Statement_of_Objectives_Q_&_A_Feb_2017.pdf
PDF 216 KB Posted
- Attached to
- SBEAS FINAL REQUEST FOR PROPOSAL Federal contract opportunity
- Solicitation number
- FA8771-17-R-1000
About this file
SOO Questions and Answers
View the file
Other files for this federal contract opportunity
Show all 50
SBEAS FINAL REQUEST FOR PROPOSAL has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Objectives Q & A Feb 2017
Question or Comment Answer
Consider TO-based contract types (FFP, T&M, Cost+, etc.) for varying requirements.
The Government has considered all FAR 16 applicable contract types to be determined by a
Contracting Officer at the task order level
Consider whether or not this IDIQ will also support the procurement of hardware and/or software.
This IDIQ will support the procurement of hardware and/or software at the task order level. At that time, the procurement team can utilize available sources to obtain these products (i.e., ODC)
Security layer integration should also include C&A, specifically RMF.
Section 3.1 of the Statement of Objectives has been amended to include the following verbiage:
"Information assurance to include cybersecurity, Risk Management Framework (RMF), continuous monitoring of systems as well as software security and security layer integration"
Systems administration should include Configuration Management.
Section 3.2 of the Statement of Objectives has been amended to include the following verbiage: "
Sustaining, maintaining, and administering systems, applications, databases and interfaces to include system performance monitoring, tuning, provisioning and configuration management "
Recommend adding: "Program Management" to list of activities Section 3.1 of the Statement of Objectives has been amended to include the following verbiage:
"Program management of development activities"
Recommend adding: "Service Oriented Architecture (SOA)" to Information/web services development and testing activities
3.1 of the Statement of Objectives has been amended to include the following verbiage: "
Information/web services development and information/web services testing to include Service-
Oriented Architectures"
Recommend adding: "Database Administration, to include database performance monitoring, tuning, backup and recovery" to the list of activities.
Section 3.2 of the Statement of Objectives has been amended to include the following verbiage:
"Sustaining, maintaining, and administering systems, applications, databases and interfaces to include system performance monitoring, tuning, provisioning and configuration management"
Recommend adding: "System Architecture, including DoDAF artifacts" to the list of activities.
Section 3.1 of the Statement of Objectives has been amended to include the following verbiage:
"Creating and updating system architecture and design documents"
Recommend adding: "Configuration Management, Provisioning and Configuring IT
Infrastructure Dev/Test/Sandbox/Training Environments" to the list of activities Section 3.2 and 3.4 of the SOO encompasses this intent.
Recommend adding: "Certification & Accreditation" to the list of activities
Section 3.1 of the Statement of Objectives has been amended to include the following verbiage: "
Information assurance to include cybersecurity, certification and accreditation, continuous monitoring of systems as well as software security and security layer integration"
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Will the system be required to have interoperability with any current infrastructure build-outs? If required, will the system requirements be outlined per a DoD
Directive per interoperability standards?
Interoperability Requirements will be determined at the task order level.
Consider including requirements for agile development methodologies.
Section 3.1 of the Statement of Objectives has been updated to include agile methodology; however specific requirements will be determined at the task order level
Provide an attachment outlining any third party system monitoring and/or administration tools deployed in the current environment and required to maintain and support current capabilities.
Specific tools and enviorments will be identified at the task order level.
Suggest adding change management support to the requirement Objectives 3.3 and 3.5 encompass change management within IT lifecycle appropriate for this scope
The caption reads "Information Assurance and cybersecurity, including continuous monitoring" - are we to assume "current IA processes as well as RMF"
Cybersecurity is a subset of Information Assurance. They are not synonymous. DoDI 8510.01 states
RMF has replaced DIACAP and RMF is a integrated enterprise-wide decision structure for cybersecurity risk management which seems to include current IA processes.
Can the USAF please differentiate between the development and maintenance tasks listed under Systems Development?
Section 3.1 provides System Development activities, while Section 3.2 provides Systems
Sustainment activities. Specific requirements will be differentiated at the task order levels.
Does the USAF have an approved list of mobile devices for which it anticipates application development?
The DoD's Approved Products List and the AF's approved Products list provide the guidance on allowable network devices. These lists are CAC-restricted and cannot be referenced. A list of approved products may be released on a requirement case-by-case basis at the task order level.
Recommend more detail on current methodologies used by AF (Lean, Agile, or
DoD specific) to ensure contractor has specialized and specific experience
Section 3.1 of the Statement of Objectives has been updated to include Agile, Prototype, Rapid, Dynamic, Lean, Spiral, and Waterfall methodologies. However, the intent of the SOO is to be highlevel. More detail on specific methodologies will be addressed at the task order level.
Need more specificity here: What are the current security requirements contractor must adhere to (ex DIST, NISA, IAT/IAM)?
Specific security requirements will be identified at the task order level. Section 4.1 of the SOO describes the various security levels that can be required under this contract. Additionally Section
6.0 of the SOO provides the various instructions, regulations and standards that may be included at the task order level
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Information assurance and cybersecurity should include RMF.
Section 3.1 of the Statement of Objectives has been amended to include the following verbiage:
"Information assurance to include cybersecurity, Risk Management Framework (RMF), continuous monitoring of systems as well as software security and security layer integration"
Recommend adding: "Program Management" to list of activities Section 3.2 of the Statement of Objectives has been amended to include the following verbiage: "
Program management of Contractor system sustainment activities
Recommend adding: "Configuration Management, Provisioning and Configuring IT
Infrastructure Dev/Test/Sandbox/Training Environment" to the list of activities Section 3.2 and 3.4 of the SOO encompasses this intent.
Recommend adding: "Hardware/Software Refresh" to the list of activities The Government has taken your recommendation under consideration.
Recommend adding: "Certification & Accreditation" to the list of activities
Section 3.2 of the Statement of Objectives has been amended to include the following verbiage: "
Information assurance to include cybersecurity, certification and accreditation, continuous monitoring of systems as well as software security and security layer integration"
Will the program require for example a Life Cycle Sustainment Plan, such as DoD
Instruction 5000.02 that includes design, development, testing and evaluation, fielding and operational planning?
Lifecycle documents will be specified at the Task Order Level
Provide an attachment outlining the technical tools, databases, softwares and hardwares required to maintain and support current capabilities.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
Describe ticket management/help desk software tools deployed in the current environment.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
Suggest adding change management support to the requirement Sections 3.3.and 3.5. of the Statement of Objectives encompass change management within IT
Lifecycle
We understand that this IDIQ contemplates work with both new and existing systems. It would be helpful to provide an appendix listing the current systems that would be eligible for sustainment/enhancement under this IDIQ, as well as their technical characteristics.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
The USAF should consider adding tasks specific to networking and sustainment activities to foster application availability.
There are existing AF contracts to address the networking scope of work: NetOps and Infrastructure
Solutions Full and Open and Small Business contracts. Link:
http://www.netcents.af.mil/Contracts/NETCENTS-2/NetOps/
What is the current architecture the systems are based on? Must have a contractor with specific, deep knowledge and experience.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
What tools does the AF have licensed and use for performance tuning, monitoring and measurement? A background in their use would be beneficial to the AF selecting qualified contractor(s).
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Will this include support for COTS ERP systems such as Oracle EBS financials or
Kronos? If so, it will be critical to list these core systems and the contractor must have practical and recent experience with such.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
Recommend adding: "IT Inventory and Asset Management" The Government does not feel this is within the scope of this contract.
Recommend adding: "Mobile Device Support" to the list of activities Section 3.2 of the Statement of Objectives covers this objective.
Recommend adding: "Field Support" to the list of activities
Section 3.3 of the Statement of Objectives will be amended to include the following verbiage:
"Service desk, field and technical support to include access management, event management, incident management, problem management, and request fulfillment"
Recommend adding: "Technical Support" to the list of activities
Section 3.3 of the Statement of Objectives will be amended to include the following verbiage:
"Service desk, field and technical support to include access management, event management, incident management, problem management, and request fulfillment"
Will IT support services in addition include network security, network administration, data management and recovery, end-user console management and other related activities?
The Government feels this is not within the scope of this contract.
Provide an attachment outlining the technical tools, databases, softwares and hardwares required to maintain and support current capabilities.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
Consider inclusion of any requirements to support asset configuration, installation/deployment and management.
For the scope of this contract, Section 3.2 of the Statement of Objectives includes "... administering systems...to include... provisioning and configuration management" this is the only hardware support in scope of this contract
It would be helpful to elaborate more on what Information Display Services is intended to encompass. It could mean dashboarding, business intelligence, or the
Air Force might have something else in mind.
Section 3.3 of the Statement of Objectives will be amended to include the following verbiage:
"Information Display Services, including but not limited to, mashups, dashboards, portals, and rich internet applications (RIA)"
Computing environments should include hybrid cloud.
Section 3.4 of the Statement of Objectives will be amended to include the following verbiage: "3.
Commercial and Hybrid Cloud environments"
Will the system be out of compliance with AFI 33-200 by using a Commercial
Cloud environments?
Individual task order solicitations will specify the environments for the systems supported.
Cybersecurity requirements and certification & accreditation requirements for individual systems are addressed at the task order level.
Provide an attachment outlining the technical tools, databases, softwares and hardwares required to maintain and support current capabilities.
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
"Mobile" is a device by which can access applications, not a computing environment where applications are hosted, so doesn't make sense in this grouping.
The Government has taken this recommendation under consideration.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Does the USAF have approved commercial cloud environments? Yes, the USAF has approved cloud environments however due to the rapid change in technology, cloud environments may be requested and provided by the procurement teams at the task order level.
Quality processes are needed to demonstrate commitment, ISO:9001 The Government has taken this recommendation under consideration.
Recommend adding ITIL for service deliver requirements since this is an industry standard and is included in many Task Orders as a requirement.
ITIL certifications are achieved by individuals not companies, the government will not require these certifications at the IDIQ level. Task orders will specify as appropriate.
Recommend bidders have at least CMMI Level 3 by the end of the transition period, rather than the base period. The lack of certification well into the base period outs the government at risk.
The Government has taken this recommendation under consideration.
Why not be CMMI Level certified at contract award, not 120 days after base period. This means processes will not be in place to manage the individual TO.
The Government will take this questions/comment under consideration.
Recommend the Government consider CMMI or CMMI Dev Level 3 (minimum) The Government has taken this recommendation under consideration.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
The CMM requirement appears to be an error. Perhaps the certification requirements should say "All contractors shall achieve a minimum of Capability
Maturity Model Integration (CMMI) Services Level 2, or CMMI Development
Level 2 certification 120 days before the end of the base period."?
Section 3.5 of the Statement of Objectives will be amended to include the following verbiage:
"Apply disciplined/best practices for systems engineering process optimizations.
• Each contract holder is required to have at least one of the following certfiications at the time of contract award: International Standard Organization Certifications (ISO) 20000 OR, ISO/IEC 27000
OR CMMI Development Level 2 or higher certification.
• Each contract holder shall have obtained either ISO 20000 OR ISO/IEC 270000 AND CMMI
Development Level 2 or higher certification 120 days prior to the end of the base period.
• All Certifications shall be maintained throughout the life of the contract."
Consider requiring PMP certification from the Program Manager. The Government has taken this recommendation under consideration.
Consider requiring ITIL Expert and Foundations certifications to shape, implement and sustain support activities and processes.
ITIL certifications are achieved by individuals not companies, the government will not require these certifications at the IDIQ level. Task orders will specify as appropriate.
Consider inclusion of performance-based incentives at the TO level. The consideration is more appropriate to address at the Task Order level.
The USAF should consider including ISO 9001, ISO 20000, and ISO 27001 certifications in order to identify companies with dedicated understanding of industry best practices.
The Government has taken this recommendation under consideration.
Contract Transition should be a requirement to be demonstrated, as this is key to many Task orders and critical to maintaining productions systems..
There is no transition or performance taking place at the IDIQ level. These types of terms and conditions shall be addressed at the Task Order level.
Talent Management should be included to include providing metrics on time to fill vacancies, and retention rate. Under staffed programs are negatively impacted with schedule slippage and under bid contracts suffer from high employee turn-over and job dissatisfaction.
The Government has taken this recommendation under consideration.
Section should include Risk and Cost Management, and SME talent to support emerging technology requirements.
Section 3.3 of the Statement of Objectives include the following verbiage: "IT Business analysis and functional area expertise for business process areas"
What is the minimum clearance level needed for the Program Manager?
Clearance requirements and policies shall be addressed at the task order level.
Recommend the government require a PM certification (e.g. PMI) The Government has taken this recommendation under consideration.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Can the USAF please verify that a TS Facility clearance is required and that
TS/SCI work will be supported through the contract.
Facility Clearance requirements will be addressed at the task order level.
Recommend bidders have at least a Secret level and preferably Top Secret level clearance at least by the end of the transition period. This eliminates delays and potential risks if midway through a task order, the requirement for a higher clearance becomes necessary and the offeror doesn't have one. The Government has taken this recommendation under consideration.
Will the contractor be on-ramped to the full and open contract if no longer a small business?
No. The NETCENTS 2 Full and Open contract and the SBEAS contract are not linked, so there is no opportunity to on-ramp from the SBEAS IDIQ to the NETCENTS 2 Full and Open contract.
What if by removing the contractor, the contractor drops below the ceiling when the task order ends. Can they be reinstated if not on the full and open contract?
No. The NETCENTS 2 Full and Open contract and the SBEAS contract are not linked.
Reinstatement to the SBEAS IDIQ is not an option should a contractor fall below the ceiling when the task order ends.
Recommend CMMI Development Level 3 to demonstrate both commitment and the level of maturity required in some Task Orders. Should be obtained PRIOR to award. There has been plenty of lead time on this acquisition and CMMI has been a prevailing requirement in industry for several years.
The Government has taken this recommendation under consideration.
Consider adding information providing potential place(s) of performance, as well as any provisions for providing off-site services and support. Place of Performance shall be considered at the Task Order level.
Consider inclusion of an LCAT structure that provides a list of required labor categories and offers Basic, Senior, Principal and SME levels for each.
The Government has taken this recommendation under consideration. However, this is not something the Government intends to implement under this contract.
Placing costs on contractor for "obtaining/possessing" security clearances would be cost prohibitive. A single security clearance investigation can easily amount to tens of thousands of dollars. Suggest the government amend this requirement.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Describe the potential range of security classification requirements.
Section 4.1 of the Statement of Objectives include the following verbiage: " The ID/IQ will support the following levels of security: Unclassified; Unclassified, But Sensitive; Secret (S); Secret Sensitive
Compartmented Information (S/SCI); Top Secret (TS); and Top Secret Sensitive Compartmented
Information (TS/SCI).
Task orders may require personnel security clearances up to and including Top Secret and may require all employees to be United States citizens. The security clearance requirements will depend on the security level requirements at the task order level. The task orders may also require access to sensitive compartmented information (SCI) for which SCI eligibility will be required. Contractors shall be able to obtain adequate security clearances prior to performing services under the task order.
All contractors located on military installations shall also comply with Operations Security (OPSEC) requirements as set forth in DoD Directive 5205.02, Operations Security Program and AFI 10-701, Operations Security. In accordance with DoD 5200.2-R, Personnel Security Program (Jan 87), DoD military, civilian, consultants and contractor personnel using unclassified automated information systems, including e-mail, shall have, at a minimum, a completed favorable National Agency Check plus Written Inquiries (NACI)."
What is the highest clearance level anticipated on a task order?
The Government is unable to assess the anticipated security requirements at the IDIQ level. All security requirements shall be addressed at the Task Order level
Does the USAF intend to specify a minimum Facilities Clearance Level (FCL) to be awarded SBEAS?
Facility Clearance requirements will be addressed at the task order level.
We recommend the Government does not restrict past performance examples to
541511 NAICS code. Relevant work aligned with the SBEAS scope described in the SOO is being performed by qualified small businesses under other NAICS codes such as 541512, 541712, and 541611.
The Government has not finalized its method of evaluation at this time. This recommendation has been taken under consideration.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
We believe that the Capability Maturity Model Integration (CMMI ) Development
Level 3 should be the minimum CMMI certification. Based on the technical objectives of this SOO and type of work expected under this IDIQ, the government will be much better served with the type of companies that apply processes and best business practices not only at the project level but at organizational level.
Specially since this is an IDIQ and Task management under this vehicle will be a key differentiator for the proposal. We recommend that requirements for the minimum certification Tier 3 to be CMMI Development Level 3.
The Government has taken this recommendation under consideration.
Should include Contract Kick-off presentation, to set clear expectations among all parties.
The Government has taken this recommendation under consideration.
This paragraph provides a website where certifications, specifications, standards, policies and procedures may be found. The URL provided does not work.
The link is not hyperlinked. Please copy and paste into a web browser to access.
The referenced url is not valid - Error 404 Page Not Found:
"http://www.netcents.af.mil/Portals/30/documents/NETCENTS-
2/AppSrvsDocuments/Application%20Services%20Standards%2018%20July%201
6.pdf?ver=2016-09-06-162242-560"
Please retry the link as we do not encounter any issues on our end. Please copy and paste the link into your browser.
Section 4 indicates that the system will require a mobile application development
(Mobile App). Will Mobile Apps be required to meet DISA/NSA DoD Mobility
Program specifications for development, testing, integration and deployment?
Individual task order solicitations will specify the requirements. This is an AF-wide contract, not all capabilities requiring support across the AF are known at this time.
Will other type of capabilities be needed such as incident management reporting and other advanced information assurance DoD practices?
Specific cybersecurity and incident management requirements shall be addressed at the Task Order level.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Contractors are required to comply with AFI 33-200 Air Force Cybersecurity
Program Management, DoDI 8500.01, and all other AF and DoD cybersecurity policies. The Air Force and DoD clearly value the importance of cybersecurity -especially with respect to systems development, systems sustainment, and IT services. Given this, it essential for contractors to demonstrate capability with information security. Contractors should apply industry recognized best practices to cybersecurity much like they apply industry recognized best practices to systems engineering processes (e.g. CMM or CMMI). Would the Government consider valuing contractors who have obtained the industry recognized ISO 27001:
Information Security Management certifications on the SBEAS procurement?
The Government has taken this recommendation under consideration.
Both SOO Sections refer for CMMI Development (DEV); however, CMMI-DEV provides a single, comprehensive framework for organization to assess their development and maintenance process and improve performance. Though the
SBEAS IDIQ will likely have some product development awardees, many of the awardees will be contracting firms that focus on providing services. CMMI for
Services (SVC) provides a comprehensive, integrated set of guidelines for providing superior services. It is recommended that the government consider altering the CMMI Level 2 requirements to include CMMI-SVC Level 2 ratings.
The Government has taken this recommendation under consideration.
The requirement specifies that " Capability Maturity Model (CMM), Capability
Maturity Model Integration (CMMI), or CMMI Development Level 2 certification
(at a minimum)" be obtained 120 days before the end of the base period. Given that this contract is for both Services and Solutions, and given the overlapping nature of the CMMI processes, would the Government consider CMMI Services Level 2 as an alternative to CMMI Development Level 2.
Small Business Enterprise Application Solutions (SBEAS) Statement of Objectives (SOO) Reference # FA8771-17-R-1000
Minimum Requirements Tier 1 should be eliminated in it's entirety for the following reason(s): The purpose if this ID/IQ is to obtain qualified contractors for a wide variety of IT Services. A 'wide variety' by definition may mean certain services are not requested/required in the base period of the contract, and as a result you may be eliminating firms with unique, specialized expertise that may be required in option years. Potentially leaving remaining firms without certain expertise.
The Government has taken this recommendation under consideration.
Would like to see additional clarification regarding recertification, etc. with regards to JVs The Government has taken this recommendation under consideration.
Why not be CMMI Level certified at contract award, not 120 days after base period. This means processes will not be in place to manage the individual TO.
The Government has taken this recommendation under consideration.
Recommend the Government consider CMMI or CMMI Dev Level 3 (minimum) The Government has taken this recommendation under consideration.
In the interest of allowing for the highest level of competition, we suggest section
4.3.3 to read: All contractors shall achieve a minimum of Capability Maturity
Model (CMM), Capability Maturity Model Integration (CMMI), or CMMI
Development Level 2 certification or any ISO 9001:2015 or ISO 27000 certification 120 days before the end of the base period.
Many competitive small businesses are great candidates to be solid contractors on the SBEAS ID/IQ however, budget constraints for small businesses may play a negative role in obtaining costly new certifications if they already possesses other industry standard company certifications, thus limiting the playing field.
ISO 20000 or ISO 27000 are the only ISO certifications the government is considering under this contract.
The CMM requirement appears to be an error. Perhaps the certification requirements should say "All contractors shall achieve a minimum of Capability
Maturity Model Integration (CMMI) Services Level 2, or CMMI Development
Level 2 certification 120 days before the end of the base period."?
The Government has taken this recommendation under consideration.
The acquisition strategy should consider offering a complimentary IV&V task order(s) to provide program oversight, as well as adjudicate engineering and architectural decisions that affect hosting and deployment decisions that best serve the government rather than the vendor's interests.
File details come from the government source that posted it. Updated .