Draft_PWS.docx
DOCX document 65 KB Posted
- Attached to
- REQUEST FOR INFORMATION - Global Application Research, Development, Engineering & Maintenance (GARDEM) Federal contract opportunity
- Solicitation number
- FA8750-18-R-0001
About this file
PERFORMANCE WORK STATEMENT (PWS) FOR GLOBAL APPLICATION RESEARCH, DEVELOPMENT, ENGINEERING & MAINTENANCE (GARDEM)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| GARDEM_INDUSTRY_DAY_QUESTIONS_AND_ANSWERS.pdf | ||
| Interested_Parties_List_as_of_9_April_2018.pdf | ||
| GARDEM_Industry_Day_Notice_-_06FEB18.pdf | ||
| RRS_Form_31_Request_for_Visit_Authorization_to_RRS.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
E-9-XXXX
AIR FORCE RESEARCH LABORATORY
ROME RESEARCH SITE
ROME, NEW YORK
DRAFT
PERFORMANCE WORK STATEMENT (PWS)
FOR
GLOBAL APPLICATION RESEARCH, DEVELOPMENT, ENGINEERING & MAINTENANCE (GARDEM)
PCSN E-7-XXXX
20 APRIL 2017
TABLE OF CONTENTS
| Paragraph |
| Subject |
| Page |
| 1.0 |
| Purpose |
| 3 |
| 2.0 |
| Description of Services |
| 3 |
| 3.0 |
| Services Summary |
| 9 |
| 4.0 |
| General Requirements/Appendix |
| 9 |
| 1.0 | PURPOSE: The objective of this effort is to perform research, development, prototyping, integration, testing, demonstration, deployment and maintenance of innovative technologies and concepts in support for Global Application Research, Development, Engineering and Maintenance (GARDEM) software baselines. |
| 1.1 | BACKGROUND: Access to information enables the rapid employment of the right military forces at the right place and time to achieve strategic objectives while preventing any adversary from doing the same. To achieve this position of dominance, GARDEM customers require maintenance of and a never-ending flow of state of the art technological capabilities to assemble actionable information from multiple data sources in order to establish and maintain battle space situational awareness and understanding. Technology development will be focused on workflow, operational reporting, intelligence reporting, intelligence exploitation, multi-source data fusion, semantic searching, faceted data navigation, data visualization, data analysis and intelligence production to provide Command, Control, Communications, Computers and Intelligence (C4I) dominance in such areas as counter Improvised Explosive Device (IED), counter-insurgency, counter-terrorism, counter-rocket and mortar, counter-unmanned aerial systems, counter-drug and strategic and operational level planning, assessment and execution. Emphasis will be placed on development that enables re-use across the above mission areas as well as in other domains. |
| 2.0 | DESCRIPTION OF SERVICES: The Contractor shall fulfill requirements that span the full spectrum of Operations and Maintenance (O&M) and Research and Development (R&D) activities supporting the functional and technical requirements of the Air Force, Department of Defense, Intelligence Community (IC) and other federal agencies. The work may include, but is not limited to: system sustainment, system installation (hardware and software), on-site engineering support, hardware and software procurement, analytical studies, system feasibility studies, system design, system trade-off studies, rapid prototyping, system demonstrations, software development, system(s) simulations, functional test and evaluation analyses, security test and evaluation analyses, technology transition, technology integration, and program management as determined on an order by order basis. The work will be performed on operational systems to include, but not limited to, the following GARDEM software baselines: |
· Combined Information Data Network Exchange (CIDNE)
· Web-enabled Temporal Analysis System (WebTAS) Enterprise (WE)
· Topic Builder
· International Distributed Uniform Reporting Environment (INDURE)
· Master Air Attack Planning Tool Kit (MAAP TK)
· Command and Control - Core (C2-Core)
· Counter - Rocket, Artillery, and Mortar (C-RAM)
· WebTAS Intelligence System Domain (WISDom)
· Coast Guard Enterprise Intelligence Framework (CG-EIF)
· Project Tool
· Long Range Aviation (LRA)
· Capacity Building Dashboard (CBD)
· Common Awareness Architecture (CAA)
· Civil Aviation Knowledge Base (CAKB)
· Integrated Space Situational Awareness (ISSA) suite of tools
2.1 SYSTEM ENGINEERING AND BASELINE ENHANCEMENTS: The requirements for each order description will vary and may encompass contractor facility and on-site system engineering, software system O&M and minor enhancements to include, but not limited to, the currently installed software baselines listed in paragraph 2.0 at the following locations. This includes providing an enterprise solution consisting of field service support, system administration, training, requirements collection and analysis, and revising intelligence and operations Standard Operating Procedures (SOPs) and Tactics, Techniques, and Procedures (TTPs). Minor enhancements will enable incremental system improvement through upgrades of individual hardware and software modules with newer modular components without redesign of entire system or large portions thereof, to include, but not limited to:
· U.S. Northern Command (USNORTHCOM) Peterson AFB
· U.S. Southern Command (USSOUTHCOM) Miami, FL,
· Civil Aviation Intelligence Analysis Center (CAIAC), Washington, DC,
· Air Force Space Command (AFSPC), Schriever AFB, CO
· Air Force Space Command (AFSPC), Peterson AFB, CO
· Joint Inter Agency Task Force - West (JIATF-W), Camp H.M. Smith, HI
· U.S. Army Pacific (USARPAC), Fort Shafter, Hawaii, HI
· Pacific Air Forces (PACAF), Honolulu, HI
· Special Operations Command, Pacific (SOCPAC), Camp H.M. Smith, HI
· U.S. Central Command (USCENTCOM) theater of operation to include, but not limited to:
· Bagram, Afghanistan
· Kabul, Afghanistan
· MacDill AFB, Tampa, FL
· Kuwait
· Iraq
· Naval Support Activity Bahrain, Bahrain
· Special Operations Joint Task Force - Afghanistan (SOJTF-A)
· Bagram, Afghanistan
· Camp Morehead, Afghanistan
· 8th Army, South Korea
· Combined Joint Task Force - Horn of Africa (CJTF-HOA), Djibouti, Djibouti
· U.S. Army Central (USARCENT), Shaw AFB, Sumter SC
· U.S. Coast Guard (USCG) Headquarters, Washington DC
· USCG Intelligence Coordination Center, Suitland, MD
· USCG Maritime Intelligence Fusion Center Pacific (MIFCPAC), Alameda, CA
· USCG Maritime Intelligence Fusion Center Atlantic (MIFCLANT), Damneck, VA
· National Ground Intelligence Center (NGIC), Charlottesville, VA
· Combined Training Center (CTC) / Joint Multinational Readiness Center (JMRC), Hohenfels, Germany
· CTC / National Training Center (NTC), Ft. Irwin, CA
· CTC / Joint Readiness Training Center (JRTC), Ft. Polk, LA
· U.S. Strategic Command (USSTRATCOM), Schriever AFB, CO
| 2.1.1 | On-site system engineering support tasks include but are not limited to system installations (para 4.3), testing (para 4.15), documentation (para 4.6), PR/CR management (para 4.2), systems engineering (para 4.5), Authorization and Assessment (A&A) (para 4.16), interface management (para 4.4), and integration. | |
| 2.1.2 | Participate in site exercises and wargames and maintain software during special contingency situations as requested by the Government. The exercise or contingency will be at or near an existing site, overseas, or remote location. Special contingency situations include, war, armed conflict, insurrection, civil or military strife. These services are designated as mission-critical. | |
| 2.1.3 | Provide a modular open standards approach to developing applications and architecture changes. | |
| 2.2 | RESEARCH AND DEVELOPMENT: Research, design, develop, engineer, and implement software enhancements to include, but not limited to: WE, LRA, CBD, CAA, ISSA suite of tools, MAAP TK and CAKB, to integrate, correlate, and fuse intelligence, command and control and operational data from a variety of databases, sensors, platforms, display the data, and provide access to the data from external systems via application and enterprise services to improve Air, Ground and Space Situation Awareness and enable data analysis. | |
| 2.2.1 | Provide on-site system research and development, test, and installation at the following locations, to include, but not limited to: |
· Air Force Space Command (AFSPC), Schriever AFB, CO
· Civil Aviation Intelligence Analysis Center (CAIAC), Washington DC
| 2.2.1.2 | On-site tasks include but are not limited to system installations (para 4.3), testing (para 4.15), documentation (para 4.6), PR/CR management (para 4.2), systems engineering (para 4.5), Authorization and Assessment (A&A) (para 4.16), interface management (para 4.4), and integration. | |
| 2.2.2 | Research, design, develop, prototype, test and integrate software and hardware solutions to meet government approved objectives. Develop and modify applications in support of command and control, operational and intelligence reporting, data analysis, and command and control exercises and operations to include but not limited to the following: | |
| 2.2.2.1 | Case studies and software to support data collection, management, analysis and reporting solutions. | |
| 2.2.2.2 | Candidate software enhancements to adapt to changing tactics and evolving threats. | |
| 2.2.2.3 | Data access, storage, user interface, services and information retrieval patterns to mature GARDEM capability system architecture with goal of improving interoperability. | |
| 2.2.2.4 | Mission applications across the air, space, cyber, and maritime domains. | |
| 2.2.2.4.1 | Service-based mission planning application. This includes new data interfaces with Air Operations Center (AOC) applications and data sources, to include but not limited to Air Operations Database (AODB), Modernized Intelligence Database (MIDB), Joint Targeting Database (JTDB), Digital Aeronautical Flight Information File (DAFIF), Friendly Order of Battle (FrOB), weather data, and Theater Battle Management Core System (TBMCS). | |
| 2.2.2.4.2 | Service-based Intelligence Surveillance and Reconnaissance (ISR) mission planning application that includes data interfaces with operational collection management systems and data to include, but not limited to, Strategy to Task for Kill Chain Effectiveness (STAKE), Planning tool for Resource Integration, Synchronization, and Management (PRISM), Reconnaissance, Surveillance, and Target Acquisition (RSTA), Joint Integrated Prioritized Collection List (JIPCL), Joint Integrated Prioritized Target List (JIPTL) and Unified Collection Operations Reporting Network (UNICORN). | |
| 2.2.2.4.3 | Service-based space planning application that integrates space & terrestrial sensor status and configuration data with space assets data and capabilities into theater planning systems, command and control, and airborne support and execution platforms. | |
| 2.2.2.5 | Routing of digital information with minimal man-in-the-loop operations, across various interfaces, network/security domains, formats and mediums as needed. | |
| 2.2.2.5.1 | Novel database and data interfaces with cross domain solutions to include Information Support Server Environment (ISSE) Guard. | |
| 2.2.2.5.2 | Design, develop, implement and demonstrate capabilities to exploit data at multiple classification levels supporting mission domains. | |
| 2.2.2.6 | High fidelity modeling/simulation for mission planning and mission rehearsal. | |
| 2.2.2.7 | Information Fusion capabilities that includes collection, association, correlation, processing, analysis, storing, exploitation, and dissemination of fused information intelligence from multiple data sources, sensor sources, sensor types, Human Intelligence (HUMINT), Signal Intelligence (SIGINT), Imagery Intelligence (IMINT), Measures and Signature Intelligence (MASINT), and other data sources as required. | |
| 2.2.2.7.1 | Knowledge-based predictive analysis capabilities from fusing behavioral models and/or historical data with current ISR data to accurately predict future operational events or geographical areas for concern. | |
| 2.2.2.7.2 | Automated tools to extract, discover, analyze, and link together sparse evidence from vast amounts of data across multiple sources. Advanced search and query, link analysis, knowledge analysis, social network analysis and group detection technologies. | |
| 2.2.2.7.3 | Civil aviation fusion, indications & warning, and correlation algorithms. | |
| 2.2.2.8 | Novel methods for open source intelligence (OSINT) fusion and analysis to include web and directory crawling of enterprise and web data sources to include but not limited to RSS feeds, SharePoint, dark and deep web data, and migration to cloud infrastructure. | |
| 2.2.2.9 | Adaptive display technology, visualization techniques, and qualitative temporal and spatial reasoning to support the higher levels of information fusion. | |
| 2.2.2.9.1 | Provide these technical capabilities across a broad range of data sets from extremely large data sets to very specific domain dependent data sources to improve overall accuracy and situational awareness. | |
| 2.2.2.9.2 | Design, develop, implement and demonstrate capability to perform fusion, exploitation and visualization of multiple data sources into one common display. | |
| 2.2.2.9.3 | Capability to store raw observations and processed (fused) data using nontraditional data types in various formats. | |
| 2.2.2.9.4 | Capability to incorporate and enhance government supplied detection algorithms and work with multiple teammates towards common goal within a cloud computing environment. | |
| 2.2.2.9.5 | Capability to disseminate the raw and fused data to tactical, operational and strategic users. | |
| 2.2.2.9.6 | Capability to interface with existing organizations and tools. | |
| 2.2.2.9.7 | Analytical software solutions to include database schema development. |
| 3.0 | SERVICES SUMMARY (SS): The following table identifies and describes the performance objectives and thresholds for the critical tasks/work requirements specified in the PWS. This is also the Surveillance Checklist for contract performance period. |
| Performance |
Objective
PWS
Reference Performance Threshold/ Standard
| Quality of performing requirements. |
| 2.0 |
| Requirements are successfully completed on-time as defined in each order PWS 95% of the time. |
| Security. |
| 4.13 |
| Implement security controls to assure 100% compliance to security protection requirements. |
| Resources. |
| 4.13 |
| Cleared, adequate resources and cleared qualified personnel are maintained at the levels required for successful performance of each order PWS 95% of the time and without adverse effect on the mission. |
| Quality of documentation & deliverable(s). |
| 2.0 |
| Not less than 95% of all documentation/deliverables are complete, accurate, and IAW the order CDRLs. Documentation fulfills its intended use, meets standards and purpose. |
| Timeliness of deliverables |
| 2.0 |
| Not less than 95% of all documentation/deliverables are on time IAW the order CDRLs. |
| Completeness of software deliverables |
| 2.0 |
| Not less than 98% of all software delivered. |
| Management. |
| 4.7 |
| Order management activities completed IAW the PWS. Information and status provided is complete, accurate and timely 95% of the time and without adverse effect on the mission. |
| Report Quality Assurance/ Quality Control. |
| 4.1, 4.2, 4.5, 4.7 |
| 100% of all newly created reports will be Quality Controlled. |
| 1.8 Testing - Problem Reports |
| 4.15 |
| No more than 2 Category 1 PRs identified in round 1 of any Government Acceptance Test. Zero Category 1 PRs acceptable after round 2. |
| 4.0 | GENERAL REQUIREMENTS (Applicability will be determined on an order by order basis) | |
| 4.1 | PROJECT WORK PLAN | |
| 4.1.1 | Perform the work required in accordance with Project Work Plans coordinated with the Program Manager. The Government will provide the detailed performance information for the work effort that must be covered by a work plan. Work plans shall facilitate the Government’s ability to identify specific programs for analysis, provide clarifications, and to emphasize/deemphasize the existing requirements already identified in the PWS. | |
| 4.1.2 | Each project work plan shall show utilization of agile software development and project management practices and include the following: | |
| 4.1.2.1 | Program or project name, overview, stakeholder and Points Of Contact (POC) including Government, User, and Customer, Date, Period of Performance, Appropriation Category, Accounting Classification Reference Number (ACRN), and contract Line Item Number (CLIN). | |
| 4.1.2.2 | Engineering description and break down of key tasks required to meet technical requirements and objectives including technical effort, design and developmental detail, and integration methodology. | |
| 4.1.2.3 | Engineering assessment of software modules and packages involved, documentation, and testing requirements. | |
| 4.1.2.4 | Total cost Rough Order of Magnitude (ROM) to include, ROM tracking number, breakdown of estimated costs including: labor categories (include work location(s)), rates, man hours, Other Direct Costs (ODCs), travel (including origin and destination, number of trips, number of personnel, duration, and purpose) | |
| 4.1.2.5 | Identification of any unique GFI, sub-contractor, and special security considerations | |
| 4.1.2.6 | Schedule identifying key milestones and key deliverables | |
| 4.1.2.7 | Identification of risks impacting cost, schedule, or performance | |
| 4.2 | PROBLEM REPORT (PR)/CHANGE REQUEST (CR) | |
| 4.2.1 | Problem Reports (PRs). Provide software engineering (at contractor facility or on-site) to maintain the baselined software by identifying, correcting, testing and documenting the resolution of the problem reports. | |
| 4.2.2 | Change Requests (CRs). Provide software engineering (at contractor facility or on-site) to enhance the baselined software by designing, developing, integrating, testing and documenting the resolution of the change requests. | |
| 4.2.3 | Implement a process for handling all PRs and CRs assigned for correction or development against the various software baselines. | |
| 4.2.4 | Maintain a central repository for the processing of all PRs, CRs, and work plans. Log, track, validate, and monitor all PRs and CRs on a continuous basis. Utilize system and software engineering metrics, procedures and practices to measure, track and review progress on PR and CR evaluation, technical resolution, coding, testing and completion. | |
| 4.2.5 | PR/CRs are categorized as follows: |
· Category 1: Prevents the accomplishment of an essential capability or jeopardizes safety, security, or other requirement designated "critical".
· Category 2: Adversely affects the accomplishment of an essential capability and no work around solution is known or adversely affects technical, cost, or schedule risks to the project or to life cycle support of the system, and no work-around solution is known.
· Category 3: Adversely affects the accomplishment of an essential capability but a work-around solution is known or adversely affects technical, cost, or schedule risks to the project or to life cycle support of the system, but a work-around solution is known.
· Category 4: Results in user/operator inconvenience or annoyance but does not affect a required operational or mission-essential capability or result in inconvenience or annoyance for development or maintenance personnel but does not prevent the accomplishment of the responsibilities of those personnel.
· Category 5: Any other effect with less impact.
4.2.6 Each PR/CR shall include the following:
· Description on system problem or enhancement to include title, date, overview of functional requirement, use case, priority and impact
· Customer Point of Contact to include name, organization, phone number and e-mail address
· US Government customer’s signature
| 4.2.7 | After a PR/CR is approved by the Government Program Management Office (PMO), generate a PR/CR work plan and PR/CR software requirement specification. |
| 4.2.8 | Provide each work plan to the Government within one (1) working day of receipt of category 1 PR/CRs, within two (2) working days of receipt of category 2 PR/CRs and within five (5) working days for category 3 through 5 PR/CRs. |
| 4.2.9 | PR/CR work plan shall include the following: |
· Total cost estimate to include the labor hours, travel, direct and indirect costs required to design, implement, test, document, and deliver to the Government
· ACRN
· Project schedule to include milestones like design, code, test and delivery phases
· Documentation affected
· PR/CR software requirement specification that shall include the following:
· PR/CR purpose, scope, perspective, functions, user classes and characteristics
· Operating environment parameters and descriptions
· Assumptions and dependencies
· Software modules affected
· Specific requirements to include mock-ups and field tables
| 4.2.10 | Upon Government PMO approval of the PR/CR work plan, design, develop, integrate, test, and deliver software with appropriate system and technical documentation. | |
| 4.3 | SYSTEM INSTALLATION | |
| 4.3.1 | Provide/perform software installation upon Government approval. | |
| 4.3.2 | Perform a site survey to define user requirements and provide an Installation Work Plan to include cost for labor, travel, hardware (if required), Commercial off the Shelf (COTS) software (if required) and schedule. | |
| 4.3.3 | Support site required acceptance testing to include, functional, interoperability, security and A&A. | |
| 4.3.4 | Perform installation rehearsals as required of newly enhanced software, hardware (if required) and COTS software (if required). Document and resolve issues found. | |
| 4.3.5 | Support Deployment Readiness Review (DRR) five (5) working days prior to scheduled installation. The DRR will include relevant Government and Contactor points of contact, installation task list with anticipated task durations, installation risks, schedule, rollback procedures (in the case of an upgrade), and status of network and end-user installation approvals. | |
| 4.3.6 | Support Go - No Go review one (1) working day prior to scheduled installation. The Go - No Go review will be a final review of the DRR information prior to installation with emphasis on any incomplete items from the DRR. | |
| 4.3.7 | Install and configure newly enhanced software, hardware (if required) and COTS software (if required) to meet the site’s operational requirements. | |
| 4.3.8 | Integrate newly enhanced systems with external systems, data bases and other data sources (i.e. streaming data, spread sheets) as required by the site. | |
| 4.3.9 | Design, develop, test, install, and maintain newly enhanced software internal data base(s). | |
| 4.3.10 | Administer site-specific training on the software listed in paragraph 2.0 for site designated users, system managers and operators. | |
| 4.4 | EXTERNAL INTERFACES | |
| 4.4.1 | Evaluate and assess any request for changes to external interfaces. Upon Government approval, provide maintenance and documentation required for continued mission application baseline software interfacing with external systems. This includes changes in machine-to-machine interfaces, data export/import, web services, Application Program Interfaces (APIs), Interface Design Documents (IDDs), message formats, data content, data providers and protocols that may affect interface software. | |
| 4.5 | SYSTEMS ENGINEERING | |
| 4.5.1 | Provide system engineering analysis of software, hardware, databases, network interfaces and web application architecture to include but not limited to: |
· Verification of vendor licenses
· Recommendation for changes/upgrades
· Traffic/Load analyses in support of enhanced network component allocation/design
· DoDAF views to include, but not limited to, Operational View (OV), System Views (SV), and Capability Views (CV)
· Network /communications configuration, systems test/validation, data base administration, workstation configuration (to include hardware/software version control)
· Demonstrate reuse and modularity of software components to DoD test organizations
· Application software modifications and enhancements
· List of deliverables include, but are not limited to:
· Software Design Description (SDD)
· System Requirements Specification (SRS)
· Interface Control Document (ICD)
| 4.6 | MANAGEMENT REQUIREMENTS | |
| 4.6.1 | Continually determine the status of the effort including technical, cost, schedule and report progress toward accomplishment of requirements across all GARDEM orders. | |
| 4.6.2 | Continually determine the status of funding required for performance. | |
| 4.6.3 | Conduct oral presentations to provide status of technical progress made to date. | |
| 4.6.3.1 | Technical Interchange Meetings (TIMs) shall include, but not limited to, status, progress, performance, funding, schedule, personnel, security, assumptions, risks and other pertinent data. | |
| 4.6.3.2 | Program Management Reviews (PMRs) shall address cost, schedule, and performance progress/issues on an order by order basis. | |
| 4.6.4 | Develop and administer a Quality Control Plan for the entire contract. Ensure that all assigned products meet their specified design, format, functional and performance requirements. Assure the quality control process is integrated into all activities supported under the contract. | |
| 4.6.5 | Develop and maintain a Standup Plan which describes the technical approach, organizational resources/staffing and management controls to include quality control, configuration management and risk management to be employed to meet the cost, performance and schedule requirements. | |
| 4.6.5.1 | Provide a staffing process to ensure appropriately cleared and qualified personnel are maintained for successful program performance. Identify and replace personnel who have left the program, acquire additional personnel to address new requirements. | |
| 4.6.5.2 | Ensure personnel comply with all Government policies, procedures and guidance for performance under this contract at any work location. | |
| 4.6.6 | Update existing Government Furnished Documentation in the form of revisions. Format and content of the changes shall not deviate from that of the existing documentation. | |
| 4.6.6.1 | Anticipated documentation include: |
Standard Operation Procedures (SOP)/Working Procedures Collection, Collaboration, and Dissemination Process Documentation Training/Familiarization Materials Software Design Description (SDD) System Requirements Specification (SRS) Interface Control Document (ICD)
| 4.6.7 | Develop Project Work Plans as requested by the COR. | |
| 4.6.8 | Document all technical work accomplished and information gained during performance of this acquisition. Include all pertinent observations, nature of problems, positive and negative results. Document procedures followed, processes developed, “Lessons Learned”, etc. Document the details of all technical work to permit full understanding of the techniques and procedures used in processes developed. Cross-reference separate process specifications delivered to permit a full understanding of the total acquisition. | |
| 4.6.9 | Review, assess and track changes to contractor generated documentation to include but not be limited to: functional, installation, A&A, and test plans. | |
| 4.6.10 | Sponsor annual GARDEM users working group. | |
| 4.6.10.1 | Conduct presentations to the working group on GARDEM related subjects coordinated with the Government. | |
| 4.6.10.2 | Conduct demonstrations of new software version releases or related functionality when available. | |
| 4.7 | CONFIGURATION MANAGEMENT (CM) | |
| 4.7.1 | Maintain and enhance CM processes for all software activities within GARDEM. Establish and maintain development, test, and production baselines in accordance with the Government-approved CM process. Coordinate, evaluate, prioritize, and schedule updates to baselines. Administer software and database baseline media library. | |
| 4.7.2 | Deliver all software developed, modified or enhanced under this effort as source and object (executable) code, API, Software Development Kit (SDK) and developer documentation on electronic media and to development environments and online software repositories as requested by the Government, including commented source listings. | |
| 4.7.3 | Developed, modified and enhanced software under this effort is to be completely maintainable and modifiable with no reliance on any non-delivered computer programs or documentation. | |
| 4.8 | COTS/GOTS SOFTWARE: As upgrades to COTS/GOTS software are released by vendors/Government agents, such upgrades must be assessed for impact to the environment in which they operate. Changes shall first be approved through the CM process established prior to adding to the baseline. Upon Government approval, apply the upgrades to the baseline. | |
| 4.9 | HELP DESK SUPPORT: Provide help desk support for GARDEM software baseline on a published forty (40) hour work week, for all operational, experimental and authorized evaluation installations. | |
| 4.10 | TRAINING AND CERTIFICATION: Establish and execute a robust training baseline and continuing education program incorporating the latest required certifications to include but not limited to system administration, database certification, security certification, and operating system certification required at the sites listed in paragraph 2.1. | |
| 4.11 | ACQUIRE HARDWARE AND SOFTWARE: At the direction of the Government, acquire approved hardware and software to support the software baselines. Include licensing, maintenance and diagnostics support software. Arrange for delivery and installation of hardware, firmware, software and licenses to Government designated sites. | |
| 4.12 | PROPERTY MANAGEMENT: No known Government Furnished Property (GFP) is anticipated at this time, however if required during performance it will be addressed and the contractor will be responsible for providing “Property Management” to include updating and maintaining the listing/database of GFP to assure the accounting and status of all GFP under the contract. | |
| 4.13 | SECURITY REQUIREMENTS | |
| 4.13.1 | Manage all aspects of security associated with performance to include personnel security access, security clearance information preparation, and liaison with Government Point of Contacts (POCs) for security related items. Capture and maintain information regarding all contract personnel and security related data. The personnel information maintained and provided to the Contracting Officer Representative (COR) shall include a list of all personnel performing under the contract, security clearance levels, sponsors, dates for performance, and government identification materials (i.e. CACs, agency badges). Provide information supporting visit requests, CACs, personnel clearance, and other security related activities. Provide softcopy and hardcopy of managed information assuring proper privacy markings and controls are utilized. Format will be Contractor-suggested, Government-approved format. | |
| 4.13.2 | Access To Private Information: Performance may require access to information covered by the Privacy Act of 1974; therefore, contractor personnel shall safeguard all such information in accordance with the Privacy Act of 1974 at all times, and shall not release such information to unauthorized persons. | |
| 4.13.3 | Export Control: The Contractor may be required to carry out technical data/information exports in support of the requirements. Ensure all items have appropriate control markings to include Scientific and Technical INFOrmation (STINFO), export control and classification. Comply with applicable ITAR requirements to meet the needs of the Government. Maintain compliance with all governing directives and policies. | |
| 4.13.4 | Security Clearance: An estimated eighteen (18) Full Time Equivalents (FTEs) with Top Secret/Special Compartmented Information (TS/SCI) access are required to perform the tasking under this contract immediately upon award. Thirty-five (35) days after award an estimated twenty eight (28) additional FTEs with TS/SCI and an estimated three (3) FTEs with Secret access are required. Sixty (60) days after award an estimated twenty one (21) additional FTEs with TS/SCI and an estimated three (3) FTEs with Secret access are required. One-hundred and nine (109) days after award an estimated fifteen (15) additional FTEs with TS/SCI and an estimated seven (7) FTEs with Secret access are required. Two-hundred (200) days after award an estimated fourteen (14) additional FTEs with TS/SCI are required. Two-hundred and eighty four (284) days after award an estimated fifty six (56) additional FTEs with TS/SCI and an estimated five (5) FTEs with Secret access are required. Compliance with DoD 5200.2-R, Personnel Security Program, January 1987 for access to TS/SCI information, systems and facilities is mandatory. All contractor personnel shall be citizens of the United States of America. | |
| 4.13.5 | Safeguarding Classified Information | |
| 4.13.5.1 | Comply with the DD Form 254, DoD Contract Security Classification Specification and attachments. Potential security violations or incidents shall be reported immediately to the AFRL COR and in writing no later than the next work day after the incident occurred. Proper controls shall be utilized (i.e., secure telephone, classified fax, classified e-mail), based on the security classification of the information associated with the possible violation. | |
| 4.13.5.2 | Conform to the provisions of DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), for safeguarding classified information and material contained on the controlled system(s)/network(s). Ensure access is provided only to those persons who have the proper security clearance, a need to know and have been trained in proper safeguarding procedures. | |
| 4.13.5.3 | Participate in the management of security access, preparation of security clearance data/forms, access requests and coordination with Government security POCs. | |
| 4.13.6 | Physical Security | |
| 4.13.6.1 | Comply with the requirements as specified on an order by order basis and individual base support letters. | |
| 4.13.6.2 | The Contractor shall be responsible for safeguarding all Government property provided for Contractor use. At the end of each work period, Contractor personnel working within Government facilities shall ensure that all Government facilities, equipment, and materials provided for their use shall be secured. The Contractor shall follow regulatory guidance concerning maintenance, use, and safety of Government facilities as identified on an order by order basis and specified at other operating locations. | |
| 4.13.6.3 | For Performance of Services during Emergency Conditions, local procedures shall be followed. | |
| 4.14 | ACCESS TO COMPUTER SYSTEMS | |
| 4.14.1 | A User ID (and/or CAC) and Password shall be requested from the designated Government representative. The request shall include the contract number, identification of the employee, including social security number. The request shall include the employee's signature and a statement that the employee understands and accepts the requirement to personally protect any password (and/or CAC) assigned to him or her as a result of the computer access request. | |
| 4.14.2 | Ensure employees do not reveal their passwords to anyone. The obligation to enforce this requirement is a material element of the security requirement herein. | |
| 4.14.3 | Notify the designated Government representative immediately of an employee’s termination from work on this effort. | |
| 4.15 | SOFTWARE TEST AND VALIDATION | |
| 4.15.1 | Conduct Unit Test, Regression Test, System Integration Test, Factory Acceptance Test, Functional Test, Test Readiness Review (TRR), User Acceptance, Installation Performance Validation Test (IPVT) and A&A testing on all releases of software baselines to ensure that the changed software meets requirements and does not adversely impact existing systems, interfaces, or security accreditation. | |
| 4.15.2 | For each software release, provide engineering support and test expertise for Government In-Plant Testing at the contractor’s facility. | |
| 4.15.3 | For each software release provide engineering support and testing expertise for Government A&A testing at the designated test facility. | |
| 4.15.4 | Implement Vulnerability Assessment, Information Assurance, and Security Readiness Review to meet DISA, DIACAP STIG, and NATO STIG compliance. Implement security fixes to address system vulnerability, patch, and penetration scans. | |
| 4.15.5 | Provide system engineering and testing expertise to Operational Test & Evaluation (OT&E) at the designated test facility. | |
| 4.15.6 | Provide system engineering and testing expertise to Development Test & Evaluation (DT&E) at the designated test facility. | |
| 4.15.7 | Provide system engineering to implement Installation Performance Validation Test (IPVT) at designated test facility. | |
| 4.15.8 | Provide technical expertise for system interoperability testing at the designated test facility. | |
| 4.16 | SYSTEM A&A: All software shall conform to the A&A requirements and system security compliance as defined in the Federal Information Security Management Act (FISMA), Department of Defense (DoD) Information Assurance Assessment and Authorization Process (DIACAP), Director of National Intelligence (DNI) Intelligence Community Directive (ICD) 503, National Institute of Standards and Technology (NIST) 800-53 for developing, coordinating, reviewing, and approving Information Technology (IT) and National Security System (NSS) Interoperability and Supportability (I&S), Defense Intelligence Agency’s (DIA) DoD Intelligence Information System (DODIIS) Information Integrators Guide (DIIG) for connecting to DoD and Air Force networks to including Unclassified but Sensitive Internet Protocol Router Network (NIPRNET), Secret Internet Protocol Routing Network (SIPRNET), and Joint Worldwide Intelligence Communication System (JWICS). |
File details come from the government source that posted it. Updated .