Attachment 1-Statement Of Work.pdf
PDF 399 KB Posted
- Attached to
- CD/DVD/Blu-Ray Federal contract opportunity
- Solicitation number
- SP7000-24-Q-1062
- Issued by
- Defense Logistics Agency
About this file
This document is a Statement of Work (SOW) for a Request for Quote (RFQ) to establish a firm-fixed price contract for a CD/DVD/Blu-Ray duplicator with label maker and 5-year warranty. The SOW outlines the minimum technical specifications for the required equipment, including a Quadcore I5-7500 processor, 16GB DDR4 memory, and support for 128GB Blu-Ray discs. The contractor will be responsible for delivery, installation, and providing on-site maintenance and repair services for 5 years. The SOW also includes requirements for training, IT configuration, and security compliance, as well as supply chain risk management measures. The RFQ is being issued by the Defense Logistics Agency (DLA) for DLA Document Services in Mechanicsburg, PA, with a solicitation number of SP7000-24-Q-1062.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| SP7000-24-Q-1062.pdf | ||
| Attachment 2 - Full Text Provisions (Vendor COMPLETION Required) temp (1).docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 1 of 7 CD/DVD/Blu-Ray Duplicator
1.0 INTRODUCTION
Defense Logistics Agency (DLA) Document Automation seeks to purchase the following equipment and associated services:
The purpose of this acquisition is to acquire a CD/DVD/Blu-Ray duplicator w/disk label maker and maintenance options for the Naval Supply Systems Command (NAVSUP) Weapon Systems Support (WSS) Code N009 Naval Nuclear Propulsion Program (NNPP) Industrial Print Center. The equipment will be used to create/duplicate CD/DVD/Blu-Ray information disks. The requested equipment and supplies represent the minimum requirements of the government.
2.0 GENERAL INFORMATION
DLA Document Services requires the equipment and associated services at the Mechanicsburg location, the purchase is for:
One (1) unit of a CD/DVD/Blu-Ray Duplicator.
The maintenance is for a 5-year warranty.
Equipment is to be delivered to DLA Document Services, Mechanicsburg, 5450 Carlisle Pike, Bldg. 6, Mechanicsburg PA 17050.
3.0 CD/DVD/Blu-Ray Duplicator Requirements:
3.1 The equipment must be Trade Agreements Act (TAA) compliant.
3.2 Minimum Specifications:
Processor: Intel Quadcore I5-7500 or Equivalent Memory: Minimum 16 GB DDR4 Keyboard: Yes Hard Drive: Minimum 256 GB SSD (OS) 1 x 4TB HDD (CACHE) Disc Capacity Minimum 600 Disc Input Capacity & 600 Disc Output Capacity CD/DVD/Blu-Ray Minimum 7 CD/DVD/Blu-Ray Recorder Drives (Dual, Triple, &
Quad Layer Support Required). Must be able to burn 25GB, 50GB, 100GB, and 128GB Blu-Ray discs.
Supported File Types Minimum support for barcode files (Multiple File Formats Ex.
PDF, JPG, and Vendor Supported Files )
NIC: Minimum 1 GB Ethernet Port Operating System: Windows 11 Professional 64-bit to be preloaded by Vendor Mouse: Yes Service: Next Business Day Onsite Service for 5 years CD Printer Color Printer capable of functioning with CD/DVD/BLU-RAY duplicator TPM Required TPM support for encryption.
Power USA power requirements (120V, 15amp, 60Hz)
SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 2 of 7
4.0 MAINTENANCE AND REPAIRS
4.1 Maintenance and repairs refer to next business day, onsite service for 5-years; the duplicator must be registered with the Original Equipment Manufacturer (OEM) for the extended maintenance as offered by the specific OEM manufacturer. The vendor shall provide a telephonic answering service number and email address to report issues. Service calls not immediately answered, must be returned within two (2) hours. Service calls above operator level repair, must respond to the facility with technician or higher-level support personnel.
4.2 On-site repair service includes spare parts for verified hardware and software failures. Parts required for repairs are provided via overnight shipment. When operator(s) can make minor adjustments or repairs using remote service to resolve an error or malfunction, a technical support group can utilize phone support to relay instructions and repair the device. If remote repairs that do not alleviate the problem or the issue is above an operator’s technical skill level, an in-person service call is immediately generated with vendor response for maintenance. Facility access is limited to Monday thru Friday 0700-1600 hours, no weekends or federal holidays.
4.3 If the Contractor chooses to repair on-site, Contractor must ensure all service technicians are eligible for access to Department of Defense facilities in accordance with the authority in DoD manual
5200.08 Volume 3, which establishes DoD access control policy and the minimum DoD security standards for controlling entry to DoD installations and stand-alone facilities. Contractors must also check and follow installation access policies specific to each DoD installation. Technicians must be eligible for access at time of the award. In addition, in the case of devices cleared for CLASSIFIED material, the contractor’s repair technicians shall ensure they do not access the CD/DVD/Blu-Ray Duplicator without a Government employee escort present and observing during the support/repair services. To ensure an escort is present, the Contractor shall contact the Customer a minimum of 24 hours prior to the site visit to schedule the time of arrival.
5.0 DELIVERY AND INSTALLATION
5.1 The Contractor will be responsible for all installation processes of the CD/DVD/Blu-Ray Duplicator.
All costs associated with providing installation of the device, shall be included in the quoted price and will not be reimbursed separately.
5.2 The Contractor shall comply with all Federal, DoD and local rules and regulations to obtain
Government installation access in order to meet all response times identified within the SOW.
5.3 The Contractor shall be responsible for any and all fees associated with the application process and/or enrollment to access the installation.
5.4 Within five (5) business days after award, the vendor shall contact the delivery location POC and begin the planning/scheduling process to insure proper installation of the CD/DVD/Blu-Ray Duplicator.
5.5 Upon completion of installation the agency POC and contractor must sign-off stating that all equipment ordered is functioning properly and fully operational.
5.6 The offeror will be responsible for installation and any necessary configuration to ensure a complete solution for all above.
SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 3 of 7
6.0 TRAINING REQUIREMENTS
6.1 The vendor shall provide a hardcopy User Manual which is concise, written in English, user friendly and provides specific steps and processes in all operational aspects regarding the use of the device and the accompanying peripherals, and software.
6.2 Within five (5) business days after the complete installation of the CD/DVD/Blu-Ray, the contractor shall provide initial hands-on, in-person training regarding the device and its software. This training must be in the English language and accomplished by an individual with expert knowledge in all operational aspects of the device and software. All costs associated with providing this initial training (to include travel costs of the contractor-provided instructor) shall be included in the quoted price and will not be reimbursed separately.
6.3 The vendor shall provide video training materials on electronic media (CD/DVD/Blu-Ray) for ongoing/recurring training. The videos must be formatted for MS Windows 10 (or Windows 11 if required) compliant systems and provide a basic operations and operator-level maintenance overview of the equipment.
7.0 EQUIPMENT AND ACCESSORIES
7.1 During the period covered under this contract, should the Government and/or the contractor desire to substitute or upgrade equipment with technology improvements, all such actions shall be approved by the Contracting Officer prior to the contractor taking any action.
7.2 If a substitution is needed, the contractor must notify the Contracting Officer and a formal review process will be conducted. Substitutions will be provided at no cost to the government.
8.0 IT CONFIGURATION: (Note: This section pertains to vendor provided equipment constructed with internal software or app configuration(s) requiring network compatibility. It is anticipated that the equipment sets are not software supported or require network access to operate. If true, this section will not be a requirement for consideration in the technical review process.)
8.1 The provided equipment will be operated using a USB connection to a secure network that the vendor will not be able to access without prior scheduling and security approval. All updates must be scheduled and provided using non-password protected CD, DVD, or Blu-Ray media scanned by the US Navy security officer prior to upload.
8.2 All contractor-provided software (including Operating System drivers) shall be supported by the contractor, and the software’s original manufacturer at all times, during its use by the government. If it becomes apparent that either the contractor or original manufacturer will no longer support any contractor-provided software, the contractor shall provide and install other software (at no cost to the government), that is still supported by the contractor and the software’s original manufacturer. Any changes to the device must be in coordination with DLA Document Services POC William Hamilton.
8.3 Contractor solution requiring software must be capable of functioning in a common security environment, given that DLA Document Services is required to add additional software that is standardized within DLA Document Services, including but not limited to McAfee Epolicy Orchestrator (multiple modules including AntiVirus and Host Intrusion Prevention), Arcsight Logger, SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 4 of 7 Active Client Software and Axway Desktop Validator.
8.4 All devices/components requiring software shall meet DoD information security specifications when interfacing with classified materials to ensure no remnants of the classified data exists after the classified process has been completed. Guidelines can be found at https://iase.disa.mil.
8.5 All devices requiring software shall be configured in compliance with all applicable DoD Security
Technical Implementation Guides (STIG) (Ref: http://iase.disa.mil/stigs). Any remaining deficiencies that cannot be resolved shall be identified by POC William Hamilton prior to the Certification and Accreditation testing phase for evaluation of acceptance.
8.6 As part of the installation process, the contractor shall label all equipment requiring software, with the appropriate classification as defined by DLA Document Services who shall provide the appropriate instructions and labels.
8.7 DLA Document Services shall provide a configuration standard and settings document for each hardware model that the vendor shall utilize when installing hardware at a designated site. This configuration standard and settings document will be developed for each device in conjunction with the vendor post-award at DLA Document Services headquarters facilities in New Cumberland, Pennsylvania.
8.8 The Contractor shall comply with the Section 508 accessibility requirements. By submission of its offer, the Contractor affirms that its Electronic Information Technology (EIT) supplies and services are accessible as outlined in the law, the standard, and FAR Subpart 39.2. The Contractor shall submit their completed OEM Voluntary Product Accessible Template (VPAT®) with their quote.
9.0 IT CERTIFICATION & ACCREDITATION, INSTALLATION AND TECHNICAL
SUPPORT: (Note: This section pertains to equipment constructed with internal software or app configuration(s) requiring network compatibility. It is anticipated that the equipment sets are not software supported or require network access to operate. If true, this section will not be a requirement for consideration in the technical review process.)
9.1 NNR will have to go through the certification and accreditation process and submit the documentation up to NAVSEA for the final approval for use on the SECNET.
10.0 SUPPLY CHAIN RISK MANAGEMENT
10.1 As part of its quote, the Contractor shall provide written documentation demonstrating how the integrity and security of all equipment, components thereof, repair parts and consumables it will provide and/or use in performing this contract will meet the standards set forth in National Institute of Standards and Technology (NIST) Special Publication 800-161. This documentation shall clearly demonstrate how the Contractor is taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services DLA receives through this contract. Additionally, this documentation shall provide specific details of what—
10.1.1 Policies the Contractor has in place to prevent both (a) the use of counterfeit or altered equipment, components thereof, consumables and parts and (b) their introduction into the
SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 5 of 7 Contractor’s supply chain.
10.1.2 Security procedures the Contractor uses to track the chain of custody of equipment, components thereof, consumables and parts, to include while this material is in storage and in transit; and
10.1.3 Steps the Contractor takes to ensure the integrity and authenticity of equipment, components thereof, repair parts and consumables to prevent tampering so they will perform according to specifications without additional unwanted functionality.
10.2 The Contractor shall continuously meet the standards of NIST Special Publication 800-161 while taking effective measures to mitigate the risks of foreign intelligence services, terrorist groups, or others from inserting unwanted functionality into the supplies and/or services provided through this contract. Upon request, the Contractor shall provide written documentation meeting all NIST requirements.
11. SECURITY AND INSTALLATION ACCESS/INSTALLATION SECURITY REQUIREMENTS
11.1 Installation Access: Vendor is required to complete SECNAV 5512_1 for base access. Vendor shall work with N009’s POC and provide a list of service technicians who are authorized to perform the service requested three weeks prior to beginning the work. This list shall include full name, date of birth, place of birth, social security number and verification that the service technician is a U.S.
Citizen. Non-U.S. Citizens are not permitted access to NAVSUP WSS, Code N009 spaces. POC for this matter is Kurt Lipusz, N009 Management Analyst, Phone number (717) 605-6260, email kurt.j.lipusz.civ@us.navy.mil
11.2 Access Compliance
11.2.1. The Contractor shall be escorted by Government personnel for all issues related to maintenance. No contractor personnel will be allowed unescorted access to government facilities.
11.2.2. The Contractor shall comply with all rules and regulations to obtain Government installation access in order to meet all response times identified within the SOW.
11.2.3. The Contractor shall comply with Government base access requirements as set forth in the base/command regulations.
11.2.4. The Contractor shall be responsible for any and all fees associated with the application process and/or enrollment to access any installation or facility.
11.2.5. For devices cleared for CLASSIFIED material, the Contractor’s repair technicians shall have a DoD security clearance equal to or higher than the classification of the device and shall provide verification when requested.
12. NETWORK SECURITY
12.1. The Contractor shall provide devices that are Trade Agreement Act (TAA) compliant and can be configured to comply with the current Defense Information Systems Agency (DISA) Security
SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 6 of 7 Technical Implementation Guide (STIG) titled Multifunction Device and Network Printer STIG (latest version and release), available at: https://cyber.mil/.
12.2 All devices shall support Simple Network Management Protocol (SNMP) version 3 (v3). Versions 1 and 2 (SNMPv1/SNMPv2) shall be disabled.
12.3. Contractors shall monitor industry standard vulnerability sites (e.g. http://nvd.nist.gov/, https://www.us-cert.gov/ncas/alerts, http://oval.mitre.org/) and take appropriate actions if their equipment is subject to a known vulnerability. When vulnerabilities are identified by the Contractor, DLA, or its customers, the Contractor shall provide remediation for distribution to all installed equipment in accordance with USCYBERCOM TASKORD regulations unless a different time period is directed by USCYBERCOM via DLA. The TASKORD is For Official Use Only. The following is authorized to be quoted from the TASKORD for reference:
12.3.1. Assured Compliance Assessment Solution (ACAS) assigns severity scores of critical, high, medium and low to plug-in findings.
a. Critical findings reflect discovery of a common vulnerability and exposure (CVE) that poses significant risk to the confidentiality, integrity, and availability of DODIN Networks. Actions to mitigate or remediate critical vulnerabilities shall be initiated upon discover with the goal of mitigation/remediation within seven (7) calendar days.
b. Findings with a severity score of high shall be addressed in the same manner as vulnerabilities addressed via Information Assurance Vulnerability Alert (IAVA) directives and mitigated or remediated within twenty-one (21) calendar days of discovery.
c. Findings with severity scores of medium and low shall be addressed in accordance with local Approving Official (AO), Information System Security Manager (ISSM), or Information System Security Officer (ISSO) guidance until further notice.
d. In all instances, DoD components shall consider exposure to threat, mission impact, sensitivity of data, and current mitigating security controls when prioritizing implementation of corrective actions.
12.4. In the event remediation cannot be achieved within the mandated timeline, the Contractor shall provide a Plan of Action and Milestones and receive approval thereof by the Customer’s agency Authorizing Official or designee for risk acceptance.
12.5. All devices shall be International Organization for Standardization (ISO)/International
Electrotechnical Commission (IEC) 15408 (Common Criteria) certified IAW CNSSP-11 using the National Information Assurance Partnership (NIAP) approved criteria or equivalent.
12.5.1. A device shall be acceptable if it is included on either the NIAP CCEVS Product Compliant List (https://www.niap-ccevs.org/Product/) or Common Criteria Portal Certified Products list (http://www.commoncriteriaportal.org/products/).
12.5.2. All devices shall have current ISO/IEC 15408 certification and recertification, if applicable, before the Contractor can schedule lab time. Guidance for Common Criteria Maintenance and Re-evaluation is available at: https://www.niap-ccevs.org/documents_and_guidance/ccevs/scheme-pub- 6.pdf
12.6. All devices shall be capable of obtaining accreditation through the Risk Management Framework
(RMF) for DoD Information Technology (IT). As part of this, the Contractor agrees to provide all
SP7000-24-Q-1062 Attachment 1 – Statement Of Work Page 7 of 7 requested information and work in good faith with DLA so the DLA customers can expeditiously obtain RMF accreditation prior to device delivery and installation. The Contractor shall also provide devices for vulnerability and STIG testing to DLA or customer’s site. The Contractor further agrees that if the proposed device(s) does not obtain RMF accreditation, the contractor shall remove the device(s). Information regarding RMF is found in Risk Management Framework (RMF) for DoD Information Technology (IT) Instruction 8510.1 dated 12 March 2014:
http://www.dtic.mil/whs/directives/corres/pdf/851001_2014.pdf.
In order to maintain RMF and STIG compliance, devices are required to be delivered with the most up-to-date firmware.
File details come from the government source that posted it. Updated .