SolarWinds_Support_PWS_23Sept20docx.docx

DOCX document 39 KB Posted

Attached to
Solar Winds software support and training Federal contract opportunity
Solicitation number
W912PQ20Q0052
Issued by
Department of the Army New York Army National Guard

View the file

Other files for this federal contract opportunity

Other files attached to Solar Winds software support and training, newest first.
File Type Posted
SolarWinds_Support_PWS_23Sept20docx.docx DOCX document
Wage Determination.txt TXT text file
W912PQ-20-Q-0052.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT (PWS)

FOR

SOLARWINDS ACCESS RIGHTS MANAGER (ARM) AND ORION INTEGRATION SERVICE CONTRACT

NEW YORK ARMY NATIONAL GUARD

(PERIOD OF PERFORMANCE: 1 YEAR: 30 SEP 20 TO 29 SEP 21 WITH 4 OPTION YEARS)

1.0 General: The New York National Guard (NYARNG) has a requirement to improve the capability and usability of active directory (AD), along with providing an auditing and management solution. This can be accomplished using the Solarwinds Access Rights Manager (ARM) application which would work cooperatively with the existing Solarwinds Orion product. This will provide a crucial component for compliance in the upcoming Command Cyber Readiness Inspection (CCRI) currently scheduled for August of 2021. The contractor will be required to configure ARM and Orion, ensure interoperability, and provide training for both Solarwind Orion and ARM products. With the COVID-19 situation, the contractor will configure and training in person (preferred) or live virtual. No self-pace training.

1.1 Scope: This performance work statement (PWS) defines requirements for the contractor to maintain, patch, upgrade and provide help desk availability to maintain the performance and efficiency of the application. This requirement is for Orion and ARM products.

1.2 Background: The MNCI Directorate of the New York State Division of Military and Naval Affairs (DMNA) requires acquisition, configuration, and Secure Technical Implementation Guidance (STIG) compliance of Solarwinds Active Rights Manager (ARM) to work cooperatively with an existing Solarwinds product (Orion) to provide highly effective Information Technology infrastructure auditing and management that is required for the NYARNG Cyber Command Readiness Inspection (CCRI). To execute this initiative properly MNCI requires on-site configuration and setup of Solarwinds Access Rights Manager (ARM) and Orion products.

1.3 Period of Performance (PoP): The Period of Performance will be on-site between: 30 September 2020 to 29 September 2021.

1.3.1 Place of Performance: 330 Old Niskayuna Road, Latham, NY 12110. If any Virtual training, it will take place on either Microsoft Teams or Cisco WEBEX platforms.

1.4 General Information:

1.4.1 Quality Control (QC): The contractor will maintain an effective QC plan (QCP) to ensure services are performed in accordance with the PWS. The contractor’s QCP is the means by which it assures itself that its work complies with the requirements to the contract. As a minimum, the contractor shall develop QC procedures that address the areas identified in paragraph 6.1.2 (required end state).

1.4.2 Quality Assurance (QA): The Government will evaluate the contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP) (Appendix E). This plan is primarily focused on what the Government must do to ensure that the contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and acceptable quality levels.

1.4.3 Recognized Holidays: the following are recognized US Holidays. The contractor shall not be required to perform services on these days:

1.4.3.1 New Year’s Day: January 1st

1.4.3.2 Martin Luther King, Jr.’s Birthday

1.4.3.3 President’s Day

1.4.3.4 Memorial Day

1.4.3.5 Independence Day: July 4th

1.4.3.6 Labor Day

1.4.3.7 Columbus Day

1.4.3.8 Veteran’s Day: November 11th

1.4.3.9 Thanksgiving Day

1.4.3.10 Christmas Day

1.4.5 Security Requirements: On-site technician/contractor, shall comply with all applicable installation/facility access and local security policies and procedures, which may be obtained from the Division of Military and Naval Affairs Chief Information Officer (CIO). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by the agency. The contractor shall ensure compliance with all personal identity verification requirements as directed by The Division of Military and Naval Affairs and/or other local policy. Should the Force Protection Condition (FPCON) change, the Government may require changes in contractor security matters or processes.

1.4.5.1 COMSEC/IT Security. All communications with DOD organizations are subject to Communications Security (COMSEC) review. All telephone communications networks are continually subject to intercept by unfriendly intelligence organizations. DOD has authorized the military departments to conduct COMSEC monitoring and recording of telephone calls originating from, or terminating at, DOD organizations. Therefore, the contractor is advised that any time contractor place or receive a call they are subject to COMSEC procedures. The contractor is require before coming to site to be properly vetted through NYARNG J2, and have a clearance level of SECRET. The contrctor shall ensure wide and frequent dissemination of the above information to all employees dealing with DOD information. The contractor shall abide by all Government regulations concerning the authorized use of the Government's computer network, including the restriction against using the network to recruit Government personnel or advertise job openings.

1.4.5.3 Protection of Personally Identifiable Information (PII). The contractor shall protect all Personally Identifiable Information (PII) encountered in the performance of services in accordance with DFARS 224.103 and DoDD 5400.11, Department of Defense Privacy Program, and DoD 5400.11-R. If a PII breach results from the contractor’s violation of the aforementioned policies, the contractor shall bear all notification costs, call-center support costs, and credit monitoring service costs for all individuals who’s PII has been compromised.

2.0 Definitions and Acronyms:

2.1.1 CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.

2.1.2 DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.

2.1.3 DELIVERABLE. Anything that can be physically delivered and includes non-manufactured things such as meeting minutes or reports.

2.1.4 KEY PERSONNEL. Familiarity with Orion products 2019.4 and ARMs 2019.4

NPM

NTM

IPAM

NTA

Netpath

NCM

Orion Core ARM Core

Orion installed in both the SIPR/NIPR networks. ARM installed only on NIPR network.

2.1.5 PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.

2.1.6 QUALITY ASSURANCE. The government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.

2.1.7 QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of contractor performance.

2.1.8 QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.

2.1.9 SUBCONTRACTOR. One that enters into a contract with a prime contractor. The Government does not have privity of contract with the subcontractor.

2.1.10 WORK DAY. N/A.

2.1.11 WORK WEEK. N/A.

2.2 ACRONYMS:

AEI Army Enterprise Infostructure AT/OPSEC Antiterrorism/Operational Security CIO Chief Information Officer DFARS Defense Federal Acquisition Regulation Supplement DMNA Division of Military and Naval Affairs (New York State) DOD Department of Defense FSO Facility Security Officer/Supervisor GFP/M/E/S Government Furnished Property/Material/Equipment/Services IA Information Assurance IS Information System(s) OCI Organizational Conflict of Interest ODC Other Direct Costs PII Personally Identifiable Information PIPO Phase In/Phase Out POC Point of Contact PRS Performance Requirements Summary PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control QCP Quality Control Program

3.0 Government Furnished Property, Material, Equipment and Services (GFP/M/E/S): N/A.

4.0 N/A.

5.0 Requirements. Contractor will have proper clearance (Secret) provide all updates, patches, software revisions and normal workday access to technical support as required to allow continuous function of the application.

5.1.1 Updates/upgrades are provided as required to maintain normal function of the application.

5.1.2 Patches are provided as required to maintain normal function of the application.

5.1.3 Access to vendor technical support via telephone or email.

5.1.4 Access to technical support is provided by e-mail or telephone.

5.1.5 Access to Technician Technical Support for issues that cannot be resolved by the above.

5.1.6 Requires to be contractors before coming to site to be properly vetted through NYARNG J2.

6.1 General Description. Below is a general description of what currently exists followed by the desired end-state.

6.1.1 Current: The MNCI directorate currently has both Solarwind Orion and ARM products in our NYARNG virtual server infrastructure. Orion installed on both SIPR and NIPR networks. ARM installed only on the NIPR network. Both products are currently on 2019.4 but due to STIG requirements might be updated to the latest version. The MNCI Directorate requires either on-site configuration support or live virtual support of both Solarwind ARM and Orion. Orion is currently monitoring 265 out of 500 nodes and Orion NPM is monitoring 208 out of 500 nodes. ARM is monitoring NYARNG organizational unit (OU) and is monitoring permissions on all NYARNG file servers. MNCI staff requires the Solarwinds products to be compliant for NYARNG Cyber Command Readiness Inspection (CCRI) and be configure to assist MNCI staff to be in compliance for CCRI. This must be done without additional 3rd party solutions that will incur additional costs to DMNA. Due to COVID-19, Employees of MNCI are working both in person and virtual during the hours of 0700-1700.

6.1.2 Required End State: Configuration, integration and compliance all of NYARNG Solarwinds products to achieve a compliant and integrated software solution in which it will be use as a requirement for successful IT infrastructure management and control necessary for the passing of NYARNG CCRI in August 2021.

6.1.3 Functional Specs: The requirements described below MUST be included in the solution quoted/proposed. Requirements:

6.1.3.1 This contract will provide:

6.1.3.1.1 Installation, configuration, and make compliant software:

6.1.3.1.2 Solarwinds Access Rights Manager (ARM)

· Analysis and configured ARMS based on NYARNG Infrastructure

· Workflows/templates that need to be created and tested (Appendix A) General user:

· New users request

· File share group request

· Change position request

· Renewal of account

· Privilege user:

· New user request

· User Data Owner Request

· Renewal of account

· Change Data Owner Request

· Recertification of user account

· Create CCRI reports (Appendix B)

· Make CCRI Compliant (Appendix C)

· Configure Data Owner Hierarchy

· Configure Active Directory Logga

· Configure File Server Logga

· Configure User Management

· Configure Dashboards

· Configure web client

· Allow administrators to add notes to user accounts and groups

· Set up Permission Analysis on both Active Directory and File Server

· Set up Security Monitoring on both Active Directory and File Server

· Setup and configure Role and Process Optimization

· Set up scans for both AD and File Shares

· Set up and teach how to create templates

· Set up Easy Connect CSV and SQL

· Set up alerts and custom reports (Appendix D)

· Set up and configure Data Owners infrastructure

· Set up and define ARM user’s roles and permissions.

6.1.3.1.3 Solarwinds Orion:

· Analysis and configured ARMS based on NYARNG NIPR/SIPR Infrastructures

· Create and configure Executive Dashboard

· Compliance for CCRI

· Complete upgrade to the latest version

· Configure new features of the most recent version

· Maximize the usage of NYARNG Orion product based on current licensing

· Configure and check STIG Compliance checker

· Set up generating network visualization

· Configure device lifecycle management

· Set up configuration backup

· Set up alerts custom, monitors, and reports

· Set up DNS and DHCP Monitoring and Management

· Set up SysLog and Orion Log monitoring

· Set up Monitoring of ASA

· Set up Monitoring of wireless networks

· Create custom monitors in NPM

· Set up monitoring of Hardware Health

· Proper account provisioning

· IPAM VMware Integration setup

· Set up Net flow management

6.1.3.1.4 System testing and validation

· Capture equipment status and configuration report

· Create Solarwinds Support request to update configuration information

· Verify configuration aligns with the design

6.1.3.1.5 Instruction and education

· Instruct and educate selected users of Solarwinds ARM and Orion products and configuration

· Create how-to guides based on the configuration of NYARNG Solarwinds environment

6.1.3.1.6 Optional Requirements: None.

Appendixes

Appendix A8
Appendix B8
Appendix C9
Appendix D9
Appendix E10

Appendix A The following are a combination of workflow to include creating templates and recertification request.

General user:

· New user’s request- General user logs into ARMS web portal, filling out a form to request an account and uploads the forms. Then routes to J2 that can check user’s security level. Once J2 approves, route to IA for final approval which then creates the account in Active Directory and associates the account to the right groups.

· File Share Group Request- General user logs into ARMS web portal, fills out a form to request access to a file share. Routes to data owner of the share drive.

· Change position- General user logs into ARMS web portal, fills out a form to request change of position, routes to IA for final approval

· Renewal of account- General user logs into ARMS web portal, fills out a form to request renewal of account to included uploading documents/certification.

· Privilege user:

· New Privilege User Request- Potential privilege user logs into ARMS web portal, filling out a form to request an account and uploads the forms. Routes to IA for final approval which then creates the account in Active Directory, associate Data Owner, and associates the account to the right groups.

· User Data Owner Request- Privilege user logs into ARMS web portal, fills out a form to request to be a Data Owner. Routes to IA and add them to data owner.

· Renewal of Account- Privilege user logs into ARMS web portal, fills out a form to request renewal of account every three months. Routes to IA for approval.

· Change Data Owner Request- Privilege user logs into ARMS web portal, fills out a form to request to change Data Owner. Routes to IA and change them to new data owner.

· Recertification of user account- Privilege users logs into the ARMs web portal, fill out a form and upload documentations. Routes to IA for approval.

Appendix B The following are the CCRI reports that need to be created/set up

· Who is in each file share group permissions

· Who is in privilege groups

· What file share groups belong in each file share

· What level of privilege does each group/account have on a file share

· Who has access where

· Group Membership and account details

· Inactive accounts

· Local accounts on servers Appendix C The following is to make Solarwinds Products CCRI Compliant:

· Make sure both Solarwinds Orion and ARMs up to date with the latest STIG

· Make sure both Solarwinds Orion and ARMs are up to the latest National Guard Bureau support OS and software

· Make sure both Solarwinds Orion and ARMs have SSL Certificates Appendix D Setup, configure, and create alerts on the following reports:

· Set up and configure reports to be run on web client

· ARMs, Active Directory, and File share.

· Active Directory OU members and group membership

· Who has passwords on their accounts

· Permission differences

· Directories who owners are not administrators

· Usage of everyone and authenticated users

· Unresolved SIDs

· Direct permissions

· Who has access through which permission groups

· Where do employees of a manager have access

Appendix E

QUALITY ASSURANCE SURVEILLANCE PLAN

For: SOLARWINDS ACCESS RIGHTS MANAGER (ARM) AND ORION INTEGRATION SERVICE CONTRACT Contract Number:

Contract Description:

Contractor’s name: Solar Winds (hereafter referred to as the contractor).

1. PURPOSE.

This Quality Assurance Surveillance Plan (QASP) provides a systematic method to evaluate performance for the stated contract. This QASP explains the following:

· What will be monitored.

· How monitoring will take place.

· Who will conduct the monitoring.

· How monitoring efforts and results will be documented.

This QASP does not detail how the contractor accomplishes the work. Rather, the QASP is created with the premise that the contractor is responsible for management and quality control actions to meet the terms of the contract. It is the Government’s responsibility to be objective, fair, and consistent in evaluating performance. In addition, the QASP should recognize that unforeseen and uncontrollable situations may occur.

This QASP is a “living document” and the Government may review and revise it on a regular basis. However, the Government shall coordinate changes with the contractor. Updates shall ensure that the QASP remains a valid, useful, and enforceable document. Copies of the original QASP and revisions shall be provided to the contractor and Government officials implementing surveillance activities.

The following FAR clauses may apply depending on contract type:

N/A.

2. GOVERNMENT ROLES AND RESPONSIBILITIES.

The following personnel shall oversee and coordinate surveillance activities.

a. Contracting Officer (KO) - The KO shall ensure performance of all necessary actions for effective contracting, ensure compliance with the contract terms, and shall safeguard the interests of the United States in the contractual relationship. The KO shall also ensure that the contractor receives impartial, fair, and equitable treatment under this contract. The KO is ultimately responsible for the final determination of the adequacy of the contractor’s performance.

Assigned KO:

Organization or Agency: New York State Division of Military and Naval Affairs Telephone: (518) 786- Email:

b. Contract Specialist (KS) - The KS acts as an acquisition consultant and serves as liaison between the TMA Contract Operations Division – Falls Church (COD-FC) and the requesting program office, as well as liaison between the TRICARE Management Activity (TMA) and the supporting contracting office.

Assigned KS:

Telephone: (518) 786- Email: .civ@mail.mil

c. Contracting Officer’s Representative (COR) - The COR is responsible for technical administration of the contract and shall assure proper Government surveillance of the contractor’s performance. The COR shall keep a quality assurance file. At the conclusion of the contract or when requested by the KO, the COR shall provide documentation to the KO. The COR is not empowered to make any contractual commitments or to authorize any contractual changes on the Government’s behalf. The contractor shall refer any changes they deem may affect contract price, terms, or conditions to the KO for action.

Assigned COR: Dennis D. Kavanagh Telephone: 518-786-4819 Email: dennis.d.kavanagh.civ@mail.mil

Other Key Government Personnel –

Title: Systems Administrator Name: Ms Jeanette Gibson Telephone: (518) 786-4872 Email: Jeanette.m.gibson5.mil@mail.mil

Title: Network Manager Name: SFC John Mustico Telephone: (518) 786-4818 Email: john.m.mustico.mil@mail.mil

3. CONTRACTOR REPRESENTATIVES:

The following employees of the contractor serve as the contractor’s Program Manager and Task Manager for this contract.

a. Program Manager - Telephone:

Email:

b. Task Manager - Telephone:

Email:

c. Other Contractor Personnel - Title:

Telephone:

Email:

4. PERFORMANCE STANDARDS.

Performance standards define desired services. The Government performs surveillance to determine if the contractor exceeds, meets or does not meet these standards.

The Performance Requirements Summary Matrix, paragraph in the Performance Work Statement includes performance standards. The Government shall use these standards to determine contractor performance and shall compare contractor performance to the Acceptable Quality Level (AQL).

Performance Requirements Summary

This Performance Requirements Summary includes performance standards. The Government will use these standards to determine contractor performance and will compare contractor performance to the Acceptable Quality Level (AQL).

PWS Paragraph
Task
Performance Standard
Acceptable Quality Levels (AQL)
Surveillance Method / By Whom

Para. 6.1.3.1.1

The contractor shall provide a configured and compliant application. Installation.
Application and updates/upgrades are installed, tested and certified as fully functional by MNCI Staff.
Application meets performance standards.
Network Administrator confirms proper functioning. Report to COR.

Para. 6.1.3.1.2

The contractor will ensure applications configured to NYARNG infrastructure with all with all workflows and templates created and tested IAW App A, B, C, and D
Applications are correctly configured and templates and workflows functioning IAW App A, B, C, and D
Application meets performance standards.
Network Administrator and Network Manager confirms proper functioning. Report to COR.

Para. 6.1.3.1.3

The contractor shall ensure configuration system testing and validation meets all STIG And CCRI implementation requirements for NIPR and SIPR infrastructures. Contractor provides properly vetted and credentialed personnel to work on NIPR and SIPR enclaves.
Configuration meets all STIG and CCRI implementation and configuration standards for NIPR and SIPR infrastructures. Contractor personnel are properly vetted and credentialed.
Application meets performance standards.
Network Administrator and Network Manager confirms proper functioning. Report to COR.

Para. 6.1.3.1.4 Contractor provides validated system testing configuration reports and verifies configuration aligns with requested design.

Validated testing and configuration report verifies configuration and alignment with requested design.
Application meets performance standards.
Network Administrator and Network Manager confirms proper functioning. Report to COR.
Para. 6.1.3.1.5
Contractor provides instruction/education to select users on applications and production/reports to include how-to guides based on the configuration of the Solar Winds environment created.
Selected users receive appropriate level of training and reference materials to effectively and efficiently enter data, create/receive reports.
Application meets performance standards.
Network Administrator and Network Manager confirms proper functioning. Report to COR.

5. INCENTIVES. N/A.

6. METHODS OF QA SURVEILLANCE.

Various methods exist to monitor performance. The COR shall use the surveillance methods listed below in the administration of this QASP.

Regardless of the surveillance method, the COR shall always contact the contractor's task manager or on-site representative when a defect is identified and inform the manager of the specifics of the problem. The COR, with assistance from the COD KS, shall be responsible for monitoring the contractor’s performance in meeting a specific performance standard/AQL.

a. DIRECT OBSERVATION.

b. MANAGEMENT INFORMATION SYSTEMS (MIS).

c. PERIODIC INSPECTION.

d. USER SURVEY. .

e. VALIDATED USER/CUSTOMER COMPLAINTS. PWS.

f. PERIODIC SAMPLING.

g. RANDOM SAMPLING.

Surveillance results may be used as the basis for actions (to include payment deductions) against the contractor. In such cases, the Inspection of Services clause in the Contract becomes the basis for the KO’s actions.

8. RATINGS.

Metrics and methods are designed to determine if performance exceeds, meets, or does not meet a given standard and acceptable quality level. A rating scale shall be used to determine a positive, neutral, or negative outcome. The following ratings shall be used:

EXCEPTIONAL:
Performance significantly exceeds contract requirements to the Government’s benefit.
SATISFACTORY:
Performance meets contractual requirements.
UNSATISFACTORY:
Performance does not meet contractual requirements.

9. DOCUMENTING PERFORMANCE.

a. ACCEPTABLE PERFORMANCE.

The Government shall document positive performance. A report template is attached. Any report may become a part of the supporting documentation for fixed fee payments, award fee payments, or other actions.

b. UNACCEPTABLE PERFORMANCE.

When unacceptable performance occurs, the COR shall inform the contractor. This will normally be in writing unless circumstances necessitate verbal communication. In any case the COR shall document the discussion and place it in the COR file.

When the COR determines formal written communication is required, the COR shall prepare a Contract Discrepancy Report (CDR), and present it to the contractor's task manager or on-site representative. A CDR template is attach to this QASP.

The contractor shall acknowledge receipt of the CDR in writing. The CDR will specify if the contractor is required to prepare a corrective action plan to document how the contractor shall correct the unacceptable performance and avoid a recurrence. The CDR will also state how long after receipt the contractor has to present this corrective action plan to the COR. The Government shall review the contractor's corrective action plan to determine acceptability.

Any CDRs may become a part of the supporting documentation for contract payment deductions, fixed fee deductions, award fee nonpayment, or other actions deemed necessary by the KO.

10. FREQUENCY OF MEASUREMENT.

a. Frequency of Measurement.

During contract/order performance, the COR shall take periodic measurements, weekly as specified in the AQL column of the Performance Standards Summary Matrix, and shall analyze whether the negotiated frequency of measurement is appropriate for the work being performed.

b. Frequency of Performance Assessment Meetings.

The COR shall meet with the contractor quarterly to assess performance and shall provide a written assessment.

File details come from the government source that posted it. Updated .