Statement of Work -DO 3 - Platform Capability Production.pdf

PDF 422 KB Posted

Attached to
Cyber TRIDENT Federal contract opportunity
Solicitation number
W900KK-20-R-0001
Issued by
Department of the Army Materiel Command Contracting Command Orlando Contracting Center

About this file

This statement of work describes requirements for the Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT) Delivery Order 3 contract. The contract will provide support for the Persistent Cyber Training Environment Platform Capability Production, including technology insertion, addressing technology obsolescence and evolution issues, and developing capabilities from the backlog. Requirements include program management, development operations following an agile process, cybersecurity engineering, logistics support, and testing. The contractor must develop, integrate, test, deploy and sustain capabilities for the Persistent Cyber Training Environment platform in compliance with the statement of work while using an agile development approach and DevOps processes.

View the file

Other files for this federal contract opportunity

Other files attached to Cyber TRIDENT, newest first.
File Type Posted
DO 0003-Order-SOW-CDRLs.pdf PDF
TO 0001-Order-SOW-CDRLs.pdf PDF
TO 0002-Order-SOW-CDRLs.pdf PDF
Slides - Industry Day - Pre-Solicitation Briefing Slides Contracts - 4-30-20.pptx PPTX presentation
Attach 18 - Past Perf Questionnaire - Cyber TRIDENT - 4-15-20 Updated.docx DOCX document
Attach 1 - SOW - Base CYBER TRIDENT Base SOW - 29 Apr 2020 Updated.pdf PDF
Attach 4 - RCS Price List - 4-24-20 Updated.docx DOCX document
CDRL_Base_SOW.pdf PDF
RFP - W900KK-20-R-0001 DRAFT 30 Apr 2020 Updated.pdf PDF
SOW - DO 3 CYBER TRIDENT DO 3 SOW - 29 Apr 2020 Updated.pdf PDF
SOW - TO 1 CYBER TRIDENT TO 1 SOW - 29 Apr 2020 Updated.pdf PDF
Attach 17 - Proposal Cost Price Workbook 4-30-20 Updated.xls XLS spreadsheet
SOW - TO 2 CYBER TRIDENT TO 2 SOW - 29 Apr 2020 Updated.pdf PDF
Consolidated Industry Questions 1-200 4-30-2020 Posted (2).pdf PDF
Consolidated Industry Questions 1-200 4-30-2020 Posted.pdf PDF
Consolidated Industry Questions-Answer 1-74.pdf PDF
Q_A from Draft RFP.pdf PDF
Q-As -Cyber TRIDENT W900KK-20-R-0001 27 Mar 2020.pdf PDF
Distribution Agreement - Cyber TRIDENT Solicitation -Final 13 Mar 2020.pdf PDF
List of Attachments - 13 Mar 2020.pdf PDF
Attach 19 - Q-A Spreadsheet-12 Mar 2020.xlsx XLSX spreadsheet
Instructions for Obtaining Distribution D Document - 13 Mar 2020.pdf PDF
Statement of Work - DO 1 - Infrastructure and Maintenance.pdf PDF
Attach 14 - PCTE DD254.pdf PDF
Instructions to Obtain Distribution D Documents.docx DOCX document
Attach 16 - SF1408 - Pre-Award Suvey of Prospective Contractor Acctg System.pdf PDF
Attach 2 -Contract Labor Rates.docx DOCX document
Attach 15 - Pre-Award Survey of Prospective Contractor Acctg System Checklist.pdf PDF
RFP - W900KK-20-R-0001 DRAFT 10 Mar 2020.pdf PDF
Statement of Work - DO 2 - Integraton Factory.pdf PDF
Attach 5 Small Business Participation Proposal Form.DOCX DOCX document
Attach 1 - Statement of Work - Basic Contract - Cyber TRIDENT.pdf PDF
00 Solicitation Attachment List.pdf PDF
Attach 18 - Past Perf Questionaire - Cyber TRIDENT.docx DOCX document
Show all 34

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

SOW-2020-011-03

STATEMENT OF WORK

for the

Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT)

Delivery Order 3 – Persistent Cyber Training Environment (PCTE) Platform Capability Production

U.S. Army Program Executive Office for Simulation, Training, and Instrumentation (PEO STRI)

12211 Science Drive Orlando, FL 32826-3276

Revision Number Date Log of Changes Made and Description of

Reason Changes Approved By

Table of Contents

1. SCOPE

1.1 Introduction

2. APPLICABLE DOCUMENTS

3. REQUIREMENTS

3.1 Program Management

3.1.1 Monthly Report

3.1.2 Associate Contractor Agreements (ACAs)

3.1.3 Schedule

3.1.3.1 Earned Value Management System (EVMS)

3.1.3.2 Integrated Baseline Reviews (IBR)

3.1.4 Risk Management

3.1.5 Program Management Reviews (PMRs)

3.1.6 Facilities

3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions

(CHESS) Program

3.2 Development Operations (DEVOPS) Process

3.2.1 Capability Development, Integration, Delivery and Sustainment

3.2.2 Integration Factory

3.2.3 Agile Ceremonies

3.2.4 Continuous Integration (CI)/Continuous Delivery (CD) Pipeline

3.2.5 Agile System Engineering

3.2.6 Requirements

3.2.7 Architecture

3.2.8 Design

3.2.9 Integration

3.2.10 Test

3.2.11 Configuration Management (CM)

3.2.12 Release Management

3.2.13 Metrics

3.3 Cybersecurity

3.3.1 Security Engineering

3.3.2 Army Training and Certification Tracking System (ATCTS) Training

3.3.3 OPSEC Clauses/COMSEC/Declassification

3.3.3.1 Requirements for OPSEC Training

3.3.3.2 Anti-Terrorist Training (AT Level 1)

3.3.3.3 Active Shooter Training

3.3.3.4 Access to Government Information Systems

3.3.3.5 Professional Training and Certification

3.3.3.6 Personal Identifiable Information (PII)

3.3.4 Security and Access Controls

3.3.4.1 General Security

3.3.4.2 Security Clearances

3.3.4.3 Access and General Protection/Security Policy and Procedures

3.3.4.4 Handling or Access to Classified Information

3.3.4.5 Disclosure of Information

3.3.4.6 Effective Use of Controls

3.3.4.7 System Security Plan (SSP)

3.4 Logistics

3.4.1 Licensing and Warranty Management

3.4.2 Data Rights and Commercial Software Agreements

3.4.2.1 Commercial Software Agreements:

3.5 Test

3.5.1 CI/CD Testing

3.5.2 Defect Management and Resolution

4. ADDITIONAL CONTRACTOR REQUIREMENTS

4.1 Interaction and/or Disclosure with Foreign Country/Foreign National

Personnel APPENDIX A: Epics

STATEMENT OF WORK

SOW-2020-011-03

for the Persistent Cyber Training Environment (PCTE) -

Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber

TRIDENT)

Delivery Order Three (3)

1. SCOPE

This Statement of Work (SOW) defines the scope of the Project Manager Cyber Test and Training (PM CT2) Product Manager Cyber Resiliency and Training (PdM CRT) Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT) Delivery Order Three (3). The Cyber TRIDENT Indefinite Delivery/Indefinite Quantity (IDIQ) is utilized by Department of Defense (DoD) organizations and other non-DoD agencies that have related cyber training needs. The Cyber TRIDENT IDIQ provides the management, integration, maintenance, and evolution for the PCTE platform, and provides total system/subsystem acquisition life cycle support for the PCTE system baseline.

This Delivery Order Three (3) SOW defines the detailed requirements that PdM CRT requires to have performed under the Cyber TRIDENT IDIQ contract in support of the PCTE Platform Capability Production. PM CT2 defines the PCTE Platform Capability Production under Cyber TRIDENT Delivery Order Three (3) to include:

• Technology Insertion

• Technology Obsolescence and Evolution

• Backlog Capability Development:

1.1 Introduction

Delivery Order Three (3) will provide the necessary contractor support for the Platform Capability Production of the PCTE capabilities. This covers any technology insertion, obsolescence and evolution for the PCTE capabilities, as well as, addressing the backlog of desired capability development as defined in Appendix A of the SOW.

2. APPLICABLE DOCUMENTS

The applicable documents listed in the Base SOW are applicable to Delivery Order 3. Reference Section 2 of the Base SOW for full list.

3. REQUIREMENTS

The contractor shall provide the Platform Capability Production for the PCTE capabilities. The contractor shall design, deliver, and test platform capabilities to be integrated by Delivery Order

2. This will require activities that include technology insertion, technology obsolescence and evolution, and backlog capability development to ensure compliance with Delivery Order (DO) requirements and timely delivery of required products. The contractor shall provide engineering, materials, equipment, and testing for the PCTE Delivery Order Three (3) as described in this

SOW.

3.1 Program Management

The contractor shall provide the overall management and administrative effort necessary to ensure that the requirements of this Delivery Order Three (3) are accomplished. The contractor shall track DO progress, deliverables and financials utilizing metrics specified by the Government. The contractor shall participate, contribute, and execute as an attendee in the Delivery Order 2 hosted agile ceremonies, design reviews, product demonstrations, Integrated Product Team (IPT) meetings, partnering, transition meetings, conferences, installations, post installation assessments, and life cycle planning of current and future systems/software releases.

3.1.1 Monthly Report

The contractor shall submit a Contractors Progress, Status and Management Report that provides information to include but not limited to schedules, accomplishments, metrics, risks, issues, problems, and deficiencies related to this DO’s activities. The monthly report shall include, but not be limited to, status on the below requirements:

• Financial Data

• Agile Event Participation

• Agile Reporting and Metrics

• User Feedback/Prioritization

• Release Planning

• Continuous Integration/Continuous Development Pipeline

• Configuration Management

• Testing Metrics

• Status of Risk Management Issues and Resolutions

CDRL Number CDRL Name CDRL A301 Contractors Progress, Status and Management Report, DI-MGMT-80227

3.1.2 Associate Contractor Agreements (ACAs)

The contractor shall implement ACAs with other PCTE and third-party contractors as required for exchanging data, accessing and using third party software and equipment, receiving technical support, working interface and integration issues, and DoD Cyber user event planning and execution. The contractor shall ensure that ACAs are maintained to achieve development of the platform and maintain PCTE interoperability and event planning and execution, as applicable.

ACAs shall provide for and permit the complete and unbiased exchange of technical information and data relating to PCTE integration, development and deployment. Agreements shall be structured so that all Cyber TRIDENT and PCTE contractors are obligated to protect proprietary data and classified information from all unauthorized use or disclosure. ACAs shall be submitted to the Government for review prior to execution.

3.1.3 Schedule

The contractor shall plan, execute and deliver contributions within the Government agile scrum processes implemented within Delivery Order 2. The contractor shall align the schedule to trace to the Agile ceremonies and Industry best practices such as sprint duration, release planning, and other appropriate Agile planning processes. The contractor shall deliver in accordance with the government led monthly sprint periods resulting in incremental capability improvement/incorporation leading to six (6)-month formal releases.

3.1.3.1 Earned Value Management System (EVMS)

The contractor shall integrate cost, schedule, and performance management information. The contractor shall develop, implement, maintain, and use an EVM system that complies with Industry Guidelines ANSI/EIA-748 and meets contractual requirements. The contractor shall document the integrated cost and schedule status of work progress on the contract and relate technical performance with cost and schedule accomplishment using procedures for planning work, controlling costs, and measuring performance based on ANSI/EIA-748. Contractor shall incorporate and integrate performance information reported by subcontractors into Contractor’s management system. Contractor shall be responsible for reviewing and assuring the validity of all subcontractor reporting. (DI-MGMT-81861)

CDRL Number CDRL Name CDRL A303 Integrated Program Management Report (IPMR), DI-MGMT-81861

3.1.3.2 Integrated Baseline Reviews (IBR)

The contractor shall engage jointly with the Government’s Program Manager in IBRs to evaluate the risks inherent in the contract’s planned performance measurement baseline. Initially, this shall occur as soon as feasible but not later than six (6) months after award, and subsequently following all major changes to the DO. Each IBR shall verify that the contractor is using a reliable performance measurement baseline, which includes the entire contract scope of work, is consistent with contract schedule requirements, and has adequate resources assigned. Each IBR shall also record any indications that effective EVM is not being used. IBRs shall also be conducted on subcontracts that meet or exceed the EVM application threshold. The prime contractor shall lead the subcontractor IBRs, with active participation by the Government.

3.1.4 Risk Management

The contractor shall promptly notify the Government of contract performance risks, issues, problems, and deficiencies. In accordance with the contractor’s risk management plan, implement risk detection and identification, assignment of risk categories, risk mitigation planning, mitigation plan implementation, corrective action, tracking of compliance, reporting of status and planning for risk abatement. The contractor shall promptly provide and execute corrective actions plans, in consultation with the Government. The contractor shall include in each Contractor Monthly Progress, Status and Management Report the status of all outstanding contract performance risks, issues, problems, and deficiencies, as well as corrective actions with respect thereto.

3.1.5 Program Management Reviews (PMRs)

The contractor shall host Program Delivery Order (DO) Review quarterly (per year) to inform the Government of program risks and issues. The contractor shall conduct Technical Interchange Meetings (TIMs) and In Progress Reviews (IPRs) as directed by the Government. The reviews shall provide a forum for IPT members to clarify the following areas of this DO that include but not limited to:

• Technology Insertion

• Technology Obsolescence and Evolution

• Backlog Capability Development

The meetings shall be conducted at the contractor’s Orlando facility unless otherwise agreed-to by the Government. PMR shall cover DO program risks and issues that can affect the entire Cyber TRIDENT portfolio, including parallel DOs-specific issues and risks as appropriate. The contractor shall post agendas and meeting minutes to established web portals or SharePoint sites.

CDRL Number CDRL Name CDRL A302 Report, Record of Meeting/Minutes, DI-ADMN-81505

3.1.6 Facilities

The PCTE program has implemented an Agile software development methodology requiring active and daily on-site Government presence to conduct the various Agile ceremonies including daily standup meetings, weekly Architectural meetings, monthly sprint planning meetings, and release planning workshops. As a result of this active and daily Government presence and to facilitate Government testing and collaboration, the facility shall be located no more than ten

(10) miles from PEO STRI at 12211 Science Dr, Orlando, FL 32826.

3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions (CHESS) Program The contractor shall procure hardware, software, and licensing to support the Delivery Order 3 Integration Factory activities. Delivery Order 1 shall track, inventory, and maintain detailed information on procurements made under Delivery Order 3. The contractor shall comply with the Army’s CHESS program. Under Program Executive Office Enterprise Information Systems (PEO EIS), CHESS is the mandatory source for commercial Information Technology (IT) purchases. CHESS contracts provide IT products and services that comply with U. S. Army Network Enterprise Technology Command (NETCOM), Army and DoD policy and standards.

Purchasers of commercial hardware and software must satisfy IT requirements by utilizing CHESS contracts and DoD Enterprise Software Initiative agreements first, regardless of dollar value. Any purchase made outside of CHESS contracts requires a waiver. A complete list of CHESS contracts and the on-line waiver process can be found at https://protect-us.mimecast.com/s/yDPLCR6K3OIrGJ7iqywOR?domain=chess.army.mil

3.2 Development Operations (DEVOPS) Process

3.2.1 Capability Development, Integration, Delivery and Sustainment To develop, integrate, test, deploy, and sustain capabilities for the PCTE Platform, the contractor shall adhere to the holistic Government led Dev Ops process and utilize the integration factory established in Delivery Order 2: Integration Factory.

3.2.2 Integration Factory

When participating in the DevOps process, the contractor shall use the integration factory which includes but is not limited to a collaborative meeting space, development environment, and tools.

The contractor shall leverage the collaborative meeting space to attend and participate in Agile ceremonies in a multi-vendor environment as directed by the Government. The contractor shall use the remotely accessible development environment to develop, integrate, test, deploy, and sustain capabilities for the PCTE platform. The contractor shall use the integration factory tooling to participate in Agile Ceremonies and Government ceremonies as well develop, integrate, test, deploy, and sustain capabilities for the PCTE platform. The contractor shall collaborate with the integration factory staff and PCTE vendors to manage PCTE hardware and software infrastructure as directed by the Government.

3.2.3 Agile Ceremonies

The contractor shall participate in Agile ceremonies to develop, refine, and prioritize requirements as well as plan and monitor the development, testing, integration, and deployment of capabilities for the PCTE platform. The contractor shall participate in Agile ceremonies with other PCTE vendors and provide the Government with regular visibility into the status of capability development. The contractor shall use the integration factory tooling to participate in Agile ceremonies. The contractor shall contribute requirements to the Product Backlog and refine them as directed by the Government Product Owner. The contractor shall ensure that the state of the assigned Backlog items aligns with actual development status.

3.2.4 Continuous Integration (CI)/Continuous Delivery (CD) Pipeline The contractor shall collaborate with the integration factory staff to develop Continuous Integration/Continuous Delivery (CI/CD) pipelines to automate the staged build, test, integration, release, and deployment of their capabilities as described in Delivery Order 2: Integration Factory. The contractor shall collaborate with integration factory staff to resolve issues that are discovered during the execution of their CI/CD pipelines as directed by the Government. The contractor shall collaborate with the integration factory staff to analyze production errors with their capability to mitigate those problems in the system design stage.

3.2.5 Agile System Engineering

The contractor shall apply Agile methodologies based on industry best practices throughout the PCTE effort, with all work planned in sprints, defined within a product backlog, with the goal of having a shippable product at the end of each sprint. The contractor's agile process shall achieve results through continuous capability enhancements, prompt response to emerging needs, demonstrated reliability, on reoccurring release cycles. The contractor shall participate and contribute in the Delivery Order 2 hosted agile ceremonies, including sprint planning, daily sprint standups, sprint retrospectives and sprint demonstrations. The contractor shall provide the requisite technical and programmatic support to complete the required tasks of the individual DOs associated with the PCTE engineering and management. These tasks shall encompass the efforts associated with the development, dissemination, engineering, management, and maintenance of the PCTE architecture, components, and documentation. These tasks shall also include the work efforts associated with the engineering, management, and tracking of PCTE fielded products, PCTE services and platform. The contractor shall identify an agile means of developing, integrating, testing and releasing the PCTE platform consisting of various contributions through an agile methodology facilitating CMF user feedback.

3.2.6 Requirements

The contractor shall execute and manage the development of PCTE software in accordance with the requirements in the contractor's software development process plan. The requirements form the basis for all efforts for the design, development, integration, production, testing and fielding of major and minor iterations of PCTE. The contractor shall deliver products, including ancillary support services, hardware, and software, that support the enterprise management. All analysis and results shall be documented in an integrated database and made available to the Government.

As part of this activity, the contractor shall work within the IPT to iterate the system and System-of-System (SoS) software requirements. The contractor shall manage and record the operational concept for the developed products, and assess the impact of the architectural design to the PCTE platform (identifying the components of the system, their interfaces, and a concept of execution among them) and the traceability between the system components and system requirements for standard and non-standard aids and devices necessary for the system to function and operate.

Based upon analysis of system requirements, system design, and other considerations, the contractor shall manage and record the software requirements to be met by each software item, the methods to be used to ensure that each requirement has been met, and the traceability between the software item requirements and system requirements. The contractor shall manage the evaluation of the Information Assurance (IA) requirements to assess any impacts on developed software and provide potential solutions. The contractor shall conduct architecture evaluations, including stakeholders external to the contractor's organization, for each software build.

3.2.7 Architecture

The contractor shall adhere to the PCTE governance processes and ceremonies to develop PCTE system requirements and architecture in accordance with the contractor’s Agile system engineering process established in Delivery Order 2: Integration Factory. When contributing to the PCTE architecture, the contractor shall consider the entire lifecycle of the system including but not limited to development, maintenance, and deployment. The architecture shall be designed for extensibility, scalability, maintainability, availability, usability and security using an approach that is based on open standards, products and patterns. The contractor shall contribute to the PCTE operational concept for the system, architectural design of the system (identifying the components of the system, their interfaces, and a concept of execution among them), and the traceability between the system components and system requirements.

The contractor shall research and evaluate the existing PCTE architecture documented in the PCTE PDK and amend it to integrate their capabilities. All analysis and results shall be documented using the integration factory tools and in the PCTE PDK as directed by Government team. The contractor is encouraged to suggest revisions to Government requirements where such revisions would result in cost or schedule reduction or performance improvements. The contractor shall evaluate the PCTE cybersecurity requirements to assess any impacts on developed capability and provide potential solutions, if applicable. In addition, the contractor shall determine if existing open source products are capable of meeting any operational capabilities, perform a detailed product reuse evaluation, and document the results of the analysis. The contractor shall conduct architecture evaluations, including stakeholders external to the contractor’s organization, for each iteration of PCTE. As part of this activity, the contractor shall participate in the PCTE Architecture Working Group (AWG) to iterate on the PCTE system architecture as well as conduct evaluations and reviews.

3.2.8 Design

The contractor shall research, investigate, evaluate, and design capabilities to integrate into the PCTE platform to meet system requirements throughout the entire lifecycle of the system. The contractor shall design the capabilities to be integrated into the PCTE platform to be highly cohesive, loosely coupled, and have severable components to have an open systems architecture capable of procuring at the component level. The capabilities shall be designed for extensibility, scalability, maintainability, availability, usability and security using an approach that is based on open standards, products and patterns. The PCTE platform includes the hardware and software infrastructure as well as the networks and other enabling infrastructure required for the CMF operators to access the system. The PCTE platform also includes the vendor software that allows the CMF to plan, prepare, execute, and assess cyber training events.

The contractor shall work within the PCTE AWG to iterate on designs as directed by the Government. The contractor shall review, evaluate, and recommend improvements to existing designs documented in the PCTE PDK as well as the collaborative wiki. The contractor shall review, evaluate, and recommend improvements to PCTE vendor designs as directed by the Government. Design includes not only design to requirements, but selection of existing products, including open source, to meet system requirements and iterating the requirements to allow use of existing products throughout the life of each delivery order. Products that perform IA functions are considered cybersecurity or cybersecurity-enabled IT products and shall be selected from the DOD Unified Capabilities Approved Product List and configured in accordance with DOD-approved security configuration guidelines. These include databases which must comply with the DISA database Security Technical Implementation Guide (STIG).

The contractor shall document the PCTE platform designs including but not limited to physical designs and logical designs as well as components of the system, their interfaces, and a concept of execution among them. The contractor shall document designs using the PCTE integration factory tools and incorporate them with the PCTE PDK as directed by the Government team.

3.2.9 Integration

The Contractor shall support the acceptance, modification, integration, and test of future capabilities in order to deliver a comprehensive PCTE system. The Government and contractor/subcontractor team members shall be able to exchange information and collaborate in a distributed environment. The integration environment, shall be based on processes and standards construct that supports data and requirements management, stores collaborative artifacts, software, tools, Technical Data Package (TDP), and architecture products. The Contractor's integration and testing processes shall ensure that new provided capabilities, handover packages, change sets, and bug fixes are fully implemented and satisfy their requirements and respective Use Cases without impacting existing capability prior to integration into the main PCTE baseline.

3.2.10 Test

The contractor shall support the continuum of PCTE platform testing across the agile development lifecycle in accordance with Section 3.5.

3.2.11 Configuration Management (CM)

The contractor shall initially sustain and mature the current CM methodology to establish and maintain the integrity of the components, services, products, and assets throughout the PCTE life cycle. CM shall be implemented throughout the entire period of execution for all components, services, products, and assets of the PCTE system. CM shall be a proactive activity within the PCTE system. CM shall identify, track, and document configuration items, control the configuration items and changes to them, and record and report status, and change activities to these configuration items. CM shall function as a multidimensional version of a typical CM process (multi-phased, multi-program, multi-tiered, multi-instantiated, and multi-baseline), binding the PCTE products and activities. CM shall support parallel development, distribution, and build releases. CM shall address use by all developers, products, and vendors.

The contractor’s CM efforts shall:

a) Identify the configuration items, components, and related work products that will be placed under configuration management

b) Establish and maintain a configuration management and change management system for controlling work products

c) Create or release baselines for internal use and for delivery to the customer

d) Track change requests for the configuration items

e) Control changes in the content of configuration items

f) Establish and maintain records describing configuration items, and

g) Perform configuration audits to maintain the integrity of the configuration baselines.

The PCTE CM shall synchronize with all of CM activities for products and product support within the PCTE system and provide an overarching CM method for all assets, artifacts, and processes. The contractor shall document the software handover process for all other PCTE vendors and shall utilize the CM infrastructure to manage these products. The contractor shall ensure a complete audit trail of decisions and design modifications made to systems, hardware, and/or software being developed, managed, or maintained are tracked and reported

3.2.12 Release Management

The contractor shall execute the release management process for the PCTE platform through the CI/CD Agile process. The contractor shall provide examples, instructions, and tools for developers to integrate their components into the PCTE system. The contractor shall work with each vendor to execute the release management through the development, test, and integration process by planning, scheduling, and controlling the entire software build through each six (6) month iteration. The contractor shall update the production environment using an automation of application installation or a combination of manual installations and automation scripts to deploy applications to the production area of PCTE for all components defined in the reference architecture. The contractor shall manage the PCTE capabilities through each delivery monitoring user management, user access controls, communication services, support services, and monitoring services. The contractor shall ensure each iteration of software is tested prior to the deployment onto the production plane of the RCS.

3.2.13 Metrics

The contractor shall execute the capture and reporting of the Operational Effectiveness and Suitability, Usability, Agile Development, technical performance (e.g., performance scaling, pub-sub, serialization, and API conformance), programmatic, and compliance (e.g., test coverage, and compliance of common component dependency) metrics to validate and verify the capabilities and features delivered by each vendor. The contractor shall document these findings and provide the metrics as feedback to the Government to structure and effectively inform the development to result in an operationally effective platform needed to meet the desired end state.

The contractor shall execute the capture and reporting of agile metrics discussed below to focus on the delivery of the PCTE software. The contractor shall execute the capture and reporting of each of these but not limited to the following agile metrics; Sprint Burndown, Epic and Release Burndown, Velocity and Defect Work-off, to ensure the development process runs smoothly and a cumulative flow is available to the Government team and vendors as necessary to ensure the flow of work across the teams and vendors is consistent.

3.3 Cybersecurity

The contractor shall ensure cybersecurity is implemented throughout all capabilities and products developed under Delivery Order 3 to ensure no negative impacts to the PCTE accreditation. The contractor shall implement cybersecurity in products and capabilities at a number of classification levels and environments to include Closed, Restricted Networks (CRNs), Open Secret Internet Protocol (IP) Router (SIPRNET), Open Non-Classified IP Router (NIPRNET), and Top Secret/Sensitive Compartmented Information (SCI).

1. The contractor shall leverage the National Information Assurance Partnership (NIAP) and the Common Criteria Evaluation and Validation Scheme (CCEVS) to ensure Defense Information Systems Agency (DISA) approved software and hardware are utilized within the PCTE construct and PCTE supported components, services, and assets.

2. The contractor shall also ensure that the common components and services developed and maintained within PCTE are implemented in accordance with DISA STIG compliance.

The contractor shall complete the DISA STIGs implementation for the IT technology developed and provide completed STIG checklists to document compliance.

3. The contractor shall evaluate the security of the products created on this delivery order, both physical and logical, identifying exposures and providing protective options for reducing security risk. The contractor shall deliver upgrades to the system in a configuration that will pass a certification and will not negatively impact the existing accreditation.

4. The contractor shall implement protective measures to provide Information Security.

When Classified or Controlled information is introduced into the PCTE, the contractor shall adhere to the provisions within AR 380-5 regarding the classification, transmission, transportation, and safeguarding of this information. Cryptography shall be Federal Information Processing Standards (FIPS) 140-2 compliant. There shall be a mechanism established to ensure encrypted data can be recovered in the event the primary encryption system fails.

5. The contractor shall integrate protective mechanisms into the system and applications to provide identification and authentication, access control, accountability, availability, confidentiality, privacy, data integrity, and non-repudiation.

6. The contractor shall test and certify that application software is designed to function in a properly secured operating system environment and is free of elements that might be detrimental to the secure operation of the resource operating system, as described in National Institute of Standards and Technology Special Publication (NIST SP) 800-37.

7. The contractor shall use Government approved assessment tools to perform cyber security testing to document, verify, and validate each applicable operating system security configuration.

8. The contractor shall document the unincorporated security controls defined in the applicable STIG and unincorporated IA and Vulnerability Alerts (IAVA’s) in the Plan of Action and Milestones (POA&M) document.

3.3.1 Security Engineering

The contractor shall comply with the Agile ceremonies, DevOps process, and Security Engineering process created under Delivery Order 2 that emphasizes the collaboration of PCTE Vendors, Operations Team as well as Cyber Security Teams. The DevOps process shall emphasize cyber security teams collaborating with all teams to ensure the continued secure operations as products and capabilities are developed. When engineering security solutions for the PCTE platform, the contractor shall consider the Authority to Operate (ATO) that is being maintained under Delivery Order 2. When engineering security solutions, the contractor shall consider the existing security solutions described in the PCTE PDK for efficiency and reuse potential.

The contractor shall implement and integrate a holistic approach to Information Security (IS) and data security that protects against unauthorized (accidental or intentional) disclosure, modification, or destruction.

1. The IS security shall consider the following:

a. All hardware and software functions, characteristics, and features

b. Operational procedures

c. Accountability procedures

d. Access controls, remote computers, and terminal facilities

e. Management constraints

2. The contractor shall provide an adequate level of protection for the IS and data contained in the IS. An adequate system ensures a security approach commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.

3. The IS security and Cybersecurity approach shall include controls that are part of the day-to-day operations of the system, and are compliant with AR 25-2, DoDI 8500.01, DoDI 8510.01, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A and DoDI 8582.01.

The contractor shall collaborate with PCTE Vendors and leverage the integration factory tooling to comply with the established cyber security stages in the CI/CD pipelines for all capabilities and products created to automate the identification of vulnerabilities. The contractor shall perform manual vulnerability analysis on the system when automated solutions do not exist.

When possible, the contractor shall automate the implementation of security controls.

3.3.2 Army Training and Certification Tracking System (ATCTS) Training

The Contractor shall require that lead and support personnel performing Cybersecurity job functions possess the Information Assurance Management (IAM) or Information Assurance Technical (IAT) certification relevant to their role within the execution of this contract and IAW DoDD 8140.01, DoD 8570.01-M, AR 25-2 (4-3 Information Assurance Training), and Army BBP 05-PR-M-002. IA engineers, analysts, and technicians shall complete the required “IA Awareness Training.” Method of training for “IA Awareness training” is https://cs.signal.army.mil/default.asp “DoD Cyber Awareness Mandatory IA Training,” The

Contractor’s IA Team shall complete the required “Information Assurance Fundamentals Training.”

1. This shall include the methods, skills, use, and mechanisms to maintain the level of security of the IS.

2. The training shall be geared toward the audience and their roles and responsibilities with respect to the system’s operation and maintenance (i.e., system administrator, network administrator, hardware maintenance, etc.).

3. The contractor shall utilize DOD 8570.01-M as a guide in the development of the IA

Training content.

3.3.3 OPSEC Clauses/COMSEC/Declassification

The contractor shall ensure this Delivery Order is in compliance with the base contract existing OPSEC Standing Operating Procedure/plan within ninety (90) calendar days of DO award making any necessary updates, to be reviewed and approved by the responsible Government OPSEC officer. The plan’s updates shall include a process to identify critical information, where it is located, who is responsible for it, how to protect it, and why it needs to be protected. The contractor shall implement OPSEC measures as ordered by the Government. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.

3.3.3.1 Requirements for OPSEC Training

Per AR 530-1, Operations Security, new contractor employees must complete Level I OPSEC training within thirty (30) calendar days of their reporting for duty. The contractor shall ensure all applicable employees have completed OPSEC initial training, annual refresher training, and shall certify their work force has completed the training through the submission of completion certificates(s) to the COR, or the Contracting Officer when a COR is not assigned, within thirty

(30) days of arrival on the installation. OSPEC training can be accomplished at the Defense Security Services website at: https://securityawareness.usalearning.gov/opsec/

3.3.3.2 Anti-Terrorist Training (AT Level 1)

All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete AT Level I awareness training within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the Contracting Officer within 30 calendar days after completion of training by all contractor employees and subcontractor personnel. AT Level I awareness training is available at the following website: https://atlevel1.dtic.mil/at or other Service specific websites.

The contractor shall ensure all US based Contractor employees and associated subcontractor employees to make available and to receive Government provided area of responsibility (AOR) specific AT awareness training as directed by applicable DoD, Service policy and regulations.

Specific AOR training content is directed by the Combatant Commander with the unit Anti- Terrorism Officer (ATO) being the local point of contact.

3.3.3.3 Active Shooter Training

All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete active shooter training as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel.

3.3.3.4 Access to Government Information Systems

All contractor employees with access to a Government Information System must be registered in the applicable Service training and certification system at commencement of DO performance and must successfully complete DoD Information Assurance Awareness training prior to being granted access to information systems (IS) and then annually thereafter.

3.3.3.5 Professional Training and Certification

The contractor shall be responsible to ensure that employees, to include subcontractor employees, at all times maintain the required professional training and certifications required for their job description(s) and role(s).

Per DoD 8570.01-M, DoDD 8140.01, Defense Federal Acquisition Regulation Supplement (DFARS) 252.239.7001 and applicable Service regulations, the contractor employees supporting Cybersecurity/IT functions shall be appropriately certified upon DO award. The baseline certifications as stipulated in DoD 8570.01-M for specific positions shall be completed upon DO award.

3.3.3.6 Personal Identifiable Information (PII)

All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete training in the handling and protection of PII as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel. PII training is available at https://securityawareness.usalearning.gov/piiv2

3.3.4 Security and Access Controls

3.3.4.1 General Security

The contractor shall ensure that personnel at all times comply with applicable Government security policies and procedures. In addition, to ensure expedited reporting, the contractor shall ensure that required security reporting is implemented in a manner that does not require contractor employees to notify contractor management chains of a reportable security situation prior to them reporting it to the appropriate Government channels.

3.3.4.2 Security Clearances

The contractor shall issue security clearances only to those contractors who will have access to classified information up to the TS/SCI level for PCTE. Some positions/duties may not require a clearance, but all positions/duties will require investigation for duties and access to U.S.

Government systems and technical information. The Contractor shall ensure that employees performing under this contract have the appropriate clearance not to exceed the requirements supported.

3.3.4.3 Access and General Protection/Security Policy and Procedures Contractor and all associated subcontractor employees shall comply with applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by Government representative). The contractor shall also provide all information required for background checks to meet installation access requirements to be accomplished by installation authorities. Contractor workforce shall comply with all personal identity verification requirements as directed by applicable DoD, Service and local policy. In addition to the changes otherwise authorized by the changes clause of this DO, should the Force Protection Condition (FPCON) at any individual facility or installation change, the Government may require changes in contractor security matters or processes.

The Common Access Card (CAC) shall be the principal identity credential for supporting access to DoD installations, facilities, buildings, controlled spaces, and access to U.S. Government information systems. A National Agency Check with Inquiries (NACI) or equivalent national security clearance [e.g. National Agency Check with Local Agency Checks including Credit Check (NACLC)] will be required for permanent issuance of the credential. The Government may issue the credential upon favorable return of the Federal Bureau of Investigations (FBI) fingerprint check, pending final favorable completion of the NACI or equivalent. There shall be no additional NACI or equivalent submission for an individual holding a valid national security clearance.

The contractor shall account for all forms of U.S Government-provided identification credentials issued to contractor employees in connection with the performance of this DO. The contractor shall return such identification credentials to the issuing agency at the earliest of any of the circumstances listed below, unless otherwise determined by the U.S. Government. The Contracting Officer may delay final payment under an individual DO if the Contractor fails to comply with these requirements. The contractor and all associated subcontractors shall return all identification credentials when:

a. No longer needed for DO performance.

b. Completion of contractor employee’s employment.

c. DO completion or termination.

For all contractors and associated subcontractor employees who do not require a CAC, they must comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB), applicable Service, installation, facility and area Commander installation/facility access and local security policies and procedures (provided by Government representative), or, at Outside of Continental United States (OCONUS) locations, in accordance with status of forces agreements (SOFA) and other theater regulations.

3.3.4.4 Handling or Access to Classified Information

The contractor shall comply with FAR 52.204-2, Security Requirements. This clause involves access to information classified "Confidential," "Secret," or "Top Secret". The contractor shall comply with (1) The Security Agreement (DD Form 441), including the National Industrial Security Program Operating Manual (DOD 5220.22-M), (2) any revisions to DOD 5220.22-M, and (3) Contract Security Classification Specification (DD Form 254).

3.3.4.5 Disclosure of Information

The contractor shall comply with the protection standards and guidance described in DoD Manual 5200.1 to prevent foreign intelligence collection and/or the unauthorized disclosure of information.

3.3.4.6 Effective Use of Controls

The contractor shall screen all electronic deliverables or electronically provided information for malicious code using DoD approved anti-virus software prior to delivery to the Government. The contractor shall utilize appropriate controls (firewalls, password protection, encryption, digital certificates, etc.) at all times to protect DO related information processed, stored or transmitted on the contractor’s and Government’s computers/servers to ensure confidentiality, integrity, availability, authentication and non-repudiation. The contractor shall ensure provisions are in place that will safeguard all aspects of information operations pertaining to this DO in compliance with all applicable SOW references.

3.3.4.7 System Security Plan (SSP)

The contractor shall safeguard covered defense information that resides on their internal unclassified information systems and networks to satisfy the security requirements of DFARS 252.204-7012, and in accordance with NIST SP 800-171 (Protecting Unclassified Information in Nonfederal Information Systems and Organizations). The contractor shall update the approved system security plan (SSP) with any new information from this DO that addresses implementation of the NIST SP 800-171 security requirements to include any associated plans of action for each of the contractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s), and the subcontractor’s tier one level subcontractor(s), vendor(s), and/or supplier(s), who process, store, or transmit covered defense information associated with the execution and performance of this DO.

3.4 Logistics

The contractor shall plan and support activities for logistics, fielding and maintenance of the infrastructure for the PCTE products created under this Delivery Order.

3.4.1 Licensing and Warranty Management

The contractor shall only install software updates for licensed software approved by the program office. The contractor shall support maintenance packages with the licensed software. The contractor shall not violate any rules or laws with software license agreements. The Contractor shall stay in compliance with all software license agreements. The contractor shall coordinate with Delivery Order 1 to provide software license agreement management to include inventory, tracking, accounting for and monitoring all types of software license agreements. The contractor shall be responsible for installing all updates and installation for all systems that require necessary upgrades. The contractor shall provide installation, implementation and training for each software license. The contractor shall provide all cost and fees associated with software and licensing agreement updates to include forecasting future cost and fees. The contractor shall provide detailed lists of all software and licensing agreements, schedule updates and cost of software to program office.

3.4.2 Data Rights and Commercial Software Agreements

The contractor shall provide data rights for technical data and documentation applicable to both software and hardware, so that the Government can maintain and modify the system(s) using Government personnel and third-party contractors. This includes, but is not limited to, software rights, data, source codes, drawings, and warranties. The contractor shall make a willful attempt to analyze feasible non-proprietary solutions and incorporate them when applicable to the effort.

To the maximum extent possible, CRT event-specific capabilities and content shall be developed with the minimum use of proprietary software and artifacts as they develop customized software-based capabilities and content for event environments. The contractor shall disclose to the Government where the contractor has implemented or used proprietary or otherwise protected software and/or event content in an event. User provided software, data, and content is excluded from this disclosure.

3.4.2.1 Commercial Software Agreements:

The contractor shall provide licenses and/or agreements for commercial software tools. The contractor shall acknowledge that the FAR clause at 12.212(a) requires the Government to acquire commercial computer software or commercial computer software documentation under licenses customarily provided to the public to the extent such licenses are consistent with Federal law and otherwise satisfy the Government's needs.

3.5 Test

3.5.1 CI/CD Testing

The contractor shall test CI/CD components and products, tailored to the PCTE system requirement. The CI/CD process and tools shall enable the rapid integration, test and deployment of PCTE vendor "black box" capabilities to support iterative analysis by CMF operators. The CI/CD testing shall include a baseline maturation chain which iteratively moves PCTE system builds through defined stages leading from individual component development to deployed.

Specific controls and compliance gates shall be established to promote a build from one state to the next and strict traceability shall be applied to ensure the heritage of all builds are available.

The contractor shall test and verify a virtual infrastructure…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .