N3943019R2126-0001.pdf
PDF 469 KB Posted
- Attached to
- Synopsis of Enterprise Computer and Information Technology Support Services (ECITS) Federal contract opportunity
- Solicitation number
- N3943019R2126
About this file
This performance work statement describes enterprise computer and information technology support services required by the Naval Facilities Engineering Command. The contractor shall provide services including systems development lifecycle support, cybersecurity support, business systems operations and support, IT operations management, cloud operations and system development, and enterprise analysis and management services. The contractor must have the capability to perform tasks in areas such as requirements analysis, systems analysis, systems configuration, database administration, documentation development, and project management. The contractor shall also provide cybersecurity support services including risk management framework compliance, information assurance continuity planning, and technical writing. Additional requirements include business systems operations and support, IT operations management, and enterprise analysis and management services. The contractor must have the necessary security clearances and certifications and follow all security and privacy protocols defined in the document.
N3943019R2126-0001.pdf
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| N3943019R2126-0009.pdf | ||
| N3943019R2126-0008.pdf | ||
| N3943019R2126_0001-0008_(Conformed_Copy).pdf | ||
| N3943019R2126_0001-0007_(Conformed_Copy).pdf | ||
| N3943019R2126-0007.pdf | ||
| N3943019R2126_0001-0006_(Conformed_Copy).pdf | ||
| N3943019R2126-0006.pdf | ||
| Attachment_J-1_Schedule_of_IDIQ_Price.xlsx | XLSX spreadsheet | |
| N3943019R2126-0005.pdf | ||
| Attachment_J-7_Safety_Data_Sheet_-_Safety_Narrative.docx | DOCX document | |
| N3943019R2126-0004.pdf | ||
| Attachment_J-1_Schedule_of_IDIQ_Price.xlsx | XLSX spreadsheet | |
| CDRLS.zip | ZIP file | |
| N3943019R2126-0003.pdf | ||
| N3943019R2126-0002.pdf | ||
| ECITS_ATTACHMENTS.zip | ZIP file | |
| N3943019R2126.pdf | ||
| N3943019R2126_ECITS_Pre-Solicitation_Notice.pdf |
Show all 18
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
AMENDMENT OF SOLICITATION/MODIFICATION OF CONTRACT
Except as provided herein, all terms and conditions of the document referenced in Item 9A or 10A, as heretofore changed, remains unchanged and in full force and effect.
15A. NAME AND TITLE OF SIGNER (Type or print)
30-105-04EXCEPTION TO SF 30
APPROVED BY OIRM 11-84
STANDARD FORM 30 (Rev. 10-83) Prescribed by GSA
FAR (48 CFR) 53.243
The Purpose of this amendment is to:
1) Provide response to offeror questions
2) Filled in dates for Block 9 of the SF33
3) Remove language in Section C from Section 2.7 Travel / Temporary Duty (TDY) of the PWS
4) Corrected NAICS codes in Sect I clauses
5) Added 8(a) language to Section L.1
See page tw o Summary of Changes for more details.
1. CONTRACT ID CODE PAGE OF PAGES
J 1 40
16A. NAME AND TITLE OF CONTRACTING OFFICER (Type or print)
16C. DATE SIGNED
BY 23-May-2019
16B. UNITED STATES OF AMERICA15C. DATE SIGNED15B. CONTRACTOR/OFFEROR
(Signature of Contracting Officer)(Signature of person authorized to sign)
8. NAME AND ADDRESS OF CONTRACTOR (No., Street, County, State and Zip Code) X N3943019R2126
X 9B. DATED (SEE ITEM 11)
22-May-2019
10B. DATED (SEE ITEM 13)
9A. AMENDMENT OF SOLICITATION NO.
11. THIS ITEM ONLY APPLIES TO AMENDMENTS OF SOLICITATIONS
X The above numbered solicitation is amended as set forth in Item 14. The hour and date specified for receipt of Offer is extended, X is not extended.
Offer must acknowledge receipt of this amendment prior to the hour and date specified in the solicitation or as amended by one of the following methods:
(a) By completing Items 8 and 15, and returning copies of the amendment; (b) By acknowledging receipt of this amendment on each copy of the offer submitted;
or (c) By separate letter or telegram which includes a reference to the solicitation and amendment numbers. FAILURE OF YOUR ACKNOWLEDGMENT TO BE RECEIVED AT THE PLACE DESIGNATED FOR THE RECEIPT OF OFFERS PRIOR TO THE HOUR AND DATE SPECIFIED MAY RESULT IN
REJECTION OF YOUR OFFER. If by virtue of this amendment you desire to change an offer already submitted, such change may be made by telegram or letter, provided each telegram or letter makes reference to the solicitation and this amendment, and is received prior to the opening hour and date specified.
12. ACCOUNTING AND APPROPRIATION DATA (If required)
13. THIS ITEM APPLIES ONLY TO MODIFICATIONS OF CONTRACTS/ORDERS.
IT MODIFIES THE CONTRACT/ORDER NO. AS DESCRIBED IN ITEM 14.
A. THIS CHANGE ORDER IS ISSUED PURSUANT TO: (Specify authority) THE CHANGES SET FORTH IN ITEM 14 ARE MADE IN THE
CONTRACT ORDER NO. IN ITEM 10A.
B. THE ABOVE NUMBERED CONTRACT/ORDER IS MODIFIED TO REFLECT THE ADMINISTRATIVE CHANGES (such as changes in paying office, appropriation date, etc.) SET FORTH IN ITEM 14, PURSUANT TO THE AUTHORITY OF FAR 43.103(B).
C. THIS SUPPLEMENTAL AGREEMENT IS ENTERED INTO PURSUANT TO AUTHORITY OF:
D. OTHER (Specify type of modification and authority)
E. IMPORTANT: Contractor is not, is required to sign this document and return copies to the issuing office.
14. DESCRIPTION OF AMENDMENT/MODIFICATION (Organized by UCF section headings, including solicitation/contract subject matter where feasible.)
10A. MOD. OF CONTRACT/ORDER NO.
2. AMENDMENT/MODIFICATION NO. 5. PROJECT NO.(If applicable)
6. ISSUED BY
3. EFFECTIVE DATE
22-May-2019
CODE
NAVFAC EXWC
CODE ACQ / NAVAL BASE VENTURA COUNTY
1100 23RD AVE BLDG 1100
PORT HUENEME CA 93043-4301
N39430 7. ADMINISTERED BY (If other than item 6)
4. REQUISITION/PURCHASE REQ. NO.
CODE
See Item 6
FACILITY CODECODE
EMAIL:TEL:
N3943019R2126
SECTION SF 30 BLOCK 14 CONTINUATION PAGE
SUMMARY OF CHANGES
SECTION SF 30 - BLOCK 14 CONTINUATION PAGE
The following have been added by full text:
AMENDMENT 1
a) Provide Government answers to the following contractor’s questions:
Q1: Form 33 does not specify if it a set-aside contract. If yes, please let us know the set-aside classification, if any.
A1: SF 33 Now reflects change that this contract is set aside for 8(a) firms only. Please see revised section L.1 Stating “This solicitation is for a Multiple Award, Indefinite Delivery Indefinite Quantity (IDIQ) Contract set aside for 8(a) participants.”
Q2: The due date box is blank. Please let us know the due date to submit proposal.
A2: Please note the NECO announcement indicates a solicitation close date of 8 July 2019 by 1500 PST. This has been included in section L.6 “Submission of Offers” to say “The proposals shall be submitted to the cited address below no later than 8 July 2019 by 1700 PST.”
Q3: Please clarify the applicable NAICS code. The FBO posting indicates 541512 while the solicitation document indicates 541519.
A3: The NAICS code has been updated to reflect the correct NAICS code selected “541512”. Changes to the solicitation are in clauses 52.204-8 and 52.219-1.
Q4: Please clarify if there is any difference between the five major subsections identified in the pre-solicitation and what has been advertised in the formal RFP.
A4: No changes have been made to the five major subsections from the pre-solicitation to formal RFP. These five major sub-sections are located in Section C 3.2 Performance Requirements.
b) Portions of this Solicitations were altered as follows:
1. Block 9 of the SF33 was completed.
2. In Section C, paragraphs 1, 2, 3, Air Travel, and Non-Reimbursable Travel were removed from 2.7 Travel / Temporary (TDY).
3. Changed and corrected NAICS Code in Section I, clauses 52.204-8 and 52.219-1 from 541219 to 541219.
4. Section L.1 now states, “This solicitation is for a Multiple Award, Indefinite Delivery Indefinite Quantity (IDIQ) Contract set aside for small business 8(a) participants.”
SECTION A - SOLICITATION/CONTRACT FORM
The required response date/time 08-Jul-2019 05:00 PM has been added.
The number of offeror copies required 1 has been added.
SECTION C - DESCRIPTIONS AND SPECIFICATIONS
The following have been modified:
STATEMENT OF WORK
PERFORMANCE WORK STATEMENT
ENTERPRISE COMPUTER AND INFORMATION TECHNOLOGY SERVICES (ECITS)
1. INTRODUCTION
The Naval Facilities Engineering Command (NAVFAC) Command Information Officer (CIO) is procuring information technology services including Systems Development Lifecycle support, Cyber Security support, Business Systems Operations and Support, IT Operations Management, and Enterprise Analysis and Management Services in support of all NAVFAC personnel, stakeholders and users throughout the world. The NAVFAC Information Technology Center (NITC) serves as NAVFAC primary Information Technology service provider offering a wide variety of technical solutions and support to the NAVFAC organization.
1.1. Mission
NITC is NAVFAC center of excellence for delivery of Enterprise Business Systems and applications.
NITC is focused on IT service delivery and support of Enterprise business applications that enable Navy business processes. NITC is responsible for the complete system life cycle (design, development, implementation, operations/maintenance, enhancement), Enterprise Operations support, system cyber security, Information Technology (IT), Cloud Systems Operations and Development, as well as supporting NAVFAC business systems, applications, hardware and software. NITC is the Central Design Agency (CDA) for NAVFAC business systems and provides/manages the hosting infrastructure for non-mainframe business systems. NITC is the CDA for mainframe systems that are unique to NAVFAC (e.g. FIS).
1.2. Background
NAVFAC Command Information Officer (CIO) is responsible for the oversight and management of Information Technology tools and capabilities to NAVFAC personnel, stakeholders and users throughout the world. NITC reports to the CIO office. The NITC organization provides the expertise, management discipline, and specialized technical skills necessary to ensure that best value Information Technology is acquired and managed in a manner consistent with law, and DoD and DoN policies and procedures. NITC delivers a range of services including: CDA responsible for software configuration and sustainment of Navy facilities systems;
production system support for all NAVFAC enterprise systems; command-wide management of Navy Marine Corps Internet (NMCI) / Next Generation (NGEN) and Navy Enterprise Network (ONE-NET) services; IT/IM acquisition and portfolio management; telecommunications support, NAVFAC Cloud Brokerage; and Cyber Security and Cyber Security compliance for systems, devices and networks.
1.3. Scope
NOTE: Complete list of acronyms applicable to this Performance Work Statement (PWS) are explained in Appendix B.
The scope of this effort is to acquire IT services and solutions through the performance of broad ranges of services across multiple functional areas, including but are not limited to:
- Systems Development Lifecycle Support
- Cyber Security Support
- Business Systems Operations and Support
- IT Operations Management and Enterprise
- Cloud Operations/Migration/System Development
- Secure DevOps Infrastructure
- Analysis and Management Services.
The contractor may be required to possess one or more of the following credentials at the individual task order level:
ISO 9001:2000
ISO 9001:2008
CMMI Level III (or higher) – DEV CMMI Level III (or higher) – SVC Oracle Certified Gold Partner Microsoft Certified Partner
ISO/IEC 20000
Information Technology Infrastructure Library (current version)
PARTNER PROGRAM
2. GENERAL REQUIREMENTS
2.1 Non-Personal Services
The Government shall neither supervise contractor employees nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor's responsibility to notify the Procuring Contracting Officer (PCO) immediately.
2.2 Business Relations
The contractor shall successfully integrate and coordinate all activity needed to execute the requirement.
The contractor shall manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.
2.3 Contract Administration and Management
The following subsections specify requirements for contract, management, and personnel administration.
2.3.1 Contract Management
The contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to the requirement. The contractor must maintain continuity between the support operations at various locations and the contractor's corporate offices. Localities requiring support may include, but not limited to:
1. Port Hueneme, CA
2. San Diego, CA
3. Washington DC
4. Pearl Harbor, HI
5. Norfolk, VA
6. Yokosuka, Japan
7. Kansas City, MO
8. Bremerton, WA
Specific place of performance will be addressed at the task order level.
2.3.2 Contract Administration
The contractor shall establish processes and assign appropriate resources to effectively administer the requirement. The contractor shall respond to Government requests for contractual actions in a timely fashion. The contractor shall have a single point of contact between the Government and Contractor personnel assigned to support contracts or task orders. The contractor shall assign work effort and maintaining proper and accurate time keeping records of personnel assigned to work on the requirement.
2.3.2.1 Contractor Personnel Security Status Report. The purpose of this report is to maintain current and accurate records of the hiring and related clearance status of all contractor and subcontractor personnel. Information contained is considered Personally Identifiable Information (PII) and must be protected and transmitted as such. Verification of U.S. citizenship and background investigation results for all personnel will be conducted by the government Security Management Office.
The report shall contain, at minimum:
a. Full name, with middle name, as applicable, with social security number;
b. Citizenship status with date and place of birth;
c. Proof of the individual’s favorably adjudicated background investigation at the applicable level
(as required by each functional area of the PWS), consisting of identification of the type of investigation performed, date of the favorable adjudication, name of the agency that made the favorable adjudication, and name of the agency that performed the investigation. If personnel shall be performing across multiple functional areas with different required IT levels, the personnel shall demonstrate performance at the highest required IT level;
d. Company name, address, phone and fax numbers with email address;
e. Location of on-site workstation or phone number if off-site;
f. Delivery order or contract number and expiration date; and name of the Contracting Officer;
g. Contract labor category
h. Date request letter sent to Contracting Officer’s Representative (COR)
i. Date of Common Access Card (CAC) issuance and expiration;
j. Comments (if applicable)
The Contractor Personnel Security Status Report shall be delivered within 10 business days of award. The Contractor is required to provide and keep current the information for each individual.
Should any contractor or subcontractor personnel information or status change, or if contractor/subcontractor employees are added or removed from employment on this contract, the Contractor shall provide an updated information list within 3 business days of the change. See CDRL 0001- Contractor Personnel Security Status Report.
2.3.2.2 Monthly Contract Status Report. Each Prime contractor shall create and maintain a contract summary monthly status report which reports on high level metrics, performance, cost (including Earned Value Management metrics when applicable)/price and schedule elements for all active awards within the reporting time period. Strategic planning, staffing/training and certification status, risk management, problem and issue identification/resolution and action plans shall be included. See CDRL 0002- Monthly Contract Status Report.
2.3.2.3 Monthly Contract Status Report Meeting. Each Prime contractor shall participate in a contract summary monthly status meeting with government personnel such as the contracting officer and CORs. The prime shall ensure participation from their designated staff. The contract summary monthly status report shall be reviewed and discussed.
2.3.2.4 Contract Corrective Action Plan. A corrective action plan is a step by step plan of action that is developed to achieve targeted outcomes for resolution of identified problems or issues. The government may request that the contractor submit a corrective action plan for contract administration and management issues (including safety, training, security, clearance and cybersecurity workforce issues) if determined necessary. To be submitted ad hoc in accordance with CDRL- 0003 Contract Corrective Action Plan upon request.
2.3.3 Personnel Administration
The contractor shall provide management and support as required. The contractor shall provide for their employees during designated Government non-work days or other periods where Government offices are closed due to weather or security conditions. The contractor shall maintain the good standing of their employees by providing initial and refresher training as required to meet the performance work statement (PWS) and basic contract requirements. The contractor shall make necessary travel arrangements for employees. The contractor shall provide necessary infrastructure to support contract tasks for on-site and off-site support on a task order basis. The contractor shall provide administrative support to employees in a timely fashion (time keeping, leave processing, pay, emergency needs).
2.3.3.1 Contractor Training Requirements. All active contractor personnel working under this contract, including all subcontractor personnel, shall successfully complete the current applicable version of the DoD Cyber Awareness Challenge on an annual basis. The current version is Cyber Awareness Challenge 2019;
it is available in TWMS for resources with TWMS access or via DISA website (URL will be provided or KIOSK located in EXWC Buildings made available). All active contractor personnel, including subcontractors, are required to successfully complete an online OPSEC training course on an annual basis.
All contractor personnel, including subcontractor personnel, requiring a NMCI email account or system access shall successfully pass the required annual training to maintain the account and/or access. See section 4.1.3 for access requirements.
Additionally, all contractor personnel (including subcontractor personnel) located at a Government facility (such as Naval Base Ventura County) shall successfully complete and keep current any safety and security training required by that on-site location. Training may include, but is not limited to:
1. Active Shooter training
2. Naval Criminal Investigation Service (NCIS)
3. Records Management
4. Privacy and PII Awareness Training
The contractor shall maintain and keep up-to-date their employee Cyber certification and base safety/security and access training, and shall pay for all labor, training, training travel, study time, exam and certification/re-certification. The government may request proof of completion at any time.
2.4 Subcontract Management
The contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement. The prime contractor will manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations.
2.5 Contractor Personnel, Disciplines, and Specialties
The contractor shall accomplish the assigned work by employing and utilizing qualified personnel. The contractor shall match personnel skills to the work or task with a minimum of under/over employment of resources. All resources assigned shall meet all personnel requirements, including clearance standing and cybersecurity workforce standing, at time of task order award.
Contractor and subcontractor personnel may be required to hold professional certifications, as noted within individual task orders. See Appendix C – Professional Certifications for further information regarding professional certifications. See PWS section 4.1.7 for Cyber Security Workforce requirements.
The Contractor shall provide the necessary resources and infrastructure to manage, perform, and administer the contract.
2.5.1 Contractor Identification
All Contractor employees shall ensure that when participating in meetings with Government and/or other Contractor employees, that their personnel properly identify themselves as Contractor employees so that their actions will not be construed as acts of Government officials.
As per DFARS 211.106, “Contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification for meetings with Government personnel. All contractor employees shall appropriately identify themselves as contractor employees in telephone conversations and in formal and informal written correspondence.”
Contractor shall ensure that external correspondence signed by Contractor employees is on company letterhead. Internal correspondence, including e-mail and memoranda, must include the name of the company in the signature line or in another clearly identifiable location. In all contact with the public and Government officials, contractor personnel shall identify themselves as contractor employees working under contract to NAVFAC.
Contractor shall ensure that their onsite personnel, when receiving or placing telephone calls, identify their employer, in addition to whatever other appropriate greeting are used.
All Contractor staff working on-site at any of the client installations during task order performance shall wear at all times a DoD or Contractor furnished Identification. Additionally, contractor workspaces will be clearly marked “contractor” and their company name and their name.
The Contractor must comply with the implementation of Federal Information Processing Standards (FIPS) Publication Number 201, Personal Identify Verification of Federal Employees, and Contractors.
2.6 Location and Hours of Work
Accomplishment of the results contained in this PWS requires work at contractor facilities, on-site at government facilities, locations during travel in support of designated activities. Remote work may be authorized as described within individual task orders.
The exact locations of individual efforts will be designated on each individual task order as described in section 2.3.1.
Hours of work shall vary based on the task being performed, but will generally conform to the NAVFAC standard business hours of 0600-1800. Certain tasks may require work and travel after normal business hours, including evenings, weekends, and holidays. NITC is a 24/7/365 facility. Some task orders will require support 24/7/365 and/or on-call support after standard business hours.
Actual hours of work will be included within individual task orders.
Normal workdays are Monday through Friday except US Federal Holidays. Workers typically work eight
(8) hours per day, 40 hours per week. Flextime workers start not earlier than 0600 and not later than 0900.
All employees are expected to be available during core hours (0900 to 1500).
2.7 Travel / Temporary Duty (TDY)
Travel locations include both CONUS and OCONUS and will be specified at the task order level.
Anticipated locations include but are not limited to:
1. Port Hueneme, CA
2. San Diego, CA
3. Washington DC
4. Pearl Harbor, HI
5. Norfolk, VA
6. Yokosuka, Japan
7. Kansas City, MO
8. Bremerton, WA
9. Charleston, SC
10. Naples, Italy
11. Rota, Spain
12. Marianas, Guam
3. PERFORMANCE REQUIREMENTS
3.1 Basic Requirements
Contractor support is required to assist NITC in achieving their goals and objectives. Primary areas of consideration are Systems Development Lifecycle, Cyber Security, Production Systems, IT Operations Support, Operations Support, and Enterprise Analysis and Project Management. This PWS specifies the tasks to be performed, deliverables to be provided and performance objectives to be met in support of NAVFAC business systems.
The Contractor shall furnish all work, management, supervision, labor and materials necessary to ensure the effective and efficient performance of functions identified throughout this PWS which make up this requirement.
The Contractor must be capable of providing flexible, responsive, and high quality services and support. The Contractor will conduct travel and reviews that are necessary to ensure the effective and efficient performance of functions identified throughout this PWS which make up this requirement.
NOTE: Any proposed use of open source technology must be pre-approved by the Government at its discretion.
Approval is not guaranteed. Any code developed under this contract is the property of the government and any portion of the code must be submitted to the government upon request.
It should be understood that delivery of requirements includes meeting setup, attendance, phone calls or any other support activity. Further requirements relating to these support activities will be noted in individual task orders.
NITC requires the usage of work induction, tracking and monitoring tools such as HP Service Manager (HPSM), HP Quality Center (HPQC) and Service Ticketing System (STS) for assigned deliverables/tasking. Specific usage requirements will be noted in individual task orders.
NITC requires all custom software developed by the government or its contractors furnished or maintained to be committed to the NITC managed/maintained Source Control Management (SCM) System prior to deployment into any NITC functional environment (on premise or cloud based).
NITC reserves the right to require all require all custom software developed by the government or its contractors to be built/compiled/deployed from NITC SCM System, through NITC managed/maintained delivery and integration toolchains, and not received via offsite or localized deployment or build processes. Custom software developed by the government or its contractors may be required to pass functional and operational analysis tasks prior to allowing deployment possibly including, but not limited to: unit/integration testing, static code analysis, UI/GUI testing, dynamic system analysis, included library security and licensing validation.
NITC reserves the right to require all require all custom software developed by the government or its contractors and Commercial-Off-the Shelf (COTS) systems be deployed from NITC managed/maintained artifact repositories.
NITC reserves the right to require all require all custom software developed by the government or its contractors to be developed in NITC specified architectures, languages, and/or frameworks. Specific requirements will be noted in individual task orders.
3.2 Performance Requirements
The Contractor shall perform the following tasks in accomplishing the requirements of this contract. The Contractor shall provide the necessary timely support to meet emergent requirements as requested by the program manager, technical point of contact, or other properly designated authority.
3.2.1 Systems Development Life Cycle (SDLC)
Designated IT-2. See background investigation and clearance requirements for all personnel.
NAVFAC develops and maintains software solutions to Navy business requirements. Solutions may be COTS products, COTS that have been modified and configured for the specific needs of the government, or custom software developed by the government or its contractors.
NITC has the requirement to support and execute the Systems Development Life Cycle (SDLC) of NAVFAC’s business systems. The effort will cover all activities and documentation of SDLC including: Requirements Analysis, Planning, Implementation, Testing, Documentation, Deployment, Maintenance, and Information Security, (NIST 800-64 R2). The process model employed to achieve SDLC should be based on the nature of the individual business system and its constraints. The contractor shall have the ability to implement different process models within its existing project management framework. NAVFAC systems are required to adhere to the Risk Management Framework (RMF) which includes categorization, security control selection, security control implementing (to include best practices and implementing in compliance with Security Technical Implementation Guidelines (STIGs), Cyber Tasking Orders (CTO), Information Assurance Vulnerability Management (IAVM), and other security directives as issued), access security controls, authorize system and monitor Security Controls.
In the absence of a task order specified standard, all deliverables shall measurably align with software development best practices and standards as defined by the Institute of Electrical and Electronics Engineers- Computer Society (IEEE-CS).
3.2.1.1 Requirements Analysis –A set of procedures and processes followed by the project team to determine functional and system requirements and their relative importance to users. Users’ requirements are documented meaningfully using automated requirements gathering tools such as Unified Modeling Language (UML), wherever applicable. Engage with government program management and subject matter experts as applicable to develop functional requirements consistent with new, improved, or changed capabilities desired by the government for new or existing business systems.
3.2.1.2 Systems Analysis – Engage with government architecture lead(s) to determine systems solutions, architecture, and design based on approved requirements documents.
3.2.1.3 Systems Configuration – Perform system configuration activities on COTS software solutions as described in systems design documents both at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.1.4 Systems Conversion - Converting systems from current environments to new ones including newer evolving/evolved web-based technologies including DoD approved Cloud Service Providers (CSP) technology offerings. May include the development of specifications, programming, testing and documentation. Legacy systems may also be selected for the development of new front-end user interfaces.
New user interfaces may include web-based or web-enabled front ends, REST (Representational State Transfer) APIs, and mobile device interfaces (iOS/Android).
3.2.1.5 Systems Deployment – Support deployment of new and updated COTS or government or contractor developed software systems to include data migration both at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves and may require deployment built/compiled from NITC SCM System, through NITC managed/maintained delivery and integration toolchains.
3.2.1.6 Systems Monitoring – Provide monitoring services for systems automated processes to insure correct operation and timely remediation of issues both at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.1.7 Systems Programming – Perform systems programming activities on government AND/OR CUSTOMIZED COMMERCIAL developed software as described in systems design documents including the option to require that all custom software developed by the government or its contractors to be developed in NITC specified architectures, languages, and/or frameworks. Specific requirements will be noted in individual task orders.
3.2.1.8 Database Administration – Perform database administration tasks associated with systems maintenance to include optimization, security, data migration, version updates, and privacy activities both at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.1.9 Test Planning – Develop test plans for both COTS and government or contractor developed software to validate that the systems perform as designed and provide the capability described in approved requirements documents. Additional test planning services may include support and development of NITC’s emerging automated testing infrastructure as part of software delivery and integration deliverables for both COTS and government or contractor developed software systems; this may include testing script/code automation and deployed test automation frameworks.
3.2.1.10 Quality Assurance – Utilize approved test plans to provide unit, integration, and functional testing of COTS and government or contractor developed software systems. Support of emerging automated testing infrastructure as part of software delivery and integration deliverables for both COTS and government or contractor developed software systems; this may include testing script/code automation and deployed test automation frameworks.
3.2.1.11 Document Development – Develop NAVFAC tailored documentation for COTS and government or contractor developed software systems to include Technical Manuals, User Manuals, Quick Reference Guides, and Training Materials as defined in the task order. The document is dynamic in that it will be modified to take advantage of new methodologies, techniques and tools, e.g., CASE. The documentation follows the latest approved standards at the time of development of the system.
3.2.1.12 Virtual Training – Provide training via webinar, computer-based training, or similar methodology to end users of the system.
3.2.1.13 On-Site Training – Provide on-site training in a classroom environment for end users of the system.
3.2.1.14 Cyber Security – Evaluate NIST 800-53 security controls to include compliance with Information Assurance Vulnerability Alerts (IAVAs), Information Assurance Vulnerability Bulletins (IAVBs), Cyber Tasking Orders (CTOs), and Security Technical Implementation Guides (STIGs) for applicability to systems and recommend resolutions and/or temporary mitigations to cybersecurity impacts. The Contractor shall support implementation of Cyber Security issue resolutions. Support and integrate with automated security testing of both COTS and government or contractor developed software using NITC static code analysis, dynamic system analysis, included library security validation and active system validation.
3.2.1.15 Project Management – Provide project management services to insure that schedules are established for all work items and presented on a recurring basis in a standard format including an integrated master schedule at the system level. Project management shall also include Contractor resource management; tracking of budget, deliverables delivery, deliverables validation, and quality control.
3.2.1.16 Surge Capability - Provide IT surge capability to support short suspense and unplanned requirements for existing and emerging business systems and technologies, including requirements definition, design, and deployment of information technology to support NAVFAC’s business requirements, including the integration of NAVFAC's core facilities management, construction management, and installation management systems.
3.2.2 Cyber Security
The terms Cyber Security and Information Assurance (IA) are used synonymously in this PWS. DoD, DoN and NAVFAC Cyber Security policies, processes and procedures are continuously evolving to successfully counter Cyber Security threats and current protocol and standards must be followed at all times. The government requires Cyber Security support in accordance with current DODINST 8500.1, 8500.2, NIST 800 series, SECNAVINST 5239 related policies, internal NAVFAC and established internal NITC Standard Operating Procedures (SOP’s) for the following 3 major areas: Cyber Security Risk Management Framework (RMF) and Compliance and Audit Support, Information Assurance Continuity and Recovery Planning Support, and Cyber Security Technical Writing Support.
Additionally, IT systems security implementation is required for NAVFAC business systems. The Federal Information Security Management Act of 2002 (FISMA) shall be continuously reviewed and complied with.
Each business system listed in Appendix A of the PWS undergoes FISMA review or re-accreditation annually.
New business systems may be added within the contract period of performance.
Cyber Security Risk Management Framework (RMF) and Compliance and Audit requirements include providing analytical, technical and documentation support to NAVFAC for supporting RMF, compliance, and auditing efforts, ensuring the command implements Cyber Security standards, policies, and objectives as defined in DODINST 8500.1, 8500.2, NIST 800 series, SECNAVINST 5239 related policies and established Standard Operating Procedures (SOPs).
Information Assurance Continuity and Recovery Planning support requirements includes providing IA continuity and recovery planning support and represents a broad scope of activities designed to sustain and recover critical IT services following an emergency. This functional area supports the Business Continuity Plan (BCP), Continuity of Operations Plan (COOP), Contingency Plan (CP), Disaster Recovery Plan (DRP), Occupancy Evacuation Plan (OEP), Crisis Communication Plan (CCP) and the Cyber Incident Response Plan
(CIRP).
Cyber Security Technical Writing support requirements include the creation of technical documentation. The type of documentation will be determined based on the individual system and customer need. The government will provide standards and procedures related to IA support, as requirements are identified. The tasks completed under this contract will provide Cyber Security policy support to NAVFAC with respect to Federal, DoD, and DON Cyber Security related data calls and related taskers. All documentation will be designed using standard NAVFAC tools and capable of being printed or deployed via the NAVFAC portal or the Navy network.
3.2.2.1 Requirements Gathering - Gather necessary RMF requirements data to construct a RMF package for NAVFAC Business Systems. Document any RMF issues and maintain meeting minutes inclusive of documenting the meeting discussions, decision points, and action items.
3.2.2.2 Policy, Process and Procedure Information Management and Analysis - Review, maintain, and disseminate information for NITC/NAVFAC RMF procedures and business processes. Review, assess, and provide written comments on new and updated DoD, NIST, SECNAV and NAVFAC security policies and procedures.
3.3.2.3 Cyber Security Monitoring - Provide continuous monitoring of the security posture of the datacenter through analysis and risk assessments focused on the measurement of compliance in the confidentiality, availability and integrity including the authorization, authentication and non-repudiation of users and information (data) for all NAVFAC Information Systems.
3.2.2.4 RMF Test and Evaluation - Perform RMF Test and Evaluation (T&E) for NAVFAC in accordance with DoD, NIST, SECNAV policies and internal processes. Prepare and monitor Master List of Findings (MLOF) and Plan of Action and Milestones (POA&Ms) in support of risk mitigation efforts including scans, appropriate checklists, and T&E findings. Review all inputs, validate compliance, report and track all discrepancies and compile all required final information and artifacts into a comprehensive RMF package.
3.2.2.5 Change Request Analysis - Review and provide written comments for change requests submitted by Configuration and Change Management (CCM), Business Continuity, and Cyber Security teams for changes that affect the RMF package.
3.2.2.6 Vulnerability and Risk Analysis - Perform risk analysis and provide recommendations for Information Systems vulnerability finding reports in support of Cyber Security compliance requirements.
Utilize NITC approved automated vulnerability assessment tools such as Security Readiness Review (SRR) scripts, and DISA Security Checklists to verify comprehensive and complete implementation of security requirements.
3.2.2.7 Continual Process Improvement - Gather necessary continuity and recovery planning requirements for NAVFAC Information Systems to improve BCP, COOP, CP, DRP, OEP, CCP and CIRP processes. Attend and provide meeting minutes for COOP and DRP meetings documenting the meeting discussion including decision points and action items.
3.2.2.8 Recommendations - Support, research, improve, and provide written recommendations for BCP, COOP, CP, DRP, OEP, CCP and CIRP processes and policies. Review current Cyber Security compliance documents and provide written recommendations for completion of Cyber Security compliance documents for hosted applications and hosting environments. Study, analyze, and make recommendations in eliminating, reducing, and mitigating system and network vulnerabilities.
3.2.2.9 Compliance Evaluation - Conduct exercises to evaluate and report BCP, COOP, CP, DRP, OEP, CCP and CIRP compliance findings to client representatives and government management by providing after action and lessons learned reports. Provide a weekly status report utilizing the approved weekly status report format. Maintain an acceptable level of recovery capability compliance in accordance with guidelines established by DoD, NIST 800 Series, SECNAVINST and local policies and procedures.
3.2.2.10 Documentation Development and Technical Writing – Develop and expand NAVFAC tailored documentation for Cyber Security and RMF events for Cyber Security policy related review boards, integrated process teams (IPTs), RMF package review teams, test and evaluation working groups, SOPs and other Cyber Security and RMF meetings. Review Cyber Security correspondence, project plans, data call responses, technical reports, metrics reports and policy documents for correctness, grammar and formatting.
3.2.2.11 Subject Matter Expertise - Provide expertise in the application of Navy correspondence, documentation standards, practices, and methods, procedures in producing, maintaining, and management of Cyber Security documentation, records and publications.
3.2.3 Business Systems Operations and Support
The NAVFAC Information Technology Center (NITC) has the requirement to provide Operations, Maintenance, Sustainment and Support for Production and Development NAVFAC Enterprise Business Systems and related Services currently hosted onsite at NITC Port Hueneme/ Navy Data Center Port Hueneme (NDC PH) , at a designated Navy Enterprise Data Center (NEDC), at a designated COOP/DR Data Center/Site and/or in a future Commercial/Government Cloud Environment, to include, but not limited to all Information Technology (IT). This includes both a physical and highly virtualized infrastructure that is complex, highly integrated and highly available (HA) for systems and services located in all Production, Acceptance/Quality Assurance and Development/Test environments/regions.
3.2.3.1 Day-to-Day – Operations, sustainment, monitoring and maintenance of existing hardware, parts replacements, applications services, operating systems, utility software, internal network, system integration and interconnectivity, internal network management, troubleshooting, system availability monitoring, performance optimization, systems tuning and configuration, security compliance and mitigations, service request fulfillment, software patches, system change and configuration implementation and tracking, continuous process improvement and procedure documentation. This includes off-hour call-back support and weekend maintenance support. Support may be required at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.3.2 Recurring Support – For day-to-day technical, operational, sustainment, maintenance, and monitoring of the overarching NAVFAC hosting infrastructure to include: servers, storage, operating systems, backups, applications technology stacks, internal network infrastructure; systems integration;
internal network connectivity; cabling; IAV and STIG security fixes; one-off patches and software component release updates; system change and configuration tracking; service fulfillment requests;
troubleshooting; continuous process improvements, and documentation. Support may be required at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.3.3 Recurring Support – Change Management Procedures – All tasks performed under this contract shall be performed in compliance with all established NAVFAC/NITC Change, Configuration and Release Management Procedures. Support may be required at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.3.4 Server Administration – Manage the installation, configuration, upgrade and sustainment of all virtual and physical servers running the following operating systems including but not limited to Microsoft Windows, Linux, UNIX and VMWare (ESXi). This will include but not be limited to the daily, weekly and monthly sustainment and maintenance of each hardware device. Support may be required at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves.
3.2.3.5 Business System, Web Site and Application Administration – Provide installation and configuration of software updates, component upgrades, and one-off patches. Maintain business systems interfaces to ensure full functionality and accessibility. The contractor shall document all configuration items applied in each environment, and track all changes as they are implemented. The contractor shall be responsible for configuring integration between internal and external systems interfaces and services to ensure full functionality and user accessibility. Support may be required at on premise data center facilities or DoD approved Cloud Service Providers (CSP) enclaves and may require deployment built/compiled from NITC SCM System, through NITC managed/maintained delivery and integration toolchains.
3.2.3.6 Disaster Recovery / COOP – Develop, maintain, and periodically test disaster recovery and continuity of operations plans for systems, technologies, and environments.
3.2.3.7 Database Administration – Perform database administration tasks on DBMS associated with NAVFAC Business Systems including database maintenance and sustainment, version updates, installation, configuration, optimization, System/Security patch management, privacy activities, backup/recovery, Data management (export/import/loading (ETL)), user management, and daily monitoring and troubleshooting of DBMS utilized including, but not limited to Oracle, Microsoft SQL Server and Sybase
3.2.3.8 Technical Writer and Document Development – Provide detailed documentation to include Technical Manuals, User Manuals, Quick Reference Guides, Training Materials, Configuration and Diagrams of System as defined in the task order.
3.2.3.9 Systems Deployment – Support deployment of new and updated hardware/devices, virtual appliances, operating systems, databases and applications to include, but not limited to, data migration, network implementation, virtual and physical installation as defined in the task order.
3.2.3.10 On-Site Training – Provide on-site training in a classroom and/or hands on environment for users of the system(s).
3.2.3.11 Cyber Security – Scan for unauthorized files/accounts/passwords; Execute security scans and fix vulnerabilities so as to comply with Information Assurance Vulnerability Alerts (IAVAs), Information Assurance Vulnerability Bulletins (IAVBs), Cyber Tasking Orders (CTOs), and Security Technical Implementation Guides (STIGs) for applicability to systems, recommend and implement resolutions and/or temporary mitigations to cybersecurity impacts. The Contractor shall support implementation of Cyber Security issue resolutions.
3.2.3.12 Optimization and Performance Tuning – Provide optimization and tuning in all areas of the hosting infrastructure including but not limited to networks, servers, operating systems, applications, utilities, databases, storage and backups including daily, weekly and monthly monitoring of systems for resource-intensive activity, take corrective action when necessary, perform capacity planning, system benchmarking, monitor space, I/O, CPU and memory usage on servers, and analyze, optimize and tune all system and devices for optimum performance.
3.2.3.13 Network and Inter-Connectivity Management – Provide for the installation, configuration, maintenance, sustainment and operation of the network infrastructure devices in all environments this will include but not be limited to the daily, weekly and monthly sustainment and maintenance of each network device. This includes the management, sustainment, maintenance and the configuration of all network devices
3.2.3.14 Storage Management – Provide for the installation, configuration, maintenance, sustainment and operation of storage for each designated environment including but not limited to configuring redundant storage systems for high availability and data integrity. This includes the Configuration, maintenance, sustainment and monitoring of data replication between the designated hosting facility and the designated COOP/DR site, interconnectivity between the storage device and client servers; Monitor system alerts, troubleshoot and resolve problems, Work with government technical lead or vendors for parts replacements to resolve hardware problems, develop and maintain storage configuration item checklist.
3.2.3.15 Backup and Recovery - Provide for development, implementation, configuration, maintenance, sustainment and periodically testing of backup and recovery for all systems, including but not limited to servers, databases, application and other technologies, in all designated environments.
3.2.3.16 VM Management – Manage all recurring maintenance tasks necessary to maintain the operation of the VMware vSphere environments. These include, but are not limited, to installation and configuration of software updates, component upgrades, and one-off patches, deploying virtual servers, datastore, and performance tuning of the virtual environments. Maintain business systems interfaces to ensure full functionality and accessibility. Document all configuration items applied in each environment, and track all changes as they are implemented.
3.2.3.17 Account Management – Manage all network, operating system, database, storage, and other accounts related.
3.2.3.18 Software and Hardware Management – Provide all recurring maintenance and sustainment tasks necessary to maintain all systems and devices, including not limited to the operation of the servers, operating systems, applications, utilities, network, backup and storage and other designated devices.
Maintenance tasks include those tasks identified by the government as mandatory, and items identified by the contractor as necessary to maintain and sustain the operation of the hosted environments. These include but are not limited to: Archive log files; optimizing storage space; Locking/deleting obsolete accounts;
Update anti-virus signatures; Update configuration baselines; Run system integrity diagnostics; Apply patches, hot fixes, and updates; Scan for unauthorized files/accounts/passwords; Execute security scans and fix vulnerabilities; Install/repair/replace hardware devices and peripheral devices; Update maintenance spreadsheet; Test all maintenance tasks and ensure successful completion of all tasks.
3.2.3.19 Project Management – Provide…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .