Attachment L-6 MIOES Evaluation Scenarios DRFP Inc2.docx

DOCX document 68 KB Posted

Attached to
MDA IT Operations & Engineering Solutions (MIOES) - CANCELED Federal contract opportunity
Solicitation number
HQ0857-MIOES-ZA
Issued by
DOD Missile Defense Agency

About this file

This document appears to be an attachment containing scenarios for the MDA IT Operations & Engineering Solutions (MIOES) contract opportunity. The scenarios cover a range of areas including cybersecurity, agile adoption, cloud adoption, enterprise monitoring, cyber incident response, digital transformation, network connectivity, real-time data delivery, efficient IT operations, end user services, engineering review board processes, event protection and facility operations. The scenarios provide detailed background information and questions for offerors to address, focusing on their approaches, methodologies, and recommendations to meet the government's requirements in these areas. This attachment is likely part of the solicitation package for the MIOES contract, which will provide IT operations and engineering support services to the Missile Defense Agency.

View the file

Other files for this federal contract opportunity

Other files attached to MDA IT Operations & Engineering Solutions (MIOES) - CANCELED, newest first.
File Type Posted
MIOES TO Phase-in Schedule (Preliminary).pptx PPTX presentation
MDA 5013.06 - Source Selection Procedures.pdf PDF
MIOES MDIOC Facility Operations and Sustainment PWS DRFP Inc3.pdf PDF
Attachment L-5 MIOES Question Matrix DRFP Inc3.xlsx XLSX spreadsheet
MIOES 1-on-1 Participant List and Topics.xlsx XLSX spreadsheet
MIOES DRFP Inc1 CONSOLIDATED QandAs.xlsx XLSX spreadsheet
MIOES Industry Day Overview and Instructions.docx DOCX document
Attachment L-3 OCI Analysis Disclosure Form DRFP Inc2.pdf PDF
MIOES LCAT Table DRFP Inc2.xlsx XLSX spreadsheet
MIOES Section M DRFP Inc2.docx DOCX document
MIOES Acquisition Strategy Summary - 14 June DRAFT RFP.pdf PDF
MIOES Industry Monthly CSSP - June.pptx PPTX presentation
MIOES Industry Monthly Chargeback Showback - May.pptx PPTX presentation
23F7300_PWS.pdf PDF
MIOES SE Overview (15 Feb 24).pptx PPTX presentation
22F8900_PWS.pdf PDF
23F3100_PWS.pdf PDF
23F8600_PWS.pdf PDF
22F8004_PWS.pdf PDF
22F8003_PWS.pdf PDF
23F4100_PWS.pdf PDF
MIOES Industry Monthly April 2024.pdf PDF
20230405-MIOES_Industry_Day_POC.xlsx XLSX spreadsheet
IRES_AttchJ-01_Encl1_HLO.docx DOCX document
20230103-MIOES_Industry_Day_POC.xlsx XLSX spreadsheet
20221110-MIOES_Industry_Day_POC.xlsx XLSX spreadsheet
Attachment J-03 - IRES Labor Category Descriptions.xlsx XLSX spreadsheet
Exhibit A - MDA Mandatory CDRLs.docx DOCX document
Exhibit B - IRES CDRLs.docx DOCX document
Attach L-06 - Client Authorization Letter.docx DOCX document
Attach L-11 - EITS SOO (A0005).docx DOCX document
Attach L-12 - FEO SOO (A0005).docx DOCX document
Attach L-16 - Cost Price WB 3 (A0003).xlsx XLSX spreadsheet
Section M (A0006).docx DOCX document
Attachment J-02 - IRES WBS and CSDR.pdf PDF
Attach L-02 - Team List.docx DOCX document
Attach L-05 - Consent Letter.docx DOCX document
Attach L-07 - PPQ (A0001).docx DOCX document
Attach L-14 - Cost Price WB 1 (A0001).xlsx XLSX spreadsheet
MIOES_Industry_Day_POC.xlsx XLSX spreadsheet
Sections A-K (A0007).pdf PDF
Attachment J-06 - PEIP.pdf PDF
Attachment J-07 - Compliance Documents List.docx DOCX document
Attach L-01 - Library Request Form v2.2.pdf PDF
Attach L-03 - OCI Disclosure Form v2.0 (Extended).pdf PDF
Attach L-04 - CDM.xlsx XLSX spreadsheet
Attach L-08 - Transition SOO (A0002).docx DOCX document
Attach L-09 - IRES TO Award-Modification Process.docx DOCX document
Attach L-13 - IRES ERI Data.xlsx XLSX spreadsheet
Attach L-15 - Cost Price WB 2 (A0001).xlsx XLSX spreadsheet
Show all 50

MDA IT Operations & Engineering Solutions (MIOES) - CANCELED has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

HQ0857-25-R-0001

Section L Scenario Attachment #TBD

MIOES

Section L Scenario Attachment #TBD

The Government will select a subset of the following scenarios for inclusion in the final RFP. The Government will down-select based on those criteria we feel will best discriminate between Offerors and feedback received from industry.

The Government is seeking feedback/comments/recommendations on each scenario.

Scenario Number
Scenario Title
1
Cybersecurity
2
Agile Adoption
3
Cloud Adoption
4
Missile Defense Space Enterprise Architecture (MDSEA)
5
Enterprise Monitoring
6
CERT Response
7
Digital Transformation
8
Network Connectivity
9
Delivery of Real-Time Data
10
Efficient Information Systems Operations
11
End User Services
12
Engineering Review Board
13
Event Protection, Monitoring and Reporting
14
MDIOC Facility Operations

Scenario 1: Cybersecurity

The National Institute of Standards and Technology (NIST) is a non-regulatory bureau of the U.S. Department of Commerce responsible for developing information security standards and guidelines, including minimum requirements for federal systems (except national security systems unless otherwise approved by appropriate federal officials exercising policy authority over such systems).

The Federal Information Security Modernization Act (FISMA) publications are developed by NIST in accordance with its statutory responsibilities under the Federal Information Security Modernization Act (FISMA) of 2014, 44 U.S.C. § 3551 et seq., Public Law (P.L.) 113-283.

The requirements in FIPS 200 are the minimum for federal information and information systems (i.e., enterprise information technology). These requirements are not intended to keep the highest tier adversaries from impacting our national security systems. In fact, Risk Management Framework (RMF) explicitly excludes national security systems. Committee on National Security Systems Instruction (CNSSI) 1253 modifies the Federal Information Processing Standard (FIPS) 199 categorization, uses the NIST Special Publication (SP) 800-53 controls, creates overlays of those controls, and authorizes the use of RMF for national security systems.

The RMF developed by NIST effectively brings together all of the FISMA-related security standards and guidance to promote the development of comprehensive and balanced information security programs by agencies. The RMF set of controls from NIST 800-53 includes non-cybersecurity controls like physical security, supply chain risk management (SCRM), etc. Therefore, organizing the security disciplines under a single branch enables synergy in support of RMF.

All information systems within MDA must meet and maintain compliance requirements IAW regulations such as Federal Information Security Modernization Act (FISMA), the NIST RMF, and NIST Special Publications 800 series guidance to protect controlled unclassified information (CUI), personal identifiable information (PII) and classified information. Key requirements include providing skilled cybersecurity personnel certified according to DoD 8570.01-M and 8140.03, ensuring all systems meet Security Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) compliance, and delivering documentation such as system diagrams, hardware/software lists, concept of operations (CONOPS), and security control implementation plans with the ultimate goal of obtaining an Authorization to Operate (ATO). The contractor will assist MDA in meeting and maintaining cybersecurity standards for information technology (IT) and operational technology (OT) systems and services.

Assumptions:

The Contractor should take into consideration all existing authorities and policies of the Director of National Intelligence regarding the protection of sensitive compartmented information (SCI), as directed by Executive Order 12333 and other laws and regulations.

The Contractor shall satisfy the RMF requirements of subchapter III of chapter 35 of Title 44, United States Code (U.S.C.), also known as the “Federal Information Security Management Act (FISMA) of 2002”

The Contractor should enable MDA to meet the standards required by the Office of Management and Budget (OMB) and the Secretary of Commerce, pursuant to FISMA and section 11331 of Title 40, U.S.C. FIPS 199 / CNSSI 1253 Security Categorization. The Contractor shall participate in categorization discussions with the program managers (PMs), functional leads, and the Information System Security Manager (ISSM) and provide all required FIPS 199 documentation as requested to support security categorization.

Cybersecurity Assurance will be achieved through abiding by all applicable cybersecurity policies, regulations, and directives to ensure a favorable Assessment and Authorization (A&A) decision(s). This includes recommending system categorization based on sound technical expertise, then document the results. The Contractor shall mitigate risk identified through the RMF authorization process down to a level acceptable to the Authorizing Official (AO).

The Contractor will be expected to protect unclassified DoD data from unauthorized access or disclosure in accordance with DoDI 8582.01, “Security of Unclassified Information on Non-DoD Information Systems.” CUI: All Government CUI obtained by the Contractor shall be protected in accordance with NIST SP 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations”. The Contractor shall protect classified DoD data from unauthorized access or disclosure in accordance with Department of Defense Manual (DODM) 5200.01, “DoD Information Security Program: Overview, Classification, and Declassification”.

1. Introduction MDA’s diverse missions are supported by a complex, heterogeneous, geographically dispersed IT and network environment. This includes a combination of scalable, flexible, virtualized infrastructure and physical hardware, providing data transport, storage, processing and cybersecurity services to support Research, Development, Test & Evaluation (RDT&E) and operational Enterprise missions. Some environments have the elasticity to scale with demand, adapt to emerging requirements, and provide architectural commonality across future experimental and operational Tier III environments in support of MDA activities. Additionally, the MDA allows connections to other MDA authorized systems as well as external connections to non-MDA systems. The Agency hosts legacy and future R&D Missile Defense System capabilities and future operational systems. This information is used by numerous stakeholders for IT portfolio and cybersecurity management activities, such as project management, vulnerability management, software license management, compliance tracking, etc. The MDA seeks to improve cybersecurity resiliency with zero trust and incorporate digital transformation. This contract will be responsible for developing and maintaining the authorization strategy, of all MDA Enterprise Support Systems including RDT&E and business information systems in support of initial ATOs and ongoing authorizations. To ensure system Confidentiality, Integrity and Availability, the MDA supports multi-level system categorization compliance in accordance with applicable cybersecurity mandates to include real-time Tier III monitoring and reporting in alignment with MDA Tier II.

SCENARIO 1a (Current Environments):

MDA’s current IT portfolio includes approximately 85 unique information systems with thousands of assets that span more than 160 geographically separated locations, which all must obtain and maintain a moderate to low-risk authorizations.

1. Give a detailed example on your approach to operate and sustain the environments in the most cost-effective ready state to include how to assess, capture and track the current systems and assets. How would you mitigate cybersecurity vulnerabilities with a cost effective, innovative strategy to improve the risk posture to key stakeholders?

2. Describe your methodology to continually review processes and policies; systems modifications; critical components; and essential upgrades to improve system function, interoperability, and automate near real-time reporting of the risk posture to enable the government to make informed decisions throughout the life cycle.

3. Describe your approach and success rate for both recruiting and retaining Cybersecurity and IT Cyberspace skills required to maintain a cyber-resilient program.

SCENARIO 1b (Enhancement):

The development and sustainment of complete and accurate representation of the environment to support the system authorization in a timely manner is of the upmost importance to the Agency. The customer has requested some enhancement and new capabilities. You must ensure the Government has enough information to make a risk-based decision before deploying into the environment for customer consumption.

1. What constitutes a security relevant change? Describe how you ensure cybersecurity is integrated and validated throughout the development. Explain your approach to assess the change, identify cyber requirements, and present the risk to the government?

2. How would you decompose and accurately document the changes in the authorization boundary? How do capture, track and manage any unmitigated risk?

3. What methods would you use to ensure Computer Network Defense (CND) services are aligned and the changes are postured to maintain cyber resiliency throughout the life cycle IAW the Cybersecurity Service Provider (CSSP) - Service-level Agreement (SLA)?

SCENARIO 1c (New Environment):

Your team is responsible for designing, developing, implementing, integrating and operating a solution that leverages new technology including a new assess and authorization package.

1. Describe how to derive customer expectations and structure the cybersecurity requirements to develop & deliver an innovated solution. Identify key policies and define in detail what constitutes a compliant cyber program and incorporate best practices.

2. Give a detailed example on how you integrated an effective cybersecurity program throughout the development lifecycle. Articulate the approach taken, the artifacts required, and key indictors to obtain a moderate to low-risk Authority-to-Operate with alignment to local Computer Network Defense (CND) standardized services. What is your continuous monitoring strategy to ensure the system/environment maintains compliance throughout the lifecycle? What innovative processes would you use to keep key stakeholders informed and engaged with the system management?

3. Describe your approach to assess, track, and manage all assets including supply chain risk management reviews and vendor dependencies to meet organizational design standards, policies, and authorized approaches to maintain compliance throughout the lifecycle. What automated reporting would you use to enable the Government to continuously view and track the lifecycle of “All” IT assets?

Scenario 2: Agile Adoption

Background: MDA’s office of the Chief Information Officer (CIO) has a desire to transform from using Waterfall to using more Agile processes for developing, implementing and sustaining IT solutions. The goal is to deliver value to our customers incrementally at a faster pace than that of traditional waterfall delivery times. Explain the approach your organization would take to transition away from a mostly Waterfall to a mostly Agile project management environment. As part of the approach, provide discussion that:

1. Demonstrates a thorough understanding of the Agile transition methods and culture required to cultivate such transitions.

2. Identifies the skills and level of effort required to thoroughly address how projects get identified as being a good candidate for Agile or conversely, how projects would not be a good candidate for Agile project management.

3. Identifies how projects are scrutinized to determine the best Agile methodology to use. (e.g., Project A needs to use SAFe, and Project B should use KANBAN)

4. Address what level of support will be needed from MDA’s office of the CIO to assist and maintain an Agile project management environment.

5. Identifies common challenges when transitioning an organization from Waterfall to Agile project management and ways to overcome those.

6. Identifies what capabilities, certifications and training that may be useful to support this transition.

7. Identifies preferred contract types that best support an Agile environment.

8. Presents proven technical efficiencies, innovative strategies, and Agile frameworks.

9. Currently when a project is being executed, a lot of the team members may be working on multiple projects. Include in your discussion how your organization would approach the staffing management to foster an Agile working environment while also balancing funding and workload demand.

Scenario 3: Cloud Adoption

Background: MDA has a large and federated portfolio of legacy systems and applications that are using on premise hardware and have different organizational owners. MDA, much like the broader DoD, is moving toward a cloud-first approach to gain the benefits cloud offers. While MDA is far on its journey toward cloud adoption, the transition poses challenges that prevent maximum cloud usage and slows the rate of adoption. Some examples include federated ownership (non-CIO owned IT infrastructure), poor metrics to calculate return on investment, changes in organizational cost sharing, managing bandwidth and communications reliability between cloud and on premise. Describe your approach to maximize the adoption of cloud by a federated government agency while covering the following in your response:

1. How can automation be leveraged for migration and sustainment of cloud workloads and describe measurable benefits?

2. Describe controls that could be put in place to track, manage and report accurate cost information and trends to the customer?

3. Describe the selection criteria to determine the best commercial cloud vendor for a particular workload?

4. What types of services are best to stay on premise and why?

5. What is your approach to multi-cloud?

6. What should be done about legacy processes that inhibited rapid adoption, modification and management of cloud workloads? How should governance processes be tailored to enable rapid adoption, modification and management of cloud workloads while still maintaining oversight?

7. What characteristics of cloud provide the largest benefit to a program element’s mission success?

Scenario 4: Missile Defense Space Enterprise Architecture (MDSEA) Background: The Missile Defense Space Enterprise Architecture (MDSEA) provides the MDA, Space Systems (MDA/SS) directorate with Space Enterprise Architecture(s) and Satellite Operations Center(s) required for current and future Research and Development (R&D) and Space Operations activities. The MDSEA hosts legacy and future R&D Ballistic Missile Defense System (BMDS) space capabilities and future operational systems. The MDSEA will eventually replace the legacy Missile Defense Space Center (MDSC) Core architecture with up-to-date technology.

The MDSEA is a combination of scalable, flexible, virtualized infrastructure and physical hardware, providing data transport, storage, processing, and cybersecurity services to support the MDA Space Systems' RDT&E and operational missions. The MDSEA environment has the elasticity to scale with demand, adapt to emerging requirements, and provide architectural commonality across future experimental and operational Tier III environments in support of MDA space activities. The MDSEA allows connections to other MDA authorized systems as well as external connections to non-MDA systems. To ensure system Confidentiality, Integrity and Availability, the MDSEA supports multi-level system categorization compliance in accordance with applicable cybersecurity mandates to include real-time Tier III monitoring and reporting in alignment with MDA Cyber Security Service Provider/Computer Emergency Response Team (CSSP/CERT).

Assumptions:

a. MDSEA shall have the capability to support a space sensor data volume of 60 TB / day from all data sources.

b. Space sensor data retention requirements range from 1-year minimum for all data, 3 - 6 years for data that can support cybersecurity incident investigations, to 7 years for a limited amount of authentication records.

c. MDSEA shall have the capability to support management of space sensor data from minimum of two (2) endpoints on MDA Space Sensor networks.

d. Cloud services are utilized for both as secure space data sources and as potential components of the overall solution(s).

e. Space sensor data from existing space sensor data sources in the MDA environment, (e.g., logs, cybersecurity tools, hardware and software inventory tools, etc.), need to be integrated into the solution(s).

f. The concept(s) for updating developing, integrating, operating, maintaining, and sustaining the system must support extendibility and integration of new space sensor data sources from new space sensor systems.

Expected MDSEA Requirements:

a. MDSEA Mission Capability Upgrades (Planning and Design): Provide engineering expertise and capabilities to maintain mission systems across the MDSC facility. Contractor shall work with the MDSC staff to prioritize the execution of maintenance activities. Upon identification of the need for a system upgrade, the contractor shall establish the statement of need; coordinate data elements; develop a schedule and integrate it into the IMS; establish stakeholder requirements; develop detailed designs; and define capabilities.

b. MDSEA Mission Capability Upgrades (Discrete Implementation(s)): Develop schedule(s) and integrate it/them into the Integrated Master Schedule (IMS), for implementing solutions, upgrades, enhancements, and reconfigurations to complete planning, design, procurement, implementation, documentation, and CM activities. The contractor shall perform network and software design, perform development and testing, establish connectivity, develop lessons learned, document operating procedures, and update architecture drawings.

c. Additional Site Activation(s): Support the implementation of an additional site to support development, testing, and remote administration of the MDSEA RDT&E enclave. This enclave is supported with MDA Unclassified Local Area Network (ULAN) and Classified Local Area Network (CLAN) connections via existing long-haul communications networks. Added sites shall have the capability to remotely access the system status as well as function for all MDSEA RDT&E environments, and support Interface Exchange Service (IES) development and MDSEA internal testing efforts. Implementation tasks to be performed include the following:

· Procurement

· Facility modifications

· Equipment installation

· Testing

· eMASS updates

· Virtual Desktop Infrastructure (VDI) capability to support hosted missions will be IAW the Government-approved design

d. Reduce MDA/SS’s Information Technology (IT) Burden by Leveraging MDA Enterprise Services (Certified Network Defender (CND) Services):

· Vulnerability Scanning

· System Patching

· Host-Based Security System (HBSS)

· Security Logging

· Domain Controllers

· Identity Management Services

· Timing Services

· System Backup and Restoral Services

Questions:

1. What would be your team’s approach(s) be to design, develop, implement, integrate, and operate the solution(s) of future MDSEA in the MDA environment(s)?

2. How would your team develop, design, and integrate a data solution(s) for storage and distribution of Space Sensor data coming from Ground Entry Points (GEPs)?

3. What cost-effective recommendations (technical, product, process, etc.) would your team make to meet MDA’s Missile Defense Space Enterprise Architecture needs in a-d above?

4. Not all Space Sensor data needs to go to every functional stakeholder of a Space Sensor. Data Analysts are interested in the sensor images. Satellite Operators are interested in the space sensor Time, Telemetry, and Communication (TT&C) data. How would your team organize and deliver relevant space sensor data to different audiences (Data Analysts and Operators, etc.) so they receive the satellite and sensor data that is relevant to them?

5. How would your team develop and present MDSEA program (non-Cybersecurity) risk scorecards? What metrics would your team consider as contributors to comprehensive risk scores?

Scenario 5: Enterprise Monitoring Background: The CIO provides a large portfolio of services to the MDA Enterprise. These services are delivered using thousands of servers (virtual and physical), multiple networks and network devices, multiple operating systems and consists of Open Source, Government and Commercial Off the Shelf (COTS) software. Due to this complexity, monitoring the status of services can be challenging. Often users report when there are service interruptions prior to when the monitoring capability can. This can be due to monitoring not being configured correctly with the rights thresholds, the correct things not being monitored, or the understanding of what servers, applications, etc. are involved in the delivery of services.

Questions:

1. What would be your approach to effectively monitor a large portfolio of services in a highly complex environment?

2. How would you effectively map servers to applications to services?

3. How would you identify Service interdependencies?

4. How would you identify potential service interruptions before they happen?

5. What would your process be to identify root cause?

6. How and when would you communicate service interruptions to the MDA community?

7. What would you monitor, how and why?

Scenario 6: Cyber Attack Response Background: The MDA unclassified business network is experiencing a sophisticated cyber-attack. The Security Operations Center (SOC) has identified multiple indications of compromise to include:

· Aggressive scanning of internal networks from multiple user workstations on the MDA domain

· The endpoint security solution on multiple user workstations has reported the creation of new local administrator accounts

· Alerts from the boundary protection stack of multiple connections from MDA-owned devices to foreign IP ranges where the MDA has no presence

The unclassified business network continues to operate as expected for most users however the help desk is experiencing an increased call volume with users reporting slow or unresponsive workstations.

Questions:

Based on the scenario above, describe how your team would respond. Address each of the following, using one to two paragraphs each.

1. Determine the incident category in accordance with CJCSM 6510.01B and develop a draft report with recommendations on which parties internal and external to the MDA should be notified of the incident.

2. What immediate actions would you recommend to mitigate the ongoing incident?

3. What approach would you use to eradicate malware and prevent spread or reinfection?

4. If the incident is discovered to be more widespread across the Agency, describe how you would provide surge support to investigate/mitigate the incident.

5. Describe how you would collect and develop lessons learned and then use this information to make recommendations to the MDA.

Scenario 7: Digital Transformation Background: The Missile Defense Agency is made up of several “2-letter” organizations that have specific programs to execute with associated funding from Congress. Some organizations have started to adopt digital transformation technologies and practices to support program execution. Unfortunately, other organizations within MDA continue to use legacy processes and technology. For example, spreadsheets are used to manage Program Objective Memorandum (POM) submissions, technology roadmap planning, requirements management, and cost modeling for chargeback/showback. Email is used as a workflow engine to request and approve funding to execute requirements. Static drawings are used to represent network and system topologies, business processes, and workflows.

As the Agency adopts digital transformation and the associated technologies and practices such as model based systems engineering, zero trust, digital acquisition, artificial intelligence, and machine learning, it is imperative that there is broad Agency adoption of these transformational technologies and practices.

Considering the information provided in the background, what approach would you recommend the Agency take to effectively execute a digital transformation? Please include answers to the following questions in your response.

1. How would you assess a large organization such as the MDA on its readiness for digital transformation?

2. What are the most common challenges of a digital transformation and how are they overcome?

3. What would be your approach to bring together multiple semi-independent siloed organizations into an Enterprise digital transformation adoption strategy?

4. What digital capabilities would you recommend the Agency invest in to support a digital transformation and why?

5. What skills and talent are needed to support digital transformation and how would you recommend the Agency develop the skills and talent needed across the civilian and contractor workforce?

6. How would you recommend we measure if our digital transformation strategy is effective?

7. Have you assisted other organizations with their digital transformation? If so, what frameworks were used and why?

Scenario 8: Network Connectivity

Background: Multiple MDA customers, as well as, industry partners will often require Unclassified and/or Classified MDA Network connectivity that includes planning for and the execution of remotes sites for events such as; flight tests, ground tests, cyber tests, war games and exercises. Establishing and maintaining this connectivity is a critical component to ensuring stakeholders have the ability to collaborate during requirements, planning and integration, execution and analysis phases for various test and event exercises. It is important to understand, most MDA sites are not designed exactly the same and may require customized solutions.

Questions:

1. When preparing to establish remote services in support of an event, describe your execution methodology from initial requirements gathering to site close out?

2. How would you control and track execution costs to ensure cost overruns and schedule delays are avoided.

Scenario 9: Delivery of Real-Time Data

Background: Given the broad range of MDA enterprise service offerings (lines of service) within the CIO portfolio which includes projects that may vary from the simple to the most complex, the office of the CIO desires a Management Information System (MIS) that will provide the Agency leadership team within the office of the CIO an organized and current view of information that is needed to support decision making regarding the entire CIO portfolio.

In addition to services offerings, this system(s) and procedures would need to gather data from a range of data sources (financial, project, asset life cycle, procurement, customer billing etc.) compile it and present it in a readable format. The output would need to be in real time information readily available for make decisions ranging from daily to top-level strategy.

Questions:

1. How would you deliver this capability?

2. Describe your approach for creating cost models and deliver timeframes for services offerings.

3. Describe your approach for adding new service offerings to the catalog quickly.

4. Describe how you would automate the output of this system.

Scenario 10: Efficient Information Systems Operations

Background: MDA’s IT and communications infrastructure is located around the globe (6 principal and 160 remote sites), is valued at approximately $250M and must remain available 24x7 while keeping in compliance with; Federal, DoD, Agency and Local acquisition policy and regulatory requirements.

As the prime contract for MDA enterprise service offerings, MIOES will deploy innovative solutions to meet the general user and warfighter capability requirements within a budget constraint environment.

Consideration must be given to today’s rising cost of equipment, labor and software.

Questions:

1. Describe a methodology that could be adopted to assess the acquisition and sustained operations of information systems to include life cycle management of all IT components, custom developed software, vendor dependent devices, supply chain of hardware and software, industrial control systems, and outdated or legacy systems. Identify best practices and strategies that enable efficiencies in the acquisition cost and sustainment of information systems operations.

2. What methodologies/processes could be incorporated to track, monitor and report project life cycle management from cradle to grave through its transition to operations and sustainment?

3. What methodologies/processes could be incorporated into Service Level Agreements that would ensure accurate tracking, monitoring and reporting for both the Government and Government customers?

Scenario 11: End User Services

1. What process and or methodology would you implement as an automated solution to evaluate the data/metrics, perform trend analysis, and continuously evaluate data, taking actions as necessary? What data and metrics would you continuously monitor to identify trends and take action to reduce impact to customers? Explain in detail the methods used to provide this service including near-real time identification, analysis and reporting. Must contain EoL/EoS info, etc.

2. Incident management is a process used by IT operations and DevOps teams to respond to and address unplanned events and or degradation that can affect service quality or service operations. Resolution of incidents frequently require the performance of Tier I troubleshooting to determine if the issue is within MDA’s scope prior to contacting the external service provider as needed. How would you determine if the problem was within MDA’s scope or if external assistance and resolution as required? How would you identify persistent issues, engage stakeholders to formulate a plan to prevent the recurring issues?

3. A trouble ticket provides the agency IT service desk team with contextual information on the support request, along with other identifiers such as status, priority, and ticket category. These ticket parameters help the MDA IT service desk manage their ticket queue better. MDA is experiencing issues with minimizing backlog in a timely manner, inaccurate and nonstandard contextual information. What process and or methodology would you provide as a solution that performs data normalization while enhancing and optimizing the current process, focuses on customer experience, and is cost effective?

4. In MDA’s current environment, users report their current issues to the service desk and the service desk responds by answering a call and creating a ticket or reading an email received and converting it into a ticket. No self-service option(s) are available that removes the human interactions from the scenario. What approach would you take to minimize customer service labor yet improve customer experience?

5. Currently, MDA’s Configuration Management is a process that is totally dependent on human interaction and manual input. This human interaction and manual input has caused MDA’s configuration management database to contain inconsistencies throughout the equipment lifecycle. What process or methodology would you implement to normalize the management of IT asset information and provide consistent, accurate data (data quality and data consistence) to include current configuration.

6. MDA requires the ability to track IT assets to include automated reporting allowing the government visibility and accountability of all IT assets. Describe your approach to assess, track, and manage all assets including supply chain risk management reviews and vendor dependencies to meet organizational design standards, policies, and authorized approaches to maintain compliance throughout the lifecycle. What automated solution would you use to enable the Government to view and track the lifecycle of all CIO-managed IT assets near real time?

Scenario 12: Engineering Review Board Background: The Missile Defense Integration and Operations Center (MDIOC) Engineering Review Board (ERB) is the forum for review of projects modifying the MDIOC facility. The MDIOC ERB provides reviews to ensure requirements are validated, align with facility standards, and solutions are integrated across the MDIOC facility. The ERB’s intent is to improve project cost/schedule/performance for tenants while enforcing MDIOC standards and ensuring facility configuration management (CM). We manage CM via the MDIOC Facility Technical Baseline. The MDIOC Facility Technical Baseline consists of three supporting baselines: requirements, architectural, and engineering. Sound CM is paramount to ensuring the accuracy of the MDIOC Facility Technical Baseline. The ERB is used to ensure MDIOC Facility Technical Baseline management. Establishing and maintaining a MDIOC Facility Technical Baseline and ensuring effective CM in a dynamic environment is a very difficult challenge and requires a concerted effort.

Scenario: An MDA 2-letter desires to reconfigure a portion of the Research Facility (building 720). This reconfiguration requires both facility (physical infrastructure) and IT (network connectivity and individual workstations) support.

Assumptions:

1. The facility control activities of the MDIOC ERB do not duplicate or fall within the scope of MDA Directive 5000.05 Single Technical Authority, MDA Instruction 5000.20 Engineering Technical Review Process, and the MDA Systems Engineering Plan because the facility work covered by the MDIOC ERB process does not change or control any Element or Component of the Missile Defense System as defined in those three documents.

2. MDA programs, non-MDA Government organizations, and contractors performing work affecting MDIOC architecture, systems, facilities baseline, or space utilization must be approved by the MDIOC ERB.

3. The MDIOC ERB serves as a single pathway for anyone within the facility to complete a project and combines requirements for Information Technology (IT), facilities infrastructure, and systems engineering (e.g., governance).

4. This project will induce changes to the MDIOC Facility Technical Baseline.

5. Multiple MDA 2-letters, with a variety of supporting contracts, are responsible for maintaining a portion of the MDIOC Technical Baseline. They update/maintain various authoritative data sources which are part of the technical baseline.

6. The MDIOC Technical Baseline exists as both physical and digital artifacts.

7. The MDIOC Technical Baseline exists in authoritative data sources that may not be integrated or digitally aligned.

8. The 2-letter requesting this project utilizes a technical contractor that is not on MIOES, but MIOES will have to interact with that technical contractor during the ERB process (e.g., requirements generation, updating their authoritative data sources).

9. The portion of the Research Facility (building 720) that is being modified adjoins other workspaces that are not managed by this 2-letter and shares facility infrastructure resources (e.g., walls, HVAC, and electrical power) with these neighboring workspaces.

Questions:

1. Describe your approach to administering the MDIOC ERB to ensure the project meets facility standards (both IT and infrastructure), ensures the accurate capture of customer requirements, validates these requirements are met, verifies an integrated solution is implemented, and ensures any changes to the MDIOC are accurately captured in the MDIOC Facility Technical Baseline.

2. Considering the systems engineering “V,” what activities/milestones are appropriate to effectively manage the ERB process?

3. List any existing governance, industry tools, or industry standards you recommend be considered for this scenario.

4. What metrics would you develop to monitor the success (cost/schedule/performance) of the ERB in overseeing this effort over time?

5. Define what functional stakeholders within the facility should be responsible for which aspects of MDIOC facility technical baseline management, and why.

6. Describe your approach for establishing and maintaining authoritative data sources.

7. Describe your approach to transitioning from a document based technical baseline to a model based technical baseline.

8. How do you ensure MDIOC Technical Baseline management activities are effective?

Scenario 13: Event Protection, Monitoring and Reporting Background: The MDIOC can be considered both an operations facility and a test range. Concurrent Missile Defense System operations and test events occur on a daily basis. There are multiple 24/7/365 operations centers and during major flight tests, hundreds of MDA employees relocate to the MDIOC to support flight test preparation and execution.

Assumptions

1. Missile Defense System operations take precedence over all other activities.

2. The MDIOC Government team cannot influence similar event protection measures at other locations. Do not expand this scenario beyond the confines of the MDIOC with the exception of MDA owned network resources.

3. The MDIOC facility is 35+ years old. Ongoing preventative and corrective “break-fix” maintenance activities will occur during all or a majority of the operations/test periods.

4. Non-MDA stakeholders (combatant commands) are present in the MDIOC, and support Missile Defense System operations and test.

5. The major flight test requires its MDIOC resources protected for 45 continuous calendar days.

Scenario: Describe your approach to ensuring the ongoing protection of operational assets within the facility while also protecting the resources necessary to conduct a major flight test also being concurrently executed from the facility. In describing your approach, include answers to the following:

Questions:

1. Describe what functional stakeholders within the facility should be responsible for which aspects of this effort, and why.

2. What periodic activities (e.g., daily/weekly/monthly) are recommended for effective event management, monitoring and reporting?

3. Describe a process to ensure the situational awareness of MDIOC stakeholders in all potential impacting activities. How is pertinent information on planned/ongoing operations, test, and maintenance (to include potentially impacting base activities) collected, integrated, and shared across the facility.

4. The adjudication of work during an event protection period has historically been a manual process; leveraging the knowledge of subject matter experts to make decisions on whether proposed work can proceed based on risk. How would you adopt automation, artificial intelligence, or machine learning across multiple baselines (facilities, event, IT) to objectively and efficiently evaluate the risk of proposed work as it relates to event execution.

5. Two high priority flight test events are underway at the facility. In order to facilitate a Government decision, what criteria would you develop to priority rank them?

6. When reviewing proposed work to ensure it does not conflict with ongoing activities, describe your approach to the review/approval process? What functional stakeholder do you recommend that should ultimately approve proposed work?

7. Assuming a process escape occurs that could disrupt an ongoing event, how would you conduct the root cause investigation, adjudication, and reporting?

8. List any existing governance, industry tools, or industry standards you recommend be considered for this scenario.

Scenario 14: MDIOC Facility Operations

Background: A program in the MDIOC is converting a space, of approximately 5,000 square feet, from storage to an Operations Center. This area will be filled with personnel working in cubicles, with each work station having an unclassified computer, a classified computer, and four monitors. Additionally, one wall of the Operations Center will be used as a video wall.

With the new Operations Center, the capacity of the Uninterrupted Power Supply (UPS) will need to be increased to support all of the equipment in the new Operations Center. Therefore, an additional breakers section as well as breakers will need to be installed in the UPS, and power will need to be ran to the new Operations Center. The UPS has an A and B side, and each side will need to be shut down completely in order to safely install the new breaker sections and breakers. The UPS has not been shut down completely since being installed ten years ago.

For the past five years all computer systems, servers, and other electronic equipment in the facility have been installed with either power from the A and the B side of the UPS, or with an Automatic Transfer Switch that has the ability to provide power from either A or B. Unfortunately, the legacy equipment that was installed greater than five years ago, might only receive power from A or B, but there is no documentation to determine the configuration of this equipment which constitutes approximately 75% of the facility.

During the design portion of the project, it was determined that the air handling unit (AHU), currently providing tempered air to the storage space, would not be able to handle the anticipated heat load once converted to an Operations Center. Therefore, a new AHU is being installed along with new supply and return duct work. Due to limited options, the routing of the duct work will have to pass through several rooms, which are currently occupied by various programs, above the drop ceiling, before it reaches the new Operations Center. One of these rooms is an operational sensitive compartmented information facility (SCIF). The existing duct work coming from the current AHU will be demolished.

Assumptions

1. In order for personnel to operate within the MDIOC, they must either have a security clearance and a restricted area badge, or be accompanied by a cleared escort.

2. As the facility project implementation contractor, you will be responsible for providing either badged employees to execute the work, or provide the badged personnel to escort your workers.

3. The MDIOC does not utilized the Schriever SFB Department of Public Works for any maintenance purposes within the facility.

4. Scheduled and unscheduled maintenance will be performed by the MIOES contractor’s Facilities Operations and Maintenance task order.

5. Facility Projects will be executed by the MIOES contractor’s Infrastructure Support Project task order.

6. The MDIOC is over 30 years old with assets that are original to the facility, many of which are past end of life. Ongoing preventative and corrective maintenance activities will occur on a 24x7 basis.

7. Many portions of the Research Facility (building 720) adjoin other workspaces that are managed by different 2-letters, yet they still share facility infrastructure resources (e.g., walls, HVAC, and electrical power).

8. Significant coordination with Mission Assurance/Systems Engineers is required prior to shutting off any type of equipment such as AHUs, computer room air conditioning (CRAC), electrical switch gear, etc. Most outage lead times take up to five weeks or more for planning and coordination.

Questions:

1. From the initial design, through implementation, and closeout of this project, how would you integrate the Infrastructure Support Projects task order, the Facility Operations and Maintenance task order, and with Cybersecurity?

2. What maintenance opportunities, if any, are presented during facility projects such as this? How would you maximize these opportunities?

3. Describe your approach to corrective maintenance, in a facility as complex as the MDIOC.

4. Explain your approach to executing the requirements of the project. Do you intend on operating as a General Contractor? How much, if any, of the work do you intend on self-performing? Will you compete the work of your subcontractors or use preferred companies? What is your approach to the procurement of large pieces of equipment such as the AHU or breaker sections and breakers?

5. What recommendations would you make to meet all of the project requirements, while also minimizing the cost and schedule impacts?

6. Explain the project management methodologies that you use, and why you execute project management in this way? What successes, issues, and challenges have you seen with this approach to managing facility projects?

7. Who are the key stakeholders, and what is your coordination plan with them?

8. How would you communicate issues, setbacks, and outages with all the stakeholders? What mitigation strategies would you implement to ensure this project has a minimal impact on all those effected?

9. List any existing governance or industry standards you recommend be considered for this scenario.

10. Describe how you would collect and develop lessons learned from this project, and all others moving forward, then use this data to make recommendations to the MDA.

File details come from the government source that posted it. Updated .