Draft PWS EITS Support Services - Dec 2022.pdf
PDF 601 KB Posted
- Attached to
- Synopsis/Special Notice for Sole Source award for Enterprise Information Technology Services (EITS) Support Services Federal contract opportunity
- Solicitation number
- HT001123R0011
- Issued by
- Defense Health Agency
About this file
This is a special notice for a sole source award of a bridge contract for Enterprise Information Technology Services (EITS) Support Services. The Defense Health Agency intends to award a firm-fixed price, six-month base contract with one six-month option period to Zygos Consulting LLC. The contractor will provide acquisition advisory support such as consulting with clients to define needs, developing acquisition strategies and concepts, and providing strategic advice and recommendations. The period of performance is through December 2023. The place of performance is Falls Church, Virginia. This is designated as a small business set-aside. While the notice states any responsible sources may submit a proposal, it indicates the agency's intent to award sole source to the named incumbent.
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DHA PWS Template V11 March 1, 2021
Department of Defense Defense Health Agency
Performance Work Statement
Enterprise Information Technology Services (EITS) Support Services
Deputy Assistant Director of Information Operations/J-6
(DAD IO/J-6)
Portfolio and Resource Management Division (PRMD)
Contract Number: HT0011-21-F-0027
Version:
Date: 15 Dec 2022
March 1, 2021
PART 1
1.0 GENERAL INFORMATION
1.1 This is a non-personal services contract to provide non-personal services to provide Enterprise Information Technology Services (EITS) Support Services to support the Assistant Director Healthcare Administration (AD HCA), Deputy Assistant Director of Information Operations/J-6 (DAD IO/J-6) mission. This performance work statement (PWS) identifies the specific scope and deliverables for these services for the specified period of performance.
1.2 Description of services/introduction: The contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform EITS Support Services as defined in this Performance Work Statement (PWS) except for those items specified as government furnished property and services. The contractor shall perform to the standards in this PWS.
1.3 Background: The DHA operates under the policy guidance and directorate of the Office of the Assistant Secretary of Defense (OASD) Health Affairs (HA). The Deputy Assistant Director Information Operations (DAD IO)/J-6 Directorate Chief Information Officer (CIO) is a principal advisor to the ASD HA, the Principal Deputy Assistant Secretary of Defense (PDASD) HA, and the DHA Director on all matters pertaining to Military Health System (MHS) Information Technology (IT), to include strategic planning; IT capital planning and investment processes;
linking performance measures to MHS and DHA priorities and goals; emerging IT, data standardization, cyber security; establishing appropriate external coalitions and communications related to IT; consolidation mandates of Section 702 of the National Defense Authorization Act (NDAA) of 2017, as amended by Section 711 of the Fiscal Year (FY) 2019 NDAA, Clinger- Cohen Act, Federal IT Acquisition Reform Act (FITARA) compliance, and guiding the IT integration and standardization across the MHS. The DAD IO/J-6 is responsible for the organization and management of the directorate to accomplish its mission effectively and economically.
This contract will support all of DHA DAD IO/ J-6 efforts across the MHS and be managed by the Information Technology Business Strategy and Rationalization (ITBSR) Branch of PRMD.
This branch is responsible for:
• Realizing the MHS Enterprise Information Technology Services (EITS) Program Management Office (PMO) objectives by establishing the EITS Integrator, Capability Service Provider (CSP), the Geographic Service Provider (GSP) procurements
• Providing guidance and direction to staff across the entire MHS to accomplish Information Technology implementation at all Military Treatment Facilities (MTF's)
• Providing management, supervision, technical direction and coordination of acquisition actions, reporting, and analytical activities
• Reviews and recommends acquisition policies related to J6 for DAD IO/J6 approval
• Coordinates acquisition activities for the DAD IO/J6 program offices and divisions
• Liaison acquisition activities with external/internal entities for DAD IO/J6
March 1, 2021
• Craft acquisition policies related to J6 for DAD IO/J6 approval
• Managing Procurement System Administration o Procurement Liaison o Status of Acquisition and Completed Procurement Packages o Review and Report on J6 Contracts
• Processing and tracking payments o Review and report on invoice payments
• Overseeing Contract Administration o Contracting Officer Representative (COR) for contracts valued >$100M and/or those special interest contracts as determined by DAD IO/J6 CIO o Contractor Performance Assessment Reports Updates o Contractor Status Report
• Perform rationalizations efforts on J6 contracts o Review contract requirements for potential reuse of existing enterprise agreements or create enterprise agreements as needed o Identify contracts for potential rationalization across directorate
• Review and ensure new, recompete, and modification contract packages (PWS, Acq Strategy, etc.) meet DAD IO standards
• Gatekeeper for the DHA Service Contract Approval Request (D-SCAR) process
• Provide shared acquisition services to J6 Divisions and Branches
1.4 Objectives: The end-state goal is to improve the quality of Information Technology Business Strategy and Rationalization (ITBSR) Branch products in support of the DAD IO/J-6 strategic initiatives. Additionally, the Contractor(s) shall provide EITS Support Services consultation of preferred acquisition strategies to manage the acquisition lifecycle from initiation to closeout, which includes support for contract administration, development, execution, preparation and maintenance of the contract file, and participation in Integrated Product Teams (IPT). The Contractor shall analyze and measure the probable effects of various acquisition strategies, and make recommendations on acquisition strategies to ITBSR.
1.5 Scope: Acquisition Advisors typically perform the following types of functions: consults with client to define need or problem; initiates, supervises, and/or develops concepts and strategies for complex programs; provides strategic advice, guidance, and expertise to program and project staff; provides detailed analysis, evaluation, and recommendations for improvements for mission critical challenges/issues; leads studies and leads surveys to collect and analyze data to provide advice and recommend solutions.
1.6 Period of Performance (PoP): See Delivery Information on SF1449
1.7 Organizational Conflict of Interest (OCI): Because the work under this contract involves supporting the DHA in planning, programming, budgeting, and executing (PPBE) Information Technology (IT) finances as well as strategically aligning and rationalizing DAD IO/J-6 IT acquisition support functions and services across the Military Health System (MHS) and managing the MHS IT portfolio, the contract holder will have broad‐based access to competitively useful information, will be in a position to influence the development of MHS IT
March 1, 2021 requirements, and regularly will be called upon to provide the government with objective recommendations and advice.
As such, the contracting officer has determined that the work performed under the contract will give rise to OCI for the contract holder and any of its owners, partners, subsidiaries, affiliates, team members, and subcontractors both during performance and in relation to potential future Government contracts, particularly the DAD IO/J-6 contracts.
Therefore, the Contract holder and any of its owners, partners, subsidiaries, affiliates, team members, and subcontractors shall be ineligible to perform as a contractor, subcontractor, or team member on any of the to‐be‐awarded DAD IO/J-6 contracts associated with the EITSI, GSP, and CSP associated contracts for the duration of the contract and for 18 months after the final day of performance under the contract.
1.8 Administrative specifications
1.8.1 Place of performance: The work shall be performed at the contractor’s facility within the Falls Church, VA Area and/or location approved by COR. The address for Defense Health Headquarter (DHHQ) is located at 7700 Arlington Blvd, Falls Church, VA. The Government will provide access to Government controlled facilities and equipment, as required. The Contractor will be provided keys or codes for access to the Government facility. These keys and codes shall be controlled, tracked, and protected. Upon termination of the period of performance, all keys and/or access badges to the Government facility shall be turned in to the COR.
1.8.2 Recognized Federal holidays: The contractor is not required to perform services on Federal holidays.
New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day President’s Day Veteran’s Day Memorial Day Thanksgiving Day Juneteenth Christmas Day Independence Day
1.8.3 Hours of operation: The contractor is responsible for conducting business Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. The contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons.
1.8.4 Emergency Services: On occasion, services may be required to support an activation or exercise of contingency plans outside the normal duty hours.
1.9 Contractor travel: RESERVED
March 1, 2021
1.10 Other Direct Costs (ODC): RESERVED
1.11 Quality
1.11.1 Quality assurance (QA): The government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan provides a systematic method for the Government to evaluate performance and to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.12 Contractor personnel
1.12.1 CAC requirements: For all contractors who will work in Government facilities, the Facilities Security Officer (FSO)/Company's Security point of contact (POC) will provide the Government all the required information per the DHA CAC request process current version 2.1, January 2018, or more recent when updated. See process attached at Part 7 Section 7.1.1 of the PWS. A CAC is the standard identification for eligible DoD contractor personnel.
1.12.1.1 The contractor shall return all CACs to the COR upon the departure of the contractor(s).
1.12.2 Contractor onboarding and training. The contractor shall complete all requirements, training, and forms as prescribed in the following requirements:
1.12.2.1 The DHA’s “Onboarding Checklist for Contractor Employees” is located at the DHA Onboarding and Offboarding Portal at https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx
1.12.2.2 The DHA’s contractor training instructions embedded at Part 7 Section 7.1.2.
1.12.2.3 The contractor shall comply with onboarding requirements of the DHA for contractors needing to be issued CAC identification, including DoD- and DHA-directed training and forms submission, prior to network access, as displayed in the In/Out-Processing Portal at:
https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx (note: Public Key Infrastructure (PKI)-restricted, printed versions available).
1.12.3 Physical Security: The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, on government facilities, equipment, and materials shall be secured.
1.12.4 Key control: The contractor shall establish and implement methods of making sure all keys/key cards issued to the contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the contractor by the Government shall be duplicated. The contractor shall develop procedures covering key control that shall be included in the QCP. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas.
https://info.health.mil/cos/admin/hr/IO/SitePages/Home.aspx https://info.health.mil/cos/admin/hr/IO/SitePages/home.aspx
March 1, 2021
The contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the CO.
1.12.4.1 In the event keys, other than master keys, are lost or duplicated, the contractor shall, upon direction of the CO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the contractor.
In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the contractor.
1.12.4.2 The contractor shall prohibit the use of Government issued keys/key cards by any persons other than the contractor’s employees. The contractor shall prohibit the opening of locked areas by contractor employees to permit entrance of persons other than contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the CO.
1.12.5 Lock combinations: The contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the contractor’s
QCP.
1.13 Key personnel (Contractor): EITS Strategic Advisor (1 FTE):
The EITS Strategic Advisor is an individual whose qualifications and expertise are exceptional and/or highly unique and is an expert who demonstrate through leadership in their area of expertise through publications, speaking engagements, media citations, or other recognized interactions, by having participated in the Section 809 Panel (preferred) and/or related DoD acquisition innovation boards, see paragraph 5.1.1. DADIO/J-6 requires EITS Strategic Advisors who are experts in DoD acquisition and contracting, especially related to recent legislative and regulatory efforts to streamline acquisition and introduce innovative processes.
Strategic Advisors must have a minimum of 15 years professional experience and a master’s degree with Contracting Officer experience a plus, or 20 years of professional experience and a bachelor’s degree with Contracting Officer experience a plus.
1.14 Data rights: The Government will retain rights to all data produced in the course of developing, deploying, training, using and supporting DHA or other federal agencies that utilize this order.
1.15 Reporting
1.15.1 Contractor Manpower Reporting (CMR): RESERVED.
1.15.2 Non-Disclosure Agreement (NDA): All contractor personnel who will obtain access to proprietary, classified, or confidential information or any information release of which is protected or governed by law or regulation associated with DHA acquisitions shall be required to complete and sign a DHA contractor NDA (DHA Form 49) prior to beginning work on the
March 1, 2021 subject contract (Deliverable 1) The contractor shall execute an NDA on behalf of the company and shall ensure that all staff assigned to, including all subcontractors and consultants, or other personnel performing on contract/Task order execute an NDA protecting the procurement sensitive information of the Government and the proprietary information of other contractors.
The NDA shall be executed not later than first day of employment and to be renewed upon exercising a contract option period. Assignment of staff who has not executed this statement or failure to adhere to this statement shall constitute default on the part of the contractor. The contractor shall maintain originally signed NDAs of individual employees and provide copy to the COR.
1.15.3 Government’s COR: The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure that the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notifies both the CO and contractor of any deficiencies; coordinate availability of government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting contract.
1.15.4 Post award conference/periodic progress meetings: The contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with FAR Subpart 42.5. The CO, COR, and other Government personnel, as appropriate, may meet periodically with the contractor to review the contractor's performance.
At these meetings the CO will apprise the contractor of how the government views the contractor's performance and the contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.
1.16 Contractor Identification
1.16.1 Contractor personnel performing services in a contractor capacity in a Government facility are required to possess and wear an identification badge that displays his or her name and the name of their company. All contractor personnel shall identify themselves as contractor support personnel in all forms of communication with all entities with whom DHA/Deputy Assistant Director for Acquisition (DAD-A)/Head of the Contracting Activity (HCA) has business dealings. The contractor shall: Answer all telephone calls and have a personalized voice message with an introductory statement that includes the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting the DAD-A understands that the person is contractor support personnel.
Include a title block in all emails that states the fact that the person is contractor support personnel. Ensure all those with whom the person interacts in any face-to-face dealings while supporting DHA/DAD-A/HCA understands that the person is contractor support personnel.
March 1, 2021
1.16.2 Contractor personnel will be required to attend meetings or otherwise communicate with Government and/or other contract representatives to meet the requirements of this order.
Contractor personnel shall make their contractor status known during introductions.
1.16.3 Contractor personnel, while performing in a contractor capacity, are prohibited from using their retired or reserve component military rank or title in any written or verbal communications associated with the contracts in which they provide services.
1.17 Contractor Access to Health Affairs (HA)/DHA Network(s)
1.17.1 FSO/Company's Security POC shall notify the DHA Personnel Security Office after being awarded a contract that requires access to a DoD system (If applicable, if not delete 1.16.1 and 1.16.2 and replace to 1.16 Reserved). Contractor personnel requiring access to the HA/DHA networks for performance of their tasks require a background investigation and the security awareness training. The contractor shall be prepared for this process as it could take two (2) or more weeks. The FSO/Security POC shall submit a Standard Form (SF) 85/86 to DHA's Personnel Security Office for a background investigation.
1.17.2 Company's FSO/Security POC must notify the Personnel Security Office when the contractor has submitted the SF-85/86. The FSO/Security POC, or the COR must notify the DHA Personnel Security Office in writing of a contractor's termination from the contract, including the termination date.
1.18 Personnel Security
1.18.1 The contractor shall comply with DoD 8570.01-M, “Information Assurance Workforce Improvement Program, CH4” November 10, 2015 as amended; 8500.01, “Cybersecurity”, dated March 14, 2014; DoD Manual (DoDM) 6025.18, “Implementation of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule Compliance in DoD Health Care Programs” dated March 3, 2019, Department of Defense Instruction (DoDI) 6025.18 “HIPAA Privacy Rule Compliance in DoD Health Care Programs”, dated March 13, 2019; and DoDM
5200.02 “Procedures for the DoD Personnel Security Program (PSP),” incorporation change 3, effective September 24, 2020. Contractor responsibilities for ensuring personnel security include, but are not limited to, meeting the following requirements:
1.18.1.1 Follow the DHA Personnel Security Office guidelines for submittal of security clearances. Contact the DHA Personnel Security Office for guidance on the appropriate background investigation required for personnel on the contract. The DHA Personnel Security Office can be reached at (703) 275-6038.
1.18.1.2 Initiate, maintain, and document personnel security investigations appropriate to the individual’s responsibilities and required access to Controlled Unclassified Information (CUI).
1.18.1.3 DHA Personnel Security Office does not deny any access to any automated information system (AIS), network, or Controlled Unclassified Information (CUI). If a contractor receives an unfavorable background investigation, the request for access will be sent back to the FSO for
March 1, 2021 further action. Any unfavorable adjudication will result in DHA Personnel Security Office not signing off on any access request.
March 1, 2021
PART 2
2.0 DEFINITIONS, ACRONYMS, AND APPLICABLE
PUBLICATIONS/INSTRUCTIONS
2.1 Definitions:
2.1.1 Category D: Information Technology (IT) and Telecommunications Services (called D- Services)
2.1.2 Category R: Support (Professional/Administrative/Management) Services (called R- Services)
2.1.3 Contracting Officer (CO): A person with the authority to enter into, administer, and/or terminate contracts and make related determinations and findings.
2.1.4 Contracting Officer’s Representative (COR): An individual, including a contracting officer’s technical representative (COTR), designated and authorized in writing by the CO to perform specific technical or administrative functions. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.5 Nonpersonal services contract: a contract under which the personnel rendering the services are not subject, either by the contract’s terms or by the manner of its administration, to the supervision and control usually prevailing in relationships between the Government and its employees.
2.1.6 Quality Assurance Surveillance Plan (QASP): An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance. The Government may either prepare the QASP or require the offerors to submit a proposed quality assurance surveillance plan for the Government’s consideration in development of the Government’s plan.
2.1.7 Program Manager (PM): An individual who is responsible for the cost, schedule and performance of a specific project. The PM must understand and manage multiple discipline areas in order the successfully execute a project. This individual does NOT have authority to change the terms and conditions of the contract.
2.2 Acronyms:
AO Authorizing Official ATO Authority to Operate CAP Cloud Access Point CDRL Contract Data Requirement List CIO Chief Information Officer CJCSM Chairman of the Joint Chiefs of Staff Manual CND SP Computer Network Defense Service Provider
March 1, 2021
CNSS Committee on National Security Systems CO Contracting Officer CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTR Contracting Officer's Technical Representative CS Contract Specialist CSP Cloud Service Provider CUI Controlled Unclassified Information DD 254 Department of Defense Contract Security Requirement List (if applicable) DFARS Defense Federal Acquisition Regulation Supplement DHA Defense Health Agency DISA Defense Information Systems Agency DOD Department of Defense DoDI Department of Defense Instruction EULA End User License Agreements.
FAR Federal Acquisition Regulation FedRAMP Federal Risk Authorization and Management Program HIT Health Information Technology IA Information Assurance IS Information System IAVM Information Assurance Vulnerability Management NDA Non-Disclosure Agreement NIST National Institute of Standards and Technology OCI Organizational Conflict of Interest OCONUS Outside Continental United States (includes Alaska and Hawaii) ODC Other Direct Costs P-ATO Provisional Authorization to Operate PA Provisional Authorization PHI Protected Health Information PIEE Procurement Integrated Enterprise Environment PII Personally Identifiable Information PK Public Key PKI Public Key Infrastructure PMO Program Management Office POC Point of Contact PoP Period of Performance PPSM Ports, Protocols, and Services Management PRS Performance Requirements Summary PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Plan RMF Risk Management Framework SAR Security Assessment Report
March 1, 2021
SP Special Publication SRG Security Requirements Guide(s) STIG Security Technical Implementation Guide(s) TE Technical Exhibit TOS Terms of Service WAWF Wide Area Workflow (located within PIEE)
2.3 Applicable Publications, DHA Administrative Instructions (AI), etc.
Federal Acquisition Regulation (FAR) Defense Federal Acquisition Regulation Supplement (DFARS)
Defense Acquisition System (DoD Directive 5000.1)
Cybersecurity (DoDI 8500.01) Risk Management Framework for DoD Information Technology (DoDI 8510.01) Identify Authentication for Information Systems (DoDI 8520.03) DoD Privacy Program (DoD Directive 5400.11) DoD Health Information Privacy Regulation (DoD 6025.18-R) Personnel Security Program Requirements (DoD 5200.2-R) DoD Information Security Program: Controlled Unclassified Information (CUI) (DoD5200.01, Vol 4)
March 1, 2021
PART 3
3.0 GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
The Requiring Activity Authority has assessed the need for Government Furnished Property, Equipment, and Services and determined:
3.1 Services: The Government:
☐ Will NOT provide Government Furnished Services in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Government Furnished Services required in support of this contract/task orders. These Services are described below:
3.1.1 Annual Mandatory Training.
Contractor personnel will provide proof of required training to the CORwithin 3 business days of each training course completion. Cyber Awareness training is required prior to gaining network access, and annually thereafter. HIPAA training, Level 1 Antiterrorism Awareness training, Operations Security (OPSEC) Awareness training, and others as may be assigned are required to be completed within 30 days of being assigned, and annually thereafter.
3.1.2 New Systems Training.
The Government will provide training as required for new systems that it elects to add to the duties of the site support contractor. The training will be via industry standard training courses or courses as approved by the Government.
3.2 Facilities: The Government:
☐ Will NOT provide Facilities in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Facilities in support of this contract/task orders. The Government provided Facilities are described below:
For work performed within Government facilities, the Government will provide the necessary workspace for the contractor staff to provide the support outlined in the PWS to include desk space, telephones, computers, and other items necessary to maintain an office environment.
3.3 Utilities: The Government:
☐ Will NOT provide Utilities in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Utilities in support of this contract/task orders. The Government provided Utilities are described below:
March 1, 2021
For work performed within Government facilities, the Government will provide access to any utilities required in the performance of this contract. The Contractor shall instruct employees in utilities conservation practices, and shall be responsible for operating under conditions that preclude the waste of utilities.
3.4 Equipment: The Government:
☐ Will NOT provide Equipment in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ WILL provide Equipment in support of this contract/task orders. The Government provided Equipment is described below
The Government will provide laptop computers and cellular phones necessary to perform the tasks specified in this PWS for work performed both outside and inside government facilities.
For work performed within government facilities, the government will provide access to printers, scanners, shredders, and telephones for business purposes only.
This equipment is authorized for transaction of official Government business only and shall not be used for personal business. Personal long distance calls are not authorized and the cost of all personal long distance calls made by contractor or subcontractor employees may be deducted from the Contractor/s invoice payments. Telephones, facsimile machines and computer equipment to include laptops are subject to communications security monitoring at all times.
Contractor and subcontract employees may be issued keys signed for at scheduled and unscheduled key control inspections. The Contractor shall be required to reimburse the Government for lost keys, or lockset (if lockset is required to be replaced) as a result of lost keys.
The cost of replacement of keys/locksets may be deducted from payments to the Contractor.
Items issued will remain the property of the Government and the Contractor will maintain proper accountability of issued equipment. Equipment shall not be removed from the facilities shown in paragraph 3.2 above, unless otherwise specified in the Performance Work Statement. They are to be used, turned in and/or disposed of as directed by the Contracting Officer Representative or Contracting Officer.
3.4.1 Procurement Integrated Enterprise (PIEE), GFP Module Application The contractor shall be responsible for obtaining and maintaining access, training and successful operation of the PIEE/GFP Module application for the entirety of the contract/task order PoP.
The PIEE GFP Module application is located at the following website: https://wawf.eb.mil/piee-landing/. Access to PIEE/GFP Module application training materials and in-depth information applicable to the contractor’s responsibilities regarding GFP can be found at the following website: https://dodprocurementtoolbox.com/.
Contracting Office Responsibilities:
The Contracting Office shall ensure close coordination and validation of the GFP items with the COR and DHA Accountable Property Officer prior to uploading the GFP Attachment into the PIEE/GFP Module. At the time GFP is anticipated and identified, the Government will upload the GFP Attachment into the PIEE/GFP Module. It is the Contracting Office’s responsibility to https://wawf.eb.mil/piee-landing/ https://wawf.eb.mil/piee-landing/ https://dodprocurementtoolbox.com/
March 1, 2021 prepare, upload and maintain the GFP Attachment in the PIEE/GFP Module in accordance with the GFP Attachment instructions provided at the DoD Procurement Toolbox. The CO and COR shall manage and keep an inventory of any GFP associated with contract/task orders awarded through DHA, in accordance with applicable FAR Part 45, DoD FAR Supplement (DFARS) 245 with respective clauses, DHA AI 095 and PD 45-01 following the change in disposition of items listed on that PIEE/GFP Module Attachment.
The contracting office will also review, acknowledge, reject and/or approve shipment orders provided by the contractor as appropriate. Functional roles can be determined within the Contracting Office, and requested within the PIEE/GFP Module system.
Contractor Responsibilities:
A key contractor responsibility is to work with the CO and COR to ensure the PIEE/GFP Module data, to include the PIEE/GFP Attachment, provides a timely, complete and accurate accounting of the GFP applicable to the contract/task order. Contractors are required to report the receipt of any GFP shipped to them, regardless of whether it is listed on the GFP Attachment for their contract. Similarly, contractors are required to utilize the GFP Module application in conjunction with the shipment of GFP to the Government, or in reporting Property Loss of GFP issued (such as destruction or loss). Discrepancies or disputes regarding property shipped to or shipped from the contractor must be reported via the GFP Module application, with the CO having authority over final designation of status.
The contractor shall report semi-annually 100% inventories, reconciliations, and final disposition of GFP provided by the government. Final invoices will not be paid pending GFP reconciliation.
Contractors shall be aware of and ensure compliance with applicable FAR Part 45, DFARS 245 and 252.245, Defense Pricing and Contracting Policies, Procurement Integrated Enterprise Environment Standards, DHA Administrative Instruction 094 and DHA Guidance. A semi-annual GFP inventory shall be required by the Contractor and reported to the COR (CDRL 02).
3.5 Materials: The Government:
☐ Will NOT provide Materials in support of this contract/task order. As a result, this paragraph is Not Applicable.
☒ IS providing Materials in support of this contract/task orders. The Government-provided Materials are described below: The Government will provide standard office supplies as necessary to perform the tasks specified in this PWS.
March 1, 2021
PART 4
4.0 CONTRACTOR FURNISHED ITEMS AND SERVICES
4.1 General: For Contractor off-site facilities the contractor shall furnish all supplies, equipment, facilities and services required to perform work listed under Section 5 of this PWS.
The contractor will specifically provide facilities, utilities, desk space, high speed internet connection, and access to telephones, printers, scanners and other equipment necessary to maintain an office environment for work performed at the Contractor’s off-site facilities.
4.2 Secret Facility Clearance: A Secret Facility Clearance is not required.
4.3 Materials: The Contractor shall furnish materials, supplies and equipment necessary to meet the requirements under the PWS
4.4 Equipment: Except as expressly provided under Part 3 of this PWS, the Contractor is responsible for providing the equipment, materials, and related support it needs to perform the integrated services of this PWS.
4.5 Facilities: Except as expressly provided in Part 3 of this PWS, the Contractor is responsible for providing the facilities and facilities-related support it needs to provide the Contractor Services.
The Contractor shall perform at contractor or other facilities when Government space is not available or during emergency/contingency situations. During emergency/contingency situations the contractor shall ensure necessary workspace for the contractor staff is available to provide the support outlined in the PWS to include desk space, telephones, computers, and other items necessary to maintain an office environment.
March 1, 2021
PART 5
5.0 SPECIFIC TASKS
5.1 EITS Strategic Advisor (1 FTEs)
The EITS Strategic Advisor is an individual whose qualifications and expertise are exceptional and/or highly unique and is an expert who demonstrate through leadership in their area of expertise through publications, speaking engagements, media citations, or other recognized interactions, by having participated in the Section 809 Panel (preferred) and/or related DoD acquisition innovation boards, see paragraph 5.1.1. DADIO/J-6 requires EITS Strategic Advisors who are experts in DoD acquisition and contracting, especially related to recent legislative and regulatory efforts to streamline acquisition and introduce innovative processes.
Strategic Advisors must have a minimum of 15 years professional experience and a master’s degree with Contracting Officer experience a plus, or 20 years of professional experience and a bachelor’s degree with Contracting Officer experience a plus.
5.1.1 Special Qualifications: DHA DAD IO requires acquisition innovation and thought leadership based on participation in and/or Subject Matter Expert (SME) knowledge of recent DoD acquisition reform, streamlining, and improvement initiatives and associated legislation.
Participation in the Section 809 Panel preferred.
These may include:
• Defense Innovation Board (DIB) Software Acquisition Practices (SWAP) report and recommendations
• Defense Science Board (DSB) Design and Acquisition of Software for Defense Systems report and recommendations
• Section 813 Panel on Intellectual Property and Data Rights report and recommendations
• Office of Management Budget (OMB) Policy Memo M-19-13: Category Management:
Making Smarter Use of Common Contract Solutions and Practices
• In progress revisions to DoDI 5000.02, DoDI 5000.74, DoDI 5000.75
• Current DoD cloud services acquisition initiatives (e.g., Joint Enterprise Defense
Infrastructure [JEDI], Defense Enterprise Office Solutions [DEOS])
• Best practices and state-of-the-art techniques in Fair Opportunity and Source Selection
• Other Transaction Agreements and Commercial Solutions Opening
• Agile acquisition approaches and techniques
• Pending revisions to DoD Small Business strategy based on Section 851 of the FY 2019
NDAA
• Acquisition reform provisions included in National Defense Authorization Acts
(NDAAs) for FYs 2016-2019
5.2 Acquisition Support Analyst, (3 FTEs)
The contractor shall provide day to day acquisition support analysis to include but not limited to, the following tasks:
March 1, 2021
1) The Contractor shall provide acquisition and strategic advice to identify, understand, analyze, articulate, and ensure EITS efforts are implemented in a timely manner as determined by the EITS Program Manager and/or EITS Integrator (EITSI) Program Manager.
2) The Contractor shall provide acquisition and strategic support to realize EITS implementation of future EITSI call orders, Geographic Service Providers (GSP), Capability Service Providers (CSP) procurements, and those determined by the EITS Program Manager or designated government lead.
3) The Contractor shall provide strategic support and guidance to ensure technical reports provided to the EITS Program Manager and/or EITS Integrator (EITSI) Program Manager by the EITSI are aligned to the success and efforts of the program.
5.2.1 The Acquisition Support Analyst personnel must have excellent verbal, written, and interpersonal communication skills and excellent presentation skills at the senior leader level (DoD senior leaders preferred). Acquisition Support Analyst must have a minimum of 10 years acquisition support experience, with a minimum of 2 years Government experience preferable, and a Bachelor’s Degree (preferred) or equivalent work experience.
5.2.2 When using education/certification in conjunction with labor categories, the COR in coordination with the CO must establish a review process of contractor personnel to ensure labor category requirements are met.
March 1, 2021
PART 6
6.0 INFORMATION TECHNOLOGY & SECURITY
6.1 Classification of Work: All work under this contract is unclassified; however, contractor personnel will undergo a criminal background investigation and a favorable National Agency Check with Inquiries (NACI) or higher. The contractor personnel must be able to obtain and maintain favorable suitability adjudication prior to commencement of duties; one major legal issue with 36 months of the suitability adjudication date is automatically disqualifying. The contractor will pre-screen employees for major issues relating to; Intoxicants, Drug Use, Financial Responsibility, Sexual Misconduct, Honesty, Disruptive or Violent Behavior, Employment Misconduct or Negligence, Illegal possession of Firearms or Weapons, acts of terrorism, Security denials or revocations, Serious Mental Health Issues, Associates or Relatives with issued that directly relate to the Contractor, and misuse of Information Technology Systems. It is highly recommended Contractors bring their original passport or birth certificate.
The final Suitability Determination will be made by DHA leadership through the Security Office.
The Contractor personnel will be removed from the network and may be removed from the facility at any time if they are found unsuitable through the continuing evaluation process.
If Contractor personnel received interim declination or eligibility denial by the Defense Industrial Security Office (DISCO) or any other Central Adjudication Facility (CAF), this action is automatically disqualifying and overrides local suitability determinations.
If a Contractor personnel is found unqualified for any reason or the personnel submits their resignation, the personnel shall be replaced with a qualified individual within 5 business days.
Contractor personnel will be required to sign a Non-Disclosure Agreement (NDA) due to access to Procurement Sensitive information. Violation of this NDA will be grounds for immediate removal of the contract employee.
6.2 The TIER 1 or TIER 2 levels and position sensitivity designation for positions under this contract is:
6.2.1 TIER II: Non-critical sensitive position (A position where an individual is responsible for systems design, operation, testing, maintenance, and/or monitoring that is carried out.)
6.3 Personally Identifiable Information (PII)/Protected Health Information (PHI), Procurement, and Federal information requirements:
Refer to DHA Procedures, Guidance and Information Part 24 – Protection of Privacy and Freedom of Information PII/PHA and Federal Information Requirement DHA PGI 224.1-90 if applicable.
6.3.1. Data Sharing Agreements (DSAs): Contractors requiring access to PII, which includes PHI, or access to de-identified data, are subject to the DHA Privacy and Civil Liberties Office (DPCLO) (Privacy Office) Data Sharing Program. This program requires DHA to enter into DSAs with parties outside the MHS who use or create MHS data. A DHA contract may use the term Data Use Agreement (DUA) rather than DSA. DSAs assure that outside parties protect
March 1, 2021
MHS data in accordance with the Privacy Act and the HIPAA Rules. To apply for a DSA, the contractor submits a Data Sharing Agreement Application (DSAA) to the DHA DPCLO. The contractor submits the DSAA even if a subcontractor will be the party accessing MHS data.
After review and approval of the DSAA, the Privacy Office provides a DSA to the contractor for execution.
6.3.2. Processing Procurement Sensitive Information: All individuals shall seek guidance from the CO regarding the coordination of documents, dissemination, and transmission of procurement sensitive information. Procurement sensitive information shall not be transmitted electronically unless encryption is utilized. Depending on a particular procurement, other restrictions may apply.
6.4 Training
6.4.1 Contractor employees performing cybersecurity/cyberspace functions shall comply with the following requirements:
6.4.1.1 Training: All contractor and associated subcontractor employees working Cybersecurity Information Assurance (IA)/Cyberspace functions must comply with DoD training requirements in Department of Defense Directive (DoDD) 8140.01 and DoD 8570.01-M. Contractors shall identify, document, track, and report qualifications of contract support personnel who perform cyberspace work roles.
6.4.1.2 Certification: The contractor shall ensure that personnel accessing IS have the proper and current IA certification to perform IA functions at contract award in accordance with DoD 8570.01–M, IA Workforce Improvement Program. The contractor shall meet the applicable IA certification requirements as outlined in DFARS 252.239-2001, including:
6.4.1.2.1 DoD-approved IA workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01–M; and
6.4.1.2.2 Appropriate operating system certification for IA technical positions as required by DoD 8570.01–M.
6.4.1.2.2.1 Upon request by the Government, the contractor shall provide documentation supporting the IA certification status of personnel performing IA functions.
6.4.1.2.2.2 Contractor personnel who do not have proper and current certifications shall be denied access to DoD IS for the purpose of performing IA functions.
6.4.2 User requirements: All contractor employees that require access to DHA IT must comply with the requirements of DHA-Procedural Instruction 8140.01, Acceptable Use of DHA IT, to include those contract employees with privileged access.
6.5 Cybersecurity Requirements for Non-DoD IT or Covered Contractor Information Security (IS):
March 1, 2021
6.5.1 The contractor shall, at time of award, have implemented the security requirements prescribed in the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations” (available via the internet at http://dx.doi.org/10.6028/NIST.SP.800- 171), in accordance with DFARS clause 252.204-7012.
6.5.2 NIST SP 800-171 DoD Assessment Methodology. The DFARS provision 252.204-7019 introduces the “NIST SP 800-171 DoD Assessment Methodology” requirement. This requirement enables a strategic assessment of a contractor’s implementation of the NIST SP 800- 171 requirements as required in DFARS clause 252.204-7012. The DoD Assessment Methodology requirement flows down to subcontractors.
6.5.2.1 Basic Assessment: The contractor shall obtain and maintain access to the Supplier Performance Risk System (SPRS) via the PIEE, (available via the internet at https://www.sprs.csd.disa.mil/)
6.5.2.1.1 The contractor shall perform a Basic Assessment, using the NIST SP 800-171 DoD Assessment Scoring Template, and enter the results electronically in SPRS for each covered contractor information system that is relevant to an offer, contract, task order, or delivery order.
See Attachment 2, Deliverable Schedule Table.
6.5.2.1.2 The contractor shall ensure that applicable subcontractors also have their results of a current assessment posted in SPRS prior to awarding a subcontract or other contractual instrument in accordance with DFARS clause 252.204-7020.
6.5.3 The contractor shall provide the government with access to its facilities, systems, and personnel when necessary to conduct or renew a higher-level (i.e., Medium or High) assessment in accordance with DFARS clause 252.204-7020.
6.5.4 Cybersecurity Maturity Model Certification (CMMC): The CMMC (DFARS clause 252.204-7021) builds upon the NIST SP 800-171 DoD Assessment Methodology by adding a comprehensive and scalable certification element to verify the implementation of processes and practices associated with the achievement of a cybersecurity maturity level. The CMMC is designed to increase assurance to the DoD that federal contract information (FCI) and DoD Controlled Unclassified Information (CUI) is protected at a level commensurate with the risk.
The CMMC requirement flows down to subcontractors.
6.5.4.1 The contractor shall have a current (i.e., not more than three years old) CMMC certificate in SPRS issued by an accredited CMMC Third Party Assessment Organization (3PAO) at the required CMMC level. The description of CMMC levels is available at https://www.cmmcab.org/.
6.5.5 The contractor shall submit requests to vary from NIST SP 800-171 in writing to the CO or COR, for consideration by the DoD Chief Information Officer (CIO). The contractor need not implement any security requirement adjudicated by an authorized representative of the DoD CIO https://www.sprs.csd.disa.mil/ https://www.cmmcab.org/
March 1, 2021 to be non-applicable or to have an alternative, but equally effective, security measure that may be implemented in its place.
6.5.6 If the DoD CIO has previously adjudicated the contractor’s requests indicating that a requirement is not applicable or that an alternative security measure is equally effective, a copy of that approval shall be provided to the CO or COR when requesting its recognition under this contract.
6.5.7 Cloud Computing: If the contractor intends to use an external cloud service provider, on their behalf, to store, process, or transmit any DoD CUI in performance of this contract, the contractor shall require the cloud service provider meets security requirements equivalent to those established by the Government for the Federal Risk and Authorization Management Program (FedRAMP) Moderate baseline (https://www.fedramp.gov/) and that the cloud service provider complies with requirements in paragraphs 6.5.8 through 6.5.14 for cyber incident reporting, malicious software, media preservation and protection, access to additional information and equipment necessary for forensic analysis, and cyber incident damage assessment.
6.5.7.1 If the information is DoD CUI-specific (e.g., PII/PHI), then the contractor shall ensure the external cloud service provider meet the security requirements equivalent to FedRAMP High baseline.
6.5.8 Cyber Incident Reporting Requirement
6.5.8.1 When the contractor discovers a cyber incident that affects a covered contractor information system or the covered defense information residing therein, or that affects the contractor’s ability to perform the requirements of the contract that are designated as operationally critical support and identified in the contract, the contractor shall:
6.5.8…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .