TO 0001-SOW-CDRLs 6-8-20.pdf
PDF 958 KB Posted
- Attached to
- Cyber TRIDENT Federal contract opportunity
- Solicitation number
- W900KK-20-R-0001
About this file
This is a statement of work for a task order to provide infrastructure and maintenance support for the Persistent Cyber Training Environment platform. Key details include:
-
The contractor shall manage maintenance for the PCTE infrastructure, including providing 95% availability of the PCTE infrastructure calculated monthly. Infrastructure includes regional compute and storage nodes located at multiple DoD sites.
-
Help desk, tier 3 technical support, and on-site maintenance shall be provided for government-furnished equipment. Cybersecurity maintenance and compliance activities such as risk management framework documentation shall also be conducted.
-
Facilities, logistics, property management, software asset management, and diminishing manufacturing sources management requirements are outlined. License procurement and material acquisition must follow DoD policies.
-
Additional requirements include Army training and certification tracking, operations security training, and enterprise-wide contractor manpower reporting using the eCMRA system.
View the file
Other files for this federal contract opportunity
Show all 31
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
W900KK-21-F-TO01
Section B – Supplies or Services and Prices
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
1001 9 Months Infrastructure and Maintenance
FFP
The contractor shall provide Infrastructure and Maintenance support services on a monthly basis IAW Basic Contract CLIN 0003, # SOW-2020-011, Section 3.6.1 and TO 0001 SOW # 2020-011-01.
Year 1
FOB: Destination
PSC CD: 7010
NET AMT _______________
1002 1 lot Materials for Replacement Parts
COST
The contractor shall provide materials as required IAW to Basic Contract, CLIN 0014, # SOW -2020-011, Section 3.1.11 and TO 0001 SOW # 2020-011-01.
MAX COST _______________
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
1003 1 ea Manpower Reporting
FFP
Enterprise-Wide Contractor Manpower Reporting Application (eCMRA) - The contractor shall input annually all required labor information in the CMRA IAW Basic Contract CLIN 0015 and IAW SOW Section 4.1 for the services provided for contract year 1.
2001 12 Months OPTION Infrastructure and Maintenance
FFP
Year 2
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
1002 1 lot OPTION Materials for Replacement Parts
COST
The contractor shall provide materials as required IAW to Basic Contract, 2003 1 ea OPTION Manpower Reporting
FFP
Enterprise-Wide Contractor Manpower Reporting Application (eCMRA) - The contractor shall input annually all required labor information in the CMRA IAW Basic Contract CLIN 0015 and IAW SOW Section 4.1 for the services provided for contract year 2.
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
3001 12 Months OPTION Infrastructure and Maintenance
FFP
Year 3
3002 1 lot OPTION Materials for Replacement Parts
COST
The contractor shall provide materials as required IAW to Basic Contract, ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
3003 1 ea OPTION Manpower Reporting
FFP
Enterprise-Wide Contractor Manpower Reporting Application (eCMRA) - The contractor shall input annually all required labor information in the CMRA IAW Basic Contract CLIN 0015 and IAW SOW Section 4.1 for the services provided for contract year 3.
4001 12 Months OPTION Infrastructure and Maintenance
FFP
Year 4
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
4002 1 lot OPTION Materials for Replacement Parts
COST
The contractor shall provide materials as required IAW to Basic Contract, 4003 1 ea OPTION Manpower Reporting
FFP
Enterprise-Wide Contractor Manpower Reporting Application (eCMRA) - The contractor shall input annually all required labor information in the CMRA IAW Basic Contract CLIN 0015 and IAW SOW Section 4.1 for the services provided for contract year 4.
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
5001 12 Months OPTION Infrastructure and Maintenance
FFP
Year 5
5002 1 lot OPTION Materials for Replacement Parts
COST
The contractor shall provide materials as required IAW to Basic Contract, ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
5003 1 ea OPTION Manpower Reporting
FFP
Enterprise-Wide Contractor Manpower Reporting Application (eCMRA) - The contractor shall input annually all required labor information in the CMRA IAW Basic Contract CLIN 0015 and IAW SOW Section 4.1 for the services provided for contract year 5.
Section C – Descriptions and Specifications
C1 Order of Precedence
STATEMENT OF WORK
The SOW, under Attachment 1, is incorporated into Section C1 for purposes of FAR Clause 52.215-8, “Order of Precedence.”
Section E – Inspection and Acceptance
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
1001 Destination Government Destination Government 1002 Destination Government Destination Government 1003 Destination Government Destination Government 2001 Destination Government Destination Government 2002 Destination Government Destination Government 2003 Destination Government Destination Government 3001 Destination Government Destination Government 3002 Destination Government Destination Government 3003 Destination Government Destination Government 4001 Destination Government Destination Government 4002 Destination Government Destination Government 4003 Destination Government Destination Government 5001 Destination Government Destination Government 5002 Destination Government Destination Government 5003 Destination Government Destination Government
CLAUSES INCORPORATED BY REFERENCE
52.246-4 Inspection of Services – Fixed Price AUG 1996 52.246-3 Inspection of Supplies – Cost Reimbursement May 2001
Infrastructure and Maintenance CLINs inspection and acceptance criteria:
• Inspection and Acceptance shall consist of maintaining a 95% availability of the PCTE infrastructure calculated on a monthly basis.
• The 95% availability shall be measured against each RCS individually. The availability time is 24 hours a day, 7 days a week.
• Unavailability of RCS fielded facilities, networks connectivity, or awaiting Government provided replacement parts is deleted from the platform availability time.
(Reference SOW Para 3.2.1)
Section F – Deliveries or Performance
DELIVERY INFORMATION
CLIN QUANTITY SHIP TO ADDRESS DODAAC CAGE
1001 N/A PEO STRI ORLANDO W906ZL
DELIVERY DATE
POP 1 OCT 2021
TO 30 JUN 2022 JAMES KOZLOWSKI
12211 SCIENCE DRIVE
ORLANDO FL 32826
407-208-5864 FOB: Destination
1002 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
1003 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
2001 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
2002 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
2003 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
3001 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
3002 N/A (SAME AS PREVIOUS LOCATION): W906ZL
FOB: Destination
3003 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
4001 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
4002 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
4003 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
5001 N/A (SAME AS PREVIOUS LOCATION) W906ZL
FOB: Destination
5002 N/A (SAME AS PREVIOUS LOCATION) W906Z
FOB: Destination
5003 N/A (SAME AS PREVIOUS LOCATION) W906Z
POP 1 OCT 2021 TO
30 JUN 2022
POP 1 OCT 2021 TO
30 JUN 2022
POP 1 JUL 2022 TO
30 JUN 2023
POP 1 JUL 2022 TO
30 JUN 2023
POP 1 JUL 2022 TO
30 JUN 2023
POP 1 JUL 2023 TO
30 JUN 2024
POP 1 JUL 2023 TO
30 JUN 2024
POP 1 JUL 2023 TO
30 JUN 2024
POP 1 JUL 2024 TO
30 JUN 2025
POP 1 JUL 2024 TO
30 JUN 2025
POP 1 JUL 2024 TO
30 JUN 2025
POP 1 JUL 2025 TO
30 JUN 2026
POP 1 JUL 2025 TO
30 JUN 2026
POP 1 JUL 2025 TO
30 JUN 2026 FOB: Destination
Section G – Contract Administration Data
CLAUSES INCORPORATED BY FULL TEXT
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (DEC 2018)
(a) Definitions. As used in this clause—
“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.
“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.
“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(b) Electronic invoicing. The WAWF system provides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232- 7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall—
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.beta.sam.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:
(1) Document type. The Contractor shall submit payment requests using the following document type(s):
(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.
(ii) For fixed price line items—
(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.
Combo Type invoice for FFP CLINs Cost Voucher for Cost Reimbursement CLINs
(Contracting Officer: Insert applicable invoice and receiving report document type(s) for fixed price line items that require shipment of a deliverable.)
(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.
See (A) above
(Contracting Officer: Insert either “Invoice 2in1” or the applicable invoice and receiving report document type(s) for fixed price line items for services.)
(iii) For customary progress payments based on costs incurred, submit a progress payment request.
(iv) For performance based payments, submit a performance based payment request.
(v) For commercial item financing, submit a commercial item financing request.
(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.
[Note: The Contractor may use a WAWF “combo” document type to create some combinations of invoice and receiving report in one step.]
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table for FFP CLINs*
Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC To be completed at Contract Award Issue By DoDAAC W900KK Admin DoDAAC** To be completed at Contract Award Inspect By DoDAAC W906ZL
Ship To Code Ship From Code Mark For Code Service Approver (DoDAAC) W906ZL Service Acceptor (DoDAAC) Accept at Other DoDAAC LPO DoDAAC DCAA Auditor DoDAAC N/A Other DoDAAC(s)
Routing Data Table for Cost Reimbursement CLINs
Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC W900KK Issue By DoDAAC W900KK Admin DoDAAC** To be completed at Contract Award Inspect By DoDAAC W906ZL Ship To Code N/A Ship From Code Mark For Code N/A Service Approver (DoDAAC) Service Acceptor (DoDAAC) W906ZL Accept at Other DoDAAC LPO DoDAAC DCAA Auditor DoDAAC To be completed at Contract Award Other DoDAAC(s)
(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert “See Schedule” or “Not applicable.”)
(**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)
(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.
(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.
(g) Email notification shall be sent with each invoice or voucher submission to the following contacts:
Contracting Officer Representative
Ph 407-208-5864 James.r.kozlowski.civ@mail.mil
Rebeca Gonzalez Ph 407-384-3968 Rebeca.a.gonzalez.civ@mail.mil
The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.
- Ronald Crowder, ronald.j.crowder.civ@mail.mil, ph 407-208-3032, Group Administrator (GAM)
- Thomas Bunch, thomas.j.bunch.civ@mail.mil, ph 407-384-3792, GAM
Officer: Insert applicable information or “Not applicable.”)
(1) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.
(End of clause)
G2 - Contract Administration Data
Payment Instructions:
https://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#pa yment_instructions, G3 AWARD/EXERCIS E OF OPTION
The Government may unilaterally exercise any or all CLINs designated as an option in Section B of this task order. These option CLINs will be exercised at the Government’s discretion to extend the period of performance of the task order up to twelve (12) months, but may be for less time. Such options may be exercised by issuing a contract modification not later than the last day of the current period of performance. The Government shall comply with FAR 52.217-9, “Option to Extend the Term of the Contract” notice requirements.
Option CLINs Description of CLIN Exercise Period
CLIN 2001 Infrastructure and Maintenance 1 Jul 2022 – 30 Jun 2023 CLIN 2002 Materials for Replacement Parts 1 Jul 2022 – 30 Jun 2023 CLIN 2003 Manpower Reporting 1 Jul 2022 – 30 Jun 2023 CLIN 3001 Infrastructure and Maintenance 1 Jul 2023 – 30 Jun 2024 CLIN 3002 Materials for Replacement Parts 1 Jul 2023 – 30 Jun 2024 CLIN 3003 Manpower Reporting 1 Jul 2023 – 30 Jun 2024 CLIN 4001 Infrastructure and Maintenance 1 Jul 2024 – 30 Jun 2025 CLIN 4002 Materials for Replacement Parts 1 Jul 2024 – 30 Jun 2025 CLIN 4003 Manpower Reporting 1 Jul 2024 – 30 Jun 2025 CLIN 5001 Infrastructure and Maintenance 1 Jul 2025 – 30 Jun 2026 CLIN 5002 Materials for Replacement Parts 1 Jul 2025 – 30 Jun 2026 CLIN 5003 Manpower Reporting 1 Jul 2025 – 30 Jun 2026 mailto:ronald.j.crowder.civ@mail.mil mailto:thomas.j.bunch.civ@mail.mil http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions
Section I – Contract Clauses
52.245-1 Government Property JAN 2017
Section J - List of Documents, Exhibits and Other Attachments
EXHIBITS AND ATTACHMENTS
Section J - List of Documents, Exhibits and Other Attachments
Attachments Name Date # of Pages Attachment 1 Statement of Work, #2020-011-01 29 Apr 20202 40 pages Attachment 2 DD254, DoD Contract Security
Classification Specification (See Basic Contract, Attach 14)
25 May 2020 3 pages
Attachment 3 Government Furnished Property Listing (See Basic Contract Attach 9)
10 Mar 2020 4 pages
Attachment 4 Government Equipment (PCTE HW-SW) Property Listing (See Basic Contract Attach 10)
09 Mar 2020 16 pages
Exhibits
A101 DI‐MGMT‐81928 CONTRACTORS PROGRESS AND
STATUS REPORT
3 June 2020 1 page
A102 DI‐ADMN‐81505 Report, Record of Meeting/Minutes 3 June 2020 1 page B101 DI‐MISC‐80711A Maintenance Plan 3 June 2020 1 page B102 DI‐MISC‐80711A Trouble Ticketing/Problem Reporting
Plan 3 June 2020 1 page
C101 DI‐MGMT‐80269 PCTE Consolidated GFE Report 3 June 2020 2 pages C102 DI‐MISC‐80711A Property Management System Plan 3 June 2020 1 page C103 DI‐MGMT‐81994 Priced Bill of Materials 3 June 2020 1 page C104 DI‐SESS‐81758 Logistics Product Data 3 June 2020 1 page C105 DI‐TMSS‐80527C Commercial Off‐The‐Shelf (COTS)
Manuals & Associated Supplemental Data
3 June 2020 2 pages
SOW-2020-011-01
STATEMENT OF WORK
SOW-2020-011-01
for the
Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT)
Task Order One (1) - Persistent Cyber Training Environment (PCTE) Infrastructure and Maintenance
U.S. Army Program Executive Office for Simulation, Training, and Instrumentation (PEO STRI)
12211 Science Drive Orlando, FL 32826-3276
Revision Number Date Log of Changes Made and Description of
Reason Changes Approved By
Table of Contents
1. SCOPE
1.1 Introduction
1.2 Goals and Objectives
2. APPLICABLE DOCUMENTS
3. REQUIREMENTS
3.1 Program Management
3.1.1 Monthly Report
3.1.2 Associate Contractor Agreements (ACAs)
3.1.3 Schedule
3.1.4 Risk Management
3.1.5 Program Management Reviews (PMRs)
3.1.6 Facilities
3.1.6.1 Contractor’s Developmental/Test Facilities
3.1.6.2 Sensitive Compartmented Information Facility (SCIF)
3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions
(CHESS) Program
3.2 Operations
3.2.1 PCTE Maintenance and Support
3.2.2 Infrastructure Tier 3 Technical Support
3.3 Cybersecurity
3.3.1 Risk Management Framework (RMF)
3.3.1.1 Cyber Reports and Tasks Schedules
3.3.1.2 Cyber Technical and Meeting Support
3.3.2 Army Training and Certification Tracking System (ATCTS) Training
3.3.3 OPSEC
3.3.3.1 Requirements for OPSEC Training
3.3.3.2 Anti-Terrorist Training (AT Level 1)
3.3.3.3 Active Shooter Training
3.3.3.4 Access to Government Information Systems
3.3.3.5 Professional Training and Certification
3.3.3.6 Personal Identifiable Information (PII)
3.3.3.7 Security and Access Controls
3.3.3.7.1 General Security
3.3.3.7.2 Security Clearances
3.3.3.7.3 Access and General Protection/Security Policy and Procedures
3.3.3.7.4 Handling or Access to Classified Information
3.3.3.7.5 Disclosure of Information
3.3.3.7.6 Effective Use of Controls
3.3.3.7.7 System Security Plan (SSP)
3.4 Logistics
3.4.1 Maintenance Support
3.4.2 Property Accountability and Management
3.4.2.1 Inventory Support
3.4.3 Supply Management
3.4.4 Licensing and Warranty Management
3.4.5 Supportability
3.4.6 Software Asset Management
3.4.7 Obsolescence Management/Diminishing Manufacturing Sources and
Material Shortages (DMSMS)
3.4.8 Item Unique Identification (IUID)
4. ADDITIONAL CONTRACTOR REQUIREMENTS
4.1 The Enterprise-Wide Contractor Manpower Reporting Application
(eCMRA)
Statement of Work
SOW-2020-011-01
Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT)
Task Order One (1) - Persistent Cyber Training Environment (PCTE) Infrastructure and Maintenance
1. SCOPE
This Statement of Work (SOW) defines the scope of the Project Manager Cyber Test and Training (PM CT2) Product Manager Cyber Resiliency and Training (PdM CRT) Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT) Task Order One (1). The Cyber TRIDENT Indefinite Delivery/Indefinite Quantity (IDIQ) is utilized by Department of Defense (DoD) organizations and other non-DoD agencies that have related cyber training needs. The Cyber TRIDENT IDIQ provides the management, integration, maintenance, and evolution for the PCTE platform, and provides total system/subsystem acquisition life cycle support for the PCTE system baseline.
This Task Order One (1) SOW defines the detailed requirements that PdM CRT requires to have performed under the Cyber TRIDENT IDIQ contract in support of PCTE Infrastructure and Maintenance for the PCTE platform. PM CT2 defines the Infrastructure and Maintenance of the PCTE platform under Cyber TRIDENT Task Order One (1) to include:
• Cybersecurity Maintenance and Compliance
• Information Technology (IT) Support
• Facilities
• Development Regional Compute and Storage (RCS), Production RCS Support
• Tier 3 Infrastructure Technical Support
• Sensitive Compartmented Information Facility (SCIF) Operations
• License Procurement and Management
• Logistics
• Property Management
1.1 Introduction
Task Order One (1) will provide the necessary contractor support for Infrastructure and Maintenance of the PCTE platform. This covers the various hardware and software platforms, networks, and security operations across the fielded sites of PCTE.
1.2 Goals and Objectives
The objective of Cyber TRIDENT Task Order One (1) is to provide Infrastructure and Maintenance for the evolving PCTE Platform. Cyber TRIDENT Task Order One (1) will specifically support the PCTE solution evolving infrastructure and the required maintenance of the infrastructure along with the security operations to comply with all Army and DoD regulations and policies.
2. APPLICABLE DOCUMENTS
The applicable documents listed in the Base SOW are applicable to Task Order 1. Reference Section 2 of the Base SOW for full list.
3. REQUIREMENTS
The contractor shall provide Infrastructure and Maintenance support of the PCTE capabilities.
The contractor shall deliver platform capabilities for integration, to include performing testing prior to fielding the platform. This will require such activities that include IAVA management, IT Support, Facilities, Development RCS, Production RCS, Help Desk, JDIF/SCIF Operations, License Procurement and Management, Logistics, Property Management, Risk Management Framework (RMF)across the PCTE RCS fleet. The contractor shall provide engineering, materials, equipment, testing, technical and operations support for the PCTE as described in this Task Order (TO) One (1) SOW. The work scope of TO 1 shall be managed and tracked within the visibility and construct of the TO 2 established agile ceremonies.
3.1 Program Management
The contractor shall provide the overall management and administrative effort necessary to ensure that the requirements of this TO are accomplished. The contractor shall track TO progress and deliverables, utilizing data driven metrics to inform the Government of the TO status. The contractor shall participate, contribute, and execute as an attendee in the TO hosted agile ceremonies, design reviews, product demonstrations, Integrated Product Team (IPT) meetings, partnering, transition meetings, conferences, installations, post installation assessments, and life cycle planning of current and future systems/software releases.
3.1.1 Monthly Report
The contractor shall submit a Contractor’s Progress and Status Report that provides information to include but not limited to schedules, accomplishments, metrics, risks, issues, problems, and deficiencies related to this TO’s activities. The monthly report shall include, but not be limited to, status on the below requirements. The contractor shall propose additional metrics to better inform the Government on TO status.
• Property Management – the contractor shall identify all new contractor acquired property (CAP) in support of the infrastructure and maintenance and changes to government property inventory (attachment 9) and government furnished property inventory (attachment 10) occurring during month of performance.
• Software Licensing Management – the contractor shall report the purchases, updates and expiration of all software licenses occurring during month of performance.
• Help Desk Metrics – the contractor shall provide metrics on Tier 3 technical support provided during month of support IAW Trouble Ticketing/Problem Reporting Plan
(CDRL B102)
• Infrastructure Availability and Uptime Metrics - the contractor shall provide the availability of the PCTE infrastructure (all RCS nodes) IAW Section 3.2.1 calculated on a monthly basis.
CDRL Number CDRL Name CDRL A101 Contractor’s Progress and Status Report, DI-MGMT- 81928
3.1.2 Associate Contractor Agreements (ACAs)
The contractor shall implement ACAs with other PCTE and third-party contractors as required for exchanging data, accessing and using third party software and equipment, receiving technical support, working interface and integration issues, and DoD cyber user event planning and execution. The contractor shall ensure that ACAs are maintained to achieve development of the platform and maintain PCTE interoperability and event planning and execution, as applicable.
ACAs shall provide for and permit the complete and unbiased exchange of technical information and data relating to PCTE integration, development and deployment. Agreements shall be structured so that all Cyber TRIDENT and PCTE contractors are obligated to protect proprietary data and classified information from all unauthorized use or disclosure. ACAs shall be submitted to the Contracting Officer for review prior to execution.
3.1.3 Schedule
The contractor shall document the planned events and milestones, accomplishments, and activities based on supporting other active TO/DOs. The schedule shall include a detailed account of all tasks necessary to support schedule, goals, and objectives of other active TOs/DOs. The contractor shall demonstrate that schedule activities are synchronized across all other active TOs/DOs, and available for Government review.
3.1.4 Risk Management
The contractor shall promptly notify the Government of contract performance risks, issues, problems, and deficiencies. In accordance with the contractor’s risk management plan, implement risk detection and identification, assignment of risk categories, risk mitigation planning, mitigation plan implementation, corrective action, tracking of compliance, reporting of status and planning for risk abatement. The contractor shall promptly provide and execute corrective actions plans, in consultation with the Government. The contractor shall include in each Contractor’s Progress and Status Report the status of all outstanding contract performance risks, issues, problems, and deficiencies, as well as corrective actions with respect thereto.
3.1.5 Program Management Reviews (PMRs)
The contractor shall host Program TO Review quarterly (per year) to inform the Government of TO risks and issues. The contractor shall conduct Technical Interchange Meetings (TIMs) and In Progress Reviews (IPRs) as directed by the Government. The reviews shall provide a forum for IPT members to clarify the following areas of this TO to include but not limited to:
• Cybersecurity Management and Compliance
• IT Support
• Facilities
• Development RCS, Production RCS
• Logistics
The meetings shall be conducted at the contractor’s facility. PMR shall cover TO program risks and issues that can affect the entire Cyber TRIDENT portfolio, including parallel TOs/DOs-specific issues and risks as appropriate. The contractor shall post agendas and meeting minutes to established web portals or SharePoint sites.
CDRL A102 Report, Record of Meeting/Minutes, DI-ADMN-81505
3.1.6 Facilities
3.1.6.1 Contractor’s Developmental/Test Facilities
The contractor shall operate and maintain a facility that supports all PCTE (TOs/DOs), to include TO 0002 and DO 0003 operations at the Unclassified, Secret, and Top-Secret classification levels with the ability to incorporate PCTE end users to include Government and Industry. The contractor shall have Government Foreign Disclosure written approval prior to allowing Coalition partners access to any facility. The PCTE program has implemented an Agile software development methodology requiring active and daily on-site Government presence to conduct the various Agile ceremonies including daily standup meetings, weekly Architectural meetings, monthly sprint planning meetings, and release planning workshops. As a result of this active and daily Government presence and to facilitate Government testing and collaboration, the facility shall be located no more than ten (10) miles from PEO STRI at 12211 Science Dr, Orlando, FL 32826. This facility will include the Government provided PCTE RCS infrastructure to be used as a test bed for system configuration and software development to enable support of the PCTE Production and Development RCS. The facility equipment provided by the Government must be dedicated to PCTE activities and tasks.
The contractor shall provide the necessary physical space, power, cooling, and network connectivity needed to house the Government Furnished Equipment (GFE) hardware, software, and networking components (see Attachment 7). The RCS equipment includes a PCTE development RCS and the facility shall be able to support the build out of RCS configurations.
The contractor shall provide physical space, power and Heating, Ventilation, Air Conditioning (HVAC) in accordance with specifications (see Attachment 7, (e)). The contractor shall provide connectivity to the equipment with appropriate bandwidth to support PCTE’s RCS fleet across multiple classification levels.
The contractor Facility Security Officer/Contractor Special Security Officer (FSO/CSSO) shall ensure that all prime and subcontractor personnel comply with the Government security policies and procedures outlined in the Department of Defense Contract Security Classification Specification DD 254 and its attachments for Base SOW and TO 1.
The contractor shall provide and manage an integration factory which includes but is not limited to a collaborative meeting space, development environment (i.e., Remote, Compute, and Storage), and tools at an unclassified level. The collaborative meeting space at an unclassified level shall include but not be limited to the following features:
• A core meeting space that supports as least one hundred (100) participants for conducting Agile Ceremonies, traditional Government Ceremonies, and any other ceremonies/meetings required by the contractor’s Agile system engineering process.
• At least five (5) break-out rooms that accommodate at least twenty (20) participants per room.
• Video and audio teleconferencing tools for remote participants in each space / room.
• Video projection system in each space / room.
• Internet and power access for attendees in each space / room.
• Audio system and microphones for projecting participants voice in each meeting space / room.
• Whiteboards and office supplies in each space/room to support Agile Ceremonies, traditional Government Ceremonies, and any other ceremonies/meetings required by the contractor’s Agile system engineering process.
3.1.6.2 Sensitive Compartmented Information Facility (SCIF)
The contractor shall create a Co-use (CUA) agreement to utilize the Government provided SCIF until the contractor provided SCIF is completed and accredited. Upon completion of the contactor provided accredited SCIF, the contractor shall operate and maintain the SCIF at the contractor facility as required to maintain accreditation. See Base Contract SOW, Section 3.1.9.2 for details on SCIF configuration requirements.
3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions (CHESS) Program The contractor shall procure hardware, software, and licensing to support the TO 1 activities to include infrastructure and maintenance related procurements. The contractor shall comply with the Army’s CHESS program when making procurements. Under Program Executive Office Enterprise Information Systems (PEO EIS), CHESS is the mandatory source for commercial Information Technology (IT) purchases. CHESS contracts provide IT products and services that comply with U. S. Army Network Enterprise Technology Command (NETCOM), Army and DoD policy and standards. Purchasers of commercial hardware and software must satisfy IT requirements by utilizing CHESS contracts and DoD Enterprise Software Initiative agreements first, regardless of dollar value. Any purchase made outside of CHESS contracts requires a waiver. A complete list of CHESS contracts and the on-line waiver process can be found at:
https://protectus.mimecast.com/s/yDPLCR6K3OIrGJ7iqywOR?domain=chess.army.mil https://protectus.mimecast.com/s/yDPLCR6K3OIrGJ7iqywOR?domain=chess.army.mil
3.2 Operations
The contractor shall manage PCTE platform operations to ensure a system availability for a high quality, persistent user experience. The work tasks described in this TO are intended to address the core functionalities of capability operations. The contractor shall perform all of the required tasks necessary to ensure the continued functions to support the capability. PCTE will be located at a number of sites enabling cyber range transport capabilities and existing emulated network environments (maneuver areas). The current PCTE sites include:
1. Fort Gordon, GA
2. Ft. Meade, MD
3. Suffolk, VA
4. Joint Base San Antonio, TX
5. Oahu, HI
6. Orlando, FL
3.2.1 PCTE Maintenance and Support
The contractor shall manage the maintenance for PCTE infrastructure (all RCS nodes). This includes but is not limited to the following:
• Shall provide a 95% availability of the PCTE infrastructure calculated on a monthly basis. The 95% availability shall be measured against each RCS individually. The availability time is 24 hours a day, 7 days a week. Unavailability of RCS fielded facilities, networks connectivity, or awaiting Government provided replacement parts is deleted from the platform availability time.
• Coordinate with Government site representatives to facilitate PCTE release deployment schedule and maintenance tasks to not impact PCTE operations
• Assist, maintain, and update Memorandums of Agreement (MOAs) and Inter-Agency Service Agreements (ISAs)
• Perform on-going test and performance validation of the PCTE RCS at designated sites
• Activate and perform ongoing maintenance and monitoring of RCS nodes in accordance with Program Management Office Technical Operations Management (TOM) guidelines to maintain availability of the system
• Regularly apply software patches and updates for any COTS/GOTS products utilized on the PCTE RCS platform
The contractor shall provide on-site maintenance for the PCTE platform for all equipment listed in Attachment 9 and 10 of the Base contract. The contractor shall maintain RCS nodes in a variety of security enclaves. This includes but is not limited to unclassified, secret, and TS/SCI.
The contractor shall develop, maintain, and plan technical patches of the platform for the RCS software, hardware, and network configuration.
CDRL B101 Maintenance Plan, DI-MISC-80711A
3.2.2 Infrastructure Tier 3 Technical Support
PCTE has a multi-tier support structure that is enabled through the Tier 0-3 levels. Tier 0 is the unit providing initial support. Tier 1 is Government provided through the Joint Cyber Training Enterprise (JCTE). Tier 2 is PCTE PM supported. Tier 3 is the Cyber TRIDENT contractor for PCTE Infrastructure related trouble tickets and the PCTE CIC vendors are responsible to cyber training platform software related trouble tickets.
The contractor shall design and implement a Tier 3 Technical Support capability to provide support for escalated PCTE platform and infrastructure related trouble tickets as coordinated from Tier 2. The contractor shall provide technical and subject matter expertise that matches the current baseline and future updated capabilities of PCTE to diagnose and resolve problems identified by Tier 2 and documented in trouble tickets. Tier 3 Technical Support includes resolution of infrastructure problems such as connectivity, diagnostics, interface problems, and performance-related problems. The contractor shall have 24 hours from the point of Tier 3 notification of a trouble ticket to resolve the action. The Tier 3 Technical Support function provides Tier 2 point of access to request help in identification and resolution of enterprise application infrastructure-related problems. The Tier 3 Technical Support function shall maintain support communications through a phone line, dedicated email address, channels on the PCTE platform’s onboard chat capability, and leverage the existing enterprise-wide Trouble Ticketing/Problem Reporting System (TTPRS) accessible from the PCTE platform. The Tier 3 Technical Support shall be staffed in order to provide customer support 24 hours a day, seven (7) days a week. The contractor should document the procedures for handling trouble tickets at multiple levels of classification.
CDRL B102 Trouble Ticketing/Problem Reporting Plan, DI-MISC-80711A
3.3 Cybersecurity
The contractor shall adhere to the PCTE approved type accreditation. The contractor shall monitor the accreditation compliance of cybersecurity at a number of classification levels and environments to include Closed, Restricted Networks (CRNs), Secret Internet Protocol (IP) Router (SIPRNET), Non-Classified IP Router (NIPRNET), and Top Secret/Sensitive Compartmented Information (SCI).
The Contractor shall monitor accreditation compliance of the Army Best business Practices Federal Information System Management Act (FISMA) security requirements, Appendix II of OMB A-130, to include the configuration of systems to Security Technical Implementation Guides (STIGs) compliance, patch management, Information Assurance Vulnerability Management (IAVM), AR 380-5, National Security Telecommunications and Information Systems Security Policy (NSTISSP), No. 11 with revisions, “ National Policy Governing the Acquisition of Information Assurance (IA) and IA-enabled Information Technology Product,” DoDI 8500.01, and must be compliant with all NETCOM Tactics Techniques Plans (TTPs) which can be found at Risk Management Framework (RMF) Knowledge website cyclical support to remediate or mitigate know critical issues, and other Information Assurance functions.
1. The contractor shall also ensure that the software, components, and services maintained within PCTE are in accordance with DISA STIG compliance. The contractor shall monitor the DISA STIGs implementation for the IT technology developed and configuration manage the TO 2 completed STIG checklists to enforce compliance.
2. The contractor shall ensure compliance of the Cybersecurity/RMF process to guide management and design actions, document RMF decisions and certification efforts, specify and track RMF requirements, identify possible Cybersecurity solutions, synchronize RMF with CM activities, and maintain operational systems security.
3. The contractor shall conduct assessments of the PCTE supporting infrastructure for security vulnerabilities and weaknesses. The contractor shall report and ensure compliance with protective measures in accordance with the PCTE accreditation to address identified vulnerabilities and weaknesses to the Government.
4. The contractor shall continually evaluate the security of the system, both physical and logical, identifying exposures and providing protective options for reducing security risk.
5. The contractor shall ensure protective measures are maintained to provide Information Security. When Classified or Controlled information is introduced into the PCTE, the contractor shall adhere to the provisions within AR 380-5 regarding the classification, transmission, transportation, and safeguarding of this information. Cryptography shall be Federal Information Processing Standards (FIPS) 140-2 compliant. There shall be a mechanism established to ensure encrypted data can be recovered in the event the primary encryption system fails.
6. The contractor shall maintain protective mechanisms into the system and applications to provide identification and authentication, access control, accountability, availability, confidentiality, privacy, data integrity, and non-repudiation.
7. The contractor shall use Government approved assessment tools to perform cyber security testing to document, verify, and validate each applicable operating system security configuration.
8. The contractor shall provide input into the documentation of the unincorporated security controls defined in the applicable STIG and unincorporated IAVA’s in the Plan of Action and Milestones (POA&M) document to ensure future compliance with the ATO is maintained.
3.3.1 Risk Management Framework (RMF)
The Contractor shall maintain the current PCTE RMF accreditation and perform reaccreditation tasks at the time of recertification. The Contractor shall adhere and ensure compliance with the RMF documentation and participate in the necessary milestones to include, but not limited to, the System Registration Review (SRR), System Security Plan (SSP), System Contingency Plan
(SCP), System Configuration Management Plan (SCMP), systems Plan of Action and Milestones (POA&M), Information Assurance Vulnerability Alert (IAVA) Reports, STIG Deviation Reports, STIG Checklists, Accreditation and Data Flow Boundaries, Software and Hardware Lists for each system configuration.
The Contractor shall ensure the system remains in a configuration compliant with the current type accreditation Authority to Operate (ATO) certification to the RMF Confidentiality, Integrity, and Availability (CIA) and Certification Level (CL) of all levels at moderate. The contractor shall report any ATO waivers or deviations to the PM through the Configuration Management process.
The Contractor shall support Assessment and Authorization associated activities to use a third-party validator to scan the system for IA vulnerabilities. The Contractor shall provide Cybersecurity Subject Matter Expertise (SME) to support the annual review of each accredited system/sub-system’s IA controls according to Federal Information Security Management Act (FISMA) guidance in conjunction with the Information Systems Security Officer (ISSO) and the Information System Security Manager (ISSM) and /or PEO STRI IA designee. The Contractor shall conduct quarterly IA scans on Government Furnished Equipment (GFE) and provide to the Government as part of the annual review.
The Contractor shall follow production specification and evaluation requirements of the National Institute of Standards and Technology (NIST), Special Publications (SP) 800.53 Security and Privacy Controls for Federal Information Systems and Organizations, Committee on National Security Systems Instruction (CNSSI) 4009, CNSS, Glossary, Common Criteria, and National Information Assurance Partnership (NIAP) Approved Product List (APL). All incorporated IA products, and IA-enabled IT products that require use of the product’s IA capabilities, acquired under the contract, shall comply with the National Telecommunications and Information Systems Security Policy (NTSISSP) No. 11 “National Policy Governing Acquisition Assurance (IA) and IA-enabled Technology Product.”
3.3.1.1 Cyber Reports and Tasks Schedules
The Contractor shall complete the following requirements and report:
• Quarterly Reports o IAVA Reports o Vulnerability Scan Reports
ACAS/Nessus Scans SCAP Scan Reports on all COTS Software and Hardware STIG Checklists STIG Deviation Reports Software Security Reports for any developmental software Updated Configuration Drawings Updated Software and Hardware Reports
POA&M
• FISMA Annual Review Report o ACAS/Nessus Scans o SCAP Scan Reports on all COTS Software and Hardware o STIG Checklists o STIG Deviation Reports o Software Security Reports for any developmental software o Updated Configuration Drawings o Updated Software and Hardware Reports o POA&M
3.3.1.2 Cyber Technical and Meeting Support
The cybersecurity team should be integrated in the agile ceremonies and shall attend and support various meetings to include, but not limited to:
• Integrated Product Team (IPT) Meetings
• Program Management Reviews (PMR’s)
• System Testing and/or Integration Events
• Technical Interchange Meetings (TIM)
• Training Events
• Cyber Meetings
• Configuration Management Board Meetings
3.3.2 Army Training and Certification Tracking System (ATCTS) Training The Contractor shall require that lead and support personnel performing Cybersecurity job functions possess the Information Assurance Management (IAM) or Information Assurance Technical (IAT) certification relevant to their role within the execution of this contract and IAW DoDD 8140.01, DoD 8570.01-M, AR 25-2 (4-3 Information Assurance Training), and Army BBP 05-PR-M-002. IA engineers, analysts, and technicians shall complete the required “IA Awareness Training.” Method of training for “IA Awareness training” is https://cs.signal.army.mil/default.asp “DoD Cyber Awareness Mandatory IA Training,” The Contractor’s IA Team shall complete the required “Information Assurance Fundamentals Training.”
1. This shall include the methods, skills, use, and mechanisms to maintain the level of security of the IS.
2. The training shall be geared toward the audience and their roles and responsibilities with respect to the system’s operation and maintenance (i.e., system administrator, network administrator, hardware maintenance, etc.).
https://cs.signal.army.mil/default.asp
3. The contractor shall utilize DOD 8570.01-M as a guide in the development of the IA Training content.
3.3.3 OPSEC
The contractor shall ensure this TO is in compliance with the base contract existing OPSEC Plan and Standing Operating Procedure/plan within ninety (60) calendar days of TO award making any necessary updates, to be reviewed and approved by the responsible Government OPSEC officer. The plan’s updates shall include a process to identify Critical Information List (CIL), where it is located, who is responsible for it, how to protect it, and why it needs to be protected in accordance with Security Classification Guides (SCGs). The contractor shall implement OPSEC measures as ordered by the Government. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.
3.3.3.1 Requirements for OPSEC Training
Per AR 530-1, Operations Security, new contractor employees must complete Level I OPSEC training within thirty (30) calendar days of their reporting for duty. The contractor shall ensure all applicable employees have completed OPSEC initial training, annual refresher training, and shall certify their work force has completed the training through the submission of completion certificates(s) to the COR, or the Contracting Officer when a COR is not assigned, within thirty
(30) days of arrival on the installation. OSPEC training can be accomplished at the Defense Security Services website at: https://securityawareness.usalearning.gov/opsec/
3.3.3.2 Anti-Terrorist Training (AT Level 1)
All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete AT Level I awareness training within thirty (30) calendar days after TO start date or effective date of incorporation of this requirement into the TO, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the Contracting Officer within 30 calendar days after completion of training by all contractor employees and subcontractor personnel. AT Level I awareness training is available at the following website: https://atlevel1.dtic.mil/at or other Service specific websites.
The contractor shall ensure all US based Contractor employees and associated subcontractor employees to make available and to receive Government provided area of responsibility (AOR) specific AT awareness training as directed by applicable DoD, Service policy and regulations.
Specific AOR training content is directed by the Combatant Commander with the unit Anti- Terrorism Officer (ATO) being the local point of contact.
3.3.3.3 Active Shooter Training
All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete active shooter training as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after https://protect-us.mimecast.com/s/10sqC4xvMQuBVRwfNKr6z?domain=securityawareness.usalearning.gov https://protect-us.mimecast.com/s/KTyvC5ywNQFZJwrT4smug?domain=atlevel1.dtic.mil
TO start date or effective date of incorporation of this requirement into the TO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel.
3.3.3.4 Access to Government Information Systems
All contractor employees with access to a Government Information System must be registered in the applicable Service training and certification system at commencement of TO performance and must successfully complete DoD Information Assurance Awareness training prior to being granted access to information systems (IS) and then annually thereafter.
3.3.3.5 Professional Training and Certification
The contractor shall be responsible to ensure that employees, to include subcontractor employees, at all times maintain the required professional training and certifications required for their job description(s) and role(s).
Per DoD 8570.01-M, DoDD 8140.01, Defense Federal Acquisition Regulation Supplement (DFARS) 252.239.7001 and applicable Service regulations, the contractor employees supporting Cybersecurity/IT functions shall be appropriately certified upon TO award. The baseline certifications as stipulated in DoD 8570.01-M for specific positions shall be completed upon TO award.
3.3.3.6 Personal Identifiable Information (PII)
All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete training in the handling and protection of PII as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after TO start date or effective date of incorporation of this requirement into the TO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel. PII training is available at https://securityawareness.usalearning.gov/piiv2.
3.3.3.7 Security and Access Controls
3.3.3.7.1 General Security
The contractor Facility Security Officer/Contractor Special Security Officer (FSO/CSSO) shall ensure that all prime and subcontractor personnel comply with the Government security policies and procedures outlined in the Department of Defense Contract Security Classification Specification DD 254 and its attachments for this contract.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .