N0018921QR002 Solicitation.pdf
PDF 1022 KB Posted
- Attached to
- OIS Special Projects Federal contract opportunity
- Solicitation number
- N0018921QR002
About this file
This is a solicitation for specialized software development and functional analysis support services for the Naval Supply Systems Command (NAVSUP) Ordnance Information System (OIS) Program Management Office. The services include functional analysis, requirements management, application development, integration, quality assurance and testing, and deployment support for specific OIS special projects identified by the Program Manager. Quotes are due by August 19, 2021 at 4:00PM EST and shall be submitted electronically. The anticipated type of contract is firm-fixed price. The solicitation is set aside as a Women-Owned Small Business competition under $16.5 million size standard NAICS 541330. The period of performance is one base year with four optional one-year periods.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Amendment N0018921QR002.pdf | ||
| SYNOPSIS OIS special projects.pdf | ||
| DD254 April 2018 Version OIS Special Projects Services.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SEE ADDENDUM
(No Collect Calls)
N0018921QR002 16-Aug-2021
b. TELEPHONE NUMBER
717-605-5325
8. OFFER DUE DATE/LOCAL TIME
04:00 PM 19 Aug 2021
5. SOLICITATION NUMBER 6. SOLICITATION ISSUE DATE
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
STANDARD FORM 1449 (REV. 2/2012)
Prescribed by GSA – FAR (48 CFR) 53.212
(TYPE OR PRINT)
(SIGNATURE OF CONTRACTING OFFICER)
ADDENDA ARE
26. TOTAL AWARD AMOUNT (For Gov t. Use Only )
23.
CODE 10. THIS ACQUISITION IS
SUCH ADDRESS IN OFFER
17b. CHECK IF REMITTANCE IS DIFFERENT AND PUT
BELOW IS CHECKED
TELEPHONE NO.
N001899. ISSUED BY
18b. SUBMIT INVOICES TO ADDRESS SHOWN IN BLOCK 18a. UNLESS BLOCK
7. FOR SOLICITATION
INFORMATION CALL:
a. NAME
NICOLE C. IKENA-MILLER
2. CONTRACT NO. 3. AWARD/EFFECTIVE DATE 4. ORDER NUMBER
(TYPE OR PRINT)
30b. NAME AND TITLE OF SIGNER 30c. DATE SIGNED 31b. NAME OF CONTRACTING OFFICER
30a. SIGNATURE OF OFFEROR/CONTRACTOR 31a.UNITED STATES OF AMERICA
0 27a. SOLICITATION INCORPORATES BY REFERENCE FAR 52.212-1. 52.212-4. FAR 52.212-3. 52.212-5 ARE ATTACHED.
25. ACCOUNTING AND APPROPRIATION DATA
1. REQUISITION NUMBER
20.
ADDITIONAL SHEETS SUBJECT TO THE TERMS AND CONDITIONS SPECIFIED.
OFFEROR TO COMPLETE BLOCKS 12, 17, 23, 24, AND 30
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
ARE NOT ATTACHED
27b. CONTRACT/PURCHASE ORDER INCORPORATES BY REFERENCE FAR 52.212-4. FAR 52.212-5 IS ATTACHED. ADDENDA ARE ARE NOT ATTACHED
(BLOCK 5), INCLUDING ANY ADDITIONS OR CHANGES WHICH ARE
SET FORTH HEREIN, IS ACCEPTED AS TO ITEMS:
. YOUR OFFER ON SOLICITATION
28. CONTRACTOR IS REQUIRED TO SIGN THIS DOCUMENT AND RETURN
% FOR:SET ASIDE:UNRESTRICTED ORX
SMALL BUSINESS
17a.CONTRACTOR/ CODE FACILITY
OFFEROR CODE
NAVSUP FLC NORFOLK CONTRACTING
MECHANICSBURG OFFICE
ATTN: N IKENAMILLER
5450 CARLISLE PIKE BOX 2020
MECHANICSBURG PA 17050-2411
18a. PAYMENT WILL BE MADE BY CODE
RATED ORDER UNDER
DPAS (15 CFR 700)
13a. THIS CONTRACT IS A
13b. RATING
CODE15. DELIVER TO CODE N00023 16. ADMINISTERED BY
12. DISCOUNT TERMS11. DELIVERY FOR FOB DESTINA-
TION UNLESS BLOCK IS
MARKED
SEE SCHEDULE
14. METHOD OF SOLICITATION
RFQ IFB RFPX
NAVSUP HEADQUARTERS
AMANDA JOHNSON
5450 CARLISLE PIKE
BLDG. 309
MECHANICSBURG PA
TEL: 717.605.2925 FAX:
FAX:
TEL: 717-605-5325 SERVICE-DISABLED
VETERAN-OWNED
SMALL BUSINESS
8(A)
HUBZONE SMALL
BUSINESS
SIZE STANDARD:
$16,500,000
NAICS:
541330
X
OFFER DATED
29. AWARD OF CONTRACT: REF.
DELIVER ALL ITEMS SET FORTH OR OTHERWISE IDENTIFIED ABOVE AND ON ANY
COPIES TO ISSUING OFFICE. CONTRACTOR AGREES TO FURNISH AND
EMAIL:
TEL:
31c. DATE SIGNED
SEE SCHEDULE
SCHEDULE OF SUPPLIES/ SERVICESITEM NO. QUANTITY UNIT UNIT PRICE AMOUNT
24.22.21.19.
WOMEN-OWNED SMALL BUSINESS (WOSB)
ELIGIBLE UNDER THE WOMEN-OWNED
SMALL BUSINESS PROGRAM
EDWOSB
32g. E-MAIL OF AUTHORIZED GOVERNMENT REPRESENTATIVE
SOLICITATION/CONTRACT/ORDER FOR COMMERCIAL ITEMS
(CONTINUED)
PAGE 2 OF70
ACCEPTED, AND CONFORMS TO THE CONTRACT, EXCEPT AS NOTED: ______________________________________________________
32a. QUANTITY IN COLUMN 21 HAS BEEN
RECEIVED INSPECTED
32b. SIGNATURE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32c. DATE 32d. PRINTED NAME AND TITLE OF AUTHORIZED GOVERNMENT
REPRESENTATIVE
32e. MAILING ADDRESS OF AUTHORIZED GOVERNMENT REPRESENTATIVE 32f . TELEPHONE NUMBER OF AUTHORIZED GOVERNMENT REPRESENTATIVE
37. CHECK NUMBER
FINALPARTIALCOMPLETE
36. PAYMENT35. AMOUNT VERIFIED
CORRECT FOR
34. VOUCHER NUMBER
FINAL
33. SHIP NUMBER
PARTIAL
38. S/R ACCOUNT NUMBER 39. S/R VOUCHER NUMBER 40. PAID BY
41a. I CERTIFY THIS ACCOUNT IS CORRECT AND PROPER FOR PAYMENT
41b. SIGNATURE AND TITLE OF CERTIFYING OFFICER 41c. DATE
42a. RECEIVED BY (Print)
42b. RECEIVED AT (Location)
42c. DATE REC'D (YY/MM/DD) 42d. TOTAL CONTAINERS
STANDARD FORM 1449 (REV. 2/2012) BACK
Prescribed by GSA – FAR (48 CFR) 53.212
AUTHORIZED FOR LOCAL REPRODUCTION
PREVIOUS EDITION IS NOT USABLE
SEE SCHEDULE
20.
SCHEDULE OF SUPPLIES/ SERVICES
21.
QUANTITY UNIT
22. 23.
UNIT PRICE
24.
AMOUNT
19.
ITEM NO.
N0018921QR002
Section SF 1449 - CONTINUATION SHEET
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
0001 12 Months Labor
FFP
All efforts required to complete the work required under the PWS FOB: Destination
PSC CD: R499
NET AMT
0002 Lot Travel
COST
Travel IAW the PWS and applicable travel regulations
ESTIMATED COST
1001 12 Months OPTION Labor
FFP
All efforts required to complete the work required under the PWS
1002 Lot OPTION Travel
COST
Travel IAW the PWS and applicable travel regulations
2001 12 Months OPTION Labor
FFP
All efforts required to complete the work required under the PWS
2002 Lot OPTION Travel
COST
Travel IAW the PWS and applicable travel regulations
3001 12 Months OPTION Labor
FFP
All efforts required to complete the work required under the PWS
3002 Lot OPTION Travel
COST
Travel IAW the PWS and applicable travel regulations
4001 Months OPTION Labor
FFP
All efforts required to complete the work required under the PWS
4002 Lot OPTION Travel
COST
Travel IAW the PWS and applicable travel regulations
PERFORMANCE WORK STATEMENT
Performance Work Statement (PWS) for Contract Support for Ordnance Information System (OIS) Special Projects Support Services
1.0 Introduction: Naval Supply Systems Command (NAVSUP) Ordnance Information System (OIS) Program Management Office is to obtain functional analysis and development support services to enable delivery of specific special projects. These special projects will be identified by the OIS Program Manager and will be worked autonomously from OIS sustainment and fleet support.
2.0 Background: The NAVSUP OIS utilizes web-based logistical and inventory management tools, as well as, maintains a global presence of ordnance logistics experts to provide front line support and training to our Warfare Enterprise customers. OIS provides critical “real time” worldwide ordnance visibility. OIS not only improves and simplifies the day-to-day ordnance inventory management, it also gives our warfighters in the Fleet and on the front lines a critical tool to help them prevail in combat. Additionally, the NAVSUP OIS supports a multitude of customers who often require specialized support, outside of standard day-to-day sustainment operations and customer support.
2.1 Requiring Organization:
The organization requiring the services outlined in the Performance Work Statement (PWS) is:
NAVSUP Business Systems Center 5450 Carlisle Pike Suite 409 Mechanicsburg PA 17050
2.2 Project Description:
The purpose of this PWS is to obtain contract services to enable delivery of special projects through functional analysis and solution enhancement, if necessary. The objective is to allow specific, ad-hoc customer requirements, vetted by the OIS Program Manager, to be completed in an expeditious manner apart from normal OIS operations.
3.0 Scope:
The goal of this PWS is to obtain contractor support services to provide the following services in support of specific NAVSUP OIS customers with specialized, niche information systems:
• Business system integration that may include the need for any of the following services:
o System Analysis o Requirements Management o Application Development o Integration o Quality Assurance and Testing o Deployment
• Project Management
4.0 Directives:
The contractor shall comply with the following directives, and any updated/future versions as they are released:
• Federal Information Security Modernization Act of 2014 (“FISMA”)
• Common Criteria for Information Technology Security Evaluation, Part 3: Security Assurance Components, April 2017, Version 3.1, Revision 5, CCMB-2017-04-003
• DoD Instruction 5400.11, DoD Privacy and Civil Liberties Programs, 29 January 2019 (incorporating Change 1, 8 December 2020)
• DoD Directive 8000.01, Management of the DoD Information Enterprise, 17 March 2016 (incorporating Change 1 July 2017)
• DoD Directive 8140.01, Cyberspace Workforce Management, 5 October 2020
• DoD Instruction 4161.02, Accountability and Management of Government Contract Property, 27 April 2012 (incorporating Change 2, 31 August 2018)
• DoD Instruction 8320.07, Implementing the Sharing of Data, Information, and Information Technology (IT) Services in the Department of Defense, 3 August 2015 (incorporating Change 1, 5 December 2017)
• DoD Instruction 8500.01, Cybersecurity, 14 March 2014, Change 1, 7 October 2019
• DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology, 12 March 2014 (incorporating Change 2, 29 December 2020)
• DoD Instruction 8582.01, Security of Non-DoD Information Systems Processing Unclassified Nonpublic DoD Information, 9 December 2019
• SECNAVINST 5510.36B, DoN Information Security Program, 12 July 2019
• DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 December 2005 (incorporating Change 4, 10 November 2015)
• SECNAV Instruction 5211.5F, Department of the Navy Privacy Program, 20 May 2019
• SECNAV Instruction 5239.3C, DON Cybersecurity Policy, 2 May 2016
• SECNAV M-5239.2, DoN Information Assurance Manual, June 2016
• OPNAVINST 5239.1D, U.S. Navy Cybersecurity Program, 18 July 2018
• OPNAVINST 5239.4, Chief of Naval Operations Cybersecurity Safety Program, 14 September 2018
• SECNAV Manual M-5239.2, DON Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual, 27 June 2016
• CJCSI 6211.02D, Defense Information Systems Network (DISN) Responsibilities, 24 January 2012
• DoD Public Key Infrastructure (https://cyber.mil/pki-pke)
• ISO/IEC/IEEE 12207:2017 Systems and Software Engineering – Software Life Cycle Processes
• ANSI/EIA 649C-2019 – Configuration Management Standard
• ANSI/EIA 836B-2015 – Configuration Management Data Exchange and Interoperability
• Federal Risk and Authorization Management Program (“FedRAMP”)
• Department of Defense Cloud Computing Security Requirements Guide, Version 1, Release 3, dated 6 March 2017
• All applicable Security Requirements Guides, Security Technical Implementation Guides, and National Security Agency security configuration guides when assessment and authorization is required
• NIST SP 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations, December 2018
• U.S. Navy Risk Management Framework Process Guide, Version 3.1, 2 September 2020
• NIST SP 800-53 Revision 45, Security and Privacy Controls for Information Systems and Organizations, September 2020, includes updates as of 10 December 2020
• NIST SP 800-53A Revision 4, Assessing Security and Privacy Controls in Federal Information Systems and Organizations, December 2014, includes updates as of 18 December
• NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, February 2020
• NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, June 2018
• NAVSUPINST 5239.5, Cybersecurity and Defensive Cyberspace Operations Policy, 25 March 2019
• ISO/IEC 19770-1:2017 – Information Technology – IT Asset Management – Part 1: IT Asset Management Systems - Requirements
• ISO/IEC 19770-2:2015 - Information Technology -- Software Asset Management -- Part 2: Software Identification Tag
• ISO/IEC 19770 Series - Information Technology – IT Asset Management
• A Guide to the Project Management Body of Knowledge (PMBOK® Guide) - Sixth Edition
• Section 508 of the Rehabilitation Act of 1973 (amended by the Workforce Investment Act of 1998, 7 August 1998)
• SECNAVINST 5720.44C - Department of the Navy Policy for Content of Publically Accessible World Wide Web Sites, 21 February 2012 (incorporating Change 1, 14 October 2014)
• SECNAVINST 5510.30C, Department of Navy Personnel Security Program, 24 January
• Homeland Security Presidential Directive (HSPD)12, Policy for a Common Identification Standard for Federal Employees and Contractors, 27 August 2004
• DoD Manual 5200.02, Procedures for the DoD Personnel Security Program (PSP), 3 April 2017 (incorporating Change 1, 29 October 2020)
• DoD Manual 5200.08-R, Physical Security Program, 9 April 2007 (incorporating Change 2, 19 October 2020)
• NTTP 3-13.3, Operations Security (OPSEC), September 2017
• DoD Instruction 5200.48, Controlled Unclassified Information (CUI), March 6, 2020
• NSAMECHINST 5530.1C CH-1, Naval Support Activity Mechanicsburg Installation Access Control, 23 August 2019
• Executive Order 13467 as amended, Establish the Roles and Responsibilities of the National Background Investigations Bureau and Related Matters, 30 June 2008
• Executive Order 13526, Original Classification Authority, 29 December 2009
• DoD Manual 5220.22, National Industrial Security Program Operating Manual, February 2006 (incorporating Change 2, 18 May 2016)
• DoD Manual 5220.22, Volume 2, National Industrial Security Program: Industrial Security Procedures for Government Activities Operating Manual, 1 August 2018 (incorporating Change 1, 30 September 2020)
• DoDM 5200.01 Volume 1, DoD Information Security Program: Overview, Classification, and Declassification, 24 February 2012 (incorporating Change 2, 28 July 2020)
• DoDM 5200.01 Volume 2, DoD Information Security Program: Marking of Information, 24 February 2012 (incorporating Change 4, 28 July 2020)
• DoDM 5200.01 Volume 3, DoD Information Security Program: Protection of Classified Information, 24 February 2012 (incorporating Change 3, 28 July 2020)
5.0 Requirements/Tasks: The contractor shall be obligated contractually to perform every requirement in this performance work statement. Not every performance requirement has a related standard expressed in this document or in the Quality Assurance Surveillance Plan (QASP). In such cases the performance standard is either inherent in the requirement or performance is to be in accordance with standard commercial practice.
Per DFARS 211.106, contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification for meetings with Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal and informal written correspondence.
5.1 Program Management. The project manager shall be responsible for:
5.1.1 Providing direction, guidance, and advisement to teams assigned OIS tasks in accordance with published schedules.
5.1.2 Communication with the Technical Assistant (TA) providing regular updates regarding progress of tasks, costs, risks and any possible impediments to meeting the specified deliverable dates and budget, as required.
5.1.3 Reviewing deliverables, establishing/maintaining metrics, and providing general technical direction to staff supporting the team’s efforts.
5.1.4 Identifying and making recommendations on strategies and approaches to resolve risks, issues, and concerns that may be encountered during contract execution.
5.2 Project Management. The project manager shall be responsible for:
5.2.1 Initiating, executing, controlling, delivering, and closing projects using industry-standard project management methodologies.
5.2.2 Developing and providing details on budget, cost, and schedule estimates and actuals.
5.2.3 Defining the project management approach and optimizing procurement strategies.
5.2.4 Preparing the resource requirements of the project, and executing to those requirements.
5.2.5 Determining and controlling scope and submitting project baseline change request if necessary.
5.2.6 Monitoring project-level milestones and evaluating progress.
5.2.7 Assuring proper coordination and communication with project team, customers, and management.
5.2.8 Identifying issues and risks impacting project schedule, deliverables, and overall success, as well as mitigating or providing strategies to resolve these items.
5.2.9 Briefing customers, Program/Project team, and management on project status, strategies, software solutions, and other communications deemed necessary by the Government lead.
5.3 Functional Analysis. The functional analyst shall be responsible for:
5.3.1 Providing functional authority and functional knowledge expertise for specialized Ordnance Logistics and Management processes.
5.3.2 Obtaining requirements from customers/users.
5.3.3 Analyzing system requirements and converting requirements to functional design to be created into detailed logic for coding into computer language.
5.3.4 Identifying, defining, or modifying interfaces with other systems/applications, ensuring agreements are formally documented with the interfacing system/application.
5.3.5 Developing test plans, and executing test events and regression tests, as required.
5.3.6 Conducting Validation and/or User Acceptance testing with customers/users, as necessary.
5.3.7 Performing configuration management for the assigned systems in accordance with established standards.
5.4 Software Engineering. The software developer/engineer shall:
5.4.1 Perform functions relating to design, software engineering/programming (create/maintain source code) and unit testing.
5.4.2 Analyze/refine systems requirements, determine and design system/application architecture, write/debug/maintain code (using the defined software development processes), and develop/maintain system/application documentation.
5.4.3 Conduct overall system tests to ensure functional unit inter-relationships are functioning properly.
5.4.4 Support customer/users in testing, assuring software and systems quality and functionality.
5.4.5 Determine the feasibility of design alternatives, translate systems requirements into application prototypes, and develop problem resolutions.
5.5 Transition Support. The project manager, functional analyst and/or software developer/engineer shall:
5.5.1 Transition - Phase In. The contractor shall participate in transition-in phase tasks to orderly and efficiently transition as responsible party. The transition phase shall consist of phaseout training from the incumbent and transition of all Government Furnished Information (GFI) relevant to the tasks specified herein.
This transition-in phase shall not in any way hinder the performance of the contractor's normal instructional duties required by this contract. The incoming contractor shall provide a designated point of contact, and a detailed Transition Plan for the migration of government data, functions and services from the incumbent. The Transition Plan shall provide a timeline for support personnel, transition and sufficient detail to ensure that no break in services is experienced. The contractor shall submit a Resource Allocation Plan to the TA within 7 days of award.
Transition - Phase Out. At the end of the period of performance, as the incumbent, the contractor shall provide a designated point of contact at least 60 days prior to the end of the period of performance, and provide advice, knowledge transfer and support in the timeline and transition plans of government data, functions and services to the new awardee.
6.0 Deliverables: All deliverables must meet the format requirements specified by the
Contracting Officer’s Representative. Documentation related to these services shall be made available electronically. The following list details the contract deliverables:
6.1 Monthly Status Report. Status reports shall be sent electronically to the Technical Assistant (TA) and Contracting Officer’s Representative (COR) on a monthly basis (due by 1700 on the 10th day of every month documenting the performance on the order. The status report shall include the following elements:
• Resources by name
• Labor Category
• Status of work with accomplishments documented
• Any issues/problems encountered or possible and recommended solutions
• Identify any Government dependencies that are overdue which impact schedule or performance
6.2 Monthly (if applicable) Travel Reports. Travel reports shall be sent electronically to the TA and COR. Travel reports shall include: destination, dates of travel, subjects discussed, and any issues/problems encountered and recommended solutions.
6.3 Deliverables are outlined in the chart below:
Deliverable Delivery Timing
5.3.2 Customer requirements documents.
As Required
5.3.3 Functional design documents. As required
5.3.5 and 5.4.3 Test plans and documented test results. As required
5.5.1 Transition Plan
Transition – Phase in
6.4 Monthly Payment Request. The contractor shall submit a monthly payment request (invoice) electronically using Wide Area Workflow (WAWF). WAWF is available on the internet at https://wawf.eb.mil.
Included with the invoice shall be support documentation such as, but not limited to, travel authorizations/receipts (if applicable), etc. Invoices received without the support documentation (in the correct format) will be rejected.
The contractor shall submit a final invoice or zero cost invoice to properly close out the contract.
6.5 Mandatory Annual Training: The contractor shall participate in DoD/DoN mandatory annual training when announced by the Government.
Contractors are required to complete the following mandatory training and any updated/future training as released: 1) Personally Identifiable Information (PII); 2) DoN Records Management: Everyone's Responsibility; 3) Anti-Terrorism/Force Protection Awareness; 4) Combating Trafficking in Person; 5) Operations Security (OPSEC); 6) Training & Readiness – The Active Shooter. The contractor shall complete DoD Cyber Awareness Challenge v4 mandatory training two weeks after contract award. Jacqueline Jamison 717-605-3357, or Antonio Arturet-Millan, 717-605-8192, are the POCs for the Cyber Awareness training. Training can be accessed at https://cyber.mil/training/cyber-awareness-challenge/.
Unless stated otherwise, the following instructions apply to all deliverables:
• All versions of the deliverables required by the order shall be delivered electronically to the COR and TA and/or his/her designee and shall be subject to Government review and approval.
• Deliverable due dates shall take into account the review periods described below.
• Draft deliverables will be reviewed and feedback and/or requested changes provided within 7 business days (unless otherwise specified).
• Government reserves the right to request a formal review session with the contractor during these timeframes and may request that the contractor make changes to any version of a deliverable.
• Government will review and approve or reject all final versions of all deliverables within 7 business days of receipt (unless otherwise specified).
• If any deliverable is rejected, the contractor will be notified within the specified time periods and will have 7 calendar days within which to rework the deliverable and resubmit for Government approval. All changes to any version of a deliverable and/or deliverable outline shall be approved by the COR or TA. If more than the specified number of calendar days is required for Government review and approval, the COR or TA will inform the contractor of the need for an extension within the initial review period.
• Contractor shall prepare and submit the deliverables on or before the required due date to the COR and TA or designee via email. For deliverables that are not documents, the contractor shall submit a description of the deliverable and any associated documentation or descriptive information. In no case shall any deliverable be received by the Government less than 21 calendar days prior to the end of the Period of Performance.
• Rejection of any deliverable by the Government does not excuse the contractor from meeting the baseline due dates for any other deliverables.
7.0 Period of Performance:
Work shall be performed from the period of performance start date for one year with four (4) additional option periods. A 30 day start-up period is required as defined below. The contractor shall follow appropriate local base policy for reporting to work during severe weather and base closure. The contractor is not authorized to begin work until both the Visit Authorization Request (VAR) and System Authorization Access Request - Navy (SAAR-N) forms have been successfully processed and base and system access have been granted.
ON-BOARDING PROCESS
All contractor resource onboarding documents must be submitted via the prime contractor. An employee is considered to be “productive” upon completion of the following items:
a. Visit Authorization Request (VAR)
b. Contractor Information Request Form (CIRF)
c. FD-258 fingerprint card/Contractor Responsibility
d. Completed EQIP (Electronic Investigation)/Contractor Responsibility
e. All contractor resource(s) must have an active JPAS profile
f. Common Access Card (CAC)
g. Facility Clearance Level per DD Form 254
h. Individual Contractors adjudicated at the appropriate level
i. System Authorization Access Request – Navy (SAAR-N)
j. Cyber Awareness Training Certification
k. Information Assurance (IA) certification (if applicable)
Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services.
Note (2): Dual Citizenship and Foreign Nationals are not allowed access to the functional/system side of the NAVSUP Ordnance Information System.
Contractor and subcontractor employees performing under this order are required to sign a Non-disclosure Agreement (NDA) as part of their onboarding process. Refer to DFARS 252.204- 7000, Disclosure of Information, and DFARS 252.204-7003, Control of Government Personnel Work Product.
8.0 Place of Performance:
The following location is the primary site for performance:
• Naval Special Warfare Development Group (NSWDG), 472 Polaris Ave, Bldg 586, Virginia Beach, VA 23461
Primary area of support will be performed at the site listed above. For some tasks and with TA approval, the contractor may work remotely from their facility, home or be required to travel to other Navy/DOD sites in support of this PWS. Overseas Travel is not required.
All SIPR work shall be performed within a Secured Facility approved by the TA.
9.0 Travel:
The contractor may be required to travel to CONUS locations.
Travel shall be in accordance with FAR 31.205-46. All travel must be pre-approved in writing by the TA and COR prior to the actual travel and all travel must be funded in the contract prior to any travel expenses being incurred. No travel shall occur outside of the period of performance dates of the contract. Travel 12 hours or less, per diem does not apply. Foreign (overseas) Travel will not be required for this order.
If travel is required, the contractor is responsible for making all needed arrangements for their personnel.
9.1 Travel Policy. The Government will reimburse the contractor for allowable travel costs incurred by the contractor in performance of this PWS and determined to be in accordance with FAR subpart 31.2, subject to the following provisions:
• Travel required for tasks assigned under this contract shall be governed in accordance with rules set forth for temporary duty travel in FAR 31.205-46.
9.2 Travel other. Travel, subsistence, and associated labor charges for travel time are authorized whenever a task assignment requires work to be accomplished at a temporary alternate worksite. Travel performed for personal convenience will not be reimbursed.
9.3 Air/Rail Travel. In rendering the services, the contractor shall be reimbursed for the actual costs of transportation incurred by its personnel not to exceed the cost of economy class rail, or plane fare, to the extent that such transportation is necessary for the performance of the services hereunder and is authorized by the Contracting Officer’s Representative (COR). Such authorization by the COR shall be indicated in the order or in some other suitable written form.
10.0 Security:
Contractors providing support on this task order shall require a (minimum) SECRET security clearance. A DD Form 254 is required.
Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information (DEC 2019)
Executive Order 13467, Reforming Processes Related to Suitability for Government Employment, Fitness for Contractor Employees, and Eligibility for Access to Classified National
Security Information, and Homeland Security Presidential Directive (HSPD)-12, requires government agencies to develop and implement Federal security standards for Federal employees and contractors. The 5 CFR 32 part 157 in concert with DoD Manual 1000.13, Vol 1, implements the Federal Standards.
APPLICABILITY
This text applies to all DoD sponsored individuals who require CAC eligibility (or login and P/W if acceptable per contract) for: Physical access to DoD facilities or non-DoD facilities on behalf of DoD; Logical access to information systems (whether on site or remotely); or remote access to DoD networks that use only the CAC logon for user authentication, or access to sensitive and protected information. This applies to the Office of the Secretary of Defense, the Military Departments, the Office of the Chairman of the Joint Chiefs of Staff and the Joint Staff, the Combatant Commands, the Office of the Inspector General of the DoD, the Defense Agencies, the DoD Field Activities, and all other organizational entities within the DoD (hereinafter referred to collectively as the "DoD Components").
Each contractor employee providing services at a Navy Command under this contract is required to obtain a Department of Defense Common Access Card (DoD CAC). Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.
ACCESS TO FEDERAL FACILITIES
Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this text will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command's Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual's performance under the contract.
START-UP PERIOD
All contractor resource onboarding documents must be submitted via the prime contractor. The prime contractor shall make all necessary preparations to assume full responsibility for productive performance as of the performance start date.
Definition of "productive":
a. Visit Authorization Request (VAR)
b. Contractor Information Request Form (CIRF)
c. FD-258 fingerprint card/ Contractor Responsibility
d. Completed EQIP (Electronic Investigation)/Contractor Responsibility
e. All contractor resource(s) must have an active JPAS profile
f. Common Access Card (CAC)
g. Facility Clearance Level per DD Form 254
h. Individual Contractors adjudicated at the appropriate level
Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services, and no reimbursement will be paid by the Government for efforts expended during the start up period.
Note (2): Foreign Nationals are not allowed access to DoD/DoN system applications.
ACCESS TO DOD IT SYSTEMS
In accordance with SECNAV M-5510.30, contractor employees who require access to DoN or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to sensitive information.
Sensitive information includes information protected under the Privacy Act, to include Protected Health Information (PHI). All contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II. IT Levels are determined by the requiring activity's Command Information System Security Manager (ISSM)/Information Assurance Manager (IAM).
Contractor employees requiring privileged or IT-I level access, (when specified by the terms of the contract) require a Single Scope Background Investigation (SSBI) or T5 or T5R equivalent investigation, which is a higher level investigation than the National Agency Check with Law and Credit (NACLC)/T3/T3R described below. Due to the privileged system access, an investigation suitable for High Risk national security positions is required. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical Level 1, and must be trained and certified on the Operating System or Computing Environment they are required to maintain.
Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the contractor employee's duties, such employees shall in-process with the Navy Command's Security Manager and Information System Security Manager (ISSM)/Information Assurance Manager (IAM) upon arrival to the Navy command and shall out-process prior to their departure at the completion of the individual's performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The decision to authorize access to a government IT system/network is inherently governmental. The contractor supervisor is not authorized to sign the SAAR-N; therefore, the government employee with knowledge of the system/network access required or the COR shall sign the SAAR-N as the "supervisor".
The SAAR-N shall be forwarded to the Command's Security Manager at least 30 days prior to the individual's start date. Failure to provide the required documentation at least 30 days prior to the individual's start date may result in delaying the individual's start date.
When required to maintain access to required IT systems or networks, the contractor shall ensure that all employees requiring access complete annual Cyber Awareness) training, and maintain a current requisite background investigation. The Contractor's Security Representative shall contact the Command Security Manager for guidance when reinvestigations are required.
INTERIM ACCESS
The Command's Security Manager may authorize issuance of a DoD CAC and interim access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.
DENIAL OR TERMINATION OF ACCESS
The potential consequences of any requirement under this text including denial or termination of physical or system access in no way relieves the contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall plan ahead in processing their employees and subcontractor employees. The contractor shall insert this text in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally-controlled information system/network and/or to government information, meaning information not authorized for public release.
CONTRACTOR'S Facility Security Officer
The contractor’s Facility Security Officer (FSO) is the point of contact for all security related issues. Within three work days after contract award, the contractor shall provide to the requiring activity's Security Manager and the Contracting Officer, in writing, the name, title, address and phone number for the Contractor's Facility Security Officer. The Contractor's Facility Security Officer shall be the primary point of contact on any security matter. The Contracting Officer, Technical Assistant, and Command Security Manager, shall be notified immediately if the Facility Security Officer is replaced or removed. All Sub Vendors shall provide to the Prime Vendor the name, title, address and phone number for the Contractor's Facility Security Officer.
The Sub Vendor interacts with the Prime Vendor, and typically would not converse with the Contracting Officer, Technical Assistant, or Command Security Manager
Security Awareness Training Education
The Facility Security Officer of the Prime Vendor shall make certain that all Contractors complete all required Security Awareness Training Education. Contractors shall register their Public Key Infrastructure (PKI) Certificates on their Common Access Card (CAC). Registering PKI certificates enable the Security Manager to track their training in Total Workforce Management Services (TWMS). At a minimum Security Awareness Training Education annually includes: Anti-Terrorism Level I, OPSEC, Derivative Classification, Counter Intelligence Awareness and Reporting, and Security Awareness. SIPRNET and NATO training may be required depending upon position and access to NATO Information or the SIPRNET.
OPSEC
Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise, as outlined in NTTP 3-13.3M/MCTP 3-32B. The contractor shall consult with the OPSEC Program Manager within 5 working days of receipt of order to determine all special circumstances affecting OPSEC under this requirement. In any case where there is uncertainty or ambiguity regarding OPSEC measures, the contractor shall consult the OPSEC Program Manager as soon as possible.
BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL
PROCESS FOR CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS
OR PERFORMING SENSITIVE DUTIES
Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Contractor employees under this contract are recognized as Non-Critical Sensitive [ADP/IT-II] positions when the contract scope of work require physical access to a federally controlled base, facility or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to contractor employees who access Privacy Act and Protected Health Information (PHI), provide support associated with fiduciary duties, or perform duties that have been identified as National Security Positions. At a minimum, each contractor employee must be a US citizen and have a favorably completed NACLC or T3 or T3R equivalent investigation to obtain a favorable determination for assignment to a non-critical sensitive or IT-II position. The investigation consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. The Contractor’s Company is responsible for the processing of Background Investigations.
Failure to provide the required documentation at least 30 days prior to the individual's start date shall result in delaying the individual's start date. Background investigations shall be reinitiated by the Contractor’s Company as required to ensure investigations remain current throughout the contract performance period. The Contractor's Facility Security Officer shall contact the Command Security Manager immediately if a Contractor’s Personal Clearance Level is suspended or denied.
The Prime Vendor, and all Sub Vendors, are required to possess a Facility Clearance Level of Secret or above. The Facility Security Officer shall immediately notify the Contracting Officer, Technical Assistant, and Command Security Manager, if changes to status of the Facility Clearance Level occurs to either the Prime Vendor or Sub Vendors. A Prime Vendor shall not perform duties on the contract without an Active Secret or above Facility Clearance Level. If the Prime Vendor fails to obtain or maintain a Facility Clearance Level, no Sub Vendor is allowed to perform duties on the contract.
Regardless of their duties or IT access requirements ALL contractor employees shall in-process with the Command's Security Manager upon arrival to the command and shall out-process prior to their departure at the completion of the individual's performance under the contract.
Employees requiring IT access shall also check-in and check-out with the Navy Command's Information Systems Security Manager (ISSM)/Information Assurance Manager (IAM)Manager.
Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The SAAR-N shall be forwarded to the Navy Command's Security Manager at least 30 days prior to the individual's start date. Failure to provide the required documentation at least 30 days prior to the individual's start date shall result in delaying the individual's start date.
The contractor shall ensure that each contract employee requiring access to IT systems or networks complete annual Cyber Awareness training, and maintain a current requisite background investigation. Contractor employees shall accurately complete the required investigative forms prior to submission to the Command Security Manager. The Command's Security Manager will review the submitted documentation for completeness prior to submitting it to the Office of Personnel Management (OPM); Potential suitability or security issues identified may render the contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the contractor from meeting any contractual obligation under the contract. The Command's Security Manager will forward the required forms to OPM for processing. Once the investigation is complete, the results will be forwarded by OPM to the DoD Central Adjudication Facility (CAF) for a determination.
The contractor’s Facility Security Officer shall submit a Visit Authorization Request (VAR) and Contractor Information Request Form (CIRF) directly to the Technical Assistant (TA), for all contractor personnel performing contract related services. The Facility Security Officer shall submit via the Joint Personnel Adjudication System, a visit request to all Security Management Offices (SMO) that access is required. Visit Access Request submitted in the Joint Personnel Adjudication System need to specify the buildings required for classified work. The Navy Command will take JPAS "Servicing" role over the contractor employee during the hiring process and for the duration of assignment under that contract. The VAR requires annual renewal for the duration of the employee's performance under the contract.
(End of Clause)
DoD 8570.01-M Information Assurance Workforce Improvement Program.
The contractor shall have Information Assurance (IA) Workforce Improvement Program certificates for Cybersecurity positions. See the DoD Cyber Exchange website for DoD Approved 8570 Baseline Certifications aspxhttps://cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/.
Project Manager __X___ No Additional IA Certification Required _____Information Assurance DoD 8570.01-M Required:
IA Certification Level: N/A Baseline Certification: N/A Substitutes for Baseline Certification: N/A
Computing Environment Certification: None Privileged system access is not required for this labor category.
Functional Analyst: IAT-1 _____ No Additional IA Certification Required __X___Information Assurance DoD 8570.01-M Required:
IA Certification Level IAT Level I Baseline Certification: Network+CE Substitutes for Baseline Certification:
A+CE
Cisco Certified Network Associate-Security (CCNA-Security) System Security Certified Practitioner (SSCP)
Software Developer/Engineer: IAT-1 _____ No Additional IA Certification Required __X___Information Assurance DoD 8570.01-M Required:
IA Certification Level IAT Level I Baseline Certification: Network+CE Substitutes for Baseline Certification:
A+CE
Cisco Certified Network Associate-Security (CCNA-Security) System Security Certified Practitioner (SSCP)
Privileged system access is not required for this order. A DD254 Contract Security Classification is required.
The contracting officer will ensure that contractor personnel accessing DoD information systems have the appropriate and current information assurance baseline certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. Prior to being engaged and upon request by the Government, the Contractor shall provide documentation supporting the information assurance baseline certification status of personnel performing information assurance functions to the contracting officer. Contractor personnel who do not provide appropriate and current baseline certifications shall be deemed unauthorized to access DoD information systems.
The Contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program.
The Contractor shall meet the applicable information assurance certification requirements, including-
(1) DoD-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M.
(2) Appropriate operating system certification for information assurance technical positions as required by DoD 8570.01-M.
(a) Upon request by the Government, the Contractor shall provide documentation supporting the information assurance certification status of personnel performing information assurance functions.
(b) Contractor personnel who do not have proper and current certifications shall be denied access to DoD information systems for the purpose of performing information assurance functions.
Proof of the above indicated IA baseline certification is to be provided for all contractor personnel prior to time of engagement. In addition to the IA certificate, active enrollment and participation in the certification maintenance program must be established prior to contract award to ensure the appropriate access can be secured by contractor resources.
All required IA baseline certifications must be current at the contract period start date;
there is no “grace” period to obtain these certifications. Questions and additional information requirements may be addressed by contacting the NAVSUP Business Systems Center Information System Security Manager (ISSM).
Certification shall be forwarded to:
Jacquelin Jamison, Code 94 NAVSUP Business Systems Center ISSM 5450 Carlisle Pike, Suite 409 Mechanicsburg, PA 17050 Email: Jacquelin.jamison@navy.mil
Language used to supplement DFARS Clause 252.204-7012 entitled, “Safeguarding Covered Defense Information and Cyber Incident Reporting” from the memorandum Updated Implementation of “the DIB Memo” dated 06 Sep 2019:
1. System Security Plan and Plans of Action and Milestones (SSP/POAM) Reviews
a) Within thirty (30) days of contract award, the Contractor shall make its System Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the contractor's facility. The SSP(s) shall implement the security requirements in Defense Federal Acquisition Regulation Supplement (DF ARS) clause 252.204-7012, which is included in this contract. The Contractor shall fully cooperate in the Government's review of the SSPs at the Contractor's facility.
b) If the Government determines that the SSP(s) does not adequately implement the requirements of DFARS clause 252.204-7012 then the Government shall notify the Contractor of each identified deficiency. The Contractor shall correct any identified deficiencies within thirty
(30) days of notification by the Government. The contracting officer may provide for a correction period longer than thirty (30) days and, in such a case, may require the Contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies.
The Contractor shall immediately notify the contracting officer of any failure or anticipated failure to meet a milestone in such a POAM.
c) Upon the conclusion of the correction period, the Government may conduct a follow-on review of the SSP(s) at the Contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies in the SSP(s).
d) The Government may, in its sole discretion, conduct subsequent reviews at the Contractor's site to verify the information in the SSP(s). The Government will conduct such reviews at least every three (3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty (30) days' notice to the Contractor.
2. Compliance to NIST 800-171
a) The Contractor shall fully implement the CUI Security Requirements (Requirements) and associated Relevant Security Controls (Controls) in NIST Special Publication 800-171 (Rev.
1) (NIST SP 800-171), or establish a SSP(s) and POA&Ms that varies from NIST 800-171 only in accordance with DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract.
b) Notwithstanding the allowance for such variation, the contractor shall identify in any SSP and POA&M their plans to implement the following, at a minimum:
(1) Implement Control 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network. In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, such as CNC equipment, etc., a combination of physical and logical protections acceptable to the Government may be substituted;
(2) Implement Control 3.1.5 (least privilege) and associated Controls, and identify practices that the contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .