Asset_Config_Management_SOW.pdf
PDF 569 KB Posted
- Attached to
- Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
- Solicitation number
- HB0001-18-R-0003
- Issued by
- Department of Defense Cyber Command
About this file
Asset_Config_Management_SOW
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Resume_Template.pdf | ||
| ACS_050515_eform.pdf | ||
| dd2875_(blank).pdf | ||
| SIP_050515_eform.pdf | ||
| SCI_Reporting_Memo.pdf | ||
| Foreign_Travel_Questionnaire.pdf | ||
| CS_050515_eform.pdf | ||
| SSO_Toolkit_SOW.pdf | ||
| SCI_Pre_Screen_Questionaire_DEC_2017.pdf | ||
| USCC_Non-Disclosure_Agreement.pdf | ||
| dd254_SNOW.pdf | ||
| SSO_Toolkit_CONOPS.pdf | ||
| HR_Toolkit_Conops__Task_Management.pdf | ||
| FORM_4414_Rev_12-2013_fillable_(Savable).pdf | ||
| SF312.pdf | ||
| Past_Performance_Template.pdf | ||
| HR_Toolkit_SOW.pdf | ||
| Questionaire_Response_Attachment_20180119.pdf | ||
| 10-SIP_Instructions.pdf | ||
| Religious_Mission_Trip_February_2015.pdf | ||
| HR_Toolkit_Process_Flows_Final.pdf | ||
| US_Cyber_Command_Pre_Screen_Notice_20180308.pdf | ||
| SSO_Automation_Automation_Vision.pdf | ||
| J6_forms.pdf | ||
| ServiceNow_SOW_General_Provisions.pdf | ||
| Language_Immersion_Trip_February_2015.pdf | ||
| SCI_ATTESTATION.pdf |
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRAFT Page 1 of 9 04/02/18
United States Cyber Command 1
ServiceNow Asset Management and 2
Configuration Management 3
Statement of Work 4
DRAFT 5
April 9, 2018 7
DRAFT Page 2 of 9 04/02/18
PAGE INTENTIONAL LEFT BLANK 10
DRAFT Page 3 of 9 04/02/18
Contents 13
1. Introduction .......................................................................................................................................... 3 14
2. Background ........................................................................................................................................... 4 15
3. Scope ..................................................................................................................................................... 4 16
4. Tasks ...................................................................................................................................................... 4 17
5. Section 508 Compliance ........................................................................................................................ 6 18
6. Place of Performance ............................................................................................................................ 6 19
7. Contractor Requirements ..................................................................................................................... 6 20
7.1. Key Staff ............................................................................................................................................ 6 21
7.2. Availability of Staff ............................................................................................................................ 6 22
7.3. Staff Training/Certification ............................................................................................................... 6 23
8. Period of Performance .......................................................................................................................... 7 24
9. Task Order Type .................................................................................................................................... 7 25
10. Security Requirements – Information Security and other miscellaneous requirements ................. 7 26
10.1. Personnel: ..................................................................................................................................... 7 27
10.1.1. Individual Security Clearance: ....................................................................................................... 7 28
10.1.2. System Administrators Security Requirements: ........................................................................... 7 29
11. Travel................................................................................................................................................. 7 30
12. Deliverables:...................................................................................................................................... 7 31
1. Introduction 34
USCYBERCOM plans, coordinates, integrates, synchronizes and conducts activities to: direct the 36 operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; 37 prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable 38 actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our 39 adversaries. 40
The Command has three main focus areas: Defending the DoDIN, providing support to combatant 41 commanders for execution of their missions around the world, and strengthening our nation's ability to 42 withstand and respond to cyber attack. 43
The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, 44 and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate 45
DRAFT Page 4 of 9 04/02/18 resilient, reliable information and communication networks, counter cyberspace threats, and assure 46 access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and 47 certification standards that will enable the Services to build the cyber force required to execute our 48 assigned missions. The command also works closely with interagency and international partners in 49 executing these critical missions. 50
2. Background 52
As part USCYBERCOM’s elevation as a combatant command , USCYBERCOM must implement policies, 53 processes, procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. 54
USCYBERCOM plans to utilize ServiceNow capabilities as a set of tools to become compliant with the 55
CCA through the implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging 56 the ServiceNow Now Platform workflow and task management capabilities to provide automated, data 57 driven applications to support to the internal operations of USCYBERCOM as well as the operational 58 mission needs. 59
3. Scope 60
The scope of this SOW is procure ServiceNow professional consulting services to perform the 61 implementation, configuration, training, operations and maintenance of USCYBERCOM’s ServiceNow’s 62
Asset Management and Configuration Management features. 63
4. Tasks 65
The services the contractor shall provide consists of following: 66
4.1. Project Management 67
The contractor shall provide project management oversight for all tasks under this award. Project 68 management services shall be consistent with the best practices identified by the Project 69
Management Institute. 70
4.2. Out of the Box Functionality 71
4.2.1. The contractor shall utilize out of the box functionality as the preferred implementation 72 approach. The objective of utilizing “out of the box” functionality is to ensure that 73
USCYBERCOM is able to upgrade to future versions of ServiceNow without requiring 74 additional expenses due to customization to migrate to the new versions. 75
4.2.2. Customization Approval: If the contractor proposes a customization, employing other 76 than ServiceNow “out of the box” functionality, the contractor will obtain prior approval 77 from the COR. 78
4.3. ServiceNow architecture, installation and configuration: 79
4.3.1. The contractor shall design the overall architecture of the ServiceNow application within 80 each of the three security enclaves (unclassified, Secret, Top Secret). The hosted locations 81 for these security enclaves will include, but not limited to, AWS GovCloud Unclassified, 82
Secret and Top Secret cloud environments. 83
DRAFT Page 5 of 9 04/02/18
4.3.2. The contractor shall install and configure the ServiceNow listed features to operate within 84 the USCYBERCOM technical environments (Unclassified, Secret and Top Secret). The 85 features to be implemented in accordance with the attached Concept of Operations for IT 86
Service Management. The features to be implemented within the task order are: 87
4.3.2.1. Asset Management 88
4.3.2.2. Configuration Management 89
4.3.2.3. Discovery 90
4.4. Asset Management and Configuration Management Processes: 91
4.4.1. ITIL Process Definition: The contractor shall work with USCYBERCOM to define and 92 customize the ITIL industry best practices related to Asset Management (AM) and 93
Configuration Management (CM) to operate within USCYBERCOM. 94
4.4.2. ITIL Policy Guidance: The contractor shall provide guidance to USCYBERCOM regarding 95 corresponding AM and CM policies that shall support the implementation of AM and CM 96 within USCYBERCOM. 97
4.5. Data Exchange with National Security Administration (NSA) instance of ServiceNow 98
4.5.1. The contractor shall implement the exchange of data between USCYBERCOM’s instance of 99
ServiceNow and NSA’s instance of ServiceNow. 100
4.6. System Security Plan: 101
The contractor shall complete the system security plan (SSP) required for the ServiceNow 102 application to start development and testing within USCYBERCOM technical environment 103
(Interim Approval to Test (IATT)) and an “Authorization To Operate” (ATO). The contractor shall 104 be required to complete a SSP for each security enclave (Unclassified, Secret, Top Secret). The 105 contractor shall be required to coordinate with other directorates and subcontractors within 106
USCYBERCOM to complete the SSP. Further the contractor shall update the SSP as required. 107
The SSP shall be compliant with the National Institutes Standards and Technology (NIST) Risk 108
Management Framework (RMF) and the corresponding NIST Special Publication (800-53) as 109 well as USCYBERCOM specific security controls in obtaining an ATO. 110
4.7. Knowledge Transfer: 111
The contractor shall provide technical and functional knowledge transfer of each configured 112 feature(s) implemented to the USCYBERCOM IT operations and maintenance organization. This 113 knowledge transfer shall consist of both informal and formal methods. Additionally, the 114 contractor shall produce documentation to correspond to the “AS BUILT” configuration of each 115 application to be used by the technical operations and maintenance organization. 116
4.8. End User Training: 117
The contractor shall develop end user training materials for each application prior to going live. 118
This training shall consist primarily of “just-in-time” training, utilizing a self-service training 119 model and a combination of video screen captures and textual materials. 120
4.9. Operations and Maintenance Support: 121
DRAFT Page 6 of 9 04/02/18
The contractor shall provide ongoing operations and maintenance (O&M) support for the 122
ServiceNow installation and configurations within each of the security enclaves implemented 123 within USCYBERCOM. This O&M support shall include maintaining the ServiceNow 124 installations, configurations and support for the AM, CM and Discovery features as well as 125 upgrading the ServiceNow application itself if required. O&M does not include supporting the 126 operating system or functionality below the ServiceNow application layer. 127
5. Section 508 Compliance 128
The contractor shall complete all requirements of this statement of work in accordance with the 129 following Section 508 standards of the Rehabilitation Act of 1973: 130
1194.21 (Software Applications and Operating Systems); 131
1194.22 (Web-based Intranet and Internet Information and Applications); 132
1194.24 (items c, d, and e) (Video and Multimedia Products) ; 133
1194.31 (Functional Performance Criteria); and 134
1194.41 (Information, Documentation, and Support) 135
6. Place of Performance 137
USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755. 138
All work will be performed within USCYBERCOM’s offices in the greater Ft. Meade, Maryland 139 area. 140
7. Contractor Requirements 141
7.1. Key Staff 142
Contractor will propose which staff/labor categories shall be key position. Contractor shall 143 provide written notification of the replacement of any key staff to the CO. Key staff must hold 144 an active Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter 145
Intelligence Polygraph (CI/Poly), TS/SCI with CI/Poly . 146
7.2. Availability of Staff 147
USCYBERCOM intends to award the task order within twenty (20) business days of the RFP 148 submission. Key Staff proposed must be available to start work within five (5) days of task 149 order/delivery order award. Full staffing must be in place within ten (10) days of task order 150 award. 151
7.3. Staff Training/Certification 152
Contractor shall include in their bid the specific certifications of their proposed staff. 153
Representative examples of certifications could include, but not limited to: PMP, Security+, 154
DRAFT Page 7 of 9 04/02/18
ServiceNow, ITIL , Microsoft Certified Professional, Amazon Web Services. Contractor shall 155 submit resumes of the proposed staff using the attached template. 156
8. Period of Performance 158
The period of performance will be five (5) months from task order award. 159
9. Task Order Type 160
This task order will be issued as a Time and Materials award. 161
10. Security Requirements – Information Security and other 162 miscellaneous requirements 163
10.1. Personnel: 164
10.1.1. Individual Security Clearance: 165
All individuals working on this task order must possess an active Top Secret (TS)/ 166
Sensitive Compartmented Information (SCI) with a Counter Intelligence Polygraph (CI 167
Poly), TS/SCI with CI/Poly. 168
10.1.2. System Administrators Security Requirements: 169
staff who may be system administrators or require elevated network or systems access, 170 must comply with DoD 8570.01-M requirements in addition to an active TS/SCI with CI 171 polygraph. 172
11. Travel 173
Local travel will be required, but not reimbursed by the government. Local travel is defined as a 174
50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755. No additional travel is 175 anticipated. 176
12. Deliverables: 177
The following is a list of consolidated deliverables. All deliverables shall be sent softcopy to the 178
Contracting Officer’s Representative (COR). For deliverables that are not documentation, a 179 delivery memo shall be sent to the COR, specifying the deliverable and date delivered. 180
DRAFT Page 8 of 9 04/02/18
Deliverable Number
Deliverable Reference
Deliverable Name Deliverable Format
Government or Contractor Format
Due Date1
1. 4.1 Project Kickoff Meeting/ Kickoff presentation
Contractor 10 days after contract start date
2. 4.1 Communication Plan
MS Word Contractor 15 days after contract start date
3. 4.1 Risk Management Plan
MS Word Contractor 15 days after contract start date
4. 4.1 Issue Management Plan
MS Word Contractor 15 days after contract start date
5. 4.1 Project Schedule
MS Project Contractor 15 days after contract start date, then weekly updates
6. 4.2 ServiceNow Software
Physical Media 5 days after contract start date
7. 4.3 Install and configure baseline ServiceNow software in Unclassified environment
Functioning baseline application
10 days after
USCYBERCOM
provides hosting environment
8. 4.3 Install and configure baseline ServiceNow software in Secret environment
Functioning baseline application
10 days after
USCYBERCOM
provides hosting environment
9. 4.3 Install and configure baseline ServiceNow software in Top Secret environment
Functioning baseline application
10 days after
USCYBERCOM
provides hosting environment
10. 4.4 Asset Management Concept of Operations Document
MS
Word/Visio
Government 35 days after contract start date
DRAFT Page 9 of 9 04/02/18
11. 4.4 Configuration Management Concept of Operations Document
MS
Word/Visio
Government 35 days after contract start date
12. 4.7 Security
CONOPS
MS
Word/Visio
Government 45 days after contract start date
13. 4.7 Configure Management Plan
MS
Word/Visio
Government 45 days after contract start date
14. 4.7 System Security Plan
MS
Word/Visio
Government 75 days after contract start date
15. 4.8 Knowledge Transfer
MS Word or Video format
Contractor NLT 1 one month prior to Initial Operating Capability
16. 4.1 Weekly Activity Report
MS Word Government Wednesday, 5 PM each week
17. 4.1 Monthly Activity Report
MS Word Contractor 3rd workday of each month
1 Due dates are business days
File details come from the government source that posted it.