SSO_Toolkit_SOW_final.pdf
PDF 713 KB Posted
- Attached to
- ServiceNow Federal contract opportunity
- Solicitation number
- HB0001-18-R-0012
- Issued by
- Department of Defense Cyber Command
About this file
SSO_Toolkit_SOW_final
View the file
Other files for this federal contract opportunity
Show all 29
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SSO Toolkit SOW Page 1 of 8 05/22/18
United States Cyber Command
Special Security Office Tool Kit
Statement of Work
May 22, 2018
SSO Toolkit SOW Page 2 of 8 05/22/18
Contents
1. Scope
2. Tasks
3. Place of Performance
3.1. Development Work location:
3.2. Implementation Work Location
3.3. Operations and Maintenance Work Location
4. Contractor Staffing Requirements
5. Period of Performance
6. Task Order Type
7. Security Requirements – Information Security and other miscellaneous requirements
7.1. Personnel:
7.1.1. Individual Security Clearance:
7.1.2. System Administrators Security Requirements:
8. Deliverables:
SSO Toolkit SOW Page 3 of 8 05/22/18
1. Scope The contractor shall procure ServiceNow professional consulting services to perform the implementation, configuration, training, operations and maintenance of USCYBERCOM’s ServiceNow’s
Workflow and ServiceNow Now custom application features for USCYBERCOM Special Security Office
Toolkit.
Reference: Concept of Operations for US Cyber Command Special Security Office Task Management Tool, dated May 11, 2018
2. Tasks The services the contractor shall provide consists of following:
2.1. Project Management
The contractor shall provide project management oversight for all tasks under this award. Project management services shall be consistent with the best practices identified by the Project
Management Institute.
2.2. Out of the Box Functionality
2.2.1. The contractor shall utilize out of the box functionality as the preferred implementation approach. The objective of utilizing “out of the box” functionality is to ensure that
USCYBERCOM is able to upgrade to future versions of ServiceNow without requiring additional expenses due to customization to migrate to the new versions.
2.2.2. Customization Approval: If the contractor proposes a customization, employing other than ServiceNow “out of the box” functionality, the contractor will obtain prior approval from the COR.
2.3. ServiceNow architecture, installation and configuration:
2.3.1. The contractor shall design the overall architecture of the ServiceNow application within the unclassified security enclave. The hosted location for the unclassified security enclave will be AWS GovCloud unclassified.
2.3.2. The contractor shall install and configure the ServiceNow listed features to operate within the USCYBERCOM unclassified environment. The features to be implemented in accordance with the attached Concept of OPERATIONS for US CYBER COMMAND Special
Security Office Task Management System (SSO Toolkit). The ServiceNow features to be implemented within the task order are:
2.3.2.1. ServiceNow Platform;
2.3.2.2. ServiceNow Now Platform Custom Application.
2.4. Software Development Management Process utilizing native ServiceNow functionality
2.4.1. The vender shall recommend and implement within ServiceNow a development methodology comprised of the following:
2.4.1.1. Requirements management: submission and status of all requirements.
SSO Toolkit SOW Page 4 of 8 05/22/18
2.4.1.2. Defect management: submission and status of all reported defects.
2.4.1.3. Change Management: tracking the status of all requirements and defects and whether they are associated with a specific software release they are incorporated into.
2.4.1.4. Release Management: cataloguing and tracking each requirement and defect and associating these with a software release.
2.4.1.5. LifeCycle Status: Tracking the status of each requirement and defect through the software development lifecycle.
2.5. SSO Toolkit Implementation
2.5.1. The vender shall implement an application within ServiceNow that implements the vision and requirements identified within the SSO Toolkit document.
2.5.2. The contractor shall recommend process improvements that utilize native ServiceNow features to optimize each process to reduce processing time while increasing transparency to leadership. The contractor shall document these business process improvements using standardized business process models such as use cases, business process model and notation (BPMN) or other methods approved by USCYBERCOM.
2.6. Post-Implementation Support:
2.6.1. The contractor shall provide post-implementation support to include end-user training, resolve any technical issues and support knowledge transfer to USCYBERCOM support team
2.7. System Security Plan:
The contractor shall complete the system security plan (SSP) required for the ServiceNow application to start development and testing within USCYBERCOM technical environment
(Interim Approval to Test (IATT)) and obtain an “Authorization To Operate” (ATO). The contractor shall be required to complete a SSP for the unclassified security enclave. The contractor shall be required to coordinate with other directorates and subcontractors within
USCYBERCOM to complete the SSP. Further the contractor shall update the SSP as required.
The SSP shall be compliant with the National Institutes Standards and Technology (NIST) Risk
Management Framework (RMF) and the corresponding NIST Special Publication (800-53) as well as USCYBERCOM specific security controls in obtaining an ATO.
2.8. Knowledge Transfer:
The contractor shall provide technical and functional knowledge transfer of each configured feature(s) implemented to the USCYBERCOM IT operations and maintenance organization. This knowledge transfer shall consist of both informal and formal methods. Additionally, the contractor shall produce documentation to correspond to the “AS BUILT” configuration of each application to be used by the technical operations and maintenance organization.
2.9. End User Training:
The contractor shall develop end user training materials for each application prior to going live.
This training shall consist primarily of “just-in-time” training, utilizing a self-service training model and a combination of video screen captures and textual materials.
SSO Toolkit SOW Page 5 of 8 05/22/18
2.10. Operations and Maintenance Support:
The contractor shall provide ongoing operations and maintenance (O&M) support for the
ServiceNow installation and configurations within each of the security enclaves implemented within USCYBERCOM. This O&M support shall include maintaining the ServiceNow installations, configurations and support for HR Toolkit application as well as upgrading the
ServiceNow application itself if required. O&M does not include supporting the operating system or functionality below the ServiceNow application layer.
3. Place of Performance Performance of this order shall be at USCYBERCOM’s primary offices are located at 9800
Savage Road, Ft. Meade, Maryland 20755.
3.1. Development Work location:
All development activities for the SSO Toolkit shall be performed at the contractor site.
Contractor’s work location must be within 10 miles of 9800 Savage Road, Ft. Meade, Maryland
20755 and have space for meetings with USCYBERCOM staff. Contractor staff shall also be required to periodically attend meetings at USCYBERCOM facilities. Staff working at the contractor’s work location must be a US citizen and eligible to obtain a Top Secret (TS)/
Sensitive Compartmented Information (SCI) with a Counter Intelligence Polygraph (CI/Poly).
Contractor may be required to provide a ServiceNow development environment at the same release level to be installed at USCYBERCOM, accessible at contractor site.
3.2. Implementation Work Location
The implementation of the SSO Toolkit will be at USCYBERCOM’s primary office, noted above.
3.3. Operations and Maintenance Work Location
The Operations and Maintenance of the SSO Toolkit will be at USCYBERCOM’s primary office, noted above.
4. Contractor Staffing Requirements The contractor shall propose the labor category mix and hours to complete the tasking herein.
The staffing plan shall identify and personnel critical to accomplishing the work and proposed clearances for each full time equivalent.
5. Period of Performance The period of performance will be four (4) months from task order award.
6. Task Order Type This task order will be issued as a Time and Materials award.
SSO Toolkit SOW Page 6 of 8 05/22/18
7. Security Requirements – Information Security and other miscellaneous requirements
7.1. Personnel:
7.1.1. Individual Security Clearance:
Key staff, operations and maintenance staff, and any staff attending meetings at
USCYBERCOM must possess an active TS/SCI with CI/Poly. All other staff supporting this task order must be a US Citizen and eligible to obtain a TS/SCI with CI/Poly clearance.
7.1.2. System Administrators Security Requirements:
Staff who may be system administrators or require elevated network or systems access, must comply with DoD 8570.01-M requirements in addition to an active TS/SCI with CI polygraph.
8. Deliverables:
The following is a list of consolidated deliverables. All deliverables shall be sent softcopy to the
Contracting Officer’s Representative (COR). For deliverables that are not documentation, a delivery memo shall be sent to the COR, specifying the deliverable and date delivered.
SSO Toolkit SOW Page 7 of 8 05/22/18
Deliverable Number
Deliverable Reference
Deliverable Name Deliverable Format
Government or Contractor Format
Due Date1
1. 4.1 Project Kickoff Meeting/ Kickoff presentation
Contractor 10 days after contract start date
2. 4.1 Communications Plan
MS Word Contractor 10 days after contract start date
3. 4.1 Risk Management Plan
MS Word Contractor 10 days after contract start date
4. 4.1 Issue Management Plan
MS Word Contractor 10 days after contract start date
5. 4.1 Project Schedule MS Project Contractor 10 days after contract start date, then weekly updates
6. 4.3 ServiceNow Software
Physical Media
5 days after contract start date
7. 4.3 Install and configure baseline ServiceNow software in Unclassified environment
Functioning baseline application
10 days after
USCYBERCOM
provides hosting environment
8. 4.5 Implement SSO Toolkit
Application 55 days after contract start date
9. 4.5 SSO Toolkit Initial Operating Capability
Application 65 days after contract start date
10. 4.6 Post Implementation Support
Immediately upon IOC until end of Period of Performance
11. 4.7 Security Concept of Operations Document
MS
Word/Visio
Government 40 days after contract start date
12. 4.7 Configure Management Plan
MS
Word/Visio
Government 40 days after contract start date
13. 4.7 System Security Plan
MS
Word/Visio
Government 50 days after contract start date
1 Due dates are business days
SSO Toolkit SOW Page 8 of 8 05/22/18
14. 4.8 Knowledge Transfer
MS Word or Video format
Contractor NLT 1 one month prior to Initial Operating Capability
15. 4.9 End-User Training
MS Word or Video format
Contractor NLT 1 one month prior to Initial Operating Capability
16. 4.1 Weekly Activity Report
MS Word Government Wednesday, 5 PM each week
17. 4.1 Monthly Activity Report
MS Word Contractor 3rd workday of each month
File details come from the government source that posted it. Updated .