eBusiness Draft SOW.pdf

PDF 1 MB Posted

Attached to
NAVAIR Procurement Group Electronic Business (eBusiness) Support RFI Federal contract opportunity
Solicitation number
Not on record
Issued by
Department of the Navy Naval Air Systems Command Naval Air Warfare Center

About this file

This is a Statement of Work (SOW) for NAVAIR Procurement Group Electronic Business Support services to be provided to the NAVAIR Contracts E-Business Office (NCEBO). The SOW outlines requirements for comprehensive management and support of NAVAIR's contract writing and eBusiness systems, including the Standard Procurement System (SPS) and electronic Procurement System (ePS).

The contractor's key responsibilities include: providing full lifecycle functional and technical support for NAVAIR's eBusiness systems; managing system sustainment, sunsetting, implementation and data migration; supporting integration between Contract Writing Systems, Enterprise Resource Planning (ERP) systems and other eBusiness platforms; providing audit support for FISCAM and SBA compliance; delivering Tier 1 and 2 technical support; maintaining the Knowledge Management Portal; supporting process automation and AI/RPA initiatives; and providing cradle-to-grave business financial management support across OMN, NWCF, RDT&E, and APN funding sources. The work will be performed 100% at contractor facilities or via telework, with no government site presence required. The contractor must possess U.S. citizenship and security clearances up to Top Secret for privileged access personnel, with Secret clearance required for other staff.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

NAVAIR Procurement Group Electronic Business (eBusiness) Support Statement of Work

Statement of Work

1. Background/Scope

1.1 Background

The NAVAIR Contracts E-Business Office (NCEBO) V212 is responsible for the comprehensive planning, management, deployment, maintenance, and operation of Contracts eBusiness Systems within the Naval Air Systems Command (NAVAIR). NCEBO serves as the central point for managing and overseeing these systems to ensure the seamless execution of NAVAIR’s procurement and contracting processes. The office plays a critical role in providing Subject Matter Expertise (SME) and oversight for compliance efforts, including audits related to the Federal Information System Controls Audit Manual (FISCAM) and the Statement of Budgetary Authority (SBA).

These efforts ensure the accuracy and timeliness of the Contract Vendor Pay (CVP) process and the Procure-to-Pay (P2P) process, where the contract writing systems are vital in ensuring accurate vendor payments and maintaining procurement integrity from start to finish.

NCEBO is primarily responsible for the architecture, implementation, support, and management of contract writing and eBusiness systems across NAVAIR. This includes overseeing the deployment and continuous operation of key systems such as the Standard Procurement System (SPS) and the electronic Procurement System (ePS), which are critical to NAVAIR's acquisition and contracting activities. By managing these systems, NCEBO ensures they align with NAVAIR’s strategic objectives and operational requirements, while providing ongoing support to keep the systems functional and responsive to mission needs.

Additionally, NCEBO oversees compliance with audit and financial regulations, ensuring that eBusiness systems and processes meet federal standards and support accurate reporting, especially during audits such as FISCAM and SBA. The office also plays a pivotal role in training and workforce development by designing and executing training programs for NAVAIR personnel. These programs ensure that employees are proficient in using contracts eBusiness systems and that they comply with all regulatory and operational guidelines. NCEBO’s training efforts extend across the NAVAIR enterprise.

In supporting NAVAIR’s Data Strategy, NCEBO facilitates the alignment of business systems and data to promote better operational efficiency and decision-making. NCEBO plays an integral role in ensuring that contract writing systems are effectively integrated with other financial, logistics, and data management systems, contributing to total asset accountability and visibility across NAVAIR.

Collaboration is essential to NCEBO's success, and the office works closely with internal stakeholders such as the Comptroller, Budget and Financial Management (BFM) offices, and logistics teams to ensure alignment between financial, procurement, and logistics systems. Externally, NCEBO coordinates with financial management systems and audit entities, ensuring that NAVAIR's contract writing systems are integrated with broader Navy and Department of Defense (DoD) platforms, such as Navy ERP, while maintaining compliance with audit and regulatory requirements.

NCEBO is also responsible for the oversight of all NAVAIR Contract Writing sites and provides ongoing eBusiness system support across the command. This includes surge support during high-demand periods or critical operational events, ensuring seamless system functionality and user assistance. The office manages the implementation and integration of eBusiness systems across the command, ensuring that new technologies and updates are successfully deployed.

In addition to its operational and compliance responsibilities, NCEBO actively participates in various Navy-wide working groups, including those focused on Asset Management and Property Accountability (AM/PA), Government

Furnished Property (GFP), and Procure-to-Pay (P2P). Through its participation in these initiatives, NCEBO helps to shape and align contract writing systems and eBusiness solutions with Navy-wide goals and standards.

NCEBO supports strategic planning initiatives within NAVAIR by providing guidance on the development, refinement, and implementation of acquisition and procurement systems. The office continuously identifies and implements process improvements to enhance operational efficiency and align with Navy and DoD-wide initiatives.

By ensuring the successful implementation and ongoing support of contract writing and eBusiness systems, NCEBO contributes to NAVAIR’s ability to meet its mission objectives and deliver high-quality aviation solutions to the fleet.

1.2 Scope

The contractor shall continue to provide full lifecycle functional and technical support for NAVAIR’s Contracts eBusiness Systems. This support includes the sustainment and sunsetting of existing systems and the implementation, data migration, and strategic documentation for future systems. NCEBO requires specific attention to the integration of Contract Writing Systems (CWS), Enterprise Resource Planning (ERP) Systems, and associated eBusiness systems. The contractor must possess a deep institutional knowledge of these systems, gained through previous experience with NAVAIR to deliver critical support with minimal learning curve and risk.

Key systems include:

Contract Writing Systems (CWS): Sustainment and modernization to ensure operational efficiency and alignment with NAVAIR’s contracting needs.

ERP Systems: Support for NAVAIR’s ERP systems, ensuring functionality and alignment with procurement, financial, and contracting requirements.

Associated eBusiness Systems: Alignment of all eBusiness platforms with NAVAIR’s overarching data-centric strategies and compliance needs.

3.1.1 Contractor Responsibilities

The contractor shall provide the following services to support NAVAIR and NCEBO:

Oversight and Management of eBusiness Architecture: The contractor will continue providing oversight for the overall eBusiness architecture within NAVAIR, ensuring alignment with NAVAIR’s mission and enterprise data strategies. Subject matter expertise and of NAVAIR’s processes and systems is required to address both the strategic and operational requirements of the Command.

System Sustainment and Sunsetting: The contractor will manage the lifecycle of legacy systems, ensuring that their sunsetting does not disrupt mission-critical operations. Expertise and experience of NAVAIR business processes and key stakeholders is required to handle transitions smoothly, ensuring that all new systems are integrated properly without compromising NAVAIR’s operational capabilities.

Data Migration and Strategic Documentation: With NAVAIR’s shift toward a more data-centric business environment, the contractor will ensure that all data migrations maintain integrity and compliance with both DoD and DON standards. Additionally, they will provide strategic documentation that aligns with NAVAIR’s data strategy and broader enterprise requirements.

Audit and Compliance Support: The contractor shall support NCEBO in its audit and compliance activities, including FISCAM and SBA audits. Extensive experience with these processes will ensure that all documentation is aligned with NAVAIR’s requirements for contract writing systems and the overall Procure-to- Pay (P2P) process.

Surge Support and Training: The contractor will provide surge support as needed to meet NAVAIR’s dynamic operational needs, such as during periods of heightened audit activity or system transitions. This surge support includes maintaining the scalability of systems, ensuring that NAVAIR’s procurement and contracting functions remain uninterrupted. The contractor will also provide ongoing training for NAVAIR personnel, using their established knowledge of NAVAIR’s systems to develop and deliver training programs tailored to the Command’s specific needs.

Key Collaboration and Stakeholder Engagement: The contractor shall continue to collaborate closely with NAVAIR stakeholders, including participation in key working groups:

NAVAIR and Navy Asset Management and Property Accountability groups NAVAIR and Navy Government Furnished Property (GFP) working groups NAVAIR Comptroller and BFM related working groups DoN P2P working groups DoN CWS Teams

Inherently Governmental Functions No item in the SOW shall be interpreted to have the contractor perform any services that are inherently governmental services or personal services as defined in FAR 2.101 - (See "Inherently governmental function" and "Personal services contract').

2. Applicable documents:

2.1 Department of Defense specifications

2.1.1 DoD National Industrial Security Program Operating Manual (NISPOM) codifying 32 Code of Federal Regulations Part 117, NISPOM Rule.

2.1.2 SECNAV M-5510.36B, Department of the Navy, Information Security Program, 12 Jul 2019.

2.1.3 DoDI 5200.48, Controlled Unclassified Information (CUI), 6 Mar 2020.

2.1.4 DoDD 5400.07, DoD Freedom of Information Act (FOIA) Program, 5 Apr 2019.

2.1.5 DoDI 5230.24, Distribution Statements on Technical Documents, Change 3, 15 Oct 2018

2.1.6 SECNAV M-5510.30C, Department of the Navy, Personnel Security Program, 24 Jan 2020.

2.1.7 OPNAVINST 3440.17A, Navy Installation Emergency Management Program, 1 Aug 2014

2.1.8 DODI 8582.01 - Security of NON-DOD Information Systems Processing Unclassified Non-Public DOD Information

2.1.9 NIST SP 800-171 – Special Publication: Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations

2.2 Department of Defense standards

A comprehensive list of Navy regulatory documents can be found at the DON Chief Information Officer (CIO) website http://www.doncio.navy.mil/.

The Contractor shall be responsible for researching and complying with any additional regulations applicable to the task areas in which they are involved.

2.3 Other Government documents (e.g. NAVAIR Documents)

2.3.1 NAVAIR SPS Standard Operating Procedure (SOP) for NAVAIR Contracts.

NAVAIR 2.0 Contracts (Secure) Website - https://myteam.navair.navy.mil/km/20

2.3.2 NAVAIR Instruction A

2.3.3 National Institute of Standards and Technology Special Publication 800-XX

2.4 Industry documents N/A

3. Requirements

3.1 General Requirements

3.1.1 Compatibility - The Contractor shall maintain the capability to prepare documents and software packages compatible with the Government IT environment through the security classification of Unclassified. The current operating environment required for this contract includes:

Microsoft Windows 10 Microsoft Project 2010

Microsoft Office Professional Plus 2010 Adobe Acrobat XI (reader) Internet access Standard Procurement System

Electronic Procurement System (ePS)

PIEE

The Contractor shall maintain the ability to interface with and transfer data to and from requiring office software applications and their upgraded versions. The Contractor shall ensure that all media are virus free when delivered.

The Contractor shall be capable of Internet and LAN communications with the NCEBO Contractor personnel shall be capable of maintaining real-time communications, both voice and data transfer capabilities, with NCEBO during working hours whether at Contractor work site or on travel.

3.1.2 Work Location, Facilities and Telework

3.1.2.1 Work location: Approximately 0 percent of work will be performed at Government site and 100 percent of work to be performed at Contractor site or applicable telework locations.

3.1.2.2 Meeting support: In support of the tasking outlined in this SOW, the Contractor shall have the capability to host and conduct meetings at the classification levels up to unclassified with the capacity to support a minimum of 50 persons using Government provided MS Teams capabilities.

3.1.2.3 Telework: The Contractor may allow employees to telework with approval from the COR in writing, that a positions tasking is eligible for telework. The Contractor, may utilize alternate worksites/locations and telework to support continued performance of SOW tasks in accordance with company policy. When using telework, the Contractor remains responsible for contract performance and compliance with any applicable cost accounting standards and contract cost principles / procedures.

3.1.3 Contract Status reporting: The Contractor shall provide the following documentation.

3.1.3.1 Monthly Progress and Financial Status Report: The Contractor shall provide a progress and financial status report in accordance with the Contract Data Requirement List (CDRL A001). The report shall include work accomplished since submittal of the last report, both monthly and cumulative man-hour labor costs expended by labor category and material and travel costs.

3.1.4 Work Schedule to include Compressed Work Schedule (CWS), holidays, and installation closure.

3.1.4.1 Work schedule: The Contractor shall provide the required services and staffing coverage during normal working hours. Normal working hours are usually 8.5 hours (including a 30-minute lunch break), from 0700 to 1700 each Monday through Friday (except on the legal holidays specified in paragraph 3.1.4.1.2).

3.1.4.1.1 Compressed Work Schedule (CWS): CWS is an alternative work schedule to the traditional five 8.5 hour workdays (which includes a 30-minute lunch) worked per week. Under a CWS schedule, an employee completes the following schedule within a two-week period of time: Eight weekdays are worked at 9.5 hours each (which includes a 30-minute lunch), one weekday is alternately worked as 8.5 hours (which includes a 30-minute lunch) and one weekday is not worked by the employee. The result is 80 hours worked every two weeks, with 44 work hours one week and 36 work hours the other.

The Contractor may allow its employees to work a CWS schedule provided the requirements of this SOW are met.

If the Contractor chooses to allow its employees to work a CWS schedule in support of this contract, any additional costs associated with the implementation of the CWS schedule vice the standard schedule are unallowable costs under this contract and will not be reimbursed by the Government. Additionally, the CWS schedule shall not prevent Contractor employees from providing necessary staffing and services coverage as required by the Government to the ACOR/COR.

3.1.4.1.2 Holidays: The Government observes the Federal holidays identified on the Office of Personnel Management (OPM) website: https://www.opm.gov/policy-data-oversight/pay-leave/federal-holidays/#url=Overview.

The Contractor is permitted to observe the above Federal Holidays in accordance with its corporate policy.

3.1.4.1.3 Installation closure: When Federal facilities are closed by the Government, or when Federal employees are officially excused from work due to a holiday or a special event, severe weather, a security threat, or any other Government facility related problem that prevents Federal personnel from working at the Government facility, contractor personnel assigned to work at that facility in support of such Federal employees shall follow their parent company’s policies.

While generally contractor personnel may not perform work on-site at a Government facility without oversight from Federal personnel, in very limited circumstances, work being performed by contractor personnel may be deemed mission essential and performance of such mission essential work may be authorized to continue at the Government facility despite the facility being otherwise closed for normal operations. The circumstances permitting work being performed by contractor personnel to be deemed mission essential are extremely limited and generally only apply to performance of efforts related to public health, safety, or matters related to national security. The cognizant Contracting Officer must concur with any determination that work being performed by contractor personnel is mission essential.

3.1 Other Direct Costs:

3.1.5.1 Travel: Travel may include general and administrative expenses, but shall not include profit. Temporary travel to other locations in support of program tasking may be required. If required, temporary travel locations include Lakehurst, NJ, Orlando, FL, Crystal City, VA, and China Lake, FL

The contractor is required to attend the annual P2P Training Symposium, as well as attending periodic Navy eBusiness meetings in Northern Virginia. Other travel may be required and will be determined by the COR/TPOC.

This list is not all inclusive as locations may change over the life of the contract.

3.1.5.2 Material: Incidental material will be required in the performance of this Contact, and all incidental material purchases shall be IAW C-TXT-242.95XX Procedures and Approvals Required Prior to Incurring Direct Material Costs (Sep 2021). All materials not depleted during the performance of this contract shall become Government property upon completion of this contract. The contractor shall transfer all materials not depleted to the COR by way of Material Inspection and Receiving Report (DD Form 250). Material costs may include general and administrative expenses but shall not include profit/fee.

3.1.6 Subcontractors: Provisions stated herein shall be clearly and effectively communicated to all subcontractors providing support under this contract. All provisions of this SOW shall flow down to subcontractors providing support under this contract.

3.1.7 Management of Contractor Personnel: The Government will neither supervise contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances will the Government assign tasks to, or prepare work schedules for, individual contractor employees. The Contractor shall manage its employees and guard against any actions that are of the nature of personal services, or give the perception of personal services.

3.2 Security

3.2.1 Citizenship Requirements: Only U.S. citizens may perform under this contract, unless waived by the Government. If the Contractor cannot find qualified U.S. citizens to perform the work, the Contractor shall submit a citizenship waiver request with justification to the Government Security Office. The waiver request should include:

a. The individual's name, date and place of birth, position title, and current citizenship.

b. A statement that a qualified U.S. citizen cannot be hired in sufficient time to meet the contractual requirements.

c. A statement of the unusual expertise possessed by the applicant.

d. A statement that access will be limited to a specific government contract (specify contract number).

e. A statement that the Contractor has obtained an export license for the information required to perform the contract.

3.2.2 Investigative Requirements:

Unclassified: All contractor personnel must be eligible to perform Non-Critical Sensitive work as defined by SECNAV M-5510.30C. All contractor personnel are required to have a favorably adjudicated Tier-3 investigation from the OPM. The Contractor shall submit a request for personnel security investigation to the Government Security Office. The Government Security Office shall initiate the contractor employee's Electronic Questionnaire for Investigations Processing (eQIP) and shall perform a preliminary screening of the contractor employee's eQIP for suitability and derogatory information. The contractor employee shall provide all requested information pursuant to the Privacy Act of 1974. The Government Security Office may deny the contractor employee access to Government facilities and information and may prohibit the contractor employee from performance of sensitive duties for failure to provide requested information or when derogatory or adverse information is present on the contractor employee's eQIP. In such cases, the contractor employee may not perform on the Contract.

AND

Classified: Contractor personnel requiring Privileged access to the Contract Writing Servers will require a Top Secret clearance level, all other contractor employees will be required to obtain a clearance at the Secret level.

The Classification of the work performed will be annotated in the Contract's DD-254, Contract Security Classification Specification Form. Contractor personnel shall require access to classified information in performance of this Contract up to and including Top Secret facility level, with a safeguarding level of Top Secret, non possessing. The Contractor is responsible for ensuring that all personnel receive the requisite investigation and are favorably adjudicated IAW National Industrial Security Program Operating Manual (NISPOM) codifying 32 Code of Federal Regulation Part 117, NISPOM Rule. Contractor employees who fail to meet security clearance requirements may not access classified information or perform sensitive duties. In such cases, the Offeror employee may not perform on the Contract.

3.2.3 Common Access Card (CAC)/Public Key Infrastructure (PKI), System Authorization Access Request

(SAAR-N).

3.2.3.1 SAAR-N: All contractor personnel requiring access to Government Information Technology (IT) systems shall have an approved System Authorization Access Request (SAAR-N) Form OPNAV 5239/14 (Rev Sep 2011) on file, and complete required Annual Information Awareness Training. New employees must submit their SAAR forms within thirty (30) days of their first day of work. Instructions for processing the SAAR-N forms are available at: CCSG11_OPNAV_5239_14SAAR_N.pdf (navy.mil) SAAR-N forms shall be submitted to the Contracting Officer’s Representative (COR), Government Technical Point of Contact (TPOC), or to the assigned government Trusted Associate Sponsorship System (TASS) Trusted Associate.

3.2.3.2 Command Access Cards (CAC) / Local Badges: Contractor CACs and facility specific identification badges will be issued by the Government to on-site Offeror personnel and shall be visible at all times while personnel are at the Government site. The Contractor shall furnish all requested information required to facilitate issuance of identification badges. All CACs and identification badges issued to Contractor employees shall be returned to the TA following completion of the contract, relocation or termination of an employee, or upon request from the Contracting Officer’s Representative/PCO. The Government will provide the Contractor access to Government facilities, as required, for performance of tasks under this contract.

3.2.3.3 DD-254: The Contractor shall comply with security requirements specified in the DD-254 attached to this contract. Information or data that the Contractor accesses shall be handled at the appropriate classification level.

3.2.3.3.1 The Contractor will require access to:

1.1.1.1.1 Non-SCI

North Atlantic Treaty Organization (NATO) Information Foreign Government Information Controlled Unclassified Information (CUI) SIPRNet access required at Government Facilities

3.2.3.3.2 In performing this Contract, the Contractor will:

Have access to classified information only at another contractor’s facility or a Government activity Perform services only Have operations security (OPSEC) requirements Receive, store, or Generate Controlled Unclassified Information (CUI)

3.2.4 Information Security. If the work is performed at the Contractor's facility, the Contractor shall implement and maintain security procedures and controls to prevent unauthorized disclosure of classified information and controlled unclassified information (CUI) and to control distribution of CUI in accordance with National Industrial Security Program Operating Manual (NISPOM) codifying 32 Code of Federal Regulations Part 117, NISPOM Rule and SECNAV M-5510.36B, Department of the Navy, Information Security Program. I

All contractor facilities shall provide an appropriate means of storage for CUI and materials. All CUI including legacy FOUO information and Covered Defense Information (CDI) (meeting the definition DFARS Clause 252.204–7012, Safeguarding Covered Defense Information and Cyber Incident Reporting) generated and/or provided under this Contract shall be marked and safeguarded as specified in DoD Instruction 5200.48, Controlled Unclassified Information (CUI) available at https://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/520048p.PDF.

Any product containing CDI shall be assigned a distribution statement (distribution statements B through F) using the criteria set forth in DoDI 5230.24, Distribution Statements on Technical Documents and have this statement displayed per DoDI 5230.24, Enclosures 3 and 4. Distribution is authorized to the Requiring Office's Organization and supported Activity only. Other requests for deliverables under this Contract shall be referred to the TPOC/COR of this Contract for approval.

All controlled unclassified technical information shall be appropriately identified and marked with the following distribution statement(s):

Distribution Statement (Insert Appropriate Letter and Authorization Title), (Insert Appropriate Reason Category) (dated – (Date of Distribution Authorization). Other requests shall be referred to: Commander, Naval Air Systems Command, Attn: Program/User Agency mailing address

3.2.4.1 Marking. All information generated by the Contractor shall be properly marked. Classified information shall be marked IAW DoDM 5200.01, Vol 2, Marking of Classified Information. CUI, including Legacy FOUO information generated and/or provided under this Contract shall be marked IAW DoDI 5200.48. Technical information shall also be marked with appropriate Distribution Statements and Export Control warnings IAW DoDI

5230.24 and program Security Classification Guidance.

3.2.4.2 Public Release. Any CUI pertaining to this Contract shall not be released for public dissemination, including posting to any social media sites such as Facebook or Twitter, unless it has been approved for public release by appropriate U.S. Government authority. Proposed public releases shall be submitted for approval prior to release through:

Public Affairs Office 47123 Buse Road, RADM William A. Moffett Building Patuxent River, MD 20670-1547

3.2.4.3 Loss, Compromise and/or Electronic Spillage of Classified or Controlled Unclassified Information:

All instances of loss, compromise and electronic spillage of classified or controlled unclassified information shall be reported to the COR, TPOC and Government Security Office within 72 hours of the incident occurring.

3.2.4.4 Compliance to NIST 800-171

In accordance with DOD INSTRUCTION 8582.01 SECURITY OF NON-DOD INFORMATION SYSTEMS PROCESSING UNCLASSIFIED NONPUBLIC DOD INFORMATION, the Contractor shall implement the CUI Security Requirements (Requirements) and associated Relevant Security Controls (Controls) in NIST Special Publication 800-171 (Rev. 1) (NIST SP 800-171), or establish a System Security Plans (SSP) and Plans of Action and Milestones (POAM) that varies from NIST 800-171 only in accordance with DFARS clause 252.204- 7012(b)(2), for all covered contractor information systems affecting this contract.

The Contractor shall, at a minimum, meet the Basic Safeguarding Requirements as follows to meet the comparable security requirements of the NIST SP 800-171 as indicated.

The Government may, in its sole discretion, conduct reviews at the Contractor’s site to verify compliance. The Government will conduct such reviews at least every three (3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty (30) days’ notice to the Contractor.

If the Government determines that the security controls do not adequately implement the requirements of NIST 800- 171, then the Government shall notify the Contractor of each identified deficiency. The Contractor shall correct any identified deficiencies within thirty (30) days of notification by the Government. The contracting officer may provide for a correction period longer than thirty (30) days and, in such a case, may require the Contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies. The Contractor shall immediately notify the contracting officer of any failure or anticipated failure to meet a milestone in such a POAM.

Upon the conclusion of the correction period, the Government may conduct a follow-on review at the Contractor’s facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies.

3.2.5 Operations Security (OPSEC): The Contractor shall develop, implement, and maintain an OPSEC program to protect controlled unclassified and classified activities, information, equipment, and material used or developed by the Contractor and any subcontractor during performance of the contract. The Contractor shall be responsible for the subcontractor implementation of the OPSEC requirements. This program may include Information Assurance and Communications Security (COMSEC). The OPSEC program shall be in accordance with National Security Decision Directive (NSDD) 298, and at a minimum shall include:

1) Assignment of responsibility for OPSEC direction and implementation.

2) Issuance of procedures and planning guidance for the use of OPSEC techniques to identify vulnerabilities and apply applicable countermeasures.

3) Establishment of OPSEC education and awareness training.

4) Provisions for management, annual review, and evaluation of OPSEC programs.

5) Flow down of OPSEC requirements to subcontractors when applicable.

While performing aboard NAVAIR or NAVAIR sites, the Contractor shall comply with facility OPSEC program instructions and contribute to organization-level OPSEC efforts. Include OPSEC as part of its ongoing security awareness program and take all required Agency training. Be responsive to the Supporting OPSEC Manager on a non-interference basis. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of operations performed by the RO and Contractor in support of the mission.

3.2.6 Anti-Terrorism Force Protection and Emergency Management: The work performed on this contract is not Emergency Essential in accordance with OPNAVINST 3440.17A and Government Emergency Management, Antiterrorism and/or Continuity of Operations Plans. Contractor personnel shall comply with all Government Emergency Management, Antiterrorism and/or Continuity of Operations Plans and directives. Contractor personnel shall not report for work at Government facilities upon declaration of Force Protection Condition CHARLIE or in any event or emergency where Government officials direct curtailment of operations to “Mission Essential Only”.

All Contractor personnel assigned to a Government facility shall complete annual Antiterrorism (Level One) and Active Shooter training.

3.2.7 Cyber Incident Response

The Contractor shall, within fifteen (15) days of discovering the cyber incident (inclusive of the 72-hour reporting period, reference https://dibnet.dod.mil/portal/intranet/), deliver all data used in performance of the contract that the Offeror determines is impacted by the incident and begin assessment of potential warfighter/program impact.

Incident data shall be delivered in accordance with the Department of Defense Cyber Crimes Center (DC3).

Reference https://www.dc3.mil/Organizations/DIB-Cybersecurity/DIB-Cybersecurity-DCISE/

In delivery of the incident data, the Contractor shall, to the extent practical, remove Contractor-owned information from Government covered defense information.

If the Contractor subsequently identifies any such data not previously delivered to DC3, then the Contractor shall immediately notify the contracting officer in writing and shall deliver the incident data within ten (10) days of identification. In such a case, the Contractor may request a delivery date later than ten (10) days after identification.

The contracting officer will approve or disapprove the request after coordination with DC3.

3.2.8 NCIS/Industry Monitoring In the event of a cyber-incident or at any time the Government has indication of a vulnerability or potential vulnerability, the Contractor shall cooperate with the Naval Criminal Investigative Service (NCIS) and associated law enforcement agencies, which may include cooperation related to: threat indicators; pre-determined incident information derived from the Contractor's infrastructure systems; and the continuous provision of all Contractor, or vendor logs that show network activity, including any additional logs the Contractor, subcontractor, or vendor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.

If the Government determines that the collection of all logs does not adequately protect its interests, the Contractor shall cooperate with the NCIS to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by NCIS, on the Contractor's information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an NCIS network device shall be the subject of a separate agreement negotiated between NCIS and the Contractor. In the alternative, the Contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by NCIS. Use of this alternative approach shall also be the subject of a separate agreement negotiated between NCIS and the Contractor.

In all cases, the collection or provision of data and any activities associated with this statement of work shall be in accordance with federal, state, and non-US law.

3.3 Detailed Support Requirements: This section provides the detailed support to be provided by the Contractor.

3.3.1 Functional eBusiness Support

The eBusiness Architecture and Management function provides centralized oversight and leadership for NAVAIR’s eBusiness technical architecture and portfolio. Effective management ensures standardized business practices, information sharing, and collaboration across various NAVAIR sites, promoting alignment in architecture and business operations. The overarching goal is to establish an eBusiness Architecture and Management oversight lead who will focus on optimizing the efficiency and responsiveness of the NAVAIR eBusiness environment. The following objectives outline the key responsibilities and expected outcomes:

A. Maximizing Efficiency: The lead shall maximize the efficiency of the eBusiness environment by providing timely, high-quality management, oversight, and coordination between architecture Subject Matter Experts (SMEs) at each NAVAIR eBusiness site. These sites include HQ, LKE, PAX, TSD, WD, JSF, COMFRC, DASN (P), and other DoD sites as required. The coordination will ensure seamless integration and collaboration between sites to drive consistent business practices.

B. Adapting to New Requirements: The lead shall adapt to the changing needs of NAVAIR and maintain the capability to support new requirements and processes that impact eBusiness systems. This includes ensuring the systems' ability to evolve with initiatives such as Navy Enterprise Resource Planning (NERP), security updates, ePS integration, Standard Procurement System (SPS) upgrades, and changes stemming from FIAR (Financial Improvement and Audit Readiness) or other audit-driven requirements.

C. Realistic Oversight Plan: The lead shall develop and maintain an oversight plan that is appropriate, realistic, and deliverable, ensuring that all stakeholders are aligned with the goals and objectives of the eBusiness enterprise

(CDRL XXX).

D. Process Improvements and Value Addition: The lead shall incorporate process improvements and changes that improve the services provided to end users and add value to command initiatives. These improvements will enhance user experience, streamline operations, and increase overall system efficiency.

E. Technical Portfolio Management: The lead shall manage and regularly update the technical portfolio of eBusiness systems across NAVAIR and the Navy, ensuring that the systems are up to date, aligned with enterprise standards, and capable of supporting NAVAIR’s contracting and procurement needs.

F. Oversight of RMF Accreditation: The lead shall be responsible for oversight of NAVAIR eBusiness systems’ Risk Management Framework (RMF) accreditation process, including system security, compliance, and ongoing risk management. This includes managing activities such as Baseline Change Requests (BCRs) to ensure system integrity and compliance.

G. Management of Data Feeds: The lead shall be responsible for the oversight and management of key data feeds that integrate with NAVAIR’s eBusiness systems. This includes data exchange with the Navy ERP Interface, NAVAIR Proposal Analysis Division, Comprehensive Cost and Requirements System (CCARS), Defense Agencies Initiative (DAI), Acquisition Management System (AMS), Small Business Dashboard, Contract Closeout systems, and the NAVAIR Data Warehouse via secure file transfer protocols SFTP and HTTPS.

H. Management of Tools and System Interfaces: The lead shall manage and oversee critical tools and system interfaces, such as the Procurement Data Standard Conformed Award Utility (PDS CAU), data migration tools, and the AMS to ePS interface. These tools are essential for ensuring data standardization, system compatibility, and operational efficiency.

I. Data Migration Oversight:

a. Data Cleansing: The lead shall be responsible for overseeing the data cleansing of NAVAIR’s Procurement Data Standard (PDS) data. This involves reviewing the data for consistency and ensuring it adheres to the required standardized format, thereby eliminating redundant, outdated, or inaccurate information.

b. System Integration: The lead shall ensure that the data migration process integrates legacy system data into ePS (electronic Procurement System), ensuring that future procurement actions and historical data are properly aligned with standard formats and workflows.

c. Testing and Validation: The lead shall oversee testing and validation to confirm that migrated data has been correctly transferred and functions properly within the new system. This ensures that the integrity and usability of procurement data are maintained.

d. Training and User Adaptation: The lead shall be responsible for providing end-user training on PDS error resolution and the new system features. This includes developing user training materials to ensure that staff are equipped to manage data migration issues and adapt to the new processes

3.3.2 General eBusiness Support

To accomplish the tasks described in this Statement of Work (SOW) and ensure the efficient management and oversight of NAVAIR’s eBusiness systems, the contractor shall perform as a lead/project manager and shall:

A. Provide Expert Task Management and Resource Allocation: Assist NAVAIR management by providing highly experienced leadership in supporting and overseeing task efforts. The contractor shall leverage other contractor resources and allocate them efficiently to meet the objectives of each task, ensuring high performance and adherence to NAVAIR’s mission goals.

B. Prioritize and Manage Resources Effectively: Utilize extensive knowledge of NAVAIR’s operational environment to assist management in organizing task priorities. The contractor shall allocate sufficient resources, ensuring that every task is completed on time and within the required scope to meet NAVAIR’s business objectives.

C. Ensure Effective Communication and Reporting: Maintain clear and consistent communications with NAVAIR Government personnel and program office staff, ensuring they are kept up to date on the status of all supported projects and tasks. The contractor shall promptly notify Government personnel of any programmatic or logistical problems, offering immediate resolutions when issues arise. Both verbal and written communications shall be used as appropriate.

D. Accountability for Task Completion and Process Documentation: Take responsibility for all assigned tasks, ensuring follow-through from inception to completion. The contractor shall document and update all relevant processes, aligning with NAVAIR’s current and emerging requirements to support operational consistency and audit readiness.

E. Provide Advanced Business Process Support: Offer advanced business process support for NAVAIR’s contracting and related contract systems, utilizing deep expertise in these systems to ensure seamless operation and integration with NAVAIR’s broader procurement, data, and compliance strategies.

F. Develop and Execute POA&M for SPS and ePS Service Releases: Create and maintain a comprehensive Plan of Action & Milestones (POA&M) for both SPS (Standard Procurement System) and ePS (electronic Procurement System) service release upgrades and patches. The contractor shall manage and execute all upgrades and patches for each software update/release, ensuring system stability, minimal operational disruption, and compliance with NAVAIR’s long-term goals.

G. Develop POA&M for ePS Service Releases: Create and execute a POA&M for the implementation of ePS (electronic Procurement System) service releases. The contractor shall ensure that all ePS updates are fully integrated with existing systems and processes, supporting NAVAIR’s evolving procurement needs.

H. Conduct Transactional Analysis for Navy ERP, SPS, and ePS Interactions: Perform comprehensive transactional analysis of interactions between Navy ERP, SPS, and ePS, including transactions between SPS to Navy ERP and ePS to Navy ERP. The contractor shall proactively research and troubleshoot any transactional failures across these systems, ensuring data accuracy, operational continuity, and seamless integration within NAVAIR’s eBusiness environment.

I. Provide Desktop User Support: Offer Tier 1 and Tier 2 support for desktop hardware, software, and peripheral devices. The contractor shall ensure rapid response and resolution of user issues to maintain high levels of operational efficiency for NAVAIR personnel utilizing eBusiness systems.

J. Tier 1 & 2 Troubleshooting for Acquisition Management System (AMS) and ePS Issues: Provide Tier 1 and Tier 2 technical support for AMS and ePS. The contractor shall utilize a strong understanding of these systems to troubleshoot and resolve issues efficiently, minimizing downtime and ensuring the continuity of mission-critical functions.

K. Comprehensive Functional Support Desk Management with Information Technology Infrastructure Library (ITIL) and Support Ticket Tracking: Oversee and manage the functional support desk, ensuring that all incoming inquiries and technical issues are addressed promptly and effectively. The contractor shall implement ITIL best practices in managing support tickets and use issue tracking software to ensure proper documentation, resolution, and reporting of all issues. This process ensures transparency, accountability, and continuous improvement in NAVAIR’s eBusiness system support.

3.3.3 Audit Support

The objective of the Audit Support is to provide expert resources with in-depth knowledge of ongoing Navy audit efforts, including FISCAM (Federal Information System Controls Audit Manual), SBA (Statement of Budgetary Authority), and all related FIAR (Financial Improvement and Audit Readiness) efforts. The support provided must focus on implementing process improvements and providing oversight for audit-related findings, ensuring all necessary controls are fully adhered to, documented, and aligned with NAVAIR's compliance requirements. The contractor will participate in both internal NAVAIR audits and external Navy-wide audits as required, with direct communication and coordination with auditors as a critical component of the role.

The contractor shall:

A. Support Audits and Related Requests: Assist in responding to audit requests, including providing artifacts, supporting documentation, and responding to Notice of Findings and Recommendations (NFR) issued by auditors.

This includes supporting both the physical audit process and any follow-up audit events, ensuring timely and accurate submission of required materials.

B. Demonstrate Expertise in Audit-Related Controls: Be highly knowledgeable in audit-related controls, particularly as they pertain to NAVAIR's Contracts eBusiness Systems as a feeder system in the Contract Vendor Pay (CVP) process. The contractor shall understand the system’s role in facilitating compliance within the CVP process and other procurement-related functions.

C. Define and Document Processes and Artifacts: Develop, document, and refine processes, procedures, and training materials necessary for addressing audit findings. The contractor shall ensure these materials are comprehensive and aligned with the audit requirements. This includes the development and submission of Contract Data Requirements List (CDRL) A005, ensuring that all artifacts pertaining to audit findings are well-documented and accurate.

D. Provide Audit Findings to Leadership: Regularly report audit findings and insights to NAVAIR leadership, highlighting areas where additional user training is required to maintain compliance. The contractor shall identify and communicate compliance gaps, recommending corrective actions and user training to mitigate future audit risks.

E. Participate in Audit-Related Meetings and Recommendations: Attend meetings with NAVAIR personnel, auditors, and relevant stakeholders to provide input, make recommendations, and assist in the development and implementation of new processes and procedures for the eBusiness audit environment. The contractor’s expertise shall ensure that proposed changes are compliant with audit standards and improve NAVAIR’s audit readiness.

F. Attend Training for New Software and Processes: Attend Government-provided and/or contractor-provided training sessions that support the implementation of new software or processes relevant to NAVAIR’s eBusiness systems and audit requirements. The contractor shall ensure they stay current with all process changes, system updates, and best practices to continue delivering high-quality audit support.

3.3.4 Data Integration and Alignment Support

The objective of the Data Integration and Alignment support is to provide highly skilled resources who understand the data compiled and produced by NAVAIR’s Contract Writing Systems (SPS, SeaPort-e, ePS), as well as data from other systems such as the Federal Procurement Data System-Next Generation (FPDS-NG), Workload Requirements and Planning (WRAP), and Procurement Management Tool (PMT). The contractor shall ensure this data is effectively used, shared, and aligned to support NAVAIR’s Data Strategy goals, which include: Increasing Data Integration, Establishing Enterprise Data Standards, Improving Data Accessibility, and Strengthening Data Analytical Expertise. The contractor shall actively participate in working groups, integration efforts, data mapping, and data alignment initiatives to support these command objectives.

The contractor shall:

A. Provide Expertise in Data Mining and Data Alignment: Leverage deep knowledge of data mining, extraction, and alignment processes to support NAVAIR’s data integration efforts. The contractor shall help identify, organize, and align data from various systems to ensure it can be effectively utilized for decision-making and command-level initiatives.

B. Demonstrate Knowledge of Contracts Data in Core Systems: Possess comprehensive knowledge of contracts data housed in systems such as SPS, SeaPort-e, ePS, FPDS-NG, WRAP, and PMT. The contractor shall understand how data flows between these systems and other business systems, ensuring accurate integration and alignment in support of NAVAIR’s broader enterprise goals.

C. Develop Processes and Documentation for Data Integration and Alignment: Define, document, and develop processes, procedures, training materials, and artifacts related to contracts data integration and alignment. This includes ensuring that NAVAIR’s systems and personnel can effectively utilize contract data in a manner that aligns with DoD and DON data standards and supports continuous data accessibility improvements.

D. Provide Feedback and Recommendations to Leadership: Regularly offer expert feedback and actionable recommendations to Government Leadership regarding the most effective ways to use and align contracts data with other business systems data. This feedback shall focus on enabling NAVAIR leadership to make more informed and data-driven decisions, improving the efficiency and accuracy of procurement and contract management activities.

E. Participate in Meetings and Provide Input on Contract Data Initiatives: Attend relevant meetings and working groups, contributing to discussions related to contract data integration efforts. The contractor shall provide input and recommendations on how contract data can be used to inform command buying decisions, enhance historical trend analysis, and support broader NAVAIR and Navy data initiatives.

3.3.5 Management and Oversight of Technical Support

The contractor shall provide expert management and oversight of technical resources to ensure the smooth operation, optimization, and maintenance of NAVAIR’s eBusiness systems and databases. This includes responsibility for coordinating resources, troubleshooting, and supporting integration with Navy ERP and other electronic acquisition systems.

The contractor shall:

A. Provide Oversight and Management of Technical Resources:

1. Optimize Operations and Database Support: Oversee technical resources responsible for optimizing the operations of NAVAIR’s Contract Writing Systems. This includes providing technical support in setting up, controlling machine configurations, troubleshooting issues, and tuning and maintaining the databases at NAVAIR eBusiness sites to ensure high performance and reliability.

2. Manage Functional and Technical…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .