking and systematic reduction of risks that could impact the Contractor’s ability to meet its technical, cost and schedule objectives.

C.3.4 Meetings, Reviews, Conferences, and Evaluations

C.3.4.1 General Requirements

The Contractor must provide the Government suitable working space at its primary work location with access to the internet for four Government representatives in support of meetings, reviews, evaluations, etc.

The Contractor must support recurring status reviews and planning meetings, Technical Interchange Meetings (TIMs), Program Management Reviews (PMR), requirements/design reviews, test readiness reviews, and evaluations with the Government to discuss program progress, identify potential problems, mitigate risks, and resolve concerns and issues. The Contractor must provide appropriate qualified and accountable personnel able to respond to most of the Government questions during the meeting.

The Contractor must provide secure (controlled access and not via a free service) teleconferencing, video and on-line meeting capabilities for all meetings with the Government unless otherwise directed. The Contractor must provide adequate facilities to meet attendance requirements for all conferences, meetings, reviews, and evaluations that cannot be effectively accomplished using teleconferencing methods. Government facilities will only be used at Government's direction or approval of the Contractor’s request.

The Contractor must provide draft agendas, presentation material, meeting minutes and action items in accordance with the related CDRL/DID M02.

The Contractor must track action items assigned during meetings until the disposition of the action is agreed to by the Government. Once the disposition of an action has been completed and validated by the Government, the action may be closed, however the Contractor must maintain a history of all items for life of the contract.

C.3.4.2 Program Management Reviews (PMR)

The Contractor must conduct reviews for all active work required under the contract at least monthly. The first PMR must be held per the date in Section F.4 (Key Milestones). For all PMRs, the COR may modify the meeting schedule and location to accommodate special program needs. At PMRs, the Contractor must provide, at a minimum, the program’s management, technical, cost and schedule status. The Contractor must provide a Government approved agenda, presentation materials, action item list and meeting minutes for all PMRs.

The PMR must be accomplished nominally during one working day and must include topics listed in the related CDRL M02 DID at a minimum.

- 9 -

The Contractor must provide draft agendas, presentation material, meeting minutes and action items in accordance with the related CDRL/DID M02.

C.3.4.3 Post-Award Conference (PAC)

The Contractor must arrange and host a Post-Award Conference (PAC) per the date in Section F.4 (Key Milestones). The Contractor must demonstrate adequacy of proposed planning efforts to meet all contractual requirements. The Contractor must provide an overview of the following CDRLs at the PAC:

CDRL M01: Program Management Plan (PMP)

CDRL M07: Contract Transition Plan

CDRL C01: Configuration Management Plan (CMP)

CDRL E01: Systems Engineering Management Plan (SEMP)

CDRL E06: Software Development Plan (SDP)

CDRL L01: Integrated Support Plan (ISP)

CDRL Q01: Quality System Plan (QSP)

CDRL T01: Contractor Master Test Plan (CMTP)

The Contractor must provide draft agendas, presentation material, meeting minutes and action items in accordance with the related CDRL/DID M02.

C.3.4.4 Other Meetings

At the request of the Government or the Contractor, Technical Interchange Meetings (TIMs) must be held, with approval of the FAA COR, to discuss issues that require mutual resolution or further clarification. Anticipate one day per month average throughout duration of the contract.

The Contractor must provide draft agendas, presentation material, meeting minutes and action items in accordance with the related CDRL/DID M02.

The Contractor must participate in TFMS stakeholders meetings (e.g., the TFMS Deployment Team) upon request of the FAA COR. Anticipate one day per month average when release development activities are underway. The Contractor will not be responsible for agenda, material or minutes.

Other known meeting requirements including design, development, test and operations are specified within the context of their related Sections herein and in CDRL/DID M02.

- 10 -

C.3.5 Program Control

C.3.5.1 Contract Work Breakdown Structure (CWBS)

The Contractor must prepare, deliver and maintain a detailed Government approved Contract Work Breakdown Structure (CWBS) in accordance with the related CDRL/DID M03. The CWBS must align to the TFM2 Program WBS provided in Attachment J-8. The CWBS must describe the work that will be accomplished and must facilitate management data collection and reporting. The Contractor must use the CWBS as the primary framework for contract planning, budgeting, and reporting program cost and schedule status to the Government.

C.3.5.2 Earned Value Management System (EVMS)

The Contractor’s EVMS must comply with ANSI/EIS-748 Revision C and be capable of accurately accommodating the data for all work performed under the contract including subcontractors. The EVMS must be used to plan/measure performance and identify cost/schedule variances. The Contractor must be ready to pass an FAA audit of its EVMS by 90 days after contract award.

The Contractor must prepare, deliver and maintain an Integrated Program Management Report (IPMR) in accordance with the related CDRL/DID M04 that examines the actual expenditures measured against the planned expenditures. The data used to generate performance information must also be used to prepare and deliver a Contract Funds Status Report (CFSR) in accordance with the related CDRL/DID M05 providing funding status and requirements.

The Contractor must submit all proposed changes to EVMS to the Contracting Officer for approval prior to implementation.

The Contractor agrees to provide access to all pertinent records and data requested by the Contracting Officer, or authorized representatives, needed by the FAA to verify the Contractor's EVMS compliance during performance of this contract.

C.3.5.3 Integrated Baseline Review (IBR)

The Contractor must support the Government led IBR to review the Contractor’s processes and procedures for scheduling work, allocating resources, and managing risk. An IBR is intended to ensure the Government and Contractor mutually understand program scope, schedule, resources, risks, and ensure the Contractor’s approach to managing the requirements, cost and schedule baselines is adequate.

- 11 -

The contractor must refer to the NDIA IBR Guide Rev. 1 dated September 1, 2010 for guidance in preparing for, participating in, and supporting the IBR. The Contractor must hold an IBR within 180 days, or sooner if required in Section F.4.1 (Key Milestones), after the formal award of the TFM-2 contract. This IBR evaluates both the program management’s and the Contractor’s implementation of the performance measurement baseline. Upon completion of the IBR, the Government will provide a letter of findings. The Contractor must provide a response to address all issues identified in the letter of findings, within the timeframe identified by the Government, detailing how the Contractor will remedy all shortfalls to the CO’s satisfaction.

In accordance with AMS policy 4.16.2, the Government intends to conduct regular contractor EVM surveillance at the contract management level. Upon the Contracting Officer’s request, the government reserves the right to review one or more areas of interest pertaining to the Contractor’s processes and procedures for scheduling work, allocating resources, and managing risk in the interim of a formal IBR. These reviews will focus on the particulars of specific activity related to newly awarded CLINs. The government anticipates these activity related reviews will occur approximately twice per contract year, and will typically occur after the award of future enhancement development CLINs. If an awarded CLIN represents a major change to the terms, conditions, and/or processes used to manage the contract, then a formal IBR may be requested at the Contracting Officer’s direction.

C.3.5.4 Performance Measurement

The Contractor must collect, maintain and report metrics on the performance of the program and system for the duration of the contract. The Contractor must document the definition of each indicator or metric, method(s) used to calculate it, the approved target value, and actual values for that indicator or metric for the reporting period(s). The Contractor must use trend analysis and forecasting techniques in order to proactively identify systematic issues with the program and system. All metrics must be updated at appropriate periodic intervals and the data used to compute them must be provided to the FAA upon request. The Contractor must prepare, deliver and maintain a Management Indicators Report in accordance with related CDRL/DID M06.

C.3.5.5 Quality Assurance (QA)

The Contractor must prepare, deliver, maintain, comply with a Government approved Quality System Plan (QSP) in accordance with the related CDRL/DID Q01.

The inspection requirements specifically set forth in Section E must be part of the Contractor's overall Quality Assurance (QA) program. The absence of Government inspection does not relieve the Contractor of the responsibility of ensuring that all products or supplies submitted to the Government for acceptance comply with all requirements of the contract.

Delivery specific inspection requirements will be defined in specific CLIN tasks.

All QA operations performed by the Contractor must be subject to Government verification at any time which will consist of, but not be limited to:

- 12 -

a. Government surveillance of the operations to determine if practices, methods and procedures of the quality program are being properly applied;

b. Government inspection of QA evaluations, audits and reports; and

c. Government product inspection to verify acceptability.

C.3.5.6 Configuration Management (CM)

Configuration Management Plan (CMP) in accordance with the related CDRL/DID C01 which covers roles, process and procedure details.

The Contractor must minimize duplication of information across CDRLs to minimize CM complexity by referencing other documents for details best maintained elsewhere. All subcontractors must comply with the CM policy and procedures.

The Contractor must retain detailed change history for all CDRLs and provide to the Government upon COR request. Draft updates to CDRLs must be delivered with revision marks unless the COR approves a waiver in advance.

The Contractor must prepare, deliver and maintain a Configuration Status Accounting Report (CSAR) in accordance with the related CDRL/DID C02.

The Contractor must prepare Engineering Change Proposals (ECP), in accordance with the related CDRL/DID C03, upon CO request. The Contractor must not prepare unsolicited ECPs and will not be compensated for doing so.

If the Contractor desires a temporary waiver to, or relief of, a requirement, the Contractor must submit a Request for Deviation (RFD) in accordance with the related CDRL/DID C04 for Government approval.

C.3.5.6.1 Configuration Audits

Configuration Audit Plan (CAP) in accordance with the related CDRL/DID C05.

If required per CLIN specific tasking, the Contractor must conduct a Functional Configuration Audit (FCA) and a Physical Configuration Audit (PCA) with Government oversight and report results in a Configuration Audit Report (CAR) with the related CDRL/DID C06. Audits must be performed to validate that all Configuration Items (CI) have been developed in accordance with the requirements and design documentation. No changes to any CI to be audited are allowed starting one week prior to start or during conduct of audit.

- 13 -

C.4 SECURITY

C.4.1 General

The Contractor must designate an individual responsible for compliance with all security-related requirements associated with the execution of this contract.

The Contractor must comply with all the security-related clauses in Section I including 3.14.-2 Contractor Personnel Suitability Requirements, and 3.14-4 Access to FAA Systems and Government Issued Property. The Contractor must ensure that only authorized personnel have access to TFMS operations components (supporting NAS efficiency-critical services) and sensitive data.

The Contractor must ensure all employees and subcontractors complete the Government’s annual security awareness training, retain records of completion, and provide to the Government upon request.

The Contractor must comply with the security-related requirements in Section H including H.3 Release of Information, H.4 AMS clause 3.13-15 Confidentiality of Data and Information, and H.11 Employee Termination.

The Contractor must comply with the applicable documents listed in section C.2.1 for all work performed under this contract, including development, operations and maintenance.

The Contractor must review all proposed system changes to ensure security is not compromised.

A Contractor’s security subject matter expert must participate in meetings upon Government request including:

a. Meetings of the Government’s Information System Security Officer’s (ISSO) Security Authorization Team to facilitate development of the Security Authorization/Information Security Continuous Monitoring Package and related activities.

b. Support security impact analyses of significant system changes and briefings to the ISSO/ATO Information Systems Security Program Office.

c. Participate in Program Trouble Report (PTR) analysis and patch packaging meetings as needed (see C.10.2.1.2).

d. Participate in security test planning and execution.

The Contractor must safeguard all GFI, GFE/GFP and property purchased under this contract.

- 14 -

C.4.2 Operations Support

The Contractor must prepare, deliver, maintain, and comply with the following Government approved CDRLs in accordance with the related CDRL and DID:

CDRL/DID S01 TFMS System Characterization Document (SCD)

CDRL/DID S02 Systems Security Plan (SSP)

CDRL/DID S03 NAS System Contingency Plan (NSCP)

CDRL/DID S04 Security Standard Operating Procedures (SSOP)

CDRL/DID S05 Privacy Threshold Assessment (PTA), and Privacy Impact Assessment (PIA), if required

CDRL/DID S06 Plan of Action and Milestones (POAM) Status Report

The contractor must support the FAA ATO Information Security Continuous Monitoring (ISCM) Process, to include:

a. Conduct and support vulnerability scanning activities, including regular credentialed vulnerability scans on all operating systems and devices, web applications, and database servers (when enterprise-wide FAA tool is available) and comply with FAA remediation timeframe requirements.

b. Perform routine system audits at least annually or upon major releases and provide support for all Government-led audits.

c. Address and resolve ongoing mitigation activities for security weaknesses identified in the information system’s Plan of Action and Milestones (POAM).

d. Prepare, as necessary, tickets, security Change Requests (CRs) and take corrective action when approved by the Government.

e. Build and maintain TFMS security encryption.

f. Perform security configuration and management of firewalls, VPN devices, Operating Systems, and encryption settings to comply with security requirements.

g. Support incident response reporting and data calls to the NAS Security Operations Center.

h. Ensure the collection and transmission of system security event audit logs to the NAS Security Operations Center (SOC). This will include the ability to transmit operating system security logs to a centralized SOC collection server.

- 15 -

C.5 ENGINEERING, DESIGN AND DEVELOPMENT

The Contractor’s system engineering efforts must consider all aspects of performance, quality, life cycle cost, maintainability, reliability, schedule, data processing reserves, and future growth requirements. The Contractor must maintain effective control over the system engineering, design and development processes, including subcontracted items and services, to ensure early detection of problems, and mitigate risk to reduce risk to cost, performance, and schedule.

The Government reserves the right to witness all contractor efforts to accomplish the SOW requirements and maintains the right to approve or reject resulting processes and products before subsequent related processes and products are implemented. The contractor shall maintain an interface with Government project personnel, users/customers/clients, sponsors, software quality and configuration management personnel, and the independent verification and validation agent throughout the execution of this SOW.

The Contractor must prepare, deliver, maintain and comply with a Government approved Systems Engineering Management Plan (SEMP) in accordance with the related CDRL/DID E01.

C.5.1 Engineering Services

Engineering Services will be required for TFM related efforts, and may also be sponsored by other FAA organizations external to the TFMS Program Office. The Contractor must perform system and software engineering tasks per Task Orders issued under this contract. The Contractor must comply with Task Order procedures described in Section G.8 Ordering Procedures. When directed, the Contractor must prepare and deliver a Task Work Plan in accordance with the related CDRL/DID E13.

Examples of system engineering tasks include: analyze FAA provided requirements for future enhancements and propose changes to the existing system in order to meet them; conduct change impact assessments and estimates; and perform feasibility and trade-off assessments.

Examples of software engineering tasks include: development of risk mitigation prototype software; and minor miscellaneous changes/updates to TFMS products, e.g. web pages.

The Contractor must deliver results of all engineering analysis in a Technical Report, per the Task Order requirements, with an appropriately specific sub-title in accordance with the related CDRL/DID E12, unless work is covered by a specific CDRL other than CDRL E12.

- 16 -

C.5.2 Requirements Analysis and Development

The Contractor must perform requirements analysis, as directed by the Government. The Contractor’s analysis must include generation of the interface requirements and performance specifications needed to ensure all TFMS components (including software, hardware, and user/customer/client) will work together to meet overall requirements. These requirements provide the basis for formal Government acceptance testing. Requirement analysis methodologies must be used to ensure the completeness and clarity of all requirements.

The Contractor must provide requirements analysis including:

a. Transformation and integration of the GFI and GFP (where applicable) provided for each Government approved TFMS enhancement/change request (e.g., Concept of Operations and capability System Specification Documents) into the existing TFMS requirements documentation.

b. Allocation of requirements to appropriate hardware/software configuration items.

c. Identification of development constraints including cost, resources, time/schedule, budget, hardware to be supported, existing software to be utilized, portability and maintainability requirements, and anticipated changes.

d. Analysis of requirements to assess potential problems, prioritization and evaluation of feasibility of implementation and alternative solutions (risk management).

e. Representation of requirements with proper notation such as prototyping, modeling, or use of requirements analysis tools.

f. Communication of requirements in a clear manner to ensure consistent understanding among all stakeholders and to reduce ambiguity.

The contractor must document the traceability of all requirements from origin through lowest level component.

For each FAA approved change request, the Contractor must update, deliver, maintain and comply the following Government approved TFMS documents in accordance with the related CDRL/DID (the basis for formal Government acceptance testing):

CDRL/DID E02 System/Subsystem Specification (SSS)

CDRL/DID E03 Interface Requirements Specification (IRS)

- 17 -

The Contractor must provide written notification to the Government if any approved SSS or IRS changes require an update to the Government maintained System Specification Document (SSD) or Interface Requirements Document (IRD).

Requirements analysis results not applicable to existing TFMS requirements documentation must be documented in a Technical Report with an appropriately specific sub-title in accordance with the related CDRL/DID E12.

The Contractor must derive, allocate and validate requirements subject to FAA approval. All changes, including editorial, must be approved by the Government’s designated Requirements Lead or alternate. The Contractor must maintain change history throughout duration of the contract.

The Contractor must plan and host Requirements Reviews, as needed, to support requirements analysis activities to ensure timely progress to completing baseline changes for each FAA approved enhancement/change. Anticipate one or more for each TFMS release primarily via teleconference. The Contractor must provide draft agendas, presentation material, meeting minutes and action items in accordance with the related CDRL/DID M02.

C.5.3 System-level Design

The contractor must apply the Government approved system design and management practices identified in the E01 SEMP to ensure the continued quality and maintainability of the TFMS.

Based on each Government approved TFMS enhancement/change, the Contractor must prepare, deliver, maintain and comply with updates the following TFMS documents in accordance with the related CDRL/DID:

CDRL/DID E04 System/Subsystem Design Document (SSDD) CDRL/DID E05 Hardware Architecture Document (HAD)

System design supporting activities resulting in information not directly applicable to enhancement end-state TFMS design documentation must be documented in a Technical Report with an appropriately specific sub-title in accordance with the related CDRL/DID E12.

The Contractor must plan and a host System Design Review (SDR) for each release, to be scheduled in accordance with Section F.4.1 Key Milestones. The objective of the System Design Review is to gain Government acceptance of proposed changes to system-level requirements and design. This technical exchange must cover the topics in CDRL/DID M02 at a minimum. The Contractor must provide draft agendas, presentation material, meeting minutes and action items in accordance with the related CDRL/DID M02. Upon satisfactory resolution of Government comments, the Government will authorize the Contractor to proceed with detailed design activities.

See Section F.4.2 for a TFMS typical release timeline and more information.

- 18 -

C.5.4 Detailed Design

Based on each Government approved TFMS enhancement/change, the Contractor must prepare, deliver, maintain and comply with updates the following TFMS documents in accordance with the related CDRL/DID:

CDRL/DID E07 Software Requirements Specification (SRS) CDRL/DID E08 Software Design Document (SDD) CDRL/DID E09 Database Design Document (DBDD) CDRL/DID E10 Interface Control Document (ICD)

The Contractor’s software design must make use of unmodified commercial software (i.e.

commercial-off-the-shelf, open…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .