Attachment_01_-_TADS_Overarching_Performance_Work_Statement.docx
DOCX document 75 KB Posted
- Attached to
- Technology Applications Development and Sustainment (TADS) Federal contract opportunity
- Solicitation number
- FA4600-19-R-A001
About this file
This performance work statement outlines requirements for the Technology Applications Development and Sustainment indefinite-delivery, indefinite-quantity contract to provide capability development and sustainment services to the Air Force Weather Systems Program Office. Key requirements include systems engineering, software development, configuration management, logistics analysis, installation, and sustainment services to deploy and maintain weather sensing, processing, and dissemination capabilities. The contractor must develop and sustain capabilities using open architectures and manage changes to technical solutions. The contractor shall also perform hardware and software maintenance, license management, systems administration, and systems performance measurement. Cybersecurity requirements include implementing and sustaining security controls, conducting scans and remediating vulnerabilities, and supporting risk management framework activities and documentation. The contractor must maintain CMMI level 3 and describe processes in plans for systems engineering, program management, security, and configuration management.
Attachment 01 - TADS Overarching Performance Work Statement
View the file
Other files for this federal contract opportunity
Show all 30
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
TECHNOLOGY APPLICATION DEVELOPMENT AND SUSTAINMENT (TADS)
TADS Overarching Performance Work Statement
(PWS)
FA4600-19-R-A001
Attachment 01 24 June 2019
| 1 Introduction | 4 |
| 1.1 Mission | 4 |
| 1.2 Enterprise Description | 4 |
| 1.3 Objectives | 5 |
| 2 General Requirements | 6 |
| 2.1 Non-Personal Services | 6 |
| 2.2 Business Relations | 6 |
| 2.2.1 Ordering | 6 |
| 2.2.2 Small Business Participation | 6 |
| 2.2.3 Mandatory Sources | 6 |
| 2.2.4 Closeout | 6 |
| 2.3 Location and Hours of Work | 7 |
| 2.4 Travel / Temporary Duty (TDY) | 7 |
| 2.5 Contingency Support | 8 |
| 2.6 Performance Evaluation | 8 |
| 2.7 Data Rights | 8 |
| 2.8 Innovation | 8 |
| 2.9 Capability Maturity Model Integration (CMMI)® | 9 |
| 3 Performance Requirements | 9 |
| 3.1 Capability Development | 9 |
| 3.1.1 Systems Engineering | 9 |
| 3.1.2 System Test and Evaluation | 13 |
| 3.1.3 Implementations | 13 |
| 3.1.4 Installations | 13 |
| 3.1.5 Systems Decommission | 13 |
| 3.1.6 Facilities Integration | 13 |
| 3.1.7 Data Management | 14 |
| 3.2 Capability Sustainment | 14 |
| 3.2.1 Systems Performance Measurement | 14 |
| 3.2.2 Hardware Maintenance | 15 |
| 3.2.3 Software Maintenance | 15 |
| 3.2.4 License Management | 15 |
| 3.2.5 Systems Administration | 15 |
| 3.3.1 Cybersecurity Tasks | 16 |
| 3.3.2 Cybersecurity Documents | 17 |
| 3.4 Program Management | 17 |
| 3.4.1 Financial Management | 18 |
| 3.4.3 Program Management Meetings | 18 |
| 3.4.4 Program Risks | 18 |
| 4 Special Requirements | 18 |
| 4.1 Security and Safety | 19 |
| 4.1.1 Security | 19 |
| 4.1.1.1 Access Devices | 19 |
| 4.1.1.2 Security Directive Compliance | 19 |
| 4.1.1.3 Escort Duties | 19 |
| 4.1.1.4 Contractor Area Access | 20 |
| 4.1.1.5 Restricted Areas | 20 |
| 4.1.2 Safety | 20 |
| 4.2 Transition | 20 |
| 4.2.1 Phase-in | 20 |
| 4.2.2 Phase-out | 20 |
| 4.3 Government Furnished Property (GFP) | 21 |
| 4.3.1 Government Furnished Test Equipment | 21 |
| 4.3.2 End of Life, Government Furnished Property | 21 |
| 4.3.3 Government Furnished Computer Equipment | 21 |
| 4.3.4 Physical Security | 21 |
| 4.4 Government Facilities | 21 |
| 4.4.1 Contractor Office Space | 22 |
| 4.4.2 Government Provided Services | 22 |
| 4.4.3 Facility Hazards | 22 |
| 4.4.4 Equipment Relocation | 22 |
| 4.5 Quality | 23 |
| 4.6 Operational Security (OPSEC) | 23 |
| 4.7 Packaging and Shipping | 23 |
| 4.8 Mail | 23 |
FA4600-19-R-A001
Attachment 01 -- TADS Performance Work Statement
Performance Work Statement (PWS) Technology Application, Development and Sustainment Vision Statement To deliver to the Air Force Weather warfighter, combatant forces, and decision makers the most accurate and timely space and terrestrial environmental intelligence anywhere.
1 Introduction This Performance Work Statement (PWS) specifies the U.S. Air Force Life Cycle Management Center Air Force Weather (AFW) Systems Program Office requirement for new capability deployment and sustainment services. These services ensure AFW meets warfighter requirements for actionable weather information needed in worldwide military unit operations, weapons employment planning, resource planning, and strategic decision making. To meet the changing warfighting environment and structure, AFW must innovate and rapidly deploy new capabilities to provide critical environmental situational awareness where needed. The services required are new technology analysis and planning, research, development, requirements analysis, systems engineering, capability design and development, system modification, configuration analysis and management, end of life replacement, integration, test, sustainment (including but not limited to software and hardware modification, adaptive, and corrective activities), systems performance evaluation, logistical analysis and management, and fielding.
This PWS establishes the overall goals, objectives, expectations, responsibilities, and nature of TADS task orders. This document provides neither an all-inclusive nor exclusive description of requirements that may be ordered within scope of the Indefinite-Delivery-Indefinite-Quantity (IDIQ) contract.
1.1 Mission
The mission of AFW is to arm our nation's forces with essential air and space environmental intelligence, training, and technical services to ensure battlespace awareness and decision superiority. The 557th Weather Wing (WW) produces weather products for the US combat forces, the combatant commands, all United States Air Force (USAF) major commands, all United States Army (USA) major commands, and other agencies as directed by the Chief of Staff, USAF. AFW collects, quality controls, and processes worldwide terrestrial and space meteorological data to provide a wide range of tailored military products describing the present and future states of the aerospace environment. The Contractor shall provide the capability development and sustainment necessary for AFW systems to be available to support AFW's mission(s).
1.2 Enterprise Description
The AFW enterprise consists of data ingest, data processing, data distribution, and sensors world-wide. These elements consist of hardware, software, communications, sensors and people who provide environmental information to customers in the Department of Defense, other federal departments and agencies and other countries. The enterprise ingests weather observations, satellite data and radar data, stores and processes the data to produce reports and forecasts. These results are sent to customers via several communication outlets including a web presence and machine to machine. Weather information is available in all security enclaves.
The strategic data center at Offutt Air Force Base (AFB) and climatological data center at Ashville, NC provide data and forecast products for worldwide operations. Operational Weather Squadrons provide regional products to areas of responsibility. Weather flights assigned to various units provide specific products to meet the mission needs of the supported units.
AFW possess capabilities required by USAF and USA mission planning, situational awareness tools and automated flight planning services. Weather Common Component (WxCC) provides environmental data services that are interoperable with flight planning systems, mobility planning systems, Air Operation Centers, intelligent data services, Joint Environmental Tool Kit and Consolidated Airdrop Tool.
Environmental awareness is not confined to terrestrial operations but also includes space, outside earth's immediate atmosphere. Ground sensors provide ionospheric characterization. Solar observation data is compiled and analyzed. A combination of space environmental models and data ingest provides tools to identify environmental threats and issue warnings to space and terrestrial operations.
AFW provides capabilities to produce and distribute an integrated suite of weather products for the Modeling and Simulation community. The software application is hosted on GovCloud. Products are produced for human and machine consumption, and are distributed for event execution.
A major requirement will be to move the data processing orientation from hardware centric to software centric - Cloud Computing, building elastic applications. Cloud computing will allow AFW to quickly expand and contract with mission needs. It has the promise of providing disaster recovery for fixed base processing elements and increased collaboration among AFW elements, anywhere.
AFW wants to investigate and implement innovative ideas to improve mission performance such as big data analytics, machine learning and improvements in meteorological and space weather science. AFW wants to continue to integrate Government sponsored initiatives and prototypes. A major initiative is Air Force systems integration which allows delivery of data/products directly into warfighter applications.
1.3 Objectives
The TADS objectives are to provide cost-effective capability development and sustainment for the AFW enterprise bringing new requirements and innovations to fruition. Orders under TADS will support development, delivery, and sustainment of an integrated system of weather enterprise hardware and software dedicated to providing accurate, consistent, relevant, and timely environmental intelligence. The specific objectives are:
a. Assess the risks and plan the prototyping and integration of new technologies that increase the relevance of environmental intelligence in mission planning and execution across DoD and coalition operations.
b. Design effective solutions to satisfy technical, operational, cybersecurity, and personnel requirements. Maximize use of modular, interoperable components with the focus on reducing disparate capabilities and drive toward a common baseline.
c. Fully integrate multi-level (multiple enclave) cybersecurity capabilities into the design, development, testing, fielding, operation, and sustainment.
d. Increase overall AFW enterprise system reliability and optimize performance of current and future capabilities to ensure the timely delivery of actionable environmental intelligence to meet the full spectrum of military planning and operations.
e. Meet 24/7 system operational availability and performance requirements to provide operational support across all Combatant Commands, national agencies, and international organizations.
2 General Requirements This section describes the general requirements for this contract. The following sub-sections provide details of various considerations concerning performance other than desired outcomes.
2.1 Non-Personal Services
The Government shall neither supervise Contractor employees nor control the method by which the Contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual Contractor employees. It shall be the responsibility of the Contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the Contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor's responsibility to notify the contracting officer immediately.
2.2 Business Relations
The Contractor shall successfully integrate and coordinate all activity needed to execute the contract to deliver the required capabilities and to sustain the AFW enterprise. The Contractor shall manage the timeliness, completeness, and quality of the overall contract as well as the individual orders. The Contractor shall be transparent and provide timely notice of any real or perceived problems that affect the cost, schedule or performance of any aspect of the AFW enterprise, to include the development of any required corrective action plans. The Contractor shall effectively manage all sub-Contractors and where applicable and appropriate. The Contractor shall seek to ensure customer satisfaction and will ensure the ethical behavior of all Contractor personnel.
2.2.1 Ordering
The contracting officer shall provide a Task Order Request (TOR) for all orders. After a TOR is sent to the Contractor, the contracting officer shall be the conduit for all related communications between the Government and Contractor until the TOR is awarded. The Contractor shall provide an adequate proposal within 20 business days after TOR receipt. Contract Attachment 3 – Ordering Process provides more detailed instructions.
2.2.2 Small Business Participation
The TADS small business goal is to subcontract at least 20% of the total obligations across all orders to small businesses. If the goal is not met during any reporting period, the Contractor shall be required to demonstrate their good faith efforts to meet the subcontracting goals. Failure to meet the small business goal may result in negative past performance ratings and liquidated damages in accordance with FAR Clause 52.219-16, Liquidated Damages—Subcontracting Plan.
2.2.3 Mandatory Sources
The Contractor shall use DoD Enterprise Software Initiative (www.esi.mil) sources to procure all commercial software, enterprise licenses, and Software as a Service (SaaS) when the Enterprise Software Initiative has an existing agreement available.
2.2.4 Closeout
For all orders, the Contractor shall complete all closeout actions and provide a final release of claims to the contracting officer within 180 calendar days after the task order is physically complete, as defined by FAR 4.804-4.
For the IDIQ contract, the Contractor shall complete all necessary closeout actions within one (1) calendar year after the IDIQ is physically complete, as defined by FAR 4.804-4.
2.3 Location and Hours of Work
Accomplishment of the results contained in each task order requires work at various Contractor, sub-Contractor, and Government facilities. Government locations include but are not limited to the HQ 557th WW location in the Lt. General Thomas S. Moorman Building (Bldg 185) on Offutt Air Force Base (AFB) NE and the adjoining areas on Offutt AFB, and the 14th Weather Squadron, 151 Patton Ave Room 120, Asheville, NC. The Contractor shall perform services at other locations including other AFW locations.
The Contractor's normal hours of operation shall be 0730 to 1630 US Central Time, Monday through Friday, excluding federal holidays. The Government retains the right to change normal working hours at any time. The Contractor shall meet unscheduled mission or emergency requirements on a 24-hour basis, 365 days a year. The Contractor shall provide surge support for requirements as determined by Government priority and tasking. Surge support is defined as short-term support (a few weeks duration) above normal operational levels necessary to address high priority immediate needs.
The Contractor personnel deemed non-essential for current on-site operations by the Government's CORs may be released during duty hours upon notification by the applicable base authority of a severe weather contingency or other emergency requiring release of Government personnel from duty. The Contractor shall participate in Government directed exercises, such as Shelter In Place (SIP), active shooter and fire drills. This list is not to be considered all inclusive.
The following legal holidays are observed:
| New Year’s Day* | 1 January | ||
| Martin L. King’s Birthday | Third Monday in January | ||
| President’s Day | Third Monday in February | ||
| Memorial Day | Last Monday in May | ||
| Independence Day* | 4 July | ||
| Labor Day | First Monday in September | ||
| Columbus Day | Second Monday in October | ||
| Veteran’s Day* | 11 November | ||
| Thanksgiving Day | Fourth Thursday in November | ||
| Christmas Day* | 25 December |
* Holidays that fall on Saturday are observed on the preceding Friday and holidays that fall on Sunday are observed on Monday.
2.4 Travel / Temporary Duty (TDY)
The Contractor may be required to travel within the contiguous United States and overseas in order to meet task order requirements. All Contractor travel shall be approved by the COR prior to occurrence.
The Contractor shall be responsible for obtaining any passports or visas and making travel arrangements to and from any CONUS and OCONUS locations. The Contractor may be required to travel by Government-provided transportation. The Government must submit a request for Government-provided transportation. When commercial air travel is authorized, the Contractor shall utilize coach, tourist, or similar accommodations.
Video Teleconference (VTC) or other alternate methods may be deemed mandatory versus travel, but this is a Government decision.
Transportation, per diem, and lodging expenses required in the performance of temporary duty shall be reimbursed to the Contractor in accordance with the Federal Acquisition Regulation FAR 31-205-46 and the Federal Travel Regulation.
Reimbursement for travel shall be on a cost-reimbursable basis upon submission of proper invoices and supporting documentation.
2.5 Contingency Support
The Contractor shall establish relationships with Contractor partners to provide contingency support to resolve applications, network, or system problems that may require assistance from an outside expert. Contingency support may be necessary during other than duty hours.
2.5.1 Continuity of Operations (COOP) Support
When called upon during major enterprise outages the Contractor shall provide personnel to relocate to an alternate CONUS 557 WW operating location to support 557 WW Continuity of Operations (COOP). The intent is to provide Contractor personnel with expertise in the following areas; network, software, system, hardware, data base, data distribution, and enterprise storage engineering, and systems administration to assist 557 WW to plan for and reconstitute capabilities that enable 557 WW mission essential functions to be performed at an alternate location. Billeting, consumables and transportation will be provided by the Government. Contractor will provide 557 WW quarterly input to the wing's COOP Fly-Away Kit, as described in paragraph 3.1.1.6.3.
When called upon the contactor shall provide minimum required number personnel to assist 557 WW to continue operations within Building 185 during COOP scenarios that may require individuals to remain on base 24/7 for up to 60 days. The intent is for contract personnel to continue to enable the 557 WW to operate, maintain and sustain the same applications, systems, and capabilities at the same level as for normal day-to-day operations. Billeting and consumable supplies will be provided by the Government.
2.6 Performance Evaluation
The Government will evaluate the Contractor's performance. The Incentive Fee Plan and the Services Summary as defined in individual task orders will specify the criteria of evaluation. In addition, Contractor performance shall be evaluated using the system performance measurement as awarded in each order. Government personnel will record all surveillance observations. Surveillance will be done in accordance with the inspection and acceptance clauses and the Government’s Quality Assurance Surveillance Plan.
2.7 Data Rights
Data rights are established based on the contract clauses and manner of funding for each deliverable. The Contractor must notify the contracting officer prior to committing to the use of privately developed items, components, processes or computer software with other than unlimited rights If at any time other than unlimited rights are proposed for delivery under this contract, the contracting officer reserves the right to negotiate the minimum technical data rights required.
2.8 Innovation
AFW seeks new approaches, ideas and inventions to better arm our nation's forces with more timely and accurate air and space environmental intelligence, training, and technical services to ensure battlespace awareness and decision superiority. No part of the enterprise is beyond the application of information, imagination and initiative to satisfy the needs and expectations of AFW customers. It is required that the Contractor be a proponent of new ideas and approaches to revolutionize AFW capabilities. AFW will also work to incentivize Contractor innovation that results in cost savings to the Government.
2.9 Capability Maturity Model Integration (CMMI)®
The Contractor shall maintain CMMI Development, Maturity Level 3, for the organizational unit responsible for TADS contract management and execution. The appraisal result shall be verifiable in the CMMI Institute Published Appraisal Results list available at https://sas.cmmiinstitute.com/pars/pars.aspx
3 Performance Requirements The following section specifies the overall capability development and the capability sustainment performance required under the IDIQ. Specific requirements shall be detailed in a Task Order Statement Of Objectives (SOO) or PWS.
3.1 Capability Development
The Contractor shall develop environmental intelligence capabilities for AFW. The Contractor shall provide systems engineering, requirements analysis, operational and technical analysis, design, software engineering, configuration management, logistics support analysis, development, integration, cyber security engineering, safety analysis, training support and risk management services as required per order.
3.1.1 Systems Engineering
The Contractor shall perform systems engineering to deploy new capabilities, and expand existing capabilities by upgrading, modifying, extending the service life and inserting new technology into the AFW systems. The Contractor shall employ disciplined systems engineering processes in accomplishing orders using commercial best practices for conducting technical reviews and performing requirements analysis, operational and technical analysis, design, software engineering, configuration management, logistics support analysis, development, integration, security, safety, risk management, implementation, and decommissioning. The Contractor shall ensure all designs consider open, flexible, and expandable/scalable architecture. The Contractor's design processes will manage changes in technical solutions given requirements reprioritization, budget adjustments, or new technologies. The Contractor shall document its systems engineering processes in a Systems Engineering Management Plan (SEMP). The Contractor shall assure System Security Engineering (SSE) is integrated into all task orders. The Contractor shall describe the SSE processes in the SEMP and, as part of its technical proposal, shall describe the use of its SSE processes in specifying and designing a system that is protected against internal and external threats as well as against hardware and software vulnerabilities. The Contractor shall describe what steps are planned or taken to include SSE as an integral part of its overall approach that will be used to deliver the required system capability. The Contractor shall use automated processes to fulfill SSE processes unless otherwise not possible.
3.1.1.1 Technical Reviews
The Contractor shall conduct technical reviews. The contactor shall describe system and software development and implementation processes in the SEMP. The Contractor shall conduct design review. The Contractor shall present the design and the traceability of requirements and derived requirements into the design. The Agile process may modify the design during its iterations. The Contractor shall identify all interfaces and changes to be made. The Contractor shall conduct integration readiness reviews. The Contractor shall identify the status of each element to be integrated and the degree of integration required. The Contractor shall present the maturity of each element for integration and the integration issues/challenges. The Contractor shall conduct implementation reviews. The Contractor shall present the tasks to accomplish, resources required, equipment/software, required capabilities to be implemented, and proposed schedule. The Contractor shall conduct technical interchange meetings. The technical interchange meetings shall exchange information on the functional and performance requirements, operational and performance characteristics, interface issues cyber security issues, integration issues, test issues, implementation issues, schedule issues, safety issues, sustainment issues, and proposed system changes.
3.1.1.1.1 Project Plan Reviews
The Contractor shall present the Contractor’s understanding of the Government’s TOR requirements.
3.1.1.1.2 Requirement Reviews
The Contractor shall document traceability from derived requirements to Government provided requirements, and from requirements to approved baselines.
3.1.1.1.3 Design Reviews
The contactor shall present the design and the traceability of requirements and derived requirements into the design. The Agile process may modify the design during its iterations. The Contractor shall identify all interfaces and the changes to be made.
3.1.1.1.4 Integration Readiness Reviews
The Contractor shall identify the status of each element to be integrated and the degree of integration required. The Contractor shall present the maturity of each element for integration and the integration issues/challenges.
3.1.1.1.5 Implementation Reviews
The contactor shall present the tasks to accomplish, resources required, equipment/software required capabilities to be implemented, proposed schedule, and contingency approach for a potential failed implementation.
3.1.1.1.6 Technical Interchange Meetings
The Contractor shall exchange information on the functional and performance requirements, operational and performance characteristics, interface issues, cyber security issues, integration issues, test issues, implementation issues, schedule issues, safety issues, sustainment issues, and proposed system changes.
3.1.1.2 Requirements Analysis
The Contractor shall perform requirements analysis. The Contractor shall document requirements including traceability from derived requirements. The traceability will be from the mission requirements and concepts of operations to the elements of the design. The Contractor shall identify the technical requirements of each design element. All derived requirements must be verifiable unless waived by the Government. The results shall be design requirements.
3.1.1.3 Operational and Technical Analysis
The Contractor shall perform operational and technical analysis. The Contractor shall identify, investigate, and analyze candidate operational concepts and technology enhancements and assess their applicability to AFW. The Contractor shall technically evaluate and recommend the feasibility of implementing new technologies. The Contractor shall recommend value-added engineering changes to reduce the cost of ownership.
3.1.1.4 Design
The Contractor shall perform design. The Contractor shall describe system and software development and implementation processes in the SEMP. The Contractor shall document the requirements to be met by each element of the design and traceability to mission requirements. The Contractor shall document the software architectural design of each element. The Contractor shall define and document a description of each software unit. The Contractor shall perform design which incorporates as many of the modular, open system architecture characteristics as described in Appendix C, Defense Science Board 2010 Summer Study as possible. The Contractor shall ensure all system safety, operational safety, and chemical, physical, radiological and biological health hazards are identified and eliminated, reduced or controlled. The Contractor shall submit for Government approval a training plan and training materials. The Contractor shall design and deliver operator training, software training, and systems administration training.
3.1.1.5 Software Engineering
The Contractor shall perform software engineering. The Contractor shall develop, implement and maintain processes to manage the software development life cycle processes. The Contractor shall perform software development in accordance with a Secure Software Development Life Cycle model. The Contractor shall perform requirements development, design, code and unit test, and integration test. The planning of requirements into builds may be accomplished using agile processes. The Contractor shall deliver to the Government all source code, development tools, data files and database files, and scripts. The Contractor shall provide version description documents for each change. The Contractor's processes should meet certified industrial standards. The Contractor shall develop and adhere to Secure Coding Practices for all software developed, maintained, and sustained under this PWS using a Secure Software Development Lifecycle (S-SDLC). The Contractor shall ensure software assurance IAW current applicable STIGs/SRGs and the current version of Software Assurance Countermeasures in Program Protection Planning.
3.1.1.6 Configuration/Release Management
The Contractor shall perform configuration management. The configuration management processes shall be documented in the SEMP. The Contractor shall accomplish baseline identification, change control, release management, status accounting and auditing. Configuration management data shall be easily and electronically accessible to the Government in native format to enable manipulation for Government use. The Contractor shall automate configuration management processes.
3.1.1.6.1 System Performance Baseline
The system performance baseline will consist of requirements standards, system configuration, component specific configuration/setup instructions, system and software documentation, software media, costs, facilities/equipment/property, and maintenance requirements as applicable, transition to operations plan, training, information security, remaining work, and risks.
3.1.1.6.2 Change Requests
The Contractor shall participate in the change management processes as defined by the Government. The Contractor shall keep current the designated Change Management tools with hardware and software, including what software is installed on each IS, hostnames, full descriptions, etc... IAW specific enclave security requirements. Information submitted to the designated tool shall be complete and accurate according to established submission practices and guidelines. Changes to the Information System shall include a complete Bill of Material (BOM) for any software changes documenting all software dependencies. The Contractor shall utilize designated Change Management tools to keep current the status of mandatory directives and coordinate any required actions with stakeholders external to the program (to include Government). The Contractor shall prepare change requests and appropriate documentation change to describe the scope and impact to include development and sustainment estimates for a modification and upgrade or any change to configuration baselines.
3.1.1.6.3 Status Accounting
The contactor shall define, capture, store, and provide access to all configuration information needed to manage the assigned AFW system project configuration baselines and provide end-to-end traceability. The Contractor shall use baseline management software and keep baselines current to which the Government may access.
3.1.1.6.3.1 COOP Fly-Away Kit
Contractor will provide physical back-up of all configuration information and baselines for inclusion with 557 WW's COOP Fly-Away Kit. Back-ups will be provided quarterly on Government-approved external disk drives and/or digital disks.
3.1.1.6.4 Version Control
The Contractor shall maintain a version control system for all software artifacts.
3.1.1.7 Logistics Support Analysis
The contactor shall recommend the sustainment approach for each development and modified system element. As part of systems engineering's requirements derivation process, the Contractor shall identify supportability requirements and plans to satisfy system availability requirements. The Contractor shall document the results including repair approach, training, on-site spares, and vendor agreements. The Contractor will produce drawings with design engineering to document maintainability configurations.
3.1.1.8 Development
The Contractor shall produce the capabilities required using the designs approved by the Government. The Contractor shall develop capabilities using an incremental methodology with each increment consisting of a portion of the requirements of the project. After the development of each increment, the result shall proceed to verification and validation while the next increment development begins.
3.1.1.9 Integration
The Contractor shall perform element, unit, subsystem, and systems integration. With Government assistance, the Contractor shall work with other Contractors to integrate and test new capabilities. The Contractor shall plan integration from the beginning of requirements analysis and will identify integration issues/challenges through design and test.
3.1.1.10 Risk Management
The Contractor shall provide risk assessments. The Contractor shall document risk management process in the SEMP. The Contractor shall identify risks and develop risk mitigation strategies to ensure projects have the greatest probability to achieve objectives. The Contractor shall determine a risk probability, impact, and exposure value for each identified risk. The Contractor shall use a risk management tool for documenting risk and risk mitigation strategies. The Contractor shall make this tool available to the Government.
3.1.2 System Test and Evaluation
The Contractor shall plan, conduct and assist the Government in testing developed systems. The Contractor shall document its test processes in the SEMP. The Contractor shall plan, conduct and document Test Readiness Reviews. The reviews shall present the test plan/procedures including test equipment, staff, schedule, requirements to be verified, problem reports to be addressed, and known risks if any. At test results reviews, the Contractor shall present requirements verification and problem reports. The Contractor shall conduct development test and evaluation using the developed equipment. The Contractor shall document test results. The test plan shall include a requirements traceability matrix. Deficiencies shall be identified based on the definitions in TO 00-35D-54. The Contractor shall assist the Government in conducting Government test and evaluation and operational use evaluation. The Contractor’s test plan shall include the assessment, verification, and validation of all security controls, including Administrative and Management Controls, Technical Controls, and Operational and Procedural Controls, as well as all performance parameters.
3.1.3 Implementations
The Contractor's methodology for implementing change shall be documented in the SEMP. The Contractor shall obtain Government concurrence before implementing change in test and production. Before implementing into production, the Contractor shall review with the Government test results and the correction of any defects identified.
3.1.4 Installations
The Contractor shall install software and hardware worldwide for space and environmental sensing, data analysis, and data/information dissemination and reporting. The Contractor shall conduct site selections and site surveys, perform spectrum analysis, and procure equipment. The Contractor shall provide a site installation plan including a schedule with milestones. The Contractor shall perform site installation security testing.
3.1.5 Systems Decommission
The Contractor shall decommission systems when replaced to include physical deinstallation of equipment, removing cables and equipment, preparation of all forms necessary and transportation of equipment to Defense Logistics Agency Disposition Services, development of associated plans for decommissioning, request disposal instructions, and update of all user manual, technical data and drawings.
3.1.6 Facilities Integration
The Contractor shall evaluate the adequacy of Government provided facilities and alter designs to integrate with these facilities. The Contractor shall conduct and deliver to the Government an annual assessment of the adequacy of existing power in all enclaves. The Contractor shall conduct an assessment of facility HVAC, UPS, and battery backup systems.
3.1.7 Data Management
The Contractor shall develop and maintain data management processes and document them in the Program Management Plan (PMP).
3.1.7.1 Records Handling
The Contractor shall establish, maintain and administer an integrated data management system for collection, control, publishing and delivery of all program documents. The data management system shall include but not be limited to the following types of documents: CDRLs, White Papers, Status Reports, Audit Reports, Agendas, Presentation Materials, Minutes, Contract Letters and TO Proposals. The Contractor shall provide the Government with electronic access to this data, including access to printable reports. All physical records, files, documents and work papers provided and/or generated by the Government and/or generated for the Government in performance of this PWS, maintained by the Contractor which are to be transferred or released to the Government or successor Contractor, shall become and remain Government property and shall be maintained and disposed of IAW AFMAN 33-363, Management of Records; AFI 33-364, Records Disposition – Procedures and Responsibilities; the Federal Acquisition Regulation and/or the Defense Federal Acquisition Regulation Supplement, and AFI 33-322 Records Management Program as applicable. The data management system shall hold all relevant program data previous to the start of this contract. The Contractor shall publish a monthly listing of all data added or removed from the repository.
3.1.7.2 Scientific and Technical Information (STINFO)
The Contractor shall ensure that all Scientific and Technical Information (STINFO) procedures are followed and all materials, regardless of media type, generated under this contract have the appropriate STINFO markings IAW AFI 61-204 prior to initial coordination and final delivery.
3.1.7.3 Markings
Materials shall be appropriately marked with distribution statements as described in the Contract Data Requirements List (CDRL) and shall be appropriately marked with export-controlled technical data restrictions, destruction notice, copyrighted material, proprietary information, classification level, and special notices, as required.
3.2 Capability Sustainment
The Contractor shall perform the following services to maintain the weather capability to the required availability.
3.2.1 Systems Performance Measurement
The Contractor shall establish and maintain a system performance measurement process and recommend system performance metrics to include cyber security. The PMP shall contain the performance measurement process and proposed metrics.
3.2.2 Hardware Maintenance
The Contractor shall perform hardware maintenance to include all actions, parts, and equipment necessary for repairing or restoring to operations. The Contractor shall evaluate each hardware end-item against the applicable STIG/SRG or checklists as directed by DISA for each action. Additionally, for STIG/SRGs or checklists that are supported by automated test tools, the Contractor shall deliver the test reports generated by the test tools.
3.2.3 Software Maintenance
The Contractor shall perform maintenance of software baselines. The Contractor shall perform software maintenance in accordance with a Secure Software Development Life Cycle model. The Contractor shall document its software maintenance processes in the SEMP. The Contractor shall deliver to the Government source and executable code developed and supporting documentation. The Contractor shall evaluate each software end-item against the applicable STIG/SRG or checklists as directed by DISA for each action. Additionally, for STIG/SRGs or checklists that are supported by automated test tools, the Contractor shall deliver the test reports generated by the test tools.
All Contractor developed, modified, or sustained software shall be scanned using Static and Dynamic Application Security Testing (SAST/DAST) with static and dynamic code analysis tools as directed by the Government to identify any potential security vulnerabilities. Open findings shall be analyzed, audited and presented to the Government as part of the originating task. Findings either newly introduced or reintroduced during activities will be corrected as part of that task prior to delivery. For those items that cannot be corrected immediately, and for those findings that are inherited from the enterprise, a POAM must be submitted to the Government (AFLCMC).
3.2.4 License Management
The Contractor shall obtain annual licensing and update services on third-party software, software drivers, and diagnostic software, necessary site licenses and any vendor support. It shall include all hardware and software subscription services.
3.2.5 Systems Administration
The Contractor shall perform system administration. The Contractor shall perform all software and operating system installations, patches, maintenance, and performance tuning for changes requiring elevated system account privileges. The Contractor shall perform configuration changes in response to Defense Information Systems Agency vulnerability scanning tool(s) prior to implementation and maintenance tasking orders including Information Assurance Vulnerability Management (IAVM). The Contractor shall answer all identified vulnerabilities along with creating and maintaining Plan of Action and Milestones.
3.2.6 Network Administration
The Contractor shall perform network management services, network configuration management and maintenance of the infrastructure components of the network in all enclaves. The Contractor shall document its network sustainment processes in the SSP. The Contractor shall configure and install network switches, routers, network security devices and network cabling.
3.2.7 Systems Analysis
The Contractor shall assess the performance of systems using Government developed metrics and report status. The Contractor will provide trend reports and identify root causes. The Contractor shall analyze system problems occurring in operations and identify correction/remedy strategies 24/7.
3.3 Cybersecurity
The Contractor shall examine mandatory requirements and documentation, and assist in implementing any new requirements promulgated by law and Government policy. The Contractor shall describe its cybersecurity processes in the SEMP. The Contractor shall ensure all required cybersecurity and cyber resiliency requirements are implemented for all hardware and software in accordance with applicable DoD and Air Force standards.
3.3.1 Cybersecurity Tasks
The Contractor shall identify potential program, system, and engineering risks that pertain to cybersecurity; and participate in and support the development of risk mitigation plans and monitoring of risk mitigation activities. The Contractor shall perform risk assessment, analysis, testing and evaluations to ensure compliance in areas of cybersecurity.
The Contractor shall deliver software that is secure by ensuring security requirements are addressed in software development, sustainment and maintenance. The Contractor shall conduct security scans, document vulnerabilities, correct vulnerabilities, and document the resolution or mitigation of vulnerabilities. The Contractor shall support the Government’s effort to accomplish RMF accreditation by assessing the validity of vulnerabilities identified during formal and informal testing, recommending corrective actions to resolve or mitigate vulnerabilities, and estimating the level of effort and time required to resolve valid vulnerabilities.
Mandatory directives are issued to ensure maximum protection of network/assets. The Contractor shall perform software maintenance activities necessary for mandatory directive compliance unless directed otherwise by the Government. The Contractor shall perform system upgrades IAW mandatory directives and vendor requirements for all Information Systems (IS) as directed. All mandatory directives will be accomplished NLT the Air Force or Defense Information Services Agency (as applicable) required due date as listed. The Contractor shall update technical documents as necessary and as part of each action.
The Contractor shall perform, or review, applicable DISA STIG/SRG checklists on no less than a quarterly basis or as otherwise directed by the Government. Up-to-date STIG/SRG checklists as provided by DISA, DAST/SAST, and other Government directed activities will be required for each sustainment activity.
The Contractor shall comply with A&A requirements as mandated by Federal laws and policies, including making available any documentation, and physical and logical access needed to support this requirement. The level of effort for the A&A is based on the Information System’s (IS)’s official categorization IAW Committee on National Security Systems (CNSS) Instruction No. 1253, Security Categorization and Control Selection for National Security Systems. The Contractor shall apply IT security control requirements to address the level of security required to protect the confidentiality, integrity and availability of the IS data and resources. Solutions shall be compatible with system or network hardware and software configurations and shall be approved by the configuration managers of the system and network. The Contractor shall be responsible for, and assist in, fulfilling RMF management, operational, technical, and privacy controls as agreed upon with the Government.
The Contractor shall verify compliance of AFWWS accreditation package IS system configurations using a Defense Information Systems Agency (DISA) Security Compliance Checker (SCC) leveraging the latest version of corresponding DISA Security Content Automation Protocol (SCAP) benchmarks available and complete all remaining manual DISA Security Technical Implementation Guide (STIG) checklist items utilizing the DISA STIG Viewer, http://iase.disa.mil/stigs/scap/Pages/index.aspx. The Contractor shall execute all applicable DISA STIGs/SRGs for all Contractor developed, sustained, and modified software and information systems, all external Government-Off-The-Shelf (GOTS), Commercial-Off-The-Shelf (COTS), open source, plug-in, and shareware software, and document the results in support of IS security and compliance. The Contractor shall mitigate or resolve all findings to the satisfaction of, and as prioritized by, the Government (AFLCMC).
3.3.2 Cybersecurity Documents
The Contractor shall review and contribute in the preparation of any required security-related documentation including but not limited to Program Protection Plan (PPP), Anti-tamper Plan, cybersecurity strategy (CSS), Criticality Analysis, Security Classification Guide, System Security Plan (SSP), Ports, Protocols and Services (PPS), and populating Federal Information security Management Act (FISMA) master records. With Government oversight, the Contractor will develop and provide well defined A&A documentation to include, but not limited to, plans, policies, diagrams, templates, processes and audit trails of processes, Plan of Action and Milestones (POA&M), Secure Technical Implementation Guide (STIG) and/or applicable Security Requirements Guide (SRG) checklist, static/dynamic code scans and analysis, for designated acquisition, modification, or sustainment activities in support of A&A requirements. The Contractor shall prepare for submission of all Risk Management Framework (RMF) documents for all program components in accordance with DODI 8510.01 to include all required supporting Assessment and Authorization documentation. Documentation produced for A&A activities shall be delivered in submission-ready formats according to recognized standards. The Contractor shall provide evaluations of Time Compliance Network Order (TCNO) and Common Vulnerability Exposures (CVEs), or other such directive sets for individual systems are needed. The Contractor shall assist in assessment and authorization strategy development leading to full Authority to Operate/Authority to Connect (ATO/ATC) in accordance with the current version of DODI 8510.01 including populating the tools that support the process.
The Contractor shall document its mandatory directive compliance processes in the SEMP. For those mandatory directives that cannot be done by the required date, due to mitigating measures that are not available, or cannot be complied as directed in the order, the Contractor must provide a corrective action plan with milestones (i.e. POA&M) to the Government.
The Contractor shall provide and maintain a description of all internal and external interfaces, information being exchanged and protection mechanisms associated with each interface in support of managing ports, protocols, and services, in a submission ready format consistent with PPSM template requirements. The Contractor shall provide a description of all user roles required for access control and access privileges assigned to each role, unique security requirements including where they are implemented, the purpose and technical details of implementation (e.g. encryption strength/algorithm for data at rest), description of all categories of sensitive information stored and protection plans for each (e.g. privacy act, HIPAA), restoration procedures and priorities of each subsystem, process or information source, data flow diagrams, and system/network connectivity diagrams. All users for identified privileged access or roles shall be 8570 compliant and maintain all appropriate certifications necessary for the duration their role.
3.3.3 Cybersecurity Training
Without exception, the Contractor shall provide fully qualified, and certified, personnel appropriately trained to support the AFWWS IS. The Contractor shall provide evidence of training. The Contractor is responsible for ensuring that personnel remain cognizant and knowledgeable within their area of expertise including emerging and proven technologies applicable to the work being performed under this contract.
3.4 Program Management
The Contractor shall provide the technical approach, organizational resources and management controls to be employed to meet cost, schedule and performance requirements for each order during the contract period of performance. The contactor shall provide its program management processes in a PMP.
3.4.1 Financial Management
The contractor shall complete Cost and Software Data Reporting (CSDR) CDRLs in accordance with the attached DD Form 2794 CSDR Plan.
3.4.1.1 Contract Work Breakdown Structure (CWBS) and CWBS Dictionary The Government will provide the MIL-STD-881D (appendix J) WBS down to the minimally viable reporting level as required in CDRL A013. The contractor may report to a lower level as deemed necessary. The contractor shall define and structure the work on this contract using a CWBS and associated CWBS dictionary. The contractor shall maintain the CWBS and CWBS Dictionary IAW MIL-STD-881D (appendix J). The contractor shall maintain the CWBS and CWBS Dictionary also IAW the attached DD Form 2794 CSDR Plan.
3.4.1.2 Cost Data Summary Report
The contractor shall provide a summary of direct and indirect cost data to the Government IAW the attached DD Form 2794 CSDR Plan.
3.4.1.3 Functional Cost-Hour Report
The…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .