TOS II Exhibit B DIDs.pdf

PDF 4 MB Posted

Attached to
Test Operations and Sustainment (TOS) II Federal contract opportunity
Solicitation number
FA910122RB001
Issued by
Department of the Air Force Materiel Command Test Center

View the file

Other files for this federal contract opportunity

Other files attached to Test Operations and Sustainment (TOS) II, newest first.
File Type Posted
TOS II SF30_FA910122RB001_Amendment 0006.pdf PDF
TOS II Attachment 12 Section L_V2.pdf PDF
TOS II SF33 - FA910122RB001_Part 1 of 2_Pg 1-45_V2.pdf PDF
TOS II SF33 - FA910122RB001_Part 2 of 2_Pg 46-112_V2.pdf PDF
TOS II FRFP Questions and Answers_23JUN23.pdf PDF
TOS II Attachment L_12 SB Participation Template_V1.pdf PDF
TOS II FRFP Questions and Answers_21JUN23.pdf PDF
TOS II SF33 - FA910122RB001_Part 1 of 2_Pg 1-45_V1.pdf PDF
TOS II SF33 - FA910122RB001_Part 2 of 2_Pg 46-112_V1.pdf PDF
TOS II SF30_FA910122RB001_Amendment 0004.pdf PDF
TOS II Attachment 13 Section M_V1.pdf PDF
TOS II FRFP Questions and Answers_15JUN23.pdf PDF
TOS II FRFP Questions and Answers_13JUN23.pdf PDF
TOS II FRFP Questions and Answers_9JUN23.pdf PDF
TOS II SF30_FA910122RB001_Amendment 0003.pdf PDF
TOS II Attachment 7 PWS_V1.pdf PDF
TOS II FRFP Questions and Answers_7JUN23.pdf PDF
TOS II SF30_FA910122RB001_Amendment 0002.pdf PDF
TOS II Attachment L_9.1 Cost Model for Sub_Amended.xlsx XLSX spreadsheet
TOS II SF30_FA910122RB001_Amendment 0001.pdf PDF
TOS II Attachment L_3 PPQ Cover Letter_Amended.pdf PDF
TOS II Attachment 8.1 CAP_ Arnold_NFAC_T9.pdf PDF
TOS II Attachment L_1 PPI Tool.pdf PDF
TOS II Attachment L_2 PPQ.pdf PDF
TOS II Attachment L_3 PPQ Cover Letter.pdf PDF
TOS II Attachment L_5 Subcontractor Consent Letter.pdf PDF
TOS II Attachment 13 Section M.pdf PDF
TOS II FRFP Cover Letter.pdf PDF
TOS II SF33 - FA910122RB001_Part 1 of 2_16MAY23.pdf PDF
TOS II Exhibit A CDRLs.pdf PDF
TOS II Attachment 5 Award Fee Term Plan.pdf PDF
TOS II Attachment 7 PWS.pdf PDF
TOS II Attachment 8 GFP_ Arnold_NFAC_T9.pdf PDF
TOS II Attachment 8.3 CAP_ AVSF_LGTF_NRTF.pdf PDF
TOS II Attachment L_10 Surge Project Sample Task.pdf PDF
TOS II Exhibit C CBAs.pdf PDF
TOS II Attachment 3 SCLS Wage Determinations.pdf PDF
TOS II Attachment 8.2 GFP_ AVSF_LGTF_NRTF.pdf PDF
TOS II Attachment 12 Section L.pdf PDF
TOS II Attachment L_12 SB Participation Template.pdf PDF
TOS II Attachment L_4 Client Authorization Letter.pdf PDF
TOS II Attachment 6 SOO.pdf PDF
TOS II SF33 - FA910122RB001_Part 2 of 2_16MAY23.pdf PDF
TOS II Attachment 1 Workload by WBS.pdf PDF
TOS II Attachment 2 DD254.pdf PDF
TOS II Attachment 4 Construction Wage Determinations.pdf PDF
TOS II Attachment L_6 Relevancy Matrix.pdf PDF
TOS II Attachment L_9 Cost Model for Prime.xlsx XLSX spreadsheet
TOS II Attachment L_9.1 Cost Model for Sub.xlsx XLSX spreadsheet
TOS II Attachment L_11 Surge Project Sample Task Questions.pdf PDF
Show all 50

Test Operations and Sustainment (TOS) II has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

FA9101-22-R-B001

Exhibit B

Data Item Descriptions

Test Operations and Sustainment (TOS) II

16 May 2023

DATA ITEM DESCRIPTION

Title: JOINT SPECIAL ACCESS PROGRAM IMPLEMENTATION GUIDE (JSIG) SYSTEM

AUTHORIZATION PACKAGE (SAP)

Number: DI-ADMN-81969 Approved Date: 20140807 AMSC Number: F9488 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: 20 (AFRL/RYS) Applicable Forms: N/A Use/Relationship: The JSIG SAP is used to identify, control, and authorize a contractor’s proposed stand-alone computer systems and/or networks created and used during the performance of this contract. The contract Information System Security Officer (ISSO) or Information System Security Manager (ISSM) must submit the SAP documentation for a proposed system or network to the Authorizing Official (AO), Delegated Authorizing Official (DAO), or the Program Security Officer (PSO). The AO, DAO, or the PSO must provide written approval of any new information system or network before processing can begin.

a. The SAP describes the methods to: (1) identify systems, security responsibilities and requirements; (2) define overall security standard practice guidance and procedures; (3) identify potential problem areas and determine solutions; and (4) develop security awareness inputs into the overall system security process.

b. This Data Item Description (DID) defines the data required to obtain information systems authorization in accordance with the JSIG. A copy of the JSIG can be obtained from the government program office.

c. This DID contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.

Requirements:

1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices, and revisions, shall be as cited in the ASSIST at the time of the solicitation or contract.

a. Department of Defense (DoD) JSIG

b. DoD JSIG Template Handbook.

c. Government Program Office Guidance.

(Copies of these documents are available from the Government Agency awarding the contract.)

2. Format: The JSIG SAP Documentation shall be presented in Microsoft Word formats outlined by the DoD JSIG, DoD JSIG Template Handbook and the Government Information Assurance Officer (IAO). The initially used format arrangement shall be used for all subsequent submissions.

3. Content: A JSIG system/network authorization package typically consists of:

a. Authorization Package Cover Letter.

DISTRIBUTION STATEMENT A. Approved for public release; distribution is unlimited.

Source: http://assist.dla.mil Downloaded: 2023 04 13T13:52Z

Check the source to verify that this is the current version before use.

DI-ADMN-81969

b. Authorization to Operate (ATO) Letter.

c. Security Assessment Report (SAR).

d. Risk Assessment Report (RAR).

e. System Security Plan (SSP).

f. Security Control Traceability Matrix (SCTM).

g. Plan of Action and Milestones (POA&M).

h. ISSO/ISSM Appointment Letter.

i. ISSO/ISSM 8570 Certification (per DoD 8570.01-M, Information Assurance Workforce Improvement Program).

(Copies of this document are available online at http://www.dtic.mil/whs/directives/index.html.)

j. General User’s Guide (GUG).

k. Privileged User’s Guide (PUG).

l. Software List.

m. Software Approval Forms for High-Risk.

n. Hardware List.

o. Any other supporting documentation required via above documentation (facility accreditation, etc.)

3.1. An SSP will be developed and maintained for each proposed stand-alone system or network.

3.2. If an approved Interagency Standing Operating Procedure (IASOP) exists for previously authorized systems/networks, and will apply to the proposed system/network, submit a copy of the IASOP in addition to the items a through o, above.

3.3. The SAP documentation will be revised when any modifications are made to any portion of the system, network, personnel, or documentation.

3.4. Classification of documentation will be applied in accordance with security classification guides or classification tables. “Distribution Statement F. Further dissemination only as directed by (inserting controlling DoD office) (date of determination) or higher DoD authority.”

applies to this package.

4. End of DI-ADMN-81969.

Source: http://assist.dla.mil Downloaded: 2023 04 13T13:52Z

Title: OPERATIONS SECURITY (OPSEC) PLAN

Number: DI-MGMT-80934C Approval Date: 20101213 AMSC Number: 9178 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Office of Primary Responsibility: NS/I925 Applicable forms: N/A

Use/Relationship: The OPSEC Plan is used to identify and monitor a contractor’s OPSEC activities during the performance of a contract. It is intended to be a living document that will require periodic updates throughout the life of the contract. The OPSEC plan; (1) Describes the OPSEC environment to include identification of critical information, the OPSEC threat and vulnerabilities an adversary might exploit to acquire critical information, (2) Documents the OPSEC risk analysis, (3) Identifies proposed and actual OPSEC measures, (4) Defines and assigns specific OPSEC responsibilities and ties the OPSEC Plan to the contractor’s corporate OPSEC Program, and (5) Serves as a repository of the OPSEC history of the contract.

a. This Data Item Description (DID) contains the format and content preparation instructions for the data product generated by the specific and discrete task requirements delineated in the contract.

b. This DID is applicable only when the contracting activity determines that the sensitivity of the contracted effort warrants OPSEC protections.

c. The contractor’s implementation of the OPSEC Plan, approved by the contracting activity, is subject to joint audit and/or inspection by the Defense Security Service and the contracting activity.

d. This DID supersedes DI-MGMT 80934B.

Requirements:

1. Reference documents: The applicable issue of the documents cited herein, including their approval dates and dates of any applicable amendments, notices and revisions, shall be as specified in the contract.

a. “Applying OPSEC to U.S. Government Acquisitions and Contracts”. This document is available from the Interagency OPSEC Support Staff (IOSS) at the following web address:

www.ioss.gov.

b. Department of Defense Manual (DODM) 5205.02M, DOD Operations Security (OPSEC) Program Manual, dated November 3, 2008.

Source: http://assist.dla.mil Downloaded: 2023 04 13T13:54Z

DI-MGMT-80934C

c. Department of Defense Contract Security Classification Specification (DD 254). This document is included as a part of all Request for Proposals (RFP) and Contracts involving classified data.

d. Contract Data Requirements List (CDRL). This document is included as a part of all RFP and contracts containing data deliverable requirements.

e. National Industrial Security Program Operating Manual (NISPOM) 5220.22M, dated February 28. 2006.

2. Format: The OPSEC Plans shall be submitted in contractor determined format and, at a minimum, consist of the following sections listed in the Content Section below.

3. Content:

3.1 COVER PAGE

The cover page for an OPSEC Plan shall clearly present, at a minimum, the following information:

1. Title of the Acquisition Program

2. Title of the Document (i.e. “Operations Security Plan”)

3. Reference to the government contract number

4. Date of latest revision

5. Name, signature and title of the preparer of the OPSEC Plan

6. Name, signature and title of the approver of the OPSEC Plan.

7. Reference for whom the document was prepared (Contracting activity)

8. Reference by whom the document was prepared (Corporation)

9. All appropriate distribution or classification statements

3.2 TABLE OF CONTENTS PAGE

The Table of Contents for an OPSEC Plan shall outline each section contained in the OPSEC Plan.

3.3 PREFACE PAGE

The purpose of the Preface is to provide a brief, unclassified, overview of the program and the need for OPSEC measures. The specific objectives of the contracted effort shall be introduced with reference to all strategic participants and partnerships required to make the program a success. The anticipated development of any innovative concepts or technologies shall also be introduced in the Preface.

The Preface shall reference all links between the OPSEC Plan and any corporate OPSEC Program(s). The Preface may conclude by referencing requirement documents such as the contract number, Contract Security Classification Specification (DD254), Contract Data

Requirements List (DD1423) and any other pertinent guidance provided by the contracting activity. It shall also provide an OPSEC point of contact, with contact information, for additional guidance or assistance such as the OPSEC program manager or contractor program manager.

3.4 OPSEC PLAN INTRODUCTION

3.4.1 Purpose and Scope: The purpose of the OPSEC Plan shall be effectively communicated in this section and include a description of the scope of the OPSEC Plan (unique physical locations, subcontractors, suppliers, period of performance, etc.).

3.4.2 Authorities: The requirement to protect critical information shall be documented within this section. Documenting the requirement can be achieved by referencing the Corporate OPSEC Program (Policy) and Plan, DODM 5205.-2M, specific contract documents including the DD254 for contracts involving classified data, or other contracting activity specific guidance.

3.4.3 OPSEC Plan Major Activity Timeline: This section shall include a list of all major OPSEC Plan activities such as quarterly OPSEC Working Group Meetings, Annual Assessments, scheduled OPSEC awareness training, Sub-contractor OPSEC Assessments and Surveys, Threat and Vulnerability Reviews, etc. This section shall also include scheduled OPSEC Plan reviews.

3.4.4 Responsibilities: The OPSEC Plan shall identify whom is responsible for the major activities described in the Plan. For example (not intended as an inclusive list):

The OPSEC Manager shall be identified by name and include a list of duties that may include:

1. Coordinate all OPSEC policy responsibilities/ procedures within the program.

2. Revise the Program OPSEC Plan as necessary.

3. Convene and coordinate the annual Program OPSEC Assessment.

4. Disseminate updated threat information to program personnel.

5. Assist in the review of contract requirements for OPSEC considerations.

6. Conduct OPSEC briefing(s) upon customer approval of the plan.

7. Principal advisor to the Contractor Program Manager on all OPSEC matters.

8. Develop/Disseminate Program Critical Information List (CIL).

9. Promote OPSEC awareness within the program.

The Contractor Program Manager shall be identified by name and include a list of duties that may include:

1. Responsible for the overall implementation of the program/contract.

2. Ensure proper OPSEC procedures are implemented by program personnel.

3. Ensure all subcontractors and suppliers supporting the program develop and implement procedures in compliance with the Program OPSEC Plan.

4. Remain cognizant of emerging OPSEC threats and vulnerabilities that may adversely impact upon the success of the program.

5. Actively participate in periodic Program OPSEC assessments.

6. Remain cognizant of any changes in critical information and communicate them to the Program OPSEC Manager.

7. Promote OPSEC awareness within the program.

A short description of the expectations and responsibilities of all program personnel (including subcontractors and suppliers) shall be provided and may typically include:

1. Remain compliant with all applicable OPSEC Plans.

2. Maintain an awareness of all applicable CIL.

3. Attend all OPSEC program briefings.

4. Timely reporting of any OPSEC concerns to the Contractor Program Manager and/or the Program OPSEC Manager.

5. Generation of OPSEC Plans (sub-contractors or suppliers only).

3.4.5 Organizational OPSEC Communications and Interfaces: A description as to how the OPSEC Plan will be communicated to all personnel supporting the program (hardcopy, via a webpage, briefings, etc.).

3.4.5.1 Internal: In this section the OPSEC Plan shall identify all anticipated OPSEC interfaces internal to the corporation such as the senior corporate leadership, corporate OPSEC Working Group, OPSEC coordinators, program personnel, etc.

3.4.5.2 External: In this section the OPSEC Plan shall identify all anticipated external points of contact such as the contracting activity, Defense Contract Management Agency (DCMA), The Defense Security Service (DSS), Federal Bureau of Investigation (FBI) and local law enforcement and their primary role within the OPSEC program (i.e. DCMA audits acquisition management practices, DSS provides security oversight, FBI and law enforcement may provide threat data). Subcontractor and supplier OPSEC points of contact shall be similarly identified.

3.4.6 Marking, Handling and Distribution of Documents: This section shall provide a description of marking, handling, storage, access and transmission authorizations and procedures for any critical information provided to, or generated by, the contractor.

Reference to the program classification guide, Freedom of Information Act and any additional guidance provided by the contracting activity may be cited as applicable.

3.5 THREAT

3.5.1 General Threat: This section shall identify and demonstrate an understanding of the overall threat to program critical information throughout the anticipated duration of the contract/program. For example, an information systems program might note the following:

DSS analysis of 2008 threat data shows, “Information systems, especially C4ISR related systems remained the primary sought-after technology for East Asia and Pacific Region countries. Direct requests (often via the Internet) and other suspicious Internet activity continued to be the preferred method of collection. Information systems are primary targets for Near East adversaries of the United States. Near East commercial entity activity indicates a growing collusion between commercial entities and government associated entities such as universities, public agencies and research and development centers. Adversaries using HUMINT and OSINT collection methods represent a significant threat to program critical information. i

The section shall conclude with a brief description of all identified intelligence collection methods that may be expected to be used by an adversary to acquire critical information.

Note: A general description of intelligence collection methods may be found in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov.

3.5.2 Program Detailed Threat: This section shall be similar to section 3.5.1 above referencing any known direct threats to acquisition specific elements of critical information within the program/contract. As complete a description of each threat as possible shall be provided while maintaining the overall plan classification at the unclassified level. Since detailed threat information may derive from classified sources, reference to source documents as provided by the government contracting activity or other reputable source is permitted.

3.5.3 Threat Analysis: Each threat identified in sections 3.5.1 and 3.5.2 shall be analyzed to determine the level of threat to the corresponding critical information. The results of this analysis shall be presented in this section. A description of the specific threat analysis method used by the contractor to quantify each threat shall be included in this section.

Note: For additional guidance and a sample threat analysis methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.02.

3.5.4 Changes Within Threat Environment: The Threat section shall conclude with a statement that addresses how new threat data is to be received and incorporated into the OPSEC Plan to ensure OPSEC risk remains in compliance with all applicable guidance.

3.6 CRITICAL INFORMATION

3.6.1 General: Critical information shall be identified within this section of the plan and a comprehensive program Critical Information List (CIL) shall be included.

3.6.2 Critical Information List: Guidance on the creation of a CIL is contained within “Applying OPSEC to Government Acquisitions and Contracts,” available at www.ioss.gov, DODM 5205.02M, or may be provided by the contracting activity. Ideally the CIL shall remain unclassified to facilitate wide internal distribution, but may provide reference to classified information as applicable.

3.7 VULNERABILITY

3.7.1 General: The Vulnerability section of the OPSEC Plan shall describe the analysis of activities (indicators) that point to OPSEC vulnerabilities an adversary can exploit to acquire critical information. This section shall contain a list of all identified OPSEC vulnerabilities.

3.7.2 List of OPSEC Vulnerabilities: Each vulnerability shall be described in sufficient detail as to communicate to the contracting activity the extent of the vulnerability. The Vulnerability List shall remain unclassified, but may provide reference to classified information if applicable. Reference to classified reports and other information shall include an unclassified description of the documentation (report title, number, etc.) and the source responsible for publication of the information.

Note: A list of typical OPSEC vulnerabilities which may require OPSEC measures may be found within “Applying OPSEC to Government Acquisitions and Contracts”, available at www.ioss.gov or may be provided by the contracting activity. These sample vulnerabilities are not all inclusive and the submitted vulnerability list shall be tailored to the specific acquisition or contract.

3.7.3 Vulnerability Analysis: Once potential program vulnerabilities have been identified, the magnitude of each vulnerability shall be determined using a consistent methodology identified and documented in this section of the OPSEC Plan. The results of this analysis shall also be described in this section.

Note: For additional guidance and a sample vulnerability methodology see, “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.8 RISK ASSESSMENT

3.8.1 General: The OPSEC risk of a program represents the probability of compromise of critical information and the impact to the program/contract taking into account the threat and vulnerabilities. The acceptable level of OPSEC risk (as determined by senior leadership, or the contracting activity) shall be described in this section in terms consistent with the selected OPSEC methodology.

3.8.2 Risk Assessment: The specific OPSEC risk shall be described in terms consistent with the OPSEC methodology selected for determining OPSEC threat and vulnerability.

The method, and the results of the assessment, shall be presented in this section. The conclusion of the risk assessment shall result in an ordinal ranking of OPSEC risk (highest to lowest).

Note: Additional guidance and a sample risk methodology are available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov and DODM 5205.0-2M.

3.9 OPSEC MEASURES

3.9.1 General: This section of the OPSEC Plan shall identify specific OPSEC

Measures proposed for mitigating OPSEC risk to acceptable levels including the cost to implement each measure. A sampling of common OPSEC measures is available in “Applying OPSEC to Government Acquisitions and Contracts” at www.ioss.gov . This list is not to be considered exhaustive and is provided as guidance for the development of the program/contract specific list of potential OPSEC measures.

3.9.2 Residual Risk: This section shall contain an analysis of residual OPSEC risk, in terms consistent with the OPSEC methodology selected, as a result of implementation of each OPSEC measure presented in section 3.9.1. This section shall identify which OPSEC measures will be implemented and the rationale for those that will not.

3.10 OPSEC Program Chronology: This section shall document significant program OSPEC events throughout the lifecycle of the program. Significant events may include changes to the CIL, changes in program leadership or results of program assessments and surveys (including subcontractors). At a minimum, this section shall include a brief description of the event, date of occurrence, actions taken by the contractor and final disposition. A known compromise of critical information need only be referenced in keeping with the intended classification of this document.

Note: The history contained herein may be used by the government as a part of an OPSEC or security audit conducted by the contracting activity, DSS or other authorized agency.

3.11 ACRONYMS: This section shall include a complete list of acronyms used in the Program OPSEC Plan (i.e., CDRL – Contract Data Requirements List, DID – Data Item Description, etc.).

3.12 REFERENCES: This section shall include a complete list of all references cited in the Program OPSEC Plan (i.e. DoD Manual 5205.02-M, dated November 3, 2008, Contract Number, Corporate OPSEC Plan(s)/Program(s), etc.).

i The specific example provided derives from annual documentation produced by the Defense Security Service, Counterintelligence Office in 2009. Current assessments may be found at https://www.dss.mil/isp/count intell/count intell.html.

4. END OF DI-MGMT-80934C.

Title: DATA ACCESSION LIST (DAL)

Number: DI-MGMT-81453B Approved Date: 20170601 AMSC Number: F9810 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Preparing Activity: 11 (AFLCMC/EZSC) Project No.: MGMT-2017-020 Applicable Forms: N/A

Use/Relationship: The purpose of the Data Accession List (DAL) is to provide a medium for identifying contractor internal data which has been generated by the contractor in compliance with the work effort described in the Statement of Work (SOW). The DAL shall also identify subcontractor/vendor data which has been generated per the Supplier Data Requirements List (SDRL) and the SOW. The DAL is an index of the generated data that is made available upon request for the period of performance of the contract as well as any additional period of time negotiated between the Government and the contractor and cited in the contract. The DAL is not a requirement to deliver all the data listed. The Government can use the list to order data from the list as cited in the contract.

a. This data item description (DID) is not a substitute for standard data requirements that are contractually applied.

b. This DID contains the format, content, and intended use information for the data deliverable resulting from the work task described in the solicitation.

c. This DID supersedes DI-MGMT-81453A.

Requirements:

1. Reference Documents. None.

2. Format. The DAL shall be in the contractor’s format.

3. Content. The DAL shall specify internally generated data and computer software used by the contractor (including subcontractor/vendor data) to develop, test, and manage the program. The format and content of the data listed on the DAL shall be as prepared by the contractor to document compliance with the SOW Task and contract requirements.

3.1 The list shall include the identification number, title which shall describe content, security classification, and in-house release date.

3.2 The list shall also identify the Government Rights to the data using the following codes:

GPR - Government Purpose Rights UR - Unlimited Rights LR - Limited Rights RR - Restricted Rights (computer software only) CLR - Commercial License Rights for commercial technical data CSLR - Commercial Software License Rights for commercial computer software and commercial computer software documentation SNLR - Specifically Negotiated License Rights

DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.

Source: http://assist.dla.mil Downloaded: 2023 01 22T14:50Z

DI-MGMT-81453B

3.3 Once data is listed on the DAL the data shall be made available to the Government as cited in the contract.

End of DI-MGMT-81453B.

Source: http://assist.dla.mil Downloaded: 2023 01 22T14:50Z

Title: Statement of Work (SOW)

Number: DI-MGMT-81606 Approval Date: 15 February 2001 AMSC Number: G7426 Limitation: N/A DTIC Applicable: N/A GIDEP Applicable: No

Office of Primary Responsibility: G/TS-ALS

Applicable Forms: None

Use/relationship:

The Statement of Work (SOW) shall describes the actual work to be performed on an acquisition procurement as specified by the procuring activity. The SOW shall be procured when requiring contractor support to assist with developing DoD acquisition packages.

Requirements:

l. Contract. This data item is generated by the contract which contains a specific and discrete work task to develop this data product.

2. Content. The content of the SOW shall contain information that fullfils the acquiring activities requirements as identified by the Government on the DD Form 1423, Contract Data Requirements List (CDRL).

3. Format. The format for the SOW shall be in contractors format unless otherwise specified by the DD 1423, or the COR.

End of DI-MGMT-81606

Source: http://assist.dla.mil Downloaded: 2023 04 13T13:56Z

Title: Integrated Program Management Data and Analysis Report (IPMDAR)

Number: DI-MGMT-81861C Approval Date: 20210830 AMSC Number: 10265 Limitation: N/A DTIC Applicable: No GIDEP Applicable: No Preparing Activity: OUSD (A&S) ADA Project Number: MGMT-2021-011

APPLICABLE FORMS: N/A

1. USE/RELATIONSHIP:

1.1 The Integrated Program Management Data and Analysis Report (IPMDAR) contains data for measuring contract execution progress on Department of Defense (DoD) acquisition contracts. The IPMDAR's primary purpose to the Government is to reflect current contract performance status and the forecast of future contract performance. This Data Item Description (DID) contains the format, content requirements, and intended use of information for the data deliverable resulting from the work task described in the solicitation.

1.2 The IPMDAR consists of the following three components:

1.2.1 Contract Performance Dataset (CPD). Provides performance/execution data from the contractor’s existing management systems.

1.2.2 Schedule (Comprised of both the Native Schedule File and the Schedule Performance

Dataset (SPD)). Provides data from the contractor’s Integrated Master Schedule (IMS).

1.2.3 Performance Narrative Report (Comprised of both the Executive Summary and the Detailed

Analysis Report). Provides narrative analysis of data provided in the CPD and the Schedule.

1.3 IPMDAR Outline.

1.3.1 Data reported shall reflect all negotiated contract work and include the total scope of Authorized Unpriced Work (AUW) efforts.

1.3.2 Data reported shall reflect the output of the contractor's Earned Value Management System (EVMS).

1.3.3 Data reported in the CPD, Schedule, and Performance Narrative Report shall be as of the same reporting period.

1.4 Direct Reporting Contractor Role.

1.4.1 A Direct Reporting Contractor is any contractor required to provide the IPMDAR directly to the Government. This includes prime contractors, subcontractors, intra-government work agreements, and other agreements, based on the contract type, value, duration, nature of the work scope, and the criticality of the information. In this document, instances of “Contractor” are synonymous with “Direct Reporting Contractor.” 1

1 In the event that the Direct Reporting Contractor is a contractor other than the prime, the Direct Reporting Contractor will additionally report to the prime. Subcontractor data shall be provided to the prime in a manner that supports the contractor’s submission to the Government.

Source: http://assist.dla.mil Downloaded: 2022 06 09T12:13Z

DI-MGMT-81861C

1.5 Data Repository. The Office of the Under Secretary of Defense (OUSD) Acquisition, Data and Analytics (ADA) Integrated Program Management (IPM) Division maintains a secure website, the Earned Value Management Central Repository (EVM-CR)2, for all unclassified, proprietary, and non-proprietary data from programs and contracts that have EVM reporting requirements, regardless of a program’s Acquisition Category (ACAT) designation or a contract’s value. The EVM-CR is housed on an unclassified computer system designed to control sensitive and proprietary contractor data. The system will accept only unclassified data including contracts with EVM data that are marked as Controlled Unclassified Information (CUI) (formerly known as For Official Use Only (FOUO)), Business Sensitive, and/or Proprietary. No classified material shall be provided to the EVM-CR.

Refer to DoD Manual 5200.01 Volume 4 for information regarding designation and marking of Controlled Unclassified Information (CUI).

1.6 Electronic Submission and Files. Refer to the ADA IPM Website and the IPMDAR Implementation Guide for information about electronic data submission format requirements as defined in the File Format Specifications (FFS) and Data Exchange Instructions (DEI).3 The FFS provides clarification for technical requirements of the files themselves and does not supersede data requirements outlined in this document.

1.6.1 The CPD shall be formatted in accordance with the applicable DoD-approved FFS and DEI.4

1.6.1.1 Non-Cumulative Time Phased to Date. This refers to a CPD delivery with time phased historical data from contract award. The Government may request Historical Contract Performance Data in place of the normally provided CPD, typically no more than annually (specific encoding definitions of Historical Contract Performance Data can be found in the FFS and DEI).

1.6.2 The Schedule shall be provided electronically as follows:

1.6.2.1 The Schedule Performance Dataset (SPD) in accordance with the applicable DoD-approved

FFS and DEI.

1.6.2.2 The Native Schedule File consistent with the contractor’s schedule tool (e.g., MPP, XER).

The Data Dictionary shall be included as part of the contractor’s Native Schedule File, or in a human-readable file format (e.g., PDF, XLSX, DOCX), containing searchable text, in accordance with the contractor’s internal system description.

1.6.3 The Performance Narrative Report (Executive Summary and Detailed Analysis) shall be provided electronically in the contractor’s human-readable file structure (e.g., DOCX, PDF), containing searchable text.

1.7 Signatures. The contractor’s program manager or designee shall sign the final Performance Narrative Report or a separate signature page to note the completion of the data submission. This signature confirms the information reported in all of the provided components is authoritative and used by the contractor to manage the program. Electronic signatures are acceptable.

1.7.1 Proprietary Disclosure Statement. A company proprietary disclosure statement is required and shall be provided as part of the Performance Narrative Report submission or separate

2 https://www.acq.osd.mil/evm/ 3 Conversion utilities and tools can be found at: https://www.acq.osd.mil/evm/ 4 https://www.acq.osd.mil/evm/ signature page and shall be notated in the CPD and SPD files. (Refer to CPD FFS 2.2.2 and

SPD FFS 2.2.1)

1.8 Delivery Timing.

1.8.1 Monthly Submission Requirement. IPMDAR data shall be required at least monthly. The reporting frequency shall be specified in the Contract Data Requirements List (CDRL). All reports shall reflect data from the same accounting period and shall be provided at any time after the close of the contractor’s accounting period, but no later than sixteen (16) business days after the contractor’s accounting period end date.

1.8.1.1 Incremental Delivery. Reports may be provided incrementally, including preliminary data, with the number of days for delivery of each submittal tailored in the CDRL. Data delivered is not considered authoritative until the final submission and signature. The recommended incremental delivery process is the Schedule, followed by the CPD and the Executive Summary, Government review of submittals, Government directed Detailed Analysis, Contractor Detailed Analysis delivery and all final data.5

2. DOCUMENT REQUIREMENTS:

2.1 Data Submission. The IPMDAR shall be provided to the ADA EVM-CR. The EVM-CR will only accept unclassified, proprietary, and non-proprietary data from programs and contracts that have EVM reporting requirements, regardless of a program’s Acquisition Category (ACAT) designation or a contract’s value.

2.2 Common Heading Information. This section shall provide information for metadata fields that are common across the datasets. (Refer to CPD FFS 2.2.2 and SPD FFS 2.2.1)

2.2.1 Contractor. Provide the reporting contractor’s name, division (if applicable), facility location, mailing address, and Commercial and Government Entity (CAGE) or Data Universal Numbering System (DUNS) code.

2.2.2 Contract. Provide the contract name (e.g., Low Rate Initial Production (LRIP) Lots 1-4), contract number, contract type, and applicable effort name (e.g., LRIP 1, Contract Line Item Number 1, Task 1). Effort name shall refer to the subdivision of reporting below the contract level.

2.2.3 Program. Provide the program name, or enter the type, model, and series or other military designation of the prime item or items purchased on the contract. The program phase (e.g., development, production) shall also be provided.

2.2.4 Report Period. Identify the current period covered by the reported data.

2.3 Contract Performance Dataset (CPD). This section shall include the following:

2.3.1 Heading Information. This section shall provide information for metadata fields that are resident in the CPD. All values provided in the Heading Information shall be reported in dollars, and shall include the following: (Refer to CPD FFS 2.2.4)

2.3.1.1 Negotiated Contract Cost (NCC). The NCC shall not contain profit or fee, the estimated value of undefinitized change orders (known as AUW), or cost growth (overrun) above the original estimated cost.

5 Reference the IPMDAR Implementation Guide for an example of the incremental delivery timeline.

2.3.1.2 Estimated Cost of AUW. Provide the total dollar value (excluding fee or profit) of the approved work scope associated with AUW. AUW is a contract scope change that is directed by the Government contracting officer, but has not yet been fully negotiated/definitized.

2.3.1.3 Target Fee. Provide the applicable fee that applies to the NCC.

2.3.1.4 Target Price. Provide the target price (NCC plus target fee) applicable to the definitized contract effort.

2.3.1.5 Estimated Price. Provide the estimated final contract price. The estimated price shall be based on the contractor’s Most Likely Estimate at Completion (EAC) for all authorized work, including: the appropriate fee, incentive, and cost sharing provisions.6

2.3.1.6 Contract Ceiling. Provide the contract ceiling price applicable to the definitized effort. This is only applicable to contracts with a ceiling.

2.3.1.7 Estimated Contract Ceiling. Provide the estimated ceiling price applicable to all authorized contractual efforts including both definitized and undefinitized efforts. This is only applicable to contracts with a ceiling.

2.3.1.8 Program Management EACs. These values represent the contractor program manager's EACs which may differ from Performance Measurement Baseline (PMB) EAC provided in

2.3.2.2.4.1 due to risk, opportunities, and other identifiable factors and executive insight.

2.3.1.8.1 Best Case EAC. Provide the contractor program manager’s Best Case EAC, defined as the best case scenario for the estimate of costs to complete all work on the program.

2.3.1.8.2 Worst Case EAC. Provide the contractor program manager’s Worst Case EAC, defined as the worst case scenario for the estimate of costs to complete all work on the program.

2.3.1.8.3 Most Likely EAC. Provide the contractor program manager’s Most Likely EAC, defined as the value that the contractor’s management believes is the most possible outcome based upon the estimate of costs to complete all work on the program.

2.3.1.9 Original NCC. Provide the dollar value (excluding fee) negotiated in the original contract.

2.3.1.10 Contract Budget Base (CBB). Provide the CBB. The CBB shall be defined as the total amount of performance measurement budget that is allocated to contract work and is the sum of 2.2.1.1, NCC, and 2.2.1.2, Estimated Cost of AUW.

2.3.1.11 Total Allocated Budget (TAB). Provide the sum of all budgets allocated to the performance of the contractual effort (includes CBB and any additional performance measurement budget that may have been established if an OTB has been implemented).

2.3.1.12 Contract Start Date. Provide the date the contractor was authorized to start work on the contract, regardless of the date of contract definitization.

2.3.1.13 Contract Definitization Date. Provide the date the contract was originally definitized. If the contract is not definitized, the contract definitization date shall be left blank.

2.3.1.14 Baseline Completion Date (previously known as Planned Completion Date). Provide the completion date for which the budgets allocated in the PMB have been planned. This date represents the planned completion of all efforts on the contract and shall reflect the time to complete the work scope.

6 This number shall reconcile with the estimated price in the Contract Funds Status Report (CFSR), as applicable.

2.3.1.15 Contract Completion Date. Provide the contract completion date in accordance with the latest contract modification.

2.3.1.16 Forecast Completion Date (previously known as Estimated Completion Date). Provide the contractor program manager’s latest forecast completion date. This date represents the projected completion of all effort on the contract, consistent with the Schedule forecast completion date. This date shall be consistent with the Most Likely EAC.

2.3.1.17 Over Target Baseline/Over Target Schedule (OTB/OTS) Date. Provide the first report date that all reprogramming adjustments were fully incorporated in the PMB, if applicable.

2.3.1.18 Calculated Values. The following values are calculated and are not reported separately.

2.3.1.18.1 Negotiated Contract Changes. Provide the total cost (excluding fee) of all definitized contract changes which shall be defined as changes that have occurred since definitization of the original contract and is the difference between 2.2.1.1 (NCC) and 2.2.1.9 (Original

NCC).

2.3.2 Performance Data. The data provided in the CPD shall be reported in both dollars and hours unless tailored in the CDRL.

2.3.2.1 Structures. The following items shall be represented in the CPD structures. These structures are encoded as tables as described in the DEI.

2.3.2.1.1 Work Breakdown Structure (WBS). Provide the contractor’s WBS. (Refer to CPD FFS 2.2.10)

2.3.2.1.2 Organizational Structure. Provide the organizational categories that reflect the contractor’s internal management structure. Organizational categories can reflect different organization types, such as functional or Integrated Product Team (IPT), and can be arranged in a hierarchical structure. (Refer to CPD FFS 2.2.11)

2.3.2.1.3 Control Accounts.

2.3.2.1.3.1 Provide the list of control accounts established at the intersection of the WBS and organizational structure. Control accounts shall be traceable to the WBS and organizational structure, such that each control account is associated with a single WBS element and a single organizational structure element. (Refer to CPD FFS 2.2.12)

2.3.2.1.4 Work Packages. If work package data is required by the CDRL, work packages shall be traceable to the associated control accounts. A work package is the point at which work is planned, progress is measured, and earned value is computed. (Refer to CPD FFS 2.2.15)

2.3.2.1.5 Subcontractors. Efforts being conducted by major subcontractors shall be clearly marked as such in the organizational structure. Subcontractors with an EVM flow down requirement shall be considered major subcontractors. (Refer to CPD FFS 2.2.9)

2.3.2.1.6 Reporting Calendar. Provide the list of reporting periods for which detail data is reported.

The reporting calendar shall span the time-phasing of the entire baseline and forecast.

Accounting period start and end dates and working hours shall be included. (Refer to CPD

FFS 2.2.18)

2.3.2.1.7 Planning Packages. If planning package data is required by the CDRL, it shall be identified separately from work packages in the appropriate structure. A planning package is a logical aggregation of future work within a control account that cannot yet be planned in detail at the work package or task level. (Refer to CPD FFS 2.2.15)

2.3.2.1.8 Summary Level Planning Packages (SLPP). If applicable, identify summary level planning packages separately from control accounts. SLPPs are aggregations of work for far-term efforts that are not yet able to be identified at the control account level, but are traceable to WBS and organizational structure elements. (Refer to CPD FFS 2.2.12)

2.3.2.2 Summary Data. The following items shall be represented in the CPD at a summary level.

2.3.2.2.1 Indirect Costs are costs that cannot be identified specifically against a particular program or activity, and must be controlled and budgeted at a functional or organizational level.

Indirect Costs shall be reported as both cumulative-to-date and time phased non-cumulative-to-complete data. (Refer to CPD FFS 2.2.5, 2.2.7, and 2.2.8)

2.3.2.2.1.1 Cost of Money (COM). Provide summary-level performance data for the Facilities Capital COM allocated to the contract. Indicate “add” or “non-add” status of summary-level values. “Non-add” means detail dollar values include burdening for COM; “add” means detail dollar values do not include burdening for COM.

2.3.2.2.1.2 General and Administrative (G&A). Provide summary-level performance data for the applicable G&A costs. Indicate “add” or “non-add” status of summary-level values. “Non-add” status means detail dollar values include burdening for G&A; “add” status means detail dollar values do not include burdening for G&A.

2.3.2.2.1.3 Overhead (OH). Provide summary-level performance data for the sum of all indirect costs, excluding COM and G&A. Indicate “add” or “non-add” status of summary-level values.

“Non-add” status means detail dollar values include burdening for OH; “add” status means detail dollar values do not include burdening for OH.

2.3.2.2.2 Undistributed Budget (UB). (Refer to CPD FFS 2.2.5)

2.3.2.2.2.1 Provide the amount of budget applicable to contract work scope that has not yet been distributed in the baseline per the contractor’s EVM system description.

2.3.2.2.2.2 Provide the EAC for the scope of work associated with UB.

2.3.2.2.3 Management Reserve (MR). Provide the value of the contractual budget held for management control purposes, risks, and unplanned in-scope effort. (Refer to CPD FFS 2.2.5)

2.3.2.2.4 Summary Cross-Check Data. Non-calculated, hard encoded (manually entered) summed values used as a validation reference for calculated values. (Refer to CPD FFS 2.2.5)

2.3.2.2.4.1 Provide the PMB subtotals for cumulative-to-date values for Budgeted Cost of Work Scheduled (BCWS), Budgeted Cost of Work Performed (BCWP), Actual Cost of Work Performed (ACWP), and Reprogramming Adjustments (Cost Variance, Schedule Variance, and Budget), as well as total values for EAC and Budget at Complete (BAC). The values provided shall be inclusive of the cumulative totals for UB, OH, G&A, and COM. All values shall be provided in both dollars and hours, as appropriate.

2.3.2.3 Detail Data. Detail data shall be comprised of the BCWS, BCWP, ACWP, and Estimate to Complete (ETC), reported by control account unless reporting by work package level is specified in the CDRL. Detail Data shall be identified by Element of Cost (EOC), and shall consist of Labor, Material, Other Direct, and Subcontractor costs. Detail Data is reported as both cumulative-to-date and time-phased-to-complete data.

2.3.2.3.1 Cumulative-To-Date Data. Cumulative-to-date values shall be provided for BCWS, BCWP, and ACWP. (Refer to CPD FFS 2.2.19, 2.2.20, and 2.2.21)

2.3.2.3.2 Time-Phased-To-Complete Data. To-complete data shall be provided for both BCWS and ETC as time-phased non-cumulative values. BCWS values shall be time-phased by reporting period starting with the next consecutive reporting period and continue through the end of the Baseline Completion Date. ETC values shall be time-phased by reporting period starting with the next consecutive reporting period and continuing through the end of the Forecast Completion Date. (Refer to CPD FFS 2.2.22 and 2.2.23)

2.3.2.4 Calculated Values. The following values are calculated.

2.3.2.4.1 Cost Variances. The cost variances are calculated by subtracting ACWP from BCWP values.

2.3.2.4.2 Schedule Variances. The schedule variances are calculated by subtracting BCWS from

BCWP values.

2.3.2.4.3 Budget at Completion (BAC). In addition to the manually entered summary cross check value, the BAC values are calculated by summing the BCWS values.

2.3.2.4.4 Estimate at Completion (EAC). In addition to the manually entered summary cross check value, the EAC values are calculated by summing the ACWP and ETC values.

2.3.2.4.5 Variance at Completion (VAC). The VAC values are calculated by subtracting the EAC from the BAC values.

2.3.2.4.6 Hierarchical Totals. The values associated with the WBS and organizational structure are calculated by summing the data provided at the control account or work package level (if applicable).

2.3.2.5 Contract Performance Over Target Baseline (OTB) and/or Over Target Schedule (OTS) Data Elements. (Refer to CPD FFS 2.2.24)

2.3.2.5.1 Cost Variance Adjustments. If the contractor adjusts or eliminates variances applicable to completed work, the adjustments made to the cost variances shall be provided by control account. Note: adjustments made shall be reported as amounts added to the old variances to reach the new variances (or to eliminate the variances, as applicable).

2.3.2.5.2 Schedule Variance Adjustments. If the contractor adjusts the schedule variances for completed work, the adjustments made to the schedule variances shall be provided by control account. Note: adjustments made shall be reported as amounts added to the old variances to reach the new variances (or to eliminate the variances, as applicable).

2.3.2.5.3 Budget Adjustments. Provide the total amounts added to the budget, consisting of the sum of the budgets used to adjust variances applicable to completed work, plus the additional budget added for remaining work.

2.3.2.5.4 Programming Adjustments. The values provided shall represent cumulative adjustments for all previous and current reprogramming adjustments, in hours or dollars or both. If a reprogramming adjustment has occurred, it must be reported in all future reports.

2.3.2.5.5 Formal Reprogramming Timeliness. Formal reprogramming can require more than one month to implement. During formal reprogramming, reporting shall continue, at a minimum, to include ACWP, and the latest reported cumulative BCWS and BCWP will be maintained until the OTB/OTS is implemented.

2.4 Schedule (Native Schedule File and Schedule Performance Dataset (SPD)). Unless otherwise specified, all items below pertain to both the Native Schedule File and SPD.

2.4.1 Requirements.

2.4.1.1 Content. The Schedule consists of horizontally and vertically integrated discrete tasks/activities, consistent with all authorized work, and relationships necessary for successful contract completion. The Schedule is a single integrated network that also contains significant external interfaces, subcontractor discrete work, Government furnished equipment/ information/property and relationship dependencies for the entire contractual effort.

2.4.1.1.1 Production Contract Schedule. Production contracts utilizing a Manufacturing Requirements Planning (MRP) or an Enterprise Requirements Planning (ERP) system will include a representation of the discrete effort contained in the MRP/ERP in the Production Contract Schedule.

2.4.1.2 External Interfaces. The Schedule shall contain and identify significant external dependencies that involve a relationship or interface with external organizations, including Government-furnished items (e.g., decisions, facilities, equipment, information, and data).

The required and projected delivery dates shall also be identified.

2.4.1.3 Calendars. The Schedule shall contain all calendars that define working and nonworking time periods. (Refer to SPD FFS 2.2.6, 2.2.7, and 2.2.8)

2.4.1.4 Schedule Progress. The schedule shall reflect accurate remaining durations, start dates, and finish dates for all tasks/activities and milestones with respect to the status date. (Refer to

SPD FFS 2.2.10)

2.4.2 Required Content. The following items shall be represented in the Schedule:

2.4.2.1 If a Statement of Work (SOW) or Integrated Master Plan (IMP) are used for vertical schedule integration, those references shall be provided in both the SPD and native schedule. (Refer to SPD FFS 2.2.9)

2.4.2.2 Milestones. Provide zero duration schedule events marking the due date for accomplishment of a specified work scope or objective. Milestone may mark the start, an interim step, or the end of one or more activities. (Refer to SPD FFS 2.2.9)

2.4.2.3 Tasks/Activities. Provide elements of work with duration and logical relationships/dependencies. Task/activity names shall be concise and unique in respect to other names within the Schedule. The name of each task/activity shall clearly reflect the scope, output (e.g., deliverable), and place within the Schedule architecture so that the content can be understood without the subproject task structure, if applicable. (Refer to

SPD FFS 2.2.9)

2.4.2.4 Duration. Provide the length of time estimated, realized, and/or remaining to accomplish a task/activity. (Refer to SPD FFS 2.2.10)

2.4.2.5 Baseline Dates and Information. Provide baseline dates for all items within the PMB. (Refer to SPD FFS 2.2.3 and 2.2.10)

2.4.2.6 Control Account/Work Package Identification. (Refer to SPD FFS 2.2.9)

2.4.2.6.1 Every discrete task/activity, work package, and planning package shall be traceable to a control account.

2.4.2.6.2 Control accounts and, if…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .