PWS FY25-FY29 IT SUPPORT Contract.pdf

PDF 467 KB Posted

Attached to
IT and Cybersecurity Support Federal contract opportunity
Solicitation number
N0018924CZ071
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This document is a Performance Work Statement (PWS) for an IT and Cybersecurity Support Services contract for the Navy Medicine Operational Training Command (NMOTC) located in Pensacola, Florida, and its subordinate detachments. The objective is to provide local IT and cybersecurity support services, including network management, network security administration, systems administration, application development, and web services. The contract will be a firm-fixed-price award with a 12-month base period and four 12-month option years. Key personnel requirements are specified, and the contractor must have appropriate security clearances. The government will provide necessary facilities, equipment, and materials. The contractor will be responsible for providing all other labor, supervision, transportation, supplies, and services required to perform the work.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

IT Support Services for Navy Medicine Operational Training Command

PART 1 GENERAL INFORMATION

1. General. This is a non-personal services contract to provide Information Technology and Cybersecurity support services. The Government will not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

1.1. Description of Services/Introduction. The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items for non-personal services necessary to perform IT support services at Navy Medicine Operational Training Command (NMOTC) Headquarters Pensacola, Florida and its subordinate commands as defined in this Performance Work Statement (PWS) except for those items specified as Government furnished property and services. The Contractor shall perform to the standards in this contract.

1.2. Background. Navy Medicine Operational Training Command (NMOTC) is an echelon four (4) shore activity located aboard Naval Air Station in Pensacola, Florida. NMOTC reports to the Navy Medicine Force Support Command (NMFSC) located in San Antonio, TX. NMOTC Information Management and Technology Department provides people, processes, technologies, facilities, skills, knowledge, and abilities necessary to develop, host, operate, and maintain critical education and training IT environments for the NMOTC Enterprise.

These IT and Cybersecurity Services support the command programs and activities for professional, technical, and consultative services in operationally related Fleet and Fleet Marine Force medical matters worldwide.

NMOTC conducts education and training programs for medical department personnel in various operational medical disciplines. NMOTC manages, coordinates, and provides selected operational programs (aviation physicals and survival training) and services in direct support of the operating forces as directed by higher authority. Currently IT services are being supported by task order number N68836-20-F-0139-P00012.

NMOTC has five detachments, 18 training centers/activities, staffed, and trained across eight civilian institutions, and 12 Navy/Marine Corps bases nationwide. NMOTC conducts 63 instructional program courses, 42 operational medicine courses, and 21 survival training courses, producing nine Navy Enlisted Classifications, six Navy Officer Billet Classifications, and three Additional Qualification Designations.

NMOTC consists of the following components:

1.2.1. Naval Survival Training Institute (NSTI) located in Pensacola, FL, assists the joint warfighter in winning the fight by providing safe, effective, and relevant human performance and survival training for all DoD personnel. NSTI has eight Aviation Survival Training Centers (ASTCs) at the following locations:

Pensacola, FL; Cherry Point, NC; Norfolk, VA; Jacksonville, FL; Patuxent River, MD; Miramar, CA;

Whidbey Island, WA; Lemoore, CA.

1.2.2. Naval Aerospace Medical Institute (NAMI) located in Pensacola, FL supports Navy and Marine Corps aviation units through aviation personnel screening, expert aeromedical evaluation and consultation, hyperbaric medicine support, services development, and application of aeromedical standards and training of aeromedical personnel for operational assignments.

1.2.3. Naval Undersea Medical Institute (NUMI) located in Groton, CT, provides training in Undersea Medicine and Radiation Health to officers and enlisted Sailors who will support warfighters in the Submarine Force, Naval Special Warfare, Naval Expeditionary Combat Command, the USMC, and BUMED. NUMI provides expert consultation in undersea medicine and radiation health.

1.2.4. Surface Warfare Medical Institute (SWMI) located in San Diego, CA, is a leader in providing medical education, operational training, and certification for medical, dental and fleet personnel ashore and afloat in support of global operations. SWMI conducts Surface Forces and Dive medical training annually for 224 Independent Duty Corpsman and over 150 Surface Medical Department Officers in support of US Fleet, Fleet Marine Force and Coalition Naval Forces. SWMI provides consultation and Continuing

Medical Education for Surface, Submarine, Air and Fleet Marine Force Providers. SWMI sub-component, Navy Drug and Alcohol Counselor School is located in Point Loma, CA.

1.2.5. Naval Special Operations Medical Institute (NSOMI) located at Fort Bragg, NC conducts combat medical training for Special Operations Forces to include Recon Corpsmen, SEAL and Special Warfare Combat-Craft Crewman (SWMCC) Medics under U.S. Special Operations Command.

1.2.6. Hospital Corpsman Trauma Training (HMTT) provides first-term Hospital Corpsman with trauma experience prior to reporting to their first operational assignment. NMOTC supports the following HMTT locations: HMTT Jacksonville, FL (JAX), HMTT Great Lakes, IL (GLKS), HMTT Cleveland, OH (CLE), and HMTT Raleigh, NC (RAL).

1.2.7. Training Navy Trauma Center, Philadelphia, PA (UPENN) Strategic Health Alliance for Readiness and Performance (NSHARP) is embedded within the Level I trauma center to function independently, enhancing clinical competencies/skills sustainment to bolster readiness by providing real-world opportunities of exposure to high-acuity illnesses and injuries not commonly found in the military treatment facility setting.

1.2.8. Naval Trauma Training Center, Los Angeles, CA (NTTC) located in Los Angeles County at the University of Southern California (LAC+USC) Medical Center provides an ideal environment for student exposure to 25,000 trauma evaluations and 6,000 trauma admissions annually. LAC+USC is a 650-bed Level-1 Trauma Center just east of downtown Los Angeles.

The NMOTC Information Management and Technology Department service delivery environment across the NMOTC Enterprise is comprised of a series of interconnected IT systems whose purpose is the integration of information, applications, and processes within the Navy Medicine and Defense Health Agency (DHA) organizational boundaries. The NMOTC Information Management and Technology Department traditional and wireless network transport environments include Non-Classified Internet Protocol Router Network (NIPR), Secret Internet Protocol Router Network (SIPR), Defense Health Agency Medical Communication of Interest (MEDCOI), Defense Information Systems Agency (DISA), and Navy Marine Corps Intranet (NMCI) network services.

NMOTC Information Management and Technology Department maintains enterprise-wide systems that support the Operational Medicine and Aviation Survival community with science and technology, data analytics, business solutions, and IM&T acquisitions. Cloud computing [Infrastructure-As-A-Service (IAAS), Platform- As-A-Service (PAAS), and Software-As-A-Service (SAAS)] are quickly drawing interest for future training requirements at NMOTC. Cloud based services are providing cost effect capabilities to increase efficiencies in support of Operational Medicine and Aviation Survival to the Fleet. Policies, such as the Navy's "Cloud First," further directs the need to move to cloud services, whether or not the cloud deployment model is private, community, public, or hybrid. NMOTC Enterprise is seeking assistance in establishing this operating environment that provides better protection, transport, and reliability for business services and data.

1.3 Objectives. The objective of this contract is to provide local IT and Cybersecurity support services to NMOTC located in Pensacola, Florida, and all subordinate detachment locations.

1.4 Scope. The NMOTC Information Management and Technology Department IT Service Area activities are performed in close cooperation and coordination with, but not limited to: Application Integration and Business Intelligence Support, Desktop Support Services, IT Operations, Customer Portfolio Management and Cyber Support Services. Services are typically accomplished through integrated product or project teams, comprised of Government and Contractor personnel. The NMOTC Information Management and Technology Department and the associated IT Enterprise provides services to over 100,000 end-users world-wide to include 1,300 unique operational medicine program owners across Navy Medicine, individual projects, laboratories, and other Fleet and Fleet Marine Force medical organizations. This spans from embedded single person IT support through complete IT systems architecture development, engineering, infrastructure, deployment, sustainment, administration, data hosting, and system retirement.

1.5 Period of Performance. The period of performance shall be for twelve (12) Month Base and four (4), 12-month option years.

1.6 Hours of Operation.

1.6.1 Normal Duty Hours. The contractor will provide on-site coverage at specified sites Monday through Friday during the core business hours established by each location. The basic work week consists of 8-hours per day, 5 days per week, Monday through Friday. The Contractor must always maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.

1.6.2 Federal Government Holidays.

a. The following are recognized as Federal Holidays:

New Year’s Day 1st day of January Martin Luther King Jr.'s Birthday 3rd Monday of January Presidents Day 3rd Monday of February Memorial Day Last Monday of May Juneteenth 19th Day of June Independence Day 4th day of July Labor Day 1st Monday of September Columbus Day 2nd Monday of October Veterans Day 11th day of November Thanksgiving Day 4th Thursday of November Christmas Day 25th day of December

b. When one of the above designated legal holidays falls on a Sunday, the following Monday will be observed as a legal holiday. When a legal holiday falls on a Saturday, the proceeding Friday is observed as a legal holiday. This list of holidays relates to Government duty days and is not intended to supplement or otherwise alter the provisions of any Wage Determination regarding applicable paid holidays.

c. If Government personnel are furloughed, the Contractor shall contact the KO or the COR to receive direction. It is the Government’s decision as to whether the contract price/cost will be affected because of Government shutdown and/or furloughed Government employees. In the event of a government shutdown or furloughed Government employee(s) impacts contract price/cost, a negotiated settlement will be reached as deemed appropriate by the KO.

1.6.3 Emergency Services. On occasion, services may be required to support network outages or maintenance and contingency exercises outside the normal duty hours described above; weekend/holiday services are considered emergency services and are to be distinguished from routine services. Emergency services will be authorized by the KO. The Contractor’s responsibilities for emergency services are described by title in Part 5

1.6.4 Inclement Weather Operations. In cases of severe weather, the KO may authorize exceptions. When exceptions are granted, the Contractor shall make up all missed services within twenty-four (24) hours after the severe weather has terminated, unless the KO authorizes additional time. Rescheduling to provide make-up services shall not be a basis for a claim by the Contractor for additional compensation.

1.7 Place of Performance. The work to be performed under this contract will be performed at the following locations:

SERVICE LOCATION

Network Management Services Technical Support Services Operations Support Services Application Development Services Web Services and Database Administration

NMOTC Headquarters 220 Hovey Road Pensacola, FL 32508

Network Management Services Technical Support Services

SWMI

34101 Farenholt Ave.

San Diego, CA 92134

Technical Support Services

NUMI Naval Submarine Base 159 Trout Ave.

Groton, New London, CT 06349

Technical Support Services

NSOMI

1st SWTG, Bldg. 5-3845 3004 Ardennes Street, Stop A Fort Bragg, NC 28310-9610

Application Development and Web Services

NSTI

55 Blvd Pensacola, FL 32508

Application Development and Web Services

NAMI

340 Hulse Road Pensacola, FL 32058

Locations to be Supported via Travel for Routine Site Visits:

NDACS

ASTC Miramar 45486 Boyington Road San Diego, CA 92145

NTTC

2051 Marengo Street Los Angeles, CA 90033

HMTT Raleigh, NC HMTT Jacksonville, FL HMTT Cleveland, OH HMTT Great Lakes, IL

Aviation Survival Training Centers as listed in Section 1.2.1.

1.8. Type of Contract. The Government will award a Firm Fixed Price contract.

1.9. Quality Control. Quality Control is the responsibility of the Contractor. The Contractor is responsible for the delivery of quality services to the Government in accordance with (IAW) the terms and conditions contained in Federal Acquisition Regulation (FAR) Subpart 52.212-4 entitled, “Contract Terms and Conditions - Commercial Items” and applicable sub-clauses pertaining to quality control.

a. The Contractor shall develop, implement, and maintain an effective Quality Control System which includes a written Quality Control Plan (QCP). The QCP shall implement standardized procedure/methodology for monitoring and documenting contract performance to ensure all contract requirements are met. The Contractors’ QCP must contain a systematic approach to monitor operations to ensure acceptable services are provided to the Government. The QCP, as a minimum, shall address continuous process improvement;

procedures for scheduling, conducting and documentation of inspection; discrepancy identification and correction; corrective action procedures to include procedures for addressing Government discovered non-conformances; procedures for root cause analysis to identify the root cause and root cause corrective action to prevent re-occurrence of discrepancies; procedures for trend analysis; procedures for collecting and addressing customer feedback/complaints. The Contractor shall provide to the Government their quality control documentation within five (5) calendar days after contract award. Once electronic copy of a comprehensive written QCP shall be submitted to the KO and COR (electronic copies shall be in Adobe PDR or MS Office). Changes to the QCP after award shall be submitted to the KO and COR in an electronic copy within five (5) calendar days prior to the proposed changes thereafter. After acceptance of the quality control plan the Contractor shall receive the Contracting Officer’s acceptance in writing of any proposed change to their QC System regarding this contract.

b. Corrective Actions. If, at any time, it is determined by the KO that the quality control system, personnel, instructions, controls, tests, or records are not providing results which conform to contract requirements, action shall be taken by the Contractor to correct the deficiency. If a Contract Discrepancy Report (CDR) is issued the Contractor shall develop a Corrective Action Plan (CAP) which identifies the root cause, Corrective Action (CA) for the root cause, CA for the specific non-conformance and CA to the root cause to prevent recurrence and a corrective action including the timeline for completion.

1.10. Quality Assurance. The Government will evaluate the Contractor’s performance under this contract in accordance with (IAW) the Quality Assurance Surveillance Plan (QASP). This plan is a government only document primarily focused on what the Government must do to assure that the Contractor has performed IAW the requirements of the contract. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable deficiency rate(s) as illustrated within the PWS and Performance Requirements Summary (PRS). All performance ratings will use (Exceptional, Very Good, Satisfactory, Marginal, or Unsatisfactory), as defined in FAR subpart 42.15, Contractor Performance Information. The Government reserves the right to conduct compliance surveillance of any contractual requirement of this acquisition.

1.10.1 Contracting Officer’s Representative (COR). The Surveillance and Performance Monitoring (SPM) and Joint Appointment Module (JAM) are in Procurement Integrated Enterprise Environment (PIEE) https://wawf.eb.mil/ for nomination, tracking, documentation, and management of CORs will be used. The COR will be identified by separate letter. The COR monitors all technical aspects of the task order and assists in contract administration. The COR is authorized to perform the following functions: Assure that the Contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the Contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, and specifications; monitor Contractor's performance and notify both the KO and Contractor of any deficiencies; coordinate availability of Government equipment furnished; and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially regarding changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.11. Security Access

1.11.1. Access and General Protection/Security: Policy and Procedures. Contractor and all associated subcontractor-Contractors employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative). The Contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements as directed by DoD, Department of the Navy (DoN) and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in Contractor security matters or processes.

1.11.2. Defense Biometric Identification System (DBIDS). Defense Biometric Identification System (DBIDS) increases installation security and communications by receiving frequent database updates on changes to personnel/credential status, law enforcement warrants, lost/stolen cards, and force protection conditions.

The system provides a continuous vetting anytime the DBIDS card is scanned at an installation entry point.

a. If you currently have a Navy Commercial Access Control System (NCACS) card, the following is required to get a DBIDS credential:

Present your NCACS Card and a completed copy of the SECNAV FORM 5512/1 to the base

Visitor Control Center representative.

The VCC will pull up your information in the computer, ensuring all information is current and correct.

Once your information is validated, a temporary DBIDS credential is provided.

Your temporary credential will have an expiration date, prior to which you will need to obtain your permanent DBIDS credential (~ 180 days).

For each additional U.S. Navy installation to which you need access, the first time you visit you only need to bring your DBIDS credential and statement of purpose for base access when arriving at the Visitor Control Center.

The representative will enter base access authorization and then you may proceed to work.

b. If you do NOT have an NCACS Card, the following is required to obtain a DBIDS credential:

Present a letter or official document from my government sponsoring organization that provides the purpose for your access.

Present valid identification, such as a passport or Real ID Act-compliant state driver's license.

Present a completed copy of the SECNAV 5512/1 form to obtain your background check.

Upon completion of the background check, the Visitor Control Center representative will complete the DBIDS enrollment process, which includes your photo, fingerprints, base restrictions, and several other assessments; after all this is done, you will be provided with your new DBIDS credential.

You may now proceed to work.

For additional questions about obtaining a DBIDS card, contact your local base visitor control center.

Additional information is available at https://www.cnic.navy.mil/om/dbids.html.

1.11.3. Contractor Unclassified Access to Federally Controlled Facilities, Sensitive Information, Information Technology (IT) Systems or Protected Health Information. Homeland Security Presidential Directive (HSPD)-12 requires Government agencies to develop and implement Federal security standards for Federal employees and Contractors. The Deputy Secretary of Defense Directive-Type Memorandum (DTM) 08- 006 – “DoD Implementation of Homeland Security Presidential Directive – 12 (HSPD-12)” dated November 26, 2008 (or its subsequent DoD instruction) directs implementation of HSPD-12. This clause is in accordance with HSPD- 12 and its implementing directives.

APPLICABILITY

This clause applies to Contractor employees requiring physical access to any area of a federally controlled base, facility, or activity and/or requiring access to a Department of the Navy (DoN) or Department of Defense (DoD) computer/network/system to perform certain unclassified sensitive duties. This clause also applies to Contractor employees who access Privacy Act and Protected Health Information, provide support associated with fiduciary duties, or perform duties that have been identified as National Security Position, as advised by the command security manager. It is the responsibility of the responsible security officer of the command/facility where the work is performed to ensure compliance.

Each Contractor employee providing services at a Navy Command under this contract is required to obtain a Department of Defense Common Access Card (DoD CAC). Additionally, depending on the level of computer/network access, the contract employee will require a successful investigation as detailed below.

ACCESS TO FEDERAL FACILITIES

Per HSPD-12 and implementing guidance, all Contractor employees working at a federally controlled base, facility or activity under this clause will require a DoD CAC. When access to a base, facility or activity is required Contractor employees shall in-process with the Command’s Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual’s performance under the contract.

ACCESS TO DOD IT SYSTEMS

In accordance with SECNAV M-5510.30, Contractor employees who require access to DoN or DoD networks are categorized as IT-I, IT-II, or IT-III. The IT-II level, defined in detail in SECNAV M-5510.30, includes positions which require access to information protected under the Privacy Act, to include Protected Health Information (PHI). All Contractor employees under this contract who require access to Privacy Act protected information are therefore categorized no lower than IT-II. IT Levels are determined by the requiring activity’s Command Information Systems Security Manager.

Contractor employees requiring privileged, or IT-I level access, (when specified by the terms of the contract) require a T5 or T5R equivalent investigation, which is a higher-level investigation than the T3/T3R described below. Due to the privileged system access, an investigation suitable for High-Risk national security positions is required. Individuals who have access to system control, monitoring, or administration functions (e.g., system administrator, database administrator) require training and certification to Information Assurance Technical Level 1 and must be trained and certified on the Operating System or Computing Environment they are required to maintain.

Access to sensitive IT systems is contingent upon a favorably adjudicated background investigation. When access to IT systems is required for performance of the Contractor employee’s duties, such employees shall in-process with the Navy Command’s Activity Security Manager and Information Systems Security Manager upon arrival to the Navy command and shall out- process prior to their departure at the completion of the individual’s performance under the contract. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing Navy Information Technology resources. The decision to authorize access to a Government IT system/network is inherently governmental. The Contractor supervisor is not authorized to sign the SAAR-N; therefore, the Government employee with knowledge of the system/network access required or the COR shall sign the SAAR-N as the “supervisor”.

The SAAR-N shall be forwarded to the Command’s Activity Security Manager at least 30 days prior to the individual’s start date. Failure to provide the required documentation at least 30 days prior to the individual’s start date may result in delaying the individual’s start date.

When required to maintain access to required IT systems or networks, the Contractor shall ensure that all employees requiring access complete annual Cyber Awareness, Operational Security (OPSEC) and DoD Mandatory Controlled Unclassified Information (CUI) training and maintain a favorable background investigation. The Contractor’s Security Representative shall contact the Activity Security Manager for guidance when clearance actions are required.

INTERIM ACCESS

The Activity's Security Manager may authorize issuance of a DoD CAC and interim access to a DHA or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the Contractor employee working on the contract under interim access will be denied access to the computer network and this denial will not relieve the Contractor of his/her responsibility to perform.

DENIAL OR TERMINATION OF ACCESS

The potential consequences of any requirement under this clause including denial or termination of physical or system access in no way relieves the Contractor from the requirement to execute performance under the contract within the timeframes specified in the contract. Contractors shall prepare in advance for processing their employees and subcontractor employees. The Contractor shall insert this clause in all subcontracts when the subcontractor is permitted to have unclassified access to a federally controlled facility, federally controlled information system/network and/or to Government information, meaning information not authorized for public release.

CONTRACTOR’S SECURITY REPRESENTATIVE

The Contractor shall designate an employee to serve as the Contractor’s Security Representative. Within three workdays after contract award, the Contractor shall provide to the requiring activity’s Security Manager and the Contracting Officer, in writing, the name, title, address and phone number for the Contractor’s Security Representative. The Contractor’s Security Representative shall be the primary point of contact on any security matter. The Contractor’s Security Representative shall not be replaced or removed without prior notice to the Contracting Officer and Activity Security Manager.

BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR

CONTRACTORS ASSIGNED TO NATIONAL SECURITY POSITIONS OR PERFORMING

SENSITIVE DUTIES

Navy security policy requires that all positions be given a sensitivity value based on level of risk factors to ensure appropriate protective measures are applied. Contractor employees under this contract are recognized as Non-Critical Sensitive [ADP/IT-II] positions when the contract scope of work require physical access to a federally controlled base, facility, or activity and/or requiring access to a DoD computer/network, to perform unclassified sensitive duties. This designation is also applied to Contractor employees who access Privacy Act and Protected Health Information (PHI), provide support associated with fiduciary duties, or perform duties that have been identified as National Security Positions. At a minimum, each Contractor employee must be a US citizen and have a favorably completed T3 or T3R equivalent investigation to obtain a favorable determination for assignment to a non-critical sensitive or IT- II position. The investigation consists of a standard NAC and a FBI fingerprint check plus law enforcement checks and credit check. Each Contractor employee filling a non-critical sensitive or IT-II position is required to complete:

SF-86 Questionnaire for National Security Positions (or equivalent OPM investigative product) An electronic fingerprint submission Original Signed Release Statements

Failure to provide the required documentation at least 30 days prior to the individual’s start date shall result in delaying the individual’s start date. Background investigations shall be reinitiated as required to ensure investigations remain current (not older than 5 years) throughout the contract performance period.

Regardless of their duties or IT access requirements ALL Contractor employees shall in-process with the Command’s Activity Security Manager upon arrival to the command and shall out-process prior to their departure at the completion of the individual’s performance under the contract. Employees requiring IT access shall also check-in and check-out with the Navy Command’s Information Systems Security Manager. Completion and approval of a System Authorization Access Request Navy (SAAR-N) form is required for all individuals accessing DHA Information Technology resources. The SAAR-N shall be forwarded to the Navy Command’s Activity Security Manager at least 30 days prior to the individual’s start date. Failure to provide the required documentation at least 30 days prior to the individual’s start date shall result in delaying the individual’s start date.

The Contractor shall ensure that each contract employee requiring access to IT systems or networks maintain Continuous Evaluation enrollment with favorable clearance eligibility. Contractor employees shall accurately complete the required investigative forms prior to submission to the Activity Security Manager.

The Command’s Activity Security Manager will review the submitted documentation for completeness prior to submitting it to the Office of Personnel Management (DCSA); Potential suitability or security issues identified may render the Contractor employee ineligible for the assignment. An unfavorable determination is final (subject to SF-86 appeal procedures) and such a determination does not relieve the Contractor from meeting any contractual obligation under the contract. The Command’s Activity Security Manager will forward the required forms to DCSA for adjudication.

If the Contractor employee already maintains a favorably adjudicated clearance, the Contractor shall submit a Visit Authorization Request (VAR) via the Defense Information Systems for Security (DISS) or a hard copy VAR directly from the Contractor’s Security Representative. Although the Contractor will take DISS “Owning” role over the Contractor employee, the Navy Command will take DISS "Servicing" role over the Contractor employee during the hiring process and for the duration of assignment under that contract. The Contractor shall include the IT Position Category per SECNAV M-5510.30 for each employee designated on a VAR. The VAR requires annual renewal for the duration of the employee’s performance under the contract.

BACKGROUND INVESTIGATION REQUIREMENTS AND SECURITY APPROVAL PROCESS FOR

CONTRACTORS ASSIGNED TO OR PERFORMING NON-SENSITIVE DUTIES

Contractor employee whose work is unclassified and non-sensitive (e.g., performing certain duties such as lawn maintenance, vendor services, etc) and who require physical access to publicly accessible areas to perform those duties shall meet the following minimum requirements:

Must be either a US citizen or a US permanent resident with a minimum of 3 years legal residency in the United States (as required by The Deputy Secretary of Defense DTM 08- 006 or its subsequent DoD instruction) and Must have a favorably completed T1 investigation equivalent including a FBI fingerprint check prior to installation access.

To be considered for a favorable trustworthiness determination, the Contractor’s Security Representative must submit for all employees each of the following:

SF-86 Questionnaire for Non-Sensitive Positions An electronic fingerprint submission Original Signed Release Statements

The Contractor shall ensure each individual employee has a current favorably completed T1 equivalent investigation or ensure successful FBI fingerprint results have been gained and investigation has been processed with OPM.

Failure to provide the required documentation at least 30 days prior to the individual’s start date may result in delaying the individual’s start date.

* Consult with your Activity Security Manager and Information Systems Security Manager for local policy when IT-III (non-sensitive) access is required for non-US citizens outside the United States.

1.11.4. Security Requirements. Contractor personnel performing work under this contract must have a SECRET/TOP SECRET at time of the proposal submission and must maintain the level of security required for the life of the contract IAW SECNAV 5510.30.

POSITIONS SECURITY CLEARANCE

Network Management Support

SF86/TS

Technical Services Support

SF86/SECRET

Operations Support Services

SF86/SECRET

Application Development Support

SF86/SECRET

Web Services Support SF86/SECRET

1.11.5. Physical Security. The Contractor shall be responsible for safeguarding all Government equipment, information and property provided for Contractor use IAW OPNAVINST 5530.14E CH-2, Navy Physical Security and Law Enforcement Program. Contractor shall maintain a physical security checklist/log which will be forwarded to the COR on a quarterly basis. At the close of each work period, Government facilities, equipment and materials shall be secured.

1.11.6. Key Control. The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop and implement a key control program and procedures compliant with OPNAVINST 5530.14E CH-2 to ensure that keys are controlled and safeguarded. The plan shall be incorporated within the Contractor’s Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the KO, COR, and Activity Security Manager.

a. In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the KO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor. Any Government property stolen or damaged in association with keys being duplicated, misplaced, or lost by the Contractor personnel shall be reimburse the Government accordingly.

b. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the KO.

1.11.7. Lock Combinations. The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s Quality Control Plan.

1.11.8. Security of Classified Items, Systems, and Information. The Contractor shall not access, view, possess, or use classified information under this contract. The Contractor shall immediately contact the COR for instructions if access to classified information becomes necessary or if the Contractor falls into the possession of classified information while performing services under this contract.

1.11.9. Personally Identifiable Information (PII). Work under this contract requires access to personally identifiable information (PII) and information protected by the Privacy Act of 1974. At a minimum, the Contractor shall meet eligibility requirements for a position of trust. The Contractor shall comply with all applicable DoD security regulations and procedures during the performance of this contract. Contractor personnel shall not disclose and must safeguard procurement sensitive information, computer systems and data, privacy act data, sensitive but unclassified (SBU) information, and all Government personnel work products that are obtained or generated in the performance of this contract.

1.11.10. Facility Access Determination (FAD). The Department of the Navy (DoN) has determined that all DoN Information Systems are sensitive regardless of whether the information is classified or unclassified. All personnel accessing DoN Computer systems shall undergo investigation for a position of trust to verify their trustworthiness. The Government will include Facility Access Determination (FAD) program requirements in the contract specifications when determinations for facility access only will be required on the Contractor employees.

1.12. Clearance. At a minimum, all work is expected to be unclassified sensitive data including Personally Identifiable Information (PII). However, in accordance with SECNAV M-5510.30, all contractor employees must have the security clearance specified at 1.11.4 of the PWS. The Contractor shall meet all requirements of the Privacy Act; DoD 5239 & 8570 instructions.

1.13. Safety. The Contractor shall establish and maintain a safety plan of which a draft plan shall be submitted to the KO at the time of proposal. Contractor’s final Safety Plan shall be submitted no later than (NLT) 5 calendar days after contract award.

1.13.1. To provide safety control for protection to the life and health of employees and other persons; for prevention of damage to property, materials, supplies, and equipment; and for avoidance of work interruptions in the performance of this contract, the Contractor shall comply with 29 CFR 1910, Occupational Safety and Health Standards. The Contractor shall comply with the above and all other applicable DoD, Navy, Federal, State and Local safety, and health requirements.

1.13.2. Environment and OSHA. The Contractor shall comply with all local, State, and Federal environmental and occupational safety laws, rules, and regulations hereby incorporated by reference. Any apparent conflict between compliance with such local, State, and Federal environmental and occupational safety laws, rules, regulations, and compliance with the requirements of the contract shall be immediately brought to the attention of the KO or authorized representative for final resolution. The Contractor shall notify the KO or authorized representative in writing in addition to any verbal notification of such conflict. The Contractor shall be liable for all fines, penalties, and costs which result from violations of, or failure to comply with, all such local State, or Federal laws, rules, and regulations. All unsafe acts or conditions fostered by the Contractor or Contractor personnel may be grounds for the KO or authorized representative to halt all Contractor performance with a commensurate deduction of monies due to the Contractor until such unsafe conditions are corrected. The Contractor shall take due caution not to endanger personnel during performance of this contract. Upon discovery of a serious hazard such as, but not limited to, fire, or large fuel spill, the Contractor shall notify the KO or designated representative and COR.

1.13.3. Reporting Mishaps. The Contractor shall train personnel to recognize fire and safety hazards and encourage personnel in the performance of their duties to report fire and safety hazards and unsafe conditions to their supervisor. The Contactor shall take corrective action to remedy reported deficiencies IAW the terms of this contract. The COR shall be notified of deficiencies beyond the terms of this contract. The Contractor shall adhere to reporting of mishaps IAW OPNAVINST 5102.1D MCO P5102.1B, Navy & Marine Corps Mishap and Safety Investigation, Reporting, And Record Keeping Manual. In addition, the Contractor shall report injury or occupational illness to on-duty Contractors and Contractor accidents involving Navy property and personnel.

1.13.4. Emergency Services.

a. The Contractor shall have competent personnel trained and capable of dealing with minor personnel injuries. The Contractor’s employees shall immediately notify their supervisor of any accident requiring emergency medical treatment. The Contractor shall, in turn, notify the KO or COR within 30 minutes of the incident.

b. Emergency medical treatment and services for Contractor personnel is the responsibility of the

Contractor.

1.13.5. Personnel Safety. The Contractor shall immediately correct all safety deficiencies upon notification of the deficiencies by the KO, designated representative, or COR, and shall notify the KO of the corrective action to be taken.

1.14. Personnel. For purposes of this paragraph, the term “personnel” or “employee(s)” refers to any person performing work related to this contract, including but not limited to, the Contractor’s employees, agents, representatives, or subcontractor. The Contractor shall staff this effort with trained, competent, and capable employee(s) for the discipline they are assigned to. Contractor personnel shall present a clean, neat and professional appearance. The Contractor shall ensure that employees meet all applicable federal, state, local, and installation certification, licensing, medical requirements, and qualifications to perform all assigned tasks and functions as defined in this contract prior to commencement of work. The Contractor shall not permit any personnel to work under this contract if such person is identified by a Government authorized representative to the Contractor as a potential threat to the health, safety, security, general well-being, or operational mission of the Navy and performance locations listed in section 1.7. All Contractors’ personnel shall comply with installation security and access procedures and the Contractor’s final Safety Plan.

1.14.1. Motor Vehicle Operators. Contractor’s personnel, whose tasks involve operation of any vehicles, shall possess a valid U.S. state driver’s license, certificates and permits, applicable for the type and class of vehicle being operated.

1.14.2. Conflict of Interest.

a. Organizational Conflict of Interest. Contractor and subcontractor personnel performing work under this contract may receive, have access to, or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications, or work statements, etc.), or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5, Organizational and Consultant Conflicts of Interest. The Contractor shall notify the KO immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the KO to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the KO, and in the event the KO unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the KO may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.

b. Employment of Government Personnel. The Contractor shall not knowingly employ any person who is a U.S. Government employee if employing that person would create a conflict of interest. Additionally, the Contractor shall not knowingly employ any person who is an employee of the Government, either military or civilian, unless such person seeks and receives written approval according to DoD 5500.7- R, Joint Ethics Regulations (JER) by the individual’s commander or director. A copy of the authorization will be provided to the COR. In addition, the Contractor is prohibited from employing Government Quality Assurance Representatives (QAR) whom the Contractor knows or should have known are responsible for monitoring any contracts/subcontracts awarded to the service provider.

1.14.3. Contractor Code of Business Ethics and Conduct. IAW FAR Subpart 3.1004(a) FAR Clause 52.203-13, Contractor Code of Business Ethics and Conduct, the Contractor shall comply with established regulations to include application of FAR Clause to applicable subcontracts.

1.14.4. Conduct of Employees. Contractor personnel’s conduct shall not reflect discredit upon the Government.

The Contractor shall ensure that personnel present a professional appearance. The Contractor’s employees shall observe and comply with all local policies and procedures concerning fire, safety, environmental protection, sanitation, security, and possession of firearms or other lethal or illegal weapons or substance.

The Contractor is responsible for ensuring that any Contractor employees providing services under this contract conduct themselves and perform services in a professional, safe, and responsible manner. The Contractor shall remove from the job site any employee for reasons of misconduct or security. In accordance with Department of Defense (DOD) Directive 5500.7-R, “Joint Ethics Regulation”, Contractor employees must avoid being improperly influenced in the execution of their duties under the contract.

Particular attention should be paid to acceptance of gifts/ gratuities, and on non- disclosure of sensitive or classified information. The Contractor shall ensure employee conduct complies with 41 U.S. C 423 relative to release of acquisition related information or actions or discussions which may prejudice future competitions. The Contractor shall ensure no contractor employees conduct political related activities or events on United States of America (USA) Facilities.

1.14.5. Special Qualifications.

a. Education: The Contractor employees shall, at a minimum, possess all education requirements listed under each specific position description.

b. Experience: The Contractor employees shall have a minimum experience as listed under each specific position description.

c. Proof of education and experience for key personnel shall be provided with the Contractor’s proposal.

Proof of education and experience for all other personnel (not hired under right of first refusal provision at FAR 52-222-17) shall be provided no later than 10 days prior to award start date.

1.14.6. Key Personnel: The following personnel are considered key personnel by the Government: Staffing Plan Matrix

a. Technical Services Site Manager:

1. The Contractor shall provide a Site Manager who shall be responsible for the performance of the work.

The name of this person and an alternate, who shall act for the Contractor when the manager is absent, shall be designated in writing to the KO within 10 calendar days after contract award; thereafter any changes shall be provided five (5) business days prior to expected change and no less than 24- hours after unplanned changes. The Site Manager or alternate shall have full authority to act for the Contractor on all contract matters relating to daily operation of this contract.

2. The Site Manager or alternate shall be available by text/email/phone to provide remote system access during outage or as needed Monday through Friday including Federal holidays or when the Government facility is closed for administrative reasons.

3. Contractor employees performing as Site Manager under this contract shall have a minimum of 10 years DoD/DON industry experience or 15 years general IT experience and a minimum of 5 years supervisory leadership experience providing IT support on platforms under the DoD governance, policy, and regulations industry or 7 years general supervisory experience.

b. Network Security Administrator/alternate

1. The Contractor shall provide a Network Security Administrator who shall be responsible for network boundary and accreditation oversight. The name of this person and an alternate who shall act for the Contractor when the Network Security Administrator is absent shall be designated in writing to the KO within 10…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .