HB000118R0012.pdf
PDF 738 KB Posted
- Attached to
- ServiceNow Federal contract opportunity
- Solicitation number
- HB0001-18-R-0012
- Issued by
- Department of Defense Cyber Command
About this file
HB000118R0012
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
HB000118R0012 29-May-2018
b. TELEPHONE NUMBER 8. OFFER DUE DATE/LOCAL TIME
12:00 PM 22 Jun 2018
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
HB00019. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
ROBERT A. SHEEHAN
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
0 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED ORX
SMALL BUSINESS
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
US CYBER COMMAND
USCYBERCOM ACQUISITION
9800 SAVAGE ROAD SUITE 6317
FORT MEADE MD 20755
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE HB0001 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
US CYBER COMMAND
ROBERT A. SHEEHAN
USCYBERCOM ACQUISITION
9800 SAVAGE ROAD SUITE 6317
FORT MEADE MD 20755
TEL: FAX:
FAX:
TEL: SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$15,000,000
NAICS:
541611
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF27
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
HB000118R0012
Section SF 1449 - CONTINUATION SHEET
SCOPE: BPA SOW
SCOPE: BPA SOW
Contents
1. Introduction
2. Background
3. Scope
4. Labor Categories
5. Section 508 Compliance
6. Place of Performance
7. Vendor Requirements
7.1. ServiceNow Expertise
7.2. United States Owned Company or Subsidiary
7.3. Key Staff
7.4. Availability of Staff
7.5. Staff Training/Certification
8. Period of Performance
9. Contract Type
10. Security Requirements – Information Security and other miscellaneous requirements
11. Government Furnished Equipment
12. Travel
13. Supply Chain Risk Management (SCRM)
1. Introduction
United States Cyber Command (USCYBERCOM) plans, coordinates, integrates, synchronizes and conducts activities to: direct the operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our adversaries.
The Command has three main focus areas: Defending the DoDIN, providing support to combatant commanders for execution of their missions around the world, and strengthening our nation's ability to withstand and respond to cyber attack.
The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate resilient, reliable information and communication networks, counter cyberspace threats, and assure access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and certification standards that will enable the Services to build the cyber force required to execute our assigned missions. The command also works closely with interagency and international partners in executing these critical missions.
2. Background As part of this elevation to a combatant command, USCYBERCOM must implement policies, processes, procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996.
USCYBERCOM plans to utilize ServiceNow capabilities as a set of tools to become compliant with the CCA through the implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging the ServiceNow Now Platform workflow and task management capabilities to provide automated, data driven applications to support to the internal operations of USCYBERCOM as well as the operational mission needs.
3. Scope The contractor shall provide services and software to support specific implementation(s) of the ServiceNow products at USCYBERCOM. The contractor shall implement:
Develop data driven applications, specific to USCYBERCOM operational needs, test and integrate the applications onto various platforms;
Implement the Information Technology Service Management (ITSM) processes within USCYBERCOM utilizing the capabilities of ServiceNow.
The contractor shall provide support in the following areas:
1. Asset Management
2. Configuration Management
3. Incident Management
4. Problem Management
5. Change Management
6. Knowledge Management
7. Release Management
8. Requirements Management
9. Service Desk
10. Service Catalogue
11. Service Level Management
12. J1 HR/SSO Toolkit
13. HQ OPS Support
14. Operations & Maintenance
15. Surge Support
16. Training
4. Labor Categories USCYBERCOM recognizes that a successful implementation of ServiceNow will require a range of skills and expertise provided by the vendor’s staff. USCBYERCOM has identified the required skills and corresponding experience levels of these skills in the section below. Below the table, is a clarification of the required skills and other qualifications associated with each USCYBERCOM ServiceNow Labor Category. The vendor will identify the proposed labor category from their GSA IT Schedule 70 for each of these USCYBERCOM defined Labor Categories.
4.1. Information Systems Security Engineer (ISSE):
The ISSE will be responsible for leading and writing documentation in support of the ServiceNow installation and any custom applications obtaining an Authorization To Operate (ATO). The ISSE must possess:
a) DoD 8570-M certification (IASAE Level II)
b) Minimum ten (10) years IT experience
c) Four (4) years experience as an ISSE
d) Experience designing, documenting and implementing a wide range of security controls.
e) Experience writing documentation in support of obtaining an ATO implementing NIST
Special Publication 800-53 and 800-37
f) Active TS/SCI with CI/Poly
g) Familiarization/experience with XACTA – desirable, not required
h) Strong written, analytical and oral communication skills
4.2. AWS Cloud Architect
The AWS Cloud Architect will work with the ServiceNow SME and USCYBERCOM’s architecture and engineering division to recommend an AWS Cloud based architecture for hosting the ServiceNow instances in each of the different security enclaves (unclassified, secret and Top Secret). The proposed architecture will integrate into the existing USCYBERCOM AWS cloud architectures leveraging common services and identifying ServiceNow unique cloud hosting requirements. The AWS Cloud Architect must possess:
a) Minimum ten (10) years IT experience.
b) Minimum of two (2) successful ServiceNow AWS private cloud or hybrid cloud deployments.
c) Proven ability to architect, design and implement cloud-based and/or cloud-native solutions to include identity and access management.
d) Experience working with users to gather requirements, writing functional and technical specifications and communicating technical requirements.
e) Hands-on experience configuring supporting common infrastructure roles and tools (e.g.:
DNS, NTP, Group Policy, Active Directory/ADFS, Web Application Firewalls, logging services, web proxies, etc.).
f) Hands-on experience with infrastructure as code concepts and related software highly preferred (e.g. Chef, Puppet, CloudFormation, Terraform, JSON).
g) Practical experience sizing hardware and storage needs.
h) AWS: Certified Solutions Architect – Professional.
4.3. ServiceNow Subject Matter Expert (SME):
The ServiceNow SME sets the strategic direction for the implementation of ServiceNow within USCYBERCOM across all three security domains (unclassified, secret and top secret) defining and implementing an architecture that supports USCYBERCOM’s objectives. The SME is the expert on the functionality within ServiceNow and recommends best practices to USCYBERCOM associated with the implementation of each ServiceNow feature. The SME must possess:
i) Minimum ten (10) years IT experience.
j) Minimum of six (6) successful ServiceNow deployments of ITSM and/or workflow applications using ServiceNow. Preferred to have three (3) with US Government agencies.
k) Experience in implementing large-scale custom development and/or systems integration projects in one or more phases of the Software Development Life Cycle (SDLC).
l) Experience working with users to gather requirements, writing functional and technical specifications and communicating technical requirements.
m) Administering and developing within ServiceNow.
n) Demonstrated experience in:
i) Creating and configuring forms and screen updates using ServiceNow and/or Java
ii) Creating, updating and maintaining JavaScript, AngularJS
iii) Experience with identity and access management, including use of MS Active
Directory and lightweight directory access protocol (LDAP)
iv) Experience in ServiceNow Deployment API’s
o) ITIL Certification.
p) Minimum two (2) ServiceNow certifications.
4.4. ServiceNow Developer – Senior
The ServiceNow Developer – Senior will lead the development team as they implement ServiceNow features in conjunction with the ServiceNow SME. The ServiceNow Developer –
Senior is responsible for the successful deployment of ServiceNow within USCYBERCOM.
The ServiceNow Developer – Senior is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. ServiceNow Developer – Senior is the primary technical interface to the USCYBERCOM project manager and/or Contract Officer’s Representative (COR). Key skills the ServiceNow Developer – Senior must possess at time of starting the project:
a) Minimum ten (10) years IT experience.
b) Minimum of four (4) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow. Prefer to have two (2) which are to US Government agencies.
c) Ability to create and configure forms and screen updates using ServiceNow and/or AngularJS, JavaScript, Jelly, .NET.
d) Minimum of two (2) years experience implementing and maintaining identity and access management, including use of MS Active Directory, LDAP and Single Sign On (SSO).
e) Minimum of four (4) years experience developing using Java, Java Script, AngularJS or .Net experience.
f) Minimum two (2) ServiceNow certifications.
4.5. ServiceNow Developer – Mid
The ServiceNow Developer – Mid will participate as a member of the development team as they implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior. The ServiceNow Developer – Mid is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. The ServiceNow Developer – Mid must possess:
a) Minimum of four (4) years experience developing applications.
b) Minimum of two (2) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow.
c) Minimum of two (2) years experience developing using Java, Java Script, AngularJS or
.Net experience.
d) Minimum of two (2) years experience web services integration using SOAP, REST JSON or similar technologies.
e) Minimum one (1) ServiceNow certification.
4.6. ServiceNow Developer – Junior
The ServiceNow Developer – Junior will participate as a member of the development team as they implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior. The ServiceNow Developer – Junior is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications.
The ServiceNow Developer – Junior must possess:
a) Minimum of two (2) years experience developing and/or implementing ServiceNow.
b) Minimum of one (1) year of experience developing using Java, Java Script, AngularJS, Jelly or .Net experience.
4.7. Business Analyst – Senior
Primary point of contact with the user community to identify and clarify problem(s) to be solved through the use of ServiceNow application features. Will lead user community in structured meeting using industry standard requirements processes, such as use cases or Business Process Model and Notation (BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and others. The Business Analyst – Senior is an expert on the functional capabilities of ServiceNow and is a visionary mapping user needs to solutions. The Business Analyst – Senior must possess:
a) Minimum ten (10) years IT experience
b) Minimum of four (4) successful ServiceNow deployments, including ITSM and building user applications using ServiceNow. Prefer to have two (2) that are to US Government agencies.
c) Minimum one (1) ServiceNow certification.
Desired skills for the Business Analyst – Senior are:
d) Ability to convert users’ needs to technical requirements.
e) Strong verbal skills, ability to present to senior leadership.
f) Strong technical writing skills.
4.8. Business Analyst – Mid
Performs under the guidance of the Business Analyst – Senior to identify and clarify problem(s) to be solved through the use of ServiceNow application features. Will lead user community in structured meeting using industry standard requirements processes, such as use cases or Business Process Model and Notation (BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and others. The Business Analyst – Mid is a knowledgeable on the functional capabilities of ServiceNow. The Business Analyst – Mid must possess:
g) Minimum six (6) years IT experience.
h) Minimum of two (2) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow. Prefer to have two (2) which are to US Government agencies.
Desired skills for the Business Analyst – Mid are:
i) Ability to convert users’ needs to technical requirements.
j) Strong verbal skills, ability to present to senior leadership.
k) Strong technical writing skills.
5. Place of Performance USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755. All work will be performed at USCYBERCOM’s offices within the greater Ft. Meade, Maryland area or at the contractor’s facility. Specific work locations will be designated in each order.
6. Vendor Requirements
6.1. ServiceNow Expertise
Vendors who wish to submit a bid, must be a ServiceNow Gold Services certified partner. The ServiceNow Gold Services certified partner must be the prime for the contract.
6.2. United States Owned Company or Subsidiary
Vendors who wish to submit a bid, must be a United States wholly owned company or subsidiary.
6.3. Key Staff
Vendors will propose which staff/labor categories shall be key position. Contractor shall provide prior written notification of the replacement of any key staff to the CO. Key staff must hold an active Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter Intelligence Polygraph (CI/Poly), TS/SCI with CI/Poly.
7. Ordering Period The contract shall be five (5) years. Each order will have a specific period of performance.
8. Contract Type There will be multiple orders for this contract. Each order will identify whether it is a firm fixed price or Time and Materials order.
9. Security Requirements – Information Security and other miscellaneous requirements
9.1. Personnel:
9.1.1. Personnel Security Requirements: Each order will detail the specific personnel security requirements.
9.1.2. Information Security Staff: Staff who will be responsible for the development of system security plan and its artifacts must possess an active TS/SCI with CI/Poly at the time of order award start.
9.1.3. Operations and Maintenance: Personnel supporting the operations and maintenance activities (work location is USCYBERCOM offices), must hold an active TS/SCI with CI polygraph.
9.1.4. System Administrators: staff who may be system administrators or require elevated network or systems access under the operations and maintenance CLINS or surge CLINS, must comply with DoD 8570.01M requirements AND possess an active TS/SCI with CI polygraph.
9.2. Facility Security Clearance. The work to be performed under this contract is up to the Top Secret level and will require Sensitive Compartmented Information (SCI) access eligibility for some personnel. Therefore the company must have a final Top Secret Facility Clearance from the Defense Security Service Facility Clearance Branch.
9.3. Contractor personnel shall comply with all local security requirements including entry and exit control for personnel and property at the government facility.
9.4. Contractor employees shall be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by Government. Failure to comply with Government security regulations and requirements shall require the company to provide the Government with a written remediation/corrective action plan; furthermore, failure to comply with such requirements can be cause for removal and the contractor will not be able to provide service on this contract/order.
9.5. Contractor employees with an incident report in Joint Personnel Adjudication System (JPAS) or its replacement system (Defense Information System for Security (DISS) Joint Verification System (JVS)) who have had their access to classified information suspended will not be permitted to fill positions under this contract/order.
9.6. The Contractor shall not divulge any information, classified or unclassified, about USCYBERCOM, DoD or National Security Agency (NSA) files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the DoD/NSA facility. Identification shall be worn and displayed as required at all times.
9.7. USCYBERCOM retains the right to request removal of contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, conflict with the interest of the Government.
9.8. Contractor personnel will generate or handle documents that contain For Official Use Only information at the Contractor and/or Government facility. Contractor shall have access to, generate, and handle classified material only at the location(s) listed in the place of performance section of this document. All contractor deliverables shall be marked in accordance with DoDM 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of Information Act Program, unless otherwise directed by the Government. The contractor shall comply with the provisions of the DoD Industrial Security Manual for handling classified material and producing deliverables.
Additionally, the contractor shall comply with USCYBERCOM security policies.
9.9. The Contractor shall afford the Government access to the contractor’s facilities, installations, operations, documentation, databases and personnel used in performance of the contract. Access shall be provided to the extent required to carry out a program of IT inspection (to include vulnerability testing), investigation and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of data or to the function of information technology systems operated on behalf of USCYBERCOM or DoD, and to preserve evidence of computer crime
9.10. Identification of Non-Disclosure Agreements (NDA): All USCYBERCOM Contractors must execute a USCYBERCOM-provided contractor non-disclosure agreement (NDA) for all services contracts regardless of award amount. The NDA must be signed within one week of contract/TO award. When a new contractor joins the contract, the NDA must be signed by the individual before being approved to work on the contract. The USCYBERCOM contractor is responsible for obtaining and maintaining NDAs for each contractor employee assigned to the contract. Copies of the signed NDA will be provided to the COR.
9.11. DD254
A DD254 documenting contract security requirements will be issued upon contract award and incorporated by reference.
10. Government Furnished Equipment Vendor shall provide all equipment, information, workspace and other facilities at vendor’s worksite. Any deviations to this shall be listed in the specific order(s).
11. Travel Local travel will be required, but not reimbursed by the government. Local travel is defined as a 50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755.
12. Training The contractor shall provide personnel that are qualified to meet all requirements of the statement of work. Any training available at a commercial source shall be considered to be of general utility to the Contractor and the course, labor and travel costs are note to be billed to the Government.
Training will be provided by the government only when such software/systems are uniquely designed/fabricated by, or for, the Government and such training is otherwise unavailable to the Contractor. Courses conducted by Government schools may be made available to Contractor personnel where it has been clearly determined by the Contracting Officer (in writing) that training on specialized or unique government equipment is essential in carrying out the terms of the contract and the training is otherwise unavailable from commercial source.
13. Supply Chain Risk Management (SCRM)
This vendor and its associated delivery/task orders are subject to the Federal SCRM policies and regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017 Notice of Supply Chain Risk, 252.239-7018 Supply Chain Risk, DoD Instruction
5200.44 Protection of Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and Procedures. Each individual delivery and/or task order will submit a SCRM Plan as part of the technical proposal, which addresses, at a minimum, Supply Chain Security Controls as specified in the delivery/task order and described in the Committee on National Security Systems Instruction (CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST) Special Publications (SP)).
The vendor shall submit a SCRM plan as part of its technical proposal that describes how the vendor will reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract.
Control Number
H W
SW Srv c
SA-12 Supply Chain Protection x x x SA-12(1) Supply Chain Protection / Acquisition Strategies / Tools /
Methods x x x*
SA-12(2) Supply Chain Protection / Supplier Reviews x x x* SA-12(5) Supply Chain Protection / Limitation of Harm x x x*
SA-12 (7) Supply Chain Protection Assessments Prior to Selection / Acceptance/ Update x x x*
SA-12 (8) Supply Chain Protection / Use of All-Source Intelligence x x x* SA-12 (9) Supply Chain Protection / Operations Security x x x
SA-12
(10)
Supply Chain Protection / Validate as Genuine and Not Altered x x x*
SA-12
(11)
Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors x x x
SA-12
(12)
Supply Chain Protection / Inter-Organizational System Components x x x
SA-12
(13)
Supply Chain Protection / Critical Information System Components x x x*
SA-12
(14)
Supply Chain Protection / Identity and Traceability x x x*
SA-12
(15)
Supply Chain Protection / Process to Address Weaknesses or Deficiencies x x x
IR-4 (10) Incident Handling / Supply Chain Coordination x x x* IR-6 (3) Supply Chain Protection / Incident Reporting / Coordination
With Supply Chain x x x*
SA-11 Developer Security Testing and Evaluation x x x* SA-14 Criticality Analysis x x x* SA-15 Development Process, Standards, and Tools x x x* SI-7 Software, Firmware, and Information Integrity x x x* CM-4 Security Impact x x x* PM-16 Threat Awareness Program x x x
*Not required if there will be no procurement of hardware, firmware, or software systems.
13.1. SCRM Deliverables:
SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The vendor shall provide an updated SCRM Plan to the COR and Program Manager within five (5) business days whenever there is a change that affects one or more security controls as described in the Committee on National Security Systems Instructions (CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST) Special Publications (SP)). At a minimum the following events substantiate the need for an update: changes in company ownership, changes in senior company leadership, supplier changes, subcontractor changes, and ICT supply chain compromises.
Vendor employees may be required to take periodic mandatory training courses provided through the agency, such as records management training and other training required by statute, regulation, DoD, or DISA policy. (Note if there are specific courses you will require from your contractors, insert those here.) No other training of contractor personnel shall be provided by the Government unless authorized by the Contracting Officer.
14. Section 508 Accessibility Standards.
The vendor shall complete all requirements of this statement of work in accordance with the following Section 508 standards of the Rehabilitation Act of 1973. The following Section 508 Accessibility Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) to this acquisition.
Technical Standards
1194.21 - Software Applications and Operating Systems
1194.22 - Web Based Intranet and Internet Information and Applications
1194.23 - Telecommunications Products
1194.24 - Video and Multimedia Products
1194.25 - Self-Contained, Closed Products
1194.26 - Desktop and Portable Computers
1194.41 - Information, Documentation and Support
The Technical Standards above facilitate the assurance that the maximum technical standards are provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic and information technology (E&IT) products are proposed.
Functional Performance Criteria
1194.31 - Functional Performance Criteria
Reference Applicable Documents:
1. Statement of Work:
a. Asset Config Management SOW Final, Dated May 22, 2018. Length: 7 pages
b. HR Toolkit SOW FINAL, Dated May 22, 2018. Length: 8 pages
c. HR Toolkit SOW FINAL, Dated May 22, 2018. Length 8 pages
2. Source Selection Plan
a. Source Selection Plan Snowy Eagle, Dated May 30, 2018. Length: 17 pages
3. DD 254
a. Department of Defense Contract Security Classification Specification
PRICING
The contract hereby incorporates ____ % discount on the GSA schedule ____________________ for all labor and software for the ordering period.
ORDERING PERIOD
The ordering period for the Blanket Purchase Agreement shall be for a period of 60 months after date of award, unless terminated sooner.
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 1 Job Order for Asset and Configuration Mgmt
T&M Reference SOW, entitled "Asset Config Management SOW Final" dated: May 22, 2018 Reference CONOPS, entitled "Asset Config Management Conops Final" dated:
March 21, 2018
PURCHASE REQUEST NUMBER: F1ATCY8121AW01
FOB: Destination
BRAND NAME/SOLE SOURCE: BN
TOT ESTIMATED PRICE
CEILING PRICE
0002 1 Job Order for Human Resources
T&M Reference SOW, entitled "HR Toolkit SOW FINAL" dated: May 22, 2018
Reference CONOPS, entitled "HR Toolkit Conops Task Management" dated:
February 14, 2017
PURCHASE REQUEST NUMBER: F1ATCY8121AW01
0003 1 Job Order for SSO
T&M Reference SOW, entitled "SSO Toolkit SOW final" dated: May 22, 2018
Reference CONOPS, entitled "May 11, 2018" dated: May 11, 2018
PURCHASE REQUEST NUMBER: F1ATCY8121AW01
0004 1 Job Order for FY18 Software
FFP
PURCHASE REQUEST NUMBER: F1ATCY8121AW01
NET AMT
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
0001 Destination Government Destination Government 0002 Destination Government Destination Government 0003 Destination Government Destination Government 0004 Destination Government Destination Government
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC /
CAGE
0001 POP 02-JUL-2018 TO
01-NOV-2018
N/A US CYBER COMMAND
ROBERT A. SHEEHAN
USCYBERCOM ACQUISITION
9800 SAVAGE ROAD SUITE 6317
FORT MEADE MD 20755
HB0001
0002 POP 02-JUL-2018 TO
01-NOV-2018
N/A (SAME AS PREVIOUS LOCATION)
0003 POP 02-JUL-2018 TO
01-NOV-2018
N/A (SAME AS PREVIOUS LOCATION)
0004 POP 02-JUL-2018 TO
01-JUL-2019
N/A (SAME AS PREVIOUS LOCATION)
CLAUSES INCORPORATED BY REFERENCE
52.202-1 Definitions NOV 2013 52.203-3 Gratuities APR 1984 52.203-6 Restrictions On Subcontractor Sales To The Government SEP 2006 52.203-12 Limitation On Payments To Influence Certain Federal
Transactions
OCT 2010
52.203-17 Contractor Employee Whistleblower Rights and Requirement To Inform Employees of Whistleblower Rights
APR 2014
52.204-2 Security Requirements AUG 1996 52.204-4 Printed or Copied Double-Sided on Postconsumer Fiber
Content Paper
MAY 2011
52.204-7 System for Award Management OCT 2016 52.204-9 Personal Identity Verification of Contractor Personnel JAN 2011 52.204-10 Reporting Executive Compensation and First-Tier
Subcontract Awards
OCT 2016
52.204-13 System for Award Management Maintenance OCT 2016 52.204-14 Service Contract Reporting Requirements OCT 2016 52.204-16 Commercial and Government Entity Code Reporting JUL 2016 52.204-18 Commercial and Government Entity Code Maintenance JUL 2016 52.204-19 Incorporation by Reference of Representations and
Certifications.
DEC 2014
52.204-21 Basic Safeguarding of Covered Contractor Information Systems
JUN 2016
52.204-22 Alternative Line Item Proposal JAN 2017 52.209-6 Protecting the Government's Interest When Subcontracting
With Contractors Debarred, Suspended, or Proposed for Debarment
OCT 2015
52.209-7 Information Regarding Responsibility Matters JUL 2013
52.209-9 Updates of Publicly Available Information Regarding Responsibility Matters
JUL 2013
52.209-10 Prohibition on Contracting With Inverted Domestic Corporations
NOV 2015
52.210-1 Market Research APR 2011 52.212-4 Contract Terms and Conditions--Commercial Items JAN 2017 52.212-4 Alt I Contract Terms and Conditions--Commercial Items (JAN
2017) Alternate I
JAN 2017
52.215-1 Instructions to Offerors--Competitive Acquisition JAN 2017 52.215-8 Order of Precedence--Uniform Contract Format OCT 1997 52.215-19 Notification of Ownership Changes OCT 1997 52.215-22 Limitations on Pass-Through Charges--Identification of
Subcontract Effort
OCT 2009
52.215-23 Limitations on Pass-Through Charges OCT 2009 52.216-21 Requirements OCT 1995 52.219-8 Utilization of Small Business Concerns NOV 2016 52.219-16 Liquidated Damages-Subcontracting Plan JAN 1999 52.219-28 Post-Award Small Business Program Rerepresentation JUL 2013 52.222-2 Payment For Overtime Premiums JUL 1990 52.222-3 Convict Labor JUN 2003 52.222-19 Child Labor -- Cooperation with Authorities and Remedies JAN 2018 52.222-20 Contracts for Materials, Supplies, Articles, and Equipment
Exceeding $15,000
MAY 2014
52.222-21 Prohibition Of Segregated Facilities APR 2015 52.222-26 Equal Opportunity SEP 2016 52.222-26 (Dev) Equal Opportunity (Deviation 2017-O0008) SEP 2017 52.222-35 Equal Opportunity for Veterans OCT 2015 52.222-36 Equal Opportunity for Workers with Disabilities JUL 2014 52.222-36 (Dev) Equal Opportunity for Workers with Disabilites (Deviation
2017-O0008)
SEP 2017
52.222-37 Employment Reports on Veterans FEB 2016 52.222-50 Combating Trafficking in Persons MAR 2015 52.222-53 Exemption from Application of the Service Contract Labor
Standards to Contracts for Certain Services--Requirements
MAY 2014
52.222-54 Employment Eligibility Verification OCT 2015 52.223-5 Pollution Prevention and Right-to-Know Information MAY 2011 52.223-6 Drug-Free Workplace MAY 2001 52.223-18 Encouraging Contractor Policies To Ban Text Messaging
While Driving
AUG 2011
52.224-1 Privacy Act Notification APR 1984 52.224-2 Privacy Act APR 1984 52.224-3 Privacy Training JAN 2017 52.227-1 Authorization and Consent DEC 2007 52.227-2 Notice And Assistance Regarding Patent And Copyright
Infringement
DEC 2007
52.227-11 Patent Rights--Ownership By The Contractor MAY 2014 52.228-7 Insurance--Liability To Third Persons MAR 1996 52.232-7 Payments Under Time-And-Materials And Labor Hour
Contracts
AUG 2012
52.232-8 Discounts For Prompt Payment FEB 2002 52.232-17 Interest MAY 2014 52.232-20 Limitation Of Cost APR 1984 52.232-23 Assignment Of Claims MAY 2014 52.232-23 Alt I Assignment of Claims (May 2014) - Alternate I APR 1984 52.232-25 Prompt Payment JAN 2017
52.232-33 Payment by Electronic Funds Transfer--System for Award Management
JUL 2013
52.232-39 Unenforceability of Unauthorized Obligations JUN 2013 52.232-40 Providing Accelerated Payments to Small Business
Subcontractors
DEC 2013
52.233-1 Disputes MAY 2014 52.233-2 Service Of Protest SEP 2006 52.233-3 Protest After Award AUG 1996 52.233-4 Applicable Law for Breach of Contract Claim OCT 2004 52.237-2 Protection Of Government Buildings, Equipment, And
Vegetation
APR 1984
52.242-1 Notice of Intent to Disallow Costs APR 1984 52.242-3 Penalties for Unallowable Costs MAY 2014 52.242-5 Payments to Small Business Subcontractors JAN 2017 52.242-13 Bankruptcy JUL 1995 52.242-15 Stop-Work Order AUG 1989 52.243-1 Changes--Fixed Price AUG 1987 52.243-3 Changes--Time-And-Material Or Labor-Hours SEP 2000 52.243-6 Change Order Accounting APR 1984 52.244-2 Subcontracts OCT 2010 52.246-2 Inspection Of Supplies--Fixed Price AUG 1996 52.246-6 Inspection--Time-And-Material And Labor-Hour MAY 2001 52.246-16 Responsibility For Supplies APR 1984 52.246-20 Warranty Of Services MAY 2001 52.247-34 F.O.B. Destination NOV 1991 52.249-2 Termination For Convenience Of The Government (Fixed-
Price)
APR 2012
52.249-6 Termination (Cost Reimbursement) MAY 2004 52.249-8 Default (Fixed-Price Supply & Service) APR 1984 52.249-14 Excusable Delays APR 1984 52.252-2 Clauses Incorporated By Reference FEB 1998 252.201-7000 Contracting Officer's Representative DEC 1991 252.203-7000 Requirements Relating to Compensation of Former DoD
Officials
SEP 2011
252.203-7002 Requirement to Inform Employees of Whistleblower Rights SEP 2013 252.203-7004 Display of Hotline Posters OCT 2016 252.203-7005 Representation Relating to Compensation of Former DoD
Officials
NOV 2011
252.204-7000 Disclosure Of Information OCT 2016 252.204-7002 Payment For Subline Items Not Separately Priced DEC 1991 252.204-7003 Control Of Government Personnel Work Product APR 1992 252.204-7005 Oral Attestation of Security Responsibilities NOV 2001 252.204-7008 Compliance With Safeguarding Covered Defense Information
Controls
OCT 2016
252.204-7009 Limitations on the Use or Disclosure of Third-Party Contractor Reported Cyber Incident Information
OCT 2016
252.204-7012 Safeguarding Covered Defense Information and Cyber Incident Reporting
OCT 2016
252.204-7015 Notice of Authorized Disclosure of Information for Litigation Support
MAY 2016
252.205-7000 Provision Of Information To Cooperative Agreement Holders DEC 1991 252.209-7004 Subcontracting With Firms That Are Owned or Controlled By
The Government of a Country that is a State Sponsor of Terrorism
OCT 2015
252.211-7003 Item Unique Identification and Valuation MAR 2016
252.211-7008 Use of Government-Assigned Serial Numbers SEP 2010 252.215-7013 Supplies and Services Provided by Nontraditional Defense
Contractors.
JAN 2018
252.216-7002 Alt A Time-and-Materials/Labor-Hour Proposal Requirements-- Non-Commercial Item Acquisition with Adequate Price Competition Alternate A
FEB 2007
252.216-7006 Ordering MAY 2011 252.219-7003 Small Business Subcontracting Plan (DOD Contracts) APR 2018 252.223-7004 Drug Free Work Force SEP 1988 252.223-7006 Prohibition On Storage, Treatment, and Disposal of Toxic or
Hazardous Materials
SEP 2014
252.223-7007 Safeguarding Sensitive Conventional Arms, Ammunition, and Explosives
SEP 1999
252.225-7004 Report of Intended Performance Outside the United States and Canada--Submission after Award
OCT 2015
252.225-7012 Preference For Certain Domestic Commodities DEC 2017 252.226-7001 Utilization of Indian Organizations and Indian-Owned
Economic Enterprises, and Native Hawaiian Small Business Concerns
SEP 2004
252.227-7013 Rights in Technical Data--Noncommercial Items FEB 2014 252.227-7015 Technical Data--Commercial Items FEB 2014 252.227-7016 Rights in Bid or Proposal Information JAN 2011 252.227-7037 Validation of Restrictive Markings on Technical Data SEP 2016 252.231-7000 Supplemental Cost Principles DEC 1991 252.232-7003 Electronic Submission of Payment Requests and Receiving
Reports
JUN 2012
252.232-7006 Wide Area WorkFlow Payment Instructions MAY 2013 252.232-7010 Levies on Contract Payments DEC 2006 252.237-7010 Prohibition on Interrogation of Detainees by Contractor
Personnel
JUN 2013
252.239-7001 Information Assurance Contractor Training and Certification JAN 2008 252.239-7010 Cloud Computing Services OCT 2016 252.239-7017 Notice of Supply Chain Risk NOV 2013 252.239-7018 Supply Chain Risk OCT 2015 252.239-7999 (Dev) Cloud Computing Services. (DEVIATION 2015-O0011) FEB 2015 252.242-7005 Contractor Business Systems FEB 2012 252.242-7006 Accounting System Administration FEB 2012 252.243-7001 Pricing Of Contract Modifications DEC 1991 252.243-7002 Requests for Equitable Adjustment DEC 2012 252.244-7000 Subcontracts for Commercial Items JUN 2013 252.246-7000 Material Inspection And Receiving Report MAR 2008 252.247-7023 Transportation of Supplies by Sea APR 2014
CLAUSES INCORPORATED BY FULL TEXT
52.219-4 NOTICE OF PRICE EVALUATION PREFERENCE FOR HUBZONE SMALL BUSINESS
CONCERNS (OCT 2014)
(a) Definitions. See 13 CFR 125.6(e) for definitions of terms used in paragraph (d).
(b) Evaluation preference. (1) Offers will be evaluated by adding a factor of 10 percent to the price of all offers, except--
(i) Offers from HUBZone small business concerns that have not waived the evaluation preference; and
(ii) Otherwise successful offers from small business concerns.
(2) The factor of 10 percent shall be applied on a line item basis or to any group of items on which award may be made. Other evaluation factors described in the solicitation shall be applied before application of the factor.
(3) When the two highest rated offerors are a HUBZone small business concern and a large business, and the evaluated offer of the HUBZone small business concern is equal to the evaluated offer of the large business after considering the price evaluation preference, award will be made to the HUBZone small business concern.
(c) Waiver of evaluation preference. A HUBZone small business concern may elect to waive the evaluation preference, in which case the factor will be added to its offer for evaluation purposes. The agreements in paragraphs
(d) and (e) of this clause do not apply if the offeror has waived the evaluation preference.
___ Offeror elects to waive the evaluation preference.
(d) Agreement. A HUBZone small business concern agrees that in the performance of the contract, in the case of a contract for
(1) Services (except construction), at least 50 percent of the cost of personnel for contract performance will be spent for employees of the concern or employees of other HUBZone small business concerns;
(2) Supplies (other than procurement from a nonmanufacturer of such supplies), at least 50 percent of the cost of manufacturing, excluding the cost of materials, will be performed by the concern or other HUBZone small business concerns;
(3) General construction. (i) At least 15 percent of the cost of contract performance to be incurred for personnel will be spent on the prime contractor's employees;
(ii) At least 50 percent of the cost of the contract performance to be incurred for personnel will be spent on the prime contractor's employees or on a combination of the prime contractor's employees and employees of HUBZone small business concern subcontractors;
(iii) No more than 50 percent of the cost of contract performance to be incurred for personnel will be subcontracted to concerns that are not HUBZone small business concerns; or
(4) Construction by special trade contractors. (i) At least 25 percent of the cost of contract performance to be incurred for personnel will be spent on the prime contractor's employees;
(ii) At least 50 percent of the cost of the contract performance to be incurred for personnel will be spent on the prime contractor's employees or on a combination of the prime contractor's employees and employees of HUBZone small business concern subcontractors;
(iii) No more than 50 percent of the cost of contract performance to be incurred for personnel will be subcontracted to concerns that are not HUBZone small business concerns.
(e) A HUBZone joint venture agrees that the aggregate of the HUBZone small business concerns to the joint venture, not each concern separately, will perform the applicable percentage of work requirements.
(f)(1) When the total value of the contract exceeds $25,000, a HUBZone small business concern nonmanufacturer agrees to furnish in performing this contract only end items manufactured or produced by HUBZone small business concern manufacturers.
(2) When the total value of the contract is equal to or less than $25,000, a HUBZone small business concern nonmanufacturer may provide end items manufactured by other than a HUBZone small business concern manufacturer provided the end items are produced or manufactured in the United States.
(3) Paragraphs (f)(1) and (f)(2) of this section do not apply in connection with construction or service contracts.
(g) Notice. The HUBZone small business offeror acknowledges that a prospective HUBZone awardee must be a HUBZone small business concern at the time of award of this contract. The HUBZone offeror shall provide the Contracting Officer a copy of the notice required by 13 CFR 126.501 if material changes occur before contract award that could affect its HUBZone eligibility. If the apparently successful HUBZone offeror is not a HUBZone small business concern at the time of award of this contract, the Contracting Officer will proceed to award to the next otherwise successful HUBZone small business concern or other offeror.
(End of clause)
52.225-25 PROHIBITION ON CONTRACTING WITH ENTITIES ENGAGING IN CERTAIN ACTIVITIES OR
TRANSACTIONS RELATING TO IRAN--REPRESENTATION AND CERTIFICATIONS. (OCT 2015)
(a) Definitions. As used in this provision--
Person--
(1) Means--
(i) A natural person;
(ii) A corporation, business association, partnership, society, trust, financial institution, insurer, underwriter, guarantor, and any other business organization, any other nongovernmental entity, organization, or group, and any governmental entity operating as a business enterprise; and
(iii) Any successor to any entity described in paragraph (1)(ii) of this definition; and
(2) Does not include a government or governmental entity that is not operating as a business enterprise.
Sensitive technology--
(1) Means hardware, software, telecommunications equipment, or any other technology that is to be used specifically--
(i) To restrict the free flow of unbiased information in Iran; or
(ii) To disrupt, monitor, or otherwise restrict speech of the people of Iran; and
(2) Does not include information or informational materials the export of which the President does not have the authority to regulate or prohibit pursuant to section 203(b)(3) of the International Emergency Economic Powers Act (50 U.S.C. 1702(b)(3)).
(b) The offeror shall email questions concerning sensitive technology to the Department of State at CISADA106@state.gov.
(c) Except as provided in paragraph (d) of this provision or if a waiver has been granted in accordance with 25.703- 4, by submission of its offer, the offeror—
(1) Represents, to the best of its knowledge and belief, that the offeror does not export any sensitive technology to the government of Iran or any entities or individuals owned or controlled by, or acting on behalf or at the direction of, the government of Iran;
(2) Certifies that the offeror, or any person owned or controlled by the offeror, does not engage in any activities for which sanctions may be imposed under section 5 of the Iran Sanctions Act. These sanctioned activities are in the areas of development of the petroleum resources of Iran, production of refined petroleum products in Iran, sale and provision of refined petroleum products to Iran, and contributing to Iran's ability to acquire or develop certain weapons or technologies; and
(3) Certifies that the offeror, and any person owned or controlled by the offeror, does not knowingly engage in any transaction that exceeds $3,500 with Iran's Revolutionary Guard Corps or any of its officials, agents, or affiliates, the property and interests in property of which are blocked pursuant to the International Emergency Economic Powers Act (50 U.S.C. 1701 et seq.) (see OFAC's Specially Designated Nationals and Blocked Persons List at http://www.treasury.gov/ofac/downloads/t11sdn.pdf).
(d) Exception for trade agreements. The representation requirement of paragraph (c)(1) and the certification requirements of paragraphs (c)(2) and (c)(3) of this provision do not apply if—
(1) This solicitation includes a trade agreements notice or certification (e.g., 52.225-4, 52.225-6, 52.225-12, 52.225- 24, or comparable agency provision); and
(2) The offeror has certified that all the offered products to be supplied are designated country end products or designated country construction material.
(End of provision)
252.204-7012 SAFEGUARDING COVERED DEFENSE INFORMATION AND CYBER INCIDENT
REPORTING (OCT 2016)
(a) Definitions. As used in this clause--
Adequate security means protective measures that are commensurate with the consequences and probability of loss, misuse, or unauthorized access to, or modification of information.
Compromise means disclosure of information to unauthorized persons, or a violation of the security policy of a system, in which unauthorized intentional or unintentional disclosure, modification, destruction, or loss of an object, or the copying of information to unauthorized media may have occurred.
Contractor attributional/proprietary information means information that identifies the contractor(s), whether directly or indirectly, by the grouping of information that can be traced back to the contractor(s) (e.g., program description, facility locations), personally identifiable information, as well as trade secrets, commercial or financial information, or other commercially sensitive information that is not customarily shared outside of the company.
Controlled technical information means technical information with military or space application that is subject to controls on the access, use, reproduction, modification, performance, display, release, disclosure, or dissemination.
Controlled technical information would meet the criteria, if disseminated, for distribution statements B through F using the criteria set forth in DoD Instruction 5230.24, Distribution Statements on Technical
Documents. The term does not include information that is lawfully publicly available without restrictions.
Covered contractor information system means an unclassified information system that is owned, or operated by or for, a contractor and that processes, stores, or transmits covered defense information.
Covered defense…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .