ServiceNow_SOW_General_Provisions.pdf

PDF 620 KB Posted

Attached to
Enterprise Architecture (EACOE) Quick Start Federal contract opportunity
Solicitation number
HB0001-18-R-0003
Issued by
Department of Defense Cyber Command

About this file

ServiceNow_SOW_General_Provisions

View the file

Other files for this federal contract opportunity

Other files attached to Enterprise Architecture (EACOE) Quick Start, newest first.
File Type Posted
SSO_Automation_Automation_Vision.pdf PDF
J6_forms.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
SCI_ATTESTATION.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
USCC_Non-Disclosure_Agreement.pdf PDF
dd254_SNOW.pdf PDF
SSO_Toolkit_CONOPS.pdf PDF
HR_Toolkit_Conops__Task_Management.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
SF312.pdf PDF
Past_Performance_Template.pdf PDF
HR_Toolkit_SOW.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
10-SIP_Instructions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
Asset_Config_Management_SOW.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
Resume_Template.pdf PDF
ACS_050515_eform.pdf PDF
dd2875_(blank).pdf PDF
SIP_050515_eform.pdf PDF
SCI_Reporting_Memo.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
CS_050515_eform.pdf PDF
SSO_Toolkit_SOW.pdf PDF
Show all 27

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DRAFT Page 1 of 14 04/09/18

United States Cyber Command 1

ServiceNow Statement of Work 2

Common Provisions for all Task Orders 3

DRAFT 4

April 9, 2018 6

DRAFT Page 2 of 14 04/09/18

THIS PAGE INTENTIONAL LEFT BLANK 9

DRAFT Page 3 of 14 04/09/18

Contents 11

1. Introduction .......................................................................................................................................... 3 12

2. Background ........................................................................................................................................... 4 13

3. Scope ..................................................................................................................................................... 4 14

4. Labor Categories ................................................................................................................................... 4 15

5. Section 508 Compliance ........................................................................................................................ 8 16

6. Place of Performance ............................................................................................................................ 9 17

7. Vendor Requirements ........................................................................................................................... 9 18

7.1. ServiceNow Expertise........................................................................................................................ 9 19

7.2. United States Owned Company or Subsidiary .................................................................................. 9 20

7.3. Key Staff ............................................................................................................................................ 9 21

7.4. Availability of Staff ............................................................................................................................ 9 22

7.5. Staff Training/Certification ............................................................................................................... 9 23

8. Period of Performance .......................................................................................................................... 9 24

9. Contract Type ...................................................................................................................................... 10 25

10. Security Requirements – Information Security and other miscellaneous requirements ............... 10 26

11. Government Furnished Equipment ................................................................................................ 12 27

12. Travel............................................................................................................................................... 12 28

13. Supply Chain Risk Management (SCRM) ......................................................................................... 12 29

1. Introduction 32

USCYBERCOM plans, coordinates, integrates, synchronizes and conducts activities to: direct the 34 operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; 35 prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable 36 actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our 37 adversaries. 38

The Command has three main focus areas: Defending the DoDIN, providing support to combatant 39 commanders for execution of their missions around the world, and strengthening our nation's ability to 40 withstand and respond to cyber attack. 41

The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, 42 and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate 43

DRAFT Page 4 of 14 04/09/18 resilient, reliable information and communication networks, counter cyberspace threats, and assure 44 access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and 45 certification standards that will enable the Services to build the cyber force required to execute our 46 assigned missions. The command also works closely with interagency and international partners in 47 executing these critical missions. 48

2. Background 50

As part of this elevation to a combatant command, USCYBERCOM must implement policies, processes, 51 procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. USCYBERCOM plans to 52 utilize ServiceNow capabilities as a set of tools to become compliant with the CCA through the 53 implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging the ServiceNow 54

Now Platform workflow and task management capabilities to provide automated, data driven 55 applications to support to the internal operations of USCYBERCOM as well as the operational mission 56 needs. 57

3. Scope 58

The scope of this document is provide guidance that applies to all Contract Line Items (CLINS)/ Orders 59 issued under this contract. 60

4. Labor Categories 62

USCYBERCOM recognizes that a successful implementation of ServiceNow will require a range of skills 63 and expertise provided by the vendor’s staff. USCBYERCOM has identified the required skills and 64 corresponding experience levels of these skills in the section below. Below the table, is a clarification of 65 the required skills and other qualifications associated with each USCYBERCOM ServiceNow Labor 66

Category. The vendor will identify the proposed labor category from their GSA IT Schedule 70 for each of 67 these USCYBERCOM defined Labor Categories. 68

USCYBERCOM ServiceNow Labor Category Vendor Proposed Labor Category

Information Systems Security Engineer

ServiceNow Subject Matter Expert

ServiceNow Developer – Senior

ServiceNow Developer – Mid

ServiceNow Developer – Junior

Business Analyst – Senior

Business Analyst - Mid

DRAFT Page 5 of 14 04/09/18

4.1. Information Systems Security Engineer (ISSE): 71

The ISSE will be responsible for leading and writing documentation in support of the ServiceNow 72 installation and any custom applications obtaining an Authorization To Operate (ATO). Key skills the 73

ISSE must possess at time of starting the project: 74

a) DoD 8570-M certification (IASAE Level II) 75

b) Minimum ten (10) years IT experience 76

c) Experience designing, documenting and implementing a wide range of security controls in an 77

AWS Cloud environment. 78

d) Experience writing documentation in support of obtaining an ATO implementing NIST Special 79

Publication 800-53 and 800-37 80

e) Familiarization/experience with XACTA 81

f) Strong written, analytical and oral communication skills 82

g) Active TS/SCI with CI/Poly 83

4.2. ServiceNow Subject Matter Expert (SME): 85

The ServiceNow SME sets the strategic direction for the implementation of ServiceNow within 86

USCYBERCOM across all three security domains (unclassified, secret and top secret) defining and 87 implementing an architecture that supports USCYBERCOM’s objectives. The SME is the expert on the 88 functionality within ServiceNow and recommends best practices to USCYBERCOM associated with the 89 implementation of each ServiceNow feature. Key skills the SME must possess at time of starting the 90 project: 91

a) Minimum ten (10) years IT experience 92

b) Minimum of eight (8) successful ServiceNow deployments of ITSM, four (4) of which are to US 93 Government agencies 94

c) Experience in implementing large-scale custom development and/or systems integration 95 projects in one or more phases of the SDLC 96

d) Experience working with business users to gather requirements, writing functional and technical 97 specifications and communicating technical requirements 98

e) Administering and developing within ServiceNow 99

f) Ability to create and configure forms and screen updates using ServiceNow and/or Java 100

g) Ability to create, update and maintain JavaScript, AngularJS 101

h) Experience with identity and access management, including use of MS Active Directory and 102

LDAP 103

i) Advanced experience in ServiceNow Deployment API’s 104

j) Minimum of three (3) implementations of ServiceNow in an AWS Cloud environment 105

k) ITIL Certification 106

l) Minimum two (2) ServiceNow certifications 107

4.3. ServiceNow Developer – Senior 109

DRAFT Page 6 of 14 04/09/18

The ServiceNow Developer – Senior will lead the development team as they implement ServiceNow 110 features in conjunction with the ServiceNow SME. The ServiceNow Developer – Senior is responsible for 111 the successful deployment of ServiceNow within USCYBERCOM. The ServiceNow Developer – Senior is 112 responsible for application user interface configuration and development, workflow configuration, 113 development of USCYBERCOM specific applications, and integration with other USCYBERCOM 114 applications. ServiceNow Developer – Senior is the primary technical interface to the USCYBERCOM 115 project manager and/or Contract Officer’s Representative (COR). Key skills the ServiceNow Developer – 116

Senior must possess at time of starting the project: 117

a) Minimum ten (10) years IT experience 118

b) Minimum of eight (8) successful ServiceNow deployments, including ITSM and building user 119 applications using ServiceNow, four (4) of which are to US Government agencies 120

c) Knowledge of ServiceNow database hierarchies and design 121

d) Administering and developing within ServiceNow 122

e) Ability to create and configure forms and screen updates using ServiceNow and/or AngularJS, 123

JavaScript, Jelly, .NET 124

f) Experience with identity and access management, including use of MS Active Directory and 125

LDAP 126

g) Ability to create, update and maintain JavaScript 127

h) Advanced experience in ServiceNow Deployment API’s 128

i) Minimum of four (4) years experience developing using Java, Java Script, AngularJS or .Net 129 experience 130

j) Minimum of two (2) years experience implementing ServiceNow in an AWS Cloud environment 131

k) Strong technical writing skills 132

l) Business Analysis skills, to convert business users’ needs to technical requirements 133

m) Minimum two (2) ServiceNow certifications 134

n) Minimum one (1) Amazon Web Services certification 135

DRAFT Page 7 of 14 04/09/18

4.4. ServiceNow Developer – Mid 138

The ServiceNow Developer – Mid will participate as a member of the development team as they 139 implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior. 140

The ServiceNow Developer – Mid is responsible for application user interface configuration and 141 development, workflow configuration, development of USCYBERCOM specific applications, and 142 integration with other USCYBERCOM applications. Key skills the ServiceNow Developer – Mid must 143 possess at time of starting the project: 144

a) Minimum of four (4) years experience developing applications 145

b) Minimum of three (3) successful ServiceNow deployments, including ITSM and building user 146 applications using ServiceNow. 147

c) Knowledge of ServiceNow database hierarchies and design 148

d) Administering and developing within ServiceNow 149

e) Ability to create and configure forms and screen updates using ServiceNow and/or Java 150

f) Ability to create, update and maintain JavaScript 151

g) Advanced experience in ServiceNow Deployment API’s 152

h) Minimum of two (2) years experience developing using Java, Java Script, AngularJS or .Net 153 experience 154

i) Minimum of two (2) years experience implementing ServiceNow in an AWS Cloud environment 155

j) Strong technical writing skills 156

k) Business Analysis skills, to convert business users needs to technical requirements 157

l) Minimum one (1) ServiceNow certifications 158

m) Minimum one (1) Amazon Web Services certification 159

4.5. ServiceNow Developer – Junior 161

The ServiceNow Developer – Junior will participate as a member of the development team as they 162 implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior. 163

The ServiceNow Developer – Junior is responsible for application user interface configuration and 164 development, workflow configuration, development of USCYBERCOM specific applications, and 165 integration with other USCYBERCOM applications. Key skills the ServiceNow Developer – Junior must 166 possess at time of starting the project: 167

a) Minimum of two (2) years experience developing and/or implementing ServiceNow 168

b) Administering and developing within ServiceNow 169

c) Ability to create and configure forms and screen updates using ServiceNow and/or Java 170

d) Ability to create, update and maintain JavaScript 171

e) Minimum of one (1) years experience developing using Java, Java Script, AngularJS or .Net 172 experience 173

DRAFT Page 8 of 14 04/09/18

4.6. Business Analyst – Senior 175

Primary point of contact with the user community to identify and clarify problem(s) to be solved through 176 the use of ServiceNow application features. Will lead user community in structured meeting using 177 industry standard requirements processes, such as use cases or Business Process Model and Notation 178

(BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and 179 others. The Business Analyst – Senior is an expert on the functional capabilities of ServiceNow and is a 180 visionary mapping user needs to solutions. Key skills of the Business Analyst – Senior are: 181

a) Minimum ten (10) years IT experience 182

b) Minimum of eight (8) successful ServiceNow deployments, including ITSM and building user 183 applications using ServiceNow, four (4) of which are to US Government agencies 184

c) Strong technical writing skills 185

d) Strong verbal skills, ability to present to senior leadership 186

e) Business Analysis skills, to convert business users’ needs to technical requirements 187

f) Minimum one (1) ServiceNow certifications 188

4.7. Business Analyst – Mid 190

Performs under the guidance of the Business Analyst – Senior to identify and clarify problem(s) to be 191 solved through the use of ServiceNow application features. Will lead user community in structured 192 meeting using industry standard requirements processes, such as use cases or Business Process Model 193 and Notation (BPMN), to produce written artifacts, such as Concept of Operations, Requirements 194 documentation and others. The Business Analyst – Mid is an knowledgeable on the functional 195 capabilities of ServiceNow. Key skills of the Business Analyst – Senior are: 196

g) Minimum six (6) years IT experience 197

h) Minimum of four (4) successful ServiceNow deployments, including ITSM and building user 198 applications using ServiceNow, two (2) of which are to US Government agencies 199

i) Strong technical writing skills 200

j) Strong verbal skills, ability to present to senior leadership 201

k) Business Analysis skills, to convert business users’ needs to technical requirements 202

l) Minimum one (1) ServiceNow certifications 203

5. Section 508 Compliance 206

The vendor shall complete all requirements of this statement of work in accordance with the 207 following Section 508 standards of the Rehabilitation Act of 1973: 208

1194.21 (Software Applications and Operating Systems); 209

1194.22 (Web-based Intranet and Internet Information and Applications); 210

1194.24 (items c, d, and e) (Video and Multimedia Products) ; 211

DRAFT Page 9 of 14 04/09/18

1194.31 (Functional Performance Criteria); and 212

1194.41 (Information, Documentation, and Support) 213

6. Place of Performance 215

USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755. 216

All work will be performed at USCYBERCOM’s offices within the greater Ft. Meade, Maryland 217 area. Specific CLINS may specify additional work locations. 218

7. Vendor Requirements 219

7.1. ServiceNow Expertise 220

Vendors who wish to submit a bid, must be a ServiceNow Gold Services certified partner. The 221

ServiceNow Gold Services certified partner must be the prime for the contract. 222

7.2. United States Owned Company or Subsidiary 223

Vendors who wish to submit a bid, must be a United States wholly owned company or 224 subsidiary. 225

7.3. Key Staff 226

Vendors will propose which staff/labor categories shall be key position. Contractor shall provide 227 written notification of the replacement of any key staff to the CO. Key staff must hold an active 228

Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter Intelligence 229

Polygraph (CI/Poly), TS/SCI with CI/Poly. 230

7.4. Availability of Staff 231

USCYBERCOM intends to award the contract within sixty (60) business days of the RFP 232 submission. Key Staff proposed must be available to start work within five (5) days of task 233 order/delivery order award. Full staffing must be in place within ten (10) days of task 234 order/delivery order award. 235

7.5. Staff Training/Certification 236

Vendor shall include in their bid the specific certifications of their proposed staff. 237

Representative examples of certifications could include, but not limited to: PMP, Security+, 238

ServiceNow, ITIL , Microsoft Certified Professional, Amazon Web Services. 239

8. Period of Performance 241

The contract shall be five (5) years. Each order will have a specific period of performance for 242 that order. 243

DRAFT Page 10 of 14 04/09/18

9. Contract Type 244

There will be multiple CLINS under this contract. Each CLIN will identify whether it is a firm 245 fixed price or Time and Materials CLIN. The table below is a listing of the service CLINS to be 246 established under this contract: 247

1. Asset Management 248

2. Configuration Management 249

3. Incident Management 250

4. Problem Management 251

5. Change Management 252

6. Knowledge Management 253

7. Release Management 254

8. Requirements Management 255

9. Service Desk 256

10. Service Catalogue 257

11. Service Level Management 258

12. J1 HR/SSO Toolkit 259

13. HQ OPS Support 260

14. Operations & Maintenance 261

15. Surge Support 262

10. Security Requirements – Information Security and other 263 miscellaneous requirements 264

10.1. Personnel: 265

10.1.1. CLIN Personnel Security Requirements: Each CLIN will detail the specific personnel 266 security requirements for that specific CLIN. 267

10.1.2. Information Security Staff: Staff who will be responsible for the development of system 268 security plan and its artifacts must possess an active TS/SCI with CI/Poly at the of task 269 order/delivery order award start. 270

10.1.3. Operations and Maintenance: Personnel supporting the operations and maintenance 271 activities (work location is USCYBERCOM offices), must hold an active TS/SCI with CI 272 polygraph. 273

10.1.4. System Administrators: staff who may be system administrators or require elevated 274 network or systems access under the operations and maintenance CLINS or surge CLINS, 275 must comply with DoD 8570.01M requirements AND possess an active TS/SCI with CI 276 polygraph. 277

10.2. Facility Security Clearance. The work to be performed under this contract is up to the 278

Top Secret level and will require Sensitive Compartmented Information (SCI) access eligibility 279 for some personnel. Therefore the company must have a final Top Secret Facility Clearance 280 from the Defense Security Service Facility Clearance Branch. 281

10.3. Contractor personnel shall comply with all local security requirements including entry 282 and exit control for personnel and property at the government facility. 283

10.4. Contractor employees shall be required to comply with all Government security 284 regulations and requirements. Initial and periodic safety and security training and briefings will 285

DRAFT Page 11 of 14 04/09/18 be provided by Government security personnel. Failure to comply with Government security 286 regulations and requirements shall require the company to provide the Government with a 287 written remediation/corrective action plan; furthermore, failure to comply with such 288 requirements can be cause for removal and the contractor will not be able to provide service 289 on this contract/order. 290

10.5. Contractor employees with an incident report in JPAS who have had their access to 291 classified information suspended will not be permitted to fill positions under this 292 contract/order. 293

10.6. The Contractor shall not divulge any information, classified or unclassified, about 294

USCYBERCOM, DoD or National Security Agency (NSA) files, data processing activities or 295 functions, user identifications, passwords, or any other knowledge that may be gained, to 296 anyone who is not authorized to have access to such information. The Contractor shall observe 297 and comply with the security provisions in effect at the DoD/NSA facility. Identification shall be 298 worn and displayed as required at all times. 299

10.7. USCYBERCOM retains the right to request removal of contractor personnel regardless of 300 prior clearance or adjudication status, whose actions, while assigned to this contract, conflict 301 with the interest of the Government. 302

10.8. Contractor personnel will generate or handle documents that contain For Official Use 303

Only information at the Contractor and/or Government facility. Contractor shall have access 304 to, generate, and handle classified material only at the location(s) listed in the place of 305 performance section of this document. All contractor deliverables shall be marked in 306 accordance with DoDM 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of 307

Information Act Program, unless otherwise directed by the Government. The contractor shall 308 comply with the provisions of the DoD Industrial Security Manual for handling classified 309 material and producing deliverables. The contractor shall comply with USCYBERCOM 310

Instruction 5200-03: Security Classification Guide. 311

10.9. The Contractor shall afford the Government access to the contractor’s facilities, 312 installations, operations, documentation, databases and personnel used in performance of the 313 contract. Access shall be provided to the extent required to carry out a program of IT 314 inspection (to include vulnerability testing), investigation and audit to safeguard against threats 315 and hazards to the integrity, availability and confidentiality of data or to the function of 316 information technology systems operated on behalf of USCYBERCOM or DoD, and to preserve 317 evidence of computer crime 318

10.10. Identification of Non-Disclosure Agreements: All USCYBERCOM Contractors must 319 execute a USCYBERCOM-provided contractor non-disclosure agreement (NDA) for all services 320 contracts regardless of award amount. The NDA must be signed within one week of 321 contract/TO award. When a new contractor joins the contract, the NDA must be signed by the 322 individual before being approved to work on the contract. The USCYBERCOM contractor is 323 responsible for obtaining and maintaining NDAs for each contractor employee assigned to the 324 contract. Copies of the signed NDA will be provided to the COR. A sample of the NDA is 325 included with this RFP. 326

10.11. DD254 327

10.12. A DD254 documenting contract security requirements will be issued upon contract 328 award. A draft DD254 is included with this RFP. 329

DRAFT Page 12 of 14 04/09/18

11. Government Furnished Equipment 330

Vendor shall provide all equipment, information, workspace and other facilities at vendor’s 331 worksite. There will be no government furnished equipment. 332

12. Travel 333

Local travel will be required, but not reimbursed by the government. Local travel is defined as a 334

50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755. 335

13. Supply Chain Risk Management (SCRM) 337

This vendor and its associated delivery/task orders are subject to the Federal SCRM policies and 339 regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017 340

Notice of Supply Chain Risk, 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of 341

Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA 342

Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and 343

Procedures. Each individual delivery and/or task order will submit a SCRM Plan as part of the technical 344 proposal, which addresses, at a minimum, Supply Chain Security Controls as specified in the 345 delivery/task order and described in the Committee on National Security Systems Instruction (CNSSI) 346

1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST) 347

Special Publications (SP)). 348

This contract and its associated delivery/task orders are subject to the Federal SCRM policies and 349 regulation including the Defense Federal Acquisition Supplement (DFARS) 252.239-7017 Notice of 350

Supply Chain Risk, DFARS 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of 351

Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA 352

Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and 353

Procedures. 354

The vendor shall submit a SCRM plan as part of its technical proposal that describes how the vendor will 356 reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in 357

CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract. 358

Control

Number

HW SW Srvc

SA-12 Supply Chain Protection x x x

SA-12(1) Supply Chain Protection / Acquisition Strategies / Tools / Methods x x x*

SA-12(2) Supply Chain Protection / Supplier Reviews x x x*

DRAFT Page 13 of 14 04/09/18

SA-12(5) Supply Chain Protection / Limitation of Harm x x x*

SA-12 (7) Supply Chain Protection Assessments Prior to Selection / Acceptance/

Update x x x*

SA-12 (8) Supply Chain Protection / Use of All-Source Intelligence x x x*

SA-12 (9) Supply Chain Protection / Operations Security x x x

SA-12 (10) Supply Chain Protection / Validate as Genuine and Not Altered x x x*

SA-12 (11) Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors x x x

SA-12 (12) Supply Chain Protection / Inter-Organizational System Components x x x

SA-12 (13) Supply Chain Protection / Critical Information System Components x x x*

SA-12 (14) Supply Chain Protection / Identity and Traceability x x x*

SA-12 (15) Supply Chain Protection / Process to Address Weaknesses or

Deficiencies x x x

IR-4 (10) Incident Handling / Supply Chain Coordination x x x*

IR-6 (3) Supply Chain Protection / Incident Reporting / Coordination With

Supply Chain x x x*

SA-11 Developer Security Testing and Evaluation x x x*

SA-14 Criticality Analysis x x x*

SA-15 Development Process, Standards, and Tools x x x*

SI-7 Software, Firmware, and Information Integrity x x x*

CM-4 Security Impact x x x*

PM-16 Threat Awareness Program x x x

*Not required if there will be no procurement of hardware, firmware, or software systems. 360

13.1. SCRM Deliverables: 361

SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The vendor shall provide an updated SCRM Plan to 363 the COR and Program Manager within five (5) business days whenever there is a change that affects one 364 or more security controls as described in the Committee on National Security Systems Instructions 365

(CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology 366

(NIST) Special Publications (SP)). At a minimum the following events substantiate the need for an 367 update: changes in company ownership, changes in senior company leadership, supplier changes, 368 subcontractor changes, and ICT supply chain compromises. 369

DRAFT Page 14 of 14 04/09/18

Vendor employees may be required to take periodic mandatory training courses provided through the agency, such 371 as records management training and other training required by statute, regulation, DoD, or DISA policy. (Note if 372 there are specific courses you will require from your contractors, insert those here.) No other training of contractor 373 personnel shall be provided by the Government unless authorized by the Contracting Officer. 374

14. Section 508 Accessibility Standards. The following Section 508 Accessibility 376

Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) 377 to this acquisition. 378

Technical Standards 380

1194.21 - Software Applications and Operating Systems 382

1194.22 - Web Based Intranet and Internet Information and Applications 383

1194.23 - Telecommunications Products 384

1194.24 - Video and Multimedia Products 385

1194.25 - Self-Contained, Closed Products 386

1194.26 - Desktop and Portable Computers 387

1194.41 - Information, Documentation and Support 388

The Technical Standards above facilitate the assurance that the maximum technical standards are 390 provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to 391 ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic 392 and information technology (E&IT) products are proposed. 393

Functional Performance Criteria 395

1194.31 - Functional Performance Criteria 397

File details come from the government source that posted it.