PWS 8-23-21_Brokerage Support.docx

DOCX document 58 KB Posted

Attached to
Request for Information NAVSUP BSC Brokerage Support Services Federal contract opportunity
Solicitation number
N0018921QR027
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This document is a performance work statement outlining brokerage contractor support services required by the Naval Supply Systems Command. The contractor shall provide planning, designing, architecting, brokering, implementation, installation and sustainment support across multiple data centers and host providers. Specific requirements include enterprise brokerage support, information assurance support, brokerage architecture support, mission owner onboarding, brokerage implementation and operations such as trusted cloud credential management, service catalog implementation, monitoring and auditing, brokerage tool implementation and sustainment, and web/application/database administration. The contractor must also provide mentoring, knowledge transfer, technical documentation and product support. The period of performance is 12 months with four optional 12-month extensions. The place of performance is Mechanicsburg, Pennsylvania.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information NAVSUP BSC Brokerage Support Services, newest first.
File Type Posted
Request for Information_NAVSUP BSC Brokerage Support.docx DOCX document
Request for Information (RFI)_NAVSUP BSC Brokerage Support.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS) Brokerage Contractor Support Services (BCSS)

1.0 Introduction: Naval Supply Systems Command (NAVSUP) is composed of over 10,000 employees and more than 170,000 customers and other supporting users around the globe involved in supply chain related information-sharing. They all require a globally accessible enterprise information infrastructure that provides direct support to joint warfighters, national level leaders, and other critical supply chain customers across the full spectrum of NAVY operations.

Recently, NAVSUP has been expanding into multiple data centers and host providers. These new efforts have increased brokering, architecture, governance, onboarding and implementation support requirements. Meeting these requirements effectively and efficiently requires applying a consistent approach to reviewing, securing, managing and procuring services to ensure that coordination and integration between vendors is optimized across all the NAVSUP data center and host providers.

NAVSUP Business Systems Center (BSC) Navy Technical Authority (NTA) Brokerage Contractor Support Services (BCSS) needs under this effort include meeting the increased demands supporting the expansion into alternate host providers. This effort will require planning, designing, architecting, brokering, implementation, installation and sustainment support. The contractor will provide Information Assurance related information as needed. In all cases, full knowledge transfer is required.

2.0 Background: Broker and governance support services are required to support protecting and delivering web and network based communication traffic across NAVSUP’s multiple datacenters and host providers. The contractor will be required to work with NAVSUP BSC organic resources to implement, test, audit and integrate NAVSUP web applications across all NAVSUP data centers. The contractor will also work within the NAVSUP BSC Brokerage to support other Mission Owners (MO) across Federal, Department of Navy (DoN), Department of Defense (DoD) and other areas seeking hosting services from NAVSUP BSC.

2.1 Requiring Organization: The organization requiring the services outlined in the Performance Work Statement (PWS) is:

NAVSUP Business Systems Center 5450 Carlisle Pike, Suite 409 Mechanicsburg PA 17050-2411

2.2 Project Description: The purpose of this PWS is to obtain contract services for advising on how to define and then implement brokerage processes, procedures, tools and services consistently across all NAVSUP BSC NTA approved host providers. This project also includes onboarding new services from said host providers as they come online and engaging with Mission Owners as they bring requirements to leverage said NAVSUP BSC NTA brokerage services.

3.0 Scope: The scope of this PWS includes brokerage related planning, architecting, designing, implementation, onboarding, migrating, installation, integration and sustainment support consistently across NAVSUP BSC’s multiple host providers, to include the Defense Research and Engineering Network (DREN), NAVSUP Amazon Web Services GovCloud (NAG) and NAVSUP Oracle DoD GovCloud (NOD). The contractor is required to provide expertise and support in the resolution of system problems and provide customer support in concert with NAVSUP BSC organic staff.

The following application support will be required:

· Defining and implementing brokerage related documents, artifacts, policies, procedures and services applying industry best practices and following appropriate company and DoD/DoN Policies.

· Onboarding NAVSUP BSC NTA approved mission owners that bring requirements to consume the NTA’s brokerage services. In some cases this effort will include web/application/database services consulting.

· Providing brokerage operation consulting and support including addressing configurations, troubleshooting and adding new features to the brokerage architecture and tools.

· Mentoring and knowledge transfer including educating the government workforce and supporting Information Assurance (IA) accreditation efforts.

4.0 Directives: The contractor shall comply with the following directives, and any updated/future versions as they are released:

•Federal Information Security Modernization Act of 2014 (“FISMA”)
•Common Criteria for Information Technology Security Evaluation, Part 3: Security Assurance Components, April 2017, Version 3.1, Revision 5, CCMB-2017-04-003
•DoD Instruction 5400.11, DoD Privacy and Civil Liberties Programs, 29 January 2019 (incorporating Change 1, 8 December 2020)
•DoD Directive 8000.01, Management of the DoD Information Enterprise, 17 March 2016 (incorporating Change 1 July 2017)
•DoD Directive 8140.01, Cyberspace Workforce Management, 5 October 2020
•DoD Instruction 4161.02, Accountability and Management of Government Contract Property, 27 April 2012 (incorporating Change 2, 31 August 2018)
•DoD Instruction 8320.07, Implementing the Sharing of Data, Information, and Information Technology (IT) Services in the Department of Defense, 3 August 2015 (incorporating Change 1, 5 December 2017)
•DoD Instruction 8500.01, Cybersecurity, 14 March 2014, Change 1, 7 October 2019
•DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology, 12 March 2014 (incorporating Change 3, 29 December 2020)
•DoD Instruction 8582.01, Security of Non-DoD Information Systems Processing Unclassified Nonpublic DoD Information, 9 December 2019
•SECNAVINST 5510.36B, DoN Information Security Program, 12 July 2019
•DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 December 2005 (incorporating Change 4, 10 November 2015)
•SECNAV Instruction 5211.5F, Department of the Navy Privacy Program, 20 May 2019
•SECNAV Instruction 5239.3C, DON Cybersecurity Policy, 2 May 2016
•SECNAV M-5239.21, DoN Information Assurance Manual, June 2016
•OPNAVINST 5239.1D, U.S. Navy Cybersecurity Program, 18 July 2018
•OPNAVINST 5239.4, Chief of Naval Operations Cybersecurity Safety Program, 14 September 2018
•SECNAV Manual M-5239.2, DON Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual, 27 June 2016
•SECNAV Manual M-5510.30, Department of the Navy Personnel Security Program, 1 June 2006
•CJCSI 6211.02D, Defense Information Systems Network (DISN) Responsibilities, 24 January 2012
•DoD Public Key Infrastructure (https://cyber.mil/pki-pke)
•ISO/IEC/IEEE 12207:2017 Systems and Software Engineering – Software Life Cycle Processes
•ANSI/EIA 649C-2019 – Configuration Management Standard
•ANSI/EIA 836B-2015 – Configuration Management Data Exchange and Interoperability
•Federal Risk and Authorization Management Program (“FedRAMP”)
•Department of Defense Cloud Computing Security Requirements Guide, Version 1, Release 3, dated 6 March 2017
•All applicable Security Requirements Guides, Security Technical Implementation Guides, and National Security Agency security configuration guides when assessment and authorization is required
•NIST SP 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations, December 2018
•U.S. Navy Risk Management Framework Process Guide, Version 3.2, 2 September 2020
•NIST SP 800-53 Revision 5, Security and Privacy Controls for Federal Information Systems and Organizations, September 2020, includes updates as of 10 December 2020
•NIST SP 800-53A Revision 4, Assessing Security and Privacy Controls in Federal Information Systems and Organizations, December 2014, includes updates as of 18 December 2014
•NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, February 2020
•NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, June 2018
•NAVSUPINST 5239.5, Cybersecurity and Defensive Cyberspace Operations Policy, 25 March 2019
•ISO/IEC 19770-1:2017 – Information Technology – IT Asset Management – Part 1: IT Asset Management Systems - Requirements
•ISO/IEC 19770-2:2015 - Information Technology -- Software Asset Management -- Part 2: Software Identification Tag
•ISO/IEC 19770 Series - Information Technology – IT Asset Management
•A Guide to the Project Management Body of Knowledge (PMBOK® Guide) - Sixth Edition
•Section 508 of the Rehabilitation Act of 1973 (amended by the Workforce Investment Act of 1998, 7 August 1998)
•SECNAVINST 5720.44C - Department of the Navy Policy for Content of Publically Accessible World Wide Web Sites, 21 February 2012 (incorporating Change 1, 14 October 2014)
•SECNAVINST 5510.30C, Department of Navy Personnel Security Program, 24 January 2020
•Homeland Security Presidential Directive (HSPD)12, Policy for a Common Identification Standard for Federal Employees and Contractors, 27 August 2004
•DoD Manual 5200.02, Procedures for the DoD Personnel Security Program (PSP), 3 April 2017 (incorporating Change 1, 29 October 2020)
•DoD Manual 5200.08-R, Physical Security Program, 9 April 2017, (incorporating Change 2, 19 October 2020)
•NTTP 3-13.3, Operations Security (OPSEC), September 2017
•DoD Instruction 5200.48, Controlled Unclassified Information (CUI), March 6, 2020
•NSAMECHINST 5530.1C CH-1, Naval Support Activity Mechanicsburg Installation Access Control, 23 August 2019
•ASN(RDA) and DON CIO Joint Memorandum, Department of the Navy Cloud Policy, 7 December 2020
•NAVADMIN 122-21, Navy Cloud Implementation Plan, 9 June 2021

5.0 Requirements/Tasks: The contractor shall perform every requirement in this performance work statement. Not every performance requirement has a related standard expressed in this document. In such cases the performance standard is either inherent in the requirement or performance is to be in accordance with standard commercial practice.

5.1 Planning / Management: The contractor shall:

5.1.1 Prepare Project Plans describing the technical, functional, and procedural activities required for the execution of all tasks and delivery of all capabilities specified within this performance work statement. Include information on management methods related to quality assurance, software updates, problem notification, problem resolution, license agreements, professional services, and general customer engagement methodologies.

5.1.2 Prepare an Implementation Plan describing the architectural/technical approach, organizational resources and management controls to be employed to meet the cost, performance and schedule requirements throughout execution. Provide status reports that addresses current licensing, software updates, known problems, upcoming enhancements, and the quality or need for any professional services that go beyond just providing a tool.

Performance Standard: All work associated with the tasks described in section 5.1 above will be consistent with industry best practices and following Enterprise and Project specific standards including software development and version control. All documentation released will follow the government Configuration Management process and management controls.

Assessment Method: All documents will be vetted and reviewed for completeness and sufficiency with the Government and all identified stakeholders within five (5) business days.

5.2 Enterprise Cloud Program Governance, Program Management/Implementation Capability and Organization Change The contractor shall provide NAVSUP a successful transition to the efficient and effective use of cloud-based services provided by DOD authorized and approved Cloud Service Providers (CSPs) which meet the Federal FEDRAMP and DoD Impact Level cloud approvals. The contractor shall deliver not only an understanding of the technology, but also a comprehensive establishment of Cloud governance and critical operating elements to include: workflows, processes, management, workforce support and structure. Additionally, the contractor shall integrate this governance model seamlessly with existing Enterprise IT governance, IT operating models addressing processes, policies, and boards and tools, which will require a concerted organization change effort.

5.2.1 Enterprise Brokerage Support: The contractor shall:

5.2.1.1 Advise the NAVSUP architecture and cloud teams during definition of the NAVSUP Cloud Computing strategic direction and the delivery of cloud computing capabilities to achieve that future vision, and strategic goals/objectives adhering to DoD, NAVSUP, and industry best standards.

5.2.1.2 Build upon and align with existing NAVSUP enterprise strategies, roadmaps, and plans.

5.2.1.3 Develop artifacts/templates/models related to governing, managing, procuring, implementing and sustaining brokerage services. Examples include but not limited to service tagging strategies, naming conventions, on boarding processes, service catalog definitions, etc.

5.2.1.4 Develop detailed plans and roadmap to execute the cloud computing strategies. Provide detailed documentation as applicable regarding cloud advisory details, observations, recommendations.

5.2.1.5 Write any required business case analysis and support those that are performed by the architecture and cloud teams.

5.2.1.6 NAVSUP BSC Brokerage leverages services based in NAVSUP’s Amazon Web Services GovCloud (NAG), and NAVSUP Oracle DoD GovCloud (NOD) environments. The government requires the contractor to developer a consistent approach across both cloud service providers (CSP) during architecture, planning, onboarding, implementing, sustaining, etc events. The instances where different approaches between the NAG and NOD are required due to fundamental differences in each CSP shall be fully documented. As NAVSUP BSC’s brokerage efforts grow, other service providers may be added as determined necessary by onboard new Mission Owner (MO) customers.

Performance Standard: Clear, well-written, detailed documents with a table of contents; free of spelling and grammatical errors, and factually accurate 100% of the time.

Assessment Method: All documents will be vetted and reviewed for completeness, sufficiency and accuracy with the Government and all identified stakeholders within five (5) business days.

5.2.2 Information Assurance Support

The contractor shall support NAVSUP BSC accreditation/reaccreditation efforts by providing any technical documentation/support for these tasks as required. Workload items include introducing new processes and configuration standards to meet the increased Information Assurance (IA) accreditation requirements of auditability, reporting, monitoring, and implementing cloud services for mission owners that utilize NAVSUP BSC’s NAG and NOD environments as well as other CSP environment that NAVSUP BSC adds as growth occurs over time.

Performance Standard: Throughout the entire software lifecycle for this effort, Information Assurance (IA) requirements will be identified as the accreditation process is always on going. Efforts that fall within this category shall be planned (POA&M), documented, implemented, and within timelines agreed upon between the NAVSUP Architecture and Cloud Teams, TA, Application SME, and contractor 95% of the time.

Assessment Method: All documents will be vetted and reviewed for completeness, sufficiency and timeliness with the Government and all identified stakeholders within five (5) business days.

5.2.3 Brokerage Architecture Support: The contractor shall:

5.2.3.1 Conduct a suitability analysis, identifying appropriate service models (e.g. SaaS, PaaS, and IaaS) and deployment models (e.g. private, public, or hybrid) for NAVSUP NTA efforts.

5.2.3.2 Provide recommendations to the government for leveraging best practices for the industry/service models above.

5.2.3.3 Develop the business case to quantify cost and benefits for implementing recommended models.

5.2.3.4 Define required auditing and monitoring plans, reports and artifacts.

5.2.3.5 Creating diagrams, designs, and implementation plans for new or expanded services that are on boarded into NAVSUP BSC’s service catalog.

5.2.3.6 Apply consistent strategies whenever possible across all NAVSUP host environments.

Performance Standard: Clear, well-written, detailed documents with a table of contents; free of spelling and grammatical errors, and factually accurate 100% of the time.

Assessment Method: All documents will be vetted and reviewed for completeness, sufficiency and accuracy with the Government and all identified stakeholders within five (5) business days.

5.2.4 Mission Owner Onboarding: The NAVSUP BSC NTA Brokerage has been established to onboard Mission Owner (MO) workload into NAVSUP BSC’s approved host providers including the DREN, NAG and NOD. The contractor shall provide:

5.2.4.1 Onboarding or Migration planning, including developing the onboard/migration roadmap.

5.2.4.2 Onboarding/Migration execution and possible application refactoring.

5.2.4.3 Analyze and assess the Mission Owner’s current on premise and cloud computing environments to identify cloud computing capability needs and gaps. This shall include but is not limited to researching and assessing costs and benefits of each alternative, risks/issues, and dependencies.

Performance Standard: All work associated with the tasks described in section 5.2.4 above will be consistent with industry best practices and following Enterprise and Project specific standards including software development and version control. All documentation released will follow the government Configuration Management process and management controls.

Assessment Method: All documents will be vetted and reviewed for completeness and sufficiency with the Government and all identified stakeholders within five (5) business days.

5.3 Brokerage Implementation and Operations: The contractor shall:

5.3.1 Trusted Cloud Credential Management (TCCM): Support NAVSUP BSC Identity and Access Management (IdAM) team in implementing and operationally supporting access control to NAVSUP BSC hosted environments. Requirements include developing procedures for proper logging and auditing user activities. Apply least privilege principles when managing access control procedures. Leverage industry best practices to expand current NAVSUP IdAM systems as necessary while ensuring a common consistent approach is applied all NAVSUP approved host environments.

5.3.2 Service Catalog Implementation: Document, evaluate, analyze, design, identify best practices, perform architectural reviews and implement/sustain new Cloud Service Provider (CSP) services as they become available to the NAVSUP BSC or required by Mission Owner requirements. Where possible, NAVSUP BSC requires a consistent approach across the NAG, NOD and future CSP/Host Providers NAVSUP BSC may onboard.

5.3.3 Monitoring/Auditing: Monitor and audit the use of the NAVSUP BSC NTA services by the NTA teams and any Mission Owners. Aspects of this task include but not limited to usage monitoring, performance monitoring, auditing user activity, managing alerts and tracking issues. Where possible, NAVSUP BSC requires a consistent approach across the NAG, NOD and future CSP/Host Providers NAVSUP BSC may onboard.

5.3.4 Brokerage Tool Implementation/Sustainment: Document and perform analysis, design, architectural reviews installation and configuration tasks required for successfully implementing/sustaining tools that comprise the NAVSUP BSC NTA environment such as Juniper SRX, Palo Alto Firewalls, CISCO Software, and F5 software including Big-IP and its related modules for the purpose of monitoring providing a DoD compliant Secure Computing Architecture (SCA) VDSS stack. In some cases the contractor shall be required to consult on addressing operational issues.

5.3.5 Web Server / Application Server / Database Administration: Provide Web Server, Application Server and Database administration services consistent with the approved NAVSUP reference technologies. Such technologies include but are not limited to Oracle based tools such as current versions of Oracle HTTP Server (OHS), Web Logic, Oracle Databases, Microsoft IIS and SQL Servers and other less common tools such as Apache based software Web Server and Tomcat servers and Red Hat JBoss application servers. These services will be performed in conjunction with all tasks identified in this work statement. Specific Web Server/Application Server/ Database Administration services are required in support of:

5.3.5.1 Mission Owner onboarding workloads as the mission owner requirements are implemented by the brokerage.

5.3.5.2 NAVSUP BSC implementing a continuous operations (COOP) resilient environment of its on premise environments into NAVSUP BSC approved host environments (such as the NOD). The NAVSUP BSC On Premise Reference Architecture includes Oracle Fusion Middleware software stacks (IdAM, SoA, Web Center/Content Management, OBIEE, custom built WebLogic apps, WebLogic ORDS and Database tools including APEX)and Microsoft Windows technologies including IIS, SQL Server and Active Directory.

5.3.5.3 DEVSECOPS implementations as NAVSUP expands into use of Infrastructure as Code (IaC) and Kubernetes/Container based deployments and creating Continuous Integration/Continuous Deployment (CI/CD) pipelines.

5.3.6 Test, Evaluation & Interoperability:

5.3.6.1 Create test plans and perform testing of the installation and configurations to ensure the product is operating properly to specification.

5.3.6.2 Assist the government team with any required interoperability testing and/or interoperability waiver requests as needed (not common).

5.3.6.3 Provide any internal testing results for NAVSUP BSC Brokerage NTA provided services or tools.

5.3.7 Brokerage Certification and Accreditation: The contractor shall work in coordination with the government architects, systems/network/host administrators and cyber security personnel to ensure the brokerage and mission owner environments are granted and maintains an authority to operate (ATO) under the Navy Authorization Official (NAO). This help will include assisting the NAVSUP Validators by providing any documentation, software changes, or systems changes required for to receive an ATO.

5.3.8 Technical Documentation: Document or provide access to maintained technical programming components. Where necessary, documents include: Installation Guides, Usage Guides, Administration Guides, Integration Guides, Configuration Recommendations and Software Updates. The contractor will follow all Enterprise standards including the Service Delivery Model (SDM) and Project specific standards and requirements.

5.3.9 Product Support and Sustainment: Provide ongoing support for the NAVSUP NTA brokerage tools and other IaaS, PaaS, and SaaS services including those indicated in the Section 5 and its subtasks. This support shall include: support contact numbers and methods, patch updates/fixes, monitor and troubleshoot integrations, support hours, enhancement request procedures, and customer notification methods for issues and updates.

Performance Standard: All work associated with the tasks described in section 5.3 above will be consistent with industry best practices and following Enterprise and Project specific standards including software development and version control. All software released will follow the government Configuration Management process and management controls.

Assessment Method: All documents will be vetted and reviewed for completeness and sufficiency with the Government and all identified stakeholders within five (5) business days.

5.4 Mentoring/Knowledge Transfer: The contractor shall provide a comprehensive application Transfer of Knowledge to NAVSUP BSC personnel. Contractor shall present areas of knowledge transfer as succinct, shop usable lesson plans. The contractor shall:

5.4.1 Explain what procedures are incorporated into production are necessary for testing and how fixes /functional additions.

5.4.2 Provide walkthrough exercises of all application modules explaining each.

5.4.3 Have the government team assist on some easier tasks to become familiar.

5.4.4 Address government teams questions.

5.4.5 Assist Navy resources on troubleshooting and debugging problems.

5.4.6 Provide source code instructional tools.

Mentoring events shall be accomplished monthly covering the tasks of this PWS using the five Knowledge Transfer mechanisms defined below. The contractor shall actively provide daily mentoring support for Navy team while the contractor accomplishes daily activities. The intent of this mentoring is to ensure government employees have the knowledge and familiarity with the tasks to ensure Navy team independent processing of future similar tasks. BSC has provided an estimated number of monthly occurrences to provide a general basis for how frequently each technique may be implemented.

· Serial Transfer (estimated monthly occurrences: 4): the knowledge the contractor team has gained from doing a task in one setting is transferred to the Navy team for the next time the task is required in a different setting.

· Near Transfer (estimated monthly occurrences: 4): The explicit knowledge the contractor has gained from doing a frequent and repeated task is documented to be reused by Navy teams doing similar work.

· Far Transfer (estimated monthly occurrences: 8): Tacit knowledge the contractor has gained from doing a non-routine task is made available to Navy teams doing similar work in another part of the system. Tacit knowledge (as opposed to formal, codified or explicit knowledge) is the kind of knowledge that is difficult to transfer to another person by means of written transcript.

· Strategic Transfer (estimated monthly occurrences: 1): The collective knowledge of the contractor is needed to accomplish a strategic task that occurs infrequently but is critical to the Navy.

· Expert Transfer (estimated monthly occurrences: 1): A Navy team facing a question beyond the scope of its own knowledge seeks the expertise of the contractor for solution.

Performance Standard: All work associated with the tasks described in Section 5.4 above will be consistent with industry best practices and following Enterprise and Project specific standards including software development and version control. All software released will follow the government Configuration Management process and management controls.

Assessment Method: All documents will be vetted and reviewed for completeness and sufficiency with the Government and all identified stakeholders within five (5) business days.

6.0 Deliverables: All deliverables must meet the format requirements specified by the Contracting Officer’s Representative (COR). Documentation related to these services shall be made available electronically. The following details the contract deliverables:

6.1 Monthly Status Reports: The contractor shall send status reports electronically to the Technical Assistant (TA) and Contracting Officer’s Representative (COR) on a monthly basis (due by 1700 on the 10th day of every month) documenting the performance on the order. The status report shall include the following elements:

· Resource(s) by name

· Date project/task received

· Percentage of project/task completed

· Estimated date of project/task completion

· Issues/problems encountered and recommended solutions

· Identify any Government deficiencies that are overdue which impact schedule or performance

· Evaluate performance and determine adequacy of staffing.

6.2 Source Code: Contractor shall use the government’s repository tool, currently Azure DevOPS. All Code shall be checked-out before use and working updates checked in at the end of each day.

6.3 Knowledge Transfer: When written knowledge is to be captured, knowledge will be stored in wiki articles, MS Office documents (docs, spreadsheets, presentations) and stored in government approved knowledge repositories. Contractor will create log containing knowledge transfer tasks performed in MS Excel or an agreed upon tool. Cumulative log will be delivered as part of the status reports from beginning of period of performance.

6.4 Monthly Payment Request: The contractor shall submit a monthly payment request (invoice) electronically using Wide Area Workflow (WAWF) by the 10th day of each month. WAWF is available on the internet at https://piee.eb.mil.

The Period of Performance (POP) for each invoice shall be for one calendar month. Included with the invoice shall be support documentation such as, but not limited to, travel authorizations (if applicable) and a monthly status report. Invoices received without the support documentation (in the correct format) will be rejected.

The contractor shall submit a final invoice or zero cost invoice to properly close out the contract.

6.5 Mandatory Annual Training: The contractor shall participate in DoD/DoN mandatory annual training when announced by the Government.

Contractors are required to complete the following mandatory training and any updated/future training as released: 1) Personally Identifiable Information (PII); 2) DoN Records Management: Everyone's Responsibility; 3) Anti-Terrorism/Force Protection Awareness; 4) Combating Trafficking in Person; 5) Operations Security (OPSEC); 6) Training & Readiness – The Active Shooter. The contractor shall complete DoD Cyber Awareness Challenge v4 mandatory training two weeks after contract award. Jacqueline Jamison 717-605-3357, or Antonio Arturet-Millan, 717-605-8192, are the POCs for the Cyber Awareness training. Training can be accessed at https://cyber.mil/training/cyber-awareness-challenge.

Deliverables General Statement: Unless stated otherwise, the following instructions apply to all deliverables:

· Deliverable due dates shall take into account the review periods described below.

· Draft deliverables will be reviewed and feedback and/or requested changes provided within 7 business days (unless otherwise specified).

· Government reserves the right to request a formal review session with the contractor during these timeframes and may request that the contractor make changes to any version of a deliverable.

· Government will review and approve or reject all final versions of all deliverables within 7 business days of receipt (unless otherwise specified).

· If any deliverable is rejected, the contractor will be notified within the specified time periods and will have 7 calendar days within which to rework the deliverable and resubmit for Government approval. All changes to any version of a deliverable and/or deliverable outline shall be approved by the COR. If more than the specified number of calendar days is required for Government review and approval, the COR will inform the contractor of the need for an extension within the initial review period.

· Contractor shall prepare and submit the deliverables on or before the required due date to the COR or designee via email. For deliverables that are not documents the contractor shall submit a description of the deliverable and any associated documentation or descriptive information. In no case shall any deliverable be received by the Government less than 21 calendar days prior to the end of the Period of Performance.

7.0 Performance Standards:

One Touch Support

Performance Requirement
Surveillance Method
Frequency
Acceptable Quality Level
Para 5.1
Prepare Project and Implementation Plans.
TA will review documentation for completion and sufficiency.
Monthly
95%
Para 5.2.1
Provide documentation related to the Enterprise Brokerage support.
TA will review documentation for completion, sufficiency and accuracy.
Weekly
100%
Para 5.3.6
Create test plans and assist with interoperability testing.
TA will review documentation and code for completion and sufficiency.
Weekly
95%
CTIP
Compliance with FAR 52.222-50
COR will review documentation or interview contractor personnel
Annually
100%

8.0 Period of Performance (PoP): This contract will have a performance period of 12 months and four 12-month option periods.

9.0 Place of Performance: The following location is the primary site for performance:

• Naval Support Activity, Naval Supply Systems Command, 5450 Carlisle Pike, Building 409, Mechanicsburg PA 17050

No contractor services shall be performed on Saturdays, Sundays, Government Holidays or during base closures. The contractor shall follow appropriate local base policy for reporting to work during severe weather and base closure. The contractor is not authorized to begin work until both the Visit Authorization Request (VAR) and System Authorization Access Request - Navy (SAAR-N) forms have been successfully processed and base and system access have been granted. Remote work is authorized with the coordination and approval of the COR.

10.0 Travel: Travel will not be required.

11.0 Security: Per DFARS 211.106, contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification for meetings with Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal and informal written correspondence.

ACCESS TO FEDERAL FACILITIES

Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this text will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command's Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual's performance under the contract.

ON-BOARDING PROCESS

All contractor resource onboarding documents must be submitted via the prime contractor. An employee is considered to be “productive” upon completion of the following items:

a.Visit Authorization Request (VAR)
b.Contractor Information Request Form (CIRF)
c.FD-258 fingerprint card/Contractor Responsibility
d.Completed EQIP (Electronic Investigation) within 20 days after contract award/Contractor Responsibility
e.All contractor resource(s) must have an active JPAS profile within 20 days after contract award
f.Common Access Card (CAC)
g.System Authorization Access Request – Navy (SAAR-N)
h.Cyber Awareness Training Certification
i.Information Assurance (IA) certification (if applicable)
j.Individual Contractors adjudicated at the appropriate level

Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services, and no reimbursement will be paid by the Government for efforts expended during the start-up period.

Note (2): Foreign Nationals are not allowed access to the functional/system side of Enterprise Resource Planning (ERP).

TEMPORARY ACCESS

The Command's Security Manager may authorize issuance of a DoD CAC and temporary access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under temporary access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.

Security Awareness Training Education The Prime Contractor shall make certain that all Contractors complete all required Security Awareness Training Education. Contractors shall register their Public Key Infrastructure (PKI) Certificates on their Common Access Card (CAC). Registering PKI certificates enable the Security Manager to track their training in Total Workforce Management Services (TWMS). At a minimum the contractor must annual complete Security Awareness, Anti-Terrorism Level I, OPSEC, and Counter Intelligence Awareness and Reporting, and Security Awareness.

OPSEC

Contactor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise, as outlined in NTTP 3-13.3M/MCTP 3-32B. The contractor shall consult with the OPSEC Program Manager within 5 working days of receipt of order to determine all special circumstances affecting OPSEC under this requirement. In any case where there is uncertainty or ambiguity regarding OPSEC measures, the contractor shall consult the OPSEC Program Manager as soon as possible.

DoD 8570.01-M Information Assurance Workforce Improvement Program The contractor shall have Information Assurance (IA) Workforce Improvement Program certificates for Cybersecurity positions. See the Information Assurance Support Environment (IASE) website for DoD Approved 8570 Baseline Certifications: https://cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/ ______ No Additional IA Certification Required

__X___ Information Assurance DoD 8570.01-M Required:

IA Certification Level: IAT-2 Baseline Certification: CompTIA Security+ CE Substitutes for Baseline Certification: CCNA Security; CySA+; GICSP; GSEC; CND; SSCP Computing Environment Certification: AWS Solutions Architect, Oracle Cloud Infrastructure (OCI) Certified Architect, Oracle Database Server, Oracle WebLogic, Microsoft Certified Engineer, Red Hat Linux or equivalent certification

Privileged system access is required.

Privileged Access. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical Level 1. They must also be trained and certified on the Operating System or Computing Environment they are required to maintain. They must have IT-I security designation. A person with privileged access must have an initiated Single Scope Background Investigation (SSBI).

The COR will ensure that contractor personnel accessing DoD information systems have the appropriate and current information assurance baseline certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. Prior to being engaged and upon request by the Government, the Contractor shall provide documentation supporting the information assurance baseline certification status of personnel performing information assurance functions to the contracting officer. Contractor personnel who do not provide appropriate and current baseline certifications shall be deemed unauthorized to access DoD information systems.

The Contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. The Contractor shall meet the applicable information assurance certification requirements, including:

1) DoD-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M.

2) Appropriate operating system certification for information assurance technical positions as required by DoD 8570.01-M.

a) Upon request by the Government, the Contractor shall provide documentation supporting the information assurance certification status of personnel performing information assurance functions.

b) Contractor personnel who do not have proper and current certifications shall be denied access to DoD information systems for the purpose of performing information assurance functions.

Proof of the above indicated IA baseline certification is to be provided for all contractor personnel prior to time of engagement. In addition to the IA certificate, active enrollment and participation in the certification maintenance program must be established prior to contract award to ensure the appropriate access can be secured by contractor resources. All required IA baseline certifications must be current at the contract period start date; there is no “grace” period to obtain these certifications. Computing environment certification must be current no later than six (6) months after start. Questions and additional information requirements may be addressed by contacting the NAVSUP Business Systems Center Information System Security Manager (ISSM).

Certification shall be forwarded to:

Cory Harvey Information System Security Manager (ISSM) NAVSUP Business Systems Center, 9412 5450 Carlisle Pike Mechanicsburg, PA 17050 Phone: (717) 605-6872 Email: cory.a.harvey.civ@us.navy.mil

Language used to supplement DFARS Clause 252.204-7012 entitled, “Safeguarding Covered Defense Information and Cyber Incident Reporting” from the memorandum Updated Implementation of “the DIB Memo” dated 06 Sep 2019:

1. System Security Plan and Plans of Action and Milestones (SSP/POAM) Reviews

a) Within thirty (30) days of contract award, the Contractor shall make its System Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the contractor's facility. The SSP(s) shall implement the security requirements in Defense Federal Acquisition Regulation Supplement (DF ARS) clause 252.204-7012, which is included in this contract. The Contractor shall fully cooperate in the Government's review of the SSPs at the Contractor's facility.

b) If the Government determines that the SSP(s) does not adequately implement the requirements of DFARS clause 252.204-7012 then the Government shall notify the Contractor of each identified deficiency. The Contractor shall correct any identified deficiencies within thirty (30) days of notification by the Government. The contracting officer may provide for a correction period longer than thirty (30) days and, in such a case, may require the Contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies. The Contractor shall immediately notify the contracting officer of any failure or anticipated failure to meet a milestone in such a POAM.

c) Upon the conclusion of the correction period, the Government may conduct a follow-on review of the SSP(s) at the Contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies in the SSP(s).

d) The Government may, in its sole discretion, conduct subsequent reviews at the Contractor's site to verify the information in the SSP(s). The Government will conduct such reviews at least every three (3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty (30) days' notice to the Contractor.

2. Compliance to NIST 800-171

a) The Contractor shall fully implement the CUI Security Requirements (Requirements) and associated Relevant Security Controls (Controls) in NIST Special Publication 800-171 (Rev. 1) (NIST SP 800-171), or establish a SSP(s) and POA&Ms that varies from NIST 800-171 only in accordance with DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract.

b) Notwithstanding the allowance for such variation, the contractor shall identify in any SSP and POA&M their plans to implement the following, at a minimum:

1) Implement Control 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network. In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, such as CNC equipment, etc., a combination of physical and logical protections acceptable to the Government may be substituted;

2) Implement Control 3.1.5 (least privilege) and associated Controls, and identify practices that the contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its subcontractors, suppliers, or vendors based on need-to-know principles;

3) Implement Control 3.1.12 (monitoring and control remote access sessions) – Require monitoring and controlling of remote access sessions and include mechanisms to audit the sessions and methods.

4) Audit user privileges on at least an annual basis;

5) Implement:

i. Control 3.13.11 (FIPS 140-2 validated cryptology or implementation of NSA or NIST approved algorithms (i.e. FIPS 140-2 Annex A: AES or Triple DES) or compensating controls as documented in a SSP and POAM); and,

ii. NIST Cryptographic Algorithm Validation Program (CAVP) (see https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program);

6) Implement Control 3.13.16 (Protect the confidentiality of CUI at rest) or provide a POAM for implementation which shall be evaluated by the Navy for risk acceptance,

7) Implement Control 3.1.19 (encrypt CUI on mobile devices) or provide a plan of action for implementation which can be evaluated by the Government Program Manager for risk to the program.

3. Cyber Incident Response

a) The Contractor shall, within fifteen (15) days of discovering the cyber incident (inclusive of the 72-hour reporting period), deliver all data used in performance of the contract that the Contractor determines is impacted by the incident and begin assessment of potential warfighter/program impact.

b) Incident data shall be delivered in accordance with the Department of Defense Cyber Crimes Center (DC3) Instructions for Submitting Media available at http://www.acq.osd.mil/dpap/dars/pgi/docs/Instructions _for_ Submitting_ Media.docx. In delivery of the incident data, the Contractor shall, to the extent practical, remove contractor-owned information from Government covered defense information.

c) If the Contractor subsequently identifies any such data not previously delivered to DC3, then the Contractor shall immediately notify the contracting officer in writing and shall deliver the incident data within ten (10) days of identification. In such a case, the Contractor may request a delivery date later than ten (10) days after identification. The contracting officer will approve or disapprove the request after coordination with DC3.

4. Naval Criminal Investigative Service (NCIS) Outreach The Contractor shall engage with NCIS industry outreach efforts and consider recommendations for hardening of covered contractor information systems affecting DON programs and technologies.

5. NCIS/Industry Monitoring

a) In the event of a cyber-incident or at any time the Government has indication of a vulnerability or potential vulnerability, the Contractor shall cooperate with the Naval Criminal Investigative Service (NCIS), which may include cooperation related to: threat indicators; pre-determined incident information derived from the Contractor's infrastructure systems; and the continuous provision of all Contractor, subcontractor or vendor logs that show network activity, including any additional logs the contractor, subcontractor or vendor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.

b) If the Government determines that the collection of all logs does not adequately protect its interests, the Contractor and NCIS will work together to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by NCIS, on the Contractor’s information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an NCIS network device shall be the subject of a separate agreement negotiated between NCIS and the Contractor. In the alternative, the Contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by NCIS. Use of this alternative approach shall also be the subject of a separate agreement negotiated between NCIS and the Contractor.

c) In all cases, the collection or provision of data and any activities associated with this statement of work shall be in accordance with federal, state, and non-US law.

12.0 Government Furnished Equipment (GFE):

The government will furnish necessary office workspace for Contractor staff performing at NSA Mechanicsburg including computer hardware, software and access to local telephones. The government will furnish all equipment, tools and servers used to maintain software and host these applications. If the contractor is supporting off-site, the government will provide government furnished computers for access to government systems (if needed).

13.0 Qualifications/Experience:

Development personnel who are assigned by the Contractor must be highly experienced and knowledgeable in the following areas:

· Commercial, FEDRAMP High/ DoD Impact Level 2, 4, and 5 Amazon Web Services (AWS) cloud offerings.

· Commercial, FEDRAMP High/ DoD Impact Level 2, 4, and 5 Oracle Cloud Infrastructure (OCI) cloud offerings.

· Web Sever, Application Server, and Database administration in Oracle and Microsoft toolsets.

· Administering Oracle Fusion Middleware application stacks.

· AWS DoD Impact Level 6 cloud offerings

· OC DoD Impact Level 6 cloud offerings.

· Firewall management

· Networking and related device experience

· Firewall and other security stack tools included in security stack toolsets and thus desired include CISCO Firepower, Juniper SRX VPN and Palo Alto firewalls.

14.0 Non-Disclosure Agreement (NDA):

Contractor and subcontractor employees performing work under this effort are required to sign a Non-Disclosure Agreement (NDA) as part of their onboarding process. The contractor shall maintain copies of all signed agreements and have the documents readily available at the COR’s request. Refer to DFARS 252.204-7000, Disclosure of Information, and DFARS 252.204-7003, Control of Government Personnel Work Product.

15.0 NAVSUP Business Systems Center Procedures for Contractor Access/Visit Authorization Request (VAR):

1. A company letter to the Technical Assistant (TA) containing the following information:

a. Contract Information

1) Contract Number

2) Date Issued

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .