Smoke_MOD_SOW190015(Nov2019)__Final.docx
DOCX document 247 KB Posted
- Attached to
- Surface Fire Fighting Trainer Smoke/Fog Generation System Federal contract opportunity
- Solicitation number
- N6134020R0013
View the file
Other files for this federal contract opportunity
Show all 50
Surface Fire Fighting Trainer Smoke/Fog Generation System has more files on GovTribe.
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SOW 190015
25 November 2019
| SOW 190015 |
| 25 November 2019 |
Appendix C
| SOW 190015 |
| 25 November 2019 |
STATEMENT OF WORK
FOR THE
SURFACE FIRE FIGHTING TRAINER
SMOKE/FOG GENERATION SYSTEM
DEPARTMENT OF THE NAVY
NAVAL AIR WARFARE CENTER
TRAINING SYSTEMS DIVISION
12211 SCIENCE DRIVE
ORLANDO, FL 32826
APPROVED BY: DATE:
Roberto Soto-Albino Project Manager NAWCTSD-Code 1.3.6.1
APPROVED BY: DATE:
Daniel Chwalisz Division Head NAWCTSD-Code 4.6.8.3
APPROVED BY: DATE:
Tony Cintron Logistics Management Integration Branch Head NAWCTSD-Code 6.6.4.10
DISTRIBUTION STATEMENT C - Distribution authorized to U.S. Government agencies and their contractors (fill in reason) (date of determination). Other requests for this document shall be referred to (insert controlling DoD office).
Table of Contents
| Section | Title | Page |
| 1. | SCOPE | 1 |
| 2. | APPLICABLE DOCUMENTS | 2 |
| 2.1 | Government Documents | 2 |
| 2.2 | Non-Government Documents | 3 |
| 3. | REQUIREMENTS | 4 |
| 3.1 | General Tasks | 4 |
| 3.1.1 | Program Management | 4 |
| 3.1.1.1 | Program Planning | 4 |
| 3.1.1.2 | Subcontractor Management and Reporting | 5 |
| 3.1.1.3 | Integrated Product Teams (IPTs) | 5 |
| 3.1.1.4 | Risk Management | 5 |
| 3.1.1.5 | Quality Management | 5 |
| 3.1.1.5.1 | Use of Contractor’s Inspection Equipment | 6 |
| 3.1.1.6 | Configuration Management (CM) | 6 |
| 3.1.1.6.1 | Change Management | 6 |
| 3.1.1.6.2 | Configuration Status Accounting | 6 |
| 3.1.1.6.3 | Configuration Audits | 6 |
| 3.1.1.7 | Information Management | 6 |
| 3.1.1.7.1 | Data Management | 6 |
| 3.1.2 | Security | 7 |
| 3.1.2.1 | Operations Security (OPSEC) [No OPSEC Plan/CDRL] | 7 |
| 3.1.2.2 | Unclassified Contractor-Owned Network Security - Safeguarding of Unclassified Controlled Technical Information | 7 |
| 3.1.2.3 | Cyber Incident and Compromise Reporting | 8 |
| 3.1.2.4 | Access to DoD Installations, Government Information, and Information Technology (IT) Systems - Personnel Security Background Checks and DBIDS | 8 |
| 3.1.2.5 | Personnel Security - Background Checks | 9 |
| 3.1.2.6 | International Traffic and Arms Regulation | 9 |
| 3.1.2.7 | Personnel Security - Reporting of Adverse or Derogatory Information related to Contractors | 9 |
| 3.1.2.8 | Contractor “Out-processing” Policy | 9 |
| 3.1.2.9 | Government-Issued Personal Identification | 10 |
| 3.1.2.10 | Transmission of Controlled Unclassified Information (CUI) via e-mail | 10 |
| 3.1.2.11 | Transmission of Controlled Unclassified Information (CUI) via S.A.F.E | 10 |
| 3.1.3 | Cybersecurity (Navy) | 10 |
| 3.1.3.1 | Cybersecurity Assess and Authorize (A&A) Support | 11 |
| 3.1.3.2 | Software Integrity Testing and Certification | 11 |
| 3.1.3.3 | CS Compliance | 11 |
| 3.2 | Detailed Tasks | 11 |
| 3.2.1 | Trainer Modification Task | 11 |
| 3.2.2 | Systems Engineering Processes | 11 |
| 3.2.2.1 | System Requirements Definition | 11 |
| 3.2.2.2 | Software Detailed Design | 12 |
| 3.2.2.2.1 | Software Detailed Design Verification | 12 |
| 3.2.2.2.2 | Programming High Order Language(s) (HOL) Selection | 12 |
| 3.2.2.3 | Implementation | 12 |
| 3.2.2.3.1 | Software Implementation | 12 |
| 3.2.2.3.1.1 | Software Unit Construction and Testing | 12 |
| 3.2.2.3.1.1.1 | Software Code Verification | 12 |
| 3.2.2.3.2 | Software Integration | 12 |
| 3.2.2.3.3 | Software Integration Verification | 12 |
| 3.2.2.3.3.1 | Software Qualification Testing | 13 |
| 3.2.2.4 | System Integration | 13 |
| 3.2.2.5 | System Qualification Testing | 13 |
| 3.2.2.6 | Device Transition | 13 |
| 3.2.2.6.1 | Software Installation | 13 |
| 3.2.2.6.2 | Software Product | 13 |
| 3.2.2.6.2.1 | Cold Start Procedures | 13 |
| 3.2.2.6.2.2 | Installation and Configuration Procedures | 14 |
| 3.2.2.6.2.3 | Media and Storage Devices | 14 |
| 3.2.2.6.2.4 | Cold Start and Installation Procedure Media | 15 |
| 3.2.2.6.2.5 | Automated Processes | 15 |
| 3.2.2.6.2.6 | Contractor Execution | 15 |
| 3.2.2.7 | System Validation | 15 |
| 3.2.2.7.1 | Software Acceptance Support | 15 |
| 3.2.2.8 | E3 Engineering | 16 |
| 3.2.2.8.1 | ESD Management | 16 |
| 3.2.2.9 | Reliability and Maintainability (R&M) Engineering | 16 |
| 3.2.2.9.1 | Failure Reporting, Analysis and Corrective Action System (FRACAS) | 16 |
| 3.2.2.9.2 | R&M Predictions | 17 |
| 3.2.2.10 | Human Factors Engineering | 17 |
| 3.2.3 | Conferences and Reviews | 17 |
| 3.2.3.1 | Post Award Conference (PAC) | 17 |
| 3.2.3.1.1 | PAC Entry Criteria | 18 |
| 3.2.3.1.2 | PAC Exit Criteria | 18 |
| 3.2.3.1.3 | Logistics Guidance Conference (LGC) | 19 |
| 3.2.3.1.4 | Technical Manual Initial Guidance Conference (TMIGC) | 19 |
| 3.2.3.1.5 | Option Award Event | 19 |
| 3.2.3.2 | Systems Engineering Technical Reviews (SETR) | 19 |
| 3.2.3.2.1 | System Requirements Review-System Functional Review (SRR-SFR) | 20 |
| 3.2.3.2.1.1 | SRR-SFR Entry Criteria | 20 |
| 3.2.3.2.1.2 | SRR-SFR Exit Criteria | 21 |
| 3.2.3.2.2 | Critical Design Review | 21 |
| 3.2.3.2.2.1 | CDR Entry Criteria | 22 |
| 3.2.3.2.2.2 | CDR Exit Criteria | 22 |
| 3.2.3.2.3 | TRR Conferences | 22 |
| 3.2.3.3 | IPT Meetings | 22 |
| 3.2.3.4 | Provisioning Item Selection Conference (PISC) | 23 |
| 3.2.3.4.1 | PISC Entry Criteria | 23 |
| 3.2.3.4.2 | PISC Exit Criteria | 23 |
| 3.2.3.5 | Technical Manual (TM) In-Process Reviews (IPRs) | 23 |
| 3.2.4 | Commercial and Non-Developmental Items (CaNDI) | 24 |
| 3.2.5 | Parts Standardization | 24 |
| 3.2.5.1 | TPE requirements | 24 |
| 3.2.5.1.1 | Parts Selection Criteria for TPE | 24 |
| 3.2.5.1.2 | Replacement of Parts | 24 |
| 3.2.6 | System Safety Tasks | 25 |
| 3.2.7 | Product Assurance Audits and Inspections | 25 |
| 3.2.8 | System Test and Evaluation | 25 |
| 3.2.8.1 | Responsibility for Tests | 25 |
| 3.2.8.2 | Test Authority | 25 |
| 3.2.8.3 | T&E Program Planning | 25 |
| 3.2.8.4 | Test Resources and Facilities | 26 |
| 3.2.8.5 | Test Methods | 26 |
| 3.2.8.6 | Test Criteria | 26 |
| 3.2.8.7 | Alignment | 26 |
| 3.2.8.8 | Test Log | 26 |
| 3.2.8.9 | Changes During Testing | 27 |
| 3.2.8.9.1 | Software Changes During Government Testing | 27 |
| 3.2.8.10 | Changes After Testing | 27 |
| 3.2.8.11 | T&E Deficiency Reporting System | 27 |
| 3.2.8.11.1 | Deficiency Report Review Board | 27 |
| 3.2.8.12 | T&E Program Components | 28 |
| 3.2.8.12.1 | Baseline Configuration Audit (BCA) | 28 |
| 3.2.8.12.2 | Conformance Inspections | 28 |
| 3.2.8.12.2.1 | Functional Configuration Audit (FCA) | 28 |
| 3.2.8.12.2.1.1 | DT-2 (Contractor Preliminary Inspection) | 29 |
| 3.2.8.12.2.1.2 | DT-3 (Government Preliminary Inspection) | 29 |
| 3.2.8.12.2.1.3 | DT-4 (Contractor Final Inspection) | 29 |
| 3.2.8.12.2.1.4 | Test Readiness Review (TRR) | 30 |
| 3.2.8.12.2.1.4.1 | TRR Entry Criteria | 30 |
| 3.2.8.12.2.1.4.2 | TRR Exit Criteria | 31 |
| 3.2.8.12.2.1.5 | DT-5 (Government Final Inspection) | 31 |
| 3.2.8.12.2.2 | Physical Configuration Audit (PCA) | 32 |
| 3.2.8.12.2.2.1 | On-site PCA | 32 |
| 3.2.8.12.2.2.1.1 | On-site PCA Entry Criteria | 32 |
| 3.2.8.12.2.2.1.2 | On-site PCA Exit Criteria | 32 |
| 3.2.9 | Integrated Logistics Support (ILS) Program | 32 |
| 3.2.9.1 | Material Support | 33 |
| 3.2.9.1.1 | Development of Logistics Product Data (LPD) | 33 |
| 3.2.9.1.2 | Initial Support Kit (ISK) | 33 |
| 3.2.9.1.3 | Engineering Data for Provisioning (EDFP) | 33 |
| 3.2.9.1.4 | Bill of Materials (BOM) for Logistics and Supply Chain Risk Management | 34 |
| 3.2.9.1.5 | Obsolescence Management Program Planning | 34 |
| 3.2.9.1.6 | Obsolescence Management/DMSMS | 34 |
| 3.2.9.1.7 | Buy Through The Prime (BTTP) | 34 |
| 3.2.9.2 | System Hardware Warranties | 35 |
| 3.2.9.3 | Technical Manuals (TM) | 35 |
| 3.2.9.3.1 | TM Validation | 36 |
| 3.2.9.3.2 | TM Verification | 36 |
| 3.2.10 | Facility Requirements | 36 |
| 3.2.10.1 | Facility Safety | 37 |
| 3.2.10.2 | Disposal of Hazardous Materials, Waste, and Equipment | 37 |
| 3.2.10.3 | Floor Repair | 37 |
| 3.2.10.4 | Facility Clean Up | 37 |
| SOW 190015 | ||
| 25 November 2019 |
| SOW 190015 |
| 25 November 2019 |
Table of Contents
Section Title Page vi v
APPENDICES
| Appendix | Title | Page |
| A | Terms and Definitions | 36 |
| SOW 190015 |
| 25 November 2019 |
Table of Contents
Statement of Work For the Surface Fire Fighting Trainer Smoke/Fog Generation System
SCOPE
This Statement of Work (SOW) establishes the contractor’s task requirements for the delivery of a Smoke/Fog generation system for the surface Fire Fighting Trainers (FFTs); with options for the removal of the surrogate Aqueous Film Foaming Foam (AFFF) system for all surface FFTs located in Newport, RI, Norfolk, VA, Great Lakes, IL, San Diego, CA, and Mayport, FL, and the non-skid resurfacing and hatch/scuttle replacements for the Damage Control Wet Trainers (DCWTs) in Newport, RI, San Diego, CA and Norfolk, VA. This Smoke/Fog generation system will allow all surface FFTs to establish a new technology baseline and the reduction of life-cycle costs throughout the life of the surface FFT system program. The use of the new technology baseline will include integration, testing, and delivery of the smoke/fog generation system in support of the surface FFT devices located in:
| Device |
| S/N |
| Location |
| FFT 19F3A |
| 1 |
| Newport, Rhode Island |
| FFT 19F1B |
| 2 |
| Norfolk, Virginia |
| FFT 19F3C |
| 2 |
| Great Lakes, Illinois |
| FFT 19F1B |
| 1 |
| San Diego, California |
| FFT 19F4A |
| 2 |
| Norfolk, Virginia |
| FFT 19F4A |
| 1 |
| San Diego, California |
| FFT 19F4A |
| 3 |
| Mayport, Florida |
| FFT 19F1A |
| 1 |
| Mayport, Florida |
| FFT 19F3B |
| 2 |
| Norfolk, Virginia |
| FFT 19F3B |
| 1 |
| San Diego, California |
| FFT 19F5 |
| 1 |
| Great Lakes, Illinois |
| DCWT |
| 1 |
| Newport, Rhode Island |
| DCWT |
| 1 |
| Norfolk, Virginia |
| DCWT |
| 1 |
| San Diego, California |
The tasks required in this SOW are within the scope of the Basic Training Systems Contract (TSC) IV Indefinite Quantities Contract (IQC) SOW 170035.
APPLICABLE DOCUMENTS
The following documents of the issue listed form a part of this SOW to the extent specified herein. In the event of a conflict between documents referenced herein and the contents of this SOW, the contents of this SOW take precedence. Nothing in this SOW, however, supersedes applicable laws and regulations, unless a specific exemption has been obtained.
Government Documents
SPECIFICATIONS:
| Naval Air Warfare Center Training Systems Division (NAWCTSD) |
| PRF 190016 |
| - |
| Surface Fire Fighting Trainer Smoke/Fog Generation System, dated 16 July 2019 |
OTHER PUBLICATIONS:
| Code of Federal Regulations (CFR) |
| 29 CFR 1910.147 |
| - |
| The control of hazardous energy (lockout/tagout) |
| 22 CFR Parts 120-130 |
| - |
| International Traffic and Arms Regulation (ITAR) |
(OSHA regulations are downloadable from https://www.osha.gov/law-regs.html & https://apps.dtic.mil/dtic/tr/fulltext/u2/a312382.pdf)
Defense Federal Acquisition Regulations Supplement (DFARS)
| DFAR 252.204-7012 |
| - |
| Safeguarding Covered Defense Information and Cyber Incident Reporting |
(DFARS Clauses are downloadable from http://www.acq.osd.mil/dpap/dars/dfarspgi/current/index.html)
Federal Acquisition Regulation (FAR)
| FAR 52.222-54 |
| - |
| Safeguarding Covered Defense Information and Cyber Incident Reporting |
(FAR Regulation is downloadable from https://www.govinfo.gov/content/pkg/CFR-2011-title48-vol2/pdf/CFR-2011-title48-vol2-sec52-222-54.pdf)
Office of the Chief of Naval Operations (OPNAV)
| OPNAVINST 11010.20H |
| - |
| Navy Facilities Projects |
(OPNAVINST Instructions are downloadable from https://www.secnav.navy.mil/doni/opnav.aspx#InplviewHashcacf3aef-aed4-433a-8ce5-a45245715b5c=)
National Institute of Standards and Technology (NIST)
| NIST SP 800-37 |
| - |
| Guide for Applying the Risk Management Framework to Federal Information Systems |
NIST SP 800-53
| - |
| Security and Privacy Controls for Federal Information Systems and Organizations |
| NIST SP 800-171 |
| - |
| Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations |
(NIST publications can be downloaded from https://www.nist.gov)
National Security Decision Directive (NSDD)
| NSDD 298 |
| - |
| National Operations Security Program |
(NSDD publications can be downloaded from https://www.hsdl.org/?abstract&did=463214)
Department of Defense (DoD) Handbooks
| MIL-HDBK-217F, Notice 2 |
| - |
| Reliability Prediction of Electronic Equipment |
| MIL-HDBK-472, Notice 1 |
| - |
| Maintainability Prediction |
(Copies of the above handbooks are available at http://quicksearch.dla.mil, or from the Standardization Document Order Desk, 700 Robbins Ave., Bldg 4D, Philadelphia, PA 19111-5094.)
| DoD Manuals |
| DoD 5010-12M |
| - |
| Procedures for Acquisition Management of Technical Data |
| DoDI 8510.01 |
| - |
| Risk Management Framework (RFM) |
| DoDI 8520.02 |
| - |
| Public Key Infrastructure & Public Key Enabling |
(The above publication is available at https://www.esd.whs.mil/DD)
| NAVAIR Instructions |
| NAVAIRINST 4355.19E |
| - |
| Systems Engineering Technical Review Process, dated 6 Feb 2015 |
(NAVAIR Instructions are downloadable from https://directives.navair.navy.mil)
| United States (U.S.) Code |
| Title 10, Section 2451 - 2456 |
| - |
| Defense Standardization Program |
(U.S Code is downloadable from http://uscode.house.gov/search/criteria.shtml)
NAWCTSD
| SOW 170035 |
| - |
| Statement of Work for The Training Systems Contract (TSC) IV, dated 28 July 2017 |
| TMCR 19-13 |
| - |
| Technical Manual Contract Requirements, Fire Fighting Trainer Upgrade, dated 11 June 2019 |
Non-Government Documents
INDUSTRY STANDARDS
| American National Standards Institute (ANSI)/American Society for Quality (ASQ)/ International Organization for Standardization (ISO) |
| ANSI/ASQ/ISO Q9000-2015 |
| - |
| Quality Management Systems - Fundamentals and Vocabulary |
| ANSI/ASQ/ISO Q9001-2015 |
| - |
| Quality Management Systems - Requirements |
| ANSI/ASQ/ISO Q9004-2009 |
| - |
| Quality Management Systems - Guidelines for Performance Improvements |
(Copies of the above documents are available from www.ansi.org)
| ANSI/Institute of Electrical and Electronics Engineers (IEEE) |
| ANSI/IEEE 1008-1987 |
| - |
| IEEE Standard for Software Unit Testing |
| IEEE 12207-2008, 2nd Edition |
| - |
| Systems and Software Engineering – Software Life Cycle Processes |
| IEEE 15288-2008, 2nd Edition |
| - |
| Systems and Software Engineering – System Life Cycle Processes |
| IEEE 42010-2011 |
| - |
| System and Software Engineering- Architecture Description |
| IEEE 1016-2009 |
| - |
| Systems Design Software Design Descriptions |
| IEEE 15289-2001 |
| - |
| Systems and Software Engineering- Content of life-cycle information products |
(Copies of this document are available from www.ieee.org or IEEE Service Center, 445 Hoes Lane, Piscataway, NJ 08854-1331.)
| SAE International/Electronic Industries Alliance (EIA) |
| SAE/EIA-649-1 2014 |
| - |
| Configuration Management Requirements for Defense Contracts |
(Copies of the above document are available from www.ansi.org)
REQUIREMENTS
General Tasks Program Management The contractor shall organize, coordinate, and control the program activities to ensure compliance with the contract requirements and the timely delivery of the required product and services. The contractor shall provide the resources necessary to complete the tasks specified in this SOW. The contractor shall maintain active and effective risk management, quality management, and safety programs utilizing existing or internally defined processes. The contractor shall prepare the Integrated Program Management Report (IPMR) (Integrated Master Schedule (IMS)) and the Contractor’s Progress, Status, and Management Report (Monthly Status Report (CPSMR)) In Accordance With (IAW) Contract Data Requirements List (CDRL).
Program Planning The purpose of the program planning process is to produce and communicate effective and workable program plans. The contractor shall define, document, manage, and apply program planning processes IAW IEEE Std 12207-2008, sections 6.1.2.3.4.5, 6.3.1, and 7.1.1.3.1. The contractor shall develop, document, implement, control, and maintain an Integrated Master Schedule (IMS) that presents the contractor’s and subcontractors’ schedules to meet the requirements of the contract. The contractor shall develop and document a tiered scheduling system showing the program milestones and prerequisite events, conferences, reviews, data submittals, and deliveries. The contractor shall construct the IMS to ensure that the program milestones are met and to ensure that deliveries meet the requirements of the contract. The contractor shall revise the IMS, where necessary, to reflect contract changes. The contractor shall use the IMS as a week-to-week execution tool and to periodically assess progress in meeting program requirements. The contractor shall provide an IMS that details weekly resource allocation, weekly planned task progress, event start/finish dates, and milestones dates but shall otherwise minimize IMS size and complexity. The contractor shall prepare the Integrated Program Management Report (IPMR) (Integrated Master Schedule (IMS)) IAW CDRL.
Subcontractor Management and Reporting The contractor shall manage subcontracts, including those that are Firm-Fixed Price (FFP). The contractor shall ensure the timely award of subcontracts, the integration of the subcontractors’ plans into program schedules, and the monitoring of the subcontractors’ staffing plans, to include the execution of those staffing plans to the required levels with the required skills. The contractor shall ensure that the subcontractors’ efforts, to include technical, quality, configuration management, and risk processes are accomplished per contract requirements. The contractor shall ensure that subcontractors use objective criteria to measure performance. The contractor shall integrate the subcontractors’ IPMR into the contractor’s scheduling system. The contractor shall include the subcontractors’ IPMR in the contractor’s IPMR required in the IPMR cited above in 3.1.1.1.
Integrated Product Teams (IPTs) The contractor shall define, document, implement, and maintain an IPT structure for the duration of the contract. IPT membership will consist of multi-functional stakeholders working together with a product-oriented focus. Each IPT will be empowered to make critical life cycle decisions regarding each product or process within their purview. IPTs will be applied at various levels ranging from the overall structure of an organization to informal groups functioning across existing units. With Government input, the contractor shall define and document the composition, structure, roles, and responsibilities of each IPT. Each IPT will maintain a list of membership. Each IPT will consist of Government and contractor personnel and have Government and contractor co-chairs. Each IPT will publish an agenda before each meeting. Each IPT will record and maintain meeting minutes. IPT minutes will be shared among and between the other IPTs.
Risk Management The contractor shall conduct risk management to systematically control the uncertainty to meet cost, schedule, and performance requirements. The contractor shall provide the Government visibility into the contractor’s tools, assessment, mitigation, and control techniques. The contractor shall define, document, manage, and apply a risk management process IAW IEEE 12207-2008, section 6.3.4. The contractor shall participate in the Government Risk Working Group established for this program. The contractor shall report risk information, data, and analysis in the Contractor’s Progress, Status, and Management Report (CPSMR) cited in 3.1.1 above.
Quality Management The contractor shall define, document, manage, and apply a quality management process IAW IEEE 12207-2008, sections 6.2.5 and 7.2.3; and ANSI/ASQ/ISO Q9001-2015 (or equivalent quality management system). The contractor may use ANSI/ASQ/ISO Q9000-2015 and ANSI/ASQ/ISO Q9004-2009 for guidance.
Use of Contractor’s Inspection Equipment The contractor shall make measuring and testing devices available for use by the Government when required to determine conformance with contract requirements. The contractor shall provide the personnel needed to operate such devices and to verify calibration, accuracy, and condition.
Configuration Management (CM) The contractor shall define, document, manage, and apply a CM process IAW IEEE 12207-2008, section 6.3.5 and 7.2.2; and SAE/EIA-649-1 2014. The contractor shall place Government-Furnished Software (GFS), NDI, and Commercial Item software, and each item’s associated documentation under CM upon receipt. The contractor shall place Commercial Item software items under CM as “disk image” files of the physical media.
Change Management The contractor shall define, document, manage, and apply a process to accomplish change management. The contractor shall use Engineering Change Proposals (ECPs) and Requests for Variance (RFVs) to request changes to an approved baseline. The contractor shall prepare the Engineering Change Proposal (ECP) and Request for Variance (RFV) IAW CDRLs.
Configuration Status Accounting The contractor shall define, document, manage, and apply a process to accomplish configuration status accounting. The contractor shall identify and document all items incorporated into or deleted from the training device during development and modification. The contractor shall prepare the Technical Directive (TD) (Training Equipment Change Directive (TECD)) IAW CDRL.
Configuration Audits The contractor shall define, document, manage, and apply a process to accomplish configuration audits. The contractor shall conduct and participate in the Functional and Physical Configuration Audits (FCA and PCA), as specified in 3.2.8.12.2.1 and 3.2.8.12.2.2.
Information Management The contractor shall define, document, manage, and apply an information management process IAW IEEE 12207-2008, section 6.3.6 and 7.2.1. The contractor shall include the status of technical data deliveries in the CPSMR cited above in 3.1.1.
Data Management The contractor shall develop, manage, and implement a data management process for data deliverables. The contractor shall establish and implement procedures to manage the configuration of contractually required data, including data provided by subcontractors. The contractor may use DoD 5010-12M as guidance during the preparation of the CDRL items. The contractor can obtain copies of the Data Item Descriptions (DIDs) cited in the CDRL items from the following web site: http://quicksearch.dla.mil/qsSearch.aspx. The contractor shall ensure that all data item deliverables are delivered without read-write restrictions and without password protection.
Security The security requirements specified herein shall apply to the contractor and subcontractors. The contractor shall comply with applicable on-site security regulations related to government installation and facility access.
Operations Security (OPSEC) [No OPSEC Plan/CDRL] The contractor shall develop, implement, and maintain an OPSEC program to protect controlled unclassified and classified activities, information, equipment, and material used or developed by the contractor and all subcontractors during performance of the contract. Guidelines for applying the Risk Management Framework to federal information systems to include conducting the activities of security categorization, security control selection and implementation, security control assessment, information system authorization, and security control monitoring are provided in NIST SP 800-37. This program may include Cybersecurity and Communications Security (COMSEC). The OPSEC program shall be in accordance with National Security Decision Directive (NSDD) 298. If the contractor does not have an established OPSEC Plan that addresses the protection of, critical information, sensitive, proprietary, or controlled unclassified information, the Government will provide a template for the Contractor’s internal development of an OPSEC Plan. Additional OPSEC program planning guidance can be found in DI-MGMT-80934C, OPERATIONS SECURITY (OPSEC) PLAN and NAVAIR OPERATIONS SECURITY (OPSEC) REQUIREMENTS. The OPSEC program, at a minimum, shall include:
a. Assignment of responsibility for OPSEC direction and implementation
b. Issuance of procedures and planning guidance for the use of OPSEC techniques to identify vulnerabilities and apply applicable countermeasures
c. Establishment of OPSEC education and awareness training to include Basic OPSEC training, produced by the Interagency OPSEC Support Staff (IOSS), which can be found at https://www.iad.gov/ioss/department/opsec-fundamentals-course-opse1300-opse1301-opse1300e-10045.cfm (OPSE1301 OPSEC Fundamentals)
d. Provisions for management, annual review, and evaluation of OPSEC programs
e. Flow down of OPSEC requirements to subcontractors when applicable Unclassified Contractor-Owned Network Security - Safeguarding of Unclassified Controlled Technical Information The safeguarding of Controlled Unclassified Technical Information applies to prime contractors and their subcontractors (if applicable) for information resident on or transiting through contractor unclassified information systems. The contractor shall provide security to safeguard unclassified controlled technical information on their unclassified information systems from unauthorized access and disclosure. The contractor shall take means (defense-in-depth measures) necessary to protect the confidentiality, integrity, and availability of Government controlled unclassified information.
a. The contractor shall manage and maintain contractor-owned unclassified IT network assets used to process U.S. Government controlled unclassified information (sensitive information) IAW DFAR 252.204-7012,
(1) The security requirements in National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171, “Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations,” http://dx.doi.org/10.6028/NIST.SP.800-171 that is in effect at the time the solicitation is issued or as authorized by the Contracting Officer, as soon as practical, but not later than December 31, 2019. The Contractor shall notify the DoD CIO, via email at osd.dibcsia@mail.mil, within 30 days of contract award, of all security requirements specified by NIST SP 800-171 not implemented at the time of contract award; or
(2) Alternative but equally effective security measures used to compensate for the inability to satisfy a particular requirement and achieve equivalent protection accepted in writing by an authorized representative of the DoD CIO; and
b. Apply other information systems security measures when the Contractor reasonably determines that information systems security measures, in addition to those identified in paragraph (b)(1) of DFAR 252.204-7012, may be required to provide adequate security in a dynamic environment based on an assessed risk or vulnerability.
Cyber Incident and Compromise Reporting The contractor shall report to DoD certain cyber incidents that affect unclassified controlled technical information resident on or transiting contractor unclassified information systems set forth IAW DFAR 252.204-7012. The contractor shall also provide the report to the NAWCTSD Contracting Officer, NAWCTSD Security Manager, and the NAWCTSD Information Systems Security Manager (ISSM).
Access to DoD Installations, Government Information, and Information Technology (IT) Systems - Personnel Security Background Checks and DBIDS
a. The Common Access Card (CAC) shall be the principal identity credential for supporting interoperable access to DoD installations and access to U.S. Government information systems IAW FAR 52.204-9. The Defense Biometric Identification System (DBIDS) shall be used for contractors and vendors who do not have a CAC, but only requires access to a base/installation Navy command. The Contractor shall first coordinate with the appropriate NAWCTSD Contracting Officer Representative /Technical Point of Contact or government sponsor to request an application to be process through the NAWCTSD Security Office Trusted Agents for issuance of the CAC or via the Trusted Associate Sponsorship System. The base Visitor Control Center representative will process request for installation access using the DBIDS. More information for obtaining the CAC can be found at http://www.cac.mil/common-access-card/getting-your-cac/for-contractors/ and for DBIDS at https://www.cnic.navy.mil/om/dbids.html.
b. Contractor personnel who do not have a security clearance, but require a CAC in performance of their sensitive duties (including access to controlled unclassified information, but not access classified information), shall coordinate with the NAWCTSD Security Office to complete a National Agency Check with Local Agency Checks including Credit Check (NACLC/TIER- 3) background investigation, which includes submission of fingerprints and the Standard Form SF-86 (Questionnaire for National Security Positions). The contractor shall submit the Standard Form 86 to the NAWCTSD Security Office for processing. There shall be no additional NACLC/TIER-3 submissions for contractors holding a valid national security clearance. The Government may issue the credential upon favorable return of the Federal Bureau of Investigations (FBI) fingerprint check, pending final favorable completion of the NACLC/TIER-3.
c. Access to restricted areas, controlled unclassified information or Government Information Technology by contractor personnel shall be limited to those individuals who have been determined trustworthy as a result of the favorable completion of a NACLC/TIER-3R or who are under the escort of appropriately cleared personnel. Where escorting such persons is not feasible, a NACLC/TIER 3 shall be conducted and favorably reviewed by the appropriate DoD component, agency, or activity prior to permitting such access.
d. The contractor shall comply with the Cybersecurity and personnel security requirements for accessing U.S. Government IT systems specified in the contract. The contractor shall review and become familiar with the credentialing standards presented in OPM Memorandum for Issuing Personal Identity Verification cards to use as an aid in their employee selection process. The NAWCTSD Security Office will apply the credentialing standards and execute the credentialing process for individual contractors.
Personnel Security - Background Checks Contractor personnel shall undergo the company internal vetting process prior to gaining access to U.S. Government controlled unclassified information. To comply with immigration law, the contractor shall use the Employment Eligibility Verification Program (E-Verify) IAW FAR 52.222-54.
International Traffic and Arms Regulation The contractor shall ensure that foreign persons, as defined under section 120.16 of the International Traffic and Arms Regulation (ITAR) (22 CFR, Parts 120 – 130), are not given access to U.S. Government controlled unclassified information, sensitive information, defense articles, defense services, or technical data, as defined in the ITAR, Part 120, without proper issuance of an export license from the U.S. Government authority.
Personnel Security - Reporting of Adverse or Derogatory Information related to Contractors The Contractor shall report to the NAWCTSD Security Office adverse or derogatory information pertaining to on-site CSS personnel (when applicable) or contractor personnel in direct support of this contract. Information reported to the Government Contracting Agency shall be integrated and reported in Contractor Performance Assessment Reporting System (CPARS) on contractor performance of PERsonnel SECurity (PERSEC) related aspects of contractor performance.
a. Adverse or derogatory information reporting of contractor personnel. Example: Domestic Violence arrest, or other violent or sexual crime arrest or self-report.
b. When contractor personnel receive a revocation of an Interim or denial for the issuance of a CAC until final adjudication
c. When a denial or suspension of clearance occurs for a contractor employee
d. When contractor employee receives a final denial of eligibility for a security clearance.
Contractor “Out-processing” Policy The contractor and subcontractor(s) (when applicable) shall have in place (established and enforced ) an “out-processing” policy for employees that leave the company, including suspension of account access, return of all PCs, laptops, smartphones, and other electronic devices (Government-furnished IT equipment and contractor-issued IT equipment) that contain U.S. Government Controlled Unclassified Information. The contractor shall also ensure that out-processed employees receive debriefings on the need to maintain confidentiality of U.S. Government Controlled Unclassified Information.
Government-Issued Personal Identification The contractor and subcontractor(s) (when applicable) shall account for all forms of U.S Government-provided identification credentials (CAC or U.S. Government-issued identification badges) issued to the contractor (or their employees in connection with performance) under the contract. The contractor shall return such identification credentials to the issuing agency at the earliest of any of the circumstances listed below, unless otherwise determined by the U.S. Government. The contracting officer may delay final payment under the contract if the contractor or subcontractor fails to comply with these requirements.
a. When no longer needed for contract performance.
b. Upon completion of the contractor employee’s employment.
c. Upon contract completion or termination Transmission of Controlled Unclassified Information (CUI) via e-mail The Contractor shall use approved encryption to safeguard the electronic transmission of all Controlled Unclassified Information. The Contractor shall ensure that when transmitting CUI over non-secure e-mail (e.g. not connected to the Navy Marine Corps Intranet through Broadband Unclassified Remote Access System / Virtual Private network), those transmissions are encrypted using Department of Defense Public Key Infrastructure (PKI), or an approved DoD External Certificate Authority, in accordance with Public Key Infrastructure & Public Key Enabling, DoDI 8520.02, 24 May 2011.
Transmission of Controlled Unclassified Information (CUI) via S.A.F.E Safe Access File Exchange (SAFE). SAFE is designed to provide an alternative way to send encrypted files other than email. Information regarding the use of SAFE can be found at https://safe.apps.mil/. The contractor shall ensure the following:
a. All files transferred via SAFE shall be for official US Government related business.
b. All files transferred via SAFE shall be UNCLASSIFIED.
c. SAFE cannot be used to transmit classified information
d. All files shall be encrypted Cybersecurity (Navy) When applicable, the contractor shall design, develop, document, integrate, verify, and deliver a security architecture for the trainer that satisfies the DODI 8510.01 Risk Management Framework (RMF) security control set as defined in NIST SP 800-53 Security Categorization as (Confidentiality= Low), (Integrity=Low), (Availability=Low), and meets the IA performance requirements specified in Specification 190016. Implementation of controls shall be tailored in accordance with Naval Air Warfare Center (NAWC) Training Systems Domain Guide, Targets of Evaluation (TOE) Low-Impact Group A (LIGA).
Cybersecurity Assess and Authorize (A&A) Support The contractor shall support the DODI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT), Change 1 dated May 24, 2016 as outlined in the Naval Air Warfare Center (NAWC) Training Systems Domain Guide, Version 1.0 dated September 2016.
Software Integrity Testing and Certification The contractor shall test and certify that the trainer applications software are designed to function in a properly secured operating system environment and is free of elements that might be detrimental to the secure operation of the resource operating system, as described in NIST SP 800-53 . The contractor shall provide a Vendor Compliance Assessment Report for Software (VCARS) for contractor-developed software applications. Commercial Item software does not require a VCARS.
CS Compliance The contractor shall test, verify, and document that the security architecture and configuration of modified trainer components are in compliance with the security requirements and security control set as defined in NIST SP 800-53 Security Categorization as (Confidentiality= Low), (Integrity=Low), (Availability=Low), as further defined in Naval Air Warfare Center (NAWC) Training Systems Domain Guide, Version 1.0 dated September 2016 for TOE LIGA and in Specification 190016. The contractor shall perform and document manual security control assessments, support the government’s Risk Analysis efforts and provide input to the Plan of Actions and Milestones (POA&M) IAW NAWC Training Systems Domain Guide Security Assessment Procedures Document for the Omnibus Standalone-Unclassified Training Systems.
Detailed Tasks Trainer Modification Task The contractor shall perform the following trainer modification task to meet the requirements specified in this SOW and NAWCTSD Specification PRF 190016:
a. Smoke/Fog generation Upgrade
b. Removal of the AFFF system
c. DCWT non-skid repair and resurfacing
d. DCWT Hatch/Scuttle replacements
Systems Engineering Processes The contractor shall use the system engineering processes to define the requirements for the system, to transform the requirements into an effective product, and to verify and validate the functionality of the delivered product.
System Requirements Definition The purpose of the system requirements definition process is to define the requirements for a system that can provide the performance defined in this SOW and NAWCTSD Specification PRF 190016. The contractor shall define, document, manage, and apply a requirements definition process IAW IEEE 12207-2008, section 6.4.1.
Software Detailed Design The purpose of the software detailed design process is to provide a design for the software that implements and can be verified against the requirements and the software architecture, and is sufficiently detailed to permit coding and testing. The contractor shall define, document, control, maintain, and implement software detailed design IAW IEEE Std 42010-2011; IEEE Std 1016-2009; and IEEE/EIA 15289-2011 sections 7.2, 10.20, 10.69, 10.70, and 10.38. The contractor shall prepare the Scientific and Technical Reports (Software Design Description (SDD)) IAW CDRL.
Software Detailed Design Verification The contractor shall perform software detailed design verification IAW IEEE Std 12207-2008, section 7.2.4.3.2.2.
Programming High Order Language(s) (HOL) Selection The contractor shall determine, through a formal process, the HOL(s) for use in the training system. The contractor shall consider development tools, portability, maintainability, and overall life cycle cost in making the selection(s). The contractor shall not utilize platform specific language extensions without Government authorization.
Implementation The contractor shall define, document, control, maintain, and perform implementation IAW IEEE 15288-2008, section 6.4.4.
Software Implementation The contractor shall define, document, control, maintain, and perform software implementation IAW IEEE 12207-2008, section 7.1.1.
Software Unit Construction and Testing The contractor shall define, document, control, maintain, and implement software construction IAW IEEE 12207-2008, section 7.1.5. The contractor shall accomplish software unit testing IAW ANSI/IEEE 1008-1987.
Software Code Verification The contractor shall perform software code verification IAW IEEE 12207-2008, section 7.2.4.3.2.3.
Software Integration The contractor shall define, document, control, maintain, and implement software integration IAW IEEE 12207-2008, section 7.1.6.
Software Integration Verification The contractor shall perform software integration verification IAW IEEE 12207-2008, section 7.2.4.3.2.4.
Software Qualification Testing The contractor shall define, document, control, maintain, and implement software qualification testing IAW IEEE 12207-2008, section 7.1.7.
System Integration The contractor shall define, document, manage, and apply a system integration process IAW IEEE 12207-2008, section 6.4.5.
System Qualification Testing The contractor shall define, document, manage, and apply a system verification process IAW IEEE 12207-2008, section 6.4.6.
Device Transition The contractor shall define, document, manage, and apply a system transition and installation process IAW IEEE 15288-2008, section 6.4.7.
Software Installation The contractor shall define, document, control, maintain, validate, and implement software installation IAW IEEE 12207-2008, section 6.4.7.
Software Product The contractor shall define, document, control, maintain, validate, and prepare the trainer software IAW IEEE/EIA 15289-2011 sections 7.8, and 9.2 Table 4. The contractor shall deliver the software, and databases required to meet the performance defined in this SOW and NAWCTSD Specification PRF 190016. The contractor shall deliver the non-Commercial Item software with corresponding source code, build tools, build procedures, executable code, and configuration information. The contractor shall deliver the Commercial Item software with the associated vendor manuals, documentation, physical media, warranty information, licenses, and installation procedures. The contractor shall transfer to the Government at device acceptance, the Commercial Item software licenses. The contractor shall prepare the Scientific and Technical Reports (Software Product Specification (SPS)) IAW CDRL.
Cold Start Procedures The contractor shall develop, document, control, maintain, validate and prepare, computational subsystem cold start procedures that meet the verification requirements specified in NAWCTSD Specification PRF 190016. The contractor shall prepare a cold start procedure for each computational subsystem that is delivered with associated software source code. The contractor shall prepare a cold start procedure for each computational subsystem that is composed of contractor acquired discrete components (e.g. computer hardware, operating system, and application software), which are then integrated by the contractor. The contractor shall not use a disk image to accomplish a cold-start. The contractor shall develop cold start procedures:
a. For configuring applicable computer hardware settings such as in a Basic Input/Output System (BIOS) or firmware
b. For installing and configuring each operating system, to include user accounts, network connectivity, device drivers, and Cybersecurity controls
c. For installing and configuring each software application
d. For installing the deliverable source code
e. For performing a software build(s) where executable program(s) are created from deliverable source code
f. For introducing Government-authorized source code changes; where the existing software build is removed and a new build is created
g. That consist of detailed descriptive action to be performed; the expected result following the action; and an area to document abnormalities, discrepancies, errors, and pass/fail status
h. That ensure that complex sequences of cold-start actions are broken down into discrete steps
i. That can be accomplished without referring to external documentation
j. That include listing the physical software media required to perform the cold-start
k. That include Commercial Item software activation data, such as serial numbers and key codes Installation and Configuration Procedures The contractor shall develop, document, control, maintain, validate, and prepare the installation and configuration procedures that meet the verification requirements specified in NAWCTSD Specification PRF 190016. The contractor shall prepare installation and configuration procedures for each computational subsystem acquired as a tightly integrated, ready to use turnkey system. Turnkey describes a Commercial Item that is pre-built, in which everything needed is put together by a vendor and sold as a bundle. Examples of turnkey subsystems could include Commercial Item control loaders, aural cueing, and image generators. The contractor shall develop installation and configuration procedures:
a. For configuring applicable computer hardware settings such as in a BIOS or firmware
b. For restoring the system software, such as the operating system, applications and data, to the original delivered configuration.
c. For configuring the system software for use within the training device, such as user accounts, network connectivity, and Cybersecurity controls
d. That consist of detailed descriptive action to be performed; the expected result following the action; and an area to document abnormalities, discrepancies, errors, and pass/fail status
e. That ensure that complex sequences of installation and configuration actions are broken down into discrete steps
f. That can be accomplished without referring to external documentation
g. That include listing the physical software media required to perform the installation and configuration procedure
h. That include Commercial Item software activation data, such as serial numbers and key codes Media and Storage Devices The contractor shall provide to the Government the blank media and mass storage devices necessary to perform each subsystem cold start and installation procedure. The Government will retain custody and control of the media and storage devices created or used by the Government to accomplish testing. The contractor shall provide the additional media and mass storage devices necessary for the contractor’s internal archiving, development, testing, and other engineering and CM purposes.
Cold Start and Installation Procedure Media The contractor shall prepare a unique set of physical media for each computational subsystem. The contractor shall prepare the physical media required to perform each subsystem cold-start procedure with labeling that:
a. Is formatted consistently
b. Is permanently attached to the physical media
c. Identifies the software vendor name
d. Identifies the software product name
e. Identifies the software version number
f. Identifies the software release date
g. Identifies the contractor’s Configuration Control identifier
h. Identifies the total number of media pieces that compose each configured item
i. Identifies the individual piece number within a multiple piece item, such as “Disk 2 of 5” or “DVD 1 of 3” Automated Processes The contractor shall document, control, maintain, and validate all computational automated processes (e.g., scripts, batch files, job control language, kick-start, and slipstreamed media) in the same manner as software items.
Contractor Execution Prior to the start of Test Readiness Review (TRR), the contractor shall execute and validate each subsystem cold start and installation procedure. The contractor shall perform the entire cold start and installation procedure, step-by-step as written, and document the results of each step. The contractor shall present the results of each contractor-run cold start and installation procedure to the Government for review at the following TRR event. The contractor shall execute, document, correct and validate each cold start and installation procedure until no discrepancies exist.
System Validation The contractor shall define, document, manage, and apply a system validation process IAW IEEE 15288-2008, section 6.4.8; and the system Test and Evaluation (T&E) requirements specified herein.
Software Acceptance Support The contractor shall define, document, control, and implement software acceptance support IAW IEEE 12207-2008, section 6.4.8.
E3 Engineering The contractor shall establish an E3 control program that meets the program objectives and assures that the trainer meets the E3 requirements specified in NAWCTSD Specification PRF 190016. The contractor shall incorporate applicable E 3 controls (see items a. through f. below) into the design approach, hardware selection, and the integration of the trainer equipment into the trainer site's electromagnetic environment (EME) specified in NAWCTSD Specification PRF 190016. The contractor shall use E3 design effort which considers the Electrostatic Discharge (ESD) developed by the students operating the trainer. The contractor shall use E3 design effort which considers electromagnetic emissions generated by the equipment in use at the trainer site and the electromagnetic emissions which will be generated by the integration of the trainer equipment into the EME at the installation site(s). During the E3 control planning effort, the contractor shall generate E3 control techniques to be implemented and the verification method by which the contractor shall verify that the trainer meets the specified E3 requirements. The contractor shall include E3 controls as a topic of discussion in the scheduled technical reviews. The contractor shall correct the bonding issues found during testing. The E3 controls shall include:
a. Electromagnetic Environment (EME) - See A.1.4.1
b. Electromagnetic Compatibility (EMC) - See A.1.4.2
c. Electromagnetic Interference (EMI) - See A.1.4.3
d. Electrostatic Discharge (ESD) - See A.1.4.4
e. Lightning effects - See A.1.4.5
f. Electrical bonding - See A.1.4.6 ESD Management The contractor shall establish, implement, and document an ESD control program for the protection of ESD sensitive electrical and electronic parts, assemblies, and equipment from damage due to ESD. Applicable functions where ESD control elements are to be applied are design, production, inspection and test, storage and shipment, installation, maintenance, and repair. The ESD control program elements to be considered are classification, design protection for Trainer Peculiar Equipment (TPE - see A.1.10) only, protected areas, handling procedures, protective coverings, training, marking of hardware, documentation, packaging, quality system requirements, and audits and reviews.
Reliability and Maintainability (R&M) Engineering The contractor shall establish and maintain active and effective R&M programs that meet program objectives. The R&M programs shall ensure that the training system equipment, including Commercial Items (see A.1.1), Commercially available Off-The-Shelf (COTS) items (see A.1.2), NDI (see A.1.8), and TPE (see A.1.10), meet the R&M requirements specified in NAWCTSD Specification PRF 190016. The contractor shall include the R&M programs as topics of discussion during the scheduled program reviews.
Failure Reporting, Analysis and Corrective Action System (FRACAS) The contractor shall establish and maintain a closed loop FRACAS that applies to the failures that occur throughout development, manufacture, handling, checkout, and testing of the trainer equipment, including subcontracted items. Failure analysis shall identify failure causes and the corrective actions. The contractor shall collect maintainability data (e.g., failure isolation, repair, and checkout times) as an integral part of the FRACAS. The contractor shall present a summary of the R&M data collected under FRACAS at the scheduled program reviews.
R&M Predictions The contractor shall develop R&M predictions for the trainer equipment to examine the probability, early in the program, that the R&M requirements of NAWCTSD Specification PRF 190016 will be met with the proposed design. The contractor may use MIL-HDBK-217F as guidance for reliability prediction methods and MIL-HDBK-472 for the maintainability prediction methods.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .