JWAC IT Services (JITS) IDIQ_Final DRAFT for RFI.pdf
PDF 516 KB Posted
- Attached to
- IT Services RFI Federal contract opportunity
- Solicitation number
- FA4890RFI0001
About this file
This is a draft Performance Work Statement (PWS) for the Joint Warfare Analysis Center (JWAC) IT Services (JITS) Indefinite Delivery/Indefinite Quantity (IDIQ) contract. The document outlines comprehensive IT support services for JWAC, located at Naval Support Activity - South Potomac in Dahlgren, Virginia, with work spanning unclassified to Top Secret//Sensitive Compartmented Information//Special Access Program (TS//SCI//SAP) environments.
The PWS details two primary task order examples: 1) IT Support Services, which includes system administration, Windows and Linux administration, cyber security operations, and service desk support, and 2) JCCE Development & Support Services, focusing on software development, DevSecOps, software engineering, and laboratory environment management. The contract requires highly technical personnel with expertise in cloud computing, containerization, cybersecurity, software development, and various programming languages, with an estimated workload of approximately eight Full-Time Equivalents (FTEs) for software development and five FTEs for lab environments. Contractors must possess advanced certifications, including Security+ and Information Assurance Technical (IAT) II certification, and be prepared to work in a complex, multi-classification computing environment utilizing technologies like Cisco, VMware, Kubernetes, and various cloud platforms.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| JITS - RFI Questions Final Draft.xlsx | XLSX spreadsheet | |
| Questions and Answers.xlsx | XLSX spreadsheet | |
| Copy of JITS - RFI Vendor Response Sheets.xlsx | XLSX spreadsheet | |
| JITS - RFI for JWAC IT Services (JITS).pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
UNCLASSIFIED
JWAC IT Services (JITS) IDIQ
Draft for RFI Purposes Only
Performance Work Statement (PWS)
Xxxx XX, 2026
JOINT WARFARE ANALYSIS CENTER (JWAC)
Dahlgren, VA
C.1 TABLE of CONTENTS
C.1 TABLE of CONTENTS
C.2 BACKGROUND
C.3 PURPOSE and OVERVIEW OF SYSTEMS
C.3.1 Figure 1
C.3.2 Table 1: JWAC IT Operational Environment
C.4 General Requirements
C.4.1 Scope
C.4.2 Surge Support and Subject Matter Expertise
C.5 TASK ORDER EXAMPLE #1 – IT Support Services
C.5.1 System Administration & Operations Support
C.5.2 Windows System Administration and Operations Support Requirements
C.5.3 Linux Administration and Operations Support
C.5.4 Cyber Security and Operations Support
C.5.5 Service Desk Administration
C.6 TASK ORDER EXAMPLE #2 – JCCE Development & Support Services
C.6.1 General Requirements
C.6.2 JCCE CORE SUPPORT
C.6.3 JCCE LAB (JCCE-L)
C.6.4 (U) JCCE SOFTWARE DEVELOPMENT (JCCE-SDIMS)
C.6.5 Application of Software Development
C.6.6 DELIVERABLES
C.6.7 SERVICES SUMMARY
C.7 ADMINISTRATIVE REQUIREMENTS
C.8 SECURITY REQUIREMENTS
C.2 BACKGROUND
The Joint Warfare Analysis Center (JWAC) provides the combatant commands, Strategic
Command (STRATCOM), and the Joint Staff with effects-based, precision targeting options for selected networks and nodes in order to carry out the national security and military strategy of the United States during peace, crisis, and war. JWAC is a 400-member command comprised of approximately 360 civilians and 40 military located on Naval Support Activity – South Potomac
(NSA-SP) in Dahlgren, Virginia. Dahlgren is located in King George County, Virginia.
C.3 PURPOSE and OVERVIEW OF SYSTEMS
The JWAC IT environment is composed of the JWAC Compartmented Computing Environment
(JCCE) architecture operating at multiple classification levels with up to 600 users/clients on each. This architecture is a secure highly virtualized computing platform based within an existing data center. The infrastructure is based on Cisco Unified Computing System and NVidia DGX servers, NetApp data storage, Cisco Nexus and Catalyst networking and VMware virtualization technologies. The architecture builds on the system, network, and storage virtualization and leverages automation and remediation, scanning, monitoring, DevSecOps principles and other capabilities to ensure consistency and security across multiple, independent highly secure environments running Windows Server, Linux and Windows client operating systems.
More specifically, the JCCE environment is implemented on a Cisco FlexPod inspired architecture, a Cisco Validated Design Specification that combines Cisco Unified Computing
System (UCS), Cisco Nexus networking and NetApp Clustered Data ONTAP storage into a converged infrastructure platform. The server environment is nearly 100% virtualized or containerized using VMware vSphere or Rancher (RKE2) Kubernetes respectively, with virtual machines running Microsoft Windows Server and Enterprise Linux. Microsoft Windows 11 is used for both physical and virtual clients. The JCCE environment utilizes shared infrastructure services to support systems and services at the Unclassified up to Top Secret (TS)//Sensitive
Compartmented Information (SCI)/Special Access Required (SAR) level with multiple, restricted access tenants hosting highly restricted SCI and/or Special Access Program (SAP) data, systems, and methods. JCCE core services include functions such as Network Time Protocol (NTP), Domain Name Service (DNS), Windows Software Update Services (WSUS) (to support patching), auditing, and Host-Based Security System (HBSS) monitoring Trellix endpoint security and antivirus. The JWAC operates four major production networks at the following security levels: unclassified, secret, and two at top secret. These production networks operate independently and share no hardware or software resources.
All unclassified advancement/development and testing is performed on a dedicated development stack and deployed to target tenants operating in three broad security domains (unclassified, secret and top secret) hosted on dedicated hardware stacks (refer to Figure 1). Any operational issues discovered in the production environments are corrected in the development environment on the development stack through a change request/change management process. Multiple tenants may exist on each hardware stack; additional tenants and stacks may be added during the life of the contract. Updated services are deployed after a testing and approval process. All services, barring security limitations, are developed on the development stack. Not all services are deployed to all production tenants.
C.3.1 Figure 1
C.3.2 Table 1: JWAC IT Operational Environment
The following table is provided for reference to outline the scope of the JWAC IT operations environment including operating systems, software, and administration tools in which it will be necessary to understand and demonstrate administration experience in order to provide IT support. All products and versions in the table below are subject to lifecycle upgrades.
Functional Area Scope
Operating Systems
• Microsoft Windows 11+
• Microsoft Windows Server 2022+
• Red Hat Enterprise Linux 8 & 9+
• VMWare 8+
• Automation tools such as Cloudbolt
System Administration Software Tools • Microsoft Intune
• WSUS
• Python
• PowerShell
• Bash
• Kubernetes
• Artifactory
• GitLab
• Microsoft Desired State Configuration (DSC)
• Ansible Automation Platform
• Automation tools such as Cloudbolt
Data Administration Software Tools
• Quantum StorNext Software
• NetApp VSC
• NetApp Snapshots and SnapVault
• NetApp OnTAP
Software Development Tools
• Microsoft Visual Studio 2022+
• GitLab
• See also the JWAC Enterprise Information
System table below
Account Management and Directory
Services
• Active Directory
• Lightweight Directory Access Protocol (LDAP)
• DNS
• VMWare VSphere
• Security certificates
Key Services
• Microsoft Exchange
• JIRA
• SharePoint
• MS SQL
• PostgreSQL Database Software
• Open Source Software Image Map (OSSIM)
• JavaScript
• Internet Information Services (IIS)
Monitoring and Auditing Development
Software Tools
• LogRhythm NextGen SIEM
Cybersecurity Tools
• DISA DoD Enterprise Cyber Security Tools
(http://iase.disa.mil/Pages/index.aspx#)
• Trellix ePolicy Orchestrator
• Assured Compliance Assessment Solution (ACAS)
Cloud Computing
• AWS Virtual Private Cloud (VPC)/Azure Virtual
Network (VNet)
• Elastic Compute Cloud (EC2)
• AWS Simplified Storage Service (S3)/Azure Blob
Storage
• Elastic Kubernetes Services (EKS)/Azure
Kubernetes Services (AKS)
• Directory Services and Identity and Access
Management (IAM)
Network Administration • Forescout Suite of network security tools http://iase.disa.mil/Pages/index.aspx
• Cisco Identity Services Engine (ISE)
• Cisco Switches
• Palo Alto Firewalls
• Voice over Internet Protocol (VOIP)
• TCP, IP, HTTPS, SSL, DHCP, DNS
• Knowledge of encryption, ports, certificate management
Monitoring
• InfluxDB
• Telegraf
• Grafana
• OpenSearch
C.4 General Requirements
C.4.1 Scope
The JITS - IDIQ contract vehicle streamlines the delivery and management of application and infrastructure services and functions for current and emerging requirements. The successful offeror shall have relevant experience in essential IT services and the functions listed within this document. Task orders may contain requirements for one to many of the IT services and functions listed.
The scope descriptions for potential task orders within this PWS outline the typical work requirements and potential work that may be issued at the discretion of the government. The scope described herein is meant to provide a general overview of the work acts and needs of
JWAC, but it is not intended to be limiting of future support that the agency may need from this contract. Examples of such future emergent needs may include, but not be limited to, the adaptation to and the use of Artificial Intelligence (AI), Internet of Things (IoT), Edge
Computing, Quantum Computing, High Performance Computing/Clustering, etc. The existing computing environments at JWAC consist of unclassified, secret, and top secret JCCE environments. Task orders may include some, or all, of the potential requirements that are presented in the sections below.
C.4.2 Surge Support and Subject Matter Expertise
In conjunction with Task Orders issued, additional support may be ordered at the discretion of the government. The contractor shall provide tiered support (Tiers 1 – 4) subject matter expertise on an ad-hoc/surge support or as required basis to support emergent needs with personnel in the required competencies to support additional requirements that arise during regular operations, integration of new services, or related cyber security requirements. JWAC expects that in some cases the contractor may need to reach out to vendors (such as Microsoft, CISCO, etc.) to support these tasks. The contractor shall provide adequate resources, who are cleared to the classification level specified for the requirements, to meet these requirements. Tasks orders will be negotiated and provide ample ramp up times to accomplish mission needs.
C.5 TASK ORDER EXAMPLE #1 – IT Support Services This task order will provide, onsite at JWAC, software development, data science, cyber security and system management support services for JWAC’s IT environments. The service provider shall provide all personnel, supervision and security clearances to effectively maintain and advance the existing JWAC Compartmented Computing Environment (JCCE) infrastructure, which includes four isolated production and two R&D environments. The service provider shall also provide software development solutions as needed to support JWAC’s internal customers and to support automation of the JCCE architecture. JWAC requires support services for specified tasks within JWAC’s General Services (GENSER), Sensitive Compartmented
Information (SCI), and Special Access program (SAP) offices.
C.5.1 System Administration & Operations Support
C.5.1.1 Provide via automated solutions System Administration and DevOps Engineering at the Tier 1-3 levels respectively in close coordination with a team of government civilians, military, and contracted personnel.
C.5.1.2 Maintain, administer, and automate all information network operations, software, and communications systems including system administration support.
C.5.1.3 Engineering support and system administration for all aspects of server and client systems, enterprise software, account management, cybersecurity of all networks utilized at the
JWAC, support for Cloud environments such as Azure, AWS, etc., remote distributed environment and the establishment of high-performance enabled platforms and AI solutions to enhance JWAC’s mission.
C.5.1.4 Provide IT personnel who shall efficiently and effectively support the Command’s Tier
1 and Tier 2 Service Desk (“Help Desk”) operations, with sufficient onsite personnel to accommodate the number of requests and other tasks received via JIRA, phone calls, Teams, email, and/or in-person walk-ins.
C.5.2 Windows System Administration and Operations Support
Requirements
C.5.2.1 The contractor shall have a detailed understanding of Windows and Linux systems and be able to apply that knowledge to perform systems administration and operation of
JWAC’s networks and system within the JWAC JCCE architecture described above.
C.5.2.2 The contractor shall operate, observe, administer, and upgrade computer systems, devices, and software to include configuration, provisioning for use, integration with storage and networking, load balancing and optimization, security patching, software deployment and installation, updating, backup, restoration, and shall include expertise in containerization technologies such as Docker and container orchestration platforms such as Kubernetes, encompassing the deployment, management, and scaling of containerized applications, as well as the configuration and management of Kubernetes clusters and their associated resources.
C.5.2.3 The contractor shall also provision and deliver computer systems and services, then ensure information systems and network appliances are operated, maintained, and disposed of in accordance with security policies and practices.
C.5.2.4 The contractor shall perform electronic and manual data transfer and certificate management.
C.5.2.5 The contractor shall maintain computer systems in a fully operational state through monitoring, alerting, troubleshooting and implementing remediation and restoration activities to a compliant operational state. This includes performing periodic reporting of system status, providing input into and maintaining Standard Operating Procedures (SOPs) and providing documentation of workflows, system configurations and routing tasks.
C.5.2.6 The contractor shall conduct the cybersecurity portion of the self-inspection’s checklist, review and provide technical and cyber security coordination on all Bodies of
Evidence that make up the authorization package, identify any and all vulnerabilities and implement countermeasures, and notify customer when changes occur that might affect authorization accreditation.
C.5.3 Linux Administration and Operations Support
C.5.3.1 The contractor shall provide Linux Administration support working in a mixed
Windows and Linux environment and shall have detailed knowledge and demonstrated experience in installing, upgrading and maintaining Red Hat Linux, using Ansible for configuration management, as per the JWAC JCCE architecture described above.
C.5.3.2 The contractor shall develop streamlined processes and maintain the computing environments with efficiency via automation scripts or other programming languages including utilizing the DevSecOps methodologies of system automation and management of cloud architectures. Programming and scripting support will be provided with one or more of the following languages: PowerShell, Java Script, Python, Bash.
C.5.3.3 The contractor shall manage Kubernetes namespaces and containers, optimize performance of the system environment including storage and networking, provide special system builds and maintenance and integration of Linux applications, and provide support to
JWAC IT partners providing systems, imagery, and data tools.
C.5.3.4 The contractor shall maintain health and performance of Linux systems (physical, virtual and containerized) on multiple networks, respond to monitored alarms and thresholds, and develop new monitoring requirements and automate recovery procedures for monitored conditions with scripts and workflows.
C.5.3.5 The contractor shall develop templates and scripts to perform automated administrative changes, patches and updates, configuration settings, and other system and infrastructure maintenance tasks such as system restart/rebuild/recovery, software installation and configuration.
C.5.3.6 The contractor shall perform troubleshooting activities on Linux systems and related environments which include diagnosing unique and complex system, network, and application issues, and assist with troubleshooting efforts during system outages and support system downtime efforts, exercises, and other special events that may occur outside of normal business hours.
C.5.3.7 The contractor shall create, update, and interpret software service architecture diagrams depicting service dependencies and interaction with other service components and services.
C.5.4 Cyber Security and Operations Support
C.5.4.1 The contractor shall have detailed knowledge and demonstrated experience in cyber security administration and operations and be able to apply that knowledge within the
JWAC JCCE architecture described in section C.2.
C.5.4.2 The contractor shall have strong working knowledge of security incident event management tools (SIEM) such as LogRhythm and be able to apply that knowledge to support all aspects of JWAC cybersecurity as the basis for the auditing and network security monitoring capability.
C.5.4.3 The contractor shall maintain the auditing/monitoring capability in a fully operational state by installing and maintaining software, monitoring system performance and function, troubleshooting, and restoring systems to correct operations; and shall confirm the operational status of the auditing/monitoring infrastructure before 0800 on regular work days.
C.5.4.4 The contractor shall operate scanning, patching and remediation tools.
C.5.4.5 The contractor shall administer, configure and monitor Linux-based workstations and servers hosting the cybersecurity architecture which includes clustered data and compute nodes.
C.5.4.6 The contractor shall have the ability to apply analytical and problem-solving skills to analyze data related to incident management and provide a written summary of analysis in order to improve IT service operations and prevent future events.
C.5.4.7 The contractor shall update, modify source code, scripts, and system configurations, in order to implement required cybersecurity features and capabilities.
C.5.5 Service Desk Administration
C.5.5.1 The contractor shall have knowledge and experience in desktop support and be able to apply that knowledge within the JWAC JCCE architecture described above.
C.5.5.2 The contractor shall have knowledge to support incident management processes and apply that knowledge in regards to (1) Service Strategy, (2) Service Design (3) Service
Transition, (4) Service Operation and (5) Continual Service Improvement.
C.5.5.3 The contractor shall provide service desk/help desk support during the working hours of 0700-1600 Monday through Friday.
C.5.5.4 The contractor shall provide maintenance, deployment, and enhancement to the desktops, servers, printers/peripherals, and network infrastructure. This includes performing initial tier 1 troubleshooting of all client systems and peripherals and escalating more challenging incidents to tier 2 administrators/operators work across service teams to investigate and resolve challenging incidents affecting their area of responsibility.
C.5.5.5 The contractor shall process all tier 1 service support requests and provide communication to the requestor on status and potential workarounds; and shall perform periodic reporting of system service status to include uptime, incidents, problems, and open issues, etc. The contractor shall provide system administration support and workflow development for incidents and asset management in Jira; and collaborate with customers and provide Jira tracking, workflow and reporting solutions to meet their requirements.
C.5.5.6 The contractor shall provide user account services including performing user certificate issuance.
C.5.5.7 The contractor shall provide tier 1 communication services of maintaining and managing Voice Over Internet Protocol (VOIP) communications and managing land line telephone systems.
C.5.5.8 The contractor shall perform data transfers between JWAC networks.
C.5.5.9 The contractor shall be able to lift and move equipment weighing up to 50 pounds.
C.6 TASK ORDER EXAMPLE #2 – JCCE Development & Support
Services
C.6.1 General Requirements
C.6.1.1 The contractor shall execute workflows through an automation and orchestration platform for services.
C.6.1.2 The contractor shall coordinate with Cyber Security team members to ensure secure system operations in all aspects of system and service development and maintenance, per
JWAC’s DevSecOps implementation.
C.6.1.3 The contractor shall ensure compliance of all assigned hardware and equipment and subsequent configurations to the most recent Information Assurance Vulnerability Alerts
(IAVAs) and Security Technical Implementation Guides (STIGs). JWAC performs cyber security compliancy scans on assigned systems at least monthly but may scan as often as needed to ensure compliancy with all IAVAs. The contractor shall ensure new systems (end client or server) have been scanned for 100% compliancy or establish an approved waiver from JWAC Cyber Security.
C.6.1.4 The contractor shall assist with troubleshooting efforts during system outages and support system downtime efforts, exercises and other special events which may occur outside of normal business hours.
C.6.1.5 The contractor shall maintain equipment and software maintenance records, submit support calls for replacement, and repair of hardware and software that is under warranty coverage or under maintenance, and track calls to completion.
C.6.1.6 The contractor shall serve as custodian for equipment and classified material and support inventory activities and reconciliation of inventory results.
C.6.1.7 The contractor shall conduct research on products, services, protocols, and standards in support of procurements.
C.6.1.8 The contractor shall advise management and users on software and hardware solutions, or upgrades that improve systems and operations effectiveness for assigned systems.
C.6.1.9 The contractor shall develop system administrative scripts in a version control system as identified in the JWAC JCCE architecture described in section C.2.
C.6.1.10 The contractor shall participate in regular team meetings to discuss accomplishments, progress and issues related to tasking and shall provide, as required, formal/informal briefs, presentations, and reports.
C.6.1.11 The contractor shall provide input to maintain Standard Operating Procedures
(SOPs) and provide documentation of service workflows, system configurations, and routine tasks, currently accomplished in Jira.
C.6.1.12 The contractor shall utilize a monitoring system designated by JWAC to create systems and services that automatically detect and recover from anomalous events.
C.6.1.13 The contractor shall provide Platform as a Service (PaaS), Infrastructure as a
Service (IaaS) and Function as a Service (FaaS) system admin support both in Windows and
Linux to provision cloud resources to include virtual private cloud (VPC).
C.6.1.14 The contractor shall ensure information systems and network appliances are operated, maintained, and disposed of in accordance with security policies and practices.
C.6.2 JCCE CORE SUPPORT
C.6.2.1 The contractor shall have detailed understanding of software development using
DevOps practices (e.g., CI/CD, Version Control, and IDEs) and experience with Windows
Server and Enterprise Linux, and be able to apply that knowledge to the requirements defined below. For workload planning the contractor should note that to complete all of the tasks associated with the JCCE Core Support Requirements it has inherently taken approximately three (3) senior level and three (3) mid-level Full Time Equivalents (FTEs) historically.
C.6.2.2 The contractor shall provide the software development services to support the implementation, monitoring and management of five key areas of the JCCE environment:
(1) transition and operation services, (2) identity, authentication and authorization (IAA) services, (3) compliance services, (4) monitor, alert and remediation services, and (5) automation/orchestration services.
C.6.2.3 The contractor shall create, update, and interpret software service architecture diagrams depicting service dependencies and interaction with other service components and services. These diagrams will be available for the contractors working on-site.
C.6.2.4 The contractor shall develop automated workflows, scripts, and configurations using
Ansible for streamlined system and service installation, configuration, and management.
This includes implementing monitoring checks and remediations for automated self-repair capabilities.
C.6.2.5 The contractor shall develop templates and scripts to perform automated administrative changes, patches and updates, configuration settings, and other system and infrastructure maintenance tasks such as system restart/rebuild/recovery, software and patch installation and configuration.
C.6.2.6 The contractor shall develop blueprints and actions for automated system and service provisioning, recovery and processes using automation tools such as CloudBolt.
C.6.2.7 The contractor shall utilize configuration management tools such as the Ansible
Automation Platform to maintain system consistency, integrity, and reliability.
C.6.2.8 The contractor shall utilize a monitoring system designated by JWAC to create systems and services that automatically detect and recover from anomalous events.
C.6.2.9 The contractor shall apply knowledge and skills with Microsoft SQL Server DB, in fulfilling the requirements defined in the PWS.
C.6.2.10 The contractor shall be required to be proficient in the scripting languages of
PowerShell/JavaScript/Python/Bash, to adequately support requirements defined in the
PWS.
C.6.2.11 The contractor shall apply their knowledge of network technologies and techniques such as TCP, IP, HTTP, HTTPS, SSL, DHCP, DNS, encryption, ports and security certificates in fulfilling the requirements defined in the PWS.
C.6.2.12 The contractor shall provide services to develop scripts and workflows for the automated installation, configuration, management and monitoring of a variety of IAA services to include Microsoft Active Directory 2022+, DNS, DHCP, and certificate services within the JCCE environment.
C.6.2.13 The contractor shall provide services to develop scripts and workflows for the automated installation, configuration, management and monitoring of a variety of compliance management services to primarily consist of Trellix antivirus, DISA Assured
Compliance Assessment Solution (ACAS) and Microsoft Windows Server Update Services
(WSUS) within the JCCE environment.
C.6.2.14 The contractor shall provide services to 1) design, develop, and enhance continuous monitoring solutions within the JCCE environment OpenSearch, Logstash; 2) develop Ansible playbooks to configure systems and services and script in a variety of languages including python, bash, and PowerShell to implement automated remediation actions in response to monitored conditions.
C.6.2.15 The contractor shall provide services to develop scripts and workflows for the automated installation, configuration, management and monitoring of a variety of automation related software services to include CloudBolt, Microsoft Windows Remote
Management (WinRM)/SSH, Microsoft Internet Information Services (IIS) Web Services, and the NGINX/Apache Web (HTTP) Server.
C.6.2.16 The contractor shall provide services to develop scripts and workflows for the automated installation, configuration, management, and monitoring of a variety of file, database and data labeling software services and protocols to include Microsoft SQL Server, Microsoft Internet Information Services (IIS) Web Services, Common Internet File System protocol, Network File System protocol and the Apache Web (HTTP) Server.
C.6.2.17 The contractor shall provide subject matter expertise as required to support short-term goals and stretch goals with personnel in the required competencies to support anomalies that arise during implementation of capabilities and services.
C.6.2.18 The contractor shall participate in frequent team meetings to discuss accomplishment, progress and issues related to the requirements defined in section C.4 on an as needed basis determined by the governments need.
C.6.2.19 The contractor shall provide services to install, upgrade and maintain Red Hat
Linux OS distributions.
C.6.2.20 The contractor shall provide services using version control systems such as GitLab.
C.6.2.21 Contractor must have experience with DevSecOps delivery pipeline methodologies and practices.
C.6.2.22 Contractor must have experience with Kubernetes orchestration, and developing containerized applications.
C.6.2.23 The contractor shall provide services to ensure compliance of all assigned hardware and equipment and subsequent configurations to the most recent IA Vulnerability
Alerts (IAVAs) and Security Technical Implementation Guides (STIGs). JWAC performs cyber security compliancy scans on assigned systems at least monthly but may scan as often as needed to ensure compliancy with all IAVAs. The Contractor will ensure new systems have been scanned for 100% compliancy or establish an approved waiver from JWAC
Cyber Security.
C.6.2.24 The contractor shall have experience with end-user customer service, incident management tools, be able to work under deadlines, and work well independently or as a member of a team.
C.6.3 JCCE LAB (JCCE-L)
C.6.3.1 The contractor shall update and maintain an existing code base consisting of Ansible playbooks, and automation tools similar to CloudBolt in support of multiple environments consisting of both Microsoft Windows servers/workstations and Linux servers/workstations.
These updates are based on software and operating system updates and when Cyber Security mandates are issued.
C.6.3.2 For workload planning the contractor should note that to complete all of the tasks associated with the JCCE Lab effort it has inherently taken approximately five (5) Full Time
Equivalents (FTE) historically.
C.6.3.3 The contractor shall develop and modify code to automate the deployment of new services per request by the Technical Point of Contact (TPOC) in the lab environments primarily utilizing Docker containers deployed and monitored via Rancher.
C.6.3.4 The contractor shall configure, provision, and update a VMware vSphere/ESXi environment including modifying existing code (workflows and actions) for CloudBolt cloud management platform or similar automation software.
C.6.3.5 The contractor shall develop and modify software to configure, provision, and update a Cisco networking environment utilizing a Representational State Transfer (REST)
Application Program Interface (API).
C.6.3.6 The contractor shall develop and modify software to automate the configuration, provisioning and updating of network attached storage devices.
C.6.3.7 The contractor shall troubleshoot, remove, repair, and upgrade IT systems and hardware in the lab environments.
C.6.3.8 The contractor shall have knowledge of design, deployment and management of provisioning servers to deploy Windows and Linux machines with secured OS images.
C.6.3.9 The contractor shall develop software in a Linux environment utilizing a source control repository.
C.6.3.10 The contractor shall create, update, and interpret software service architecture diagrams depicting service dependencies and interaction with other service components and services.
C.6.3.11 The contractor shall develop and modify templates and scripts to perform automated administrative changes, patches and updates, configuration settings, and other system and infrastructure maintenance tasks such as system restart/rebuild/recovery, software installation and configuration.
C.6.3.12 The contractor shall utilize a monitoring system designated by JWAC to create systems and services that automatically detect and recover from anomalous events.
C.6.3.13 The contractor shall apply knowledge of network technologies and techniques such as Transmission Control Protocol (TCP), Internet Protocol (IP), Hyper Text Transfer
Protocol (HTTP), HTTP Secure (HTTPS), Transport Layer Security (TLS), Dynamic Host
Configuration Protocol (DHCP), Domain Name Service (DNS), encryption, ports and security certificates in fulfilling the requirements defined in the PWS.
C.6.3.14 The contractor shall modify and develop scripts (PowerShell, JavaScript, or other) and workflows for the automated installation, configuration, management and monitoring of a variety of compliance management services to include Trellix antivirus, DISA Assured
Compliance Assessment Solution (ACAS) within the JCCE environment.
C.6.3.15 The contractor shall have experience with end-user customer service, incident management tools, be able to work under deadlines, and work well independently or as a member of a team.
C.6.3.16 The contractor shall have knowledge of DoD Risk Management Framework
(RFM) based security controls, Cyber policies, and system security hardening process include patching, scanning and updates.
C.6.3.17 The contractor shall have knowledge of the design, deployment and management of configuration management environments to maintain systems in compliance with DoD security controls and policies.
C.6.3.18 The contractor shall have knowledge of the installation, configuration, deployment and management of network devices such as switches, routers, firewalls and virtual networking solutions including automated deployment, security hardening configuration and troubleshooting.
C.6.4 (U) JCCE SOFTWARE DEVELOPMENT (JCCE-SDIMS)
C.6.4.1 The JWAC architecture is based on technologies and platforms which currently include: Windows Server, Enterprise Linux, Windows .NET, Java, Microsoft Structured
Query Language (SQL) Server, HBase, Cloudera Hadoop, Microsoft Visual Studio, GitLab, Extract Transform Load Frameworks, NiFi, PowerShell, and MongoDB. JWAC is implementing a Development Security Operations (DevSecOps) architecture that allows for continuous delivery (CD) and continuous release (CR) of service/systems (software or hardware) and offers the ability for the system to detect its level of functionality and to self-correct.
C.6.4.2 Software engineering services expand into all parts of Application Lifecycle
Management including hardware and software research and recommendation, interface design and refinement, automated testing, automated deployment, data security, database design and implementation, and application development and integration. The development efforts include areas such as analytical modeling, geographic information systems, multi-threading, data preparation and manipulation, exception handling, product development and training, web technology integration, software packaging, and application security development. Most of this work is developed on or for the JWAC in-house system.
However, a number of the capabilities are currently, or will be, exported or integrated with existing DoD Cloud services. To assist the contractor in estimating workload/support requirements, the contractor should know that to complete all of the tasks associated with
SDIMS it has inherently taken approximately eight (8) Full Time Equivalents (FTE) historically. TS//SCI cleared personnel are preferred; however, this requirement can support up to three personnel cleared only to SECRET.
C.6.4.3 Software development will entail a wide range of aspects to include:
1) Creation of new and unique software applications used only at JWAC
2) Integration of COTS/GOTS/Open-Source packages into JWAC analytical workflows
3) Plugins to existing applications and quick turn-around prototypes or point solutions
4) Securing applications and development processes
5) Automation of software development, release, and deployment processes
6) Upgrades and maintenance of existing applications and scripts
7) Integration with DoD Cloud services to include creation of new Cloud services, migration of existing intranet services, and integration with existing Cloud services
8) Architecture design, documentation, and reviews/evaluation of software packages/services
C.6.4.4 The following table describes the JWAC Enterprise Information System (EIS) required for SDIMS. All versions in the table below are subject to lifecycle upgrades.
Table 2: EIS
Data
Code and data complexity
JWAC's current software development environment includes the following types of software languages: C#, Java, JavaScript, Python, Linux
Shell/Bash, and PowerShell.
The following application types: Windows Applications, Blazor, WPF, Asp.Net Core Web Apis, and Python Fast Web Apis.
Historically we have been a Windows fat client application shop with the applications written in C# or VB.Net which have been deployed using an
MSI from MCM, formerly known as SCCM. This means we have to support legacy application types such as: Analyst Notebook Plugins, ArcGIS Plugins, Text Extraction, Open Modeling Environment, Product
Management, Unstructured Data Analysis, Point Solutions for parsing and data transformation, VBA Macros, build automation to release software on multiple machines utilizing PowerShell scripts, Automated scripts to stand up new database, web, or modeling servers.
Current stance is that all new development will adhere to the Software
Quality Assurance Framework (SQAF) where safe, secure, and compliant software is written and deployed. New applications should be using Cloud
Native technologies such as Docker images as well as other services provided by Cloud providers. Microservice architectures with contained databases are a priority. All applications should be built and deployed using a CICD pipeline with a preference of the pipeline being one of our approved pipelines.
JWAC's projects vary from a 1-person project to multi-person project teams consisting of Government and Contractor personnel.
Stability Varies based on complexity and customer needs.
Number of concurrent users Varies, typically 1-20 within an application.
Application age
Differs between projects and varies widely. Enterprise and legacy projects have been known to last longer than 10 years while point solutions last anywhere from 1 to 3 months.
Life expectancy Multi-year projects.
Operating system Windows 11, Red Hat Linux
Platform Microsoft Server 2022+
Programming Languages Mastered: (C#, Python) Knowledge of: VB.Net, Java, Javascript, PowerShell, Linux/Bash Shell, C++
Database SQL Server 2022+, PostgreSQL 14+, Accumulo, MongoDB
COTS
Visual Studio 2022+, ArcGIS Desktop 10.x, ArGIS Pro, Analyst
Notebook 9.x, DevExpress 24+, GoDiagram 5.x, Remote View 4.x, Jira Service Management, Microsoft Office 365/2021+, Eclipse 4.x, GIT, NiFi 1.x, MS SQL Server 2022+, GitLab, .Net Core 8+, .Net
Framework 4.7+, Java
C.6.5 Application of Software Development
C.6.5.1 Processes, Guidelines and Principles
The Contractor shall follow JWAC working processes as specified in the Performance Work
Statement (PWS) with GSA Contracting Officer Representative (COR) and JWAC Technical
Point Of Contact (TPOC) oversight.
Additionally, the Contractor shall follow all JWAC software development processes, guidelines, principles, current/emerging configuration management practices, secure programming practices/procedures (unit tests, code analysis, etc.), compliance guidelines, and standards.
C.6.5.2 Scope and Lifecycle Responsibilities
The Contractor shall be accountable for the assigned product lines, software applications, or services to include conception, requirements, design and architecture, test, and release. These products will be developed for customer-bases that average two dozen or less assets who focus on iterative research & development. There is an expectation of production releases to be occurring at least once a month.
C.6.5.3 Project Management and Coordination
The Contractor shall utilize JWAC’s standard project management and coordination tools to track progress, maintain source control, and provide status on code commits if the application is developed in-house/JWAC cloud. The current standard tooling used for these purposes are Jira and GitLab, for project tracking and source control, continuous integration and continuous delivery (CI/CD) pipelines. The current project management framework is based on the Scaled
Agile Framework (SAFe) (https://www.scaledagileframework.com/, refer to Essential SAFe) development model. Each application is planned quarterly for a twelve (12) week train and is released a minimum of every two (2) weeks with emerging bug fixes occurring more often. High level progress shall be logged on the Software Development SAFe Board and progress is briefed to management at least every two (2) weeks.
C.6.5.4 Team Meeting Participation
The Contractor shall participate in team meetings to discuss accomplishments, progress and issues related to the software and services defined previously. These meetings can vary in frequency from daily to bi-weekly.
C.6.5.5 Teamwork
The Contractor shall work independently and as part of a team. When on a team, the team will consist of both government and contractor software developers as well as product owners, system administrators, and various stakeholders.
C.6.5.6 Communication
The Contractor shall clearly communicate to customers potential resolutions, strategies, options, issues, bugs, and other project related actions.
C.6.5.7 Briefings, Proposals, and Documentation
The Contractor shall develop and deliver briefings, technical proposals, and architecture documentation (e.g., service architecture diagrams depicting service dependencies and interaction with other service components and services) that are presented within the software development group.
C.6.5.8 Requirements and Implementation
The Contractor shall collect and analyze varying customer application requirements and implement solutions to include creating new software solutions, adding on to existing applications, creating new interfaces, creating and/or running automated tests, fixing bugs in existing applications, creating /updating plug-ins, creating new services, automate software deployments, and creating/updating specialized macros to meet customer needs. Requirements shall be documented as work items.
Workflow and Design Documentations
The Contractor shall create workflows and design documentation.
Previous requests for design documentation have included methods, configurations, best practices, design patterns, visualizations, templates, user interfaces, and entire applications.
These shall be documented as requested and stored in source control.
C.6.5.9 Development & Deployment
The Contractor shall develop methods, configurations, practices, design patterns, visualizations, templates, user interfaces, and applications.
C.6.5.10 Database Development
The Contractor shall utilize a JWAC approved database technology in fulfilling the requirements defined in this Task Order (TO).
C.6.5.11 Interface Administration
The Contractor shall administer the interfaces of JWAC's applications by assisting with front-end functionality in the form of debugging tasks, development of new functions, and updating the client-facing look and feel.
C.6.5.12 Automated Scripts
The contractor shall develop, maintain and modify templates and scripts to perform automated administrative changes, patches and updates, configuration settings, software management functions, and other software, system and infrastructure maintenance tasks such as system restart/rebuild/recovery, software installation and configuration.
The contractor shall modify and develop scripts (PowerShell, JavaScript, or other) and workflows for the automated installation, configuration, management and monitoring of a variety of software compliance management services (e.g., anti-virus, code analysis tools).
C.6.5.13 Evolving Data Requirements
The Contractor shall respond to real-world evolving requirements and develop solutions involving varying data formats on an extremely condensed timeline. Examples of these requests can take the form of small standalone applications as well as embedded macros or plugins for traditional commercial software like Microsoft Word, Excel, and PowerPoint that need to be delivered in timeframes that can vary from hours to weeks.
C.6.5.14 Source Control
The Contractor shall store deliverables including code, scripts, and templates using JWAC’s source control tools and methodologies.
C.6.5.15 Automation and Software Deployment Tools, Scripts, and Add-Ins
The Contractor shall develop DevSecOps automation and software deployment tools, scripts, and add-ins for use with existing and new CD and CR software services in JWAC’s IT environment.
The project team (see 3.1.3.2) will participate together in the entire service lifecycle including design, development, testing (which includes Test Driven Development (TDD)), build/test automation, and release configuration.
C.6.5.16 Troubleshooting Support
The Contractor shall provide troubleshooting support to assist in resolving technical issues and system degradation. Support shall include triage and assessment, root cause analysis, system restoration, and documented after-action recommendations. The Contractor shall provide training, assistance, briefings, and written job aids for software services provided to end users.
C.6.5.17 Tuning, Analysis, Backup, and Recovery
The Contractor shall conduct performance tuning, log analysis, and backup and recovery processes.
C.6.5.18 Monitoring and Automation
The Contractor shall develop monitoring and automation services to integrate with JWAC’s architecture and will implement automated remediation of services based upon failed monitoring checks, if possible.
The Contractor shall monitor and maintain/repair applications.
The Contractor shall respond to monitored alarms and thresholds within one business day according to mission needs.
The Contractor shall develop and maintain application monitoring requirements and automated detection of and recovery procedures for monitored conditions with scripts and workflows.
C.6.5.19 Documentation
The Contractor shall deliver clear documented requirements, specifications, processes, documented technical environments specifications, processes and procedures, testing plans, and project plans.
C.6.5.20 Knowledge Base Documentation and Inventory
The Contractor shall maintain proper knowledge management practices in order to organize and distribute knowledge, develop and train assets, and implement and maintain technologies. The resulting knowledge base and documentation should be relevant and easily filterable so it can be used accurately by the customers.
C.6.5.21 Downtime Support
The Contractor shall assist and/or support IT downtimes as defined in Section C.4.9.3.
C.6.5.22 Business Management Efficiency and Optimization Tool Suites - Website and Portal
The Contractor shall gather requirements, design, prototype, package and perform maintenance for cloud service based external facing JWAC website and portal for use across multiple classification domains.
The Contractor shall perform a Cloud Service Provider evaluation, load testing, compliance verification and implementation, and transition of software services.
C.6.5.23 Financial and Budget Management
The Contractor shall gather requirements, design, prototype, package, and perform maintenance for program and budget management efficiency tools and services to support procurement development, execution, and budget planning.
C.6.5.24 Task Management Tools and Services
The Contractor shall integrate and perform maintenance for task management tools and services with product management portal to include API interface and web services enhancements.
C.6.5.25 Workforce Development, Talent Management Tools and Services
The Contractor shall gather requirements, design, prototype, package and perform maintenance for workforce development and talent management tools and services.
C.6.5.26 Recruiting and Hiring Efficiency Tools and Services
The Contractor shall gather requirements, design, prototype, package and perform maintenance for recruiting and hiring efficiency tools and web services.
C.6.5.27 Analytical Tool Maintenance, Efficiency, and Optimization Tool Suites (Authorization
Service). The Contractor shall perform maintenance, enhancements, and upgrades to the authorization web services.
C.6.5.28 JWAC Framework Utilities and Libraries
The Contractor shall perform maintenance, enhancements, and upgrades to the JWAC
Framework NuGet library.
C.6.5.29 (U) DevSecOps Automation and Development Optimization Tools
The Contractor shall perform maintenance, enhancements, and upgrades to existing DevSecOps automation and software deployment tools, scripts, and add-ins to existing CD and CR application services.
The Contractor shall perform research, design, and development of a DevSecOps automation and software deployment model for a Linux-based development environment.
C.6.5.30 String Manager Web Services
The Contractor shall develop feature enhancements, upgrades, and perform maintenance to
String Manager web services to include certificate authentication and a load balanced high availability service architecture.
C.6.5.31 Assembly Resolver Library Migration
The Contractor shall migrate Assembly Resolver Library from Visual Basic to C# language
C.6.5.32 Common File Format Library Migration
The Contractor shall migrate Common File Format Library from Visual Basic to C# language and migrate the base file technology from Extensible Markup Language to JavaScript Object
Notation.
C.6.5.33 Maintenance for Data Processing and Integration Tools and Modules
The Contractor shall gather requirements, design, prototype, package and perform maintenance for data processing and integration tools and modules within and between existing JWAC, COTS, and GOTS applications.
C.6.5.34 Analytical Tool Suites Research and Development (Point Solutions)
The Contractor shall develop quick turnaround (typically completed in less than two weeks of development or a period defined by the TPOC) point solutions for JWAC users including tasks similar to implementing geospatial solutions, data parsing and transformation, pattern detection-based searching of multiple file types, preparing and manipulating data, and data verification.
C.6.5.35 Data Integration and Processing Research and Development, Data Management Text
Architecture
The Contractor shall develop, integrate, upgrade, and maintain a diverse data management text architecture built largely with open source technologies in a distributed computing Linux environment on an as needed basis determined by the TPOC.
The Contractor shall integrate, configure and tune COTS, GOTS and open source technologies.
Examples are: Apache SOLR, NiFi, PostgreSQL, SQLite, Tika, and Automated Message
Handling System.
The Contractor shall perform periodic, typically quarterly, architecture reviews of JWAC’s existing text architecture tools, approaches, extraction engines, indexing engines, and maintenance-overhead resulting in a recommendation for the optimization, enhancement and adjustments.
The Contractor shall enact approved recommendations from the text architecture services review.
C.6.5.36 Modeling Tool Suites Research and Development (Plugins and Modeling Tools)
The Contractor shall create…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .