53-0012-22_1300988622 SOW.pdf

PDF 372 KB Posted

Attached to
IT Services (Radar Division) Federal contract opportunity
Solicitation number
N00173-22-RFI-FW05
Issued by
Department of the Navy Secretary of the Navy Office of Naval Research

About this file

This statement of work describes IT services required by the Naval Research Laboratory's Radar Division. The scope of work includes technical, administrative, and user support for unclassified and classified Microsoft and Linux systems, networks, and services for up to 125 users. Specific requirements involve designing, implementing, and maintaining Active Directory environments, file and print servers, workstations, backup services, and storage systems. The contractor must also support cybersecurity and information assurance systems and participate in the Navy's certification and accreditation process. All personnel are required to hold certain IT certifications and undergo background investigations. The period of performance is five years from the date of award.

The related sources sought notice and request for information is to gauge interest from potential vendors for fulfilling these IT services requirements and to determine set-aside eligibility. The Navy plans to issue a solicitation package for these requirements and is currently in the planning stages, modifying the language as needed. Interested parties should respond with the required format by the specified response date.

View the file

Other files for this federal contract opportunity

Other files attached to IT Services (Radar Division), newest first.
File Type Posted
Radar Division IT SOW 2022_1_31.pdf PDF
IT Personnel Qualification 2022_1_31.pdf PDF
53-0005-22_Level of Effort - Radar IT Services.xlsx XLSX spreadsheet
53-0005-22_IT Personnel Qualification 2021_01_28.pdf PDF
53-0005-22_Radar Division IT SOW 2022_01_28.pdf PDF
53-0005-22 Statement of Work.pdf PDF
53-0005-22_Requirements for On-Site Contractors.docx DOCX document
53-0005-22_Sources Sought Notice - Radar IT Services.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work

Radar Division Information Technology Support

1.0 Introduction

1.1 This Statement of Work describes the Information Technology support requirements for the

Radar Division of the Naval Research Laboratory (NRL), Washington, DC. The mission of the Radar Division is to conceive, develop, demonstrate, document, and transition RF sensing concepts, technologies, and intellectual property that provide technological advantage for the US military. This is accomplished through basic research, exploratory development, and advanced technology demonstrations in partnerships across the laboratory, with Warfare Centers, FFRDCs, UARCs, academia, and industry, and in support to the requirements and acquisition communities. Fundamental to the mission is the performance of high quality forward-leaning research and engineering that is rigorous, complete, and detailed, and performed with consideration of the Navy and Marine tactical operating environments.

The Radar Division consists of three branches and administrative staff that share a Division-level IT infrastructure. The Division infrastructure is based on the Microsoft Active Directory and also includes Linux systems. External communication and networking is provided by NRL and the Division is responsible for supporting Division IT users, equipment, and specialized networking. The Division maintains unclassified and Collateral

Secret IT equipment.

1.2 Background

The Radar Division has approximately 125 government and contractor IT users, many with multiple unclassified and collateral Secret systems. The division maintains Microsoft Exchange Servers for staff at both classification levels. At present, the unclassified Microsoft Exchange domain is internet routable, but it will be limited to internal access in the near future. Unfortunately, a specific data for this transition is not yet defined. A closed-network collateral Secret Microsoft Exchange domain (REDNET), and multiple stand-alone unclassified and collateral Secret systems are also maintained.

Division IT users have migrated external email services to the unclassified NRL Enterprise network (G-Net) Outlook Exchange Server but will require continued support maintaining email accounts and data and maintaining Outlook clients on Division-maintained computers.

At a future date, all users will receive an NRL Enterprise-provided computer for internet access, email, and other services. While minimal user support for the NRL enterprise equipment is expected to be necessary, it will be necessary of Division IT staff to assist users to identify and resolve issues with the NRL Enterprise equipment.

The current Radar Division Collateral Secret internal REDNET network and all standalone systems will be unaffected by the migration to the NRL enterprise solution. Current Radar Division unclassified servers and desktops will be maintained for continued use, but will not route to the internet once the migration to the NRL enterprise system is complete. The internal network will be referred to as the Radar Research Net (R-Net).

The Radar Division maintains a CISCO CODEC-based Video TeleConference (VTC) facility operating at the unclassified and Collateral Secret level and has other IT equipment such as multi-function printers/copiers, meeting room computers and projectors, and other similar items that require IT support services.

1.3 Scope

The scope of this effort encompasses technical, administrative, and user (customer) support on Unclassified and Collateral Secret systems and networks for the Naval Research Laboratory Radar Division as well as user assistance for NRL Enterprise and Navy Enterprise IT services (i.e. Flank Speed). Current equipment includes: Windows and Linux clients and servers, Operating Systems include Windows: Exchange 2012 R2, Exchange 2016, Exchange 2019, Linux Cent OS7, AlmaLinux 8, Windows 10 SHB, Linux CentOS 7, Debian, and Ubuntu Fedora.

2.0 Applicable Documents

2.1 Department of Defense

2.1.1 DODD 8500.1 – Cybersecurity

2.1.2 DOD 5220.22 – National Industrial Security Program

2.1.3 DOD Directive 8570.01M - Information Assurance Workforce Improvement

Program

2.1.4 DoD 5200.01 Vol. 4 - DoD Information Security Program: Controlled Unclassified Information (CUI)

2.2 Navy

2.2.1 SECNAV M-5239.3 DON Cybersecurity Manual

2.3 NRL

2.3.1 NRLINST 5510.40E – NRL Security Manual

2.3.2 NRLINST 5211.2F – Privacy Act Policy and Responsibilities

2.3.3 NRLINST 5239.4A – NRL Cybersecurity Workforce Program

2.3.4 NRL M-5239.5 – Naval Research Laboratory Cyber Incident Response Manual

2.3.5 NRL5239.5A – Cyber Incident Response Policy

3.0 General Requirements:

The Contractor shall provide comprehensive IT technical, administrative, and user services in support of an enterprise infrastructure of systems that meet appropriate DoD and Navy accreditation and inspection parameters in support of the Radar Division mission. Services shall be provided in-person, remotely and by telephone.

3.1 The Contractor shall have its support team in place and fully functioning at the time of the base-period contract award or exercise of contract option(s).

3.2 On-site staff is required on all Government workdays.

3.3 The contractor will execute the technical requirements in a manner that provides for high quality, timely, equipment and user support while incorporating the proper mix and the most effective use of personnel and skills.

3.4 Tasking

3.4.1 Design, Development, and Administration of Radar Division Unclassified and Classified Microsoft Windows Based Computer Systems and Services

3.4.1.1 The Contractor shall provide technical and engineering support toward the design, development, installation, test, and operation of Microsoft Windows systems and services in the Radar Division enterprise environment (accommodating up to 125 users) in accordance with appropriate DoD/USN/NRL security practices and reporting requirements. Performance of this task includes the requirements analysis for, and design and development of, Windows Active Directory environments and all component systems, including, but not limited to:

Domain Controllers; DNS servers, file, print, patch management, database, and email; administrative and user workstations for system administrative personnel; and PKI support for servers and applications.

3.4.1.2 The Contractor will support the management of a Windows Server system supporting workstations for up to 125 users utilizing industry standard tools. Experience with Microsoft Endpoint Configuration Manager (MECM), Windows Server Update Services (WSUS), Group Policy and other tools selected for use within the environment is required on both unclassified and classified networks. All hardware and software configurations will comply with DoD Standard Technical

Implementation Guides (STIGs) and any applicable DoD/Navy standards. Demonstrated knowledge of and experience applying STIGs, creating STIG checklists and documentation in support of Navy accreditation, and providing Standard Operating Procedures (SOPs) is required.

3.4.1.3 The Contractor will support Radar Division staff with the use of the Navy’s approved Flank Speed environment(s). The Contractor is expected to have experience and knowledge of the requirements of the Flank Speed and will assist Division users to identify and resolve issues with the Flank Speed environment and the installation and configuration of the Flank Speed application on Division computers. Support will include collaboration with tier 1/2 support personnel, when needed, to ensure swift resolution of issues affecting user access that may require action at the server or individual user computer level.

3.4.1.4 All systems will be documented and tracked in an inventory control system used for configuration control and verification of compliance with relevant NRL/Navy/DoD security requirements. Familiarity and experience with software and configuration management systems such as Belarcs BelManage and BelSecure is required. The Contractor must have experience with ticketing software for documentation, issue tracking, and issue resolution. A ticketing system shall be utilized.

3.4.1.5 The contractor shall configure all systems and services to meet

Information Assurance Vulnerability Alert Bulletin (IAVA/B) compliance requirements as well as all applicable Standard Technical Implementation Guide (STIG) requirements and compliance with all Navy Communications Tasking Orders (CTO), Operations Orders (OPORD) and other Navy and/or DoD Directives as applicable to the subject SOW. All compatible systems currently have the Symantec Security System client installed and the Contractor shall have experience with configuring and using this software. The contractor shall support obtaining and installing DoD certificates to secure required systems and services. System scans will be reviewed for vulnerabilities and findings remediated in a timely fashion. Experience in reviewing system logs to determine blocks and coordinating required settings with the NRL IA team is required. The contractor will have experience reviewing and remediating vulnerability findings from the Assured Compliance

Assessment Solution (ACAS), SCAP/SSC, Belarcs BelManage and BelSecure tools as well as from other DoD approved/required tools and applications.

3.4.1.6 The contractor shall provide support to research and test new hardware and software products to assure compatibility with current and future information systems environments. The contractor, in support of this requirement, shall provide support in the requirements definition and procurement of supplies and equipment, to include evaluation hardware and software. The contractor shall maintain documentation on the design, performance and configuration of all servers, networks, services, and database products in support of Navy Certification and Accreditation requirements. Documentation includes, but is not limited to, Standard Operating Procedures (SOPs), Configuration Management Guides, diagrams and flow charts depicting system architecture, STIG checklists, responses to Risk Management Framework (RMF) controls, and creation of Plan of Action and Milestone (POA&M) entries. The contractor will have demonstrated experience in the creation and management of accreditation packages for system.

3.4.1.7 The Contractor shall provide support for the automated management and maintenance of service accounts in an enterprise level IT environment.

Service account management and maintenance tasks that are expected to be automated via scripting or other tools include, but are not limited to, password control and service configuration.

3.4.1.8 Monitor the four current Xerox AltaLink C8035 Multifunction Printer maintenance and supply status and interface with Xerox to obtain supplies and repairs. Supplies and repair of the devices are provided via a separate Radar Division support contract with Xerox.

3.4.1.9 Monitor the two current Cisco SX80 CODECs that are part of the unclassified and Secure VTC facility maintained by the Radar Division.

The Contractor shall interface with the VTC support contractor for required maintenance and service of the VTC equipment and CODECs.

The VTC equipment is supported via a separate Radar Division support contract and the CODECs are supported via the DON JELA contract.

3.4.1.10 The contractor shall design, implement and provide Division-wide backup services for all production services in accordance with NRL, STIG, and RMF guidance. This service shall provide for continuity of operations for critical server based enterprise data. Such as critical server infrastructure imagery with product such a Veratas System Recovery and Data Duplication.

3.4.1.11 Support configuration and maintenance of storage systems such as

Promise Technology and Dell Scalable Storage System.

3.4.2 Design, Development and Administration of Division Level Unclassified and

Classified Linux-Based Computer Systems and Services

3.4.2.1 The contractor shall provide technical and engineering support toward the design, development, installation, test, and operation of Linux-based systems and IT services for the Division environment. Performance of this task includes the design and deployment of both physical and virtual servers providing a variety of IT services and running Alma Linux, CentOS, Ubuntu and other enterprise Linux OS variants. Experience in the architecture, installation, configuration and management of Linux servers is required.

3.4.2.2 Familiar with Centrify for management and integration of Linux Systems into a Windows Domain on Classified and Unclassified networks.

3.4.2.3 The contractor shall provide user support to the user base supported by the Linux systems and services. This support includes in-person support, configuration and troubleshooting, assistance via telephone and email, as well as the creation of documentation and help guides.

3.4.2.4 The contractor shall configure all systems and services to meet Information Assurance Vulnerability Alert Bulletin (IAVA/B) compliance requirements as well as all applicable and appropriate Standard Technical Implementation Guide (STIG) requirements and compliance with all Navy Communications Tasking Orders (CTO), Operations Orders (OPORD) and other Navy and/or DoD Directives as applicable to the subject SOW. All compatible systems currently have the Symantec Security System client installed. The contractor shall support obtaining and installing DoD certificates to secure the required systems and services. System scans shall be reviewed for vulnerabilities and findings remediated in a timely fashion. Experience reviewing system logs to determine blocks and coordinating required settings with the NRL IA team is required. The contractor will have experience reviewing and remediating vulnerability findings from the Assured Compliance Assessment Solution (ACAS), SCAP/SSC, Belarcs

BelManage, and BelSecure tools as well as from other DoD approved/required tools and applications.

3.4.2.5 The contractor shall provide support in researching and testing new hardware and software products to assure compatibility with current and future information systems environments. The contractor, in support of this requirement, shall provide support procuring supplies and equipment, to include evaluation hardware and software.

3.4.2.6 The contractor shall maintain documentation on the design, performance and implementation of all servers, networks, services, and database products in support of Navy Certification and Accreditation requirements. Documentation shall include, but is not limited to, Standard Operating Procedures (SOPs), Configuration Management Guides, diagrams and flow charts depicting system architecture, STIG checklists, responses to Risk Management Framework (RMF) controls, and creation of Plan of Action and Milestone (POA&M) entries. The contractor will have demonstrated experience in the creation and management of accreditation packages.

3.4.2.7 Support configuration and maintenance of storage systems such as OSNexus Scalable Storage System.

3.4.3 Computer Cybersecurity (CS) and Information Assurance (IA)

3.4.3.1 The contractor shall provide technical and engineering support toward the design, development, installation, test, and operation of Cybersecurity (CS) and Information Assurance (IA) systems and services. Performance of this task shall include the design, development, and implementation of DoD-mandated CS/IA products.

These products include, but are not limited to: Assured Compliance Assessment Solution (ACAS), and other information Assurance Tools.

This task will also include the testing and installation of all mandated software modules associated with these products, as well as the creation of mandatory reports and data sets required for Certification and Accreditation.

3.4.3.2 The contractor shall participate in the Navy Certification and Accreditation process for Radar Division equipment, assisting with all facets of the accreditation review and documentation process. The contractor will engage with other NRL information assurance personnel for the purpose of providing necessary reports and data to meet mandated accreditation requirements. The Contractor must have experience in achieving Authorization to Operate under the Department of Defense System Accreditation.

3.4.3.3 The contractor shall configure all systems and services to meet Information Assurance Vulnerability Alert Bulletin (IAVA/B) compliance requirements as well as applicable Standard Technical Implementation Guide (STIG) requirements and any relevant DoD or

Navy Directives.

3.4.4 Infrastructure & Facility Support

3.4.4.1 The contractor shall provide technical expertise and engineering support towards the design, installation, implementation and operation of Division-level storage and file server solutions.

3.4.4.2 The contractor shall provide support in managing computer room facilities at the infrastructure level, including but not limited to:

installation and management of equipment racks, power distribution, battery backup, and cabling within Radar Division computer rooms. The contractor shall provide, in support of this requirement, mechanisms for facility monitoring, power monitoring and management, and environmental monitoring and management.

4.0 CERTIFICATIONS AND TRAINING:

4.1 In addition to all other required certifications, task areas 3.1, 3.2, 3.3, and 3.4 require that all personnel possess and maintain certifications as specified in DoD Directive 8570.01M (Information Assurance Workforce Improvement Program). The contractor shall ensure that all personnel assigned to this task are fully certified within 90 days of onboarding, are provided necessary ongoing training to retain certifications and are re-certified as specified by the certificate granting organization.

4.2 The contractor will arrange for and ensure that all personnel are trained as necessary on new hardware or software products as they are introduced into the environment. Where required by vendors and DoD/DoN regulations, contractor will obtain certifications to ensure support contracts and compliance posture remain valid.

5.0 Security and Privacy Act Requirements

5.1 All contractors assigned to this contract must be U.S. Citizens. Contractor personnel requiring access to Secret information and/or systems must possess a final DoD-granted Secret security clearance, based on a completed and favorably adjudicated DoD Tier 3 investigation. Access to unclassified information and/or systems at NRL or offsite at the Contractor facility requires, at a minimum, a favorably adjudicated DoD Tier 3 investigation.

Contractor personnel performing any function designated as a component of the Cyber

Security Work Force (CSWF), and/or having privileged user access to NRL information systems will require background investigations and security clearances commensurate with the access level and security classification of the system being accessed as specified in DON 5239.2M (2009).

5.2 The contractor will NOT be required to generate, receive, or store CLASSIFIED material at the contractor’s facility.

5.3 A visit request is required for all personnel assigned to work on this contract. Visit requests must include full name, social security number, contract number and state if Government furnished computer equipment will be required.

5.4 The Prime contractor will forward a copy of all subcontracts and task orders related to this contract, regardless of classification. All subcontracts and task orders must be approved in advance, in writing, by the Head of the Naval Research Laboratory’s Information Security office. The prime contractor will coordinate the approval of all subcontracts and task orders with the Contracting Officer’s Representative (COR). The COR will in turn, coordinate the approved paperwork with the Head of NRL’s Information Security office. Prime contractor will provide the security classification guidance for classified work required under this contract to subcontractors.

5.5 Proprietary, Privacy Act, or Controlled Unclassified Information associated with this contract must be handled/controlled IAW DoD 5200.01 Vol. 4.

5.6 NATO briefings required. NATO access authorized at SECRET level only. Initial NATO briefings must be within a 5 year scope of the completed investigation. Visit request and a copy of NATO indoctrination must be sent to NRL Code 1231 for all initial NATO briefings, prior to access. NATO briefings date must be within the current year. Annual refresher briefings for NATO access are required. A copy of the signed annual re-briefings must be forwarded to NRL Code 1231 annually.

5.7 All contractors (including subcontractors) identified in the Statement of Work shall supplement their current security practices by requiring any personnel involved in executing the contract to complete Government-sponsored and administered Operations Security (OPSEC) training, OPSE-1301 and any other OPSEC guidance that may pertain to a project.

5.8 All classified work must be done at the Government facility. Unclassified work, identified in this SOW, may be done offsite at the contractor facility, utilizing Government Furnished Equipment (GFE), at the discretion of the Radar Division and in coordination with the COR.

Contractor personnel working offsite must be available for on-site technical meetings and work groups during normal business hours.

5.9 All NRL data must remain on NRL owned and operated systems and servers. No NRL data, computer code, or details shall be stored on contractor or public servers. Printed copies of Controlled Unclassified Information shall only be kept within Radar Division spaces and shall not be kept in the contractor facility or elsewhere.

6.0 Deliverables

1) Monthly Progress Reports

2) Monthly Contractor On-Site Labor and Financial Reports

3) Hardware/Software Products & Documentation

4) Written Documentation

5) Certification Documentation & Reports

6) Personnel Training Plan

7) Technical Reports (Interim & Final)

Monthly Technical Progress Reports shall include the following information:

1) Description of the work accomplished,

2) Summary of issues or concerns, if any.

Monthly Financial reports shall include the following information:

1) Funding history, showing when and how much money was added to each ACRN for each person on the task, amounts allocated to labor and material, along with cumulative task funding for labor and material;

2) Funding balance for labor and materials in each ACRN and by person at the beginning of the monthly reporting period;

3) Labor hours and amounts expended for labor and materials in each ACRN and by person during the monthly reporting period;

4) Funding balance for labor and materials in each ACRN and by person at the end of the monthly reporting period.

7.0 Period of Performance

The period of performance for this effort is sixty (60) months from date of award

8.0 Additional Requirements

The contractor shall provide the above-stated services during NRL Radar Division normal core working hours, 0800-1700 Monday through Friday or during other agreed upon hours, except for

Federal holidays. Flexible work hours may be used to ensure that some range of technical services are available during the time specified, taking into account the need for maximum support during NRL core work hours. Deviation from these support hours and any use of telework to meet local support requirements shall be proposed to and coordinated with the Contracting Officer's Representative (COR) in advance. On occasion, the Division may require after hours or weekend efforts, for example but not limited to, support of a scheduled outage or to react to an emergency or security situation. After hours support shall be coordinated between the

COR and the Contractor local site Program Manager (PM). The NRL COR shall provide the PM with advance notification and specific needs, if known in advance. Contractor personnel shall also investigate, provide recommendations for remedial action, and pursue corrective action in case of emergency situations.

The Contractor PM will ensure that the necessary support activities are adequately covered and communicate and coordinate any changes with the NRL COR.

File details come from the government source that posted it. Updated .