HR_Toolkit_SOW.pdf

PDF 585 KB Posted

Attached to
Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
Solicitation number
HB0001-18-R-0003
Issued by
Department of Defense Cyber Command

About this file

HR_Toolkit_SOW

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Architecture (EACOE) Quick Start, newest first.
File Type Posted
SSO_Automation_Automation_Vision.pdf PDF
J6_forms.pdf PDF
ServiceNow_SOW_General_Provisions.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
SCI_ATTESTATION.pdf PDF
SF312.pdf PDF
Past_Performance_Template.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
10-SIP_Instructions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
Asset_Config_Management_SOW.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
USCC_Non-Disclosure_Agreement.pdf PDF
dd254_SNOW.pdf PDF
SSO_Toolkit_CONOPS.pdf PDF
HR_Toolkit_Conops__Task_Management.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
Resume_Template.pdf PDF
ACS_050515_eform.pdf PDF
dd2875_(blank).pdf PDF
SIP_050515_eform.pdf PDF
SCI_Reporting_Memo.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
CS_050515_eform.pdf PDF
SSO_Toolkit_SOW.pdf PDF
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT Page 1 of 10 04/09/18

United States Cyber Command 1

J1 Staff Management Tool Kit 2

Statement of Work 3

DRAFT 4

April 9, 2018 6

DRAFT Page 2 of 10 04/09/18

PAGE INTENTIONAL LEFT BLANK 9

DRAFT Page 3 of 10 04/09/18

Contents 11

1. Introduction .......................................................................................................................................... 3 12

2. Background ........................................................................................................................................... 4 13

3. Scope ..................................................................................................................................................... 4 14

4. Tasks ...................................................................................................................................................... 4 15

5. Section 508 Compliance ........................................................................................................................ 6 16

6. Place of Performance ............................................................................................................................ 6 17

6.1. Development Work location: ............................................................................................................ 7 18

6.2. Implementation Work Location ........................................................................................................ 7 19

6.3. Operations and Maintenance Work Location ................................................................................... 7 20

7. Contractor Requirements ..................................................................................................................... 7 21

7.1. Key Staff ............................................................................................................................................ 7 22

7.2. Availability of Staff ............................................................................................................................ 7 23

7.3. Staff Training/Certification ............................................................................................................... 7 24

8. Period of Performance .......................................................................................................................... 7 25

9. Task Order Type .................................................................................................................................... 7 26

10. Security Requirements – Information Security and other miscellaneous requirements ................. 8 27

10.1. Personnel: ..................................................................................................................................... 8 28

10.1.1. Individual Security Clearance: ....................................................................................................... 8 29

10.1.2. System Administrators Security Requirements: ........................................................................... 8 30

11. Travel................................................................................................................................................. 8 31

12. Deliverables:...................................................................................................................................... 8 32

1. Introduction 35

USCYBERCOM plans, coordinates, integrates, synchronizes and conducts activities to: direct the 37 operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; 38 prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable 39 actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our 40 adversaries. 41

DRAFT Page 4 of 10 04/09/18

The Command has three main focus areas: Defending the DoDIN, providing support to combatant 42 commanders for execution of their missions around the world, and strengthening our nation's ability to 43 withstand and respond to cyber attack. 44

The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, 45 and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate 46 resilient, reliable information and communication networks, counter cyberspace threats, and assure 47 access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and 48 certification standards that will enable the Services to build the cyber force required to execute our 49 assigned missions. The command also works closely with interagency and international partners in 50 executing these critical missions. 51

2. Background 53

As part USCYBERCOM’s elevation as a combatant command , USCYBERCOM must implement policies, 54 processes, procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. 55

USCYBERCOM plans to utilize ServiceNow capabilities as a set of tools to become compliant with the 56

CCA through the implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging 57 the ServiceNow Now Platform workflow and task management capabilities to provide automated, data 58 driven applications to support to the internal operations of USCYBERCOM as well as the operational 59 mission needs. 60

3. Scope 61

The scope of this SOW is procure ServiceNow professional consulting services to perform the 62 implementation, configuration, training, operations and maintenance of USCYBERCOM’s ServiceNow’s 63

Workflow and ServiceNow Now custom application features. 64

4. Tasks 66

The services the contractor shall provide consists of following: 67

4.1. Project Management 68

The contractor shall provide project management oversight for all tasks under this award. Project 69 management services shall be consistent with the best practices identified by the Project 70

Management Institute. 71

4.2. Out of the Box Functionality 72

4.2.1. The contractor shall utilize out of the box functionality as the preferred implementation 73 approach. The objective of utilizing “out of the box” functionality is to ensure that 74

USCYBERCOM is able to upgrade to future versions of ServiceNow without requiring 75 additional expenses due to customization to migrate to the new versions. 76

DRAFT Page 5 of 10 04/09/18

4.2.2. Customization Approval: If the contractor proposes a customization, employing other 77 than ServiceNow “out of the box” functionality, the contractor will obtain prior approval 78 from the COR. 79

4.3. ServiceNow architecture, installation and configuration: 80

4.3.1. The contractor shall design the overall architecture of the ServiceNow application within 81 each of the three security enclaves (unclassified, Secret, Top Secret). The hosted locations 82 for these security enclaves will include, but not limited to, AWS GovCloud Unclassified, 83

Secret and Top Secret cloud environments. 84

4.3.2. The contractor shall install and configure the ServiceNow listed features to operate within 85 the USCYBERCOM technical environments (Unclassified, Secret and Top Secret). The 86 features to be implemented in accordance with the attached Concept of OPERATIONS for 87

US CYBER COMMAND Human Resources Information System (HR Toolkit). The ServiceNow 88 features to be implemented within the task order are: 89

4.3.2.1. ServiceNow Platform 90

4.3.2.2. ServiceNow Now Platform Custom Application 91

4.4. Software Development Management Process utilizing native ServiceNow functionality 92

4.4.1. The vender shall recommend and implement within ServiceNow a development 93 methodology comprised of the following: 94

4.4.1.1. Requirements management: submission and status of all requirements 95

4.4.1.2. Defect management: submission and status of all reported defects 96

4.4.1.3. Change Management: tracking the status of all requirements and defects and 97 whether they are associated with a specific software release they are associated with 98

4.4.1.4. Release Management: cataloguing and tracking each requirement and defect 99 and associating these with a software release 100

4.4.1.5. LifeCycle Status: Tracking the status of each requirement and defect through 101 the software development lifecycle. 102

4.5. HR Toolkit Implementation 103

4.5.1. The vender shall implement an application within ServiceNow that implements the vision 104 and requirements identified within the HR Toolkit document. 105

4.5.2. The contractor shall recommend process improvements that utilize native ServiceNow 106 features to optimize each process to reduce processing time while increasing transparency 107 to leadership. The contractor shall document these business process improvements using 108 standardized business process models such as use cases, business process model and 109 notation (BPMN) or other methods approved by USCYBERCOM. 110

4.6. Post-Implementation Support 111

4.6.1. The contractor shall provide post-implementation support to end-user training, resolve 112 any technical issues and support knowledge transfer to USCYBERCOM support team. 113

4.7. System Security Plan: 114

The contractor shall complete the system security plan (SSP) required for the ServiceNow 115 application to start development and testing within USCYBERCOM technical environment 116

(Interim Approval to Test (IATT)) and to obtain an “Authorization To Operate” (ATO). The 117 contractor shall be required to complete a SSP for each security enclave (Unclassified, Secret, 118

Top Secret). The contractor shall be required to coordinate with other directorates and 119

DRAFT Page 6 of 10 04/09/18 subcontractors within USCYBERCOM to complete the SSP. Further the contractor shall update 120 the SSP as required. The SSP shall be compliant with the National Institutes Standards and 121

Technology (NIST) Risk Management Framework (RMF) and the corresponding NIST Special 122

Publication (800-53) as well as USCYBERCOM specific security controls in obtaining an ATO. 123

4.8. Knowledge Transfer: 124

The contractor shall provide technical and functional knowledge transfer of each configured 125 feature(s) implemented to the USCYBERCOM IT operations and maintenance organization. This 126 knowledge transfer shall consist of both informal and formal methods. Additionally, the 127 contractor shall produce documentation to correspond to the “AS BUILT” configuration of each 128 application to be used by the technical operations and maintenance organization. 129

4.9. End User Training: 130

The contractor shall develop end user training materials for each application prior to going live. 131

This training shall consist primarily of “just-in-time” training, utilizing a self-service training 132 model and a combination of video screen captures and/or textual materials. 133

4.10. Operations and Maintenance Support: 134

The contractor shall provide ongoing operations and maintenance (O&M) support for the 135

ServiceNow installation and configurations within each of the security enclaves implemented 136 within USCYBERCOM. This O&M support shall include maintaining the ServiceNow 137 installations, configurations and support for HR Toolkit application as well as upgrading the 138

ServiceNow application itself if required. O&M does not include supporting the operating 139 system or functionality below the ServiceNow application layer. 140

5. Section 508 Compliance 141

The contractor shall complete all requirements of this statement of work in accordance with the 142 following Section 508 standards of the Rehabilitation Act of 1973: 143

1194.21 (Software Applications and Operating Systems); 144

1194.22 (Web-based Intranet and Internet Information and Applications); 145

1194.24 (items c, d, and e) (Video and Multimedia Products) ; 146

1194.31 (Functional Performance Criteria); and 147

1194.41 (Information, Documentation, and Support) 148

6. Place of Performance 150

USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755. 151

DRAFT Page 7 of 10 04/09/18

6.1. Development Work location: 152

All development activities for the HR Toolkit shall be performed at the contractor site. 153

Contractor’s work location must be within 10 miles of 9800 Savage Road, Ft. Meade, Maryland 154

20755 and have space for meetings with USCYBERCOM staff. Contractor staff shall also be 155 required to periodically attend meetings at USCYBERCOM facilities. Staff working at the 156 contractor’s work location must be a US citizen. 157

6.2. Implementation Work Location 158

The implementation of the HR Toolkit will be at USCYBERCOM’s primary office, noted above. 159

6.3. Operations and Maintenance Work Location 160

The Operations and Maintenance of the HR Toolkit will be at USCYBERCOM’s primary office, 161 noted above. 162

7. Contractor Requirements 163

7.1. Key Staff 164

Contractor will propose which staff/labor categories shall be key position. Contractor shall 165 provide written notification of the replacement of any key staff to the CO. Key staff must hold 166 an active Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter 167

Intelligence Polygraph (CI/Poly), TS/SCI with CI/Poly. 168

7.2. Availability of Staff 169

USCYBERCOM intends to award the task order within twenty (20) business days of the RFP 170 submission. Key Staff proposed must be available to start work within five (5) days of task 171 order/delivery order award. Full staffing must be in place within ten (10) days of task order 172 award. 173

7.3. Staff Training/Certification 174

Contractor shall include in their bid the specific certifications of their proposed staff. 175

Representative examples of certifications could include, but not limited to: PMP, Security+, 176

ServiceNow, ITIL , Microsoft Certified Professional, Amazon Web Services. Contractor shall 177 submit resumes of the proposed staff using the attached template. 178

8. Period of Performance 180

The period of performance will be four (4) months from task order award. 181

9. Task Order Type 182

This task order will be issued as a Time and Materials award. 183

DRAFT Page 8 of 10 04/09/18

10. Security Requirements – Information Security and other 184 miscellaneous requirements 185

10.1. Personnel: 186

10.1.1. Individual Security Clearance: 187

Key staff, operations and maintenance staff, and any staff attending meetings at 188

USCYBERCOM must possess an active TS/SCI with CI/Poly. All other staff supporting this 189 task order must be a US Citizen. 190

10.1.2. System Administrators Security Requirements: 191

Staff who may be system administrators or require elevated network or systems access, 192 must comply with DoD 8570.01-M requirements in addition to an active TS/SCI with CI 193 polygraph. 194

11. Travel 195

Local travel will be required, but not reimbursed by the government. Local travel is defined as a 196

50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755. No additional travel is 197 anticipated. 198

12. Deliverables: 199

The following is a list of consolidated deliverables. All deliverables shall be sent softcopy to the 200

Contracting Officer’s Representative (COR). For deliverables that are not documentation, a 201 delivery memo shall be sent to the COR, specifying the deliverable and date delivered. 202

DRAFT Page 9 of 10 04/09/18

1 Due dates are business days

Deliverable Number

Deliverable Reference

Deliverable Name Deliverable Format

Government or Contractor Format

Due Date1

1. 4.1 Project Kickoff Meeting/ Kickoff presentation

Contractor 10 days after contract start date

2. 4.1 Communications Plan

MS Word Contractor 10 days after contract start date

3. 4.1 Risk Management Plan

MS Word Contractor 10 days after contract start date

4. 4.1 Issue Management Plan

MS Word Contractor 10 days after contract start date

5. 4.1 Project Schedule MS Project Contractor 10 days after contract start date, then weekly updates

6. 4.3 ServiceNow Software

Physical Media

5 days after contract start date

7. 4.3 Install and configure baseline ServiceNow software in Unclassified environment

Functioning baseline application

10 days after USCYBERCOM provides hosting environment

8. 4.6 Configuration Management Concept of Operations Document

MS

Word/Visio

Government 20 days after contract start date

9. 4.5 Implement HR Toolkit

Application 55 days after contract start date

10. 4.5 HR Toolkit Initial Operating Capability (IOC)

Application 65 days after contract start date

11. 4.6 Post Implementation Support

Immediately upon IOC until end of Period of Performance

12. 4.7 Security Concept of Operations Document

MS

Word/Visio

Government 40 days after contract start date

13. 4.7 Configure Management Plan

MS

Word/Visio

Government 40 days after contract start date

14. 4.7 System Security Plan

MS

Word/Visio

Government 50 days after contract start date

DRAFT Page 10 of 10 04/09/18

15. 4.8 Knowledge Transfer

MS Word or Video format

Contractor NLT 1 one month prior to Initial Operating Capability

16. 4.9 End-User Training

MS Word or Video format

Contractor NLT 1 one month prior to Initial Operating Capability

17. 4.1 Weekly Activity Report

MS Word Government Wednesday, 5 PM each week

18. 4.1 Monthly Activity Report

MS Word Contractor 3rd workday of each month

File details come from the government source that posted it.