Attachment 1 - Operations Task Order.doc

DOC document 380 KB Posted

Attached to
Defense Information Systems Agency Information Technology Enterprise Support Services Federal contract opportunity
Solicitation number
HC1047-12-R-4013
Issued by
Defense Information Systems Agency

View the file

Other files for this federal contract opportunity

Other files attached to Defense Information Systems Agency Information Technology Enterprise Support Services, newest first.
File Type Posted
DRFP QA - Final.pdf PDF
Attachment 3 - Knowledge Management Sample Task Order.doc DOC document
Attachment 12 - Past Performance Client Authorization Letter.docx DOCX document
Attachment 6 - Enterprise Architecture Sample Task Order.doc DOC document
Attachment 16 - Question-Answer Template.docx DOCX document
DRFP HC1047-12-R-4013.doc DOC document
Attachment 14 - Labor Category Definitions.doc DOC document
Attachment 10 - Past Performance Questionnaire Cover Letter and Questionnaire.docx DOCX document
Attachment 2 - Information Assurance Sample Task Order.doc DOC document
Attachment 15 - Certificate of Non-Disclosure.docx DOCX document
Attachment 7 - Form 1 Tasking Template.doc DOC document
Attachment 9 - Contractor Roster List.xls XLS spreadsheet
Attachment 4 - Application Management Sample Task Order.doc DOC document
Attachment 8 - Applicable Policy References and Guidance.doc DOC document
Attachment 11 - Subcontractor-Teaming Partner Consent Letter.docx DOCX document
Attachment 5 - IT Service Management Sample Task Order.doc DOC document
Attachment 13 - CLIN Structure and Labor Pricing.xls XLS spreadsheet
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Defense Information Systems Agency

Chief Information Officer DISA Information Technology Enterprise Support Services (DESS)

HC1047-12-D-XXXX

Task Order (TO) 0001 (Version 1.0)

31 January 2012 Table of Contents

1Chief Information Officer

1DISA Information Technology Enterprise Support Services (DESS)

11.

Task Order Contracting Officer Representative’s (COR’s)

11.1 Primary Task Order COR:

11.2 Alternate Task Order COR:

12.

Task Order Title:

23.

Background

44.

Objectives

55.

Scope

55.1 Task Order Administration

55.2 IT Service Desk

55.3 Information and Mission Assurance

65.4 Global Cable Plant

65.5 IT Enterprise Architecture

65.6 Network, Application and Server Engineering

65.7 Transition and Implementation of Enterprise Services

76.

Specific Tasks

76.1 Task 1 – Task Order Administration

76.2 Task 2 – IT Service Desk Support

126.3 Task 3 – Information Assurance Incidents and Problem Management Support

156.4 Task 4 – Cable Plant Management Support

166.5 Task 5 - Enterprise Architecture Support

186.6 Task 6 - Solution Engineering and Deployment Support

246.7 Task 7 – Transition to Enterprise Services Support

257.

Place of Performance

257.1 Primary Place of Performance

277.2 Alternate Place of Performance

278.

Travel Requirements

289.

Period of Performance

2810.

Task Order Deliverables

2811.

Task Order Service Levels and Performance Metrics

2812.

Security Requirements

2812.1 The VAR/VAL should be sent via one of two methods.

3113.

Government-Furnished Equipment (GFE)/Government-Furnished Information (GFI)

3113.1 Contractor Access

3113.2 GFI Listing

3114.

Other Pertinent Information or Special Considerations

3114.1 Identification of Potential Conflicts of Interest (COI).

3114.2 Identification of Non-Disclosure Requirements.

3214.3 Inspection and Acceptance Criteria.

3215.

Section 508 Accessibility Standards

Task Order Number:
HC1047-12-D-XXXX-0001

1. Task Order Contracting Officer Representative’s (TO COR’s)

Primary Task Order COR:

Name:
John A. Doe
Organization:
DISA/CIO

Department of Defense Activity

Address Code (DODAAC):

HC1047

Address:
Defense Information Systems Agency

DISA HQ Complex (Command Bldg)

6910 Cooper Ave

For Meade, MD, 20755

Phone Number:
301-225-XXXX
Fax Number:
301-225-XXXX
E-Mail Address:
john.a.doe@disa.mil

Alternate Task Order COR:

Name:
Jane A. Doe
Organization:
DISA/CIO

Department of Defense Activity Address Code (DODAAC):

HC1047

Address:
Defense Information Systems Agency

DISA HQ Complex (Command Bldg)

6910 Cooper Ave

For Meade, MD, 20755

Phone Number:
301-225-XXXX
Fax Number:
301-225-XXXX
E-Mail Address:
jane.a.doe@disa.mil

2. Task Order Title:

Defense Information Systems Agency’s (DISA’s) Information Technology (IT) Enterprise Support Services (DESS) Operational Support.

3. Background The Defense Information Systems Agency is a Combat Support Agency responsible for connecting US Forces and their coalition partners to the DoD’s Global Information Technology (IT) Enterprise. DISA provides IT networks, computing infrastructure, and enterprise services in direct support of US Warfighters to facilitate the seamless exchange of information on a global scale.

The mission of DISA’s Chief Information Officer (CIO) is to, “Lead and govern the delivery and operation of secure world-wide enterprise IT services enabling the efficient and effective execution of DISA’s global combat support missions.” In order to accomplish this mission, the DISA CIO must:

· Provide an efficient and effective IT infrastructure and services to support the Agency’s warfighting mission.

· Achieve a Mission Assurance posture that ensures the security and continuity of the Agency’s internal IT Enterprise’s infrastructure and services against an ever evolving spectrum of threats.

· Maintain compliance with all DOD information governance policies and legislation.

· Govern a common architecture and service delivery framework to drive efficiencies in business system investments and portfolio and knowledge management capabilities.

DISA’s Office of the Chief Information Officer (CIO) operates and maintains the agency’s internal Information Technology (IT) enterprise, which provides administrative computing services to the DISA Director, the majority of agency’s civilian, military and support contractor personnel and secure workspaces located within industry partner’s commercial facilities. DISA’s internal Information Technology (IT) enterprise provides internal unclassified, secret, and top secret communications across DISA’s 39 worldwide locations. High visibility customers include the Pentagon and the White House Communication Agency. DISA’s internal enterprise includes all hardware, software, middleware, cable plant infrastructure, technical settings, tools, devices and configurations, including all supporting infrastructure and related ancillary and functional components, that are required to provide IT services across three classification levels (e.g., unclassified, secret, and top secret). These components, referred to herein as “DISA IT Enterprise Components" include, but are not limited to, all servers, desktop terminals, laptops, cables, routers, switches, firewalls, intrusion detection systems and voice capabilities (e.g., telephones) and supporting infrastructure. The DISA CIO’s IT Operations Center is responsible for monitoring and operating all components of the agency’s internal enterprise.

The DISA CIO’s IT Operations Center must ensure that the agency’s global internal network, applications, monitoring & reporting capabilities, engineering capabilities, server operations, administration, Tier’s 1/2/3 Service Desk support, telephone and VOIP services, information security functions, and audio visual and Video Teleconference (VTC) capabilities, are available to support the agency’s mission on a 24/7/365 basis. The IT Operations Center’s activities ensure that DISA’s full complement of IT services is contiguously provided to approximately 8,200 users at 39 CONUS and OCONUS locations.

The DISA IT Enterprise Service Desk is organized into three tiers: Tier I, Tier II and Tier III. Tier I is the initial support level responsible for gathering the customer’s information and trying to determine the customer’s issue by analyzing the symptoms to determine the problem. The resolution capabilities of Tier I technicians are typically limited to well known or documented problems and network outages. Tier I technicians should be able to handle over 90% of users problems without escalating the issue to the next level. DISA IT Enterprise’s Tier II support contains more experienced and knowledgeable personnel. Resolution of Tier II problems usually requires a desk side visit, or the utilization of remote control tools used to take over the user’s machine, and typically involves returning a DISA IT Enterprise component to an established baseline. These functions require systems administration privileges and/or replacements of various hardware components, software repair, or diagnostic testing to identify and troubleshoot the problem. Tier III is DISA IT Enterprise’s highest level of support and is responsible for handling the most difficult problems. Resolution of Tier III issues require expert-level troubleshooting and analysis methods, and often require vendor-specific support. DISA IT Enterprise’s Tier III technicians also conduct technical research to develop solutions for new or recurring problems. If DISA IT Enterprise’s Tier III technicians determine that a problem can be solved, they are responsible for designing, developing and testing the solution. Detailed information regarding the DISA IT Enterprise call Center/Helpdesk procedures can be found in the attached DISA IT Enterprise Tier I, II and III Incident Management SOP’s.

DISA’s internal IT enterprise provides access to DoD networks on three classification levels and provides the following services:

· Office Productivity Applications

· Internet and Intranet access

· Voice and Video over IP

· Video Teleconference (VTC)

· Voice Over Secure IP (VOSIP)

· Information Services

· Data Storage and Access to mission oriented databases

· Access to applications maintained on non-DISA networks

· Defense Red Switch Network (DSRN)

· Collaborative Services

· Remote-Access and Teleworking support

· Communications Security (COMSEC)

· Message Services

US government personnel assigned to the CIO’s IT Operations Center manage the operation of DISA’s internal IT enterprise with support contractors performing many functions. Responsibilities across these functions are delineated as either contractor or government functions (see Appendix). As a result, there are numerous touch points between contractor and government personnel executing their responsibilities.

DISA’s internal IT Enterprise provides the full complement of IT services for approximately 4,200 DISA employees at the DISA Headquarters Building (1.1 million square feet of total office space) located at Fort Meade, as well as an additional 4,000 DISA employees accessing the enterprise via Local Area Networks (LAN’s) located at 39 continental US (CONUS) and overseas (OCONUS) Department of Defense (DoD) locations. A major portion of DISA’s IT Enterprise service work is performed at the DISA Headquarters. Additionally, a significant amount of the work is performed by support teams traveling to the agency’s CONUS and OCONUS DoD locations. All of DISA’s internal IT Enterprise services are Local Area Network (LAN) based, and operate within the boundaries of the DISA facility D-mark and the desktop.

DISA’s global IT enterprise network is comprised of the data, voice and video infrastructure that supports the mission requirements of the DISA Director, its Strategic Business Units and subordinate Directorates. The enterprise employs over 550 physical and virtual servers on three classification levels, and uses approximately 9 principle tool suites to monitor its world-wide status. The DISA IT enterprise provides network access to mission oriented databases and applications maintained on non-DISA networks. In total, the enterprise supports over 8,200 DISA users worldwide. The services provided by DISA’s internal IT Enterprise are currently based out of Fort Meade, Maryland. However, DISA is anticipating numerous consolidation initiatives for its IT infrastructure and anticipates that DISA’s CONUS and OCONUS locations will be acquiring support services from the DISA IT Enterprise base at Fort Meade.

4. Objectives The objective of this Task Order is to enable the DISA CIO to deliver operational excellence in the day-to-day operation of agency’s internal IT enterprise. The ability to deliver stable and efficient operation of the agency’s IT services and supporting infrastructure are a critical enabler of DISA’s warfighting support mission, and an essential component of delivering combat support in the dynamic and threat-intensive environment of 21st century cyberspace. Specifically, the objectives of the DISA CIO’s IT Enterprise Operations Center are to:

· Deliver excellence in IT Service Desk support

· Achieve and maintain robust and a Information and Mission Assurance (IA and MA) posture across DISA’s internal IT enterprise

· Manage and improve the efficiency of the IT Cable Plant and supporting infrastructure

· Effectively leverage Enterprise Architecture practices to enhance the enterprise’s overall performance

· Engineer and deploy solutions to Network, Server and Applications incidents, problems and events

· Seamlessly transition to DoD provided Enterprise Services

5. Scope This Task Order encompasses the full range of operational support capabilities that are required by the DISA CIO to operate, maintain, and modernize the agency’s internal IT enterprise. The functional scope of the tasks associated with this effort is detailed below.

Task Order Administration The contractor shall provide the government three specific deliverables to identify and demonstrate the contractor’s plan to transition the responsibilities identified in this Task Order, provide management oversight to the contractor’s workforce, and manage the contractor’s professional relationship with the Government throughout the lifecycle of the Task Order. The three deliverables associated with this effort are a Transition Plan, a Project Management Plan and a Concept of Operations.

IT Service Desk The contractor shall provide technical services to perform the mission of the DISA IT Enterprise Tier I, Tier II, and Tier III Service Desk and Network Monitoring functions. Additionally, the contractor shall provide a limited amount of Tier II Service Desk support as directed by the government. The tasks specified in this area designed to improve the performance and enhance the capabilities of DISA’s IT Enterprise Service Desk.

Information and Mission Assurance The contractor shall provide technical expertise to the IA Team responsible for ensuring the security posture of DISA’s internal IT enterprise. The tasks specified in this area are designed to develop, implement and maintain a comprehensive security strategy for DISA’s internal IT enterprise while remaining compliant with all applicable DoD Directives and Instruction pertaining to Information Assurance.

Global Cable Plant The contractor shall provide technical expertise to install, test, maintain, evaluate, and repair all DISA IT enterprise cable plant infrastructure. These tasks include the development of Cable Plant documentation (i.e., cable infrastructure upgrade design documents), maintenance and repair status reports, configuration management documentation, operational instructions, and engineering specifications.

IT Enterprise Architecture The contractor shall provide technical expertise to develop and maintain DODAF views and conduct technical analysis on DISA’s internal IT enterprise components to enable the government’s ability to make data driven decisions regarding future investment in best-practices (i.e., ITIL & eTOM) process improvements in the areas of, but not limited to, Configuration Management (CM), Asset Management (AM), Knowledge Management (KM) and IT Enterprise Portfolio and Program Management (EPPM) capabilities.

Network, Application and Server Engineering The contractor shall provide technical subject matter expertise to design, develop, test and implement technical engineering solutions to resolve Network, Application and Server events, problems and incidents. In addition to technical solution development, the contractor shall provide subject matter expertise to evaluate the effectiveness and efficiency of the business process in the CIO’s IT Operations Center as part of a technical and non-technical continuous process improvement initiative to increase the performance of the CIO’s IT operations center and reduce the number of events, problems, and incidents occurring on DISA IT Enterprise Components.

Transition and Implementation of Enterprise Services The contractor shall provide subject matter expertise to conduct technical and non-technical analysis in support of DISA transition from DISA-hosted IT services to DoD-provided Enterprise Services (i.e., DoD Enterprise Email and DOD Enterprise SharePoint). The contractor shall conduct analysis to enable the government’s ability to make data driven decisions regarding, but not limited to, the compatibility of existing DISA IT Enterprise Components to interoperate with DoD Enterprise Services applications, the validity of transition plans for implementing DoD Enterprise Services, the operational effectiveness of implemented DoD Enterprise Services, and changes and/or impacts to the existing Life Cycle Management Plan for DISA IT Enterprise Components.

6. Specific Tasks

Task 1 – Task Order Administration 30 days after Task Order award, the Contractor shall provide the Government with the following:

6.1.1 DESS Transition Plan

The Contractor(s) shall submit to the Government, a Transition Plan that details the contractor(s) plan for assuming the professional responsibilities identified in this Task Order within 60 days of Task Order award.

6.1.2 DESS Program Management Plan

The Contractor(s) shall submit to the Government, a Project Management Plan (PMP) that details the contractor(s) plan for completing the tasks identified in this Task Order.

6.1.3 DESS Concept of Operations

The Contractor(s) shall submit to the Government, a Concept of Operations (CONOPS) that details the contractor(s) plan for managing their professional relationship with the Government.

Task 2 – IT Service Desk Support

6.1.4 Provide 24x7x365 Tier I Services to the DISA IT Enterprise Service Desk

6.1.4.1 Provide Tier I Service Desk Support, IAW the DISA IT Enterprise Tier I Incident Management SOP, to DISA IT Enterprise Users and DISA Field Office DISA IT Enterprise System Administrators.

6.1.4.2 Develop improvements/enhancements based on industry best practices (for example ITIL, eTOM and HDI, etc.) to increase the accuracy and efficiency of the DISA IT Enterprise Tier I Incident Management SOP.

6.1.4.3 Serve as the Single Point of Contact (SPOC) on the DISA IT Enterprise Service Desk for the coordination, execution/resolution, and optimization of Tier I Incident Management capabilities.

6.1.4.4 IAW the DISA IT Enterprise Tier I Incident Management SOP, record, assess, track, monitor, and escalate trouble tickets for DISA IT Enterprise incidents and problem resolution, and verify with the DISA IT Enterprise customer when the incident/problem has been resolved.

6.1.4.5 Upon receipt of a fix notice from Tier II, request verification from the user that the problem is resolved and close the trouble tickets IAW the Incident Management Tier I SOP when the fix has been verified by the user.

6.1.4.6 Provide technical expertise sufficient to conduct Tier I level troubleshooting against known problems or outages and take corrective action to resolve the incident.

6.1.4.7 Perform Tier I problem recording and classification IAW the DISA IT Enterprise Tier I Incident Management SOP.

6.1.4.8 Identify and record Tier I errors IAW the DISA IT Enterprise Tier I Incident Management SOP.

6.1.4.9 Provide technical expertise sufficient to resolve Tier I problem arbitration.

6.1.4.10 Conduct technical analysis to develop a Weekly Tier I Trend Analysis Report, based on government defined parameters, which identify the cause of increases and/or decreases (i.e., design changes, outages, events, and other network impact occurrences) in trouble ticket trends.

6.1.4.11 Populate and maintain the content of the DISA IT Enterprise Knowledgebase (i.e., the known error database) self-help service.

6.1.5 Provide Afterhours and Weekend/Holiday Tier II Services to the DISA IT Enterprise Service Desk

6.1.5.1 Provide Tier II Service Desk Support services, as directed by the Government, IAW the DISA IT Enterprise Tier II Incident Management SOP, to end users and Field Office System Administrators.

6.1.5.2 Develop improvements/enhancements (based on industry best practices (for example ITIL, eTOM and HDI, etc.) to increase the accuracy and efficiency of the DISA IT Enterprise Tier II Incident Management SOP.

6.1.5.3 Resolve and or escalate Tier II incidents IAW the DISA IT Enterprise Tier II Incident Management SOP.

6.1.5.4 Perform Tier II problem recording and classification IAW the DISA IT Enterprise Tier II Incident Management SOP.

6.1.5.5 Identify and record Tier II errors IAW the DISA IT Enterprise Tier II Incident Management SOP.

6.1.5.6 Provide technical expertise sufficient to resolve DISA IT Enterprise Tier II problem arbitration.

6.1.5.7 Perform Tier II trend analysis IAW the DISA IT Enterprise Tier II Incident Management SOP.

6.1.5.8 Perform Tier II operational troubleshooting and problem resolution for all DISA IT Enterprise Components.

6.1.5.9 Monitor and report the impact of design changes IAW the DISA IT Enterprise Tier II Incident Management SOP.

6.1.5.10 Troubleshoot and resolve DISA IT enterprise Cable Plant outages and throughput degradations.

6.1.6 Provide 24X7X365 Tier III Services to the DISA IT Enterprise Service Desk

6.1.6.1 Provide Tier III Service Desk Support services, IAW the DISA IT Enterprise Incident Management Tier III SOP, to all DISA IT Enterprise Components.

6.1.6.2 Develop improvements/enhancements based on industry best practices (e.g. ITIL, eTOM and HDI, etc.) to increase the accuracy and efficiency of the DISA IT Enterprise Tier III Incident Management SOP.

6.1.6.3 Perform Tier III troubleshooting and problem resolution on all DISA IT Enterprise Components.

6.1.6.4 Monitor and report the impact of design changes IAW the DISA IT Enterprise Tier III Incident Management SOP.

6.1.6.5 Upgrade operating systems, install software applications, install new desktop/laptop workstations, reconfiguring existing PCs/Laptops for new users, reimage existing PCs/Laptops, and integrate desktop applications into DISA IT Enterprise workstations.

6.1.6.6 Perform Capacity Management analysis on DISA IT Enterprise components and report the findings IAW the DISA IT Enterprise Tier III Incident Management SOP.

6.1.6.7 Resolve LAN/WAN engineering problems associated with DISA IT Enterprise component (e.g., LAN hardware, gateways, premise equipment, and systems software).

6.1.6.8 Perform critical/emergency Tier III system administration tasks (e.g., Performing server reboots), as directed by the Government, after normal working hours (Eastern Time) to keep systems running (e.g., maintain 24/7 availability).

6.1.6.9 Perform infrastructure integration analysis and troubleshooting for new DISA IT Enterprise components.

6.1.6.10 Integrate new DISA IT Enterprise Network Management Systems (i.e. Alterpoint, Open View, Sight Scope, etc).

6.1.6.11 Interface with vendors and Technical Support Reps, as required, to resolve hardware and software issues on DISA IT Enterprise components.

6.1.6.12 Operate and maintain the DISA IT Enterprise Verification and Integration Facilities (a platform for the validation and staging of Enterprise enhancements prior to final implementation) to ensure the testing environment logically represents to the operational environment.

6.1.6.13 Design, develop, validate, and acquire Government approval in writing for, Systems Change Requests (SCR’s) to include, but not limited to, new router builds and configurations, new switch builds and configurations, VoIP Designs, router Access Control Lists (ACL’s), etc.

6.1.6.14 Perform Tier III incident and problem management IAW the DISA IT Problem Management SOP.

6.1.6.15 Request verification from the end user and close the trouble tickets IAW the DISA IT Enterprise Incident Management Tier III SOP when the fix has been verified by the end user.

6.1.6.16 Monitor the impact of design changes implemented and report the finding IAW the DISA IT Enterprise Tier III Incident Management SOP.

6.1.7 Provide DISA IT Enterprise Monitoring and Reporting Services

6.1.7.1 Provide 24x7x365 Network Monitoring and Reporting services to perform the mission of the DISA IT Enterprise System Monitoring Center (DSMC).

6.1.7.2 Monitor all DISA IT Enterprise components and IT services and report to the DSMC Watch Officer when established performance measures, thresholds and/or tolerances are exceeded, or if deviations from established patterns/measures are detected. (Examples of IT services currently monitored by the DSMC include but are not limited to: Directory Services, Job Scheduling (e.g., backups and patch deployment), DNS, DHCP, RAS, and VPN, Technical Controls, user desktop environment status and NAC, firewall, routers, switches, servers, server services (e.g., email, spooler, etc,) and systems (e.g., exchange, file, print and authentication services).

6.1.7.3 Operate DISA IT Enterprise Network Management Systems (i.e. Alterpoint, Open View, Sight Scope, etc).

6.1.7.4 Identify, and acquire Government approval for, additional and/or improved DSMC Service Monitoring Controls and/or capabilities that enhance the situational awareness of the operational posture of the DISA IT Enterprise.

6.1.7.5 IAW the DISA IT Enterprise Event Management SOP (currently in draft) initiate reporting documentation to facilitate technical response, track and report, IAW the schedule directed by the Watch Officer, the status of efforts until final resolution.

6.1.7.6 Provide DESS Status Update Reports to comply with DISA’s daily reporting requirement to the DSMC Watch Officer (currently three times per day at 0700, 1200 and 1600).

6.1.7.7 Facilitate the execution (schedule conference room, establish DCO session, phone bridge and meeting technology support) of the daily CIO Operational Status Brief (typically conducted at 0830) and provide and present daily operational DISA IT Enterprise performance statistics (e.g., Call Center statistics, incident statistics, request fulfillment (RIDs) statistics, circuit utilization statistics, trend analysis and special reports, etc.).

6.1.7.8 Draft, and acquire Government approval for, implement and maintain, an enhanced DSMC Event Management SOP, based on industry best practices (e.g., ITIL and eTOM), to increase the accuracy and efficiency of the DSMC monitoring and reporting capability.

6.1.7.9 Monitor all DISA IT Enterprise security components and IT security services and report to the DISA CIO when established performance measures, thresholds and/or tolerances are exceeded or if deviations from established patterns/measures are detected. (Examples of IT services currently monitored by the CIO include but are not limited to: IDS and Deployed IA Devices and Systems, Tier III IDS and WIDS, NAC, NetIQ Security Manager, HBSS and IA Tools).

6.1.7.10 Monitor Environmental Controls and Sensors in the DISA IT Enterprise Operating Centers to include, but not limited to, Computer Equipment Room (CER), Mission Equipment Room (MER), JWICS Computer Equipment Room (JCER), Communications Computer Equipment Room (CCER), Telephone Rooms, Wiring Closets, etc., and report to the DSMC Watch Officer when established performance measures, thresholds and/or tolerances are exceeded or if deviations from established patterns/measures are detected.

6.1.7.11 Develop, validate and acquire Government approval for the development of new Standard Operating Procedures (SOPs) for Network Monitoring.

6.1.7.12 Conduct technical analysis, as directed by the Government, to develop threshold criteria and enhance the processes and tools supporting the DISA IT Enterprise Event Management SOP Task 3 – Information Assurance Incidents and Problem Management Support

6.1.8 DISA IT Enterprise Information Assurance Support

6.1.8.1 As directed by the Government, design, evaluate, pilot, and acquire Government approval to deploy, capabilities to ensure the confidentiality, availability, integrity of the DISA IT Enterprise data, and the authentication, access control, and non-repudiation capabilities of the DISA IT Enterprise IAW the DoD 8500 series of Directives and Instructions.

6.1.8.2 Develop, obtain Government approval, implement and maintain, a DISA IT Enterprise Security Plan to support risk management decisions related to the overall security posture of the enterprise.

6.1.8.3 Develop DISA IT Enterprise Security SOP to include Personally Identifiable Information (PII) as defined in DoDI 5400.16.

6.1.8.4 Investigate abnormal activity in the monitoring data of IA tools (e.g., HBSS, IDS, WIDS, NAC and NetIQ) and report findings to the Government IAW DISA IT Enterprise Security SOP.

6.1.8.5 Conduct Forensic investigation as directed by the government IAW DISA IT Enterprise Security SOP.

6.1.8.6 Perform information security related analysis and request government approval to execute (e.g., US CYBERCOM, FRAGOs, CTOs) IAW DISA IT Enterprise Security SOP.

6.1.8.7 As directed by the government, conduct technical research of DoD security policy, STIGS, and DISA IAVM processes as they relate to all DISA IT Enterprise components as directed by the Government.

6.1.8.8 As directed by the government, validate that DISA IT Enterprise components comply with the appropriate DISA Security Technical Implementation Guides (STIGs).

6.1.8.9 As directed by the government, update and maintain Security Baselines in the DISA Vulnerability Management System (VMS).

6.1.8.10 As directed by the government, register all new assets into VMS, apply role based permissions and complete self assessment.

6.1.8.11 Perform the initial IA assessment on newly configured systems by running DoD/DISA required IA configuration and scanning programs (e.g., but not limited to Gold Disk, Retina).

6.1.9 Support for Implementing IA Vulnerability Alert (IAVA’s)

6.1.9.1 As directed by the government, perform security testing for new patches, IAVAs, Operating Systems (OS) and application upgrades in the DISA IT Enterprise Verification and Integration Facilities (EVIF).

6.1.9.2 As directed by the government, develop and obtain implementation approval for, performance improvement plans to integrate IAVA remediation into routine DISA IT Enterprise security operations.

6.1.9.3 As directed by the government, execute Field Engineering Notification (FEN) installation for DMS Servers.

6.1.10 Technical Input for the Development of Network Security Policy

6.1.10.1 As directed by the government, conduct technical analysis of vulnerabilities to determine the impact to the DISA IT Enterprise security posture.

6.1.10.2 As directed by the government, conduct quantitative and/or qualitative analysis to determine the risk to DISA IT Enterprise.

6.1.10.3 As directed by the government, provide written recommendation to the Government for the information security policy changes to address the remediation of vulnerabilities.

6.1.10.4 As directed by the government, provide draft language of security policy additions/modifications to the Government.

6.1.11 Conduct Network Security Scans and Operational Security (OPSEC) Activities

6.1.11.1 As directed by the government, perform analysis to ensure access control and credentials issued are based on role performance.

6.1.11.2 As directed by the government, perform security scans against known vulnerabilities and STIGs as part of first Article Testing for proposed new DISA IT Enterprise hardware and summarize results and remediation recommendations and provide to the Government test lead.

6.1.11.3 As directed by the government, perform analysis to ensure access control credentials are aligned to active DISA IT Enterprise user accounts.

6.1.11.4 As directed by the government, provide the Government with a list of inactive DISA IT Enterprise accounts recommended for termination.

6.1.11.5 As directed by the government, conduct analysis to identify DISA IT Enterprise assets whose security posture could be improved through enhanced authentication technology.

6.1.12 Prepare and Evaluate Documents and Data in Support of the DOD Information Assurance Certification and Accreditation Process (DIACAP)

6.1.12.1 As directed by the government, document and maintain DISA IT Enterprise Topology in Microsoft VISIO and submit to the DISA IT Enterprise Configuration Control Board (CCB) for approval.

6.1.12.2 As directed by the government, perform technical analysis and generate the documentation required to comply with all Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) activities as defined in DoDI 8510.01.

6.1.12.3 As directed by the government, perform technical analysis in support of DoDI 8510.01 security Site Assistance Visits (SAVs), Command Cyber Readiness Inspections (CCRIs) related activities (these activities will be performed in addition to and outside of the normal DISA IT Enterprise accreditation process).

6.1.12.4 As directed by the government, conduct Penetration Testing on DISA IT Enterprise assets in support of DoDI 8510.01 and present summary of results and data acquired to the government.

Task 4 – Cable Plant Management Support

6.1.13 Design, Implement, and Maintain the IT Enterprise Cable Plant Infrastructure

6.1.13.1 As directed by the government, conduct installation cable plant analysis (All new DISA IT enterprise cable installations and repairs must be compliant with NITISSIAM TEMPEST/2-95, RED/BLACK Installation Guidance).

6.1.13.2 As directed by the Government, perform Site Survey Visits to conduct technical analysis of DISA IT Enterprise infrastructure.

6.1.13.3 As directed by the Government, initially populate and maintain, as changes are made, all DISA IT Enterprise site cable plant infrastructures in the DISA IT Enterprise SITEWARE application.

6.1.13.4 As directed by the Government, assemble Bill of Material (BOM) and labor estimate for existing infrastructure maintenance, new installations and life cycle replacement projects.

6.1.13.5 As directed by the Government, install Protective Distribution System (PDS), with prior approval by DISA IT Site Security or the Certified Tempest Technical Authority (CTTA).

6.1.13.6 As directed by the Government, install and verify the proper function of cable racks and cabinets, evaluate inventory accuracy, power requirements, rack space, and equipment delivery IAW National Electrical Code (NEC) 2011, American National Standard Institute (ANSI)/National Fire Protection Association (NFPA) 70.

6.1.13.7 As directed by the Government, install new Patch Panels, LAN, CCTV or Telephone Cable installation requirements for DISA IT enterprise locations at DISA IT enterprise locations, to include new sites, new buildings, or new work spaces and/or cable rooms IAW NITISSIAM TEMPEST/2-95, RED/BLACK Installation Guidance.

6.1.13.8 As directed by the government, Install Crypto and Communications Equipment (DSU/ CSU for Data Circuit) as directed by the Node Site Coordinator (NSC) IAW NITISSIAM TEMPEST/2-95, RED/BLACK Installation Guidance.

6.1.13.9 As directed by the government, install Protective Distribution Systems (PDS for Classified Systems) as directed by Security or the CTTA and IAW National Security Telecommunication & Information Systems Security Instruction (NTISSI) 7003, Protective Distribution Systems (PDS).

6.1.13.10 As directed by the government, prepare Bill of Materials (BOM) for PDS and Cable Plant Installation IAW National Security Telecommunication & Information Systems Security Instruction (NTISSI) 7003, Protective Distribution Systems (PDS).

Task 5 - Enterprise Architecture Support

6.1.14 Strategic Planning and IT Enterprise Portfolio Management Support

6.1.14.1 Develop a DISA IT Enterprise Five Year Strategic Plan to identify/propose a logical and sequential breakdown of projects required to accomplish the goals of the DISA IT Enterprise IAW with the DISA Campaign Plan.

6.1.14.2 As directed by the government, develop Project Plans to document the efforts required to achieve the specific goals and objectives of the DISA IT Enterprise Five Year Strategic Plan.

6.1.14.3 As directed by the government, conduct technical analysis, to develop and maintain the DISA IT Enterprise, DoD Architecture Framework (DODAF) views, (e.g., to include but not limited to OVs, TVs and SVs), other network architecture documents as requested.

6.1.14.4 Conduct the administrative functions, to include but not limited to, preparing agendas, documenting minutes, representing user requirements to ensure the smooth execution of the weekly DISA IT Enterprise Requirements Board (DRB) and DISA IT Enterprise Configuration Control Board (CCB).

6.1.14.5 Develop Standard Operating Procedures (SOP) for the conduct of DISA IT enterprise Requirements Board (DRB) and Configuration Control Board (CCB) meetings.

6.1.14.6 Perform the day to day operation of the business tools supporting the DISA IT enterprise requirements process, (the DISA IT Enterprise currently employs the Requirements Identification Tracking System (RITS).

6.1.14.7 Develop Standard Operating Procedures (SOP) for the Requirements Identification Tracking System (RITS).

6.1.15 IT Enterprise Asset and Configuration Management Support

6.1.15.1 Develop, document and maintain a Standard Operating Procedures (SOP) for DISA IT Enterprise Configuration Management that specifically identifies the process and procedures for the identification, prioritization and successful execution of Configuration Items (CI), CI Actions (e.g., CI creation, deletion, modification, etc.) and the accurate retention of CI’s in the DISA IT Enterprise Configuration Management Database (CMDB).

6.1.15.2 Develop and maintain a DISA IT Enterprise Configuration Management Database (CMDB) that documents and maintains the configuration baseline for all DISA IT Enterprise components.

6.1.15.3 Develop and execute Government specified queries and/or reports from the Configuration Management Database (CMDB) to generate data in support of DISA IT enterprise management decisions.

6.1.15.4 As directed by the Government, conduct Government-defined Configuration Management Audits

6.1.15.5 Conduct CMDB Quality Assurance Reviews as directed by the Government.

6.1.15.6 Perform the daily operation of the Altiris and Alterpoint applications supporting the DISA IT Enterprise’s Asset and Configuration Management capabilities.

6.1.15.7 Develop, document and maintain Standard Operating Procedures (SOP) for processes and procedures (based on industry best practices, e.g., ITIL and eTOM) for the operation of DISA IT Enterprise’s Altiris and Alterpoint based Asset Management capabilities.

6.1.15.8 Perform the daily operation of the business tools supporting the DISA IT Enterprise Change Management Process, (DISA IT Enterprise currently employs the DISA IT Enterprise Management Infobase (DEMI) system.

6.1.15.9 Develop and maintain a Standard Operating Procedures (SOP) for business tools supporting the DISA IT Enterprise Infobase (DEMI) system.

6.1.16 IT Enterprise Project Management Support

6.1.16.1 Migrate the development instance of the DISA IT enterprise Microsoft Project Sever 2010 (Enterprise Project and Portfolio Management (EPPM) applications) from its developmental/test environment into its production environment in a DISA Enterprise Service Center (DESC).

6.1.16.2 Provide full Life Cycle Management (LCM) to assure core business hour availability of the DISA IT enterprise Microsoft Project Sever 2010 (Enterprise Project and Portfolio Management (EPPM) application (i.e., applying patches, upgrades, enhancements, configuration changes, backups, etc.) to perform the agency’s Portfolio and Project Management functions.

6.1.16.3 Maintain a development instance of the DISA IT enterprise Microsoft Project Sever 2010 (Enterprise Project and Portfolio Management (EPPM) application) in the developmental/test environment to facilitate the testing of patches, configuration changes, enhancements, and enable the development of new EPPM capabilities.

6.1.16.4 Provide professionally credentialed Microsoft Master Schedulers to develop, upload and maintain Microsoft Project Sever 2010(EPPM) schedules into the EPPM application and conduct Microsoft Project Sever 2010(EPPM) training sessions.

Task 6 - Solution Engineering and Deployment Support

6.1.17 Perform Projects Management (PM) activities and enable engineering and operational enhancement projects

6.1.17.1 As directed by the government, create briefings for DISA IT Enterprise projects and/or other technical initiatives.

6.1.17.2 As directed by the government, create and maintain Microsoft Project Integrated Master Schedules (IMS) to include resource loading &leveling and risk components.

6.1.17.3 As directed by the government, capture meeting discussions, status reports and administrative actions/tasking (e.g., develop meeting minutes).

6.1.17.4 As directed by the Government, provide technical analysis and systems administration (e.g., create, maintain and organize folders), for DISA IT Enterprise virtual workspaces

6.1.17.5 As directed by the government, conduct technical analysis to provide data to support requirements determination and DISA IT Enterprise purchases.

6.1.17.6 Conduct technical analysis as directed by the Government in support of “First Article Testing” IAW F.A.R. subpart 9.3.

6.1.17.7 As directed by the government, develop and maintain technical documentation for DISA IT Enterprise components.

6.1.17.8 As directed by the government, provide technical instruction sessions for site administrators related to upgrades or changes to the existing enterprise’s network devices, such as but not limited to, servers, routers, switches, and firewalls, etc.

6.1.17.9 As directed by the government, conduct technical analysis to evaluate the configuration and resulting functionality of all DISA IT Enterprise components and provide recommendations for increased capacity or functionality.

6.1.17.10 As directed by the government, propose technical specifications and/or configurations to optimize capabilities/performance.

6.1.17.11 As directed by the government, develop new technical specifications and/or configurations for DISA IT enterprise components and obtain government approval in writing prior to implementation.

6.1.17.12 As directed by the government, install and configure DISA IT enterprise components.

6.1.17.13 As directed by the government, provide Project Plans which identify Bill of Materials (BOM), labor costs, government coordination requirements, project schedule, technical approach, project objectives and anticipated benefits and information assurance requirements.

6.1.17.14 As directed by the government, conduct technical analysis of proposed solutions to validate the accuracy of product/capability to evaluate whether anticipated performance enhancements will be realized on DISA IT Enterprise.

6.1.17.15 Conduct monthly verifications to ensure that the DISA IT Enterprise components in the Enterprise Verification and Integration Facilities (EVIF) contain the same baseline configurations and settings as the DISA IT Enterprise components in the production environment.

6.1.17.16 As directed by the government, execute patching and system updates for the DISA IT Enterprise Components and update the Infobase (DEMI) application per the SOP.

6.1.17.17 Prior to the deployment of IT patches and system updates for DISA IT Enterprise components, conduct technical analysis in Enterprise Verification and Integration Facilities (EVIF) environment to determine the operational impact to DISA IT Enterprise of the proposed patch/system update.

6.1.17.18 Develop and obtain government approval for, DISA IT Enterprise Release and Deployment SOP.

6.1.17.19 Develop, and obtain government approval for, a Data Replication and Disaster Recovery Continuity of Operations Plan (COOP) for DISA IT Enterprise Headquarters Campus components and sites within the NCR.

6.1.17.20 As directed by the government, develop and validate new DISA IT enterprise server and workstation/client operating systems and application images.

6.1.17.21 As directed by the government, validate that new images for servers and workstations/clients are fully compliant with all operating system and application patches and STIGs.

6.1.17.22 As directed by the government, execute the DISA IT Enterprise security validation scan (e.g., SCVI, Retina) and provide the scan record to the Government for validation.

6.1.18 Develop and Implement Technology Insertion Procedures

6.1.18.1 As directed by the Government, conduct technical compatibility and functionality research on new technologies, to determine the feasibility and interoperability with the existing DISA IT Enterprise architecture.

6.1.18.2 As directed by the Government, conduct technical analysis to evaluate the functional areas of DISA IT Enterprise storage management (e.g., capacity planning, acquisition and provisioning, operational practices configuration management and data recovery) and identify areas for process improvement and recommendations for potential storage management solutions, strategies and plans for the DISA IT Enterprise architecture.

6.1.18.3 As directed by the government, draft new and/or review existing IT processes and propose modifications and/or additions to increase efficiency or correct process deficiencies.

6.1.18.4 Draft new and/or review existing IT processes to ensure the technology insertion process for new DISA IT enterprise components includes notification and positive acknowledgement from the DSMC and incorporates the new DISA IT Enterprise Component(s) into the event management system.

6.1.18.5 As directed by the government, conduct technical research evaluate the options for an automated and integrated enhanced situational awareness dashboard capability to integrate the capabilities of the DSMC.

6.1.19 Enterprise Technical Solution Development and Implementation Support

6.1.19.1 As directed by the government, provide subject matter expertise to conduct technical analysis, to develop and implement solutions to resolve technical problems with DISA IT Enterprise components.

6.1.19.2 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the development and design of new DISA IT Enterprise services.

6.1.19.3 As directed by the government, conduct technical analysis, to develop and implement solutions to resolve technical problems with the packaging and integration of DISA IT Enterprise desktop applications.

6.1.19.4 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the configuration and integration of DISA IT Enterprise application software.

6.1.19.5 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the maintenance of the standardized DISA IT Enterprise desktop image.

6.1.19.6 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with DISA IT Enterprise continuity solutions.

6.1.19.7 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with engineering solutions for a high-mobility (e.g., telework and travel) workforce.

6.1.19.8 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems related to the adoption of Internet Protocol Version 6 (IPv6) on DISA IT Enterprise (Form 1).

6.1.19.9 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems related to the design of Domain Name Services (DNS), Dynamic Host Change Protocol (DHCP), Remotes Access Serves (RAS), Virtual Private Networks (VPNs), and Voice Over Internet Protocol (VoIP) services on DISA IT Enterprise.

6.1.19.10 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the adoption of new and or modified Directory services.

6.1.19.11 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the design of existing DISA IT Enterprise Components (e.g., servers, client devices, cable plant, etc.).

6.1.19.12 As directed by the government, conduct technical analysis to develop and implement solutions to resolve problems with the adoption of new and or modified Information Assurance/Security products.

6.1.19.13 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the integration of systems management software on DISA IT Enterprise servers and clients.

6.1.19.14 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the integration of new messaging hardware and software on DISA IT Enterprise.

6.1.19.15 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with the integration of a standardized DISA IT Enterprise desktop image in new hardware platforms.

6.1.19.16 As directed by the government, conduct technical analysis to develop and implement solutions to resolve the technical problems associated with defining, designing and maintaining Active Directory servers.

6.1.19.17 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with designing the Enterprise’s Windows, Unix and Other Operating Systems (OS) servers.

6.1.19.18 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems with designing, testing and implementing mobile computing device platforms on the DISA IT Enterprise.

6.1.19.19 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical associated with the design and modification of email services.

6.1.19.20 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems associated with the design and modification of Defense Messaging Service (DMS) services.

6.1.19.21 As directed by the government, conduct technical analysis to develop and implement solutions to resolve technical problems identified through Perform Acceptance Testing.

6.1.20 Establish Processes and Procedures for Implementing System Changes

6.1.20.1 As directed by the government, develop, document and maintain processes and procedures, based on industry best practices (e.g., ITIL and eTOM), for the prioritization and implementation of changes to the DISA IT Enterprise Components.

6.1.20.2 As directed by the government, conduct technical analysis and present the findings on the proposed change to the DISA IT Enterprise which clearly articulates the rationale for the proposed change, and the anticipated impact to the enterprise operating environment, and the anticipated impact to the security posture of the DISA IT Enterprise.

6.1.20.3 As directed by the government, develop transition plans, based on industry best practices (e.g., ITIL and eTOM), to ensure the implementation of the change, and the transition from the Engineering Team to the Operations Team, are executed without disruption to the DISA IT…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .