Attachment_2_-_Legacy_App_Systems_PWS_1Jun17.pdf
PDF 368 KB Posted
- Attached to
- Legacy Application Systems Study RFQ Federal contract opportunity
- Solicitation number
- FA8734-17-R-0003_RFQ_Legacy_App
About this file
Performance Work Statement - Legacy App Study
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment_4_-_Past_Performance_Questionnaire.pdf | ||
| RFQ_Legacy_Application_Study.pdf | ||
| Attachment_3_-_GFI_-_Master_Application_List.xlsx | XLSX spreadsheet | |
| Attachment_1_-_Provisions_and_Clauses.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Legacy Application Study Attachment 2
LEGACY SYSTEMS STUDY
AFPEO BES/HIH Business Sustainment Contract
Performance Work Statement
1 June 2017
TABLE OF CONTENTS
1. INTRODUCTION
1.1 BACKGROUND
1.2 SCOPE
1.3 DESCRIPTION OF SERVICES
2. SYSTEM DESCRIPTIONS
2.1 Case Management System (CMS) Web (Core) and Personnel Processing Applications
(PPAs)
2.2 Assignment Management System (AMS) / Millennium / Base Level Service Delivery
Model (BLSDM) / Aviator Retention Pay (ARP)
2.3 Virtual Military Personnel Flight (vMPF) / Virtual Record of Emergency Data
(vRED) / Orders Processing Application (OPA)
2.4 Other Web Applications (OWAs)
2.5 Virtual Personnel Services Center (vPSC)
2.6 Air Force Fitness Management System II (AFFMS II)
2.7 AFPC Secure and AFPC Secure Maintenance Application
3. GENERAL REQUIREMENTS
3.1 CONTRACT MANAGEMENT
3.2 BILLABLE HOURS
3.3 NON-PERSONAL SERVICES
3.4 CONTRACTOR IDENTIFICATION
3.5 TRAINING
3.6 CYBERSECURITY
4. RECORDS, FILES, DOCUMENTS
5. SECURITY REQUIREMENTS
5.1 OBTAINING AND RETRIEVING IDENTIFICATION MEDIA
5.2 PASS AND IDENTIFICATION ITEMS
5.3 SUITABITLITY INVESTIGATIONS
5.4 LISTING OF EMPLOYEES
5.5 FREEDOM OF INFORMATION ACT PROGRAM (FOIA)
5.6 REPORTING REQUIREMENTS
5.7 ADDITIONAL SECURITY REQUIREMENTS
5.8 PHYSICAL SECURITY
5.9 TRAFFIC LAWS
6. SYSTEM AND NETWORK AUTHORIZATION ACCESS REQUESTS
7. PROTECTION OF SYSTEM DATA
8. SECTION 508 OF THE REHABILITATION ACT
9. ORGANIZATIONAL CONFLICT OF INTEREST (OCI)
10. ON-SITE TASK APPROVAL PROCESS
11. ENTERPRISE-WIDE CONTRACTOR MANPOWER REPORTING
APPLICATION (E-CMRA)
12. DATA DELIVERABLES (EXHIBIT 1)
APPENDIX A: OTHER WEB APPLICATIONS LISTING
Document Change Record
Date Page(s) Section Change
1. INTRODUCTION
1.1 BACKGROUND
The Air Force Life Cycle Management Center (AFLCMC), Business and Enterprise Systems
(BES) Directorate, Human Resources Systems Division (HIH) is responsible for acquiring and maintaining information technology (IT) systems that support the Air Force/A1 mission and the operations at Headquarters Air Force Personnel Center (HQ AFPC) Joint Base San Antonio
(JBSA) Randolph, Texas. The AF/A1 mission is to deliver a global 24/7 total force personnel service capability providing integrated, standardized systems that are easy to access and use.
1.2 SCOPE
The scope of this effort is for the contractor to conduct an analysis of the existing legacy systems identified in Section 2 of this Performance Work Statement (PWS) and orchestrate an end-to-end process that not only creates a repository of meta-data that allows for collaborative decision analysis capability that the Government can adopt, but also provides a recommended roadmap of modifications and improvements that the Government can apply to existing systems in order to make key evidence-based decisions on each of the applications, which will:
1) Provide the documentation that breaks down what the system is doing and also identifies areas of optimization based on knowledge such as where the dead code and redundant code resides;
2) Allow the Government to consolidate applications (whether into the Oracle E-
Business Suite [EBS] or within a subset of Web Applications);
3) Prepare the Government for the Data Center Optimization Initiative (DCOI) established in OMB Memorandum M-16-19 to host on a commercial cloud.
Upon completion of the analysis, the contractor shall provide a fit-gap analysis to identify how
EBS or existing systems/applications can be utilized to modernize the legacy systems.
In order to facilitate this effort, the Government is prepared to provide access to all relevant materials, including all source code and development space.
All products delivered to the Government shall NOT be proprietary to the contractor, and it is the
Government’s intention to use the information and deliverables derived from the study described in this PWS for future acquisitions as Government Furnished Information.
1.3 DESCRIPTION OF SERVICES
The contractor must possess Subject Matter Experts in the area of Air Force Personnel and
Human Systems Integration to ensure optimal user experience. The contractor shall identify the deltas between the requirements of the legacy systems and the capabilities of EBS. Within the first 120 days of contract award, the contractor shall complete a preliminary assessment of the source code of all applications to determine language of application, inventory of files, lines of code, complexity, data dictionary, dead code, and interfaces, and provide recommendations to the Government on how to proceed with the remainder of the study. The documentation shall include source code logistics, source code complexity, dead code details, data dictionaries, system detail diagrams, data flow diagrams, program flow diagrams, program logic, business logic, and data models in Structured Query Language (SQL)/Data Definition Language (DDL) format.
This information will provide the baseline documentation needed to assess the status and maturity of the applications as well as the foundation by which all applications will be documented in the future. This information shall be stored in a contractor-created repository hosted on a Government environment that will allow evidence-based decisions to be made by the
Government. With this information, the contractor shall provide their recommendations based on the Government’s desire to reduce costs associated with sustainment of the IT portfolio.
The contractor shall recommend whether the applications should be migrated from legacy language to a modern language to enable re-hosting on a cloud environment, replaced by another application with similar functionality (including, but not limited to, EBS), or moved into a business rules engine.
All deliverables must be Risk Management Framework (RMF)-compliant to the maximum extent practicable to support future RMF requirements.
At the completion of the contract, the contractor shall provide system-specific (reference PWS paragraph 2) presentation sessions to the Government to ensure complete and thorough understanding of all deliverables at the Government facility.
2. SYSTEM DESCRIPTIONS
The AF/A1 portfolio contains AFMilPerS, a network of web-based applications, which allows users to access public and private pages and to perform military personnel actions not readily available in the MilPDS. AFMilPerS is a collection of more than 60 individual web and
Windows-based applications. For this effort, the scope includes: Assignment Management
System (AMS), Case Management System (CMS), Virtual Military Personnel Flight (vMPF), Automated Records Management System Legacy Conversion (ARMS-LC), and Other Web
Applications (OWA). Additionally, Legacy Human Resources (HR) applications use web-based applications to authenticate users and to determine their levels of authorized access to public and private pages based on designated roles and responsibilities. For the effort described in this
PWS, the scope includes Air Force Personnel Center Secure (AFPC Secure).
2.1 Case Management System (CMS) Web (Core) and Personnel Processing Applications
(PPAs)
CMS Web Core allows Financial Services Offices (FSO) and Military Personnel Flights (MPFs) to route customers’ cases to an appropriate agency that needs to resolve the problem. CMS support for military pay and personnel agencies are at all levels, which include Base, MAJCOM, AFPC, and DFAS. It is also the single source for pay record resolution and information about
AF military pay problems.
CMS PPAs:
Base Level Delivery Service Model (BLSDM)
Designated Location Move (DLM)
Evaluation Appeals (EvalAppeals) Web
Exceptional Family Member Program (EFMP) Web
High School Senior Assignment Deferment (HSSAD)
Homebasing/Follow-on Assignments (Homebase) Web
Humanitarian Reassignment and Deferment (HUMI) Web
Service Date Verification (SDV) Web
Verify Withdraw/Cancel Assignment (VWCR) Web
Voluntary Separation Web (VolSep) Web
2.2 Assignment Management System (AMS) / Millennium / Base Level Service Delivery
Model (BLSDM) / Aviator Retention Pay (ARP)
AMS provides Active Duty personnel access to current authorization and requirements lists, procedural guidance and information, and personnel information. AMS allows members, commanders, and Major Commands (MAJCOMs) to work with the appropriate assignment officers at HQ AFPC to fill positions with qualified and eligible mission-ready resources.
Millennium provides all of the supporting documentation for the officer assignment process, which includes, but is not limited to, Single Unit Retrieval Formats (SURFs), Airmen
Development Plans (ADPs), Vulnerability to Move List (VML), Requisitions, and 214 Form.
CMS BLSDM PPA is separate from AMS BLSDM application; both systems require separate accounts to be created with authorized roles.
ARP automates the ARP agreement application process for the AF ARP Program for the active duty component. ARP provides a monetary bonus to rated active duty officers for their continued service in the AF. ARP is used to allow eligible active duty officers to apply for the program and for the Business Process Owner (BPO) to process their ARP agreements.
2.3 Virtual Military Personnel Flight (vMPF) / Virtual Record of Emergency Data (vRED) /
Orders Processing Application (OPA) vMPF allows the member to view different areas of their personnel record and make limited updates to certain personnel information.
vRED is used to support the AF Casualty Program by providing timely/accurate next of kin contact information necessary to complete casualty notifications.
OPA provides on-demand member information to automatically populate the Permanent Change of Station (PCS) order. OPA provides projected departure date information daily on requested assignment action numbers.
2.4 Other Web Applications (OWAs)
The OWA system descriptions are listed in Appendix A.
2.5 Virtual Personnel Services Center (vPSC)
vPSC is a dashboard which provides the member basic information, development plan status, and development plan reviewer history.
Personnel Records Display Application (PRDA) is an electronic viewer for the Automated
Records Management System (ARMS) containing role based access (RBA).
Airmen Development Plan (ADP) will be replaced by MyVector at a date to be determined.
ADP offers a mentoring network for managing career development with the input and guidance from an assigned mentor.
RBA grants authorities designated to member.
2.6 Air Force Fitness Management System II (AFFMS II)
AFFMS II provides a means of capturing, storing, displaying, and analyzing AF personnel fitness management data. This application utilizes the GCSS-AF Portal and framework security services to control access to the system and its data.
2.7 AFPC Secure and AFPC Secure Maintenance Application
AFPC Secure provides a single secure login point for potentially any of the AFPC Secure webs.
This application uses PKI and Reduced Sign On from the portal to validate users for access into secured web applications.
AFPC Secure Maintenance Application is a Windows application used to maintain the AFPC
Secure web application users and applications that it secures.
2.8. Automated Records Management System Legacy Conversion (ARMS-LC)
ARMS is an Air Force Personnel Center (AFPC) managed communications-computer system initiative for Master Personnel Records management at HQ AFPC and HQ ARPC which utilizes
Commercial Off The Shelf (COTS) software and Storage Area Network (SAN) technology for storage and retrieval.
The ARMS programs accomplish the storage, retrieval, and life cycle management of Master
Personnel Records for all active duty, Air National Guard, and Air Force Reserve personnel.
These programs are comprised of on-line, real-time, and batch processing that includes Web access and digital paper scanning.
3. GENERAL REQUIREMENTS
3.1 CONTRACT MANAGEMENT
The contractor shall establish and provide a qualified workforce capable of performing the tasks required in this PWS. The contractor shall institute and maintain a process that ensures problems and action items discussed with the Government are tracked through resolution and shall provide timely status reporting to the Government.
3.2 BILLABLE HOURS
If necessary, in order for man-hours to be billed, deliverable services must have been performed in direct support of this PWS.
3.3 NON-PERSONAL SERVICES
The Government will neither supervise contractor employees nor control the method by which the contractor performs the tasks required in this PWS. Under no circumstances shall the
Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor feels that any actions constitute, or are perceived to constitute, personal services, it shall be the contractor’s responsibility to notify the Contracting Officer (CO) immediately.
These services shall not be used to perform work of a policy/decision-making or management nature; i.e., inherently Governmental functions. All decisions relative to programs supported by the contractor shall be the sole responsibility of the Government.
3.4 CONTRACTOR IDENTIFICATION
All contractor personnel shall wear AF-approved or provided picture identification badges so as to distinguish themselves from Government employees. When conversing with Government personnel during business meetings, over the telephone, or via electronic mail, contractor personnel shall identify themselves as such to avoid situations arising where sensitive topics might be better discussed solely between Government employees. Contractors shall identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks shall identify contractor company affiliation. Where practicable, contractors occupying collocated space with their Government program office should identify their work space area with their contractor name and company affiliation.
3.5 TRAINING
Contractor personnel are required to possess the skills necessary to support the contractor’s minimum requirements of the labor category under which they are performing. Training necessary to meet minimum requirements is not the responsibility of, and will not be paid for, by the Government.
3.6 CYBERSECURITY
The contractor shall ensure that all system and application deliverables meet the requirements of all Department of Defense (DoD) and AF Cybersecurity policy as identified in the next few paragraphs.
System Cybersecurity
For those solutions that will not inherit existing network security controls, and thus will integrate an entirely new application system consisting of a combination of hardware, firmware, and software, system security assurance is required at all layers of the Transmission Control
Protocol/Internet Protocol (TCP/IP) DoD Model. The contractor shall ensure that all system deliverables comply with DoD and AF Cybersecurity policy, specifically DoDI 8500.01, Cybersecurity, and AFI 17-130, Air Force Cybersecurity Program Management. To ensure that cybersecurity policy is implemented correctly on systems, contractors shall ensure compliance with DoD and AF Certification and Accreditation policy, specifically Department of Defense
Instruction (DoDI) 8510.01, Risk Management Framework (RMF) for DoD Information
Technology (IT) and AFI 17-101 Risk Management Framework (RMF) for Air Force
Information Technology (IT). The contractor shall also support activities and meet the requirements of DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling, in order to achieve standardized, PKI-supported capabilities for biometrics, digital signatures, encryption, identification, and authentication.
Application Cybersecurity
The contractor shall ensure that all application deliverables adhere to Public Law 111-383, the
“Skelton National Defense Authorization Act for Fiscal Year 2011,” Section 932, which strategizes the general need for software assurance. Specifically, the contractor shall ensure that all application deliverables comply with the Defense Information Systems Agency (DISA)
Application Security and Development Security Technical Implementation Guide (STIG), which includes the need for source code scanning, the DISA database STIG, and a Web Penetration
Test to mitigate vulnerabilities associated with SQL injections, cross-site scripting, and buffer overflows.
4. RECORDS, FILES, DOCUMENTS
All physical records, files, documents, and work papers, provided and/or generated by the
Government and/or generated for the Government in performance of this PWS, maintained by the contractor which are to be transferred or released to the Government or successor contractor, shall become and remain Government property and shall be maintained and disposed of in accordance with AFMAN 33-363, Management of Records; AFI 33-364, Records Disposition –
Procedures and Responsibilities; the Federal Acquisition Regulation (FAR) and/or the Defense
Federal Acquisition Regulation Supplement (DFARS), as applicable. Nothing in this section of the PWS alters the rights of the Government or the contractor with respect to patents, data rights, copyrights, or any other intellectual property or proprietary information as set forth in any other part of this PWS.
5. SECURITY REQUIREMENTS
5.1 OBTAINING AND RETRIEVING IDENTIFICATION MEDIA
As prescribed by the AFFARS 5352.242-9000, Contractor access to Air Force installations, the contractor shall comply with the following requirements:
The contractor shall obtain base identification and vehicle passes for all contractor personnel who make frequent visits to or perform work on the AF installation cited in the contract.
No later than three days prior to start of contract work, the contractor shall submit a written request on company letterhead (or electronic mail correspondence) to the Government Program
Manager (with a copy to Contract Specialist) listing the following: project title, project number, contract number, location of work site, contract start and end dates, work schedule, and names of contractor employees needing access to the base, including full legal name, date of birth, sex, race, SSAN, state issued identification card or driver’s license number, and name of subcontractor(s), if applicable. The Government will provide a template to be used when submitting the visitor pass request. The authorized Government Program Manager will endorse the request and forward it to the issuing base pass and registration office or Security Forces for processing. Contractors shall present Government (state or federal) issued ID and INS Form 9
Employment Eligibility Verification (Form I-9) before being issued a pass to enter the installation. A Wants and Warrants check is conducted for every person before a pass is issued.
Personnel employed by the contractor must get a pass for their privately owned vehicles at the installation Visitor Reception Center with proof of following: liability insurance, current license plates, current state inspection sticker, valid state driver license, and a phone number for sponsor on base.
Vehicles owned by the contractor with the company name permanently printed on them are not required to obtain a pass as long as a current work order is presented at the time of entry to the installation. However, current liability insurance, state inspection sticker, and registration are required. The person driving the vehicle must have a valid operator license for the type of vehicle being driven.
The contractor is responsible for ensuring employees report to the installation Visitor Reception
Center to present their Form I-9.
Upon completion or termination of the contract or expiration of the identification passes, the contractor shall ensure that all base identification passes issued to contractor employees are returned to the issuing office. If a contractor employee has been terminated, the pass shall be retrieved and returned to Security Forces to ensure the employee does not have base access. If the pass is not retrieved, Security Forces shall be notified so base access is not allowed. Upon completion of the contract, the contractor shall return all issued installation access passes to the issuing authority.
Failure to comply with these requirements may result in withholding of final payment.
5.2 PASS AND IDENTIFICATION ITEMS
Installation Access Pass (IAP) (DBIDS), Visitor/Vehicle Pass (AFI 31-113), used for contracts for less than one year to include one-day visits (i.e. warranty work).
Installation Access Card (IAC) (DBIDS), Civilian Identification Card (AFI 31-113), used for contracts for more than one year or more which do not require access to controlled areas or
Government computer systems.
DoD Common Access Card (CAC), (AFI 36-3026), used for contracts for more than one year and requirement exists for access to the Government computer systems and software. CAC applications are accomplished by Trusted Agents via the Trusted Agent Sponsorship System
(TASS).
5.3 SUITABITLITY INVESTIGATIONS
For contracts requiring IT-Level III computer access, contractor personnel shall successfully complete, at a minimum, a Tier 1 background investigation (formerly known as a NACI), before being issued a CAC and operating a Government furnished workstation. The contractor shall comply with the DoD 5200.2-R, Personnel Security Program, AFMAN 33-152, User
Responsibilities and Guidance for Information Systems, and AFI 17-130, Cybersecurity Program
Management, requirements. Tier 1 investigation requests are initiated using the Standard Form
85 and are submitted to the installation Information Protection Office through the using agency’s
Unit Security Manager within five days of contract start. Tier 1 investigations are provided by the Government at no additional cost to the contractor.
For contracts requiring routine access to the installation in excess of 180 days, the contractor shall complete a Tier 1 investigation. These investigations are submitted using the Standard
Form 85, and are submitted to the Information Protection Office through the using agency’s Unit
Security Manager within five days of contract start.
5.4 LISTING OF EMPLOYEES
The contractor shall maintain a current listing of employees. The list shall include each employee's name, social security number, and date of investigation if service work involves unescorted entry to AF restricted or other sensitive areas designated by the Installation
Commander. The list shall be validated and signed by the company supervisor and provided to the Contracting Officer prior to the contract start date. Updated listings shall be provided when an employee's status or information changes.
5.5 FREEDOM OF INFORMATION ACT PROGRAM (FOIA)
The contractor shall comply with DoD Regulation 5400.7-R/Air Force Supplement, DoD
Freedom of Information Act Program, requirements. The regulation sets policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding For Official Use Only (FOUO) material. The contractor shall comply with AFI 33-
332, Air Force Privacy and Civil Liberties Program, when collecting and maintaining information protected by the Privacy Act of 1974 authorized by Title 10, United States Code, Section 8013. The contractor shall remove or destroy official records only in accordance with
AFMAN 33-363, Management of Records, or other directives authorized in AFI 33-364, Records
Disposition—Procedures and Responsibilities.
5.6 REPORTING REQUIREMENTS
The contractor shall comply with AFI 71-101, Volume 1, Criminal Investigations, and Volume
2, Protective Service Matters, requirements. Contractor personnel shall report to an appropriate authority any information or circumstances of which they are aware may pose a threat to the security of DoD personnel, contractor personnel, resources, and classified or unclassified
Defense information. Contractor employees shall be briefed by their immediate supervisor upon initial on-base assignment and as required thereafter.
5.7 ADDITIONAL SECURITY REQUIREMENTS
In accordance with DoDM 5200.01 and AFI 16-1404, Air Force Information Security Program, the contractor shall comply with AFMAN 33-152, User Responsibilities and Guidance for
Information Systems; AFI 17-130, Cybersecurity Program Management; applicable AFKAGs, AFIs, and AFSSIs for Communication Security (COMSEC); and AFI 10-701, Operations
Security (OPSEC). The contractor shall comply with DoD Standard 22/Force Protection
Condition Measures, DoD Standard 25/Level I-AT Awareness Training, and associated tasking contained in AFI 10-245, Antiterrorism (AT) standards. Level I AT Awareness training is available for contractor personnel and can be requested by calling the installation Antiterrorism
Office.
5.8 PHYSICAL SECURITY
Areas controlled by contractor employees shall comply with base Operations Plans/instructions for FPCON procedures, Random Antiterrorism Measures (RAMS), and local search/identification requirements. The contractor shall safeguard all Government property, including controlled forms provided for contractor use. At the close of each work period, Government training equipment, ground aerospace vehicles, facilities, support equipment, and other valuable materials shall be secured. During increased FPCONs, contractors may have limited access to the installation and should expect entrance delays.
5.9 TRAFFIC LAWS
The contractor and their employees shall comply with base traffic regulations.
6. SYSTEM AND NETWORK AUTHORIZATION ACCESS REQUESTS
For contractor personnel who require access to DoD, DISA, or AF computing equipment or networks, the contractor shall have the employee sign and submit a System Authorization Access
Report (SAAR), DD Form 2875, when access is needed.
7. PROTECTION OF SYSTEM DATA
Unless otherwise stated in the contract, the contractor shall protect system design-related documents and operational data whether in written or electronic form via a network in accordance with all applicable policies and procedures for such data, including DoD Regulations
5400.7-R and 5200.1-R, to include the latest changes and applicable service/agency/combatant command policies and procedures. The contractor shall protect system design-related documents and operational data at least to the level provided by SSL/TSL-protected web site connections with certificate and or user ID/password-based access controls. In either case, the certificates used by the contractor for these protections shall be DoD or Intelligence Community (IC)-approved PKI certificates issued by a DoD approved External Certification Authority (ECA) and shall make use of at least 128-bit encryption.
8. SECTION 508 OF THE REHABILITATION ACT
The contractor shall meet the requirements of regulations at 36 CFR Part 1194, particularly
1194.22, which implements Section 508 of the Rehabilitation Act of 1973, as amended. Section
508 (as amended) of the Rehabilitation Act of 1973 (20 U.S.C. 794d) established comprehensive requirements to ensure: (1) Federal employees with disabilities are able to use IT to do their jobs; and (2) members of the public with disabilities who are seeking information from Federal sources will be able to use IT to access the information on an equal footing with people who do not have disabilities.
9. ORGANIZATIONAL CONFLICT OF INTEREST (OCI)
Whenever the Government solicits information from the contractor for the purposes of issuing a potential contract (or, if the Government issues a contract without first soliciting information from the contractor), unless the contract states that it is exempt from the OCI provisions, the contractor shall promptly review the services ordered prior to commencing performance and inform the Contracting Officer, in writing, of any pre-existing circumstances which might create a conflict of interest under the OCI provisions of this contract with a plan to mitigate conflicts.
In such event, the Government may, in its sole discretion, either cancel the contract with no cost to the Government or grant a waiver to the OCI provisions and direct the contractor to proceed with performance. This process will apply over the life of the contract.
10. ON-SITE TASK APPROVAL PROCESS
The contractor shall notify the on-site Contracting Officer’s Representative (COR) in writing seven (7) business days before a requirements analysis/conceptual design visit, site survey, and other on-site tasks are to be performed. The following information shall be provided: names of employees; SSANs; Security Clearance level; location; project number; on/about date planned for on-site work; anticipated duration of visit; and support required.
11. ENTERPRISE-WIDE CONTRACTOR MANPOWER REPORTING APPLICATION
(E-CMRA)
The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: http://www.ecmra.mil/. Reporting inputs will be for the labor executed during the period of performance during each Government Fiscal Year (FY), which runs October 1 through http://www.ecmra.mil/
September 30. While inputs may be reported any time during the FY, all data shall be reported no later than September 30 of each calendar year, beginning with 2017. Contractors may direct questions to the help desk at: http://www.ecmra.mil/.
12. DATA DELIVERABLES (EXHIBIT 1)
As stated previously, all products delivered to the Government shall NOT be proprietary to the contractor, and it is the Government’s intention to use the information and deliverables derived from the study described in this PWS for future acquisition as Government Furnished
Information.
In an RMF-compliant deliverable, the contractor shall provide, at a minimum, the requirements identified below (also located on the DD Form 1423, Contract Data Requirements List [CDRLs] to be provided at contract award):
A001: Assessment of Legacy Applications o Conduct a preliminary assessment of the source code of all applications described in this
PWS to determine language of code, lines of code, inventory of files, complexity, dead code, and interfaces, and provide recommendations to the Government on how to proceed with the rest of the study.
o Conduct an assessment of the legacy applications based on source code logistics, source code complexity, dead code details, data dictionaries, system detail diagrams, data flow diagrams, program flow diagrams, data models in SQL/DDL format, program logic, and business logic.
Measure of Success: A001 is successful when the preliminary assessment is delivered within the first 120 days of contract award, detailing the rest of the study with a preliminary analysis that defines the language of code, lines of code, inventory of files, complexity, dead code, and interfaces.
A002: Create a meta-data repository and process for collaborative decision analysis for use by the Human Resources Systems Division.
Measure of Success: A002 is successful when the meta-data repository is created and it correctly includes the following information per application: source code logistics, source code complexity, dead code details, data dictionaries, system detail diagrams, data flow diagrams, program flow diagrams, program logic, business logic, and data models in SQL/DDL format.
The contractor shall provide instructions and demonstrate how to access and use the meta-data repository.
A003: Conduct a fit-gap analysis
Identify how EBS, or existing systems/applications, can be utilized to modernize the legacy systems.
o Recommend whether the application should be migrated from legacy language to a modern language to enable re-hosting on a cloud environment, replaced by another application with http://www.ecmra.mil/ similar functionality (including but not limited to EBS), or moved into a business rules engine.
o Identify level of effort, feasibility, and required code re-writes necessary to minimize customizations as well as any needed database restructure.
Measure of Success: A003 is successful when the fit-gap analysis is conducted and the contractor provides recommendations to Government based on three different conditions:
1. If the application should be migrated from legacy language to a modern language to enable re-hosting on a cloud environment.
2. If the application should be replaced by another application with similar functionality
(including but not limited to EBS).
3. If the application should be moved into a business rules engine.
A004: Roadmap of Legacy modifications and improvements o Data Center Optimization Initiative directive to host on a DoD-approved cloud environment.
o Identify what applications have duplicative capability that should be consolidated into one.
Measure of Success: A004 is successful when the contractor provides the following:
1. a roadmap identifying the applications that the contractor recommends should be consolidated or refactored in order to be DCOI-compliant; and
2. the logical order in which the consolidations or refactoring should be executed.
A005: Provide Documentation to the Government o Identify capability duplicative of that inherently included in EBS.
o Identify any additional infrastructure requirements necessary for inclusion into EBS.
Measure of Success: A005 is successful when all documentation is provided to the Government in a manner that clearly describes all requisite architecture/infrastructure requirements necessary to realize the transfer of capability from a legacy web application to EBS.
APPENDIX A: OTHER WEB APPLICATIONS LISTING
Application/Project Name Notes
Active Directory - Groups and Users
Used by FSAs and developers to troubleshoot users based on group membership. Updated to support AFPC and AREA52 domains.
Air Force Officer Qualification Test Scores
1. AFOQTSMaint
2. AFOQTS
Authorized Service Interruption Web (ASINet) ASINet
Awards and Decorations
1. AwardsMaintNet
2. AwardsNet
3. AwardsDMZ
Base MDBS
1. BaseMDBS
2. BaseMdbsMaint
Board Secretariat Maintenance BoardSecNet20_Maint
College Loan Repayment Plan (CLRP)
1. CLRP
2. CLRPMaint
Competitive Level Codes Maintenance
Application CompLMaint
Disability Pay Calculator DisabilityPayCalculator
Discoverer Users Password web DupWeb
Enlisted Promotion
1. EProm
2. EPromMaint
FSA Data Maintenance Support Application for Bobby Waldo
Health Professions Education Requirements
Board Web
HPERB
IG Investigations and Inquiries IGInvestigationsAndInquiries
Mil Print Strip
1. MilPrintStripControlCenter
2. MilModPrintView
3. MilPrintAuthUserMaint
4. PrintStripService
5. SASReportRecall
6. MilPDSSasRpt
Pascodes
1. Pascodes
2. PascodesMaint
Personnel Quality-Of-Life Measurement Tool
1. PersTempo
2. PersTempoMaint
Requirements Management System
1. RMS
2. RMSMaint
Reserve Management Vacancy System Web
1. RMVS
2. RMVSSsanListMaint
Retirement Separations Calculator web RetSepCalc
RMVS Interactive Refresh
RMVS SSAN List Maintenance Application Generates updated AFPC Secure Access list for the RMVS application
Senior or Intermediate Developmental
Education Process web
1. ISDE
2. ISDEMaint
Standardized Competitive Level Codes web
TEMPO Management and Tracking System BurdensomePT (TMTS)
Testing Access System for AFPC Secure
(TASA) allows developers and testers in the DEV and ITE environments to emulate another user with their assigned CAC.
TASA users that are emulating another SSAN are reset by a
SQL Server Job to their True SSAN each night at 10PM CDT.
This application should never be installed to the Production
Environment. It is intended only as a Development and
Testing tool.
Web Application Configuration Maintenance
Application .Net 20
Windows Maintenance application that is used to maintain the key value pairs stored in the Web Application Configuration
Database. This application is important for maintaining connection strings and other vital information for HIGG Web applications.
Web Application Error Log Monitor
Application
Windows Maintenance application developed for FSAs, Project Managers, and developers to assist in troubleshooting web applications that maintain error log information in the
Web Application Configuration databases for all environments.
File details come from the government source that posted it. Updated .