ID04160049_PWS_FINAL_11_18_2016_Rev_2.docx

DOCX document 128 KB Posted

Attached to
myPers Federal contract opportunity
Solicitation number
ID04160049
Issued by
General Services Administration Federal Acquisition Service Assisted Acquisition Services

About this file

PWS myPers

View the file

Other files for this federal contract opportunity

Other files attached to myPers, newest first.
File Type Posted
ID04160049_JA_12142016_Redacted.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

General Services Administration Federal Acquisition Service Assisted Acquisition Services Division Southeast Sunbelt Region Atlanta, GA 30308

Contract No.: ID04160049

PWS Date: November 18, 2016 GSA Senior Contracting Officer:

Faith Shelton Phone: (404) 215-8777 Email: faith.shelton@gsa.gov

GSA Customer Account Manager (CAM):

Patti Slay

Phone:(404) 331.0231
Email:patti.slay@gsa.gov

Client Organization:

Air Force Personnel Operations Activity (AFPOA) 1960 1st Street West, B977 JBSA

RAFB, TX 78150-4453

Primary Client Representative/COR Keith L. Kent Air Force Personnel Operations Activity (AFPOA) DSN 665-4645 Comm: 210.565.4645 Keith.kent.1.@us.af.mil

Alternate COR:

Trudy Bussey, Civ, DAF myPers Program Management

COMM:(210) 565-5206 DSN: 665-5206

Project Name:

myPers Period of Performance:

Basic Period: 12/01/2016 - 11/30/2017 Option Year 1: 12/01/2017 - 11/30/2018 Option Year 2: 12/01/2018 - 11/30/2019

Contract Type:

Funding:

☒
Firm Fixed Price
☒
Severable
☐
Labor Hour
☐
Non-Severable
☐
Time and Material
☐
Hybrid
☐
Fully Funded
☒
Performance-based
☒
Incrementally Funded

Vehicle:

Competition:

☐
MAS Schedule
☐
Competitive
☐
GWAC Alliant
☒
Noncompetitive
☐
GWAC Alliant SB
☐
GWAC VETS
☐
GWAC 8a STARS II
☐
GWAC (Other) *NETCENTS-2, AF
☒
Open Market
1.0 Introduction
Attachment A, FAR Clauses, Supplements & Executive Orders
Attachment F, Acronyms
2.0 Scope
Attachment B, Non-Personal Services
Attachment G, Performance

Requirements Summary

(PRS)

3.0 Performance Requirements
Attachment C, Invoice Requirements
Attachment H, Quality Assurance Surveillance Plan (QASP)
4. Contract Deliverables
Attachment D, Quality Control

and Acceptance Attachment I, Cybersecurity Requirements

Attachment E, Organizational Conflict of Interest (OCI)

CONTRACT MODIFICATIONS: (Listed in Descending Order)

Amendment #1 dated 11/28/16
Attachment G, Performance Requirements Summary (PRS) Updated matrix and 7.6. Suitability Investigations - AFMAN 17-1201 User Responsibilities and Guidance for Information Systems, DATA SECURITY REQUIREMENTS - AFI 17-130 Information Assurance (IA) Management and AFMAN17-1301 COMPUSEC

Introduction: Work is to be accomplished for the United States Air Force, Air Force Personnel Operations Activity (AFPOA), JBSA Randolph AFB, and Texas, herein referred to as Client, through the General Services Administration (GSA), Federal Acquisition Service (FAS), Southeast Sunbelt Region.

1.0 Background. The United States Air Force Total Force Service Center (TFSC) implements programs covering all aspects of the personnel lifecycle, including accessions, education and training, assignments and deployments, promotions, evaluations, retirements, and separations for United States Air Force military and civilian personnel. TFSC employs a diverse workforce of Air Force active military, civilian, guard, and contractor staff responsible for personnel programs, policies, and operations for military, civilian, and retirees worldwide.

myPers is the solution for the Total Force (TF) A1 community that is providing a Customer Relationship Management (CRM) software platform for personnel knowledge, business processes, transactional services and front end web facing/platform. This acquisition will continue current case management operations on the existing approved Federal Risk and Authorization Management Program (FedRAMP) Level 4/5 commercially-owned Department of Defense (DoD) Cloud.

myPers platform unifies the Air Force Personnel Center (AFPC) and Air Reserve Personnel Center (ARPC) in an approved facility that maintains the following:

Total Force Usability: Total Force personnel services on a single instance of software.

Total Force Web that provides access to the Total Force Knowledge Base and CRM Data Model: Total Force Airmen access personnel knowledge and services.

The myPers platform includes capabilities such as:

· Web Self Service

· Chat

· E-mail Management

· Case Management

· Interaction Management

· Incident Collaboration9

· Government Configurable Capabilities

· Policy Automation

· Knowledge Management

· Knowledge Base

· Reporting Capability/Analytics

NOTE: From this point forward, “myPers CRM Platform” is all encompassing of the above mentioned capabilities unless specifically noted otherwise.

2.0 Objective.

· Continue case management operations that support myPers on a commercially-owned DoD Cloud

· Sustain and maintain software and hardware licenses

· Provide education and training with the delivery and sustainment of the current application

· Administer and maintain the myPers Platform

· Maintain Commercial Cloud Services Terms and Conditions See Section 9

· Maintain the Total Force Policy Automation Services

· Ensure regularly scheduled software updates and assistance/expertise in their execution

· Provide the necessary assistance to the government for incorporating system/product enhancements

3.0 Scope. The following are within the scope of this project:

3.1 Application Sustainment, Hosting and Maintenance

Sustain all contractors delivered application code for the myPers CRM platform

3.2 CRM Administration

Maintain services to assist the Government in the management, monitoring, and administration of the CRM platform Incidents will be managed in accordance with the Customer Care Package. See Service Summary Section 8.

3.3 Project Management

Ensure successful sustainment, hosting and maintenance of the myPers CRM platform by providing overall management support for the individual projects to ensure they all move together toward meeting the Total Force (TF) overall goals Proactively manage and monitor the delivered solution, identify, assess and mitigate risks, provide regular status reporting to the Directorate of Information and Technology (DP0) and TF management, participate in reviews, identify new initiatives and enhancements, and ensure ongoing quality assurance Facilitate any change management process associated with the maintenance and sustainment of the myPers CRM platform

3.4 FUNCTIONAL ARCHITECTS (Unfunded/Optional CLIN 008)

On site Functional Architects will review the current systems, processes, applications, and architecture assessing the capabilities. Additionally, architects will construct designs and recommendations to streamline processes, improve functional capabilities, automate workflows, and provide techniques for the real-time integration of applications using industry best practices and open standards.

NOTE: This CLIN is currently unfunded and unpriced. In the event this position is deemed necessary a fully negotiated modification will be executed to add this position to the task order.

3.5 USABILITY STUDY (Unfunded/Optional CLIN 009)

Web Design and Configuration

· Perform a comprehensive myPers web Usability Study that incorporates newest web design features and takes advantage of all current upgrade capabilities

· Include review of desktop and mobile applications and/or solutions across the AF/A1 enterprise that focus on self-service capability or place emphasis on Tier 0 applications, or assist in enhancing field HR professional’s ability to process transactions.

· Study should leverage expert knowledge of system capabilities and configuration options to maintain efficiencies through automation that meet transactional workflow processing and ease of use.

NOTE: This CLIN is currently unfunded and unpriced. In the event funding becomes available a fully negotiated modification will be executed to add this item to the task order.

4.0 ROLES AND RESPONSIBILITIES

4.1 Detailed below are the Government roles and responsibilities for the sustainment of the CRM platform:

Participate in maintenance and sustainment steps, provide and coordinate participation of Government points of contact to provide access to subject matter expertise

Work with key implementation stakeholders to assess risks, prioritize activities, and validate and institute any policy changes resulting from approved “To-Be” improvements

Identify and oversee stakeholders tasked with completing maintenance, sustainment and application enhancement activities

Adopt a timely and effective issue resolution process such that any issue can be resolved in accordance with the Project Plan and the Change and Configuration Management Plan

Approve test scenarios/cases associated with maintenance and sustainment activities

Assist as required when outside activities/interfaces/ integration affect the overall functionality of the CRM platform

Perform User Acceptance Testing in a test environment in accordance with the Test Plan and User Acceptance Test Cases

Authorize deployment of features associated with sustainment and maintenance activities

Ensure all data integrated with the application is in the proper format before it is integrated

Approve any administrative or enhancement recommendations

Prioritize implementation activities and validate and institute any policy changes resulting from approved recommendations

Submit myPers CRM Platform “Break/Fixes” to the Contractor Customer Care

Provide process for requesting authorization of travel

Approve all travel authorizations prior to travel being conducted

Finalize and approve the “to-be” data model and field mapping for data import and data migration

Identify data elements and records to import and migrate to the hosted version

Perform work on the solution including the cleanup of data elements to support the “to-be” data model

Adopt a timely and effective deliverables approval process such that any approval of deliverables (draft and final) can be obtained within ten (10) business days from the date of delivery, or in accordance with the Project Plan

Support Contractor in performing multiple data migration and data import runs (setup, initial, final)

Ensure that the system and database on the current environment are configured correctly and that database integrity has been maintained

Approve the Functional Requirements & Design Document(s)

Make available or develop web services, XML, and/or Simple Object Access Protocol (SOAP) based Application Programming Interface (API) for the integration with Air Force systems

4.2 Detailed below are the Contractor roles and responsibilities for the maintenance, sustainment and hosting of the delivered myPers CRM platform:

Schedule and conduct routine maintenance

Ensure adequate and timely notification to the Government for personnel notification

Notify the Government for maintenance items such as hotfixes and service packs to the Contractor applications

Notify the Government for changes made by the System Administrator

Notify the Government for routine maintenance on infrastructure/architecture systems

Ensure all hosting hardware and software meets the needs of the government at all times

Ensure system software vulnerability to include scans to protect, prevent, mitigate, eliminate, report any and all threats

Provide regular status and metric reporting on all PWS tasks and associated system capabilities as approved by the Government

Proactively assess Customer impact of all delivery functions

Monitor Incident traffic to ensure commitments are met and appropriate resources are dedicated to issues based on severity

Coordinate cross-functional teams for unscheduled work

Ensure on-time delivery of Contractor commitments to Customers

Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30. While inputs may be reported any time during the FY, all data shall be reported no later than October 31 of each calendar year, beginning with 2016. Contractors may direct questions to the help desk at help desk at: http://www.ecmra.mill

Configure data mapping details documented in the design document(s)

Write User Acceptance Test Cases in accordance with the Test Plan

Validate government acceptance of data mapping and data import and data migration activities

Schedule and conduct functional design validation session(s)

Schedule and conduct technical design validation session(s)

Validate government acceptance of Technical Requirements and Design Document(s)

Escalate the approval of the deliverables when approvals and/or comments on deliverables in not obtained within five (5) business days from the date of delivery, or in accordance with the Project Plan unless otherwise directed by the Government

Perform quality assurance (QA) testing

Ensure Internet Protocol Version 6 (IPv6) Compliance. Reference NIST 500-267 and NIST 500-281 for additional guidance on IPv6 requirements. A Supplier's Declaration of Conformity (SDOC) is required, as outlined in the two previous NIST documents. The template for the SDOC can be found at the following URL: http://www-x.antd.nist.gov/usgv6/sdoc.html." as per FAR 11.002 (g).

The contractor shall provide a secure, alternate facility, which is located in Phoenix, Arizona and more than 100 miles away from the hosting site. The facility shall be connected through an approved DISA Cloud Access Point (CAP) to DoD NIPRNET (.mil), and equipment and support personnel shall be provided when notified, by the Air Force Continuity of Operations Plan (COOP) Recovery Coordinator or designated representative, of a declared computer operations disaster and during scheduled tests or exercises. The contractor will utilize the Contractor Recovery Services, including the in-place hardware and equipment, as the alternate facility. If the hosting facility is not available, or the contractor desires use of another facility as the secure, alternate computer facility, then the alternate facility must be FedRamp Impact Level 4/5 facility to operate that facility, to include the hardware and equipment requirements.

4.3 Customer Care Support - Customer Liaison

The contractor shall be responsible:

Drives Root Cause Analysis (RCA) process to make both organizations stronger

Proactively communicate software upgrades/updates and benefits with an appreciation for Customer’s business environment

Ensures smooth transition of delivery activities

Involved in / aware of change management

Queue Monitoring / Management

5.0 GOVERNMENT FURNISHED PROPERTY

The Government will provide, when necessary for the performance of this PWS the following:

Internet access for resources that pertain to supporting the project where WIFI is accessible on government installation.

Air Force Personnel Operations Activity (AFPOA), Air Force Personnel Center (AFPC) and Air Reserve Personnel Center (ARPC) physical locations as required.

The Contractor shall maintain accurate control and accountability of any and all Government Furnished Property/Equipment in accordance with terms and conditions of this contract.

Damage to government property that is caused by the contractor shall be governed by the applicable property clauses in the Federal Acquisition Regulations and its associated supplements as required.

6.0 Travel and expenses (CLIN 004). The Contractor shall be required to perform Government approved travel within the Continental United States (CONUS). Prior to travel the Contractor shall coordinate with and receive Government authorization from the COR for all travel, without approval travel is not valid and reimbursement will be denied unless the parties determine otherwise. The Government shall provide the process and templates required for authorization of travel. The Contractor shall be responsible for obtaining all passenger transportation, lodging, and subsistence. Reimbursement of CONUS travel costs shalll be in accordance with the Federal Travel Regulations per FAR 31.205-46. The Contractor shall travel using the lowest cost mode transportation commensurate with the mission requirements. When necessary to use air travel, the Contractor shall use the tourist class, economy class, or similar lodging accommodations to the extent they are reasonably available and commensurate with the mission requirements. Travel will be reimbursed on a cost reimbursable basis; no profit or fee will be paid.

Note: ALL travel requests should be issued via GSA ASSB/ITSS Action Memo for request and approval. The Joint Travel Regulation (JTR) applies to OCONUS travel.

Travel Budget Total = $75,000 – Break out as follows:

Base Year - $25,000 Option Year 1 - $25,000 Option Year 2 - $25,000 Six Month Extension - $12,500

7.0 SECURITY REQUIREMENTS

This requirement may involve classified information and is therefore a classified acquisition. Contractor personnel shall possess a current and valid security clearance before operating workstations that have access to Air Force networks. These investigations shall be initiated and funded by the contractor, and submitted by the Government.

The Contractor shall comply with the DoD 5200.2-R, Personnel Security Program, and AFI 33-119, Electronic Mail (E-Mail) Management and Use, requirements. DoD Contract Security Classification Specification form (DD254) will be required for authorized administrators (i.e., database administrators, incident responders). The software will be hosted on a DoD environment at a commercial facility and must comply with DoD Information Assurance policies and directives as identified in Attachment I. The contractor shall ensure a secure means of communication is available for the purpose of reporting a classified spillage.

Freedom of Information Act Program (FOIA). The Contractor shall comply with DoD Regulation 5400.7-R/Air Force Supplement, DoD Freedom of Information Act Program, requirements. The regulation sets policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding For Official Use Only (FOUO) material. The Contractor shall comply with AFI 33-332, Air Force Privacy Act Program, when collecting and maintaining information protected by the Privacy Act of 1974 authorized by Title 10, United States Code, and Section 8013. The Contractor shall remove or destroy official records only in accordance with AFMAN 37-139, Disposition of Records—Standards, or other directives authorized in AFI 37-138, Records Disposition—Procedures and Responsibilities.

Additional Security Requirements. In accordance with DoD 5200.1-R and AFI 31-401, the Contractor shall comply with AFI 33-202, Computer Security; AFI 33-203, Emission Security (EMSEC) Program; AFI 33-204, Information Protection Security Awareness, Training, and Education (SATE) Program; applicable AFKAGs, AFIs, and AFSSIs for Communication Security (COMSEC); and AFI 10-1101, Operations Security (OPSEC) Instructions. The Contractor will comply with DOD Standard 22 – Level 1 AT Awareness training and associated tasking IAW AFT 10-245, Antiterrorism Program standards

7.1. Visitor Group Security Agreement (VGSA). The contractor shall enter into a long-term visitor group security agreement if service performance is on base. This agreement shall outline how the contractor integrates security requirements for service operations with the Air Force to ensure effective and economical operation on the installation. The agreement shall include:

a. Security support provided by the Air Force to the contractor shall include storage containers for classified information/material, use of base destruction facilities, classified reproduction facilities, use of base classified mail services, security badging, base visitor control, investigation of security incidents, base traffic regulations and the use of security forms and conducting inspections required by DoD 5220.22-R, Industrial Security Regulation, AFPD 16-14, Security Enterprise Governance, and Air Force Instruction 16-1406, Air Force Industrial Security Program.
b. Security support requiring joint Air Force and contractor coordination includes packaging classified information, mailing and receiving classified materials, implementing emergency procedures for protection of classified information, security checks and internal security controls for protection of classified material and high-value pilferable property.
c. On base, the long-term visitor group security agreement may take the place of a Standard Practice Procedure (SPP).

7.2. Obtaining and Retrieving Identification Media. As prescribed by the AFFAR 5352.242-9000, Contractor access to Air Force installations, the contractor shall comply with the following requirements:

a. The contractor shall obtain base identification and vehicle passes for all contractor personnel who make frequent visits to or perform work on the Air Force installation(s) cited in the contract. Contractor personnel are required to wear or prominently display installation identification badges or contractor-furnished identification badges while visiting or performing work on the installation.

b. No later than three working days prior to contract commencement, the contractor shall submit a written request on company letterhead to the program manager listing the following: contract number, location of work site, start and stop dates, and names of contractor employees needing access to the base. The authorized program manager will endorse the request and forward it to the issuing base pass and registration office or security forces for processing. Contractors will present government (state or federal) issued ID, and INS Form 9 (I9), before being issued a pass to enter the installation. Before being issued a pass to enter the installation, a Wants and Warrants check will be conducted for every individual requesting a pass. Personnel employed by the contractor must get a pass for their privately owned vehicles at the installation Visitor Reception Center, with proof of following:
(1) Liability Insurance
(2) Current License Plates
(3) Current State Inspection Sticker (If Required)
(4) Valid State Driver License
(5) A phone number for sponsor on base
c. Vehicles owned by the contractor with the company name permanently printed on them are not required to obtain a pass as long as a current work order is presented at the time of entry. However, current liability insurance, state inspection sticker, and registration is required. The person driving the vehicle must have a valid operator license for the type of vehicle.
d. The contractor is responsible for ensuring employees report to Visitor Reception Center, to present their Form I-9 (Employment Eligibility Verification).

e. Upon completion or termination of the contract or expiration of the identification passes, the contractor shall ensure that all base identification credentials issued to contractor employees are returned to the issuing office. If a contractor employee has been terminated, the credentials will need to be retrieved and returned to issuing activity so that employee does not have base access. If the credential is not retrieved then SF will need to be notified so base access is not allowed.

f. Failure to comply with these requirements may result in withholding of final payment.

7.3. Pass and Identification Items. The contractor shall ensure the following pass and identification items required for service performance are obtained for employees and non-government owned vehicles:

a. Installation Access Pass (IAP) (DBIDS), Visitor/Vehicle Pass (AFI 31-113), used for contracts for less than six months to include one-day visits (i.e. warranty work).
b. Installation Access Card (IAC) (DBIDS), (AFI 31-113), used for contracts for more than six months or more.

c. DoD Common Access Card (CAC), (AFI 36-3026), used for contracts for more than six months and requirement exists for specific employees as identified by the government COR. CAC applications are accomplished by Trusted Agents via the Trusted Agent Sponsorship System (TASS).

7.4. Security Clearance Requirements. The contractor must possess or obtain an appropriate facility security clearance (Secret) prior to performing work on a classified government contract. If the contractor does not possess a facility clearance the government will request one. The government assumes costs and conducts investigations for Top Secret, Secret, and Confidential facility security clearances. The contractor shall request personnel security clearances, at the company’s expense, for employees requiring access to classified information within 15 days after receiving a facility clearance or, if the contractor is already cleared, within 15 days after service award. Due to costs involved with security investigations, requests for personnel security clearances shall be kept to the minimum amount employees required to perform contract requirements.

7.5. Listing of Employees. The contractor shall maintain a current listing of employees. The list shall include employee's name, social security number, and level of security clearance. The list shall be validated and signed by the company Facility Security Officer (FSO) and provided to the contracting officer and Information Protection Office (IP) office at each performance site 30 days prior to the service start date. Updated listings shall be provided when an employee's status or information changes. A Visit Request for all employees with security clearances is required to be sent through the Joint Personnel Adjudication System (JPAS), and must be updated at least annually. The contractor shall notify the IP Office at each operating location 30 days before on-base performance of the service. The notification shall include:

a. Name, address, and telephone number of company key management representatives.
b. The contract number and contracting agency.

c. The highest level of classified information to which employees require access.

d. The location(s) of service performance and future performance, if known.
e. The date service performance begins.
f. Any change to information previously provided under this paragraph.

7.6. Suitability Investigations. Contractor personnel not requiring access to classified shall successfully complete, as a minimum, a Tier 1 (formerly known as a NACI investigation), before operating government furnished workstations. The contractor shall comply with the DoD 5200.2-R, Personnel Security Program, AFMAN 33-152, User Responsibilities and Guidance for Information Systems, AFMAN 17-1201 User Responsibilities and Guidance for Information Systems and AFI 33-200, Cybersecurity Program Management, requirements. Tier 1 investigations requests are initiated using the Standard Form (SF) 85 and are submitted to the installation Information Protection Office through the using agency’s Unit Security Manager. Tier 1 investigations are different from the Wants and Warrants checks, and are provided by the government at no additional cost to the contractor.

7.7. Entry Procedures to Controlled/Restricted Areas. Contractor personnel requiring unescorted entry to areas designated as controlled or restricted areas by the installation commander shall comply with base access requirements and will possess, as a minimum, a favorable suitability determination. These requirements are contained in AFI 31-101, Integrated Defense, for installation access and AFI 31-501, Personnel Security, for suitability determinations. The contractor shall comply and implement local base procedures for entry to Air Force controlled/restricted areas. For on-base cleared facilities over-sighted by the base ISPM, contractors shall comply with the National Industrial Security Program Operating Manual (NISPOM), previously referred to as the Industrial Security Manual (ISM), to implement controlled/restricted area requirements. The IP Office shall approve the establishment, construction, and modification of all contractor designated controlled areas before they may be used to limit access.

7.8. Security Monitor Appointment. The contractor shall appoint a security representative for the on base long term visitor group. The security representative may be a full-time position or an additional duty position. The security representative shall work with the host organization to provide employees with training required by DoDM 5200.01, Information Security Program, and AFI 16-1404, Air Force Information Security Program. The contractor shall provide initial and follow-on training to contractor personnel who work in Air Force controlled/restricted areas. Air Force restricted and controlled areas are explained in AFI 31-101, Integrated Defense.

7.9. Additional Security Requirements. In accordance with DoDM 5200.01, Information Security Program and AFI 16-1404, Air Force Information Security Program, the contractor shall comply with applicable AFKAGs, AFIs, and AFSSIs for Communication Security (COMSEC); and AFI 10-701, Operations Security (OPSEC) Instructions. The contractor will comply with DoD Standard 22/Force Protection Condition Measures, DoD Standard 25/Level I-AT Awareness Training, and associated tasking contained in AFI 10-245, Antiterrorism (AT) standards. Level I AT Awareness training is available for contractor personnel and can be requested by calling the local installation AT Office.

7.10. Freedom of Information Act Program (FOIA). The contractor shall comply with DoD Regulation 5400.7-R/Air Force Supplement, DoD Freedom of Information Act Program, requirements. The regulation sets policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding For Official Use Only (FOUO) material. The contractor shall comply with AFI 33-332, Air Force Privacy and Civil Liberties Program, when collecting and maintaining information protected by the Privacy Act of 1974 authorized by Title 10, United States Code, and Section 8013. The contractor shall remove or destroy official records only in accordance with AFI 33-322 Records Management, or other directives.

authorized in AFI 33-364, Records Disposition—Procedures and Responsibilities.

7.11. Reporting Requirements. The contractor shall comply with AFI 71-101, Volume- 1, Criminal Investigations, and Volume-2, Protective Service Matters, requirements. Contractor personnel shall report to an appropriate authority, any information or circumstances of which they are aware may pose a threat to the security of DoD personnel, contractor personnel, resources, and classified or unclassified defense information. Contractor employees shall be briefed by their immediate supervisor upon initial on-base assignment and as required thereafter.

7.12. Physical Security. Areas controlled by contractor employees shall comply with base Operations Plans/instructions for FPCON procedures, Random Antiterrorism Measures (RAMS) and local search/identification requirements. The contractor shall safeguard all government property, including controlled forms, provided for contractor use. At the close of each work period, government training equipment, ground aerospace vehicles, facilities, support equipment, and other valuable materials shall be secured. During increased FPCONs, contractors may have limited access to the installation and should expect entrance delays.

7.13. Operating Instructions. For controlled areas used exclusively by the contractor, the contractor shall develop an Operating Instruction (OI) for internal circulation control, protection of resources and to regulate entry into Air Force controlled areas during normal, simulated and actual emergency operations. The OI shall be written in accordance with AFI 31-101, the local base Operations Plan usually referred to as an OPLAN and AFI 10-245, Air Force Antiterrorism (AT) Standards, and coordinated through the ISPM.

7.14. Key Control. The contractor shall establish and implement key control procedures in the Quality Control Plan to ensure keys issued to the contractor by the government are properly safeguarded and not used by unauthorized personnel. The contractor shall not duplicate keys issued by the government. Lost keys shall be reported immediately to the contracting officer. The government replaces lost keys or performs re-keying. The total cost of lost keys, re-keying or lock replacement shall be deducted from the monthly payment due to the contractor. The contractor shall ensure its employees do not allow government issued keys to be used by personnel other than current authorized contractor employees. Contractor employees shall not use keys to open work areas for personnel other than contractor employees engaged in performance of duties, unless authorized by the government functional area chief.

7.15. Lock Combinations. The contractor shall establish procedures in local OIs ensuring lock combinations are not revealed to unauthorized persons and ensure the procedures are implemented. The contractor is not authorized to record lock combinations without written approval by the government functional area chief. Records with written combinations to authorized secure storage containers or Secure Storage Rooms (SSR), shall be marked and safeguarded at the highest classification level as the classified material maintained inside the approved containers. The contractor shall comply with DoD 5200.1-R security requirements for changing combinations to storage containers used to maintain classified materials.

7.16. Traffic Laws. The contractor and their employees shall comply with base traffic regulations.

7.17. Healthcare. Healthcare provided at the local military treatment facility on an emergency reimbursable basis only.

8.0 SERVICE SUMMARY

PERFORMANCE STANDARDS

Area of Support
Deliverables
Schedule
Program Management
· Project Plan/Schedule (CDRL A001)

· Monthly Activity Report (CDRL A002)

· Travel Expense Tracker (CDRL A003)

· NLT 30 Days After Project Plan/Schedule is created by Contractor and agreed to by the Government, then as required Contract Award

· NLT 30 Days After Contract Award Monthly. Activity Report is created by Contractor and agreed to by the Government, then monthly

· NLT 30 Days After Travel Completion

CRM Platform Sustainment and Maintenance
· Technical and Functional Design Document Updates

· Configuration Control/Management Plan

· Routine Maintenance Schedule

· NLT 30 Days after Contract Award.

· NLT 30 Days following Government Approval

· NLT 30 Days After Contract Award

CRM Administration
· Management Dashboards

· Status Report/Analytics

· NLT 30 Days After Contract Award, then as required

· NLT 30 Days After Contract Award, then as required

Education Services
· Training Plan
· NLT 30 Days following Government Approval

PERFORMANCE STANDARDS

Area of Support
Performance
Standard
myPers CRM Platform Sustainment
· System availability

· Scheduled maintenance downtime

· See Definition of Performance Standards below

myPers CRM Administration
· Availability – maintenance

· Availability - break/fix

· 8 hours a day, 5 days a week, 52 weeks a year

· See Definition of Customer Care Package below

Disaster Recovery
If hosting site is declared a disaster, the contractor must make the disaster recovery facility and all contracted equipment/services available in the timeframes identified in the contract.

PERFORMANCE STANDARDS DEFINITIONS

Maintaining the “Customer Care Package” includes the elements identified below. This package does not include support for user defined configurations performed by Customer. This package does include support for user defined configurations performed by Contractor. The Customer Care Package is not available for Enterprise Analytics. Elements include:

Access to the Contractor knowledge base via the support portal Provision of the following support for version upgrades:

Communication of major release changes Support in the creation of upgrade test site General support of upgrade process questions via incident Kick off meeting to outline important upgrade topics Management of incidents submitted during upgrade test site stage (pre and post upgrade) Regularly scheduled status meetings Facilitation of successful User Acceptance Testing process utilizing Upgrade Checklist Upgrade Plan Contractor Project Manager available for post-upgrade assistance Cleared Personnel Unlimited email support – agent allocation based on pool Assigned Customer Care Specialist Phone support Severity 1 and 2: 24x7x365 Severity 3 and 4: 5x24 Business Days Customer Care Service Level Objectives based on table below

Description of Service
Severity Level
Action Steps
Availability
Response Time
Customer Care Service Level Objectives
Severity Level 1
Target Response
7x24X365
15 Minutes
Target Resolve
7x24X365
1 Hour
Target Refer
7x24X365
1 Hour

Severity Level 2

Target Response
7x24X365
4 Hours
Target Resolve
7x24X365
24 Hours
Target Refer
7x24X365
24 Hours

Severity Level 3

Target Response
5x24 Business Days
48 Hours
Target Resolve
5x24 Business Days
5 Business Days
Target Refer
5x24 Business Days
5 Business Days

Severity Level 4

Target Response
5x24 Business Days
72 Hours
Target Resolve
5x24 Business Days
10 Business Days
Target Refer
5x24 Business Days
10 Business Days
Customization Support
Support of Customizations (Integrations, Extensions) written by Contractor Professional Services (PS)

· Upgrade of Customizations (Integrations, Extensions) written by PS

· Requirements Document

· Test Plan Document

· Migration of Customizations

· QA Testing of Customizations against Test Plan

Application Availability
Application Availability acceptable quality limit of 98% (measured at the end of each calendar quarter) based on application availability or accessible by Air Force end users.
Hosting Availability
Hosting availability subject to Commercial Facility deliverables around the Mission Assurance Category (MAC) level three (III) systems, FedRAMP Level 4/5, and exclusively between the Customer and Air Force.

“Application Availability” means the number of minutes in a calendar quarter that Customer’s Support Home Page is available for normal business use by end users, expressed as a percentage of the total number of minutes in a quarter after subtracting the following from the total minutes: (i) minutes of outage during the quarter for maintenance performed by Contractor or for maintenance performed by its hosting partner the Contractor; (ii) minutes of outage during upgrades; (iii) minutes of outage during any interruption caused by a failure of the Internet, the telephone, the power supply, or the hosting environment and/or hardware controlled by Contractor; and (iv) minutes of outage caused by force majeure. Events that impact the application’s ability to provide services as a result of events within the Contractor enclave that impact the hardware solution are not eligible to be applied toward the Application Availability Target. “Business Day” means the 24 hour period for each day of the week excluding Saturday and Sunday, with the Business Day for Monday commencing at 12:00AM Monday and the Business Day for Friday ending12:00AM Saturday. Customer may choose to start its Business Day in one of seven time zones that are supported by Contractor. Supported time zones are GMT, GMT -5 (EST), GMT -6 (CST), GMT -7 (MST), GMT -8 (PST), GMT +9 (Tokyo), and GMT +11 (Sydney, Australia). All supported time zones will observe daylight savings time shifts as appropriate for the local area.

“Customer Care Specialist (CCS)” is a technically oriented project manager working in Contractor’s Customer Care organization. The CCS will provide accountability, internal customer advocacy, and customer focused management across departments in order to provide a holistic management structure for top accounts. The CCS will be designated to support multiple accounts as a shared resource.

· CCS’ responsibilities limited to:

“Email Support” allows the support contact to submit Incidents initially via the support page at crm.Contractor.com. Once submitted, further correspondence by the submitter on a given Incident may be conducted via email or via updates to the Incident via the support page at crm.Contractor.com. Incidents may not be initially submitted via email.

“Incident” means any request for technical assistance submitted to the Customer Care team. Technical assistance includes but is not limited to diagnosis of error messages, assistance with application crash or installation issues and application troubleshooting. Incidents that Contractor determines to be a result of a defect in the Contractor product or a hosting outage will be excluded from Customer’s number of Incidents. Technical assistance excludes training, customizations, business requirements analysis, configuration assistance (other than answering ‘how to” questions related to configuration), and hosting or hardware assistance. Customer Care will route those requests to the appropriate Contractor resource.

“Severity Level 1” means the production use of the solution has stopped, or application performance has been so severely impacted that work cannot reasonably continue. Examples of Severity Level 1 include:

· The end-user pages are inaccessible from the Internet

· All or the majority of agents are unable to access the administrative console for their job function

· A service channel (e.g. e-mail, voice, chat) is not functioning

· Access to core functionality within a console is so impaired that agents cannot work (e.g. Analytics does not work, Marketing campaigns cannot be launched, critical views not populating, all rules not functioning)

NOTE: It is a general principle that we do not accept Severity Level 1 for non-production sites. Exceptions to this principle, which need to be explicitly stated during Incident submittal, include:

· If the issue found on the upgrade site is going to negatively impact or cause the cut over to fail or become a high severity issue in production

· If Customer has integrated test sites into their production environment to facilitate their business processes then the test sites need to be treated as production sites.

“Severity Level 2” means important product features are unavailable with no acceptable workaround. Production use of the solution is continuing; however, there is a serious impact on productivity or service levels. Examples of Severity Level 2 include:

· An integrated custom tab is failing, causing agents to access the integrated data from another application, thereby slowing down response time substantially

· One or a small percentage of agents are consistently unable to access the agent desktop

· An issue is causing properly constructed rules to fail causing agents to manually route incidents

· An issue is causing deflection rates to decrease substantially

“Severity Level 3” means important product features are unavailable but a workaround is available, or less significant product features are unavailable with no reasonable workaround. Work has a minor loss of operational functionality, or implementation resources. Examples of Severity Level 3 include:

· Agedatabase utility is behind causing some cached reports to display incomplete data sets

· Open Database Connectivity (ODBC) Replication is behind

· A small percentage of agent workstations are experiencing periodic errors

· Bold tags are not rendered properly in answers

“Severity Level 4” means requests for information (how to), enhancements or documentation clarification regarding the product, but there is no impact on daily operation of the solution. The implementation or production use of the solution is continuing and there is no work being impeded at the time. Examples of Severity Level 4 include:

· An application message is misspelled

· A request for a new feature

· A single, non-reproducible application crash

· How to configure or set up features in the product

“Support Home Page” means the entry page on the end-user interface in Contractor Service that contains links leading to main functions.

“Target Response” means an objective to provide notification by Contractor to Customer within the stated timeframe.

“Target Resolution” means an objective to provide a permanent workaround or solution by Contractor within the stated timeframe.

“Target Refer” for Incidents submitted by Customer that involve the operations provided by Contractor, “Target Refer” means an objective to provide notification by Contractor within the stated timeframe.

“Incident Handling”: Incidents are assigned a severity level according to impact on Customer’s business. The severity level definitions below are used to assess the situation and properly classify the issue for handling.

· Once Contractor determines that the root cause of any outage or impact lies outside of Contractor’s ability to control, the severity can be reduced to a more appropriate level. Examples of root causes outside of Contractor’s control:

· Location where the affected agents reside is unable to get to the Internet in general

· Redirect from Customer site to the custhelp.com domain is failing on the Customer’s site

· A routing or Internet outage outside the infrastructure of Contractor’s upstream providers

· Customer’s network is not configured to allow proper execution of the solution -proxy servers, firewall, available bandwidth, packet shaping, etc.

· Hardware issues at the Cloud Access Point

9.0 USAF COMMERCIAL CLOUD SERVICES TERMS AND CONDITIONS

"Configuration control" means having the Contractor's authority to change the hardware and software used in the DoD Cloud Services environment.

"Data Breach" is used to include the loss of control, compromise, unauthorized disclosure, unauthorized acquisition, unauthorized access, or any similar term referring to situations where persons other than authorized users and for an other than authorized purpose have access or potential access to personally identifiable information, whether physical or electronic, that leads to a loss of confidentiality.

"Government" for the purposes of this Contract refers to the United States Air Force Personnel Center & Air Force Reserve Center (AFPC/ARPC).

"Government data" means any data created or obtained in the course of official Government business (all text, files, images, graphics illustrations, information, data (including PII), audio, video, photographs and other content and material (other than applications)), provided by the Government or on behalf of the Government's users that resides in, or runs on or through the DoD Cloud Services environment.

"Government-related data" means any information created or maintained by the Contractor in its standard and ordinary course of business that identifies Government data. This does not include Contractor's standard business records (legal, financial, etc.).

"Isolate" means to logically segregate, store, manage, and maintain data logically separate and apart from any other customer's data in order to preserve information integrity and prevent interaction.

"NACI" means the basic and minimum investigation required by the Federal government for employees and Contractors under HSPD -12. These investigations are submitted using the SF 85, and are submitted to the Government's Information Protection Office through the Unit Security Manager (Mr. Jimmy Ray), Bldg 499, Randolph AFB.

"Operational control" means having Contractor's authority over the components of the DoD Cloud Services environment to include the hardware, software, operational processes and personnel used to process Government data.

"Personally Identifiable Information" means data stored in the DOD cloud services environment under this Contract that can be used to distinguish or identify (trace) an individual's identity: such as name, social security number, date and place of birth, mother's maiden name, and bio-metric records, which are collected and maintained by an agency, including, but not limited to, education; financial transactions; and medical, criminal, or employment history.g

"Retrievable Electronic/Digital Data" (REDD) means Government data and Government- related data stored and retrieved in electronic/digital formats. Because the wide variety of commercial titles (such as cloud, on-demand self-service, broad network access, resource pooling, rapid elasticity, and measured service) generally address selected capabilities, the term REDD encompasses the full range of capabilities, including without limitation commercial offerings for software-as-a-service, infrastructure-as-a-service, and platform-as-a-service.

"Spillage" means a security incident that results in the transfer of classified or controlled unclassified information onto an information system not accredited (i.e., authorized) for the appropriate security level.

1. The Contactor shall require all employees who will have access to Government data, the architecture that supports Government data, or any physical or logical devices/code up to the accreditation boundary (the system as defined in the System Security Plan) to pass the appropriate background investigation required by the Government. At a minimum, all Contractor employees with access to the Government data, the architecture that supports Government data or any physical or logical devices/code will pass a routine NACLC (Access Level II) investigation prior to accessing Government data and be a US person as defined in Executive Order 12333. The Government agrees that it shall sponsor any required background investigation and that Contractor shall submit as many sponsor requests as Contractor deems necessary to operate the DoD Cloud Services environment.

2. (1) Any interruption in the availability of the Cloud Services shall be handled in accordance with the Contractor Cloud Enterprise Hosting and Delivery Policy.

(2) Interruptions in the Cloud Service shall be handled in accordance with the Cloud Enterprise Hosting and Delivery Policy. If there is an interruption, the Contractor shall provide regular updates, as reasonably practicable under the circumstances, to the Government on the status of returning the Cloud Service to an operating state.

(3) If Contractor identifies a compatibility and/or interoperability issue between the Government's systems, infrastructure, and processes and the Cloud Services that affects Contractor's provision of Cloud Services, the Contractor shall promptly notify the Government and provide reasonable assistance to the Government to identify appropriate remedies and if applicable, and available under the circumstances, provide reasonable assistance to the Government to facilitate a smooth and seamless transition to an alternative solution and/or provider.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .