IPM_PWS_Final.pdf

PDF 469 KB Posted

Attached to
Identity Protection Management Support Services (IPM) Federal contract opportunity
Solicitation number
HQ0034-17-R-0122
Issued by
DOD Washington Headquarters Service

About this file

HQ0034-17-R-0122 Performance Work Statement (PWS)(IPM)

View the file

Other files for this federal contract opportunity

Other files attached to Identity Protection Management Support Services (IPM), newest first.
File Type Posted
HQ0034-17-R-0122-0001_Amend_1.pdf PDF
Final_Questions_and_Answers_Amendment.pdf PDF
Orgainiztional_Conflict_of_Interest_(OCI)_Amend_1.pdf PDF
IPM_PWS_Final_Rev_81017_Amend_1.pdf PDF
Final_PAST_PERFORMANCE_EVALUATION_QUESTIONNAIRE.pdf PDF
Solicitation_Questions_and_Answers_Final.pdf PDF
DD_Form_254_1_20170717.pdf PDF
PAST_PERFORMANCE_EVALUATION_QUESTIONNAIRE.pdf PDF
NDA_IPM.pdf PDF
OCI.pdf PDF
HQ0034-17-R-0122_072417_-Final1.pdf PDF
Show all 11

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

JOINT SERVICE PROVIDER (JSP)

IDENTITY PROTECTION

AND

MANAGEMENT SUPPORT SERVICES

PART 1

GENERAL INFORMATION

1. GENERAL: This is a non-personnel services contract to provide Identity Protection Management (IPM) Support Services. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

1.1 Description of Services/Introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform Identity Protection and Management Support Services as defined in this Performance Work Statement except for those items specified as government furnished property and services.

1.2 Background: The contractor shall perform to the standards in this contract for Identity Protection and Management Support Services. The Joint Service Provider (JSP) provides a full range of information technology products, services, solutions and customer support to the Office of the Secretary of Defense (OSD), the Chairman of the Joint Chiefs of Staff (CJCS) and the Joint Staff (JS), the Director of Administration (DA), the Pentagon Force Protection Agency (PFPA), the Washington Headquarters Services (WHS) and other various OSD offices to meet mission and business requirements. JSP also provides advice and assistance to OSD and other senior managers to ensure that Information Technology (IT) and information resources are managed in a manner that implements the policies and procedures of legislation and the priorities established by OSD.

1.3 Objective: The overall objective of the JSP Identity Protection and Management Support Services is to support the identity verification and issuance of strong credentials (e.g.

name, DoD ID number) for access to DoD protected online resources leveraging the DoD Public Key Certificates. Public Key Certificates are issued within the broader DoD Public Key Infrastructure which provides the framework for the delivery of services around generation, production, distribution, control, accounting and destruction of Public Key Certificates. DoD PKI certificates enable the end user to perform authentication, digital signature, and encryption. JSP IPM shall continue to provide responsive and high quality IPM services to JSP, OSD, CJCS, JS, DA, PFPA, WHS, and other external customers to meet their mission and business requirements.

1.4 Scope: The contractor shall provide the following types of Identity Protection Management Support Services to JSP and its customers:

• Program Management

• IPM Support to Information Technology (IT) Operations

• Public Key Infrastructure (PKI) Certificate Request Processing & Token Issuance

• PKI and Security Engineering, Technical, and Policy Support

1.5 Period of Performance: The period of performance will consist of a base period of twelve months with four (4)-12 month option periods.

1.6 General Information:

1.6.1 Quality Control: The Contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s quality control program is the means by which he assures himself that his work complies with the requirement of the contract. The QCP shall be delivered via electronic mail within 30 days of contract award. Amendments/changes to the QCP shall be delivered to the COR and KO within three business days following any change.

1.6.2 Quality Assurance: The government shall evaluate the Contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.6.3 Recognized Holidays: The Contractor is not required to perform services on holidays.

New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day President’s Day Veterans’ Day Memorial Day Thanksgiving Day Independence Day Christmas Day

1.6.4 Hours of Operation: The contractor shall perform support services on-site (in Government work spaces) during Normal Working Hours (NWH) for the purposes of supporting JSP customers and the JSP network infrastructure. The contractor shall also provide on-site support during Extended Working Hours (EWH). The COR/TM provides written notice to the contractor at least one (1) business days in advance, and specifies the task areas that require support. Normal and extended working hours are defined as follows:

Normal Working Hours (NWH)

0700-1700 Monday through Friday, excluding Government holidays and times during which the Government is declared closed by Office of Personnel Management

(OPM).

Extended Working Hours (EWH)

Extended Working Hours are all hours outside of NWH (including weekends and Government holidays and times during which the Government is declared closed by the Office of Personnel Management (OPM))

1.6.5 Place of Performance: The primary place of performance will be at the Mark Center, Pentagon, and other Government facilities within the National Capital Region (NCR). In addition, the contractor may be required to provide support at other JSP locations, such as Hampton Roads, VA, and JSP COOP sites outside the NCR. The specific locations of the COOP sites are sensitive and will not be provided till after the contract is awarded.

1.6.6 Type of Contract: The government will award a Hybrid Contract which will include Firm Fixed Price Contract Line Item Numbers (CLINS) , Labor Hour CLINs, and Time and Material CLINs.

1.6.7 Security Requirements: The Contractor must have a current Secret Facility Clearance from the Defense Security Service (DSS) at the time of proposal submission and must maintain the level of security required for the life of the contract. No exceptions. The Government shall not sponsor any offeror for the clearance. In addition, the contractor personnel performing work under this contract must have a current Secret Security Clearance reflected in the Joint Personnel Adjudication System (JPAS) at entrance on duty, and must maintain the level of security required for the life of the contract. The prime contractor is required to flow-down the Secret Facility Clearance requirements to subcontractors under this contract. The security requirements are in accordance with the attached DD Form 254.

1.6.7.1 Physical Security Requirements: The Contractor shall be responsible for safeguarding all government equipment, information, and property provided for Contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.

1.6.7.2 Key Control: The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer.

1.6.7.2.1. In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

1.6.7.2.2. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.

1.6.7.3 Lock Combinations. The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s Quality Control Plan.

1.6.7.4 Cyber Security: JSP supports workstations that reside on the NIPRNet, SIPRNet and Joint Worldwide Intelligence Communications System (JWICS). Contractor personnel who perform work on DoD Automated Information Systems (AIS) must have one of three position sensitivity designations ADP-I: BI, ADP-II DNACI/NACI, and ADP-III NAC/ENTNAC in accordance with (IAW) DoD 5200.2-R, Personnel Security Program. These designations are Critical Sensitive ADP-I or Non-Critical Sensitive ADP-II. The Contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DODD 8140.01, Cyberspace Workforce Management and DoD 8570.01-M, Information Assurance Workforce Improvement Program.

1.6.7.5 The Contractor shall instruct all new contractor employees in DOD Information Security Requirements and Guidance, to include DoD Manual (DoDM) 5200.01, Volume 3, DoDM 5200.01, Volume 4, DoD 5400.11-R, CNSS Policy No. 18, and CNSSI No. 1001. All Contractor employees must understand and follow the policy and guidance to protect classified and controlled unclassified information and prevent unauthorized disclosures. Contractors are responsible for negligent discharge of classified information and shall reimburse the government the cost of sanitizing equipment and clean-up. In addition, costs (e.g., for credit monitoring) may apply if the data spill(s) results in the exposure of personally identifiable information (PII). DoD and its Government agencies are not responsible for the payment of certification(s) or recertification for Contractor employees.

1.6.7.6 Negligent Discharge of Classified Information (NDCI): When information is placed on or processed on an information system with insufficient security controls to appropriately protect it (e.g., classified data on an unclassified system) there is a potential for an unauthorized disclosure.

Such actions will be classified as a security violation, specifically a negligent discharge of classified information or NDCI. Contractors that cause NDCIs during the course of the contract shall be held financially liable for all actual accumulated restoration costs incurred, as described below, but not less than $2,500 per incident. Such costs will be deducted from the contract price, and are not reimbursable.

a. Restoration costs above $2,500 will be itemized. DISA has developed a Classified Message Incident Standard Operating Procedures (SOP) that will be followed in the event of an NDCI by the Contractor. Personally Identifiable Information (PII) incidents fall under this category. This is not an exclusive remedy (e.g., in the case of PII spillage, identity theft or other insurance may be needed to protect the individuals).

b. NDCI Cleanup actions may include the following actions:

i. Server destruction

ii. Hard drive wipe and destruction

iii. Containment actions”

1.6.7.7 NATO SECURITY: The Contractor shall comply with the NATO security requirements specified in the DD254. This includes support on equipment, which processes NATO classified information. Actual knowledge of, generation, or production of NATO classified information is not required for performance of the contract. Cleared personnel are required to perform this service because access to NATO classified information cannot be precluded by escorting personnel. Contractor shall obtain government approval for access to NATO information and follow government policy to safeguard NATO information. Contractor shall not have access to NATO information until all approvals are in place and NATO access recorded in Joint Personnel Adjudication System (JPAS). The Prime Contractor must receive approval from the Government Contracting Activity (GCA) to grant NATO access to a subcontractor.

1.6.7.8 The prime contractor is required to flow-down the Secret Facility Clearance and Secret Clearance requirements for contractor personnel to subcontractor for services performed under this contract. Subcontractors shall comply with the same security requirements as the prime contractor. The Contractor shall issue DD Form 254s to each subcontractor, as directed by the Government, reflecting the level of security requirements applicable, based off the level of support provided by the subcontractor.

1.6.8 Special Qualifications: Contractor personnel will be required to sign a Non-Disclosure Agreement. The contractor shall provide NDA’s Five (5) days after contract award.

1.6.9 Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor's performance. At these meetings the Contracting Officer will apprise the Contractor of how the government views the Contractor's performance and the Contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government.

1.6.10 Contracting Officer’s Representative (COR): The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies;

coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.6.11 Key Personnel: The personnel listed below are considered essential to the work being performed under this contract. Before removing, replacing, or diverting any of the listed or specified personnel or facilities, the Contractor shall (1) notify the Contracting Officer fifteen

(15) working days in advance and (2) submit justification (including proposed substitutions) in sufficient detail to permit evaluation of the impact on this contract. The Contractor shall make no diversion without the Contracting Officer's written consent; provided that the Contracting Officer may ratify in writing the proposed change, and that ratification shall constitute the Contracting Officer's consent required by this document. The proposed substitution of personnel must meet or exceed the education, experience, and other technical requirements of the personnel being replaced. No change in personnel shall be made by the Contractor without the prior written consent of the Contracting Officer. In the event the proposed substitution of key personnel does not meet or exceed the education, experience, and other technical requirements of the personnel being replaced, the Government reserves the right to require continued performance of previously approved key personnel or to require substitution of acceptable replacements for the individuals specified below. The key personnel listed below may, with the consent of the contracting parties, be amended from time to time during the course of the Contract to either add or delete personnel as appropriate.

Key Personnel Title Minimum Qualification

Project Manager

Education:

N/A

Years of Experience:

10 Years in Information Technology Management 10 Years in Information Assurance/Cybersecurity

Certifications:

Project Management Professional (PMP) or CompTIA Advanced Security Practitioner (CASP) or Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager

(CISM)

Experience:

- Experience in successfully providing concurrent support to multiple DoD or federal agencies.

- 10 year requirements identified can be concurrent and/or overlapping.

Lead SME

Education:

N/A

Years of Experience:

Seven (7) Years in Information Assurance/Cybersecurity Seven (7) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

CASP or CISSP

Experience:

- Experience in the DoD or Federal agencies dealing with the technical and policy aspects of enabling strong authentication and robust logical access control through the use of public key cryptography and related technologies

- History of installing, configuring, and troubleshooting IPM-related products, conducting hands-on evaluation and testing of IPM-related technologies, and dealing with vendors to resolve technical issues

- Participation in policy working groups or governance bodies for DoD or Federal PKI or PKE

- 7 years requirements identified can be concurrent and/or overlapping.

Technology SME

Education:

N/A

Years of Experience:

Seven (7) Years in Information Assurance/Cybersecurity Seven (7) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

CASP or CISSP

Experience:

- Experience in the DoD or Federal agencies dealing with the technical aspects of enabling strong authentication and robust logical access control through the use of public key cryptography and related technologies

- History of installing, configuring, and troubleshooting IPM-related products, conducting hands-on evaluation and testing of IPM-related technologies, and dealing with vendors to resolve technical issues

Policy SME

Education:

N/A

Years of Experience:

Seven (7) Years in Information Assurance/Cybersecurity Seven (7) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

CASP or CISSP

Experience:

- History of participation in policy working groups or governance bodies for DoD or Federal PKI or PKE

1.6.11.1 Definition of the Labor Hour for Non-Key Personnel: The personnel listed below are non-key personnel that identifies the minimum qualifications needed to perform services specificed in this PWS.

Non- Key Personnel Title Minimum Qualification

Subject Matter Expert (Master)

Education:

N/A

Years of Experience:

Five (5) Years in Information Technology Management OR Seven (7) Years in Information Assurance/Cybersecurity

Certifications:

IAM II (CISSP or CISM or CASP CE) OR IAT III (CISSP or CASP CE) Certified Information Systems Security Professional (CISSP) Certified Information Security Manager (CISM) CompTIA Advanced Security Practitioner Continuing Education

(CASP CE)

Experience:

- History of participation in policy working groups or governance bodies for DoD or Federal PKI or PKE.

Subject Matter Expert (Senior)

Education:

N/A

Years of Experience:

Seven (7) Years in Information Assurance/Cybersecurity Seven (7) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

IAT III (CISSP or CASP CE) Certified Information Systems Security Professional (CISSP) CompTIA Advanced Security Practitioner Continuing Education

(CASP CE)

Experience:

- History of participation in policy working groups or governance bodies for DoD or Federal PKI or PKE

- Seven (7) year requirements identified can be concurrent and/or overlapping.

Information Security Specialist (Master)

Education:

N/A

Years of Experience:

Five (5) Years in Information Assurance/Cybersecurity Five (5) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

IAT II

CompTIA Security+ Continuing Education (Security + CE)

Registration Authority/Key Recovery Agent (RA/KRA) training on NIPR and SIPR (DISA certificate)

Experience:

- Five (5) year requirements identified can be concurrent and/or overlapping.

- Five (5) years as Registration Authority/Key Recovery Agent (RA/KRA) NIPR and SIPR

- NPE RA Computer Based Training Certificate (DoD PKI Office)

- TMS Release 5/6 Training Session Certificate (DoD PKI Office)

Information Security Specialist (Senior)

Education:

N/A

Years of Experience:

Three (3) Years in Information Assurance/Cybersecurity Three (3) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

IAT II

CompTIA Security+ Continuing Education (Security + CE)

Registration Authority/Key Recovery Agent (RA/KRA) training on NIPR and SIPR (DISA certificate)

Experience:

- Three (3) year requirements identified can be concurrent and/or overlapping.

- Three (3) years as Registration Authority/Key Recovery Agent (RA/KRA) on NIPR and SIPR

Web Content Analyst

Education:

N/A

Years of Experience:

Three (3) Years in Information Assurance/Cybersecurity Three (3) Years in technical positions focusing primarily on DoD or Federal PKI or PKE

Certifications:

IAT II

CompTIA Security+ Continuing Education (Security + CE)

Registration Authority/Key Recovery Agent (RA/KRA) training on NIPR and SIPR (DISA certificate)

Experience:

- Three (3) year requirements identified can be concurrent and/or overlapping.

- Zero to One (0-1) years as Registration Authority/Key Recovery Agent (RA/KRA) on NIPR and SIPR

1.6.12 Identification of Contractor Employees: All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed. Contractor personnel will be required to obtain, use, and display a Common Access Card in the performance of this service.

1.6.13 Certification Requirements: All personnel assigned to the contract shall be certified in accordance with DODD 8140.01, Cyberspace Workforce Management and DoD 8570.01-M, Information Assurance Workforce Improvement Program or their replacements. The certifications must be uploaded into the Government defined certification tracking system within five days of start date. All compliance information will be recorded and distributed in accordance with the JSP Cyber Security Center (CSC) Workforce Improvement Program Standard Operating Procedure (SOP). All contract employees shall be DOD 8570.01-M certified prior to starting work. The contracting officer will ensure that contractor personnel are appropriately certified.

Contractors have up to 6 months to obtain the rest of the qualifications for their position.

Additional training on local or system procedures may be provided by the DoD organization receiving services. All contract employees shall maintain applicable certifications as prescribed by the appropriate governing bodies for the certification and the applicable government directives and regulations. Contractor personnel who do not maintain their certifications status will be deemed non-compliant. Non-compliance contractors will result in privileged account(s) being disabled and subject to removal from the contract.

Deliverables:

Certifications loaded in the Army Training and Certification Tracking System (ATCTS) or JSP Certifications Released to Defense Manpower Data Center (DMDC)

1.6.14 Travel: In accordance with FAR 31.205-46-Travel Cost, under the Federal Travel Regulation, the contractor shall provide travel in support of the requirement. The contractor will travel to a city outside the National Capital Region (NCR) to perform Identity Protection Management Support Services listed in Part 5-Specific Task. Travel within the NCR is not separately priced. See Technical Exhibit 6 for travel estimates outside the NCR. The contractor shall provide written request for travel to the Contracting Officer Representative (COR) and Government Task Monitor (GTM) prior to finalizing any travel arrangements. Request for travel shall include the name of the person traveling, the travel destination, dates of travel, mode of transportation, and estimated costs for travel. All travel must be pre-approved in writing by the COR and GTM prior to purchase of any tickets and commencement of travel.

1.6.14.1. All travel that is performed outside the normal business hours in accordance with the PWS Section 1.6.4 titled “Hours of Operations” shall be charged against the Time and Materials (T&M) CLINs. All travel that is performed outside the normal business hours in accordance with the PWS Sections 1.6.4 titled “Hours of Operations” shall be charged against the Labor Hour (LH) CLINs. Travel that occurs under the Firm Fixed Price (FFP) CLINs within the normal business hours shall be charged to the FFP CLINs.

1.6.14.2. All travel within the National Capital Region (NCR) is included in the price of this contract. The contractor shall NOT bill the Government for travel related expenses within the NCR for any CLIN or SUBCLIN under this contract.

1.6.15 Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government.

These documents and materials may not be used or sold by the contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.

1.6.16 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the Contracting Officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the Contracting Officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the Contracting Officer and in the event the Contracting Officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the Contracting Officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.

1.6.17 Phase-In: To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the Contractor shall have personnel on board, during the seven

(7) day phase in/phase out periods. During the phase in period, the Contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date under CLIN 0011.

1.6.17.1 The Contractor shall submit a Transition-In Plan, no later than seven (7) calendar days after contract award, which contains a reasonable, realistic approach for assuming full contractual responsibility without disruption or degradation of performance during the start-up period. At a minimum, the transition-in plan shall be inclusive of the transition of the documentation, operating procedures and other resources, including to devices, equipment, software and systems under JSP’s responsibility as related to this PWS from the current incumbent Contractor or the Government. The plan shall also address knowledge transfer, shadowing, and a training program for Contractor personnel, and a date for accepting responsibilities for each division of work described in the plan.

1.6.17.2 The Contractor shall execute its transition plan and work closely with the incumbent Contractor and the Government to assure uninterrupted contract support. Phase-in activities shall also include Contractor attendance at program reviews, participation in working groups, briefings, on-site communications, and full disclosure of technical, cost, and programmatic information.

1.6.17.3. Within the phase-in period, the Contractor shall ensure all Key Personnel start performance on the first day of the contract period of performance. The Contractor shall reach 100% qualified staffing levels within (7) calendar days of the contract effective date.

1.6.17.4 The Contractor shall work professionally with the outgoing Contractor to achieve a successful and timely transition. The Contractor shall transition all services without interruption or degradation of service levels. The Contractor shall verify system and facility access with the Government.

1.6.17.3 Kick-Off Meeting

The Contractor shall plan and conduct a Contract Kick-off Meeting no later than five (5) days after award at the Government site location. All Contractor key personnel will be required to attend the meeting. The Government reserves the right to include limited VTC participation at the Kick-off Meeting. The Contractor shall prepare and provide required meeting materials, including but not limited to agenda and presentation. The Contractor shall record, distribute and report status of Kick-off meeting action items.

1.6.18 Phase- Out: The contractor shall provide a Transition-Out plan NLT sixty (60) calendar days prior to expiration of the contract. The contractor shall maintain complete configuration management documentation that is totally assessable to the designated Government representatives via a web portal (unless otherwise mutually agreed). The contractor shall identify how it will coordinate with the incoming contractor and Government personnel to transfer knowledge regarding the following:

• Project management processes

• Points of contact

• Location of technical and project management documentation

• Status of ongoing technical initiatives

• Appropriate contractor to contractor coordination to ensure a seamless transition.

• Identify schedules and milestones

• Identify actions required of the Government.

• Establish and maintain effective communication with the incoming contractor/Government personnel for the period of the transition via weekly status meetings.

PART 2

DEFINITIONS & ACRONYMS

2. DEFINITIONS AND ACRONYMS

2.1 DEFINITIONS:

2.1.1 ADP-I positions – Those positions in which the incumbent is responsible for the planning, direction, and implementation of a computer security program; major responsibility for the direction, planning and design of a computer system, including the hardware and software; or, can access a system during the operation or maintenance in such a way, and with a relatively high risk for causing grave damage, or realize a significant personal gain.

2.1.2 ADP-II positions – Those positions in which the incumbent is responsible for the direction, planning, design, operation, or maintenance of a computer system, and whose work is technically reviewed by a higher authority of the ADP-I category to insure the integrity of the system. This is a critical sensitive position.

2.1.3 Certificate – A digital representation of information that, at a minimum, identifies the certification authority issuing it, names or identifies its subscriber, contains the subscriber's public key, identifies its operational period, and is digitally signed by the certification authority issuing it.

2.1.4 Certificate Authority – A CA is an entity trusted by one or more users to create and assign certificates. A CA that signs its own certificate is called a Root CA or a Trusted Root. CAs that have certificates issued by another CA are called Subordinate CAs. CAs are responsible for issuing certificates, publishing certificates, and revoking certificates by placing them on Certificate Revocation Lists (CRL).

2.1.5 Certificate Policy – A named set of rules that indicates the applicability of a certificate to a particular community and/or class of information systems with common security requirements.

A certificate policy may be used by a relying party to help in deciding whether a certificate and the binding therein, is sufficiently trustworthy for a particular information system.

2.1.6 Certification Practice Statements – A statement of the practices that a Certificate Authority, Registration Authority, or other PKI component employs in issuing, revoking, and renewing certificates and providing access to them, in accordance with specific requirements specified in a CP.

2.1.7 Contractor Performance Assessment Reporting System – a paperless contractor evaluation system with the purpose of ensuring that current, complete, and accurate information on contractor performance is available for use in procurement source selections.

2.1.8 Critical Contractor Personnel – Those contractor personnel identified by the Government as COOP deployers.

2.1.9 Public Key Enabling– The incorporation of the use of certificates in association with application and hardware capabilities to provide security services such as authentication, confidentiality, data integrity, and non-repudiation.

2.1.10 Public Key Infrastructure – The framework and services that provide for the generation, production, distribution, control, accounting and destruction of public key certificates.

2.1.11 Quality Assurance Surveillance Plan – provides a systematic method to evaluate performance under the contract and explains what will be monitored, how monitoring will take place, who will conduct the monitoring, and how monitoring efforts and results will be documented.

2.1.12 Requirements Engineering – The actions required of capturing, structuring, and accurately representing the user’s requirements so that they can be correctly embodied in systems which meet those requirements (i.e. are of good quality).

2.1.13 Single Scope Background Investigation - The government-wide investigation required of those who need access to Top Secret classified national security information. This background investigation covers the past seven years of the subject's activities (or to age 18, whichever is less). It includes verification of citizenship and date and place of birth, and well as national agency records checks on the subject‘s spouse or cohabitant, interviews with selected references and former spouses

2.1.14 Software Testing – is an empirical investigation conducted to provide stakeholders with information about the quality of the product or service under test, with respect to the context in which it is intended to operate. This includes, but is not limited to, Unit testing, Regression Testing, and Performance testing, Security testing the process of executing a program or application with the intent of finding software bugs. It can also be stated as the process of validating and verifying that a software program/application/product meets the business and technical requirements that guided its design and development, so that it works as expected and can be implemented with the same characteristics.

2.1.15 Technical Services – Actions that include, but not limited to programming, system designing, system analysis, workflow and dataflow analysis, database analysis, and data migration.

2.1.16 Tokens – Private keys associated with certificates are stored in tokens, which can either be software or hardware based. Software tokens for private keys are typically stored on workstations within applications. Hardware tokens are Smart Cards or other devices used to generate, store, and protect cryptographic information, and can themselves perform cryptographic functions.

2.1.17 Trusted Agent - A Trusted Agent (TA) is an individual explicitly aligned with one or more Registration Authority (RA) who has been delegated the authority to authenticate Subscribers for their particular group; office, or geographical location. A TA serves as an interface between the Subscriber and the RA by performing identity proofing for those Subscribers that cannot appear in person before a RA. A TA does not have privileged access to either the DoD PKI or NSS PKI components to authorize certificate issuance, certificate revocation, suspension, restoration, or key recovery. Instead, the TA provides the vetting and subscriber information to the RA in support of the token registration process. No request submitted by a TA is implemented until approved by a RA.

2.2 ACRONYMS:

A&A Assessment and Authorization AIS Automated Information System ARA Automated Recovery Agent ATCTS Army Training and Certification Tracking System (ATCTS) CAC Common Access Card CASP CompTIA Advanced Security Practitioner CISM - Certified Information Security Manager CISSP - Certified Information Systems Security Professional CJCS Chairman of the Joint Chiefs of Staff CLIN Contract Line Item Number CND Computer Network Defense CNSS Committee for National Security Systems CO Contracting Officer COR Contracting Officer’s Representative CP Certificate Policy CPARS Contractor Performance Assessment Reporting System CPR CAC Pin Reset CS Cyber Security CSC Cyber Security Center COR Contracting Officer Representative COOP Continuity of Operations Plan CPMWG Certificate Policy and Management Working Group CTO Communication Task Order DA Director of Administration DIA Defense Intelligence Agency DISA Defense Information Systems Agency DISR DoD Information Technology Standards Repository DMDC Defense Manpower Data Center DoD Department of Defense DoDM DoD Manual ECAC Enterprise Change Advisory Committee ECCB Enterprise Change Control Board EST Enrollment over Secure Transport ETA Enhanced Trusted Agent EWH Extended Working Hours FISMA Federal Information Security Modernization Act GCA Government Contracting Activity GIG Global Information Grid GTM Government Task Monitor IAVM Information Assurance Vulnerability Management ILSP Integrated Logistics Support Plan IPM Identity Protection Management IPMSCG Identity Council, the Identity Protection and Management Senior Coordinating Group ITIL Information Technology Infrastructure Library KM Knowledge Management JS Joint Staff JSP Joint Service Provider JWICS Joint Worldwide Intelligence Communications System LRA Local Registration Authority

LTMA Less Than Medium Assurance MIPR Military Interdepartmental Purchase Request MOA Memorandum of Agreement MSA Mobility Systems Administrator NACLCNational Agency Check with Local Agency and Credit Check NATO North Atlantic Treaty Organization NCR National Capital Region NDCI Negligent Discharge of Classified Information NEATS NIPRNet Enterprise Alternate Token System (NEATS) NPE Non-Person Entity NSS National Security Systems NWH Normal Working Hours OCSP Online Certificate Status Protocol OMB Office of Management and Budget OSD Office of the Secretary of Defense PFPA Pentagon Force Protection Agency PII Personally Identifiable Information PIN Personal Identification Number PKE Public Key Enablement PKI Public Key Infrastructure PPIRS Past Performance Information Retrieval System PUWG Privileged User Work Group PWS Performance Work Statement QASP Quality Assurance Surveillance Plan QPP Quality Program Plan RA Registration Authority RFC Request for Change RMF Risk Management Framework RPS Registration Practice Statement SCAP Security Content Automation Protocol SME Subject Matter Expert SOP Standard Operating Procedure SRR Security Readiness Review SSBI Single Scope Background Investigation SSL Secure Sockets Layer STIG Security Technical Implementation Guide TA Trusted Agent TLS Transport Layer Security TMS Token Management System VTC Video Teleconference VMS Vulnerability Management System WHS Washington Headquarters Service

PART 3

GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

3. GOVERNMENT FURNISHED ITEM S AND SERVICES:

3.1. Services: The government will provide basic services to phones, desks, utilities, information technology, and general office supplies) while working in Government facilities.

3.2 Facilities: Basic facilities such as work space and its associated operating requirements (i.e., phones, desks, utilities, information technology, and general office supplies) will be provided while working in Government facilities. Tele-workers will only use government furnished equipment to remotely access the WHS network.

3.3 Equipment: The Government will provide will provide basic services to phones, desks, utilities, information technology, and general office supplies) while working in Government facilities. Tele-workers will only use government furnished equipment to remotely access the WHS network.

The Contractor shall furnish equipment to meet the requirements under this PWS that are not listed under Section 3 of this PWS.

3.4 Utilities: The Government will provide all necessary utilities in the facility for the contractor’s use in performance of tasks outlined in this PWS. The Contractor shall instruct employees in utilities conservation practices. The contractor shall be responsible for operating under conditions that preclude the waste of utilities

GFP/I to be Provided Description

Personnel Workspace

On-site office space for up to fourteen IPM Support contractor personnel will be provided at various JSP operating locations (see section 1.5.5), subject to space availability and requirements. All IPM Support contractor personnel will be provided a standard workspace, which includes a desktop computer, network and printer access, office supplies, telephone, facsimile and access to a copier.

Personal Devices At the discretion and approval of the Government, personal communication and IT devices (e.g., BlackBerry, pager, cell phone, laptop, etc.) will be provided to critical IPM Support contractor personnel (e.g., COOP deployers, etc.).

Technical Data and Software Licenses

At the discretion and approval of the Government, applicable and relevant technical data and software licensing will be provided to the IPM Support contractor. This includes PKI middleware and certificate validation software for user workstations and any software required for Registration Authority (RA) and Common Access Card (CAC) Personal Identification Number (PIN) Reset (CPR) workstations.

PKI Hardware Adequate quantities of card readers, hardware tokens (e.g. Alt Token, SIPR Token), and other hardware items necessary to deploy and support PKI capabilities for WHS & OSD will be provided.

Knowledge Management Platforms

Mechanisms such as file shares and web servers for managing IPM information will be provided.

GSA Safe 5 drawer safe with individual locks

Operational Room Dedicated and firewalled operational room (restricted access to only RA and support team)

NIPR Network connectivity, NIPR laptop, NIPR RA Workstation Lockdown, Alt Token Stocks, Log Book(s)

SIPR Network connectivity, SIPR workstation w/ removable hard drive or laptop, SIPR RA workstation lockdown, SIPR token stock, log book(s)

PART 4

CONTRACTOR FURNISHED ITEMS AND SERVICES

4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES:

4.1 General: The Contractor shall furnish all supplies, equipment, facilities and services required to perform work under this contract that are not listed under Section 3 of this PWS.

4.2 Secret Facility Clearance: The Contractor must have a Secret Facility Clearance from the Defense Security Service (DSS) at the time of proposal submission and must maintain the level of security required for the life of the contract. No exceptions. The Government shall not sponsor any offeror for the clearance. In addition, the contractor personnel performing work under this contract must have a current Secret Security Clearance reflected in the Joint Personnel Adjudication System (JPAS) at entrance on duty, and must maintain the level of security required for the life of the contract. The prime contractor is required to flow-down the Secret Facility Clearance requirements to subcontractors services performed under this contract. Please see attached DD-254.

4.3. Materials: NA

4.4. Equipment: NA

PART 5

SPECIFIC TASKS

5 SPECIFIC TASKS:

5.1 Basic Services: This is a non-personal services contract to provide Identity Protection Management Support Services. The government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the contractor, who, in turn is responsible to the government.

5.2 Program Management Support Services: The contractor shall provide Program Management Support Services shall actively manage the performance of tasks described within this Performance Work Statement (PWS). The contractor shall allocate their staff and resources as necessary to meet the specified performance objectives. The contractor shall conduct planning, monitor performance, and report results.

5.2.1 The contractor shall perform program management for JSP IPM projects, including development of project plans and supporting documentation, tracking and reporting of progress, and coordination with government stakeholders and customers. Program management shall be performed in accordance with established project management methodologies, such as Project Management Institute (PMI) or Information Technology Infrastructure Library (ITIL), including templates and documentation requirements.

5.2.2 The contractor shall develop and execute a Quality Program Plan (QPP) for JSP IPM activities in support of this PWS. Within the plan, the contractor shall address the collection, analysis, and reporting of performance data. The contractor shall provide a weekly summary of contractor activities in support of the IPM requirements defined within this PWS.

5.3 IPM Support Services: The contractor shall provide IPM Support Services for Tier III and Tier IV support in the form of IPM contractor support to JSP IT operations staff, including the JSP Help Desk. Tier III and Tier IV are the contractor's levels of resolution that have been escalated beyond the Tier I and Tier II levels, handled by the JSP Help Desk. Tiers I and II are not in scope of these requirements.

5.3.1 Tier III IPM Support: In the Tier III capacity, the contractors shall assist and provide support to Server Operations, Desktop Engineering, End Point Security, and Back Office Projects, Enterprise Network Monitoring Services and VIP support to solve intermediate technical problems related to IPM and confirm the nature of more complex issues before referring to Tier IV. Tier III assistance, also includes providing clarification to JSP customers on DoD and Federal IPM related policies and directives (See Part 6- Applicable Publications).

5.3.2 Tier IV IPM Support: In the Tier IV capacity, the contractors shall assist and provide support to Problem Management, Solutions/Desktop Engineering, Applications Engineering and Architecture to solve intermediate technical problems related to IPM and confirm the nature of more complex issues. Issues escalated to Tier IV are those that cannot be resolved at the Tier III level. Tier IV assistance, also includes providing clarification to DoD and Federal IPM related policies and directives (See Part 6-Applicable Publications).

5.4 JSP PKI Issuance Infrastructure: The contractor shall provide deployment, operation, maintenance assessment & authorization, and life cycle planning support to JSP. The Coverage of systems will include to CAC PIN Reset (CPR) and DoD Registration Authority (RA) workstations, the Less Than Medium Assurance service (LTMA) infrastructure service. The contractor shall perform a variety of tasks as described in detail below, but shall not undertake system or software work that has not been approved through the JSP Enterprise Change Advisory Committee (ECAC).

5.4.1 The contractor shall provide technical assistance for IPM-related deployments to JSP. This assistance will primarily be in the form of planning, engineering, testing, and troubleshooting, but may occasionally include installation work, including the distribution of software to workstations and servers.

5.4.2 The contractor shall operate and maintain a CAC PIN Reset (CPR) workstation as well as NIPRNet and SIPRNet DoD RA workstations within their workspaces.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .