ServiceNow_SOW_General_Provisions_final.pdf
PDF 766 KB Posted
- Attached to
- ServiceNow Federal contract opportunity
- Solicitation number
- HB0001-18-R-0012
- Issued by
- Department of Defense Cyber Command
About this file
ServiceNow SOW General Provisions final
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
BPA SOW Page 1 of 13 05/22/18
United States Cyber Command
ServiceNow Blanket Purchase Agreement
Statement of Work
May 22, 2018
BPA SOW Page 2 of 13 05/22/18
Contents
1. Introduction
2. Background
3. Scope
4. Labor Categories
5. Section 508 Compliance
6. Place of Performance
7. Vendor Requirements
7.1. ServiceNow Expertise
7.2. United States Owned Company or Subsidiary
7.3. Key Staff
7.4. Availability of Staff
7.5. Staff Training/Certification
8. Period of Performance
9. Contract Type
10. Security Requirements – Information Security and other miscellaneous requirements
11. Government Furnished Equipment
12. Travel
13. Supply Chain Risk Management (SCRM)
BPA SOW Page 3 of 13 05/22/18
1. Introduction
United States Cyber Command (USCYBERCOM) plans, coordinates, integrates, synchronizes and conducts activities to: direct the operations and defense of specified Department of Defense (DoD) information networks (DoDIN) and; prepare to, and when directed, conduct full spectrum military cyberspace operations in order to enable actions in all domains, ensure US/Allied freedom of action in cyberspace and deny the same to our adversaries.
The Command has three main focus areas: Defending the DoDIN, providing support to combatant commanders for execution of their missions around the world, and strengthening our nation's ability to withstand and respond to cyber attack.
The Command unifies the direction of cyberspace operations, strengthens DoD cyberspace capabilities, and integrates and bolsters DoD's cyber expertise. USCYBERCOM improves DoD's capabilities to operate resilient, reliable information and communication networks, counter cyberspace threats, and assure access to cyberspace. USCYBERCOM is designing the cyber force structure, training requirements and certification standards that will enable the Services to build the cyber force required to execute our assigned missions. The command also works closely with interagency and international partners in executing these critical missions.
2. Background As part of this elevation to a combatant command, USCYBERCOM must implement policies, processes, procedures and tools to be compliant with the Clinger Cohen Act (CCA) of 1996. USCYBERCOM plans to utilize ServiceNow capabilities as a set of tools to become compliant with the CCA through the implementation of ITIL processes. Additionally, USCYBERCOM also will be leveraging the ServiceNow
Now Platform workflow and task management capabilities to provide automated, data driven applications to support to the internal operations of USCYBERCOM as well as the operational mission needs.
3. Scope The contractor shall provide services and software to support specific implementation(s) of the
ServiceNow products at USCYBERCOM. The contractor shall implement:
Develop data driven applications, specific to USCYBERCOM operational needs, test and integrate the applications onto various platforms;
Implement the Information Technology Service Management (ITSM) processes within
USCYBERCOM utilizing the capabilities of ServiceNow.
BPA SOW Page 4 of 13 05/22/18
The contractor shall provide support in the following areas:
1. Asset Management
2. Configuration Management
3. Incident Management
4. Problem Management
5. Change Management
6. Knowledge Management
7. Release Management
8. Requirements Management
9. Service Desk
10. Service Catalogue
11. Service Level Management
12. J1 HR/SSO Toolkit
13. HQ OPS Support
14. Operations & Maintenance
15. Surge Support
16. Training
4. Labor Categories USCYBERCOM recognizes that a successful implementation of ServiceNow will require a range of skills and expertise provided by the vendor’s staff. USCBYERCOM has identified the required skills and corresponding experience levels of these skills in the section below. Below the table, is a clarification of the required skills and other qualifications associated with each USCYBERCOM ServiceNow Labor
Category. The vendor will identify the proposed labor category from their GSA IT Schedule 70 for each of these USCYBERCOM defined Labor Categories.
4.1. Information Systems Security Engineer (ISSE):
The ISSE will be responsible for leading and writing documentation in support of the ServiceNow installation and any custom applications obtaining an Authorization To Operate (ATO). The ISSE must possess:
a) DoD 8570-M certification (IASAE Level II)
b) Minimum ten (10) years IT experience
c) Four (4) years experience as an ISSE
d) Experience designing, documenting and implementing a wide range of security controls.
e) Experience writing documentation in support of obtaining an ATO implementing NIST Special
Publication 800-53 and 800-37
f) Active TS/SCI with CI/Poly
g) Familiarization/experience with XACTA – desirable, not required
h) Strong written, analytical and oral communication skills
BPA SOW Page 5 of 13 05/22/18
4.2. AWS Cloud Architect
The AWS Cloud Architect will work with the ServiceNow SME and USCYBERCOM’s architecture and engineering division to recommend an AWS Cloud based architecture for hosting the ServiceNow instances in each of the different security enclaves (unclassified, secret and Top Secret). The proposed architecture will integrate into the existing USCYBERCOM AWS cloud architectures leveraging common services and identifying ServiceNow unique cloud hosting requirements. The AWS Cloud Architect must possess:
a) Minimum ten (10) years IT experience.
b) Minimum of two (2) successful ServiceNow AWS private cloud or hybrid cloud deployments.
c) Proven ability to architect, design and implement cloud-based and/or cloud-native solutions to include identity and access management.
d) Experience working with users to gather requirements, writing functional and technical specifications and communicating technical requirements .
e) Hands-on experience configuring supporting common infrastructure roles and tools (e.g.: DNS, NTP, Group Policy, Active Directory/ADFS, Web Application Firewalls, logging services, web proxies, etc.).
f) Hands-on experience with infrastructure as code concepts and related software highly preferred
(e.g. Chef, Puppet, CloudFormation, Terraform, JSON).
g) Practical experience sizing hardware and storage needs.
h) AWS: Certified Solutions Architect – Professional.
4.3. ServiceNow Subject Matter Expert (SME):
The ServiceNow SME sets the strategic direction for the implementation of ServiceNow within
USCYBERCOM across all three security domains (unclassified, secret and top secret) defining and implementing an architecture that supports USCYBERCOM’s objectives. The SME is the expert on the functionality within ServiceNow and recommends best practices to USCYBERCOM associated with the implementation of each ServiceNow feature. The SME must possess:
i) Minimum ten (10) years IT experience.
j) Minimum of six (6) successful ServiceNow deployments of ITSM and/or workflow applications using ServiceNow. Preferred to have three (3) with US Government agencies.
k) Experience in implementing large-scale custom development and/or systems integration projects in one or more phases of the Software Development Life Cycle (SDLC).
l) Experience working with users to gather requirements, writing functional and technical specifications and communicating technical requirements.
m) Administering and developing within ServiceNow.
n) Demonstrated experience in:
i) Creating and configuring forms and screen updates using ServiceNow and/or Java
ii) Creating, updating and maintaining JavaScript, AngularJS
iii) Experience with identity and access management, including use of MS Active Directory and lightweight directory access protocol (LDAP)
BPA SOW Page 6 of 13 05/22/18
iv) Experience in ServiceNow Deployment API’s
o) ITIL Certification.
p) Minimum two (2) ServiceNow certifications.
4.4. ServiceNow Developer – Senior
The ServiceNow Developer – Senior will lead the development team as they implement ServiceNow features in conjunction with the ServiceNow SME. The ServiceNow Developer – Senior is responsible for the successful deployment of ServiceNow within USCYBERCOM. The ServiceNow Developer – Senior is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. ServiceNow Developer – Senior is the primary technical interface to the USCYBERCOM project manager and/or Contract Officer’s Representative (COR). Key skills the ServiceNow Developer –
Senior must possess at time of starting the project:
a) Minimum ten (10) years IT experience.
b) Minimum of four (4) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow. Prefer to have two (2) which are to US Government agencies.
c) Ability to create and configure forms and screen updates using ServiceNow and/or AngularJS, JavaScript, Jelly, .NET.
d) Minimum of two (2) years experience implementing and maintaining identity and access management, including use of MS Active Directory, LDAP and Single Sign On (SSO).
e) Minimum of four (4) years experience developing using Java, Java Script, AngularJS or .Net experience.
f) Minimum two (2) ServiceNow certifications.
4.5. ServiceNow Developer – Mid
The ServiceNow Developer – Mid will participate as a member of the development team as they implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior.
The ServiceNow Developer – Mid is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. The ServiceNow Developer – Mid must possess:
a) Minimum of four (4) years experience developing applications.
b) Minimum of two (2) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow.
c) Minimum of two (2) years experience developing using Java, Java Script, AngularJS or .Net experience.
d) Minimum of two (2) years experience web services integration using SOAP, REST JSON or similar technologies.
e) Minimum one (1) ServiceNow certification.
BPA SOW Page 7 of 13 05/22/18
4.6. ServiceNow Developer – Junior
The ServiceNow Developer – Junior will participate as a member of the development team as they implement ServiceNow features under the direction and guidance of the ServiceNow Developer - Senior.
The ServiceNow Developer – Junior is responsible for application user interface configuration and development, workflow configuration, development of USCYBERCOM specific applications, and integration with other USCYBERCOM applications. The ServiceNow Developer – Junior must possess:
a) Minimum of two (2) years experience developing and/or implementing ServiceNow.
b) Minimum of one (1) year of experience developing using Java, Java Script, AngularJS, Jelly or
.Net experience.
4.7. Business Analyst – Senior
Primary point of contact with the user community to identify and clarify problem(s) to be solved through the use of ServiceNow application features. Will lead user community in structured meeting using industry standard requirements processes, such as use cases or Business Process Model and Notation
(BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and others. The Business Analyst – Senior is an expert on the functional capabilities of ServiceNow and is a visionary mapping user needs to solutions. The Business Analyst – Senior must possess:
a) Minimum ten (10) years IT experience
b) Minimum of four (4) successful ServiceNow deployments, including ITSM and building user applications using ServiceNow. Prefer to have two (2) that are to US Government agencies.
c) Minimum one (1) ServiceNow certification.
Desired skills for the Business Analyst – Senior are:
d) Ability to convert users’ needs to technical requirements.
e) Strong verbal skills, ability to present to senior leadership.
f) Strong technical writing skills.
4.8. Business Analyst – Mid
Performs under the guidance of the Business Analyst – Senior to identify and clarify problem(s) to be solved through the use of ServiceNow application features. Will lead user community in structured meeting using industry standard requirements processes, such as use cases or Business Process Model and Notation (BPMN), to produce written artifacts, such as Concept of Operations, Requirements documentation and others. The Business Analyst – Mid is an knowledgeable on the functional capabilities of ServiceNow. The Business Analyst – Mid must possess:
g) Minimum six (6) years IT experience.
h) Minimum of two (2) successful ServiceNow deployments, including ITSM and/or building user applications using ServiceNow. Prefer to have two (2) which are to US Government agencies.
Desired skills for the Business Analyst – Mid are:
BPA SOW Page 8 of 13 05/22/18
i) Ability to convert users’ needs to technical requirements.
j) Strong verbal skills, ability to present to senior leadership.
k) Strong technical writing skills.
5. Place of Performance USCYBERCOM’s primary offices are located at 9800 Savage Road, Ft. Meade, Maryland 20755.
All work will be performed at USCYBERCOM’s offices within the greater Ft. Meade, Maryland area or at the contractors facility. Specific work locations will be designated in each order.
6. Vendor Requirements
6.1. ServiceNow Expertise
Vendors who wish to submit a bid, must be a ServiceNow Gold Services certified partner. The
ServiceNow Gold Services certified partner must be the prime for the contract.
6.2. United States Owned Company or Subsidiary
Vendors who wish to submit a bid, must be a United States wholly owned company or subsidiary.
6.3. Key Staff
Vendors will propose which staff/labor categories shall be key position. Contractor shall provide prior written notification of the replacement of any key staff to the CO. Key staff must hold an active Top Secret (TS)/ Sensitive Compartmented Information (SCI) with a Counter Intelligence
Polygraph (CI/Poly), TS/SCI with CI/Poly.
7. Ordering Period The contract shall be five (5) years. Each order will have a specific period of performance.
8. Contract Type There will be multiple orders for this contract. Each order will identify whether it is a firm fixed price or Time and Materials order.
9. Security Requirements – Information Security and other miscellaneous requirements
9.1. Personnel:
9.1.1. Personnel Security Requirements: Each order will detail the specific personnel security requirements.
9.1.2. Information Security Staff: Staff who will be responsible for the development of system security plan and its artifacts must possess an active TS/SCI with CI/Poly at the time of order award start.
BPA SOW Page 9 of 13 05/22/18
9.1.3. Operations and Maintenance: Personnel supporting the operations and maintenance activities (work location is USCYBERCOM offices), must hold an active TS/SCI with CI polygraph.
9.1.4. System Administrators: staff who may be system administrators or require elevated network or systems access under the operations and maintenance CLINS or surge CLINS, must comply with DoD 8570.01M requirements AND possess an active TS/SCI with CI polygraph.
9.2. Facility Security Clearance. The work to be performed under this contract is up to the Top
Secret level and will require Sensitive Compartmented Information (SCI) access eligibility for some personnel. Therefore the company must have a final Top Secret Facility Clearance from the Defense Security Service Facility Clearance Branch.
9.3. Contractor personnel shall comply with all local security requirements including entry and exit control for personnel and property at the government facility.
9.4. Contractor employees shall be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by
Government. Failure to comply with Government security regulations and requirements shall require the company to provide the Government with a written remediation/corrective action plan; furthermore, failure to comply with such requirements can be cause for removal and the contractor will not be able to provide service on this contract/order.
9.5. Contractor employees with an incident report in Joint Personnel Adjudication System (JPAS) or its replacement system (Defense Information System for Security (DISS) Joint Verification
System (JVS)) who have had their access to classified information suspended will not be permitted to fill positions under this contract/order.
9.6. The Contractor shall not divulge any information, classified or unclassified, about
USCYBERCOM, DoD or National Security Agency (NSA) files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the DoD/NSA facility. Identification shall be worn and displayed as required at all times.
9.7. USCYBERCOM retains the right to request removal of contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, conflict with the interest of the Government.
9.8. Contractor personnel will generate or handle documents that contain For Official Use Only information at the Contractor and/or Government facility. Contractor shall have access to, generate, and handle classified material only at the location(s) listed in the place of performance section of this document. All contractor deliverables shall be marked in accordance with DoDM 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of
Information Act Program, unless otherwise directed by the Government. The contractor shall comply with the provisions of the DoD Industrial Security Manual for handling classified material and producing deliverables. Additionally, the contractor shall comply with
USCYBERCOM security policies.
9.9. The Contractor shall afford the Government access to the contractor’s facilities, installations, operations, documentation, databases and personnel used in performance of the contract.
Access shall be provided to the extent required to carry out a program of IT inspection (to
BPA SOW Page 10 of 13 05/22/18 include vulnerability testing), investigation and audit to safeguard against threats and hazards to the integrity, availability and confidentiality of data or to the function of information technology systems operated on behalf of USCYBERCOM or DoD, and to preserve evidence of computer crime
9.10. Identification of Non-Disclosure Agreements (NDA): All USCYBERCOM Contractors must execute a USCYBERCOM-provided contractor non-disclosure agreement (NDA) for all services contracts regardless of award amount. The NDA must be signed within one week of contract/TO award. When a new contractor joins the contract, the NDA must be signed by the individual before being approved to work on the contract. The USCYBERCOM contractor is responsible for obtaining and maintaining NDAs for each contractor employee assigned to the contract. Copies of the signed NDA will be provided to the COR.
9.11. DD254
A DD254 documenting contract security requirements will be issued upon contract award and incorporated by reference.
10. Government Furnished Equipment Vendor shall provide all equipment, information, workspace and other facilities at vendor’s worksite. Any deviations to this shall be listed in the specific order(s).
11. Travel Local travel will be required, but not reimbursed by the government. Local travel is defined as a
50 mile radius from 9800 Savage Road, Ft. Meade, MD, 20755.
12. Training The contractor shall provide personnel that are qualified to meet all requirements of the statement of work. Any training available at a commercial source shall be considered to be of general utility to the Contractor and the course, labor and travel costs are note to be billed to the Government.
Training will be provided by the government only when such software/systems are uniquely designed/fabricated by, or for, the Government and such training is otherwise unavailable to the
Contractor. Courses conducted by Government schools may be made available to Contractor personnel where it has been clearly determined by the Contracting Officer (in writing) that training on specialized or unique government equipment is essential in carrying out the terms of the contract and the training is otherwise unavailable from commercial source.
13. Supply Chain Risk Management (SCRM)
This vendor and its associated delivery/task orders are subject to the Federal SCRM policies and regulations including the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239-7017
Notice of Supply Chain Risk, 252.239-7018 Supply Chain Risk, DoD Instruction 5200.44 Protection of
Mission Critical Functions to Achieve Trusted Systems and Networks, Section 806 of the FY2011 NDAA
Requirements for Information Relating to Supply Chain Risk, and internal DISA SCRM Processes and
BPA SOW Page 11 of 13 05/22/18
Procedures. Each individual delivery and/or task order will submit a SCRM Plan as part of the technical proposal, which addresses, at a minimum, Supply Chain Security Controls as specified in the delivery/task order and described in the Committee on National Security Systems Instruction (CNSSI)
1253 Appendix D (companion publication to National Institute of Standards and Technology (NIST)
Special Publications (SP)).
The vendor shall submit a SCRM plan as part of its technical proposal that describes how the vendor will reduce and mitigate Supply Chain Risk using the security controls outlined below (further described in
CNSSI 1253, Appendix D and NIST SP 800-53), as applicable to your contract.
Control
Number
HW SW Srvc
SA-12 Supply Chain Protection x x x
SA-12(1) Supply Chain Protection / Acquisition Strategies / Tools / Methods x x x*
SA-12(2) Supply Chain Protection / Supplier Reviews x x x*
SA-12(5) Supply Chain Protection / Limitation of Harm x x x*
SA-12 (7) Supply Chain Protection Assessments Prior to Selection / Acceptance/
Update x x x*
SA-12 (8) Supply Chain Protection / Use of All-Source Intelligence x x x*
SA-12 (9) Supply Chain Protection / Operations Security x x x
SA-12 (10) Supply Chain Protection / Validate as Genuine and Not Altered x x x*
SA-12 (11) Supply Chain Protection / Penetration Testing / Analysis of Elements, Processes, and Actors x x x
SA-12 (12) Supply Chain Protection / Inter-Organizational System Components x x x
SA-12 (13) Supply Chain Protection / Critical Information System Components x x x*
SA-12 (14) Supply Chain Protection / Identity and Traceability x x x*
SA-12 (15) Supply Chain Protection / Process to Address Weaknesses or
Deficiencies x x x
IR-4 (10) Incident Handling / Supply Chain Coordination x x x*
IR-6 (3) Supply Chain Protection / Incident Reporting / Coordination With
Supply Chain x x x*
SA-11 Developer Security Testing and Evaluation x x x*
SA-14 Criticality Analysis x x x*
BPA SOW Page 12 of 13 05/22/18
SA-15 Development Process, Standards, and Tools x x x*
SI-7 Software, Firmware, and Information Integrity x x x*
CM-4 Security Impact x x x*
PM-16 Threat Awareness Program x x x
*Not required if there will be no procurement of hardware, firmware, or software systems.
13.1. SCRM Deliverables:
SUPPLY CHAIN RISK MANAGEMENT PLAN UPDATE: The vendor shall provide an updated SCRM Plan to the COR and Program Manager within five (5) business days whenever there is a change that affects one or more security controls as described in the Committee on National Security Systems Instructions
(CNSSI) 1253 Appendix D (companion publication to National Institute of Standards and Technology
(NIST) Special Publications (SP)). At a minimum the following events substantiate the need for an update: changes in company ownership, changes in senior company leadership, supplier changes, subcontractor changes, and ICT supply chain compromises.
Vendor employees may be required to take periodic mandatory training courses provided through the agency, such as records management training and other training required by statute, regulation, DoD, or DISA policy. (Note if there are specific courses you will require from your contractors, insert those here.) No other training of contractor personnel shall be provided by the Government unless authorized by the Contracting Officer.
14. Section 508 Accessibility Standards.
The vendor shall complete all requirements of this statement of work in accordance with the following
Section 508 standards of the Rehabilitation Act of 1973. The following Section 508 Accessibility
Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) to this acquisition.
Technical Standards
1194.21 - Software Applications and Operating Systems
1194.22 - Web Based Intranet and Internet Information and Applications
1194.23 - Telecommunications Products
1194.24 - Video and Multimedia Products
1194.25 - Self-Contained, Closed Products
1194.26 - Desktop and Portable Computers
BPA SOW Page 13 of 13 05/22/18
1194.41 - Information, Documentation and Support
The Technical Standards above facilitate the assurance that the maximum technical standards are provided to the Offerors. Functional Performance Criteria is the minimally acceptable standards to ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic and information technology (E&IT) products are proposed.
Functional Performance Criteria
1194.31 - Functional Performance Criteria
File details come from the government source that posted it. Updated .