Historical Data - ACITS4 SOW 80ARC020D0006.pdf
PDF 1 MB Posted
- Attached to
- Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) Federal contract opportunity
- Solicitation number
- 80TECH21R0007
About this file
This statement of work outlines cybersecurity and information technology services required by the National Aeronautics and Space Administration. The contractor shall provide a range of enterprise solutions including cloud computing support, data center management, systems administration, IT governance, security operations, networking, applications management, and scientific computing support. The contractor must comply with all applicable federal, NASA, and requesting organization policies and procedures. Key responsibilities involve maintaining and operating IT infrastructure, researching emerging technologies, managing cybersecurity programs, and supporting business systems. The period of performance is one base year plus four option years.
View the file
Other files for this federal contract opportunity
Show all 50
Cybersecurity and Privacy Enterprise Solutions and Services (CyPrESS) has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
80ARC020D0005 ACITS4 Statement of Work Section J(a), Attachment 1
TABLE OF CONTENTS
1 INTRODUCTION
2 SCOPE
3 AMES CONSOLIDATED INFORMATION TECHNOLOGY SERVICES 4 REQUIREMENTS
3.1 CONTRACT MANAGEMENT REQUIREMENTS
3.1.1 TECHNICAL DIRECTION
3.1.2 RESOURCE TRACKING
3.1.3 RESOURCE ACQUISITION
3.1.4 WORKFORCE MANAGEMENT AND ALLOCATION
3.1.4.1 Employee Background Checks and Clearances
3.1.4.2 Certifications
3.1.4.3 Workforce Training
3.1.5 HEALTH, SAFETY, AND ENVIRONMENTAL REQUIREMENTS
3.1.6 RISK MANAGEMENT
3.1.7 QUALITY MANAGEMENT AND ASSURANCE
3.1.8 RECORDS MANAGEMENT AND VITAL RECORDS MANAGEMENT FOR CONTINUED OPERATIONS
3.1.9 GOVERNMENT PROPERTY MANAGEMENT
3.1.9.1 Connectivity of Government Property
3.1.10 SOFTWARE MANAGEMENT
3.1.11 TRAVEL MANAGEMENT
3.1.12 DELIVERABLES AND REPORTS
3.1.13 PHASE-OUT
3.1.14 MANAGEMENT AND HANDLING OF SENSITIVE INFORMATION/DATA
3.2 TECHNICAL REQUIREMENTS
3.2.1 IT SYSTEMS SUPPORT
3.2.1.1 Cloud Computing
3.2.1.2 Data Center
3.2.1.3 System Administration
3.2.1.4 Hardware/Software Maintenance
3.2.1.5 Data Storage Retrieval and Archival
3.2.2 IT GOVERNANCE SUPPORT
3.2.2.1 IT Governance and Policy Analysis
3.2.2.2 Technical Planning and Analysis
3.2.2.3 Project Management
3.2.3 CYBERSECURITY
3.2.3.1 Emerging Cybersecurity Technology
3.2.3.2 Security Operations Center (SOC) Specific Services
3.2.3.3 Patch Management and Deployment
3.2.3.4 Vulnerability Scanning Systems
3.2.3.5 Incident Response Life Cycle
3.2.3.6 Cybersecurity Forensics
3.2.3.7 Assessment and Authorization Consulting and Auditing Support
3.2.3.8 Perimeter Firewall Systems
3.2.3.9 Anti-virus and Anti-malware Services
3.2.3.10 Host-based Intrusion Detection and Prevention
3.2.3.11 Content Monitoring and Filtering
3.2.3.12 Full Packet Capture and Flow Monitoring
3.2.3.13 Event Log Collection and Correlation
3.2.3.14 Network Access Control
3.2.3.15 Penetration Testing
3.2.3.16 Organizational Computer Security Official Support
3.2.3.17 Board Participation
3.2.3.18 IT Security Consultation and Engineering
3.2.3.19 DART/MERT Involvement
3.2.4 NETWORK AND COMMUNICATIONS SYSTEMS AND SUPPORT
3.2.4.1 Emerging Network Technology
3.2.4.2 Network Services
3.2.4.3 Network and Communication Infrastructure
3.2.4.4 Distributed Systems
3.2.4.5 Audio, Video, and Voice Communication Systems
3.2.4.6 Radio Frequency (RF) and Emergency Communication Systems
3.2.5 APPLICATIONS MANAGEMENT AND SUPPORT
3.2.5.1 IT Support to Financial Services
3.2.5.2 IT Support to Human Resources, Personnel Security, Safety and Mission Assurance, Environmental Management, and Logistics
3.2.5.3 IT Support to Business Systems and Infrastructure
3.2.5.4 Web and Mobile Applications
3.2.5.5 Collaborative and Information-based Systems
3.2.5.6 Application Management
3.2.5.7 Data Management and Analysis
3.2.5.8 Application Testing
3.2.5.9 Website Registration
3.2.6 SCIENTIFIC COMPUTING SYSTEMS AND SUPPORT
3.2.6.1 Scientific Applications
3.2.6.2 Data Acquisition and Analysis
3.2.6.3 Modeling and Tool Development
3.2.6.4 Hardware Support
3.2.6.5 Experiment Support
3.2.7 IT SUPPORT CENTER
4 PHASE-IN
5 LIST OF ACRONYMS
1 INTRODUCTION
The Ames Consolidated Information Technology Services 4 (ACITS4) Statement of Work (SOW) defines the scope necessary to provide Information Technology (IT) capabilities and expertise in support of applied research, engineering, maintenance, and operations for various requesting organizations, including Ames Research Center (ARC), other National Aeronautics and Space Administration (NASA) facilities, other Government Agencies (e.g., Department of Defense (DoD), Federal Aviation Administration (FAA), and National Oceanic and Atmospheric Administration (NOAA)).
The ACITS4 contract includes a wide range of support functions, including those for standard and non-standard operating systems, system interfaces, or for use within a dynamic environment such as the IT Security Operations Center (SOC), a cyber research laboratory, or test facility. These functions include but are not limited to computing support services (including system administration, hardware and software maintenance, and development of new software applications, deployment of commercially available software, modification of existing software to change or add to its functionality) for systems that are either uniquely configured or highly specialized in function.
Where feasible, it is the Government’s intent to consolidate all IT services at ARC that are not currently addressed under other NASA Agency contracts, Solutions for Enterprise-Wide Procurement (SEWP), or General Services Administration (GSA) contracts under the ACITS4 contract as other ARC IT contracts expire. This will comply with NASA’s requirements for the oversight of IT by the Office of the Chief Information Officer (OCIO) under the Federal Information Technology Acquisition Reform Act (FITARA). This consolidation will provide the visibility and transparency of IT spending and IT management at ARC through the center’s Chief Information Officer (CIO) office. In addition, it will ensure consistent implementations of best practices, IT standards, process and procedures, particularly in cybersecurity, across all the IT environments in mission support and mission programs and projects.
ARC is located in the heart of California's Silicon Valley at the core of the research cluster of high-tech companies, universities, and laboratories that define the region's character. ARC plays a critical role in support of America's space and aeronautics programs. Further information on the ARC mission and its contribution to the NASA vision can be obtained from the web site https://www nasa.gov/ames.
To accomplish its mission, the Center depends heavily on state-of-the-art IT, embracing computer systems ranging from laptop and desktop computers to Data Center and Cloud computing; network systems ranging in size and complexity; and all associated operating interfaces, input/output, data transfer, data management, and data analysis systems.
Due to rapidly increasing Agency use of commercial cloud services, it is expected that cloud computing will continue to be an emphasis for NASA as ARC serves in its role as the host center for the Agency service office, Enterprise Managed Cloud Computing (EMCC), under the NASA OCIO Computing Services Program Office (CSPO). As such, on-going innovation will be required in all aspects of cloud use (technical, business processes, security, and governance) to maintain the Center’s current leadership position and to continually deliver new cloud capabilities that are suitable for addressing NASA’s unique mission challenges.
ARC offers a newly renovated state-of-the-art Data Center as a demand-based service, which provides scalability, high-availability, and exceptional power efficiency. As applications, data, and storage requirements grow, so do ARC’s demand for higher port density and bandwidth. The ARC Data Center services include: Server Hosting (Physical and Virtual), Data Storage services, and System Administration services.
Cybersecurity at ARC is responsible for managing and overseeing five main functions: Intrusion Detection and Monitoring; Incident Response and Forensics; Patch and Vulnerability Management; IT Security Training and Awareness Program; IT Security Authorization and Accreditation and associated Research & Development/Innovation behind each of these core functions.
2 SCOPE
The ACITS4 contract structure for 1 base year and 4 option years of ACITS4 is outlined as follows in Request for Proposal, Section B “Supplies and Services to be Provided”:
CLINs Contract Element (Pricing type)
General Requirements Definition
Specific Requirements Definition
0001 Phase-in (Firm Fixed Price (FFP)) Section 4.1 Phase-in Same as General
Requirements Definition 0002, 0005, 0008, 0011, Contract Management (Cost Plus Fixed Fee
(CPFF))
Section 3.1 Contract Management Requirements
Same as General Requirements Definition
0003, 0006, 0009, 0012, Core Technical Services
(CPFF)
Section 3.2 Technical Requirements Technical Directions
0004, 0007, 0010, 0013, Indefinite Quantity / Indefinite Delivery (IDIQ) (CPFF or FFP)
Section 3.2 Technical Requirements Task Orders (TOs)
The descriptions below represent the Government’s best effort to project future IT research and development requirements. Contract management and technical requirements are outlined in Sections 3.1 and 3.2, respectively.
The Contractor shall be responsible for providing a flexible, responsive, coordinated, and comprehensive research workforce that possesses the qualifications to perform the defined requirements. The Contractor shall administer all work to be performed, and assure the availability of qualified personnel and resources.
Performance of the Core Technical Services under Section 3.2 are further subject to the specific written technical directions from the Contracting Officer Representative (COR), with approval from the Contracting Officer (CO).
The technical directions will be provided to the Contractor after award. Technical directions will include defined requirements (such as deliverables and significant milestone dates) and established performance measurement criteria.
The Government will use task orders (TOs) to support Indefinite Delivery/Indefinite Quantity (IDIQ) requirements under the scope of Section 3.2. A TO will only be issued if the CO and COR determine that the new requirement cannot be supported under the established Core Technical Services. TOs will include defined requirements (such as deliverables and significant milestone dates), negotiated cost and fee, and established performance measurement criteria Individual task plans shall be negotiated and managed on a per task basis. Contractor shall report technical progress on the Monthly Progress Report, Section J(a), Attachment 2, “Contract Data Requirements List (CDRL)”, Item 17, and resource expenditures for Contract Management, Core Technical Services, and each cost reimbursement task order monthly on a NF 533 (CDRL Item 16) to the Government. IDIQ TOs will be issued in accordance with NASA FAR Supplement (NFS) 1852.216-80, Task Ordering Procedure.
The ACITS4 contract shall provide services including, but not limited to, IT capabilities and expertise for research, engineering, maintenance, and operations where existing agency enterprise contracts are unable to do so.
constitutes a basis for any increase or decrease in the total estimated contract cost, the fixed fee (if any), or the time required for contract performance; changes any of expressed terms, conditions, or specifications of the contract; or interferes with the Contractor’s rights to perform the terms and conditions of the contract. Any disagreement with the aforementioned items or between the COR and the Contractor must be elevated to and resolved by the CO.
3.1.2 RESOURCE TRACKING
The Contractor shall track and report status, labor hours and costs, other direct costs (ODCs), and indirect costs to perform Contract Management (including Phase-in and Phase-out), Core Technical Services, and IDIQ TOs under this contract. Monthly and quarterly NF 533 reports (CDRL Items 15 and 16) are to include details at the Contract Management, Technical Direction, TO, and charge point levels for labor and ODCs, e.g., Subcontractor and Subcontractors of Subcontractors, travel, training, and materials. ODCs shall be broken down into the following sub-categories: IT Hardware/Hardware Maintenance (servers, network switches, etc.), Software/Software Maintenance, Parts, Equipment/Tools, Travel, Training, Subcontractor costs. ODCs that do not fit in these categories shall be identified directly. Use of “miscellaneous” or “other” ODC categories will not be permitted.
3.1.3 RESOURCE ACQUISITION
The Contractor shall not perform purchasing functions or act in any other way as an agent for the government per ARC 52.230-90 Contractor Purchasing.
The Contractor will be allowed to purchase items that are IT related or in support of work under this SOW (except for office supplies). The Contractor shall acquire resources not otherwise provided by the requesting organization (e.g., staff, equipment, supplies, software) as needed to support the successful completion of all work. For NASA acquisitions, the Contractor shall utilize the Agency’s Enterprise License Management Team (ELMT) when acquiring software for NASA in accordance with the NFS 1807.70 (Enterprise License Management Team (ELMT) Program) when possible to ensure the Agency is getting the best price value or utilizing existing contracts. Additionally, it shall utilize the Solutions for Enterprise-Wide Procurement (SEWP), Agency Consolidated End-user Services (ACES), or any other Agency-wide contracts, or government-wide contracts (e.g., GSA) before procuring any software or hardware through the ACITS4 contract. For non-NASA acquisitions, Contractor shall follow appropriate organizational policies and directives. All software purchased under the contract shall be purchased in the name of NASA Ames Research Center or other Federal Agency requestors and not in the name of the Contractor.
The Contractor shall follow FAR 52.225-5 (Trade Agreements Act, TAA Designated Country List [515 & 516]) when procuring IT resources. For non-NASA acquisitions, Contractor shall follow appropriate organizational policies and directives.
General office supplies needed in support of any activities of this SOW to be purchased and provided by the Government using Store Stock (Building 255), The Contractor shall obtain office supplies as needed through the
COR.
The Contractor shall follow ARC policies (e.g. NFS 1852.211-70 Packaging, Handling, and Transportation) pertaining to any shipping and receiving of any equipment for this SOW. Contractor shall coordinate with ARC Logistics any shipping and receiving for any deliveries to N233 docking area. For work performed for other requesting organizations, the Contractor shall comply with the logistics policies and procedures of those organizations.
The contractor, in accordance with the contract and requesting organizational policies (e.g. NASA, DoD, etc.), can acquire equipment not presently available as Installation-Accountable Government Property (IAGP) and/or Government Furnished Equipment (GFE) when there is a requirement in the technical direction or the task order. The Government will provide the contractor with guidance on where the equipment will be considered IAGP or GFE.
3.1.4 WORKFORCE MANAGEMENT AND ALLOCATION
The Contractor shall provide overall contract and technical management, including oversight of all resources, facilitating the sharing of expertise as required across the contract. The Contractor shall plan, manage, report, control, and deliver products and services for all contract management requirements, technical directions, and IDIQ TOs as issued by the CO; manage the resources allocated by requesting organization for all requirements in a manner to ensure goals are reached in accordance with agreed upon milestones; and ensure that personnel assigned to specific requirements have the training and expertise required for those requirements.
Prior to each contract year, the Government will prepare technical directions for Core Technical Services, including ODCs and cost charge points related to the next contract year. The Contractor shall review the technical directions and provide its implementation plan. The implementation plan shall discuss the technical approach for performing the work and staying within the Cost Plus Fixed Fee proposed in Section B.
Prior to each contract year and when otherwise necessary, the Government will prepare a TO for each new requirement to provide direction for work requirements and ODCs, and cost charge points. The Contractor shall review the TOs and provide the required information in accordance with NASA FAR Supplement (NFS) 1852.216- 80 Task Ordering Procedure.
The Contractor shall identify redundant, conflicting, and/or complementary needs among the technical directions and TOs and propose approaches to leveraging resources to ensure that conflicts are resolved and that needs are met.
The Contractor shall provide a management structure to effectively manage a professional and technical workforce engaged in a wide range of IT-related services and development. The Contractor shall have organizational structure, procedures, and administrative support functions to effectively and efficiently manage the work performed under this contract. The Contractor shall meet regularly with the CO and the COR to discuss contract status and issues.
The Contractor shall ensure through documented discussions with the CO that all technical directions and TOs clearly identify all products and services that the Contractor is responsible for delivering or providing.
3.1.4.1 Employee Background Checks and Clearances
The Contractor shall ensure that all foreign national visitors and all employees have completed the required background checks, approvals, and clearance requirements for access to worksites (e.g., NASA Ames Research Center) according to directives and policies of the requesting organization.
Performance under this contract will require positions at the “Secret” and “Top Secret” clearance for access to and/or generation of classified information, work in a security area, or both. Additionally, some positions under this contract will require personnel with access to TOP SECRET sensitive compartmented information (SCI) information.
Pertaining to foreign national employees performing work for NASA, Contractor shall comply with NPR 1600.4A (Identity and Credential Management) Section 4.2.10:
“Physical access permissions are granted by the Center Protective Services Office. IT access permissions are granted by IT system owners. The decision to grant physical and/or logical access to foreign nationals to NASA's restricted areas, mission essential infrastructure, sensitive or classified information, and/or export-controlled data may require a higher level of identity vetting due to the heightened risk of exposing these areas and data.”
Other requesting organizations may have similar polices, and Contractor shall comply with those policies when hiring foreign nationals. Government will identity the technical areas in which foreign national restrictions are to be exercised via the technical directions and TOs.
The Contractor shall submit the Department of Defense Contract Security Classification Specification Form (DD 254) per CDRL Item 1. The number of Contractor employees needing security clearances may fluctuate over the course of the contract. Based on current trends, there is a projected need for 50 to 90 security clearances (for example 65 at the Secret level and 10 Top Secret).
3.1.4.2 Certifications
The Contractor shall ensure that its staff have all required certifications prior to start of contract base period.
Contractor shall ensure that staff performing the work have the required qualifications as stated in the Labor Category Descriptions for ACITS4 contract. These certifications fall primarily in the areas of IT security, networking, and health status (e.g., for flight test support). Contractor shall ensure that all certifications are maintained and renewed per the requirements of the certification, and provide an electronic report (CDRL Item 29) containing a list of employees certified, names of certificates, certification date, and certification expiration dates quarterly.
3.1.4.3 Workforce Training
The Contractor shall ensure that all contract employees attend relevant training provided by the requesting organization or required by the contract, prior to the due dates. The Contractor shall ensure that all certifications are maintained and renewed per the requirements of the certification. The Contractor shall provide an electronic report (CDRL Item 28) for all travel and training quarterly. The Contractor shall also provide a Contractor’s Employee Training Program (CDRL Item 13) to include at least organizational conflict of interest (OCI) training and sensitive information management training.
3.1.5 HEALTH, SAFETY, AND ENVIRONMENTAL REQUIREMENTS
The Contractor shall comply with the health and safety requirements contained in Ames Procedural Requirements (APR) 8715.1 (Ames Safety and Health Procedural Requirements), and NPR 8715.1 (NASA Occupational Safety and Health Procedural Requirements), the system safety and mission assurance requirements in NPR 7120.5 (NASA Program and Project Management Processes and Requirements), environmental policies and procedures contained in NASA Policy Directive, NPD 8500.1 (NASA Technical Standards System). If the requesting organization is non- NASA (e.g., DoD), the Contractor shall follow the policies of the requesting organization. The Contractor shall update its Safety and Health Plan as required.
3.1.6 RISK MANAGEMENT
The Contractor shall ensure that the CO has awareness and insight into all risks associated with the Contractor's ability to accomplish requirements. The Contractor shall include identification, assessment, prioritization, and mitigation of any risks within their responses to technical directions and TOs in accordance with NASA Procedural Requirement NPR 8000.4 (Agency Risk Management Procedural Requirements).
3.1.7 QUALITY MANAGEMENT AND ASSURANCE
The Contractor shall participate with the requesting organizations to upgrade and maintain required plans, procedures, and work instructions in order to maintain the organization's compliance with any third-party quality assurance system and shall participate in any audits to maintain the quality system certification. Where the Contractor has primary responsibility for a functional or business area, the Contractor shall have primary responsibility for maintaining compliant documentation associated with that area in accordance with NASA Policy Directive NPD 8730.5 (NASA Quality Assurance Program Policy).
3.1.8 RECORDS MANAGEMENT AND VITAL RECORDS MANAGEMENT FOR CONTINUED OPERATIONS
The Contractor shall provide support for the installation (if required), maintenance, operations, upgrades, configuration management, archiving, customer support, training, and IT security of electronic records systems and related applications, including tracking systems for technical reports and data. The Contractor shall work with the Center Records Management point-of-contact (POC) to ensure that they are in compliance with Center/Agency requirements. These commercial, government, and military/modified off-the-shelf (COTS, GOTS, MOTS) applications must meet requesting organization’s requirements and support the respective organization’s records management best practices.
The Contractor shall provide technical support and coordination to ensure effective and efficient Records Management and Vital Records Management, including, but not limited to, entering records into the system, reviewing policies and procedures, supporting day-to-day operations, and archiving records. The Contractor shall maintain and update standard operating procedures (SOPs) (see CDRL Item 31) to govern all contract activities.
3.1.9 GOVERNMENT PROPERTY MANAGEMENT
Government will provide all appropriate equipment and software necessary for the performance of work under this contract unless otherwise noted. The contractor shall follow NASA rules regarding movement and assignment of government owned equipment and Agency Consolidated End-user Services (ACES) supplied equipment and provide information upon request for the following information: Property Assignments, Property Location, Unused Equipment and any required data needed for Equipment.nasa.gov (NASA Property database). Equipment information in Equipment.nasa.gov is listed in Section J(a), Attachment 3, “Installation-Accountable Government Property List”.
The Government shall acquire and provide all on-site Contractors with desktop computers and services for equipment requiring access to the NASA internet protocol (IP) space through the Agency’s enterprise provider or other CIO-approved IT equipment necessary to meet the requirements. Any on-site Contractor-provided equipment connected to the NASA IP space shall comply with NFS 1852.204-76 (Security Requirements for Unclassified Information Technology Resources) and NASA IT Security Handbook ITS-HBK 2810.02-05 (Security Assessment and Authorization External Systems).
The Government may provide or the Contractor may acquire property (Government Furnished Property or Contractor Acquired Property) that is not currently in Equipment.nasa.gov. The Contractor shall manage this property, as well as Installation-Accountable Government Property, in accordance with NASA Ames Policy Directive APD 4200.2 (Equipment Management), Section H (Employees), or applicable requesting organization policy, to ensure accountability. The Contractor shall generate a NASA Form (NF) 1018, “NASA Property in the Custody of Contractors” report as stated in CDRL Item 23. The Contractor, CO, and COR will review monthly the property managed by the Contractor, and the CO will determine if any property should be added to Section J(a), Attachment 3, and included in Equipment.nasa.gov.
3.1.9.1 Connectivity of Government Property
The ACITS4 Contractor shall determine, subject to Government approval, the most appropriate method to connect devices from offsite and near-site facilities that require connectivity to resources on the local/wide area network (LAN/WAN). All connectivity will follow NPD 2810 NASA Information Security Policy and NPR 2810 Security of Information Technology.
3.1.10 SOFTWARE MANAGEMENT
The Contractor shall provide software management services, including the design, development, implementation, modification, maintenance, and operations of software algorithms, applications, and tools. The Contractor shall employ best software practices. The Contractor shall consider acquiring cost effect alternatives such as COTS, GOTS, and MOTS before developing any new software. The Contractor shall provide an analysis of why COTS, GOTS, or MOTS solutions are not acceptable if the design or development of any Center-developed software solution is required. The Contractor shall provide solutions to address software issues, such as those that may arise with standards, reuse, training, upgrades, compatibility, licensing, intellectual property rights, and security.
The Contractor shall provide an electronic report (CDRL Item 26) containing a list of software and software licenses, to include: application name, description, cost, software language, version, number of licenses, license renewal date, application type, requesting organization, application owner, and technical POC semi-annually; see CRDL for details.
All software purchased under the contract shall be purchased in the name of NASA Ames Research Center or other Federal Agency requestors and not in the name of the Contractor.
In performing contract requirements, the Contractor shall use Agency-approved software as needed, e.g.:
• Archer-Risk Information Security Compliance System (Archer-RISCS), IT security—Assessment and
Authorization (A&A);
• Information Technology Security–Enterprise Data Warehouse (ITS-EDW), inventory for security plans;
• SAP, finance;
• Continuous Diagnostics and Mitigation (CDM);
• Equipment nasa.gov, property;
• Procurement for the Public Sector (PPS), contracts;
• Invoice Routing and Information System (IRIS), finance;
• e-Invoice, finance;
• Contractor Performance Assessment Reporting System (CPARS); and
• ServiceNow, help desk.
The Government may also identify any further Agency-approved software.
3.1.11 TRAVEL MANAGEMENT
Contractor personnel may be required to travel for short periods of time to attend planning meetings, participate in industry site visits, attend technical conferences, or support requesting organizations. Travel may include flying in military research aircraft in support of flight hardware/software experiments, and would require medical clearance.
All foreign travel by Contractors supporting NASA requirements must be completed following the policies and procedures of the Ames International Services Office and NFS 1852.242-71 Travel Outside of the United States.
The Contractor shall provide an electronic report (CDRL Item 28) for all travel and training quarterly.
3.1.12 DELIVERABLES AND REPORTS
The Contractor shall provide all contract deliverables and reports identified and described in the CDRL. In the event that the Contractor proposes and the Government accepts inclusion of Limited Rights Data or Restricted Computer Software as part of contract deliverables, and where the Government needs the assistance of third-party subject matter experts to resolve an emergency, the Government may need to provide such experts with access to Contractor Limited Rights Data and Restricted Computer Software. See paragraph (g) of Section I, FAR clause 52.227-14 Rights in Data—General (Alt. II)(Alt. III)[as modified by NFS 1852.227-14 Rights in Data—General].
The technical directions and TOs will contain additional deliverables that the Contractor shall provide. Deliverables specified in technical directions and TOs may include weekly/monthly technical reports, IT security plans, technical documentation, software licensing renewal records, standard operating procedures, etc.
3.1.13 PHASE-OUT
The Contractor is responsible for the orderly transfer of duties and records, including complete equipment and systems records, to the incoming Contractor or NASA, if there is no successor contract. This shall be accomplished in an expeditious manner, consistent with the phase-in schedule, while precluding interruption to the scheduled requirements in the technical directions and TOs. During Phase-out, the Contractor shall have transferred all records and documentary material in an orderly manner and vacated all areas of Contractor responsibility, having left them in a clean, professional state and having completed the check-out process. The Contractor shall submit a phase-out plan (CDRL Item 7) no later than 60 days before the end of the contract for government review and approval.
3.1.14 MANAGEMENT AND HANDLING OF SENSITIVE INFORMATION/DATA
The contract will support numerous IT systems that handle significant volumes of sensitive information/data across NASA, other Government Agencies, and other non-Governmental organizations. The Contractor and its subcontractors (all tiers) shall manage and handle sensitive information/data, which includes Government Sensitive Information (GSI), third-party proprietary information, and Personally Identifiable Information (PII) in the form of operational, research, business, medical, and law enforcement data embedded within IT systems, in accordance with contract requirements and its approved Sensitive Information Management Plan (see CDRL Item 12). Examples of such contract clauses include, but are not limited to: Section H, “ARC 52.227-93 Management and Protection of Data”; Section H, “ARC 52.227-96 Handling of Data”; Section I, “52.224-1 Privacy Act Notification”; Section I, “52.224-2 Privacy Act”; Section I, “52.224-3 Privacy Training ”; and Section I, “1852.237-72 Access to Sensitive Information ”.
3.2 TECHNICAL REQUIREMENTS
The technical requirements described in this SOW support general purpose IT services and products required to accomplish missions, programs, and projects for requesting organizations, including ARC, other NASA facilities, and other Government Agencies (e.g., DoD, FAA, NOAA, etc.). The work under this SOW is not for data entry or office administration.
IT services and products are to include Cloud Computing, Data Center, Systems Administration, IT Governance Support, Security Operations Center, Cybersecurity, Network and Communications Support, Application Maintenance Support and Scientific Computing. The Contractor shall look to emerging technologies and innovation as a core component of every requirement, where applicable. The Contractor shall be responsible for product testing and evaluation. The Contractor shall recommend to the Government emerging COTS/GOTS/MOTS technologies that might be implemented to meet Government needs and contract requirements.
In the performance of this SOW the Contractor may be required to support IT projects with cybersecurity elements that are subject to the scope of NPR 7120.7 (NASA Information Technology and Institutional Infrastructure Program and Project Management Requirements).
3.2.1 IT SYSTEMS SUPPORT
3.2.1.1 Cloud Computing
The Contractor shall support the technical, cybersecurity, business aspects, and governance of NASA’s use of cloud computing services with an emphasis on commercial cloud services, including research and development (R&D) to advance NASA’s ability to effectively leverage the still evolving cloud model and rapidly growing solutions marketplace. Support will be required in the areas of cloud solution architecture, compute, storage, cybersecurity (e.g., Assessment & Authorization (A&A)), implementation of Software as a Service (SaaS) solutions, information assurance, networking, virtualization, database management systems, capacity planning, performance tuning, resource accounting, web application platforms, selected web applications, Platform as a Service (PaaS), and Infrastructure as a Service (IaaS) . These activities include technical design, architecture, and integration of Commercial Cloud services with NASA infrastructure; ensuring compliance with Center and Agency IT security compliance and governance requirements, Identity and Credential Management, configuration management, continuous monitoring, system upgrade and improvement, computing operations, incident management, maintenance of systems documentation and procedures, and contingency planning. The Contractor shall ensure Commercial Cloud Services comply with all Federal (e.g. Federal Risk and Authorization Management Program (FedRAMP)), NASA, and Center level policies, procedures, standards, and guidelines pertaining to IT security as applied to Federal systems.
The Contractor shall develop and support large, dynamically scalable cloud-based compute and storage configurations spanning geographic locations and supporting thousands of diverse workloads and applications using a metered, utility-like delivery model. The Contractor shall support R&D to develop and deliver leading edge cloud capabilities, using both NASA on premise and commercial cloud services, as required to meet the needs of requesting organization missions. The Contractor’s efforts in this area shall provide technical and business management support in the areas of cloud SaaS, PaaS, and IaaS, and a variety of other general and specialized cloud services.
3.2.1.2 Data Center
The ARC Data Center is currently comprised of facilities in buildings N233, N254, M16 with a total of 5 rooms covering ~11,000 square feet and over 150 racks containing 800+ servers both physical and virtual. It is expected that the location and number of facilities will be dynamic over the life of the ACITS4 contract. These facilities enable ARC to provide infrastructure, Mission, Agency, and Government-wide services with outstanding availability and reliability. The Data Center currently has ~ 2Pb (petabyte) of storage (on premise and cloud storage platforms).
The Contractor shall ensure that best practices and lessons learned are implemented and maintained in the ARC Data Centers. The Contractor shall manage both the environmental conditions (including, but not limited to, power, heating, ventilation, and air conditioning (HVAC), uninterruptible power supply (UPS), backup generators, and power distribution units (PDUs)) and the IT equipment (including, but not limited to, servers, backup, cables, network connections, and storage systems). In this capacity, the Contractor is responsible for diverse efforts, including, but not limited to, operations, cybersecurity incident remediation and mitigation, configuration management, installing and testing new equipment, monitoring all systems including IT and environmental equipment, specialized cleaning of the IT facilities as required, documentation, development of standard operating procedures (SOPs), access control, cable management, and capacity planning and management. Using computer aided design (CAD) tools, the contractor shall create, and/or modify building architectural, mechanical, electrical, and equipment system drawings as required.
The technology systems and requirements necessary to provide optimal support to the Data Centers are expected to change over the lifetime of this contract. The Contractor shall have a thorough knowledge and extensive experience in current emerging technologies relative to data center support and efficiencies (e.g., virtual systems, cloud computing, and the “green initiative”). The Contractor shall provide ARC with the benefit of its experience and expertise in relevant emerging technologies to optimize the Data Center services.
Data Center services are offered to meet customer requirements. Data Center standard services include support for hardware, applications, upgrades to operating systems (OS), maintaining applications, IT security such as obtaining an Authorization to Operate (ATO), etc.). At a minimum, the Data Center offers equipment hosting, which includes space, power, and cooling. Support can range from the Data Center being responsible for all customer services, or divided between the Data Center and the customer. Memo of Understanding documents are drawn up between the Data Center and any customer of the Data Center to clarify the level of support and identify the system security control responsibilities owned by the Data Center and the customer.
The Contractor shall investigate, test, and recommend cost effective alternative solutions (including emerging technology and innovation) that can provide enterprise class compute services; as well as keep current on virtualization and cloud based computing solutions that integrate with enterprise class environments. The contractor will provide oversight, as needed, for vendors who provide specialty skills that offset or enhance the experience level of the work being performed.
3.2.1.2.1 Storage Engineering & Administration
The Contractor shall operate and maintain the hardware and software that comprise the storage area network (SAN), which integrates multiple disk arrays between Code I Data Centers within two fabrics, providing redundancy that is uniformly managed by the Contractor. The Contractor is responsible for all storage communications between storage devices and servers; operating and managing the redundancy across both SAN fabrics; provisioning servers for the SAN; managing capacity including quick and seamless storage expansion to existing servers; storage replication;
and enables more effective disaster recovery processes.
The Contractor shall also provide proposals and recommendations for periodic refresh storage infrastructure hardware and investigate, test, and recommend cost effective alternatives that can provide enterprise class storage services; as well as keep current on cloud based storage solutions that integrate with enterprise class environments.
3.2.1.2.2 Simple Mail Transfer Protocol (SMTP)/Messaging
The Contractor shall operate and maintain the Center SMTP mail relays, which support all email traffic within the Center. This traffic includes all of the registered SMTP servers requiring incoming mail. These relays perform the primary virus and spam scanning on email entering the Center's servers. This includes support and administration of the agent and master servers and the current application, Proofpoint, residing on those servers. This also includes support of the Regulatory Compliance module that can block Social Security numbers from being sent in the clear.
In addition, the Contractor shall support the transition to the Agency SMTP service, ensure continued operations from ARC resources and escalate non-ARC managed issues to the Agency team.
3.2.1.3 System Administration
The Contractor shall provide products and services in order to maintain a stable, efficient, and productive computer system and computing environment following industry best practices. System administration includes system software maintenance and updates, ensuring compliance with requesting organization’s cybersecurity requirements, cybersecurity incident remediation, service level agreements (SLAs), Memoranda of Understanding (MOU), user account management, configuration management, system upgrade and improvement, computing operations, maintenance of systems documentation and procedures, system backup, capacity planning, contingency planning, and issue resolution. The Contractor shall develop and maintain SOPs and other technical documentation as required.
The Contractor shall ensure that system administrators respond to cybersecurity directives (e.g., mitigation action recommendations (MARs)) to address cybersecurity vulnerabilities and threats in accordance with the NASA Information Security Incident Management handbook (ITS-HBK-2810.09-02A) or equivalent requesting organization policy.
3.2.1.4 Hardware/Software Maintenance
The Contractor shall provide for the repair and replacement of hardware components and software modules, applications, and systems necessary to ensure the operability of all covered computing and communication systems.
Supporting functions include problem diagnosis; repair or replacement of failing or failed components; verifying that components, modules, and applications meet applicable standards; system performance testing and verification;
data integrity and restoration; and an understanding of applicable cybersecurity considerations regarding sensitive or classified data or systems. The Contractor shall be responsible for managing service and maintenance agreements to ensure theses are up-to-date and renewed following NASA (or requesting organization) procurement policies.
3.2.1.5 Data Storage Retrieval and Archival
The Contractor shall provide the IT systems and related services necessary to store and maintain reliable and secure access to large amounts of electronic data. Technical areas of focus include systems engineering, deployment, and operations; storage for near-term, long-term, and archival requirements; shared access and security features; data integrity; backup systems; disaster plans; user interface and access systems; identification of potential sources for required products and services; and assessment of relevant emerging technologies and technical approaches. Data storage retrieval and archives must preserve all security metadata, audit logs, and security related fields associated with the data.
3.2.2 IT GOVERNANCE SUPPORT
3.2.2.1 IT Governance and Policy Analysis
The Contractor shall provide IT Governance and policy analysis with regards to existing policies, procedures, and guidelines, and their impact to the requesting organization. The Contractor shall comply with all Federal, NASA, Center level, and requesting organization policies, procedures, standards, and guidelines pertaining to Federal records management as applied to Federal systems. Governance and policy analysis includes cybersecurity and information assurance.
3.2.2.2 Technical Planning and Analysis
The Contractor shall provide technical support associated with IT resources management; planning for new IT investments, systems and IT facilities; definition of near-term and long-range IT investments and requirements;
cybersecurity, information assurance, and operations techniques, processes, procedures, planning, and analysis; and evaluation of new standards, practices, and policies. The Contractor shall provide technical and reporting support for all IT planning, including, but not limited to: Capital Planning and Investment Control (CPIC) (an OCIO responsibility), Summary Investment Business Case (SIBC), and IT Portfolio management support.
The Contractor shall provide technical resources, documentation, and artifacts to support engineering analysis and the evaluation of emerging IT solutions, cybersecurity operations, technologies, architectures, and systems, development of business/use cases, cost/benefit estimates, definition of functional requirements and synthesis of IT systems requirements, and identification of relevant alternative solutions in support of Enterprise Architecture (EA).
3.2.2.3 Project Management
The Contractor shall comply with all Project Management Office (PMO) requirements, methodology, and best practices. The Contractor will manage projects within the defined methodology of the NPR 7120.7 (NASA Research and Technology Program and Project Management Requirements), NPR 7150 (NASA Software Engineering Requirements), and NPR 7123 (Systems Engineering Procedural Requirements) frameworks or equivalent policies of non-NASA requesting organizations as applicable. The Contractor shall develop project plans, schedules, risk analysis, stakeholder management, communications management, and other applicable documents for the PMO.
3.2.3 CYBERSECURITY
The Contractor shall be responsible for the maintenance and operations of IT systems, which include firewalls, all the supporting hardware, software, firmware, data, versioning, IT security support systems, vulnerability and patch management, incident response and forensics, log aggregation, and correlation.
The Contractor shall comply with all Federal, NASA, Center level, and applicable non-NASA requesting organizations (e.g., DoD and U.S. Army) policies, procedures, standards, and guidelines pertaining to IT security as applied to Federal systems.
The Contractor shall provide needed support in the area of cyber laws and ethics. The Contractor is responsible for supporting the Agency cybersecurity efforts and ensuring that all cybersecurity findings are tracked, reported, and mitigated by the system administration teams.
Our mission is to protect NASA system and network resources from internal and external cyber-security related threats on the Center and Agency levels.
3.2.3.1 Emerging Cybersecurity Technology
The Contractor shall be responsible for researching emerging IT Security threats, trends, and technology. The Contractor shall research IT Security threats encountered in other Federal entities and commercial entities that may be targets of the latest threats.
3.2.3.2 Security Operations Center (SOC) Specific Services
The Security Operations Center (SOC) is the nerve center for detection and monitoring of information security incidents for the Agency. The SOC’s goal is to provide the Agency with continuous, uninterrupted (24/7/365) event detection, situational awareness, and incident management capabilities to enable the Agency to maintain a sound and secure information assurance posture. The SOC also provides notifications to NASA responders for mitigation action and to US-CERT for National Situational Awareness.
The Contractor shall support the SOC, which operates in a three tiered system:
3.2.3.2.1 Tier 1
Tier 1 is the Contact Center and initial intake of all NASA security related topics/issues. Tier 1 handles most incoming and outgoing communication from the SOC and performs all stakeholder account administration for the SOC. The primary task of Tier 1 is to triage end-user actions coming into the SOC.
3.2.3.2.2 Tier 2
Tier 2 operations support requires 24/7/365 staffing with three shifts. The primary focus of Tier 2 is to monitor agency sensors and SOC systems for incidents, provide incident handing and response support for the Agency, provide analysis of incidents using available data, and coordinate with Tier 1 and Tier 3 (including Threat and Vulnerability Assessment (TVA)). In addition, Tier 2 is comprised of nine distinct functional areas to include:
• SOC Outage Management
• Incident Management and Reporting o US-CERT Procedures o Data Spillage Procedures o Alert Procedures o Incident Analysis Procedures o Incident Handling Procedures o Secure Communication
• Tier 2 Analysis Reference Guides o Attack Methodology o Tool Guides o Analysis Methodology
• Email Protection Management
• Network Blocks o Network IP Block Request o Detection Integration Services (DNS) Sinkhole Blocks o IP Sinkhole Blocks
• DNS Sinkhole o Workflows o Creating Configuration Files o IMS Task Assignment o Querying o Adding to Blacklist Domain
• Triage Analyst Procedures o Calldown List o Escalation Procedure o Information Request o SOC Alerts
• Escalation Procedure o Management Notification o Infrastructure Issues o Technical Analysis Questions
• Other SOC Related Procedures o Accounts Setup o Reports
§ Adhoc SOC Reports § SOC Daily Activity Report § SOC Weekly Status Report § SOC Monthly Status Report § SOC Quarterly Status Report o SOC Annual Status Report Reference/Document Library (products developed/maintained by the contractor) § NASA to Cloud Service Diagram § NASA Agency Network Diagram § HQ Network Diagram § Wide Area Networks (WAN) Logical Structure § Agency White List § NASA Centers Map § External Email Security Stack § NASA Connectors § Terminal Access Point (TAP) Configurations § NASA IPv6 Allocated Addresses § Other SOC related references
3.2.3.2.3 Tier 3
NASA needs both proactive and reactive capabilities in addressing computer security at the Agency level. Tier 3 is comprised of six distinct functional areas to include:
• Computer Forensics and Incident Analysis – The Contractor shall provide for emergency off hour support within ½ hours' notice for off-site (online and phone support) and on-site support within 2 hours. The Contractor shall provide forensics support, as part of the incident response process. The Contractor shall review Tactics, Techniques, and Procedures (TTPs) to determine mitigation actions required to prevent future incidents.
• Threat and Vulnerability Assessment – The Contractor shall support the tracking, reporting, management, and remediation of threats against the Agency.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .