Statement of Work.pdf

PDF 811 KB Posted

Attached to
IT Support Services Federal contract opportunity
Solicitation number
15M30023QA3700002
Issued by
Department of Justice US Marshals Service

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR QUOTATION (RFQ) STATEMENT OF WORK (SOW)

JUSTICE PRISONER AND ALIEN TRANSPORTATION SYSTEM (JPATS)

JPATS MANAGEMENT INFORMATION SYSTEM (JMIS)

AND MOVEMENT PACKET (MPAC)

PART 1 – GENERAL INFORMATION

The Justice Prisoner and Alien Transportation System (JPATS) is a division of the U.S.

Marshals Service (USMS), which is a component of the Department of Justice (DOJ). JPATS has approximately 100 federal employees and 120 support contractors located in three sites.

JPATS coordinates and transports prisoners for the U.S. Marshals Service, Bureau of Prisons (BOP), and for state and local jurisdictions. JPATS’ mission is to provide effective scheduling and safe/reliable transportation of Federal, State, Local, and military prisoners providing the best value to our customers and the taxpayer.

The United States Marshals Service (USMS), Information Technology Division (ITD) staff is responsible for providing Information Technology (IT) support to meet the operational and administrative needs of the organization. ITD maintains a separately funded contract for core enterprise IT services and operations but relies on augmentation of services for special program technical delivery by divisions, as needed and through additional contract options with specialized vendor services.

JPATS technical support teams under the leadership of the JPATS Program Office will provide the augmentation of enterprise IT services for JPATS technical and programmatic services, systems, and applications in support of prisoner management and transport operations.

JPATS Technical services adhere to the enterprise governance requirements for compliance and technical operations, under oversight from and aligned with ITD lifecycle services.

JPATS Technical Services Team (JPATS IT Team) Support Background - The JPATS IT technical support is currently provided by four (4) JPATS ITD personnel, four (4) JPATS Business Integration Center (BIC) support personnel and supplemented by eight (8) full and part time IT contractors; Section 3.21: Task Order Key Personnel Resources (KPR) and Attachment 4: Key Personnel Resources Qualifications and Individual Labor Categories.

Approximately 90 other ITD personnel (not including contractors) across the nation provide enterprise core technical services delivery and service other U.S. Marshals Service business units and sites. Enterprise IT services may be supplemented as necessary by industry expertise outside the scope of this task order.

The USMS JPATS Program Office is seeking to award a task order against the General Services Administration’s (GSA) Governmentwide Acquisition Contract (GWAC), Alliant 2 to meet the IT service delivery requirements for JPATS operations.

PART 2 – GENERAL TASK ORDER REQUIREMENTS

1.0 SCOPE: JPATS will leverage the GSA GWAC, Alliant 2, for a non-personal services task order designed to provide professional IT services for the JPATS technical lifecycle services, inclusive of government developed and maintained services JPATS Management Information System (JMIS), Movement Packet (MPAC) Commercial Off-The-Shelf (COTS), custom developed technical solution products and integration to core USMS IT Systems. The Government will provide oversight for this contract and shall require the Contractor to exercise any supervision or control over the contract service providers performing the services herein for delivery of those services. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government for delivery to meet the service requirements from the JPATS Program Operations COR.

2.0 Description of Services Required: The contractor shall provide all personnel, management, supervision, and other non-personal services necessary to perform operate and maintain the JPATS IT Services portfolio, JMIS application and MPAC application; inclusive of GOTS, COTS and custom developed products as defined in this task order, except for those items specified in Section 3.22 Government Furnished Resources, Equipment and Services. The contractor shall perform to the standards in this contract and as agreed to by the USMS Contract Officer Representative (COR). Service Level Objectives (SLOs) details, descriptions, and measures are located in Technical Exhibit 1: Service Level Objectives.

2.1 Task Order Program Management Support Delivery Requirement: Program

Management Support SLOs: There are eight (8) primary SLOs that will be provided by the Contractor under this contract to achieve quality performance and meet the service delivery requirements for task order management for delivery of these contracted services:

2.1.1 Task Order Contract and Contract Personnel Management

2.1.2 Contract Deliverables Management

2.1.3 Program Logistics and Communications Management

2.1.4 Program Documentation Support

2.1.5 Program Personnel Resources, Prioritization, and Schedule Management

2.1.6 Program Costs Management

2.1.7 IT Acquisition and Program Budget Projection Support

2.1.8 Centralized JPATS IT Services Delivery Management

JPATS, operated by the U.S. Marshals Service, is the largest transporter of prisoners in the world, handling approximately 500 requests each day to move prisoners between judicial districts and correctional institutions. In fiscal year 1999, JPATS started operating under its own revolving fund, charging its customers for each prisoner moved. JPATS is mandated to charge actual costs back to each of its customers which is accomplished through automated technology services. Each financial expense is tracked in detail and categorized in order to bill customers accurately, provide income statements, and develop budget and pricing projections for each fiscal year, and mid-year adjustment periods, and long-term planning.

On a quarterly basis JPATS reports its financial and operational status to the USMS and Bureau of Prisons (BOP) and must demonstrate it is operating in an efficient and effective manner, therefore this information is vital to JPATS, its customers, and auditors. Reports detailing JPATS activity and financial status must be available at a moment’s notice and on a regular basis in real-time or near-real time. The JPATS supports the federal judiciary by scheduling and transporting prisoners to courts and detention facilities around the country, including sentenced prisoners who are in the custody of the BOP. For fiscal year 2021, JPATS scheduled and moved 92,158 prisoners and scheduled 205,926 movements of those prisoners. A network of aircraft, cars, vans, and buses accomplish these coordinated movements and leverage logistical IT tools. JPATS operates a fleet of aircraft which moves prisoners over longer distances more economically and with higher security than commercial airlines. Nearly all air movements are done aboard USMS owned or leased aircraft. On average, JPATS operates three large and one small sized aircraft per day, most of which follow a regular schedule. In addition to federal prisoners, JPATS aircraft transport non-federal prisoners as well. Military and civilian law enforcement agencies use JPATS to shuttle their prisoners between different jurisdictions at about 50 percent of commercial cost. They comprise the only government-operated, regularly scheduled passenger airline in the nation.

JPATS serves approximately 40 cities, plus every other major city in the United States on an as-required basis. Integration with standard industry aviation technology tools is leveraged daily and must be maintained. Detailed itineraries are produced, maintained, and required to ensure that each prisoner appears in court at the designated time. The JPATS scheduling function is located in Kansas City, Missouri with air fleet operations located in Oklahoma City, Oklahoma and an additional hub in Las Vegas, Nevada. Technical services supporting the JPATS mission scope are continually improved to meet the evolving requirements and to maintain compliance as needed and as requested by the COR.

2.2 JPATS Technical Service Delivery Requirement:

JPATS Technical Support Service Delivery applies to all JPATS program areas and shall be performed to quality standards outlined to achieve the SLOs and prevent system impacts during all technical lifecycle phases. JPATS follows USMS enterprise IT lifecycle processes and ensures compliance of all services.

JPATS develops and maintains JPATS program technical infrastructure. The backbone of JPATS Information Technology Unit is Applications, Systems, Services, and Database Administration. JPATS maintains multiple environments of systems for development, test, user acceptance, training, and production on different servers, which must be current and fully operational during the business day. Additionally, JPATS exists as a unit within the US Marshals Service (USMS) and must maintain specific security, continuity, and disaster recovery standards. Each of these standards present significant challenges during upgrades that required a strong understanding of ITD core infrastructure, Oracle COTS technology and JPATS software ecosystem to ensure risk mitigation during implementation to provide technical guidance on steps that lead to successful upgrade paths. In order to provide continued software infrastructure support that keeps the JPATS IT Systems current and up to date, the Systems and Database Administrators must have strong expertise and skills with a variety of technologies and workflows.

JPATS develops and maintains JPATS program mobile services and support. Support for field operations requires multiple capabilities with complex environmental constraints.

Capabilities including mobile application, web-based services, application Program Interface (API), Internet of Things (IoT), and service-to-service options shall require lifecycle support.

JPATS currently utilizes a custom, Apple-native mobile application to provide operational personnel with critical data on inmates being transported; and information on the current and future trips, stops, pickups and drop offs critical to logistical movements integrated from JMIS Transportation, in near-real time. Additionally, JPATS integrates biometric and artificial intelligence capabilities to facilitate automated intelligence availability for prisoner identification, verification and transfer expediting the movement process. Integration delivery access of digital movement documentation from MPAC must be delivered by the mobile application.

JPATS develops and maintains JPATS program technical interface(s) to internal and external services, systems, and applications. In FY 2016, the USMS embarked on an organization wide, multi-year, modernization, case management and operational system replacement called Capture. Capture encompasses modernization options which currently provide functionality for Prisoner Management, Investigations Management, and Judicial Security cases. This system uses web service-based interfaces with the JMIS to fully support the Prisoner Management Cases. The JMIS IT Team is highly involved in the key services required to support these and other external systems interfaces. Other support that falls under this task include project management, business process definition, requirements definition and management, webservice interface development, and functional testing. Deep knowledge of the JPATS movement request process, manifest creation, movement packet information, and JPATS prisoner movement process is required to provide the necessary support for the initiative.

There are twenty-three (23) primary JPATS Technical Support Service Delivery SLOs that are applicable to all delivered technical services in support of the JPATS Program operations and shall be provided by the Contractor under this contract to achieve quality performance and meet the service delivery requirements for continuous JPATS Program operations:

2.2.1 Centralized JPATS Information Technology (IT) Services, Systems, Application Lifecycle Management

2.2.2 Research, Analysis and Design Recommendation Deliverable(s)

2.2.3 Project Traceability Matrix Deliverable(s)

2.2.4 Project, Development, Innovation, and Enterprise Integration Deliverable(s)

2.2.5 Service Design Deliverable(s)

2.2.6 Cybersecurity and Compliance Information Assurance

2.2.7 Transition and Deployment Deliverable(s)

2.2.8 Innovation and Pipeline Improvement(s)

2.2.9 User Acceptance Testing Deliverable(s)

2.2.10 User Acceptance Deliverable(s)

2.2.11 Technical Capabilities Lifecycle Operations and Management

2.2.12 Software Operations Lifecycle Management

2.2.13 Code Lifecycle Management Deliverable(s)

2.2.14 Functional Systems and Services Integration Deliverable(s)

2.2.15 Backup (BU), Disaster Recovery (DR) and Continuity of Operations (COOP)

2.2.16 Operations and Maintenance (O&M) Lifecycle Deliverable(s)

2.2.17 Change Management Lifecycle Deliverable(s)

2.2.18 Asset Management

2.2.19 Maintain Service and System Performance

2.2.20 Training Support

2.2.21 Customer Support

2.2.22 Data Management

2.2.23 Emergency Management and Operations

2.3 JPATS Application Delivery Requirement: A collection of application and tools make up the JPATS technical portfolio suite of application services in scope for the delivery of this requirement. The major applications JMIS, MPAC and Core Support Application services require the contractor to provide lifecycle support inclusive of continued service improvements and cost value efficiency modernization. There are four (4) main and one (1) optional JPATS Application Delivery, operational program application, SLO(s) required:

2.3.1 JMIS Application Operations and Delivery

• JMIS Transportation/ Scheduling

• JMIS Financials

• JMIS Business Intelligence/Reporting

• JPATS Assisted Routing & Scheduling (JARS)

• JPATS Mobile Application

2.3.2 MPAC Application Operations and Delivery

2.3.3 Support Application(s) Operations and Delivery

• Flight Operations

• Alerts/Monitoring

• Automation Tools

2.3.4 JMIS Financials Evaluation and Replacement (Optional CLIN Section 3.7.11)

JMIS Application Operations and Delivery: The JMIS application fulfills three roles 1) producing JPATS budget and billing, 2) scheduling transportation of prisoners and 3) supporting operations and missions. JPATS established financial side and transportation side services which have been in operation since 2010. The system continues to be enhanced and maintained by the JPATS ITD technical support team in the Kansas City, Missouri offices. JMIS provides cost accounting for all JPATS operating expenses including budgeting; billing of Federal and Non-Federal prisoners; prisoner transportation scheduling processes; air and ground route scheduling; automated prisoner and vehicle transportation planning; route optimization; business intelligence reporting and analytics; and integration with all external COTS and GOTS “feeder” systems. In Scope feeder system examples: Sentry, Collins Aerospace FOS, UFMS, Capture, CJIS, DOJ/ITD core services, and eICF. JMIS is built on two Oracle COTS applications, Oracle E-Business Suite (EBS) and Oracle Logistics/ Oracle Transportation Management (OTM). A custom-built interface is utilized for the transportation scheduling module using Oracle Application Express (APEX). Oracle’s Business Intelligence (OBIEE) is used for reporting, performance metric dashboards and analytic research. A custom-built Apple-native mobile application is used during prisoner transportation operations to facilitate protected movement, identification, and transfer operations. There is a General Algebraic Modeling System (GAMS) mathematical engine which is used to recommend the most optimal routes projected for JPATS to operationally run in the upcoming week. This contract shall provide sustainment, O&M and lifecycle technical support services of the JMIS application. The Government may require major and minor application enhancements and new product integration during the period of performance.

• JPATS Reporting: JPATS requires reporting capabilities including technical systems, business services, and governance reporting. Reports must be available in standard USMS formats and leverage existing enterprise data analytic visualization tools.

Reports must be maintained following data and records policies with privacy and cybersecurity protections. All artificial intelligence or algorithmic code used must be done in an ethical manner and must ensure equitable transparency.

• JPATS Planning System Support: The JPATS Assisted Routing & Scheduling System

(JARS) is a system based on Oracle Logistics (OTM version 6.4.1) that provides coordinated and standardized planning of Trips and Prisoners one to nine weeks out. Each night the JARS Planning Engine runs, plans and schedules 80% of the pipeline of prisoner movement requests. JARS provides schedulers with “accepted” trips each day, 7 days out, which serve as an advanced starting point from which to refine and execute. In order to provide JPATS with precise support of this detailed system, the IT support staff must possess strong experience with the Transportation Network, particularly with regard the support and maintenance of the OTM components of JARS. In the past year, 225 ground schedules were created for new trips, 1,258 itineraries were updated. These were added to the existing network configuration data that has been developed over the past ten years. In order to continue JARS enhancements, the JARS support role must have strong expertise and skills in Oracle Logistics/OTM, Oracle databases, the JPATS Transportation Network, and the JARS implementation of the JPATS Network.

• Route Optimizer Support: The Route Optimizer for the recommendation of scheduled air routes is a system implemented as a Mixed Integer Optimization Model in GAMS that is solved by the open-source CBC solver. The Route Optimizer uses prisoner passenger (PAX) forecasts using the time-based location of planned and scheduled prisoners and scheduler logic for prioritizing the filling of route legs to drive the selection of PAX maximizing route sets. The Route Optimizer also includes operational constraints such as flight duration, airport visits, three leg trips, four leg trips, stops, and routes that users can adjust to develop operationally acceptable route schedules. The Route Optimizer Support Role must have strong expertise and skills in mathematical optimization, GAMS, CBC, and the algorithms used to develop PAX forecasts.

MPAC Application Operations and Delivery: The MPAC application automates the paperwork required to transport and exchange custody, ensuring the completeness of electronic travel packets prior to prisoner movement, while providing personnel in the movement process the capability to view digital documents. The USMS and BOP requires continued delivery of and improvements to the Movement Packet (MPAC) systems. Key to this delivery is the update and maintenance of existing MPAC portals, the establishment of mobile capabilities and improvements to include retrieval of digital documents and establishing an electronic travel packet workflow. MPAC is a custom-built Java web-based application and primarily consists of three shared code base portals for access by JPATS transportation network customer bases (BOP, USMS, and State/local or contract facilities). The contractor shall provide technical assistance with interconnection lifecycle operations related to the cross-agency user and data sharing functionality needed for delivery. The contractor shall notify the USMS of potential improvements or risks to the services which need to be addressed. This contract shall provide activities in support of the management, sustainment, and O&M of the MPAC application. The Government may require major/minor application enhancements and/or new products to support this service during the period of performance.

• MPAC Support: JPATS develops, maintains and enhances the MPAC suite of applications, which provide key stakeholders/operating partners the ability to view prisoner movements, manage digital documents, search prisoner information, conduct/approve medical/security protocols and manage personnel access to external portals. The MPAC applications are used by more than 1,000 users and require ongoing user training support as new users are provided access. Key to this support is the user training for the MPAC suite of applications.

Support Application(s) Operations and Delivery: The Contractor as part of the JPATS ITD team shall manage systems and services which provide support operations to JPATS internal business units including finance, scheduling, customer, strategic decision making, and flight operations. Due to the specialized nature of JPATS’ Private Transportation Network based business, the unique nature of the supporting financial, scheduling, logistics and reporting systems, and its agile development environment, JPATS IT contract support requires specialized functional and technical skills to effectively support internal business units and operations. The Contractor is expected to encompass significant skills, experience, and JPATS institutional knowledge provide much of the IT support to JPATS in terms of data transformation, protected access, and systems development, enhancements, and maintenance.

• JPATS System Monitoring and Alerts: JPATS requires a highly available system and utilizes a complex set of monitoring and alerts to verify systems are operating as expected, data integrated is maintained, and system interconnections are operational.

JMIS Financials Evaluation and Replacement – The JMIS Financials system, part of the JPATS Management Information System (JMIS) suite of systems, provides budgeting, billing, and accounting financial services for JPATS. The JMIS Financials system is comprised of Oracle Electronic Business Suite, which is a complex enterprise-level financial management system of which JPATS uses a small portion. Due to its complexity, Oracle EBS provides challenges to install, upgrade and patch when considering the limited JPATS use of the enterprise solution.

JPATS is considering an optional CLIN to evaluate potential replacement of the Oracle Electronic Business Suite (EBS) with an alternative financials system. At a minimum, this evaluation will address the following factors:

• Replacing the complexity of the Oracle EBS installation and operations and maintenance (O&M)

• Eliminating duplicate work to maintain two general ledgers (GLs)

• Updating/automating financial capabilities and streamlining JPATS processes

The Contractor shall deliver lifecycle support and enhancements for JPATS Program Applications to meet the SLOs at the required performance quality.

2.4 Information Technology Requirements: Delivery of information technology systems and services is governed by USMS ITD under the direction of the Chief Information Officer (CIO) and aligned to the Federal and DOJ technology policies and requirements. USMS maintains compliant enterprise core technical services through a line-of-business lifecycle agile delivery model. Special programs are required to meet the base core technical compliance requirements and follow established enterprise lifecycle processes. Compliance with Enterprise IT requirements shall be measured by the JPATS COR through the JPATS Technical Service Delivery SLO(s).

2.4.1 Technical Security Requirements: The Contractor shall ensure all existing, new and proposed technology is in compliance with applicable legal, regulatory, Department of Justice (DOJ) and USMS policy requirements to achieve and maintain an Authority to Operate (ATO) where applicable as outlined in Attachment A - PGD-14-03 Acquisition of High and Moderate Impact IT Systems; and Attachment B – DOJ PGD 15-03 DOJ Security

Requirements for procured technical solutions and services; and Attachment C – Cloud Service Provider Requirements; and Attachment D – Standards and compliance Requirements. The Contractor shall allow technical solutions, products or services to be inspected for federal and USMS compliance. The USMS COR can approve acceptance of technical solutions, products, and services provided proper authorization is achieved through the current USMS Information Technology Division change management process for Authority to Test or Authority to Operate as needed.

The contractor shall ensure all existing and proposed technical Government-Owned Technology systems and services (GOTS) and Commercial-Off-The-Shelf (COTS) services maintain the required compliant controls and data management framework required for USMS policy throughout the lifecycle, unless a risk-based decision waiver is granted by USMS Chief Information Officer (CIO) for a risk mitigated deviation of the control. The contractor shall ensure technology and performance of existing and new solutions are consistent with Industry and Technology guidance best practices. Technical services review meetings may be requested, as needed for change management activities related to directly provided Vendor systems and services which house USMS information. Limited review of access and records elements associated with the Commercial Services which are part of the managed services delivery and not considered directly attributed as USMS owned or operated systems and services may be required. Status reports, meetings, and artifacts related to use of vendor systems housing USMS management information during the system or service lifecycle for enablement, audit support, changes inclusive of patching and updates, and vulnerability response may be required if requested.

The contractor shall ensure technical services that are delivered, configured, maintained and optimized are aligned to the strategic plan, operational plan, and enterprise architecture. The Contractor shall deliver research, analysis, design, development, engineering, testing, integration, validation, implementation, transition, asset management, vulnerability mitigation, upgrades, image enhancements, Operating System enhancements, service remediation, restoration, optimization, cyber control, configuration management, feature optimization, capability management, compliance assurance, change management, portfolio management, project management, program management, investment management, enterprise architecture management, communications, reporting, and task management services related to the JPATS line-of-business lifecycle technical requirements.

The Contractor shall deliver services support for all aspects of the JPATS IT lifecycle related to Government-owned Government-Operated (GOGO), Government-owned Contractor-operated (GOCO), and Contractor-Owned Contractor-operated (COCO) IT services, hardware, software, applications, cloud, solutions, systems, applications, web services, processes, and platforms supporting the Government IT environment. The contractor shall meet the USMS specified requirements for compliance or notify USMS and address any deviation to the services which do not meet the standard delivery model;

impactful assumptions, and technical limitations which must be listed and clarified as to the nature and scope of the limitation for consideration of acceptance by USMS. The vendor is required to ensure supply chain risk (SCRM) is managed and mitigated. A SCRM Plan may be requested. For technical services SCRM should be addressed in the compliance controls and reporting.

The Contractor shall provide change and configuration management policy and procedures that streamline operations, track changes, and prevent untested, ad-hoc change in the production environment. The Contractor shall maintain active knowledge of current and emerging technologies and identify the potential impact to the Government IT enterprise services. The Contractor shall maintain an accurate, reportable inventory of USMS IT accounts, hardware, software, licenses, services, solutions, products and assets.

The Contractor shall ensure service stability, availability, reliability, policy compliance, and performance to meet the contract delivery. The Contractor shall provide Business and Customer support for IT operations lifecycle communications, knowledge management, and training on delivered services; and shall advise Customers on emerging technology options. Performance tuning and continuous improvement is required. The Contractor shall have the option to research, analyze, provide a proof of concept, and recommend more efficient options for achieving the standard or enhanced performance requirements delivered under the contract. The Contractor may recommend optional innovative approach option(s) for Government consideration. The Contractor may suggest services, systems, or solutions that can be provided under the JPATS GWAC SOW as an Other Direct Cost (ODC) option; where services can be provided at a reduced cost, or in a more effective design, or business process model for consideration by the Government. The Contractor shall identify service performance challenges, where the government defined growth exceeds the Contractor ability to identify cost offset efficiencies; the Contractor shall notify the COR to request consideration for a potential modification upon agreement by the Government.

2.4.2 Information Systems Security Assurance Requirements: The contractor shall ensure applications, database services, mobile applications, website, application interfaces, and portal platform services are maintained with required access controls and data management oversight inclusive of reporting for any Government-owned (GOTS) or commercially leveraged (COTS) services. Access controls must allow modern authentication which enforces 2 factor minimum multifactor authentication and ensures a unique login for each user. Service accounts shall be used for system-to-system access unless alternative compliant option, mobile application or an optional API is available and approved by the USMS for allowing authorized system-to-system service communication.

Logging of access must be maintained for audit compliance and when possible, made exportable to be used with USMS enterprise cybersecurity tools. Contractor supplied technology which have network connections must allow for auto-discovery when connected to the USMS network; must be able to support use of SNMP; allow for enterprise security settings with options for central controlled management; must support IPv4 and IPv6 network address interconnections; and must allow automated enterprise configuration change management for web interfaces, API operations, universal device drivers, configuration settings and device based operations where applicable.

The Contractor shall assist the Government authorized representative, which may be a federal or contractor member of the Cyber Security Branch (CSB), Information System Security Officer (ISSO); with implementation of security controls, Assessment and Authorization (A&A), Authority to test (ATT), Authority to Operate (ATO), vulnerability management, risk mitigation, and maintenance of current Government-owned services;

and to maintain accurate security documentation in DOJ Cyber Security Assessment and Management (CSAM) systems. The Contractor shall develop Plan of Action and Milestones (POA&M) for identified security deficiencies; and manage and resolve POA&MS according to Government approved schedule(s). Security Certification and Accreditation control validation activities are separately scoped, through a USMS separately maintained Government-owned service; but Cyber risk is measured through operational cyber protections and must be embedded in the JPATS IT Core delivery services for architecture, design and delivery; of systems, solutions and services provided by JPATS IT Lifecycle Operations.

JPATS IT support is required to provide design information, discussion coordination, collaborative interaction with stakeholders, and communication by written and oral means to support the dependent IT Cyber Security Branch (CSB) requirements. The JPATS support resources provide architectural design documents, diagrams, configuration baselines, reports, patches, system updates, vulnerability mitigation, infrastructure protections, and response in support of specific security related questions, processes, or requested actions; and JPATS services support must ensure compliance inclusive of audit support requested by the Cyber Security Branch Audit management team.

USMS owns/maintains systems, solutions, infrastructure, licenses, end user devices and support services that can be leveraged for IT Lifecycle Operations delivery; and that are considered Government-Owned and services, which may be GOTS or COTS that are considered Contractor-Operated. DOJ USMS data and services must be maintained in accordance with federal compliance requirements and support services provided within Attachment H Personnel and Property Contractor Compliance Requirements.

2.4.3 Information and Data Requirements: The USMS owns the rights to all data/records produced as part of this contract and shall have unlimited rights to use, dispose of, or disclose such data contained therein as it determines to be in the public interest. The vendor shall not create or maintain any records containing any USMS information that are not specifically tied to or authorized by the contract. Further, disposition and destruction of records is EXPRESSLY PROHIBITED unless authorized by the USMS. The vendor shall prevent the alienation or unauthorized destruction of records, including all forms of mutilation. Willful and unlawful destruction, damage, or alienation of Federal records is subject to the fines and penalties imposed by 18 U.S.C. 2701. All Information Systems (IS) that process, store, or transmit USMS information are required to establish a process to ensure adequate security is in place. The IS are subject to federal, departmental, and USMS policies and procedures. The contractor shall comply with best security practices and follow the security guidelines of the approved Interconnection Agreements.

The contractor shall make reasonable efforts within the existing IT system to implement the following security controls: system security categorization, access control, awareness and training, audit and accountability, incident response identification and authentication, password management, accountability and audit trails, warning banner, assignments and segregation of system responsibilities/permission, personnel security, physical and environmental security, storage and marking.

Media Disposal and Reuse: When no longer usable, CDs, DVDs, tape cartridges, thumb drives and other similar items used to process Sensitive But Unclassified (SBU) shall be destroyed by cross-cut shredding, incineration or degaussing, whichever method is available, appropriate, and cost effective as determined by the contractor. Any Contractor-owned equipment used to process or store USMS data shall be sanitized according to Government regulations when the Contractor-owned equipment is disposed of or at the end of the contract. When no longer required for mission or project completion, IT storage media that will be reutilized, media shall be overwritten with software and protected consistent with the data sensitivity and/or at the highest classification level at which they were previously used, whichever the contractor deems appropriate.

All information related to this contract created or produced in part or in whole, regardless of type of media, is to be maintained for the duration of the contract, made available upon request, and upon termination of the contract shall be turned over to the USMS. Any vendor produced and used algorithms or artificial intelligence, or automated machine-based learning code outside commercial off the shelf (COTS) services produced for use in this contract must meet the USMS policy and be reported for tracking throughout the lifecycle. All data at rest shall reside within the contiguous United States, the District of Columbia, and Alaska (CONUS) with a minimum of two unique, geographically separated, different and distant geographic locations. Data shall be maintained to ensure high availability. Data in all non-volatile memory media used to cache data on devices shall employ a method of data erasure to protect data in accordance with NIST 800-88. If not handled properly, release of these media could lead to an occurrence of unauthorized disclosure of information. Data at rest and in transit shall be encrypted and protected to Federal Information Security Management Act (FISMA), Federal Information Processing Standards (FIPS), and USMS standards.

The contractor is responsible to remove all USMS data from decommissioned technical products, services, and solutions. Removal of data prior to disposition of old systems shall be done as directed by the USMS ITD Cyber information security officer upon notification by the USMS JPATS COR.

The contractor shall be responsible for safeguarding all government equipment, information and property provided for contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured. It shall be understood that throughout the performance of this contract, the contractor will have access to information that is the sole property of the federal government and/or other organizations. The contractor and staff will be required to enter into a confidentiality agreement with USMS that ensures the non-disclosure of information relating to this project outside of the USMS and other agencies or organizations identified by USMS. The contractor shall sign a corporate Non-Disclosure Agreement found in Attachment E – Corporate Non-Disclosure Agreement.

Limited Official Use (LOU): Unclassified information that has been determined to require protection against unauthorized disclosure must be identified as LOU to ensure that all persons having access to the information are aware of the protection requirement. The preferred method of identification of LOU material is to mark “LIMITED OFFICIAL USE” on the header and footer of each page.

All press statements and releases related to the contract shall receive advance written approval by the Contracting Officer and the Office of General Counsel (OGC). Examples include, but not limited to, website notices & advertisements, use of the USMS name & seal, and images of USMS personnel.

2.4.4 Contract Personnel and Physical Security Requirements: The Contractor Services must be delivered to achieve quality performance levels in a value centric, industries best practices, results oriented model and will allow services provided by remote work centers, telework support, pooled partial time SME resource(s) from multiple specialties, or full-time resources to provide the Government the greatest flexibility for value-add efficiencies in delivery and performance.

All personnel providing services must meet the requirements outlined in Attachment H – Personnel and Property Contractor Compliance Requirements; and sign a non-disclosure agreement found in Attachment F – DOJ USMS Non-Disclosure Agreement; and Attachment G

– DOJ Rules of Behavior General Users; and complete annual training. Contractors with elevated and privileged access shall be required to sign additional disclosures.

The Contractor may propose a model for staffing and support services delivery aligned to the Contractors best practices, if the model meets the JPATS SLOs and Required service delivery tasks; and the government agrees with the proposed model.

2.4.4.1 Key and Card Control: The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer. The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.

2.4.4.2 Contractor Facility Access: While in USMS facilities, or other government facilities on USMS’ behalf and as part of this contract, the Contractor shall comply with posted evacuation procedures and instructions provided by security and emergency management personnel. In the event that Contractor personnel duty station(s) become inaccessible, with COR approval, the Contractor shall implement Continuity of Operations and Procedures (COOP) validation to ensure that customer support and service availability performance continues to meet the delivery requirements.

Contractor access to Government facilities - During the life of this contract, the rights of ingress to and egress from any Government facility for the Contractor's representatives shall be made available in accordance with the requirements set forth in Part 3: General Contract Performance Information. The Contractor personnel and resources shall comply with Government policies, during all operations on Government premises, including the rules and regulations governing the conduct of personnel and the operation of the facility. The Government reserves the right to require Contractor personnel to "sign-in" upon entry and "sign-out" upon departure from the Government facility and may require inspection of equipment or personal artifacts upon request. When any Contractor or subcontractor personnel (that require frequent access to a Government facility) enter a Federal building for the first time, the Contractor shall allow one hour for security processing and the fabrication of buildings access passes. Passes and/or electronic passkeys are the property of the U.S. Government and subject to periodic review by the Contractor's supervisor and may be verified against the employee's personal identification. The Contractor's employees shall present themselves for the issuance of renewed passes when required by the Government as scheduled by the COR or his/her designee. The Contractor shall notify the COR when employee passes are lost and must immediately apply for reissue of a replacement pass. It is the Contractor's responsibility to return passes and any other electronic pass keys issued to the Contractor by the Government to the COR or his/her designee when a Contractor’s employee is dismissed, terminated or assigned to duties not within the scope of this contract. The Contractor shall provide and ensure the capability to add, remove, re-locate, and/or alter the support resources; and optional services and ad-hoc deliverables as requirements change during its mission. Contractor provided Subject Matter Expertise (SME) personnel or resources may provide partial services, at flexible part-time intervals;

and provide services from temporary, remote or alternative locations with the ability for flexible work schedules in support of delivery to meet the required tasks and SLOs; and provide JPATS services to meet the delivery requirements.

2.4.4.3 Identification of Contractor Employees: All contract personnel attending meetings, answering Government telephones, and working in other situations where their contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by contractors are suitably marked as contractor products or that contractor participation is appropriately disclosed.

2.5 Key Personnel Security Requirements: The Contractor must provide on-site support for

Contractor staff considered Key Personnel Resource(s) (KPR), to manage critical area performance coordination, ensure performance delivery and to adequately address areas related to the overall contract program, technical, and operations task management. The Contractor shall use Government owned facilities and enterprise services for the JPATS IT Team. JPATS Services consumed by USMS stakeholders shall be approved by USMS ITD, in a Government-owned-Contractor-operated (Go-Co) enterprise operations delivery model, unless otherwise agreed by the JPATS COR. The Contractor may suggest alternatives to the KPR, staffing resource models, and Government-Owned services for consideration by the Government for adaptation.

Alternative contractor USMS site service support requires a 24 hour advanced notice for all physical site deliveries and work activity; with site coordination on delivery restrictions applicable to the receiving site. Notification to the JPATS COR is required.

KPR Security Requirements – Contractor personnel must be aware of their obligation for IT information assurance and security requirements; and shall demonstrate understanding of the privacy laws by completing the required privacy and IT security training as requested by the Government. Contractors play a vital role in protecting USMS networks and information from hackers and other cyber-attacks. It is the contract staff member’s responsibility to understand the “Rules of Behavior” governing IT security. Contractor personnel are responsible for the security of Government property and information in all work locations including remote Contractor staff locations. Accessing sensitive information while working at a non-Government facility presents additional risks compared to accessing sensitive information from within physically secured office space. The security measures specified cover not only information systems and technology, but all aspects of information handled by contract personnel, including paper files and other information formats, data storage devices, and telecommunications equipment (e.g., laptops, smartphones). Contract personnel are required to keep Government property and information safe, secure, and separated from personal property and information. The Contractor agrees to adhere to applicable guidelines, standards of conduct, safety and security requirements. Due to Law Enforcement Sensitive information processing through USMS IT Systems and services. Contract personnel shall require a standard USMS Clearance. Additional TS/SCI cleared resources may be considered as needed by the Government and upon approval from the Government may be processed without limitation too the Government to address a mission requirement. The Government may allow some resources to work in reduced capacity with restricted access limitations during the Transition-In period for non-sensitive information transition coordination pending an approved risk acceptance waiver is provided by the authorized government authority. At no time shall a Contractor have access to information outside of the authorized classification level without validation of procession of a valid clearance.

The Contractor shall be responsible for all program oversight, activity oversight, and project management activities related to the delivery of IT Services. The Contractor shall designate a primary single point of contact for all Government stakeholder management, communication and escalation requirements. USMS will work with the Contractor assigned single point of contact to coordinate milestone schedules, delivery priorities and requirements; and to conduct periodic status meetings to review performance, issues, and potential risks. The frequency of the meetings will be mutually agreed upon by the Government and Contractor;

but will occur no less than once monthly and at least once quarterly and twice annually. The Contractor single point of contact, or Government agreed, authorized representative; shall provide weekly implementation progress updates when there is an active project and service transition in progress. A real-time status dashboard or report may be considered as an alternative to the status update, upon agreement by the Government and Contractor post contract award. The Contractor shall ensure minimal changes in Key Personnel Resources (KPR) occur over the life of the contract.

The Contractor is responsible for pre-screening all perspective employees for suitability for work on any resulting contract and for assuring that all such persons have a government-performed background investigation completed prior to assignment to the contract. The Contractor shall assure that the person(s) to be utilized in the performance any resulting contract shall have been approved by the USMS PSB, as a result of the Government performed background investigation, prior to conducting work. The intent and purpose of the investigation is to preclude assignment of any individual who poses a threat to the Government or successful contract completion due to past unlawful or unsuitable conduct.

KPR Clearance requirements are detailed in Attachment H – Personnel and Property Contractor Compliance Requirements. All Contractor employees performing work on this contract shall be issued a Personal Identity Verification (PIV) PIV Card. Employees who will not be onsite shall be required to travel to the nearest Government credentialing facility twice; once to enroll and once to activate their PIV Card. The Contractor shall submit a Contractor Security Report upon Contract award, and each time contractor personnel changes occur during the period of performance of the contract.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .