PWS Draft ITSS.docx

DOCX document 108 KB Posted

Attached to
RFI for USMC M&RA Information Technology Service & Support (ITSS) Federal contract opportunity
Solicitation number
M00264-25-RFI-007
Issued by
United States Marine Corps

About this file

This document is a draft Performance Work Statement (PWS) for Information Technology Service and Support (ITSS) required by the United States Marine Corps (USMC) Manpower and Reserve Affairs (M&RA) division. The PWS outlines the objectives, scope, and performance requirements for contractor support to maintain and enhance the Manpower Information Portal (MIP) system and related IT services. Key requirements include project management, new application development, database administration, cybersecurity, data analytics, and helpdesk support. The PWS describes the current MIP system environment, partnering philosophy, performance tasks, administration and general requirements, security considerations, and deliverables. This PWS is being provided as part of a Request for Information (RFI) for USMC M&RA ITSS, which is a pre-solicitation notice and not an actual solicitation.

View the file

Other files for this federal contract opportunity

Other files attached to RFI for USMC M&RA Information Technology Service & Support (ITSS), newest first.
File Type Posted
RFI.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

USMC MANPOWER AND RESERVE AFFAIRS

DRAFT Performance Work Statement (PWS) for Information Technology Service and Support (ITSS)

1 EXECUTIVE SUMMARY

The United States Marine Corps, Manpower and Reserve Affairs (M&RA), Manpower Information Technology (MIT) Branch requires the ability to efficiently develop and sustain software agnostic, cloud native applications in a cloud environment. Cloud native application services provide a wealth of benefits that M&RA can leverage to provide the right services, at the right place and time in service to our customers. This aligns with Department of Defense goals, provides a sound technical platform for the future force, and provides the best value for the taxpayer.

M&RA requires the ability to aggregate, transform, and analyze USMC manpower data. Analysis of USMC manpower data provides context and support to decisions made in the manpower space.

M&RA is adopting a Zero Trust strategy for its information systems. Legacy applications are being migrated to a microservices-based system using service-mesh architecture, attribute-based access control, and Identity, Credential, and Access Management (ICAM). Applications in support of this effort are to be developed through the DevSecOps framework using a continuous integration and continuous deployment (CI/CD) pipeline. Software supply chain security assurance measures are to be integrated into the CI/CD pipelines. This framework is currently being implemented and is scheduled for completion no later than fiscal year (FY) 2027.

2 MISSION

Manpower and Reserve Affairs (M&RA) employs integrated manpower systems across the service enterprise that attracts, develops, retains, and supports our Marines, their families, and our civilian workforce as they pursue their professional aspirations and personal career goals. Collectively, these systems provide our commanders a picture of the human “steel” necessary to fight and win the Nation’s battles. M&RA consists of eight divisions; this requirement supports the Manpower Information Technology Branch within Manpower Information Division.

Manpower Information Technology (MIT) Branch’s mission is to provide M&RA with all aspects of IT system support enabling the Marine HRDP. This support includes operation and maintenance of the Manpower Information Portal (MIP), application configuration and maintenance, database administration, cloud administration and support, product and technology management, web-page and user interface development, and customer support for the IT systems within the Department's purview. MIT Branch drives technical requirements and advancement to ensure Marine Corps talent management IT solutions keep pace with current technology industry standards with the staff assistance necessary to plan, develop, control, integrate, and enhance manpower information systems for both garrison and expeditionary environments.

3 SCOPE

The objective of this Performance Work Statement (PWS) is to provide support to the Manpower Information Portal (MIP) system and the MIT Branch.

The goal of this PWS is to provide M&RA with contractor support that will work jointly with Military and Federal civilian employees to support current and emerging M&RA information technology service and support requirements.

M&RA information technology requirements are dynamic in nature and subject to law, policy, and regulation changes. This effort will encompass the following specific types of ITSS for M&RA:

•Project Management
•New application development
•Maintenance and enhancement of legacy applications within the MIP System
•Database administration and maintenance support
•Network Engineering/Administration support
•Cybersecurity support
•Information Security Continuous Monitoring for M&RA and the MIP system
•Maintenance and enhancement of the M&RA SharePoint support

· Technology Evolution and Modernization

• Data Analytics support

4 CURRENT ENVIRONMENT

The MIP System supports active and reserve components and separated and retired Marines. Applications within the MIP System store, process, and display Personally Identifiable Information (PII) & Protected Health Information (PHI) and require Public Key Infrastructure compliance. The MIP System utilizes current versions of Red Hat Enterprise Linux and Oracle application and database tier. The web applications have a standard three-tiered architecture (web, application and database). Applications within the MIP System are currently coded in JSP, JSF, Angular, Java EE, and PLS/SQL. The database tier is currently in Oracle 19c. The web tier is Apache. As technology evolves and the cloud marketplace matures, M&RA may leverage emerging cloud technology for increased efficiency. Within the MIP System, production resides within AWS GovCloud (US) Information Level 4, pre-production resides within AWS GovCloud (US) Information Level 4, and development resides within AWS GovCloud (US) Information Level 2.

Reference Appendix D for a list of current applications, services and databases within the MIP System.

5 PARTNERING PHILOSOPHY

A major intent of this PWS is to create a "partnership" between MI Division and the contractor. Within the context of this PWS, "partnership" means an interactive, mutually-supportive professional relationship that is open, collaborative, agile, and customer-oriented. In addition to meeting the objectives described herein, the contractor will be expected to:

· Consistently take steps to understand M&RA’s current and emerging information technology requirements and propose suitable technical solutions, as appropriate.

·Proactively identify and propose improvements that will drive down application and sustainment costs, including systemic and process-related improvements, as appropriate.
·Work collaboratively with other contractors, Government agencies, and business partners to ensure mission success.
·Work collaboratively with other contractors and Government personnel implementing Information Technology Service Management (ITSM) best practices and fulfilling duties as services leads.

6 PERFORMANCE TASKS

The Contractor will be responsible for its overall responsiveness, cost control, adherence to schedules, technical quality of work, management of contractor team’s efforts, and the accomplishment of overall program objectives. Except for those items specifically stated as Government- provided in Section 7.9, the Contractor will furnish everything needed to perform this contract.

To achieve the objectives described above, the Contractor will perform the following tasks:

6.1 Project Management

6.1.1 Provide a primary Project Manager (PM), and alternate contractor point of contact that is responsible for the management of tasks, subtasks, and deliverables within this PWS.

6.1.2 Provide overall project management to include detailed project planning, progress planning, risk mitigation, requirements gathering, quality assurance, user training, and customer support.

Contract Data Requirements List (CDRL) A001: Executive Weekly Action Report (EWAR)

6.1.3 Email an Executive Weekly Action Report (EWAR) to the Contracting Officer’s Representative (COR) and Alternate Contracting Officer’s Representative (ACOR) by 1630 each Monday utilizing the agency template provided at award. This report updates problems and what actions are being taken to address them, suggestions for improvement, and any items that require a decision by the COR.

6.1.4 Ensure applications are maintained in accordance with references in Appendix B and C, and other superseding guidance as directed by the COR.

6.1.5 Mark all documents produced or revised by Contractors or developed through Contractor participation as "Contractor generated documents" or otherwise identified in an obvious manner that discloses the Contractor's participation, unless otherwise directed by the COR.

6.1.6 Coordinate and host a contract award kick-off meeting as determined by the COR. If the COR so determines, a kick-off meeting, for the purpose of discussing objectives and deliverables in order to achieve a clear and mutual understanding of contract requirements, will occur within five (5) business days after contract award at Marine Corps Base Quantico (Marsh Center Building), 3280 Russell Road, Quantico, VA, 22134 (or through other meeting methods as directed by the COR).

6.1.7 The PM will meet at least weekly with the COR via teleconference or at the location identified in 7.5.1 during the first month of the performance period to assess onboarding and other administrative requirements. Meetings will be as often as necessary thereafter, as determined by the COR at no further cost to the government. However, if the Contractor requests, a meeting will be held whenever a Contract Discrepancy Report (CDR) is issued at no further cost to the government.

6.1.8 Assess technical and functional documentation as they mature.

CDRL A002: Risk Mitigation Plan

6.1.9 Develop a Risk Mitigation Plan to support all project objectives and maintain a viable risk posture providing a mature defense-in-depth implementation ensuring confidentiality, integrity, and availability to M&RA data and any future systems and infrastructure.

6.1.10 Plan and conduct quarterly contract status meetings. The primary purpose of these meetings is to review contract performance status and address contract-related issues. Meetings are expected to last no more than one (1) hour. At a minimum, the meeting will include appropriate Contractor representative, the Contracting Officer, the COR, and Government technical personnel, as appropriate; however, the Contracting Officer may choose to include other Government attendees.

6.1.11 This meeting will be held via phone conference call, or at a location determined by the Contracting Officer. The Contractor is responsible for setting up the phone conference facilities.

6.1.12 Each meeting will cover the following contract status topics, as appropriate:

· Status of contract deliverables/tasks (updates since last meeting).

· Performance issues encountered or expected (e.g., potential delays).

· Required Government actions.

· Compliance with staffing / critical personnel requirements (see PWS 7.8).

· Funding status of LH and T&M CLINs.

· Contract modifications, requests, claims, etc..

· Invoice submission, payment status.

· Discussion on contractor performance against QASP metrics.

· Discussion of LH CLIN utilization.

CDRL A003: Quarterly Meeting Minutes

6.1.13 Provide meeting minutes to the Contracting Officer within seven (7) business days of the meeting.

6.2 Platform Support

6.2.1 Maintain and update change requests in the government’s tracking system.

6.2.2 Perform MIP capacity management to ensure IT resources are in place and available to satisfy planned needs and ensure those assets are effectively used. Identify any issues and recommended remediation to the COR.

6.2.3 Provide consolidated billing for Cloud Service Provider to support the Government’s business and operations utilizing ODC funds.

6.2.4 Inform the COR on AWS Marketplace offerings that could benefit M&RA.

6.2.5 Advise the COR on estimated costs with usage and ways to reduce this cost in AWS GovCloud.

6.2.6 Recommend improvements to infrastructure security architecture and tools.

6.2.7 Monitor performance and throughput of the MIP and provide monthly report to the COR.

6.2.8 Perform analysis of performance metrics and conduct performance tuning where necessary to meet or exceed identified service levels and acceptable quality levels (see Appendix E) and include summary of analysis in monthly report to COR.

6.2.9 Ensure the MIP meets or exceeds defined performance and availability standards as outlined in Appendix E.

6.2.10 Report all outages or component failures to the COR within 30 minutes of identification or first report.

6.2.11 Provide subject matter expertise to support development and maintenance of the MIP contingency plan in accordance with NIST SP 800-34, the system security plan, and the MIP continuous monitoring program. Assist the ISSM in assessing the contingency plan to ensure successful recovery from system disaster.

6.2.12 Assist the ISSM in establishing and maintaining Configuration Management (CM) and Change Management processes in accordance with NIST SP 800-128, NIST SP 800-53 CM-1 through CM-9, and FIPS 200.

6.2.13 Provide subject matter expertise and support to the ISSM in establishing a configuration management database (CMDB) to track and document the configuration of IT assets and components.

6.2.14 Support the ISSM in establishing version control processes for the MIP system.

6.2.15 Provide recommendations and support the implementation of automation tools and technologies to streamline change and configuration management workflows.

6.2.16 Provide subject matter expertise in the implementation of Zero Trust (ZT) in accordance with the DoD Zero Trust Strategy, DoD Zero Trust Reference Architecture, DON Zero Trust Implementation Plan, supporting USMC direction, NIST SP 800-204, NIST SP 800-204a-d, NIST SP 800-207, NIST SP 800-207a.

6.2.17 Provide subject matter expertise to assist in building, authorizing, and maintaining a Continuous Integration / Continuous Delivery (CI/CD) pipeline for the MIP.

6.3 Database Administration

6.3.1 Provide database administration and maintenance support to the MIP’s databases (see Appendix D for list of databases).

6.3.2 Provide database monitoring, optimization, development, and data querying.

6.3.3 Build and maintain “working documents” and/or “how to guides” in support of Database Administration.

6.3.4 Provide account creation and maintenance, user assistance, data training, and knowledge transfer for Manpower personnel.

6.3.5 Provide security administration, auditing, and disaster recovery support. Databases will be compliant with current cybersecurity guidelines as set forth in Security Technical Implementation Guidelines (STIG) and the M&RA vulnerability management program.

6.3.6 Ensure databases are maintained in accordance with DoD Directives (See Appendix B and C) and other superseding guidance as directed by the COR.

6.3.7 Maintain configuration management of production and development databases in accordance with the MIP system security plan and MIT Branch configuration management processes.

6.3.8 Ensure production and developmental databases are identical, unless otherwise approved by the Government, for all security, software, and data configurations.

6.3.9 Provide expert technical advice in leveraging cloud native database technologies to ensure effective and efficient cloud operations.

6.3.10 Ensure RMAN (Oracle Databases) are backed up daily; ensure all back-ups are current, secure, and available.

6.4 Application Development

6.4.1 Develop new applications within the MIP System (up to 4 per year) in latest version of Java, Angular, or other required language(s) directed by COR.

CDRL B001

6.4.2 Maintain/enhance applications within the MIP System as directed by the COR.

6.4.3 Use the Government tracking system to manage all application requirements and system change requests.

6.4.4 Document a level of effort (LOE) to complete the ECP within the assigned ticket prior to beginning change requests.

6.4.5 Test changes in the developer’s local environment before pushing to Government provided development environment (MIT refers to as “user acceptance testing” (UAT) environment).

6.4.6 Test changes in UAT environment before notifying the MIT Application Team Lead.

6.4.7 Push code changes live at a time/day approved by the Configuration Control Board.

6.4.8 Evaluate the production environment, to ensure all changes were successfully deployed and submit the results to the MIT Change Manager.

6.4.9 Provide expert technical consulting and analyst support necessary to document, design, and implement required changes.

6.4.10 Provide skilled technical onsite daily support for Manpower applications and troubleshooting expertise in Oracle Database, Web Logic, Java, Angular, Docker, GitLab, and SQL technologies.

6.4.11 Provide configuration management, version control and bug tracking of all source code, servers, web applications, architectures, and their associated configurations within the MIP System.

6.4.12 Ensure that MIP applications are maintained in accordance with appropriate Department of Defense (DoD) directives, policies and guidelines.

6.4.13 Develop Mobile Applications as required.

CDRL B002

6.4.14 Provide skilled technical expertise and guidance in emerging and cloud native technologies to ensure the applications are using industry standards.

6.4.15 Configure applications to meet DoD Zero Trust requirements as required.

6.4.16 Integrate applications into MIP’s Continuous Integration / Continuous Delivery (CI/CD) pipeline as required.

6.4.17 Update applications to microservices-based architecture with a service mesh as required.

6.5 Helpdesk Support

6.5.1 Provide help desk support for MIP Applications Monday through Friday, from 0730 through 1630 Eastern Time, with the exception of all Federal holidays, by fielding calls, answering emails, resolving issues wherever possible, and referring issues that cannot be immediately resolved to higher level support.

6.5.2 Provide help desk support on Saturday, from 0730 through 1630 Eastern Time, when required.

6.5.3 Develop and maintain “how-to” guides to fix common MIP issues.

6.5.4 Develop and maintain a turnover binder detailing helpdesk tasks, history, and documentation.

6.5.5 Create and maintain a ticketing system to capture metrics on common issues and provide recommendations on how to reduce calls and emails.

6.5.6 Manage access control and associated trackers to applications as required.

6.5.7 Provide support to build and maintain manpower webpages and SharePoint.

6.6 Cybersecurity Support

6.6.1 Support the implementation of the Risk Management Framework for the Manpower Information Portal in accordance with NIST SP 800-39, NIST SP 800-37, and DoDI 8510.01.

6.6.2 Support the adoption and implementation of the guidelines set forth in NIST SP 800-53r5 (Security and Privacy Controls for Information Systems and Organizations) for the MIP.

6.6.3 Endpoint Security

6.6.3.1 Using Cyber Operational Readiness Assessment (CORA) methodology as a foundation, conduct weekly audits of Manpower Information Portal devices to identify vulnerabilities, gaps, and potential threats in a Trellix and Microsoft endpoint security environment that ensures compliance with NIST, DISA, DoD, DON, and Marine Corps standards.

6.6.3.2 Implement and maintain endpoint protection solutions to safeguard systems against malware, ransomware, and other malicious activities for the Manpower Information Portal.

6.6.3.3 Provide guidance and support to administrators for systems directly supporting the M&RA mission regarding best practices for endpoint security and threat mitigation.

6.6.3.4 Establish compliance reporting and dashboards that support monitoring endpoint security task order compliance for all systems directly supporting the M&RA mission.

6.6.4 Vulnerability Management

6.6.4.1 Conduct vulnerability management through the M&RA Patch and Vulnerability Group in accordance with NIST SP 800-40r2-r4, DoDI 8531.01, and the JFHQ-DoDIN IAVM Program.

6.6.4.2 Perform vulnerability scanning, web vulnerability scanning, Static Analysis Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Security Technical Implementation Guide (STIG) vulnerability assessments and scans on systems, networks, and applications, as directed, to identify and mitigate security weaknesses.

6.6.4.3 Continuously monitor and evaluate emerging threats and vulnerabilities to proactively mitigate potential risks.

6.6.4.4 Provide vulnerability remediation prioritization recommendations through impact assessment results, environmental metrics, base metrics, and temporal metrics using the Common Vulnerability Scoring System (CVSS).

6.6.4.5 Ensure all vulnerabilities identified that cannot be remediated within required timelines are mitigated and documented in the system POA&M using the USMC Governance, Risk, and Compliance tool.

6.6.4.6 Using CORA assessment methodology as a foundation, establish compliance reporting and dashboards that support monitoring vulnerability scanning and vulnerability management task order and DoD policy compliance for all systems directly supporting the M&RA mission.

6.6.5 Incident Response

6.6.5.1 Maintain the M&RA Incident Response policy in accordance with DoDI 8530.03 and related DON and USMC direction.

6.6.5.2 Develop and document annual tabletop exercises for MIP incident response and related plans (e.g. crisis communication plans, contingency plans) in accordance with NIST SP 800-84.

6.6.5.3 Participate in incident response tabletop exercises for all systems directly supporting the M&RA mission and incorporate lessons learned into M&RA and MIP Incident Response policies, where applicable.

6.6.6 Information Security Continuous Monitoring

6.6.6.1 Support Information Security Continuous Monitoring (ISCM) monitoring plans for systems directly supporting the M&RA mission in accordance with NIST SP 800-137.

6.6.6.2 Establish and maintain continuous monitoring mechanisms to detect and enable response to security incidents in real-time through BDP, AWS Cloud Watch, Cloud Trail, and system auditing.

6.6.6.3 Maintain CMRS reporting requirements for each system supporting the M&RA mission.

6.6.6.4 Monitor and maintain M&RA Privileged Access Agreements and inform privileged users of PAA expiration with 30 days’ notice.

6.6.6.5 Provide monthly basic and annual detailed assessments of ISCM plans for systems directly supporting the M&RA mission IAW NIST SP 800-137a and NISTIR 8212.

6.6.6.6 Develop a tools and gap analysis for continuous improvement and automation of M&RA continuous monitoring program.

6.6.6.7 Ensure all POA&M items for the MIP are updated at least every 7 calendar days.

6.6.6.8 Monitor POA&Ms for all M&RA supporting systems and report POA&M items that have not been updated for longer than 7 calendar days.

6.6.7 Provide Information Systems Security Engineer (ISSE) support for the Configuration Control Board and Engineer Review Boards, as required to ensure all changes are meeting DoD, DoN, and USMC cybersecurity requirements and industry best practices.

6.6.8 Support development and maintenance of Privacy Impact Assessments (PIAs) for the Manpower Information Portal and the applications within the Manpower Information Portal.

6.6.9 Provide support for assess-only authorizations, Operational Directives, Marine Corps Directives (MCD), Marine Forces Cyberspace Command (MFCC) direction, White Team, Red Team, and Cyber Protection Team (CPT) coordination, and Inspector General audits.

CDRL A004: M&RA Monthly Cybersecurity Report

6.6.10 Maintain monthly reporting for the M&RA cybersecurity program. Reports will include, but are not limited to:

6.6.10.1 ATO and PIA status for each system directly supporting the M&RA mission.

6.6.10.2 Incident status and trends

6.6.10.3 DoDI 8531.01 and ACAS TASKORD 20-0020 or successor direction compliance with trend analysis

6.6.10.4 Endpoint Security compliance with TASKORD 8600-24 and successor direction with trend analysis

6.6.10.5 NIST SP 800-107a continuous monitoring with trend analysis

6.6.10.6 Vulnerability management status with trend analysis that includes weighted average vulnerability management scores in accordance with JFHQ-DoDIN methodology, include vulnerabilities of note

6.6.10.7 POA&M item status for POA&M items with mitigated risk levels of “High” or greater for systems directly supporting the M&RA mission

6.6.10.8 Maturity ratings for DevSecOps in the M&RA CI/CD pipelines

6.6.10.9 Zero trust implementation status for each system directly supporting the M&RA mission

6.6.10.10 Action items for AO and M&RA leadership

CDRL A005: MIP Weekly Cybersecurity Report

6.6.11 Establish and maintain weekly reporting in support of the Manpower Information Portal continuous monitoring program.

6.7 Data Analysis

6.7.1 Provide data analysis in response to customer requests submitted via the Personnel Data Support Request (PDSR) application.

6.7.2 Develop and maintain dashboards as required.

6.7.3 Develop and maintain “how-to” guides on common analyses.

6.7.4 Develop and maintain a turnover binder.

CDRL A006: Manpower Data Dictionary

6.7.5 Develop and maintain a data dictionary for manpower data.

7 ADMINISTRATION AND GENERAL REQUIREMENTS

7.1 Spillage Responsibilities

7.1.1 In addition to complying with the references in Appendix B and C, the Contractor will comply with the following:

7.1.2 The Contractor will promptly assist and coordinate with the Government when notified by M&RA MIT of a spillage.

7.1.3 The Contractor will immediately report to the Government any spill of data by the Contractor into the environment hosting M&RA MIT data. The Contractor will clean up the spill in accordance with the DoD Cloud Computing Security Requirements Guide and DFARS 252.239- 7010 at no further cost to the government.

7.1.4 If the Contractor incurs additional cost to correct the spillage, or the effort to correct the spillage causes a delay in the performance of any part of the work under this contract, and such costs or delays were not caused by any act or omission of the Contractor, an equitable adjustment may be made in accordance with DFARS 252.243-7002.

7.1.5 Contractor requests for an equitable adjustment after final payment under this contract will not be allowed.

7.2 Contract Management

7.2.1 The Contractor will establish and provide a qualified workforce capable of performing the required tasks. The Contractor will monitor work performance, measure results, ensure delivery of contracted product deliverables and solutions, support management and decision-making, and facilitate communications. The Contractor will identify risks, resolve problems, and verify effectiveness of corrective actions. The Contractor will institute and maintain a process that ensures problems and action items discussed with the Government are tracked through resolution and will provide timely status reporting. Results of Contractor actions taken to improve performance will be tracked, and lessons learned incorporated into applicable processes and given to the COR after actions completed. The Contractor will establish and maintain a documented set of disciplined, mature, and continuously improving processes for administering all contract and contract efforts with an emphasis on cost-efficiency, schedule, performance, responsiveness, and consistently high-quality delivery.

7.2.2 The Government anticipates a one (1) to two (2) month delay in full operational capability while the Government assists the Contractor obtaining the necessary credentials and access to the M&RA system, The Project Manager must be on-site at contract award, and at a minimum, all Critical positions must be filled no later than 15 business days after the start of the period of performance; all remaining positions must be filled no later than 30 business days after the start of the period of performance.

7.2.3 No later than five business days after contract award, the contractor will provide the COR a written timeline and plan for accomplishing, at a minimum, the below tasks. In the event circumstances warrant the Phase-In Plan is not required, the COR will promptly notify the Contractor CDRL A004 is not required:

7.2.3.1 Assuming Database Administration responsibilities;

7.2.3.2 Assuming Information Technology Service Management responsibilities;

7.2.3.3 Assuming Application Development responsibilities;

7.2.3.4 Assuming Help Desk & Web Design responsibilities;

7.2.3.5 Assuming Cyber Security responsibilities;

7.2.3.6 Conducting a joint inventory of Government provided workstations.

CDRL A007: Phase-In Plan

7.3 Security and Documentation Support

7.3.1 The Contractor will provide reviews and reports on proposed changes to system hardware, software, or environment for impacts to the system security posture and system authorization.

7.4 Records, Files, and Documents

7.4.1 All physical and electronic records, files, documents, and work papers, provided and/or generated by the Government and/or generated for the Government in performance of this PWS, maintained by the Contractor which are to be transferred or released to the Government or successor contractor, will become and remain Government property and will be maintained and disposed of in accordance with Management of Records, Records Disposition – Procedures and Responsibilities; the Federal Acquisition Regulation, and/or the Defense Federal Acquisition Regulation Supplement, as applicable. Nothing in this section alters the rights of the Government or the Contractor with respect to patents, data rights, copyrights, or any other intellectual property or proprietary information as set forth in any other part of this PWS or the Application Services contract of which this PWS is a part (including all clauses that are or will be included or incorporated by reference into that contract).

7.5 Place of Performance / Hours of Operation

7.5.1 Services will be performed at Marine Corps Base Quantico (Marsh Center Building), 3280 Russell Road, Quantico, VA, 22134.

7.5.2 The Contractor may be able to perform certain tasks remotely (e.g. telework), however it is not guaranteed that telework will be authorized, or, if authorized, not limited in scope by the COR. Telework is determined only with expressed coordination between the Contractor and the COR.

7.5.3 The Contractor must be available to conduct business, correspond and attend meetings with the Government during normal duty hours. Normal duty hours are 0700 - 1700 ET Monday through Friday, except for all Federal holidays or when the Government facility is closed. The Government facility may be closed due to weather conditions, power outages, water outage, or due to a local or national emergency.

7.5.4 Maintenance occurs every Thursday from 1800 ET until complete.

7.5.5 The Contractor may be required outside normal duty hours for any mission critical event(s) determined by the COR that requires immediate attention.

7.6 Travel

Travel is not anticipated in the execution of this contract. The Government will not reimburse travel and related expenses to the contractor for daily travel to and from the contractor’s facility or the Marsh Center Building.

7.7 Management/Acquisition of 3rd Party Software Licenses

7.7.1 The Contractor will provide the COR with the rationale for obtaining software for this effort. Software licenses will be transferable to the Government and will not conflict with Federal law or the needs of the Government. Prior to purchase, the licenses will be submitted to the Contracting Officer (KO) and COR for review. If the KO determines provisions are inconsistent with Federal law and regulation or does not meet Government needs, e.g., does not provide a license of the required scope, the Contractor will negotiate changes with the software vendor at no additional cost to the Government. After the KO's review of the license provisions, price quotes for software and licenses will be submitted to the KO and COR for review prior to purchase. If the Contractor is unable to negotiate changes that are acceptable to the Government, the KO and COR will be notified immediately. The Contractor will obtain the KO’s concurrence prior to proceeding with any software and licenses procurement.

7.7.2 Licenses or Terms and Agreements for third party software acquired on behalf of the Government will not include the following:

7.7.3 Indemnification – IAW 13 USC 1341 - Government cannot indemnify vendor; all indemnification language will be removed.

7.7.4 Patent & Copyright Infringement Litigation - 28 USC 516 - Only the Department of Justice (DOJ) has authority to control any Intellectual Property litigation on behalf of the Government; any contradictory language will be removed.

7.7.5 Disputes, Venue & Jurisdiction – IAW 41 USC 71, FAR 52.21204(d) – The Contracts Disputes Act places venue in Federal Court; licenses will not have jurisdiction and venue in State Court.

7.7.6 Binding Arbitration - FAR 33.214(g) – Will not agree to binding arbitration.

7.7.7 Automatic Renewal 31 USC 1341 – No automatic renewal language is acceptable, as it poses a potential Anti-Deficiency Act (ADA) violation.

7.7.8 Payment, NET 30 days - 31 USC 3903 - Payments are subject to the Prompt Payment Act; NET 30 payment will not be guaranteed.

7.7.9 Order of Precedence - FAR 52.212-4(s) will be the "official" order of precedence rather than one submitted by the licensor.

7.7.10 Audit Clause - Will be replaced with "upon conclusion of the license and upon written request of the licensor, the Government will provide a certificate of compliance duly executed by an official with authority to provide such certification."

7.7.11 Termination Rights – IAW FAR 52.212-4(l) & (m) - There will be no unilateral termination by the licensor.

7.7.12 Installation and other restrictions – There will be no click licenses and the Contractor will be certain license agreement comports with mission requirements.

7.7.13 Third Party Software - Imbedded software will be identified and checked for legal sufficiency and authorization to be used on the Marine Corps Enterprise Network (MCEN).

7.7.14 Taxes – IAW FAR 52.212-4(k) – Any applicable taxes will be included in the licensor’s price.

7.8 Staffing and Critical Positions

7.8.1 Staffing

7.8.1.1 All tasks prescribed in this PWS require 100% staffing at the beginning of the period of performance. The contractor must provide personnel at the appropriate level of staffing to meet the requirements, application of qualified capabilities, floating or cross-trained personnel, and staff resource balancing, for the support described throughout Section 6. The contractor will, as an independent contractor, and not as an agent of the Government, furnish all management, labor, tools, supplies, and materials (except as provided by the Government) necessary to perform the requirements contained in the PWS.

7.8.2 Critical Positions

7.8.2.1 Certain skilled experienced professional and/or technical personnel are essential for accomplishing the work to be performed. These individuals are defined as “Critical Positions” and are those persons whose resumes were marked by the vendor as “Critical Position” and submitted in the contractor’s proposal.

7.8.2.2 The Contractor agrees that personnel in the designated critical positions in Table 1 will not be removed from the contract effort, replaced or added to the contract without a compelling reason and without compliance with this section. The Government will not approve substitutions for the sole convenience of the Contractor. No substitution or replacement of the critical positions will be authorized within the first 240 days after contract award.

7.8.2.3 The Contractor will submit a request, via email, to the COR and KO at least six months prior to voluntarily diverting any critical positions to other programs or contracts. The Contractor’s request must provide justification for the replacement, identify the proposed replacement, and explain how the replacement's skills, experience, and credentials meet or exceed the requirements of the contract. The proposed replacement’s resume and a signed letter of intent will accompany the request. The KO and COR will evaluate such requests and promptly notify the Contractor of approval or disapproval. The Contractor will not divert, replace, or announce any such change to critical positions without the written consent of the KO.

7.8.2.4 If the Contractor terminates an employee for cause or the employee separates from the Contractor voluntarily, with less than a thirty-day notice, the Contractor will provide the maximum notice practicable under the circumstances. Any personnel the Contractor offers as a replacement will possess experience and qualifications equal to or better than the requirements of the contract.

Table 1: Contract Critical Positions

Billet
CIO-SP3 Labor Category
Minimum Qualifications Required
Project Manager
Project Manager
· AWS Certified Cloud Practitioner

· Lean Six Sigma Certification

· AWS Cloud Economics Accreditation

· Bachelor’s Degree

Amazon Web Service (AWS) GovCloud Lead
Subject Matter Expert
· AWS Certified Solutions Architect

· AWS Certified Development Operations Professional

· AWS Certified System Administrator

· AWS Certified Developer

· Bachelor’s degree in Computer Science or related degree

· Tier 3 Security Clearance

Oracle Expert / Technical Lead
Subject Matter Expert
· CompTIA Security+

· Masters Degree in an Computer Science, Cyber Security or other related field

Senior Application Developer
Application Programmer
· CompTIA Security+
Cyber Security Specialist
Computer Security System Specialist
· Bachelor’s degree in Computer Science, Computer Engineering, Mechanical Engineering or other relevant degree

· Certified Information Systems Security Professional (CISSP)

· Information Systems Security Certification Consortium (ISC)2

· DISA Host Based Security System Admin

· DISA Host Based Security System Advanced

· DISA Assured Compliance Assessment Solution

· Tier 3 Security Clearance

Database Administrator
Database Management Specialist
· CompTIA Security+

· Oracle Database Administrator Certified Associate (OCA)

· Oracle SQL Fundamentals

· 5+ years experience as an Oracle Database Administrator

Data Analyst
Database Management Specialist
· CompTIA Security+

· Oracle Database Administrator Certified Associate (OCA)

· Oracle SQL Fundamentals

7.9 Government Furnished Workstations

7.9.1 The Government may provide workstations, such as desks, chairs, telephones, cell phone, and computers that are incidental to the place of performance for the Contractor to use in the performance of the contract. If provided, the Contractor will account for and maintain all Government furnished workstations. Management of the Government’s cloud environment will be done only with Government-authorized equipment. Exceptions to this must be approved by the COR in advance.

7.9.2 Government furnished property (GFP) clauses are effective in the event Government furnished computers are taken off-site (e.g. situational telework). Government furnished property under this contract is provided in Attachment 1, GFP List.

7.10 Security Requirements

7.10.1 Security Clearance Requirements. All contractors require a minimum of a Tier 1 security clearance (formerly NACI Level 1). The AWS GovCloud Lead, Information Assurance Manager and any other contractor performing tasks within section 6.7 of this PWS require a Tier 3 – non critical sensitive (SECRET) clearance. Contractor personnel will possess appropriate security clearances as of contract award date. This contract, its attachments and appendixes are unclassified.

7.10.2 Citizenship and Clearance Requirements. All personnel that will access classified information, classified systems, or classified areas, will be US citizens and have a valid security clearance. Contractor personnel that will not access classified information, systems, or areas, are required to have and maintain a public trust.

7.10.3 Identification Badges. The Contractor will comply with Marine Corps Base Quantico’s (MCBQ) or other federal Government facility’s contractor identification procedures, including identification of contractor status at meetings. The Contractor personnel will comply with all MCBQ rules, regulations, and security requirements when entering, visiting, or leaving the base. These rules, regulations, and security requirements include the following: presenting valid identification for base entrance, obeying all posted directives, and providing strict adherence to the Provost Marshal Office (PMO) direction in instances where the PMO have been dispatched to a particular location. The contractor is required to provide identification badges for their employees. All contractor personnel will wear these badges while on duty on the Government site. Badges are required to identify (including photograph) the individual, company name, and be clearly and distinctly marked as contractor. Size, color, and style are to be mutually agreed to by the Contractor and COR.

7.10.4 Identification in the Workplace. When conversing with Government personnel during business meetings, over the telephone or via electronic mail, contractor/subcontractor personnel will identify themselves as such to avoid situations arising where sensitive topics might be better discussed solely between Government employees. Contractors will identify themselves on any attendance sheet or any coordination documents they may review. Electronic mail signature blocks will identify their company affiliation. Where practicable, contractor/subcontractors occupying collocated space with their Government program customer should identify their work space area with their name and company affiliation.

7.10.5 Contractor Consent to Background Checks. All contractor personnel must consent to a Law Enforcement Automated Data System (LEADS) Check or National Agency Check with Written Inquiries (NACI). The Contractor will conduct the background checks on all of its employees working under this contract. The Contractor will not employ persons for work on this contract if such employee is identified as a potential threat to the health, safety, security, general wellbeing or operational mission of the installation and its population, nor will the Contractor employ persons under this contract who have an outstanding criminal warrant as identified through the National Crime Information Center (NCIC). Background checks will verify if a person is wanted by local, state, and federal agencies. Information required to conduct a background check includes: full name, driver’s license number, and/or social security number, date of birth, and completion of a background check questionnaire. Completion of a successful background check does not invalidate the requirement for having the appropriate level of security clearance and an escort when the Contractor personnel are working within controlled or restricted areas.

7.10.6 Access to Installation during Force Protection Conditions (FPCONs). The Contractor will be assigned a mission essential designation IAW requirements contained in the installation’s Integrated Defense Plan or Installation Antiterrorism Plan. Only the installation commander or the unit commander requesting contract services will assign the mission essential designation.

7.10.7 Access to Government Facilities with Controlled or Restricted Areas. The Government, based on assessment of the Contractor’s need, will provide the Contractor access to M&RA facilities from the commencement of the contract until contract completion. Only contractor personnel possessing the proper clearance will be authorized entry to restricted areas. All contractor personnel must either have the appropriate building access permissions and ID cards or otherwise must be continuously escorted by Government approved personnel. The MI Program Management Office, M&RA, or its successor organization, will assist contractor personnel in processing the necessary DoD forms to obtain base or area badges for access to Government facilities.

7.10.8 Physical Property Protection. Property protection for facility where the Contractors’ primary work center is located will be the responsibility of the local facility manager and local Government Security Manager, or their duly authorized representative, Integrated Defense and command/local directives. The Contractor will safeguard all Government-owned equipment and materials in his/her possession or use.

7.10.9 Data/Intellectual Property Protection. At the completion of the contract or when turning-in Government IT equipment to the Government, the Contractor will not remove, change, or manipulate data, files, computer code, operating systems, and other information residing on any Government owned/provided storage media in the use and care of the Contractor without the expressed written authorization by the Contracting Officer or the COR. This requirement is invoked whether the computer files are placed there by contractor employees in the course of contractor performance, or otherwise provided by the Government or the Contractor. Also, in no case will the Contractor destroy or remove data on a Government owned storage media or device to a point that it is not easily recoverable using OS data recovery tools, without expressed written permission of the Government.

7.10.10 Safeguarding Classified and Unclassified Information. The Contractor will handle and safeguard all classified and unclassified information in accordance with DoD standards for storing, processing, and handling classified or unclassified information and systems. Contractor personnel will have the appropriate security clearance for the facilities in which the work is required.

7.10.11 Non-Disclosure Requirements. In performance of this contract, the Contractor may have access to sensitive, non-public information. The Contractor agrees to (a) use and protect such information from unauthorized disclosure in accordance with DoDI 8582.01, Security of Unclassified DoD Information on Non-DoD Information Systems, Ch. 1 27 October 2017; (b) use and disclose such information only for the purpose of performing this contract and to not use or disclose such information for any personal or commercial purpose; (c) obtain permission of the Government before disclosing/discussing such information with a third party; (d) return and/or electronically purge, upon Government request, any non-public, sensitive information no longer required for contractor performance; and (e) advise the Government of any unauthorized release of such information. In accordance with FAR 9.505-4, contractor and subcontractor must sign a company to company non-disclosure agreement whenever contractor or subcontractor employees may gain access to proprietary information of other companies and provide those agreements to the Contracting Officer. The Government will require contractor personnel to sign a non-disclosure statement to protect non-public and sensitive information of other contractors and/or the Government; the Contractor will deliver these to the Government.

7.10.12 Protection of System Data. Unless otherwise stated in the contract, the Contractor will protect system design- related documents and operational data whether in written form or in electronic form via a network in accordance with all applicable policies and procedures for such data, including DoD Regulation 5400.7-R and DoD Manual 5200.01(v1-v4) to include latest changes, and applicable service/agency/ combatant command policies and procedures. The Contractor will protect system design related documents and operational data at least to the level provided by Secure Sockets Layer (SSL)/Transport Layer Security (TLS)/ HTTP Strict Transport Security (HSTS)-protected web site connections with certificate and or user ID/password-based access controls. In either case, the certificates used by the Contractor for these protections will be DoD or intelligence community (IC) approved Public Key Infrastructure (PKI) certificates issued by a DoD or IC approved External Certification Authority (ECA) and will make use of at least 256-bit symmetric key encryption.

7.10.13 System and Network Authorization Access Requests. For contractor personnel who require access to DoD, DISA, or USMC computing equipment or networks, the Contractor will have the employee, prime or subcontracted, sign and submit a System Authorization Access Report (SAAR), DD Form 2875.

7.10.14 System Security Requirements. Contractor personnel will comply with all DoD security requirements pursuant to DoD 5200.2, DoD Personnel Security Program, which requires DoD military, and civilian personnel, as well as DoD consultant and Contractor personnel who perform work on sensitive automated information systems (AIS) to be assigned to positions which are designated sensitive. All personnel must complete Annual Information Assurance training as well as attend a counter intelligence briefing once every calendar year. All personnel must comply with DoD 8570.01-M, Information Assurance Workforce Improvement Program and must provide certifications prior to contract start date.

7.10.15 Information Security. Information in Contractor Possession. Information given to the Contractor during the life of this contract must only be used for the purpose of carrying out the provisions of this contract.

7.10.16 For Official Use Only Information. Agency information marked “For Official Use Only” or bearing other sensitivity markings will be handled in accordance with agency information security program regulations and instructions provided on the DD Form 254. This information will not be divulged or disclosed without agency permission. Requests for disclosure will be addressed to the Government COR. Contractor personnel will ensure information that is considered sensitive or proprietary is not compromised.

7.10.17 Privacy Act. Work on this project requires that personnel have access to Privacy Information (PII). PII will be safeguarded in compliance with Federal/DoD PII guidelines, Title 5 U.S.C 552a: The Privacy Act of 1974, DoD Publication 5400.11-R: Department of Defense Privacy Program, and DoD Directive 5400.11: DoD Privacy Program.

7.10.18 HIPAA and PHI. Work on this project requires that personnel have access to Health Insurance Portability and Accountability Act (HIPAA) and Protected Health Information (PHI). HIPAA and PHI will be safeguarded in compliance with Federal/DoD guidelines, DoD Instruction 8580.02: Security of Individually Identifiable Health Information in DoD Health Care Programs, Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules (45 C.F.R.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .