Silverlight - Statement of Objectives_26 Oct.docx

DOCX document 43 KB Posted

Attached to
MS Silverlight Licenses Federal contract opportunity
Solicitation number
FA701421R0002
Issued by
Department of the Air Force Headquarters District Washington

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

TITLE

STATEMENT OF OBJECTIVES, (21 Sep 2020)

1. DESCRIPTION OF SERVICES:

BACKGROUND:

1.1. This Statement of Objectives (SOO) defines the Department of the Air Force Office of Special Investigations (OSI) requirement to update/modernize programing code used in three command-wide data applications: the production management tool (Abraxas), the OSI Foreign Disclosure Management System (AFDMS), and the DSS Tracker.

All three applications use a Microsoft SQL backend with Abraxas, AFDMS and the DSS Tracker serving as the user interface. These applications were developed using Microsoft Silverlight which reaches “End of Service” in October 2021. Due the pending discontinuation of Microsoft Silverlight, OSI requires a modern solution to upgrade applications using Microsoft Silverlight to HTML5, JavaScript, or similar web-based user interface compatible with a Microsoft SQL. This modernization must maintain the capability to track, manage, archive and publish all of OSI’s analytical production, foreign disclosure determinations, and track referrals/documentation archived in the DSS Tracker. The following provides an overview of the three applications:

Abraxas – Abraxas is the Command’s web-based production management tool which manages analytical Requests for Information (RFI) and Production Requirements (PRs), the analytical production flow at all levels, validation and assignments, associated data entry, publication, archive and provides unique requirement and product identifiers. This tool also generates customizable reports for all requirements, manages generated production in response to requirements as well as generates custom reports for every data entry field for monthly, quarterly and annual higher-level reporting. Abraxas is also interconnected with the following sub-applications: The Command’s Analytical web-request page, the Command’s Analysis Production Library (APL), the Command’s analytical production feedback mechanism and ultimately the posting of published formal production on both the SIPRNet and JWICS OSI webpages via a custom SharePoint application developed by HQ/XI.

AFDMS – The OSI foreign disclosure program assists AFOSI HQ as well as field units globally by approving the transfer of OSI-originated classified and controlled unclassified information to authorized representatives of a foreign government or international organization on both a strategic and tactical level. Command Foreign Disclosure Officers (FDO) utilize the AFDMS to receive, process, document and archive disclosure determinations command-wide. AFDMS is a web-based management tool which tracks FDO requests from cradle-to-grave. This tool also generates reports for higher-level reporting. AFDMS is available on both SIPRNet and JWICS.

DSS Tracker – The DSS Tracker (now DCSA) provides an easy searchable interface to upload and parse referral email messages and associated/supporting documents. The application enables simple workflow based on attribute tagging in the initial upload. Information is analyzed and data that can’t be attributable is placed into a queue. The application provides administrative oversight of referrals and a search function that allows real-time discovery of historical data and company information provided by DCSA.

1.2. OBJECTIVES / APPROACH:

1.2.1. Objective:

1.2.1.1. This project will upgrade three applications (Abraxas, AFDMS and the DSS Tracker) currently coded with Microsoft Silverlight to HTML5, JavaScript, or similar web-based user interface compatible with a Microsoft SQL backend.

1.2.2. Approach:

1.2.2.1. This code modernization will follow an agile approach and update OSI applications in the following order: Abraxas, AFDMS, and finally the DSS Tracker.

1.3. TASK/SCOPE OF WORK: The contractor will conduct the following tasks under this effort.

1.3.1. Update current Abraxas application Microsoft Silverlight code to HTML5, JavaScript, or similar web-based user interface while maintaining current application capabilities, lists, and workflows on SIPRNet.

1.3.2. Update current AFDMS application Microsoft Silverlight code to HTML5, JavaScript, or similar web-based user interface while maintaining current application capabilities, lists, and workflows on SIPRNet and JWICS.

1.3.3. Update current DSS Tracker Microsoft Silverlight code to HTML5, JavaScript, or similar web-based user interface while maintaining current application capabilities, lists, and workflows on SIPRNet.

1.4. SPECIAL QUALIFICATIONS: At a minimum, all contract personnel shall:

1.4.1. Be a US citizen.

1.4.2. Understand and be knowledgeable of the current AFMC, USAF requirements, and security processes.

1.4.3. Maintain a TS/SCI security clearance. NOTE: While the majority of work can be performed at the Unclassified and Secret security classification level, access to the work area as well as deployment of updated AFDMS code on JWICS will require a Top Secret security clearance.

1.4.4. Acquired experience as the designated lead of a project or program.

1.4.5. Understand the funding process associated with the project’s life-cycle cost.

1.4.6. Understand AF and DoD systems/security requirements.

1.4.7. Have proficiency with computers, Microsoft Windows, Microsoft Project, Microsoft Office software, Microsoft SQL, and web development.

1.4.8. Present a professional appearance, and wear badges identifying them as contractors.

2. DELIVERABLES

2.1. Monthly Reports will include expenditures, schedule, and technical performance progress reports detailing the previous month’s accomplishments, to include financial expenditures and remaining balances, any deviations to cost, schedule, and technical performance milestones, or any issues that are or may prevent/hamper program success shall be provided to the Contracting Officer Representative (COR) and OSI ICON Center program manager by the last day of the month.

2.2. Detailed project schedule listing milestones and completion dates

2.3. Meeting Minutes as required.

2.4. Updated fully functioning code for all three applications.

2.5. Configuration documents for all three applications.

3. GENERAL INFORMATION: The Contractor will prepare and submit to OSI ICON Center reports, plans, studies, schedules, and project reviews in hard and electronic copy format. All content must be marked appropriately according to classification levels. Also, if applicable include the Export Control Warning: WARNING- This document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751, et. seq.) or the Export Administration Act of 1979, as amended, Title 50, U.S.C., App. 2401 et. seq. Violations of these export laws are subject to severe criminal penalties. Disseminate in accordance with provisions of DoD Directive 5230.25.

4. Cybersecurity Assessment and Authorization (A&A): The Contractor shall provide a documented secure solution IAW DoDI 8580.01 for the Electronic Records System project that meets Cybersecurity Assessment requirements that results in Authorization by the Air Force designated Authorizing Official (AO) using the Risk Management Framework (RMF) process. The project System Categorization with an impact level of Moderate is as follows:

Confidentiality: Moderate Integrity: Moderate, Availability: Moderate Impact: Moderate Overlays: Privacy

The Contractor shall implement a security configuration for all hardware and software components of the project to satisfy compliance with the security controls identified in CNSSI 1253 Table D-1, Security Control Baselines. The effort will be assessed and validated by the Government IAW DoDI 8510.01 and National Institute of Standards and Technology (NIST) 800.53, Revision 4 and NIST 800-53A, Revision 4.

Accordingly, the Contractor shall initiate RMF for the project using the Air Force RMF methodology incorporated within the Air Force Enterprise Mission Assurance Support Service (eMASS) system. The Contractor shall satisfy all requirements to complete RMF Steps 2 - , and provide support to Step 5. In accordance with NIST 800-53A, Revision 4 and for a moderate impact system no later than ten (10) months after contract award to ensure a full unconditional Authority to Operate (ATO) is granted.

The Contractor shall identify, manage, and verify adherence to cybersecurity requirements in the same manner as all other system requirements. The Contractor shall identify the requirements that are security critical and establish corresponding controls for these requirements. The Contractor shall ensure and document bi-directional traceability between security controls and requirements.

The Contractor shall identify and implement the applicable cybersecurity controls from Committee on National Security Systems Instruction (CNSSI) No. 1253 for the system using the Risk Management Framework developed by the project, and meet other cybersecurity requirements as stated in Government technical requirements documents. The controls as implemented in the system design shall be documented and submitted as an artifact due upon government request through the project period of performance. The Contractor shall document bi-directional traceability between security controls and requirements.

The Contractor shall select products that have been evaluated against the EAL in accordance with the International Common Criteria for Information Technology Security Evaluation, the DISA APL, the Air Force EPL, or the NIST Federal Information Processing Standard Publication (FIPS PUB) 140-2 (Security Requirements for Cryptographic Modules), as appropriate.

The Contractor shall securely configure all COTS operating system, middleware, and application software.

The Contractor shall ensure that the standard methodology for installation, operation, maintenance, update, and/or patching of software does not alter the secure configuration settings from the approved configuration.

4.1 eMASS A&A Tool: The Contractor shall use the eMASS Tool to manage the System Authorization package. The Contractor shall obtain an AF account to allow them to access the eMASS tool via remote or on Base from the .mil domain. The Contractor shall coordinate eMASS access with the Government.

The Contractor shall fulfill the ‘C&A Team’ (or A&A Team) role of the ‘Package Approval Chain’, as defined in the eMASS RMF User Guide for the systems deployed under this project. In this role, the Contractor shall address all RMF controls in the RMF package and upload artifacts relevant to this project into the eMASS. The Contractor shall provide compelling evidence for all security controls test results. The Contractor shall be responsible for ensuring their inputs satisfy the assessment and authorization of the RMF requirements process that will lead to an Interim Authorization to Test (IATT) if applicable, an unconditional Authorization to Operate (ATO) and finally the Authority to Connect (ATC) from the Air Force Authorizing Official assigned to the system.

The Contractor shall coordinate with PMO Cybersecurity personnel to assist and participate in the Air Force RMF process with the roles of Program Information System Security Manager (ISSM), Information System Security Engineer (ISSE), and Independent Verification and Validation (IV&V). The Contractor shall work with, and accept input and feedback from, the Government PMO team during the execution of this Delivery Order.

4.2 Cybersecurity Assessment: The Contractor shall document all Cybersecurity test assessment procedures in the Security Assessment Plan (SAP) and all compliance results in the Security Assessment Report (SAR) and electronically submit to the Government. SAP methodology shall be consistent with NIST 800-30, Guide for Conducting Risk Assessments, and NIST SP 800-115, Technical Guide to Information Security Testing and Assessment. The Contractor shall assess the security controls in accordance with the Government approved SAP and DoD assessment procedures. Test assessment procedures are used to verify that security controls have been properly implemented and that the vulnerability patches are current. The Contractor shall document and use all applicable DISA Security Requirements Guides (SRGs) and Security Technical Implementation Guides (STIGs) as part of the overall security control assessment. The DoD Knowledge Service (KS) is the authoritative source for security control assessment procedures.

The Contractor shall record actual results of the Security Control Assessment in the SAR and Plan of Action and Milestone (POA&M). The Contractor shall include in the SAR, output from automated test tools or screen shots that depict aspects of system configuration produced during the assessment. If no vulnerabilities are found through the process of executing the assessment procedures, the Contractor shall record the security control as compliant (C). Security controls that are not technically or procedurally relevant to the system, as determined by the AO, shall be recorded by the Contractor as not applicable (N/A) in the POA&M, with sufficient justification. If vulnerabilities are found, the control is recorded as Non-compliant (NC) in the POA&M, with sufficient explanation. The Contractor shall record the status and results of all security control assessments in the control set in the SAR.

The Contractor shall deliver the following artifact documentation as part of the RMF Security Authorization package. Detailed information on the content of the security authorization package is available on the DoD Knowledge Service:

a. All artifacts developed through RMF activity

b. eMass generated Security Plan (SP)

c. Credentialed scan results using Assured Compliance Assessment Solution (ACAS) tools covering all applicable assets within the accreditation boundary

d. Disaster Recovery with Backup and Restoration procedures

e. Contractor POA&M

f. Hardware and Software list in AO required format

g. System topology in AO required format

h. Contractor Security Assessment Plan (SAP)

i. Contractor Security Assessment Report (SAR)

j. Vulnerability Management Plan

k. Patch Management Plan

l. Incident Response Plan

m. Continuity of Operations Plan

n. Ports, Protocols, and Services (PPS) Worksheet (latest version)

4.2 Cybersecurity Validation Testing (Test & Evaluation)/Security Test & Evaluation (ST&E): The Government PMO will utilize the Test and Evaluation event performed by the independent Agent of Security Controls Assessor (ASCA), using the Government approved, Security Assessment Plan, as the formal test for system certification. The Contractor shall support the Government in its cybersecurity compliance assessment efforts by providing systems engineering and documentation support. Should the results of the Contractor Security Assessment and Government PMO Security Assessment events not match, the Contractor shall work with the Government to identify where the differences were generated and perform documentation, resolution, and POA&M related mitigation steps, in order to resolve the discrepancy.

The Contractor shall provide engineering and cybersecurity support to all Government-conducted evaluation events in support of the RMF efforts.

4.3 Vulnerability Mitigation: The Contractor shall ensure there are no “Very High” or “High” levels of risk as defined by NIST SP 800-30 for Non-compliant (NC) security controls. The Contractor shall ensure that NC security controls assessed through Contractor led test events that have “Very High” or “High” levels of risk be resolved or mitigated prior to Government security test events. The Contractor shall identify and resolve or mitigate all Moderate, Low, and Very Low levels of risk for NC security controls. Any level of risk which cannot be mitigated must be approved by the Government. The Contractor shall develop or document in the existing POA&M, residual levels of risk present in the system which must be approved by the Government along with a plan to mitigate or eliminate those risks in the future.

In the case where test results are classified, the Contractor shall not update the NIPR RMF Tool with the results, but shall instead use manual or automated methods to document the findings / vulnerabilities in order to generate a classified POA&M. The Contractor shall have the ability to process classified information. A classified POA&M shall be provided via SIPRNet e-mail, or if not available, by a Defense Security Service (DSS) approved physical means (example CD) to a Government appointed representative per direction of the Government PMO. The Contractor shall update the POA&M documentation as needed, should security weaknesses be discovered, in consultation with the Government PMO. POA&M milestones shall be used to track security vulnerabilities and weaknesses and to determine appropriate disposition.

4.4 Cybersecurity Personnel: The Contractor shall designate an individual as their Cybersecurity lead.

a.The Contractor shall ensure the Lead be experienced in the DoD RMF process, interact with Government assigned RMF personnel and participate in Cybersecurity working groups and meetings.
b.The Contractor shall ensure the Lead have at least 3 years of Cybersecurity related experience and, at a minimum, be Information Assurance Technical (IAT) Level II certified IAW Table C3.T4 of DoD 8570.01-M. The Contractor shall ensure personnel providing management level support such as risk evaluation, be Information Assurance Manager (IAM) Level II or above.
c.Some systems may require additional specialty experience and certification levels such as the “Computer Network Defense-Service Provider Specialty (CND-SP)”. The certification in the CND-SP category most likely to apply to AFLCMC/HNI Contractors is “Infrastructure Support (CND-IS)”. CND-IS personnel test, implement, deploy, maintain, and administer the infrastructure systems which are required to effectively manage the CND-SP network and resources. This may include routers, firewalls, intrusion detection/prevention systems, and other CND tools as deployed within the NE or enclave. The Contractor shall consider individuals within CND-SPs who maintain these infrastructure devices be considered CND-IS. The CND-IS position requirements are listed in DoD 8570.01-M, Table C11.T4. The Contractor shall ensure the Lead have at least 4 years of experience in supporting CND and/or network systems and technology. The Contractor shall ensure all personnel working on cybersecurity related tasks comply with all certification, evaluation, sustainment training, background investigation, and experience requirements of DoD 8570.01-M for the CND-IS specialty. The CND-SP terminology has been changed to Cyber Security Service Provider (CSSP) by the Department of Defense.
d.The Contractor shall ensure the Lead or designee have an active AF Portal and eMASS account.
e.The Contractor shall ensure the Lead serve as the Point of Contact for all RMF test events such as security assessments and penetration tests. The Contractor shall ensure the Lead address all aspects of RMF security control implementation during these events.

5. PLACE OF PERFORMANCE: This SOO provides for FTE personnel who will be located in Russell Knox Building, MCB, Quantico, VA to support the Microsoft Silverlight code modernization (Telework is available). With the approval of the AF Contracting Officer’s Representative (COR) alternative place(s) of performance may be approved if advantageous to the government. The Government work area will include a desk, chair, computer, and telephone for the position. The Government will provide additional equipment upon determination of need. All materials will remain the property of the Government and will be returned upon request or at the end of the contract period of performance.

6. PERIOD OF PERFORMANCE: The initial period of performance will be 6-months from the date that the contract is awarded, and option years for this task may be exercised thereafter for application maintenance and/or work flow updates. This SOO will cover the initial base year plus two one-year option periods.

7. HOURS OF PERFORMANCE: Work shall generally be performed during the working hours of 0730 – 1630, Monday through Friday. Work performed during other than standard hours shall be coordinated with the COR. Any unresolved coordination will be referred to the Contracting Officer (CO). The contractor shall maintain personal continuity to the maximum extent possible. Service will not be required for the following federal holidays on the observed day:

· New Year’s Day, January 1st (or as observed)

· Martin Luther King’s Birthday, 3rd Monday in January

· President’s Day, 3rd Monday in February

· Memorial Day, Last Monday in May

· Independence Day, July 4th (or as observed)

· Labor Day, 1st Monday in September

· Columbus Day, 2nd Monday in October

· Veteran’s Day, November 11th (or as observed)

· Thanksgiving Day, 4th Thursday in November

· Christmas Day, December 25th (or as observed)

8. Contractor Personnel and Security Clearance Requirements: All tasks must be conducted in full compliance with DOD security regulations. Contractor personnel must have or be able to receive a TS/SCI clearance. The contractor will be required to have a facility clearance and an approved DD 254, Contract Security Classification Specification, on file for this contract prior to the contract start date. The contractor shall request security clearances for personnel requiring access to CLASSIFIED information/offices within 16 working days of onboarding.

8.1. Visitor Group Security Agreement (VGSA): The Service Provider shall enter into a long-term group security agreement. This agreement shall outline how the contractor integrates security requirements for contract operations with the Air Force to ensure effective and economical operation on the installation. The agreement should address:

8.1.1. Security support provided by the AF to the contractor. This requirement includes storage containers for classified information/material; use of base destruction facilities; classified reproduction facilities; use of base classified mail services; security badges; base visitor control; investigation of security incidents; base traffic regulations; and the use of security forms and conducting inspections required by DoD 5220.22-R, Industrial Security Regulation, and Air Force Instruction 31-601, Industrial Security Program Management.

8.1.2. Security support requiring joint AF and contractor coordination includes packaging classified information, mailing and receiving classified materials, implementing emergency procedures for protection of classified information, security checks and internal security controls for protection of classified material and high value property.

9. SECURITY CLASSIFICATION GUIDANCE: All U.S. entities, contractors, and vendors conducting work in support of the OSI Microsoft Silverlight code modernization will review Department of Defense (DoD) instructions 5210.67 and 5210.83 with regard to classification guidance for each project they are involved with and adhere to all and any applicable DoD and/or Defense Threat Reduction Security Classification Guide. All entities will implement proper classification markings on all media, e.g., documents and electronic mail.

10. SERVICES SUMMARY:

Performance Objective
Reference
Threshold
PO-1: The requirements experts must submit, to the COR, a Monthly Progress Reports. The Monthly Progress Reports shall detail requirements experts’ activities during the reporting month and plans for the following month.
Para 2.1
No more than 1 late report per quarter
PO-2: Since end of support date is drive by Microsoft, it is imperative that the project schedule is adhered to 100%.
Para 2.2
No deviation from the agreed upon project schedule
PO-4: Update the three applications discussed in this SOO. All applications must be fully functional with no disruptions in processes or accessibility
Para 1.3
Zero deviations from this requirement

11. GOVERNMENT FURNISHED PROPERTY AND SERVICES:

11.1. Facilities and Support Services.

11.1.1. The Government will provide use of all available facilities and support services, materials, publications and forms, and equipment required for contract performance (except as designated in the contract).

11.1.2. The contractor shall keep government-furnished supplies, equipment, and work areas in a safe, orderly, and clean condition.

11.1.3. The contractor shall notify the Government whenever maintenance of equipment is required.

11.1.4. The contractor will return all equipment purchased/leased or obtained from the Government at the completion of this contract or at the request of the Government.

11.2. Space.

11.2.1. Any space used by the contractor in performance of this contract may be used for other purposes during the contractor’s absence.

11.2.2. Items of clothing, personal effects or equipment may not be secured at the facility. The Government will not be liable for theft, damage to or loss of personal items.

11.3. Telephone. The Government will provide local telephone service and long distance code, Class-A telephone lines, and Defense Switching Network lines limited to matters related to the performance of this contract (while contractor personnel are at the RKB bldg). Personal long distance calls are not authorized.

11.4. Badges.

11.4.1. The government will provide a(n) Common Access Cards CAC card/ID badge as appropriate.

11.4.2. Badge will be worn/displayed at all times.

11.4.3. The government will provide (CACs). The contractor shall return all issued items upon contract expiration or termination. Additional information is included in AFFARS Clause 5352.242-9001, CACs for Contractor Personnel.

11.4.4. Upon completion of performance or termination of the contract by the CO, the contractor shall turn in all ID badges and any other document issued by the government to the issuing office, COR or project manager.

12. APPLICABLE DOCUMENTS: In addition to guidance contained in the Statement of Objectives (SOO) the following documents are applicable:

12.1. CJCSI 5123.01h Charter Of The Joint Requirements Oversight Council (JROC) and Implementation of the Joint Capabilities Integration and Development System (JCIDS), 31 Aug 2018

12.2. JCIDS Manual 31 Aug 2018

12.3. AFI 17-101, Risk Management Framework (RMF) for Air Force Information Technology (IT)

12.4. AFI 17-130, Cybersecurity Program Management

12.5. AFMAN 17-1303 Cybersecurity Workforce Improvement Program

12.6. DoDI 8500.01 – Cybersecurity

12.7. DoDI 8510.01 – Risk Management Framework (RMF) for DoD Information Technology (IT)

12.8. DoDI 8551.01 – Ports, Protocols, and Services Management (PPSM) (May 28, 2014)

12.9. DoDI 8580.1 – Information Assurance (IA) in the Defense Acquisition System

12.10. CNSSI 1253 – Security Categorization and Control Selection for National Security Systems

12.11. NIST SP 800-53, Revision 4 - Security and Privacy Controls for Federal Information Systems and Organizations

12.12. NIST SP 800-53A, Revision 4 - Guide for Assessing the Security Controls in Federal Information Systems and Organizations, Building Effective Security Assessment Plans

12.13. NIST 800-30 - Guide for Conducting Risk Assessments

12.14. NIST 800-37 - Guide for Applying the Risk Management Framework to Federal Information Systems: A Security Life Cycle Approach

12.15. NIST SP 800-39, Managing Information Security Risk: Organization, Mission, and Information System View

12.16. NIST SP 800-115, Technical Guide to Information Security Testing and Assessment

12.17. FIPS Publication 140-2 - Security Requirements for Cryptographic Modules

12.18. FIPS Publication 199 - Standards for Security Categorization of Federal Information and Information Systems

12.19. FIPS Publication 200 - Minimum Security Requirements for Federal Information and Information Systems

13. POINTS OF CONTACT:

Contracting Officer Representative:

Name: Melissa Daniels
Email: melissa.daniels.3@us.af.mil
Phone: 571-305-8836

OSI ICON Center (Program Manager) Point of Contact:

Name: Jim Krills Email: james.krills.1@us.af.mil Phone: 571-305-8603

Technical Point of Contact:

Name: Robert Bivins Email: robert.bivins.1@us.af.mil Phone: 571-305-8721

File details come from the government source that posted it. Updated .