ServiceNow_SOW_General_Provisions.pdf
PDF 620 KB Posted
- Attached to
- Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
- Solicitation number
- HB0001-18-R-0003
- Issued by
- Department of Defense Cyber Command
About this file
ServiceNow_SOW_General_Provisions
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SSO_Automation_Automation_Vision.pdf | ||
| J6_forms.pdf | ||
| Language_Immersion_Trip_February_2015.pdf | ||
| SCI_ATTESTATION.pdf | ||
| SCI_Pre_Screen_Questionaire_DEC_2017.pdf | ||
| USCC_Non-Disclosure_Agreement.pdf | ||
| dd254_SNOW.pdf | ||
| SSO_Toolkit_CONOPS.pdf | ||
| HR_Toolkit_Conops__Task_Management.pdf | ||
| FORM_4414_Rev_12-2013_fillable_(Savable).pdf | ||
| SF312.pdf | ||
| Past_Performance_Template.pdf | ||
| HR_Toolkit_SOW.pdf | ||
| Questionaire_Response_Attachment_20180119.pdf | ||
| 10-SIP_Instructions.pdf | ||
| Religious_Mission_Trip_February_2015.pdf | ||
| HR_Toolkit_Process_Flows_Final.pdf | ||
| Asset_Config_Management_SOW.pdf | ||
| US_Cyber_Command_Pre_Screen_Notice_20180308.pdf | ||
| Resume_Template.pdf | ||
| ACS_050515_eform.pdf | ||
| dd2875_(blank).pdf | ||
| SIP_050515_eform.pdf | ||
| SCI_Reporting_Memo.pdf | ||
| Foreign_Travel_Questionnaire.pdf | ||
| CS_050515_eform.pdf | ||
| SSO_Toolkit_SOW.pdf |
Show all 27
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRAFT Page 1 of 14 04/09/18
United States Cyber Command 1
ServiceNow Statement of Work 2
Common Provisions for all Task Orders 3
DRAFT 4
April 9, 2018 6
DRAFT Page 2 of 14 04/09/18
THIS PAGE INTENTIONAL LEFT BLANK 9
DRAFT Page 3 of 14 04/09/18
Contents 11
1. Introduction .......................................................................................................................................... 3 12
2. Background ........................................................................................................................................... 4 13
3. Scope ..................................................................................................................................................... 4 14
4. Labor Categories ................................................................................................................................... 4 15
5. Section 508 Compliance ........................................................................................................................ 8 16
6. Place of Performance ............................................................................................................................ 9 17
7. Vendor Requirements ........................................................................................................................... 9 18
7.1. ServiceNow Expertise........................................................................................................................ 9 19
7.2. United States Owned Company or Subsidiary .................................................................................. 9 20
7.3. Key Staff ............................................................................................................................................ 9 21
7.4. Availability of Staff ............................................................................................................................ 9 22
7.5. Staff Training/Certification ............................................................................................................... 9 23
8. Period of Performance .......................................................................................................................... 9 24
9. Contract Type ...................................................................................................................................... 10 25
10. Security Requirements – Information Security and other miscellaneous requirements ............... 10 26
11. Government Furnished Equipment ................................................................................................ 12 27
12. Travel............................................................................................................................................... 12 28
13. Supply Chain Risk Management (SCRM) ......................................................................................... 12 29
1. Introduction 32
USCYBERCOM plans, coordinates, integrates, synchronizes and conducts activities to: direct the 34 operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; 35 prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable 36 actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our 37 adversaries. 38
The Command has three main focus areas: Defending the DoDIN, providing support to combatant 39 commanders for execution of their missions around the world, and strengthening our nation's ability to 40 withstand and respond to cyber attack. 41
The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, 42 and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate 43
DRAFT Page 4 of 14 04/09/18 resilient, reliable information and communication networks, counter cyberspace threats, and assure 44 access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and 45 certification standards that will enable the Services to build the cyber force required to execute our 46 assigned missions. The command also works closely with interagency and international partners in 47 executing these critical missions. 48
2. Background 50
As part of this elevation to a combatant command, USCYBERCOM must implement policies, processes, 51 procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. USCYBERCOM plans to 52 utilize ServiceNow capabilities as a set of tools to become compliant with the CCA through the 53 implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging the ServiceNow 54
Now Platform workflow and task management capabilities to provide automated, data driven 55 applications to support to the internal operations of USCYBERCOM as well as the operational mission 56 needs. 57
3. Scope 58
The scope of this document is provide guidance that applies to all Contract Line Items (CLINS)/ Orders 59 issued under this contract. 60
4. Labor Categories 62
USCYBERCOM recognizes that a successful implementation of ServiceNow will require a range of skills 63 and expertise provided by the vendor’s staff. USCBYERCOM has identified the required skills and 64 corresponding experience levels of these skills in the section below. Below the table, is a clarification of 65 the required skills and other qualifications associated with each USCYBERCOM ServiceNow Labor 66
Category. The vendor will identify the proposed labor category from their GSA IT Schedule 70 for each of 67 these USCYBERCOM defined Labor Categories. 68
USCYBERCOM ServiceNow Labor Category Vendor Proposed Labor Category
Information Systems Security Engineer
ServiceNow Subject Matter Expert
ServiceNow Developer – Senior
ServiceNow Developer – Mid
ServiceNow Developer – Junior
Business Analyst – Senior
Business Analyst - Mid
DRAFT Page 5 of 14 04/09/18
4.1. Information Systems Security Engineer (ISSE): 71
The ISSE will be responsible for leading and writing documentation in support of the ServiceNow 72 installation and any custom applications obtaining an Authorization To Operate (ATO). Key skills the 73
ISSE must possess at time of starting the project: 74
a) DoD 8570-M certification (IASAE Level II) 75
b) Minimum ten (10) years IT experience 76
c) Experience designing, documenting and implementing a wide range of security controls in an 77
AWS Cloud environment. 78
d) Experience writing documentation in support of obtaining an ATO implementing NIST Special 79
Publication 800-53 and 800-37 80
e) Familiarization/experience with XACTA 81
f) Strong written, analytical and oral communication skills 82
g) Active TS/SCI with CI/Poly 83
4.2. ServiceNow Subject Matter Expert (SME): 85
The ServiceNow SME sets the strategic direction for the implementation of ServiceNow within 86
USCYBERCOM across all three security domains (unclassified, secret and top secret) defining and 87 implementing an architecture that supports USCYBERCOM’s objectives. The SME is the expert on the 88 functionality within ServiceNow and recommends best practices to USCYBERCOM associated with the 89 implementation of each ServiceNow feature. Key skills the SME must possess at time of starting the 90 project: 91
a) Minimum ten (10) years IT experience 92
b) Minimum of eight (8) successful ServiceNow deployments of ITSM, four (4) of which are to US 93 Government agencies 94
c) Experience in implementing large-scale custom development and/or systems integration 95 projects in one or more phases of the SDLC 96
d) Experience working with business users to gather requirements, writing functional and technical 97 specifications and communicating technical requirements 98
e) Administering and developing within ServiceNow 99
f) Ability to create and configure forms and screen updates using ServiceNow and/or Java 100
g) Ability to create, update and maintain JavaScript, AngularJS 101
h) Experience with identity and access management, including use of MS Active Directory and 102
LDAP 103
i) Advanced experience in ServiceNow Deployment API’s 104
j) Minimum of three (3) implementations of ServiceNow in an AWS Cloud environment 105
k) ITIL Certification 106
l) Minimum two (2) ServiceNow certifications 107
4.3. ServiceNow Developer – Senior 109
DRAFT Page 6 of 14 04/09/18
The ServiceNow Developer – Senior will lead the development team as they implement ServiceNow 110 features in conjunction with the ServiceNow SME. The ServiceNow Developer – Senior is responsible for 111 the successful deployment of ServiceNow within USCYBERCOM. The ServiceNow Developer – Senior is 112 responsible for application user interface configuration and development, workflow configuration, 113 development of USCYBERCOM specific applications, and integration with other USCYBERCOM 114 applications. ServiceNow Developer – Senior is the primary technical interface to the USCYBERCOM 115 project manager and/or Contract Officer’s Representative (COR). Key skills the ServiceNow Developer – 116
Senior must possess at time of starting the project: 117
a) Minimum ten (10) years IT experience 118
b) Minimum of eight (8) successful ServiceNow deployments, including ITSM and building user 119 applications using ServiceNow, four (4) of which are to US Government agencies 120
c) Knowledge of ServiceNow database hierarchies and design 121
d) Administering and developing within ServiceNow 122
e) Ability to create and configure forms and screen updates using ServiceNow and/or AngularJS, 123
JavaScript, Jelly, .NET 124
f) Experience with identity and access management, including use of MS Active Directory and 125
LDAP 126
g) Ability to create, update and maintain JavaScript 127
h) Advanced experience in ServiceNow Deployment API’s 128
i) Minimum of four (4) years experience developing using Java, Java Script, AngularJS or .Net 129 experience 130
j) Minimum of two (2) years experience implementing ServiceNow in an AWS Cloud environment 131
k) Strong technical writing skills 132
l) Business Analysis skills, to convert business users’ needs to technical requirements 133
m) Minimum two (2) ServiceNow certifications 134
n) Minimum one (1) Amazon Web Services certification 135
DRAFT Page 7 of 14 04/09/18
4.4. ServiceNow Developer – Mid 138
The ServiceNow Developer – Mid will participate as a member of the development team as they 139 implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior. 140
The ServiceNow Developer – Mid is responsible for application user interface configuration and 141 development, workflow configuration, development of USCYBERCOM specific applications, and 142 integration with other USCYBERCOM applications. Key skills the ServiceNow Developer – Mid must 143 possess at time of starting the project: 144
a) Minimum of four (4) years experience developing applications 145
b) Minimum of three (3) successful ServiceNow deployments, including ITSM and building user 146 applications using ServiceNow. 147
c) Knowledge of ServiceNow database hierarchies and design 148
d) Administering and developing within ServiceNow 149
e) Ability to create and configure forms and screen updates using ServiceNow and/or Java 150
f) Ability to create, update and maintain JavaScript 151
g) Advanced experience in ServiceNow Deployment API’s 152
h) Minimum of two (2) years experience developing using Java, Java Script, AngularJS or .Net 153 experience 154
i) Minimum of two (2) years experience implementing ServiceNow in an AWS Cloud environment 155
j) Strong technical writing skills 156
k) Business Analysis skills, to convert business users needs to technical requirements 157
l) Minimum one (1) ServiceNow certifications 158
m) Minimum one (1) Amazon Web Services certification 159
4.5. ServiceNow Developer – Junior 161
The ServiceNow Developer – Junior will participate as a member of the development team as they 162 implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior. 163
The ServiceNow Developer – Junior is responsible for application user interface configuration and 164 development, workflow configuration, development of USCYBERCOM specific applications, and 165 integration with other USCYBERCOM applications. Key skills the ServiceNow Developer – Junior must 166 possess at time of starting the project: 167
a) Minimum of two (2) years experience developing and/or implementing ServiceNow 168
b) Administering and developing within ServiceNow 169
c) Ability to create and configure forms and screen updates using ServiceNow and/or Java 170
d) Ability to create, update and maintain JavaScript 171
e) Minimum of one (1) years experience developing using Java, Java Script, AngularJS or .Net 172 experience 173
DRAFT Page 8 of 14 04/09/18
4.6. Business Analyst – Senior 175
Primary point of contact with the user community to identify and clarify problem(s) to be solved through 176 the use of ServiceNow application features. Will lead user community in structured meeting using 177 industry standard requirements processes, such as use cases or Business Process Model and Notation 178
(BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and 179 others. The Business Analyst – Senior is an expert on the functional capabilities of ServiceNow and is a 180 visionary mapping user needs to solutions. Key skills of the Business Analyst – Senior are: 181
a) Minimum ten (10) years IT experience 182
b) Minimum of eight (8) successful ServiceNow deployments, including ITSM and building user 183 applications using ServiceNow, four (4) of which are to US Government agencies 184
c) Strong technical writing skills 185
d) Strong verbal skills, ability to present to senior leadership 186
e) Business Analysis skills, to convert business users’ needs to technical requirements 187
f) Minimum one (1) ServiceNow certifications 188
4.7. Business Analyst – Mid 190
Performs under the guidance of the Business Analyst – Senior to identify and clarify problem(s) to be 191 solved through the use of ServiceNow application features. Will lead user community in structured 192 meeting using industry standard requirements processes, such as use cases or Business Process Model 193 and Notation (BPMN), to produce written artifacts, such as Concept of Operations, Requirements 194 documentation and others. The Business Analyst – Mid is an knowledgeable on the functional 195 capabilities of ServiceNow. Key skills of the Business Analyst – Senior are: 196
g) Minimum six (6) years IT experience 197
h) Minimum of four (4) successful ServiceNow deployments, including ITSM and building user 198 applications using ServiceNow, two (2) of which are to US Government agencies 199
i) Strong technical writing skills 200
j) Strong verbal skills, ability to present to senior leadership 201
k) Business Analysis skills, to convert business users’ needs to technical requirements 202
l) Minimum one (1) ServiceNow certifications 203
5. Section 508 Compliance 206
The vendor shall complete all requirements of this statement of work in accordance with the 207 following Section 508 standards of the Rehabilitation Act of 1973: 208
1194.21 (Software Applications and Operating Systems); 209
1194.22 (Web-based Intranet and Internet Information and Applications); 210
1194.24 (items c, d, and e) (Video and Multimedia Products) ; 211
DRAFT Page 9 of 14 04/09/18
1194.31 (Functional Performance Criteria); and 212
1194.41 (Information, Documentation, and Support) 213
6. Place of Performance 215
USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755. 216
All work will be performed at USCYBERCOM’s offices within the greater Ft. Meade, Maryland 217 area. Specific CLINS may specify additional work locations. 218
7. Vendor Requirements 219
7.1. ServiceNow Expertise 220
Vendors who wish to submit a bid, must be a ServiceNow Gold Services certified partner. The 221
ServiceNow Gold Services certified partner must be the prime for the contract. 222
7.2. United States Owned Company or Subsidiary 223
Vendors who wish to submit a bid, must be a United States wholly owned company or 224 subsidiary. 225
7.3. Key Staff 226
Vendors will propose which staff/labor categories shall be key position. Contractor shall provide 227 written notification of the replacement of any key staff to the CO. Key staff must hold an active 228
Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter Intelligence 229
Polygraph (CI/Poly), TS/SCI with CI/Poly. 230
7.4. Availability of Staff 231
USCYBERCOM intends to award the contract within sixty (60) business days of the RFP 232 submission. Key Staff proposed must be available to start work within five (5) days of task 233 order/delivery order award. Full staffing must be in place within ten (10) days of task 234 order/delivery order award. 235
7.5. Staff Training/Certification 236
Vendor shall include in their bid the specific certifications of their proposed staff. 237
Representative examples of certifications could include, but not limited to: PMP, Security+, 238
ServiceNow, ITIL , Microsoft Certified Professional, Amazon Web Services. 239
8. Period of Performance 241
The contract shall be five (5) years. Each order will have a specific period of performance for 242 that order. 243
DRAFT Page 10 of 14 04/09/18
9. Contract Type 244
There will be multiple CLINS under this contract. Each CLIN will identify whether it is a firm 245 fixed price or Time and Materials CLIN. The table below is a listing of the service CLINS to be 246 established under this contract: 247
1. Asset Management 248
2. Configuration Management 249
3. Incident Management 250
4. Problem Management 251
5. Change Management 252
6. Knowledge Management 253
7. Release Management 254
8. Requirements Management 255
9. Service Desk 256
10. Service Catalogue 257
11. Service Level Management 258
12. J1 HR/SSO Toolkit 259
13. HQ OPS Support 260
14. Operations & Maintenance 261
15. Surge Support 262
10. Security Requirements – Information Security and other 263 miscellaneous requirements 264
10.1. Personnel: 265
10.1.1. CLIN Personnel Security Requirements: Each CLIN will detail the specific personnel 266 security requirements for that specific CLIN. 267
10.1.2. Information Security Staff: Staff who will be responsible for the development of system 268 security plan and its artifacts must possess an active TS/SCI with CI/Poly at the of task 269 order/delivery order award start. 270
10.1.3. Operations and Maintenance: Personnel supporting the operations and maintenance 271 activities (work location is USCYBERCOM offices), must hold an active TS/SCI with CI 272 polygraph. 273
10.1.4. System Administrators: staff who may be system administrators or require elevated 274 network or systems access under the operations and maintenance CLINS or surge CLINS, 275 must comply with DoD 8570.01M requirements AND possess an active TS/SCI with CI 276 polygraph. 277
10.2. Facility Security Clearance. The work to be performed under this contract is up to the 278
Top Secret level and will require Sensitive Compartmented Information (SCI) access eligibility 279 for some personnel. Therefore the company must have a final Top Secret Facility Clearance 280 from the Defense Security Service Facility Clearance Branch. 281
10.3. Contractor personnel shall comply with all local security requirements including entry 282 and exit control for personnel and property at the government facility. 283
10.4. Contractor employees shall be required to comply with all Government security 284 regulations and requirements. Initial and periodic safety and security training and briefings will 285
DRAFT Page 11 of 14 04/09/18 be provided by Government security personnel. Failure to comply with Government security 286 regulations and requirements shall require the company to provide the Government with a 287 written remediation/corrective action plan; furthermore, failure to comply with such 288 requirements can be cause for removal and the contractor will not be able to provide service 289 on this contract/order. 290
10.5. Contractor employees with an incident report in JPAS who have had their access to 291 classified information suspended will not be permitted to fill positions under this 292 contract/order. 293
10.6. The Contractor shall not divulge any information, classified or unclassified, about 294
USCYBERCOM, DoD or National Security Agency (NSA) files, data processing activities or 295 functions, user identifications, passwords, or any other knowledge that may be gained, to 296 anyone who is not authorized to have access to such information. The Contractor shall observe 297 and comply with the security provisions in effect at the DoD/NSA facility. Identification shall be 298 worn and displayed as required at all times. 299
10.7. USCYBERCOM retains the right to request removal of contractor personnel regardless of 300 prior clearance or adjudication status, whose actions, while assigned to this contract, conflict 301 with the interest of the Government. 302
10.8. Contractor personnel will generate or handle documents that contain For Official Use 303
Only information at the Contractor and/or Government facility. Contractor shall have access 304 to, generate, and handle classified material only at the location(s) listed in the place of 305 performance section of this document. All contractor deliverables shall be marked in 306 accordance with DoDM 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of 307
Information Act Program, unless otherwise directed by the Government. The contractor shall 308 comply with the provisions of the DoD Industrial Security Manual for handling classified 309 material and producing deliverables. The contractor shall comply with USCYBERCOM 310
Instruction 5200-03: Security Classification Guide. 311
10.9. The Contractor shall afford the Government access to the contractor’s facilities, 312 installations, operations, documentation, databases and personnel used in performance of the 313 contract. Access shall be provided to the extent required to carry out a program of IT 314 inspection (to include vulnerability testing), investigation and audit to safeguard against threats 315 and hazards to the integrity, availability and confidentiality of data or to the function of 316 information technology systems operated on behalf of USCYBERCOM or DoD, and to preserve 317 evidence of computer crime 318
10.10. Identification of Non-Disclosure Agreements: All USCYBERCOM Contractors must 319 execute a USCYBERCOM-provided contractor non-disclosure agreement (NDA) for all services 320 contracts regardless of award amount. The NDA must be signed within one week of 321 contract/TO award. When a new contractor joins the contract, the NDA must be signed by the 322 individual before being approved to work on the contract. The USCYBERCOM contractor is 323 responsible for obtaining and maintaining NDAs for each contractor employee assigned to the 324 contract. Copies of the signed NDA will be provided to the COR. A sample of the NDA is 325 included with this RFP. 326
10.11. DD254 327
10.12. A DD254 documenting contract security requirements will be issued upon contract 328 award. A draft DD254 is included with this RFP. 329
DRAFT Page 12 of 14 04/09/18
11. Government Furnished Equipment 330
Vendor shall provide all equipment, information, workspace and other facilities at vendor’s 331 worksite. There will be no government furnished equipment. 332
12. Travel 333
Local travel will be required, but not reimbursed by the government. Local travel is defined as a 334
50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755. 335
13. Supply Chain Risk Management (SCRM) 337
This vendor and its associated delivery/task orders are subject to the Federal SCRM policies and 339 regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017 340
Notice of Supply Chain Risk, 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of 341
Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA 342
Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and 343
Procedures. Each individual delivery and/or task order will submit a SCRM Plan as part of the technical 344 proposal, which addresses, at a minimum, Supply Chain Security Controls as specified in the 345 delivery/task order and described in the Committee on National Security Systems Instruction (CNSSI) 346
1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST) 347
Special Publications (SP)). 348
This contract and its associated delivery/task orders are subject to the Federal SCRM policies and 349 regulation including the Defense Federal Acquisition Supplement (DFARS) 252.239-7017 Notice of 350
Supply Chain Risk, DFARS 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of 351
Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA 352
Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and 353
Procedures. 354
The vendor shall submit a SCRM plan as part of its technical proposal that describes how the vendor will 356 reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in 357
CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract. 358
Control
Number
HW SW Srvc
SA-12 Supply Chain Protection x x x
SA-12(1) Supply Chain Protection / Acquisition Strategies / Tools / Methods x x x*
SA-12(2) Supply Chain Protection / Supplier Reviews x x x*
DRAFT Page 13 of 14 04/09/18
SA-12(5) Supply Chain Protection / Limitation of Harm x x x*
SA-12 (7) Supply Chain Protection Assessments Prior to Selection / Acceptance/
Update x x x*
SA-12 (8) Supply Chain Protection / Use of All-Source Intelligence x x x*
SA-12 (9) Supply Chain Protection / Operations Security x x x
SA-12 (10) Supply Chain Protection / Validate as Genuine and Not Altered x x x*
SA-12 (11) Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors x x x
SA-12 (12) Supply Chain Protection / Inter-Organizational System Components x x x
SA-12 (13) Supply Chain Protection / Critical Information System Components x x x*
SA-12 (14) Supply Chain Protection / Identity and Traceability x x x*
SA-12 (15) Supply Chain Protection / Process to Address Weaknesses or
Deficiencies x x x
IR-4 (10) Incident Handling / Supply Chain Coordination x x x*
IR-6 (3) Supply Chain Protection / Incident Reporting / Coordination With
Supply Chain x x x*
SA-11 Developer Security Testing and Evaluation x x x*
SA-14 Criticality Analysis x x x*
SA-15 Development Process, Standards, and Tools x x x*
SI-7 Software, Firmware, and Information Integrity x x x*
CM-4 Security Impact x x x*
PM-16 Threat Awareness Program x x x
*Not required if there will be no procurement of hardware, firmware, or software systems. 360
13.1. SCRM Deliverables: 361
SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The vendor shall provide an updated SCRM Plan to 363 the COR and Program Manager within five (5) business days whenever there is a change that affects one 364 or more security controls as described in the Committee on National Security Systems Instructions 365
(CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology 366
(NIST) Special Publications (SP)). At a minimum the following events substantiate the need for an 367 update: changes in company ownership, changes in senior company leadership, supplier changes, 368 subcontractor changes, and ICT supply chain compromises. 369
DRAFT Page 14 of 14 04/09/18
Vendor employees may be required to take periodic mandatory training courses provided through the agency, such 371 as records management training and other training required by statute, regulation, DoD, or DISA policy. (Note if 372 there are specific courses you will require from your contractors, insert those here.) No other training of contractor 373 personnel shall be provided by the Government unless authorized by the Contracting Officer. 374
14. Section 508 Accessibility Standards. The following Section 508 Accessibility 376
Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) 377 to this acquisition. 378
Technical Standards 380
1194.21 - Software Applications and Operating Systems 382
1194.22 - Web Based Intranet and Internet Information and Applications 383
1194.23 - Telecommunications Products 384
1194.24 - Video and Multimedia Products 385
1194.25 - Self-Contained, Closed Products 386
1194.26 - Desktop and Portable Computers 387
1194.41 - Information, Documentation and Support 388
The Technical Standards above facilitate the assurance that the maximum technical standards are 390 provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to 391 ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic 392 and information technology (E&IT) products are proposed. 393
Functional Performance Criteria 395
1194.31 - Functional Performance Criteria 397
File details come from the government source that posted it.