Draft_SDMS_PWS_20_Jan_17_.pdf
PDF 494 KB Posted
- Attached to
- Software Development Maintenance Services Federal contract opportunity
- Solicitation number
- FA6643-17-R-0005
About this file
DRAFT SDMS PWS
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Questions_and_Answers_4.docx | DOCX document | |
| Questions_and_Answers_3.docx | DOCX document | |
| Amendment_0002.pdf | ||
| QUESTIONS_AND_ANSWERS_2_.docx | DOCX document | |
| FA6643-17-R-0005-0001.pdf | ||
| SDMS_Attachment_4_Spreadsheet.xlsx | XLSX spreadsheet | |
| SDMS_Attachment_2.docx | DOCX document | |
| QUESTIONS_AND_ANSWERS_FA6643-17-R-0005_SDMS.docx | DOCX document | |
| 24.b_RAFB_Prime_Contractor_VGSA_SDMS-(AFRC)_DRAFT.docx | DOCX document | |
| SDMS_DD_254_Documents.pdf | ||
| Solicitation_SDMS_FA6643-17-R-0005.pdf | ||
| SDMS_Attachment_1.docx | DOCX document | |
| SDMS_CDRLs.pdf | ||
| SDMS_Attachment_3.docx | DOCX document | |
| SDMS_PWS_24_Feb17_FINAL.pdf | ||
| SDMS_Attachment_2.docx | DOCX document | |
| SDMS_Attachment_1.docx | DOCX document | |
| SDMS_Attachment_3.docx | DOCX document | |
| SDMS_PWS_26_Jan_17_DRAFT.docx | DOCX document |
Show all 19
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRAFT
Software Development Maintenance
Services (SDMS)
Performance Work Statement (PWS)
For
Headquarters Air Force Reserve Command
Dated: 20 Jan 2017
1. PURPOSE
1.1 Headquarters Air Force Reserve Command (HQ AFRC), Communications
Directorate (HQ AFRC/A6) is responsible for the sustainment and maintenance of software applications and tools which support daily operations and enterprise solutions. HQ AFRC is located on Robins AFB GA and requires on-site contracted services in support of the Software Development, Engineering and Support Branch within the Network Systems Division.
1.2 Organization: The AFRC organization with primary responsibility is A6.
2. SCOPE
The general scope of the requirement covers modernization programming and maintenance of all existing, planned, and future Air Force Reserve IT systems and related software, reference Attachment 1; capturing user and business owner requirements; performing database administration for consolidated databases; identifying functional, security, and performance requirements; developing logical and physical database models; providing design and program documentation, and supporting the Certification & Accreditation
(C&A) process.
3. REQUIREMENTs/DESCRIPTION OF SERVICEs
The Contractor shall design, develop, test and package systems and software changes as well as provide problem resolutions for all existing, planned, and future Air Force Reserve IT systems and related software. Reference Attachment 1. The Government owns all developed, modified, or converted source modules, processes, programs, scripts, operating instructions, databases, system files, documentation, test files and test conditions used to develop each approved system change request executed according to schedules. The contractor shall provide any of the above items upon completion (or upon request by the government) of each item, and any that are in progress at conclusion of the contract.
3.1 Systems Sustainment
The Contractor shall design, develop, test and package systems and software changes as well as provide problem resolutions for the existing system. The contractor shall maintain the current system and provide software change and problem fixes as required.
The contractor shall provide to the Government all developed, modified, or converted source modules, processes, programs, scripts, operating instructions, databases, system files, documentation, test files and test conditions used to develop each approved systems change request. (CDRL #A002) Specific tasks include the following:
3.1.1 Maintain existing systems and environments IAW disciplined engineering practices and sustain applications, databases and interfaces in compliance with applicable AF/DoD standards.
3.1.2 Support system sustainment activities to include maintaining existing legacy systems and environments and to sustain applications, databases and interfaces. Each system shall be evaluated for better functionality and modernization.
3.1.3 Provide application services to support, maintain and operate systems or services. The current systems and environments supported are listed in Attachment
1.
3.2 Systems Maintenance, Migration and Integration
The contractor shall ensure that the systems requirements comply with applicable documents and standards specified in Attachment 2 of this PWS.
3.2.1 The Contractor shall conduct software programming, software security, web services programming, web services testing, smart phone or other IT device applications and testing, security layer integration, database clean-up, data wrapping and data conversion.
3.2.2 The Contractor shall program, operate and maintain test applications, models and databases to determine optimal solutions for integration concepts and problems integral to the integration process. Develop schedules and implementation plans, including parallel operations, identification of technical approaches and a description of anticipated prototype results. (CDRL # A005)
3.2.3 The Contractor shall perform system performance tuning, system re-hosting and integration services.
3.2.4 The Contractor shall utilize Government-Off-The-Shelf (GOTS) or approved government owned Commercial-Off-The-Shelf (COTS) tools for systems design and programming.
3.2.5 The Contractor shall ensure all mobile applications receive their RMF (IA
Certification) and they must be device agnostic. Ensure compliance with the DoD
Mobile Development Strategy V2.0 dated May 2012.
3.3 Information Services
The Contractor shall provide application and content presentation services that identify and exploit existing services, create new Service-Oriented Architecture (SOA) applications and data services, create presentation services, define, align and register vocabularies, expose information assets for discovery in the Metadata Environment
(MDE) for Communities of Interest (COI), provide wrapping services and provide data layer connectivity.
3.3.1 SOA Applications and Data Services
The Contractor shall expose authoritative data, as defined, by recommending improvements to business process, identifying the sources for the authoritative data and execute user roles and permissions for information access as directed by COI.
3.3.2 Create Aggregation Services
The Contractor shall:
3.3.1.1 Create aggregation services that deliver capabilities by coupling multiple core data services to construct new information assets.
3.3.1.2 Invoke enclave security services to mitigate security issues from aggregating data from multiple Authoritative Data Sources (ADS).
3.3.1.3 Create repositories for new authoritative data generated from aggregation services.
3.3.1.4 Create services through which content can be combined, searched and/or correlated.
3.3.3 Create Presentation Services
3.3.3.1 Create presentation services that are required to display information unique to a specific set of users and to deliver specific mission capabilities.
3.3.3.2 Ensure these presentation services to be available from the SOA infrastructure to provide content on-demand.
3.3.4 Specify Information Assets for Exposure
3.3.4.1 Generate specifications for exposing authoritative data as information asset payloads.
3.3.4.2 Create semi-automated services that enable the specification of information assets by editing, sorting, filtering and translating.
3.3.4.3 Utilize applicable data definitions and standards for information assets to be exposed
3.3.4.4 Create schema/documentation for organizations to register for use throughout the DoD enterprise.
3.3.5 Registering Services
The Contractor shall support the registration of ADS exposure services, aggregation services and presentation services.
3.3.6 Web Services
The Contractor shall create and maintain web services using standards as defined within the Enterprise Architecture to enable sharing of data across different applications in an enterprise.
3.3.7 Vocabulary Management
3.3.7.1 Support the development of vocabularies.
3.3.7.2 Create and maintain Web Ontology Language (WOL) vocabularies and schemas.
3.3.7.3 Verify vocabularies do not overlap and/or contradict other ADS vocabularies.
3.3.7.4 Resolve discrepancies and eliminate redundancies of vocabularies.
3.3.7.5 The contractor shall support the alignment, articulation and registration of vocabulary artifacts.
3.3.8 Data Stores
3.3.8.1 Create and maintain data stores.
3.3.8.2 Provide services such as data cleansing, redundancy resolution and business rule validation.
3.3.8.3 Monitor and maintain these data stores to ensure data availability, accuracy, precision and responsiveness.
3.3.9 Information Exposure Services
3.3.9.1 Provide application services.
3.3.9.2 Prepare and standardize data retrieved from legacy information sources
3.3.9.3 Modify the information source’s interface, data and/or behavior for standardized accessibility.
3.3.9.4 Transform communication interfaces, data structures and program semantic alignment.
3.3.9.5 Provide standardized communication/program wrapping services, data language translation, etc.
3.3.9.6 Employ configuration management plan of existing legacy baseline code and data exposure code.
3.4 Systems Operations
The Contractor shall provide operational support services including; database administration, systems administration, customer training and help desk support of both legacy and new applications and systems IAW AFI 17-100 Network Operations and DoD
8570.01M Information Assurance Workforce Improvement Program.
3.4.1 Database Administration
The Contractor Shall:
3.4.1.1 Create and test backups of data, provide data cleansing services, verify data integrity, implement access controls.
3.4.1.2 Assist programmers of data exposure services with engagement of the database.
3.4.2 Systems Administration
3.4.2.1 Install, support and maintain servers. Plan and respond to network service outages.
3.4.2.2 Diagnose software and hardware failures to resolution.
3.4.2.3 Implement and ensure security preventive measures are fully functioning.
3.4.2.4 Monitor and enhance system performance.
3.4.2.5 Maintain STIG compliance on hardware and software.
3.4.3 Customer Training
3.4.3.1 Provide on-site training at Government locations.
3.4.3.2 Ensure training stays current with the services offered throughout the life of the contract.
3.4.4 Help Desk Services
The Contractor shall provide Help Desk Tier 2 and Tier 3 support for technical assistance, support of multiple software versions, training, warrant, and maintenance for all Software Development Maintenance Support (SDMS) applications.
3.4.4.1 Tier 2 –Support for application software and/or hardware beyond the basic support provided by a Tier 1 helpdesk.
3.4.4.2 Tier 3 – Usually subject matter experts, support on complex hardware and
OS software issues.
3.5 Agent of the Certifying Authority (ACA) Support Services
The Contractor shall ensure completed, and validated C&A/RMF packages for systems they are responsible for.
3.6 Tasks Performed
3.6.1 SDMS Onsite Program Management
The Contractor shall identify an On-Site Program Manager (PM) who shall be the primary representative responsible for all work awarded, participating in
Program/Project Management Reviews and ensuring all standards are adhered to and prioritize daily work schedule in keeping with productivity standards and approved project schedules. The name and phone number shall be provided, in writing, to the
HQ AFRC/PKA CO and the AFRC/SCXP COR upon award. The Contractor shall notify the AFRC/SCXP COR and AFRC/PKA CO thirty (30) calendar days in advance of the effective date of any substitution along with a detailed explanation of the circumstances necessitating the proposed substitution. (CDRL # A013)
3.6.1.1 Key Personnel Designation and Qualification Requirements
For the purpose of the overall performance of this effort, the Program Manager shall be designated as Key Personnel. The key personnel shall have the following experience, knowledge, skills and business acumen to meet the requirements of this PWS.
3.6.1.1.1 Five years or more of program management experience including handling or managing workforce of up to 20 personnel
3.6.1.1.2 Experience with liaison activity associated with various levels of management within DoD including contracting and acquisition
3.6.1.1.3 3.6.1.1.3 Experience in personnel management, strategic planning, risk management, change management
3.6.1.1.4 3.6.1.1.4 Experience performing mathematical and analytical functions required to capture and produce meaningful metrics
3.6.1.1.5 3.6.1.1.5 Technical knowledge regarding software development languages identified in Attachment 1, computers, systems, databases, general use software programs and office equipment
3.6.1.2 Coordinate the efforts of the SDMS team.
3.6.1.3 Investigate and test new technologies.
3.6.1.4 Participate in Analysis of Alternatives.
3.6.1.5 Contribute to Command innovation strategy sessions.
3.6.1.6 Provide status reports. (CDRL # A019)
3.6.1.7 Provide Rough Order of Magnitude (ROM)s for new requirements.
(CDRL # A021)
3.6.1.8 Review Bounded User Requirements as presented through Service
Development and Delivery Process (SDDP).
3.6.1.9 Maintain and update, as needed, software governance.
3.6.1.10 Develop and maintain approved weekly work plans/reports that reflect tasks, resource, metrics, and schedule milestones deliverable to COR monthly and within 5 business days of task assignment. Track and report monthly task performance metrics, delivered no later than 10th day of each month. which at a minimum should include the following (CDRL # A009):
3.6.1.10.1 Help desk recording and resolution times
3.6.1.10.2 Percent of work items passing quality assurance testing on first pass
3.6.1.10.3 Percent of work items passing production testing on first pass
3.6.1.10.4 Percent of items requiring multiple reworks
3.6.1.11 Update and maintain required Information Assurance and other certification-related documentation and supporting coordination for the SDMS framework and associated tools. (e.g., FISMA, NDAA, C&A, RMF, etc.).
(CDRL # A010)
3.6.1.12 Provide administrative support to the team. Contractor shall reserve and coordinate meeting times/places, set-up teleconference numbers, prepare agendas, provide read-ahead documentation, and take, distribute and post meeting minutes for SDMS-related meetings.
3.6.1.13 The contractor shall establish and maintain a configuration management process as prescribed by AF procedures and participate in a Configuration Control
Board (CCB) meeting, which is chaired by the Government. The CCB will control changes to the software/hardware configuration and record and report change processing and implementation status.
3.6.1.14 Use a requirements management process utilizing Team Foundation
Server (TFS). Contractor shall advise the Government leads of requirements requiring immediate attention. Participate with Government personnel on a
Requirements Review Panel to discuss and recommend prioritization of requirements as needed.
3.6.1.15 Provide customer service
3.6.2 Service Capabilities
3.6.2.1 Sustain all existing SOA consumer service
3.6.2.2 Upgrade/provide services based on requirements
3.6.2.3 Provide Service Development Life Cycle (SDLC) for all new service capabilities.
3.6.2.4 Provide service health metrics (NIPR/SIPR).
3.6.2.5 Implement and operate the technologies and tools to manage the technical aspects of the SDMS portion of any AFRC data sharing or SOA environment architecture (i.e. libraries, repositories, and/or registries for interface definitions, ontologies, semantics, vocabularies, metadata, as well as discovery services).
3.6.3 SQL Server Support
3.6.3.1 Create SQL Server Reporting Services reports.
3.6.3.2 Perform SQL Server Reporting Services site maintenance.
3.6.3.3 Design, document and implement new schemas.
3.6.3.4 Maintain data quality metrics and provides upon request.
3.6.3.5 Administer all operational data stores (ODS).
3.6.3.6 Administer all databases.
3.6.3.7 Perform database tuning and configuration.
3.6.3.8 Perform database clustering and configuration.
3.6.3.9 Maintain and create SQL Server Integration Services packages.
3.6.4 Environmental Systems Research Institute (ESRI) Geospatial Capability
3.6.4.1 Provide ESRI sustainment, including installing software updates and software administration.
3.6.4.2 Create new presentation layers, queries, filters, services, scripting, and programming, to meet requirements.
3.6.5 Server Support
3.6.5.1 Perform Operating System updates. Ensure NIPR/SIPR CAT vulnerabilities for each assigned server does not exceed AFRC, AF, DISA, or
DoD vulnerability thresholds: <2.49 vulnerabilities per each assigned server.
Category 1 (CAT I) vulnerabilities must be eliminated within 24 hours of the fix action being made available.
3.6.5.2 Perform application maintenance and configuration (IIS, MS SQL
Servers, Windows Servers, etc.).
3.6.5.3 Validate backups and restorations through coordination with COR
3.6.5.4 Develop, maintain and test a Disaster Recovery Plan and capability utilizing AFRC-provided hardware and services. A quarterly disaster recovery plan is required to be submitted 5 business days after each quarter and approved by the government within 5 business days. The test results of the recovery plan shall be submitted annually to the designated Government representative. (CDRL
# A011)
3.6.6 Software Maintenance/Sustainment
3.6.6.1 Program and maintain applications, sustain existing applications, in support of AFR missions and capabilities utilizing SDDP and SDLC.
3.6.6.2 Test all aspects of applications IAW with Government approved testing process
3.6.6.3 Create demonstration models as needed
3.6.6.4 Recommend data sources and interface designs
3.6.6.5 Draft/create screen layouts and menu designs
3.6.6.6 Draft/create report designs
3.6.6.7 Modify/Upgrade application and implement changes, including all life-cycle phases according to schedules. 95% of scheduled upgrades and/or maintenance are executed according to schedule. 95% of requests for unscheduled software maintenance are responded to within 48 hours. (CDRL #
A003)
3.6.6.8 Modify/Upgrade applications to promote new technologies
3.6.6.9 Attend technical interchange meetings
3.6.6.10 Create/Maintain/deliver to government, documentation of all code, to include user help files. Develop and maintain up-to-date digital and hard copy user documentation for framework applications/capabilities, to include user guides, administrator guides, tutorials, and online help within 5 days of release. (CDRL #
A015)
3.6.6.11 Create operating systems agnostic mobile apps for requirements as required.
3.6.7 ARCNet Program Support
3.6.7.1 Create Advanced Distributed Learning Service (ADLS) equivalent and unit unique CBTs
3.6.7.2 Provide onsite/webinar ARCNet training as requested
3.6.7.3 Utilize Remedy to record requests
3.6.7.4 Manage customer feedback through Interactive Customer Evaluation
(ICE)
3.6.7.5 Manage the AFRC & ANG ancillary training program as it relates to
ARCNet
3.6.7.6 Maintain ARCNet Community of Practice (COP) for users
3.6.7.7 Maintain Volunteer Reserve System (VRS) requirements and participates in VRS Configuration Control Board (CCB)
3.6.7.8 Work with designated POCs to obtain the information required to configure ARCNet for users and coordinate training sessions to ensure a successful fielding visit. Schedule user orientation training requests and track user orientation training sessions in an automated system. Perform on-site or remote configuration, orientation, and application training to ARCNet users via one-on- one and/or group training sessions.
3.6.8 Business Software Analyst (CDRL # A014)
3.6.8.1 Work with key project stakeholders to formulate and communicate requirements. Prior to programming, a business analysis to translate requirements into useable design specifications and proposed release packages shall be provided to government for approval. SDDP documents are delivered within 30 days of task assignment and approved by the government within 5 days. (CDRL #
A014)
3.6.8.2 Work with project stakeholders to translate their requirements into something that programmers can understand as well as to translate the resulting questions that the programmers have into something the stakeholders can understand. Prior to programming, a business analysis to translate requirements into useable design specifications and proposed release packages shall be provided to government for approval. SDDP documents are delivered within 30 days of task assignment and approved by the government within 5 days. (CDRL #
A014)
3.6.8.3 Work with project stakeholders to identify, model and then document their requirements and business domain details. Prior to programming, a business analysis to translate requirements into useable design specifications and proposed release packages shall be provided to government for approval. SDDP documents are delivered within 30 days of task assignment and approved by the government within 5 days. (CDRL # A014)
3.6.8.4 Aid in writing User Acceptance Test (UAT) cases and will be a liaison between project stakeholders and testing during UAT (CDRL # A020)
3.6.8.5 Identify and model process requirements
3.6.8.6 Identify and model data requirements
3.6.8.7 Identify business rules requirements
3.6.8.8 Test requirements
3.6.8.9 Works closely with Enterprise Architecture to facilitate SDDP
3.6.8.10 Lead Projects through SDDP as required
3.7 Over and Above
The Contractor will be required to perform major system modifications and initiate guidance changes outside of anticipated workload. This support will be on an as needed basis as defined by the Government. Support will be negotiated at the time as cost reimbursable under the over and above CLIN.
4. ENGINEERING REQUIREMENTS
4.1 Systems Engineering
4.1.1 Life-Cycle Systems Engineering
The Contractor shall employ disciplined systems engineering processes including, but not limited to, requirements recommendations/documentation, technical management and control, system/software design and architecture, integrated risk management, configuration management, data management, and test, evaluation, verification and validation practices throughout the period of performance of IAW AFI 20-101, Integrated Life Cycle Management.
4.1.2 Business and Enterprise Systems (BES) Process Directory
If applicable, the Contractor shall follow and refer to the Air Force Program Executive
Office (AFPEO) Business Enterprise Systems (BES) Process Directory website https://acc.dau.mil/bes for common plans, procedures, checklists, forms and templates that support system life-cycle management and systems engineering processes as it applies to Defense Acquisition, Technology and Logistics tailored to Capability
Maturity Model Integrated (CMMI) disciplines, or be able to demonstrate comparable processes and artifacts.
The Contractor shall recommend solutions that employ principles of open technology development and a modular open systems architecture for hardware and software as described in the DoD Open Technology Development Guidebook and Net-Centric
Enterprise Solutions for Interoperability (NESI) body of knowledge. The contractor’s systems engineering plan and design activities shall also adhere to the DoD
Information Sharing and Net-Centric Strategies published by the DoD CIO, and the engineering body of knowledge and lessons-learned accumulated in NESI.
4.2 Architecture and System Design
The Contractor shall support the design and programming of systems and applications and their integration into the overarching enterprise architecture. The Contractor shall provide all required artifacts, and supporting architectural documentation, for any tasks identified in the contract.
4.2.1 Department of Defense Architectural Framework (DoDAF) Guidance
The Contractor shall provide all required artifacts, and supporting architectural documentation in compliance with the latest Department of Defense Architectural
Framework (DoDAF) Enterprise Architecture guidance http://dodcio.defense.gov/Portals/0/Documents/DODAF/DM2%20VDD%20v2.02.pdf
?ver=2015-08-26-162815-293. (CDRL # A022)
4.2.2 Global Combat Support System (GCSS) Developer’s Guide
The Contractor shall follow and comply with GCSS guidelines for systems and applications that will be deployed to the GCSS environment.
4.2.3 DoD Mobility Strategy
For any systems or applications that have requirements for deployment on mobile technology, Contractors shall follow and comply with the DoD Mobility Strategy.
4.2.4 Federal Desktop Core Configuration (FDCC)
All services provided shall function and be in compliance with the Federal Desktop
Core Configuration (FDCC).
4.3 Configuration Management
The Contractor shall accomplish Configuration Management (CM) activities as described.
CM activities include baseline identification, change control, status accounting and auditing.
4.4 Testing
https://acc.dau.mil/bes http://dodcio.defense.gov/Portals/0/Documents/DODAF/DM2%20VDD%20v2.02.pdf?ver=2015-08-26-162815-293 http://dodcio.defense.gov/Portals/0/Documents/DODAF/DM2%20VDD%20v2.02.pdf?ver=2015-08-26-162815-293
The Contractor shall conduct rapid testing and deployment of Core Data Services and
Aggregation and Presentation Layer Services using testing environments. The contractor shall configure testing environments to support functional testing with Government provided infrastructure.
4.4.1 Test Lab. Not applicable.
4.4.2 Regression Testing. Not applicable.
4.4.3 Product/System Integration Testing
The Contractor shall perform testing and inspections of all system services to ensure the technical adequacy and accuracy of all work, including reports and other documents required in support of that work. The contractor shall conduct on-site testing when requested. When specified by the Government, the contractor shall participate with the Government in testing the complete system or application which may include premise equipment, distribution systems or any additional telecommunications equipment or operating support systems identified in the contract.
After appropriate corrective action has been taken, all tests including those previously completed related to the failed test and the corrective action shall be repeated and successfully completed prior to Government acceptance. Pre-cutover audits will consist of verification of all testing completed by the contractor such that the system is deemed ready for functional cutover. As part of this audit, any engineered changes or approved waivers applicable to the installation will be reviewed and agreed upon between the contractor and the Government. Post-cutover audits will verify that all post-cutover acceptance testing has been performed satisfactorily IAW the standard practices and identify those tests, if any, which have not been successfully completed and must be re-tested prior to acceptance. Testing shall be performed in two steps:
operational testing, then system acceptance testing. The contractor shall provide a logical test process that minimizes interruptions and avoids sustained downtime and presents a contingency procedure to be implemented in the event of systems failure during testing.
4.4.4 Simulated Operational Testing
The Contractor shall conduct testing ranging from data entry and display at the user level combined with system loading to represent a fully operational system. The contractor shall accomplish operational testing IAW the Government-approved test plan (CDRL # A001) as specified in the contract. The plan shall consist of a program of tests, inspections and demonstrations to verify compliance with the requirements of this contract. The contractor shall document test results in the test report(s). The contractor shall furnish all test equipment and personnel required to conduct operational testing. During the installation/test phase, the Government reserves the right to perform any of the contractor performed inspections and tests to assure solutions conform to prescribed requirements. The contractor shall be responsible for documenting deficiencies and tracking them until they are resolved. The Government will not be expensed for correcting deficiencies that were the direct result of the contractor’s mistakes.
4.4.5 Acceptance Testing
The Contractor shall provide on-site services during the acceptance-testing period.
Acceptance testing shall be initiated upon acceptance of the operational test report and approval of the acceptance test plan. (CDRL # A001) If a phased installation concept is approved in the Systems Installation Specification Plan (SISP), acceptance shall be based on the increments installed IAW the SISP.
4.4.6 System Performance Testing
The Contractor shall provide system performance testing. The acceptance test will end when the system or application has maintained the site-specific availability rate specified in the contract. In the event the system or application does not meet the availability rate, the acceptance testing shall continue on a day-by-day basis until the availability rate is met. In the event the system or application has not met the availability rate after 60 calendar days, the Government reserves the right to require replacement of the component(s) adversely affecting the availability rate at no additional cost.
4.5 Information Assurance
The Contractor shall ensure that all system or application deliverables meet the requirements of DoD and AF Information Assurance (IA) policy. Furthermore, the
Contractor shall ensure that personnel performing IA activities obtain, and remain current with, required technical and/or management certifications.
4.5.1 System IA
For those solutions that will not inherit existing network security controls, and thus integrate an entirely new application system consisting of a combination of hardware, firmware and software, system security assurance is required at all layers of the
TCP/IP DoD Model. The Contractor shall ensure that all system deliverables comply with DoD and AF IA policy, specifically DoDI 8500.2, Information Assurance
Implementation, and AFI 33-200, Air Force Cybersecurity Program Management. To ensure that IA policy is implemented correctly on systems, contractors shall ensure compliance with DoD and AF Certification & Accreditation policy, specifically DoDI
8510.01, Risk Management Framework (RMF) for DoD Information Technology, and
AFI 17-101, Air Force Certification and Accreditation (C&A) Program (AFCAP). The contractor shall also support activities and meet the requirements of DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling, in order to achieve standardized, PKI-supported capabilities for biometrics, digital signatures, encryption, identification and authentication.
4.5.2 Application IA
For those solutions that will be deployed to Infrastructure as a Service (IaaS), Platform as a Service (PaaS) or similar environments, and thus inherit existing network security controls, application security assurance is required at the Application layer of the
TCP/IP DoD Model. The Contractor shall ensure that all application deliverables adhere to Public Law 111-383, which states the general need for software assurance.
Specifically, the contractor shall ensure that all application deliverables comply with the Defense Information Systems Agency (DISA) Application Security &
Development Security Technical Implementation Guide (STIG), which includes the need for source code scanning, the DISA Database STIG, and a Web Penetration Test to mitigate vulnerabilities associated with SQL injections, cross-site scripting and buffer overflows. The contractor shall also support activities and meet the requirements of DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK)
Enabling, in order to achieve standardized, PKI-supported capabilities for biometrics, digital signatures, encryption, identification and authentication. (CDRL # A016)
4.5.3 Personnel IA
Personnel performing Information Assurance (IA) activities are required to obtain, and remain current with, technical and/or management certifications to ensure compliance with DoD 8570.01-M, Information Assurance Workforce Improvement
Program, 19 December 2005 (with all current changes). The Contractor shall ensure contract personnel meet and maintain the certification standards set forth in AFMAN
17-1303.
5. GENERAL REQUIREMENTS
5.1 Period of Performance
Performance shall commence at date specified in contract for a one-year basic period with five annual options.
5.2 Place of Performance
The Contractor personnel shall perform on-site at HQ AFRC/A6-SCXP, Robins AFB, Ga. Occasional travel to Air Force, Air Force Reserve, or Air National Guard locations will be required for training purposes. Telework is NOT authorized without written approval by the CO.
5.3 Normal Work Hours:
Normal duty hours are 7:00 AM to 4:00 PM, with the exception of federal holidays. No virtual offices. Contractor shall be available to work Unit Training Assembly (UTA) weekends based on the HQ AFRC UTA schedule. The Government reserves the right to change duty hours at any time.
5.4 Federal Holidays
The Contractor shall not have staff present at the government installation facilities on federal holidays. The federal holidays observed are as follows: New Year’s Day, Martin
Luther King’s Birthday (as celebrated), Presidents’s Day (as celebrated), Memorial Day, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day and
Christmas Day.
5.5 Overtime
The Contractor personnel may require overtime hours due to unanticipated, short deadline work. Overtime work means each hour of work in excess of eight (8) hours in a day or in excess of 40 hours in a work week that is officially required. The Contractor shall coordinate the request for overtime with the AFRC/A6 COR and be approved in advance by the AFRC/PKA CO in accordance with FAR 52.222-2, Payment for Overtime
Premiums, as supplemented in the Air Force Federal Acquisition Regulation.
5.6 Government Items:
The Government will provide the following items:
5.6.1 FDCC Windows PC with Microsoft Office Suite (Outlook, Word, Excel, PowerPoint, etc.)
5.6.2 Telephone (local/long distance calls authorized as dictated by Task Order performance requirements)
5.6.3 Facsimile
5.6.4 Copier
5.6.5 Printer
Contractor will provide supplies for performance of the work. A joint inventory will be conducted at various times throughout the contract to account for government items. Any discrepancies in inventory will be resolved under Air Force Report of Survey processes.
All items will be returned at the end of the contract.
5.7 Non-Personal Services
The Government will neither supervise contractor employees nor control the method by which the Contractor performs the required tasks, unless methods are expressly disallowed by Air Force or DoD guidance or policy. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services or give the perception of personal services. If the contractor feels that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s responsibility to notify the HQ AFRC/PKA
CO immediately. These services shall not be used to perform work of a policy/decision making or management nature, i.e., inherently Governmental functions. All decisions relative to programs supported by the contractor shall be the sole responsibility of the
Government. These operating procedures may be superseded by Theater Commander’s direction during deployments.
5.8 Contractor Identification
All Contractor/subcontractor personnel shall be required to wear AF-approved or provided picture identification badges so as to distinguish themselves from Government employees.
When conversing with Government personnel during business meetings, over the telephone or via electronic mail, contractor/subcontractor personnel shall identify themselves as such to avoid situations arising where sensitive topics might be better discussed solely between Government employees. Contractors/subcontractors shall identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify their company affiliation. Where practicable, contractor/subcontractors occupying collocated space with their Government program customer should identify their work space area with their name and company affiliation.
5.9 Performance Reporting
The Contractor’s performance will be monitored by the Government and reported in
Contractor Performance Assessment Reports (CPARs) or a Customer Survey. Performance standards shall include the contractor’s ability to provide or satisfy the following:
5.9.1 Provide satisfactory solutions to requirements with the necessary customer service.
5.9.2 Provide solutions and services that meet or exceed specified performance parameters.
5.9.3 Deliver timely and quality deliverables to include accurate reports and responsive proposals.
5.9.4 Ensure solutions to requirements are in compliance with applicable policy and regulation.
5.10 Program Management/Project Management
The Contractor shall identify an On-Site Program Manager (PM) who shall be the primary representatives responsible for all work awarded under this task order, participating in
Program/Project Management Reviews and ensuring all standards referenced herein are adhered to. The names and phone numbers shall be provided, in writing, to the HQ
AFRC/PKA CO and the AFRC/SCXP CORs upon award.
5.11 Services Delivery Summary
The Contractor’s performance at the contract level will be assessed monthly by a process that measures success towards achieving defined performance objectives. The Services
Delivery Summary will be IAW AFI 63-101, Integrated Life Cycle Management, AFI 10-
601, Operational Capability Requirements Development and FAR Subpart 37.6, Performance-Based Acquisition.
5.12 Records, Files, and Documents
All physical records, files, documents and work papers, provided and/or generated by the
Government and/or generated for the Government in performance of this PWS, maintained by the contractor which are to be transferred or released to the Government or successor contractor, shall become and remain Government property and shall be maintained and disposed of IAW AFMAN 33-363, Management of Records; AFI 33-364, Records
Disposition – Procedures and Responsibilities; the Federal Acquisition Regulation, and/or the Defense Federal Acquisition Regulation Supplement, as applicable. Nothing in this section alters the rights of the Government or the contractor with respect to patents, data rights, copyrights or any other intellectual property or proprietary information as set forth in any other part of this PWS or the Application Services contract of which this PWS is a part (including all clauses that are or shall be included or incorporated by reference into that contract).
5.13 Protection of System Data
Unless otherwise stated in the contract, the Contractor shall protect system design-related documents and operational data whether in written form or in electronic form via a network in accordance with all applicable policies and procedures for such data, including
DoD Regulation 5400.7-R and DoD Manual 5200.01(v1-v4) to include latest changes, and applicable service/agency/combatant command policies and procedures. The contractor shall protect system design related documents and operational data at least to the level provided by Secure Sockets Layer (SSL)/Transport Security Layer (TSL)-protected web site connections with certificate and or user ID/password-based access controls. In either case, the certificates used by the contractor for these protections shall be DoD or IC approved Public Key Infrastructure (PKI) certificates issued by a DoD or IC approved
External Certification Authority (ECA) and shall make use of at least 128-bit encryption.
5.14 System and Network Authorization Access Requests
For Contractor personnel who require access to DoD, DISA or Air Force computing equipment or networks, the contractor shall have the employee, prime or subcontracted, sign and submit a System Authorization Access Report (SAAR), DD Form 2875.
5.15 Travel
The Contractor shall coordinate specific travel arrangements with COR thirty days in advance, unless emergency travel (will be coordinated immediately), and obtain advance, written approval from HQ AFRC/PKA CO for any travel. The contractor’s request for travel shall be in writing and contain the purpose of the trip, number of participants, dates, locations and estimated costs of the travel. The Contractor travel payment is limited to reasonable and allowable costs to the extent that they do not exceed on a daily basis the maximum per diem rates in effect at the time of travel as set forth in the Government’s
Joint Travel Regulation, Volume 2 and allowable per FAR 31.205-46, Travel Costs. No profit or fee will be paid.
5.16 Training
Contractor personnel are required to possess the skills necessary to support their company’s minimum requirements of the labor category under which they are performing.
Training necessary to meet minimum requirements will not be paid for by the
Government.
5.16.1 Mission-Unique Training
In situations where the Government organization being supported requires some unique level of support because of program/mission-unique needs, then the Contractor will negotiate with the HQ AFRC/PKA CO.
5.17 Data Rights and Non-Commercial Computer Software
In order to implement the provisions at DFARS 252.227-7013(b) and (e) and DFARS
252.227- 7014(b) and (e) and DFARS 252.227-7017, the contractor shall disclose to the
Contracting Officer if not previously disclosed in the proposal, any technical data or non-commercial computer software and computer software/source code documentation developed exclusively at government expense in performance of this PWS. This disclosure shall be made whether or not an express requirement for the disclosure is included or not included in the PWS. The disclosure shall indicate the rights asserted in the technical data and non-commercial computer software by the contractor and rights that would be acquired by the government if the data or non-commercial software was required to be delivered under this PWS. This disclosure requirement also applies to segregable routines of non-commercial software that may be developed exclusively at Government expense to integrate Commercial Software components or applications provided under a commercial software license or developed to enable Commercial Software to meet requirements.
5.18 Software Support and Data Rights
Unless specified otherwise in the PWS, the Contractor shall fully support all software to support integrated solutions on this contract. The contractor shall be able to support all software revisions deployed or resident on the system and sub-systems. The data rights ownership/licensing guidance is specified in DFARS 252.227-7013 and 252.227-7015
5.19 COTS Manuals and Supplemental Data
The Contractor shall provide documentation for all systems services delivered under this
PWS. The Contractor shall provide COTS manuals, supplemental data for COTS manuals and documentation IAW best commercial practices (i.e. CD-ROM, etc.). This documentation shall include users’ manuals, operators’ manuals, maintenance manuals and network and application interfaces if specified in the task order.
5.20 Transition and Decommissioning Plans
The Contractor shall create transition and decommissioning plans that accommodate all of the non-authoritative data sources (non-ADS) interfaces and ensure that necessary capabilities are delivered using approved ADSs.
5.21 Section 508 of the Rehabilitation Act
The Contractor shall meet the requirements of the Access Board’s regulations at 36 CFR
Part 1194, particularly 1194.22, which implements Section 508 of the Rehabilitation Act of 1973, as amended. Section 508 (as amended) of the Rehabilitation Act of 1973 (20
U.S.C. 794d) established comprehensive requirements to ensure: (1) Federal employees with disabilities are able to use information technology to do their jobs, and (2) members of the public with disabilities who are seeking information from Federal sources will be able to use information technology to access the information on an equal footing with people who do not have disabilities.
5.22 Continuation of Mission-Essential Services during a Crisis.
5.22.1 Definition of Mission-Essential Services.
In accordance with DFARS 252.237-7023(a)(1), Continuation of Essential Contractor
Services, “ ‘Essential contractor service’ means a service provided by a firm or individual under contract to DoD to support mission-essential functions, such as support of vital systems, associated support activities, and similar services provided to foreign military sales customers under the Security Assistance Program. Services are essential if the effectiveness of defense systems or operations has the potential to be seriously impaired by the interruption of these services, as determined by the appropriate functional commander or civilian equivalent.”
5.22.2 Designation of Services as Mission-Essential.
In accordance with DFARS 237.7602(a), The Continuation of Essential Contractor
Services/Policy, DFARS 252.237-7023(a)(2), and Air Force Instruction (AFI) 10-403, Deployment Planning and Execution, paragraph 1.9.1.33.2, the Functional Commander
(FC) or civilian equivalent has determined these services are not mission-essential and will not continue in the event of a crisis.
5.23 Contractor Manpower Reporting.
In accordance with the Secretary of the Air Force for Acquisition (SAF/AQ)
Memorandum, Implementation of FY11 NDAA [National Defense Authorization Act]
Section 8108 [of Public Law 112-10 of the Department of Defense and Full-Year
Continuing Appropriations Act, 2011], Contractor Inventory, dated 13 Nov 2012, the
Contractor shall provide an annual count of Contractor personnel performing work if the
DoD is the requiring activity, if the acquisition is using U.S. Government appropriated funds, and if the acquisition is equal to or greater than the Simplified Acquisition
Threshold (SAT) [currently $150,000.00]. This requirement includes supply contracts with embedded services elements, Architect & Engineering (A&E), and Research &
Development (R&D) contracts.
In accordance with the Office of the Secretary of Defense (OSD) Memorandum, Enterprise- wide Contractor Manpower Reporting Application, dated 28 Nov 2012, the
Contractor shall report all Contractor labor hours, including subcontractor labor hours, required for performance of the services provided under the contract at the Enterprise-wide
Contract Manpower Reporting Application (eCMRA) site below. Reporting shall be conducted for each fiscal year (FY), which extends 01 October through 30 September.
While inputs may be made any time during the FY, all data shall be reported no later than
31 October of the following FY. The Contractor may direct questions to the help desk at the eCMRA site: http://www.ecmra.mil
6 SERVICES DELIVERY SUMMARY
Performance Objectives
PWS Para Performance Threshold
Develop and maintain an approved work schedule
3.6.1.10 100% compliance delivered within 5 business days of task assignment.
Update and maintain required
Information Assurance and related certification documentation
3.6.1.11 100% compliance http://www.ecmra.mil/
Track and report monthly task performance metrics
3.6.1.10 100% compliance delivered no later than 10th day of each month.
Develop, maintain and test a Disaster
Recovery Plan
3.6.5.4 100% compliance
Submitted five days after each quarter and approved by the government within 5 days; test results submitted annually
Translate requirements into useable design specifications.
3.6.8.1 -
3.6.8.3
100% compliance
Delivered within 30 days of task assignment and approved by the government within 5 days.
Develop and maintain up-to-date user documentation
3.6.6.10 100% compliance deliverable within 5 days of release.
Perform Source Code Scanning 3.6.6.2, 4.5.2 100% compliance
Perform Configuration Management 3.6.1.13 100% compliance
Perform scheduled Software management.
3.6.6.7 95% of scheduled upgrades and/or maintenance executed according to schedule.
Perform unscheduled Software
Management.
3.6.6.7 95% of requests responded to within
48 hours.
Perform Vulnerability management 3.6.5.1 <2.49 vulnerabilities per each assigned server; Category 1 (CAT I) vulnerabilities eliminated within 24 hours of available the fix action.
7 SECURITY REQUIREMENTS
The Contractor shall comply with all applicable security regulations and directives identified herein and other security requirements as shown elsewhere in this contract.
7.0.1 Work on this contract requires a minimum of a Secret clearance.
7.0.2 Personnel are required to read, store, process sensitive information and operate/program sensitive database or equipment.
7.0.3 The Contractor shall ensure that all personnel assigned to this contract understand and adhere to the Privacy Act of 1974.
7.0.4 Contractors shall comply with all Government security procedures and ensure security measures are in place to protect equipment and data from physical and virus damage, theft, loss, or access by unauthorized individuals. (See AFI 33-112, AFI 33- 138, Incident Response and Reporting, AFI 33-200, Information
Assurance (IA) Management, AFMAN 33-223, Identification and Authentication, Air Force Systems Security Instruction (AFSSI) 8502, Organizational Computer
Security, AFSSI 8522, Access to Information Systems, and AFSSI 8580, Remanence Security).
7.0.5 Contractor personnel shall complete mandated training required for performance of this contract IAW AFI 36-2201, Air Force Training Program, paragraph
7.4.10., as stated below and/or as required by the AFRC/A6 COR. The required training shall be completed prior to commencing performance with evidence of course completion submitted to the COR:
7.0.5.1 DoD Information Assurance Awareness (ZZ133098)
7.0.5.2 Security Administration (ZZ133078)
7.0.5.3 Fire Extinguisher Safety (AFI 91-203)
7.0.5.4 For personnel with classified IS access, the following training is required
IAW AFI 16-1404, Air Force Information Security Program:
7.0.5.4.1 Derivative Classification (every 2 years)
7.0.5.4.2 Marking Course (1 time requirement)
7.0.5.5 Training Certificates. The contractor personnel shall provide certificates of required Government training.
7.3 Data Integrity
Data pertaining to other contracts and services reside on systems used by AFRC. The
Contractor shall not divulge this information or use this information for the contractor’s gain. In addition, any and all records, files, documents, and work papers, regardless of the type of media created in (e.g., physical, electronic, etc.) provided and/or generated by the
Government and/or generated for the Government in performance of this PWS, maintained by the Contractor which are to be transferred or released to the Government or successor
Contractor, shall become and remain Government property and shall be maintained and disposed of IAW…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .