N68335-15-R-0178_Solicitation.pdf

PDF 973 KB Posted

Attached to
NAWC-AD 4. 8. 1 Engineering and Technical Support Services Federal contract opportunity
Solicitation number
N68335-15-R-0178
Issued by
Department of the Navy Naval Air Systems Command Naval Air Warfare Center

About this file

Solicitation

View the file

Other files for this federal contract opportunity

Other files attached to NAWC-AD 4. 8. 1 Engineering and Technical Support Services, newest first.
File Type Posted
RFI_24_Nov_2015.pdf PDF
N68335-15-R-0178-0001_Solicitation.pdf PDF
RFI_16_Nov_2015.pdf PDF
QASP_for_Engility_follow-On.pdf PDF
Attachment_P3_Past_Performance_Questionnaire.doc DOC document
Attachment_P2_Wokforce_Hour_Matrix.xls XLS spreadsheet
CDRLs_A001_through_A004_for_Engility_follow-On_b.pdf PDF
Attachment_P1_Wokforce_Qualifications.xls XLS spreadsheet
DD_254_signed_N68335-15-R-0178.pdf PDF
Attachment_P4_Cost-Price_Spreadsheet.xls XLS spreadsheet

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

CODE

(Hour)

PAGE(S)

until 11:00 AM local time 16 Dec 2015

X

A

X B

X C

D

EX

X

G

F 55 - 60

61 - 82

X H 83 - 89

RATING PAGE OF PAGES

7. ISSUED BY

(Date)

IMPORTANT - Award will be made on this Form, or on Standard Form 26, or by other authorized official written notice.

Previous Edition is Unusable 33-134 STANDARD FORM 33 (REV. 9-97)

Prescribed by GSA

FAR (48 CFR) 53.214(c)

1 89

(If other than Item 7)

15A. NAME 16. NAME AND TITLE OF PERSON AUTHORIZED TO

AND

ADDRESS

SIGN OFFER (Type or print)

OF

OFFEROR

AMENDMENT NO. DATE

15B. TELEPHONE NO (Include area code) 17. SIGNATURE15C. CHECK IF REMITTANCE ADDRESS

IS DIFFERENT FROM ABOVE - ENTER

SUCH ADDRESS IN SCHEDULE.

18. OFFER DATE

1. THIS CONTRACT IS A RATED ORDER

UNDER DPAS (15 CFR 700)

2. CONTRACT NO.

N68335 8. ADDRESS OFFER TO

See Item 7

9. Sealed offers in original and 3 copies for furnishing the supplies or services in the Schedule will be received at the place specified in Item 8, or if handcarried, in the depository located in

CAUTION - LATE Submissions, Modifications, and Withdrawals: See Section L, Provision No. 52.214-7 or 52.215-1. All offers are subject to all terms and

N/A conditions contained in this solicitation.

10. FOR INFORMATION

CALL:

A. NAME (NO COLLECT CALLS)

11. TABLE OF CONTENTS

SOLICITATION/ CONTRACT FORM

SUPPLIES OR SERVICES AND PRICES/ COSTS

1 - 2

3 - 10

X I CONTRACT CLAUSES

DESCRIPTION/ SPECS./ WORK STATEMENT X

PACKAGING AND MARKING

11 - 24 J LIST OF ATTACHMENTS

INSPECTION AND ACCEPTANCE

DELIVERIES OR PERFORMANCE

26 - 28 X K

REPRESENTATIONS, CERTIFICATIONS AND

OTHER STATEMENTS OF OFFERORS

CONTRACT ADMINISTRATION DATA 29 - 33 X

SPECIAL CONTRACT REQUIREMENTS

OFFER (Must be fully completed by offeror) 34 - 37 X M

L INSTRS., CONDS., AND NOTICES TO OFFERORS

EVALUATION FACTORS FOR AWARD

NOTE: Item 12 does not apply if the solicitation includes the provisions at 52.214-16, Minimum Bid Acceptance Period.

is inserted by the offeror) from the date for receipt of offers specified above, to furnish any or all items upon which prices are offered at the price set opposite each item, delivered at the designated point(s), within the time specified in the schedule.

13. DISCOUNT FOR PROMPT PAYMENT

(See Section I, Clause No. 52.232-8)

14. ACKNOWLEDGMENT OF AMENDMENTS

(The offeror acknowledges receipt of amendments

AMENDMENT NO. DATE

to the SOLICITATION for offerors and related documents numbered and dated):

FACILITY

12. In compliance with the above, the undersigned agrees, if this offer is accepted within calendar days (60 calendar days unless a different period

SOLICITATION, OFFER AND AWARD

X

(X) SEC. DESCRIPTION (X) SEC. DESCRIPTION PAGE(S)

PART I - THE SCHEDULE

26. NAME OF CONTRACTING OFFICER (Type or print) 27. UNITED STATES OF AMERICA 28. AWARD DATE

EMAIL:TEL: (Signature of Contracting Officer)

CODE CODE

B. TELEPHONE (Include area code) C. E-MAIL ADDRESS

AWARD (To be completed by Government)

19. ACCEPTED AS TO ITEMS NUMBERED 20. AMOUNT 21. ACCOUNTING AND APPROPRIATION

22. AUTHORITY FOR USING OTHER THAN FULL AND OPEN COMPETITION:

10 U.S.C. 2304(c)( ) 41 U.S.C. 253(c)( ) (4 copies unless otherwise specified)

23. SUBMIT INVOICES TO ADDRESS SHOWN IN ITEM

24. ADMINISTERED BY (If other than Item 7) CODE 25. PAYMENT WILL BE MADE BY CODE

PART IV - REPRESENTATIO NS AND INSTRUCTIO NS

PART III - LIST O F DO CUMENTS, EXHIBITS AND O THER ATTACHMENTS

38 - 53

PART II - CO NTRACT CLAUSES

NAVAL AIR WARFARE CENTER AD (LKE)

CODE 2.5.2.2.3 BLDG 562-3

HWY 547

LAKEHURST NJ 08733-5082

FAX:

TEL:

FAX:

TEL:

NOTE: In sealed bid solicitations "offer" and "offeror" mean "bid" and "bidder".

SOLICITATION

6. REQUISITION/PURCHASE NO.5. DATE ISSUED

05 Nov 2015

4. TYPE OF SOLICITATION

SEALED BID (IFB)

NEGOTIATED (RFP)

[ X ]

3. SOLICITATION NO.

N68335-15-R-0178

Section A - Solicitation/Contract Form

POINTS OF CONTACT

Proposals under NAWCADLKE’s Request for Proposal (RFP) number N68335-15-R-0178 shall be submitted prior to 16 DEC 2015 11:00 AM EST to:

Naval Air Warfare Center Aircraft Division

Hwy 547 Bldg. 562-3 RM 307

Attn: Lisa Bethea, 25223

JBMDL, NJ 08733

Section B - Supplies or Services and Prices

ITEM NO SUPPLIES/SERVICES MAX

QUANTITY

UNIT UNIT PRICE MAX AMOUNT

0001 UNDEFINED

Labor

CPFF

Ordering Year I: In accordance with Section C, Statement of Work (SOW) and

Quality Assurance Surveillance Plan (QASP), Attachment 1

FOB: Destination

MAX COST

FIXED FEE

TOTAL MAX COST + FEE

UNIT UNIT PRICE MAX AMOUNT

0002 UNDEFINED

Labor

CPFF

Ordering Year II: In accordance with Section C, Statement of Work (SOW) and

UNIT UNIT PRICE MAX AMOUNT

0003 UNDEFINED

Labor

CPFF

Ordering Year III: In accordance with Section C, Statement of Work (SOW) and

UNIT UNIT PRICE MAX AMOUNT

0004 UNDEFINED

Labor

CPFF

Ordering Year IV: In accordance with Section C, Statement of Work (SOW) and Quality Assurance Surveillance Plan (QASP), Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0005 UNDEFINED

Labor

CPFF

Ordering Year V: In accordance with Section C, Statement of Work (SOW) and

UNIT UNIT PRICE MAX AMOUNT

0006 UNDEFINED

Travel

COST

Ordering Year I: In accordance with Section C, SOW and QASP, Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0007 UNDEFINED

Travel

COST

Ordering Year II: In accordance with Section C, SOW and QASP, Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0008 UNDEFINED

Travel

COST

Ordering Year III: In accordance with Section C, SOW and QASP, Attachment

UNIT UNIT PRICE MAX AMOUNT

0009 UNDEFINED

Travel

COST

Ordering Year IV: In accordance with Section C, SOW and QASP, Attachment

UNIT UNIT PRICE MAX AMOUNT

0010 UNDEFINED

Travel

COST

Ordering Year V: In accordance with Section C, SOW and QASP, Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0011 UNDEFINED

Material

COST

Ordering Year I: In accordance with Section C, SOW and QASP, Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0012 UNDEFINED

Material

COST

Ordering Year II: In accordance with Section C, SOW and QASP, Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0013 UNDEFINED

Material

COST

Ordering Year III: In accordance with Section C, SOW and QASP, Attachment

UNIT UNIT PRICE MAX AMOUNT

0014 UNDEFINED

Material

COST

Ordering Year IV: In accordance with Section C, SOW and QASP, Attachment

UNIT UNIT PRICE MAX AMOUNT

0015 UNDEFINED

Material

COST

Ordering Year V: In accordance with Section C, SOW and QASP, Attachment 1

UNIT UNIT PRICE MAX AMOUNT

0016 UNDEFINED

CDRLs

Ordering Year I: In accordance with Section C, SOW and QASP, Attachment 1.

Not Seperately Priced.

UNIT UNIT PRICE MAX AMOUNT

0017 UNDEFINED

Ordering Year II: In accordance with Section C, SOW and QASP, Attachment

1. Not Seperately Priced.

UNIT UNIT PRICE MAX AMOUNT

0018 UNDEFINED

Ordering Year III: In accordance with Section C, SOW and QASP, Attachment

UNIT UNIT PRICE MAX AMOUNT

0019 UNDEFINED

Ordering Year IV: In accordance with Section C, SOW and QASP, Attachment

UNIT UNIT PRICE MAX AMOUNT

0020 UNDEFINED

Ordering Year V: In accordance with Section C, SOW and QASP, Attachment

CLAUSES INCORPORATED BY FULL TEXT

5252.211-9503 LEVEL OF EFFORT (COST REIMBURSEMENT) (NAVAIR)(DEC 2012)

(a) The level of effort estimated to be ordered during the term of this contract is 470,400 man-hours of direct labor including authorized subcontract labor, if any. The contractor shall not, under any circumstances, exceed one hundred (100%) percent of the total level of effort specified in this basic contract. The estimated composition of the total man-hours of direct labor by classification is as follows: See Section L.

(b) FAR Clause 52.232-20, "Limitation of Cost" applies to fully funded orders and FAR Clause 52.232-22, "Limitation of Funds" applies to incrementally funded orders. Nothing in this clause amends the rights or responsibilities of the parties hereto under either of those two clauses. In addition, the notifications required by this clause are separate and distinct from any specified in either FAR Clause 52.232-20 or FAR Clause 52.232-22.

(c) In the event that less than one hundred (100%) percent of the established level of effort of the contract/order is actually expended by the end of the performance period, the Government shall have the option of:

(1) Requiring the Contractor to continue performance, subject to the provisions of the FAR Clause 52.232-20 or

52.232-22, as applicable, until the effort expended equals 100% of the established Level of Effort; or

(2) Effecting a reduction in the fixed fee by the percentage by which the total expended man-hours is less than one hundred (100%) percent of the established Level of Effort.

(d) The contractor agrees that effort performed in fulfillment of level of effort obligations under this contract shall include only verifiable effort in direct support of the work specified. It shall not include efforts such as work performed in transit to or from an employee's usual workplace, work during lunchtime activities, or effort performed at other non-work locations.

(e) In performing the contract/order, the contractor may use any reasonable combination of hours for the labor categories in support of section C of this contract/order.

Section C - Descriptions and Specifications

STATEMENT OF WORK

STATEMENT OF WORK (SOW) FOR ENGINEERING SERVICES FOR SUPPORT

EQUIPMENT (SE) AND AIRCRAFT LAUNCH AND RECOVERY EQUIPMENT (ALRE)

1.0 INTRODUCTION

This SOW defines the requirements for engineering and technical services needed in support of the Naval Air Systems Command (NAVAIR) Support Equipment (SE) and Aircraft Launch and Recovery Equipment (ALRE) Department.

2.0 BACKGROUND

The SE and ALRE department, through several engineering divisions (SE and ALRE Systems Engineering, ALRE Hardware Engineering, and ALRE Software Engineering) provides engineering and technical services for development and maintenance of many SE and ALRE product lines. The products are associated with launch, recovery, visual landing aids, or with maintenance of aircraft aboard Navy ships and Marine Corps airfields. The engineering and technical services generally fall into the following categories:

Requirements development and management including identification, validation, and verification of SE and ALRE systems

Design, development, modification, and maintenance of SE and ALRE systems

Introduction of capabilities and systems to the fleet

Aircraft and ship integration to enable new combinations of Aircraft and platforms to operate together.

3.0 SCOPE

The scope of this effort is to provide engineering and technical support as delineated in the tasks below.

4.0 APPLICABLE DOCUMENTS

The government will provide all necessary reference documents not generally available to the contractor as required. Throughout the life of the contract, if any instruction or document is replaced or superseded, the replacement or superseding instruction or document shall be applicable to the requirements defined in this sow.

5.0 PERFORMANCE REQUIREMENTS

The contractor shall provide technical support to the NAVAIR Lakehurst SE and ALRE department. The support will be accomplished in accordance with the paragraphs below.

5.1 Systems Engineering - The contractor shall follow NAVAIR systems engineering processes and procedures. The contractor shall gather engineering data necessary to perform sound systems engineering and resolve any technical issues as they arise. These efforts may require on-site technical support and guidance. Systems engineering support that the contractor shall provide includes but is not limited to the following:

5.1.1 – Perform requirements development and management including decomposition of operational requirements, development of functional requirements, allocation of requirements to hardware or software critical items specifications, architectural analysis with internal and external interface requirements, and the verification and validation of requirements. The contractor shall provide support to the team in documenting these requirements with inputs to such work products as the Systems Design Specification (SDS) and Component Performance Specification (CPS).

5.1.2 – Assist the government in developing acquisition related documents such as the System Engineering Plan (SEP), Requirements Analysis Document (RAD), Work Breakdown Structure (WBS), and Integrated Master Schedule (IMS).

5.1.3 – Perform trade studies and market research to evaluate new systems or upgrades and modifications to existing systems, which would increase performance, capability, efficiency, or life expectancy of SE and ALRE systems, and produce a technical report to document findings.

(CDRL A001, TECHNICAL REPORT)

5.1.4 – Perform engineering process modeling and optimization, which includes analysis of aviation operations and development of computer based process models in Pro-Model to optimize flight deck operations for ALRE and SE systems.

5.1.5 – Participate in program and technical meetings in support of designated projects. These meetings include but are not limited to, the Aircraft Procurement Navy (APN) conference, Blue Book reviews, Program Management Reviews (PMRs), Technical Interchange Meetings (TIMs), Working Groups (WGs), Systems Engineering Technical Reviews (SETRs), and the ALRE conference. The contractor shall provide meeting minutes to document issues and actions.

(CDRL A002, REPORT, RECORD OF MEETING / MINUTES)

5.1.6 - Assist the government in identifying program risks, in performing risk analysis, and identifying possible mitigations as part of the government risk management process.

5.1.7 – Assist the government in preparing for Systems Engineering Technical Reviews (SETRs), including performing analysis to determine if entry and exit criteria have been met.

5.1.8 –Review engineer drawings, test plans and design reports to help assess technical maturity of system design efforts.

5.1.9 – Review existing systems engineering processes to identify improvements that can be made or introduce new processes where necessary.

5.2 ALRE Hardware Engineering - The contractor shall perform a broad range of engineering design and analysis such as thermodynamic, power consumption, light budget, shock, vibration and finite element analysis, and documentation services in support of system, subsystem, or component design. Tasks to be performed may include, but are not limited to, design analysis utilizing computer based analysis tools such as P-Spice, Matlab, Simulink, Labview, Pro-Engineer, ALGOR, and Mechanica, preparation of technical drawings (including CAD drawings in AUTOCAD and 3-D models and use of Microsoft Office or other products to produce graphs and charts. The contractor shall provide support for capturing and filtering historical shipboard maintenance information; allocating this data into preventative and corrective maintenance levels; correlating data into mapped lowest system level indentures; and applying minor statistical analysis. The contractor shall support the program milestone events and help track processes to ensure objectives are met.

(CDRL A001, TECHNICAL REPORT)

5.2.1 – ALRE modernization of launcher and recovery systems and components. The contractor shall support development and/or fabrication of production representative designs. Production representative designs will require all the defined work products, such as technical analysis and drawings with minimal tailoring. Technology demonstration work products will be tailored as required. Work products should include specific requirements documents, design documents, and test documents.

5.2.2 – Expeditionary Air Field (EAF) modernization of landing surface systems, ancillary devices, arresting gear components, lighting systems. .The contractor shall support the development of next generation systems by analyzing strength of materials, assessing aircraft loads on equipment and assuring aircraft compatibility. The contractor will troubleshoot electric circuits, perform optics analysis, and apply and assess night vision technologies.

5.2.3 – Visual L anding A ids (VLA) and shipboard information system modernization including flight deck marking and lighting, and visual and optical landing aid systems. The contractor shall provide research capabilities to support engineering programs relating to next generation VLA systems and night vision device compatible systems.

5.3 ALRE Software Engineering - The contractor shall perform design and development in accordance with associated Systems Engineering Plan (SEP) and corresponding Software Development Plan (SDP) as applicable. The contractor shall help produce, test, and deliver source code, executable code, and associated drawings, and shall provide support for development integration into various SE and ALRE systems. The contractor shall assist in developing software design documentation in accordance with IEEE 12207. Contractor shall assist in operating and maintaining the environment for performing the software engineering function. This includes software configuration management, quality assurance, test, System Administration and infrastructure support.

Software development efforts shall comply with ASN memorandum, Software Process Improvement Initiative (SPII) guidance for use of software process improvement contract language dated 13 July 2007, ““computer software development” or “software development” means, as applicable developing or delivering new source code, modifying existing source code, coding computer instructions and data definitions, building databases schema, and performing other activities needed to implement the design of a noncommercial computer software product. This definition recognized that even small changes to software code can result in significant changes to software system behavior and quality, and, consequently, that it is necessary for developers to define and follow disciplined and appropriate processes.”

Cybersecurity tasks include completing Certification and Accreditation (C&A) activities and analysis required for the Department of Defense (DoD) Information Assurance Certification and Accreditation Process (DIACAP), and related future processes when implemented. Several components make up a C&A package including, but not limited to C&A plan, Implementation Plan, Test Plan, Incident Response Plan (IRP), Contingency Plan, Disaster Recovery Plan (DRP), ACAS scan results, DISA STIG results, Risk Assessment Report (RAR), and other supporting artifacts.

Additional tasks include support to the Functional Area Managers (FAMs) and DON Application and Database Management System (DADMS), the detailed list of software applications, as well as the DoD Information Technology Portfolio Repository-DON (DITPR-DON). Support with acknowledging, reporting applicability, reporting compliance or non-compliance, and creating or submitting mitigation plans for Information Assurance Vulnerability Management (IAVM) and Communication Task Orders (CTOs) in the Online Compliance Reporting System (OCRS). OCRS will be replaced with Vulnerability Remediation Asset Management (VRAM).

Programs and systems consist of, but are not limited to, heterogeneous operating env ironments such as Windows, Linux, and Unix based Operating Systems (OSs), real time OSs, and embedded OS based platforms. Networking equipment may or may not also be included within the accreditation boundary of the supported programs. Systems can be networked or non-networked running commercial off the shelf, Government off the shelf, system unique, and/or government mission related information platform applications.

5.4 Aviation Ship Integration (ASI) Systems Engineering - The contractor shall assist in conducting analysis to identify all aircraft and ship compatibility and integration issues. This includes the functional and physical interfaces between aircraft and ships that ensure operability, supportability, and maintainability and includes but is not limited to aircraft spotting, securing, handling and suitability for naval operations. It includes all aviation support systems required to operate aircraft on board US. Navy ships and could include SE and ALRE installation requirements room arrangements, interfaces to ship and other systems, aircraft maintenance, servicing, armament handling and storage.

5.5 Circuit Board requirements and diagnostics and repair includes diagnosing failures on circuit cards using advanced tools and techniques, repairing failures, certifying repair, and developing new technologies to improve capability to diagnose and repair failures. The contractor shall provide support services in accordance with the Naval Sea Systems Command (NAVSEA) Module Test and Repair (MTR) program and the DODMTR pinpoint test routine development requirements manual for the component level diagnostic lab at Lakehurst. In addition, the contractor shall support as required technological advances to the program with analysis, development, and integration of new technology that enhances our product to the fleet.

The contractor shall maintain the acceptable rate of circuit card test routine development for each technician of between three and five completed and certified test routines each quarter. Technicians will also provide verification of fleet developed Pinpoint and Protrack diagnostic test routines.

Government will review Shop Replaceable Assemblies (SRAs)/ Circuit Card Assemblies (CCAs) (Ready for Issue where practicable) and analyze for development of diagnostic test routines. Contractor shall provide engineering and other work required to evaluate suitability of these SRAs/CCAs for development of diagnostic test routines using the Pinpoint II test system.

Program development will follow the DOD MTR pinpoint test routine development requirements manual (NAVAIR 16-30USM676-1)) that establishes programming standards for applicability across services, and the MTR gold disk test routine development requirements manual (NAVY ST821-AG-PRO-010).

5.6 Integrated Diagnostics and Automated Test Systems (IDATS) is for developing an environment for aircraft diagnostics and testability. This includes working with diagnostics equipment that stimulates avionics equipment and analyzes signal outputs to determine proper operation. This will be accomplished using data mining, networking, hand held O-level testers with reach-back capability, and data warehousing through an integrated network.

The contactor shall perform network engineering support for design, development, testing and procurement of IDATS/ISE Navy and Marine Corps aviation support systems. The contractor shall perform trade studies to identify ways to insert IDATS solutions into the fleet to help reduce maintenance workload.

The contractor shall provide technical support of the IDATS laboratory including update of the Facilities Requirements Document (FRD) to define any new facility capability, footprint, power requirement, sound attenuation, instrumentation, data acquisition and analysis, control room monitoring, maintenance/calibration and PMA product support. The scope also includes supporting the construction and installation of laboratory by monitoring progress via facilities requirements documentation in accordance with a previously completed FRD.

5.7 Integrated Support Environment (ISE) network and information systems support includes creating an ISE to manage SE and ALRE engineering and in-service support. This includes developing an information system linking diagnostics, maintenance, supply, training, and manufacturing to determine SE/ALRE equipment proper readiness and support levels. This environment will utilize data mining, networking, maintenance and parts utiliza tion database information, and data warehousing through an integrated network. The contractor shall provide network expertise to the ISE team in the following areas:

network architecture based on the business needs network protocols, equipment, and communications network hardware/software configurations information assurance in response to Information Operations Condition

(INFOCON)

disaster recovery plan acquisition documents for the procurement of new and modified end -items of avionics SE, including specifications and other documents required to procure SE

5.7.1 Provide planning, management and operational support for the SE automated engineering design team. Support will include planning and processing of hardware and software acquisitions, obtaining approvals for hardware and software upgrades, and performing operations and maintenance on the RDT&E network, engineering work stations, design/analytical software and associated hardware and telecommunication equipment used for SE design, development, in-service engineering, and staging.

5.7.2 Develop short and long range plans to identify requirements to support the SE automated engineering design system on the NMCI and RDT&E networks. This will include identification of Information Technology (IT) requirements and preparation of the IT approval packagess in accordance with FAM, DADMS, acquisition, NMCI and RDT&E security requirements. This includes planning and coordinating set up and connection for new system users.

5.7.3 Provide daily support for the SE automated engineering design system. Support will include hardware/software installation and upgrade, system backup, troubleshooting, technical assistance to system users, and verifications of user compliance. The contractor will perform Information Assurance and system administration, and determine impacts of navy IT security data calls and information initiatives. The contractor shall interface with center engineering and IT personnel in providing the above support.

5.7.4 Provide operational support for the SE automated engineering design system. Support shall include assistance in operation of engineering workstations, the PC operating systems platforms, and associated software. The contractor shall manage the SE RDT&E network hardware, software and servers, and establish files for system users and the storage of drawings and other technical data. Contractor support shall also include management of hardware, software and lab information in spreadsheets and databases, and development and maintenance of technical data for planning and operating the SE automated engineering design system.

All IA shall be in compliance with NAVAIR policy and associated instructions.

5.8 Provide Miscellaneous support

Provide support to identify risks to the development, acceptance, production, or implementation of SE or ALRE systems. This includes trade studies to identify resolutions to technical problems.

Support the planning, management and execution of upgrades and installation of change packages. This includes field service support of SE and ALRE systems, including training of fleet personnel.

Provide engineering and technical services to reverse engineer portions of SE or ALRE and other equipment which could be the result of parts obsolescence or lack of an original technical data package.

Develop, produce, and provide inputs for documentation of SE, ALRE and related systems and prototypes as required.

Provide services to improve the quality and effectiveness of SE, ALRE and related systems. This may include process improvement efforts.

6.0 GENERAL REQUIREMENTS

All Information Technology (IT) procured on behalf of NAVAIR shall meet all DOD, DON and NAVAIR Information Assurance (IA) policies. Failure to follow these policies will result in denied access to NMCI, one net, Integrated Shipboard Network System (ISNS) and other DON, DOD and joint networks. These IA policies are standard across the department and ensure IA compatibility and interoperability.

IT systems and or networks operated by contractors subsequent to a NAVAIR Contract, regardless of the level of data processed shall be operated in accordance with the NISPOM.

Contractor-owned equipment shall be permitted connections to NAVAIR/DOD Networks in order to carry out the performance of this contract. All contractor-owned hardware and/or software shall meet DODI

8500.2 IA Controls, is subject to validation scanning and must be approved by the NAVAIR site IA manager prior to connection. The following specific criteria must be met before being connected to any DOD or NAVAIR network in support of this contract:

A. Network vulnerability scanning. NAVAIR deputy CIO for Information Assurance maintains authorized auditing tools and shall provide for firewall/port scans, device discovery scan, vulnerability assessment, and other requirements as required to ensure secure interoperability with DOD contracts. The contractor shall be responsible for the remediation of any equipment that fails these audits prior to the connection the system to the networks; results of approvals shall be documented via memorandum of agreement with the facility security officer and the defense security service representative for that contractor;

B. Extent of validation scanning. To prevent scanning of “corporate” assets, all such networks, equipment and connections shall be physically segregated from any government/contractor “corporate” networks that are not in direct support of DOD contracts;

C. Circuit provisioning. Any circuit or connection between NAVAIR and/or DOD site and the contractor site shall be provisioned via the defense information security agency and comply with CJCSI 6211.02c (series), “Defense Information System Network (DISN): policy and responsibilities,” 9 July 2008;

D. Servicing systems from a remote contractor site. Remote access service connections that allow off-station operation and/or administration of contractor owned systems, located at any NAVAIR facility or site, shall not be permitted, with the exception of those systems connecting to the command via the outreach services identified in section 7, enterprise architecture;

E. Memorandum of Agreement and inter-connection agreements. An Information Assurance memorandum of agreement (MOA) between the contractor owning the equipment and AIR-7.2.6 shall be developed and signed before the equipment can be connected to NAVAIR networks. Failure to comply with the signed MOA shall be grounds for disconnection from the Network.

F. Contractor networks and connections. Contractor-owned and operated networks are prohibited on any Naval Air Systems Command (NAVAIR) facility or site in support of this contract. The contactor may access non-government, external Internet Protocol (IP) space via the NAVAIR provided Virtual Private Network (VPN) outreach service or NAVAIR CIO approved Internet Protocol (IP) service.

G. Architecture compliance. The contractor shall ensure all IT Solutions, including database solutions, comply with the appropriate NAE enterprise architecture, and are verified by the NAVAIR enterprise architect (AIR-7.2.3) prior to build out.

H. Disclosure of pre-existing networks, circuits or connections. Any and all networks, circuits or connections between the contractor and any NAVAIR site related to previous contracts shall be identified in the MOA. Failure to comply and subsequent discovery of an unregistered network, Circuit or connection shall be grounds for immediate disconnection.

I. It approval. The contractor shall not purchase any it equipment on behalf of NAVAIR in support of this contract without a NAVAIR CIO signed IT approval

7.0 SECURITY

7.1 Only U.S. citizens may perform under this contract. The contractor will hold a Top Secret

Facility Security Clearance. All personnel performing Information Technology (IT) duties will have the necessary background investigation IAW SECNAV Instruction 5510-36 and NAVAIR Security Instruction 5510.1b. All personnel must be able to obtain a clearance at the Secret level. Personnel required to work at the Government’s site must, at a minimum, obtain an Interim Secret Clearance prior to starting work at the Government’s facility. The minimum level of personnel security clearance required to perform tasking under this contract is Secret.

7.2 The contractor may be required to generate or handle documents, manuals, drawings, or other material classified up to and including secret as specified in the DD254. The contractor will be authorized SIPRNet for the purpose of performing Information Assurance duties for purpose of Cyber Security threat analysis, and will require NATO Secret access.

7.3 Data developed for this effort shall be unclassified or of the lowest classification consistent with the information contained herein and in accordance with the requirements of National Industrial Security Program Operating Manual (NISPOM) dated January 1995.

7.4 Contractor personnel may be required to perform services in navy spaces that have security classification up to secret. Any classification guidance needed will be provided by the navy activity, and contractor personnel will need to be cleared at the level required for working in those spaces.

7.5 OPSEC - The contractor is to develop, implement, and maintain a facility level OPSEC program to protect classified and sensitive information to be used, handled, discussed, processed, stored, transmitted, or delivered at a Government facility during performance of this contract.

The contractor is responsible for subcontractor implementation of OPSEC requirements for this contract. An OPSEC plan is to be developed, and submitted to NAVAIR within 90 days of contract award for acceptance and approval.

(CDRL A003, OPSEC Plan)

8.0 CONTRACTOR PROGRESS REPORTING

The contractor shall plan and manage each technical services effort in accordance with its proposed program management approach. The contractor shall provide a monthly progress, status, and management report that contains the following information in performing the requirements of any tasking:

milestones, deliverable status, project status, and financial status. One report shall be issued each month

(CDRL A004, Contractor’s Progress, Status and Management Reports)

9.0 DELIVERABLES

9.1 The contractor shall submit engineering and technical reports. These reports shall be submitted on an as needed basis as tasks are assigned by NAVAIR.

(CDRL A001, Engineering and Technical Reports)

9.2 The contractor shall provide meeting minutes to document issues and actions.

(CDRL A002, Report, Record of Meeting / Minutes)

9.3 The contractor shall submit an OPSEC Plan, in accordance with the Security section of this document.

(CDRL A003. OPSEC Plan)

9.4 The contractor shall submit a monthly status report. The report shall include both a progress report on all ongoing tasks and a cumulative summary of all man hours expended, organized by labor category and funds expended, remaining, travel material, and other direct charges.

(CDRL A004, Contractor’s Progress, Status and Management Reports)

Information Technology and Information Assurance (IA) Related Constraints

The Government will provide all necessary reference documents not generally available to the Contractor as required. Throughout the life of the contract, if any instruction or document is replaced or superseded, the replacement or superseding instruction or document shall be applicable to the requirements defined in this SOW.

The Contractor shall not purchase any Information Technology (IT) equipment on behalf of NAVAIR in support of this Contract without a Naval Air Systems Command (NAVAIR) Command Information Officer (CIO) signed "IT" approval.

It is the Government's responsibility to ensure that any "IT" procurement (hardware/hardware maintenance, software/software maintenance, support services, web services, telecommunications, etc.) procured by the Contractor under the scope of this Contract/Task Order that contains "IT" meet the following requirements.

1. Clinger-Cohen Act:

In 1996, Congress enacted the Clinger-Cohen Act (CCA) requiring agencies to use a disciplined capital planning and investment control process to acquire, use, maintain and dispose of information technology. In accordance with the following Department of Defense Directive (DoDD), Department of Defense Instruction (DoDI), Office of the Secretary of Defense (OSD) memo, and Secretary of the Navy Instruction (SECNAVINST), CCA compliance is required for all programs that contain IT, including IT in weapons and weapons system programs. The law provides authority to the agency’s Chief Information Officer (CIO) to manage IT resources effectively. The authority to grant compliance with CCA and approve the Information Assurance (IA) strategy depends on the Acquisition Category (ACAT). DoDD Number 5000.01 “The Defense Acquisition System,” May 12, 2003, Certified Current as of November 20, 2007

a. DoDI 5000.02, “Operation of the Defense Acquisition System,” December 8, 2008

b. OSD Memo, “Clinger-Cohen Act Compliance Policy,” Mar 8 2002 c.SECNAVINST 5000.2D, “Implementation and Operation of the Defense Acquisition System and the Joint Capabilities Integration and Development System,” October 16, 2008

2. System Software / Application Compliance:

"All Information Technology Systems or software/application development, modification or support shall be performed in accordance with Defense Business Transformation guidance (formerly Business Management Modernization Program (BMMP)), Department of the Navy (DON)/Naval Air Systems Command (NAVAIR) Functional Area Manager (FAM) Policies and Guidance, Network and Server Registration, and Web Enablement mandates."

3. Web Sites, Web Enablement and Application / System Development, Modification, and Maintenance Support Services:

“All Information Technology systems, software, and website development, modification or support shall be performed in accordance with all applicable Federal, DoD, DON, and NAVAIR policy, guidance, standards, and strategies, and should be integrated within the NAVAIR Enterprise portal and collaboration environment whenever possible. Any Web sites/servers hosted/located in contractor facilities, or outside NAVAIR enclave, will transition to NAVAIR architecture and infrastructure in accordance with Legacy Shutdown guidance. Policies include, but are not limited to:

a. OMB Management of Federal Information Resources, OMB CIRCULAR NO. A-130 Revised http://www.whitehouse.gov/omb/circulars_a130_a130trans4

b. OMB Policies for Federal Agency Public Websites, OMB M-05-04 http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-04.pdf

c. Section 508, Rehabilitation Act of 1973 http://www.section508.gov/

d. Department of Defense Web Policies and Guidelines http://www.defense.gov/webmasters

e. Navy Information Operations Command (NIOC) Norfolk Web Risk Assessment Team Website https://www.nioc-norfolk.navy.mil/wra/index.html

f. DON Policy for Content of Publicly Accessible World Wide Web Sites SECNAVINST 5720.47B http://www.doncio.navy.mil/PolicyView.aspx?ID=421

g. NAVAIR CIO Website (NAVAIR specific policy and guidelines https://mynavair.navair.navy.mil/portal/server.pt/community /dcio_applications_integration___business_intelligence_%287_2_2%29/1491/web_enablement /57583

h. DISA Hosting of All Navy Websites (NAVADMIN 061/08)http://www.npc.navy.mil /NR/rdonlyres/A4E463D0-02AF- 4094-A054-BB1D807F631B/0/NAV08061.txt i. Consolidation of Navy Web Sites - Reduction of IM/IT Footprint NAVADMIN 145/07 http://www.npc.navy.mil/NR/rdonlyres/787908B8-55E8-4A6F-9BD8-A74B3C0824F0 /0/NAV07145.txt

j. DON Web Presence Policy: The Registration, Compliance of, and Investment in, All Unclassified Web Sites and Uniform Resource Locators http://www.doncio.navy.mil /PolicyView.aspx?ID=577

4. Software Development/Server Procurement: “Any tools developed that will be hosted by the Navy Marine Corps Intranet (NMCI) or run on NMCI workstations will be certified for NMCI and comply with NMCI policy. Additionally, any servers supporting this effort will be transitioned to meet the requirements of the current NAVAIR Server Consolidation effort.”

5. Navy Marine Corps Intranet (NMCI) Effective 01 October 2015, the Government will provide all NMCI services; to include IT related hardware, software, and support, necessary for the performance of this order. Implementation of these services shall be coordinated and conducted through the COR.

6. Information Assurance (IA):

A. INFORMATION ASSURANCE

Information Assurance (IA) is the discipline that protects and defends information and information systems by ensuring their availability, integrity, authentication, confidentiality, and non-repudiation. These measures include providing for restoration of information systems by incorporating protection, detection, and reaction capabilities. The following paragraphs contain United States Public Law as well as Department of Defense (DoD) and Department of the Navy (DON) IA requirements. These IA requirements stem from various DoD, Secretary of the Navy (SECNAV), Office of the Chief of Naval Operations (OPNAV), and Naval Air Systems Command (NAVAIR) policies, directives, and instructions. United States Government herein described as "Government" officials have the authority to review and examine, in conjunction with contractor personnel, the IA controls on any contractor operated system containing government information for the purposes of ascertaining proper IA posture and implementation.

B. ARCHITECTURE

The network architecture shall maximize use of the contractor’s existing infrastructure and that of its subcontractors, suppliers, the internet, and the Government Wide Area Networks (WANs), such as NIPRNET, DREN, and NMCI, and shall maintain compatibility with the NMCI architecture. The contractor shall continue to utilize a network architecture which supports the mission needs of NAVAIR Programs for the purposes of interoperability while maintaining the quality and timeliness of the technical information, data access, and delivery. The contractor shall share all observed network trends; to be utilized in quarterly IA reviews for the purposes of ascertaining the successful accomplishment of the preceding. The contractor shall implement electronic data sharing for the purposes of data reduction and to avoid the transmission of large data files over the network. Appropriate security measures shall be put in place in accordance with SECNAVINST 5239.3B, OPNAVINST 5239.3A, CJCSI 6211.02D, DoDI 8500.2, and DoDI 8520.02.

C. INFORMATION ASSURANCE PRACTICES

The contractor shall adhere to the Department of the Navy’s (DON)’s Information Assurance Program prescribed methodologies for the protection of information to support DON missions. The contractor shall utilize existing methods and processes in order to deliver secure, interoperable and integrated information management (IM) and information technology (IT) to the DON and its contract support. The contractor shall ensure that all IT systems, software and interfaces thatcontain Government data meet government security certification standards and requirements appropriate to the particular classification level of operation as specified by the US Navy, Department of Defense, or other cognizant government authority for the purposes of the above mentioned DON goals in accordance with SECNAV M-5239.1. DON IA Program policies are listed in the REFERENCES section.

D. PUBLIC KEY INFRASTRUCTURE (PKI):

Public Key Infrastructure (PKI) encryption is the chosen compliant DoD standard for protecting Controlled Unclassified Information (CUI) during transmission. CUI is defined as U.S. Government data that is NOT CLASSIFIED and that has NOT BEEN PUBLICALLY RELEASED. CUI includes but is not limited to data that is labeled or considered: For Official Use Only (FOUO), Privacy data, Contract Information, Unclassified Technical Data, Accountability information, DoD Sensitive But Unclassified (SBU). Failure to encrypt CUI during electronic transmission is considered a security weakness and must be reported to the Program Information Assurance Manager (IAM) and the Program Security Manager via the contractor’s responsible individual. The contractor shall require its personnel to adhere to the required PKI policies stated herein when transmitting CUI. The contractor shall implement DoD PKI policy per DoDI 8520.02. The contractor shall obtain and utilize PKI certificates issued by an approved External Certificate Authority (ECA) for the purposes of protecting all CUI. Approved PKI will be utilized by the contractor, its subcontractors, and suppliers when transmitting CUI via electronic means. Public Key Enablement (PKE) is the chosen DoD standard for authentication at the application level. The contractor shall utilize PKI when interacting with DoD PKI/PKE information systems and accessing DoD CUI or sensitive information.

E. ELECTRONIC MAIL(E-MAIL):

The contractor shall utilize digital signature and encryption via DoD PKI or ECA digital certificates on all electronic mail (e-mail) messages containing CUI or e-mail messaes that discusses any matter that may serve as an OPSEC indicator, per DoDI 8520.02. If contractor personnel support multiple email addresses for use under this contract then a separate PKI certificate is required for each email address. Unapproved accounts, such as AOL, HOTMAIL or YAHOO, will not be used for official business under this contract unless specifically authorized to do so by the Government per CJCSI 6510.01F.

F. DATA AT REST

The contractor shall ensure that an approved DoD product is utilized for Data at Rest (DAR) that is stored on mobile computing devices such as laptops and personal digital assistants (PDAs), or removable storage media. The cryptography shall be National Institute of Standards and Technology (NIST) Federal Information Processing Standard 140-2 (FIPS 140-2) compliant and a mechanism shall be established to ensure encrypted data can be recovered in the event the primary encryption system fails.

G. CERTIFICATION AND ACCREDITATION

For Information Technology (IT) systems which receive, process, store, display, or transmit DoD information to be delivered to the government, the contractor shall coordinate with the Program IAM to determine the IA requirements for the delivered systems. The contractor shall ensure that the delivered IT system can successfully complete either the DoD Information Assurance Certification and Accreditation Process (DIACAP) or the Platform Information Technology (PIT) Risk Approval (PRA) process; whichever is applicable. All delivered IT systems must have the ability to obtain an Authority To Operate (ATO) if going through the DIACAP process or alternatively a PIT Risk Approval letter if going through the PRA process as defined in DoDD 8500.01E, DoDI 8500.2, DoDI 8520.02, DoDI 5000.02, DoDI 8580.1, SECNAVINST 5239.3B, OPNAVINST 5239.3A and OMB A-130, Appendix III.

The contractor will assist and provide necessary documents as defined in the above policies for the purposes of completing the applicable DIACAP or PRA process. The government will provide the contractor with the DIACAP tool or the NAVAIR PRA tool, whichever is applicable.

The contractor shall employ all IA controls that are deemed appropriate by the Mission Assurance Category (MAC) and Confidentiality Level (CL) of the delivered system. The contractor shall demonstrate the required IA design features of all systems, software and interfaces to assist the government in meeting the certification standards specified by the cognizant government agency (DONCIO, NETWARCOM, SPAWAR, PEO(T), and NAVAIR). The results of certification testing shall be submitted to the government in support of a recommendation to the Designated Approving Authority (DAA) for accreditation or PIT designation, using the applicable tool. The contractor will assist the government in managing applications associated with these systems via the appropriate Functional Area Manager (FAM). The contractor will assist the government in determining the Information Assurance Vulnerability Management (IAVM) requirements for the delivered IT system where applicable.

For IT systems delivered to the government, the contractor shall provide all pertinent information to comply with Federal Information Security Management Act of 2002 (FISMA) and Information Technology Management Reform Act (Pub L. 104-106, Division E Clinger-Cohen Act) requirements as requested by the Government. IT systems shall be tested for IA requirements in accordance with the policies stated above.

For IT systems delivered to the government, the contractor shall ensure that any commercial IA or IA-enabled IT products that are utilized as part of that system have been evaluated and validated, as appropriate, in accordance with the National Information Assurance Partnership (NIAP) (http://www.niap-ccevs.org/cc-scheme/vpl/) or Common Criteria (CC). If network switches are part of the architectural design of the system then the contractor shall ensure the switching devices are equipped with the means to manage ports and that have been validated and certified by NIAP (http://www.niap-ccevs.org) or CC evaluation and validation scheme.

For IT systems delivered to the government, the contractor shall ensure that the system will incorporate IA-Enabled Operating Systems that have been validated or are under evaluation by NIAP or CC scheme and are: a) Configurable in accordance with applicable DoD Security Technical Implementation Guides (STIGs) or System and Network Attack Center (SNAC) guides. DoD STIGs and SNAC guides are available at http://iase.disa.mil/; b) Able to incorporate the DoD Information Assurance Vulnerability Management Program (IAVMP) in accordance with DoDI 8500.2; and c) Supportable for the expected lifecycle of the system. The contractor shall also ensure that the system shall incorporate the DoD licensed virus protection software available at the following DoD website:

https://patches.csd.disa.mil. The contractor shall ensure that the delivered IT system adheres to the DAR requirement

“F” DATA AT REST.

For IT systems delivered to the government, the contractor shall be familiar with and apply the following IA, IT and INFOSEC standards where applicable: Federal Information Security Management Act of 2002 (FISMA, Information Technology Management Reform Act (Pub L. 104-106, Division E Clinger-Cohen Act), National Security Telecommunications and Information Systems Security Instruction (CNSS/NSTISSI) No 1000, No. 7000, No. 7001, DoDD 5000.01 DoDD 8500.01E, DoDI 8500.2, DoDI 8520.02, DoDI 8510.01 (DIACAP), SECNAVINST 5239.3B, OPNAVINST 5239.3A, DoD MIL-STD-461F and MIL-STD-464C; CJCSM 6510.01A; CJCSI 6510.01F.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .