About this file

This document is a performance work statement outlining requirements for secure computing architecture systems administration and project management support services. The contractor shall provide expertise to manage and protect communication traffic across multiple Navy datacenters, including installing and configuring firewalls, load balancers, virtual private networks and related software. Additional requirements include application migration support, mentoring Navy personnel, and assisting with project management documentation. The contractor must comply with numerous cybersecurity directives and regulations. Qualified personnel with experience in areas like Windows, Linux and security tools are required. The period of performance is one base year with four optional one-year extensions. Work will take place at Naval Support Activity in Mechanicsburg, Pennsylvania.

View the file

Other files for this federal contract opportunity

Other files attached to Request for Information NAVSUP BSC Secure Computing Architecture (SCA) Systems Administration & Project Management Support, newest first.
File Type Posted
Request for Information (RFI)_NAVSUP BSC SCA Support.docx DOCX document
Request for Information (RFI)_NAVSUP BSC SCA Support.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS) Secure Computing Architecture (SCA) Systems Administration and Project Management Support

1.0 Introduction: Naval Supply Systems Command (NAVSUP) is composed of over 10,000 employees and more than 170,000 customers and other supporting users around the globe involved in supply chain related information-sharing. They all require a globally accessible enterprise information infrastructure that provides direct support to joint warfighters, national level leaders, and other critical supply chain customers across the full spectrum of NAVY operations.

Recently, NAVSUP has been expanding its secure computing capability using multiple data centers and host providers. These new efforts have increased secure computing architecture requirements including managing, sustaining and protecting communication traffic. These new capabilities also bring a need to develop mission owner onboarding processes, support migration of mission owner applications and support of the integration of project management principles. These efforts will ensure a seamless transition of mission owner applications to the Secure Computing Architecture (SCA) environment.

2.0 Background: Secure computing architecture support services are required to support managing and protecting web and network based communication traffic across NAVSUP’s multiple datacenters and host providers. The contractor will be required to work with NAVSUP Business Systems Center (BSC) organic resources to implement, test, audit and integrate these secure computing architecture Virtual Datacenter Security Stack (VDSS) and Virtual Datacenter Management Services (VDMS) within the NAVSUP infrastructure and web applications across all NAVSUP data centers. Onboarding new applications to this infrastructure will require coordination with application owners to ensure the SCA services meet the need of the requesting organization. The contractor will be required to work with NAVSUP BSC organic resources to ensure the seamless migration of applications to the SCA. Sound project management practices need to be implemented to ensure the projects meet or exceed cost, schedule and performance parameters and the contractor will be required to support NAVSUP BSC organic resources in executing project management tasks.

2.1 Requiring Organization: The organization requiring the services outlined in the Performance Work Statement (PWS) is:

NAVSUP Business Systems Center 5450 Carlisle Pike, Suite 409 Mechanicsburg PA 17050-2411

2.2 Project Description: The purpose of this PWS is to obtain contract services for support and maintenance of secure computing architecture, application migration and project management support necessary to deliver the related changes to the NAVSUP host providers and datacenters as described in the introduction paragraph of this document.

3.0 Scope: The scope of this PWS includes planning, designing, implementation, installation, integration and sustainment support of multiple VDSS and VDMS tools required for managing communications in and out of NAVSUP’s secure computing architectures at multiple host providers. The contractor is required to provide expertise and support in the resolution of system problems and provide customer support in concert with NAVSUP BSC organic staff. The contractor is required to provide application migration services needed to onboard new mission owner applications that migrate to the SCA.

The following application support will be required:

· Installation, Sustainment processes, operations and analysis related to providing load balancer and firewall capabilities securing communications traffic via F5 BIG IP, Cisco Firepower, Palo Alto firewalls and related technologies.

· Installation, Sustainment processes, operations and analysis related to maintaining virtual private network capabilities provided by tools such as Juniper SRX.

· Analysis and support services related to securing, ensuring high performance of and maintaining a secure computing architecture

· Mentoring and knowledge transfer including educating the government workforce and supporting Information Assurance (IA) accreditation efforts.

· Installation, Sustainment processes, operations and analysis related to Windows and Red Hat Enterprise Linux (RHEL) servers for functions to include domain controller, Bastion Host, Nessus Scanner, Internet Information Server (IIS), ePolicy Orchestrator, SQL ePolicy database and Syslog.

· Installation, Sustainment processes, operations and analysis related to providing Host Based System Security (HBSS).

· Installation, Sustainment processes, operations and analysis related to providing Assured Compliance Assessment Solution (ACAS).

· Analysis and support services related to systems administration, ensuring high performance and maintenance of a secure computing architecture.

· Analysis and support services related to migrating new mission owner applications in and out of our secure computing architectures at multiple host providers.

· Analysis and support services related to implementation of project management principles and standards.

4.0 Directives: The contractor shall comply with the following directives, and any updated/future versions as they are released:

· Federal Information Security Modernization Act of 2014 (“FISMA”)

· Common Criteria for Information Technology Security Evaluation, Part 3: Security Assurance Components, April 2017, Version 3.1, Revision 5, CCMB-2017-04-003

· DoD Instruction 5400.11, DoD Privacy and Civil Liberties Programs, 29 January 2019 (incorporating Change 1, 8 December 2020)

· DoD Directive 8000.01, Management of the DoD Information Enterprise, 17 March 2016 (incorporating Change 1 July 2017)

· DoD Directive 8140.01, Cyberspace Workforce Management, 5 October 2020

· DoD Instruction 4161.02, Accountability and Management of Government Contract Property, 27 April 2012 (incorporating Change 2, 31 August 2018)

· DoD Instruction 8320.07, Implementing the Sharing of Data, Information, and Information Technology (IT) Services in the Department of Defense, 3 August 2015 (incorporating Change 1, 5 December 2017)

· DoD Instruction 8500.01, Cybersecurity, 14 March 2014, Change 1, 7 October 2019

· DoD Instruction 8510.01, Risk Management Framework (RMF) for DoD Information Technology, 12 March 2014 (incorporating Change 3, 29 December 2020)

· DoD Instruction 8582.01, Security of Non-DoD Information Systems Processing Unclassified Nonpublic DoD Information, 9 December 2019

· SECNAVINST 5510.36B, DoN Information Security Program, 12 July 2019

· DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 December 2005 (incorporating Change 4, 10 November 2015)

· SECNAV Instruction 5211.5F, Department of the Navy Privacy Program, 20 May 2019

· SECNAV Instruction 5239.3C, DON Cybersecurity Policy, 2 May 2016

· SECNAV M-5239.21, DoN Information Assurance Manual, June 2016

· OPNAVINST 5239.1D, U.S. Navy Cybersecurity Program, 18 July 2018

· OPNAVINST 5239.4, Chief of Naval Operations Cybersecurity Safety Program, 14 September 2018

· SECNAV Manual M-5239.2, DON Cyberspace Information Technology and Cybersecurity Workforce Management and Qualification Manual, 27 June 2016

· SECNAV Manual M-5510.30, Department of the Navy Personnel Security Program, 1 June 2006

· CJCSI 6211.02D, Defense Information Systems Network (DISN) Responsibilities, 24 January 2012

· DoD Public Key Infrastructure (https://cyber.mil/pki-pke)

· ISO/IEC/IEEE 12207:2017 Systems and Software Engineering – Software Life Cycle Processes

· ANSI/EIA 649C-2019 – Configuration Management Standard

· ANSI/EIA 836B-2015 – Configuration Management Data Exchange and Interoperability

· Federal Risk and Authorization Management Program (“FedRAMP”)

· Department of Defense Cloud Computing Security Requirements Guide, Version 1, Release 3, dated 6 March 2017

· All applicable Security Requirements Guides, Security Technical Implementation Guides, and National Security Agency security configuration guides when assessment and authorization is required

· NIST SP 800-37 Revision 2, Risk Management Framework for Information Systems and Organizations, December 2018

· U.S. Navy Risk Management Framework Process Guide, Version 3.2, 2 September 2020

· NIST SP 800-53 Revision 5, Security and Privacy Controls for Federal Information Systems and Organizations, September 2020 includes updates as of 10 December 2020

· NIST SP 800-53A Revision 4, Assessing Security and Privacy Controls in Federal Information Systems and Organizations, December 2014, includes updates as of 18 December 2014

· NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, February 2020

· NIST SP 800-171A, Assessing Security Requirements for Controlled Unclassified Information, June 2018

· NAVSUPINST 5239.5, Cybersecurity and Defensive Cyberspace Operations Policy, 25 March 2019

· ISO/IEC 19770-1:2017 – Information Technology – IT Asset Management – Part 1: IT Asset Management Systems – Requirements

· ISO/IEC 19770-2:2015 - Information Technology -- Software Asset Management -- Part 2: Software Identification Tag

· ISO/IEC 19770 Series - Information Technology – IT Asset Management

· A Guide to the Project Management Body of Knowledge (PMBOK® Guide) - Sixth Edition

· Section 508 of the Rehabilitation Act of 1973 (amended by the Workforce Investment Act of 1998, 7 August 1998)

· SECNAVINST 5720.44C - Department of the Navy Policy for Content of Publically Accessible World Wide Web Sites, 21 February 2012 (incorporating Change 1, 14 October 2014)

· SECNAVINST 5510.30C, Department of Navy Personnel Security Program, 24 January 2020

· Homeland Security Presidential Directive (HSPD)12, Policy for a Common Identification Standard for Federal Employees and Contractors, 27 August 2004

· DoD Manual 5200.02, Procedures for the DoD Personnel Security Program (PSP), 3 April 2017 (incorporating Change 1, 29 October 2020)

· DoD Manual 5200.08-R, Physical Security Program, 9 April 2007, (incorporating Change 2, 19 October 2020)

· NTTP 3-13.3, Operations Security (OPSEC), September 2017

· DoD Instruction 5200.48, Controlled Unclassified Information (CUI), March 6, 2020

· NSAMECHINST 5530.1C CH-1, Naval Support Activity Mechanicsburg Installation Access Control, 23 August 2019

· ASN(RDA) and DON CIO Joint Memorandum, Department of the Navy Cloud Policy, 7 December 2020

· NAVADMIN 122-21, Navy Cloud Implementation Plan, 9 June 2021

5.0 Requirements/Tasks: The contractor shall perform every requirement in this performance work statement. Not every performance requirement has a related standard expressed in this document. In such cases the performance standard is either inherent in the requirement or performance is to be in accordance with standard commercial practice.

5.1 Planning / Management: The contractor shall:

5.1.1 Provide the technical, functional, and procedural activities required for the execution of all tasks and delivery of all capabilities specified within this performance work statement. Include information on management methods related to quality assurance, software updates, problem notification, problem resolution, license agreements, professional services, and general customer engagement methodologies.

5.1.2 Prepare an Implementation Plan describing the technical approach, organizational resources and management controls to be employed to meet the cost, schedule and performance requirements throughout execution. Provide status reports that addresses current licensing, software updates, known problems, upcoming enhancements, and the quality or need for any professional services that go beyond just providing a tool.

5.2 Product Implementation and Support/ Secure Computing Architecture (SCA) software Implementation: The contractor shall document and perform analysis, design, architectural reviews, and installation and configuration tasks required for successfully implementing DoD-compliant Secure Computing Architecture VDSS and VDMS stacks. The intent is that the contractor will perform the work on NAVSUP owned physical and/or virtual hardware within NAVSUP enterprise datacenters and host providers. The contractor shall:

5.2.1 Installations to include Cisco, Juniper, Palo Alto and F5 Big-IPs and/or add on additional modules/capabilities (plan and execute)

5.2.2 License, configure, manage, and sustain SCA software operations including the F5 Big-IP, Cisco, Juniper, and Palo Alto toolsets

5.2.3 Support onboarding customer and mission partner application/services that are expected to leverage SCA VDSS related software including Cisco, Juniper, Palo Alto and F5 Big-IP including new requirements for new installs and/or migrations from other environments

5.2.4 Troubleshoot SCA issues including those generated by the SCA implementations Cisco, Juniper, Palo Alto and F5 Big-IP to include general operations, SSL handshake/termination (break and inspect), traffic flow/issues, related network and server issues, performance related issues, and unique configurations (using F5 capabilities and/or 3rd party tools used by NAVSUP)

5.2.5 Support Big-IP/Big-IQ in multiple NAVSUP enterprise approved hosting environments

5.2.6 Installations to include Microsoft Windows servers, Microsoft SQL servers, Microsoft Internet Information Server (IIS), Red Hat Enterprise Linux servers.

5.2.7 Configure, manage, and sustain SCA software operations including the Host Based Systems Security, McAfee Agent for Windows, McAfee Policy Auditor Agent, McAfee DLP Endpoint, McAfee Asset Configuration and Compliance Module, McAfee VirusScan Enterprise and McAfee Host Intrusion Protection Service.

5.2.8 Configure, manage, troubleshoot and sustain SCA software operations including Security Content Automation Protocol Compliance Checker.

5.2.9 Configure, manage, troubleshoot and sustain SCA software operations including NESSUS Assured Compliance Assessment Solution.

5.2.10 Configure, manage, troubleshoot and sustain SCA software operations including Windows Server Update Services (WSUS).

5.2.11 Perform all required patches, upgrades, backups, restores as required.

5.2.12 Support a fully redundant HA environment.

5.3 Test, Evaluation & Interoperability: The contractor shall:

5.3.1 Create test plans and perform testing of the installation and configurations to ensure the product is operating properly to specification.

5.3.2 Assist the government team with any required interoperability testing and/or interoperability waiver requests as needed (not common).

5.3.3 Provide any internal testing results for the tool.

5.4 Security Engineering Certification and Accreditation: The contractor shall work in coordination with the government systems/network/host administrators and cyber security personnel to ensure the Secure Computing Architecture is granted and maintains an authority to operate (ATO) under the Navy Authorization Official (NAO). This help will include assisting the NAVSUP Validators by providing any documentation, software changes, or systems changes required for to receive an ATO.

5.5 Technical Documentation: The contractor shall document or provide access to maintained technical programming components. Where necessary, documents include: Test Plans, Test Procedures, Test Results, Configuration Baseline documentation, Engineering Change Requests, Installation Guides, Usage Guides, Administration Guides, Integration Guides, Configuration Recommendations and Software Updates. The contractor shall follow all Enterprise standards including the Service Delivery Model (SDM) and Project specific standards and requirements.

5.6 Product Support and Sustainment: The contractor shall provide ongoing support for the SCA tools including those indicated in Task 5.2 and its subtasks. This support shall include: support contact numbers and methods, patch updates/fixes, monitor and troubleshoot integrations, support hours, enhancement request procedures, and customer notification methods for issues and updates.

5.7 Application Migration Support: The contractor shall work with application owners who request migration from their current data centers to the SCA. This task includes:

5.7.1 Identifying Service Offerings: The contractor shall work with application owners to identify what services are needed by the application and determine if the services exist in the SCA.

5.7.2 Assist with Migrating Applications: The contractor shall assist the application owner with transferring data from their existing data center to the SCA environment.

5.8 Mentoring/Knowledge Transfer: The contractor shall complete tasks that will provide a comprehensive application Transfer of Knowledge to NAVSUP BSC personnel. Contractor shall present areas of knowledge transfer as succinct, shop usable lesson plans, including the following:

5.8.1 Contractor shall explain what procedures are incorporated into production are necessary for testing and how fixes /functional additions

5.8.2 Contractor shall provide walkthrough exercises of all application modules explaining each

5.8.3 Contractor shall have the government team assist on some easier tasks to become familiar

5.8.4 Contractor shall address government teams questions

5.8.5 Contractor shall assist Navy resources on troubleshooting and debugging problems

5.8.6 Contractor shall provide source code instructional tools Mentoring events shall be accomplished monthly covering the tasks of this PWS using the five Knowledge Transfer mechanisms defined below. The contractor shall actively provide daily mentoring support for Navy team while the contractor accomplishes daily activities. The intent of this mentoring is to ensure government employees have the knowledge and familiarity with the tasks to ensure Navy team independent processing of future similar tasks. BSC has provided an estimated number of monthly occurrences to provide a general basis for how frequently each technique may be implemented.

· Serial Transfer (estimated monthly occurrences: 4): the knowledge the contractor team has gained from doing a task in one setting is transferred to the Navy team for the next time the task is required in a different setting.

· Near Transfer (estimated monthly occurrences: 4): The explicit knowledge the contractor has gained from doing a frequent and repeated task is documented to be reused by Navy teams doing similar work.

· Far Transfer (estimated monthly occurrences: 8): Tacit knowledge the contractor has gained from doing a non-routine task is made available to Navy teams doing similar work in another part of the system. Tacit knowledge (as opposed to formal, codified or explicit knowledge) is the kind of knowledge that is difficult to transfer to another person by means of written transcript.

· Strategic Transfer (estimated monthly occurrences: 1): The collective knowledge of the contractor is needed to accomplish a strategic task that occurs infrequently but is critical to the Navy.

· Expert Transfer (estimated monthly occurrences: 1): A Navy team facing a question beyond the scope of its own knowledge seeks the expertise of the vendor for solution.

5.9 Project Management Support: The contractor shall support accomplishing program cost, schedule and performance goals and objectives while in the sustainment of programs and projects, from initial system deployment through end of system operations. The contractor shall prepare project management documentation required to support the operations, modification, maintenance, sustainment of NAVSUP SCA systems. The contractor shall:

5.9.1 Provide inputs for the establishment of cost, technical (performance), and schedule baselines, to include; coordinate and integrate each program’s schedule and milestones; create documentation that depicts the milestones, schedules, and inter-dependencies on a composite, functional area, and on an individual program basis; and record the achievement of each milestone and determine new schedules for missed milestones. The contractor shall support the management of and control of these baselines to document changes during the lifecycle of program and project.

5.9.2 The contractor shall support the development of associated documentation including agendas, minutes, action items, briefing material, Concept of Operations (CONOPs) and Charters.

5.9.3 The contractor shall coordinate meetings, conferences and work groups, and schedule rooms for program meetings. The contractor shall notify participants, provide agendas, directions and arrange for appropriate equipment. The arrangements shall be made in accordance with the procedures and schedule set by the requestor, and all changes or modifications approved by the requestor before implementation. The contractor shall submit a summary event report to include minutes and actions.

Performance Standard: All work associated with the tasks described in section 5 above will be consistent with industry best practices and following Enterprise and Project specific standards including software development and version control. All software released will follow the government Configuration Management process and management controls.

Assessment Method: All documents will be vetted and reviewed for completeness, sufficiency and accuracy with the Government and all identified stakeholders within five (5) business days

6.0 Deliverables: All deliverables must meet the format requirements specified by the Contracting Officer’s Representative (COR). Documentation related to these services shall be made available electronically. The following list details the contract deliverables:

6.1 Status Reports: Status Reports – Monthly status report shall be submitted electronically to the Technical Assistant (TA) and Contracting Officer’s Representative (COR) on company letter head in Microsoft Word and include the following elements:

· Resource(s) by name

· Date project/task received

· Percentage of project/task completed

· Estimated date of project/task completion

· Work performed during the week and task planned for the next week

· Issues/problems encountered and recommended solutions

· Identify any Government deficiencies that are overdue which impact schedule or performance

· Evaluate performance and determine adequacy of staffing.

6.2 Source Code: Contractor shall use the government’s repository tool, currently Azure DevOPS. All Code shall be checked-out before use and working updates checked in at the end of each day.

6.3 Documentation: Contractor shall provide the documentation listed below. This documentation shall be stored in a government approved repository.

6.3.1 – Plans

6.3.1.1 Project Plans

6.3.1.2 Implementation Plan

6.3.2 – Technical

6.3.2.1 Analysis / Design documents of the proposed approach

6.3.2.2 Diagrams for network and architectural reviews

6.3.2.3 Installation and configuration guides required for successfully implementing VDSS toolsets.

6.3.2.4 Test Plans detailing unit testing and integration testing approach and results

6.3.2.5 Supporting product documentation: Installation Guides, Usage Guides, Administration Guides, Integration Guides, Configuration Recommendations and Software Updates.

6.4 Knowledge Transfer: When written knowledge is to be captured, knowledge will be stored in wiki articles, MS Office documents (docs, spreadsheets, presentations) and stored in government approved knowledge repositories. Contractor will create log containing knowledge transfer tasks performed in MS Excel. Cumulative log will be delivered as part of the status reports from beginning of period of performance.

6.5 Monthly Payment Request: The contractor shall submit a monthly payment request (invoice) electronically using Wide Area Workflow (WAWF) by the 10th day of each month. WAWF is available on the internet at https://piee.eb.mil.

The Period of Performance (POP) for each invoice shall be for one calendar month. Included with the invoice shall be support documentation such as, but not limited to, travel authorizations (if applicable) and a monthly status report. Invoices received without the support documentation (in the correct format) will be rejected.

The contractor shall submit a final invoice or zero cost invoice to properly close out the contract.

6.6 Mandatory Annual Training: The contractor shall participate in DoD/DoN mandatory annual training when announced by the Government.

Contractors are required to complete the following mandatory training and any updated/future training as released: 1) Personally Identifiable Information (PII); 2) DoN Records Management: Everyone's Responsibility; 3) Anti-Terrorism/Force Protection Awareness; 4) Combating Trafficking in Person; 5) Operations Security (OPSEC); 6) Training & Readiness – The Active Shooter. The contractor shall complete DoD Cyber Awareness Challenge v4 mandatory training two weeks after contract award. Jacqueline Jamison 717-605-3357, or Antonio Arturet-Millan, 717-605-8192, are the POCs for the Cyber Awareness training. Training can be accessed at https://cyber.mil/training/cyber-awareness-challenge.

Deliverables General Statement: Unless stated otherwise, the following instructions apply to all deliverables:

· Deliverable due dates shall take into account the review periods described below.

· Draft deliverables will be reviewed and feedback and/or requested changes provided within 7 business days (unless otherwise specified).

· Government reserves the right to request a formal review session with the contractor during these timeframes and may request that the contractor make changes to any version of a deliverable.

· Government will review and approve or reject all final versions of all deliverables within 7 business days of receipt (unless otherwise specified).

· If any deliverable is rejected, the contractor will be notified within the specified time periods and will have 7 calendar days within which to rework the deliverable and resubmit for Government approval. All changes to any version of a deliverable and/or deliverable outline shall be approved by the COR. If more than the specified number of calendar days is required for Government review and approval, the COR will inform the contractor of the need for an extension within the initial review period.

· Contractor shall prepare and submit the deliverables on or before the required due date to the COR or designee via email. For deliverables that are not documents the contractor shall submit a description of the deliverable and any associated documentation or descriptive information. In no case shall any deliverable be received by the Government less than 21 calendar days prior to the end of the Period of Performance.

· Rejection of any deliverable by the Government does not excuse the contractor from meeting the baseline due dates for any other deliverables.

7.0 Performance Standards:

Secure Computing Architecture

Performance Requirement
Surveillance Method
Frequency
Acceptable Quality Level
Para 5.1
Prepare an Implementation Plan to be employed throughout execution.
TA will review documentation for completeness, sufficiency and accuracy.
Weekly
95%
Para 5.2
Document, analyze, design, perform architectural reviews and installation and configuration tasks to implement DoD-compliant Secure Computing Architecture VDSS and VDMS stacks.
TA will review documentation and installation for accuracy, sufficiency and completion.
Weekly
95%
Para 5.3
Create test plans and perform testing of the installation and configurations.
TA will review documentation and installation for accuracy, sufficiency and completion
Weekly
95%
Para 5.8
Mentoring and Transfer of Knowledge to NAVSUP BSC personnel.
TA will review documentation for completeness, sufficiency and accuracy.
Monthly
95%
Para 5.9
Prepare project management documentation to support the operations, modification, maintenance, sustainment of NAVSUP SCA systems.
TA will review documentation for completeness, sufficiency and accuracy.
Monthly
95%
CTIP
Compliance with FAR 52.222-50
COR will review documentation or interview contractor personnel
Annually
100%

8.0 Period of Performance (PoP):

This contract will have a performance period of 12 months and four, 12-month option periods.

9.0 Place of Performance:

The following location is the primary site for performance:

· Naval Support Activity, Naval Supply Systems Command, 5450 Carlisle Pike, Building 409, Mechanicsburg PA 17050 No contractor services shall be performed on Saturdays, Sundays, Government Holidays or during base closures. The contractor shall follow appropriate local base policy for reporting to work during severe weather and base closure. The contractor is not authorized to begin work until both the Visit Authorization Request (VAR) and System Authorization Access Request - Navy (SAAR-N) forms have been successfully processed and base and system access have been granted. Remote work is authorized with the coordination and approval of the COR.

10.0 Travel:

Travel will not be required.

11.0 Security:

Per DFARS 211.106, contractor employees shall identify themselves as contractor personnel by introducing themselves or being introduced as contractor personnel and displaying distinguishing badges or other visible identification for meetings with Government personnel. In addition, contractor personnel shall appropriately identify themselves as contractor employees in telephone conversations and in formal and informal written correspondence.

ACCESS TO FEDERAL FACILITIES

Per HSPD-12 and implementing guidance, all contractor employees working at a federally controlled base, facility or activity under this text will require a DoD CAC. When access to a base, facility or activity is required contractor employees shall in-process with the Command's Security Manager upon arrival to the Command and shall out-process prior to their departure at the completion of the individual's performance under the contract.

ON-BOARDING PROCESS

All contractor resource onboarding documents must be submitted via the prime contractor. An employee is considered to be “productive” upon completion of the following items:

a.Visit Authorization Request (VAR)
b.Contractor Information Request Form (CIRF)
c.FD-258 fingerprint card
d.Completed EQIP (Electronic Investigation) within 20 days after contract award
e.All contractor resource(s) must have an active JPAS profile within 20 days after contract award
f.Common Access Card (CAC)
g.System Authorization Access Request – Navy (SAAR-N)
h.Cyber Awareness Training Certification
i.Information Assurance (IA) certification (if applicable)
j.User Access Request (UAR)

Note (1): Invoicing by the contractor will begin as of the commencement of the performance period of services.

Note (2): Dual Citizenship and Foreign Nationals are not allowed access to the functional/system side of ERP/SAP.

TEMPORARY ACCESS

The Command's Security Manager may authorize issuance of a DoD CAC and temporary access to a DoN or DoD unclassified computer/network upon a favorable review of the investigative questionnaire and advance favorable fingerprint results. When the results of the investigation are received and a favorable determination is not made, the contractor employee working on the contract under temporary access will be denied access to the computer network and this denial will not relieve the contractor of his/her responsibility to perform.

Security Awareness Training Education The Prime Vendor shall make certain that all Contractors complete all required Security Awareness Training Education. Contractors shall register their Public Key Infrastructure (PKI) Certificates on their Common Access Card (CAC). Registering PKI certificates enable the Security Manager to track their training in Total Workforce Management Services (TWMS). At a minimum the contractor must annual complete Security Awareness, Anti-Terrorism Level I, OPSEC, and Counter Intelligence Awareness and Reporting, and Security Awareness.

OPSEC

Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise, as outlined in NTTP 3-13.3M/MCTP 3-32B. The contractor shall consult with the OPSEC Program Manager within 5 working days of receipt of order to determine all special circumstances affecting OPSEC under this requirement. In any case where there is uncertainty or ambiguity regarding OPSEC measures, the contractor shall consult the OPSEC Program Manager as soon as possible.

DoD 8570.01-M Information Assurance Workforce Improvement Program The contractor shall have Information Assurance (IA) Workforce Improvement Program certificates for Cybersecurity positions. See the Information Assurance Support Environment (IASE) website for DoD Approved 8570 Baseline Certifications:

https://cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/

______ No Additional IA Certification Required

__X___ Information Assurance DoD 8570.01-M Required:

IA Certification Level: IAT-2

Baseline Certification: CompTIA Security+ CE

Substitutes for Baseline Certification:

Cisco Certified Network Associate-Security (CCNA-Security) Cybersecurity Analyst (CySA+) GIAC Global Industrial Cyber Security Professional (GICSP) System Security Certified Practitioner (SSCP)

GSEC

CND

Computing Environment Certification: Microsoft Certified Solution Expert (MCSE), Red Hat Systems Administration or equivalent certification

Privileged system access is required.

Privileged Access. Individuals who have access to system control, monitoring, or administration functions (e.g. system administrator, database administrator) require training and certification to Information Assurance Technical Level 1. They must also be trained and certified on the Operating System or Computing Environment they are required to maintain. They must have IT-I security designation. A person with privileged access must have an initiated Single Scope Background Investigation (SSBI).

The COR will ensure that contractor personnel accessing DoD information systems have the appropriate and current information assurance baseline certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. Prior to being engaged and upon request by the Government, the Contractor shall provide documentation supporting the information assurance baseline certification status of personnel performing information assurance functions to the contracting officer. Contractor personnel who do not provide appropriate and current baseline certifications shall be deemed unauthorized to access DoD information systems.

The Contractor shall ensure that personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with DoD 8570.01-M, Information Assurance Workforce Improvement Program. The Contractor shall meet the applicable information assurance certification requirements, including:

1) DoD-approved information assurance workforce certifications appropriate for each category and level as listed in the current version of DoD 8570.01-M.

2) Appropriate operating system certification for information assurance technical positions as required by DoD 8570.01-M.

a) Upon request by the Government, the Contractor shall provide documentation supporting the information assurance certification status of personnel performing information assurance functions.

b) Contractor personnel who do not have proper and current certifications shall be denied access to DoD information systems for the purpose of performing information assurance functions.

Proof of the above indicated IA baseline certification is to be provided for all contractor personnel prior to time of engagement. In addition to the IA certificate, active enrollment and participation in the certification maintenance program must be established prior to contract award to ensure the appropriate access can be secured by contractor resources. All required IA baseline certifications must be current at the contract period start date; there is no “grace” period to obtain these certifications. Computing environment certification must be current no later than six (6) months after start. Questions and additional information requirements may be addressed by contacting the NAVSUP Business Systems Center Information System Security Manager (ISSM).

Certification shall be forwarded to:

Jacquelin Jamison, Code 94 NAVSUP Business Systems Center ISSM 5450 Carlisle Pike, Suite 409 Mechanicsburg, PA 17055 Email: Jacquelin.jamison@navy.mil

12.0 Government Furnished Equipment (GFE):

The government will furnish necessary office workspace for Contractor staff performing at NSA Mechanicsburg including computer hardware, software and access to local telephones. The government will furnish all equipment, tools and servers used to maintain software and host these applications. If the contractor is supporting off-site, the government will provide government furnished computers for access to government systems (if needed).

13.0 Qualifications/Experience:

Personnel who are assigned by the Contractor must be highly experienced and knowledgeable in the following areas:

· Direct experience with the following Microsoft Windows products and other services. Must be able to fully install, configure, modify, sustain, and troubleshoot the following:

· Microsoft Server OS, Microsoft SQL Server, Microsoft Internet Information Server (IIS) and Microsoft Windows Server Update Services (WSUS).

· Red Hat Enterprise Linux servers.

· Host Based Systems Security, McAfee Agent for Windows, McAfee Policy Auditor Agent, McAfee DLP Endpoint, McAfee Asset Configuration and Compliance Module, McAfee VirusScan Enterprise and McAfee Host Intrusion Protection Service.Secondary

· NESSUS Assured Compliance Assessment Solution

· Experience with a cloud provider infrastructure as a service and networking technologies (our preferred platforms include Amazon Web Services and Oracle Cloud Infrastructure)

14.0 Non-Disclosure Agreement (NDA):

Contractor and subcontractor employees performing work under this order are required to sign a Non-Disclosure Agreement (NDA) as part of their onboarding process. The contractor shall maintain copies of all signed agreements and have the documents readily available at the COR’s request. Refer to DFARS 252.204-7000, Disclosure of Information, and DFARS 252.204-7003, Control of Government Personnel Work Product.

15.0 NAVSUP Business Systems Center Procedures for Contractor Access/Visit Authorization Request (VAR):

1. A company letter to the Technical Assistant (TA) containing the following information:

a. Contract Information

1) Contract Number

2) Date Issued

3) Date of Expiration

4) Name and phone number of the TA

5) Purpose

6) Systems to be accessed

7) Files/Data required

8) Type of access required (i.e., inquiry/update/delete)

9) Equipment to be used with location and mode of access identified

10) Security point of contact including address and phone number

b. Information for all contractor employees requesting access, to include:

1) Full Name

2) Job Title

3) Date of Birth

4) Place of Birth

5) Citizenship

6) Social Security Number

7) Naturalization Number (if applicable)

8) Type and date of Security Investigation

9) Government Clearance Level (if applicable)

10) Valid email address for the Contractor’s employee

c. Appropriate Company Official's signature

2. A System Authorization Access Request Navy (SAAR-N) form (OPNAV 5239/14) with original signatures and a copy of the DOD Annual Cyber Awareness Challenge Completion Certificate for each contractor employee sent to the TA.

16.0 Points of Contact:

Technical Assistant (TA):

Name:Sean Murray
Organization/Code:NAVSUP Business Systems Center (Code 941)
Address:5450 Carlisle Pike, Suite 409
Mechanicsburg PA 17050-2411
Phone:(w) 717-605-6658
E-mail:sean.murray1@navy.mil

Alt-Technical Assistant (TA):

Name:Jerry Lester
Organization/Code:NAVSUP Business Systems Center (Code 941)
Address:5450 Carlisle Pike, Suite 409
Mechanicsburg PA 17050-2411
Phone:(w) 717-605-6658
E-mail:jerry.lester@navy.mil

Alt-Technical Assitant (TA):

Name:Matt Morley
Organization/Code:NAVSUP Business Systems Center (Code 941)
Address:5450 Carlisle Pike, Suite 409
Mechanicsburg PA 17050-2411
Phone:(w) 717-605-8007
E-mail:matthew.morley@navy.mil

COR/Invoice Acceptor:

Name:Brian McDonald
Organization/Code:NAVSUP Business Systems Center (Code 91)
Address:5450 Carlisle Pike, Suite 409
Phone:(w) 717-605-3454
E-mail:brian.c.mcdonald@navy.mil

File details come from the government source that posted it. Updated .