Attachment_0001_-_Performance_Work_Statement.pdf
PDF 4 MB Posted
- Attached to
- Standard Army Ammunition System (SAAS) Federal contract opportunity
- Solicitation number
- W52P1J-16-R-0161
About this file
Attachment 0001 Performance Work Statement Dated 09 Nov 2017
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| W52P1J16R0161_Amendment_0003_Signed.pdf | ||
| Attachment_0011_Request_for_Proposal_Questions_with_Answers.pdf | ||
| W52P1J16R0161_0002.pdf | ||
| Attachment_0010_Request_for_Proposal_Questions_with_Answers_Clarifications.pdf | ||
| Attachment_0008_Pricing_Matrix.xlsx | XLSX spreadsheet | |
| W52P1J-16-R-0161_0001.pdf | ||
| Attachment_0009_Request_for_Proposal_Questions_with_Answers.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement (PWS)
Post Production Software Support (PPSS) Standard Army Ammunition System (SAAS)
Product Lead Logistics Information Systems (PL LIS)
09 November 2017
TABLE OF CONTENTS
1.0 DESCRIPTION
1.1 SCOPE
1.2 ORDER TYPE
1.3 PERIOD OF PERFORMANCE
1.4 PLACE OF PERFORMANCE
2.0 APPLICABLE DOCUMENTS AND WEBSITES
3.0 REQUIREMENTS
3.1 GENERAL
3.1.1 Hours of Work
3.1.2 Tier 2 and Tier 3 Customer Support Hours
3.1.3 Government Holidays
3.1.4 Telework
3.1.5 Government Furnished Materials/Equipment/Property (GFM/GFE/GFP)
3.1.6 Inspection and Acceptance / FOB
3.1.7 Security/Access Requirements
3.1.8 Code Development/Software Policy Compliance
3.2 PERFORMANCE
3.2.1 Technical Support for SAAS and Future Change Packages
3.2.2 SAAS Functional and Subject Matter Expert (SME) for SAAS and All Future Change Packages
3.2.3 Customer Support for SAAS and Future Change Packages
3.2.4 Training Support for SAAS and Future Change Packages
3.2.5 Administrative Support for SAAS and all Future Change Packages
3.2.6 Test and Evaluation Support for SAAS and all Future Change Packages
3.2.7 Configuration Management
3.2.8 Information Assurance (Cyber Security) and Software Assurance Support
3.2.9 Miscellaneous Support
3.2.10 Auditability and Compliance
4.0 CONTRACT MANAGEMENT
4.1 GENERAL
4.2 PLANS, REPORTS AND MEETINGS
4.2.1 Project Management Plan (PMP)
4.2.2 Monthly Reports
4.2.3 Meetings
4.3 CONTRACTOR MANDATORY TRAINING
4.4 TRANSITION PLAN - PHASE IN/PHASE OUT
4.5 TRAVEL
4.5.1 OCONUS Travel
4.5.2 Travel to Germany
4.5.3 Travel to the Republic of Korea
4.5.4 Inoculations for Foreign Travel
4.5.5 Trip Report
4.6 PERSONNEL QUALIFICATIONS AND KEY PERSONNEL
4.6.1 Personnel
4.6.2 Resume Verification
4.6.3 Information Assurance Accreditation
4.6.4 Key Personnel
4.7 CONTRACTOR MANPOWER REPORTING (CMR)
4.8 QUALITY CONTROL
5.0 DELIVERABLES
TABLE OF CONTENTS
6.0 SECTION 508 COMPLIANCE
APPENDIX A– SAAS SYSTEM DESCRIPTIONS, HARDWARE AND OPERATING SYSTEM ENVIRONMENTS AND
INTERFACE PARTNERS
APPENDIX B - GFM/GFE LISTING
APPENDIX C – PERSONNEL QUALIFICATIONS WITH KEY PERSONNEL
APPENDIX D - SAAS ESTIMATED TRAVEL SUMMARY FOR EACH PERIOD OF PERFORMANCE
APPENDIX E – LIS SOP - TEST MANAGEMENT PROCESSES FOR SOFTWARE INTEGRATION LABORATORY (SIL)
APPENDIX F – PEO EIS POLICY MEMORANDUM #12-65, SOFTWARE CODE REVIEWS (SCR), 05 JUN 2012
APPENDIX G – HQDA EXORD 144-16
APPENDIX H – PL LIS CONFIGURATION MANAGEMENT PLAN
APPENDIX I – PL LIS CYBERSECURITY PROGRAM ISCM STRATEGY
APPENDIX J – PEO EIS POLICY MEMORANDUM #13-11, PEO EIS INFORMATION ASSURANCE (IA) PLAN OF ACTION
& MILESTONES (POA&M) PROCESS
APPENDIX K – PM AESIP RISK AND ISSUE MANAGEMENT POLICY
APPENDIX L – PL LIS PRIVACY PROGRAM
Performance Work Statement (PWS)
Post Production Software Support (PPSS) Standard Army Ammunition System (SAAS)
1.0 Description
The Product Lead Logistics Information Systems (PL LIS) requires Post Production Software Support (PPSS) for the Standard Army Ammunition System (SAAS) project. The contractor shall be responsible for the support of SAAS.
1.1 Scope
The contractor shall provide labor, supplies, materials and equipment (including software development) necessary to support the Government’s efforts to keep the SAAS system stable and operational for Department of Army (DA)-wide users. The support services provided under this PWS shall include, but are not limited to SAAS Technical Support, Functional and Subject Matter Expert Support, Customer Support, Training Support, Administrative Support, Data Migration, Testing and Evaluation Support, Configuration Management, Validation & Verification, Cyber Security and Information Assurance (IA), Miscellaneous Support, and System Enhancements.
A complete description of the SAAS system, its hardware and operating system (OS) environments and interface partners is provided at Appendix A.
The work requirements shall also include activities related to project management, quality assurance, database management, configuration management, technical research and analysis, system documentation, database administration, and operation and maintenance.
The Contractor shall comply and keep current with the appropriate Department of Defense (DoD) Services, and Army architectures, programs, policies, standards and guidelines (e.g., Security Technical Implementation Guide (STIG), Net-Centric Enterprise Services, Defense and Information Systems Network.
1.2 Order Type
This contract is a Cost-Plus-Fixed-Fee Term basis for labor. Any necessary Other Direct Costs (travel, material, equipment, licenses, etc.) shall be performed on a Cost basis (no fee).
1.3 Period of Performance
The period of performance shall be a one (1) twelve-month base period with four (4) 12-month option periods.
1.4 Place of Performance
1.4.1 Primary place of performance shall take place at the contractor’s facility. The contractor’s facility shall be within 35 miles of Fort Lee, VA. The contractor shall be required to support the deployed system at both Contiguous United States (CONUS) and Outside Contiguous United States (OCONUS) locations on a temporary basis.
2.0 Applicable Documents and Websites
The following documents are referenced for the performance of this effort. All work under this contract shall comply with the latest version of all applicable standards. The contractor shall obtain the most current versions of documentation listed and any new documentation as required. The Government reserves the right to add additional documents that may be applicable to this contract.
GOVERNING
Reference Title Source
DODI 5200.02, CH 1 DoD Personnel Security Program
(PSP)
https://dap.dau.mil/policy/ Lists/Policy%20Documen ts/DispForm.aspx?ID=41
DODI 6055.16 Explosives Safety Management Program http://dtic.mil/whs/directiv es/corres/ins1.html
DoD 8570.01-M Information Assurance Workforce Improvement Program http://dtic.mil/whs/directiv es/corres/pub1.html
DoDI 8500.01 Cybersecurity http://dtic.mil/whs/directiv es/corres/ins1.html
DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT) http://dtic.mil/whs/directiv es/corres/ins1.html
AR 73-1 Test and Evaluation https://armypubs.army.mi l/ProductMaps/PubForm/ AR.aspx
AR 25-1 Army Information Technology https://armypubs.army.mi l/ProductMaps/PubForm/ AR.aspx
AR 25-2 Information Assurance https://armypubs.army.mi l/ProductMaps/PubForm/ AR.aspx
AR 710-2
Supply Policy Below the National Level https://armypubs.army.mi l/ProductMaps/PubForm/ AR.aspx
AR 735-5 Property Accountability Policies https://armypubs.army.mi l/ProductMaps/PubForm/ AR.aspx
AR 380-67 Personnel Security Program https://armypubs.army.mi l/ProductMaps/PubForm/ AR.aspx
DA PAM 750-8 The Army Maintenance Management System (TAMMS) User’s Manual https://armypubs.army.mi l/ProductMaps/PubForm/ PAM.aspx
DA PAM 710-2-2,
Chapters 24-43
Supply Support Activity Supply System:
Manual Procedures https://armypubs.army.mi l/ProductMaps/PubForm/ PAM.aspx
DA PAM 385-64
Ammunition and Explosive Safety Standards https://armypubs.army.mi l/ProductMaps/PubForm/ PAM.aspx
HQDA EXORD 144-16 Standard Army Ammunition system (SAAS) Software Change Package
(SCP) L6F-11-00
Appendix G
ATP 4-35.1 Ammunition and Explosives Handler Safety Techniques https://armypubs.army.mi l/ProductMaps/PubForm/ ATP.aspx
CIO/G6
Memoranda
Army Golden Master (AGM) as the Standard Source for Common Operating System Baseline Configurations http://ciog6.army.mil/Poli cyLegislation/tabid/64/De fault.aspx
IEEE 828-2012
IEEE Standard for Configuration Management in Systems and Software Engineering http://standards.ieee.org/
CMMI Industry Standards for Capability Maturity Model – Integration (CMMI) & Models http://resources.sei.cmu.e du/library/
Website Enterprise Mission Assurance Support Service https://emass-army.csd.disa.mil/
MIL- HDBK- 61A (SE) Configuration Management Guidance https://acc.dau.mil/Comm unityBrowser.aspx?id=142
Website DISA Portal for Security Technical Information http://iase.disa.mil/Pages/i ndex.aspx
Homeland Security Presidential Directive-
12 (HSPD-12)
Policy for a Common Identification Standard for Federal Employees and Contractors.
http://www.dhs.gov/xabo ut/laws/gc_12176166240 97.shtm#1
PEO EIS/PM AESIP/PL LIS
PL LIS SOP
Logistics Information Systems Test Management Processes for Software Integration Laboratory (SIL), Ver 1.0, 15 Apr 2017
Appendix E
PEO EIS Policy Memorandum #12-65
PEO EIS Software Code Reviews (SCR), 5 Jun 2012
Appendix F
PL LIS Policy Configuration Management Appendix H
PL LIS Policy
Cybersecurity, Cybersecurity Program, and the Information Security Continuous Monitoring, Interim System- Level Strategy, 7 Apr 17
Appendix I
PEO EIS Policy Memorandum #13-11
Information Assurance (IA) Plan of Action and Milestones (POAM) Process Appendix J
PM AESIP Policy PM AESIP Risk Management Policy, Jan 14 Appendix K
PL LIS Policy
PL LIS Privacy Program
Appendix L https://armypubs.army.mil/ProductMaps/PubForm/PAM.aspx https://armypubs.army.mil/ProductMaps/PubForm/PAM.aspx https://armypubs.army.mil/ProductMaps/PubForm/PAM.aspx https://armypubs.army.mil/ProductMaps/PubForm/ATP.aspx https://armypubs.army.mil/ProductMaps/PubForm/ATP.aspx https://armypubs.army.mil/ProductMaps/PubForm/ATP.aspx http://ciog6.army.mil/PolicyLegislation/tabid/64/Default.aspx http://ciog6.army.mil/PolicyLegislation/tabid/64/Default.aspx http://ciog6.army.mil/PolicyLegislation/tabid/64/Default.aspx http://standards.ieee.org/ http://resources.sei.cmu.edu/library/ http://resources.sei.cmu.edu/library/ https://acc.dau.mil/CommunityBrowser.aspx?id=142238 https://acc.dau.mil/CommunityBrowser.aspx?id=142238 https://acc.dau.mil/CommunityBrowser.aspx?id=142238 http://iase.disa.mil/Pages/index.aspx http://iase.disa.mil/Pages/index.aspx http://www.dhs.gov/xabout/laws/gc_1217616624097.shtm#1 http://www.dhs.gov/xabout/laws/gc_1217616624097.shtm#1 http://www.dhs.gov/xabout/laws/gc_1217616624097.shtm#1
Federal Information Processing Standards (FIPS) Publications
FIPS 199
Standards for Security Categorization of Federal Information and Information Systems http://csrc.nist.gov/public ations/PubsFIPS.html
FIPS 200
Minimum Security Requirements for Federal Information and Information Systems http://csrc.nist.gov/public ations/PubsFIPS.html
NIST Special Publications (SP)
SP 800-18 Rev. 1 Guide for Developing Security Plans for
Federal Information Systems http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-30 Rev. 1 Guide for Conducting Risk
Assessments http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-34 Rev. 1 Contingency Planning Guide for
Federal Information Systems http://csrc.nist.gov/public ations/PubsSPs.html SP 800-37 Rev. 1 Guide for Applying the Risk
Management Framework to Federal Information Systems: a Security Life Cycle Approach http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-39
Managing Information Security Risk:
Organization, Mission, and Information System View http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-53 Rev. 4 Security and Privacy Controls for Federal Information Systems and Organizations http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-53A Rev. 4
Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-59
Guideline for Identifying an Information System as a National Security System http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-60 Vol. 1 Rev. 1 Guide for Mapping Types of Information and Information Systems to Security Categories http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-60 Vol. 2 Rev. 1 Guide for Mapping Types of Information and Information Systems to Security Categories: Appendices http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-61 Rev. 2 Computer Security Incident Handling Guide http://csrc.nist.gov/public ations/PubsSPs.html
SP 800-137 Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations http://csrc.nist.gov/public ations/PubsSPs.html
Committee on National Security Systems (CDSS) Publications
CNSSP 22 Cybersecurity Risk Management Policy https://www.cnss.gov/CN SS/issuances/Policies.cf m
CNSSI 1253
Security Categorization and Control Selection for National Security Systems https://www.cnss.gov/CN SS/issuances/instruction s.cfm http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html http://csrc.nist.gov/publications/PubsSPs.html
CNSSI 4009 Committee on National Security Systems (CNSS) Glossary https://www.cnss.gov/CN SS/issuances/instruction s.cfm
Intelligence Community (IC) Publications
ICD 503
Intelligence Community Information Technology Systems Security Risk Management, Certification & Accreditation https://www.dni.gov/files/ documents/ICD/ICD_503 .pdf
Unless stated otherwise all documents are located at www.dtic.mil. Documents citing secure location will be provided after contract award.
3.0 Requirements
3.1 General
The Contractor shall conduct itself in a cooperative manner with the Government and other Government Contractors in the execution of its responsibilities. Except for those items specifically stated as Government furnished, the Contractor shall furnish everything needed to perform this contract. In the absence of specific contract requirements, the Contractor shall use the software development industry standards and industry best practices for providing the products and services required by the contract. The Contractor shall optimize the various development, operations, and maintenance activities across the SAAS Portfolio.
The contractor shall ensure the software development and sustainment tasks listed are properly managed in accordance with (IAW) industry and Government best practices. The Contractor shall cultivate a business environment that encourages continuous and measurable process improvements for the PL LIS SAAS portfolio. The contractor shall have the capability to adapt their standard organization processes to maximize the efficiencies of the SAAS System portfolio.
3.1.1 Hours of Work. The Contractor is responsible for conducting normal business, between the hours of 0800 and 1700 Eastern Time (ET), Monday through Friday, except Federal holidays. Business hours may be adjusted with prior Contracting Officer (KO)/Contracting Officer’s Representative (COR) approval. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS.
Contractor employee’s compensation for time off due to inclement weather is solely at the contractor’s discretion; however, the contractor shall not bill the Government for such time off as direct labor cost.
3.1.2 Tier 2 and Tier 3 Customer Support Hours. Tier 2 support shall be provided from 0600 to 2200 ET, Monday through Friday. Tier 3 support shall be provided from 0800 to 1700 ET, Monday through Friday. Tier 2 and Tier 3 may be reduced to minimal staffing during Government holiday periods and inclement weather. Minimal staffing is defined as follows: Tier 2 and Tier 3 must have at least one person between the hours of 0800 and 1700 Monday through Friday.
3.1.3 Government Holidays. In the case of on-site personnel, the contractor shall adhere to Government holidays. During holidays, emergency or reduced hours, the workers will have limited access to the Government facility.
http://www.dtic.mil/
3.1.4 Telework. All telework must be IAW Government IA practices and protocols. The contractor shall provide a copy of company telework policy IAW Contract Data Requirements List (CDRL) A001 to the Government for the purpose of assuring the Government those procedures are in place.
Deliverable:
Company Telework Policy, CDRL A001, DI-MISC-80508B
3.1.5 Government Furnished Materials/Equipment/Property (GFM/GFE/GFP)
3.1.5.1 Government Furnished Materials (GFM). The Government will provide all SAAS deliverables resulting from the existing SAAS contract (W15P7T-14-C-E008). A GFM listing is provided at Appendix B.
3.1.5.2 Government Furnished Equipment (GFE). The Government will provide the Contractor with equipment necessary for software development and contractor-level (Tier 1 and Tier 2) testing of SAAS. The Government furnished SAAS equipment will be representative of equipment currently issued and in use by field units. This GFE will consist of SAAS development equipment, and fielded SAAS equipment. A GFE listing is provided at Appendix B.
All GFM/GFE/GFP will be issued using DoD Form 1149, Requisition, and Invoice/Shipping Document. All GFM/GFE/GFP not consumed or expended during contract performance shall be returned to the Government upon completion of this contract using DOD Form 1149.
A 100% inventory will be conducted each quarter in conjunction with the COR. A status report will be provided at the conclusion of each inventory.
3.1.5.3 Hardware and/or Software Purchases. The Government may require the contractor to purchase hardware, software, and related supplies to support specific projects in performance of this PWS. Once a requirement for procurement is identified, the contractor shall submit a request to the Government for approval to purchase. The request shall include the purpose, specific items, direct cost, and rationale. For Information Technology (IT) purchases the contractor shall use the Computer Hardware, Enterprise Software and Solutions (CHESS) as the primary source for procuring commercial IT Hardware and Software, IAW Army Federal Acquisition Regulation Supplement 5139.101 and Secretary of the Army Memorandum, Army Waiver Process for Commercial Off-the-Shelf (COTS) Information Technology Procurement outside the CHESS Program, 06 July 2013. If the purchase requirement is not available through CHESS, the contractor shall obtain a Statement of Non-Availability from the CHESS web site at https://chess.army.mil and then request an ITAS waiver to use non-CHESS vehicles through the CIO G6.
Warranties for all equipment/software purchased by the Contractor on behalf of the U.S.
Government must name the Government as the warrantee.
The contractor shall obtain three quotes for all purchases over the current micro-purchase threshold identified in the Federal Acquisition Regulation (FAR) and purchase the lowest quote.
The contractor shall provide all supporting documentation including waivers, quotes, and receipts to the Government, upon request.
https://chess.army.mil/
Hardware Procurements: Although this contract is targeted to provide the services as detailed in this PWS, the primary mechanism for all IT hardware procurements is through CHESS. Any hardware procured shall be compatible with current Government equipment. COR approval is required prior to any contractor purchase.
Software Procurements: IAW Defense Federal Acquisition Regulation Supplement (DFARS) 208.74, in situations where the purchase of commercial software, including preloaded software, is needed to satisfy the requirements of a particular order; requirements shall be fulfilled with the DoD Enterprise Software Initiative (ESI). When authorized by the Government, the contractor shall order from the DoD ESI sources to obtain the software to satisfy the requirement. If use of software from ESI sources is not specified initially in an order, the contractor shall coordinate with the ordering activity prior to using another source. The contractor is responsible for reviewing available DoD ESI sources. The listing of COTS software available from DoD ESI sources can be viewed on the following website: http://www.esi.mil/.
Commercial Software Licenses:
a. Commercial software and software documentation delivered under this contract shall be subject to the terms of this Mandatory Use of CHESS/ESI language and the governing commercial product license, to the extent the latter is consistent with Federal law and FAR 12.212, Computer Software. Notwithstanding the foregoing, the commercial product license shall apply only if a copy of the license is provided with the delivered product. In the event of conflict between this Mandatory Use of CHESS/ESI language and the commercial software product license, this Mandatory Use of CHESS/ESI language shall govern.
b. All software shall, as a minimum, be licensed and priced for use on a single computer or for use on any computer at a particular site.
c. The license shall be in the name of the U. S. Government.
d. The license shall be perpetual (also referred to as a nonexclusive, paid-up, worldwide license).
e. Software documentation shall be identical to that provided to a customer in the general public in the course of a private sale. The Government’s right to software documentation shall be no less than the rights provided with the associated software.
The license shall apply to any software changes or new releases.
All procurements will be on a on a cost no-fee basis. A Letter of Authorization (LOA) is required to be attached when the contractor is purchasing from CHESS. The LOA shall be issued by the KO upon request by the contractor. All applicable Government procurement processes and procedures shall be followed. All equipment, materials, and or supplies purchased by the Contractor for performing this contract and paid for by the Government is considered Contractor-Acquired Property and shall be turned over to the Government at the end of the contract.
3.1.5.4 Property Accountability. Any loss or damage to GFM/GFE/GFP shall be reported via Defense Contract Management Agency’s eTools website at http://www.dcma.mil/aboutetools/.
The contractor shall provide a quarterly Status Report of GFM/GFE/GFP.
3.1.5.5 Government Property at Government Facilities. If required, Government facilities, Government computers, equipment, and supplies will be provided to contractor personnel onsite http://www.esi.mil/ at the Ft. Lee, VA Government location and are considered incidental to that place of performance. The Contractor shall adhere to installation and facility security and access requirements.
Deliverables:
Status Report for GFM/GFE/GFP, CDRL B001, DI-MGMT-80269
3.1.6 Inspection and Acceptance / FOB
3.1.6.1 Final inspection and acceptance of all work, performance, reports, and other deliverables under this contract shall be at destination. The COR will be responsible for inspection and acceptance.
Ship to address is:
PL LIS
ATTN: SAAS Project Officer/COR 821 Lee Avenue Fort Lee, VA 23801 Department of Defense Activity Address Code (DoDAAC): W6DYG5
3.1.6.2 Scope of Inspection. All deliverables shall be delivered to the Government IAW the PWS. All deliverables will be inspected by the COR for content, completeness, accuracy, and conformance to contract requirements. Inspection may include validation of information or software through the use of automated tools and/or testing of the deliverables. The scope and nature of the testing will be sufficiently comprehensive to ensure the completeness, quality, and adequacy of all deliverables.
3.1.6.3 Basis of Acceptance. The basis for acceptance of deliverable shall be compliance with the requirements set forth in the PWS and the terms of the contract.
The Government requires a period not to exceed thirty (30) calendar days after receipt of final deliverable items for inspection and acceptance or rejection, unless otherwise specified by a written modification. Deliverable items rejected shall be corrected IAW the applicable CDRLs.
All deliverables will be accepted within thirty (30) calendar days of delivery.
Services and cost reimbursable items such as Other Direct Costs (ODCs) will be accepted upon receipt of proper documentation. For services provided under this contract, acceptance will be as specified for the tasks with which they are associated. If custom services are for software development, the final acceptance of the software program will occur when all discrepancies, errors or other deficiencies identified in writing by the Government have been resolved, either through documentation updates, program correction, or other mutually agreeable methods.
Reports, documents, and narrative type deliverables will be accepted when all discrepancies, errors or other deficiencies identified in writing by the Government have been corrected. Non-conforming products or services will be rejected. Unless otherwise agreed by the parties, deficiencies shall be corrected within 15 calendar days of the rejection notice. If the deficiencies cannot be corrected within 15 days, the Contractor shall immediately notify the COR and KO of the reason for the delay and provide a proposed corrective action plan.
3.1.7 Security/Access Requirements
3.1.7.1 Security Clearance. The highest level of facility clearance required for the contractor to perform on this contract is SECRET. The contractor will not be required to safeguard any classified material at its own facility.
The security requirements applicable to this contract are described in the DD Form 254, Contract Security Classification Specification attached as Attachment 0002 to the contract.
3.1.7.2 Access to Government Installations/Facilities/Networks/Information Systems. Contractor and all associated sub-contractors employees shall provide all information required for background checks to meet installation access requirements to be accomplished by installation Provost Marshal Office, Director of Emergency Services or Security Office. Contractor workforce must comply with all personal identity verification requirements (FAR clause 52.204- 9, Personal Identity Verification of Contractor Personnel) as directed by DoD, Headquarters, Department of the Army (HQDA) and/or local policy. In addition to the changes otherwise authorized by the changes clause of this contract, should the Force Protection Condition at any individual facility or installation change, the Government may require changes in contractor security matters or processes. The Contractor will ensure that all employees accessing SAAS data or source code shall have valid and appropriate background checks and security clearances as required. Labor categories requiring a Secret clearance or specific IA/IM privileges are identified at PWS para 4.6.4 and Appendix C.
3.1.7.2.1 Government Issued Common Access Card (CAC). For contractors requiring Common Access Card (CAC): Before CAC issuance, the contractor employee requires, at a minimum, a favorably adjudicated National Agency Check with Inquiries (NACI) or an equivalent or higher investigation in accordance with Army Directive 2014-05. The contractor employee will be issued a CAC only if duties involve one of the following: (1) Both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) Remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) Physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more. At the discretion of the sponsoring activity, an initial CAC may be issued based on a favorable review of the FBI fingerprint check and a successfully scheduled NACI at the Office of Personnel Management.
For contractors that do not require CAC, but require access to a DoD facility or installation:
Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index and Terrorist Screening Database (Army Directive 2014-05/AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.
Access to the SAAS system requires a CAC. In performance of services under this task, contractor shall insure all its personnel who require access to the SAAS system, physical access to federally controlled facilities, and access to federally controlled information systems (Government computer systems and communications networks) will have been issued identification in compliance with Homeland Security Presidential Directive-12 (HSPD-12), Policy for a Common Identification Standard for Federal Employees and Contractors. In their proposals, offerors shall confirm they will comply with the Government client's identification procedure that is implementing HSPD-12 policy.
Proof of employment and security clearance/favorable background check is required before a CAC will be issued authorizing access to the SAAS system, the Government installation, facility, and any Government computer systems. CACs may not be issued to contractors unless a data record authorizing CAC issuance is resident in the Defense Enrollment Eligibility Reporting System (DEERS). The Trusted Associate Sponsorship System (TASS) was developed as a secure and authorized means of entering Contractor data into DEERS in addition to automating the CAC application and approval process. In order to enter Contractor data into TASS, the Contractor's data must be resident in an authorized source database. The Joint Personnel Adjudication System (JPAS) is that authoritative source. The Contractor's Facility Security Office shall ensure its employee(s) has a record in JPAS prior to requesting a CAC be issued.
In all cases, the Contractor shall forward employee visit and investigation information, via the JPAS, to the PL LIS Security Officer before assignment of these individuals on this contract and shall ensure a visit request with that investigation information is provided yearly.
The Government will issue a contractor employee a CAC only if duties involve one of the following: (1) both physical access to a DoD facility and access, via logon, to DoD networks on-site or remotely; (2) remote access, via logon, to a DoD network using DoD-approved remote access procedures; or (3) physical access to multiple DoD facilities or multiple non-DoD federally controlled facilities on behalf of the DoD on a recurring basis for a period of 6 months or more.
3.1.7.2.2 Access to Ft. Lee, VA. As of 15 June 2015, Fort Lee requires a background check on everyone coming on Fort Lee who does not possess a U.S. Government CAC or Uniformed Services Identification Card. Civilian Employees issued CACs are already vetted and approved for access. All personnel without the appropriate ID must have a National Crime Information Center Interstate Identification Index background check prior to coming onto Fort Lee.
Personnel without the proper ID must go to the Visitor Control Center to request the background check in order to obtain an access pass.
3.1.7.3 Information Technology Sensitivity Level Requirements. Army Regulation (AR) 25-2 requires DoD civilian, DoD consultants, and support contractor personnel performing work on sensitive automated information systems to be assigned to positions that are designated at one of three (3) Information Assurance Technology (IAT) sensitivity levels (IAT-I, IAT-II, or IAT-III).
Labor categories requiring a specific sensitivity level are identified at PWS para 4.6.4 and Appendix C.
Figure 1 - Investigation Mapping to IT, IAT & IAM Levels
3.1.7.4 Information Assurance (IA)/Information Technology (IT) Certification. Per DoD 8570.01- M, DFARS 252.239.7001 and AR 25-2, the contractor employees supporting IAT/IAM functions shall be appropriately certified upon contract award. The baseline certification as stipulated in DoD 8570.01-M must be completed upon contract award. Specific certification requirements are identified at PWS para 4.6.4 and Appendix C.
3.1.7.5 Physical Security. The contractor shall be responsible for the development and enforcement to ensure the proper safeguarding all Government equipment, information, and property provided for contractor use.
3.1.8 Code Development/Software Policy Compliance
The Contractor shall incorporate the regular use of Software Code Review tools, designated in Program Executive Officer Enterprise Information Systems (PEO EIS) Policy Memorandum #12- 65 into their own Project Management Plan. The Contractor shall purchase the software.
The Contractor shall provide all developed source code to the Government in sufficient time to review the Software Code Quality/Software Code Assurance (SCQ/SCA) IAW PEO EIS Policy and CDRL C006. The Contractor shall provide SCQ/SCA review time in their proposed schedule. At the Government's discretion, the Integrator may be offered an instance of PEO EIS Enterprise tools that can be utilized within their development process and will be utilized within the formal review process by the PEO. Non-remediated IA findings will be accounted for and reported IAW DoD, Army, and PEO EIS Policies.
Deliverables:
Project Management Plan, CDRL B005, DI-MGMT-81797 Software Source Code & Documentation, CDRL C006, DI-IPSC-81488
3.2 Performance
3.2.1 Technical Support for SAAS and Future Change Packages
The Contractor shall sustain and maintain the operability of the SAAS system and ensure that the system is compliant with the most current DoD Regulations and Policies, and adhere to guidance as provided by the Combat Developer. Such sustainment support shall be accomplished using agile methodology and will include technical, functional and subject matter expertise, including the following functions: requirements analysis, configuration management, software programming, software coding, system testing, system security, training support, system documentation (including RoboHelp), database and data analysis, critical design reviews (CDRs), preliminary design reviews (PDRs) (IAW DoD Architecture Framework Documentation requirements), and customer support.
The contractor shall provide technical analysis for SAAS and all future enhancements, including recommendations for user interface, system processing recommendations, and implementation of functional and cyber activities related to the system as new technologies emerge. Other types of changes include, but are not limited to, changes or new guidance from either a functional or cyber perspective in relation to the reporting structure, data to report, communications procedures, and/or reporting processes. The contractor technical staff shall provide causative research, guidance and a recommendation regarding the best path forward to the Government.
The contractor shall have the ability to work with industry common software programming languages used in developing and maintaining SAAS applications, and have capability to support (e.g. plan, test, and manage) changes to software code, troubleshooting problems, and integrated Government Furnished Software and Hardware.
3.2.1.1 Software Activities
The Contractor shall be responsible for SAAS application sustainment and associated development of software releases and documentation scheduled in the Work Breakdown Structure (WBS). The Contractor can assume there will be a minimum of four (4) software releases annually using agile development processes. The software releases may include current and previous bug fixes and updates to missing functionality. The Government will identify and prioritize items to be included in the quarterly releases. Expect an average of at least 20 Change Requests (CR)/Change Items (CIs) for each release.
• The Contractor shall capture development of documentation to support software installation procedures. – See Appendix A
• The Contractor shall evaluate the current baseline and develop a strategy to improve software and database performance in a web-based environment for delivery within the first three months of the period of performance. The Contractor shall implement the strategy based on Government direction.
• The Contractor shall evaluate the current report writing capability and develop a strategy for implementing an improved and more intuitive report writing solution for delivery within first three months of the period of performance. The Contractor shall implement the strategy based on Government direction.
• The contractor shall provide program level oversight and system integration that assures software is designed and developed in one integrated fashion with reusable components.
• The contractor shall migrate existing Military Standard Requisitioning and Issue Procedures transactions to web services for sending and receiving interface data to and from trading partners.
• The contractor shall provide a capability for Material Release Acknowledgement between wholesale to retail and retail to wholesale levels.
• The contractor shall provide a capability to validate Unit Identification Code (UIC) and DODAAC information using authoritative source data.
• The contractor shall provide a capability to interface with Global Combat Support System-Army property book.
• The contractor shall provide a capability to interface with Logistic Modernization Program
(LMP).
• The contractor shall improve the interface with the National Level Ammunition Capability (NLAC) to provide full and accurate Accountable Property System Record data.
• The contractor shall provide asset visibility capabilities up through DA for all SAAS UIC’s (down to the Ammunition Supply Point/Ammunition Transfer Holding Point level Army wide.
3.2.1.1.1 Software Build Management. The Contractor shall maintain and support the build release cycle of the SAAS software suite. Activities include coordinating with the PL LIS Configuration Control Board (CCB) concerning requirements for software features and developing release plans in association with configuration management and fielding activities.
This effort will require regression testing of the products throughout a development cycle. The Contractor shall provide weekly status reports to the COR and the KO. The report will identify the status of all software modules. Status reports shall include a detailed description of all work performed, status against existing and/or planned/approved milestones, status on integrated milestone schedule, and a list and status of outstanding issues via the Software Release Plan.
3.2.1.1.2 Application Design. The Contractor shall perform in-depth requirements analysis and decomposition of all requirements by maintaining a liaison with system stakeholders and users and preparing the PDR and CDR documentation for all system changes.
3.2.1.1.3 Application Software Maintenance/Development. The Contractor shall maintain the existing software listed in Appendix A.
3.2.1.1.4 Software Updates. The Contractor shall develop software associated with problem reports (identified software deficiencies within existing functional requirements), and change requests as directed by the PL LIS CCB. The Contractor shall utilize the priority and severity rankings as assigned by the PL LIS CCB to develop schedules.
3.2.1.1.5 Database Maintenance. The Contractor shall perform modifications to the enterprise database as required to resolve problem reports and implement change request, as well as maintaining and optimizing the database for the system. The Contractor shall utilize the priority and severity rankings as assigned by the PL LIS CCB to develop schedules.
3.2.1.1.6 Systems Engineering. The Contractor shall ensure products are developed IAW sound software development practices and designs are technically robust and cover all of the requirements. Integration of all products developed both by the Contractor and Commercial off- The Shelf (COTS)/Government Off-The Shelf is managed by this activity. Maintain the viability and currency of all interfaces with external systems, and any identified software changes required as the result of modifications to the interface with external systems will be either treated as a problem report for correction or covered under a change request.
3.2.1.1.7 Software Installation. The Contractor shall develop and maintain the install and un-installs capabilities and guides of the client workstations and enterprise systems.
3.2.1.1.8 Software Documentation. The Contractor shall provide creation, maintenance and retirement of all required technical documentation as well as online help files. This includes, but is not limited to, software design, interface design, system design, Department of Defense Architecture Framework (DoDAF) artifacts, system installation instructions, system user manuals, etc. The Contractor shall provide an Integrated Master Schedule/Work Breakdown Structure 30 days after contract award, maintain, and provide updates. All documentation shall be validated as needed but at a minimum of every six months to ensure accuracy, relevance and format.
3.2.1.1.9 Software Testing. Technical support is required to support the installation, maintenance, problem resolution of software during Regression, Pre-Government Acceptance Integration Testing (Pre-GAIT), GAIT and User Acceptance Testing (UAT). UAT occurs after successful completion of GAIT and regression testing.
3.2.1.1.10 Other Test Considerations. All defects found during GAIT will be analyzed and defined by the Data Authentication Group (DAG), which will be chaired by the Government Test & Evaluation Lead. Members are comprised of the GAIT team, Subject Matter Experts (SMEs), Government Configuration Manager and Government Functionals. Any step that does not meet the expected outcome or any other incident that occurs during the test will be documented through Test Incident Reports (TIR). The full description is outlined in the PL LIS Test Management Process for Software Integration Laboratory (SIL), Appendix E.
3.2.1.2 Programming for SAAS and Future Change Packages
3.2.1.2.1 The Contractor shall provide programming capabilities in the languages, listed in Appendix A. The contractor shall provide the analysis, design, and programming modifications necessary to maintain SAAS and all future change packages.
3.2.1.2.2 The Contractor shall provide support for Information Assurance Vulnerability Alert (IAVA) and cybersecurity requirements to include analysis, impact, implementation, testing, and documentation.
3.2.1.2.3 The Contractor shall provide baseline software break-fixes by performing software/data analysis, design, coding, and testing using current technology, and provide functional/technical design documents for Government acceptance.
3.2.1.2.4 The Contractor shall perform analysis, development, documentation, implementation, and testing support necessary to interface with other systems identified by the DoD/DA.
3.2.1.2.5 The Contractor shall perform software sustainment and development. Software sustainment and development shall include software/data analysis, design, coding, testing to produce functional/technical design documents for Government acceptance.
3.2.1.2.6 The Contractor shall provide technical and functional SMEs for Tier 2 and Tier 3 customer assistance as required per PWS paragraphs 3.2.3, Customer Support, and 3.2.4, Training Support and all applicable subparagraphs.
3.2.1.2.7 The Contractor shall initiate, coordinate, and maintain system interface agreements with trading partners.
3.2.1.3 Automated Identification Technology (AIT), Hand Held Terminals (HHT), Radio Frequency Identification (RFID) Software Development for SAAS and Future Change Packages
3.2.1.3.1 The contractor shall evaluate and develop a strategy to provide an AIT software solution for use within SAAS for delivery within the first three months of the period of performance. The Contractor shall implement the strategy based on Government direction.
3.2.1.3.2 The contractor shall provide software programming capabilities and expertise to develop, update and maintain the utilization of AIT as implemented through linear and two dimensional barcode labels, HHT software applications and American National Standards Institute/International Organization for Standardization RFID tags and readers as applicable, integrating Total Asset Visibility In-Transit Processing Station or other technologies as required.
The Contractor shall provide support for IAVA and cybersecurity requirements to include analysis, impact, implementation, testing, and documentation.
3.2.1.3.3 The contractor shall provide technical and functional support for RFID providing the capability to read and write Radio Frequency Tags attached to incoming shipments of supplies and creates tags for outbound shipments. Tag data is used to report arrival of shipment to the In-Transit Visibility servers that process the receipt of incoming shipment and stores shipment information and content data on tags created for outgoing shipments. The Contractor shall provide support for IAVA and cybersecurity requirements to include analysis, impact, implementation, testing, and documentation.
3.2.1.3.4 As requested by the Government, the Contractor shall provide baseline software break-fixes by performing the following, using current technology: software/data analysis, designing, coding, testing, and providing functional/technical design documents, for Government acceptance.
3.2.1.3.5 The Contractor shall perform analysis, development, documentation, implementation, and testing support for interface with other systems identified by the DoD/DA.
3.2.1.3.6 The Contractor shall provide support for current and emerging Government and industry standards for format and content of barcode labels (currently MIL-STD-129P) and RFID tags (currently JTAV 2.5) to successfully implement integration requirements.
3.2.1.3.7 The Contractor shall provide a plan to migrate to current or emerging technologies as they become available.
3.2.1.4 Support for SAAS within a DoD Approved Data Center Utilizing Platform as a Service (PaaS) Cloud Service Environment and all Future Change Packages
3.2.1.4.1 The Contractor shall ensure that persons performing the System Administrator tasks require at a minimum an Information Assurance Technical Level One (IAT Level I) accreditation as defined in DoD 8570.01-M. The computing environment shall be a Windows-based certification. The contractor shall maintain the proper IAT accreditation during the lifetime of the contract.
3.2.1.4.2 The contractor shall provide Tier 3 help desk support for end users and resolve problem tickets for Application, Database, COTS, SAAS peripherals, and network related issues.
3.2.1.4.3 The Contractor shall perform ad hoc troubleshooting for the SAAS application database in the PaaS Environment, COTS, and SAAS peripherals, and network related issues.
The actual PaaS services/vendor has not been determined at this time.
3.2.1.4.4 The Contractor shall perform routine database administration tasks on the Structured Query Language (SQL) Server.
3.2.1.4.5 The Contractor shall evaluate current or proposed system architectures and provide guidance on improvements or alternatives for current architectures.
3.2.1.4.6 The Contractor shall interface and coordinate with external agencies such as Garrison, the Network Enterprise Center, Defense Information System Agency (DISA), and to resolve issues resulting from the enterprise network or to obtain connectivity to the enterprise network.
3.2.1.4.7 The Contractor shall produce system architecture and configuration documentation.
3.2.1.4.8 The Contractor shall create and/or implement backup and restore procedures. The Contractor shall create and/or implement disaster recovery procedures within the PaaS Framework.
3.2.1.4.9 The Contractor shall monitor and modify system performance and system/database configuration based on the performance metrics.
3.2.1.4.10 The Contractor shall automate routine system administration tasks using a scripting language such as PowerShell.
3.2.1.4.11 The Contractor shall configure and maintain the IA posture of the database system to include coordinating security scans, applying the applicable DISA STIGS and Cloud Computing Security Requirements Guide, and configuring systems to meet DoD and Army IA requirements such as CAC login utilizing the DoD Public Key Infrastructure. Contractor shall monitor IAVAs and resolve or mitigate applicable vulnerabilities within time window specified. Contractor shall monitor vendor security bulletins to obtain information of potential threats. Contractor shall validate security patches to ensure ongoing system security and integrity.
3.2.1.4.12 The Contractor shall evaluate COTS and assist the Government with obtaining Certificate of Networthiness (CoN).
3.2.1.4.13 The Contractor shall ensure the Certification and Accreditation (C&A) of the system to include producing supporting documentation of IA compliance.
3.2.1.4.14 The Contractor shall assist system managers, project and team leads in the development of project plans.
3.2.1.5 Database and Data Management for SAAS and Future Change Packages
3.2.1.5.1 The contractor shall provide Tier 3 help desk support for end users and resolve change requests for database related issues.
3.2.1.5.2 The contractor shall analyze existing data elements and determine the impact of data model changes to the system. (Data Manager/Analyst)
3.2.1.5.3 The contractor shall develop and implement a data archival solution that complies with regulatory guidance DA PAM 710-2-2, Chapter 24-43.
3.2.1.5.4 The contractor shall recommend and implement changes to the SAAS data model/schema.
3.2.1.5.5 The contractor shall ensure that software design, database design, and interfaces allow for high levels of performance, maintainability, and reliability.
3.2.1.5.6 The contractor shall define and document logical attributes and data inter-relationships for complex data structures.
3.2.1.5.7 The contractor shall design and maintain relational integrity, concurrency controls, index optimization, log clean-ups, and page files.
3.2.1.5.8 The contractor shall develop complex SQL queries and stored procedures, triggers, and functions and indexes to ensure that they are optimized for fast execution speeds to the greatest extent possible.
3.2.1.5.9 The contractor shall monitor database activity and file usage. Recommend and/or implement tuning opportunities to improve system response and run times.
3.2.1.5.10 The contractor shall recommend and implement data backup and recovery…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it.