Asset_Config_Management_SOW.pdf

PDF 569 KB Posted

Attached to
Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
Solicitation number
HB0001-18-R-0003
Issued by
Department of Defense Cyber Command

About this file

Asset_Config_Management_SOW

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Architecture (EACOE) Quick Start, newest first.
File Type Posted
Resume_Template.pdf PDF
ACS_050515_eform.pdf PDF
dd2875_(blank).pdf PDF
SIP_050515_eform.pdf PDF
SCI_Reporting_Memo.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
CS_050515_eform.pdf PDF
SSO_Toolkit_SOW.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
USCC_Non-Disclosure_Agreement.pdf PDF
dd254_SNOW.pdf PDF
SSO_Toolkit_CONOPS.pdf PDF
HR_Toolkit_Conops__Task_Management.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
SF312.pdf PDF
Past_Performance_Template.pdf PDF
HR_Toolkit_SOW.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
10-SIP_Instructions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
SSO_Automation_Automation_Vision.pdf PDF
J6_forms.pdf PDF
ServiceNow_SOW_General_Provisions.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
SCI_ATTESTATION.pdf PDF
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT Page 1 of 9 04/02/18

United States Cyber Command 1

ServiceNow Asset Management and 2

Configuration Management 3

Statement of Work 4

DRAFT 5

April 9, 2018 7

DRAFT Page 2 of 9 04/02/18

PAGE INTENTIONAL LEFT BLANK 10

DRAFT Page 3 of 9 04/02/18

Contents 13

1. Introduction .......................................................................................................................................... 3 14

2. Background ........................................................................................................................................... 4 15

3. Scope ..................................................................................................................................................... 4 16

4. Tasks ...................................................................................................................................................... 4 17

5. Section 508 Compliance ........................................................................................................................ 6 18

6. Place of Performance ............................................................................................................................ 6 19

7. Contractor Requirements ..................................................................................................................... 6 20

7.1. Key Staff ............................................................................................................................................ 6 21

7.2. Availability of Staff ............................................................................................................................ 6 22

7.3. Staff Training/Certification ............................................................................................................... 6 23

8. Period of Performance .......................................................................................................................... 7 24

9. Task Order Type .................................................................................................................................... 7 25

10. Security Requirements – Information Security and other miscellaneous requirements ................. 7 26

10.1. Personnel: ..................................................................................................................................... 7 27

10.1.1. Individual Security Clearance: ....................................................................................................... 7 28

10.1.2. System Administrators Security Requirements: ........................................................................... 7 29

11. Travel................................................................................................................................................. 7 30

12. Deliverables:...................................................................................................................................... 7 31

1. Introduction 34

USCYBERCOM plans, coordinates, integrates, synchronizes and conducts activities to: direct the 36 operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; 37 prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable 38 actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our 39 adversaries. 40

The Command has three main focus areas: Defending the DoDIN, providing support to combatant 41 commanders for execution of their missions around the world, and strengthening our nation's ability to 42 withstand and respond to cyber attack. 43

The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, 44 and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate 45

DRAFT Page 4 of 9 04/02/18 resilient, reliable information and communication networks, counter cyberspace threats, and assure 46 access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and 47 certification standards that will enable the Services to build the cyber force required to execute our 48 assigned missions. The command also works closely with interagency and international partners in 49 executing these critical missions. 50

2. Background 52

As part USCYBERCOM’s elevation as a combatant command , USCYBERCOM must implement policies, 53 processes, procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. 54

USCYBERCOM plans to utilize ServiceNow capabilities as a set of tools to become compliant with the 55

CCA through the implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging 56 the ServiceNow Now Platform workflow and task management capabilities to provide automated, data 57 driven applications to support to the internal operations of USCYBERCOM as well as the operational 58 mission needs. 59

3. Scope 60

The scope of this SOW is procure ServiceNow professional consulting services to perform the 61 implementation, configuration, training, operations and maintenance of USCYBERCOM’s ServiceNow’s 62

Asset Management and Configuration Management features. 63

4. Tasks 65

The services the contractor shall provide consists of following: 66

4.1. Project Management 67

The contractor shall provide project management oversight for all tasks under this award. Project 68 management services shall be consistent with the best practices identified by the Project 69

Management Institute. 70

4.2. Out of the Box Functionality 71

4.2.1. The contractor shall utilize out of the box functionality as the preferred implementation 72 approach. The objective of utilizing “out of the box” functionality is to ensure that 73

USCYBERCOM is able to upgrade to future versions of ServiceNow without requiring 74 additional expenses due to customization to migrate to the new versions. 75

4.2.2. Customization Approval: If the contractor proposes a customization, employing other 76 than ServiceNow “out of the box” functionality, the contractor will obtain prior approval 77 from the COR. 78

4.3. ServiceNow architecture, installation and configuration: 79

4.3.1. The contractor shall design the overall architecture of the ServiceNow application within 80 each of the three security enclaves (unclassified, Secret, Top Secret). The hosted locations 81 for these security enclaves will include, but not limited to, AWS GovCloud Unclassified, 82

Secret and Top Secret cloud environments. 83

DRAFT Page 5 of 9 04/02/18

4.3.2. The contractor shall install and configure the ServiceNow listed features to operate within 84 the USCYBERCOM technical environments (Unclassified, Secret and Top Secret). The 85 features to be implemented in accordance with the attached Concept of Operations for IT 86

Service Management. The features to be implemented within the task order are: 87

4.3.2.1. Asset Management 88

4.3.2.2. Configuration Management 89

4.3.2.3. Discovery 90

4.4. Asset Management and Configuration Management Processes: 91

4.4.1. ITIL Process Definition: The contractor shall work with USCYBERCOM to define and 92 customize the ITIL industry best practices related to Asset Management (AM) and 93

Configuration Management (CM) to operate within USCYBERCOM. 94

4.4.2. ITIL Policy Guidance: The contractor shall provide guidance to USCYBERCOM regarding 95 corresponding AM and CM policies that shall support the implementation of AM and CM 96 within USCYBERCOM. 97

4.5. Data Exchange with National Security Administration (NSA) instance of ServiceNow 98

4.5.1. The contractor shall implement the exchange of data between USCYBERCOM’s instance of 99

ServiceNow and NSA’s instance of ServiceNow. 100

4.6. System Security Plan: 101

The contractor shall complete the system security plan (SSP) required for the ServiceNow 102 application to start development and testing within USCYBERCOM technical environment 103

(Interim Approval to Test (IATT)) and an “Authorization To Operate” (ATO). The contractor shall 104 be required to complete a SSP for each security enclave (Unclassified, Secret, Top Secret). The 105 contractor shall be required to coordinate with other directorates and subcontractors within 106

USCYBERCOM to complete the SSP. Further the contractor shall update the SSP as required. 107

The SSP shall be compliant with the National Institutes Standards and Technology (NIST) Risk 108

Management Framework (RMF) and the corresponding NIST Special Publication (800-53) as 109 well as USCYBERCOM specific security controls in obtaining an ATO. 110

4.7. Knowledge Transfer: 111

The contractor shall provide technical and functional knowledge transfer of each configured 112 feature(s) implemented to the USCYBERCOM IT operations and maintenance organization. This 113 knowledge transfer shall consist of both informal and formal methods. Additionally, the 114 contractor shall produce documentation to correspond to the “AS BUILT” configuration of each 115 application to be used by the technical operations and maintenance organization. 116

4.8. End User Training: 117

The contractor shall develop end user training materials for each application prior to going live. 118

This training shall consist primarily of “just-in-time” training, utilizing a self-service training 119 model and a combination of video screen captures and textual materials. 120

4.9. Operations and Maintenance Support: 121

DRAFT Page 6 of 9 04/02/18

The contractor shall provide ongoing operations and maintenance (O&M) support for the 122

ServiceNow installation and configurations within each of the security enclaves implemented 123 within USCYBERCOM. This O&M support shall include maintaining the ServiceNow 124 installations, configurations and support for the AM, CM and Discovery features as well as 125 upgrading the ServiceNow application itself if required. O&M does not include supporting the 126 operating system or functionality below the ServiceNow application layer. 127

5. Section 508 Compliance 128

The contractor shall complete all requirements of this statement of work in accordance with the 129 following Section 508 standards of the Rehabilitation Act of 1973: 130

1194.21 (Software Applications and Operating Systems); 131

1194.22 (Web-based Intranet and Internet Information and Applications); 132

1194.24 (items c, d, and e) (Video and Multimedia Products) ; 133

1194.31 (Functional Performance Criteria); and 134

1194.41 (Information, Documentation, and Support) 135

6. Place of Performance 137

USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755. 138

All work will be performed within USCYBERCOM’s offices in the greater Ft. Meade, Maryland 139 area. 140

7. Contractor Requirements 141

7.1. Key Staff 142

Contractor will propose which staff/labor categories shall be key position. Contractor shall 143 provide written notification of the replacement of any key staff to the CO. Key staff must hold 144 an active Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter 145

Intelligence Polygraph (CI/Poly), TS/SCI with CI/Poly . 146

7.2. Availability of Staff 147

USCYBERCOM intends to award the task order within twenty (20) business days of the RFP 148 submission. Key Staff proposed must be available to start work within five (5) days of task 149 order/delivery order award. Full staffing must be in place within ten (10) days of task order 150 award. 151

7.3. Staff Training/Certification 152

Contractor shall include in their bid the specific certifications of their proposed staff. 153

Representative examples of certifications could include, but not limited to: PMP, Security+, 154

DRAFT Page 7 of 9 04/02/18

ServiceNow, ITIL , Microsoft Certified Professional, Amazon Web Services. Contractor shall 155 submit resumes of the proposed staff using the attached template. 156

8. Period of Performance 158

The period of performance will be five (5) months from task order award. 159

9. Task Order Type 160

This task order will be issued as a Time and Materials award. 161

10. Security Requirements – Information Security and other 162 miscellaneous requirements 163

10.1. Personnel: 164

10.1.1. Individual Security Clearance: 165

All individuals working on this task order must possess an active Top Secret (TS)/ 166

Sensitive Compartmented Information (SCI) with a Counter Intelligence Polygraph (CI 167

Poly), TS/SCI with CI/Poly. 168

10.1.2. System Administrators Security Requirements: 169

staff who may be system administrators or require elevated network or systems access, 170 must comply with DoD 8570.01-M requirements in addition to an active TS/SCI with CI 171 polygraph. 172

11. Travel 173

Local travel will be required, but not reimbursed by the government. Local travel is defined as a 174

50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755. No additional travel is 175 anticipated. 176

12. Deliverables: 177

The following is a list of consolidated deliverables. All deliverables shall be sent softcopy to the 178

Contracting Officer’s Representative (COR). For deliverables that are not documentation, a 179 delivery memo shall be sent to the COR, specifying the deliverable and date delivered. 180

DRAFT Page 8 of 9 04/02/18

Deliverable Number

Deliverable Reference

Deliverable Name Deliverable Format

Government or Contractor Format

Due Date1

1. 4.1 Project Kickoff Meeting/ Kickoff presentation

Contractor 10 days after contract start date

2. 4.1 Communication Plan

MS Word Contractor 15 days after contract start date

3. 4.1 Risk Management Plan

MS Word Contractor 15 days after contract start date

4. 4.1 Issue Management Plan

MS Word Contractor 15 days after contract start date

5. 4.1 Project Schedule

MS Project Contractor 15 days after contract start date, then weekly updates

6. 4.2 ServiceNow Software

Physical Media 5 days after contract start date

7. 4.3 Install and configure baseline ServiceNow software in Unclassified environment

Functioning baseline application

10 days after

USCYBERCOM

provides hosting environment

8. 4.3 Install and configure baseline ServiceNow software in Secret environment

Functioning baseline application

10 days after

USCYBERCOM

provides hosting environment

9. 4.3 Install and configure baseline ServiceNow software in Top Secret environment

Functioning baseline application

10 days after

USCYBERCOM

provides hosting environment

10. 4.4 Asset Management Concept of Operations Document

MS

Word/Visio

Government 35 days after contract start date

DRAFT Page 9 of 9 04/02/18

11. 4.4 Configuration Management Concept of Operations Document

MS

Word/Visio

Government 35 days after contract start date

12. 4.7 Security

CONOPS

MS

Word/Visio

Government 45 days after contract start date

13. 4.7 Configure Management Plan

MS

Word/Visio

Government 45 days after contract start date

14. 4.7 System Security Plan

MS

Word/Visio

Government 75 days after contract start date

15. 4.8 Knowledge Transfer

MS Word or Video format

Contractor NLT 1 one month prior to Initial Operating Capability

16. 4.1 Weekly Activity Report

MS Word Government Wednesday, 5 PM each week

17. 4.1 Monthly Activity Report

MS Word Contractor 3rd workday of each month

1 Due dates are business days

File details come from the government source that posted it.