DAF ServiceNow Consolidation and IT Asset Management Tool Development_V2-RFI.docx

DOCX document 39 KB Posted

Attached to
DAF SericeNow Consolidation and IT Asset Management Tool Development Federal contract opportunity
Solicitation number
RFISoftwareManagementSvs2024
Issued by
Department of the Air Force Materiel Command Installation and Mission Support Center Installation Contracting Agency

About this file

This document is a Performance Work Statement (PWS) for the DAF ServiceNow Consolidation and IT Asset Management Tool Development for the Headquarters (HQ) Cyberspace Capabilities Center (HQ CCC).

The key objectives are: 1) Consolidate approximately 39 existing ServiceNow platforms into 4 unified instances to streamline business processes, integrate redundant services, and enable a more cost-efficient and manageable enterprise ITSM service model. 2) Develop a DAF ServiceNow IT Asset Management (ITAM) tool to manage Air Force hardware and software assets in accordance with industry best practices and DAF cybersecurity requirements. 3) Provide Tier 3 engineering support for the consolidated ServiceNow instances.

The PWS outlines the scope of work, deliverables, performance standards, quality assurance, and reporting requirements for these efforts. Key performance metrics include 99% system availability, 99% data accuracy, and timely incident resolution and problem management. The contractor will be required to ensure the consolidated ServiceNow instances and ITAM tool meet DAF cybersecurity compliance.

View the file

Other files for this federal contract opportunity

Other files attached to DAF SericeNow Consolidation and IT Asset Management Tool Development, newest first.
File Type Posted
Sources Sought Services.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

DAF ServiceNow Consolidation and IT Asset Management Tool Development for the

Headquarters (HQ) Cyberspace Capabilities Center (HQ CCC)

PERFORMANCE WORK STATEMENT (PWS)

Contents

1.0 Introduction

1.1 Purpose

1.2 Scope

2.0 Specific Requirements

2.1 ServiceNow Instance Consolidation

2.2 Information Technology Asset Management Tool Development

2.3 DAF Instance Operations and Maintenance

3.0 General Requirements

3.1 Period of Performance

3.2 Deliverables

3.3 Contractor’s Quality Control Plan (QCP)

3.4 Quality Assurance

3.5 Holidays

3.6 Hours of Operation

3.7 Security Requirements

3.8 Freedom of Information Act (FOIA)

3.9 Controlled Unclassified Information (CUI)

3.10 Privacy Act

3.11 Records

3.12 Inherently Governmental Functions

3.13 Ethics

3.14 Non-Personnel Services

3.15 Contracting Officer Representative

3.16 Training

3.17 Contractor Key Roles

1.0 Introduction

1.1 Purpose

1.1.1 Provide support of the consolidation of ~39 existing ServiceNow platforms by providing CCC with a team of highly qualified experts to drive, track, and manage implementation of a consolidated ITSM architecture, streamlining business processes, and integrating redundant services and workflows to enable a more cost efficient and manageable enterprise ITSM service model.

1.1.2 Develop a DAF ServiceNow IT Asset Management (ITAM) tool to manage IT hardware and software assets in accordance with industry best practices and DAF cybersecurity requirements. The tool will be built to be in line with the ITAM Data Model and will provide discovery, inventory, tracking, reporting, and license management features.

1.2 Scope: Services include EIT support to

1.2.1 Provide support to consolidate 39 existing ServiceNow instances into 4 unified instances and provide ongoing operations and maintenance services. The consolidation will be led by a team of highly qualified experts who will drive, track, and manage the implementation of a consolidated ITSM.

architecture using ITIL best practices. The new unified instances will be designed to be cybersecurity compliant, following industry standards and regulations.

1.2.2 Develop a DAF ServiceNow IT Asset Management (ITAM) tool to manage Air Force hardware and software assets in accordance with industry best practices and DAF cybersecurity requirements. The tool will be built to be in line with the ITAM Data Model and will provide discovery, inventory, tracking, reporting, and license management features.

1.2.3 Provide Tier 3 engineering support for the 4 unified ServiceNow instances that were consolidated from 39 existing instances. The Tier 3 engineering support team will be responsible for addressing complex incidents and problems, performing root cause analysis, and providing guidance and recommendations for changes and releases.

2.0 Specific Requirements

2.1 ServiceNow Instance Consolidation

2.1.1.1 To reduce the number of ServiceNow instances from 39 to 4, thereby simplifying the ITSM landscape and reducing maintenance and support costs.

2.1.1.2 To streamline business processes by integrating redundant services and workflows across the existing instances.

2.1.1.3 To enable a more cost-efficient and manageable enterprise ITSM service model by consolidating resources and expertise.

2.1.1.4 To improve the overall user experience by providing a single point of access for all ITSM services within a unified instance.

2.1.1.5 To ensure a smooth transition for all users, including training and communication to minimize disruption.

2.1.1.6 To ensure scalability of the new unified instances to accommodate future growth and changes.

2.1.1.7 To ensure the new unified instances are cybersecurity compliant and follow industry standards and regulations.

2.1.2 Scope of Work:

2.1.2.1 Assessment of current ServiceNow instances to identify redundant services and workflows.

2.1.2.2 Design and implementation of a consolidated ITSM architecture using ITIL best practices.

2.1.2.3 Development and execution of a migration plan to move all data and configurations from the existing instances to the new unified instances.

2.1.2.4 Integration of all ITSM services and workflows into the new unified instances.

2.1.2.5 Testing and validation of the new unified instances to ensure all services are functioning as expected.

2.1.2.6 Training and communication to all users to ensure a smooth transition.

2.1.2.7 Go-live support and ongoing maintenance and support of the new unified instances.

2.1.2.8 Design and implementation of scalability measures for the new unified instances to accommodate future growth and changes.

2.1.2.9 Implementation of cybersecurity measures to ensure the new unified instances are compliant with industry standards and regulations.

2.1.2.10 Continuous monitoring and maintenance of the new unified instances to ensure they remain cybersecurity compliant.

2.1.3 Deliverables:

2.1.3.1 A detailed assessment report of the current ServiceNow instances, including identification of redundant services and workflows.

2.1.3.2 A design and implementation plan for the consolidated ITSM architecture using ITIL best practices.

2.1.3.3 A migration plan for all data and configurations.

2.1.3.4 A tested and validated unified ServiceNow instance for each of the 4 instances, designed with scalability in mind and cybersecurity compliance.

2.1.3.5 Training and communication materials for all users.

2.1.3.6 Go-live support and ongoing maintenance and support of the new unified instances.

2.1.3.7 A scalability plan for the new unified instances to accommodate future growth and changes.

2.1.3.8 A cybersecurity compliance report for the new unified instances.

2.1.3.9 Continuous monitoring and maintenance reports of the new unified instances.

2.2 IT Asset Management Tool Development

2.2.1 Scope of Work:

2.2.1.1 Develop ITAM tool with discovery, inventory, tracking, reporting, and license management features for Air Force hardware and software assets, in line with the ITAM Data Model.

2.2.1.2 Ensure the tool meets DAF cybersecurity requirements, including NIST 800-53 and DoD 8570.01-M.

2.2.1.3 Develop user training materials and provide training sessions to end-users.

2.2.1.4 Develop operations and maintenance procedures and documentation.

2.2.1.5 Provide ongoing maintenance and support, including bug fixes, software updates, and user support.

2.2.2 Scalability:

2.2.2.1 Handle inventory and tracking of all Air Force IT hardware and software assets.

2.2.2.2 Availability: Be available 99.9% of the time.

2.2.2.3 Security: Comply with DAF cybersecurity requirements.

2.2.2.4 Response time: Respond to user requests within 2 seconds.

2.2.2.5 Data accuracy: Maintain at least 99% data accuracy.

2.2.2.6 Training materials: Develop training materials in accordance with adult learning principles and end-users must demonstrate proficiency in using the ITAM tool after training.

2.2.2.7 Operations and maintenance procedures: Document and implement procedures and provide ongoing maintenance and support in a timely and effective manner.

2.2.3 Quality Assurance:

2.2.3.1 Code reviews and testing.

2.2.3.2 Automated regression testing.

2.2.3.3 User acceptance testing.

2.2.3.4 Compliance with ITAM best practices and industry standards.

2.2.3.5 Compliance with DAF cybersecurity requirements.

2.2.4 Acceptance Criteria:

2.2.4.1 All functional requirements have been implemented.

2.2.4.2 All performance standards have been met.

2.2.4.3 Compliance with ITAM best practices, industry standards, and DAF cybersecurity requirements has been verified.

2.2.4.4 End-users have demonstrated proficiency in using the tool.

2.2.4.5 Operations and maintenance procedures have been documented and implemented.

2.2.5 Reporting Requirements:

2.2.5.1 Weekly status reports, including progress updates, issues, and risks, and a detailed project plan

2.3 DAF Instance Operations and Maintenance Support

2.3.1 Scope of Work:

2.3.1.1 Tier 3 incident management and troubleshooting to resolve complex issues that cannot be resolved by Tier 1 and Tier 2 support.

2.3.1.2 Problem management to identify and address the root cause of recurring complex issues.

2.3.1.3 Change management to ensure all changes to the unified instances are properly tested, approved, and implemented.

2.3.1.4 Release management to ensure smooth and timely deployment of new features and functionality.

2.3.1.5 Configuration management to maintain an accurate and up-to-date configuration management database (CMDB).

2.3.1.6 Security management to ensure the unified instances are compliant with industry standards and regulations.

2.3.1.7 Reporting and communication to keep stakeholders informed of the status and health of the unified instances.

2.3.2 Performance Standards:

2.3.2.1 The Contractor shall respond to Tier 3 incidents within 2 hours and resolve them within 72 hours.

2.3.2.2 The Contractor shall resolve problems within 14 days.

2.3.2.3 The Contractor shall complete changes within 4 weeks.

2.3.2.4 The Contractor shall release new features and functionality on a quarterly basis.

2.3.2.5 The Contractor shall maintain an accurate and up-to-date CMDB.

2.3.2.6 The Contractor shall ensure the unified instances are compliant with industry standards and regulations.

2.3.2.7 The Contractor shall provide monthly reports on the status and health of the unified instances.

2.3.3 Quality Assurance:

2.3.3.1 The Contractor shall use ITIL best practices throughout the project to ensure the quality of the Tier 3 engineering support services. The Contractor shall also ensure that the unified instances are designed with scalability in mind and are cybersecurity compliant.

2.3.4 Acceptable Criteria:

2.3.4.1 Meeting the performance standards for Tier 3 incident response, problem resolution, change completion, release frequency, CMDB maintenance, and security compliance.

2.3.4.2 Providing monthly reports on the status and health of the unified instances.

2.3.5 Reporting Requirements:

2.3.5.1 The Contractor shall provide a Monthly Status Report (MSR) to the Government demonstrating the Contractor’s performance against the performance standards. The MSR shall include data on the Tier 3 incident response, problem resolution, change completion, release frequency, CMDB maintenance, and security compliance. The Contractor shall also provide any additional reports as requested by the Government.

3.0 GENERAL REQUIREMENTS

3.1 Period of Performance:

3.2 Deliverables:

3.2.1 The Contractor shall submit all deliverables in accordance with the Contract Deliverable Requirements List (CDRL) items. Email and electronic file transfer of deliverables shall be electronically encrypted IAW FIPS 140-2 standards.

3.3 Contractor’s Quality Control Plan (QCP):

3.3.1 The Contractor shall develop and maintain an effective quality control program to ensure services are delivered in accordance with this document. The contractor’s plan should be detailed to incorporate how the contractor will ensure quality services are in line with this requirement. The quality control plan shall implement procedures to identify, prevent, and ensure non-recurrence of defective services. The quality control plan shall describe the actions (measurements, inspections, quality checks or monitoring of process parameters) required to assure Advanced Plus service outputs conform to the requirements in this document.

3.4 Quality Assurance:

3.4.1 The Contractor’s performance under this contract shall be in accordance with the Service Summary (SS) items as defined in Section 4 of this document. The Government will provide a minimum of 60 days notice to the contractor for any changes to the SS.

3.5 Recognized Holidays:

3.5.1 The Government follows the established Federal Government schedule for holidays provided during each calendar year. The federal holidays observed are:

3.5.1.1.1 New Year’s Day

3.5.1.1.2 Birthday of Dr. Martin Luther King Jr.

3.5.1.1.3 Presidents Day

3.5.1.1.4 Memorial Day

3.5.1.1.5 Juneteenth, Independence Day

3.5.1.1.6 Labor Day, Columbus Day

3.5.1.1.7 Veterans Day

3.5.1.1.8 Thanksgiving Day

3.5.1.1.9 Christmas Day.

3.5.2 DAF down-days (i.e., Family Day) are considered business days and are not included in the definition of a federal holiday but may be observed at the discretion of the Government. The COR shall coordinate with the Contractor PM no less than 30 days prior to the observance any down-days. In addition to the days designated as federal holidays, the Government observes any other days as designated by Federal Statute or Executive Order.

3.6 Hours of Operations:

3.6.1 The Contractor is responsible for scheduling on-site services during normal business hours, Monday - Friday, 7:30 AM - 4:30 PM (local time) except Federal holidays or when Government facilities are closed due to local or national emergencies, administrative closings or similar Government directed facility closings, or as otherwise specified within this document to minimize impact to mission capabilities.

3.7 Security Requirements:

3.7.1 Access Control: All persons requiring access to DAF facilities or information as a part of this contract must be a citizen of the United States and may be required to submit proof of citizenship in the form of a notarized birth certificate. U.S. Passport., U.S. Citizenship and Immigration Service (USCIS) Certificate of Citizenship, or USCIS Certificate of Naturalization. All persons and materials entering HQ CCC facilities are subject to inspection at any time.

3.7.2 Information Security: All persons performing work under this contract shall protect and safeguard information in accordance with DoD, DAF/A1 directives, instructions, and procedures. These same persons shall immediately report, upon discovery, any deviation or violation of this guidance, or any unusual or suspicious activity to the AF/A1 Security Office. These same persons shall assist and cooperate in any subsequent investigations or inquiries conducted by the DAF or other Governmental agencies.

3.7.3 Confidentiality: The project and all material provided to the contractor by the DoD to include results, conclusions, and recommendations obtained thereof shall be considered confidential in nature and treated with the same level of care that the contractor treats its own confidential business information. The information shall not be disclosed, copied, modified, used (except in completion of this project) or otherwise disseminated to any other person or entity at any time to include, but not limited to inclusion in any database external to DoD without DoD’s expressed written consent.

3.7.4 Computer Use: Use of DoD Computers is for authorized use only. Computer use is subject to monitoring at any time. All data generated or collected on DAF computers becomes property of the U.S. Government and its release is subject to the needs of the Government. No person is authorized to introduce computer hardware, software, or data storage media; physically or electronically; into a DAF computer, or network device without the prior written approval of the Chief Information Officer (CIO) and notification to the Security Office. Downloading and transmitting information within USAF custody is prohibited except as provided for in the terms of this contract.

3.7.5 Common Access Card: A Common Access Card (CAC) application must be prepared and submitted to the Government for the issuance of an electronic CAC for access to the facility and Government computer systems. All contractors requiring access to the Air Force Network will comply with associated training and guidance per all applicable guidance The contractor is responsible for collecting all CACs from departing contractor employees. Within five (5) days of a contractor employee's departure from the contract, the company must turn in that contractor employee's CAC to the COR.

3.7.5.1 For contractors who require a CAC, contractors shall provide a listing of personnel who require a CAC to the contracting officer. The government will provide the contractor instruction on how to complete the Trusted Associate Sponsorship Systems (TASS) application and then notify the contractor when approved. Contractor personnel shall obtain a CAC from the nearest Real Time Automated Personnel Identification Documentation System (RAPIDS) Issuing Facility (typically the local Military Personnel Flight (MPF)). While visiting or performing work on installation(s)/location(s), contractor personnel shall wear or prominently display the CAC as required by the governing local policy.

3.7.5.2 Trusted Associate Sponsorship System (TASS): The contractor shall process CAC applications through the TASS, the procedures for which are described below. Although there is no requirement for the contractor to designate a “Corporate Facility Security Officer" (FSO) to serve as its single point of contact for the BI, the TASS application process and other CAC and security-related matters, such designation facilitates these processes. If an FSO is not established, all contractor employees requiring a CAC will be required to process their own applications. The submission process for CAC applications is as follows:

3.7.5.2.1 The contractor's FSO or contractor employee shall submit requests for a CAC via email to the designated TASS Trusted Agent (TA).

3.7.5.2.2 The Government will establish a TASS application account for each CAC Request and will provide each contractor employee a USER ID and password, via email, to the FSO. The FSO or contractor employee shall access the TASS account and complete the CAC application (entering/editing contractor information as applicable) at: https://www.dmdc.osd.mil/tass/. The FSO or contractor employee shall follow up to ensure that the TA is processing the request.

3.7.5.2.3 The Government will inform the contractor's applicant, via email, of one of the following: a. Approval.* Upon approval, the information is transferred to the DEERS database and an email notification is sent to the contractor with instructions on obtaining their CAC. The contractor proceeds to a RAPIDS station (RAPIDS Site Locator http://www.dmdc.osd.mil/rsl/). b. Rejection.* The Government, in separate correspondence, will provide reason(s) for rejection. c. Return. Additional information or correction to the application required by the contractor employee. *The contractor shall maintain records of all approved and rejected applications.

3.7.5.2.4 At the RAPIDS station, the RAPIDS Verification Officer will verify the contractor employee by SSN and two forms of identification. Identity source documents must come from the list of acceptable documents included in Form I-9, OMB No. 1615- 0047, "Employment Eligibility Verification." Consistent with applicable law, at least one document from the Form I9 list shall be a valid (unexpired) State or Federal Government-issued picture ID. The Identity documents will be inspected for authenticity and scanned and stored in the DEERS upon issuance of an ID. The photo ID requirement cannot be waived, consistent with applicable statutory requirements. The Verification Officer will capture primary and alternate fingerprints, picture, and updates to DEERS, and will then issue a CAC. Issued CACs will be valid for no longer than three years, or until the individual's contract end date (inclusive of any options), whichever is earlier.

3.7.5.2.5 The contractor shall return issued CACs to the DEERS office upon departure or dismissal of each contractor employee, and shall obtain a receipt for each card and provide it to the COR.

3.7.5.2.6 The contractor shall manage requests for new or renewal CACs in sufficient time to ensure that all contractor employees have them when needed to perform work under this contract. The contractor shall provide at least one month (30 days) advance notice to the COR, unless there are extenuating circumstances approved by the COR.

3.8 Freedom of Information Act (FOIA). All official Government records affected by this contract are subject to the provisions of the FOIA (5 U.S.C. 552/DoD 5400.7-R/AF Supplement). Any request received by the Contractor for access/release of information from these records to the public (including Government/Contractor employees acting as private citizens), whether oral or in writing, shall be immediately brought to the attention of the CO for forwarding to the FOIA Manager to ensure proper processing and compliance with the Act.

3.9 Controlled Unclassified Information (CUI). The Contractor shall comply with DODD 5400- 7, Chapter 4, DoD Freedom of Information Act (FOIA) Program requirements. This regulation sets policy and procedures for the disclosure of records to the public and for marking, handling, transmitting, and safeguarding material.

3.10 Privacy Act. Work on this contract may require that personnel have access to information protected by the Privacy Act. Contractor personnel shall adhere to the Privacy Act, Title 5 of the U.S. Code, Section 552a and applicable agency rules and regulations when handling such information.

3.11 Records. All records created and received by the Contractor in the performance of this contract shall be maintained and readily accessible. Records shall remain the property of the Government.

3.12 Inherently Governmental Functions. The Contractor shall not perform inherently governmental functions as defined in the Federal Acquisition Regulation (FAR) Subpart 7.5 in relation to this PWS.

3.13 Non-Personal Services. The Government will not supervise or task Contractor employees in any manner that generates actions of the nature of personal services, or that creates the perception of personal services. It is the responsibility of the Contractor to manage its employees directly and to guard against any actions that are of the nature of personal services or give the perception of personal services to the Government or to Government personnel. If the Contractor feels that any actions constitute, or are perceived to constitute personal services, it is the Contractor’s responsibility to notify the CO immediately. Non-personal Contractor services shall not be used to perform work of a policy/decision making or management nature.

3.14 Contracting Officer Representative. The COR will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration. The COR is authorized to perform the following functions: assure the contractor performs the technical requirements of the contract; perform inspections necessary in connection with contract performance; maintain written and oral communications with the contractor concerning technical aspects of the contract; issue written interpretations of technical requirements, including Government drawings, designs, specifications; monitor contractor's performance and notify both the Contracting Officer and contractor of any deficiencies; coordinate availability of Government furnished property; and provide site entry of contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the contractor, states the responsibilities and limitations of the COR, especially regarding changes in cost or price, estimates, or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

3.15 Training. The contractor shall incur all costs for training contractor personnel to meet the requirements of this PWS.

3.16 Contractor Key Roles.

File details come from the government source that posted it. Updated .