Attachment 0001-Performance Work Statement (PWS)_Base IDIQ_Castle Keep_v2.pdf

PDF 439 KB Posted

Attached to
Castle Keep Implementation and Sustainment Federal contract opportunity
Solicitation number
W52P1J-22-R-0049
Issued by
Department of the Army Materiel Command Joint Munitions Command

View the file

Other files for this federal contract opportunity

Show all 17

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

Defensive Cyberspace Operations (DCO)

Castle Keep Implementation and Sustainment Base IDIQ

22 June 2022

Version 7.0

CASTLE KEEP (CK)

BASE IDIQ PERFORMANCE WORK STATEMENT (PWS)

1. General

1.1. SCOPE

The proposed action will result in the award of a non-personal services Indefinite Delivery / Indefinite Quantity (ID/IQ) contract to provide comprehensive information technology support for the Defensive Cyber Operations (DCO) CASTLE KEEP information system for the Special Security Office (SSO), Department of the Army G-2 (HQDA G-2). CASTLE KEEP will be the customer-facing portal to provide automated workflow services and Sensitive Compartmented Information (SCI) program reporting, metrics, analysis, and information sharing within the Army SCI community in accordance with DoDM 5105.21 requirements. CASTLE KEEP will be hosted on the Joint Worldwide Intelligence Communication System (JWICS), Special Security Officers and other SCI officials will have access worldwide. CASTLE KEEP will be “cloud compliant” utilizing the Intelligence Community Information Technology Enterprise (IC ITE).

CASTLE KEEP serves as a work process portal that will aid management of this organization’s responsibilities, along with interactions with supporting systems across various domains of Non- Security Internet Protocol Router (NIPR), Secret Internet Protocol Router (SIPR) and JWICS, to empower increasingly effective Army-wide SCI program oversight.

During the life of the contract, the contractor shall provide comprehensive information technology support for software development, software sustainment, and system accreditation, system integration with the Army Military Intelligence (MI) Cloud on the JWICS network utilizing Amazon Web Services (AWS), and system sustainment and maintenance. The Contractor shall provide comprehensive information technology support as required to meet the Government’s mission. Army Contracting Command - Rock Island (ACC-RI) shall issue Task Orders (TO) against the resulting IDIQ contract. Each TO will define the deliverables for each particular task and shall represent a Firm-Fixed- Price (FFP) response to a ACC-RI issued Task Order PWS and shall represent all personnel and materials required to provide a turn-key solution to the Government’s requirement as defined in the Task Order PWS. Information Technology (IT) support provided during the IDIQ contract period of performance shall include the following:

Provide development, security, and operations (DevSecOps) system integration throughout software lifecycle.

Develop, test, and integrate approved capability requirements in development and test environments.

Deploy and maintain system in target production environment.

The Government intends for CASTLE KEEP’s functionality to be accessible worldwide 24/7 in support of SSO operations on JWICS. When required on specific TOs, the contractor shall provide support to daily system functionality to include minor and major capability enhancements, database maintenance, and security updates. The contractor shall maintain unclassified development, test, and integration environments and classified test, integration, and production environments in the Army MI Cloud.

The contractor shall ensure the CASTLE KEEP system is information assurance compliant with the Department of the Army Intelligence Information Management (DAMI-IM) Risk Management Framework (RMF) requirements and achieves and maintains an Authority to Operate (ATO) on the Army MI Cloud environment on JWICS.

The primary work efforts that will need to be addressed in proposals responding to this action are support of the defined requirements to provide a sustainable technological solution for the Special Security Officer/Special Security Representative (SSR) community without negatively affecting the SSO/SSR mission. In addition, maintain ancillary support functions (workflow management, database management/search, account management, training, data ingests from internal and external systems/databases, etc.) required to support SSO/SSR functions.

The contractor shall have all necessary knowledge, skills, equipment, and facilities within the team structure to conduct all required support functions within the scope of the resulting contract. These include, but are not restricted to, knowledge services such as planning, analysis, coordination, reporting, accountability, operational assessments, testing, training and security.

These also include technical integration activities within the Army MI Cloud using AWS on JWICS within IC ITE Commercial Cloud Services (C2S) platform, equipment and software testing and assessments, training support and operational integration and support. The contractor shall provide software maintenance, minor and major capability enhancements, database maintenance, maintain development, test, training, and production environments.

Operational demonstrations and testing will be required at both the government and contractor’s facilities. This task will concentrate on automating the manual processes of SSO and ensuring interoperability of information.

1.2. Background

CASTLE KEEP serves as the customer-facing portal to automate the Army’s SSO and SSR manual processes and procedures. CASTLE KEEP is an automated tool that allows SSO/SSR to manage, operate, administer, and provide policy for SCI security programs of the Department of the Army, to include Army Commands (ACOM), Army Service Component Commands (ASCC), and Direct Reporting Units (DRU). The CASTLE KEEP tool serves as a work process portal that will aid management of this organization responsibilities, along with interactions with supporting systems across various domains of NIPR, SIPR and JWICS, to empower increasingly effective Army-wide oversight.

The contractor shall provide all personnel, management support, and non-personal services necessary to support the Department of the Army SSO as defined in this PWS and subsequent task orders. This PWS is a statement of the technical, functional and performance characteristics of the work to be performed, identifies essential functions to be performed, identifies performance factors, including the location of the work, the units of work, the quantity of work units, and the standards and timeliness of the work units. The PWS and subsequent task orders serve as the scope of work and is the foundation for all work to be performed by the contractor.

1.3. Contract Management.

Army Contracting Command - Rock Island Arsenal, Rock Island, IL is the contracting agency for the Government. As the Contracting Activity for this agency, they have the authority, through a duly appointed Contracting Officer (KO), to enter into, administer, and/or terminate this contract and make related determinations and findings. Responsibilities after award are in accordance with those defined in the contract and those applicable portions of the Federal Acquisition Regulation (FAR) and its supplements. The RI KO and Contract Specialist (CS) are the only Government officials who can provide direction to the contractor resulting in changes to the scope, schedule, and cost of this effort. Any changes required by the Government Inspector or the RI Contracting Officer Representative (COR) must be approved in writing by the RI KO.

Department of the Army G-2 oversees Army Special Security Offices. The Army G-2 provides oversight and guidance for SSO/SSR whom manage Sensitive Compartmented Information Facilities (SCIFs). There are currently between 900 and 1,000 Army government SCIFs and approximately 300 Temporary SCIFs in existence. There are also an estimated 500 to 1,000 contractor SCIFs that provide support to Army contract requirements. These two organizations are partnering to improve the Army’s SSO/SSR business processes. CASTLE KEEP will support Army and other agencies and services.

CASTLE KEEP is the only automated capability to provide technical support in overseeing the SSO/SSR functions and central repository of information for use by SSO/SSRs in managing their assets. In absence of this tool, the extent of oversight consists mainly of Site Assistance Visits (SAVs) or some type of manual alerting by subordinate SSO/SSRs to a potential problem area. It is imperative to maintain and sustain this capability for SSO/SSR functions.

1.3.1. Government Management of this Contract: Contracting Officer's Representative (COR). The KO will officially designate in writing a Government COR. The COR will have responsibility for:

1.3.1.1. Ensuring that the Surveillance Plans are developed and executed by the Contracting Officer's Representative for the resulting contract and any other involved personnel.

1.3.1.2. Providing advice and assistance in resolving any performance issues which may arise during the life of the contract.

1.3.1.3. Initiating and coordinating global contract changes such as administrative changes.

1.3.1.4. Conducting other activities as specified in their COR designation memorandum.

1.3.2. Key Personnel.

1.3.2.1. Key Personnel for the Government are as follows:

Government Contracting Officer (KO): Serina A. Allingham, serina.a.allingham.civ@army.mil

Government Contracting Officer's Representative (COR): Marquita L.

Harris, marquita.l.harris.civ@army.mil

Government Contracting Project Manager (PM): LTC Dakota R.

Steedsman, dakota.r.steedsman.mil@army.mil

1.3.2.2. Key Personnel for the Contractor: Contractor shall provide a list of key personnel at submission of proposal for Government review.

1.3.2.3. The Government considers the following individuals as key personnel:

Program Manager – shall have the minimum a graduate degree

(e.g. MBA, MS, MA), Professional (PMP) Certification or Defense Acquisition Workforce Improvement Act (DAWIA) Level III certification in Program Management, Agile & Cloud experience, and minimum 10 years of experience.

Information Assurance Specialist – shall have the minimum BA/BS degree, Current Certified Information Systems Security Professional (CISSP), Security +, Certified Authorization Professional (CAP) certification, minimum IAM Level II, preferred Level III, cloud experience (e.g. AWS), and minimum 3-10 years of experience.

Senior Software Developer (or equivalent position title) – shall have minimum BA/BS degree, shall possess a current DoD 8570.01-M IAT Level II certification, extensive cloud experience (e.g. AWS), and minimum 10 years of experience.

Senior Systems Engineer (Amazon Web Service Solutions) – shall have minimum BA/BS degree, AWS Certified Solutions Architect – Professional certification, and minimum 3-10 years of experience.

The Government will consider relevant experience in lieu of a degree.

1.3.2.4. Replacement of Key Personnel: The Contractor shall notify the KO and COR prior to making any change in key personnel, as presented in its proposal submission. Prior to directing any of the specific key personnel to other programs or functional areas, the Contractor shall submit justification to substitute key personnel to the KO and COR in writing at least 30 calendar days prior to the substitution. Justification shall be in sufficient detail to include the replacement's resume, to permit evaluation of the impact of the proposed change on the program and its schedule. No substitution shall be made by the Contractor without written consent of the KO or COR in advance of any anticipated change. The Contractor shall demonstrate to the satisfaction of the KO and the COR that the qualifications of the prospective personnel are equal to or better than the qualifications of the personnel being replaced.

1.3.2.5. Impact of loss of Key Personnel: If the KO determines that a suitable and timely replacement of key personnel who have been reassigned, terminated or have otherwise become unavailable for the contract work is not reasonable forthcoming or that the resultant reduction of productive effort would be so substantial as to impair the successful completion of the contract or the service order, the contract may be terminated by the KO for default or for the convenience of the Government, as appropriate. In addition, if the Contractor is found at fault for the condition, the KO may elect to equitably decrease the contract price to compensate the Government for any resultant delay, loss or damage.

1.3.2.6. Replacement of Other Contractor Personnel: For each full time employee (FTE) proposed on the contract, the Contractor shall identify a suitable replacement and submit the required security clearance paperwork to the KO and COR for processing within calendar 30 days of vacancy for key personnel and calendar 45 days of vacancy for non-key personnel.

1.3.2.7. Acceptance of Contractor Personnel: The Government reserves the right to review and assess all prospective candidates and assess their appropriateness for work at the Government location. The Government's methodology and resultant assessment(s) regarding the approval or disapproval of the Contractor candidate(s) are not available for examination or review and will not be subject to Contractor redress.

1.3.3. Contractor Management of this Contract: Program Manager (PM). The Contractor shall designate a single PM to oversee this contract. The Contractor’s designated program manager shall serve as the single point of contact for addressing contract issues, quality issues, and overall Contractor performance. This may include coordination with the KO and the COR/COR-TO to resolve any issues that may arise, trends relating to this contract, proposed changes or modifications to this contract. The PM will be considered Key Personnel for this Contract.

1.3.3.1. The contractor shall provide program management for all subtask areas to include:

Task Planning, Preparation, and Execution (Establish Baseline and

Metrics);

Resource Management (Personnel);

Task/Project Budget Management and Cost Reporting (Cost

Controls);

Schedule and Task Performance Oversight;

Risk Management;

Quality Assurance and Controls;

Reporting and Deliverables Management;

Security Management;

Strategic Planning;

Situation Assessment and Recommendations;

Anticipatory Support (as required);

Weekly, monthly, quarterly, and adhoc meetings between the COR, Army

SSO, and Project Managers.

1.3.3.2. Task Lead/Project Manager (PM)’s Responsibility. The contractor’s PM shall actively participate in meetings, briefings, conference, seminars, weekly updates, monthly/quarterly teleconferences and progress reviews. This participation shall include providing management, technical, cost, or schedule information and other recommendations to the KO/COR.

1.3.3.3. Project Management Communications. The contractor’s PM shall provide real-time task order information to the KO/COR as requested. The contractor shall also provide system and facility readiness data. When assigned tasks/projects fall behind schedule, the contractor’s PM shall provide the KO/COR a report describing the problem, root cause(s), and a mitigation plan and timeline to resolve the problem. The contractor shall maintain a formal risk management and lessons learned program to facilitate Continuous Process Improvement (CPI).

1.3.3.4. Staff Support. The contractor shall perform all necessary administrative support requirements, including task order financial management, accounting and reporting, precision scheduling, control, and monitoring of mission support operations, task management, and coordination of responsible and efficient logistics support. The contractor shall ensure timely updates and accuracy of all tasks, task order personnel travel and leave, facility readiness, and financial reports.

1.3.3.5. Operational Reporting. The contractor shall submit reports and data as required by the appropriate Contract Data Requirements List (CDRLs) in Appendix C and D. When formats are not specified, and the contractor developed formats are allowed, the contractor shall ensure standard formats are used throughout the performance period. All reports and submission requirements shall be posted IAW established CDRL requirements. In concert with the Quality Control Plan (QCP), the contractor shall establish a process for review and submittal of all task order requirements. The contractor shall provide draft submission in accordance with CDRL requirements and shall make any corrections and adjustments necessary as identified by the Government customer.

1.3.4. Task Order Management. This section describes the responsibilities of the

Government and the Contractor associated with the administration and management of individual task orders awarded under this contract.

1.3.4.1. Government Management of the Task Order- Contracting Officer’s Representative of the Task Order (COR-TO). The COR-TO is a Government official who has been delegated by the Contracting Officer (KO) specific technical, functional and oversight responsibilities for each task order.

The COR-TO for each specific order will serve as the Government’s primary technical point of contact for all individual task order activities and issues. The COR-TO will manage the task order on a day-to-day basis, will review Contractor performance and deliverables, and will receive and approve all Contractor invoices.

1.3.4.2. Contractor Management of the Task Order- Task Manager (TM). The Contractor shall designate a single TM to serve as the Contractor’s primary point of contact for all task order activities and issues. The Contractor shall ensure that its TM provides sufficient management of each task order to ensure that the task is performed efficiently, accurately, on time, and in compliance with the requirements. The Contractor TM shall coordinate as necessary with the Contractor Program Manager and the COR-TO to ensure that individual tasks are managed consistently with overall contract requirements.

The Contractor TM shall ensure timely and accurate submission of invoices.

1.4. Period of Performance. The resulting contract shall be an ID/IQ contract with a five (5) year period of performance, consisting of five (5) 1-year ordering periods for dedicated comprehensive information technology support for the CASTLE KEEP information system.

1.5. Place of Performance.

The work to be performed under Task Orders awarded under the resulting ID/IQ contract shall be accomplished within the National Capital Region (NCR) and the contractor’s facilities. On a case-by-case basis with approval by the government, non-key personnel may augment support outside the National Capital Region.

1.6. Travel.

As designated, travel shall be used to satisfy the requirements of this Task Order. Travel is an Other Direct Cost (ODC). ODC’s are on a cost-reimbursable basis. Travel shall be in coordination with the Government and rates should be comparable to the Joint Travel Regulation (JTR) and reimbursable as outlined in the Federal Acquisition Regulations (FAR) Part 31.205-46.

1.6.1. Contractor/subcontractor personnel shall be required to travel to Government Sites for program support to include CONUS and OCONUS sites. Based on Government direction, the contractor may be required to travel within the National Capital Region; travel is expected to be required once per quarter and require 2-4 contractor personnel to participate in coordination efforts with other stakeholders.

1.6.2. All travel requires Government approval/authorization and notification to the COR/KO. The contractor shall perform temporary duty (TDY) non-local travel (both CONUS and OCONUS), as required by the contract and as stated in individual task orders during the performance of this PWS. Individual task orders will clearly define known requirements. The contractor shall submit all travel requests, security clearance information and need-to-know certification to the Government COR for review and KO for approval, at least two (2) weeks prior to the start date of the required travel.

Emergency (last minute) travel requirements shall be coordinated as above by telephone or fax, if necessary. All travel costs shall be charged to the reimbursable Travel CLIN and contractor shall verify sufficient funds are loaded in that CLIN when requesting approvals. All allowable costs will be in accordance with Joint Travel Regulation (JTR) and reimbursable as outlined in the Federal Acquisition Regulations (FAR) Part 31.205-46.

1.6.3. Travel to other government facilities or other contractor facilities may be required. The government will monitor each travel event. The contractor will manage the funds allocated for travel on each awarded Task Order.

1.6.4. Anticipated Travel: All TDY supports the coordination and communication of system requirements in support of CASTLE KEEP. Majority of travel is to the Pentagon to meet with the customer monthly/quarterly and periodically to Charlottesville, VA to the National Ground Intelligence Center (NGIC) to conduct technical exchanges with the Army Commercial Cloud Service Provider (AC2SP).

CONUS and OCONUS travel may be required for training and deployment of the system. However, the extent of travel will be identified in the individual task orders.

1.7. Security. TOP SECRET Security Clearance, based on a Tier 5 (T5) or Tier 5 Reinvestigation (T5R) within six years, with SCI eligibility is required. Access to Special Access Programs (SAP) may be required to perform duties at some point during the five year ordering period. The Government's security requirements are in accordance with the attached Defense Contract Security Classification Specification (DD Form 254). Personnel must perform within the security limitations of AR 381-10, USSID 1800, and other appropriate security regulations according to their intelligence disciplines. Contractor personnel performing work under resulting Task Orders must have the required clearance at the time of proposal submission and must maintain the level of security required for the life of the awarded contract/Task Order.

1.7.1. All Contractor personnel performing under this contract must possess and maintain a TS security clearance with SCI eligibility. This is based on a T5 or T5R within six years. This clearance information shall be included in the resume file for each individual considered. Contractor facility must have a TS facility clearance issued by the Defense Security Service (DSS).

1.7.2. Common Access Card (CAC). This card identifies one’s status as a Contractor employee accompanying the U.S. Armed Forces. This card services as identification and authorizes access to military facilities. The Government sponsor will work the

Contractor to ensure all Contractor personnel performing under this contract acquire the CAC and necessary credentials.

1.7.3. Key Control (Access Badge). The Contractor shall establish and implement methods of making sure all key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized personnel.

1.7.4. Physical Security. The Contractor shall be responsible for safeguarding all Government equipment, information, and property provided for Contractor use. At the close of each week day and period; Government facilities, equipment, and materials shall be secured.

1.7.5. Identification of Contractor Employees. Contractor personnel shall comply with all NCR and local installation instructions regarding personnel identification (ID) badge/access/security directives. All contract personnel attending meetings, answering Government telephones, and working in other situations where their Contractor status is not obvious to the third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure all documents or reports produced by Contractors are suitably marked as Contractor products or that Contractor participation is appropriately disclosed. Contractors are required to wear and display their Government issued Facility Access Badge in accordance with assigned facility procedures.

1.7.6. Information Assurance. The Contractor shall comply with each organization’s Information Assurance (IA) policies for software and hardware installed on any system within the organization. The Contractor shall ensure personnel accessing information systems have the proper and current information assurance certification to perform information assurance functions in accordance with Department of Defense (DoD) 8570.01-M, Information Assurance Workforce Program.

1.7.7. Contractor personnel assigned under this effort shall observe and comply with installation general safety, fire prevention, and security initiatives.

1.8. Type of Contract. The Government will award a Firm-Fixed Price, Indefinite Delivery/Indefinite Quantity (IDIQ) Contract with a five (5) year base period The following funding types are anticipated to be provided to support subsequent Task Orders:

Research, Development, Test and Evaluation (RDT&E) funding will be used to fund tasks supporting minor and major system enhancements and external system integration.

Operations and Maintenance (OMA) funding will be used to fund all other tasks such as maintenance, training, accreditation, and integration across the Army.

Other government agencies and services external to the Army will be required to provide supporting task orders and funding for additional requirements.

1.9. Quality Assurance.

The Government shall evaluate the Contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan (QASP). This plan is primarily focused on what the Government must do to ensure that the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).

1.9.1. Contractor Quality Control Plan (QCP) (Deliverable 1). The contractor shall develop and maintain an effective QCP to ensure services. The contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The contractor’s QCP is the means by which the contractor ensures the work complies with the requirement of the task order. Three copies of a final, comprehensive written QCP shall be submitted to the KO and COR within five business days after notice of award and when changes are made thereafter. After Government approval/acceptance of the QCP, the contractor shall receive the KO’s acceptance in writing of any proposed change to its QCP system. The Contractor QCP shall describe the following:

1.9.1.1. Management Philosophy. The Contractor QCP will discuss the organization’s technical management philosophy relative to its commitment to quality. The Contractor’s QCP shall include Quality Production, Internal Quality Checks and Reviews, and Technical Review.

1.9.1.2. Management Structure. The Contractor QCP shall identify the management of the firm that is responsible for quality.

1.9.1.3. Management Approach. The Contractor QCP will define the specific management methodology to be followed during the performance of the work, including such aspects as, documentation management and control, communications, design coordination procedures, design checks and reviews, technical review, and managerial continuity and flexibility.

1.9.1.3.1. Design checks and reviews should include a comprehensive evaluation of:

• correct application of methods

• adequacy of basic data and assumptions

• correctness of calculations

• completeness of documentation

• testing, modeling, assumptions, calculations, text, and graphic presentations in all documents for completeness and to satisfy appropriate design criteria and use of sound engineering practice

• compliance with guidance, standards, regulations, and laws

• biddability, constructability, operability, and environmental issues (if applicable)

1.9.1.3.2. Technical reviews will ensure that:

• the concepts, assumptions, features, methods, analyses, and details are appropriate, fully coordinated, and correct

• an appropriate range of feasible alternatives was evaluated

• the problems, opportunities, and issues are properly defined and scoped

• the analytical methods used are appropriate and yield reliable results

• the results and recommendations are reasonable, within policy guidelines, and supported by the presentation

• any deviations from policy, guidance, and standards are appropriately identified and have been properly approved

• the products are biddable, constructible, operable, environmentally sound, and cost effective

• the products meet the customers' needs

1.9.1.4. Documentation. All internal review documents and associated comments and responses shall be retained in the Contractor's files in auditable condition and submitted to the Government upon request.

1.9.2. Quality Surveillance. The Quality Surveillance Program shall be used as the objective basis for determining the contractor’s performance during any established reporting period. The QASP is a living document the government may review and revise on a regular basis. The QASP is not a part of the task order nor is it intended to duplicate the contractor’s QCP. The intent of the QASP is to ensure performance in accordance with the metrics set forth in the task order documents so the government receives the quality of services specified and only pays for the acceptable level of services it receives.

1.10. Hours of Operation.

The contractor shall provide support between the hours of 0600 hours and 1800 hours Monday through Friday. Extended hours and weekends to support end-users and urgent requirements may be necessary and on an as-needed basis.

1.10.1. Supplemental Overtime for Travel if needed: In support of awarded Task Orders, contractor personnel may be required to travel to various locations and work in excess of 40 hours/week on occasion. All contractor travel and overtime shall be approved in writing (electronic means including email are acceptable) by the COR/KO in advance. During performance, only actual travel costs are reimbursed in accordance with JTR and other applicable regulations.

1.10.2. Holidays. Access to Government spaces will not be available without prior authorization from the Contracting Officer’s Representative (COR) on weekends or when the facility is closed due to local or national emergencies, administrative closings, or the following federally observed holidays:

New Year’s Day Labor Day Martin Luther King Jr.’s Birthday Columbus Day Presidents Day Veterans Day Memorial Day Thanksgiving Day Juneteenth Christmas Day Independence Day

1.11. Staffing Requirements.

The contractor shall provide a sufficient number of fully trained and qualified employees to meet all reporting requirements and deliverables. Task Orders awarded under the resulting ID/IQ will be Performance Based Task Orders and the contractor shall, at all times, maintain an adequate workforce for uninterrupted performance of all tasks defined with the Task Order PWS when the Government facility is not closed. The contractor is expected to offer staffing levels based on their best judgment as to how the tasks are to be performed in accordance with the Task Order PWS.

1.11.1. The contractor shall provide all equipment, services, and labor necessary to perform the tasks unless the individual tasking documents explicitly state otherwise.

1.12. Government Networks and Communications Infrastructure.

It is the Government's intent to have Contractor automated data processing (ADP) efforts interface with required Government systems. Unless approved by the PCO, the Contractor is prohibited from the development of independent, parallel, or mirrored ADP operating systems.

If the Contractor is provided access to, or purchases services on a fee for service basis, on any Government networks or communications infrastructure, they will comply with DoD and local guidelines and requirements for review and approval prior to introducing commercial, government developed, or Contractor developed applications, software, or equipment into the environment.

1.13. Inherently Governmental Functions.

This PWS does not contain services that are inherently governmental functions as defined in FAR 7.5 – Inherently Governmental Functions.

1.14. Conflict of Interest.

Due to the nature of the activities to be supported, the Government is required to assure that the Contractor’s performance of this PWS will not result in Organizational Conflicts of Interest (OCI’s) as set forth in FAR 9.5 and subparts, which cannot be acceptably mitigated. Such OCI’s, if identified, may result in a termination for cause, or may justify a finding that the Contractor is ineligible for award of this contract. The Contractor shall create an OCI Mitigation Plan (CDRL A0012) to be provided to the Contracting Officer Representative (COR) and the Contracting Officer (KO) within 30 Calendar days after award and any subsequent changes to the COR and KO within 10 calendar days of the change.

1.15. Personal Services.

This PWS provides for services that are strictly non-personal in nature, as defined by FAR 37.104

– Personal Service Contracts. The Contractor is responsible for the management of all staff performing under this Contract and associated Task Orders. All personnel performing under this contract shall remain employees of the Contractor and shall perform contract support, workload management and other administrative functions in close-on day-to-day coordination and cooperation with DCO, G2, and ACC-RI staff as needed to meet mission goals.

1.15 Inspection and Acceptance.

Data deliverables shall be sent to the Government in accordance with the attached Contract Data Requirements Lists (CDRLs).

2. APPLICABLE DOCUMENTS

2.1. Compliance Documents. The following documents (or latest Version) provide specifications, standards, or guides that shall be complied with in order to meet the requirements of certain orders to be issued under this contract:

Federal Acquisition Regulation (FAR)

Department of Defense FAR Supplement (DFARS) Army FAR Supplement (AFARS)

Department of Defense Financial Management Regulation (DoD 7000.14-R)

2.2. Agency Standards:

DoDD 5000.01, The Defense Acquisition System (September 2020) (http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodd/500001p.pdf).

DoDI 5000.02, Operation of the Defense Acquisition System (January 2020) (https://www.acq.osd.mil/fo/docs/DSD%205000.02_Memo+Doc.pdf).

DoDI 8510.01 Risk Management Framework (RMF) for DoD Information Technology (IT) (Mar 2014) (http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodi/851001_2014.pdf).

Department of Defense, Civilian Personnel Joint Travel Regulation, Volume 2 (https://www.defensetravel.dod.mil/Docs/perdiem/JTR.pdf).

DOD Information Technology Standards Registry (DISR-online) (http://www.dsp.dla.mil/Specs- Standards/List-of-DISR-documents/) (CAC Required).

2.3. Army Regulations/Standards:

AR 25-2, Army Cybersecurity (April 2019) https://armypubs.army.mil/ProductMaps/PubForm/Details.aspx?PUB_ID=100

AR 380-5 Army Information Security Program (October 2019) https://armypubs.army.mil/ProductMaps/PubForm/Details.aspx?PUB_ID=10028

AR 380-28 Army Sensitive Compartmented Information Security Program (August 2018) https://armypubs.army.mil/epubs/DR_pubs/DR_a/pdf/web/ARN4209_AR380-28_FINAL.pdf

AR 380-49 Industrial Security Program (20 MAR 13) https://armypubs.army.mil/epubs/DR_pubs/DR_a/pdf/web/r380_49.pdf

3. REQUIREMENTS

The Government requires the following services in support of the continued development, fielding, and accreditation of its fully automated SSO management tool providing the ability to conduct continuing reviews of SCI security programs including oversight and evaluations. The Contractor shall incrementally deliver capabilities enabling the management of, and conduct training programs for SCI security officials. The resulting system shall store, share, audit and query all associated records and reports. The contractor shall support the development, testing, accreditation, fielding, and sustainment of the CASTLE KEEP Initial Operational Capability (IOC) in FY22 and Full Operational Capability (FOC) in FY23.

IOC is defined as the following:

Release of Increment 1 baseline production environment on JWICS within the Army MI Cloud provided virtual private cloud architecture.

Release of Increment 1 baseline application software accessible by the Army SSO community personnel on JWICS for operational use; incremental delivery of application software workflow and capabilities as directed by the Government.

An Authority to Operate (ATO) for the production environment and application software is issued by the Department of the Army (Intelligence) – Information Management (DAMI-IM) Authorizing Official.

Limited connectivity with external information management systems; data is primarily input by the Army SSO community and not fully ingested nor shared with external data systems.

FOC is defined as the following:

Release of required Increment 1 baseline production on JWICS with the Army MI Cloud provided virtual private cloud architecture.

Release of all Increment 1 baseline application software accessible by the Army SSO community personnel on JWICS for operational use; full delivery of application software workflow and capabilities as directed by the Government for user management, physical security, personnel security, and information security workflows.

An ATO for the production environment and application software is issued by the DAMI- IM Authorizing Official.

Connectivity and data ingestion with designated external information management systems.

3.1. Specific Performance Requirements. Below are the system performance requirements for CASTLE KEEP. The contractor shall ensure that all the performance requirements are traceable to the final product baseline, and that the product baseline is tested and acceptable to the Government prior to the ATO decision.

3.1.1. Amazon C2S Cloud. CASTLE KEEP resides on the Amazon C2S cloud on JWICS, using standard IC ITE components to include the Accumulo database from the Apache Software Foundation as the basic building blocks for configuration of the system. The contractor shall use approved cloud services and applications to support more advancement in operations with Elastic Map Reduce (EMR), AWS autoscaling, and / or containerization with EMR to support multi-region balancing that would enhance resiliency (COOP) and long-term Army or potentially DoD user growth.

3.1.2. Accuracy and Validity. The data brought into the system shall be certified and tracked to the individual user to ensure correctness and pedigree of data. The system must not alter the original data placed in the data store but will need to manipulate copies of the data for indexing, tracking, and oversight purposes. The system shall conform to 500-27 Audit.xml technical requirements.

3.1.3. Timing. The system upon deployment shall achieve an online and availability rate of 98%.. The response time for transactions or queries should be comparable to existing Amazon C2S, Accumulo, and JWICS systems of comparable size and scope.

3.1.4. Capacity Limits. The system shall support over 2,100 different SCIF/TSCIFs that are located on Government installations and at Army contractor facilities. The system shall support approximately 5,000 users, of which approximately half will access the system daily. The total data storage requirement be approximately four terabytes and the throughput will be approximately 50,000 transactions per day. Additionally, the system shall be able to store personnel security records for approximately 1.2 million personnel. The vendor shall use a government directed technical collaboration environment as a means for managing configuration documentation and storage of CASTLE KEEP’s technical and acquisition documentation. The contractor shall provide Government access to their configuration and storage system.

3.1.5. Software Environment. For CASTLE KEEP, the contractor shall use the Java programming language for all major components, but will be permitted to compliment these primary areas where suitable with additional scripting languages (e.g. JavaScript Object Notation (JSON), Linux shell, etc.) that may enhance user experience, setup and/or maintenance procedures. The contractor shall ensure that primary areas for the technical solution will utilize the AWS framework with core services including EC2 for computing power along with EBS and S3 actively used data storage, Glacier for system recovery back-ups, and Cloud Watch for resource monitoring. All systems shall be required to comply with Army Cloud Adoption policies that may require integration, consideration for further software packages or services as the platform continues to mature.

Additional services and third-party Amazon extensions may be proposed by the contractor to the Army but would be an option to be considered by the Government. The contractor shall ensure code will be written in Java to allow cross-platform data sharing in accordance with DNI and DOD standards.

3.1.6. Failure Contingencies. Current practices are primarily hardcopy in nature with paper files kept at each location. Hardcopy files will be kept until the system has fully transitioned to operational status. Once all of the hardcopy data has been migrated to CASTLE KEEP, the requirement for paper files will be removed. Since CASTLE KEEP will reside on Amazon Web Services, the need for backup and Continuity of Operations (COOP) is not necessary; it is inherent in the Amazon architecture. The only concern will be inadvertent loss of data, so to minimize data loss there will be a periodic (daily or weekly) cold backup of all data into C2S components, which will ensure that no critical data will be lost.

3.1.7. Design Considerations. The system will leverage the DNI lead IC ITE C2S platform. The Government sponsor within the JWICS domain oversees this AWS based cloud with the capability to provide systems with the necessary infrastructure components for computing power and data storage, along with security boundaries. Additional corresponding elements are to be leveraged from the IC ITE and Army G-2 provided service portfolios to support user authentication, information security management, audit, and monitoring.

Selection of the C2S platform drives consistency with the broader IC ITE initiative. Continued growth and standard enforcement will reduce the burden for long-term operation of this capability from equipment management through information assurance (IA) such that each responsibility may be aligned and delivered as layers in compliance with common standards.

3.1.8. System Functions. Key system capabilities will involve information consolidation, single point portal access available to all SSO personnel, workflow process management, audit traceability, and reporting (both standard reoccurring and ad-hoc). While workflow is a core component of the system, it is truly through oversight that it becomes empowered through centralization and reporting of key SSO functions - to include supporting documentation - to uphold adherence to strict security standards across all sites and personnel. The system itself will support up to 5000 individual users in total, with concurrent usage of up to 500 users. Availability for system users must be 24 hours a day, 7 days a week throughout the entirety of the year. Standard reoccurring scheduled maintenance windows with advance notice will be provided to the user community. While users may have access to the system around the clock, operations and maintenance along with trouble support staff dedicated to the system may be centralized and available for response within 48 hours of any incident occurrence.

3.1.9. Configuration Management. The contractor shall adhere to established software development standards and guidelines as prescribed by a minimum level 3 Capability Maturity Model (CMM), a minimum level 3 Capability Maturity Model Integration (CMMI), Institute of Electrical and Electronics Engineers (IEEE), and International Organization for Standardization (ISO). The contractor shall follow industry best practice configuration and change management policies developed in accordance with CMMI, IEEE and ISO; including creating and managing the CASTLE KEEP software, and managing baseline libraries. The contractor shall develop and maintain a Configuration Management Plan (CDRL A0007) for the duration of the contractor’s software development and integration efforts under the resulting contract.

3.1.9.1. The contractor shall develop, test and integrate software utilizing CMMI or equivalent practices, processes and services. The contractor shall maintain and track the status of each requirement using use a government directed technical collaboration environment through release, updating software baselines after reviews and/or testing and releasing updated baselines to the field.

3.1.9.2. The contractor shall use a government directed technical collaboration environment to create/update/maintain release packages in accordance with industry best practice configuration and change management policies and procedures. The contractor shall perform or participate in periodic and scheduled audits of the software baselines to verify that they conform to the documentation that defines them. The contractor shall establish and use a standard source code repository for source code management in accordance with industry best practices. The contractor shall also provide notification of implemented changes to the initiator of the change request/problem report and to the users of the system.

3.1.9.3. The contractor shall create, update, and maintain release packages for each block or version release in accordance with industry best practices.

3.1.9.4. The contractor shall maintain application/program records, such as preparation, update, coordination, and maintaining system, user, and process documentation. The contractor shall provide support to HQDA G-2 project personnel to meet their process and documentation needs in accordance with organizational policies and standards. The contractor shall provide support in the development of templates for all required process support documentation including charts and reports as required.

3.1.10. Personnel Qualifications. The Government requests contractor personnel proposed to perform under Task Orders awarded under the resulting contract have the following certifications. Resumes for the selected personnel may be submitted as part of the Contractor’s Task Order proposal submission:

3.1.10.1. Contractor personnel performing in Program Management roles shall have minimum a graduate degree (e.g. MBA, MS, MA), Professional (PMP) Certification or Defense Acquisition Workforce Improvement Act (DAWIA) Level III certification in Program Management with Agile & Cloud experience, and minimum 10 years of experience.

3.1.10.2. Contractor personnel performing in Information Assurance roles shall possess a minimum BA/BS degree, Current Certified Information Systems Security Professional (CISSP), Security +, Certified Authorization Professional (CAP) certification, minimum IAM Level II, preferred Level III, cloud experience (e.g. AWS);

minimum 3-10 years of experience.

3.1.10.3. Contractor personnel performing in Sr. Software

Development or Sr. Software Integration roles shall have a minimum BA/BS degree, shall possess a current DoD 8570.01-M IAT Level II certification, extensive cloud (e.g. AWS) and programming experience;

minimum 10 years of experience.

3.1.10.4. Contractor personnel performing in Software Development shall have a minimum BA/BS degree, software programming experience; minimum 3-10 years of experience.

3.1.10.5. Contractor personnel performing in Systems Engineering in AWS Solution roles shall possess a minimum BA/BS degree, AWS Certified Solutions Architect – Professional certification; minimum 3-10 years of experience.

3.1.10.6. Contractor personnel performing in Quality Assurance roles shall possess a minimum BA/BS degree, experience in quality control and software validation (e.g. testing, integration, quality assessment, audits, release readiness, etc.); minimum 3-10 years of experience.

3.1.10.7. Contractor personnel performing in Database Engineering roles shall have a minimum BA/BS degree, experience in data mining models/data analytics via analytical techniques of Artificial Intelligence/Machine Learning, programming languages/statistics;

minimum 3-10 years of experience.

3.1.10.8. Contractor personnel performing Systems Administrator roles shall possess a minimum BA/BS degree, experience supporting systems (e.g. design, installation, and configuration); minimum 3-10 years of experience.

3.1.10.9. Contractor personnel performing Trainer roles shall possess a minimum BA/BS degree, experience with programming and software development; minimum 3-10 years of experience.

3.2. The overall objective of this effort is to achieve program goals established by the Government for the Contractor to provide comprehensive information technology support for software development, software sustainment, system accreditation, system integration with the Army MI Cloud on the JWICS network utilizing Amazon Web Services (AWS), and system sustainment and maintenance. The Government will define specific requirements for required services in a Task Order PWS.

3.2.1. Objective 1: Software Development. The Contractor shall provide comprehensive information technology support continued development of the CASTLE KEEP system. The required support includes, but is not limited to the following:

3.2.1.1. The Contractor shall develop, test, and integrate software enhancements as identified/validated by the SSO. These activities include, but are not limited to the following:

JWICS Test, Integration, and Production environments NIPR Development and Test environments Commercial Cloud

Hosted on the Army MI Cloud, National Ground Intelligence Center (NGIC)

Cloud tools provided by Amazon Web Services (AWS) Database Management…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .