SODAS_PWS.pdf

PDF 302 KB Posted

Attached to
Test, Evaluation, and Certification (TEC) Services Draft RFP Federal contract opportunity
Solicitation number
HC1028-16-R-0007
Issued by
Defense Information Systems Agency

About this file

Special Operations DNA Analysis Solutions (SODAS) Test 13 And Evaluation Support Sample Task Order 0002

View the file

Other files for this federal contract opportunity

Other files attached to Test, Evaluation, and Certification (TEC) Services Draft RFP, newest first.
File Type Posted
Plenary_Session_Questions_and_Answers_TEC_Pre-Sol_Conf_June_6_2016_Final.pdf PDF
JITC_Guide_to_Test_Documentation.pdf PDF
Section_L_-_Attachment_1.xlsx XLSX spreadsheet
2_-_Command_Brief _TEC_Pre-Sol_Conf _6_Jun_2016.pdf PDF
3_-_TEC_Services_Contract _TEC_Pre-Sol_Conf _6_June_2016.pdf PDF
TEC_Services_Conference_Attendees.pdf PDF
1_-_Welcome _TEC_Pre-Sol_Conf _6_Jun_2016.pdf PDF
5_-_Lab_Overview_and_Briefings _TEC_Pre-Sol_Conf _6_Jun_2016.pdf PDF
4_-_Contracting_Brief _6_June_2016.pdf PDF
Attachment_9_-_JITC_TEC_-_FFP_Pricing_Scenario_Template.xlsx XLSX spreadsheet
DD1423_-_DISA_TEC_Services_CDRLs_A017-A020 _5_of_6_(201605017).pdf PDF
JCAP_Operational_View_-_2.pdf PDF
APPENDIX_B_-_Acronyms.pdf PDF
DISA_DD254.pdf PDF
DJFAS_PWS.pdf PDF
JCAP_System_View_-_6.xlsx XLSX spreadsheet
DD1423_-_DISA_TEC_Services_CDRLs_A005-A008 _2_of_6_(201605017).pdf PDF
DD1423_-_DISA_TEC_Services_CDRLs_A021 _6_of_6_(201605017).pdf PDF
JCAP_Notional_NR-KPP_Compliance_Table.pdf PDF
Attachment_8_-_JITC_TEC_-_CPFF_Pricing_Scenario_Template.xlsx XLSX spreadsheet
JCAP_System_View_-_5.pdf PDF
JITC_TEC_-_CPFF_Scenario_Pricing_Template_Instructions.pdf PDF
Attachment_7_-_JITC_TEC_-_Task_Order_1_(FFP)_Pricing_Template.xlsx XLSX spreadsheet
JCAP_Operational_View_-_3.xlsx XLSX spreadsheet
JCAP_Operational_View_-_5a.pdf PDF
JITC_TEC_-_Task_Order_1_(FFP)_Pricing_Template_Instructions.pdf PDF
DD1423_-_DISA_TEC_Services_CDRLs_A009-A012 _3_of_6_(201605017).pdf PDF
JCAP_System_View_-_4a.pdf PDF
JCAP_System_View_-_2.pdf PDF
APPENDIX_A_-_Definitions.pdf PDF
TEC_Draft_RFP_-_2_June.pdf PDF
DD1423_-_DISA_TEC_Services_CDRLs_A001-A004 _1_of_6_(201605017).pdf PDF
UC_TEC_SOW.pdf PDF
DD1423_-_DISA_TEC_Services_CDRLs_A015-A016 _4_of_6_(201605017).pdf PDF
TEC_Services_Industry_Day_Announcement_-_AMD_01.pdf PDF
TEC_Services_Industry_Day_Announcement.pdf PDF
Show all 36

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Enclosure 2d, PWS Page 1 of 13 Pages

18Nov2015/Version 10

Joint Interoperability Test Command Special Operations DNA Analysis Solutions (SODAS) Test and Evaluation Support

Performance Work Statement

Contract Number:

Task Order Number:

Tracking Number:

Follow-on to Previous Contract and Task Order Number:

1. Contracting Officer’s Representative (COR).

1.1. Primary COR.

Name:

Organization:

Department of Defense Activity Address Code (DODAAC):

Address:

Phone Number:

Fax Number:

E-Mail Address:

1.2. Alternate COR.

Name:

Organization:

DODAAC:

Address:

Phone Number:

Fax Number:

E-Mail Address:

2. Contract or Task Order (TO) Title. Joint Interoperability Test Command (JITC) Special Operations Deoxyribo-nucleic Acid (DNA) Analysis Solutions (SODAS) Test and Evaluation

3. Background.

3.1. The United States Special Operations Command (USSOCOM) requires Test and Evaluation (T&E) support from JITC to plan, conduct, and report the results of two biometric-related capability assessments per year.

USSOCOM is a unified command, tasked with the responsibility of preparing for and conducting special operations.

To enable USSOCOM to carry out its mission, the command is empowered with certain Title 10 authorities and responsibilities. Among these is the responsibility and authority to develop and acquire Special Operations Forces (SOF)-unique equipment, material, supplies, and services. These special circumstances allow USSOCOM to develop and field capabilities at a much more rapid pace than conventional forces (e.g., Army, Navy, Air Force, and Marines). SOF Acquisition, Technology and Logistics (AT&L) is the acquisition arm of USSOCOM. Under SOF AT&L, the Program Manager for Tactical Biometrics (PM-TB) manages the acquisition, fielding, sustainment, and evolutionary enhancement of specialized exploitation, biometric, and forensic data collection and processing devices that support SOF mission planning and execution. SOF biometric capabilities are in various stages of the acquisition cycle. Acquisition plans incorporate strategies for Information Technology (IT) insertion as a means to provide

Page 2 of 13 Pages continuous and timely enhancement of SOF warfighting capabilities. These devices directly support USSOCOM's priorities to deter, disrupt, and defeat terrorist threats, as well as sustain and modernize the force.

3.2. As part of this overall effort and in support of properly resourcing deployed Exploitation Analysis Centers (EAC), PM-TB is exploring commercial options to provide SOF with the ability to rapidly capture, digitize, and exploit an individual’s DNA. The primary objective of a new PM-TB program called Special Operations DNA Analysis Solutions (SODAS) is to support “Detain or Release” decisions when SOF teams encounter and detain potential “persons of interest” during operations. SODAS will support this objective, while ensuring the DNA data collected and stored is both secure and discoverable by EAC users with appropriate access credentials.

3.3. The PM-TB plans to host two SODAS capability assessment “bake-off” test events to collect both performance data and user feedback regarding candidate solutions. The T&E events are projected to include four vendor-provided SODAS DNA screening capabilities and associated components; the outcome of the T&E events may result in the selection of one device for operational deployment to an EAC. The first T&E event will take place in a controlled laboratory environment. The second T&E event will take place in a field environment with representative operational users. In support of these events, the contractor will provide T&E planning, execution, analysis and reporting services. The contractor, will collect and analyze data to characterize how well the SODAS solutions meet specified requirements and will present the results to PM-TB, but will not provide a recommendation for acquiring one system over another. The following candidate systems (ten each Hand-held and one Docking Station/Database System will be provided) are scheduled to participate in both T&E events:

• DNA Evaluator

• Fast DNA

• Bio Inspector

• DNA Now

3.4. As part of a deployed EAC, SODAS components will operate as depicted in Figure 1. Each SODAS system must provide a Hand-held DNA collection system and a local docking station/database system. The connection be-tween the Hand-held device and the docking station/database shall support secure wireless and wired connectivity, and must meet National Institute of Standards and Technology (NIST) encryption standards. In the SODAS local database, data must meet Armed Forces DNA Identification Laboratory (AFDIL) eXtensible Markup Language (XML) Data and Secure Hash Algorithm 3 (SHA-3) Hashing standards. In addition, the SODAS system must apply defined XML tags, listed in Figure 3, to the DNA records to ensure the data can be discovered by authorized EAC users via a database query.

3.5. Figure 1 depicts the SODAS data flow; SODAS system components are reflected in blue, while the data flow is purple. The SODAS data flow starts with the Hand-held DNA collection unit that connects to the docking station via a secure Radio Frequency (RF) Link to send DNA data (i.e., profile) that characterizes each DNA sample. The SODAS local database system then connects to the Armed Forces DNA Identification Laboratory (AFDIL) Analysis Request Portal, shown in green, and uploads the DNA Analysis request. Once AFDIL has compared the DNA rec-ord(s) to those in its Authoritative Database and has identified the Detain/Release status, the AFDIL Analysis Re-quest Portal will send an update to the SODAS System. The SODAS system will then update the Detain/Release information on the SOF Exploitation Node’s Portal that is accessible to EAC users via local workstations. Further-more, up to five simultaneous authorized users/administrators can access the SODAS Database; however, only ad-ministrators can change/update a record with the Detain/Release status and other pertinent information. Data should be searchable via date the DNA sample was collected, the location of the DNA collection, and name of the person who collected the DNA sample. The SODAS system will track changes and annotate the administrator’s credentials in the updated record.

Page 3 of 13 Pages

Figure 1. SODAS Data Flow Diagram

3.6. Figure 2 depicts the interactions between the user and the Hand-held DNA collection system. When the user is assigned to the subject of the DNA collection, the user must install his PKI credential certificates for the mission.

The Hand-held unit shall synch with GPS and the docking station via secure RF, and then indicate status (green or red lights) for both GPS and RF; both lights must be green for the DNA collector to start processing the sample.

Once a subject’s DNA sample is entered for processing, the user initiates the Hand-held to start processing. The Hand-held shall provide the user feedback that it is still processing (red light) or has completed processing (green light) the DNA. As part of the DNA processing sequence, the user shall input the name and physical condition of the subject of the DNA sample. Once the Hand-held has completed processing, it will queue the information for trans-mission to the SODAS docking station. The SODAS Hand-held DNA collection system shall allow a transmission queue of up to 100 DNA analysis request samples. As mission parameters allow, the user shall initiate the RF trans-mission of DNA analysis requests. The Hand-held shall give the user positive feedback (green light) for the success-ful receipt of each DNA analysis request record by the docking station.

Page 4 of 13 Pages

Figure 2. SODAS Hand-held DNA Collection Process Flow Diagram

3.7. Figure 3 reflects a notional XML structure associated with each DNA sample’s record in the SODAS data-base. The fields represent the minimum implementation; additional fields may be appropriate.

Page 5 of 13 Pages

Date Collected <dd/mm/yyyy HH:MM Zulu> Name of Individual <First Name> <Middle Initial> <Last Name> Collection Device ID# <########> Name of Collector <First Name> <Middle Initial> <Last Name> Location of Collection <Lat> <Long> Individuals Condition <Alive/Wounded/Dead> AFDIL DNA Sequence <Data> AFDIL DNA Sequence NIST SHA-3 <Data> AFDIL Request <Y/N>

Y - Date of Request <dd/mm/yyyy HH:MM Zulu> Received AFDIL Response <Y/N>

Y - AFDIL Response <Detain/Release> Y - Date of Response <dd/mm/yyyy HH:MM Zulu>

Possible Alias <Y/N> Y – Alias 1 <Alias Name>

Record last updated <dd/mm/yyyy HH:MM Zulu>

AFDIL

DNA

XML

Req.

Format

Figure 3. SODAS XML Data Structure Requirement

3.8. SODAS Hand-held Requirements. Considering the full range of the following environmental conditions be-low, users must be able to obtain and process DNA with 95 percent reliability that a physical sample is correctly pro-cessed (profile remains in-tact) and is usable for identification and data sharing purposes.

3.8.1 Users shall be able to collect and process DNA samples in a temperature range of 32 degrees Fahrenheit through 125 degrees Fahrenheit.

3.8.2 Users shall be able to collect and process DNA samples in windy conditions up to 30 knots.

3.8.3 Users shall be able to collect and process DNA samples when weather conditions are at or below 90 percent humidity.

3.8.4 Users will not collect and process DNA samples outdoors during periods of rain, snow, or other precipita-tion.

4. Objectives:

4.1 The Contractor shall submit a proposal describing their approach for T&E support of the SODAS. The detailed approach will reflect data collection to support the following attributes that PM-TB has indicated as potentially discriminating factors between the candidate systems.

Page 6 of 13 Pages

4.1.1. DNA samples are accurately processed by the Hand-held data collection system under all specified operational conditions.

4.1.2. DNA processing and secure transmission time meets threshold requirements for security and timeliness.

4.1.3. DNA XML metadata adheres to minimum specified implementations reflected in Figure 3.

4.1.4. DNA data records in the local database are discoverable and accessible only by authorized users.

4.1.5. SODAS must allow up to five simultaneous authenticated users within the EAC Network to query the

SODAS database and/or modify DNA records.

4.1.6. Tactical usability of the SODAS Hand-held data collection system.

4.1.7. Hand-held data collection system meets size and weight specifications.

5. Scope.

5.1. The Contractor shall support T&E (planning, execution, analysis, and reporting) for the two SODAS assess-ment events sponsored by PM-TB.

5.2. The Contractor’s T&E methodology provided in the response to this PWS shall reflect concepts in the DOT&E memorandum, “Best Practices for Assessing the Statistical Adequacy of Experimental Designs Used in Operational Test and Evaluation,” July 2013.

5.3. For both of the test events, PM-TB will provide a mock AFDIL site for reach back analysis; a local SOF Ex-ploitation Node; 10 local workstations on the EAC network; an EAC Portal; and a test PKI Server with 55 test certif-icates. The PKI certificates will be assigned as follows: 10 for SOF DNA collectors, 40 for Local SOF Exploitation Node users, and 5 for Local SOF Exploitation Node administrators.

5.4. The PM-TB will provide both T&E venues for a total of 15 working days, each with 10-hour test times, with an additional one-hour start up and one-hour close down, for a total of 12-hour access to the site. Additional details regarding the test events are as follows:

5.4.1. Laboratory Test Event – This five-day T&E event will take place at the National Forensic Science Technol-ogy Center in Largo, Florida. Testers will be able to vary temperature between 10o Fahrenheit and 130o Fahrenheit;

humidity levels between 20% and 95%; and wind conditions between 0 and 45 knot winds. PM-TB will provide two trained DNA Collectors for each of the four candidate systems and 20 subjects that will provide DNA samples for the test, with two of those individuals being marked as “Detain” in the mock AFDIL Database.

5.4.2. Field Test Event – This two-week T&E event will take place at Fort Bragg, North Carolina. The test event will be broken into two parts. The first week’s testing will be conducted during daylight hours, while the second week’s testing will support night operations. There is no testing on the weekends, and there are two make-up days (one per week) in the schedule if needed. The Field Test operations are described as:

5.4.2.1. PM-TB will provide four teams of SOF personnel, each with ten members.

5.4.2.2. PM-TB will design four scenarios that the SOF teams will rotate through during each week of the Field

Event.

5.4.2.3. Each scenario will employ 20 subjects who will provide DNA samples for the test, with two of those indi-viduals being marked as “Detain” in the mock AFDIL Database.

5.4.2.4. Each scenario will commence with the SOF team receiving training on the specific SODAS Hand-held de-vice they are assigned.

5.4.2.5. Each SOF team member will have a Collector PKI certificate.

5.4.2.6. Each team will use all ten of the provided Hand-held devices per candidate systems listed in Paragraph 3.3.

5.4.2.7. The SOF teams will execute the same 1-2 hour scenario four times in a test day, using a different Hand-held unit of candidate SODAS systems for each scenario run.

5.4.2.8. The four SOF teams will be running through their scenarios simultaneously and switching to a different

Hand-held data collection unit after completion of each scenario run.

5.4.2.9. SOF team members will be asked to complete a user survey at the end of each scenario run.

Page 7 of 13 Pages

5.4.2.10. User surveys must reflect the concepts in the Director, Operational Test and Evaluation (DOT&E) memo-randum, “Guidance on the Use and Design of Surveys in Operational Test and Evaluation,” June 2014.

5.4.2.11. The four SOF teams will support a different scenario each successive day until each team uses each of the candidate Hand-held systems in each scenario during daylight hours and repeats the sequence during night operations.

6. Performance Requirements.

6.1. Task 1. Test Support. The Contractor shall support planning for, conducting, and reporting the results for the two SODAS test events, the Laboratory Test Event and the Field Test Event. In providing this support, the Contractor shall support the following subtask activities:

6.1.1. Subtask 1.1 – T&E Planning. In support of both SODAS test events, the Contractor shall develop a test plan to support the conduct of each test event. In the test plan, the Contractor shall provide the following information:

a. Test event purpose, scope, and objectives.

b. Test methods, based on SBTD approaches, for addressing each test objective, to include required sample sizes and analysis methods.

c. Detailed test procedures specifying data collection sources and methods.

d. Test event schedule of planned test activities by day and hour.

e. Resource requirements to conduct each test event to include test personnel (test director, data collectors, etc.), instrumentation and automation to support data collection, administrative, and travel.

Deliverable: (To be provided with the response to this PWS)

a. Test Plan (includes both the Laboratory and Field Test Events)

6.1.2. Subtask 2. T&E Event Execution. In support of both of the SODAS test events, the Contractor shall carry out the test execution, data collection and analysis activities called for in the test plan.

Deliverables:

a. Test data collected Test Incident Reports (TIRs)

6.1.3. Subtask 3. T&E Reporting. In support of both of the SODAS test events, the Contractor shall develop both a test results briefing and a test report summarizing test findings against each of the test event objectives. The test event results briefing shall provide an overview of test event findings and shall be provided to the Government within 7 working days of the completion of each test event. The test event report shall provide detailed analysis, findings, and recommendations and shall be provided to the Government within 30 working days of the completion of the Field Test Event.

Deliverables:

a. Test Results Briefings

Page 8 of 13 Pages

b. Test Report

6.2. Task 2. SODAS Instrumentation and Automation Support. The Contractor shall describe their proposed approach for providing automation and instrumentation support to the T&E of SODAS and other similar Information Technology (IT)-based systems. The Contractor’s proposed approach for providing T&E automation and instrumentation support must account for both T&E activities performed within JITC testbed and laboratory facilities as well as T&E activities performed at customer and field locations. The Contractor’s proposed approach for providing T&E automation and instrumentation support can make use of existing or modified JITC tools and capabilities, Commercial-off-the-shelf (COTS) capabilities, and/or other Government off-the-shelf (GOTS) capabilities. The Contractor’s proposed T&E automation and instrumentation capabilities shall address the support of the following T&E functions:

a. Test requirements management

b. Test configuration management

c. Functional testing

d. Performance, capacity, and stress testing

e. Standards verification

f. Security compliance and vulnerability assessment

g. Simulation and modeling of physical systems, interfaces, and information exchanges

h. Test incident or anomaly reporting

i. Test data management and validation

j. Test data analysis and reporting

Deliverable: T&E Automation and Instrumentation Support Whitepaper (To be provided with the response to this PWS)

6.3. Task 3. Cyber Threat Security Plan.

6.3.1. Handling of Non-Public Information

In performance of this contract, the contractor may have access to Department of Defense (DoD) information. The contractor agrees (a) to use and protect such information from unauthorized disclosure IAW DoD Instruction 8582.01: Security of Unclassified DoD Information on Non-DoD Information Systems; (b) to use and disclose such information only for the purpose of performing this contract and to not use or disclose such information for any per-sonal or commercial purpose; (c) to comply with other current Federal and DoD information protection and reporting requirements for specified categories of information (e.g., medical, proprietary, critical program information (CPI), personally identifiable information, export controlled); (d) to obtain permission of the Government Requiring Activi-ty before disclosing/discussing such information with a third party; (e) to return and /or electronically purge, upon Government request, any DoD information no longer required for contractor performance; and (f) to advise the Con-tracting Officer and/or Contracting Officer’s Representative of any unauthorized release of such information.

6.3.2. Cyber Threat Security Plan

In conjunction with the Defense Federal Acquisition Regulation Supplement (DFARS) Subpart 204.73, Safeguarding Unclassified Controlled Technical Information, DFARS Clause 252.204-7012, Safeguarding unclassified controlled

Page 9 of 13 Pages technical information, and DoD, DISA, NIST, and other Federal mandated regulations, instructions, procedures, and laws, the contractor shall develop, submit, and implement upon approval a Cyber Threat Security Plan (plan).

The contractor shall submit the plan 30 days after contract award to the Contracting Officer and COR for acceptance.

The Contracting Officer and COR have 10 working days to provide an acceptance or feedback to the contractor. If no written acceptance is received within the 10 working days, then the contractor can consider the plan accepted. If the contractor receives feedback within the 10 working days, then the contractor has 10 working days to provide the Contracting Officer and COR an updated plan based on comments provided by the Government.

This plan shall be consistent with and further detail the approach contained in the contractor’s proposal that resulted in the award of this contract and in compliance with the requirements stated in the clause mentioned under this task.

This plan shall describe the processes and procedures that will be followed to ensure appropriate security of IT re-sources that are developed, processed, or used under this contract. This plan shall contain the following:

(a) Vulnerability Management: evaluate network components, security procedures, and processes for potential ex-ploitation from attack.

(b) Cyber Threat Intelligence: provide policy enforcement and end-point protection against unwarranted attacks on the network.

(c) Analytics Monitoring: provide scalable analytics solution capable of combining potential risk indicators and de-veloping leads.

(d) Mitigation and Response: provide the process on how the threat will be mitigated and responded to upon discov-ery.

(e) Lessons Learned and Action Plan: provide lessons learned and an action plan that will help all interested parties avoid repeated and similar attacks.

(f) Subcontractors: explain how your subcontractors will be required to implement this requirement within their pro-cesses in support of this task.

Annually, anniversary date of acceptance of the plan, the contractor shall submit verification to the Contracting Of-ficer and COR that the plan remains valid.

Deliverable: Cyber Threat Security Plan due 30 days after contract award.

6.3.3. Contractor Furnished Equipment

Contractor Furnished Equipment (CFE) employed for remote access to a Government network must meet or exceed equivalent Government Furnished Equipment (GFE) cyber security computing requirements. The contractor shall ensure that all CFE (hardware and software) employed to access these environments meet the following minimum Government cyber security requirements and provide periodic certification of compliance as a pre-requisite to being granted network access.

6.3.3.1. Use of personally owned systems is prohibited;

6.3.3.2. Operating systems and applications must be configured for compliance with the applicable Security

Technical Implementation Guides (STIGs);

6.3.3.3. DoD approved anti-virus and anti-spyware software must be installed and signatures must be configured to automatically update on a daily basis;

6.3.3.4. DoD approved host-level firewall must be utilized and configured to permit traffic by exception only, dropping all other traffic. If the host-level firewall provides intrusion detection or prevention, the signa-tures or rules must be updated at the same intervals as the anti-virus software;

6.3.3.5. Computers must be Information Assurance Vulnerability Management (IAVM) compliant;

6.3.3.6. Computers must be scanned with the currently approved DoD scanner solution at a minimum of every 30 days. All vulnerabilities must be remediated and reported to the cognizant Information Assurance Man-ager;

6.3.3.7. Contractor employees must possess a current Government issued Common Access Card (CAC) and in-stall Government certified CAC readers; and

Page 10 of 13 Pages

6.3.3.8. Verification of compliance with these requirements must be provided to an appointed government repre-sentative on a monthly basis.

7. Performance Standards.

Performance Areas Acceptable Quality Level (AQL) Method of Surveillance Applicable to all delivera-bles associated with this

PWS

• Final deliverables shall not exceed, on average, more than one error per page over the entire page count of the deliverable.

• The Contractor shall correct all errors associated with a final deliverable within five (5) business days of being notified of such errors

• 100% inspection of deliver-ables.

• CORs will perform monthly inspection of contract deliv-erables and document results in the CORT Tool.

Note: A “Final Deliverable” is defined as a product for which all Government comments to prior draft or interim versions of the deliverable have been satisfactorily addressed by the contractor such that the content, form, and for-mat of the product on delivery to the Government is sufficiently accurate, complete, technically sound, and free from spelling, punctuation, syntax, and grammatical errors that it is ready for final government review, staffing, ac-ceptance, and signature.

8. Place of Performance. The primary facility location is at JITC Headquarters, Ft. Huachuca, Arizona, with the T&E events taking place at the National Forensic Science Technology Center in Largo, Florida and at Fort Bragg, North Carolina.

8.1. Weekend/Federal Holiday: Work on weekends or federal holidays may be authorized. Prior coordination with the Government COR is required.

8.2. Overtime, after-hours support, and compensatory time may be required to support contingencies and testing activities. Prior coordination with the Government COR is required before the start of work.

8.3. Flex Time: Since the work involved will require very close coordination with customers in a variety of loca-tions, flex time may be approved if addressed in the proposal; otherwise, other alternatives must be addressed in the proposal. Prior coordination with the Government COR is required.

8.4. Travel: Travel may be required. Prior to traveling, the contractor is required to coordinate with the Govern-ment COR. Travel arrangements must be coordinated via email with the Government COR, such as lodging, rental cars, air travel, etc., prior to final travel arrangements to confirm trip is still necessary. Visit Access Requests should be initiated by the contractor for sites requiring verification of security clearance.

8.5. Alternate Place of Performance – Contingency Only. As determined by the COR, contractor employees may be required to work at an alternate place of performance (e.g., home, the contractor's facility, or another approved activity within the local travel area) in cases of unforeseen conditions or contingencies (e.g., pandemic conditions, exercises, government closure due to inclement weather, etc.). Non-emergency/non-essential contractors should not report to a closed government facility. Contractor shall prepare all deliverables and other contract documentation utilizing contractor resources. To the extent possible, the Contractor shall use best efforts to provide the same level of support as stated in the PWS.

9. Period of Performance. November 1, 2017 – 30 March 2018

9.1. As directed by the Contracting Officer (KO), the contractor shall continue performance in emergency or mis-sion essential conditions. Additionally, the Contractor may be required to account for the whereabouts of their per-sonnel should this information be requested by the COR.

Page 11 of 13 Pages

10. Delivery Schedule.

PWS

Task#

Deliverable Title

Format Due Date Distribu-tion/Copies

Frequency and Remarks

6.1.a 6.1.c 6.1.2.1 6.1.3.1 6.1.4.2

SODAS Test Plan (includes both Lab Event and Field Test)

MS Word Format

To be provided in response to this PWS

Once

6.1.4.2 Daily T&E

Event Reports

MS Word For-mat

1800 daily during T&E events Email

6.1.4.2 SODAS T&E

Results Briefings

MS Power Point

7 working days after conclusion of each T&E event

6.1.4.2 SODAS T&E

Report

MS Word 30 calendar days after conclusion of both the Lab and Field Tests

Email with hard copy provided to the COR

1 Report per option year

6.2.7.1 T&E

Automation and Instrumentation Support Whitepaper

MS Word Format

To be provided in response to this PWS

Not to exceed 5 pages

11. Security Requirements. SECRET.

11.1. References:

11.1.1. DOD 5200.2-R, DOD Personnel Security Program.

11.1.2. DISAI 240-110-36, Personnel Security.

11.1.3. DOD 5220.22-M, National Industrial Security Program Operating Manual.

11.1.4. DOD 5220.22-R, Industrial Security Regulation.

11.1.5. DISA Computing Services Directorate (CSD) Security Handbook.

11.1.6. DODM 5200.01, Information Security Program, 24 February 2012

11.2. Facility Security Clearance. Base PWS.

11.3. Security Clearance and Information Technology (IT) Level. Base PWS.

11.4. Investigation Requirements. Base PWS.

11.5. Adjudication for IT Access. Base PWS.

11.6. Interim IT Access. Base PWS.

11.7. Visit Authorization Letters. Base PWS.

11.8. Information Security and Other Miscellaneous Requirements. Base PWS.

11.9. Physical Security Requirements. Base PWS.

12. Government-Furnished Equipment (GFE)/Government-Furnished Information (GFI).

12.1. Base PWS.

12.2. No additional GFE/GFI is projected for this TO.

13. Other Pertinent Information or Special Considerations. The Government requires highly specialized, mul-ti-disciplinary subject matter expertise of USSOCOM’s vast operational and IT architecture; acquisition direc-tives and processes; and tactical biometric capabilities.

13.1. Identification of Possible Follow-on Work. None

13.2. Identification of Potential Conflicts of Interest (COI). Base PWS.

13.3. Identification of Non-Disclosure Requirements. Base PWS.

Page 12 of 13 Pages

13.4. Packaging, Packing and Shipping Instructions. Base PWS.

13.5. Inspection and Acceptance Criteria. Base PWS.

13.6. Property Accountability. Base PWS.

13.7. DoD Enterprise Service Management Framework (DESMF) Compliance. Base PWS.

14. Supply Chain Risk Management (SCRM). Base PWS.

14.1. Deliverable: Base PWS.

14.2. Supply Chain Risk Management Update: Base PWS.

15. Section 508 Accessibility Standards. N/A

Page 13 of 13 Pages

Appendix PM-TB SODAS System Specifications

Requirement Threshold Value Objective Value

Accuracy: Hand-held data collection system shall be able to collect and process DNA samples under all specified conditions listed in Para 3.8.1-3.8.3

95% reliability with 80% confidence

98% reliability with 80% confidence

Transmission Timeliness: Timely transmission of data from Hand-held to docking station using secure transmission link.

60 Seconds with 80% confidence

30 Seconds with 80% confidence

Transmission Security: Secure transmission link between Hand-held and docking station adheres to FIPS 140-2 Level 2 Standards and is registered at:

<http://csrc.nist.gov/groups/STM/cmvp/documents/140- 1/1401val2010.htm>

Pass/Fail Objective = Thresh-old

Data Integrity: System generates NIST’s Secure Hash Algorithm 3 (SHA-3) based on DNA Sequence.

Pass/Fail Objective = Thresh-old

Analysis Request Timeliness: Docking station/database makes DNA Request to AFDIL once received from Hand-held.

30 Seconds with 80% confidence

10 Seconds with 80% confidence

Portal Update Timeliness: Docking station/database updates local SOF Exploitation Node’s portal after AFDIL Detain/Release infor-mation is received.

30 Seconds with 80% confidence

10 Seconds with 80% confidence

Standards Compliance: DNA record’s metadata adheres to XML Format.

AFDIL XML DNA

Request Format

SODAS XML Data Structure

Data Security: Database records shall meet at a minimum NIST Federal Information Processing Standard (FIPS) 140-2 Level 3 Data at Rest protection.

Pass/Fail Objective = Thresh-old

System Access Security: SODAS requires PKI authentication for access.

Pass/Fail Objective = Thresh-old

Attribute Based Access Control: SODAS allows only those indi-viduals with Administrative privileges to change/update a DNA Record within the SODAS database.

Pass/Fail Objective = Thresh-old

Number of Users: SODAS allows up to five simultaneous users within the EAC Network to make database queries or update rec-ords.

Pass/Fail Objective = Thresh-old

Tactical Usability of Handheld: A survey measuring the opera-tors' perceptions of the system's usability and utility, including their opinions on whether the system aided or hindered mission accom-plishment, and whether it had any effects on workload.

System Usability Score of > 70%

System Usability Score of > 90%

Size/Weight: The Hand-held DNA collection system should weigh no more than 10 pounds and be no larger than 18 X 12 X 8 inches in size.

Pass/Fail Objective = Thresh-old

Delivery Indication: Hand-held Device gives SOF Operator posi-tive feedback that DNA Sample analysis request was delivered to the docking station/database system.

Pass/Fail Objective = Thresh-old

GPS Interface: Hand-held will synchronize with GPS satellites and auto-populate the DNA record with the GPS time stamp and geolo-cation data.

Pass/Fail Objective = Thresh-old

Status Indications: Hand-held will give operator feedback on communication link status to GPS and the docking station.

Pass/Fail Objective = Thresh-old

Figure 1. SODAS Data Flow Diagram
Figure 2. SODAS Hand-held DNA Collection Process Flow Diagram

File details come from the government source that posted it. Updated .