Unclass IT SOW_Dec2023.pdf

PDF 476 KB Posted

Attached to
F-35 Program Unclassified IT Support Federal contract opportunity
Solicitation number
N0001923UNCLASSIFIED
Issued by
Department of the Navy Naval Air Systems Command

About this file

This performance work statement outlines information technology support services required by the F-35 Joint Program Office. The contractor shall provide program management, operations and maintenance, service desk support, asset management, and engineering services. Key requirements include managing the F-35 Joint Virtual Enterprise network and workstations; providing service desk, desktop, and helpdesk support; maintaining telecommunications and video teleconferencing infrastructure; and performing systems administration, firewall management, and data backup services. The contractor must have U.S. citizen staff and comply with Department of Defense security standards. The period of performance is one base year with four optional one-year periods. Locations of performance include sites in the United States, Japan, and South Korea.

View the file

Other files for this federal contract opportunity

Other files attached to F-35 Program Unclassified IT Support, newest first.
File Type Posted
RFI Questions and Answers-27 Oct 23.docx DOCX document
RFI Questions and Answers-Part 1.docx DOCX document
Attachment1-Unclass IT SOW_Draft_Oct 2023.pdf PDF
REQUEST FOR INFORMATION_Unclass_23 Oct.pdf PDF
REQUEST FOR INFORMATION_Unclassified IT 5 Oct 2023.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS) FOR

INFORMATION TECHNOLOGY (IT) KNOWLEDGE BASED SERVICES (KBS) IN

SUPPORT OF THE F-35 LIGHTNING II JOINT PROGRAM OFFICE (F-35 JPO)

1.0 SCOPE

The purpose of this effort is to obtain Contractor support to provide Information Technology (IT) and Information Assurance (IA)/Cybersecurity Services (CS) to the F-35 Lighting II Joint

Program Office (F-35 JPO) Virtual Enterprise (JVE) network and standalone workstations. The

IT Services support the F-35 JPO mission and enhance its effectiveness, efficiency, and productivity by providing the Government with a full range of IT and CS services. The required services consist of program management, enterprise performance management, enterprise architecture, emerging capabilities and requirements implementation, life cycle management, operations & maintenance, enterprise data management, service desk support, IT training, and

CS support. These services are critical to the successful fielding of F-35 mission capabilities.

The Contractor shall provide resources, materials, and services as necessary to perform the tasks defined in this PWS, except as specified in the Government-Furnished Resources and Property list. Operating, maintaining, and properly managing the life cycle of hardware, software, and services is the crucial, primary service provided by this contract. Auxiliary IT engineer support will be provided to the F-35 Autonomic Logistics Information System (ALIS) team, as well as

CS support to the Air Systems team.

The F-35’s classified communications also traverse the JVE backbone. The Contractor shall provide networking services in support of the classified networks requirements by maintaining the JVE network and coordinating connections, changes, outages, etc. with the Contractor responsible for the classified systems. The Contractor shall ensure that service is maintained across the JVE network up to the switch port feeding the Tactical Local Area Network

Encryption (TACLANE) or other encryption device where support falls to the Contractor responsible for the classified system(s).

In addition to F-35 JPO-controlled networks, Government and Contractor personnel may require access to services provided on other networks. The F-35 JPO has established several trusted connections to include: af.mil, navy.mil, Lockheed Martin (LM) Autonomic Logistics

Information System (ALIS), and LM Failure Reporting, Analysis and Corrective Action System

(FRACAS). The Contractor shall maintain the JVE connections to the aforementioned systems and will work with those managing those systems to trouble-shoot issues when required.

1.1 Background

The F-35 JPO is a joint, multi-national program. It is the Department of Defense's (DoD) focal point for defining affordable next generation strike fighter aircraft weapon systems among the

United States (U.S.) Air Force (USAF), U.S. Navy (USN), U.S. Marine Corps (USMC), and

U.S. allies composed of seven (7) cooperative program partners: the United Kingdom, Italy, Netherlands, Canada, Australia, Denmark, and Norway. The F-35 JPO’s objective is to develop and deploy the F-35 Air System (AS), a three (3) variant family of highly common 5th

Generation strike fighter aircraft. The international nature of the F-35 JPO combined with the highly sensitive technologies of the total AS, requires comprehensive IT and CS services to ensure proper technology protection and dissemination for the successful execution of the F-35

JPO.

2.0 APPLICABLE DOCUMENTS

The Government will provide the Contractor copies of, or access to, all required directives, publications, and documents, as available.

A comprehensive list of Department of Defense (DoD) issuances and directives can be found at the following URL: https://www.esd.whs.mil/dd/. Department of the Navy issuances and directives can be found at: https://www.secnav.navy.mil/doni/allinstructions.aspx. US Air Force directives can be found at: http://www.e-publishing.af.mil/. Throughout the life of this contract, if any policy, instruction, or regulation is replaced or superseded, the replacement or superseding version shall apply. The Contractor is responsible for researching and complying with any additional regulations applicable to the task areas in which they are involved. Some cited in this effort include, but are not limited to:

• Section 508 Amendment to the Rehabilitation Act of 1973 - http://www.section508.gov/

• DoDD 8140.01, Cyberspace Workforce Management

• DoD 8570.01-M, Information Assurance Workforce Improvement Program

• DoD 5220.22-M Ch 2, National Industrial Security Program Operating Manual

(NISPOM)

• System Authorization Access Request (SAAR) form (DD FORM 2875, Rev 5/22)

• DoD 5500.07-R, Department of Defense Joint Ethics Regulation

• DoD 5500.7-R, Standards of Conduct

• DODI 5200.48, Controlled Unclassified Information, 6 Mar 2020

• DoD 5400.7-R, Freedom of Information Program Chapter 3 (pages 31-42) Sep 1998

• DoDD 5230.24, Distribution Statements on Technical Documents, Change 1, Effective

28 Apr 2016

• SECNAVINST 5211.5E

• SECNAVINST 5510.30B

• SECNAV M-5510.36, Information Security Program, 30 Jun 2006

• SECNAV M-5510.30, Personnel Security Program Jun 2006

• OPNAVINST 3440.17A, Navy Installation Emergency Management Program, 1 Aug

• SECNAVINST 5239.20A, Department of the Navy Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification

• SECNAV M-5239.2, DON Information Assurance Manual

• SECNAVINST 5211.5E, “Department of the Navy Privacy Program”

3.0 REQUIREMENTS

3.1 General Requirements

The Contractor shall be responsible for total lifecycle management of systems and services, as well as the associated tasking and the Contractor shall ensure that no hardware, software, or services will reach end-of-life on the F-35 JVE. The Contractor shall be responsible for technical refresh as requested by the Government.

The Contractor’s team shall be responsible for performance of the tasks and activities, as specified within this PWS, to support the following: the Government’s day-to-day IT operations management processes pertaining to IT service operations; IT engineering activities; continual service improvement across the Government’s enterprise; and managing and maintaining CS integrity of all servers, devices, storage, or cloud-based computing resources from external and internal security threats.

3.1.1 Work Location and Facilities

3.1.1.1 Work Locations & Staffing

The principal place of performance for this contract is Arlington, VA where there are numerous

F-35 JPO-leased facilities.

Below is the list of the current F-35 Program’s operating sites.

Tier 1 – JVE Users, Major IT Infrastructure, and On-Site Service Desk Support

• Arlington, VA

• Edwards Air Force Base, CA

• Manassas, VA

Tier 2 – JVE Users, Minor IT Infrastructure, and On-Site Service Desk Support

• Eglin Air Force Base, FL

• Naval Air Station Patuxent River, MD

• Fort Worth, TX

• Wright Patterson Air Force Base, OH

• Naval Air Weapons Station China Lake, CA

• Naval Air Station Point Mugu, CA

• Naval Air Station Jacksonville, FL

• Naval Support Activity Lakehurst, NJ

• Naval Air Warfare Center Training Systems Division, Orlando, FL

• Hill Air Force Base, UT

Tier 3 – JVE Users & Minor IT Infrastructure

• Langley Air Force Base, VA

• Marine Corps Air Station Beaufort, SC

• Marine Corps Air Station Cherry Point, NC

• Marine Corps Air Station Yuma, AZ

• Luke Air Force Base, AZ

• Springfield, VA

• Norfolk, VA

• Tokyo, Japan

• Cheongju, Republic of Korea

The term “Major IT Infrastructure” refers to servers, networking hardware, storage systems, power and cooling systems, backup and disaster recovery systems, monitoring and management systems, and security systems. The term “Minor IT Infrastructure” refers to networking hardware, monitoring and management systems, and other infrastructure primarily centered on supporting users across geographically distributed sites.

3.1.1.2 Staffing

The contractor must procure Key Position personnel (KP) in accordance with Attachment 9, Position Requirements, annotated in column F, Key Personnel.

3.1.1.0 Facilities

Contractor facilities for the Program Manager and Contractor staff shall be located at a

Contractor's site within one (1) miles of the F-35 JPO headquarters site in Arlington, VA. The

Government will supply office space, computer equipment, telephone, scanners, and reproduction resources when the Contractor is working at a Government site as required for performance of the contract. JVE computers and peripherals will be supplied by the Government to Contractor personnel in Arlington, VA directly supporting the Operations and Maintenance

(O&M) of the network. All office supplies shall be provided by the Contractor for performance of this contract. There is no expectation the Contractor will access corporate applications from

Government networks.

3.1.2 Hours of Operation

As an enterprise-wide service provider, the Government provides services to customers 24 hours per-day/365 days per-year. The Contractor shall provide on-site services from 0600 to 1800

(local time) at all sites listed in Section 3.1.1.1. All times are in the local time zone of the site, five days a week, excluding weekends and Federal holidays. The Contractor shall provide ‘on call’ service for enterprise support during all other times. After-hours support shall respond to site-wide or enterprise-wide outages caused by failure or outage of network infrastructure. This support is not intended to include Service Desk or individual workstation outages.

3.1.3 Contract Deliverable Requirement List (CDRLs) (Exhibit B)

The following contract deliverables shall be provided to the Government. All deliverables must meet professional standards and meet the requirements set forth in contractual documentation.

All CDRLs within this PWS shall be posted within the specified timelines and frequency of occurrence as outlined in the CDRLs. Notice of posting shall be sent to relevant Government personnel as identified on the CDRL.

CDRLs denoted with an asterisk (“*”) are required to be maintained in the Enterprise

Technology Library and updated as necessary for real-time accuracy, reference, and use.

Table 1:

CDRL Title

B001 KICK-OFF MEETING AGENDA AND SLIDES

CDRL Title

B002 MONTHLY STATUS REPORT

B003 TRIP REPORTS

B004 PROBLEM NOTIFICATION REPORTS (PNR)

B005 CONTRACT MANAGEMENT PLAN

B006 MEETING MINUTES

B007 TRANSITION-IN PLAN

B008 TRANSITION-OUT PLAN

B009 CONCEPT OF OPERATIONS

B010 IN-PROGRESS REVIEW (IPR) MINUTES

B011 PROJECT MANAGEMENT PLAN

B017 INFRASTRUCTURE IMPROVEMENT PLAN

B018 IT ROADMAP

B019 CUSTOMER SURVEY DATA REPORT

B021 TELEPHONY SUPPORT PLAN

B022 PHYSICAL INVENTORY REPORT

B024 SUMMARY REPORT OF SYSTEM PATCHES AND HOTFIXES

B031 DAILY SYSTEMS STATUS REPORT

B035 MONTHLY EXPENDITURE REPORT

B036 WEEKLY PERSONNEL STATUS REPORT

B038 SERVICE LEVEL REPORTING

3.1.4 Contractor Travel

In support of this contract, some CONUS and OCONUS travel may be required, as directed by the Government. The Contractor shall request approval to travel using a Travel Authorization

Request (TAR). The request shall be sent to the Contracting Officer’s Representative (COR), and COR approval must be obtained prior to travel and prior to incurring any travel costs.

The TAR will include the following:

• Contract Number

• Name of Traveler

• Dates

• Origin and Destination

• Organization to be visited

• Purpose of Travel

• Estimated Airfare

• Estimated Lodging within regulatory limits

• Estimated Per Diem

• Estimate Ground Transportation

• POV Use

• Miscellaneous Costs

• Justification as to why teleconferencing or video teleconferencing cannot be used

• Trip Report

Reimbursement for travel performed shall be in accordance with the Department of Defense

Joint Travel Regulation (JTR).

For OCONUS travel, the Contractor shall follow the guidelines as prescribed in the Foreign

Clearance Guide for DoD-Sponsored Contractors. The Contractor shall ensure that all OCONUS travel is approved by the COR prior to submitting the respective country clearance request via the Aircraft and Personnel Automated Clearance System (APACS).

3.1.5 Materials

Incidental materials (cabling, labels, and other peripheral items) and materials needed immediately to respond to system development requirements, system failures, and system operation requirements shall be provided by the Contractor when essential to the task performance and not provided by the Government. All materials purchased by the Contractor for the use or ownership of the Government will become property of the Government. The

Contractor shall document the transfer of the materials in the Monthly Status Report (CDRL

B002).

Types of anticipated materials includes, but is not limited to, the following:

Electronic Components and Materials:

Batteries, Cable, Cable Assemblies, Charging Devices, Connectors, Connector Accessories, Converters, Fiber Optic Cable, Fuses, Hubs, Infrared Remotes, Lamps/Bulbs, Microphones, Multimedia Equipment, Patch Cords, Power Supplies, Switches, Switchers, Twisted Pair Cable, and Wires.

Hardware/Raw Manufacturing Material:

Tools, Bolts, Boxes, Brackets, Brads, Nuts, Rack Assembly, Screws, Washers, Wood, Fiberglass, Shelters, and Plastics.

Miscellaneous Material:

Data Storage Medium, Binders, Dividers, Electronic Component Cleaning Materials, Deliverable/Documentation Consumables, Shipping/Freight Supplies/Services, and other materials in accordance with this solicitation.

Any purchased item in any quantity less than $100,000.00 shall have prior COR approval;

material purchases that exceed $100,000.00 per item shall have prior Contracting Officer approval.

Definition of IT related items.

Any equipment or interconnected system and/or subsystem of equipment used in the automatic acquisition, storage, manipulation, management, movement, control, display, switching, interchange, transmission, or reception of data information. Includes personal computers, laptops, printers, software, servers, hubs, routers, phones, facsimile machines and any related maintenance, telecommunications, training, or other support services.

The Contractor shall be required to move, relocate, or pre-stage IT equipment for enterprise support or equipment staging for DLA’s Reutilization, Transfer and Donation Program.

3.1.6 Government Technical Environment Information

3.1.6.1 Hardware

A hardware inventory of the Government IT environment with associated software shall be made available to the Contractor upon request.

3.1.6.2 Software

A representative software inventory (which may not be all inclusive) of the Government IT environment can be found in Attachment 1 (Administrator Software Tools) and Attachment 2

(End User Software Tools).

3.1.7 Performance Surveillance

The Contractor service requirements are summarized with performance metrics that relate directly to mission essential items, as well as performance thresholds, which briefly describe the acceptable levels of service required for each requirement.

3.2 Security

3.2.1 Citizenship Requirements

Only U.S. citizens may perform work under this contract per EKMS-1B AMD9, DoD Instruction

5200.2-R, and instruction SECNAV M-5239.2. Reference site: http://dtic.mil/

3.2.2 Investigative Requirements

All Contractor personnel shall maintain security clearance eligibility commensurate with the level of classification of the work performed as annotated in the Contract’s DD-254, Contract

Security Specification. The Contractor is responsible for ensuring that all personnel receive the requisite investigation and are favorably adjudicated in accordance with “32 Code of

Regulations, Part 117, National Industrial Security Program Operating Manual,” dated 24

February 2021. All information and/or data the Contractor creates shall be handled as

Government-owned and proprietary. Distribution is authorized to Requiring Office’s

Organization and supported Activity only.

3.2.2.1 Security Clearances

The Contractor shall conform to the provisions of the DoD-D-5220.22, ‘National Industrial

Security Program Operations Manual (NISPOM) and shall obtain and maintain security clearances for Contractor employees requiring access to IT systems or controlled areas. The

Contractor shall comply with SECNAVINST 5510.30B and SECNAV M-5510.30 to assure that the proper investigation is conducted for Contractor personnel. As a minimum, all Contractor personnel shall obtain and maintain a SECRET clearance; some are required to have a TOP

SECRET clearance. The Contractor shall comply with SECNAVINST 5510.30B and SECNAV

M-5510.30 to assure that the proper investigation (SSBI) is conducted for those Contractor personnel that require privileged access as defined in SECNAV 5239.1.

Full clearance levels must be acquired as soon as possible and maintained throughout the performance of the contract.

• For positions listed in Attachment 3 listed as “SECRET”: Interim clearances for

Contractors will be accepted for no greater than a period of up to 180 days from time of performance unless approved by the JPO ISSM and Security Manager. Any required certifications shall be acquired within 6 months from date employee is assigned to the program. The Contractor shall comply with the security and certifications requirements as identified in Attachment 3.

• For positions listed in Attachment 3 listed as “TOP SECRET Special Access Program”:

Interim clearances for Contractors will not be accepted for positions requiring access to

Special Access Program (SAP) data and facilities. Full clearance levels and SAP access must be maintained throughout the performance of the contract. The Contractor shall comply with the security and certifications requirements identified in Attachment 3.

The Contractor shall educate and brief employees concerning the handling and protection of CUI material, classified material, and other security measures as described herein in accordance with the NISPOM. The Contractor shall comply with mandates for annual security training.

3.2.3 Policy Adherence

The Department of the Navy (DON) Automated Data Processing (ADP) Security Program outlined in SECNAVINST 5239.3B, DON Information Assurance Policy and SECNAV M-

5239.1, DON Information Assurance Manual, applies to efforts under this contract. Contractor personnel providing services under this contract shall comply with all federal, DOD, United

States Air Force (USAF), and DON IA policies. The Contractor shall comply with

SECNAVINST 5510.30B and SECNAV M-5510.30 to assure that the proper investigation

(SSBI) is conducted for those Contractor personnel that require IT Level 1 access.

3.2.4 Contractor Access, Badges, Conflicts of Interest, and Non-Disclosure Agreements

All Contractor employees are required to obtain a Common Access Card (CAC), JSF

Identification Badge, Pentagon, or other DoD facility badge/Identification (ID), JVE system accounts (log-on and email), and/or NMCI/AFNet access. ALARACT 1740 dated 04 March

2002 provides guidance for the implementation and issuance of the CAC to all eligible

Government and Contractor personnel. The ALARACT requires that the DD Form 1172-2

(Application for DoD CAC – Defense Enrollment Eligibility Reporting System (DEERS)

Enrollment) be verified by the Contracting Officer (CO), Contracting Officer Representative

(COR), or a designated Government representative. The Contractor shall comply with security requirements for overseas travel. For travel requirements/restrictions to any foreign country, see the Foreign Clearance Guide (FCG) at the following website for applicable information:

https://www.fcg.pentagon.mil/fcg.cfm

The Contractor shall provide support of unclassified IT within classified Special Access Program

Facilities (SAPFs) and classified Sensitive Compartmented Information Facilities (SCIFs) at all

JPO locations as applicable. Unclassified IT support within these classified areas include but are not limited to refreshes, inventory, operations, and maintenance of workstations, servers, and networking equipment. All procurements will be done IAW government regulations. Sites that have large populations of JPO individuals permanently sitting within SAPFs, the Government will submit the IT CSS of that site for eligibility to be indoctrinated into SAP as applicable. An example of support would be upgrading a JVE desktop that is within a locations SAPF for lifecycle management.

Contractors for Security Operation Center (SOC), Information Assurance, Helpdesk and System

Administrators require Special Access Program (SAP) access and access to SIPRNet based on location and job function.

3.2.5 Disclosure of Information

Contractor employees shall not discuss nor disclose any information to which they are exposed during the execution of contract tasking to parties other than the originator of the information, authorized Government investigative personnel, the Contracting Officer, or COR personnel.

Improper disclosure of sensitive information may be grounds for removal of Contractor personnel. The Contractor shall ensure every individual Contractor employee completes a Non-

Disclosure Agreement (NDA) before the employee begins performance.

3.3 Detailed Support Requirements

3.3.1 Program Management (PM) Support

The Contractor shall provide PM support including the management and oversight of all activities performed by Contractor personnel and subcontractors to ensure all F-35 JPO IT and

CS services satisfy the requirements identified in this PWS. The PM will provide management, direction, administration, quality assurance, and leadership within the Contractor’s team to their personnel for the execution of each task in support of the F-35 JPO OCIO.

3.3.2 Project Kickoff Meeting

The Contractor shall schedule and coordinate a Project Kick-Off Meeting that will provide an introduction between the Contractor personnel and Government personnel who shall be involved with the contract. The meeting shall provide the opportunity to discuss technical, management, and security issues, as well as travel authorization and reporting procedures. At a minimum, the individuals who shall attend include key Contractor personnel, representatives from the F-35

JPO, other key Government personnel, the PCO, CO, and COR. The Contractor shall provide a

Kick-Off Meeting Agenda and Kick-Off Meeting Presentation (CDRL B001).

3.3.3 Management Reports, Monthly Status Report (MSR)

The MSR (CDRL B002). The Contractor shall summarize, by task area, the management and technical work conducted during the month (both scheduled and unscheduled), and the current accounting information.

3.3.4 Monthly Expenditure Report (MER)

The Contractor shall provide the Monthly Expenditure Report data in spreadsheet format in accordance with (CDRL B035).

3.3.5 Monthly Personnel Status Report

The Monthly Personnel Status Report (CDRL B036) shall provide a comprehensive list of all

Contractor personnel gains, losses, start dates, departure dates, and staffing status to include security clearance updates, upcoming leave, etc.

The Contractor shall ensure that all vacancies are filled promptly, within 25 business days for

Key Positions (KPs) and 20 business days for positions where there is only one contract position at that site. Timeline will be measured from date of vacancy to date the replacement is on-boarded, less government validation/approval time and JPO On-boarding time. Should the contractor anticipate or experience exceeding 25 business days to fill the position, the Contractor shall notify the government expeditiously and highlight in the Monthly Personnel Status Report

(CDRL B036).

3.3.6 Trip Report

The Contractor shall submit Trip Reports within five (5) business days after completion of a trip

(CDRL B003). The COR shall identify the need for a Trip Report for Continental United States

(CONUS) travel when a request for travel is submitted. Trip reports are required for all Outside the Continental United States (OCONUS) travel.

The Contractor shall reconcile the Trip Reports in accordance with the MER (CDRL B035).

3.3.7 Meeting Report

When requested by the Government, the Contractor shall submit Meeting Reports, documenting results of meetings/briefings between Government and Contractor leadership. This information shall be reported in accordance with Meeting Reports (CDRL B006).

3.3.8 Problem Notification Report (PNR)

The Contractor shall file a PNR (CDRL B004) to notify the COR/ACOR and TPOC/ATPOC of any negative issues and/or risks to the Government related to this contract. Issues or risks shall be identified by the Contractor and a PNR shall be provided to the Government no later than one

(1) business day after the problem is identified. The Contractor is required to manage issue or risks to analyze impact to the Government and monitor the results of risk control. Reporting all risks or issues will be included in the MSR’s and IPR’s.

3.3.9 Contract Management Plan (CMP)

The Contractor shall provide a CMP (CDRL B005) and control processes to ensure management visibility and effective coordination from contract startup through the cost-effective delivery of high-quality services and contract transition and close-out, and shall adhere to all Federal, DoD, and F-35 JPO directives. The CMP shall include all elements and processes to be used for successful execution of this contract to include Transition-In, Task Startup, Schedule

Management, Subcontractor Management, and collaboration with other Contractors supporting the OCIO, Quality Control, Financial Control, Issue Escalation, Risk Management, Transition-

Out, and Task Closeout.

3.3.10 Transition Plans

3.3.10.1 Transition-In Plan

The Contractor shall adhere to the Government-accepted transition-in plan submitted with its proposal. The schedule shall capture the proposed timelines for starting performance 45 calendar days after award. The formal Transition-In Plan (B007) is due no later than five (5) calendar days after award (DATOA). Revisions shall be submitted, as needed, post-award to capture any

Contractor requested changes to the approved plan.

After the Transition-In Plan (B007) is approved, the Contractor shall receive necessary

Government-Furnished Property (GFP). The Contractor shall then utilize approximately 45 calendar days to fully execute the transition-in period. The Contractor shall ensure that there shall be no service degradation during and after transition. The Government will host weekly

Transition-In Status meetings that will be attended by both the outgoing and incoming

Contractors. The Government will provide continuity between outgoing and incoming

Contractors and intervene to resolve unforeseen issues. The Contractor shall identify problem areas, challenges, and critical Government activities required in the transition.

3.3.10.2 Transition-Out Plan

The Contractor shall provide a Transition-Out Plan (CDRL B008) that shall facilitate the seamless transition from the incumbent to incoming Contractor or Government personnel at the expiration of the contract. The Contractor shall update the Transition-Out Plan on a yearly basis, to identify changes in the execution of the tasks, and shall include all applicable F-35 JPO or

DoD policy updates. The final Transition-Out Plan is due no later than six (6) months prior to expiration of the final option year.

3.3.11 Concept of Operations (CONOPS)

The Contractor shall develop a CONOPS that aligns with the industry best practices (ITIL® ) standard, CMMI Institute Capability Maturity Model Integration (CMMI) model and Project

Management Body of Knowledge PMBOK (CDRL B009). The CONOPS shall identify the forms, processes, templates, and standard operating procedures required for task execution. The

Contractor shall ensure the CONOPS considers the most current, relevant Government policies and process interactions. The CONOPS shall include detailed processes for all types of services, Swimlane charts identifying the interaction of activities within Contractor elements, F-35 JPO elements including the F-35 JPO OCIO Change Approval Board (CAB), and other Government agency elements shall also be included at the request of the Government.

3.3.12 In-Progress Review (IPR)

The Contractor shall conduct a formal quarterly IPR (CDRL B010) to be held at the F-35 JPO in

Arlington, VA. IPRs shall include the COR, TPOC, other key Government personnel, and any additional Government and Contractor representatives deemed necessary by the COR. The IPR shall provide a forum for Government review of progress, planning, and issues related to the task to include Quality, Best Practices, and Process Improvements.

The Government’s objective is to actively pursue a quality program to improve the performance and accountability in the delivery of IT & CS Services. The Contractor shall investigate, develop, document, and formalize F-35 JPO processes and procedures included in the contract.

The Contractor shall perform at a level equivalent to an ISO: 20000-1:2018 compliant program.

This level of performance shall ensure that the most current Information Technology Service

Management (ITSM) best practice areas are operationalized in the F-35 JPO. As changes are made in the standard, the Contractor shall analyze, plan, request Government approval as needed, and execute the changes required to meet the new standard. The Contractor shall utilize the benefits of the CMMI Institute Capability Maturity Model Integration (CMMI) model. This includes ensuring that application development practices are effective and institutionalized. As changes are made in the model, the Contractor shall analyze, plan, request Government approval as needed, and execute the changes.

This program shall institutionalize the four activities (Service Strategy, Service Design, Service

Transition, and Service Operation) of the ITIL4 Continual Service Improvement (CSI) Area by:

• Establishing and executing the CSI Model utilizing the Deming model (Plan, Do, Check/Study, Act.

• Exercising the ITIL CSI Seven-Step Improvement Process (identify the strategy for improvement; define what to measure; gather data; process data; analyze the data and information; present and use the information; and implement the improvement).

• Monitoring and reporting on improvement opportunities.

The Contractor shall report monthly in the MSR (see CDRL B002) their progress in applying quality, best practices, and process improvement in each of the PWS task areas, leveraging IT as an enabler, with a focus on improved deliverables and cost reduction. The Contractor shall review information from all sources and perform root cause analysis (work flowed or cross-teamed) on service tickets, poor network performance, or any other area where difficulties have been found. The Contractor shall report the root cause analysis for the current month and identify any seasonal, systemic, or other issues within the scope of this task to establish trend analysis information. Root-cause analysis shall include any recommended changes, fixes, and patches, processes, procedures, or systems, as well as any risk mitigation strategies that the Contractor recommends. The Contractor shall submit recommendations to the OCIO CAB.

3.3.13 Service Level Reporting (CDRL B038)

The Contractor shall monitor, measure, and report on the ongoing Service delivery and performance management across the enterprise. Reports shall provide data, analytics, and assessment of each individual IT Service Area’s performance achievements.

The Contractor shall manage, configure, maintain, and update electronic reporting system tools to provide real-time, near real-time, snapshot, and historical reporting of IT service data, analytics, and progress information related to the AQL detailed in the SAC. Reporting capabilities shall be presented as a “dashboard” which includes:

• IT Services operations view

• Component management view

The Contractor shall review the set of IT performance tools currently in use by the Government and identify any gaps in capability to fulfill the requisite monitoring, modeling, measurement, management, analysis, and reporting requirements.

3.3.14 Documentation Management

The Contractor shall perform lifecycle activities to create, revise, update, store, manage and provide required documentation in a form and format acceptable to the Government, including obtaining Government documentation approvals and maintaining revision control. The

Contractor shall ensure that all copies of documentation are provided in electronic format and are recorded and stored in a Government common documentation library (e.g., SharePoint).

Documentation management shall include developing, revising, updating, maintaining, reproducing, distributing, and archiving all Service Area information and documentation in electronic and hard copy format as defined by the Government. The Contractor shall validate the briefing and/or training of all Contractor personnel in methods and timeliness of preparing, developing, distributing, and/or complying with all Government documentation standards, security and quality requirements, review and approval processes, and documentation library usage. The Contractor shall monitor the documentation management process to ensure that all documentation is correct, up-to-date, and accurately depicts or describes the as-installed IT environment, and that it contains all appropriate version information, attributions, and approvals.

The contractor shall maintain a full set (library) of policies/process diagrams/SOPs leveraging the Government’s JVE environment (Teams or SharePoint) to maintain, update and expand the documentation required to operate at ISO level ISO: 20000-1:2018 2005 and in accordance with best practices described in ITIL4. The library shall include an inventory of all titles/subject areas required, as well as the documents currently on hand and under configuration control, which need review, which don’t exist, etc. Within 9 months of contract start, all documents required shall be drafted (if a policy), written and published (if not a policy) and under configuration control.

The contractor shall create and maintain complete and accurate technical drawings identifying all networks and locations detailed to the point of end user connection to the networks available for

F-35 JPO review. Upon review by COR, ACOR, and/or TPOC(s), technical drawings shall be

100% accurate, 95% of the time.

The contractor shall maintain a library of technical drawings and technical documents required for Cyber Security and Operations and Management. The library shall include an inventory of all document titles/subject areas required, as well as the technical drawings and technical documents currently on hand and under configuration control, which need review, which don’t exist, etc. Within 3 months of contract start, all required technical drawings and technical documents required shall be complete, updated, published, and under configuration control

3.4 Project Management, Enterprise Architecture, Emerging Capabilities, and Testing

The Contractor shall manage the F-35 JPO’s IT requirements management process. The

Contractor shall ensure that all requests are documented in the JPO’s service solutions management tool and are managed efficiently and effectively through resolution.

3.4.1 Requirements Management

The Contractor shall support the Government’s IT requirements management process.

Government-initiated requirements will be provided as an IT Request submitted using the F-35

JPO approved Service Desk solution or by OCIO TPOC(s) direction with COR approval. The

Contractor will evaluate each request and match the solution to the OCIO Service Catalog.

If the request cannot be fulfilled via the OCIO Service Catalog, then the Contractor will determine the best course of action, align the potential projects to OCIO’s overall strategic goals and initiatives, advise on risks to project scope, schedule, and budget. The Contractor shall identify CS requirements as appropriate and shall include them as part of the design if not explicitly included in the stakeholder and user’s requirements.

3.4.2 Project Management

The Contractor shall manage multiple IT projects that align with OCIO’s strategic goals and initiatives and shall include the following project types: new service, upgrade service, network extension/expansion, move, add, change, process improvement and emerging technologies. For each project, the Contractor shall develop and manage a project management plan to include elements such as scope, requirements, schedule, cost, quality, resources, risk, etc. In addition, the

Contractor will consolidate projects into an overarching integrated master schedule and ensure that documents are placed under project management control.

Project Management Plan (CDRL B011). The Contractor shall provide a comprehensive status of all projects across the enterprise, assist the Government to prioritize projects, the Contractor shall work cooperatively with other organizations as they plan and execute projects (such as

Facilities, DISA, Program Management Offices, Directorate of Cyber Security, etc.).

3.4.3 Special Projects (OPTION)

The Contractor shall provide, upon direction by the Government, services required for special projects utilizing the Optional Surge Support Labor CLINs. These projects include, but are not limited to, the following types of activities:

• Extension or Expansion of any F-35 JVE network to remotes sites, to include OCONUS sites. Extend F-35 JVE network in support of classified transport requirements. Processes will be created that are repeatable, minimizing project execution schedules.

• Large-scale relocation of F-35 JPO personnel: The Contractor shall assist the

Government in relocating and reconnecting IT assets associated with individual moves within the timeline specified by the Government.

3.4.4 Systems Engineering Plan

The Contractor shall prepare a Systems Engineering Plan (CDRL B016) as required. The document shall include engineering design, data management and flow designs, EA review, and network diagrams as appropriate for any project under this subtask.

3.4.5 Government Off-the-Shelf (GOTS) Applications and Alternatives

The Contractor shall endeavor to identify migration paths away from any legacy GOTS applications and develop alternative solutions for Government review. This should include, but is not limited to, as follows: (1) Free and Open-Source Software (FOSS), (2) cloud native services,

(3) COTS & GOTS to the maximum extent possible, (4) minimizing customization of commercial products to the maximum extent practicable and (5) prioritizing FOSS over cloud native services—and both over COTS. COTS vs. GOTS Proposals (B023).

For COTS applications, the Contractor shall analyze development, enhancement, and update requests and seek guidance from the Government functional application manager for requirements.

The Contractor shall enhance and support all production applications and create new applications as the need arises. These new requirements will be provided to the Contractor by use of the IT request process—only upon approval by the Government.

The Contractor shall identify risks associated with the development of new software efforts, including extension systems, the analysis and classification of those risks as to severity and likelihood, and the identification of techniques to mitigate the risks; develop, document, and adhere to effective and appropriate configuration management practices.

The Contractor shall assist with the development of business case documents by providing feasibility and business requirements analyses for existing systems or new requests and development cost estimates.

The Government must approve any development/update and enhancement requests in writing via a project charter or Change Advisory Board (CAB) approval process prior to implementation development/update or enhancement. Any ensuing efforts shall comply with the Systems

Engineering Technical Review (SETR) approach and must be approved by the Government.

3.4.5.1 Enterprise Architecture (EA) Services

The Contractor shall provide F-35 JPO EA analysis and design services that align strategic priorities with mission capabilities and technology solutions. This includes researching EA products that implement Physical Exchange Specification (PES), developing federated EA products, and providing solutions to F-35 JPO EA issues now and in the future. The Contractor shall develop the F-35 JPO EA using current industry standards aligned with the Federal

Enterprise Architecture (FEA) and DoD Joint Capability Areas (JCA). The Contractor shall provide monthly updates in the MSR (CDRL B002) on the progress of the development and alignment of the F-35 JPO EA.

The Contractor EA analysis, design, and solutions shall be in alignment and comply with the F-

35 JPO OCIO EA and shall be accepted and approved by the COR. The Contractor shall provide monthly updates in the MSR (CDRL B002) on the progress of the development of the F-35 JPO

EA.

The Contractor shall perform the below EA service functions to include, but not limited to the following:

• Architect/design strategies, missions, roles, functions, and service requirements across the F-35 JPO enterprise. This will include current and future networks.

• Conduct near-, mid-, and long-term enterprise and strategic planning. This will incorporate hardware, software, and services life-cycle management.

• Research, develop, and maintain the F-35 JPO EA for operational, system, and technical components, upgrades, new technologies, and EOL hardware/software/services.

• Analyze F-35 JPO architectures, business, and Enterprise Information Environment (EIE) processes, and IT to identify mission capability gaps, overlaps, and shortfalls; determine and recommend architectural, IT, or process solutions; automating to the maximum extent.

• Research and develop other EA components, architecture documents and plans as identified by the Government.

• Incorporate current industry standards and other key DoD architecture and net-centric planning instructions.

• Utilize the latest tools for software code development and Metadata usage to foster data standardization amongst other DoD entities.

• Identify future technologies and capabilities, generate engineering solutions, and estimates to optimize and advance the F-35 JPO’s IT infrastructure and security posture.

Tools and technologies should address classified wireless, 5G, service desk power tools, and artificial intelligence operations.

• Identify changes to DoD or vendor specifications and EOL component deadlines which may impact F-35 JPO IT operations.

• Manage hardware, software, and service life cycles. The life cycle of each should be continuously monitored, integrating components, software versions, and patching schemes as necessary to maintain the network operations at acceptable levels. Life Cycle planning and integration will be done prior to EOL in all areas.

• Provide recommendations regarding the strategic architectures’ organization and functions.

• Conduct architecture tool analysis and recommend tools for F-35 JPO use based on approved DoD and industry best standards, eliminating duplication and additional costs.

• Attend DoD, Joint Staff, USN, USMC, and USAF meetings as required.

• Establish Cybersecurity as a foundation component in the development of all enterprise artifacts.

• Manage on-premises and cloud infrastructure. Strategize, design and migrate applications, systems, IT operations, and services to the cloud environment. Identify and implement cloud efficiency and cost saving enhancements to the JPO cloud.

3.4.5.2 Test and Integration

The Contractor shall maintain a test and integration environment that will be utilized in a multi-purpose manner to support F-35 JPO requirements to include, but not limited to the following:

• Test new or emerging technologies that are recommended by the Contractor and/or identified by the Government.

• Develop and maintain the F-35 JPO standard image(s) and baselines.

• Manage the JVE and other unclassified F-35 JPO networks.

• Test, evaluate, integrate, prepare, and install patches and software version upgrades for the operational components as well as all cyber-security (CS), COTS applications, and tools.

The test and integration environment will be maintained in accordance with applicable DoD and

USCYBERCOM security standards and shall be cost effective and leverage test groups, test equipment, test systems, test users.

3.4.5.3 Testing of F-35 JPO Standard Applications

The Contractor shall utilize the test environment to independently test and integrate upgrades and patching slated for an enterprise deployment, as well as any GOTS releases. The Contractor shall identify conflicts or compatibility issues with standard hardware and software deployed on the applicable network. Prior to deployment, products will meet CS standards (as prescribed 3.3.7

Information Assurance / Cyber security Services. The Contractor will follow the CIO, F-35 JPO, Change Management Process and Directorate of Cyber Security’s Security Impact Analyses processes. Integration of applications and hardware shall be part of the development effort to maintain the F-35 network infrastructures.

Integration activities shall be used to build up a system from initial design until the approved solution is certified for use. Upon completion of any final approved build, the Contractor shall make a final configuration managed image of the software. This image shall be encrypted and stored as an authoritative source.

3.4.5.4 Market Research

The Contractor shall assist by conducting market research for life-cycle replacement or requirements changes and recommend options to the Government via the Project Management

Plan (CDRL B011). Upon request by the Government, the Contractor shall provide a Market

Research Report to the Government identifying available options and making recommendations for additional research and analysis. The Market Research Report shall be within the delivery date identified in the schedule.

3.5 Infrastructure Engineering Services

IT engineering services will consist of planning, building, testing, implementing, and controlling the life cycle of the F-35 infrastructure. The Contractor engineering team will be the subject matter experts in all infrastructure and services and contain members of the Systems, Network, Cloud and Telephony Engineering teams. These individuals will be required to develop IT infrastructure and service solutions to meet JPO mission requirements. Solutions will include integration, utilizing the latest technologies and prescribing to all applicable CS policies and procedures. The Contractor shall monitor the life cycle of the infrastructure and services, ensuring proper maintenance have been performed and planning for EOL. The engineering team will assist the administrative support team in monitoring the health of infrastructure and services.

The engineering team will assist in routinely evaluating performance and service usability to ensure each are operating at optimal efficiency. The engineering team will provide Standard

Operating Procedures (SOPs) to the administrative support teams along with assisting in the creation of test procedures, checklists, or other system health related tools. To reduce cost and redundant network circuits, the Contractor will manage and control all F-35 interconnectivity circuits, known as the JVE backbone. This includes ordering, managing, and installation of all

Defense Information Systems Agency (DISA) circuits in the DISA Storefront (DSF) Web

Application and support the JPO Director of Networks in maintaining network diagrams and schematics. The Contractor will provide assessment and management of the JVE network circuits which the classified networks utilize. The Contractor will provide IP ranges, circuit access, and security to all F-35 circuits. The Contractor will maintain and expand circuits upon request of the Government in support of classified networks. This includes any commercial circuits as well as DISA circuits.

The Contractor shall maintain current network architecture and configuration documentation that will include, but is not limited to; architectural design diagrams, engineering designs, engineering plans, component/software lists, data flow diagrams, SOPs for each F-35 JPO network and major service. This is to be comprehensive of all systems and sites including JPO cloud environments. This documentation shall be current and available in the OCIO Process

Asset Library (PAL). A review of the artifact shall be held with the TPOC(s) and/or COR no later than six (6) months after TOA.

3.5.1 Engineering Requests

The Contractor shall provide a Technical Analysis and Cost Estimate (TACE) for engineering requests submitted by the F-35 JPO community, to the COR. Requests vary in complexity from new software requirements, to deploying a new network within the unclassified environment.

The Contractor will respond within three (3) business days to all engineering requests unless the request is sufficiently complex requiring a longer period. In such cases, the Contractor shall request a longer duration from the COR and the requestor will be notified. Processes will be created to fulfill known or common requests, such as new hardware or software. The OCIO will provide email priority changes for urgent requirements; the TPOC(s) can request that a TACE be expedited. In such cases the Contractor shall complete the TACE within the standard three (3) business days.

3.5.2 Engineering Capability Growth and Emerging Technologies

The Contractor shall provide an Infrastructure Improvement Plan (CDRL B017) to address F-35

JPO engineering capability growth, life-cycle management/EOL requirements, and emerging technologies.

The Contractor shall provide a five (5) year, forward-looking IT Roadmap (CDRL B018) and provide revisions as required. The Contractor will be provided the OCIO direction, JPO mission requirements, and architect methods needed to forecast a projected path.

3.5.3 Capacity Management

The Contractor shall provide capacity management capabilities that include, but not be limited to, business capacity management, service capacity…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .