N6426725R1005.pdf
PDF 1 MB Posted
- Attached to
- Information Technology Engineering and Support Services Federal contract opportunity
- Solicitation number
- N6426725R1005
About this file
This is a Request for Proposal (RFP) issued by the Naval Surface Warfare Center Corona Division for Information Technology Engineering and Support Services. The RFP is for a 195-day Cost-Plus-Fixed-Fee "Bridge" contract intended for sole source award to Science Applications International Corporation (SAIC). The work involves maintaining and extending functionality of the Technical Support Management (TSM) Suite, consisting of TSM and Electronic Trial Card (ETC) applications used for collecting and reporting shipbuilding data.
The contractor will provide IT engineering and cybersecurity support services including program/project management, process engineering, documentation, change management, system environment support, system operations support, customization, and upgrades/migrations. Key requirements include maintaining system availability during normal business hours (6:00AM-6:00PM ET M-F), providing two regular software releases per year, and supporting four distinct TSM instances. The period of performance is March 8, 2025 through August 31, 2025, with 13,009 labor hours estimated. Personnel must possess DoD Secret clearances. The proposal submission deadline is February 28, 2025 at 2:00PM local time. A minimum 20% small business subcontracting requirement applies.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 4_Cost Summary Format Spreadsheet.xlsx | XLSX spreadsheet | |
| Attachment 3_Level-of-Effort (LOE).xlsx | XLSX spreadsheet | |
| Ex A_CDRLs.pdf | ||
| Attachment 5_DCAA Rate Check Form.xls | XLS spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
CODE
(Hour)
PAGE(S)
until 02:00 PM local time 28 Feb 2025
X
A X B X C X D
EX
X
G F 45 - 58
59 - 70 X H 71
RATING PAGE OF PAGES
7. ISSUED BY
(Date)
IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.
Previous Edition is Unusable 33-134 STANDARD FORM 33 (REV. 9-97)
Prescribed by GSA FAR (48 CFR) 53.214(c)
1 71
(If other than Item 7)
15A. NAME 16. NAME AND TITLE OF PERSON AUTHORIZED TO
AND
ADDRESS
SIGN OFFER (Type or print)
OF
OFFEROR
AMENDMENT NO. DATE
15B. TELEPHONE NO (Include area code) 17. SIGNATURE15C. CHECK IF REMITTANCE ADDRESS
IS DIFFERENT FROM ABOVE - ENTER
SUCH ADDRESS IN SCHEDULE.
18. OFFER DATE
1. THIS CONTRACT IS A RATED ORDER
UNDER DPAS (15 CFR 700)
2. CONTRACT NO.
N64267 8. ADDRESS OFFER TO
See Item 7
9. Sealed offers in original and 1 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in
CAUTION - LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and conditions contained in this solicitation.
10. FOR INFORMATION
CALL:
A. NAME (NO COLLECT CALLS)
11. TABLE OF CONTENTS
SOLICITATION/ CONTRACT FORM
SUPPLIES OR SERVICES AND PRICES/ COSTS
2 - 4
X I CONTRACT CLAUSES
DESCRIPTION/ SPECS./ WORK STATEMENT X
PACKAGING AND MARKING
5 - 23
J LIST OF ATTACHMENTS
INSPECTION AND ACCEPTANCE
DELIVERIES OR PERFORMANCE
X K
REPRESENTATIONS, CERTIFICATIONS AND
OTHER STATEMENTS OF OFFERORS
CONTRACT ADMINISTRATION DATA 27 - 31 X
SPECIAL CONTRACT REQUIREMENTS
OFFER (Must be fully completed by offeror) 32 - 36 X M
L INSTRS., CONDS., AND NOTICES TO OFFERORS
EVALUATION FACTORS FOR AWARD
NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.
is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.
13. DISCOUNT FOR PROMPT PAYMENT
(See Section I, Clause No. 52.232-8)
14. ACKNOWLEDGMENT OF AMENDMENTS
(The offeror acknowledges receipt of amendments
AMENDMENT NO. DATE
to the SOLICITATION for offerors and related documents numbered and dated):
FACILITY
12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period
SOLICITATION, OFFER AND AWARD
X
(X) SEC. DESCRIPTION (X) SEC. DESCRIPTION PAGE(S)
PART I - THE SCHEDULE
26. NAME OF CONTRACTING OFFICER (Type or print) 27. UNITED STATES OF AMERICA 28. AWARD DATE
EMAIL:TEL: (Signature of Contracting Officer)
CODE CODE
B. TELEPHONE (Include area code) C. E-MAIL ADDRESS
AWARD (To be completed by Government)
19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION
22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:
10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( ) (4 copies unless otherwise specified)
23. SUBMIT INVOICES TO ADDRESS SHOWN IN ITEM
24. ADMINISTERED BY (If other than Item 7) CODE 25. PAYMENT WILL BE MADE BY CODE
PART IV - REPRESENTATIONS AND INSTRUCTIONS
PART III - LIST OF DOCUMENTS, EXHIBITS AND OTHER ATTACHMENTS
37 - 43
PART II - CONTRACT CLAUSES
NAVAL SURFACE WARFARE CENTER CORONA DIV.
1999 FOURTH STREET BLDG 510
NORCO CA 92860
FAX:
TEL:
FAX:
TEL:
NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".
SOLICITATION
6. REQUISITION/PURCHASE NO.5. DATE ISSUED
14 Feb 2025
4. TYPE OF SOLICITATION
SEALED BID (IFB)
NEGOTIATED (RFP)
[ X ]
3. SOLICITATION NO.
N6426725R1005
Section B - Supplies or Services and Prices
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE AMOUNT
1000 13,009 Labor
Hours
Labor
CPFF
Provide support services in accordance with the SOW in Section C.
FOB: Destination
BRAND NAME/SOLE SOURCE: SS
PSC CD: DA01
ESTIMATED COST
FIXED FEE
TOTAL EST COST + FEE
2000 1 Lot
ODC
COST
ODC in support of CLIN 1000.
FOB: Destination
CDRLs
COST
CDRLs in support of CLIN 1000.
FOB: Destination
CLAUSES INCORPORATED BY FULL TEXT
B-216-H006 FEE TABLE (NAVSEA) (MAR 2019)
Labor CLIN Labor Hours Cost Per Hour*
Fee Rate Per Hour*
Loaded Hourly Rate
1000 13,009 TBD TBD TBD
*The offeror shall divide the proposed fee for each CLIN by the quantity of labor hours indicated to complete the table. Fee is calculated based on cost less FCCOM; if FCCOM is proposed, necessary columns may be added.
In the event of any inconsistency between the above table and the CLIN pricing, the CLIN pricing shall take precedence.
(End of text)
B-231-H001 TRAVEL COSTS (NAVSEA) (OCT 2018)
(a) Except as otherwise provided herein, the Contractor shall be reimbursed for its actual travel costs in accordance with FAR 31.205-46. The travel costs to be reimbursed shall be those costs for which the Contractor has maintained appropriate documentation and which have been determined to be allowable, allocable, and reasonable by the Procuring Contracting Officer, Administrative Contracting Officer, or their duly authorized representative.
(b) Reimbursable travel costs include only that travel performed from the Contractor's facility to the worksite, in and around the worksite, and from the worksite to the Contractor's facility.
(c) Relocation costs and travel costs incidental to relocation are allowable to the extent provided in FAR 31.205-35;
however, Procuring Contracting Officer approval shall be required prior to incurring relocation expenses and travel costs incidental to relocation.
(d) The Contractor shall not be reimbursed for the following daily local travel costs:
(i) travel at U.S. Military Installations where Government transportation is available,
(ii) travel performed for personal convenience/errands, including commuting to and from work, and
(iii) travel costs incurred in the replacement of personnel when such replacement is accomplished for the Contractor's or employee's convenience.
B-232-H005 PAYMENTS OF FEE(S) (LEVEL OF EFFORT)--ALTERNATE I (NAVSEA) (OCT 2018)
(a) For purposes of this contract, "fee" means "target fee" in cost-plus-incentive-fee type contracts, "base fee" in cost-plus-award-fee type contracts, or "fixed fee" in cost-plus-fixed-fee type contracts.
(b) The Government shall make payments to the Contractor, subject to and per the clause in this contract entitled "Fixed Fee" (FAR 52.216-8) or "Incentive Fee", (FAR 52.216-10), as applicable. Such payments shall be submitted by and payable to the Contractor pursuant to the clause of this contract entitled "Allowable Cost and Payment" (FAR 52.216-7), subject to the withholding terms and conditions of the "Fixed Fee" or "Incentive Fee" clause, as applicable. Fee paid per hour shall be based on total fee dollars divided by total hours to be provided. Total fee(s) paid to the Contractor shall not exceed the fee amount(s) set forth in this contract. In no event shall the Government be required to pay the Contractor any amount in excess of the funds obligated under this contract.
B-232-H006 LIMITATION OF COST OR LIMITATION OF FUNDS CLARIFICATION (NAVSEA) (OCT 2018)
The clause entitled "Limitation of Cost" (FAR 52.232-20) or "Limitation of Funds" (FAR 52.232-22), as appropriate, shall apply separately and independently to each separately identified estimated cost.
Section C - Descriptions and Specifications
STATEMENT OF WORK
TECHNICAL SUPPORT
MANAGEMENT (TSM)
INFORMATION TECHNOLOGY ENGINEERING AND SUPPORT SERVICES
1. GENERAL
1.1. Introduction
The Naval Sea Systems Command (NAVSEA), Supervisor of Shipbuilding, Conversion and Repair (SUPSHIP) Management (SEA 04Z) requires information technology (IT) engineering and support services to maintain and extend functionality of the Technical Support Management (TSM) Suite consisting of the TSM application and the Electronic Trial Card (ETC) application. These services will be provided to maintain and improve the collection and reporting of shipbuilding data collected by SUPSHIP activities and to ensure compliance with cybersecurity requirements.
The contractor shall provide support for performing the activities necessary to ensure the successful operation and maintenance of the enterprise TSM suite. It is expected that the TSM suite will be available at all times except during periods of routine maintenance. Support shall be provided in accordance with standard best practices, policies and procedures as defined by NAVSEA.
The contractor must have experience with the operations of the SUPSHIP as it relates to shipbuilder oversight. This includes specifically, but not limited to, the operations of the Quality Assurance Department, Engineering Department, Projects Office and Contracts Department. Additionally, the contractor must have experience with naval ship trials processes to include SUPSHIP, Navy Program Office and Navy Board of Inspection and Survey (INSURV).
1.2. Background
NAVSEA 04Z is located at the Washington Navy Yard, DC and provides oversight and management support to the four SUPSHIPs. The SUPSHIPs, as the Administration Contracting Office (ACO) for all new ship construction contracts and for all private sector ship repair contracts, provides oversight of these contracts. As part of this oversight requirement, the SUPSHIPs are required to document and track all material, process technical deficiencies to ensure correction of these deficiencies prior to contract completion.
The TSM suite is a custom designed contractor operated software application. It is the database and workflow management application used to document and track to completion, all material, process and technical discrepancies identified during the course of ship construction and repair.
The TSM application will be centrally hosted and is currently located at the Component Enterprise Data Center (CEDC) Charleston. The contractor will be required to interface with the CEDC staff to maintain the TSM application, assure system access, conduct system testing, and manage system security on a day-to-day basis. The contractor will also be required to support any transition to an alternate hosting facility if necessary.
The TSM Application consists of four distinct instances. One test and one production instance supports Unclassified Naval Nuclear Propulsion Information (U-NNPI) shipbuilding data and one test and one production environment supports conventional shipbuilding data. Additionally, the contractor will be required to maintain a separate development environment and test environment at the contractor’s facility for development and testing. The test environment must be accessible to NAVSEA designated users from both government and contractor locations. These environments must adhere to all Department of Defense (DoD) cybersecurity requirements. No U-NNPI will be stored at the contractor’s development environment.
There shall be no disruption in TSM operation, emergent updates, routine updates, service, accreditation or ship trials support during the transition from the current support contractor to the new contractor.
1.3. Scope
This Performance Work Statement (PWS) defines the technical and system administrative support services required to support the development and maintenance of TSM technical implementation and development, user training, software development, quality assurance, operational oversight, and includes user support, system migrations, cybersecurity support, incorporation of other systems and or software to facilitate integration with TSM, and data and records management.
In the performance of these tasks, the contractor shall have a thorough knowledge and understanding in the following areas:
• Application and Web development
• Configuration management and logistics support
• Database administration
• Help desk/end user support
• Network and application security
• System administration
• Testing and related quality standards and processes
• SUPSHIP processes for oversight of Naval ship construction
• Ship trials processes (SUPSHIP, Program Office & INSURV)
The contractor shall advise and assist the Government, but shall not make final decisions or certifications on behalf of the Government nor perform inherently Governmental functions. The contractor and its employees shall not represent the government nor appear to represent the Government in performance of these contract services. At all meetings, conferences, or sessions with the Government personnel, contractor personnel shall clearly identify their status as contractor employees.
2. REFERENCES
The following references are applicable to meeting qualifications, providing technical support services, or implementing cybersecurity requirements as they apply to support the TSM Suite.
Additional Security Requirement Guides may be applied as required.
Document How it applies
S0300-B2-MAN-010, SUPSHIP Operations Manual (Most current version)
Business and oversight process of the Supervisor of Shipbuilding.
SECNAV M-5210.2, Standard Subject Identification Code (SSIC) Manual (Most current version)
Records Management; defines how document life cycles are to be managed: identification and numbering, archival instructions, and disposal instructions.
SECNAV M-5239.2, Cyberspace Information Technology And Cybersecurity Workforce Management And Qualification Manual (Most current version)
There are three sections of the policy that apply to TSM. It outlines user roles, configuration management, and user identification and authentication.(i.e. something you know, and something you have)
National Institute of Standards and Technology (NIST) Special Publication 800-34 Revision 1 Contingency Planning Guide for Federal Information Systems (Most current version)
This document outlines contingency plans required for a system (including TSM) in case of a catastrophic failure, and includes things such as Disaster Recovery Plans and Business Impact Analysis.
DoDI 8551.01 Ports and Protocols and Service Management (PPSM) (Most current version)
This describes the system for scanning and patching DOD computers. Regular vulnerability assessments are conducted and NSWC IHEODTD IT is required to correct for vulnerabilities.
DoDM 8140.03, Cyberspace Workforce Qualification and Management Program (Most current version)
Implements policy, assigns responsibilities, and prescribes procedures for the qualification of personnel identified as members of the DoD cyberspace workforce. Identifies members of the DoD cyberspace workforce based on the cyberspace work role(s) of the position(s) assigned, as described in DoD Instruction (DoDI) 8140.02
DoDI 8500.01-M Change 1, Cybersecurity (Most current version)
Addresses architectural requirements for DoD Systems and servers to enforce vulnerability assessments and remediation as specified in 8570.01M; Requires PKI authentication in accordance with DOD regulations.
DoDI 8510.01 Risk Management Framework (RMF) for DOD Information Technology (IT) (Most current
Prescribes that all IT systems must be configured to the proper STIG and that all IT services external to version) the DOD must comply with DOD information assurance policies.
Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) (Most current version)
Guidance to secure operating systems, database systems, database name spaces, and applications.
DISA Application Security and Development STIG (Most current version)
Guidance for third party software configuration and software development.
DoD, DoN, and local IT and Cybersecurity procedures, mandates, standards and guides (Most current version)
Procedures, mandates, standards and guides are not optional and must be followed as they are distributed.
Note: The Government will provide access to the above documents at the time of award.
3. REQUIREMENTS
3.1. Workplace/Worksite
NAVSEA 04Z requires TSM operations support during normal business hours (6:00AM to 6:00PM M- F Eastern Time) with the exclusion of weekends and Federal holidays under normal working conditions. The Contracting Officer's Representative (COR) may adjust the business days or working hours as necessary to facilitate workload needs and funding requirements.
All contractor work shall be performed at contractor facilities.
3.2. Access to Proprietary Data or Computer Software
All information, data, configuration settings, code modifications, software, or other relevant information related to the TSM Suite administration, functionality development, operational support, and specifications is For Official Use Only Unclassified Data or Unclassified-Naval Nuclear Propulsion Information depending on the instance. Performance under this contract may require that the contractor have access to technical data, computer software, or other sensitive data of another party who asserts that such data or software is proprietary.
3.3. Cybersecurity Workforce (CSWF)
3.3.1. Qualifications
All contractor CSWF personnel must meet and sustain the qualification requirements for their duties in accordance with SECNAV M-5239.2, Cyberspace Information Technology and Cybersecurity Workforce Management and Qualifications Manual (Jun 2016) (including Appendix 4 thereto), including: meeting all job qualification standards; holding one or more Operating System (OS)/Computing Environment (CE) credential(s) and/or certificate(s) of training (if applicable);
sustaining the requisite on the job training (OJT), continuous learning requirements (CLR), and CSWF qualification requirements; and completing Annual Cybersecurity Awareness training, all in in accordance with SECNAV M-5239.2 and the below instructions:
The contractor shall not hire any personnel to the CSWF who do not meet the minimum CSWF qualification requirements for the functions they will be performing. These include: (1) qualifications that must be met or achieved before the contractor CSWF personnel begin performing under this contract; (2) qualifications that must be met or achieved within a specified period of time after the contractor CSWF personnel have begun performance under this contract; and (3) ongoing qualification requirements that must be met or achieved while the contractor CSWF personnel are performing under this contract. The CSWF qualifications applicable to each labor category, and when such qualifications must be met or achieved, are listed in the Cybersecurity Workforce manual. The contactor shall be responsible for ensuring all contractor CSWF personnel performing under this contract continue to meet all qualification requirements during performance, and do not allow certifications or other credentials to lapse during contract performance.
Privileged Access – Those contractor CSWF personnel who require privileged access as defined in SECNAV M-5239.2 must complete a Privileged Access Agreement (PAA) (to be provided by the Government) and meet the training/certification requirements for each OS and/or CE for which they shall have privileged access. Further, all such contractor CSWF personnel are required to have a satisfactorily adjudicated security clearance, including a single scope background investigation (SSBI), and may be subject to random polygraph examinations.
CSWF Category and Specialty Area – Specific cybersecurity functions are associated with a CSWF Category and Specialty Area. The CSWF Categories are groups of common major cybersecurity functions. The Specialty Areas are further subdivisions within each Category that represent areas of concentrated work or functions within cybersecurity. Contractor CSWF personnel may perform duties in more than one Specialty Area; in which case such personnel must meet the qualification requirements for each of the Specialty Areas under which they perform.
Continuous Learning Requirements (CLR) – The contractor shall ensure all contractor CSWF personnel performing under this contract comply with all CLR and other requirements necessary to keep their certifications, credentials, and other CSWF qualification requirements current. The costs required for contractor CSWF personnel to meet CLR or to otherwise maintain a specific expertise or commercial certification are not a direct contractor cost to the Government. The contractor shall not invoice or charge the Government for costs for training, certification tests, or other expenses related to contractor CSWF personnel’s CLR, certifications, or other training.
Additionally, per SECNAV M-5239.2, all personnel performing cybersecurity functions, including contractor CSWF personnel, are required to complete annual cybersecurity awareness training and to participate in at least 40 hours of continuous learning per year. This requirement is separate from any CLR necessary for certification and qualification maintenance, although continuous learning hours obtained in the course of qualification or certification maintenance may be counted towards the annual 40 hour continuous learning requirement. The contractor is responsible for tracking that its contractor CSWF personnel performing under this contract achieve the required 40 hours of continuous learning.
3.3.2. Qualification Tracking
The contractor is responsible for ensuring the qualifications and certification status of all contractor CSWF personnel, as described in SECNAV M-5239.2 (including the most current version of Appendix 4 thereto), are identified, documented, and tracked. The contractor shall ensure all contractor CSWF personnel are in compliance with all CSWF requirements, including qualification, certification, training, and CLR, and shall track its contractor CSWF personnel’s compliance with the CSWF requirements at all times while these personnel are performing under this contract.
The contractor shall notify the COR if any contractor CSWF personnel fails to obtain or maintain any CSWF qualification(s) during contract performance and replace such personnel to remain in compliance with the contract. Upon request, the contractor shall provide evidence to the COR documenting that its personnel have all necessary certifications and qualifications and have met all CLR, including requirements for certification(s), certification maintenance, and proof of continuing education and/or sustainment training required for cybersecurity functional responsibilities.
The contractor shall not invoice the Government for any services provided by any contractor CSWF personnel during any time such personnel are not meeting and maintaining all CSWF requirements without explicit written permission from the Contracting Officer to do so.
3.3.3. Acceptance of Responsibility
The contractor CSWF personnel shall accept responsibility for the duties and responsibilities assigned to them as members of the CSWF. This includes their responsibilities with regard to maintaining the security posture of Government ISs and/or networks to which they are assigned, reporting cybersecurity concerns or issues affecting those ISs and/or networks, and maintaining CSWF qualifications. The contractor shall therefore be responsible to the Government, as a corporate entity, for all responsibilities accepted by its personnel performing under this contract.
3.3.4. Removal from the CSWF
The contractor shall terminate contractor CSWF personnel’s appointment to the CSWF, removing such personnel from the CSWF (which shall terminate their authorization to have privileged access and all other authorization(s) to perform cybersecurity functions on ISs), upon the end of contract performance, or upon any of the following conditions:
• The personnel are no longer performing under this contract;
• The personnel are no longer performing cybersecurity functions under this contract;
• For any reason determined by the contractor, provided suitable replacement contractor CSWF personnel is/are provided to perform the function(s) the contractor CSWF personnel had been performing.
The contractor shall immediately notify the Contracting Officer and the COR, in writing, when any contractor CSWF personnel are removed from the CSWF and the reason(s) for the personnel’s removal.
4. TASKS
Final documentation resulting from requirements in this section will be stored on the NMCI intranet file share location established for SEA04Z as identified by the TPOC (Technical Point of Contact) or Contracting Officer. These documents support the SEA 04Z TSM/ETC System Capabilities Document and the TSM/ETC Operations and Maintenance Plan developed and maintained by the TPOC which provides overarching operational plans for the system.
The TSM Information Technology Engineering and Support Services for NAVSEA 04Z shall include the following:
4.1. PROGRAM/PROJECT MANAGEMENT
Provide program/project management, application configuration management and operational maintenance services to the NAVSEA and the US Navy Supervisors of Shipbuilding, Conversion and
Repair (SUPSHIPs). At times, the contractor may be required to provide specific on-site support at a given SUPSHIP site to address specific needs as required and authorized by NAVSEA 04Z.
The contractor shall attend in-process reviews, scheduling, planning, configuration management, coordination, or other applicable meetings in support of the NAVSEA 04Z and shall document meeting content, decisions, directions, and action items.
The contractor shall establish and maintain the NAVSEA 04Z project schedule with sufficient detail to establish baseline times for new functionality development, cost estimates, and estimates for corrective actions. Details will include initial estimates with actual performance adjustments.
The contractor shall develop new functionality at the direction of the COR or the TPOC.
4.2. PROCESS ENGINEERING
The contractor shall provide process engineering support to improve process simplification, process reliability, and preventive maintenance.
The contractor shall track and report on system availability, utilization, and downtime with incident reports submitted within 8 business hours of an identified system failure. Incident reports (or trouble tickets) shall be tracked to closure with a status summary reported to the COR/TPOC on a weekly basis.
4.3. DOCUMENTATION
Documentation is critical to ensure that the TSM configuration documentation is readily available to maintain the Authority to Operate (ATO), resolve issues, facilitate audits, and maintain continuity. As necessary, the contractor may review documents such as current system specifications, standard operating procedures, methods, data forms, and reports to gain a knowledge foundation.
The contractor will prepare SOPs, configuration, and other documentation that the NAVSEA Cybersecurity office may need to attain or maintain an ATO and shall update the documentation and user information annually.
The contractor shall develop and maintain current state workflow diagrams, training materials, and other documentation specific to the operation of TSM.
The contractor shall develop and update annually a TSM System Specification document detailing at the minimum: hardware and software lifecycle information (including replacement cost estimates), system architecture with port & protocol information, version information for all software used to support TSM (including replacement cost estimates).
The contractor shall document and maintain license details for all software used to support TSM.
The contractor shall maintain TSM and ETC help documentation. Help documentation will be updated with each software release.
The contractor shall maintain & update the TSM and ETC System Capabilities Document (SCD) and the TSM and ETC Operations and Maintenance Plan to ensure it reflects all software and system updates and provide updated documents within 60 days of each software version release.
Develop and maintain software release installation packages that describe all Software Change Requests (SCRs), installation notes and software version information for each software version release.
Maintain & update the TSM and ETC Data Dictionary to ensure it reflects all software and data updates and provide the updated Data Dictionary within 30 Days of each software release. (CDRL A001)
4.4. CHANGE MANAGEMENT
Change management is critical to guaranteeing modifications are consistent with the long-term system plan. Change control is vital to maintain the TSM Suite in an audit-ready state and maintain processes, procedures, and other documentation which support ATO.
The contractor shall document modifications applied to the server or development environment(s).
This includes patches, version updates, security updates, and configuration or setting changes.
The contractor shall separately document system configuration changes per server.
The contractor shall document each custom software component or code prior to implementation and delivery on production systems.
4.5. SYSTEM ENVIRONMENT SUPPORT
4.5.1 Operating System and Environment
The Component Enterprise Data Center (CEDC) Charleston maintains the Red Hat Server operating system security and underlying architecture via VMWare. Their function includes patching, securing, imaging, rebuilding, and using snapshots to facilitate server-level image backups.
The contractor shall monitor the operating system environment state and shall report and coordinate remediation activities with the CEDC and NAVSEA when issues arise with the operating system environment or server images.
The contractor shall perform software installation, setup, and maintenance.
The contractor shall notify and coordinate with the TPOC and CEDC Charleston when major changes or alterations to systems, codes, software, or subsystems occur to maintain cybersecurity and ensure appropriate image data is retained.
4.5.2. Database
The contractor shall maintain the Oracle Server instances to include software updates, patch installation, security configurations, settings, and documentation as applicable and necessary to attaining or maintaining the ATO and document any STIGs or other security settings that interrupt system operations in accordance with cybersecurity mandates and guidance.
The contractor shall maintain the individual name space(s) within the application to include patch installation, security configurations, settings, and documentation as applicable and necessary to attaining or maintaining the ATO and document any STIGs or other security settings that interrupt system operations in accordance with cybersecurity mandates and guidance.
The contractor shall document and maintain the database schema per name space used and shall document configuration alterations or modifications to include at a minimum, the source of change, date of change, impacted functionality, and rationale.
The contractor shall support database backups, imports, exports and data refreshes. Database backups shall be maintained by the CEDC Charleston.
The contractor shall monitor and maintain the security of databases through application use of user role assignments.
4.5.3. Application
The contractor shall maintain the TSM Suite to include software updates, patch installation, security configurations, and settings as applicable and necessary to attaining or maintaining the ATO and document any STIGs or other security settings that interrupt system operations.
The products and tools used in the development and maintenance of the TSM Suite include but are not limited to Red Hat, Java, JavaScript, Oracle Enterprise Edition, Oracle Enterprise Manager Cloud Control, WebLogic Server, Prime Faces, Eclipse Neon, SQL Developer, Visual Studio, Visual Basic.Net, Apache Subversion, Bugzilla and Assured Compliance Assessment Solution (ACAS).
The contractor shall provide two regular software releases per year per application. Additional emergent releases will be provided as necessary and as directed by the COR. All software changes will be approved by the TSM Configuration Control Board or the COR prior to development.
The contractor shall establish and maintain access control and user management procedures.
The contractor shall maintain passwords, file permissions, and all required system integrity procedures.
The contractor shall provide support and maintain all documentation for application certification, accreditation, ATOs and Risk Management Framework.
4.5.4. COTS Software
The contractor shall only use approved third-party software as permitted by the Department of Navy Application and Database Management System (DADMS).
The contractor shall register and maintain third-party software approval in DADMS as needed to support the TSM Suite.
The contractor shall periodically review TSM software DADMS entries to ensure compliance with Last Install Date or Last Use Date and provide the NAVSEA 04Z COR and TPOC a notification and recommended resolution guidance 9 months prior to expiration.
The contractor shall monitor major COTS applications for new versions or upgrades and will notify the COR and TPOC to impacts and schedule activities when identified.
4.6. SYSTEM OPERATIONS SUPPORT
The primary functions of the contractor are to provide cybersecurity support, system upgrade support, and system development. However, system operations support may be needed to recover from production bugs and system issues. While supporting system operations the contractor may not make inherently governmental decisions and may not operate outside the boundaries established without the consent of the COR and the TPOC.
The contractor shall develop and maintain a training program for the TSM Suite as necessary and make training materials available to SUPSHIP local administrators. The contractor may be required to provide onsite user training as directed by the COR.
The contractor will provide Help Desk services during normal business hours (0600 - 1800 ET, Monday through Friday, except for Federal Holidays). The contractor will operate and maintain the TSM Help Desk software application, manage, process and maintain all user accounts for the SUPSHIP communities and SUPSHIP designated stakeholders.
Application and maintenance releases may require work outside of the normal business hours. This is to be considered routine work and will be accomplished without the use of overtime.
Provide Help Desk Status Report including the Trouble Ticket metrics, Trouble Ticket details and daily server response time metrics (CDRL A002).
The contractor shall provide troubleshooting support during normal business hours with a response time of not more than two hours to any critical issues that may arise.
The contractor shall assist users in the event of a TSM Suite issue. Such incidents will be documented to include at a minimum: requestor, time of day, request description, cause/root cause, and corrective action.
While resolving TSM Suite issues, the contractor shall communicate with the user(s) the status of the issue resolution and ensure that the user(s) is satisfied with the solution.
The contractor shall manage all data spill responses to include scripts for cleaning any data spill.
4.7. CUSTOMIZATION
The contractor shall develop custom software or code as applicable to enable or enhance functionality.
The contractor shall perform and submit a basic business case analysis (for major functionality changes) or rationale and gain approval prior to developing custom solutions.
The contractor shall either develop or implement custom applications to expand the TSM Suite functionality.
4.8. UPGRADES, MIGRATIONS AND TRANSITIONS
The contractor shall assist the government in performing a business case analysis, analysis of alternatives, or other process to evaluate alternative information management systems as necessary.
Prior to an upgrade, migration, or transition the contractor shall review database schemas and resolve data model conflicts.
Prior to an upgrade, migration, or transition the contractor shall review workflows to assess functional changes and shall plan necessary functional change solutions as part of a migration plan.
The contractor will ensure that no application, upgrade, migration, customization, or transition is implemented without testing and evaluation in the contractor’s development and test environments as well as in the production test environment. When appropriate and with approval of the COR/TPOC, the contractor will request user evaluation of all TSM Suite implementations and upgrades to ensure that there are no major issues with defective TSM Suite software or configuration.
During an upgrade, migration, or transition the contractor shall validate that technical data fully transfers and resolve any issues.
4.9. TSM SUITE CONTINUOUS IMPROVEMENT
NAVSEA 04Z desires to continue improving the TSM Suite by improving functionality and interfaces, improving database performance and streamlining operations. These improvements must be evaluated prior to implementation and have an established positive return on investment, a defined business need, or directed by the COR or TPOC and documented in a business case analysis.
Potential improvements with dependencies that preclude the ability to capitalize on improvements after completion will not be developed.
5.0 SECURITY
All Personnel with access to production data associated with this delivery order must possess a DoD “secret” clearance. See para. 3.3.1 for additional security requirements for CSWF personnel. All deliverables associated with this task order are “unclassified” unless otherwise specified.
Security Clearances shall be in accordance with the DD254, Attachment 1.
The Contractor will be required to receive, store, and generate Controlled Unclassified Information (CUI) for this contract and will follow security guidance pertaining to CUI as listed on the DD 254.
The Contractor is required to protect critical information associated with this contract to prevent unauthorized disclosure and will observe Operations Security (OPSEC) requirements.
The Contractor shall possess a SECRET facility clearance and provide safeguarding of SECRET documents.
6.0 PERIOD OF PERFORMANCE
The period of performance shall be from 8 March 2025 through 31 August 2025.
Acronyms and Definitions:
ACAS – Assured Compliance Assessment Solution ACO – Administration Contracting Office
ATO – Authority to Operate
CDRL – Contract Data Requirement List
CE – Computing Environment
CEDC – Component Enterprise Data Center
CLR – Continuous Learning Requirement
COR – Contracting Officer’s Representative
CSWF – Cybersecurity Workforce
DADMS – Department of Navy, Application and Database Management System
DISA – Defense Information Systems Agency
ECMRA – Enterprise-wide Contractor Manpower Reporting Application
ETC – Electronic Trial Card
INSURV – Navy Board of Inspection and Survey
IT – Information Technology
NAVSEA – Naval Sea Systems Command
NIST – National Institute of Standards and Technology OJT – On-the-Job Training
OS – Operating System
PAA – Privileged Access Agreement
PSC – Product Service Code
PPSM – Ports and Protocols and Service Management PWS
– Performance Work Statement
RMF – Risk Management Framework
SCD – System Capabilities Document
SCRs - Software Change Request
C-202-H001 ADDITIONAL DEFINITIONS–BASIC (NAVSEA) (OCT 2018)
(a) Department - means the Department of the Navy.
(b) Commander, Naval Sea Systems Command - means the Commander of the Naval Sea Systems Command of the Department of the Navy or his duly appointed successor.
(c) References to The Federal Acquisition Regulation (FAR) - All references to the FAR in this contract shall be deemed to also reference the appropriate sections of the Defense FAR Supplement (DFARS), unless clearly indicated otherwise.
(d) National Stock Numbers - Whenever the term Federal Item Identification Number and its acronym FIIN or the term Federal Stock Number and its acronym FSN appear in the contract, order or their cited specifications and standards, the terms and acronyms shall be interpreted as National Item Identification Number (NIIN) and National Stock Number (NSN) respectively which shall be defined as follows:
(1) National Item Identification Number (NIIN). The number assigned to each approved Item Identification under the Federal Cataloging Program. It consists of nine numeric characters, the first two of which are the National Codification Bureau (NCB) Code. The remaining positions consist of a seven digit non-significant number.
(2) National Stock Number (NSN). The National Stock Number (NSN) for an item of supply consists of the applicable four-position Federal Supply Class (FSC) plus the applicable nine-position NIIN assigned to the item of supply.
C-204-H001 USE OF NAVY SUPPORT CONTRACTORS FOR OFFICIAL CONTRACT FILES (NAVSEA)
(OCT 2018)
(a) NAVSEA may use a file room management support contractor, hereinafter referred to as "the support contractor", to manage its file room, in which all official contract files, including the official file supporting this procurement, are retained. These official files may contain information that is considered a trade secret, proprietary, business sensitive or otherwise protected pursuant to law or regulation, hereinafter referred to as “protected information”. File room management services consist of any of the following: secretarial or clerical support; data entry; document reproduction, scanning, imaging, or destruction; operation, management, or maintenance of paper-based or electronic mail rooms, file rooms, or libraries; and supervision in connection with functions listed herein.
(b) The cognizant Contracting Officer will ensure that any NAVSEA contract under which these file room management services are acquired will contain a requirement that:
(1) The support contractor not disclose any information;
(2) Individual employees are to be instructed by the support contractor regarding the sensitivity of the official contract files;
(3) The support contractor performing these services be barred from providing any other supplies and/or services, or competing to do so, to NAVSEA for the period of performance of its contract and for an additional three years thereafter unless otherwise provided by law or regulation; and,
(4) In addition to any other rights the contractor may have, it is a third party beneficiary who has the right of direct action against the support contractor, or any person to whom the support contractor has released or disclosed protected information, for the unauthorized duplication, release, or disclosure of such protected information.
(c) Execution of this contract by the contractor is considered consent to NAVSEA's permitting access to any information, irrespective of restrictive markings or the nature of the information submitted, by its file room management support contractor for the limited purpose of executing its file room support contract responsibilities.
(d) NAVSEA may, without further notice, enter into contracts with other contractors for these services. Contractors should enter into separate non-disclosure agreements with the file room contractor. Contact the Procuring Contracting Officer for contractor specifics. However, any such agreement will not be considered a prerequisite before information submitted is stored in the file room or otherwise encumber the government.
C-211-H018 APPROVAL BY THE GOVERNMENT (NAVSEA) (JAN 2019)
Approval by the Government as required under this contract and applicable specifications shall not relieve the Contractor of its obligation to comply with the specifications and with all other requirements of the contract, nor shall it impose upon the Government any liability it would not have had in the absence of such approval.
C-227-H006 DATA REQUIREMENTS (NAVSEA) (OCT 2018)
The data to be furnished hereunder shall be prepared in accordance with the Contract Data Requirements List, DD Form 1423, Exhibit(s) A, attached hereto.
(End of Text)
C-227-H009 ACCESS TO DATA OR COMPUTER SOFTWARE WITH RESTRICTIVE MARKINGS (NAVSEA)
(JAN 2019)
(a) Performance under this contract may require that the Contractor have access to technical data, computer software, or other sensitive data of another party that contains restrictive markings. If access to such data or software is required or to be provided, the Contractor shall enter into a written agreement with such party prior to gaining access to such data or software. The agreement shall address, at a minimum, (1) access to, and use of, the restrictively marked data or software exclusively for the purposes of performance of the work required by this contract, and (2) safeguards to protect such data or software from unauthorized use or disclosure for so long as the data or software remains properly restrictively marked. In addition, the agreement shall not impose any limitation upon the Government or its employees with respect to such data or software. A copy of the executed agreement shall be provided to the Contracting Officer. The Government may unilaterally modify the contract to list those third parties with which the Contractor has agreement(s).
(b) The Contractor agrees to: (1) indoctrinate its personnel who will have access to the data or software as to the restrictions under which access is granted; (2) not disclose the data or software to another party or other Contractor personnel except as authorized by the Contracting Officer; (3) not engage in any other action, venture, or employment wherein this information will be used, other than under this contract, in any manner inconsistent with this requirement; (4) not disclose the data or software to any other party, including, but not limited to, joint venturer, affiliate, successor, or assign of the Contractor; and (5) reproduce the restrictive stamp, marking, or legend on each use of the data or software whether in whole or in part.
(c) These restrictions on use and disclosure of the data and software also apply to information received from the Government through any means to which the Contractor has access in the performance of this contract that contains restrictive markings.
(d) The Contractor agrees that it will promptly notify the Contracting Officer of any attempt to gain access to any information with restrictive markings. Such notification shall include the name and organization of the individual, company, or Government representative seeking access to such information.
(e) The Contractor shall include this requirement in subcontracts of any tier which involve access to information covered by paragraph (a), substituting "subcontractor" for "Contractor" where appropriate.
(f) Compliance with this requirement is a material requirement of this contract.
C-227-H010 COMPUTER SOFTWARE AND COMPUTER DATA BASES DELIVERED TO OR RECEIVED
FROM THE GOVERNMENT (NAVSEA) (JAN 2019)
(a) The Contractor agrees to test for viruses, malware, Trojan Horses, and other security threats such as those listed in NIST Special Publication 800-12 Rev 1, An Introduction to Computer Security, The NIST Handbook, Chapter 4, in all computer software and computer data bases (as defined in the clause entitled “Rights In Noncommercial Computer Software and Noncommercial Computer Software Documentation” (DFARS 252.227-7014)), before delivery of that computer software or computer data base in whatever media and on whatever system the computer software or data base is delivered whether delivered separately or imbedded within delivered equipment. The Contractor warrants that when delivered any such computer software and computer data base shall be free of viruses, malware, Trojan Horses, and other security threats such as those listed in NIST Special Publication 800-12 Rev 1.
(b) The Contractor agrees that prior to use under this contract, it shall test any computer software and computer data base received from the Government for viruses, malware, Trojan Horses, and other security threats listed in NIST Special Publication 800-12 Rev 1, An Introduction to Computer Security, The NIST Handbook, Chapter 4.
(c) Any license agreement governing the use of any computer software or computer software documentation delivered to the Government as a result of this contract must be paid-up, irrevocable, world-wide, royalty-free, perpetual and flexible (user licenses transferable among Government employees and personnel under Government contract).
(d) The Contractor shall not include or permit to be included any routine to enable the contractor or its subcontractor(s) or vendor(s) to disable the computer software or computer data base after delivery to the Government.
(e) No copy protection devices or systems shall be used in any computer software or computer data base delivered under this contract with unlimited or Government purpose rights (as defined in DFARS 252.227-7013 and 252.227- 7014) to restrict or limit the Government from making copies.
(f) It is agreed that, to the extent that any technical or other data is computer software by virtue of its delivery in digital form, the Government shall be licensed to use that digital-form data with exactly the same rights and limitations as if the data had been delivered as hard copy.
(g) Any limited rights legends or other allowed legends placed by a Contractor on technical data or other data delivered in digital form shall be digitally included on the same media as the digital-form data and must be associated with the corresponding digital-form technical data to which the legend(s) apply to the extent possible.
Such legends shall also be placed in human-readable form on a visible surface of the media carrying the digital-form data as delivered, to the extent possible.
C-237-H002 SUBSTITUTION OF KEY PERSONNEL (NAVSEA) (OCT 2018)
(a) The Contractor agrees that a partial basis for award of this contract is the list of key personnel proposed. Accordingly, the Contractor agrees to assign to this contract those key persons whose resumes were submitted with the proposal necessary to fulfill the requirements of the contract. No substitution shall be made without prior notification to and concurrence of the Contracting Officer in accordance with this requirement.
Substitution shall include, but not be limited to, subdividing hours of any key personnel and assigning or allocating those hours to another individual not approved as key personnel.
(b) All proposed substitutes shall have…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .