ServiceNow_SOW_General_Provisions_final.pdf

PDF 766 KB Posted

Attached to
ServiceNow Federal contract opportunity
Solicitation number
HB0001-18-R-0012
Issued by
Department of Defense Cyber Command

About this file

ServiceNow SOW General Provisions final

View the file

Other files for this federal contract opportunity

Other files attached to ServiceNow, newest first.
File Type Posted
HB0001-18-R-0012-P0002.pdf PDF
ServiceNow_RFP_Questions_V2.docx DOCX document
HB0001-18-R-0012-P0001.pdf PDF
RFP_Questions.pdf PDF
Religious_Mission_Trip_February_2015.pdf PDF
CS_050515_eform.pdf PDF
HB000118R0012.pdf PDF
SF312.pdf PDF
SSO_Toolkit_SOW_final.pdf PDF
SCI_ATTESTATION.pdf PDF
Questionaire_Response_Attachment_20180119.pdf PDF
US_Cyber_Command_Pre_Screen_Notice_20180308.pdf PDF
FY18_Software_Order.pdf PDF
Source_Selection_Plan_-_Service_Now.pdf PDF
FORM_4414_Rev_12-2013_fillable_(Savable).pdf PDF
Asset_Config_Management_SOW_Final.pdf PDF
10-SIP_Instructions.pdf PDF
ACS_050515_eform.pdf PDF
J6_forms.pdf PDF
SIP_050515_eform.pdf PDF
SSO_Toolkit_CONOPS_final.pdf PDF
Language_Immersion_Trip_February_2015.pdf PDF
Foreign_Travel_Questionnaire.pdf PDF
HR_Toolkit_Conops__Task_Management.pdf PDF
Asset_Config_Management_Conops_Final.pdf PDF
SCI_Pre_Screen_Questionaire_DEC_2017.pdf PDF
SCI_Reporting_Memo.pdf PDF
HR_Toolkit_Process_Flows_Final.pdf PDF
HR_Toolkit_SOW_FINAL.pdf PDF
Show all 29

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

BPA SOW Page 1 of 13 05/22/18

United States Cyber Command

ServiceNow Blanket Purchase Agreement

Statement of Work

May 22, 2018

BPA SOW Page 2 of 13 05/22/18

Contents

1. Introduction

2. Background

3. Scope

4. Labor Categories

5. Section 508 Compliance

6. Place of Performance

7. Vendor Requirements

7.1. ServiceNow Expertise

7.2. United States Owned Company or Subsidiary

7.3. Key Staff

7.4. Availability of Staff

7.5. Staff Training/Certification

8. Period of Performance

9. Contract Type

10. Security Requirements – Information Security and other miscellaneous requirements

11. Government Furnished Equipment

12. Travel

13. Supply Chain Risk Management (SCRM)

BPA SOW Page 3 of 13 05/22/18

1. Introduction

United States Cyber Command (USCYBERCOM) plans, coordinates, integrates, synchronizes and conducts activities to: direct the operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our adversaries.

The Command has three main focus areas: Defending the DoDIN, providing support to combatant commanders for execution of their missions around the world, and strengthening our nation's ability to withstand and respond to cyber attack.

The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate resilient, reliable information and communication networks, counter cyberspace threats, and assure access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and certification standards that will enable the Services to build the cyber force required to execute our assigned missions. The command also works closely with interagency and international partners in executing these critical missions.

2. Background As part of this elevation to a combatant command, USCYBERCOM must implement policies, processes, procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. USCYBERCOM plans to utilize ServiceNow capabilities as a set of tools to become compliant with the CCA through the implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging the ServiceNow

Now Platform workflow and task management capabilities to provide automated, data driven applications to support to the internal operations of USCYBERCOM as well as the operational mission needs.

3. Scope The contractor shall provide services and software to support specific implementation(s) of the

ServiceNow products at USCYBERCOM. The contractor shall implement:

Develop data driven applications, specific to USCYBERCOM operational needs, test and integrate the applications onto various platforms;

Implement the Information Technology Service Management (ITSM) processes within

USCYBERCOM utilizing the capabilities of ServiceNow.

BPA SOW Page 4 of 13 05/22/18

The contractor shall provide support in the following areas:

1. Asset Management

2. Configuration Management

3. Incident Management

4. Problem Management

5. Change Management

6. Knowledge Management

7. Release Management

8. Requirements Management

9. Service Desk

10. Service Catalogue

11. Service Level Management

12. J1 HR/SSO Toolkit

13. HQ OPS Support

14. Operations & Maintenance

15. Surge Support

16. Training

4. Labor Categories USCYBERCOM recognizes that a successful implementation of ServiceNow will require a range of skills and expertise provided by the vendor’s staff. USCBYERCOM has identified the required skills and corresponding experience levels of these skills in the section below. Below the table, is a clarification of the required skills and other qualifications associated with each USCYBERCOM ServiceNow Labor

Category. The vendor will identify the proposed labor category from their GSA IT Schedule 70 for each of these USCYBERCOM defined Labor Categories.

4.1. Information Systems Security Engineer (ISSE):

The ISSE will be responsible for leading and writing documentation in support of the ServiceNow installation and any custom applications obtaining an Authorization To Operate (ATO). The ISSE must possess:

a) DoD 8570-M certification (IASAE Level II)

b) Minimum ten (10) years IT experience

c) Four (4) years experience as an ISSE

d) Experience designing, documenting and implementing a wide range of security controls.

e) Experience writing documentation in support of obtaining an ATO implementing NIST Special

Publication 800-53 and 800-37

f) Active TS/SCI with CI/Poly

g) Familiarization/experience with XACTA – desirable, not required

h) Strong written, analytical and oral communication skills

BPA SOW Page 5 of 13 05/22/18

4.2. AWS Cloud Architect

The AWS Cloud Architect will work with the ServiceNow SME and USCYBERCOM’s architecture and engineering division to recommend an AWS Cloud based architecture for hosting the ServiceNow instances in each of the different security enclaves (unclassified, secret and Top Secret). The proposed architecture will integrate into the existing USCYBERCOM AWS cloud architectures leveraging common services and identifying ServiceNow unique cloud hosting requirements. The AWS Cloud Architect must possess:

a) Minimum ten (10) years IT experience.

b) Minimum of two (2) successful ServiceNow AWS private cloud or hybrid cloud deployments.

c) Proven ability to architect, design and implement cloud-based and/or cloud-native solutions to include identity and access management.

d) Experience working with users to gather requirements, writing functional and technical specifications and communicating technical requirements .

e) Hands-on experience configuring supporting common infrastructure roles and tools (e.g.: DNS, NTP, Group Policy, Active Directory/ADFS, Web Application Firewalls, logging services, web proxies, etc.).

f) Hands-on experience with infrastructure as code concepts and related software highly preferred

(e.g. Chef, Puppet, CloudFormation, Terraform, JSON).

g) Practical experience sizing hardware and storage needs.

h) AWS: Certified Solutions Architect – Professional.

4.3. ServiceNow Subject Matter Expert (SME):

The ServiceNow SME sets the strategic direction for the implementation of ServiceNow within

USCYBERCOM across all three security domains (unclassified, secret and top secret) defining and implementing an architecture that supports USCYBERCOM’s objectives. The SME is the expert on the functionality within ServiceNow and recommends best practices to USCYBERCOM associated with the implementation of each ServiceNow feature. The SME must possess:

i) Minimum ten (10) years IT experience.

j) Minimum of six (6) successful ServiceNow deployments of ITSM and/or workflow applications using ServiceNow. Preferred to have three (3) with US Government agencies.

k) Experience in implementing large-scale custom development and/or systems integration projects in one or more phases of the Software Development Life Cycle (SDLC).

l) Experience working with users to gather requirements, writing functional and technical specifications and communicating technical requirements.

m) Administering and developing within ServiceNow.

n) Demonstrated experience in:

i) Creating and configuring forms and screen updates using ServiceNow and/or Java

ii) Creating, updating and maintaining JavaScript, AngularJS

iii) Experience with identity and access management, including use of MS Active Directory and lightweight directory access protocol (LDAP)

BPA SOW Page 6 of 13 05/22/18

iv) Experience in ServiceNow Deployment API’s

o) ITIL Certification.

p) Minimum two (2) ServiceNow certifications.

4.4. ServiceNow Developer – Senior

The ServiceNow Developer – Senior will lead the development team as they implement ServiceNow features in conjunction with the ServiceNow SME. The ServiceNow Developer – Senior is responsible for the successful deployment of ServiceNow within USCYBERCOM. The ServiceNow Developer – Senior is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. ServiceNow Developer – Senior is the primary technical interface to the USCYBERCOM project manager and/or Contract Officer’s Representative (COR). Key skills the ServiceNow Developer –

Senior must possess at time of starting the project:

a) Minimum ten (10) years IT experience.

b) Minimum of four (4) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow. Prefer to have two (2) which are to US Government agencies.

c) Ability to create and configure forms and screen updates using ServiceNow and/or AngularJS, JavaScript, Jelly, .NET.

d) Minimum of two (2) years experience implementing and maintaining identity and access management, including use of MS Active Directory, LDAP and Single Sign On (SSO).

e) Minimum of four (4) years experience developing using Java, Java Script, AngularJS or .Net experience.

f) Minimum two (2) ServiceNow certifications.

4.5. ServiceNow Developer – Mid

The ServiceNow Developer – Mid will participate as a member of the development team as they implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior.

The ServiceNow Developer – Mid is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. The ServiceNow Developer – Mid must possess:

a) Minimum of four (4) years experience developing applications.

b) Minimum of two (2) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow.

c) Minimum of two (2) years experience developing using Java, Java Script, AngularJS or .Net experience.

d) Minimum of two (2) years experience web services integration using SOAP, REST JSON or similar technologies.

e) Minimum one (1) ServiceNow certification.

BPA SOW Page 7 of 13 05/22/18

4.6. ServiceNow Developer – Junior

The ServiceNow Developer – Junior will participate as a member of the development team as they implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior.

The ServiceNow Developer – Junior is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. The ServiceNow Developer – Junior must possess:

a) Minimum of two (2) years experience developing and/or implementing ServiceNow.

b) Minimum of one (1) year of experience developing using Java, Java Script, AngularJS, Jelly or

.Net experience.

4.7. Business Analyst – Senior

Primary point of contact with the user community to identify and clarify problem(s) to be solved through the use of ServiceNow application features. Will lead user community in structured meeting using industry standard requirements processes, such as use cases or Business Process Model and Notation

(BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and others. The Business Analyst – Senior is an expert on the functional capabilities of ServiceNow and is a visionary mapping user needs to solutions. The Business Analyst – Senior must possess:

a) Minimum ten (10) years IT experience

b) Minimum of four (4) successful ServiceNow deployments, including ITSM and building user applications using ServiceNow. Prefer to have two (2) that are to US Government agencies.

c) Minimum one (1) ServiceNow certification.

Desired skills for the Business Analyst – Senior are:

d) Ability to convert users’ needs to technical requirements.

e) Strong verbal skills, ability to present to senior leadership.

f) Strong technical writing skills.

4.8. Business Analyst – Mid

Performs under the guidance of the Business Analyst – Senior to identify and clarify problem(s) to be solved through the use of ServiceNow application features. Will lead user community in structured meeting using industry standard requirements processes, such as use cases or Business Process Model and Notation (BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and others. The Business Analyst – Mid is an knowledgeable on the functional capabilities of ServiceNow. The Business Analyst – Mid must possess:

g) Minimum six (6) years IT experience.

h) Minimum of two (2) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow. Prefer to have two (2) which are to US Government agencies.

Desired skills for the Business Analyst – Mid are:

BPA SOW Page 8 of 13 05/22/18

i) Ability to convert users’ needs to technical requirements.

j) Strong verbal skills, ability to present to senior leadership.

k) Strong technical writing skills.

5. Place of Performance USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755.

All work will be performed at USCYBERCOM’s offices within the greater Ft. Meade, Maryland area or at the contractors facility. Specific work locations will be designated in each order.

6. Vendor Requirements

6.1. ServiceNow Expertise

Vendors who wish to submit a bid, must be a ServiceNow Gold Services certified partner. The

ServiceNow Gold Services certified partner must be the prime for the contract.

6.2. United States Owned Company or Subsidiary

Vendors who wish to submit a bid, must be a United States wholly owned company or subsidiary.

6.3. Key Staff

Vendors will propose which staff/labor categories shall be key position. Contractor shall provide prior written notification of the replacement of any key staff to the CO. Key staff must hold an active Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter Intelligence

Polygraph (CI/Poly), TS/SCI with CI/Poly.

7. Ordering Period The contract shall be five (5) years. Each order will have a specific period of performance.

8. Contract Type There will be multiple orders for this contract. Each order will identify whether it is a firm fixed price or Time and Materials order.

9. Security Requirements – Information Security and other miscellaneous requirements

9.1. Personnel:

9.1.1. Personnel Security Requirements: Each order will detail the specific personnel security requirements.

9.1.2. Information Security Staff: Staff who will be responsible for the development of system security plan and its artifacts must possess an active TS/SCI with CI/Poly at the time of order award start.

BPA SOW Page 9 of 13 05/22/18

9.1.3. Operations and Maintenance: Personnel supporting the operations and maintenance activities (work location is USCYBERCOM offices), must hold an active TS/SCI with CI polygraph.

9.1.4. System Administrators: staff who may be system administrators or require elevated network or systems access under the operations and maintenance CLINS or surge CLINS, must comply with DoD 8570.01M requirements AND possess an active TS/SCI with CI polygraph.

9.2. Facility Security Clearance. The work to be performed under this contract is up to the Top

Secret level and will require Sensitive Compartmented Information (SCI) access eligibility for some personnel. Therefore the company must have a final Top Secret Facility Clearance from the Defense Security Service Facility Clearance Branch.

9.3. Contractor personnel shall comply with all local security requirements including entry and exit control for personnel and property at the government facility.

9.4. Contractor employees shall be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by

Government. Failure to comply with Government security regulations and requirements shall require the company to provide the Government with a written remediation/corrective action plan; furthermore, failure to comply with such requirements can be cause for removal and the contractor will not be able to provide service on this contract/order.

9.5. Contractor employees with an incident report in Joint Personnel Adjudication System (JPAS) or its replacement system (Defense Information System for Security (DISS) Joint Verification

System (JVS)) who have had their access to classified information suspended will not be permitted to fill positions under this contract/order.

9.6. The Contractor shall not divulge any information, classified or unclassified, about

USCYBERCOM, DoD or National Security Agency (NSA) files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the DoD/NSA facility. Identification shall be worn and displayed as required at all times.

9.7. USCYBERCOM retains the right to request removal of contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, conflict with the interest of the Government.

9.8. Contractor personnel will generate or handle documents that contain For Official Use Only information at the Contractor and/or Government facility. Contractor shall have access to, generate, and handle classified material only at the location(s) listed in the place of performance section of this document. All contractor deliverables shall be marked in accordance with DoDM 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of

Information Act Program, unless otherwise directed by the Government. The contractor shall comply with the provisions of the DoD Industrial Security Manual for handling classified material and producing deliverables. Additionally, the contractor shall comply with

USCYBERCOM security policies.

9.9. The Contractor shall afford the Government access to the contractor’s facilities, installations, operations, documentation, databases and personnel used in performance of the contract.

Access shall be provided to the extent required to carry out a program of IT inspection (to

BPA SOW Page 10 of 13 05/22/18 include vulnerability testing), investigation and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of data or to the function of information technology systems operated on behalf of USCYBERCOM or DoD, and to preserve evidence of computer crime

9.10. Identification of Non-Disclosure Agreements (NDA): All USCYBERCOM Contractors must execute a USCYBERCOM-provided contractor non-disclosure agreement (NDA) for all services contracts regardless of award amount. The NDA must be signed within one week of contract/TO award. When a new contractor joins the contract, the NDA must be signed by the individual before being approved to work on the contract. The USCYBERCOM contractor is responsible for obtaining and maintaining NDAs for each contractor employee assigned to the contract. Copies of the signed NDA will be provided to the COR.

9.11. DD254

A DD254 documenting contract security requirements will be issued upon contract award and incorporated by reference.

10. Government Furnished Equipment Vendor shall provide all equipment, information, workspace and other facilities at vendor’s worksite. Any deviations to this shall be listed in the specific order(s).

11. Travel Local travel will be required, but not reimbursed by the government. Local travel is defined as a

50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755.

12. Training The contractor shall provide personnel that are qualified to meet all requirements of the statement of work. Any training available at a commercial source shall be considered to be of general utility to the Contractor and the course, labor and travel costs are note to be billed to the Government.

Training will be provided by the government only when such software/systems are uniquely designed/fabricated by, or for, the Government and such training is otherwise unavailable to the

Contractor. Courses conducted by Government schools may be made available to Contractor personnel where it has been clearly determined by the Contracting Officer (in writing) that training on specialized or unique government equipment is essential in carrying out the terms of the contract and the training is otherwise unavailable from commercial source.

13. Supply Chain Risk Management (SCRM)

This vendor and its associated delivery/task orders are subject to the Federal SCRM policies and regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017

Notice of Supply Chain Risk, 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of

Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA

Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and

BPA SOW Page 11 of 13 05/22/18

Procedures. Each individual delivery and/or task order will submit a SCRM Plan as part of the technical proposal, which addresses, at a minimum, Supply Chain Security Controls as specified in the delivery/task order and described in the Committee on National Security Systems Instruction (CNSSI)

1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST)

Special Publications (SP)).

The vendor shall submit a SCRM plan as part of its technical proposal that describes how the vendor will reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in

CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract.

Control

Number

HW SW Srvc

SA-12 Supply Chain Protection x x x

SA-12(1) Supply Chain Protection / Acquisition Strategies / Tools / Methods x x x*

SA-12(2) Supply Chain Protection / Supplier Reviews x x x*

SA-12(5) Supply Chain Protection / Limitation of Harm x x x*

SA-12 (7) Supply Chain Protection Assessments Prior to Selection / Acceptance/

Update x x x*

SA-12 (8) Supply Chain Protection / Use of All-Source Intelligence x x x*

SA-12 (9) Supply Chain Protection / Operations Security x x x

SA-12 (10) Supply Chain Protection / Validate as Genuine and Not Altered x x x*

SA-12 (11) Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors x x x

SA-12 (12) Supply Chain Protection / Inter-Organizational System Components x x x

SA-12 (13) Supply Chain Protection / Critical Information System Components x x x*

SA-12 (14) Supply Chain Protection / Identity and Traceability x x x*

SA-12 (15) Supply Chain Protection / Process to Address Weaknesses or

Deficiencies x x x

IR-4 (10) Incident Handling / Supply Chain Coordination x x x*

IR-6 (3) Supply Chain Protection / Incident Reporting / Coordination With

Supply Chain x x x*

SA-11 Developer Security Testing and Evaluation x x x*

SA-14 Criticality Analysis x x x*

BPA SOW Page 12 of 13 05/22/18

SA-15 Development Process, Standards, and Tools x x x*

SI-7 Software, Firmware, and Information Integrity x x x*

CM-4 Security Impact x x x*

PM-16 Threat Awareness Program x x x

*Not required if there will be no procurement of hardware, firmware, or software systems.

13.1. SCRM Deliverables:

SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The vendor shall provide an updated SCRM Plan to the COR and Program Manager within five (5) business days whenever there is a change that affects one or more security controls as described in the Committee on National Security Systems Instructions

(CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology

(NIST) Special Publications (SP)). At a minimum the following events substantiate the need for an update: changes in company ownership, changes in senior company leadership, supplier changes, subcontractor changes, and ICT supply chain compromises.

Vendor employees may be required to take periodic mandatory training courses provided through the agency, such as records management training and other training required by statute, regulation, DoD, or DISA policy. (Note if there are specific courses you will require from your contractors, insert those here.) No other training of contractor personnel shall be provided by the Government unless authorized by the Contracting Officer.

14. Section 508 Accessibility Standards.

The vendor shall complete all requirements of this statement of work in accordance with the following

Section 508 standards of the Rehabilitation Act of 1973. The following Section 508 Accessibility

Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) to this acquisition.

Technical Standards

1194.21 - Software Applications and Operating Systems

1194.22 - Web Based Intranet and Internet Information and Applications

1194.23 - Telecommunications Products

1194.24 - Video and Multimedia Products

1194.25 - Self-Contained, Closed Products

1194.26 - Desktop and Portable Computers

BPA SOW Page 13 of 13 05/22/18

1194.41 - Information, Documentation and Support

The Technical Standards above facilitate the assurance that the maximum technical standards are provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic and information technology (E&IT) products are proposed.

Functional Performance Criteria

1194.31 - Functional Performance Criteria

File details come from the government source that posted it. Updated .