23F7300_PWS.pdf
PDF 821 KB Posted
- Attached to
- MDA IT Operations & Engineering Solutions (MIOES) - CANCELED Federal contract opportunity
- Solicitation number
- HQ0857-MIOES-ZA
- Issued by
- DOD Missile Defense Agency
About this file
This document is a Performance Work Statement (PWS) for the Missile Defense Agency (MDA) Integrated Research & Development for Enterprise Solutions (IRES) Contract Number HQ079617D0001, Task Order Title: Engineering Web Services (EWS), Task Order Number: HQ085723F7300.
The PWS outlines the objectives and requirements for operating, sustaining, and managing the EWS enclave and the Modeling and Simulation (M&S) Center. Key tasks include network support, system administration, cybersecurity, operations and maintenance, configuration management, asset management, and other support activities. The PWS specifies Service Summary Items that will be used to assess contractor performance. The period of performance is 1 April 2023-8 August 2025 and the task order type is Cost Plus Incentive Fee. Work will be performed at Schriever Space Force Base, Colorado Springs, CO, and other CONUS locations as identified by the Program Manager.
View the file
Other files for this federal contract opportunity
Show all 50
MDA IT Operations & Engineering Solutions (MIOES) - CANCELED has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT
Missile Defense Agency (MDA)
Integrated Research & Development for Enterprise Solutions (IRES)
Contract Number: HQ079617D0001
Task Order Title: Engineering Web Services (EWS)
Task Order Number: HQ085723F7300
Period of Performance: 1 April 2023–8 August 2025
Task Order Type: Cost Plus Incentive Fee ii
PERFORMANCE WORK STATEMENT REVISION HISTORY
Version Mod Date Revision/Change Description
Base Base TO 01-Apr-23 N/A iii
TABLE OF CONTENTS
1. PURPOSE
2. BACKGROUND
3. SCOPE
3.1 O&S of EWS Enclave and M&S Center
3.2 Quadrant Maintenance
4. SERVICE SUMMARY ITEMS
5. CONTRACT DATA REQUIREMENTS LIST
6. MILESTONES
7. GP, GFP, GFI, AND CAP
8. SPECIAL REQUIREMENTS
9. APPLICABLE DOCUMENTS
10. STATEMENT OF OBJECTIVES AND OUTCOMES
10.1 Task Order Administration
10.1.1 Task Order Management
10.1.2 Enterprise Task Order Support
10.1.3 Task Order Award and Modification
10.2 Task Order Operations
10.2.1 Mission and Performance Assurance .......................... Error! Bookmark not defined.
10.2.2 Procurement Services Support
10.2.3 Risk Management
10.2.4 Task Order Travel (PPWP)
10.3 Cybersecurity
10.3.1 Cybersecurity Risk Management Framework Activities—Non-Deferrable (Work
Package Level)
10.3.2 Cybersecurity Monitoring and Reporting Tools—Non-Deferrable (Work Package
Level)
10.3.3 Cybersecurity Labor (PPWP)
10.3.4 Cybersecurity Training (PPWP)
10.4 Operations and Maintenance
10.4.1 EWS Network Support—Physical
10.4.2 EWS Network Support—Virtual (Previous OASIS Work) [RESERVED]
10.4.3 OM&S EWS and M&S Center System Administration—Windows and Associated
Services
10.4.4 OM&S EWS and M&S Center System Administration—Linux and Associated
Services (Previous OASIS Work) [RESERVED]
10.4.5 EWS OM&S Transition Planning [RESERVED]
10.4.6 EWS OM&S Transition Training [RESERVED]
10.4.7 EWS Project Management/Liaison
10.4.8 Personnel Travel
10.4.9 Hardware Enhancements and Upgrades (PPWP)
10.4.10 Software Enhancements and Upgrades (PPWP)
10.4.11 Operations and Maintenance Labor (PPWP)
10.4.12 Project Management Labor (PPWP)
10.4.13 Operations and Maintenance Training PPWP
iv
10.5 Configuration, Change, Asset, Knowledge, and Customer Management and Data
Analytics
10.5.1 Configuration and Change Management
10.5.2 Asset Management
10.5.3 Knowledge Management
10.5.4 Customer Management
10.5.5 Data Analytics
10.5.6 Remedy Management (PPWP)
10.5.7 Configuration, Change, Asset, Knowledge, and Customer Management and Data
Analytics Labor (PPWP)
10.6 Other Than Collateral and Top Secret Enclave
OTC and TSE
10.6.1 —Limited Support
10.6.2 OTC and TSE— Network Support [RESERVED]
10.6.3 OTC and TSE—System Administration [RESERVED]
10.6.4 Configuration Management [RESERVED]
10.6.5 Asset Management [RESERVED]
10.6.6 Other Than Collateral Project (PPWP)
1. PURPOSE
Operate, sustain, and manage the Engineering Web Services (EWS) enclave and the Modeling and Simulation (M&S) Center.
2. BACKGROUND
IRES predecessor Task Orders (TOs) are as follows:
IRES TO 18F7300: M&S EWS and System Post-Flight Reconstruction (SPFR)
IRES TO 19F7300: EWS and SPFR
Add 21F7300 Engineering Web Services (EWS)
This TO will also follow the Systems Engineering (SE) and Integration (SE&I) requirements identified in the following IRES TO:
IRES SE and Program Integration (SE&PI)
Work under this TO will be performed at the following locations:
Schriever Space Force Base (SFB), Colorado Springs, CO (COS)
COS
Redstone Arsenal, AL
Huntsville, AL (HSV)
Georgia Tech Research Institute, GA
John Hopkins University Applied Physics Laboratory, MD
Moorestown, NJ
McClain, VA
Dahlgren, VA
Other extension sites in Continental United States (CONUS) locations as identified by the
Program Manager (PM)
3. SCOPE
Perform operations, sustainment, and management activities for the M&S Center located on
Schriever SFB at the Missile Defense Integration and Operations Center (MDIOC), Building
720, Quadrant (Quad) 2400, and for the EWS enclave. Work with the IRES SEPI TO to ensure effective integration across the program.
3.1 O&S of EWS Enclave and M&S Center
Provide system operations, sustainment, maintenance, and management, including change and
Configuration Management (CM), customer management, preventative maintenance, systems administration, cybersecurity, Asset Management (AM), hardware and software refresh, system check out, and break-fix activities.
3.2 Quadrant Maintenance
Manage the operations, maintenance, Certification and Accreditation (C&A), CM and Access
Control (AC), physical security, communication networks, computing systems, software licenses, and synchronize hardware and software upgrades of the M&S Center Quad 2400 and
MDA/DES Quad 2400 tenants.
4. SERVICE SUMMARY ITEMS
In Accordance With (IAW) the IRES Performance Evaluation and Incentive Plan, Service
Summary Items (SSIs) 1–4 are common (i.e., required on all TOs and will be assessed at the contract level (i.e., all TOs will receive the same rating). SSIs 5–11 capture the specific TO SSIs deemed essential to successful execution of the task(s).
SSI Definition
Name EWS Activities and Tasks
Identifier SSI #5
Definition The contractor shall perform and complete all necessary and required EWS activities and tasks on schedule as outlined in the agreed upon EWS Activities and Tasks Schedule (PWS paragraph 10.2.3, 10.3 #33, 10.4.1 #28, 10.4.2 #8, 10.5, 10.6).
Measurable
Concept
Schedule
Questions
Addressed
Were all necessary and required EWS activities and tasks performed and completed on schedule as outlined in the EWS Activities and Tasks Schedule during the monthly Jacobs
Accounting Period?
Baseline
Measure
On-schedule completion by TO 7300 and delivery to Government of all necessary and required
EWS activities and tasks as outlined in the EWS Activities and Tasks Schedule within the monthly Jacobs Accounting Period.
Technical Performance Measures
Contractor performs and completes all necessary and required EWS activities and tasks as outlined in the EWS
Activities and Tasks Schedule by their approved or adjudicated due dates and times.
Quality Performance Index (QPI) = 25
Contractor does not perform and complete a necessary or required EWS activity or task on schedule as outlined in the
EWS Activities and Tasks Schedule by its approved or adjudicated due date and time.
QPI Decrement = –1 QPI Per Day Late Per Task
Late
(Max QPI Decremented = –25)
Name EWS Core Systems/Services and Network Node Availability
Identifier SSI #6
Definition The contractor shall provide maximum EWS Core Systems/Services and Network
Nodes availability as outlined in PWS paragraph 10.4.1 #28.
Measurable Concept Percentage of EWS Core System/Service or Network Node availability as defined below in “Notes” over the monthly Jacobs Accounting Period.
Questions Addressed Was each specified EWS Core System/Service or Network Node available over the monthly Jacobs Accounting Period?
Baseline Measures Availability percentage of each EWS Core System/Service and Network Node within the monthly Jacobs Accounting Period.
Technical Performance Measures
Availability percentage of an EWS Core
System/Service or Network Node that
IRES TO 7300 is designated as having primary responsibility.
Tier 1 Availability Criteria Tier 2 and 3 Availability Criteria
≥ 99% Availability QPI = 25
≥ 98% Availability QPI = 20
≥ 97% Availability QPI = 15
≥ 96% Availability QPI = 10
≥ 95% Availability QPI= 5
< 95%: QPI = 0
Per Government and IRES agreed upon schedules and deadlines per circumstance (SSI #5).
Occurrence of an EWS Core
System/Service or Network Node outage due to an IRES TO 7300-attributable, non-CCB or Government approved change.
QPI Decrement = –10 Per Occurrence
Max QPI Decrement across both measurements = –25
Notes: Availability is defined as the time during core business hours that a
EWS Core System/Service or Network Node properly and fully performs its intended and designed function and purpose, and is active, accessible, usable, manageable, and maintainable.
Decrements to the availability percentage excludes planned and approved outages for a specific Core System/Service or Network
Node and excludes successful fail-overs where the redundancy/back-up design of the Core System/Service or Network Node allows EWS users to experience no mission impact (SSI #6).
EWS Core Systems/Services are those identified systems and services required for EWS operations, user access, and overall system functionality. EWS Network Nodes are those identified network nodes required for EWS system, service, and user connectivity and communication. The list of EWS
Core Systems/Services and Network Nodes are specified and maintained by the Government as Tier 1, Tier 2, or Tier 3 for availability criteria.
Name EWS CIRR Compliance
Identifier SSI #7
Definition The contract shall report EWS CIRR event/incidents IAW the procedures and timelines outlined in the EWS CIRR Memorandum (PWS paragraph 10.3, #30 and
PWS paragraph 10.4.1, #30).
Measurable Concept EWS CIRR event/incidents reported IAW the procedures and timelines outlined in the
EWS CIRR Memorandum.
Questions Addressed Were all EWS CIRR events/incidents properly reported within the timelines specified in the EWS CIRR Memorandum for the monthly Jacobs Accounting Period?
Baseline Measures EWS CIRR reportable events/incidents and reporting timelines.
Technical Performance Measures
All EWS CIRR specified events or incidents reported
IAW the EWS CIRR Policy.
QPI = 10
EWS CIRR specified event or incident occurrence not reported IAW EWS CIRR Policy.
QPI Decrement = –5 Per Occurrence
(Max QPI Decremented = –10)
Name Critical Cybersecurity and Security Events
Identifier SSI #8
Definition Negative consequences if any of these critical events involving the loss of an ATO or
EWS data occur as determined by MDA/EIR following an investigation, if applicable
(PWS paragraph 10.3, 10.4.1).
Measurable Concept Occurrence of specified critical events attributable to TO 7300.
Questions Addressed Did any of these critical events occur during the entire six-month evaluation period?
Baseline Measures Number of event occurrences during the entire six-month evaluation period.
Technical Performance Measures
Critical Cybersecurity or Security Event
Occurs
Denial of ATO (DATO) Issued QPI Decrement = –15
Per MDA 5200.02-INS, Information Security Program; DoD Instruction (DoDI)
5200.48, Controlled Unclassified Information (CUI); and DoD Manual 5200.01, Volume 3.
CUI Infraction QPI Decrement = –3
CUI Infraction Self Report QPI Decrement = –1
Classified Infraction QPI Decrement = –5
Classified Infraction Self Report QPI Decrement = –2
Classified Violation QPI Decrement = –15
Classified Compromise QPI Decrement = –15
Max QPI Decrement across all measurements = –15
Notes: (1) Infraction. An infraction is a security incident involving failure to comply with requirements (i.e., the provisions of References (d) and (f), this Manual or other applicable security policy) which cannot reasonably be expected to, and does not, result in the loss, suspected compromise, or compromise of classified information. An infraction may be unintentional or inadvertent. While it does not constitute a security violation, if left uncorrected, can lead to security violations or compromises. It requires an inquiry to facilitate immediate corrective action but does not require an in-depth investigation.
(2) Violation. Violations are security incidents that indicate knowing, willful, and negligent for security regulations, and result in, or could be expected to result in, the loss or compromise of classified information. Security violations require an inquiry and/or investigation.
(a) Compromise. A compromise is a security incident (more specifically, a violation) in which there is an unauthorized disclosure of classified information (i.e., disclosure to a person(s) who does not have a valid clearance, authorized access, or a need to know).
Name EWS Innovation
Identifier SSI #9
Definition The contract shall foster an environment and encourage innovation in its workforce with the aim of increasing the performance, efficiency, and/or the cybersecurity posture of EWS. This SSI is designed to incentivize those innovations that make a material, significant, and positive difference to the Government and the mission of
EWS or the MDA.
For example, in the area of Cybersecurity, the following would be considered innovations:
If the contractor, through automation or increased efficiency, reduces the hours needed to complete a battle rhythm task, freeing up resources to address other Government priorities
If the contractor develops a process with outside cybersecurity teams that aids in better cybersecurity practices being shared across groups, thus improving the overall cybersecurity picture for MDA, that would be considered an innovation.
This score shall be assessed once per evaluation period, but can be annotated in monthly QPR for tracking purposes.
Measurable Concept The contractor makes an improvement, proposes a project, effects change, or discovers an efficiency that saves the Government significant time or resources and/or improves performance.
Questions Addressed Is the contractor providing above and beyond service to the Government that exceeds
Government expectations and demonstrates innovation?
Baseline Measures Each approved innovation is entirely at the Government’s discretion, not subject to appeal or negotiation by the contractor. The contractor may present items for consideration to the Government as they feel it is appropriate.
Technical Performance Measures
EWS Innovation as approved by the Government (not to exceed max score of 75 during any performance assessment period).
QPI Increment = +5 Per Occurrence
5. CONTRACT DATA REQUIREMENTS LIST
The point of delivery for all Contract Data Requirements List (CDRL) products, except as noted in Exhibit C, is the MDA Electronic Content and Records Tool (ECaRT) system. The Contractor shall deliver all such products by saving and profiling them in ECaRT, with the appropriate notification of delivery letter transmitted electronically to the Government’s Data Management
Office (DMO); refer to Exhibit C for specific CDRL delivery instructions. The Department of
Defense (DD) Form 1423 associated with each CDRL is attached to the TO in Exhibit C.
Contract Data Requirements List Identification
Task CDRL DID Title Description
10.1.1.1 C001 DI-MGMT-81861/T TO HQ085723F7300:
Integrated Program
Management Report
Tailored IPMR for formats 1, 5, 6, and 7 only that contain the content and relationships required for the electronic submissions.
10.1.1.1 C002 DI-MISC-80508B/T TO HQ0785723F7300:
Task Order Status
Report, [month ending]
Provides significant accomplishments, issues, concerns, LL, and risks associated with the
TO.
Reserved C003
10.2.1.10 C004 DI-MISC-80508B/T TO HQ085723F7300:
Assessment and
Accreditation
Documentation
The deliverable for this CDRL will be the SSP. The SSP is the formal document that provides an overview of the security requirements for a system and describes the security controls in place or planned for meeting those requirements.
10.5.2 C005 DI-MISC-80508B TO HQ085723F7300:
Assets, Maintenance, Spares and Tech Refresh
Report
Submitted annually IAW DD Form
1423 requirements.
Reserved C006
Reserved C007
Exhibit C
6. MILESTONES
PWS Paragraphs Activity Date/Days after Contract (DAC)
10.1.1.1 Integrated Baseline Review (IBR) 90 Days after award
10.1.1.1 Annual IBR 12 months after initial IBR
7. GP, GFP, GFI, AND CAP
In addition to any Government Property (GP) associated with the IRES Contract Statement of
Objectives (SOO), paragraph 6.0, the following GP is applicable to this TO:
None
In addition to the Government-Furnished Property (GFP) identified in the IRES Contract, Attachment 5, the following GFP is applicable to this TO:
None
The following Government-Furnished Information (GFI) is applicable to this TO:
Responsible, Accountable, Consulted, Informed (RACI) Matrix
Tiered Services List
Critical Information Reporting Requirements (CIRR) Memo
Artifacts delivered from OASIS
EWS (and external customers), Other Than Collateral (OTC), and Top Secret Enclave
(TSE) asset status reports attribute list
All Contractor-Acquired Property (CAP) and GFP shall be managed under the terms and conditions associated with TO 22F8900: Government Property Management.
8. SPECIAL REQUIREMENTS
In addition to the special requirements identified in the IRES Contract SOO, paragraph 7.0, the following are applicable to this TO:
This TO shall be executed IAW MDA security classification guidance up to the classification level of TOP SECRET//Sensitive Compartmented Information (SCI)/
Special Access Requirement (SAR) with Formerly Restricted Data (RD) (FRD) handling requirements, No Foreign (NOFORN), and North Atlantic Treaty Organization (NATO)
SECRET. A limited number of appropriately eligible cleared positions (i.e., maximum 2–
3 individuals) are required to perform this work and provide regular status to MDA/DES.
Personnel performing Information Assurance (IA) functions must obtain one of the certifications required for their position category or specialty and level. Refer to
Appendix 3 of 8570.01-M for further implementation guidance (refer to the 8570.01-M or refer to http://iase.disa.mil/iawip/Pages/iabaseline.aspx).
9. APPLICABLE DOCUMENTS
In addition to the directives and regulations identified in the IRES Contract SOO, paragraph 8.0, the following are applicable to this TO:
http://iase.disa.mil/iawip/Pages/iabaseline.aspx
Document ID Title Originator Date
DoD Manual 5200.01, Volume
Security Policy MDA 1-Oct-20
SP 800-53 Security and Privacy Controls for
Information Systems and Organizations, Revision 5
MDA/DOI, and the National
Institute of
Standards and
Technology
(NIST)
23-Sept-20
MDA Instruction 5004.01-M Ballistic Missile Defense System Integrated
Baseline Reviews
MDA 05-Feb-16
DoD Instruction 5200.48 Controlled Unclassified Information (CUI) DoD 6-Mar-20
DoDI 5200.39 Critical Program Information (CPI)
Identification and Protection Within
Research, Development, Test, and
Evaluation (RDT&E)
DoD 28-May-15
None Director of Engineering (DE) Organization and Functions Manual
MDA/DE 19-Feb-19
DoD DI-MGMT-81644B DoD Architecture Framework
Documentation
DoD 04-Jan-17
None DoD Earned Value Management System
Implementation Guide
DoD 18-Jan-19
None Engineering Web Services (EWS)
Configuration Control Board (CCB)
Charter
MDA/DES/OPS To Be
Determined
(TBD)
TO 8002, CDRL C037 Environmental Program Plan IRES Current
Revision
None EWS Critical Information Reporting
Requirements (CIRR) Memorandum
MDA/DES/OPS 15-Oct-20
None EWS RACI Matrix MDA/DES TBD
None EWS Tiered Services List MDA/DES TBD
MDA 5200.02-INS Information Security Program MDA 22- Mar-18
PL-IRES-03-0043 IRES Configuration Management Plan IRES Current
Revision
TO 8002, CDRL C008 IRES Program Management Plan IRES Current
Revision
TO 8002, CDRL C016 IRES Risk Management Plan IRES Current
Revision
PL-IRES-12-0024 IRES Risk Management Program Plan IRES Current
Revision
PL-IRES-11-0160 IRES Supply Chain Risk Management Plan IRES Current
Revision
TO 8002, CDRL C036 Mishap Prevention and Safety Plan IRES Current
Revision
None Missile Defense Agency (MDA) Modeling and Simulation (M&S) Intended Uses
Description Document
MDA/DE 01-Jul-20
None Missile Defense Agency (MDA) Systems
Engineering Plan (SEP), Version (v)3.1
MDA/DE 17-Jul-18
None Modeling and Simulation Center Security
Operating Procedure (SOP)
MDA/ESI 14-Apr-20
MDA Manual 5200.08-M Procedures for Protection of Critical
Program Information, Mission Critical
Functions, and Critical Components within the Missile Defense Agency
MDA 01-May-19
Document ID Title Originator Date
PL-IRES-03-0230 Quality Assurance (QA) Program Plan IRES Current
Revision
DoDI 8510.01 Risk Management Framework (RMF) for
DoD Information Technology
DoD 27-Sep-18
Committee on National Security
Systems (CNSS) Instruction
Security Categorization and Control
Selection for National Security Systems
CNSS 27-Mar-14
National Counterintelligence and Security Center (NCSC)
Technical Specifications for Construction and Management of Sensitive
Compartmented Information Facilities, v1.4
NCSC 28-Sep-17
IRES Performance Evaluation and
Incentive Plan
IRES
DoD 8570.01-M Information Assurance Workforce
Improvement Plan
DoD 10-Nov-15
TO 8002 CDRL C005 IRES Systems Engineering Master Plan IRES 10-Aug-22
Special Publication (SP) 800-53, [NIST] , Revision 5
Security and Privacy Controls for
Information Systems and Organizations
NIST September
23, 2020
MDA CTO M17-017 MDA/CERT
Tasking Order (TASKORD) 16-
0043 Fragmentary Order
(FRAGO) 6.
MDA/DISA
TASKORD 20-0020. MDA/DISA
EWS CIRR Memorandum
CH-EWS-05-0268 EWS Configuration Control Board (CCB)
Charter -CUI
EWS 8-Nov-22
10. STATEMENT OF OBJECTIVES AND OUTCOMES
10.1 Task Order Administration
This Performance Work Statement (PWS) section contains the scope, objectives, and outcomes to provide TO administration and management within the integrated framework of the IRES contract. This PWS element includes both TO-specific and IRES contract scope required to manage and administer TOs.
10.1.1 Task Order Management
This PWS element represents the Stakeholder Task and Integration Manager (STIM) and IRES
Integration Management activities required to support the management of requirements of the overall TO, which includes all reporting, briefings, awards, modifications, and SSIs.
Objective #1: The contractor shall manage TO execution, resources, and information to conduct, deliver, and communicate TO requirements delivery.
Outcomes:
Manage the cost, schedule, risk, and technical performance IAW the PWS.
Provide status and insight on performance, including the metrics outlined in the Quality
Assurance Surveillance Plan (QASP).
Manage activities IAW the processes defined in the IRES Program Management Plan.
Ensure all requirements are identified, managed, validated, and verified IAW the contractor’s IRES Systems Engineering Master Plan.
Ensure a common Enterprise Architecture vision is implemented to support MDA “to-be” architectures, to include the identification of gaps and Lessons Learned (LL).
Manage the TO workforce efficiently by mitigating workforce surge and drawdown impacts, analyzing workforce trends, and forecasting workforce needs and hiring to those requirements.
Document, revise, improve, and train to the processes required by the TO.
Report status (e.g., technical, cost, schedule). Status includes cost and schedule performance by Work Breakdown Structure (WBS) and IRES organization structure;
significant accomplishments; customer concerns or issues; TO risks and mitigation status;
and performance against the IRES contract, SEPI, and TO SSIs.
Identify, track, and share performance trends with the Contracting Officer’s Technical
Representative (COTR), Assistant COTR (ACOTR), and applicable Government stakeholders.
10.1.2 Enterprise Task Order Support
This PWS element scope represents the processes and toolsets of contract-wide enterprise support required for delivery of the IRES contract. This support provides the back office functions that enable the TO’s work and resources.
10.1.2.1 Enterprise Management
Objective #1: The contractor shall provide the resources and data to enable enterprise management of this TO for contracting, human resources, business and finance, and Jacobs
Enterprise Management System (JEMS) and Cobra integration.
Outcomes:
Contracting office provides subcontracting and limitation of funds oversight, and processes TO modifications and awards IAW contractual requirements.
Provide on-demand access to program data for MDA customers and stakeholders.
Manage export control requirements to comply with DoD and MDA requirements, including International Traffic in Arms Regulations (ITAR) (22 Code of Federal
Regulations [CFR] 120-130) and technical assistance agreements processes, as required.
Provide Human Resources (HR) staff and functions to support needs for recruiting, hiring, and training a qualified workforce.
Provide business office functions to enable the execution of payroll, timekeeping, accounts receivable and payable, and travel services.
Administer small business and teammate agreements in order to achieve MDA and IRES small business goals.
Manage the workforce in a way that mitigates workforce surge and drawdown impacts, analyzes workforce trends, and forecasts workforce needs to ensure the required staffing is available to meet the requirements of the TO.
Maintain a trained and qualified workforce that is able to perform the functions necessary to operate, support, and sustain MDIOC facilities and systems required under this TO.
Develop and document processes that enable the requirements of the TO to be met.
Deliver quality and innovative work IAW the policy and direction provided in the IRES
Management System set of processes and tools.
Objective #2: The contractor administers an IRES TO Portfolio delivery system that delivers financial, Earned Value (EV), and SSI performance across TOs. The contractor shall utilize TO dashboards and automated workflows in order to manage the portfolio.
Outcomes:
Utilize an IRES Information Management System (IMS) portal to host and communicate
TO EV, performance data, and associated metrics and trends, and continuously evaluates and improves performance through the use of objective performance measures.
Objective #3: The contractor shall provide information security, physical security, export control, and cybersecurity training and processes IAW federal, DoD, and MDA requirements to safeguard the conduct of the MDA mission throughout the IRES contract.
Outcomes:
Protect MDA-identified Critical Program Information (CPI) and Critical Technologies
(CTs) to the standards required in DoD Instruction (DoDI) 5200.39, Critical Program
Information (CPI) Identification and Protection Within Research, Development, Test, and
Evaluation (RDT&E).
Protect Controlled Unclassified Information (CUI) from unauthorized access, disclosure, incident, or compromise.
Maintain System Authorization for contractor-managed systems IAW DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology.
Integrate cybersecurity requirements and considerations into SE, design, and Risk
Management (RM) processes.
Operate contractor-managed systems in IAW cybersecurity requirements.
Provide security administration in IAW applicable DoD, MDA, and local security directives, policies, procedures, and instructions for physical security and for the safeguarding of MDS-controlled and classified information, to include proper document marking, classification, storage, accountability, transmittal, and destruction.
Manage and report the status of personnel requiring privileged access and the required
DoD 8570 certifications for the Operating Systems (OSs) and/or security related tools/devices they support or operate.
10.1.2.2 Performance Management
Objective #1: The contractor shall perform program control to provide an EV Management
(EVM) System (EVMS); associated Control Account (CA) management and scheduling common tools, training, standards, and resources; and contract-wide portfolio and project
Management common tools, training, standards, and resources.
Outcomes:
Develop and manage an EVMS which provides required Integrated Program
Management Report (IPMR) formats and Baseline Review (BR) and Integrated BR (IBR) artifacts.
Perform a BR or IBR within 90 days or as otherwise specified in the TO.
Perform financial management activities in a way that ensures EVM reporting accurately reflects the current state of financial performance and status.
Structure the TO IMS for integration into the contractor’s IRES Integrated Schedule
(IIS).
Manage portfolio and project practices in a way that enables technical consistency and cost effectiveness while providing an adaptable framework for planning, managing, and completing projects for a broad range of tasks and missions.
Milestone: Integrated Baseline Review
CDRL C001: Integrated Program Management Report
CDRL C002: Task Order Status Report
Objective #2: The contractor shall perform Mission Assurance (MA), CM, RM, Quality
Assurance (QA), and Safety that promote and enforce safe and sustainable work practices to prevent personnel injury, damage to property, or harm to the environment.
Outcomes:
Manage risks IAW the IRES Cybersecurity Risk Management Plan (TO 8002, CDRL
C016).
Manage the quality of TO activities IAW the MDIOC Facility Quality Assurance Plan
(TO 8002, CDRL C043).
Manage asset configurations IAW the MDIOC Facility Configuration Management Plan
(TO 8002, CDRL C042).
Perform activities IAW the MDIOC Facility Mishap Prevention and Safety Plan (TO
8002, CDRL C036) to prevent personnel injury and property damage.
Perform activities IAW the MDIOC Facility Environmental Program Plan (TO 8002, CDRL C037) to prevent harm to the environment and maximize sustainable practices.
Objective #3: The contractor shall produce and deliver program data to ensure the products and services provided under this TO utilize established integrated processes and practices that are standardized across the IRES contract.
Outcomes:
Integrate systems integration requirements, capability gaps, and a common architecture vision across the enterprise.
Manage critical assets—including conflict forecasting and de-confliction—across the enterprise.
Track and deliver CDRLs on time and with accurate information.
Solicit and track customer satisfaction with the services and products delivered.
Collect and share LL, best practices, and accomplishments with the COTR, ACOTR, other Government stakeholders, as well as the IRES workforce.
Provide systems integration and a common MDIOC system vision and oversight that are integrated enterprise wide IAW the IRES Program Management Plan.
Provide AS9100-compliant core IRES processes, as well as tailored processes.
Objective #4: The contractor shall submit compliant TO CDRLs and reports and monitor status of all TO CDRL delivery performance IAW CDRL and milestone requirements. The contractor shall document approved processes as part of an IRES-wide management system IAW the IRES
Program Management Plan.
Outcomes:
Track upcoming CDRL deliveries for all TOs, requirements for technical editing support, and schedule to meet on-time deliveries in support of IRES SSI #4.
Coordinate technical editing, process engineering, stakeholder review, and posting of approved MDA and IRES process documents in the IRES Process Asset Library (PAL).
Provide contractual deliverables within the agreed-to schedule, in the correct formats, and to a high level of quality. Post all deliverables to Electronic Content and Records Tool
(ECaRT) and/or IRES PAL.
10.1.2.3 Functional Organizational Support
Note: This area is for functional organization support. Not all TOs will require this support.
Objective #1: The contractor shall provide a functional management oversight structure to lead, manage, and assign resources within their organization.
Outcomes:
Perform leadership, management, and administrative functions. Ensure personnel are trained and equipped to accomplish objectives.
Functional Director leads and manages the department to meet requirements.
Functional Director delivers products and services which includes the correct people, processes, and tools to meet mission requirements.
Functional Director tactically allocates and strategically forecasts resources to ensure the sustainment, renewal, and growth of the technical expertise within the department that meets current and future requirements.
Functional Department provides training, certifications, and career growth of employees.
Functional Director mentors and oversees the execution of event engineering, asset
Operations and Sustainment (O&S), systems integration, and analysis to ensure technical success.
Objective #2: The contractor shall provide functional administrative and management support to communicate and deliver enterprise integration.
Outcomes:
Develop and manage coordination, collaboration, communication, integration activities, and processes between IRES senior managers and Government leaders to support and ensure accomplishment of objectives.
Develop, standardize, and deploy through processes for event engineering, asset O&S, systems integration, and analysis.
Coordinate, integrate, and deliver innovations to the TO mission areas, and IRES as a whole, to optimize efficiencies and mission effectiveness.
10.1.2.4 Procurement Services Support
Objective: The contractor shall provide accurate and timely procurement service functions which meet the needs of the TO.
Outcomes:
Maintain a procurement capability and system that supports the procurement needs and provides status of procurements to stakeholders.
Purchase supplies and equipment IAW the IRES Supply Chain Risk Management Plan, including an authorized suppliers list for critical systems.
10.1.3 Task Order Award and Modification
Objective: The contractor shall provide the resources and data to provide timely and accurate proposals to Government requirements for proposal and other contract modification actions, to include providing support to the Integrated Product Team (IPT) and proposal development for the follow-on TO requested by the Contracting Officer or Contract Specialist.
10.2 Task Order Operations
10.2.1 Facility Operations
Objective: The contractor shall execute facility administrative activities for the M&S Center, such as AC; coordinating and scheduling meetings; coordinating projection capabilities for meetings; and developing, maintaining, and providing access to Management Knowledge Online
(MKO) Portal folders.
Outcomes:
Coordinate across other IRES TOs and with vendors and other Government customers to facilitate and provide AC to the M&S Center footprint for personnel not permanently authorized within the footprint (e.g., facility inspections, cleaning crews, VIP visits, project-related visits, inventory activities)
Perform conference and Video Teleconference (VTC) room scheduling and publish the reservation results.
Assist with room set-up for classified and unclassified VTCs.
Report to the MDIOC Integrated Service Desk (ISD) when classified and unclassified printers are not operational and facilitate paper and toner replacements.
Ensure the “Unclassified Sensitive/CUI/Proprietary Information” recycle bins are serviced through the MDIOC ISD.
Perform cubicle CM by tracking and reporting cubicle seating assignments.
10.2.2 Security Operations
Objective: Security Operations. The contractor shall perform security management functions for
M&S Center IAW MDIOC, MDA, and DoD standards.
Outcomes:
Demonstrate a repeatable cycle of security system auditing and investigation of anomalous activity.
Maintain and manage open storage certification requirements. Provide guidance to occupants on security classification requirements. Receive, generate, and reproduce classified material up to the SECRET classification.
Perform duties as the Security Assistant as defined in the Quad 2400 Security Standard
Operating Procedure (SOP). Coordinate security personnel to respond to physical information security issues and tasks on the behalf of the Security Manager in
Coordination With (ICW) MDA/DIR.
Perform block captain activities in IAW latest Government SOP.
Perform safe management, including inventories and maintenance of safe combinations.
Conduct physical security and export control activities.
10.2.3 Procurement Execution
Objective: The contractor shall provide procurement service functions in an accurate and timely manner that meets the needs of the TO.
Outcomes:
Maintain a procurement capability and system that supports the procurement needs and provides a minimum weekly status of procurements to stakeholders.
Purchase supplies and equipment IAW the IRES Supply Chain Risk Management Plan, to include an authorized suppliers list for critical systems.
10.2.4 Risk Management
Objective #1: The contractor shall perform RM by assisting in the identification of mission and non-mission risks and opportunities within the TO 7300 PWS to assure Concurrent Test, Training, and Operations (CTTO) mission success, to include the following:
TO risks are managed IAW the IRES Risk Management Plan.
Objective #2: Support TO 7300 SSI tracking and reporting.
Outcomes:
Develop and maintain the EWS Activities and Tasks Schedule (SSI #5) as outlined in
PWS paragraph 10.2.3.
10.2.5 Task Order Travel (PPWP)
This Priced Prospective Work Package (PPWP) is to support travel requested by the Government in support of the EWS mission.
10.3 Cybersecurity
10.3.1 Cybersecurity Risk Management Framework Activities—Non-Deferrable (Work
Package Level)
Note: The following skills are included in this section:
Account management and documentation
Enterprise Mission Assurance Support Service (eMASS)
Assessment and Accreditation (A&A) activities
Objective #1: The contractor shall provide full cybersecurity services and support IAW DoDI
8510.01, Risk Management Framework (RMF) for DoD Information Technology (i.e., Classified, RD, FRD, CNWDI [Classified Nuclear Weapons Design Information], and NATO Secret). The steps in the RMF are iterative, and are as follows:
1. Prepare:
a. Review, edit, and maintain the Cybersecurity Concept of Operations (CONOPS)
2. Categorize:
a. Review, edit, maintain, and test the applicability of required Confidentiality, Integrity and Availability (CIA) categorization as determined by the MDA Authorizing
Official (AO) annually
3. Select:
a. Review and apply the new Special Publication (SP) 800-53, [NIST], Revision 5
Classified eMASS overlay and tailored controls to support required caveats and/or categorization of data
4. Implement:
a. Develop, deliver, and maintain the System Security Plan (SSP)
b. Work with the Architecture and Engineering (A&E) and Operations and Maintenance
(O&M) Change Management teams to develop solutions to satisfy control language
c. Boundary protection enforcement, verification, and auditing, including all EWS
Ports, Protocols, and Services (PPS)
d. Security Technical Implementation Guide (STIG) implementation
e. Identity, user account, and privileged user management, to include training and certification compliance, enforcement, and auditing
f. Security log management and auditing
g. Protection of all MDA-identified CPI and CTs IAW DoDI 5200.39, Critical Program
Information (CPI) Identification and Protection Within Research, Development, Test, and Evaluation (RDT&E)
h. Conduct EWS specific Software Assurance (SA) tasks, to include gathering SA artifacts for the maintenance of the EWS SA Heat Map IAW required DoD, MDA, and EWS policies for software
i. Renewal, evaluation, and submittal of Removable Media Waivers (RMWs)
5. Assess:
a. Conduct annual security control audit of one-third of the controls to meet Federal
Information System Management Act (FISMA) requirements
b. Create Plans of Action and Milestones (POA&Ms) for controls that are non-compliant and not applicable
6. Authorize:
a. Build and maintain the eMASS authorization package for submission to the AO
b. Collect artifacts that support the authorization package
c. Work to resolve Authority to Operate (ATO) conditions in preparation for the next authorization decision
7. Monitor:
a. Participate in Controls Validation Tests (CVTs) that are initiated from the Security
Controls Assessor’s (SCA’s) office
b. Participate in the Command Cyber Operational Readiness Inspection (CCORI)
c. Develop memorandums to report the risk posture of EWS and its components for the
AO
d. DoD and Cybersecurity Command Task Orders (CTOs) compliance
e. IA Vulnerability Management (IAVM) prioritization and remediation
f. STIG compliance
g. Account and user auditing
h. Cybersecurity scorecard reporting
10.3.2 Cybersecurity Monitoring and Reporting Tools—Non-Deferrable (Work Package
Level)
Note: The following skills are included in this section:
RedSeal
Assured Compliance Assessment Solution (ACAS)
Endpoint Security Service (ESS)
Elastic Stack tools analysis and administration
Objective: The contractor shall provide full cybersecurity services to comply with applicable
DoD, MDA, and local security directives, policies, procedures, and instructions for physical security and for the safeguarding of MDS controlled and classified information, to include proper document marking, classification, storage, accountability, transmittal, and destruction.
Continuous monitoring and reporting and coordination with the MDA Computer
Emergency Response Team (CERT), to include IAW MDA CTO M17-017.
ePolicy Orchestrator (ePO) and Endpoint Security (ENS), to include alignment with
MDA/IC as required, IAW CTO M17-017 and Tasking Order (TASKORD) 16-0043
Fragmentary Order (FRAGO) 6.
ACAS, to include support of scanning exemptions that have valid mission impact and the validation of patching effectivity on vulnerabilities, IAW TASKORD 20-0020.
Continuous Monitoring and Risk Scoring (CMRS).
Cybersecurity terrain analytics (e.g., RedSeal).
Compliance with EWS Critical Information Reporting Requirements (CIRR) (SSI #7).
Computer Network Defense (CND), to include Incident Response (IR).
Identify, report, and respond to critical events (i.e., infractions, violations, or compromises) involving the loss of an ATO or loss of EWS data as determined by
MDA/EIR (Program Protection) (SSI #8).
Security Information and Event Management (SIEM), to include ArcSight connector alignment with the MDA CERT.
Maintain and update EWS Approved Products List (APL).
Facilitate and evaluate Data Transfer Requests (DTRs), to include examining for the presence of software that is not accounted for on the APL.
Assess change requests (i.e., Change Requests [CRQs] and Work Orders [WOs]) and customer requirements for cybersecurity alignment IAW DoD, MDA, and EWS policies.
Develop and maintain EWS Activities and Tasks Schedule. The contractor shall remain
Cybersecurity Subject Matter Experts (SMEs) for the EWS Enclave. As new requirements and tools are selected for implementation (e.g., Defense Information
Systems Agency [DISA], MDA, EWS), training shall be required.
Cybersecurity training for EWS users for reinforcement of MDA Cybersecurity policies.
10.3.3 Cybersecurity Labor (PPWP)
This PPWP is intended to provide additional labor in the area of Cybersecurity to enable the contractor to respond to increasing Government requirements beyond what was predicted in the baseline contract. It is intended for any increased labor to be added into the baseline at the next contract modification (i.e., this is not intended to be used for short-term labor requirements).
10.3.4 Cybersecurity Training (PPWP)
This PPWP is intended to provide training budget in the area of Cybersecurity to enable the contractor to get training on new technologies and maintain certifications. Examples include, but are not limited to, Elastic Observability Engineer, Data Analysis with Kibana, Information
Security (INFOSEC), and Acquired Linux Academy.
10.4 Operations and Maintenance
10.4.1 EWS Network Support—Physical
Objective: The contractor shall provide network engineering, operations, maintenance, and sustainment support for EWS, focusing on physical infrastructure, technology, and services.
Common Outcomes:
Provide all necessary network OM&S activities, focused on physical infrastructure, technology, and services, to include physical network devices (e.g., Cisco firewalls, routers, and switches) and network monitoring (e.g., Cisco Digital Network Architecture
[DNA]).
Provide all necessary network OM&S activities, to include proactive network management, configuration, monitoring, upgrading, troubleshooting, architecture development, providing subject matter expertise, and coordinating with other contracts and TOs (e.g., TO 8003), as required.
Support core hours break-fix response. Respond to degradations and failures within 2 business hours (i.e., 0700–1700 Mountain Time [MT], Monday–Friday, as outlined in the
Jacobs Accounting Periods calendar), and within 1 business day provide an estimated timeline associated with service restoral. Demonstrate minimal impact to the mission while repair activities are initiated, conducted, and completed. Incidents occurring outside of core hours shall be worked the following business day. A summary of degradations and failures, to include the response times and a root-cause analysis, shall be documented in the monthly Task Order Status Report (TOSR) (CDRL C002).
Respond to and resolve break-fix activities in a timely manner.
Perform help desk and user support.
Perform daily system status check and network monitoring on all EWS network devices.
Ensure all network devices are properly configured, are up-to-date on firmware and OS versions, and maintain cybersecurity compliance, to include boundary protection, PPS, and STIG implementation.
Coordinate all applicable EWS tasks IAW the EWS RACI Matrix.
Comply with EWS CIRR as outlined in the EWS CIRR Memorandum (SSI #7).
Coordinate with other relevant organizations, groups, and teams for the planning and execution of EWS projects.
Plan and implement technology refresh, for both hardware and software, as necessary.
Coordinate and integrate relevant aspects of EWS physical and virtual networking, as required.
Provide network engineering services, as required (e.g., CRQ review, Quality of Service
[QoS] checks, drawings).
10.4.2 EWS Network Support—Virtual (Previous OASIS Work) [RESERVED]
Objective: The contractor shall provide network engineering, operations, maintenance, and sustainment support for EWS, focusing on virtual infrastructure, technology, and services.
Common Outcomes:
Provide all necessary network OM&S activities, focused on virtual infrastructure, technology, and services, to include Virtual Desktop Infrastructure (VDI) (e.g. Citrix, Dell WYSE), network virtualization (e.g. VMWare NSX) and enterprise monitoring (e.g.
What’s Up Gold [WUG]).
Provide all necessary network OM&S activities, to include proactive network management, configuration, monitoring, upgrading, troubleshooting, architecture development, providing subject matter expertise, and coordinating with other contracts and TOs (e.g., TO 8003), as required.
Support core hours break-fix response. Respond to degradations and failures within 2 business hours (0700–1700 MT, Monday–Friday, as outlined in the Jacobs Accounting
Periods calendar), and within 1 business day provide an estimated timeline associated with service restoral. Demonstrate minimal impact to mission while repair activities are initiated, conducted, and completed. Incidents occurring outside of core hours shall be worked the following business day. A summary of degradations and failures, to include the response times and a root-cause analysis, shall be documented in the monthly TOSR
(CDRL C002).
Respond to and resolve break-fix activities in a timely manner.
Perform help desk and user support.
Perform daily system status check and network monitoring on all EWS network devices.
Ensure all network devices are properly configured, are up-to-date on firmware and OS versions, and maintain cybersecurity compliance, to include boundary protection, PPS, and STIG implementation.
Coordinate all applicable EWS tasks IAW the EWS RACI matrix.
Comply with EWS CIRR as outlined in the EWS CIRR Memorandum (SSI #7).
Coordinate with other relevant organizations, groups, and teams for the planning and execution of EWS projects.
Plan and implement technology refresh, for both hardware and software, as necessary
Coordinate and integrate relevant aspects of EWS physical and virtual networking, as required.
Provide network engineering services, as required (e.g., CRQ review, QoS checks, drawings).
10.4.3 OM&S EWS and M&S Center System Administration—Windows and Associated
Services
Objective: The contractor shall provide system administration OM&S support for EWS, focusing on Windows and associated infrastructure, technology, and services. This includes all Windows
OSs and applications, and physical user workstation/client (thick and thin/zero) deployment.
Common Outcomes:
Successful OM&S of all Windows and associated infrastructure, technology, and services.
Maintain Public Key Infrastructure (PKI) and Rivest, Shamir, and Adleman (RSA) management.
Support core hours break-fix response. Respond to degradations and failures within 2 business hours (0700–1700 MT, Monday–Friday, as outlined in the Jacobs Accounting
Periods calendar), and within 1 business day provide an estimated timeline associated with service restoral. Demonstrate minimal impact to mission while repair activities are initiated, conducted, and completed. Incidents occurring outside of core hours shall be worked the following business day. A summary of degradations and failures, to include the response times and a root-cause analysis, shall be documented in the monthly TOSR
(CDRL C002).
Respond to and resolve break-fix activities in a timely manner.
Perform help desk and user support.
Perform proactive maintenance, configuration, patching, upgrades, and troubleshooting on all relevant OSs and applications.
Prioritize vulnerability remediation.
Ensure all relevant hosts and OSs are properly configured, are up-to-date on firmware and OS versions, and maintain cybersecurity compliance, to include STIG implementation; STIG, IAVM, and CTO resolution; and SIEM integration and interoperability.
Resolve STIG, IAVM, and CTO notices to maintain cybersecurity compliance.
Core services check out and monitoring on all EWS systems.
Build, maintain, and update all relevant OS baselines and images.
Install, configure, maintain, and update all relevant and associated Customer Commercial
Off-the-Shelf (COTS) and Government Off-the-Shelf (GOTS) software.
Coordinate all applicable EWS tasks IAW the EWS RACI matrix.
Comply with EWS CIRR as outlined in the EWS CIRR Memorandum (SSI #7).
Coordinate with other relevant organizations, groups, and teams for the planning and execution of EWS projects.
Plan and implement technology refresh for both hardware and software, as necessary
Provide engineering services, as required (e.g., CRQ review, core service checks, drawings).
Perform account management, to include account requests, tracking, maintenance, review, and removal, thereby ensuring 100 percent of users have appropriate access privileges and 100 percent validity of user accounts. Document status in the monthly
TOSR (CDRL C002).
Perform account builds, set permissions, and provide account management, to include setting passwords and deleting and modifying accounts.
Deployme…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .