ID07170051_PWS_08.03.2018_Rev_01.pdf

PDF 996 KB Posted

Attached to
Advanced Joint Terminal Attack Controller Training System (AAJTS) Federal contract opportunity
Solicitation number
ID07170051
Issued by
GSA Federal Acquisition Service

About this file

PWS REVISION -01 dated August 3, 2018 The PWS is revised to add Section M.4 Financial Feasibility. The Section J List of Attachments and L.5 Proposal Format and Content Requirements are also amended.

View the file

Other files for this federal contract opportunity

Other files attached to Advanced Joint Terminal Attack Controller Training System (AAJTS), newest first.
File Type Posted
Attachment_12__Responsibility_Questionnaire_Financial.docx DOCX document
Attachment_11_Financial_Release_Authorization_Letter_Attachment_11.doc DOC document
ID07170051_IMPORTANT_Registration_Reminder.docx DOCX document
ID07170051_AAJTS_RFP_Questions_and_Answers.pdf PDF
Attachment_2_Reference_Document_List.docx DOCX document
Attachment_3_Glossary_and_Acronyms.docx DOCX document
Attachment_7_Software_Vendor_Integrity_Statement_Guidelines_Website.docx DOCX document
Attachment_8_OCI_Certification.docx DOCX document
Attachment_5_Consent_To__Purchase_Form.xlsx XLSX spreadsheet
ID07170051_PWS_6.27.18.pdf PDF
Attachment_4_CDRLs.PDF PDF
Attachment_6_Software_Vendor_Integrity_Statement_Guidelines_Application_Software.docx DOCX document
Attachment_1_Pricing_Spreadsheet.xlsx XLSX spreadsheet
Attachment_9_Past_Experience_Information_Sheet.docx DOCX document
Atttachment_10_QASP.pdf PDF
ID07170051_RFP_First_Step_READ_ME_FIRST.pdf PDF
ID07170051_PreSolicitation_Notice_Synopsis.docx DOCX document
Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

ID07170051

AAJTS TSSC

General Services Administration

Federal Acquisition Service (FAS)

Greater Southwest Region

Project Number: ID07170051

Training System Support Center (TSSC) for the

Air National Guard (ANG)

ANG Advanced Joint Terminal Attack Controller (JTAC)

Training System (AAJTS) and

Air National Guard (ANG) Advanced Joint Terminal Attack Controller

(JTAC) Training System (AAJTS) - LITE

Small Business Set Aside Acquisition

In Support of the

502d Trainer Development Squadron (502TDS)

Joint Base San Antonio (JBSA) Randolph, Texas

03 August 2018

Rev-01

SECTION B

SUPPLIES OR SERVICES AND PRICE/COST

B.1 Services Being Acquired

The work identified in this requirement shall be performed in accordance with all sections of this contract and any resultant modifications thereto.

B.2 Introduction

The overall objective of the Air National Guard (ANG) Advanced Joint Terminal Attack

Controller (JTAC) Training System (AAJTS) support contract is to provide a comprehensive operations, maintenance, and sustainment (OM&S) program to ensure ANG AAJTS Operators have fully functional base level training devices in order to satisfy JTAC, and combat controller squadron level continuation, qualification, and mission rehearsal training requirements. The

AAJTS operates in Live, Virtual, and Constructive (LVC), unclassified environment as well as the classified Combat Air Forces (CAF) Distributed Mission Operations (DMO) training environments.

Additionally, the Air National Guard (ANG) Advanced Joint Terminal Attack Controller (JTAC)

Training System (AAJTS) – LITE is a desktop simulation system which provides JTAC and

TACP training. The AAJTS - LITE utilizes the same software as the AAJTS to provide similar

JTAC training capabilities. The ANG requires 8570 IAT I certified Contractor Operator

Maintenance Support (COMS) for two of its AAJTS - LITE devices located in Oklahoma City, Oklahoma at the 138 th

Combat Training Flight (CTF).

The support contract, through General Services Administration (GSA), consists of all actions and activities required for the OM&S of the AAJTS and AAJTS - LITE.

B.3 Background

The AAJTS represents a convenient and economical JTAC training and certification solution as accredited by the Joint Fire Support Executive Steering Committee (JFS ESC). For added versatility, the AAJTS is also designed to function as a multi-training platform. With different software applications and hardware changes, the AAJTS can be modified to support multiple training platforms.

The AAJTS has been delivered to seventeen (17) ANG contiguous United States (CONUS) locations.

There are two (2) AAJTS - LITEs located in Oklahoma City, OK. Both AAJTS and AAJTS - LITEs will require training system support and field support through the implementation of a Training System

Support Center (TSSC), which will operate as a central hub to support AAJTS activities.

B.4 Contract Structure

The Government intends to award a 12 month base year period of performance and a four (4) 12 month option years under this contract.

The schedule and contract line item numbering for this requirement is as follows:

FIRM FIXED (FFP) PRICE LABOR – TOTAL SOLUTION

CLIN

Description

Total Estimated Cost

0001 FFP LABOR – Base Period

$ TBD

1001 FFP LABOR – Option Period 1

2001 FFP LABOR – Option Period 2

3001 FFP LABOR – Option Period 3

4001 FFP LABOR – Option Period 4

TIME AND MATERIALS (T&M) OTHER DIRECT COSTS (ODCs)

0002 T&M ODCs – Base Period

$ 1,915,000.00

1002 T&M ODCs – Option Period 1

2002 T&M ODCs – Option Period 2

3002 T&M ODCs – Option Period 3

4002 T&M ODCs – Option Period 4

COST REIMBURSABLE (CR) TRAVEL

CR Travel – Base Period

(No G&A, profit, or other direct fees may be applied to travel)

$170,000.00

CR Travel – Option Period 1

CR Travel – Option Period 2

CR Travel – Option Period 3

CR Travel – Option Period 4

B.7 Limitations on Subcontracting

Subcontracting is allowable in accordance with applicable clauses pertaining to, and incorporated into this contract. The Government is not procuring, and will not accept a strictly “pass through” contract arrangement. In accordance with FAR 52.219-14, Limitations in Subcontracting, the prime contractor shall provide at least 50% of the overall cost of performance incurred for personnel under this contract, as required to perform the requirements of the PWS.

B.8 Contracting Officer’s Representative (COR)

The CO for each order may designate a Contracting Officer Representative (COR) to perform specific administrative or technical functions.

The specific rights and responsibilities of the COR for each order will be described in writing, and will be provided to the Contractor. A COR has no actual, apparent, or implied authority to bind the Government.

CORs will be appointed in writing by the primary GSA contracting officer, and the Contractor will receive a copy of the appointment letter(s).

[End of Section B]

SECTION C

PERFORMANCE REQUIREMENTS

C.1 Performance Requirements

The Contractor shall perform work in accordance with this section and provide all deliverables and reports in accordance with applicable task order requirements.

C.2 Scope

This document establishes the requirements for the AAJTS and AAJTS - LITE TSSC contract. The requirements defined herein establish the scope of tasks, products, and services that may be required. The following task requirements fall within OM&S:

a. Program Management/Systems Engineering: financial management, personnel management, program security, safety, subcontract management configuration management, cybersecurity support (including security and virus scans), sustainment engineering and planning

b. Upgrades and Modifications: concurrency management, routine hardware/software modifications, and technology insertion.

c. Training Systems Support or Contractor Operations and Maintenance Support (COMS):

operations, maintenance and sustainment (OM&S) at the seventeen (17) operational locations, and training device relocation. This includes:

i. Managing and maintaining a support package to include replenishment of spares and support/test equipment required to sustain AAJTS.

ii. Interoperability: DMO integration, testing, and sustainment

iii. Qualification and Test: test planning, integration and test support, support for Simulator

Certification (SIMCERT)

iv. Contract transition activities including transfer of responsibility from the prior sustainment contract

d. Task Order Transition: Transfer to a follow-on sustainment Contractor at the conclusion of this contract

e. Deliverables: Contractor-provided master schedule, including development, delivery, installation, and test schedule for Government review and approval within six (6) weeks of award. Other deliverables included are captured in Section C.118, Deliverables.

C.3 Type of Services

This is a non-personal, commercial services contract. The Government will not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor. This is a performance-based requirement;

therefore, the Government is defining the required results, rather than dictating the processes which the

Contractor shall use to achieve those results.

C.4 Relocatable Simulation Shelter (RSS)

An RSS is a self-contained, purpose built, weatherproof, electrically powered, climate-controlled, and protected environment for the human occupants and simulator training device(s). The RSS includes self-contained environmental control through integral air conditioning/heating units, humidity control, fire detection and suppression, and integral lighting. The RSS is transportable using conventional commercial vehicles and meets the road size and weight restrictions.

C.5 Current AAJTS and AAJTS - LITE Locations

Below is a table showing the current AAJTS and AAJTS - LITE locations, including a notation for those

AAJTS devices which are housed in an RSS.

Table 1 – Training Device Locations

# Unit Location #

1 San Antonio, TX

– TSSC

San Antonio, TX –

TSSC

2 Oklahoma City, OK – 146 ASOS

(2) AAJTS - LITEs located at

OKC at the 138 th

CTF

Oklahoma City, OK

– 146 ASOS

3 Boise, ID – 124

ASOS

Boise, ID – 124

ASOS

4 Savannah, GA -

165 ASOS

Savannah, GA -165

ASOS

5 Terra Haute, IN –

113 ASOS

Terra Haute, IN –

113 ASOS

6 Ellington, TX –

147 ASOS

Ellington, TX – 147

ASOS

7 New London, NC

– 118 ASOS

New London, NC –

118 ASOS

8 Syracuse, NY –

274 ASOS

Syracuse, NY – 274

ASOS

9 Peoria, IL – 169

ASOS

Peoria, IL – 169

ASOS

10 Harrisburg, PA –

148 ASOS

Harrisburg, PA –

148 ASOS

11 Salina, KS – 284

ASOS/184IW

Salina, KS – 284

ASOS/184IW

12 Atlantic City, NJ

– 227 ASOS

Atlantic City, NJ –

227 ASOS

13 Pineville, LA –

122 ASOS

Pineville, LA – 122

ASOS

14 Meridian, MS –

238 ASOS

Meridian, MS – 238

ASOS

15 Camp Murray, WA – 111 ASOS

Camp Murray, WA

– 111 ASOS

16 Louisville, KY – Louisville, KY –

# Unit Location #

123 STS 123 STS

17 Portland, OR -125

STS

Target installation June 2018. Portland, OR -125

STS

C.6 AAJTS Connectivity to Combat Air Forces (CAF) Distributed Mission Operation (DMO)

Connectivity

The AAJTS CAF DMO connects via Air Reserve Component Network (ARCNet). The Distributed

Training Operations Center (DTOC) at the 132 FW in Des Moines operates and maintains the ARCNet.

The DTOC organizes DMO events for ANG and Air Force Reserve Combat pilots. The standards/requirements to operate on the ARCNet is the same as CAF DMO. However, connections to the CAF DMO will be made through the DTOC to the Combat Air Force (CAF) Distributed Training

Center Network (DTCN).

C.7 Program Management/Systems Engineering

The Contractor shall establish and implement a program management office function to manage all technical performance, reliability, maintainability, schedule, and data delivery requirements of the contract. The Program Manager shall serve as the main point of contact for this effort.

The Contractor shall provide a master schedule, to include development, delivery, installation and test schedule, for Government review and approval, within six (6) weeks of award.

The Contractor shall plan and manage daily operations and activities associated with providing this requirement to ensure the necessary processes and activities are performed to provide an effective and acceptable system. The Contractor shall employ effective management tools and methods to assure control of cost, schedule, and performance. The Contractor shall provide technical support to the program office throughout the duration of this effort. This includes post-installation support, which includes, but is not limited to: development of engineering and technical data, responding to requests for technical assistance, and development of technical alternatives to remedy Government-identified issues. As needed, the Contractor shall conduct, support, or participate in program management and technical reviews, meeting, and conferences to ensure effective and efficient project execution.

The Contractor shall be responsible for storage, staging, and deployment of any equipment and materials provided as part of this project, unless otherwise mutually agreed upon by the Government and the Contractor. The Contractor shall submit a Contractor’s Progress, Status and Management

Report.

CDRL A001, DI-MGMT-80227/T, Progress Report

C.8 Risk Management

The Contractor shall implement an integrated risk management program. The Contractor shall perform continuous and comprehensive risk analysis efforts to identify, prioritize, and manage all risks. The

Contractor shall propose alternatives to mitigate the effects of identified risks, and shall define criteria for initiation of alternatives. The Contractor shall provide the Government access to its risk management plan through the internet or Contractor’s electronic database. The Contractor shall present the risk status at the PMR. The Contractor shall include Government-identified risks in their risk management program.

The Contractor shall use Air Force Pamphlet 63-128, Chapter 12 as a guide to developing the risk management program.

C.9 Associate Contractor Agreements (ACAs)

(a) The Contractor shall enter into Associate Contractor Agreements (ACA) for any portion of the contract requiring joint participation in the accomplishment of the Government’s requirement. The agreements shall include the basis for sharing information, data, technical knowledge, expertise, and/or resources essential to the integration of the 502 Trainer Development Squadron (502 TDS), which shall ensure the greatest degree of cooperation for the development of the program to meet the terms of the contract. Associate contractors are listed in (g) below.

(b) ACAs shall include the following general information:

(1) Identify the associate contractors and their relationships.

(2) Identify the program involved and the relevant Government contracts of the associate contractors.

(3) Describe the associate contractor interfaces by general subject matter.

(4) Specify the categories of information to be exchanged or support to be provided.

(5) Include the expiration date (or event) of the ACA.

(6) Identify potential conflicts between relevant Government contracts and the ACA; include agreements on protection of proprietary data and restrictions on employees.

(c) A copy of such agreement shall be provided to the Contracting Officer for review before execution of the document by the cooperating contractors.

(d) The Contractor is not relieved of any contract requirements or entitled to any adjustments to the contract terms because of a failure to resolve a disagreement with an associate contractor.

(e) Liability for the improper disclosure of any proprietary data contained in or referenced by any agreement shall rest with the parties to the agreement, and not the Government.

(f) All costs associated with the agreements are included in the negotiated cost of this contract.

Agreements may be amended as required by the Government during the performance of this contract.

(g) The following contractors are associate contractors with whom agreements are required:

Contractor Address Program / Contract

Rivertech, LLC 10807 New Allegiance Drive, Suite 350-200

Colorado Springs, CO 80921-

502 Trainer Development

Squadron (TDS)

C.10 Reserved

C.11 Systems Engineering

The Contractor shall implement systems engineering processes to ensure the integration of program requirements into the products and services. The Contractor shall use ANSI/EIA 632 as a guide for

Systems Engineering, for execution of all technical program and project milestones.

C.12 Technical Reviews

Technical reviews shall be conducted during modification efforts to ensure:

a. the Contractor understands the functional and performance requirements,

b. the designs are mature and support those requirements,

c. all risks have been identified, analyzed, tracked, reported, and controlled,

d. all government-approved entrance and exit criteria have been met, and

e. the necessary Quality Assurance (QA) efforts are planned and/or performed to validate design to the original requirements.

Technical reviews shall be event-driven and not schedule-driven; that is, technical reviews shall be scheduled and accomplished when the Contractor meets the entry and exit criteria for each review. The

Contractor, with Government approval, shall combine reviews where practical and as appropriate to support each modification effort. The appropriate Government and Contractor personnel shall co-chaired by the appropriate Government and Contractor personnel. The Contractor shall produce and provide an agenda, briefing materials, and minutes for the reviews.

C.13 Technical Interchange Meeting (TIM)

Technical Interchange Meetings (TIMs) shall be informal meetings with the primary purpose of an interchange of information between the Air Force and the Contractor. TIMs shall be forums for the discussion of contract and engineering change requirements prior to, or during, ECP and/or Contract

Change Proposal (CCP) development. The Contractor shall incorporate TIMs with other program reviews where possible. These meetings may be used to define or clarify new/modified system requirements and review progress on trade studies. TIMs shall also be conducted as design reviews for

TSSC modifications. Appropriate Contractor personnel shall participate in the review/discussion of their respective areas of responsibility as required. The Contractor shall document TIMs.

C.14 Software Development

All software (including source code) delivered under this contract shall have Government Purpose Rights.

The Contractor shall follow accepted commercial developmental guidelines such as Institute of Electrical and Electronics Engineers (IEEE)/Electronic Industries Alliance (EIA) 12207 for all new or modified software. In particular, for new or modified software design, standard software modules which can be used throughout the training system shall be employed whenever feasible. In addition, the training system software design shall follow structured model requirements and provide for expansion capabilities.

C.15 Software Requirements and Architecture Development and Review

The Contractor shall develop the software requirements and architecture IAW, a documented Contractor software development process. The Contractor shall utilize an approved Design Change Request (DCR) process to request revisions to Government requirements, even where such revisions would result in cost schedule or performance benefits. Based upon analysis of system requirements, system design, and other considerations, the Contractor shall define and document the software requirements and verification methodology for each software item, and document the traceability between the software item requirements, the System/Sub-system Specification (SSS), and the System Performance Specification.

C.16 Software Test

The Contractor shall follow an established software item testing process. The Contractor shall establish test cases (in terms of inputs, expected results, and evaluation criteria), traceability between the test case and the system requirements, detailed procedures for conducting the test, and test data corresponding to each software item. The Contractor shall test the software IAW, the unit test cases, and procedures. The

Contractor shall also implement a software authorization process as per the OTI AO and ISSM.

Approved software static code analysis scans must be completed for any software developed by the contractor or not approved by the DoD. A list of analysis tools can be found in the OTI AO Software

Authorization Guide. The Contractor shall analyze the results of item testing and record the test and analysis results.

CDRL A004, DI-NDTI-80809B, Test/Inspection Report

CDRL B007, DI-IPSC-81435A, Software Design Description (SDD)

C.17 Hardware Design

The Contractor shall integrate and assemble the system hardware that satisfies the requirements identified in the AAJTS System/Subsystem Specification. The Contractor shall make use of commercial and Non-

Developmental Items (NDI) in all cases where there is a demonstrable life cycle cost benefit. In cases where commercial or NDI items are not used, the Contractor shall provide justification and a cost-benefit analysis to the Government at the Preliminary Design Review. The Contractor shall apply the systems engineering process during each level of system development (system, subsystem, and component) to refine and improve the products defined in the prior levels.

C.18 Contractor Personnel

The Contractor shall manage personnel in accordance with IAW DoD 8570.01-M and AFMAN 33 285, and shall comply with the Defense Federal Acquisition Regulation Supplement (DFARS) 252.239.7001 as well as all cybersecurity requirements stipulated in the contract.

C.19 Contractor Personnel Requirements

The Contractor shall accomplish the assigned work by employing and utilizing qualified personnel with appropriate education, training, experience, and security clearance. All Contractor personnel associated with the program must obtain and maintain an Air Force security clearance at the Secret level. Those employees working directly with software development, release and installation shall obtain and maintain the proper Cybersecurity certification as defined in in this PWS.

Contractor personnel shall present a neat appearance and be easily recognized. In accordance with IAW

DFARS 211.106, the Contractor personnel shall identify themselves as Contractor personnel by introducing themselves or being introduced as such and by displaying distinguishing badges or apparel for meetings with Government personnel. Contractor personnel shall identify themselves as Contractor employees in telephone conversations and in formal and informal written correspondence.

The Contractor shall not employ any person who is an employee of the United States Government if the employment of that person would create a conflict of interest, nor shall the Contractor employ any person who is an employee of the Department of Defense (DoD) or any subordinate branch of the DoD, either military or civilian, unless such person seeks and receives approval in accordance with the Joint Ethics

Regulation, DoD 5500.7-R, and any applicable regulations of the USAF.

C.20 Technician Qualifications

The Contractor’s AAJTS and AAJTS - LITEs technicians shall be qualified, trained, and knowledgeable in the operation and maintenance of the AAJTS, AAJTS - LITEs, and peripheral equipment, enabling them to perform the full range of required operation, maintenance, and support tasks of the training system. The Contractor shall maintain documented records of the technicians’ qualifications to perform the required tasks of this PWS and AAJTS Operations and Maintenance Manuals, and they shall be made available upon request of the COR.

The technician will also be referred to as the Contractor Operations and Maintenance Support (COMS) representative(s).

C.21 Contractor Personnel at Government Locations

The Contractor shall ensure onsite personnel coverage during required work hours at each AAJTS operating location as listed in Table 1. Work hours and work days shall be established and maintained at each location to support the local training schedule, maintenance, and sustainment efforts. The COMS representative shall be responsible for working ANG duty weekends, if required. The Contractor shall not be authorized overtime under this PWS. For any period greater than five (5) calendar days which the regular COMS representative is not available to support AAJTS operations, maintenance, or sustainment, the Contractor shall be required to have a qualified replacement available.

C.22 Pass and Identification

All Contractor personnel assigned to a base shall obtain Government required passes and long-term identification. The Contractor shall ensure employees return all passes and identification when personnel depart a site or separate from this contract. The Contractor shall comply with the Information Assurance and Personnel Security Requirements for Accessing Government IT Systems as defined by DoDI 8500.2.

C.23 High Bay and Relocatable Simulation Shelter (RSS) Sustainment and Maintenance

The TSSC shall perform TSSC high bay and Relocatable Simulation Shelter (RSS) sustainment and maintenance functions, where applicable, including the maintenance of the roof, lighting, locks, HVAC, doors, and general housekeeping. This requirement exists for both the base and all option years, and has a not to exceed (NTE) of $15,000.00. There are or will be three (3) size 1X RSSs for the AAJTS. The

TSSC shall perform total system configuration management by managing the original As Built

Configuration List (ABCL) for each upgrade and delivery and by managing the configuration of subsequent revisions and upgrades.

CDRL A005, DI-CMAN-81516, As Built Configuration List

C.24 Facility Appearance

The Contractor shall maintain Government facilities under Contractor control (e.g., training system areas, TSSC, and associated complexes) in a neat, clean, orderly and safe condition at all times. The

Government may inspect site facilities at any time during the contract.

C.25 Facility Engineering

The Contractor shall comply with the base/site facilities management programs. The Contractor shall assist in coordination of maintenance efforts between base, Contractor, and site personnel to ensure all needed repairs are accomplished, proper security procedures are followed and minor maintenance is performed as required. The Contractor shall assist, as directed by the COR, with planning, coordination and oversight of training facility projects.

C.26 Government-Furnished Property/Equipment/Information (GFP/E/I)

AAJTS Spares and Consumables

The Contractor shall manage all AAJTS program spares, and consumables, such as basic office supplies, cleaning supplies, and minor hardware.

The Contractor shall provide a proposed spare parts list, including pricing per unit, to maintain the full functionality and operability of the AAJTS devices for a period of twelve (12) months beyond the standard warranty period of one year.

CDRL B002, DI-ILSS-80134A, As Built Configuration List

Following Government acceptance of the proposed spare parts list, the TSSC shall procure and maintain an inventory, at the TSSC location, of spares necessary to maintain the full functionality and operability of the AAJTS devices for a period of twelve (12) months beyond the standard warranty period of one year.

Spares shall be identified in this contract under the ODCs, and will be funded by the Government to ensure continued operability of the AAJTS devices. In addition, materials, including annual software maintenance renewals and software license fees for AAJTS devices, and other materials to support TSSC functions and AAJTS field sites shall be included in the ODCs.

Handling and Safeguarding of Government Property

The Contractor shall track and store property, equipment, and information in a secure location. The

Contractor shall protect Government assets to prevent damage during the time the Contractor has possession.

Property Damage

When mishaps (Ref AFI 91-204) involving Government property associated with the AAJTS program occurs, the Contractor shall report the accident or incident as soon as possible, but no later than 24 hours following the event, to the COR, via email, regardless of the time of day. The Contractor shall assist in securing the scene and the damaged item(s) until released by the accident investigative authority as designated by the local Safety Office.

If the Government elects to conduct an investigation of the accident, the Contractor shall cooperate fully and shall assist Government personnel until the completion of the investigation.

The Contractor shall ensure cooperation and assistance in accident reporting and investigation.

Property Disposal

The Contractor shall make recommendations to both the CORs and GPO for condemnation of unserviceable or obsolete items. If approved by the GPO, the Contractor shall dispose of identified material through the Plant Clearance Automated Reutilization Screening System (PCARSS) process.

This includes shipment of material to the disposal site(s) as directed by the Plant Clearance Officer.

Hazardous Waste

The Contractor shall be responsible for the proper handling, storage, transportation, and disposal of all hazardous waste resulting from performance on this contract IAW AFI 32-7042 and the host base directives and guidelines. Currently, the batteries are only hazardous material used in the AAJTS.

C.27 Program Meetings

When practical, meetings may be conducted virtually (i.e., web-based, teleconference, Video

Teleconference Communication (VTC), Defense Connect Online, etc.) as long as desired meeting/conference objectives can be achieved. Audio teleconference or VTC shall be available for all scheduled meetings.

When directed by the GPO, the Contractor shall host, chair, or participate in meetings, including aircraft-associated meetings which impact the AAJTS Program, and provide minutes/trip reports for those same meetings. The Contractor shall provide agendas, briefing materials, and minutes for all AAJTS meetings that they host/manage. If the Contractor is running the meeting, the Contractor shall provide necessary briefing materials before the presentation begins.

All arrangements for meeting rooms, audio-visual equipment, etc., including room rentals, for Contractor hosted AAJTS meetings or “Government Only” meetings, shall be the Contractor’s responsibility.

C.28 Post Award Conference

The Contractor shall host and conduct a post award conference (PAC) to be held within 30 calendar days of contract award. This conference shall introduce key participants, and identify points of contact. The contractor shall document the PAC.

C.29 Program Management Review (PMR)

The Contractor shall support and document the results of AAJTS PMRs which will be conducted two times a year; one at the TSSC and the other at another Government facility. As a minimum, attendees will include the GPO, TSSC representative(s), and NGB/A staff personnel.

C.30 PMR Content

The Contractor shall, as a minimum, address the following items at PMRs though additional items may be added upon GPO direction and the Contractor may discuss other items. The Contractor shall clearly delineate items presented in the PMR that differ significantly from status provided in program CDRLs.

a. Program Health: A discussion of the AAJTS program health and its current status in meeting device availability requirements.

i. The Contractor shall also summarize program successes, as well as program issues, during the reporting period and discuss how they impact training. The report shall emphasize benefits and impacts to the Government (i.e., cost, schedule, or technical benefits).

ii. Action Item Status.

b. Risk Status: A discussion on program risks including current status of each program and project risk, the mitigation plans, and the recovery plans as appropriate. Each risk identified within the program shall be discussed with its current status, including trigger point (i.e., the watch parameter for this risk that triggers when a risk is realized) information. All risks shall be discussed, even those risks assumed by the

Contractor, as all risks can affect program performance as well. Each risk shall have a POC assigned.

c. Limitations on Subcontracting: The Contractor shall report their level of effort to ensure Small

Business prime Contractor performs at least 50% of the contract requirements as of each PMR.

d. Site Status: Facility projects, device interface status and issues, and other site issues including site management and security.

e. ECP/CCP/DEV/1067s Status: Status on major ECP/CCP/DEV/1067 projects shall be presented.

Status includes schedule and performance status and any blocks to completion.

f. Proposal Status: Proposal and Rough Order of Magnitude (ROM) cost status, as well as

Contractor recommendations on training device modifications to maintain or improve training.

g. Trade Study Status: Status on any trade studies being developed or those already submitted.

h. Deficiency Report (DR) Status: The Contractor shall discuss the program’s overall DR status.

This includes in-scope, out-of-scope, and enhancement DRs. The status shall include the initial identification date, the original planned closure date, the current planned closure date, the responsible organization/personnel assigned, the current resolution status, the priority, brief description of the DR, and the impact if not closed.

i. Quality: The Contractor shall address quality issues.

j. DMS Status looking out at least one year.

k. Cybersecurity status and review: review ATO documentation, security plans and processes at least annually for currency and applicability

l. Other issues identified by either the Contractor or the Government.

C.31 Monthly Program Teleconference

The Contractor shall arrange for and host a monthly teleconference to discuss program issues and concerns, including document deliveries, TSSC issues/concerns, Operational Site activities and limitations, Help Desk activities, Cybersecurity/Information Assurance, Logistics issues/concerns, and

Program Action Item status.

C.32 Conferences

The Contractor representative shall attend other conferences when directed by the PCO. All conference travel costs shall be reimbursed via a no-fee cost reimbursable Contract Line Item Number (CLIN). The

Contractor shall provide manpower for the Air National Guard (ANG) booth exhibits and demonstrate the versatility and multiple-integration capabilities of ANG products which are essential to the continued modernization of modeling and simulation within the ANG. The Contractor shall provide a trip report for every conference attended.

C.33 Monthly Status Report (MSR) / Quarterly Cost Burn Rate Report

The Contractor shall report monthly availability and utilization statistics, and shall provide summaries during PMRs. All training device deficiencies shall be corrected within sixteen (16) work hours of an identified deficiency. The Contractor shall strive to maintain a 95% availability goal at each operating base on a monthly basis.

CDRL A001: DI-MGMT-80277/T, CONTRACTOR’S PROGRESS, STATUS AND MANAGEMENT

REPORT

Quarterly Cost Burn Rate Report (ODC and Travel CLINs Only)

The contractor shall provide a contractor-format, cost burn-rate report, on a quarterly basis, no later than the last business day of the quarter-month. The cost report should be categorized into the following eight categories:

Program Management

COMs

Software Maintenance

Spares

Equipment

Representational

Relocation

Travel

C.34 Program Security

The Contractor shall comply with local base standards for safety and security, and shall maintain security for all facilities they occupy/manage IAW host base security requirements.

The Contractor shall protect For Official Use Only (FOUO) and classified material from unauthorized access. The Contractor shall report all security violations and/or anomalies immediately to the COR and

GPO.

The Contractor shall ensure system security plans to support the routine operation and maintenance of

AAJTS components at the collateral SECRET level IAW CAF DMO security requirements. CAF DMO security requirements are outlined in the Security Standards of the current CAF DMO Standards.

C.35 Acquisition Program Security

The Contractor shall ensure security program requirements are integrated into all program areas of this contract as required by the following:

a. DoD Directive (DoDD) 5000.01, The Defense Acquisition System

b. DoD Instruction (DoDI) 5000.02, Operation of the Defense Acquisition System

c. DoDI 5200.39, Critical Program Information (CPI) Identification and Protection within Research, Development, Test, and Evaluation (RDT&E)

d. DoDI 8500.01, Cybersecurity

e. DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT)

f. Committee on National Security Systems Instruction (CNSSI) 1253

g. AFI 17-101 Risk Management (RMF) for Air Force Information Technology (IT)

h. AFI 63-113, Program Protection Planning for Life Cycle Management

i. NIST SP 800-37, Guide for Applying the Risk Management Framework to Federal Information

Systems

j. NIST 800-53r4, Security and Privacy Controls for Federal Information Systems and

Organizations

C.36 System Security

The Contractor shall develop and maintain an overall program System Security Plan (SSP) IAW the OTI

AO job aid for RMF implementation. The Security Plan provides an overview of the security requirements for the system, system boundary description, the system identification, common controls identification, security control selections, subsystems security documentation (as required), and external services security documentation (as required). The System Security Plan can also contain, as supporting appendixes or as references, other key security-related documents such as a risk assessment, privacy impact assessment, system interconnection agreements, contingency plan, security configurations, configuration management plan, and incident response plan.

If there is already an existing security plan and ATO, the TSSC will review for updates. The TSSC shall submit a draft System Security Plan or updates to the Government no later than ninety (90) days after contract award. The TSSC shall perform final submission after receiving Government comments on the draft System Security Plan. If no comments are received within thirty (30) days, the draft shall be considered approved as the final System Security Plan.

The Vulnerability Management Plan (VMP) outlines the complete cycle of identification, classification, remediation, and mitigation of vulnerabilities. Vulnerability management includes patching, tracking, and testing.

For new programs without existing/prior program documentation, the TSSC shall submit a draft

Vulnerability Plan to the Government no later than ninety (90) days after contract award. The Contractor shall perform final submission after receiving Government comments on the draft Vulnerability

Management Plan. The VMP must be finalized NLT 90 days before ATO submission. If the VMP process is updated, the Contractor will ensure the VMP reflects the current vulnerability management process..

The Contractor shall develop, maintain, and implement all procedures for cryptographic keying material loading (if applicable), as directed by the Government.

The Contractor shall provide a separate system for classified data management in Contractor facilities with oversight y DSS or other approved authority. On DoD installations, the Contractor shall utilize approved DoD systems for classified data management. Management of classified/sensitive material/equipment shall be handled, transported, transmitted and protected IAW the National Industrial

Security Program Operating Manual (NISPOM), DoD 5220.22-M, and DD Form 254.

Note: If there is a conflict between DD Form 254 and this PWS, the DD Form 254 shall take precedence.

If a conflict is found, the Contractor shall immediately contact the PCO.

C.37 Information Security

The Contractor shall execute the training system program IAW DoD 5220.22-M, National Industrial

Security Program Operating Manual (NISPOM), DoD Instruction 5200.01, and the DoD Information

Security Program. The Contractor shall comply with all security requirements as identified in the DoD

Contract Security Classification Specification (DD Form 254). The DD Form 254 takes precedence over requirement stated in this PWS. The Contractor shall protect classified or sensitive materials and data received or generated as a part of the execution of this contract.

C.38 Industrial Security

The Contractor shall comply with the requirements of the National Industrial Security Program Operating

Manual (NISPOM), DoD 5220.22-M and AFI 16-1406 in management of the contract.

C.39 Physical Security

The Contractor shall be responsible for ensuring that all mandated physical security requirements from the DD 254 and DoD 5220.22-M are met. The Contractor shall enforce local, AF, and DoD instructions on controlled and prohibited items inside the secure area.

C.40 Contractor Facility Physical Security

The Contractor shall provide physical security in all Contractor facilities utilized to perform this contract.

The Contractor shall safeguard all Government property and data provided for Contractor use. At the end of each workday, the Contractor shall secure Government equipment, materials, and data.

C.41 Contractor Physical Security of Government Facilities

The Contractor shall be responsible for ensuring all mandated physical security requirements are met.

The Contractor shall brief personnel on their responsibilities regarding maintaining physical security, including Open Storage documentation and approval, as required.

The Contractor shall enforce local, USAF, and DoDIs on controlled and prohibited items inside the secure area. At the end of each workday, the Contractor shall secure Government facilities, equipment, and materials local directives. The Contractor shall grant access to other Contractors, as required (e.g., for the performance of modifications, maintenance, and inspections) during times directed by the GPO.

C.42 Access Control System

The Contractor shall use the site access control system established and managed by the FSO for entry control system to the AAJTS training/support facilities.

C.43 Government Facilities Key and Combination Control

Keys issued to Contractor personnel shall not be used by unauthorized persons or duplicated without authorization. The Contractor shall reimburse costs, such as replacement locks or re-keying locks, which resulted from Contractor negligence.

C.44 Contingency Procedures for Government Facilities

The Contractor shall provide security in the event of a security system malfunction at secure training facilities when Contractor personnel are on-site. The Contractor shall comply with base requirements for all real world FPCON levels. When required by real world FPCON levels, the Contractor shall secure the training facilities IAW base directives and control entry into those facilities IAW base plans unless relieved by U.S. military personnel.

The Contractor shall comply with FSO guidance during all exercises.

C.45 Personnel Security

The Contractor shall ensure the requirements for granting access to classified information are met, as defined in the following:

a. AFI 16-1404, Personnel Security Program Management

b. DD Form 254, DoD Contract Security Classification Specification

c. DoDM 5200.01 Vols 1-4, DoD Information Security Program Manual

d. DoDI 5200.02, DoD Personnel Security Program (PSP)

e. DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM)

All Contractor personnel must obtain and maintain an Air Force security clearance at the Secret level as a condition of employment. The Contractor shall obtain and maintain a JPAS account.

C.46 Security Training

The Contractor shall ensure that each Contractor/subcontractor employee completes Program Protection awareness training before performing any contract work and completes required annual refresher training throughout the period of performance. The Contractor/subcontractor shall maintain a listing by name and title of each Contractor/subcontractor employee working under this contract that has completed the required training.

Cybersecurity Contractor Training and Certification. The Contractor shall ensure that personnel accessing information systems have the proper and current cybersecurity certification to perform cybersecurity functions IAW DoD 8570.01-M. The Contractor shall meet the applicable cybersecurity certification requirements, including:

DoD-approved cybersecurity workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M.

Appropriate operating system certification for cybersecurity technical positions as required by

DoD 8570.01-M.

The Contractor/subcontractor shall maintain a listing by name and title of each Contractor/subcontractor employee working under this contract that has completed the required training. Upon request by the

Government, the Contractor shall provide documentation supporting the cybersecurity certification status of personnel performing cybersecurity functions. Contractor personnel who do not have proper and current certifications shall be denied access to DoD information systems for the purpose of performing cybersecurity functions.

C.47 Operational Security (OPSEC)

The Contractor shall apply Operations Security (OPSEC) principles and practices to reduce program vulnerability from successful adversary collection and exploitation of critical information. The

Contractor shall participate/comply with the Base/Operating location’s OPSEC plans.

The Contractor shall provide an analysis of current and future security requirements, as necessary, and implement/maintain OPSEC procedures for all program and project efforts at all levels of necessary classification IAW DoD 5220.22-M and as listed on DD Form 254.

C.48 Cybersecurity

The AAJTS, when connected to CAF DMO, is categorized as: Confidentiality (Moderate), Integrity

(Moderate), Availability (L). Currently no training or maintenance management systems are connected to the AAJTS.

The Contractor’s Cybersecurity Program shall be managed through the Risk Management Framework

(RMF) consistent with HAF A3TI AO policy, the principles established in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-37 and IAW DoDI 8510.01. The Contractor shall analyze and implement, as necessary, security controls IAW the Information Technology Determination and Categorization (ITDC) for the AAJTS data types and CAF DMO network connectivity requirements.

The Contractor shall integrate Cybersecurity into the overarching Systems Engineering process as well as

Cybersecurity events and activities included on the AAJTS IMS. The Contractor shall identify, manage, and verify Cybersecurity requirements, including Cybersecurity controls, in the same manner as all other system requirements, to ensure traceability.

Cybersecurity controls shall be evaluated IAW the latest OTI Job Aid for RMF Implementation and baseline priorities as documented in the OTI RMF Portal

(https://cs2.eis.af.mil/sites/10382/SitePages/Home.aspx). Security controls shall be implemented through

Systems Engineering Technical Processes as follows: stakeholder requirements definition, requirements analysis, architecture design, implementation, integration, verification, and validation. The Contractor shall document any cybersecurity related baseline changes and ensure adequate testing to minimize any potential impact to the functional performance of the simulator.

The Contractor shall continue to implement the DoD best practices of Cybersecurity which include confidentiality, integrity, availability, authentication, and non-repudiation. Cybersecurity requirements shall be integrated into the overall Test and Evaluation (T&E) process. Cybersecurity risks shall be identified and managed as part of the overall program risk management process (consisting of cost/schedule/performance risks).

The Contractor shall support Cybersecurity Impact Evaluations (CIE) package for system modifications and reaccreditation as required for major upgrades affecting the Cybersecurity posture of the system. In the test environment, the Contractor shall analyze and potentially implement and report compliance status for applicable security patches, including commercial patches, for the products installed on the baseline.

These results from the test environment shall be implemented in production/sustainment under coordination with the program office and Information System Security Manager (ISSM) in order to maintain concurrency.

The Contractor shall deliver required artifacts via eMASS for ISSM review and submittal to the

Authorizing Official (AO) IAW Job Aid for OTI RMF Implementation , part of the OTI Authorizing

Official Support Site. An additional reference for the RMF process and artifact templates can be found at the RMF Knowledge Service website at https://rmfks.osd.mil/rmf/Pages/default.aspx.

C.49 Information System Security Officers (ISSO)

The Contractor shall appoint qualified personnel to serve as program Information System Security

Officers (ISSOs). The ISSOs shall be responsible for performing a comprehensive evaluation of all aspects of the security features of the AAJTS Cybersecurity Program and shall ensure that AAJTS site implementation meets established security requirements.

Currently, for the AAJTS program, there is a Contractor ISSO at the TSSC performing Information

Assurance Technical (IAT) Level II (IT Security Engineer) duties. At the typical ANG unit, the COMS would provide oversight of the cybersecurity, but would not perform duties as a technical ISSO who physically logs into the system, troubleshoots, installs, and administers cybersecurity measures.

The Contractor IAT II ISSO should have access to a simulator for testing and remediation of applied security measures before they are deployed and installed on the sites' simulators. Ideally, testing and remediation would occur at the TSSC, but the ISSO location could be (most) anywhere that the contract dictates provided that the ISSO can fulfill their duties (and support a classified system).

C.50 Certification Requirements

Individuals shall possess a DoD approved cybersecurity baseline certification commensurate to category and level of the assigned position IAW DoD 8570.01-M, AFI 17-130, AFI 33-210 and AFMAN 17-1303.

DoD approved listing can be found at https://iase.disa.mil/iawip/Pages/iabaseline.aspx.

• Program ISSM shall be certified to the Information Assurance Management (IAM) Level II, with recommended certification is Certified Information Systems Security Professional (CISSP)

• TSSC System Engineers/Program ISSO (Program Level System Administrator) shall be certified to IAT Level II with recommended certification is CompTIA Security+ CE

• COMS Operator (Operating System Administrative Access/Sim System Administrator) shall be certified to IAT Level I, with recommended certification is CompTIA A+ - A+ Essentials exam and A+

Practical Applications exam

• All Contractor employees shall have the appropriate level of certification upon hire.

C.51 ISSO Duties and Responsibilities

The ISSOs shall be responsible for performing the comprehensive evaluation of all aspects of the security features of the Cybersecurity Program to ensure the training sites meets established security requirements.

The duties of the ISSO shall consist of the following:

a. In coordination with the ISSM, initiate protective or corrective measures when a cybersecurity incident or vulnerability is discovered.

b. Ensure that cybersecurity and cybersecurity-enabled software, hardware, and firmware comply with appropriate security configuration guidelines.

c. Ensure that DoD information system recovery processes are monitored and that IA features and procedures are properly restored.

d. Ensure that all DoD information system cybersecurity-related documentation is current and accessible to properly authorized individuals.

e. Implement and…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it.