PWS - IM_IT Support - DRAFT - 3Sep21.pdf

PDF 647 KB Posted

Attached to
IM and IT Support Services Federal contract opportunity
Solicitation number
FA441722KK001
Issued by
Department of the Air Force Special Operations Command

About this file

This performance work statement outlines information management and information technology support services requirements for the 1st Special Operations Medical Group at Hurlburt Field, Florida. Key details include:

  • The contractor shall provide development, configuration, consultation, training support, maintenance, and user support services for the 1SOMDG's core web and database operations, applications, network connectivity, software installation, and technical support for medical applications. This includes security support, customer support functions, medical network support, systems administration support, information systems security support, disaster recovery and contingency planning support, web and database applications support, configuration management, and cybersecurity support.

  • The statement of work specifies requirements for each of these support areas. For example, the contractor must respond to trouble tickets within defined timeframes based on priority level, ensure at least five percent of end user devices are available as backstock, and comply with all security, privacy, and data sharing regulations.

  • The performance period is for a base period of one year with four one-year options to extend. The Defense Health Agency is the contracting agency overseeing this opportunity.

View the file

Other files for this federal contract opportunity

Other files attached to IM and IT Support Services, newest first.
File Type Posted
Sources Sought Notice-Medical IM and IT Support Services -3Sep21.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

For

1st Special Operations Group (1 SOMDG) Information Management / Information Technology

(IM/IT) Services Support

At

Hurlburt Field

Florida

3 September 2021

Information Management / Information Technology (IM/IT) Services Support

TABLE OF CONTENTS

Page #

1.0 DESCRIPTION OF SERVICES 3

2.0 SERVICES SUMMARY 13

3.0 GOVERNMENT FURNISHED RESOURCES 15

4.0 GENERAL INFORMATION 17

5.0 ATTACHMENTS

1.0 DESCRIPTION OF SERVICES

1.1 Introduction: This is a non-personal services contract to provide clinical informatics and information technology services in support of the 1st Special Operations Medical Group (1 SOMDG).

1.2 Description of Services: Contractor shall provide the 1 SOMDG and medical entities embedded in operational Air Force units with development, configuration and consultation services supporting the 1 SOMDG’s core web and database operations, web applications, unique mission critical applications, network connectivity, software installation and technical support for medical applications that are supported by the 1 SOMDG as defined in this Performance Work Statement (PWS).

1.2.1 Background: The 1 SOMDG healthcare providers and their support cadre are essential to ensure that health services are provided to members within its client service base and are charged with the medical readiness of combat forces. High speed and reliable data communication systems are critical in ensuring expedient and secure information availability, allowing medical staff to provide essential and optimum health care services to a large and diverse customer base. This contract supports a heterogeneous, multi-tiered campus network, interconnected over a high- speed fiber optic transport medium, which comprises approximately 500 nodes, 21 server resources and numerous medical-specific resource applications. This network, at the lowest level, provides connectivity for messaging communications servers, clients, Transmission Control Protocol/Internet Protocol (TCP/IP) hosts, and clients located at various locations on the base and within the metropolitan area network.

1.3 Task Description.

1.3.1 Scope of Work. Services shall include: site IM/IT program oversight and support, infrastructure, hardware and software architecture oversight and maintenance, integration of data from Military Health System (MHS) and Defense Health Agency (DHA) systems, commercial health systems and regional and local applications, training support, and maintenance and user support.

1.4 Statement of Work.

1.4.1 Security Support:

1.4.1.1 Ensure requirements for safeguarding classified information and classified materials, for protecting government property and for the security of automated and non-automated management information systems and data are fulfilled. Provide a management system that prevents unauthorized disclosure of classified and sensitive unclassified information. Immediately notify appropriate Government official if any security incident or any indication of a potential unauthorized disclosure or compromise of classified or sensitive unclassified information.

1.4.2 Customer Support Functions:

1.4.2.1 Provide a centralized technical assistance service that supports problem resolution and distributes general information to 1 SOMDG user base concerning office automation.

1.4.2.2 Analyze, test, maintain, and assess software and/or other technical changes to meet operational requirements. Recommend requirements and developing plans and justifications for additions and modifications to software for network systems.

1.4.2.3 Provide Application management support of specialized Automated Information Systems including: Armed Forces Health Longitudinal Technology Application (AHLTA), Air Force Complete Immunization Tracking Application (AFCITA), Preventive Health Assessment Individual Medical Readiness (PIMR), Composite Health Care System (CHCS), Network Management System (NMS), Defense Blood Standard System (DBSS), Defense Medical Logistic Support System (DMLSS), Expense Accounting System (EAS) IV, Third Party Collection (TPOCS), Command Core System (CCS), Medical Expense and Performance Reporting System (MEPRS), Corporate Dental Application (CDR), Integrated Clinical Database (ICDB), Substance Use Assessment Tool (SUAT), Hazardous Material Information System (HMIS.Beekeeper), Command Core, Corporate Executive Information System (CEIS/M2), Digital Dental Radiography System (DDRS), PharmASSIST, AudioCARE, IMPAX system, T-Metrics, CISCO Unified Contact Center Express (UCCX), and Military Health System (MHS)

GENESIS.

1.4.2.4 Provide computer hardware/software education and user training through documentation, classroom-based courses, and informal training.

1.4.2.5 Support backup storage and protection plan providing for backup capability and retrieval capabilities, security, and operational data storage for file and print servers on diverse computer platforms such as microcomputer, stand-alone, and minicomputer suites.

1.4.2.6 Configure, integrate, and distribute peripheral, microcomputer, printer, software, and hardware systems. Troubleshoot and provide assistance with errors encountered by end users. Resolve issues via telephone, hands on, and technical methods.

1.4.2.7 Track, log, complete, and follow up on trouble ticket requests within work order priorities.

1.4.2.8 Respond to trouble tickets within timeframes established according to the following work order priority timeframes: Level 1 Critical - one (1) hour, Level 2 High – four (4) hours, Level 3 Medium – 24 hours, Level 4 Low – 72 hours.

1.4.2.9 Track trouble tickets using MHS Service Now. Close ticket when final consultation with customer has occurred. Ensure problem was resolved satisfactorily.

1.4.2.10 Conduct electronic vulnerability assessments of systems and educate users on proper methods to properly secure systems utilizing phishing, social engineering, and other industry standard techniques.

1.4.2.11 Analyze and assess equipment and performance degradation, and recommend hardware, software, and/or other technical changes necessary as well as recommend to the 1 SOMDG CIO equipment refreshment to meet operational requirements.

1.4.2.12 Collect and report statistics on trouble tickets.

1.4.3 Medical Network Support:

1.4.3.1 Provide medical network and systems administration of the 1 SOMDG LAN, including network infrastructure hardware (hubs, routers, switches, terminal servers, file and printer servers, remote access and modem servers, wireless access points, and internal/external gateway platforms). Analyze and define network requirements;

configure and optimize network servers; monitor network capacity and performance;

diagnose and resolve network problems; develop network backup and recovery procedures; manage the installation and integration of system fixes, updates and enhancements; and install, test, maintain, and upgrade network operating system software.

1.4.3.2 Recommend requirements and develop plans and justifications for additions and modifications to hardware and software for network systems.

1.4.3.3 Analyze and assess equipment and performance degradation, including determination of hardware, software, and/or other technical changes to meet operational requirements and make appropriate recommendations to the 1 SOMDG CIO.

1.4.3.4 Perform network hardware/software testing, installation, and maintenance. Install standard DHA image on network devices and end-user devices (EUDs).

1.4.3.5 Perform network-based detection of viruses and unauthorized software and facilities to counter/eliminate/control. Identify, isolate, neutralize, and handle malicious programs (viruses, worms, Trojan Horses) infecting the client organization’s network.

1.4.3.6 Maintain network and active directory operations and management experience, expert knowledge of IP networking principals, LAN/WAN technology fundamentals, and significant experience in operation, management, and troubleshooting with medical networks.

1.4.3.7 Manage and administer user ID, passwords, security keys (public/private, unique), and domain addresses utilizing Microsoft Domain Management utilities.

1.4.3.8 Manage medical wireless access points and assist Air Force Medical Services Agency with AOS upgrades.

1.4.3.9 Upgrade IOS for infrastructure in accordance with Medical STIGS and Communication Squadron STIGS.

1.4.3.10 Work with Air Force Medical Service Agency and Air Force Medical Operating Agency with infrastructure hardware and software upgrade/replacement.

1.4.3.11 Maintain oversight, and administration of file servers and services supporting local and remote users.

1.4.3.12 Manage and maintain the file and servers, workstations, operating systems and network application software.

1.4.4 Medical System Administration Support:

1.4.4.1 Provide planning, analysis, troubleshooting, integration, installation, operations, system assistance, documentation, and systems administration services for facility specific data networks, including systems, LAN, Wide Area Networks (WAN), Non- Secure Internet Protocol Router Network (NIPRNET), Medical Community-of-Interest (Med-COI), client-server, and internet access for the 1 SOMDG LAN. Perform systems administration, troubleshooting, and support of LAN operating systems, servers, and applications with little or no supervision. Directly interface with supported end-users to provide hardware, software, network, and applications problem resolution.

1.4.4.2 Install servers and configure hardware, peripherals, services, settings, directories, storage, etc. in accordance with standards and project/operational requirements.

1.4.4.3 Monitor daily, weekly, monthly backup operations, ensuring all required file systems and data are successfully backed up to the appropriate media. If physical media is used for backup operations, ensures media is stored off-site at 1 SOMDG designated location for a minimum of one month. Perform data restores as required.

1.4.4.4 Perform ongoing performance tuning, hardware upgrades, and resource optimization as required. Configure CPU, memory, and disk partitions as required.

1.4.4.5 Create, manage, and distribute SCCM/ACAS/Tanium collections, packages, advertisements, and reports for medical workstations and applications as needed.

Coordinate with SCCM, HBSS, and Tanium administrators to facilitate successful software installations for unique medical applications required at 1 SOMDG to ensure functionality with regard to standard OS and software updates.

1.4.4.6 Design and administer scripts and utilities used locally and wide to assist with LAN administration, process automation, application installations, Exchange/AD manipulation, and data collection. Manage and create logon scripts, data access, and Active Directory group policies customized for medical users and workstations.

1.4.4.7 Manage and administer user id, passwords, security keys (public/private, unique), and domain addresses utilizing Microsoft Domain Management utilities.

1.4.4.8 Provide functional server support for medical systems to include, but not limited to Digital Dental Radiology (DDR), PharmAssist, IMPAX Digital Radiology, ASIMS, DMLSS, AudioCare, DOEHRS, T-Metrics, etc.

1.4.4.9 Provide network infrastructure troubleshooting and problem resolution assistance on client-owned and operated Cisco switches.

1.4.4.10 Provide system administration for AF Medical mandated systems (hardware/software) for complete Electronic Healthcare Records.

1.4.4.11 Operate and maintain network and domain assets that are part of the WAN at various levels of security classification, to include Med-COI and NIPRNET, ensuring full interoperability and a seamless connection between internal and external systems.

1.4.4.12 Maintain AF & DoD health care information protection standards, safeguards, technical assistance, and procedures to include Health Insurance Portability and Accountability Act (HIPAA) compliance and apply all appropriate controls to safeguards medical data stored on servers and transmitted on the network.

1.4.4.13 Verify local enclave users’ completion of annual Information Assurance (IA) or Cybersecurity Challenge Computer Based Training (CBT) during the creation of user accounts.

1.4.5 Information Systems Security Support:

1.4.5.1 Support the Information Assurance Officer (IAO) to perform technical training on information security relative to personal computers, LANs, file servers, networks, and telecommunications. Perform special projects and tasks to remedy existing security weakness; Conduct network security monitoring to detect intrusions. Conduct electronic vulnerability assessments of systems. Conduct electronic vulnerability assessments of web sites.

1.4.5.2 Provide security for 1 SOMDG systems, telecommunications, and client server support to include analytical support related to personal computers, file servers, and LAN assets.

1.4.5.3 Analyze, evaluate, and make recommendations for new and emerging security technologies as well as vendor security products for their applicability and feasibility of use for personal computers, LANs, telecommunications, and networks.

1.4.5.4 Provide new users initial computer security awareness and training through documentation, classroom-based courses and informal training. Personnel will be trained within 30 days of assignment.

1.4.5.5 Provide computer security incident response support and follow AFSSI 5021 to form an Incident Response Team to respond to security incidents when needed.

Coordinate with the 1st Special Operations Communication Squadron, the Base Information Assurance Office (BIAO), Network Control Center (NCC), and other external organizations to ensure system compatibility and integrity. Respond to and report for all Government alerts, CERT notice, NOTAM notices, breaches, or other security concerns.

1.4.5.6 Monitor the supported networks to detect intrusions. Correlate information on network intrusion incidents; create incident reports, brief client organization management, client security personnel, law enforcement, and/or counterintelligence organizations on the network intrusion incidents. Assist with developing automated tools to assist in the network monitoring, intrusion detection, and reaction to incidents.

1.4.5.7 Perform research on system vulnerabilities, conduct system penetration analysis, and recommend computer security incident response tools. Immediately identify communication threats and vulnerabilities to the designated government point of contact and responsible agencies as needed.

1.4.6 Disaster Recovery, Medical Continuity of Operations and Contingency Planning:

1.4.6.1 Assist with the development of a Data Backup Plan (DBP), Disaster Recovery Plan (DRP), Emergency Mode Operations Plan (EMOP), Medical Continuity of Operations Plan (MCOOP), and Application and Data Criticality Analysis. These plans will establish recommended processes and procedures to recover all critical software programs and sensitive Government information and response operations.

1.4.6.2 Provide support in the recovery of the 1 SOMDG Information Services (IS) resources in the event of a disaster.

1.4.6.3 Perform an annual review and risk analysis of appropriate DBP, DRP, EMOP, and MCOOP plans to reduce incidents and loss of data or downtime and provide recommendations to the 1 SOMDG CIO.

1.4.7 Telephone Support:

1.4.7.1 Provide minimum support for telephony requirements at 1 SOMDG. Assist 1 SOMDG TCO with physical retrieval of data on the handset and identifying phone movement needs with the customer. Coordinating with 1 SOCS to assist users with voicemail password resets, and assists with annual TCO phone inventory.

1.4.8 Web, Database and Applications Support:

1.4.8.1 Provide web, database, and applications support to 1 SOMDG.

1.4.8.2 Analyze new applications, perform software maintenance, and make appropriate enhancements to existing applications as well as assisting customer personnel in identifying their requirements and/or problems.

1.4.8.3 Provide customers with support for updating/maintaining web pages to include graphics integral to the documents.

1.4.8.4 Provide configuration and management and database support services for microcomputer systems supporting all 1 SOMDG users.

1.4.8.5 Assist with the maintenance of the Medical Group’s Hospital Personnel (IIS) server and SharePoint web pages.

1.4.8.6 Conduct electronic vulnerability assessments of 1 SOMDG web sites.

1.4.9 Configuration Management

1.4.9.1 Perform configuration management of software. Provide centralized administration of software licenses, including multiple allocations for Special Operations Medical Group assets. Research how effective the base CM function manages Special Operations Medical Group assets and provide the Government CM improvement recommendations.

1.4.9.2 Provide assistance in maintaining inventory control and location records of Government-owned Federal Information Processing (FIP) equipment/software and disposal of property.

1.4.9.3 Ensure completion of and compliance with Authority to Operate (ATO)/Request to Operate (RTO), Information technology Data Repository (EITDR), and Designated Approval Authority (DAA) approval

1.4.10 Cybersecurity Support

1.4.10.1 Manage cybersecurity requirements to include: Network Security Improvement Program (NSIP) initiatives and requirements, Cybersecurity Vulnerability Alert monitoring, analysis and reporting, Cybersecurity issue resolution, development of Cybersecurity policy/guidance, implementation of Cybersecurity technologies, administration of Cybersecurity programs such as Information Operations Condition (INFOCON) and the Department of Defense Information Risk Management Framework (RMF) and Cybersecurity assessment and compliance monitoring.

1.4.10.2 Implement accreditation procedures and appropriate computer security measures by administering and monitoring implementation of LAN RMF. Reviews certification and accreditation documentation to ensure it is compliant with RMF standards.

1.4.10.5 Develop and implement of hardware and software safeguards to reduce risks during electronic processing of sensitive information.

1.4.10.6 Implements ACAS/HBSS/Tanium audit measures to ensure activity compliance with regulatory requirements.

1.4.10.7 Reviews and evaluates the impact of new systems or system changes in relation to DoD/DHA IA configuration management, architecture, and network security standards and requirements, including existing or proposed interfaces with other computerized systems and provide recommendation to 1 SOMDG CIO.

1.4.10.8 Reviews computer systems techniques for accessing files and the total system to assure data, files, and equipment are not compromised and fully meet security measures (to include environmental control, system stability, data integrity, system reliability) and that ports, protocols, communication links, and services adhere to the deny all, permit by exception policy, Security Requirements Guides (SRG), Security Technical Implementation Guidance (STIG), and Best Business Practices (BBP).

1.4.10.9 Provides technical security advice and assistance on the design, development, integration, implementation, and operation of all management information systems.

1.4.10.10 Ensures all Information Security and Commercial Off The Shelf (COTS)/Government Off The Shelf (GOTS) within the area of responsibility are properly certified and accredited in accordance with RMF and configuration management policies and practices prior to installing, developing, beta testing, or operating on a garrison-managed/controlled device.

1.5 Deliverables. All deliverables must meet professional standards and meet the requirements set forth in contract documentation. The contractor will be responsible for delivering all end items specified. The following items are deliverables that fall within the scope of the aforementioned tasks and all other stated deliverables.

1.6 Reports. The contractor shall provide a progress status report as necessary to the Contracting Officer Representative (COR) or Alternate (Alt) COR. The following report are required:

TITLE

DATE of

1st Submission

As of Date Date of

Subsequent Submission

DIST Copies

Monthly Status Report

1st Month after award

Previous Month Monthly COR 1 EA

Special Reports As needed N/A As needed MIS Flt/CC 1 EA

1.6.1 Monthly Status Report (MSR). The MSR must be submitted to the COR or Alt COR no later than the 15th of every month. Status reports must be accompanied by a copy of that month’s invoice. An MSR will be completed by each position assigned to the contract as a full time, regular employee. The MSR’s shall be compiled, reviewed and submitted by the Program Manager with a cover letter which synopsizes the activities and significant events occurring during the preceding month.

1.6.2 Special Reports. The contractor shall provide special reports to and as requested by the MIS Flt/CC.

1.6.4 Delivery Instructions. Deliverables will be submitted soft copy and will be compatible with Medical Community of Interest (Med-COI) desktop applications.

2.0 SERVICES SUMMARY

2.1 Service Summary (SS). The service requirements are summarized into performance outcomes that relate directly to mission essential items. The performance thresholds describe the minimum acceptable levels of service required for each requirement. The thresholds are critical to mission success and acceptable (satisfactory) performance.

SS Performance Objective PWS Para

Performance Threshold To receive Satisfactory Rating

1 Respond and resolve customer work orders

1.4.2.7 1.4.2.8 1.4.2.9

Respond to trouble tickets within timeframes established based on work order priorities.

Threshold: Respond to 95% of trouble tickets within timeframes established based on work order priorities.

2 Create and provision new user LAN accounts

1.4.3.7 1.4.4.13

Create new LAN accounts within 72 hours of receipt of LAN application.

Threshold: Create and provision 95% of new LAN accounts within 72 hours of request.

Ensure an adequate level of imaged end-user-device (EUD) inventory

1.4.3.4

The quantity of available back stock EUDs is at least five percent (5%) of all issued EUDs.

Threshold: Ensure that there is a back stock of imaged EUD available back stock EUDs is at least five percent (5%) of all issued EUDs 95% of the time.

Ensure local 1 SOMDG network connectivity is available and reliable

1.4.3.1

Ensure that network devices are able to connect to the local 1 SOMDG network.

Threshold: Ensure that the local 1 SOMDG network connectivity is available 95% of the time.

Ensure that IM/IT equipment, servers, and end-user-device receive routine software updates and patches

1.4.4.5 1.4.10.6

>=95% network devices have updated software as indicated in the Assured Compliance Assessment

Solution (ACAS) scans

Threshold: At a minimum, 95% network devices have updated software as indicated in the weekly

Assured Compliance Assessment Solution (ACAS) scans 95 % of the time

6 Complies with all security requirements

4.7.1 4.7.2 4.7.3 4.7.4

100% of employee clearances are submitted to COR and CO prior to performance start date. All security requirements must be met and maintained 100% of the time.

Threshold: Zero security violations identified during performance.

7 Complies with all training requirements 4.6

Provide qualified employees with current trainings and certifications IAW DOD 8570.01-M and local policies.

Threshold: 100% of employees have current trainings and certifications as outlined by DOD 8570.01-M and local policies 100% of the time.

3.0 GOVERNMENT FURNISHED RESOURCES

3.1 The government will provide the limited facilities, equipment, materials, and services listed here. Specific responsibilities are detailed in this section.

3.2 Facilities. The Government will furnish or make available workspace at 1 SOMDG, Hurlburt Field, Florida. The Government retains the authority to modify or realign facilities and space provided to the contractor based on current or future Air Force guidelines for space utilization, mission requirements, and personnel requirements of the contractor as necessary. Government facilities have been inspected for compliance with OSHA. No hazards have been identified for which work-arounds have been established.

Should a hazard be subsequently identified, the government will correct the hazard according to base-wide government developed and approved plans of abatement taking into account safety and health priorities. A higher priority for correction will not be assigned to the facilities provided to the contractor merely because of this contracting initiative. The fact that no such conditions have been identified does not warrant or guarantee that no possible hazard exists, or that work-around procedures will not be necessary or that the facilities as furnished will be adequate to meet the responsibilities of the contractor. Compliance with OSHA and other applicable laws and regulations for the protection of employees shall be exclusively the obligation of the contractor.

3.3 Automatic Data Processing Equipment (ADPE). The government will grant access to ADPE and training to the minimum extent necessary for mission accomplishment. The contractor shall use ADPE for controlling and tracking data and information as well as any other duties related to contract performance. The contractor shall not use government furnished ADPE or services for non-contractual related purposes. The contractor shall comply with all computer system security procedures required by the Government.

3.3.1 Local Area Network Access (LAN). In accordance with DHA-PI 8140.01, Acceptable Use of Defense Health Agency Information Technology (IT), Enclosure 2.1, contractor personnel using unclassified automated information systems that have access to sensitive information must possess, at a minimum, a National Agency Check or Entrance National Agency Check in accordance with DoD 5200.2-R, Personnel Security Program or screening.

3.3.2 Computer Security. The contractor shall maintain computer systems security integrity in accordance with the Air Force Computer Security (COMPUSEC) program (AFSSI 5102). The contractor personnel will be required to complete Joint Knowledge Online Cyber-awareness Challenge and satisfy any other local requirements set forth by the 1st Special Operations Communications Squadron or other government agency prior to being allowed access to government computers.

3.3.3 Administrative Supplies. The Government will provide reasonable amounts of administrative supplies (e.g., office supplies.)

3.4 Government-Furnished Services

3.4.1 Security Forces. The Government will provide general security service. Security Forces phone extensions are 911 for emergencies at both locations. For routine calls to the Law Enforcement Desk - Control Center, at Hurlburt Field, Florida call 850-884- 7114.

3.4.2 Postal or Installation Distribution. Official government or contractor mail that is generated as a result of performance of this contract will be handled, at government expense, via the Base Information Transfer System (BITS) at Hurlburt Field, Florida.

4.0 General Information

4.1 Quality Assurance. For all requirements of the contract, including those tasks listed in the Service Summary (SS), will follow standard surveillance and inspection procedures. Any action taken by the contracting officer as a result of surveillance will be according to the terms of this contract.

4.2 Quality Control.

4.2.1 Contents. The plan shall include a detailed description of the processes to be used during performance to ensure the services meet or exceed the requirements of the SS, the PWS and contract. The plan shall systematically provide for early identification of nonconforming services; develop metrics to track performance trends; detail corrective actions required to insure timely and acceptable performance in accordance with the PWS; identify organizational placement of the inspectors; and describe the contractor’s partnering approach with the Government to ensure mission objectives are met.

Additionally, plans that require employees to comply with the government control procedures for materials, equipment, facilities, and keys or lock combinations shall be included. To include all required security and accountability forms documentation.

4.2.2 Copy of Metrics. The contractor shall provide a copy of the metrics data along with analysis in their monthly report to the government COR. Metrics shall address each Service Summary item by location to include Comments/Significant Events, Personnel Actions, Visitors, Projects, Equipment Status, and any other contractor or Government identified metric that will facilitate successful performance of contract requirements.

4.2.3 Revisions. Revisions to the Contractor’s Quality Control Plan may be required at any time during performance of the contract to assure contractor compliance with requirements of the PWS and contract. The contractor shall make appropriate revisions and obtain acceptance of the revised plan from the contracting officer. Revised copies of the Quality Control Plan shall be provided to the contracting officer and COR upon approval from the contracting officer.

4.2.4 Performance Evaluation Meetings. The Contracting Officer may require the site leader or alternate to meet with the Contracting Officer, contract administrator, COR, and other government personnel as deemed necessary. The contractor may request a meeting with the contracting officer when he/she believes such a meeting is necessary. Written minutes of any such meetings will be recorded in the contract and signed by the site leader and the contracting officer or contract administrator. If the contractor does not concur with any portion of the minutes, such non-concurrence shall be provided in writing to the Contracting Officer by the contractor within ten (10) calendar days following receipt of the minutes.

4.3 Contractor Personnel. The contractor must ensure that personnel possess a secret security clearance prior to the start of work stated in this PWS. The contractor must maintain all personnel have a secret security clearance throughout the contract duration.

All personnel must possess or be able to obtain a secret security clearance. All contractor personnel must possess a secret security clearance prior to handling classified information or accessing IT systems requiring a security clearance.

4.3.1 The Contractor shall provide a Program Manager who shall be overall responsible for contract performance. The Program Manager shall be available via telephone within

30 minutes to address government concerns. The Program Manager does not need to be assigned to the worksite and shall not be directly billable to the contract.

4.3.2 Employees. The contractor shall ensure personnel are commensurate with manning and experience levels for each designated position and job description and IAW DOD 8570.01-M. Have the capability to read, write, speak, and understand English. Have previous experience in their designated job area or specialty. Be familiar with military command and control structures. Have the physical capabilities (be able to lift at least a 60 pound box).

4.3.2.1 The contractor shall not employ persons for work on this contract if such employee is identified to the contractor by the Contracting Officer as a potential threat to the health, safety, security, general well-being, or operational mission of the installation and its population. Where reading, understanding, and discussing safety, security, mission, and environmental issues are an integral part of a contract employee’s duties, that employee must be able to understand, read, write, and speak English.

4.3.2.2 The contractor shall not employ any person who is an employee of the US Government if employing that person would create a conflict of interest. Additionally, the contractor shall not employ any person who is an employee of the Department of the Air Force, either military or civilian, unless such person seeks and receives approval according to DoD Regulation 5500.7-R, Joint Ethics Regulations (JER). The contractor shall not employ any person who is an employee of the Department of the Air Force if such employment would be contrary to the policies in AFI 64-106, Air Force Industrial Labor Relations Activities.

4.3.3 Dress/Appearance. Contractor personnel shall present a clean and neat appearance. Contractor shall not permit cut off shorts and clothing with tears, or revealing clothing or clothing with obscene or inflammatory designs, slogans, or remarks, and clothing representing military attire such as BDUs or DCUs. The site leaders shall ensure personnel wear appropriate clothes suited for their job.

4.3.4 Smoking, Eating and Drinking. The contractor shall permit smoking, eating and drinking only in designated areas.

4.3.5 Driving License/On-base Requirements. The contractor and employees shall comply with base traffic regulations at all sites. The contractor shall ensure employees have a current and valid state/country driver’s license and government license for the type of vehicle being driven before allowing the employee to operate a government vehicle or personal vehicle on Hurlburt Field, Florida.

4.3.6 Contractor Identification. Contractor personnel shall wear badges identifying them as contractors at all times. The Government will issue Common Access Cards (CAC) through the ID Card and DEERS Personnel office. Additionally, 1 SOMDG badges are issued through the 1 SOMDG Facility Management (FM) office.

4.4 Place of Performance. The Contractor shall perform the required support at 1 SOMDG located at Building 91049, (113 Lielmanis Ave) Hurlburt Field FL. Contractor personnel shall comply with all installation and facility safety and security regulations, as well as, the health, safety, and security provisions of the contract. Contractor personnel shall report security or safety problems to the Contracting Officer and/or Security Police as appropriate.

4.5 Hours of Work. Normal duty hours are Monday through Friday, 0700 to 1700 hours, based on the projected instruction schedule, except for federal holidays.

Contractors are not to work more than 80 hours per two-week pay period.

4.5.1 Holidays and Vacation. The contractor will not normally be required to work during the following holidays. If performance is required for these holidays, it will be approved and scheduled in advance with the COR.

New Year's Day January 1 Martin Luther King Day Third Monday of January President's Day Third Monday of February Memorial Day Last Monday in May Juneteenth June 19 Independence Day July 4 Labor Day First Monday of September Columbus Day Second Monday in October Veterans Day November 11 Thanksgiving Fourth Thursday in November Christmas December 25

If the holiday falls on a Saturday, it is observed on the preceding Friday. If the holiday falls on a Sunday, it is observed on the following Monday.

4.5.2 Building Closures. If the 1 SOMDG, Hurlburt Field, FL is closed due to a scheduled or unscheduled unit event, the contractor shall ensure adequate personnel coverage to satisfy the task requirements.

4.5.3 Alternate Work Site. The COR shall approve any worksites not located in building 91049, Hurlburt Field FL for the benefit of the government before an alternate worksite is utilized. All work and task goals to be accomplished at an alternate work site will be coordinated and approved by the COR prior to utilizing any alternate work site.

4.6 Training. The contractor is responsible to schedule and coordinate specialized training that insures Contractor personnel maintain currency in military / defense specific systems to include hardware, software, and other systems applicable to the performance of the contract outlined by DOD 8570.01-M . As the need for additional training is discovered / identified, the Contractor will identify the location of the training and prepare a cost estimate for attendance and submit this estimate to the government for approval. Employees of the Contractor are expected to maintain currency in their core professional competencies in a manner that is standard practice in the industry. This includes the maintenance of certifications, attendance at required refresher courses, and obtaining training in new product releases or updates. The Government will not reimburse the Contractor for professional training and the maintenance of certifications, except where the requirement is in addition to the requirements for the position.

Additionally, contractor personnel are required to complete annual Cyber Awareness Challenge Training in accordance with the Local Security Requirements memo

4.6.1 Government Provided Training. If the contractor attends any government provided training, the contractor is responsible to provide the trained capability for the duration of the contract. Specific government provided trainings include the 1 SOMDG Red Cross First AID/CPR/AED course, RELIAS Military Medical Treatment Facilities (MTF) Annual Regulatory Training (ART) and Military Medical Treatment Facilities (MTF) Triennial Regulatory Training (TRT) and the annual Information Assurance (IA) or Cyber Awareness Challenge.

4.6.2 Standard Government Provided Training

The training listed in the table below is normally provided by the government to contractor employees. Coordinate any training requirements below with the COR.

TITLE DURATION REQ. FREQ. REMARKS

CBT

Narrative: RELIAS Military Medical Treatment Facilities (MTF) Annual Regulatory Training (ART) - Direct Pt. Care

(B) and General Staff (C)

POC: COR

1 hours Every one (1) year ALL

CBT

Narrative: Military Medical Treatment Facilities (MTF) Triennial Regulatory Training (TRT) - General Staff (C)

POC: COR

2 hours Every three (3) years ALL

CBT

Narrative: Joint Knowledge Online Cyber-awareness Challenge

POC: COR

1 hours Every one (1) year ALL

CBT

Narrative: Joint Knowledge Exchange Online HIPAA and Privacy Act Training

POC: COR

1.5 hours Every one (1) year ALL

4.7 Privacy and Security

4.7.1 Security Classification/Clearances. Contractor employees shall be cleared at the Secret levels at the start of this task. Contractors shall require access to Med-COI and

NIPRNET.

4.7.1.1 This project is classified up to Secret. All documentation that is required for security certification is the responsibility of the contractor and the client organization. DD Form 254 is required for performance of this contract.

4.7.1.2 Contractors will require a Secret clearance with a Single Scope Background Investigation (or equivalent) not older than 5 years. Contractor must comply with guidelines specified in the attached DD Form 254.

4.7.2 Privacy Act. Services performed requires that personnel have access to Privacy Information. Personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations.

4.7.3 Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security. Services performed requires that personnel have access to information covered under the HIPAA Privacy and Security rules. The Contractor agrees to abide by all applicable HIPAA Privacy and Security requirements regarding health information as defined in this clause

4.7.4 Facility Security Badges. 1 SOMDG Facility Management will provide facility security badges for all contractors at 1 SOMDG. Facility security badges must be safeguarded in accordance with 1 SOMDG policies. Facility security badges will be worn at all times while in the facility.

4.8 Conservation of Utilities. The contractor and their employees shall operate under conditions that prevent the waste of utilities.

4.9 Desired Qualifications

4.9.1 System Administrator: This is an IAT Level I position as defined in DOD 8570.01-M . Personnel shall possess at least one (1) IAT Level I Approved Baseline Certification to include:

• A+ CE

• CCNA-Security

• CND

• Network+ CE

• SSCP

IAT Level I personnel make the computing environment less vulnerable by correcting flaws and implementing IAT controls in the hardware or software installed within their operational systems.

4.9.1.1 Personnel shall possess knowledge of the current desktop Microsoft Operating System and as evidenced by experience and course completion of that operating system.

The personnel shall have one (1) year after the introduction of a new or updated Microsoft certification to ensure that all contract customer support technicians have up to date certifications. The personnel shall have complex and progressive experience in a Microsoft computer support environment with experience in a Microsoft customer service and support environment in a large critical environment.

4.9.1.2 The personnel shall be experienced in the use of any ticketing system.

4.9.1.3 The personnel shall be experienced in network devices maintenance and support.

The personnel shall be experienced in troubleshooting and repairing the standard set of peripherals for a workstation in an enterprise medical environment.

4.9.1.4 The personnel shall possess extensive knowledge of information technology, systems design and development concepts, and related policies and procedures to provide advice and consultation, verified through possession of certifications listed above and commensurate work experience.

4.9.1.5 The personnel shall possess proficiency in the systems analysis and design specialty to serve as a technical authority on a wide range of technology applications.

Must also have knowledge of emerging technology to apply new solutions to system requirements and to plan advanced system projects, verified through possession of certifications listed above and commensurate work experience.

4.9.2 Network Administrator: This is an IAT Level II position as defined in DOD 8570.01-M. Personnel shall possess at least one (1) IAT Level II Approved Baseline Certification to include:

• CCNA Security

• CySA+

• GICSP

• GSEC

• Security+ CE

• CND

IAT Level I personnel make the computing environment less vulnerable by correcting flaws and implementing IAT controls in the hardware or software installed within their operational systems.

4.9.2.1 The personnel shall have at least five (5) years of experience with DoD information processing standards, policies, and authorized system design approaches to manage large-scale projects.

4.9.2.2 The personnel shall possess extensive knowledge of information technology, systems design and development concepts, and related policies and procedures to provide advice and consultation.

4.9.2.3 The personnel shall possess proficiency in the systems analysis and design specialty to serve as a technical authority on a wide range of technology applications.

4.9.2.4 The personnel shall be proficient in analyzing and defining network requirements;

configuring and optimizing network servers; monitoring network capacity and performance; diagnosing and resolving network problems; developing network backup and recovery procedures; managing the installation and integration of system fixes, updates and enhancements; and installing, testing, maintaining, and upgrading network operating system software.

4.9.2.5 The personnel must also have knowledge of emerging technology to apply new solutions to system requirements and to plan advanced system projects.

4.9.3 Cybersecurity Specialist (ISSO): This is an IAT Level II position as defined in DOD 8570.01-M . Personnel shall possess at least one (1) IAT Level II Approved Baseline Certification to include:

• CCNA Security

• CySA+

• GICSP

• GSEC

• Security+ CE

• CND

IAT Level II personnel provide network environment (NE) and advanced level CE support. They pay special attention to intrusion detection, finding and fixing unprotected vulnerabilities, and ensuring that remote access points are well secured. These positions focus on threats and vulnerabilities and improve the security of systems. IAT Level II personnel have mastery of the functions of the IAT Level I.

4.9.3.1 The personnel shall have at least five (5) years of in-depth expertise in applying cybersecurity / Information Assurance (IA) principles in a DoD environment.

4.9.3.2 The Cybersecurity Specialist may be required to possess a Certified Information Systems Security Professional (CISSP) or DoD-approved equivalent certification.

4.9.3.3 The personnel must possess mastery of (and skill in applying) IT architecture, interrelationships among multiple IT specialties, new IT developments and applications, emerging technologies, and their application to business processes, IT security concepts, standards, and methods, project management principles, methods, and practices; and oral and written communication techniques sufficient to serve as a subject matter expert in cybersecurity/IA and manage assigned IT projects and program.

4.9.3.4 The personnel must possess mastery of (and skill in applying) total infrastructure protection environment; system security certification and accreditation requirements and processes; and Federal information systems protocols in order to integrate information systems security with other IT and security disciplines, manage network and systems accreditation, and ensure coordination and collaboration on a wide range of security activities.

4.9.3.5 The personnel must possess mastery of a wide range of IT and cybersecurity concepts, principles, and practices required to plan, direct, and evaluate Information Security (IS) programs for Automated Information Systems.

4.9.3.6 Cybersecurity Specialist must have the ability to coordinate and conduct surveys, inspections, and assistance visits that improve the level of security.

4.10 Associate Contactor Agreement:

4.10.1 During the performance of this contract, the contractor shall be required to work with other contractors who have a separate government contract. The contractor shall enter into Associate Contractor Agreement for any portion of the contract requiring joint participation in the accomplishment of the Government requirement. The agreement shall include the basis for sharing of information, data, technical knowledge, expertise, and/or resources essential to the success of the 1 SOMDG mission. The agreement shall ensure the greatest degree of cooperation for successfully meeting the terms of the contract. The agreement shall also include the agreement start and expiration dates and appropriate protection of proprietary information and restrictions on personnel.

4.10.2 Names of the associate contractors will be provided within ten (10) calendar day after the contract award and as required during the performance of the contract. Associate contractor agreements shall be provided to the government within 30 calendar days of the notification and prior to execution by the parties. Any costs of entering into and maintaining the associate contractor agreements shall be included in the negotiated costs of this contract. Liability for improper disclosure of proprietary data contained in or referenced by any agreement shall rests with the parties to the agreement and not the government. Failure to resolve disagreements with associate contractors does not entitle the contractor to any adjustment or waiver of this contract.

Attachment 1: Historical Work Order Data

Graph 1.0: 1 SOMDG Historical Work Data for May 2020 – May 2021. Green bars represent volume of work orders opened in a month and blue bars represent volume of work orders closed in a month.

Month Volume Work Orders Opened Volume Work Orders Closed May-2020 321 322 Jun-2020 382 381 Jul-2020 455 455

Aug-2020 416 454 Sep-2020 425 406 Oct-2020 474 464 Nov-2020 337 352 Dec-2020 362 381 Jan-2021 377 363 Feb-2021 338 336 Mar-2021 475 494 Apr-2021 465 434 May-2021 388 413

Table 1.0: 1 SOMDG Historical Work Data for May 2020 – May 2021.

ITEM NAME ESTIMATED QUANTITY

(per annum)

1 System Administrator 5640 hours (3) 2 Network Administrator 1880 hours (1) 3 Cybersecurity Specialist (ISSO) 1880 hours (1)

Table 2.0: 1 SOMDG IM/IT Support Historical Man Hours for May 2020 – May 2021

QUANTITY

1 SOMDG Network Users 442 users

1 SOMDG Network Devices 552 devices Table 3.0: Total 1 SOMDG Network Users and Devices (CAO 31 August 2021). Note:

All 552 network devices are scanned and receive updates on a weekly basis.

Attachment 2: Personally Identifiable Information, Protected Health Information, and Federal Information Requirements

(Revised May 23, 2017)

1. General Requirements Overview - Personally Identifiable Information (PII), Protected Health Information (PHI) and Federal Information Laws

This Section addresses the Contractor’s requirements under The Privacy Act of 1974 (Privacy Act), The Freedom of Information Act (FOIA), and The Health Insurance Portability and Accountability Act (HIPAA) as set forth in applicable statutes, implementing regulations and Department of Defense (DoD) issuances. In general, the Contractor shall comply with the specific requirements set forth in this Section and elsewhere in this Contract. The Contractor shall also comply with requirements relating to records management as described herein.

This document incorporates by reference the federal regulations and DoD issuances referred to in this Section. If any authority is amended or replaced, the changed requirement is effective when it is incorporated under contract change procedures.

Where a federal regulation and any DoD issuance govern the same subject matter, the Contractor shall first follow the more specific DoD implementation unless the DoD issuance does not address or is unclear on that matter. DoD issuances are available at http://www.dtic.mil/whs/directives.

For purposes of this Section, the following definitions apply.

DoD Privacy Act Issuances means the DoD issuances implementing the Privacy Act, which are DoDD 5400.11 (October 29, 2014) and DoD 5400.11-R (May 14, 2007).

HIPAA Rules means, collectively, the HIPAA Privacy, Security, Breach and Enforcement Rules, issued by the U.S. Department of Health and Human Services (HHS) and codified at 45 Code of Federal Regulations (CFR) Part 160 and Part 164, Subpart E (Privacy), Subpart C (Security), Subpart D (Breach) and Part 160, Subparts C-E (Enforcement), as amended.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .