DIEMZ80013_PWS_redacted.docx
DOCX document 57 KB Posted
- Attached to
- DISA Risk Management Framework (RMF) Assessment & Authorization (A&A) Support Services for Defense Red Switch Network (DRSN) Internet Protocol (IP) Federal contract opportunity
- Solicitation number
- HC102818R0057
About this file
Performance Work Statement (PWS)
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Soli_3776463_254_FY18.pdf | ||
| Provisions_and_Clauses.docx | DOCX document | |
| QASP.DOCX | DOCX document | |
| DIEMZ80013_Letter_RFP_signed.pdf | ||
| CLIN_Pricing_Worksheet.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
As of October 05, 2017
| Contract Number: |
| TBR |
1. Contracting Officer’s Representatives (CORs).
a. Primary COR:
Name:
Organization:
Department of Defense Activity Address Code (DODAAC):
Address:
Phone Number:
Fax Number:
E-Mail Address:
b. Alternate COR (ACOR):
Name:
Organization:
DODAAC:
Address:
Phone Number:
Fax Number:
E-Mail Address:
2. Task Order Title.
DISA Risk Management Framework (RMF) Assessment & Authorization (A&A) Support Services for Defense Red Switch Network (DRSN) Time Division Multiplexer (TDM) to Internet Protocol (IP) Transition Phase I
3. Background.
The DRSN Program Management Office (PMO) has an immediate requirement to achieve a transitioned Defense Red Switch Network that meets user needs and is within an acceptable level of security risk to operate within the DISA organization. In order to address the security relevant changes that result from the DRSN TDM to IP Transition, the organization must align with DRSN Requirements, Schedule, System Development Lifecycle Milestones, and the DISA Senior Leadership’s plans to request an Authority to Operate (ATO) by 23 November 2017 and brief the Secretary of Defense on transition status on 15 December 2017. Using dedicated Information Assurance (IA) Subject Matter Experts (SME) labor and automated tools to provide a return on investment throughout the RMF A&A process and deliver the Body of Evidence and Reports required to obtain an ATO with Conditions that supports Continuous Monitoring, the following work needs to be accomplished:
Transition Phase I:
1. Apply National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev 4 Risk Management Framework to bring A&A packages and supporting Body of Evidence current for Authorizing Official (AO) approval.
2. Develop new A&A Network Operations Center (NOC) packages for Ft. Meade and Scott AFB using the NIST RMF Workflow/Xacta 2.0, the automated tool that is used to process ATO packages by the 25AF AO.
3. Develop new A&A Master Site Model A&A package to enable the 42 DRSN sites to apply hybrid and site-specific security controls as identified in the NIST SP 800-53 Rev 4The DRSN sites A&A are a separate effort from the Transition Phase I described herein.
4. Objectives.
The overall objective of this PWS is to assist DISA, the DRSN Program Office obtain an ATO for DRSN TDM to IP Transition and to successfully manage and monitor IA and Assessment & Authorization activities and provide senior leaders and the PMO with a DRSN project level A&A Management and oversight of activity, status and issues relating to DRSN TDM to IP Transition.
5. Scope.
The scope outlined in this PWS includes the following:
The contractor will provide programmatic support and assist the DRSN Program Management Office (PMO) and assigned personnel in managing IA and Risk Management Framework (RMF) process by providing technical and administrative assistance to accomplish the following tasks;
· Develop and submit A&A packages for the NOCs at Ft. Meade and Scott AFB to the AO for approval.
· Update DRSN Program A&A package to NIST SP 800-53 Rev 4 using Xacta 2.0 to obtain an ATO for the DRSN TDM to IP Transition Project.
· Develop A&A Master Site Model of security controls attributable to the site and the operator that may be used by the DRSN sites and be modified to meet site specific controls application.
6. Performance Requirements.
The Contractor shall provide the following Defense Red Switch Network Information Assurance and Risk Management Framework Implementation Support in accordance with the NIST RMF Workflow/Xacta 2.0:
6.1 Task 1.0 – Task Order Management.
The Contractor shall ensure that sufficient staffing and appropriately skilled personnel are employed in the execution of this task. The Contractor’s project management shall provide the planning, scheduling, direction, coordination, and control necessary for effective and efficient accomplishment of all requirements. Moreover, this effort shall be consistent with the base contract, referenced documents, and Contractor developed (DISA approved) plans, schedules, and milestones. The Contractor’s project management processes shall verify and validate the level of effort and deliverables for each task. The Contractor shall perform the work and provide the deliverables as specified below:
Subtask 1.1 – The Contractor shall produce and deliver a Project Management Plan for evaluating and answering IA controls in EXACTA and shall update the plan with significant items/events during the execution of this effort. The contractor shall ensure the Project Management Plan describes the technical approach, organizational resources and management controls to be employed to meet the cost, performance, and schedule requirements throughout execution of this effort. Delivery method electronically.
Subtask 1.2 – The contractor shall provide a Weekly Status Report that covers all tasks contained under this effort. The report shall include a description of progress, all results, conclusions and recommendations, changes to the Contractor’s organization, problem areas, cost curves that reflect actual expenditures, trips, significant results, commitments, and the contract schedule status. All deliverables shall be delivered in soft copy email in PDF or Word format.
Subtask 1.3 – The Contractor shall provide a Monthly Progress Review (MPR) including briefing and presentation materials on all requirements covered by this effort. The MPR shall include the progress the contractor has made toward completing the RMF packages covered in this PWS. The MPR will be delivered to the PM in soft copy by e-mail.
Subtask 1.4 – The Contractor shall submit a detailed Trip Report within 10 days of returning from each trip. The Trip Report shall include travel dates, dates on site, and work accomplished while on site. The trip report will be delivered to the PM by soft copy e-mail.
Deliverables:
The collective set of deliverables for Task 1:
1. Project Management Plan
2. Weekly Status Report
3. Monthly Progress Review
4. Trip Reports
5. Briefing and Presentation Materials
6.2 Task 2 – DRSN TDM to IP Project Level A&A Management.
The contractor shall provide DISA with a mutually agreed to process to monitor and manage the TDM to IP project level A&A activities, status, and challenges through the implementation of centralized program management, supporting Top Secret/Secure Compartmented Information (TS/SCI), Nuclear Command, Control and Communications (NC3), and monitoring participating DRSN security stakeholders. This structure would establish a framework and forum for the DRSN PMO to monitor system security authorization packages associated with the DRSN TDM to IP Transition Project in accordance with mandated roles and responsibilities identified in the Project Management Plan.
Project Development; the contractor shall combine high-level principles and disciplines of program/project management with an integrated Project Management framework to give DISA an accurate and current view of the progress of processes at all levels of the TDM to IP Transition including the integrated master schedule and tracking the progress of the accreditation packages in XACTA . The contractor will collaborate with the DRSN PMO to develop high level criteria for critical projects, tasks and milestones to be measured against an integrated master schedule which will reflect the timelines for each of the six phases of the RMF process.
The collective set of deliverables for Task 2:
1. Project Management Critical Path
2. Integrated Master Schedule
6.3 Task 3 – IA Administration.
The contractor shall provide program management services to DRSN PMO and perform the following tasks:
1. The contractor shall set up and facilitate ATO review meetings, provide meeting logistics, capture meeting notes, record action items, decisions, lessons learned and IA data and review documentation for accuracy and completeness. All meeting artifacts shall be posted on DISA’s SharePoint site monthly and the DRSN IA team will review, delivery method Word Document.
2. The contractor will maintain and update DISA’s SharePoint site, to include the development of additional functionality or unclassified repositories, to facilitate communication and provide a repository for policy and processes.
3. The contractor shall update the SharePoint site’s frequently asked questions (FAQs) as needed.
4. The contractor shall respond to data calls from senior leadership and the DRSN PMO. These data call may consist of progress made on each of the six RMF phases, number of controls identified and mitigated. Number and content of Plans of actions and Milestones (POA&M).
5. The contractor shall perform strategic planning activities delineating goals and providing guidance, i.e. devising strategies in meeting specific controls and providing guidance on mitigating vulnerabilities.
Deliverables for Task 3:
1. Materials and Reports extracted from Xacta 2.0 IA Manager
2. SharePoint Repository Development and Maintenance
3. ATO Review Meeting Notes and Artifacts
6.4 Task 4 – ATO Management.
The contractor shall provide performance measurement services to DRSN PMO and perform the following tasks.
1. The contractor shall monitor the A&A status and process for the TDM to IP Transition Project ATO within the DRSN and provide a Weekly ATO Status Report to the DRSN PMO. The ATO Status Reports will be posted to the designated DISA SharePoint site weekly.
2. The contractor shall utilize quantitative methods to evaluate and analyze risks, issues and/or opportunities for the TDM to IP Transition Project and generate metrics and trends, gather data from various sources, conduct trend analysis and generate reports with the risk and issue trends and lessons learned weekly.
3. The contractor shall identify the affect a risk might have on key indicators, analyze those indicators and their reaction to early realization of that risk, develop a profile based analysis, and establish criteria from monitoring for that situation/profile and include within a weekly Metrics Report weekly.
4. The contractor shall ensure all relevant reporting documents are stored in the proper repository share point for the DRSN IP IA status.
Deliverables for Task 4:
1. Weekly ATO Status Report
2. Weekly Risk and Issues Report
3. Weekly Metrics Report
Supporting Deliverables through RMF Steps 1-6 as entered in Xacta 2.0 IA Manager in accordance with NIST SP 800-53 Rev 4 are defined below for the DRSN TDM to IP Transition Project.
Pre-Analysis & Assessment and Validation
· Review Existing Documentation
· Project Registration
RMF Step 1: Categorization
· Initial Discovery Meeting Checklist
· Security Categorization
· Information System Description
RMF Step 2: Select Security Controls
· Security Control Selection Documentation - Security Controls Traceability Matrix
· Common Controls Identification
· Updated Security Control Selection Documentation (After tailoring and Common Controls applied)
· System Security Plan Initiation
· Monitoring Strategy Review of Continuous Monitoring Plan (CMP)
· Security Plan Approval Recommendation
RMF Step 3: Implement Security Controls
· Interview Responsible Entities for Security Controls Implementation
· Validate Information System Inventories to Match Discovery Scans
· Validate Security Controls Traceability Matrix to Match Security Artifacts and Security Plan
· Document Security Control Implementation Develop Test Plan/Test Procedures
· Adjust Authorization Boundaries (If necessary)
· Review vulnerability, discovery, and compliance scans (Nmap, Nessus, SCC, or similar tool)
· Analyze Scans, Integrate Information into Risk Assessment
· Update Risk Assessment with Controls Implementation and Scan Information
RMF Step 4: Assess Security Controls
· Develop Security Assessment Plan
· Security Control Assessment Rules of Engagement/Formal In-brief
· Security Categorization Review
· System Security Plan Analysis
· Security Control Assessment (Self Compliance Testing)
· Vulnerability Assessment
· Security Assessment Report
· Update Risk Assessment with Assessment Results
· Recommended Mitigation Actions and Formal Out-brief
RMF Step 5: Authorize Information System
· Plan of Action and Milestones Development
· Compile Security Authorization Package
· Residual Risk Briefing
· Risk Acceptance Recommendation
RMF Step: 6 Continuous Monitoring
· Maintain POA&M
· Prepare for Phase II Follow-On Services for Updates, Remediation, Reporting, Security Relevant System and Environmental Changes
7. Performance Standards.
The specific performance standards for each of the deliverables required under this PWS are as follows:
| Performance Standard |
| Acceptable Quality Level (AQL) |
| Method of Surveillance |
| Task 1.1 – Project Management Plan. Plan shall be submitted on time and IAW COR guidance. |
| Submitted document is delivered with no required rework. Errors that occur are minor and are resolved in a satisfactory manner. |
| Periodic inspection of deliverable. |
| Task 1.2 – Weekly Status Report. Each Report shall be submitted on time and IAW COR guidance |
| Submitted reports are delivered with no required rework. Errors that occur are minor and are resolved in a satisfactory manner. |
| Periodic inspection of deliverables. |
| Task 1.3 – Monthly Progress Review. Briefing materials shall be submitted on time and IAW COR guidance. |
| Submitted materials are delivered with no required rework. Errors that occur are minor and are resolved in a satisfactory manner. |
| Periodic inspection of deliverables. |
| Task 1.4 - Trip Report. Each Report shall be submitted on time and IAW COR guidance. |
| Submitted reports are delivered with no required rework. Errors that occur are minor and are resolved in a satisfactory manner. |
| Periodic inspection of deliverables. |
| Task 2 – Project Management Critical Path and Integrated Master Schedule. |
| Deliverables are complete and timely without revision at least 90% of the time. |
| Routine inspection of deliverables. |
| Task 3 – Monthly Meeting Artifacts, SharePoint Repositories and documentation. |
| Submitted documents are delivered with no required rework. Errors that occur are minor and are resolved in a satisfactory manner. |
| Periodic inspection of deliverables. |
| Task 4 – Weekly ATO Status Report, Weekly Risk and Issues Report, Weekly Metrics Report. |
| Deliverables are complete, timely and meet technical objectives without revision at least 90% of the time. |
| Monthly inspection of deliverables by the DRSN PM. |
8. Incentives.
Both positive and negative performance will be documented in past performance reports/database, Contractor Performance Assessment Reporting System (CPARS), as appropriate and will be taken into consideration for follow-on work.
9. Place of Performance.
Both Contractor and Government Offices. Contractor personnel will be provided with non-designated workspace that is co-located with the Government COR located at the government offices at Ft. Meade, Maryland, San Antonio, Texas, and Scott AFB, Illinois. Contractor personnel may be required to support work, such as site surveys and implementation activities at CONUS and OCONUS U.S. facilities/bases, but this work is anticipated in Phase II with DRSN site visits.
10. Period of Performance.
September 15, 2018 through February 15, 2019.
As directed by the COR, the Contractor shall continue performance in emergency or mission essential conditions. Additionally, the Contractor may be required to account for the whereabouts of their personnel should this information be requested by the COR.
11. Delivery Schedule
The Contractor shall store and disseminate Contract Deliverables according to the specific requirements listed below for each Contract Deliverable. The Contractor shall provide a secure, digital storage capability at the Contractor facility for posting the Contract Deliverables to the DISA software, portal, and websites that the Government may direct, as applicable. The Contractor shall utilize an e-mail notification Standard Distribution to notify the Government when deliverables have been posted and are available for retrieval.
The Contracting Officer (KO), the COR and the ACOR shall have access to all of the Contract Deliverables. The COR and the ACOR shall have access to all deliverables related information, without exception. A Contract Deliverable transmittal cover letter shall be provided to the KO for each Contract Deliverable for contract audit purposes. All Contract Deliverables such as briefings, graphics, project schedules, spreadsheets, reports, and other documents shall be provided using software that is compatible with the Government (i.e., Microsoft Word, PowerPoint, Visio, Access, Project, and Excel) as applicable. Other formats such as Adobe Portable Document Format (PDF), Hyper Text Markup Language (HTML) or other acceptable applications may be used as directed by the COR as long as the Government is also provided an editable copy. The Contractor shall use the server or servers provided by the Government for the hosting of databases as contained in this PWS. Specific delivery details for each Contract Deliverable are:
| PWS Task# |
| Deliverable Title |
| Format |
| Due Date |
| Distribution Copies |
| Frequency and |
Remarks
| 1.1 |
| Management Plan |
| Government Approved Format |
| 20 days after contract award |
| 1 copy/Standard Distribution* |
| Updates as necessary. |
| 1.2 |
| Weekly Status Report |
| Government Approved Format |
| The following Monday of every week |
| 1 copy/Standard Distribution* |
| 1x/week |
| 1.3 |
| Monthly Progress Review |
| Government Approved Format |
| The first Monday of every month or as requested by the COR |
| 1 copy/Standard Distribution* |
| 1x/month and at the end of Phase I |
| 1.4 |
| Trip Reports |
| Contractor format |
| 30 days after tasking |
| 1 copy/Standard Distribution* |
| As tasked |
| 2 |
| Critical Path and Integrated Master Schedule |
| Contractor format |
| 30 days after award |
| Standard Distribution* |
| As tasked |
| 3 |
| ATO Review Meeting Notes, Artifacts, Materials/ Papers |
| Contractor format |
| 30 days after tasking |
| Standard Distribution* |
| As tasked |
| 4 |
| Weekly ATO Status Report |
| Government Approved Format |
| The following Monday of every week |
| 1 copy/Standard Distribution* |
| As needed |
| 4 |
| Weekly Metrics Report and Weekly Risk and Issues Report |
| Government Approved Format |
| The following Monday of every week |
| Standard Distribution* |
| As tasked |
*Standard Distribution
| • | One electronic copy of the transmittal letter without the deliverable to the Contracting Officer (KO/DITCO/PL) and Contracting Officer’s Representative |
| • | One electronic copy of the transmittal letter and the deliverable to the primary COR/Alt COR |
12. Security Requirements.
This section shall be considered a supplement to Block 13 of the Government provided DD Form 254, Contract Classification Specification. Also see the attached DD Form 254. The following security requirements shall apply to this effort:
References:
a. DoD 5200.2-R, DoD Personnel Security Program (PSP).
b. Defense Information Systems Agency Instruction (DISAI) 240-110-36, Personnel Security.
c. DoD Manual (DoDM) 5220.22-M, National Industrial Security Program Operating Manual.
d. DoD 5220.22-R, Industrial Security Regulation.
e. DoDI 5200.01, Vol 1-4, Information Security Program, 24 February 2012.
f. DISAI 240-110-8, Information Security.
g. DISA Policy Letter, Unauthorized Connections to Network Devices, 11 Sep 2013.
h. DISA Form 786.
12.1 Facility Security Clearance.
This effort requires work to be performed at Government-owned and operated Facilities. In addition, this PWS requires work to be performed at Contractor Facilities as well as at an Alternate Place of Performance as determined by the COR. The work to be performed under this effort is up to the Top Secret level and will require Sensitive Compartmented Information (SCI) access eligibility for some personnel. Therefore, the company must have a final Top Secret Facility Clearance (FCL) from the Defense Security Service (DSS) Facility Clearance Branch (FCB) at time of award. All contractor personnel assigned to this PWS must possess at a minimum, a Top Secret eligible security clearance on file with DISA prior to commencement of work activities under this PWS. Contractors will require an SCI briefing and will be provided access to Secret Internet Protocol Routing Network (SIPRNet) and Joint Worldwide Intelligence Communications System (JWICS) at the Government site for the execution of the applicable portions of the requirements herein.
12.2 Security Clearance and Information Technology (IT) Level.
All personnel performing on or supporting this DISA effort will be U.S. citizens. The levels of personnel security requirements under this effort covering the following types of positions:
12.2.1 The following types of positions require a final Top Secret security clearance and final IT-I (privileged level systems access) eligibility when performance starts. Immediately upon hire, the incumbents will require SCI access eligibility adjudicated by the Defense Intelligence Agency (DIA) or other Federal Adjudication Facility to perform their duties. SCI Processing for SCI eligibility will be coordinated with the supporting Government Security Manager and will begin immediately upon start of duty performance under this PWS. For NATO Information, access up to and including Top Secret/SCI material will be required for reference at the DISA HQ Facility at Fort Meade, Maryland, 25th/ACC at San Antonio, Texas, and NOC at Scott AFB, Illinois. The following contractor positions will require access to JWICS at a designated Government Facility:
· Enterprise IT Solutions Engineer Expert Lead
· INFOSEC Engineer Expert
· Program Manager
All SCI work will be monitored by the COR in conjunction with the respective Task SME (Mr. Terrence H. Wolfsen or Mr. Jose M. Rodriguez).
12.3 Investigation Requirements.
All personnel requiring Top Secret, SCI, IT-I eligibility under this effort, to include system access to the lab environments, must undergo a favorably adjudicated Single Scope Background Investigation (SSBI) as a minimum investigation. The SSBI will be maintained current within 5-years and requests for Special Background Periodic Review (SBPR) will be initiated prior to the 5-year anniversary date of the previous SSBI or SBPR.
All Contractor personnel requiring access to the systems in the FMLTC on this PWS require privileged user (IT-I) access, supported by an SSBI. Contractor personnel who do not have IT-I access are prohibited from working on the equipment in the lab.
12.5 Visit Authorization Letters (VAL).
Visit requests shall be processed and verified through the Joint Personnel Adjudication Data Base (JPAS) to SMO DKABAA10 and SMO DKADAL. JPAS visits for contracts are identified as “Other” or “TAD/TDY” and will include the Contract Number and ADP/IT-Access Level of the contract in the Additional Information section. Contractors that do not have access to JPAS may submit visit authorizations by e-mail in a password protected pdf to the COR or Government Point of Contact (POC). The COR/ACOR contact details are as follows:
a. Primary COR:
Name:
Organization:
Department of Defense Activity Address Code (DODAAC):
Address:
Phone Number:
Fax Number:
E-Mail Address:
b. Alternate COR:
Name:
Organization:
DODAAC:
Address:
Phone Number:
Fax Number:
E-Mail Address:
If JPAS is not available, The VAL must contain the following information on Company letterhead:
Company name, address, telephone number, assigned CAGE Code, facility security clearance Contract Number Name, SSN, date and place of birth, and citizenship of the employee intending to visit Certification of personnel security clearance and any special access authorizations required for the visit (type of investigation & date, adjudication date & agency, and IT access level) Name of COR/POC Date or period the VAL is to be valid
12.6 Security Contacts.
DISA Security Personnel can be contacted for security related questions as follows:
For Industrial Security or Personnel Security related issues contact (301) 225-1235 or via mail at:
Defense Information Systems Agency ATTN: MP61, Industrial Security Command Building 6910 Cooper Ave.
Fort Meade, MD 20755-7088
Defense Information Systems Agency ATTN: MP62, Personnel Security 6910 Cooper Ave.
Fort Meade, MD 20755-7088
12.7 Information Security and Other Miscellaneous Requirements.
12.7.1 Contractor personnel must comply with local security requirements for entry and exit control for personnel and property at the Government Facility.
12.7.2 Contractor employees will be required to comply with all Government security regulations and requirements. Initial and periodic safety and security training and briefings will be provided by Government security personnel. Failure to comply with Government security regulations and requirements will require the Company to provide the Government with a written remediation/corrective action plan. Furthermore, failure to comply with such regulations and requirements can be cause for removal from the PWS and the Contractor employee will not be able to provide service on this contract.
12.7.3 Contractor employees with an incident report in JPAS will not be permitted to provide service on a DISA contract.
12.7.4 The Contractor shall not divulge any information about DoD files, data processing activities or functions, user identifications, passwords, or any other knowledge that may be gained, to anyone who is not authorized to have access to such information. The Contractor shall observe and comply with the security provisions in effect at the DoD facility. Identification shall be worn and displayed as required.
12.7.5 DISA retains the right to request removal of Contractor personnel regardless of prior clearance or adjudication status, whose actions, while assigned to this contract, clearly conflict with the interest of the Government.
12.7.6 Contractor personnel will generate or handle documents that contain FOUO information at Contractor and/or Government Facilities. The Contractor shall have access to, generate, and handle classified material only at the locations listed in the Place of Performance section of this PWS. All Contractor deliverables shall be marked in accordance with DoDI 5200.1, Vol. 3, Vol. 4, Information Security, DoD 5400.7-R, Freedom of Information Act Program, unless otherwise directed by the Government. The Contractor shall comply with the provisions of the DOD Industrial Security Manual for handling classified material and producing deliverables. The Contractor shall comply with DISA Instruction 630-230-19. The Contractor shall be required to have access to COMSEC material. The Contractor shall be required to courier classified material up to the SECRET level in and around the National Capital Region (NCR) area.
12.7.7 The Contractor may be assigned by the Functional Area Government DIV/Branch Chief job order numbers associated with the specific project(s) they are working.
13. Government-Furnished Equipment (GFE)/Government-Furnished Information (GFI).
During this period of performance, the Contractor may be required to purchase equipment as requested by the COR. Upon completion of the contract period, the Contractor shall contact and receive disposition instructions from the COR for all GFE managed by the Contractor. All GFE shall remain compliant with all information security/assurance guidelines and requirements to minimize vulnerability to networks. All GFE shall be inventoried annually by the COR or a COR-designated representative to ensure proper accountability of equipment. The Contractor shall not purchase any IT accountable items (desktops, laptops, printers, or software) as ODCs without the approval of the COR. Any purchases valued greater than $5,000 will require the approval of the COR. Any accountable property that is inventoried will be labeled with a DISA bar code and entered into the property book. The Government property POC will work with the Contractor to resolve any discrepancies found during the yearly inventory phase. During the period of performance, the Contractor may be required to receive accountable equipment via hand-receipt as requested by the COR to evaluate the performance of items, systems and networks. Upon completion of the contract period or termination the said Contractor staff’s function, the Contractor shall return received accountable equipment to the DISA property custodian or contact and receive disposition instructions from the COR.
The Contractor will be provided the following Government support as GFI/GFE in support of contract to complete the work outlined for this PWS.
13.1 DISA technical libraries and all documents referenced in this PWS.
13.2 Information on DISN systems and subsystems as developed by other Government units that may affect this task.
13.3 Office work space as required and agreed upon by the contractor Program Manager, and COR.
13.4 The DISA DRSN PMO will provide the contractor a formal configuration hardware, software, and operating system equipment list, ports-protocols-services (PPS), data flows, network configuration drawings, vulnerability scans, and related manufacturer’s/vendor’s materials as GFI.
14. Other Pertinent Information or Special Considerations.
a. Identification of Possible Follow-on Work Not Included in the Scope of this Contract.
1. Phase II anticipates further DRSN programmatic build of projects and initiatives.
2. Phase III provides continued DRSN programmatic implementation and management.
3. Phase IV completes the effort of ongoing Continuous Monitoring for fully sustained DRSN operations.
i. Review & update all system operating characteristics, based on changes
ii. Periodically review control selection criteria, based on dynamic threat
iii. Maintain inventory of resources – technology, people, processes
iv. Test controls
v. Maintain/Remediate system, controls, and all security relevant documentation
vi. On-going security status reporting
b. Identification of Potential Conflicts of Interest (COI). N/A
c. Identification of Non-Disclosure Requirements. Distribution and access to the material prepared under this PWS shall be limited to DISA Personnel and direct support contractors. The material prepared by one vendor shall not be divulged to any other vendor.
d. Packaging, Packing and Shipping. N/A
e. Inspection and Acceptance Criteria. N/A
f. Property Accountability. N/A
g. Key Personnel. The Contractor shall propose key personnel with recent, relevant technical background and operational work experience that addresses the minimum qualifications and disciplines outline herein, to include network security, Risk Management Framework (RMF) requirements and IA, to affect the requirements of this PWS. The contractor shall provide current resumes of key personnel being proposed to work on this PWS. The Contracting Officer or his/her authorized representative will evaluate such requests and promptly notify the Contractor of the approval or disapproval thereof, in writing. The Contractor agrees that key personnel shall not be removed from the contract work or replaced without compliance with the following:
· If one or more key personnel for whatever reason becomes, or is expected to become, unavailable for work under this effort for a continuous period exceeding 15-calendar days, or is expected to devote substantially less effort to the work than indicated in the proposal as initially anticipated, the Contractor shall promptly notify the Contracting Officer. Upon concurrence of the Contracting Officer or his/her authorized representative, the Contractor shall promptly replace such personnel with personnel of at least substantially equal ability and qualifications.
· All requests for approval of substitutions hereunder must be in writing and provide a detailed explanation of the circumstances necessitating the proposed substitution(s). They must contain a complete resume for the proposed substitute, and any other information requested by the Contracting Officer or needed by him/her to approve or disapprove the proposed substitution. The Contracting Officer or his/her authorized representative will evaluate such requests and promptly notify the Contractor of the approval or disapproval thereof, in writing.
· For other than key personnel, the Government will consider requests for waivers of Personnel Qualifications education and/or experience requirements on a case-by-case basis. Approval of any such requests will be at the sole discretion of the Government.
h. Information Assurance (IA)
· IAW DOD Directive 8570.01-M Contractor personnel requiring ‘root’ access and have IA responsibilities on the Defense Information Systems Agency’s information systems must meet applicable IA Technical (IAT) or IA Managerial (IAM) training and certification requirements.
· DOD Directive 8570/01-M requirements (DFARS Clause 252.239-7001). The Contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DOD 8570.01-M, Information Assurance Workforce Improvement Program. The Contractor shall meet the applicable information assurance certification requirements, including: DOD- approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DOD 8570-M; and Appropriate operating system certification for information assurance technical positions as required by DOD 8570.01-M. Contractor should propose the mix of categories and levels to meet the requirements of DOD 8570.01-M in their Program Management Plan (PMP).
15. Section 508 Accessibility Standards.
The following Section 508 Accessibility Standard(s) (Technical Standards and Functional Performance Criteria) are applicable (if box is checked) to this acquisition.
Technical Standards
|_| 1194.21 - Software Applications and Operating Systems |X| 1194.22 - Web Based Intranet and Internet Information and Applications |_| 1194.23 - Telecommunications Products |_| 1194.24 - Video and Multimedia Products |_| 1194.25 - Self-Contained, Closed Products |_| 1194.26 - Desktop and Portable Computers |X| 1194.41 - Information, Documentation and Support
The Technical Standards above facilitate the assurance that the maximum technical standards are provided to the Contractor. Functional Performance Criteria is the minimally acceptable standards to ensure Section 508 compliance. This block is checked to ensure that the minimally acceptable electronic and information technology (E&IT) products are proposed.
Functional Performance Criteria
|_| 1194.31 - Functional Performance Criteria
File details come from the government source that posted it.