PWS_Scope_Command_Next_Generation_PWS_11_Mar_22.docx
DOCX document 317 KB Posted
- Attached to
- Scope Command Next Generation Federal contract opportunity
- Solicitation number
- FA810221R0008
About this file
This is a performance work statement (PWS) for the High Frequency Global Communications System (HFGCS) program. The contractor shall provide engineering services, equipment installation and testing, depot-level sustainment, and logistics support for the HFGCS. Key requirements include program management, configuration management, testing, software development and maintenance, training, depot repair, technical assistance, and supply chain management. The contractor must meet performance objectives for system updates, integration testing, reliability and availability metrics, security compliance, response times, and inventory management. The government will provide facilities, property, and transportation for locations without commercial options. This anticipated sole-source award is for incumbent Collins due to data rights restrictions.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| FA810221R0008_13April.pdf | ||
| FA810221R0008_DD254_18Mar2022.pdf | ||
| SCNG_CDRL_EXHIBIT_F_SERIES.pdf | ||
| SCNG CDRL DFARS Clauses Final.pdf | ||
| SCNG_CDRL_EXHIBIT_C_SERIES.pdf | ||
| SCNG_CDRL_EXHIBIT_B_SERIES.pdf | ||
| SCNG_CDRL_EXHIBIT_G_SERIES.pdf | ||
| FA810221R0008 14Mar22.pdf | ||
| SCNG_CDRL_EXHIBIT_E_SERIES.pdf | ||
| SCNG_CDRL_EXHIBIT_D_SERIES_UPDATE.pdf | ||
| SCNG_CDRL_EXHIBIT_H_SERIES.pdf | ||
| SCNG_CDRL_EXHIBIT_A_SERIES.pdf |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
FOR
US Air Force (USAF)
High Frequency Global Communications System (HFGCS)
System Program Office (SPO)
Scope Command Next Generation
Unclassified
11 Mar 2022
Approved by: Department of the Air Force
AFLCMC/HBDH
7697 First Street, Rm 2 Tinker AFB, OK 73145
Table of Contents
| 1. | DESCRIPTION OF SERVICES | 3 |
| 1.1 | PROGRAM MANAGEMENT | 3 |
| 1.2 | MODERNIZATION REQUIREMENTS | 4 |
| 1.3 | CONTRACTOR DEPOT MANAGEMENT (CDM) SERVICES | 15 |
| 1.4 | MODERNIZATION, REPAIRS, AND ENGINEERING SERVICES | 28 |
| 1.5 | TRAINING SERVICES REQUIREMENTS | 30 |
| 1.6 | TRAVEL REQUIREMENTS | 30 |
| 1.7 | OTHER CONTRACT ADMINISTRATIVE REQUIREMENTS | 31 |
| 1.8 | SHIPPING | 36 |
| 1.9 | Mission Essential Contractor Services: Not Applicable. | 37 |
| 2.2 | PERFORMANCE DEFICIENCIES | 38 |
| 3 | GOVERNMENT FURNISHED PROPERTY (GFP) AND SERVICES. | 39 |
| 3.1 | GFP in SIL. | 39 |
| 3.2 | GFP in Contractor Secured Storage Facility. | 39 |
| 4 | PUBLICATIONS: | 39 |
| Table 2 – Mil Handbooks, Instructions, Specification, and Standards | 40 | |
| Table 3 – DoD Directives, Instructions, Regulations, and Standards | 41 | |
| Table 4 – Air Force Manuals, Instructions, Regulations, Technical Manuals and Pamphlets | 42 | |
| Table 5 – Federal Acquisition Regulations | 43 | |
| Table 6 – CFRs | 43 | |
| Table 7 – Reference Documents | 44 | |
| Table 8 – DISA Documents | 44 | |
| Table 9 – Non-Government Publications | 45 | |
| 5.2 | APPENDIX B: Current HFGCS Locations | 51 |
| 5.3 | APPENDIX C: HFGCS Software Change Request (CR) Risk Classification Matrix | 52 |
| Figure 1 - Risk and Opportunity Classification Matrix | 53 | |
| Table 10 - Scoring of Consequences for an Issue CR | 54 | |
| Table 11 - Scoring of Consequences for an Enhancement CR | 55 |
1. DESCRIPTION OF SERVICES
High Frequency Global Communications System (HFGCS) is a Department of Defense (DoD) program that supports a ground radio equipment/network infrastructure and associated antenna subsystems in support of strategic military command and control (C2) communications. This Performance Work Statement (PWS) provides the requirements for the contractor to perform all management and support necessary to upgrade, modernize, expand, and sustain the communications system. Contractor provided services shall include providing engineering services, furnishing, installing and testing (EFI&T) system upgrades, modernization efforts, expansions, worldwide depot-level sustainment at worldwide locations, and providing full support services for Scope Command to meet new and existing requirements for equipment, hardware, and software in both the sustainment and modernization of the system. Additionally, the accomplishment of insertion studies supporting system growth through inclusion of government developed R&D assets from other programs into SCOPEs operation communications system. Current system assets are located at both within the continental United States (CONUS) sites and outside CONUS (OCONUS) sites (See Appendix B). The contractor shall consider the impact of expansion and new sites when executing the task order efforts awarded within the terms, conditions and scope of this contract.
1.1 PROGRAM MANAGEMENT
1.1.1 Program Management Support
1.1.1.1 The contractor shall provide program management support tasks considered to be contract–level support: to include as a minimum cost and schedule control and status; monthly status reports, task order level technical interchange meetings, teleconferences with the Government HFGCS System Program Office (SPO) and the contracting officer (CO), customer interface, and overall contract oversight/management support. The Program Management (PMS) function provides program management oversight at the basic contract level of individual task orders issued throughout the contracts ordering period(s).
1.1.1.2 PMS task consist of providing contract management documentation as identified by task order requirement and in compliance with the contract data requirement list (CDRL) Exhibit H. requirement listing. Contract level program management requirements are identified in applicable paragraphs below.
1.1.2 Task Order Proposals
The contractor shall submit task order proposals that provide at a minimum the following information:
1.1.2.1 Work Breakdown Structure (WBS) Costs, Task hours, Labor Categories, and descriptive narratives, which identify the basis of estimate, methodology and any project unique considerations included within the proposal to include the date of the forward pricing rate agreement/recommendation (FPRA/FPRR) number as well as the Bid Book numbering being utilized in the development of the proposal.
1.1.2.2 An estimated project schedule that identifies the WBS task duration, dependencies, and deliverables (preferred delivery format is Microsoft Project).
Proposed travel costs will address airfare, rentals, hotel, etc.)
1.1.2.3 Proposed travel costs will address/expense (airfare, rental, hotel, etc.), in compliance with FAR 31.205-46. The contractor is “not" authorized to exceed "Maximum per diem rates" as defined in Defense Contract Audit Agency's (DCAA) Contract Audit Manual (CAM). Rates shall be in accordance with Government travel regulations identified per FAR 31.205-46. Proposals shall projected travel period, number of travelers by labor category, and the location. Costs will identify source of estimate.
1.1.2.4 Installation Materials/Equipment List of Materials to include equipment nomenclature, description title, source of estimate, projected quantities and cost per item.
1.1.2.5 Subcontractor estimates to include description, quantities, cost per item up to including price per page for tech order changes/adds, and subcontractor’s quotes where applicable.
1.1.2.6 For obsolescence/replacement items, identify part, nomenclature, description, and recommend replacement part(s), available sources, and projected costs.
1.1.2.7 Contract Depot Maintenance (CDM) proposals, require that the proposal identify labor costs for specific capabilities such as 24/7 support, subcontractor spare support, time compliance network orders, etc.
1.1.3 Work Schedules
1.1.3.1 Individual task order PWSs will identify local duty day limitations which may require the contractor’s work force to adjust normal work schedules when performing activities on Government facilities.
1.1.3.2 Federally observed Holidays include: New Year’s Day, Birthday of Martin Luther King, Jr., Washington’s Birthday, Memorial Day, Juneteenth, Independence Day, Labor Day, Columbus Day, Veterans Day, Thanksgiving Day, and Christmas.
Specific holiday/schedules outside the eleven federal holidays identified above will be addressed in individual task order requirements as observed by performance on OCONUS installations. Contractor shall identify any personnel policies and labor agreements their company provides for observing holidays other than the identified eleven holidays observed by the Government or any local or foreign holiday observed when services are performed outside the United States.
1.2 MODERNIZATION REQUIREMENTS
1.2.1 Configuration Management
The contractor shall maintain configuration management (CM) in accordance with MIL-HDBK-61B, chapters 5 and 6, dated 7 Feb 2020, and the AFLCMC/HBD Configuration Management Plan (CMP), Dated 04 November 2015. Prior to implementation, a copy of the CMP is to be submitted to the CO for review. The government shall have access and/or visibility of the CMP process as required/ requested by the government.
1.2.1.1 Configuration Audits
The contractor shall assist the Government in performing verifications of the as-built configuration of the installed equipment/location utilizing the contractor's as-built documentation for the particular site during a physical configuration audit (PCA). A separate product baseline shall be established for each Scope Command location at the approval of the PCA report for that location. The contractor shall prepare a configuration audit summary to document the results of each audit. (CDRL D007, DI-SESS-81022E, Configuration Audit Summary Report).
1.2.1.2 Configuration Change Control
After Government approval of an Engineering Change Proposal (ECP), the contractor shall provide updates to the HFGCS Engineering Performance Specification (EPS) prior to deploying the system change (CDRL D006, DI-SESS-80643E Specification Change Notice (SCN)). The contractor shall provide updates/insert pages to all applicable technical orders addressing the system change prior to deployment of the change. (CDRL C006, TM-86-01P, Technical Manual Contract Requirements).
1.2.1.3 Variances
The contractor shall submit a request for deviation when a system configuration change would cause non-conformance with any pertinent specification, including the operational requirements document (ORD), EPS, MIL-STDs and North American Treaty Organization (NATO) standard agreements (STANAGs). Written approval of the CO is required prior to implementation of any variance (CDRL D009, DI-SESS-80640E, Request for Variance).
1.2.1.4 Software Baseline
Updates to the software baseline presented for acceptance testing in the System Integration Lab (SIL), or released to a site, shall be identified with an updated revision number assigned by the contractor IAW CDRL H007, DI-IPSC-81427B, Software Development Plan. Revision changes shall be detailed in the monthly status report (CDRL H001, DI-MGMT-80368A, Status Report).
1.2.1.5 Configuration Management Plan
The contractor shall be responsible for CM and for developing and maintaining a CMP (CDRL H002, DI-SESS-80858D, Contractor’s Configuration Management Plan).
1.2.1.6 Configuration Audit Plan
The contractor shall develop a configuration audit plan (CAP) in accordance with chapters 7 and 8 of MIL-HDBK-61B, Configuration Management Guidance, dated 7 February 2020, Furthermore, the contractor is required to specify how functional configuration audits (FCA) shall be conducted when a system modernization tasking changes the form, fit, or function (FFF) of any portion of Scope Command’s system. The plan shall also specify how PCAs shall be conducted in support of any configuration change (i.e., installation or replacement of hardware or software (CDRL B003, DI-SESS-81646C, Configuration Audit Plan).
1.2.1.7 System/Subsystem Design Description
Modernization efforts require the contractor to update the System/Subsystem Design Description (SSDD) for each system modernization and submit the change for approval prior to implementation. This cumulative submittal shall include existing and new configuration changes for the system (CDRL D003, DI-IPSC-81432A NOT 1, System/Subsystem Design Description).
1.2.1.8 Interface Design Description
The contractor shall provide Interface Design Description (IDD) at a minimum the IDD shall address, the Remote Console, Defense Switched Network (DSN), Non-Secure Internet Protocol Router Network (NIPRNET) gateway, Secret Internet Protocol Router Network (SIPRNET) gateway, and antenna interfaces (e.g., azimuth controller) (CDRL D002, DI-IPSC-81436A NOT 2, Interface Design Description). The contractor shall provide an IDD for other HFGCS subsystems on an as-required basis, when specified in a task order, for specific modernizations. This cumulative submittal shall include existing and new configuration changes for the system. The contractor shall update the IDD as necessary for each system modernization.
1.2.1.9 Software Development Plan
The contractor shall create and maintain the accepted Software Development Plan (SDP) in contractor format. The SDP shall address not only the contractor’s development process, but also the commercial off the shelf (COTS)/non-developmental items (NDI) software integration effort required (CDRL H007, DI-IPSC-81427B, Software Development Plan).
1.2.1.10 Status Report
The contractor shall assess the status of the program and prepare a monthly status report. The assessment shall encompass the status of the overall program and the individual status of each task order issued up to the closing date of the reporting period (CDRL H001, DI-MGMT-80368A, Status Report).
1.2.1.11 Contractor Work Breakdown Structure
The contractor shall provide a contractor work breakdown structure (CWBS) to describe plans for accomplishing the contract work scope consistent with product elements and processes. This CWBS shall serve as the framework for contract planning, budgeting, and reporting to the Government. The contractor shall provide adequate notice of schedule changes for modernization, repairs, and engineering services. Major elements of subcontracted work shall be identified in the CWBS (CDRL A001, DI-MGMT-81334D NOT 1, Contractor Work Breakdown Structure).
1.2.1.12 Data Masters
The contractor shall update site data/drawings as a result of equipment changes and reconfiguration at each site. These data/drawings shall be made available to the Government upon request of the CO (CDRL B004, DI-DRPR-81242 Not 1, Installation Control Drawings).
1.2.1.13 Notice of Revision
The contractor shall provide a Notice of Revision (NOR) specifying the affected documents and describing the changes when a SCN is issued (CDRL A004, DI-SESS-80642E, Notice of Revision).
1.2.1.14 IPv6 Products and Standards
The contractor shall include Internet Protocol version 6 (IPv6) products and standards to the maximum extent practicable for all modernizations. All products in the interim shall be configurable to operate in a dual-stacked environment (IPv4 and IPv6) running simultaneously, until a full implementation of IPv6 is achieved.
1.2.1.15 Human Systems Integration
The contractor shall follow, and update as required, the Human Systems Integration (HSI) plan (CDRL H012, DI-HFAC-81743A NOT 2, Human Systems Integration Program Plan) that addresses MIL-STD-1472, ANSI/HFES 200 and the following human-related domains in an integrated manner throughout the system life cycle:
a. Human Factors Engineering
b. Human Performance Characteristics
c. Habitability of the physical environment
d. Training
e. Environmental Safety and Occupational Health (ESOH)
f. Test and Evaluation
1.2.1.16 Data Accession
The contractor shall provide a quarterly data accession list and the status of data management efforts (CDRL H003, DI-MGMT-81453B, Data Accession List).
1.2.2 Engineering Tasks and Services
1.2.2.1 Technical Capability
The contractor shall possess, and maintain throughout the contract period, the capability to respond to various technical tasks in support of HFGCS with thorough expertise in all aspects of the system and HF communications. The contractor shall provide program-unique engineering services to EFI&T and support all requirements for the continued modernization, upgrade, and expansion of HFGCS as directed by the Government. Contractor Engineering Services shall use disciplined system engineering processes and practices and shall be compatible with Air Force Instruction (AFI) 63-101/20-101 as identified in each individual task order PWS.
1.2.2.2 Technical Studies
The contractor shall perform engineering services and integration of technical studies concerning the feasibility of anticipated future capabilities, technologies and enhancements to HFGCS as requested by the Government (CDRL D008, DI-MISC- 80508B, Technical Report-Study/Services).
1.2.3 Installation and Integration
1.2.3.1 Engineering Change Proposals
Contractor-prepared Engineering Change Proposals (ECPs) shall be provided in correct CDRL format (CDRL D004, DI-SESS-80639E, Engineering Change Proposal).
1.2.3.2 Task Orders
The contractor shall plan, prepare, and perform allied support and equipment installation, removal or modernization effort as directed in each applicable task order. The contractor shall ensure no unintended operational change or degradation occurs within the system.
1.2.3.3 Site Surveys
The contractor shall perform engineering site surveys to establish specific equipment, allied support, and communication interface requirements associated with task order requirements. If available and applicable, local base civil engineering as-built drawings, soil boring data, existing utility layouts, or other similar documents may be provided for on-site review during site surveys. The Government shall not be responsible for the accuracy of local site drawings and/or documents. Locally obtained information/documentation shall be considered “information only” and should not be relied on as a definitive source of survey data and/or for accuracy. The contractor shall develop a Telecommunications System Installation Plan (TSIP) and a Site Preparation Requirements and Installation Plan for each site where equipment installation is required (CDRL B005, DI-MGMT-81118 NOT 1, Telecommunications System Installation Plan), (CDRL B001, DI-MGMT-80033A, Site Preparation Requirements and Installation Plan).
1.2.3.4 Site Preparation
The contractor shall perform site preparation to meet the standards of National Fire Protection Association (NFPA) 101, NFPA 70, local building codes, all applicable current codes and regulations, the site-specific engineering design, and the Government accepted Site Preparation Requirements and Installation Plan when required (CDRL B001, DI-MGMT-80033A, Site Preparation Requirements and Installation Plan).
1.2.3.5 Site Cleanup
The contractor shall perform on-site cleanup of equipment and debris after performing any task requiring on-site work. All hazardous material shall be disposed of IAW local laws and policies. Excess equipment shall be disposed of as specified in each individual task order. In the absence of direction, the contractor shall request disposition instructions from the Government prior to departure from the site.
1.2.3.6 Physical Security Devices
The contractor shall inform the CO and the HFGCS SPO at least 30 calendar days prior to the action, whenever a physical security device (e.g., fence, wall, etc.) must be breached. The SPO will coordinate actions with local site authorities. During the time the physical security device is breached, the host operating organization will provide security for protected assets. The contractor shall restore the breached physical security device to the same level of protection the device provided prior to the breach.
1.2.3.7 Site Protection and Restoration
The contractor shall be responsible for restoration of all contractor-caused damage to existing landscape, environment, utility, facilities, and equipment. If the contractor fails to use reasonable care and causes damage to any property, the contractor shall replace the property or repair the damage at no cost to the Government. If the contractor fails, or refuses, to replace or repair the damage promptly, the contractor shall be responsible for any procurement costs incurred by the Government to have repairs made. Any Contractor damage restoration shall be IAW site directives and specifications.
1.2.3.8 Work Area
The contractor shall keep the installation area, including storage areas used by the contractor, free from accumulation of waste material and rubbish. Upon completion of the installation, the contractor shall leave the work area and premises in a clean and orderly condition satisfactory to the Government Contracting Officer’s representative (COR). The contractor shall assist the COR and local base personnel in accomplishing work area inspections.
1.2.3.9 Excess Equipment
The contractor shall remove all equipment rendered excess during performance of the task order requirement. When excess equipment is identified, the contractor shall request through the CO disposition guidance/instructions, sufficiently in advance of the task order completion, so that disposition can be completed prior to and/or in conjunction with task order completion.
1.2.3.10 Drawings
The contractor shall create, update, and provide as-installed communications system installation drawings for HFGCS equipment, interconnections, and facilities at each site (CDRL B004, DI-DRPR-81242 Not 1, Installation Control Drawings).
1.2.3.11 Installation Plan
The contractor shall develop a detailed installation plan prior to fielding any system and/or modernization to the existing system at the site. The contractor installation plan shall be made available to the Government upon request of the CO. For temporary modifications, the contractor shall develop a de-installation plan to return the system to its currently approved configuration baseline (CDRL B005, DI-MGMT-81118 NOT 1, Telecommunications System Installation Plan).
1.2.3.12 Modernization Support for Material and Workmanship
The Contractor shall provide one–year of maintenance support as part of all modernization task orders with support commencing upon Government acceptance of the requirement. At the end of the year, the support for the acquired materials will be incorporated under CDM. .
1.2.4 Testing
1.2.4.1 Test Plans
The contractor shall create demonstration and acceptance test plans for government review and acceptance compliant with the PWS requirement. The developed plan shall be in compliance with all engineering and performance criteria specified in the ORD and EPS, as well as all testing objectives determined through Systems Engineering documentation. All testing shall be IAW accepted test plans.
1.2.4.2 Factory Development and Demonstration Testing
The contractor shall plan and conduct developmental tests on all new or modified hardware and software introduced under an ECP. Upon completion of ECP testing the contractor shall prepare a factory demonstration test plan for government review and approval. Resulting plan will be utilized to demonstrate successful integration of system control software capabilities, as well as the capabilities of any new or upgraded COTS/NDI equipment prior to fielding. The Government will observe, approve and verify all demonstration testing and test results (CDRL E001, DI-NDTI- 80566A, Test Plan). The contractor shall submit a test report upon completion of each test (CDRL E005, DI-NDTI-80809B NOT 2, Test/Inspection Report).
1.2.4.3 Acceptance Testing
The contractor shall create an installation and acceptance test plan collaboratively with the Government, submit IAW the CDRL (E001, E002, or E004) for government review and acceptance, and witness acceptance testing by the Government IAW that test plan. Acceptance testing shall occur at system locations in order to validate that installation and configuration is as specified in each task order; to verify completeness of the installation; and to perform a functional checkout and regression test to demonstrate system performance IAW ORD, PWS, Task Order and EPS requirements. The Government will conduct acceptance testing and verify all test results. The acceptance test plan will be completed and reviewed for acceptance 30 calendar days prior to contractor beginning any installation (CDRL E004, DI-QCIC-80154A, Installation and Acceptance Test Plan). The contractor shall notify the COR at least 14 calendar days prior to installation completion. When requirements of the acceptance test plan are not met or incidents are recorded which prevent the test from being completed successfully, the contractor shall determine the cause, perform corrective actions, and perform regression tests. These regression tests shall prove to the satisfaction of the Government that all necessary corrective actions have been completed and the corrective actions cause no unintended operational change or degradation within the system. Successful completion of acceptance testing is required for final sign-off on DD Form 250. The contractor shall submit a test report upon completion of each test (CDRL E005, DI-NDTI-80809B NOT 2, Test/Inspection Report).
1.2.4.4 Required Processes
The contractor shall support required Test and Evaluation processes specified in AFI 99-103 (Capabilities Based Test and Evaluation) as identified in each individual task order PWS. The contractor shall provide technical reports, test plans and test plan/inspection reports, as required. (CDRL D008, DI-MISC-80508B, Technical Report- Study/Services), (CDRL E001, DI-NDTI-80566A, Test Plan), (CDRL E004, DI-QCIC-80154A, Installation and Acceptance Test Plan), (CDRL E005, DI-NDTI-80809B NOT 2, Test/Inspection Report)
1.2.4.5 New Station Installation
When new station installations are added to HFGCS, the contractor shall successfully complete all testing prior to cutover. The contractor shall ensure all modernizations and software modifications are integrated with HFGCS so that no unintended operational change or degradation occurs within the system.
1.2.4.6 Integrated Test Team
Upon contract award, the contractor shall be a permanent member of the integrated test team (ITT), and shall provide support for all activities outlined in the HFGCS ITT Charter for the duration of the contract.
1.2.5 Software
1.2.5.1 Software Requirements Specification
The contractor shall update the Software Requirements Specification (SRS) as required when new software versions are implemented (CDRL D001, DI-IPSC-81433A NOT 1, Software Requirements Specification).
1.2.5.2 COTS/NDI Software
The contractor shall incorporate COTS/NDI computer software within HFGCS to the maximum extent possible. The contractor shall ensure that any COTS/NDI software used has an existing and dependable support structure, and has established procedures for incorporation of changes in the post deployment software support phase of the software’s life cycle. The contractor shall document the COTS/NDI integration effort required as part of the SDP (CDRL H007, DI-IPSC-81427B, Software Development Plan).
1.2.5.3 Software Modification
The contractor shall provide software modification or change-out at all HFGCS sites, as appropriate, when software revisions are accepted by the Government. When a modification or change-out of system software is accepted by the Government, the contractor shall accomplish the change in such a manner that only one station within an operational area of responsibility (AOR) is degraded or out-of-service at any given time. The contractor shall maintain hard drive copies of the software revision currently in use at each site (minus the station’s database). The contractor shall propose a Software Installation Plan for each HFGCS location affected by the software modification or change-out (CDRL B002, DI-IPSC-81428A, Software Installation Plan).
The contractor shall develop/modify secure, reliable, resilient, assured software:
a. The contractor shall develop /utilize a secure coding guide for the program which specifies language, required constructs/practices/patterns, prohibited constructs/practices/patterns, and software comment requirements.
b. The contractor shall implement formal (e.g., Fagan) code inspection.
c. The contractor shall assess all code against the Common Weakness Enumeration (CWE), Common Vulnerabilities and Exposures (CVE), and Open Web Application Security Project (OWASP) throughout the development effort and provide reports to the Government summarizing the vulnerabilities and types of vulnerabilities found in terms of the specific CWE, CVE, and OWASP identifiers found.
d. The contractor shall ensure all developers are trained and held accountable for development of secure code including their subcontractors.
e. The methodology to be used in performing security-related and software assurance activities for software shall be documented in the SDP (CDRL H007, DI-IPSC-81427B, Software Development Plan).
It is the Government's objective for the contractor to utilize automated tools to maximize efficiency and effectiveness:
a. The contractor shall use automated tools to support software configuration control.
b. The contractor shall use at least two different commercial tools to measure software quality, and assess vulnerabilities.
c. The contractor shall not disable, or mute, any software compiler warnings without written approval from the Government.
The contractor shall provide a Software Design Description (SDD) (CDRL D005, DI- IPSC-81435A NOT 1, Software Design Description) which details the overall architecture of the software modification and outlines all the parts of the software, how the software module works, describes internal and external program interfaces as well as provides sufficient reference back to each Computer Software Configuration Item’s (CSCI) Software Requirements Specification.
1.2.5.4 Software Metrics
The contractor shall provide the Government with a software metrics summary and a list of the software, including any COTS software, at every site as part of the software metrics report. Software Lines of Code data shall be specified by module to include, at a minimum, total lines of code and modified lines of codes resulting from each applicable modernization task order. All current software revisions and build number, including COTS software (if available), shall be detailed in the report (CDRL H010, DI- MISC-80508B, Software Metrics Report). The Software Metrics report shall provide the government with the current status of data and computer software rights relevant to any and all software delivered in accordance with this contract. The report shall call out and address:
a. Technical data and computer software to be delivered with restrictions prior to delivery.
b. All rights changed as a result of a government funded modification. The metrics report shall address the percentage of software that are considered Restricted Rights as well as the percentage of Unlimited Rights software by module. The metrics report will also address any change in the percentages achieved through Government funded software modification by modification number.
c. The determination of rights to technical data and computer software shall be in accordance with DFARS Clauses 252.227-7013 and 252.227-7014. The software metrics reports may result in modification of the “Identification and Assertion of Restrictions of the Government’s Use, Release, or Disclosure of Computer Software” table contained within said clause.
1.2.5.5 Software Deliverables
The contractor shall provide the Government with the computer source code and documentation for all new and/or modified software for which the Government has Unlimited Rights or Government Purpose Rights. All documentation shall be provided at a level of sufficient detail to provide a developer with the ability to further develop the computer code (CDRL D014, DI-IPSC-81488 Computer Software Product).
1.2.6 Safety Assessment
As part of system safety management, the contractor shall perform a Safety Assessment Report for HFGCS based on MIL-STD-882E (Reference Task 301). This cumulative submittal shall include existing and new configuration changes for the system. When specified in the project task order, separate addendums for individual system modernizations/updates shall be provided when the system is at a final design configuration (CDRL H009, DI-SAFT-80102C, Safety Assessment Report).
1.2.7 Requirements Management
The contractor shall perform requirements management to ensure stated and derived requirements are captured and can be traced/linked between the higher level customer/government requirements and the lower level contractor derived requirements. When specified in the project task order, a requirements verification report shall be done for system modernizations/updates. The report shall be provided when the system is at a final design configuration. If a requirements management tool (e.g., DOORs, Jama) is utilized, the contractor shall provide the government visibility to it in support of project development (CDRL D011, DI-MISC-81283, Specification Requirements Verification Matrix).
1.2.8 Program Protection Implementation Plan
The contractor shall develop a Program Protection Implementation Plan that documents the contractor’s measures to protect CPI and critical components consistent with the government’s latest approved PPP. When specified in the project task order, updates for individual system modernizations/updates shall be provided as part of a cumulative document. This submittal shall include existing and new configuration changes for the system (CDRL H008, DI-ADMIN-81306, Program Protection Implementation Plan).
1.2.9 System Resource Analysis
The contractor shall provide a resource and usage analysis report that supports the government’s Operational Safety, Suitability and Effectiveness (OSS&E) program and system trending/analysis. The intent is to utilize existing sources of data and enable the government to graphically or otherwise depict system usage/trends in a quarterly report. The report, at a minimum, shall include resource usage metrics. The usage metrics shall include:
a. Network component bandwidth utilization (e.g., intersite links)
b. Overall station level utilization (number of levels)
c. Antenna type utilization
d. Number/type of circuits built (e.g., ALE, voice, data)
The usage metrics shall provide information down to a station, NCS, and ACAS, perspective where applicable. The system level metrics for the monthly report shall be captured monthly that includes metrics available through current system modernizations (CDRL H011, DI-MISC-80508B, Technical Report – Study/Services; System Resource Analysis).
1.2.10 Specialized Training Courses
The contractor shall provide additional HFGCS-related training courses when requested by the Government. The task order will specify the purpose and expected knowledge content of the training.
1.2.11 Modernization Training
The contractor shall conduct on-site training and provide training material to site maintenance and operations personnel. Training shall provide personnel with the knowledge and basic hands-on experience for the modernization being fielded. One set of training material shall be provided to each student during the course of the class. The number of trainees and training material distribution will be specified in each task order (CDRL A005, DI-ILSS-80872 NOT 1, Training Materials).
1.3 CONTRACTOR DEPOT MANAGEMENT (CDM) SERVICES
1.3.1 CDM Activities
The contractor shall provide logistics support in a manner consistent with the maintenance concept described in the following subparagraphs. This logistics support shall be available to the Government at contract commencement and for the duration of this contract. For any installation, system modernization, or software upgrade, CDM begins upon completion of installation acceptance testing and acceptance by the Government. The logistics support shall be sufficient to maintain the reliability, availability, and maintainability requirements as specified in the EPS.
1.3.2 Configuration Management
While performing any CDM activity, the contractor shall maintain CM for Scope Command IAW MIL-HDBK-61B, Chapters 5 and 6, Configuration Management Guidance, dated 7 Feb 2020, and Air Force Life Cycle Management Center (AFLCMC) Theater Battle Control Division (HBD) Configuration Management Plan (CMP), Rev 1.7, dated 4 Nov 15.
1.3.2.1 Software Baseline
When CDM activity includes an update to the software baseline as a result of software maintenance, testing for Government approval shall be accomplished in the SIL prior to implementation. Software maintenance builds will undergo security reviews per paragraph 1.2.5. The software version release to a site shall be identified with an updated revision number assigned by the contractor IAW CDRL H007, DI-IPSC-81427B, Software Development Plan. All revision changes shall be detailed in the monthly status report (CDRL H001, DI-MGMT-80368A, Status Report). Software maintenance builds shall also include software metrics reporting per paragraph 1.2.5.4 (CDRL H010, DI-MISC-80508B, Software Metrics Report).
1.3.2.2 Software Development Plan
The contractor shall update the Government accepted SDP as necessary (CDRL H007, DI-IPSC-81427B, Software Development Plan).
1.3.3 Logistics Support Plan
The contractor shall create and provide a Contract Integrated Logistics Support Plan (ILSP) (CDRL H006, DI-ILSS-80095, Integrated Logistics Support Plan).
1.3.4 Logistics Support Expenditures
The contractor shall provide a CDM expenditure summary for all CDM activity. The summary report shall detail cost and man-hours through the prior quarter for the logistics-related WBS elements (CDRL C001, DI-MISC-80508B, Technical Report – Studies; Logistics Management Information (LMI) Summaries). At a minimum, the following areas shall be reported.
a. Technical Assistance Given (Number of IR and AR responses).
b. Telephone Assistance Log (Number of calls and time spent on calls).
c. Software Support and Maintenance (Number of instances/time spent on each).
d. Software Security Patch Test and Evaluation (Number of instances/hours spent each occurrence).
1.3.5 Logistics Support Point of Contact
To ensure effective logistics support and management, the contractor shall provide a single point of contact (POC) for all coordination of all CDM efforts. If there are logistics support problems which cannot be resolved at the site maintenance level, the Government’s POC for resolution and general logistics support planning will be the HFGCS SPO. NOTE: Organizational (on-site, base level) maintenance consists of database management, fault detection, isolation, and replacement of Line Replaceable Units (LRUs). On-site maintenance is performed by trained military, government personnel or maintenance services contractors. These on-site technicians will request contract CDM technical assistance IAW PWS paragraph 1.3.9 and subparagraphs when equipment failures cannot be resolved by organizational-level maintenance personnel.
1.3.6 Depot Maintenance Concept
The contractor shall provide depot level support in order to sustain system reliability, availability, and maintainability as stated in EPS paragraphs 3.4.7, 3.4.8 and 3.4.9, respectively. Depot level support includes material maintenance and/or repairs requiring overhaul, upgrade, or rebuild of parts, assemblies, subassemblies, the testing and reclamation of equipment, and Item Unique Identification (IUID) marking and tracking IAW paragraph 1.3.10 regardless of the location at which the repair is performed. In addition, depot level support includes software maintenance, network maintenance, and maintenance of technical manuals to include review of Air Force Technical Order (AFTO) 22 forms from the field units on technical content problems, technical assistance (including interface support), and spare parts availability. All AFTO 22 forms will be processed through the AFLCMC/HBDH SPO and then forwarded to the contractor if needed for technical assistance. The contractor shall generate a monthly prioritization listing report of change requests (CRs) that are identified for potential software updates. CR prioritization shall be based on risk and ranked into categories using the HFGCS Software Change Request Risk Management Matrix provided in Appendix C to tailor CR prioritization. The contractor shall support discussions regarding status and sequencing of CRs intended for incorporation into future software changes. The report shall contain (at a minimum) CR number, CR title, CR date, priority, planned software incorporation, and status. The report shall be provided to the Government for potential concurrence prior to incorporation of CRs into maintenance updates and system upgrades (CDRL D010, DI-MGMT-81809, Risk Management Status Report).
1.3.6.1 Repair or Replacement Services
The contractor shall provide depot repair and replacement services for all HFGCS related equipment. The contractor shall repair or replace any failed or damaged LRU that is returned to the repair facility. IAW CDM, if the LRU is determined “obsolete” the contractor shall propose an equivalent and qualified Form, Fit, and Function (FFF) replacement. NOTE: The Government may provide Government Furnished Equipment (GFE) to the contractor for use in support of modernization efforts.
1.3.6.2 Scope of Software Responsibility
The contractor shall furnish, install, support, and manage all Government authorized application and operating system executable software used throughout Scope Command. Major operating system updates or updates to COTS products under Government sponsorship (HBSS, SPLUNK, ACAS, etc.) shall be accomplished under separate modernization task orders as addressed in paragraph 1.2. The contractor shall notify the CO and the SPO when software upgrades are beyond CDM performance/security/configuration updates to existing software and therefore require major software updates.
1.3.6.2.1 Communications Control and Management System Support
Upon commencement of this contract, the contractor shall manage, maintain, and when required, modify the Communications Control and Management System (CCMS) software suite under CDM Services, ensuring it meets all required technical operational and information assurance (IA) requirements as specified below in this paragraph. The contractor shall provide CCMS updates and fixes under CDM when software errors are discovered or improvements are implemented. All modified software shall comply with the latest version of the Application Security and Development Security Technical Implementation Guide (ASDSTIG) as prescribed by the HFGCS Information Security System Manager (ISSM). The SPO shall provide independent vulnerability scanning of all modified (source code and executables) software using a DoD approved software code scanning tool to validate ASDSTIG compliance. The contractor shall ensure that the HFGCS control network is compliant with all system security updates as prescribed by the SPO. The contractor shall ensure that all validated “Category I” vulnerabilities identified by independent software vulnerability scanning are corrected prior to implementation of the modified software. The contractor shall ensure all modernizations and software modifications are integrated with HFGCS so that no unintended operational change or degradation occurs within the system.
1.3.6.2.2 COTS License Agreements
The contractor shall acquire, furnish and renew commercial software licenses and agreements for COTS computer network operating system software and applications necessary for the operation and maintenance of the HFGCS throughout the contracted period of performance on behalf of the US Government with the exception of software and licenses provided directly from the US Government as GFE.
All such licenses are to be maintained as distinct items as originally provided by the manufacturer without integration or embedment into any contractor developed application and are not required to the archived. Licenses acquired in support of this contract shall be transferable to the US Government at contract termination or upon direction of the US Government.
1.3.6.2.3 DoD System Security Update and COTS Software Security Support
The contractor shall provide notification, review, and analysis services, as well as phone support, to facilitate the installation of DoD system security updates which include Time Compliance Network Order (TCNO) updates and patches, Security Technical Implementation Guide (STIG) requirements, as well as manufacturer recommended security related COTS component software/firmware updates, upgrades, and configuration changes applicable to all HFGCS systems and subsystems as required by the HFGCS SPO.
1.3.6.2.4 System Security Update Notification and Analysis
Upon notification of a security update by the Government or COTS manufacturer (with Government concurrence), the contractor shall configure, test, and/or analyze system security updates in a lab environment similarly configured as the fielded operational HFGCS equipment. If the security update requirement causes instability in the system, the contractor shall provide an exception report and propose a fix action or disposition, if applicable. When notified of a pending system security update, the contractor shall inform the Government (via email message) of the security update’s applicability to the HFGCS within three working days of the date of notification receipt. If the security update is applicable, the contractor shall adequately test the security update in the lab environment to determine compatibility with the existing system configuration. The contractor shall notify the Government (via email message) of the security update’s compatibility status and make a fielding recommendation for the update within ten working days after the applicability determination date. The Government will make a fielding decision and set a compliance date for each security update based on the security update’s DoD compliance date and the contractor’s fielding recommendation.
1.3.6.2.5 System Security Update Application and Reporting
The contractor shall perform and verify completion of all authorized system security updates applicable to all remotely accessible components comprising the HFGCS unclassified Control Network as required by the HFGCS SPO. The contractor shall, upon Government approval, deploy all approved security updates utilizing the automated software/patch distribution and installation features of HFGCS to the maximum extent possible. This effort shall include any related actions necessary to implement the security update to include coordination of system reboots at each HFGCS station. Where degradation of the system is likely during the security update distribution and installation, the contractor shall recommend a deployment strategy to reduce system degradation and shall coordinate with the SPO if any system downtime is required for implementation of the security update. The contractor shall ensure full system compliance with each security update by no later than the Government’s fielding decision compliance date. The contractor shall deliver a quarterly security update status report. Each security update status report shall contain a consolidated list of all security updates issued for the period. Each report shall identify each security update, the contractor’s receipt date, applicability determination date, fielding recommendation date, the Government fielding approval date, the Governments compliance date, and the fielding completion date (CDRL C001, DI-MISC-80508B, Technical Report – Study/Services; Logistics Management Information (LMI) Summaries).
1.3.6.2.6 System Security Update Verification
The SPO shall provide independent network security scanning to validate network security update compliance and provide “vulnerability per component” (VPC) ratio number on at least a monthly basis. The VPC indicates the average number of open (validated) vulnerabilities identified per HFGCS system component with Microsoft operating systems and is calculated by dividing the total number of vulnerabilities within each severity-category identified on each vulnerability scan by the total number of scanned components with Microsoft operating systems. In the performance of security update duties defined in this section, the contractor shall ensure that the final monthly average VPC ratio for “severity-category I” vulnerabilities shall not exceed 3.0 and that the overall average VPC for “severity-category II” vulnerabilities shall not exceed 6.0 for the contract period. The contractor shall also ensure that none of the validated open category I or II vulnerabilities identified is more than three months past their original compliance date as provided by the SPO. The final monthly VPC ratio measurement shall be taken at the end of the last month of the CLS task order performance period and shall only include security updates issued for the previous 11 months. The final monthly VPC ratio shall be validated and agreed upon by the contractor, the SPO, and the HFGCS ISSM. The following types of vulnerabilities are not be included in the final monthly VPC count:
a. Vulnerability scanner findings that cannot be positively verified to actually exist, known as “False Positives”.
b. Zero Day patches (vulnerabilities that Microsoft or other vendors have not come up with a patch (fix) for yet.
c. Patches not yet cleared for installation as well as those still in the installation process that are not yet completed.
d. Completed/validated patches that show up in the 12th month scan which were not previously detected.
e. Already agreed upon settings that can’t be done without affecting operation of the system.
f. Patches or settings previously deemed not applicable to the system, situation, or environment.
g. Vulnerabilities that were never issued by the Government.
h. Vulnerabilities that are flagged, but are merely checks that the vulnerability scanning system is unable to verify, therefore must be checked manually by a person.
i. Vulnerabilities on systems that cannot be reached via remote means or that are beyond the contractor’s ability to gain administrative access.
j. Vulnerabilities that require contractor modification and/or execution of stored procedure code against the database servers.
1.3.6.2.7 Software Regression Testing
When software upgrades or modifications are to be installed, excluding items covered in PWS paragraph 1.3.7.3.3, anywhere within HFGCS, the contractor shall conduct appropriate regression testing at the SIL to ensure full continued functionality and intrinsic system compatibility. The contractor shall provide specifics of the regression test for Government approval, and a Software Test Report after the test has been concluded delineating the results (CDRL E002, DI-IPSC-81439A NOT 2, Software Test Description (CDRL E003, DI-IPSC-81440A NOT 1, Software Test Report).
1.3.6.3 Software Baseline Security and Tracking
The contractor shall maintain the current system software baseline and all prior system software baselines on an unclassified secure server in the contractor’s Software Development Facility. The current baseline shall contain the most current corrections and contracted changes. The system software baseline definition shall include all third- party vendor software, specified by version and build.
1.3.6.4 System Integration Lab
The contractor shall provide a fully equipped and operational SIL, including receive, transmit, and control functionality, utilizing “like fielded” equipment models, versions, and configurations capable of…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .