Attachment_1_PWS_ICODES-V7_(9_Dec_14).pdf
PDF 563 KB Posted
- Attached to
- Integrated Computerized Deployment System -Version 7 Federal contract opportunity
- Solicitation number
- HTC711-14-R-D006
About this file
Attachment 1 PWS ICODES - V7 (9 Dec 2014)
View the file
Other files for this federal contract opportunity
Show all 33
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Attachment 1 HTC711-14-R-D006
PERFORMANCE WORK STATEMENT
FOR THE MILITARY SURFACE DEPLOYMENT
AND DISTRIBUTION COMMAND (SDDC)
INTEGRATED COMPUTERIZED DEPLOYMENT SYSTEM (ICODES)
VERSION 7
9 December 2014
This page is intentionally left blank
Table of Contents
SECTION TITLE
1.0 DESCRIPTION OF SERVICES
2.0 DELIVERABLES
3.0 SERVICE DELIVERY SUMMARY
4.0 GOVERNMENT-FURNISHED AND CONTRACTOR-FURNISHED
EQUIPMENT
5.0 GENERAL INFORMATION
6.0 SECURITY
7.0 NON-DISCLOSURE OF DATA/INFORMATION
8.0 CONTRACT TRANSITION
Appendices
A ACRONYMS
B APPLICABLE DOCUMENTS
C GOVERNMENT FURNISHED SOFTWARE/LICENSES
D NON-DISCLOSURE AGREEMENT
E SYSTEM APPLICATION DESCRIPTION
F SYSTEM REQUREMENTS DESCRIPTION
G SYSTEM ENVIRONMENT DESCRIPTION
H WORKFORCE CERTIFICATION REQUIREMENTS
I EXAMPLE AFTER ACTION REPORT
J CDRLS/DIDS
K GOVERNMENT ACCEPTANCE TEST PROCESS
INTEGRATED COMPUTERIZED DEPLOYMENT SYSTEM
VERSION 7
VISION: To provide reliable and trusted surface transportation information to the Command and to our customers.
MISSION: The Military Surface Deployment and Distribution Command (SDDC) provides global surface deployment and distribution services to meet the nation’s objectives. SDDC is the Army component of the United States Transportation Command (USTRANSCOM) Transportation Component Commands, which includes Military Sealift Command and Headquarters (HQ), Air Mobility Command (AMC).
1.0 DESCRIPTION OF SERVICES
1.1 Background.
USTRANSCOM selected the current system to be the Department of Defense (DoD) migration system from the Automated Air Load Planning System to the Integrated Computerized Deployment System for planning and managing cargo placement within marshalling yards and surface conveyances.
The current system is a joint decision-support system developed to assist users with the staging and load-planning requirements for multiple military and commercial modes of transportation. It was developed under contract to the Department of Defense by CDM Technologies and Tapestry Solutions. The system incorporates intelligent tools for staging, conveyance load planning and multi-modal planning designed and implemented in compliance with the principles of a service-oriented architecture and operating within a collaborative environment. The system enables users to plan and track cargo stowage for air, ocean, rail, and truck in a single system that affords the capability of one time entry of the data. It enables the joint community to easily create exchange and interpret cargo movement plans through a single software application. Other features assist users by providing high quality alternative solutions to complex load planning problems. The system integrates multiple knowledge-based expert systems, data storage, and a graphical user interface within a distributed and collaborative operational environment providing global services to the operating forces. Some parts of the software, specifically Integrated Cooperative Decision-Making (ICDM), are claimed to be proprietary to Tapestry Solutions thereby limiting the Government’s ability to freely use, disclose, or modify the software. The purpose of this acquisition is to maintain the capabilities of the current system and replace the ICDM proprietary code with a solution ensuring Government Purpose Rights of all deliverables.
The current Enterprise hardware and software environments (Production, Staging, Testing, and Training) are hosted within SDDC’s Common Computing Environment (CCE). Another SDDC team, comprised of system and data base administrators, manages the CCE. The CCE is virtualized in order for SDDC systems to share resources for the Command. In addition, the contractor will develop a stand-alone desktop configuration that is compatible with specified operating systems. The desktop configuration must operate either connected to or disconnected from the network.
1.2 Scope.
The scope of this contract consists of designing, developing, documenting, testing, and implementing a software solution that provides, as a minimum, the system functionality reflected in Appendix E and Appendix F, with a minimum of Government Purpose Rights. The contract also includes the following: update and maintain software and enhance automation capabilities, maintain/sustain system operations, analyze system changes, and build capabilities within SDDC’s automated system. The contractor shall coordinate with the Government to ensure all activities are well synchronized and integrated with other SDDC transportation management efforts.
The Performance Work Statement (PWS) includes the following task areas, and can be considered as two primary categories:
A. Overall Contract and Project Management
Task Area 1: Contract Level and Project Management B. Program Support
Task Area 2: Provide System Functionality Task Area 3: Sustainment Task Area 4: Enhancements
Task Area 5: Configuration Management Task Area 6: Information Assurance (IA) Task Area 7: Common Development Environment (Optional) Task Area 8: Deployment Support Module (Optional)
Task Area 7 and Task Area 8 are reserved for potential use and may be added and negotiated during the life of this contract. These Reserved tasks will be to add potential new capability or new technology.
The Government Contracting Officer, and Contracting Officer’s Representative/Alternate Contracting Officer’s Representative (COR/ACOR) are the points of contact regarding decisions on Government requirements and priorities. Unless otherwise specified in this PWS, all days designated are business days.
All tasks shall be performed in accordance with (IAW) all regulations and guidelines as shown in Appendix B and clauses included in the contract.
1.3 Specific Tasks.
1.3.1 Task Area 1: Contract Level and Project Management.
Task 1 Period of Performance: Contract Start Date throughout life of the contract.
This task consists of the functional activities relating to the administration and management of this effort. The contractor shall provide project management and oversight of all projects and tasks within the scope of this contract. The contractor shall provide oversight of all projects within the scope of this contract and shall provide and prepare documents such as point papers, briefings, and meeting minutes related to the status and performance of projects.
1.3.1.1 Subtask 1: Quarterly Status Report (QSR).
The contractor shall provide a quarterly Status Report, expected to be a high level Executive Summary, no more than two pages with attachments as required. The QSRs shall be provided to the COR/ACOR to be due on the first business day in January, April, July, and October of each year. The QSR shall describe the technical approach and management controls employed to meet the cost, performance, and schedule requirements throughout contract execution. The contractor shall prepare and sustain a milestone schedule that defines all tasks, durations, timelines, resources, and dependencies for all projects worked on this contract. The milestone schedule shall be created in Microsoft Project and provided quarterly as part of the QSR. The milestone schedule shall be maintained and kept up-to-date to identify all in-progress and planned projects, software releases (routine and complex) and tasks as they progress to completion. The contractor shall ensure the schedule includes each of the lowest level tasks not exceeding four weeks duration and each lowest level task, being dependent on the start or finish of another task. The schedule shall reflect the contractor’s most realistic timelines in order to synchronize other SDDC efforts.
The QSR shall contain the milestone schedule as described above, and shall also contain the following:
• A brief synopsis of the efforts completed, deliverables provided, conferences/trips conducted or attended during the reporting period
• Risk assessment and mitigation recommendations
• Proposed activities NOT included in the milestone schedule
• Actual and projected other direct cost (ODC) expenditures
• Monthly report of hours/employee for labor hour tasks
Deliverable: QSR due first business day of Jan, Apr, Jul and Oct of each year.
1.3.1.2 Subtask 2: Program Management Reviews (PMRs).
The contractor shall conduct PMRs 6 months and 11 months after contract award. After Gov’t acceptance of final software deliverable, the contractor shall conduct PMRs during March and September of each FY. The PMR’s typically last one day. The contractor shall present status, progress, recommendations, concerns, and hands on functional review for mature capability in the development of any tasks or documentation described within this PWS. The PMR shall reflect resolution to prior PMR actions items, new action items, record discussion activity, decisions made, date, locations, attendees, and a copy of the presentation slides used. The contractor shall provide the draft PMR slides to the COR and Government Program Manager (PM) no later than (NLT) two business days prior to the meeting. The contractor shall provide final slides, to include the milestone schedule, at the scheduled meeting. The contractor shall provide the PMR minutes NLT five business days after the meeting.
Deliverable: Draft PMR slides due NLT 2 business day prior to meeting and final PMR slides at the meeting.
Deliverable: PMR minutes NLT 5 business days after meeting.
1.3.1.3 Subtask 3: Trip Reports.
The contractor shall submit trip reports to the COR/ACOR within five business days upon completion of travel. Trip reports shall include the following: traveler’s name, trip purpose, location, length of trip, individuals contacted during trip, synopsis of all discussions, future actions identified, decisions made, and/or issues of concern arising during trip. Travel is anticipated in support of PWS tasks 1.3.3.5 and 1.3.5.3, however, is not all inclusive. Travel may be required within the Contiguous United States (CONUS) and Outside CONUS (OCONUS). OCONUS trips are not currently planned or anticipated. However, contractor personnel must be prepared to travel OCONUS should the need arise. The table below is an estimate of the annual travel requirements.
Location Estimated Trips Estimated Days Estimated People
CONUS 3 5 3
Deliverable: Trip reports due NLT 5 business days after travel completion.
1.3.1.4 Subtask 4: Employment Status Report.
The contractor shall ensure all personnel assigned to this contract meet the minimum requirements specified in the contractor’s proposal, IAW the generic position descriptions provided in the contractor’s proposal. The contractor shall notify the Contracting Officer (CO) and the COR in writing of any changes to personnel within three business days after information is known.
The contractor shall provide an employee status report (listing/spreadsheet) containing names and labor categories of personnel supporting the tasks identified in the PWS. The initial report shall be provided within 30 business days after contract start date.
Deliverable: Report due NLT 30 business days after contract start.
1.3.1.5 Subtask 5: Contractor Manpower Reporting (CMR).
The contractor shall report ALL contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for Military Surface Deployment and Distribution Command via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address http://www.cmra.army.mil/.
Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year, beginning with 2014. Contractors may direct questions to the help desk at:
https://cmra.army.mil.
The eCMRA site associated with this contract is Scott Air Force Base, IL.____
The Command of the Requiring Activity is SDDC.
The Unit Identification Code (UIC) for this requirement is W0QFAA.__
The Federal Service Code for this contract is U012/D321.____________________
Deliverable: Report due NLT 31 Oct of each year.
1.3.2 Task Area 2: Develop System Functionality (Cost Plus Fixed Fee)
Task 2 Period of Performance: Completed no later than 18 months after Performance Start Date.
1.3.2.1 Subtask 1: Analysis/Design.
The contractor shall analyze available Government artifacts from the current software to include but not limited to: source-code base, system requirements and design documents, Extensible Mark-up Language schemas/Extensible Schema Definition files, diagrams, interface and service agreements.
1.3.2.1.1 The contractor shall construct a design strategy to develop a software solution that provides, at a minimum, the system functionality reflected in Appendix E and Appendix F.
Contractor may choose to “re-use” existing artifacts or code, but is not obligated to do so. The contractor shall provide a Draft Software Design Document (SDD) 85 calendar days after contract start. The contractor shall provide a Program Design Review (PDR) 90 calendar days after contract start. The contractor shall provide a final SDD, 30 calendar days after Government provides comments to contractor. The contractor shall provide a Draft Work Breakdown Schedule (WBS) 90 calendar days after contract start. The contractor shall provide a final WBS, 30 calendar days after Government provides comments to contractor.
Deliverable: Draft SDD due 85 calendar days after contract start.
Deliverable: PDR due 90 calendar days after contract start.
Deliverable: Final SDD due 30 calendar days after Gov’t comments received.
Deliverable: Draft WBS due 90 calendar days after contract start.
Deliverable: Final WBS due 30 calendar days after Gov’t comments received.
1.3.2.2 Subtask 2: Development.
The contractor shall develop a secure solution utilizing widely accepted industry standard practices and techniques that can be easily scaled within in an “n-tiers” (data access layer, business access layer, and graphical user interface) environment. The system developed shall include each application (Appendix E) and its requirements as annotated in (Appendix F). The contractor shall provide Production Candidate for Government Acceptance Test (GAT) 16 months after contract start. The Program Management Office (PMO) will coordinate a GAT to ensure Subject Matter Expert (SME) endorsement for the developed software (See Appendix K).
The developer shall fix any SME-identified software problems that would result in mission failure if implemented before the developed software is considered Government accepted. The developer, PMO and SMEs will decide upon courses of actions and delivery schedules to remedy any software problems that do not directly impact mission success. The contractor shall provide Government Accepted Production Software 19 months after contract start.
The contractor shall provide Prototype Software at the end of the Base Period for PMO evaluation and validation of the system’s core functional capabilities: SLP, CE and TARGET (Reference Appendix E and F). The Prototype Software will adhere to all security requirements (reference 1.3.6).
The contractor shall provide Government Accepted Production Software at the end of Option Period 1.
Deliverable: Prototype Software due at the end of the Base Period.
Deliverable: Production Candidate for GAT due 16 months after contract start.
Deliverable: Gov’t Accepted Production Software due at the end of Option Period 1.19 months after contract start.
1.3.2.3 Subtask 3: Documentation.
The contractor shall provide and maintain separate documents and guides that accurately reflect the proposed as well as implemented solutions from both a technical and functional user perspective. The contractor shall provide Draft Documentation and User Guides 16 months after contract start. The contractor shall provide Final Documentation and User Guides 19 months after contract start.
Deliverable: Draft documents and guides due 16 months after contract start.
Deliverable: Final documents and guides due 19 months after contract start.
1.3.2.4 Subtask 4: Implementation.
Government acceptance of the developed software must be achieved prior to implementation (see 1.3.2.2).
The contractor shall ensure that the developed solution is configured and deployed as prescribed within the CCE service level agreement and complies with DoD IA policies, procedures and regulations. Any Category I (CAT I) vulnerabilities or conflicts with other code within the CCE are considered to be major defects.
1.3.2.5 Subtask 5: System Change Requests (SCRs)
The contractor shall enhance the software based on System Change Requests as coordinated by the Program Management Office (reference Subtask 1.3.5.2). This Subtask will end when the development period is complete.
During the development period the Government may submit SCRs based on regulatory or emerging requirements. During the development period the labor effort for SCR releases shall be allocated under this Subtask and include requirements analysis, design, development, development testing, documentation, support for Government testing, and installation support for ICODES-V7. PWS Task 1.3.4 SCR process will apply. The Government anticipates 5 SCRs to be implemented in Version 7 release with approximately 1,282 labor hours.
1.3.3 Task Area 3: Sustainment.
The contractor shall maintain, to include “bug fixes”, application software, tools, capabilities, servers, interfaces and databases, for the application, and related functionality in support of the user community: SDDC Directorate of Operations (G3), Army G4, AMC Directorate of Logistics (A4), Navy 436, United States Marine Corps Systems Command, USTRANSCOM and the Government PMO. The contractor shall maintain and update documentation on the system architecture and of existing interfaces, data and software on a routine/continuous basis.
The four Enterprise Environments (Production, Staging, Testing, and Training) are part of SDDC’s CCE. Therefore, the program receives operational System Administrator (SA) and Database Administrator support from the CCE’s support team, the Enterprise Integration Program (EIP). The contractor shall support the EIP team with any application-specific commercial-off-the-shelf (COTS), configuration, and/or application software requirements within the four environments. The contractor shall provide and maintain the development and test environments. The EIP team does not support the environments, but may provide technical advice regarding virtualization or tools that are required within the CCE.
1.3.3.1 Subtask 1: Sustain and Maintain Deployed System Applications
Support hardware environments:
• Solaris 10 (and higher) UNIX servers
• Virtualized server environments
• Windows 2008 (and higher) servers
• Storage Area Network devices
• IA Vulnerability Assessments
• Security Technical Implementation Guides (STIGs)
The contractor shall support the configurations below:
Enterprise Configuration The contractor shall provide enterprise configuration as web-based and available through the CCE on the Electronic Transportation Acquisition (ETA) website
(https://eta.sddc.army.mil). The contractor shall provide continual updates to the reference library and conveyances.
Desktop Configuration
Install on a Personal Computer Work Station that is disconnected from the network. However, a network connection allows sharing through the Information Repository (IR) and reference data is updated through the Enterprise Server. For estimation purposes, there are currently at least 1,800 desktop configuration licenses.
Resident Server Configuration
Server configured to reside and run a local version of Enterprise Suite for training, austere and operational environments. Currently, there are servers residing at the following locations: Blount Island Command, Jacksonville, Florida; Camp Johnson, Jacksonville, North Carolina; Joint Base Langley-Eustis, Newport News, Virginia; and Fort Lee, Virginia.
The contractor shall ensure the following applications and underlying services continue to support the staging and load-planning functionality and related business rules:
• Single Load Planner Conveyance Estimator (CE)
• Conveyance Builder
• Collaborative Information Workspace Administrator
• Data Cleanser
• Data Manager (DM)
• Conveyance Repository (CR)
• Hand-Held Terminal (HHT) Administrator
• IR
• Break bulk Tool
• Terminal Management Module
• Transportability Analysis Report Generator
• Cargo Symbol Manager
A description of the above applications is listed in Appendix E and the environment of each application is listed in Appendix G.
The contractor shall update the applications and underlying services to support changes to the ICODES information technology or business environments and related business rules. The contractor shall meet with the COR, the Government ICODES PM and/or the Government’s Configuration Manager (GCM) to discuss current capabilities and prioritize any proposed changes to existing Configuration Control Board (CCB) priorities.
1.3.3.1.1 Sustain Capabilities.
The contractor shall sustain the software and applications developed and delivered to the Government under this contract, and shall include, but not be limited to, the following sustainment activities:
• COTS.
• Oracle star-schema database.
• Maintain authentication to system capabilities/homepage through SDDC’s single sign-on solution, ETA.
• Maintain approximately 50 aircraft/230 configurations (+/- 10%) in ICODES CR.
• Add approximately one new aircraft.
• Update 15-20 aircrafts.
• Maintain approximately 297 ships (+/- 10%) in ICODES CR.
• Add approximately five new ships.
• Update 35 ships.
• Maintain approximately 226,918 railcars (+/- 10%) in ICODES CR.
• Update 10 railcars.
• Maintain approximately 58 reference libraries (+/- 10%) in ICODES DM.
• Maintain Shared Object Library.
• Maintain HHT .cab file included with the HHT Integration package.
• Maintain the existing software code-base for ICODES to include the following: code repositories; build environment; and agent rules.
• System help files.
• Access and approval of user accounts.
• Manage, monitor, and maintain the incoming and outgoing interface agreements listed below:
Analysis of Mobility Platform (AMP) AMP Seaport Simulation Tool Table of Organization and Equipment (TOE) Modification TOE Transportation Infrastructure Network Builder Type Unit Characteristics Global Air Transportation Execution System (GATES)-Air GATES-Surface Cargo Movement Operations System Logistics Module
Marine Air Ground Task Force (MAGTF) Deployment Support System-II (MDSS-II)- Air
MDSS-II-Surface Transportation Coordinators’ Automated Info for Movement System II-(TC-AIMS II)-Air TC-AIMS II-Surface Cargo-Max USTRANSCOM Relational Data Management
Minor updates to conveyances limited to less than 2 hours of work do not count against the number of conveyance updates as listed above. Based on historical data, the Government anticipates approximately 10 minor updates each year.
System User Bugs will be provided to the contractor as System Problem Reports (SPRs) through SERENA™ Business Manager, to which the contractor CM shall have access. The Government will provide textual descriptions to define the functional and performance problems and business rules associated with the identified problem. SPRs are not enhancements. SPR fixes will be accessed in the same method as SCRs (reference Task 1.3.4).
1.3.3.1.2 Sustain Documentation.
The contractor shall sustain and update system documentation, to include database, system user, and software application documentation after each release. Documentation shall be reviewed in April and September by the Government to address any required changes; i.e., Known Bug Reports (KBR), CE Installation Guide, Desktop Installation and SA Guide, HHT Installation and SA Guide, and User Manuals. The contractor shall provide a KBR and application/installation guides NLT 5 business days prior to each code deliverable. The contractor shall provide a Quarterly Newsletter, no more than 2 pages shall contain a review of accomplishments, i.e., announcements, release notes, frequently asked questions for the quarter. The Quarterly Newsletter shall be updated and attached to the QSR for the Government PMO review.
The contractor shall be required to provide an After Action Report (AAR) after every outage to the Government PMO, to indicate start and stop time, reason for outage, and solution within 24 hours after action is complete. The contractor shall use the Enterprise Change Control Tool (CCT) to capture and automate system outages. The CCT is an application within Serena Business Management (SBM) with capabilities to capture the information for an outage and automate after-action reporting. A sample AAR is provided at (Appendix I).
Deliverable: AAR due NLT 24 hours after action is complete.
Deliverable: KBR due 5 business days prior to each code deliverable.
Deliverable: Application/Installation Guides due NLT 5 business days prior to each code deliverable.
Deliverable: Quarterly Newsletter due first business day in Jan, Apr, Jul and Oct.
1.3.3.2 Subtask 2: Disaster Recovery (DR) Environment/ Planning.
1.3.3.2.1 Maintain Disaster Recovery Environment.
The contractor shall complete all required application configurations to ensure the software is installed and configured correctly to operate at SDDC’s DR site. The DR site is located at a separate Government facility where the contractor shall access the system(s) remotely. The contractor shall install/configure application software at the DR site within one calendar day of installing/configuring the same software on the Production site to ensure operationally current software.
Deliverable: Software Install due 1 calendar day after installation/configuration at Production site.
1.3.3.2.1.1 On-site Contingency Support (Optional)
The contractor shall provide support to the Government during contingency or emergency operations IAW approved DR and contingency operations plans. The contractor shall ensure resources/key personnel are available throughout the planned/scheduled emergency IAW the established plan (see paragraph 1.3.2.2.3).
1.3.3.2.2 Disaster Recovery/Contingency Plan.
The contractor shall update the plan no more than twice a year and provide the plan to the Government PMO/COR for DR and/or contingency operations in coordination with the enterprise Disaster Recovery Exercise (DRE) solution and SDDC’s CCE. The DR/Contingency plan shall include: crisis emergency management (onsite and offsite) (technical and functional);
DR; pre and post emergency operations requirements; and fail-over management.
Deliverable: Update DR/Contingency Plan no more than twice a year within 10 days after notice received.
1.3.3.2.3 Exercise Operations.
The contractor shall participate in the bi-annual SDDC Directorate of Information Management (G6) DRE. The exercise is an opportunity to ensure the plan is executable. The contractor shall provide one technical and one functional participant in support of the system’s DR/Contingency plan. Exercises are conducted typically during a one-week period, during normal work hours, and no more than twice a year.
1.3.3.3 Subtask 3: System Support.
1.3.3.3.1 Contractor Development Environment.
The contractor shall provide a controlled and restricted facility to build, store and maintain the development network environment. The contractor’s development environment shall contain all developmental products and services, to include databases necessary to conduct development activities within the environment. The contractor’s development environment shall be locked down IAW Defense Information System Agency (DISA) STIGs and remain fully patched. The contractor will perform monthly scanning to check for patch compliance and will provide a patch compliance report to the programs IA Security Officer.
The contractor development environment shall be physically and logically isolated from other networks, to include its Enterprise unclassified network. Security guidelines for the environment must be documented and the security program implemented shall address the security controls described in NIST Special Publication 800-53 (current version), Recommended Security
Controls for Federal Information Systems and Organizations (http://csrc.mist.gov/publications/PubsSPs.html).
Deliverable: Patch Compliance Report due monthly.
1.3.3.3.2 Government Testing Environment.
The contractor shall support the Common Development Environment (CDE) (Quality Assurance) testing environment, to include, but not limited to tuning and performing backups, database tuning and backups, and system patching. The contractor shall work with the SDDC G6 IA staff to ensure compliance with current IA guidance (see PWS Task 1.3.6). The contractor shall be responsible for loading all application and COTS software within the testing environment.
1.3.3.3.3 Common Production Environment (CPE).
The contractor shall provide a support role to the Enterprise Integration Program EIP team in monitoring server and database performance, ensuring connectivity, and complying with all security and Certification and Accreditation (C&A) requirements in the Enterprise environments.
The contractor shall participate in enterprise change management processes. The contractor shall identify and document current and planned interface, data, software or technical changes. The contractor shall introduce proposed software, interface and technical changes to the contractor’s Configuration Manager for promotion and implementation of those changes (see PWS Task 1.3.4).
The contractor shall test and troubleshoot applications after CCE outages/upgrades, typically scheduled during non-duty hours. The contractor shall coordinate with the EIP team if they discover any issues after the outage. The contractor shall assist the EIP team to restart services to return the system back to normal operations. Typical CCE maintenance outages occur on alternating Sundays, usually twice each month.
1.3.3.4 Subtask 4: Tier II/III Help Desk Support.
The contractor shall provide Tier II/III help desk support 24X7, 365 days a year for emergency support and system outages. The contractor shall respond to Tier II/III trouble tickets generated by initial contact from Tier I helpdesk, managed by a separate contract. Once the trouble tickets are received, the contractor shall log problem status in to Siebel, the current SDDC ticketing database. The contractor shall provide the software licensing code generator to Tier I help desk for the purpose of tracking Oracle Personal database licenses. The contractor shall be responsible for all functional and technical helpdesk calls/notices received from Tier I. (The historical average is 78-111 monthly). The contractor shall respond to the initial request within one hour of notification by Tier I. The contractor shall record in Siebel the detailed resolution for the Tier I escalated ticket within 48 hours after initial receipt to the Tier II/III helpdesk; Tier II/III will provide enough detail for Tier I personnel to be able to resolve the same problem in the future without escalation. The contractor shall provide a System Problem Report with a http://csrc.mist.gov/publications/PubsSPs.html resolution strategy or a System Change Request for any tickets that cannot be resolved with 48 hours of initial notification to the Tier I help desk.
1.3.3.5 Subtask 5 Training.
The contractor shall provide training to the user community in the operation of the software suite of tools, necessary system support functions, as well as planning, re-planning, cargo staging, and yard management practices. All training other than user training is support for standardized training cycles for US Transportation School Students.
1.3.3.5.1 Maritime Software Training.
The contractor shall provide one instructor for a 2-week training course, (Course Number 8C- F26/822-F25) at the United States (U.S.) Army Transportation School, Fort Eustis, VA. The course scope is to create and deliver load plans including reports and diagrams imposed by SDDC. Students will use the Single Load Planner and related modules of the developed software to develop the load plans and perform related tasks. The contractor shall coordinate approval from the PM/COR/ACOR prior to conducting training. Course materials shall be provided by the Transportation School.
1.3.3.5.2 Basic Software Training.
The contractor shall provide one instructor for a 2-week training course, Basic (Course Number 8C-F44/553-F19) at the U.S. Army Transportation School, Fort Eustis, VA. The course scope is to create and deliver a basic understanding of the developed software. Students will become familiar with the reports and diagrams, imposed by SDDC, within all of the various modules of the developed software. The contractor shall coordinate approval from the PM/COR/ACOR prior to conducting training. Course materials shall be provided by the Transportation School.
1.3.3.5.3 Mobility Warrant Officer Basic Training.
The contractor shall provide one instructor for a 2-week training course, Mobility Warrant Officer Basic (Course Number 8C-882A) at the Technical Logistics College, Fort Lee, VA. The Contractor shall receive approval from the PM/COR prior to conducting training. Course materials shall be provided by the Transportation School.
1.3.3.5.4 User Training.
The contractor shall provide user training to the user community as determined by the Government. User training is special-requested training for specific users to accomplish their specific job. This is often in support of a deploying or a recently deployed unit. This may be CONUS or OCONUS and is by request. The contractor shall travel to CONUS or OCONUS locations to support such training. Training is typically 3 – 4 business days.
1.3.4 Task Area 4: Enhancements. (Labor Hour)
The contractor shall enhance the software based on System Change Requests (SCRs) as coordinated by the Program Management Office.
The Government will require SCR development for regulatory or emerging requirements. SCR releases’ labor effort shall be allocated under Task Area 4 and include requirements analysis, design, development, development testing, documentation, support for Government testing, and installation support for ICODES-V7. Task Area 4 enhancements will be priced as Labor Hour.
The Government will provide the contractor requirements through SERENA™ Business Manager, to which the contractor CM shall have access. The Government will provide textual descriptions to further define the functional and performance requirements and business rules associated with the business processes and process tasks.
The contractor shall provide the Government a proposal, breaking out the labor categories, rates and number of hours estimated to accomplish the SCR task as well as a proposed project schedule no later than ten (10) business days after the Government’s request to provide solutions for SCRs. The project schedule shall include proposed delivery dates for a Requirements Traceability Matrix (RTM), test cases, and design documentation updates. The contractor shall provide three (3) work days of Government Acceptance Testing (GAT) support.
The contractor shall deliver the Software Version Description (SVD) for each SCR development software release.
The contractor shall deliver the Software Product Specification (SPS) for each SCR development software release.
The contractor shall deliver to the Government all non-COTS (i.e., Java, PL/SQL, XML, etc.)
developed source code, libraries, developed CIs, a build/install checklist, a revised Deployment Guide, and a revised Installation and System Administration (SA) Manual upon delivery of each software release. The Government maintains the right to review or request source code, libraries, development CIs, or architecture artifacts in draft at any time.
The design documentation updates shall be incorporated into the associated document deliverables with the next scheduled software release. The approved project schedule shall be incorporated into the existing project schedule.
Enhancements – SCRs. Historical information: FY14 resulted in 40 SCRs implemented in one release with 10,258 labor hours.
The contractor shall use the following CDRLS for the associated deliverables:
Deliverable: Price Proposal CDRL: N Deliverable: Proposed Delivery Dates CDRL: O Deliverable: Test Steps and Cases CDRL: P Deliverable: Design Documentation Updates CDRL: G Deliverable: Software Version Description (SVD) CDRL: Q
Deliverable: Software Product Specification (SPS) CDRL: R Deliverable: Non-COTS Software CDRL: J
1.3.4.1 Subtask 1: Enhance Capabilities.
Automated information systems require changes as functional requirements and operations change. Upon coordination from the Government PM, the contractor shall develop new solutions for the user community, to include custom databases, new/updated interfaces, web pages, reports, and applications to streamline or supplement SDDC business processes. The contractor Project Manager shall participate via teleconference, in the monthly Information Needs Meeting, with the COR/ACOR and the Government PMO to review the status of all ongoing updates, repairs and changes to existing capabilities and discuss and validate new workflow solutions using the CCB priorities to track. SDDC stakeholders and the Government PM will identify high priority projects via a software change request form, for development evaluation. The Contractor shall provide a price proposal, break out the labor categories, rates and number of hours to accomplish the task. Upon acceptance of a valid Contractor proposal, the Government will process a modification to the contract.
Contractor shall develop and test more complex changes/projects to be implemented in two yearly software version releases. The milestone schedule shall reflect expected release dates of routine and complex changes.
The contractor shall design, develop and implement secure applications and configurations IAW current DoD guidance. Refer to PWS task 1.3.6 for a description of the IA tasks required for this effort.
Changes to applications may include, but is not limited to, additional data sources (interface partners), additional reports to support new customer-base, migration of capability from other programs to eliminate duplicative efforts, and new capabilities based on COTS upgrades or business needs. Typical routine (minor) changes include changes to Attributes, Associations, Buttons, Defaults, ICONs, Displays, Templates, Reports, and Wizards.
Changes that are more complex may include new interface partners or new capabilities that require significantly more resources to deploy
1.3.5 Task Area 5: Configuration Management.
The contractor shall provide configuration management support for the program. The contractor’s configuration management processes shall complement the Government’s configuration management processes. The Government PMO will assign a GCM to work closely with SDDC’s G6 Enterprise Configuration Manager. The GCM will work closely with the contractor to execute the contractor’s configuration management activities.
1.3.5.1 Subtask 1: Configuration Management Planning.
The contractor’s Configuration Manager (CM) shall provide input to the Configuration Management Plan (CMP) and processes that are consistent and complement the Government’s Configuration Management processes. The CMP includes but is not limited to the following:
• Developer’s configuration management processes/procedures
• Methods, procedures, and controls
• Baselines (versioning)
• Change control
• Configuration status accounting
• Configuration Management Repository (Dimensions will be the delivery repository for source code prior to deployment-Government will provide network connection) NOTE:
Dimensions is the current delivery repository for source code. In the future, the delivery repository for Windows applications will be Team Foundation and UNIX applications will be Subversion.
• Configuration Management Process
1.3.5.2 Subtask 2: Change Control.
The contractor’s CM shall provide change control for all baselines and configuration items to include documentation, hardware, COTS software, application, source, and executable code.
The Government will provide the contractor with web access to the SDDC Enterprise CCT, currently supported by SBM software. The Government’s CCT is a tool shared by the Government PMO staff and the contractor staff and is programmed to support the configuration management process; it is hosted within the CCE. The contractor shall update the configuration management processes within the tool. The contractor shall comply with G6 configuration management standards and processes as documented within and SDDC G6 Enterprise CMPs.
The contractor shall evaluate all SCRs and SPRs. Evaluations shall include, but not limited to;
requirement clarification, requirements analysis, determination if the requirement is feasible, level of effort, adherence to standards, training impacts, and the consequences of the proposed change or identified problem. This information shall be provided to the Government for evaluation via the CCT and/or as a separate document depending upon the amount of information required or provided. This evaluation will assist the Government PMO staff and the contractor to determine how many, and which, change requests and problem fixes shall be rolled into each release, and will help to determine dependencies within the software development cycle. In general, all SPRs will be expected to be fixed in the next version or an immediate patch, depending on the severity
1.3.5.3 Subtask 3: Configuration Control Board (CCB).
The contractor’s CM shall participate in the Government’s CCE CCB, hosted by the SDDC General Staff for Communications and Information Technology (G-6). The contractor’s Configuration Manager shall be the liaison between the Government and contractor to provide additional information the CCB requires. The contractor shall participate in a weekly CCE CCB meeting lasting no more than one hour. The contractor shall keep activities focused in areas the
Government determines important, and the contractor shall ensure changes within the Government’s CCE are properly vetted across all affected programs.
1.3.5.3.1
The contractor shall participate in program level CCB meetings, hosted by the PMO. The CCB is held twice a year with teleconferences. The contractor shall analyze new requirements prior to the meeting and provide information to the Government PMO in order to prioritize program level requirements. This analysis shall be captured in the CCT. The Government PM and the CCB will determine the priority for all changes to be included in any scheduled release cycle.
1.3.5.4 Subtask 4: Base-lined Source Code.
The contractor shall provide installation guide(s) to the Government PMO for installing base-lined code to the CCE’s Common Testing Environment (CTE). The EIP team will use the installation guide(s) to deploy within the Enterprise Environments. The contractor shall assist the EIP with all releases for successful installation of the software. The contractor shall store base-lined code within SDDC’s enterprise software for versioning control prior to CTE release.
Currently, the Enterprise uses Serena Dimensions to store Source Code. The contractor shall have zero major defects (reference Task 1.3.2.4) on the base-lined software released to Production. The contractor shall ensure IA requirements are applied as detailed in PWS Task 1.3.6.
Deliverable: Base-lined source code due prior to code release to staging environment.
Deliverable: Code installation guides due prior to code release to staging environment.
Deliverable: Software Changes estimated to be due twice a year.
1.3.5.4.1 Software Release Notes.
The contractor shall prepare software release notes for each patch/release and present the release notes to the Government at the time of software delivery. The software release notes shall include all applications and shall be issued for all patches and releases. In each software release note, the contractor shall identify each SCR and System Problem Report number and provide a description of the change.
Deliverable: Software release notes due 3 days prior to release to production environment.
1.3.6 Task Area 6: Information Assurance (IA).
The contractor shall work with the Government and contractor IA team as designated within SDDC to provide and share system security data and program information.
1.3.6.1 Subtask 1: Requirements for Contractor Provision of Security Plan, IA Controls.
The contractor shall establish an IA Program to implement and sustain appropriate IA management, operation, and technical controls and processes required to safeguard DoD non-public information resident on or transiting the contractor’s unclassified information systems from unauthorized access and disclosure. Protection measures applied must be commensurate with the risks (i.e., consequences and their probability) of loss, misuse, unauthorized access, or modification of information. The contractor shall submit for Government approval an overarching security plan that describes their strategy for implementation of IA and Industrial Security requirements throughout the life of the contract. The security plan shall address the security controls described in National Institute of Standards and Technology (NIST) Special Publication 800-53 (current version), Recommended Security Controls for Federal Information Systems and Organizations (http://csrc.mist.gov/publications/PubsSPs.html), and should be tailored in scope and depth appropriate to the effort and the specific unclassified DoD information. The contractor shall submit an updated security plan as changes are made to the environment that may affect the security posture.
Deliverable: Draft security plan due 15 months after performance start then as needed.
Deliverable: Final security plan due 17 months after performance start then 2 months after a new draft plan is submitted.
1.3.6.2 Subtask 2: Accreditation Sustainment.
The contractor shall provide program specific input for the development of new application security documentation and the updating of existing application security documentation to facilitate the security accreditation of the system IAW the current C&A guidance (current guidance is DoD Instruction (DoDI) 8510.01 DoD IA C&A Process (DIACAP) – will be migrating to NIST Risk Management Framework model). The contractor shall sustain the application and its environment in compliance with the DISA STIGs. The results of the DISA STIG documentation shall reflect the current status of the system; contractor shall provide monthly updates. The contractor shall provide updates to existing C&A documentation, such as network diagrams, ports and protocol matrix, application certification package created during release cycle, and other existing documentation. This documentation is required when changes are made that may affect the security posture of the application environment. The contractor shall provide a monthly update, NLT the last business day of the month to the Government PMO for the application’s DIACAP Plan of Action and Milestones (POA&M). POA&Ms are maintained within the Enterprise Mission Assurance Support Service by the Government.
Deliverable: Draft Network diagram, ports, protocol matrix, and certification package due 15 months after start of the contract, then after changes to environment are discovered.
Deliverable: Final Network diagram, ports, protocol matrix, and certification package due 17 months after start of the contract, then after changes to the environment are discovered.
Deliverable: POA&M updates due NLT last business day of each month.
1.3.6.3 Subtask 3: Periodic Government Inspections.
The contractor shall authorize Government inspections and reviews to assure compliance with DoD IA requirements throughout the contract performance period. The contractor shall be responsible for taking corrective action based upon the impact and severity of identified weaknesses.
1.3.6.4 Subtask 4: Remote Access.
Contractor-furnished Equipment (CFE) employed for remote access to a Government network must meet equivalent Government-furnished equipment IA (cyber security) computing requirements. The contractor shall ensure that all CFE (hardware and software) employed to access these environments meet the following minimum Government IA (cyber security) requirements and provide periodic certification of compliance as a pre-requisite to being granted network access.
• Use of personally owned systems is prohibited
• Operating systems and applications must be configured for compliance with the DISA
Gold Disk and applicable STIGs
• DoD-approved anti-virus and anti-spyware software must be installed and signatures must be configured to automatically update on a daily basis
• DoD-approved personal firewall must be utilized and configured to permit traffic by exception only, dropping all other traffic. If the host-level firewall provides intrusions detection or prevention, the signatures or rules must be updated at the same intervals as the anti-virus software
• Computers must be IA Vulnerability Management compliant
• Computers must be scanned with the DoD version of E-eye Retina vulnerability scanner
(or current approved DoD scanner solution) at a minimum of every 30 days. All vulnerabilities must be remediated and reported to the cognizant IA Manager
• Contractor employees must possess a current Government-issued Common Access Card (CAC) and install Government-certified CAC readers
• Verification of compliance with these requirements must be provided to an appointed Government representative (COR/ACOR) on a monthly basis.
Deliverable: Email verification of remote access requirement due NLT last business day of each month.
1.3.6.5 Subtask 5: Detect, Analyze, Respond.
1.3.6.5.1 Reporting Requirements.
The contractor shall report to the USTRANSCOM…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .