Radar Division IT SOW 2022_1_31.pdf

PDF 194 KB Posted

Attached to
IT Services (Radar Division) Federal contract opportunity
Solicitation number
N00173-22-RFI-FW05
Issued by
Department of the Navy Secretary of the Navy Office of Naval Research

About this file

This statement of work outlines technical requirements for information technology support services for the Radar Division of the Naval Research Laboratory. The contractor shall provide IT support services including installing, configuring, operating, testing, troubleshooting, updating, fixing, replacing, maintaining, administering, and optimizing a variety of networked systems across classified and unclassified networks. Specific tasks involve implementing security technical implementation guides, monitoring networks for compliance, managing software installations, using group policy objects for updates, installing single sign-on software, managing email servers, providing help desk support, and acting as the division information system security officer. The period of performance is 60 months. The related federal contract opportunity is a sources sought notice to gauge interest from potential offerors capable of fulfilling the requirement and to determine set-aside possibilities for small businesses.

View the file

Other files for this federal contract opportunity

Other files attached to IT Services (Radar Division), newest first.
File Type Posted
53-0012-22_1300988622 SOW.pdf PDF
IT Personnel Qualification 2022_1_31.pdf PDF
53-0005-22_Radar Division IT SOW 2022_01_28.pdf PDF
53-0005-22_Level of Effort - Radar IT Services.xlsx XLSX spreadsheet
53-0005-22_IT Personnel Qualification 2021_01_28.pdf PDF
53-0005-22_Sources Sought Notice - Radar IT Services.docx DOCX document
53-0005-22 Statement of Work.pdf PDF
53-0005-22_Requirements for On-Site Contractors.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work

Information Technology Support

1.0 Purpose

1.1 This Statement of Work describes the Information Technology support the Contractor is required to provide the Radar Division of the Naval Research Laboratory (NRL), Washington, DC.

1.2 Background

The Radar Division has approximately 100 Users that operates a crossed a multiple of platforms which are classified and unclassified. There are approximately 75 Unclass servers and 400 Clients consisting of Windows and Linux. There are approximately 35 Class Servers and 30 Clients consisting of both Windows and Linux

1.3 Objective

The contractor shall provide IT support to all Radar Division personnel on Nicenet and 5300 Research Net (Unclassified) systems. The Contractor shall install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked systems. Procedures must be developed and maintained for systems such as set up, startup, shutdown, integration, troubleshooting, and operation. Information Technology professionals will monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results. Network applications and services are supported at different classification levels. Solutions are developed to monitor performance, provide scaling capability, and improve quality of service. Systems are installed, and errors resolved. Support will be provided in the preparation and testing of DoD and US Government computer and/or network systems for accreditation.

1.4 Scope

The Purpose of this effort is to assist the Naval Research Laboratory’s (NRL) Radar

Division (Code 5300) with Information Technology (IT) support for technical and administrative needs on both Classified and Unclassified Networks

2.0 General Requirements:

2.1 The Contractor shall have its support team in place and fully functioning at the time of the base contract award or exercise of contract option(s).

2.2 On-site staff is, at a minimum, required on all Government work days during core hours, see NRLINST 12620.1. Remote support is permitted as long as one person is on site during the core hours. Core hours are 0900 to 1400 Monday through Friday.

2.3 During this period the contractor will execute the technical requirements of either the base or option of the contract in a manner that provides for high quality, timely support while incorporating the proper mix and the most effective use of personnel.

Requirement for the contract award is to have a Senior Computer Systems Engineer in place at the time of award. The position requirements are listed in Personnel Qualifications.

Requirement for the contract is to have Senior Computer System Specialist in place at the time of award. The position requirements are listed in Personnel Qualifications.

Requirement for the contract is to have a System Administer in place at the time of award. The position requirements are listed in Personnel Qualifications.

The determination to exercise options may be determined at time of award or any time thereafter.

3.0 Tasking

3.1 The Radar Division has approximately 100 Users that operates a crossed a multiple of platforms. The current configuration is approximately as follows:

3.1.1 Systems and their current configuration:

3.1.1.1 Unclass servers 30 Windows, 25 Linux

3.1.1.2 Unclass clients 400 Windows 45 Linux

3.1.1.3 Servers are physical and virtual (Class and Unclass.)

3.1.1.4 Class servers 11 Windows 25 Linux

3.1.1.5 Class clients 15 Windows 15 Linux

3.1.1.6 Sever OS include Windows: 2008 R2, 2012 R2, 2016, 2019, Linux Cent

OS7, AlmaLinux 8

3.1.1.7 Workstations and Laptop OS includes Windows 10 SHB (Window 7

Standalones) Linux CentOS 7, AlmaLinux 8, Debian, and Ubuntu Fedora.

3.1.1.8 Maintaining over 27,000 different software titles and versions.

3.1.1.9 Software running on server: Software non-OS Exchange 2016, SQL

2019, IIS 8, BES/UEM 12.15, BelManage 8, BelSecure 8, SecureDoc 5, Windows Update Service Server, Symantec Endpoint Manager 14.3 RU3, Microsoft Endpoint Configuration Manager 5, TrippLite power management, Xerox print management, FlexNet License Management.

Virtualization Microsoft Hyper-V and VMWare, Visual Studio, Symantec Mail Security for Microsoft Exchange, ACAS Security Center, Tenable Nessus, SpaWar SCC/SCAP, and Veritas System Recovery.

3.2 The contractor shall provide IT support to all Radar Division personnel on an

Unclassified Enclave and 5300 Research Net (Classified) systems. The Contractor shall install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked systems. Procedures must be developed and maintained for systems such as set up, startup, shutdown, integration, troubleshooting, and operation. Information Technology professionals will monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, Security Technical Implementation Guide (STIG), applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results. Network applications and services are supported at different classification levels. Solutions are developed to monitor performance, provide scaling capability, and improve quality of service.

Systems are installed, and errors resolved. Support will be provided in the preparation and testing of DoD and US Government computer and/or network systems for accreditation.

Tasks can include, but not limited to:

3.2.1 Implement Security Technical Implementation Guides (STIGS) to harden Unclassified Enclave, and 5300 Research Net (Unclassified) systems, and network equipment per DoD standards. Use DoD approved scanning tools such as Assured Compliance Assessment Solution (ACAS), Nessus and SCC/SCAP for monitoring security of Radar Division’s Unclassified Enclave to identify and address vulnerabilities to ensure compliance with NRL/DoD Navy regulations.

3.2.2 Monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results on Unclassified Network (NICENET), and Non-Internet connected Enclave. Develop new solutions to monitor performance, provide scaling capability, and improve quality of service. Monitor and report system compliance.

3.2.3 Manage software installations on Unclassified Network and Non-Internet connected Enclave per DADMS guidelines. Verify software installs comply with the DoD approved list in the DADMS database. System Hardware and Software.

3.2.4 Use Group Policy Objects (GPOs) to maintain STIG compliance and update third party software on all systems in Radar Division Windows Active Directory (AD) domain. In addition Microsoft Endpoint Configuration Manager for supplemental third party software deployment and IAVA updating.

3.2.5 Install/configure/maintain Centrify COTS software to implement Single Sign On (SSO) to Windows, and Linux systems per DoD guidelines.

3.2.6 Manage/update/configure MS Exchange email server for Radar Division users, integrating Exchange with Windows and Linux email users. (Manage and maintain Symantec Mail Security for Microsoft Exchange.)

3.2.6.1 It is expected that email will migrate to alternative external to the division system during the period of performance of this contract. This requirement will cease at that point.

3.2.6.2 Once external email is discontinued within the Radar Division, an email server on a Non-Internet connected Enclave will be established for communications between Radar Division Personnel.

3.2.6.3 Manage Symantec Endpoint Protection host based security anti-virus/malware/spyware and firewall.

3.2.7 Configure and maintain mobile disk encryption of GFE mobile devices such as laptops using Microsoft BitLocker, WinMagic SecureDoc and Linux LUKS.

3.2.8 The ability to provide Security Engineering design and System Engineering design via the Enterprise Architecture and the ability to fully integrate both.

3.2.9 Install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked and stand-alone systems.

Maximize reliability, maintainability and availability of IT hardware and associated peripherals. Provide IT technical support for the scientific and administrative users.

3.2.10 Interface with NRL Information Systems Security and implement all required computer security procedures. Interface with the NRL networking group to maintain the Radar Division networking infrastructure.

3.2.11 Assist in the preparation and testing of DoD and US Government computer and/or network systems for accreditation

3.2.12 Install hardware and software upgrades to IT systems in accordance with technical direction from the COR

3.2.13 Perform IT systems hardware and software modifications in accordance with technical direction from the COR.

3.2.14 Maintain computer configuration management systems and databases including hardware component lists, modifications, upgrades and maintenance histories.

3.2.15 Coordinate effectively with IT hardware and software vendor representatives in troubleshooting resources affecting computing.

3.2.16 Perform duties related to Cybersecurity Testing, Evaluation, Validation and Verification of traditional and non-traditional information systems.

3.2.17 Development of Cybersecurity test plans for security testing of DoD/DoN information systems in the unclassified and classified domains DOD requirements.

3.2.18 Executing testing procedures to determine an accurate assessment of the representative systems and provide information that will formulate mitigation strategies, risk analysis, and risk-based decisions (RBD).

3.2.19 Manages the daily activities of configuration and operation of systems and performs system capacity analysis and planning. Monitors systems for acceptable performance and user accessibility.

3.2.20 Maintains servers, creates monitoring reports and logs, and ensures functionality of system links

3.2.21 Support the technical areas within information security work related to Cybersecurity

3.2.22 Provide help desk support to Radar Division personnel and support contractors to resolve computer and software issues in a timely and professional manner.

3.2.23 Maintain documentation of the Code 5300 NICENET, Non-Internet connected Enclave equipment and software configurations.

3.2.24 Install/update/configure Blackberry Enterprise Server for access to Radar Division email via iPhone cell phones.

3.2.25 Install configure and manage internal network switches used to maintain division system and server connectivity not managed by NRL Networking group.

(This includes server rack internal backbone).

3.2.26 Maintains configuration management and system history documentation for hardware and software system changes via a continuous monitoring system such as Belarc BelManage and BelSecure.

3.2.27 Maintains internal division host based security system and software via Symantec Endpoint Protection for internal firewall, malware, spyware and anti-virus support and protection.

3.2.28 Acts as division Information System Security Officer/Information Assurance Officer. Providing information assurance direction and guidance to the division when applicable. Acts as the division point of contact with NRL Cyber- Security and as interface/representative with the NRL change control board.

3.3 The contractor shall provide IT support to all Radar Division personnel Radar5300SCF (REDNET) classified systems. The Contractor shall install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked systems. Procedures must be developed and maintained for systems such as set up, startup, shutdown, integration, troubleshooting, and operation.

Information Technology professionals will monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, Security Technical Implementation Guide (STIG), applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results. Network applications and services are supported at different classification levels. Solutions are developed to monitor performance, provide scaling capability, and improve quality of service. Systems are installed, and errors resolved.

Support will be provided in the preparation and testing of DoD and US Government computer and/or network systems for accreditation.

Tasks can include, but not limited to:

3.3.1 Implement Security Technical Implementation Guides (STIGS) to harden

Radar5300SCF (REDNET (Classified Network)) systems, and network equipment per DoD standards. Use DoD approved scanning tools such as ACAS, Nessus and SCC/SCAP for monitoring security of the classified network to identify and address vulnerabilities to ensure compliance with NRL/DoD Navy regulations.

3.3.2 Monitor the networks and security devices for compliance with Department of Defense (DoD) Information Assurance regulations, applying software patches and updates, and acting upon Information Assurance Vulnerability Alert (IAVA) scan results on Radar Division Classified Network (REDNET). Develop new solutions to monitor performance, provide scaling capability, and improve quality of service.

Monitor and report system compliance.

3.3.3 Manage software installations on the Classified Network (REDNET).

Verify software installs comply with the DoD approved list in the DADMS database. System Hardware and Software.

3.3.4 Use Group Policy Objects (GPOs) to maintain STIG compliance and update third party software on all systems in Radar Division Windows Active Directory (AD) domain.

3.3.5 Install/configure/maintain Centrify COTS software to implement Single Sign On (SSO) to Windows, and Linux systems per DoD guidelines.

3.3.6 Install/manage/update/configure MS Exchange email server for Radar Division users on REDNET, integrating Exchange with Windows and Linux email users. (Manage and maintain Symantec Mail Security for Microsoft Exchange.)

3.3.7 Install, configure, operate, test, troubleshoot, update, fix, replace, maintain, administer and optimize a variety of networked and stand-alone systems. Maximize reliability, maintainability and availability of IT hardware and associated peripherals. Provide IT technical support for the scientific and administrative users.

3.3.8 Interface with NRL Information Systems Security and implement all required computer security procedures. Interface with the NRL networking group to maintain the Radar Division REDNET networking infrastructure.

3.3.9 Assist in the preparation and testing of DoD and US Government computer and/or network systems for accreditation

3.3.10 Install hardware and software upgrades to IT systems in accordance with technical direction from the COR

3.3.11 Perform IT systems hardware and software modifications in accordance with technical direction from the COR.

3.3.12 Maintain computer configuration management systems and databases including hardware component lists, modifications, upgrades and maintenance histories.

3.3.13 Coordinate effectively with IT hardware and software vendor representatives in troubleshooting resources affecting computing.

3.3.14 Perform duties related to Cybersecurity Testing, Evaluation, Validation and Verification of traditional and non-traditional information systems.

3.3.15 Development of Cybersecurity test plans for security testing of DoD/DoN information systems in the classified domains DOD requirements.

3.3.16 Executing testing procedures to determine an accurate assessment of the representative systems and provide information that will formulate mitigation strategies, risk analysis, and risk-based decisions (RBD).

3.3.17 Manages the daily activities of configuration and operation of systems and performs system capacity analysis and planning. Monitors systems for acceptable performance and user accessibility.

3.3.18 Maintains servers, creates monitoring reports and logs, and ensures functionality of system links

3.3.19 Support the technical areas within information security work related to Cybersecurity

3.3.20 Provide help desk support to Radar Davison personnel and support contractors to resolve computer and software issues in a timely and professional manner.

3.3.21 Maintain documentation of the Code 5300 REDNET equipment and software configurations.

3.3.22 Install configure and manage internal network switches used to maintain division system and server connectivity not managed by NRL Networking group. (This includes server rack internal backbone).

3.3.23 Maintains configuration management and system history documentation for hardware and software system changes via a continuous monitoring system such as Belarc BelManage and BelSecure.

3.3.24 Maintains internal division host based security system and software via Symantec Endpoint Protection for internal firewall, malware, spyware and anti-virus support and protection.

3.3.25 Acts as division Information System Security Officer/Information Assurance Officer. Providing information assurance direction and guidance to the division when applicable. Acts as the division point of contact with NRL Cyber-Security and as interface/representative with the

NRL change control board.

3.3.26 The ability to provide Security Engineering design and System

Engineering network design via the Enterprise Architecture and the ability to fully integrate both.

3.0 Deliverables

3.1 Monthly Labor and Financial Status Report

3.1.1 Funding history, showing when and how much money was added to each ACRN for each person on the task, amounts allocated to labor, travel, and material, along with cumulative task funding for labor, travel, and material;

3.1.2 Funding balance for labor and materials in each ACRN and by person at the beginning of the monthly reporting period;

3.1.3 Labor hours and amounts expended for labor and materials in each ACRN and by person during the monthly reporting period;

3.1.4 Funding balance for labor and materials in each ACRN and by person at the end of the monthly reporting period.

3.2 Task Technical Progress Reports

The contractor shall provide a monthly summary report of progress on each task of the contract that includes the following information:

3.2.1 Description of the work accomplished;

4.0 Period of Performance

The period of performance for this effort is sixty (60) months from date of award

4.1 Performance Requirements

The contractor shall perform the above-stated objectives during NRL Radar Division normal core working hours, generally 9:00 am to 3:00 pm Monday through Friday or during other agreed upon hours, except for Federal holidays. Flexible work hours may be used to ensure that some range of technical services are available during the time specified, taking into account the need for maximum support during NRL core work hours. Deviation from these support hours and any use of telework to meet local support requirements shall be proposed to and coordinated by the Contracting Officer's

Representative (COR). NRL may require after hours or weekend efforts, for example but not limited to, support of a scheduled outage or to react to an emergency or security situation. After hours support shall be coordinated between the COR and the contractor onsite IT Staff. The NRL COR shall provide the contractor onsite IT Staff with advance notification and specific needs if known in advance. Contractor personnel shall also investigate, provide recommendations for remedial action, and pursue corrective action in case of emergency situations.

5.0 Special Requirements

The section describes the special requirements for this effort. The following sub-sections provide details of various considerations on this effort.

5.1 Security

a. Specifically designated contractor personnel assigned to this contract must possess a favorably adjudicated DoD Tier 5 investigation and a final Top SECRET DoD granted personnel security clearance.

b. The contractor will NOT be required to generate, receive or store CLASSIFIED material at the contractor’s facility.

c. A visit request is required for all personnel assigned to work on this contract. Visit requests must include full name, social security number, contract number and should also state if Government furnished computer equipment will be required.

d. Prime contractor will forward a copy of all subcontracts and task orders, related to this contract, regardless of classification, must be approved in advance, in writing, by the Head of the Naval Research Laboratory’s Information Security and Special Programs.

The prime contractor will coordinate the approval of all subcontracts and task orders with the Contracting Officer’s Representative (COR). The COR will in turn, coordinate the approved paperwork with the Head of NRL’s Information Security and Special Programs.

e. Proprietary, Privacy Act or For Official Use Only Information associated with this contract, must be handled/controlled IAW DoD 5200.01 Vol. 4. Prime contractor will provide the security classification guidance for classified work required under this contract.

f. NATO briefings required. NATO access authorized at SECRET level only. Initial NATO briefings must be within a 5 year scope of the completed investigation. Visit request and a copy of NATO indoctrination must be sent to Code 1231 for all initial NATO briefings, prior to access. NATO briefings date must be within the current year.

Annual refresher briefings for NATO access are required. A copy of the signed annual re-briefings must be forwarded to NRL Code 1231 annually.

g. Foreign Nationals are not authorized to work on this contract.

h. All contractors (including subcontractors) identified in the Statement of Work shall supplement their current security practices by requiring any personnel involved in executing the contract to complete Government-sponsored and administered Operations

Security (OPSEC) training, OPSE-1301 and any OPSEC guidance that may pertain to the project.

i. Contractor personnel performing any function designated as a component of the Cyber Security Work Force (CSWF), and /or having privileged user access to NRL information systems will require background investigations and security clearances commensurate with the access level and security classification of the system being accessed as specified in DON 5239.2M (2009). System Administrators with privileged access may work in the computing, network and/or enclave environments. System Administrators with privileged access shall meet the training and certification requirements for IAT level I at the computing environment (CE), IAT level II at the network environment (NE), and IAT level III for the enclave environment as specified in DON 5239.2M (2009). The submission of a DoD TIER 5 Investigation is required for all System Administrators with privileged access serving in these position.

File details come from the government source that posted it. Updated .