Amendment 0001 Portfolio.pdf
PDF 348 KB Posted
- Attached to
- Multiple Award Construction Contract for Physical Security/ Access Control-Amendment 0006 Federal contract opportunity
- Solicitation number
- N3943020R2201
About this file
This amendment modifies the solicitation for the Multiple Award Construction Contract for Physical Security/Access Control. The amendment provides clarifying documents for the basic contract statement of work and a draft of amendments for the seed task order statement of work. The procurement uses two-phase design-build selection procedures and intends to award three to five IDIQ MACCs. This is a 100% small business set-aside with a reserve for one women-owned small business. The NAICS code is 237990 for other heavy and civil engineering construction with a size standard of $39.5 million. Eligible businesses are required to provide construction services for physical security and access control systems at Navy and Marine Corps facilities.
View the file
Other files for this federal contract opportunity
Show all 16
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
For the best experience, open this PDF portfolio in
Acrobat X or Adobe Reader X, or later.
Get Adobe Reader Now!
http://www.adobe.com/go/reader
AT/FP Internally Originated Document
Deliverable Expectation Document (DED) for AT/FP Ashore Program Contract Data Requirements List (CDRL) Deliverable
A040 (CDRL A040) Risk Management Framework (RMF) Assessment and Authorization (A&A)/Fleet Readiness
Certification Board (FRCB) Packages
DED A040
Document Change History Record
Date Pages Section Ver. Reason for Change Entered by
02/03/12 1 Initial Release. A. Martin
10/31/13 2 Major rewrite to separate C&A requirements and FRCB requirements.
Added verbiage throughout to allow the PWS to eliminate FRCB requirements in certain cases.
A. Martin
12/11/19 3 Major rewrite to make updates and revise the title based on the RMF and the latest DoD, OPNAV, NETWARCOM, etc., guidance.
V.
Racanelli
1.0 INTRODUCTION
This document provides acceptance criteria for the Risk Management Framework (RMF) Assessment and Authorization (A&A)/Fleet Readiness Certification Board (FRCB) Packages Contract Data Requirements List (CDRL) deliverable to be submitted by the Contractor as required by the AT/FP Ashore Program Contract Performance Work Statement (PWS) and Task Order PWSs. The acceptance criteria define the requirement for the Government acceptance of the deliverable. This document also clarifies the expected content of the CDRL deliverable and recommends a format to ensure the CDRL deliverable meets the requirements and specifications derived from the AT/FP Ashore Program Contract PWS and Task Order PWSs.
2.0 DELIVERABLE DESCRIPTION
The Contract Data Requirements List (CDRL) Deliverable A040 (CDRL A040) Risk Management Framework (RMF) Assessment and Authorization (A&A)/Fleet Readiness Certification Board (FRCB) Packages is broken down into two (2) elements as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS as follows: the Risk Management Framework (RMF) Assessment and Authorization (A&A) Package; and the Fleet Readiness Certification Board (FRCB) Package. The Contractor shall be responsible for preparation and submission of any deliverables associated with achieving the Cybersecurity/RMF A&A requirements and FRCB requirements for each installation, as applicable.
The RMF A&A Package includes the Cybersecurity/RMF A&A requirements for cybersecurity testing and evaluation of the systems security posture as delineated in paragraphs 2.2.2, and 2.2.2.1 through 2.2.2.2 of this DED. The Contractor shall provide RMF A&A Package deliverables to include the RMF A&A documentation and the Risk Management/Mitigation Plan as required to achieve the Cybersecurity/RMF A&A requirements for each installation, as applicable. The Contractor shall fully comply with the approved architectures, programs, standards, guidelines and references identified in this document. The Contractor shall develop and submit the RMF A&A Package deliverables for each system to be installed as part of the CDRL Deliverable A040 RMF A&A Package for review and approval by the Government as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The Cybersecurity/RMF A&A requirements shall be satisfied by following the Department of Defense (DoD) Risk Management Framework (RMF) Process, as specified in DoDI 8510.01 and 8500.01, or the current DoN RMF Instruction. The contractor shall be required to deliver a hardened system capable of achieving an authorization to operate (ATO) on Navy networks. The contractor shall provide the associated RMF documentation indicated above as deliverables in the CDRL Deliverable A040 RMF A&A Package.
The deliverables associated with CDRL Deliverable A040 RMF A&A Package provide the documentation required to be submitted by the Contractor to the Government in accordance with this DED as required by the AT/FP Ashore Program Contract/Task Order PWS. The Government will assemble the required documentation from the Contractor RMF A&A Package deliverables in the AT/FP Ashore Remedy System and make the required submittals and request proper sponsorship from the USN Office of the Navy Authorizing Official (NAO).
The FRCB Process will assess the risks of the planned installation with respect to NETWARCOM requirements for Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR) systems, or non C4ISR systems that interface with an operational network or system. The intention of the FRCB Process determines if the systems are ready for installation by evaluating the Contractor’s FRCB Package which includes the FRCB requirements as delineated in paragraphs 2.2.3 and 2.2.3.1 through 2.2.3.10 of this DED. The Contractor shall provide FRCB Package deliverables to include the FRCB documentation, the completed Installation Work Scope (IWS) Form and the Risk Management/Mitigation Plan as required to achieve the FRCB requirements for each installation, as applicable. As required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable, the Contractor shall develop and submit the FRCB Package deliverables for each system to be installed as part of the CDRL Deliverable A040 FRCB Package for review and approval by the Government. The requirement for FRCB approval shall be satisfied by following the
COMNAVIDFORINST 2500.3, NAVNETWARCOM INSTRUCTION 12271.1, COMSPAWAR M-3090.2B
Version 2.0 FRCB Handbook, FRCB Policies and Procedures - NAVNETWARCOM INSTRUCTION
12271.1, and the latest version of SPAWAR Shore Installation Process Handbook (SIPH), COMSPAWAR M-4720.1. The contractor shall provide the associated FRCB documentation indicated above as deliverables in the CDRL Deliverable A040 FRCB Package.
The deliverables associated with CDRL Deliverable A040 FRCB Package provide the documentation required to be submitted by the Contractor to the Government in accordance with this DED as required by the AT/FP Ashore Program Contract/Task Order PWS. The Government will assemble the required documentation from the Contractor FRCB Package deliverables in the AT/FP Ashore Remedy System and make the required submittals to the FRCB.
2.1 Applicable Standards
Fleet Readiness Certification Board (FRCB) Handbook - COMSPAWAR M-3090.2B Version 2.0 of 12 March 2012.
FRCB Policies and Procedures - NAVNETWARCOM INSTRUCTION 12271.1.
COMNAVIDFORINST 2500.3 Policy and Procedures for the Fleet Readiness Certification Board Process.
The latest SPAWAR Shore Installation Process Handbook (SIPH), COMSPAWAR M- 4720.1.
Appendix D1 – Shore Work Scope Instructions 9 Feb 2011 (FRCB).doc.
Appendix D2 – Installation Work Scope Form 9 Feb 2011 (FRCB).doc.
Department of the Navy Chief Information Officer Memorandum 02-10, Information Assurance Policy Update for Platform Information Technology - DON CIO Memo 02- 10.
NAVY TELECOMMUNICATIONS DIRECTIVE 03-10; FLEET READINESS
CERTIFICATION BOARD (FRCB) PROCESS 121245Z Mar 10.
OPNAVINST 1500.76 (NTSP).
DoD Instruction, 8510.01, Risk Management Framework (RMF) for DoD Information Technology.
DoD Instruction, 8500.01, Cybersecurity.
SECNAV Instruction 5510.36A, DON Information Security Program Instruction.
SECNAV Instruction 5510.30B, DON Personnel Security Program (PSP) Instruction.
DoD 5220.22-M and R, National Industrial Security Program Operating Manual, and regulation DTM 09-019 CJCS Manual 6510.01, Defense-In-Depth, Information Assurance (IA) and Computer Network Defense (CND).
DoD 8570.01-M. Information Assurance Workforce Improvement Program.
DoD Security Technical Implementation Guides (STIGs), Automated Certification and Accreditation (C&A) Scanning and Configuration Guidance, National Security Agency (NSA) Security Guides, Netcentric Enterprise Services (NCES) Framework, DoD Security Requirements Guides (SRGs), Federal Desktop Core Configuration (FDCC), and Vendor Recommended Security Guidance and Best Practice.
NIST 800-53.
2.2 Deliverable Requirements
The CDRL Deliverable A040 RMF A&A/FRCB Packages shall consist of the documentation explained in this section. An incomplete submission of documentation associated with Cybersecurity/RMF A&A requirements and FRCB requirements increases the risk that the planned installation may not meet all certification requirements. Therefore, the Government will only process partial and incomplete packages under fleet driven circumstances approved by Navy Information Dominance Forces (NAVIDFOR). In these circumstances, the Fleet and NAVIDFOR have determined that the Fleet’s needs outweigh the risks. NAVIDFOR may also waive a full FRCB package submission if it deems an installation does not meet the necessary requirements. This waiver is granted upon review of the completed Installation Work Scope (IWS) Form that is required for every project installation.
2.2.1 Request For Change (RFC) – For OCONUS Installations only
The Contractor shall complete and submit an RFC form for each system that touches a ONE-NET network (e.g., computer, monitor, KVM, etc.) or modifies a ONE-NET network (e.g., new server, additional network drops, etc.). The Contractor shall submit the completed RFC form to the Administrative Contracting Officer (ACO) no later than 160 working days prior to the planned system installation start date. An RFC number will be assigned and shall be included on the completed Installation Work Scope (IWS) Form. The RFC form is not part of the FRCB package, but the RFC form is required to reach status five (5) before the FRCB Process will begin. The RFC form should be requested from the local N6.
2.2.2 Risk Management Framework (RMF) Assessment & Authorization (A&A) Package
The Contractor shall provide RMF A&A Package deliverables to include the RMF A&A documentation and the Risk Management/Mitigation Plan for each system to be installed as part of the CDRL Deliverable A040 RMF A&A Package for review and approval by the Government as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. This requirement for approval shall be satisfied by following the Department of Defense (DoD) Risk Management Framework (RMF) Process, as specified in DoDI 8510.01 and 8500.01, or the current DoN RMF Instruction. The contractor shall be required to deliver a hardened system capable of achieving an authorization to operate (ATO) on Navy networks. This includes patching the system to pass a vulnerability scan using DISA’s Assured Compliance Assessment Solution (ACAS), applying applicable DISA Security Technical Implementation Guides (STIGs), and associated RMF documentation which includes, but is not limited to, a hardware/software list (HW/SW), Ports, Protocols, Services, Management (PPSM) data, input to the architectural diagrams, and NIST 800-53 security control supporting documentation. Refer to paragraphs
2.2.2.1 through 2.2.2.2 below for additional guidance on deliverables associated with the RMF A&A Package.
2.2.2.1 Risk Management Framework (RMF) Process
The RMF Process is an iterative process that requires collaboration from the execution contractor engineering team, Information Systems Security Engineer/Manager (ISSE/ISSM), a Navy Qualified Validator (NQV), CNIC Echelon II, USN Security Control Assessor (SCA), and USN Office of the NAO.
The contractor shall work with one or several of these entities in order to provide the proper deliverables associated with the RMF A&A Package as directed by the ISSE/ISSM. The contractor shall provide the necessary RMF A&A Package deliverables and support the required tasks outlined in this section and paragraphs of this DED. The contractor shall support the ISSE/ISSM in order to generate a comprehensive RMF A&A Package. ISSE/ISSM is responsible for the initial review and submission of the RMF A&A Package to the USN's authoritative Cybersecurity/RMF portal. The ISSE/ISSM will then notify the CNIC Echelon II that the package has been submitted. Upon review and approval from the Echelon II, they will forward the package for a certification determination based on the system’s cybersecurity posture from the USN SCA. Once the SCA has reviewed and approved, they will forward the package to the USN NAO who will issue a certification by way of an Interim Authorization to Test (IATT), Interim Authorization to Operate (IATO), or Authorization to Operate (ATO). The contractor shall support any required meetings, discussions, questions or clarifications as required by the ISSE/ISSM, Echelon II, SCA or NAO.
The outcome of the RMF Process is an ATO, IATO, or IATT letter signed by the appropriate NAO. In the case of an IATO, the USN Office of the NAO has accepted the risk and placed conditions that must be satisfied before an ATO is granted. An IATT is granted by the NAO to deploy the system to an operational environment with the sole purpose of conducting tests. The IATT is authorized for a specified period of time in order to complete the tests. A NAO certification decision is required in addition to other service/agency's IATO/ATO for any installation interfacing with Navy networks.
If the Contractor chooses to install a system or piece of software that does not already have an ATO/ IATO/IATT, they can request the Information System Security Engineer/Information System Security Manager (ISSE/ISSM) to review the system for ATO/IATO/IATT qualification. If the ISSE/ISSM assesses that the system requires an ATO/IATO/IATT, the Contractor shall complete all RMF A&A Package deliverables required for the RMF Process and submit it to the ISSE/ISSM. The ISSE/ISSM shall submit the required RMF documentation to the NAO for approval. Once an ATO/IATO/IATT letter is obtained, the Contractor shall submit the letter to the ACO and Facilities Engineering Command Team Lead (FECTL).
The FECTL will upload the letter to the NAVFAC AT/FP Information Module (AIM) Portal and notify the AT/FP Ashore Cybersecurity/RMF A&A Coordinator.
The Contractor shall be responsible for preparing and submitting the RMF A&A Package deliverables and assisting ISSE with the following requirements, as applicable. The Contractor shall be responsible to provide support for DoD Information Technology Portfolio Registry-Department of the Navy (DITPR-DON) registration, DoD Application and Database Management System (DADMS) registration, Privacy Impact Assessment (PIA) submission, e-Authentication submission, and/or additional RMF system registration requirements as defined in the current RMF Process. The following RMF A&A documentation shall be included as part of the RMF A&A Package deliverables and may be modified for the issuance of a RMF Authorization depending on the current Cybersecurity/RMF A&A requirements:
System Categorization Form.
Platform Information Technology (PIT) Designation and Accessibility Level determination (if applicable).
Security Plan.
Security Assessment Plan.
Security Assessment Report.
Enterprise Mission Assurance Support Service (eMASS) record with all RMF controls and associated Assessment Procedures reviewed for compliance.
Plan of Actions and Milestones to remediate documented cybersecurity vulnerabilities.
Privacy Impact Assessment.
Information Security Continuous Monitoring Strategy.
Risk Assessment Report.
Other required agency endorsements/letters for the RMF A&A Package in accordance with (IAW)
DoD/DON policies or instructions or memorandums.
Evidence of documentation of complete vulnerability scans/STIGs/Security Content Automation
Protocol (SCAP).
System Administrator Manuals to comply with STIG and Assessment Procedure documentation requirements.
NAVFAC CYBERSAFE Grade Determination Checklist.
Hardware (HW)/Software (SW) Infoflow Tables.
Navy RMF Step 2 Signature Page.
System Life Cycle Management (SLCM) Strategy Controls Table.
Add Memorandum for Record (MFR).
System Security Plan/Cybersecurity/RMF A&A Plan: The Contractor shall prepare and submit the following information to define the system security posture, system design, and system configuration:
o System description/mission description: The Contractor shall provide a thorough description of the system including the system mission and its components.
o System Concept of Operations: The Contractor shall provide a system concept of operations to include sites to be fielded and a rollout/implementation plan.
o System Environment and Architecture: The Contractor shall be responsible for providing the following diagrams on the site infrastructure, physical security and threat measures, and a system accurate threat analysis:
System architecture diagram: The Contractor shall provide a network diagram generated in Microsoft (MS) Visio that meets NTD 08-08 compliance. The final diagram shall be submitted in a legible Joint Photographic Experts Group (JPEG) format.
Accreditation boundary diagram: The Contractor shall provide a network diagram outlining those network components seeking accreditation in the RMF A&A Package. The diagram shall be generated in MS Visio and shall meet NTD 08-08 compliance. The final diagram shall be submitted in a legible JPEG format.
Data flow diagram: The Contractor shall provide a data flow diagram in compliance with NTD 08-08. The diagram shall be generated in MS Visio and the final diagram shall be submitted in a legible JPEG format. The data flow diagram shall address traffic direction, ports/protocols/services, and Internet Protocol (IP) addresses.
o System users and clearances: The Contractor shall prepare and submit a notional number of users, access rights, and clearance level required.
o Hardware/Software list: The Contractor shall prepare and submit a listing of the hardware and software to be installed as part of the system. The list shall address if the hardware or software is Cybersecurity enabled, National Information Assurance Partnership (NIAP) Common Criteria evaluation and validation status, Functional Area Manager status and DADMS numbers.
o Ports, protocols and services (PP&S): The Contractor is responsible for annotating internal and external ports in accordance with the DoD Ports, Protocols, Services, Management (PPSM) policy and Navy Ports, Protocols & Services (NPPS) manual.
Proper submission also needs to include traceability between the Dataflow diagram and the PP&S listing in accordance with DoDI 8551.1 and NTD 08-10.
o Configuration management plan and Information Assurance Vulnerability Management (IAVM) Process: The contractor shall provide a description of the change management process that the system adheres to and the IAVM Process that is in place to perform patch management.
Contingency plan and incident response plan: The Contractor shall prepare and submit a system specific contingency plan and incident response plan based on NIST 800-34.
System Cybersecurity testing support: ISSE/ISSM will provide the Contractor with a security test plan defining the Cybersecurity testing requirements prior to a site visit. The Contractor shall assist the validation team with proper system support during the Cybersecurity scanning in accordance with the current Cybersecurity/RMF A&A scanning guidance process. The Contractor shall:
o Provide engineering/system administration support as required.
o Review, prepare and submit remediation and mitigation plans for all system vulnerabilities discovered.
o Prepare and submit validation scans for any open vulnerabilities that the Contractor has closed/fixed post testing.
2.2.2.2 Risk Management/Mitigation Plan
The Contractor shall develop and submit a Risk Management/Mitigation Plan as required documentation.
The Risk Management/Mitigation Plan shall address the following:
Identify risk to the installation and operations (Does not include scheduling or funding risks).
Possible risks associated with the implementation of this installation.
Level of probability of occurrence and potential impact to the project.
Plan to manage or eliminate the risk, and/or impact to the project.
Actions that will be taken to continue operations if the install/upgrade fails or causes other problems.
For hot cutovers, the Risk Management/Mitigation Plan shall address measures in place to ensure no loss of operations. A hot cutover is defined as a new system that will replace an existing system that will remain in operation until the new system is activated without the customer’s/user’s operational capability being impacted.
The Risk Management/Mitigation Plan is required for both the RMF A&A Package and the FRCB Package as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as
2.2.3 Fleet Readiness Certification Board (FRCB) Package
The Contractor shall provide the FRCB Package deliverables to include the FRCB documentation, the completed Installation Work Scope (IWS) Form and the Risk Management/Mitigation Plan for each system to be installed as part of the CDRL Deliverable A040 FRCB Package for review and approval by the Government as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The FRCB Process will assess the risks of the planned installation to determine if the systems are ready for installation by evaluating the Contractor’s FRCB Package which includes the FRCB requirements as delineated in this DED. The requirement for FRCB approval shall be satisfied by following the COMNAVIDFORINST 2500.3, NAVNETWARCOM INSTRUCTION 12271.1, COMSPAWAR M-3090.2B Version 2.0 FRCB Handbook, FRCB Policies and Procedures - NAVNETWARCOM INSTRUCTION 12271.1, and the latest version of SPAWAR Shore Installation Process Handbook (SIPH), COMSPAWAR M-4720.1. Refer to paragraphs 2.2.3.1 through 2.2.3.10 below for additional guidance on deliverables associated with an FRCB Package.
2.2.3.1 Fleet Readiness Certification Board Process
The FRCB Process will assess the risks of the planned installation with respect to NETWARCOM requirements for Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR) systems, or non C4ISR systems that interface with an operational network or system. The intention of the FRCB Process determines if the systems are ready for installation by evaluating the Contractor’s FRCB Package which includes the FRCB requirements as delineated in this DED. The Contractor shall provide FRCB Package deliverables to include the FRCB documentation, the completed Installation Work Scope (IWS) Form and the Risk Management/Mitigation Plan as required to achieve the FRCB requirements for each installation, as applicable. As required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable, the Contractor develops and submits the FRCB Package deliverables for each system to be installed as part of the CDRL Deliverable A040 FRCB Package for review and approval by the Government. Any exemptions are determined by the FRCB after submission and review of the completed Installation Work Scope (IWS) Form. Once the FRCB package has been submitted to the FRCB, the approval process will take approximately 90 days.
In certain cases, an FRCB Package may not be required by the Government as delineated in this DED and the AT/FP Ashore Program Contract/Task Order PWS. The FRCB Package to include the completed IWS Form would not be required to meet the FRCB requirements for the installation of the systems, as applicable. The Cybersecurity/RMF A&A requirements and associated deliverables are still valid as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS which include the following: (1) RMF A&A Package deliverables as delineated in paragraphs 2.2.2 and 2.2.2.1 of this DED, as applicable; and (2) Risk Management/Mitigation Plan as delineated in paragraph 2.2.2.2 of this DED, as applicable. In addition, certain requirements of the FRCB Package and associated deliverables are still valid as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS which include the other deliverables as delineated in paragraphs 2.2.3.3 through 2.2.3.10 of this DED, as applicable.
The Contractor is still responsible to prepare and submit any deliverables associated with those valid requirements as part of the CDRL Deliverable A040 RMF A&A/FRCB Packages in accordance with this DED, and/or as part of other CDRL deliverables in accordance with the applicable DEDs, and/or in accordance with other requirements of the AT/FP Ashore Program Contract/Task Order, i.e., PWS, other DEDs, Performance Specifications and Requirements Traceability Matrixes, Technical Information, etc., as required by the AT/FP Ashore Program Contract/Task Order PWS, as applicable.
The system installation and post-installation test/System Operational Verification Test (SOVT) may be permitted by the Administrative Contracting Officer (ACO) prior to formal FRCB approval. The Contractor shall submit a request to the ACO to commence any activities associated with system installation and post-installation test/SOVT in advance of formal FRCB approval to the ACO for review and approval as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. System installation is defined as starting or completing anything depicted in the systems drawings for the installation of systems by SPAWAR or in the telecommunications section of the facility drawings for Contractor installations with respect to CDRL Deliverable A005 (CDRL A005) Installation Design Plan (e.g., installing mounts, racking equipment, running cables, terminating cables, etc.). All facility modifications and facility demolitions depicted in construction or facility drawings except for the telecommunications section of the facility drawings for Contractor installations with respect to CDRL Deliverable A005 (CDRL A005) Installation Design Plan are not considered part of the system installation (e.g., mechanical modifications, electrical power modifications, structural modifications, etc.). The Administrative Contracting Officer (ACO) shall be consulted if the Contractor is unclear whether an activity is to be considered a system installation prior to starting the activity.
2.2.3.2 Installation Work Scope Form
The Contractor shall complete and submit the Installation Work Scope (IWS) Form for each system to be installed by the Contractor as part of the CDRL Deliverable A040 FRCB Package to the ACO for review and approval by the Government as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The submission shall occur no later than 150 working days prior to the planned system installation start date. Upon submission of the completed Installation Work Scope (IWS) Form, Navy Information Dominance Forces (NAVIDFOR) will supply the contractor with a tracking number or official determination within two weeks upon submission of the completed Installation Work Scope (IWS) Form. The Contractor will receive a tracking number for each form submitted if NAVIDFOR determines that the FRCB review is required for the system. The Installation Work Scope (IWS) Form can be downloaded from the NAVFAC AIM Portal.
2.2.3.3 Electromagnetic Analysis and Survey
The Contractor shall ensure that all proposed NAVFAC AT/FP Ashore Program Systems/equipment with emitters to be installed by the contractor comply with requirements set forth by the electromagnetic disciplines in accordance with applicable codes, standards and references as required by the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The Contractor shall provide the Electromagnetic Analysis and Survey documentation requirements as required by the AT/FP Ashore Program Contract/Task Order PWS. Refer to the applicable section in AT/FP Ashore Program Contract/Task Order PWS for the specific Electromagnetic Analysis and Survey documentation
The Contractor shall prepare and submit the Electromagnetic Analysis and Survey documentation requirements delineated in the applicable section of the AT/FP Ashore Program Contract/Task Order PWS for each system to be installed as part of the FRCB Package deliverables associated with CDRL Deliverable A040 Risk Management Framework (RMF) Assessment and Authorization (A&A)/Fleet
Readiness Certification Board (FRCB) Packages for review and approval by the Government in accordance with this DED as required by the AT/FP Ashore Program Contract/Task Order PWS, as
2.2.3.4 Pre-Installation Testing
The Contractor shall prepare and submit the Pre-installation Test Plan for AT/FP Ashore Program Systems or Functional System Demonstration Plan for AT/FP Ashore Program Physical Security/Access Control (PS/AC) Systems as required for each system to be installed as part of the CDRL Deliverable A006 (CDRL A006) System Testing Plans for review and approval by the Government as required by DED A006 System Testing Plans and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The Government will obtain the approved Pre-installation Test Plan or Functional System Demonstration Plan as required from the NAVFAC AT/FP Ashore Remedy System and make the required submittals to the FRCB. The Contractor shall provide the test results for the Pre-Installation Test Plan for AT/FP Ashore Program Systems or the test results for the Functional System Demonstration Plan for AT/FP Ashore Program Physical Security/Access Control (PS/AC) Systems as required for each system to be installed as part of the CDRL Deliverable A006 (CDRL A006) System Testing Plans for review and approval by the Government as required by DED A006 System Testing Plans and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The Government will obtain the approved test results for the Pre-installation Test Plan or the test results for the Functional System Demonstration Plan as required from the NAVFAC AT/FP Ashore Remedy System and make the required submittals to the FRCB. See DED A006 System Testing Plans for the Pre-Installation Test Plan and test results or Functional System Demonstration Plan and test results requirements.
2.2.3.5 System Operational Verification Test (SOVT)
The Contractor shall prepare and submit the System Operational Verification Test (SOVT) Plan and the SOVT test results for each system to be installed as part of the CDRL Deliverable A006 (CDRL A006) System Testing Plans for review and approval by the Government as required by DED A006 System Testing Plans and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The Government will obtain the approved SOVT Plan from the NAVFAC AT/FP Ashore Remedy System and make the required submittals to the FRCB. At the completion of the testing, the Government will obtain the SOVT test results from the NAVFAC AT/FP Ashore Remedy System and make the required submittals to the FRCB. The SOVT test results are not required for FRCB approval, but are required for FRCB closeout.
See DED A006 System Testing Plans for the SOVT requirements.
2.2.3.6 Training Plan
The Contractor shall prepare and submit a Training Plan for each system to be installed as part of the CDRL Deliverable A040 FRCB Package for review and approval by the Government as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable.
The Training Plan shall include the following:
Front cover sheet which includes Contractor’s name, contract number, task order sites and number, the nomenclature of the program, report date, the period covered by the report, the title, the CDRL number, and document number.
Training locations, site preparation plans, provision and installation of all necessary equipment for the training sites.
Curriculum Plan that describes modules, materials, learning objectives and proficiency standards, and hours of required training for each User group, including procedures for using any AT/FP helpdesk resources.
Preliminary schedule for training, based on implementation schedule and any identified constraints for staffing, and resources for training.
The structure of the Training Plan shall be as follows:
PART I – Technical Program Data
Table of contents indicating section title and page number.
Roles and Responsibilities of the Contractor.
Record of Change Page indicating revision history.
Nomenclature-Title-Program.
Security Classification.
Manpower, Personnel, and Training Principals.
System Description.
Developmental Test and Operational Test.
Equipment/System/Subsystem Replaced.
Description of New Development.
Concepts.
In-Service Training.
Logistics Support.
Training Schedules.
Government Furnished Equipment (GFE) and Contractor Furnished Equipment (CFE) Training Requirements.
Related Training Plans and Other Applicable Documents.
PART II - Billet and Personnel Requirements
PART III - Training Requirements
PART IV - Training Logistics Support Requirements
PART V - Manpower, Personnel and Training (MPT) Milestones
PART VI - Decision Items/Action Required
PART VII - Points of Contact
2.2.3.7 Maintenance Plan
The Contractor shall prepare and submit a Maintenance Plan for each system to be installed as part of the CDRL Deliverable A040 FRCB Package for AT/FP Ashore Program Contracts/Task Orders for Execution and Technology Refreshment Projects/requirements, or as part of CDRL Deliverable A017 (CDRL A017) Maintenance Plan for AT/FP Ashore Program Sustainment Contracts for review and approval by the Government as required by this DED or DED A017 Maintenance Plan and the AT/FP Ashore Program Contract/Task Order PWS, as applicable.
The Maintenance Plan shall be tailored to describe the specific plan for each system to be installed at each individual site and contain provisions for maintaining Operational Availability (AO). Specific system operational availability will be specified in the individual task orders.
The Maintenance Plan shall include the following:
Title Page, Table of Contents, Record of Changes/Revision History, and numbered pages.
A maintenance strategy which builds procedures, processes, and products that impose no obstacles to operator duties and responsibilities during the system’s operational mission profile or the system’s performance as a component of the larger system; and/or, system performance and design.
Processes for preventive maintenance and provide a list of maintenance items and actions.
Processes for corrective maintenance and provide a list of locations, tools, support equipment, and consumables.
Provision for advance Government notification, no less than 30 days of the planned scheduled maintenance events.
Completion of scheduled maintenance within the scheduled maintenance window.
All major servicing and upgrades scheduled during off duty hours. Major servicing and upgrades may include, but are not limited to, operating system upgrades and reconfiguration of network routers or rebuilding/overhaul of equipment or structures.
Scheduling of upgrades requiring more than two days of work over holiday periods where possible.
Address the following maintenance windows:
o Regular Maintenance: Monday through Friday - Evenings from 2100 to 0500.
o Extended Maintenance: The Contractor shall coordinate schedules with the site.
Address a sustained maintenance planning function that encompasses continual review of established maintenance plans to ensure the most cost-effective maintenance is being performed on in-service support systems.
Address the age of the system, and changes in material conditions, failure modes, and the operational environment to ensure that safe and affordable readiness is maintained.
Address a method to provide all services required and materials necessary to maintain the installed AT/FP Ashore Program Systems/equipment that may be present at an operational site.
Address a method to provide maintenance scheduling and tracking integrated in the AT/FP Ashore Remedy System.
2.2.3.8 Supportability Strategy
The Contractor shall prepare and submit a Supportability Strategy for each system to be installed as part of the CDRL Deliverable A040 FRCB Package for AT/FP Ashore Program Contracts/Task Orders for Execution and Technology Refreshment Projects/requirements, or as part of CDRL Deliverable A020 (CDRL A020) Supportability Strategy for AT/FP Ashore Program Sustainment Contracts for review and approval by the Government as required by this DED or DED A020 Supportability Strategy and the AT/FP Ashore Program Contract/Task Order PWS, as applicable. The Supportability Strategy shall be submitted in lieu of the requirement for a User’s Logistics Support Summary (ULSS) for FRCB approval. The Supportability Strategy provides a means of communicating the Contractor’s support recommendations to the Government.
The deliverable shall contain a Title Page, Table of Contents, Revision History, and numbered pages.
The Supportability Strategy shall include planning, management, and program documentation for all Integrated Logistic Support (ILS) elements and shall meet all supportability requirements per NAVFAC AT/FP Ashore Performance Specifications (P-Specs) and Requirements Traceability Matrixes (RTMs), as
The minimum content of the Supportability Strategy shall include:
Details of the maintenance concept and plan.
Supply support concepts.
Test and diagnostic equipment requirements.
Technical data and operating manuals.
Training concepts and devices.
Packaging, shipping, and handling requirements.
Other resources required to sustain equipment.
2.2.3.9 Risk Management/Mitigation Plan
The Contractor shall develop and submit a Risk Management/Mitigation Plan as required documentation.
The Risk Management/Mitigation Plan shall address the following:
Identify risk to the installation and operations (Does not include scheduling or funding risks).
Possible risks associated with the implementation of this installation.
Level of probability of occurrence and potential impact to the project.
Plan to manage or eliminate the risk, and/or impact to the project.
Actions that will be taken to continue operations if the install/upgrade fails or causes other problems.
For hot cutovers, the Risk Management/Mitigation Plan shall address measures in place to ensure no loss of operations. A hot cutover is defined as a new system that will replace an existing system that will remain in operation until the new system is activated without the customer’s/user’s operational capability being impacted.
The Risk Management/Mitigation Plan is required for both the FRCB Package and RMF A&A Package as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS, as applicable.
2.2.3.10 Other Deliverables associated with the FRCB Package
The Contractor prepares and submits the following CDRL deliverables as separate data deliverables in accordance with the applicable DEDs and the Government will obtain the approved CDRL deliverables from the NAVFAC AT/FP Ashore Remedy System and make the required submittals to the FRCB:
Approved Program Schedule and Progress Report (CDRL Deliverable A002 (CDRL A002))
Approved Installation Design Plan 100% Pre-Final Design (CDRL A005/CDRL Deliverable A005)
Approved System Testing Plans (CDRL Deliverable A006 (CDRL A006))
Approved Maintenance Plan (CDRL Deliverable A017 (A017)) only for AT/FP Ashore Program Sustainment Contracts as delineated in paragraph 2.2.3.7 above.
Approved Supportability Strategy (CDRL Deliverable A020 (CDRL A020)) only for AT/FP Ashore Program Sustainment Contracts as delineated in paragraph 2.2.3.8 above.
2.3 Deliverable Format
The deliverable shall be in the form of well-organized legible documents. The deliverable shall be legible with consistency in regard to references and from section-to-section, and cross-checked with its various parts and appendices.
The Contractor shall provide electronic copy in Microsoft Office Word and Portable Document Format
(PDF).
The Contractor shall submit the system architecture diagram, the accreditation boundary diagram, and the flow data diagram in a legible JPEG format.
Files submitted to the AT/FP Ashore Remedy System shall adhere to the following file naming convention:
AAAABBBBBBBC…CDDDEEEEFFFFF.GGG
Where A = CDRL Number, B = Last 4 digits of Contract Number and 3 digit Task Order Number, C = Region Name, D = 3 Digit Month Abbreviation, E = 4 Digit Year, F = Revision or Version Number, and G = File Name Extension.
Example: A0301264011CNRMAJun2011Rev01.pdf (Do not use spaces)
3.0 KEY DELIVERABLE SUBMITTAL DATES AND METHOD OF DELIVERY
The deliverable shall be submitted in accordance with the dates identified in Appendix D Data Requirements Checklist and DED Package.
The deliverables associated with the Risk Management Framework (RMF) Assessment & Authorization (A&A) Package include the Cybersecurity/RMF A&A requirements for Cybersecurity testing and evaluation of the systems security posture. The Contractor shall provide deliverables associated with the CDRL Deliverable A040 RMF A&A Package for the Government’s RMF Process as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS. (Refer to paragraphs 2.2.2, and 2.2.2.1 through 2.2.2.2.)
The deliverables associated with the Fleet Readiness Certification Board (FRCB) Package include the following: The first submittal shall be the completed Installation Work Scope (IWS) Form at approximately 150 days prior to the scheduled installation. The remainder of the deliverables associated with the FRCB Package shall be submitted no later than 90 days prior to the scheduled installation. The Contractor shall provide deliverables associated with the CDRL Deliverable A040 FRCB Package for the Government’s FRCB Process as required by this DED and the AT/FP Ashore Program Contract/Task Order PWS.
(Refer to paragraphs 2.2.3 and 2.2.3.1 through 2.2.3.10.)
The Contractor shall provide all deliverables electronically to both the Administrative Contracting Officer (ACO) and the AT/FP Ashore Remedy System.
4.0 ACCEPTANCE CRITERIA
The following are the minimum acceptance criteria:
Deliverable meets all requirements from sections 2.0 and 3.0.
Deliverable meets the general review criteria (e.g., pages numbered, free of formatting and spelling errors, clearly written, no incomplete sections, etc.). Table of Contents depicts the correct page number, including Appendices or enclosures (e.g., Appendices and Enclosures are correctly labeled and referenced in Table of Contents).
APPENDIX B
Contractor User Guide for the AT/FP Ashore AIM and Remedy Systems
May 2019
Prepared for:
Naval Facilities Engineering Command (NAVFAC)
Anti-Terrorism/Force Protection Ashore (AT/FP Ashore)
APPENDIX B
Foreword
This User Guide constitutes “Appendix B” for Contracts and Task Orders issued under the AT/FP Ashore Program. The guide details Contractor logistics responsibilities and AT/FP Ashore processes with respect to the reporting and handling of assets, configuration management, corrective and preventive maintenance, training, documentation, and deliverables.
In the event of a conflict between the text of this document and the references cited herein, the text of this document takes precedence. Nothing in this document, however, supersedes applicable laws and regulations unless a specific exemption has been obtained.
Appendix B
TABLE OF CONTENTS
1. Introduction
1.1. The AT/FP Ashore Remedy System
1.2. The AT/FP Ashore AIM Portal
1.3. Accessing AT/FP Ashore Web Sites
2. Contractor Responsibilities:
2.1 Submitting Task Order Deliverables
2.2 Asset and Configuration Management
2.2.1 Submitting Data
2.2.2 Change Management/Engineering Change Proposals (ECPs)
2.3 Preventive Maintenance
2.3.1 Submitting and Maintaining Preventive Maintenance Schedules
2.3.2 Scheduling & Notification of Maintenance
2.4 Corrective Maintenance
2.4.1 Technical Support
2.4.2 Responding to Incidents
2.4.3 Updating Incidents
2.4.4 Resolving Incidents
3. Data Templates
4. Questions
5. Attachments
5.1 AIM User Guide
5.2 Remedy Incident Guide
5.3 Remedy CDRL Submission Guide
Table 1 – Remedy Help Desk Ticket States
1. Introduction This guide details Contractor logistics responsibilities and AT/FP Ashore processes with respect to the reporting and handling of assets, configuration management, corrective and preventive maintenance, deliverables, and project status utilizing two AT/FP Ashore Web sites, the AT/FP Ashore Remedy System and AT/FP Information Module (AIM) Portal. Details in using these systems can be found in the imbedded user guides in Section 5. Attachments.
1.1. The AT/FP Ashore Remedy System
The NAVFAC AT/FP Ashore Remedy System is a collection of computer hardware and software implemented by NAVFAC AT/FP Ashore Program Management Office (PMO) that utilizes the BMC Software, Inc. Remedy Enterprise Suite of software to provide Help Desk, Asset Management, Change Management, and Knowledge Management support. Remedy provides the following support for installed AT/FP systems:
• A Help Desk application that logs customer requests (questions, repair issues, training issues, emergencies, etc.);
• An issue resolution and tracking system;
• Automatic triggering of notifications and escalations based upon defined criteria;
• An asset tracking system;
• A preventive maintenance and inspection tracking system;
• An application that can be securely accessed remotely via the Web; and Operational
Availability (Ao) tracking based upon service call life cycles.
1.2. The AT/FP Ashore AIM Portal
The AT/FP Ashore AIM System is a web based digital dashboard that provides a customized solution for AT/FP Ashore personnel that consolidates areas of cost, schedule, performance, contracts, risks, deviations, sustainment, and actions. AIM provides single-click access to analytical and collaborative tools and brings an integrated view of AT/FP‟s knowledge sources to an individual's desktop, enabling better decision making by providing immediate access to key information.
AT/FP Information Module provides a dedicated website page for each AT/FP Ashore project, as well as higher-level views for the PMO and other teams and working groups. The AIM portal is constructed in a hierarchical fashion allowing for the concatenation of data at higher levels to provide automated high-level views of Program health.
1.3. Accessing AT/FP Ashore Web Sites
Contractors shall access the AT/FP Ashore Remedy System and the AIM Portal via the Internet through secure web sites to document and complete both execution and sustainment activities related to Contract Data Requirements List (CDRL) submissions, project status, inventory tracking, technical support and equipment maintenance history (preventive maintenance, corrective maintenance, and 24-hour emergency response).
Contractors must have the ActivClient software installed on their computers for AIM and/or Remedy account requests and active accounts. ActivClient is a commercial off-the-shelf software application and is used for user authentication for these systems including the self-registration site. The ActivClient software is updated regularly and occasional patches are released; a current version/patch level is required.
The Contractor shall obtain a Public Key Infrastructure-enabled CAC with a Personal Identification Number (PIN) and a computer with the appropriate card reader and associated software/drivers to access the AT/FP Ashore websites.
Both Remedy and AIM employ “Single Sign On (SSO)” technology for user authentication and authorization and permits approved Common Access Card (CAC) holders’ access to the database.
Access to Remedy and AIM is gained by going to the following web site and submitting a request:
https://sso.navatfp.sd.spawar.navy.mil/_layouts/AIMSelfRegistration/SelfRegistration.aspx
Once the request is approved, Remedy can be accessed at:
https://ars.navatfp.sd.spawar.navy.mil
AIM can be accessed at:
https://aim.navatfp.sd.spawar.navy.mil
Contractors shall notify the AIM/Remedy team at aim-remedy@altusts.com when personnel leave their company and/or the AT/FP Ashore program to ensure accounts are disabled in a timely manner. Notifications should be sent in advance (preferred) stating the effective date;
or at a maximum within one business day of the employee’s departure.
2. Contractor Responsibilities:
The Contractor will be responsible for the following:
• Submitting all task order deliverables including, but not limited to, asset and configuration information through the AT/FP Ashore Remedy System;
• Submitting any requested changes, in writing, to the Public Works Department/Facilities Engineering Acquisition Division/Administrative Contracting Officer (PWD/FEAD/ACO) via the standard contract process; and responding to all tasking (corrective and preventive maintenance requests) and updating the associated service calls appropriately through the AT/FP Ashore Remedy System.
• Maintaining project-related data in the AT/FP Ashore AIM Portal.
2.1 Submitting Task Order Deliverables
At a minimum, all task order CDRLs shall be submitted to the ACO and also electronically via the AT/FP Ashore Remedy System utilizing the CDRL Data Submission Form accessible in the AT/FP Ashore Remedy System Applications Console. The content and extent of task order deliverables is project specific to each individual contract/task order. A list of applicable deliverables is available in Appendix D - Data Requirements Checklist and Deliverable Expectation Document (DED) Package within each individual contract/task order.
https://sso.navatfp.sd.spawar.navy.mil/_layouts/AIMSelfRegistration/SelfRegistration.aspx https://ars.navatfp.sd.spawar.navy.mil/ https://aim.navatfp.sd.spawar.navy.mil/
2.2 Asset and Configuration Management
The AT/FP Ashore Remedy System will be utilized to track AT/FP assets and configuration management data. Contractors shall make submissions of asset data as specified in the Appendix D - Data Requirements Checklist and DED Package.
All submissions of data to the AT/FP Ashore Remedy System automatically generate a reference number of the transaction for tracking and reporting purposes.
Contractors will be notified electronically via email of either submission approval or requests for additional information. Approvals or requests for additional information will also be accessible through the AT/FP Ashore Remedy System/AIM Portal.
2.2.1 Submitting Data
Contractors shall submit all data relating to the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .