Draft_OneSAF_PWS_21June2017_TO_0001.pdf
PDF 247 KB Posted
- Attached to
- One Semi-Automated Forces - Award Notice Federal contract opportunity
- Solicitation number
- W900KK-18-R-0010
About this file
DRAFT TO 0001 PWS,
View the file
Other files for this federal contract opportunity
Show all 46
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PWS-2017-036
RFP W900KK-18-R-0010
DISTRIBUTION STATEMENT A. Approved for public release: distribution unlimited.
Performance Work Statement (PWS)
For
One Semi-Automated Forces (OneSAF)
PRODUCTION AND SUPPORT
Indefinite Delivery Indefinite Quantity
Task Order 0001
21 June 2017 Version 1.0
Prepared by U.S. Army PEO Simulation, Training, and Instrumentation
(PEO STRI)
12350 Research Parkway Orlando, FL 32826-3276 ii
Revision
Level Document Date Summary of Change Pages Affected
1.0 21 June 2017 Initial release of document All iii
1.0 SCOPE
1.1 Background
1.2 Development Environment
2.0 APPLICABLE DOCUMENTS
2.1 Department of Defense (DoD) Guidance
2.2 Other Government Documents, Drawings, and Publications
2.3 OneSAF Products
3.0 REQUIREMENTS
3.1 Program Management
3.1.1 Contract Management
3.1.1.1 Enterprise‐wide Contractor Manpower Reporting Application (eCMRA)
3.1.2 Subcontractor Management
3.1.3 Financial Management
3.1.4 Risk Management
3.1.5 Organizational Process Management
3.1.6 GFE Management
3.1.7 Purchase of Commercial Information Technlogy (IT) Equipment
3.1.8 Integrated Product Teams (IPT)
3.1.9 Post Award Conference (PAC)
3.1.10 Personnel Requirements
3.1.10.1 Key Personnel
3.1.10.2 Cyberspace Workforce Management
3.1.10.3 Security Clearances
3.2 OneSAF Processes
3.3 Systems Engineering
3.3.1 Systems Integration
3.3.2 Software Engineering and Development
3.3.2.1 Software Processes
3.3.2.2 Software Integration
3.3.3 Quality Assurance (QA)
3.3.4 Configuration Management (CM) and Control
3.4 OneSAF Software Product Line Management and Support
3.5 Test Program
3.6 Maintenance and Problem Ticket Report (PTR) support
3.7 Co‐Developer Support
3.8 Cloud Enabled
3.9 OneSAF Software Product Baseline Release
3.10 Capability Development
iv
3.11 Customer Support
3.11.1 Foreign Military Sales (FMS) Support
3.11.2 Synthetic Simulation Transformation (S2T) Product Line Management Support and Core Asset Development and Evolution
3.12 OneSAF Help Desk
3.13 Software Distribution
3.14 Training
3.15 OneSAF Integrated Development Environment (IDE)
3.15.1 IDE Obsolescence/Technology Refresh
3.15.2 IDE Extensions
3.15.3 IDE Documentation
3.16 OneSAF Secure Lab Environment Support
3.17 Transition
3.17.1 Transition‐In Plan
3.18 Cybersecurity
3.18.1 OneSAF Application Cybersecurity
3.18.2 IDE Cybersecurity
3.18.3 Secure Lab Cybersecurity
3.18.4 Corporate Network
3.19 Security and Data Handling
3.20 Operations Security (OPSEC)
3.20.1 Common Access Card (CAC) Protection Policy and Procedures
3.20.2 Performance or Delivery in a Foreign Country
3.20.3 Handling or Access to Classified Information
3.20.4 Army Training Certification Tracking System (ATCTS) Registration
3.20.5 Antiterrorism (AT) Level 1 Training
3.20.6 AT Awareness Training
3.20.7 OPSEC Training
3.20.8 Threat Awareness Reporting Program (TARP)
3.20.9 Cybersecurity/Information Technology (IT) Training
3.20.10 Cybersecurity/IT Certification
3.21 Travel
3.22 Technical Data, Noncommercial Computer Software and Noncommercial Computer Software Documentation
4.0 Acronym List
Performance Work Statement
For One Semi-Automated Forces (OneSAF)
1.0 SCOPE
This Performance Work Statement (PWS) defines the effort required for providing the capabilities needed to execute the overarching OneSAF program requirements for development, test, integration, interoperability, support, and delivery of software, data, and documentation products to the Assistant Project Manager OneSAF (APM OneSAF); the U.S. Army Modeling and Simulation (M&S) Communities (Acquisition, Analysis, Experimentation, Intelligence, Test and Evaluation, and Training); and the rest of the OneSAF user community. The OneSAF user community includes, without limitation, other U.S. Army Program Executive Offices (PEOs) and Program Managers (PMs), Training and Doctrine Command (TRADOC) Battle Labs, Research Development and Engineering Centers (RDECs) and agencies, other Department of Defense Services and Joint agencies, Government civilian organizations and agencies, academic institutions, foreign countries, and other OneSAF Co-Developers. OneSAF supports force modernization and transformation from weapons systems to brigade. OneSAF supports the Army goal of cloud and web-based software application development in order to reduce hardware and support costs and to enable rapid training at both home station and distributed locations.
OneSAF is a software product line consisting of a set of interacting components where multiple components utilize common services to satisfy a diverse set of OneSAF use cases. The OneSAF Product Line Architecture Specification (PLAS) defines the System Compositions, Products, and Components within the OneSAF product line. The PLAS defines and describes the overall architecture that governs the products and components within the OneSAF product line and illustrates how the product line can be used to construct systems that meet the OneSAF requirements.
The OneSAF Production & Support effort consists of conceptual modeling, architectural, engineering, and software development support required to enhance the OneSAF product line and correct deficiencies identified by the OneSAF Community. With Government concurrence, the OneSAF effort also includes accepting, modifying, integrating, and testing handover packages and new capabilities in support of the requirements and the OneSAF user community.
The effort provides life-cycle sustainment of the released versions. This life-cycle sustainment involves addressing maintenance updates, Problem Ticket Reports (PTRs), and security patches.
The effort also entails on-site and remote support and training for the worldwide OneSAF Community. The effort includes final acceptance and test activities required to deliver the annual and tailored version releases and patches to support OneSAF Community requirements.
1.1 Background
OneSAF was formalized as an acquisition program in April 2000 with its designation as an Acquisition Category (ACAT) III program and delegation of the Milestone Decision Authority
(MDA) to Commanding General (CG), Army Materiel Command (AMC). APM OneSAF was formally chartered by the Army Acquisition Executive (AAE) to manage all OneSAF efforts on 01 May 2000. On 16 May 2000, the MDA responsibility was delegated to the Commander STRICOM (subsequently re-designated as PEO STRI). In December 2003, Milestone B/C was approved by the MDA and the program moved forward with development of the Full Operational Capability (FOC) baseline. FOC was met in March 2006 and fielding was initiated in September 2006 with the release of OneSAF Version 1.0. Additional versions continue to be fielded with Pre-Planned Product Improvements (P3I) and Co-Developer handovers integrated into the baseline. Version 8.6 was released in August 2016 and v8.7 is planned for release in August of 2017. OneSAF reached the ACAT II status and is currently in the production and support phase of the life- cycle with ongoing software production and implementation of Pre- Planned Product Improvements (P3I) as approved by the TRADOC Project Office (TPO) OneSAF.
Through these efforts, capability enhancements are continuously being developed and integrated into the baseline typically resulting in at least a yearly version release. OneSAF has been fielded to multiple Army users within the U.S. Army M&S Communities, as well as other DoD agencies and a multitude of industry, Foreign Military Sales (FMS), and academic locations. Concurrent with P3I enhancements, customer requirements, and user feedback, needs are continuously addressed to assure maximum utilization of the system throughout the growing user community.
1.2 Development Environment
APM OneSAF has established a development environment that brings together Community/User representatives, Government team members, and Contractor software developers into a single facility. The continued goal for this Integrated Development Environment (IDE) is to have the OneSAF Production and Support effort as well as Government staff co-located within a single facility. This development environment is located at 3045 Technology Parkway, Orlando, FL 32826, and provides a working environment for contractors with access to all network infrastructure and software needed to promote effective software development. Facility operations, such as structural maintenance, physical access to the building will be provided by the Government. The development environment is a Common Access Card (CAC)-enabled, protected network-connected environment that provides for development, integration, and testing of the OneSAF software. This environment provides the ability to share information to all authorized Government organizations, users, and developers simultaneously through the dev.onesaf.mil and rt.onesaf.mil web portals. The development environment allows the contribution of ideas, comments, and suggestions as well as exchanging program information and collaboration in a distributed environment.
2.0 APPLICABLE DOCUMENTS
The following documents form a part of this PWS to the extent specified herein. In the event of a conflict between documents referenced herein and the contents of this PWS, the contents of the PWS shall be the governing requirement.
2.1 Department of Defense (DoD) Guidance
The following DoD guidance documents are available on the WWW at URL:
http://www.dtic.mil/
DFARS 252.225-7043 Antiterrorism/Force Protection for Defense Contractors Outside the US
DoD 8570.01-M Information Assurance Workforce Improvement Program DoD 5220.22-M National Industrial Security Program Operating Manual DoDD 8140.01 Cyberspace Workforce Management DoDI 5000.02 Operation of the Defense Acquisition System DoDI 5000.64 Accountability and Management of DoD Equipment and
Other Accountable Property DoDI 8500.01 Cybersecurity DoDI 8510.01 Risk Management Framework (RMF) for DoD Information
Technology (IT)
2.2 Other Government Documents, Drawings, and Publications
The following are available on the WWW at URL http://csrc.nist.gov/publications/PubsSPs.html
NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
NIST SP 800-53A Guide for Assessing the Security Controls in Federal Information Systems and Organizations
NIST SP 800-171 Protecting Controlled Unclassified Information in Nonfederal Information Systems and Organizations
The following are available on the WWW at URL http://www.apd.army.mil/
Army Regulation (AR) 25-1 Army Information Technology AR 25-2 Information Assurance AR 525-13 Antiterrorism AR 735-5 Property Accountability Policies
Joint Travel Regulation - http://www.defensetravel.dod.mil/site/travelreg.cfm Army Cloud Computing Strategy -http://ciog6.army.mil/Portals/1/Home/Tabs/Strategy/20150424_Army_Cloud_Computing_St rategy.pdf Enteprise Architecture for LandWarNet 2020 and Beyond -http://ciog6.army.mil/Architecture/tabid/146/Default.aspx
2.3 OneSAF Products
The following products are available from the OneSAF development environment:
OneSAF accreditation documentation OneSAF application software, documentation and training materials OneSAF Distribution Agreement (DA) OneSAF Electronic Process Guide (EPG) OneSAF Operational Requirements Document (ORD) V1.1, dated August 2004 OneSAF Product Line Requirement Specification (PLRS) v8.7 OneSAF Product Line Architecture Framework (PLAF) v8.7 OneSAF Product Line Architecture Specification (PLAS), v8.7 OneSAF System Integration Plan (SIP) Revision, v8.7 OneSAF V8.7 RIB Items OneSAF V8.7 Use Cases
3.0 REQUIREMENTS
The requirements defined herein shall form the basis for all work that shall be performed as part of Task Order 0001 under the OneSAF Production & Support IDIQ.
3.1 Program Management
The Contractor shall provide the overall management and administrative effort necessary to ensure that the requirements in this PWS are accomplished. The program management associated with this effort shall include technical and administrative planning, organization, coordination, resource allocation, development environment management/maintenance, and risk management. The Contractor shall plan, implement, and maintain a Life Cycle Cost (LCC) management process to minimize the cost of support. The Contractor shall use LCC to evaluate design and support alternatives, and select the resource support requirements. The Contractor shall track program progress utilizing metrics, and share the metric and related data with the Government. The Contractor shall conduct Technical Interchange Meetings (TIMs), Program Management Reviews (PMRs), In Progress Reviews (IPRs) and others as directed by the Government. The Contractor shall post agendas and meeting minutes to the IDE via the established web portals.
(DI-MGMT-80227) Contractor Progress, Status and Management Report
3.1.1 Contract Management
The Contractor shall plan, budget, schedule, and control resources allocated to meet requirements of the contract. The Contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the resources assigned to the requirement. The Contractor shall prepare, implement, and utilize the Contract Work Breakdown Structure (CWBS) and performance-based Government PWS to define the work required for the proposed effort. The Contractor shall identify elements of subcontracted work in the extended CWBS and may propose changes to the CWBS to enhance its effectiveness in satisfying program objectives.
(DI-MGMT-81334C) Contract Work Breakdown Structure (CWBS)
3.1.1.1 Enterprise-wide Contractor Manpower Reporting Application (eCMRA)
The Contractor shall report all contractor labor hours (including subcontractor labor hours) required for performance of services provided under this contract for PEO STRI (W6ECAA) via a secure data collection site. The contractor is required to completely fill in all required data fields using the following web address: http://www.ecmra.mil/ Reporting inputs will be for the labor executed during the Period of Performance (PoP) during each Government fiscal year, which runs October 1 through September 30. While inputs may be reported any time during the fiscal year, all data shall be reported no later than October 31 of each calendar year, beginning with 2013. Contractors may direct questions to the help desk at “http://www.ecmra.mil/”.
3.1.2 Subcontractor Management
The Contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement. The prime Contractor shall manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. The Contractor shall integrate subcontractors into program Integrated Product Teams (IPTs) and program management and tracking systems.
3.1.3 Financial Management
The Contractor shall maintain a detailed cost and schedule status of work progress on the contract and procedures for planning work, controlling costs, measuring performance, and generating timely and reliable information. The Contractor shall document and track the expenditure of all appropriated funds associated with the contract against each contract line item and sub-line item. The Contractor shall maintain integrated cost and schedule information on those subcontracts that, based on risk, schedule criticality, or dollar value, have the potential to impede the successful completion of the contract.
3.1.4 Risk Management
The Contractor shall prepare, implement, and maintain a risk management process that addresses the identification, analysis, mitigation planning, mitigation plan implementation, and tracking he uncertainty in the project’s ability to meet cost, schedule and performance objectives. The contractor shall provide Government insight into the contractor’s tools, assessment, mitigation, and control techniques. The contractor shall document risk management as part of the Contractor Progress, Status, and Management Report.
3.1.5 Organizational Process Management
The Contractor shall manage the overarching OneSAF processes and procedures established in the EPG. The Contractor shall recommend changes and improvements where appropriate, aimed at increasing the effectiveness and efficiency in the execution of those processes while maintaining the integrity of the product line. The Contractor shall provide process reports covering topics such as Project Planning, Requirements Management, Requirements Development, Technology Solutions, and Verification. Initial process report topics will be finalized at the Post Award Conference (PAC) by the Government and Contractor. Topics shall be revised as required throughout the contract PoP.
(DI-MISC-80711A) Scientific and Technical Report (Process Reports)
3.1.6 GFE Management
The Contractor shall maintain accountability of all major end-items provided by the Government (Government Furnished Equipment) or purchased for use under this contract (Contractor- Acquired Property). The Contractor shall maintain and update a property spreadsheet as needed with newly purchased items and remove items that have been properly returned to Government accountability. Inventories shall be conducted by the Contractor and the Government at the beginning of the contract period, once annually thereafter, and once at the conclusion of the contract unless the most recent inventory has been completed within 45 days of the end of the contracted period of performance. The Contractor shall submit the results of the inventory through contracts in accordance with AR 735-5. The contractor's property spreadsheet shall be provided to the Government for use during the inventory no later than 5 business days before the inventory is scheduled to begin.
(DI-MGMT-80259) - Physical Inventories Report
3.1.7 Purchase of Commercial Information Technlogy (IT) Equipment
The contractor shall use the Army's Computer Hardware, Enterprise Software Solutions (CHESS) program, under PEO Enterprise Information Systems (EIS), as the mandatory source for commercial IT purchases. CHESS contracts provide IT products and services that comply with Network Enterprise Technology Command (NETCOM), Army and Department of Defense (DoD) policy and standards. Purchasers of commercial hardware and software must satisfy their IT requirements by utilizing CHESS contracts and DoD Enterprise Software Initiative agreements first, regardless of dollar value. Any purchase made outside of CHESS contracts requires a waiver. A complete list of CHESS contracts and the on-line waiver process can be found at https://chess.army.mil.
3.1.8 Integrated Product Teams (IPT)
The Contractor shall utilize an IPT environment as defined by the OneSAF processes. IPT activities shall include the OneSAF contractors, users, Co-Developers and Government Agency representatives. Associate Contractor Agreements (ACA) shall be implemented and utilized with all OneSAF contractors where required (i.e. CCTT and SE Core). The Contractor shall support and provide status during the weekly IPTs. The weekly IPT meeting shall provide an overview and status of all activities and a discussion of technical and/or programmatic topics.
The Contractor shall participate in Program Management meetings, Government-led meetings, and third party IPT meetings as directed by the Government. The Contractor shall provide minutes and reports for all meetings to the development environment portal as directed by the Government.
3.1.9 Post Award Conference (PAC)
The Contractor shall schedule and conduct a PAC within 30 days after contract award. The conference shall introduce key participants with emphasis on top level management of the program, identify points of contact and discuss both parties’ understanding of the requirements to be performed, agree on metrics that shall be used as management indicators, identify any partnering approach, and other contract issues. The Contractor shall post the conference materials and minutes to the OneSAF development environment within 5 business days after the
PAC.
3.1.10 Personnel Requirements
3.1.10.1 Key Personnel
The contractor shall provide staff to support the OneSAF requirements. The following personnel employed under this contract be subjected to certification/approval by the COR and shall be dedicated at 100% to the program throughout the length of the contract.
a. Program Manager
b. Lead Software Engineer
c. Lead Systems Engineer
d. Lead Integration and Test
e. Lead Architect
3.1.10.2 Cyberspace Workforce Management
IAW DODD 8140.01 "Cyberspace Workforce Management" (11 Aug 2015), and DoD 8570.01- M "Information Assurance Workforce Improvement Program" (10 Nov 2015), personnel whose required duties include government information assurance/cybersecurity requirements will have at least one approved security-related certification.
3.1.10.3 Security Clearances
DoD Secret level security clearances are required for all personnel working on the program.
3.2 OneSAF Processes
The Contractor shall execute and maintain the overarching OneSAF processes and procedures established in the EPG. The Contractor shall recommend changes and improvements where appropriate, aimed at increasing the effectiveness and efficiency in the execution of those processes while maintaining the integrity of the product line.
3.3 Systems Engineering
The Contractor shall establish and maintain an effective systems engineering program throughout the requirements, design, testing, and integration processes in order to deliver the OneSAF capabilities in an efficient, effective and agile manner. The Contractor shall provide the management and execution of all engineering elements of the contract. The Contractor shall leverage new and evolving technologies and leverage and reuse existing products to the fullest extent practicable with the goal of reducing overall life-cycle costs.
The Contractor shall use an open systems approach as the design strategy to:
(1) Choose commercially supported specifications and standards for selected system interfaces (external, internal, functional and physical), products, practices, and tools;
(2) Integrate cloud-based technology in support of the Army’s goals including data discovery, enrichment, and reuse. The cloud computing capability shall utilize and leverage commercial technology and commodity, non-proprietary components to the maximum extent possible;
(3) Build open system architectures as the primary foundation in developing the proposed system and its elements; and
(4) Identify the means for ensuring conformance to open systems standards and profiles throughout the development process.
The Contractor shall evolve the OneSAF product line architecture over time to address new requirements and to keep pace with the advancing technical environment. Through the system engineering process, the Contractor shall provide updates to the PLAS and Product Line Requirements Specification (PLRS).
(DI-MISC-80711A) Scientific and Technical Report (OneSAF Product Line Architecture Specification) (DI-MISC-80711A) Scientific and Technical Report (OneSAF Product Line Requirement Specification)
3.3.1 Systems Integration
The Contractor shall develop and implement applicable program-level specifications and design documents for the OneSAF Product Line with consideration for critical software items, data rights and interfaces sufficient to support verification & validation, operations, maintenance, and modifications of OneSAF. The Contractor shall provide updates to the System Integration Plan (SIP), including hardware and software development/integration plans, to achieve an optimal system design, production software item, and documentation package.
(DI-MISC-80711A) Scientific and Technical Report (OneSAF System Integration Plan)
3.3.2 Software Engineering and Development
The Contractor shall establish a robust and comprehensive capability to provide conceptual modeling, knowledge acquisition and engineering; requirements analysis, code design, development and unit test; and software integration and test phases in support of activities across the entire OneSAF community. For all software development activities, the contractor shall follow industry-accepted software development best practices that apply Level 3 Capability Maturity Model Integration for Development (CMMI-DEV) equivalent processes and methodologies. The Contractor shall develop the system software to meet the incremental baseline requirements for new functionality. The Contractor shall ensure the software design is based upon a common infrastructure and common infrastructure services; that interoperability and security are built-in; and that information made available is trusted and interoperable. The Contractor shall analyze requirements concerning computer resource utilization and allocate computer resources among the software items, continuously monitor the utilization and reallocate or identify the need for additional resources. The Contractor shall conduct testing that demonstrates that the new capabilities, change sets, PTR/DR fixes, and handover packages integrated meet the requirements and their respective Use Cases as provided by the Government.
3.3.2.1 Software Processes
The Contractor shall adopt the current software development build methodology, where each capability is developed during a series of builds. The Contractor can propose tailoring as required with Government approval. The build typically consists of the Knowledge Acquisition/Knowledge Engineering (KA/KE) phase followed by subsequent builds that consist of the Requirement Analysis (RA), Design, Code and Unit Test (CUT), and Software Integration and Test (SWIT) phases. The Contractor shall perform software capability evaluations and stakeholder peer reviews at appropriate phases of the OneSAF development process to ensure that designs are supportable, testable, and conform to the OneSAF architectural specifications.
3.3.2.2 Software Integration
The Contractor shall continuously support the acceptance, modification, integration, and test of internally-developed and Co-Developer capabilities daily in order to deliver the OneSAF software, data, and documentation products. The Contractor shall support complete integration through automation and automated tests and regression testing of the product baseline utilizing supported software configurations and in supported interoperability configurations. The Contractor’s integration and testing processes shall ensure that new capabilities, handover packages, change sets, and PTR/DR fixes are fully implemented and satisfy their requirements and respective Use Cases without impacting existing capability prior to integration into the main OneSAF Software Product Line.
3.3.3 Quality Assurance (QA)
The Contractor shall implement and maintain a QA program using industry-accepted best practices and subject to Government program approval. The Contractor shall establish the QA process with full Government insight. The Contractor shall maintain records of quality conformance and shall make these records available for Government review upon request.
The Contractor shall maintain a structured quality control process on the project that ensures the prompt detection of deficiencies and initiation of necessary corrective actions for any software artifacts or deliverables found non-compliant with this PWS or the Contractor’s internal practices. The Contractor shall introduce appropriate quality controls and establish measurement points that shall provide maximum visibility into new and prior processes to assure contractual requirements are being met. The Contractor shall select the proper methods to analyze these processes to continuously improve the system. Metrics shall be developed to assist management visibility into an adequate process control system. The Contractor shall utilize a discrepancy tracking system with the ability to produce complete permanent records of all discrepancies. The Contractor shall establish a suspense system to ensure timeliness of analysis and corrective action for discrepancies and risk reduction items. The Contractor shall make all data exportable in a readable/manipulatable acceptable format for Government use.
The Government shall monitor the Contractor’s performance under this contract in accordance with the Government’s Quality Assurance Surveillance Plan (QASP).
3.3.4 Configuration Management (CM) and Control
The Contractor shall identify and manage the software product baseline configuration items and adopt and expand the established OneSAF CM process to ensure that the OneSAF product conforms to the product requirements and is identified and documented in sufficient detail to support its life-cycle. The Contractor shall follow the established OneSAF processes, contained in the EPG, to maintain system requirements, system configuration information, and all relevant information about the system. The CM process shall address the evolving production configuration and support environments (engineering, implementation and test) used to generate and test the product line. The Contractor shall exercise the CM control on all configuration baselines. The Contractor shall establish and maintain a program-level Configuration Control Board (CCB), and submit Contractor Change Proposals (CCP) or Engineering Change Proposals (ECP) for any recommended change, deviation, or waiver in accordance with (IAW) the established CM process for Government concurrence. The Contractor shall maintain the current CM processes, evaluating them and recommending improvements. The Contractor shall document and the Government shall review all changes to established baselines. The Contractor shall maintain and manage system requirements in an application that provides import/export of data in a format that is compatible with the Dynamic Object Oriented Requirements Systems (DOORS) software application.
(DI-CMAN-80639C) Engineering Change Proposal
3.4 OneSAF Software Product Line Management and Support
The Contractor shall maintain and enhance the established OneSAF software product line within the OneSAF development environment. The Contractor shall develop, enhance, maintain, and integrate capabilities (developed internally or from external users/customers) and provide version release delivery acceptable to the community. The Contractor shall maintain, support, develop, and enhance the tools, models, behaviors, compositions, and/or services of the OneSAF Product Line that meet the various System Compositions extracted from the product line for a particular use. The Contractor shall maintain CM over all daily builds as well as all delivered baselines.
The Contractor shall continuously execute the handover acceptance, modification, integration, and test of developed products to include those from Co-Developers in order to deliver the OneSAF software, data, and documentation products.
(DI-MISC-80711A) Technical Report
3.5 Test Program
The Contractor shall develop, implement, manage, and maintain an innovative integrated test program that includes plans and test procedures designed to verify the OneSAF product line (including the various configurations) meets all requirements as well as verify fixes related to integration, issue resolution, new development, or enhanced capability including mission command stimulation. The Contractor shall implement methodologies to automate tests using a well-designed framework to increase both the speed and accuracy of testing by providing a reliable structure that reduces dependence on subject matter experts while offering early baseline health indicators and informative report summaries. The Contractor shall collect metrics indicative of testing trends, performance, and baseline stability throughout and report the result to the Government during the weekly IPT meetings.
3.6 Maintenance and Problem Ticket Report (PTR) support
The Contractor shall perform recurring PTR resolution in conjunction with a prioritized list as established by the Government PTR review board in order to maintain the quality of the software product baseline.
3.7 Co-Developer Support
The Contractor shall host and participate in Co-Developer interaction and handover meetings with OneSAF users. The Contractor shall work with other Army Contractor partners and users of the OneSAF product line to identify and develop reusable software components that support cross-developer interactions, and service-specific uses of OneSAF. The Contractor shall monitor OneSAF system capabilities that are developed by Co-developers, and keep the Government informed on the progress of such efforts. The Contractor shall provide the conceptual modeling, architectural, and engineering support required to support the Co-Developer’s OneSAF software product deliveries. The Contractor shall analyze proposed handovers for impact on the OneSAF product line baseline configuration and provide recommendations for inclusion. With Government concurrence, the Contractor shall accept, modify, integrate, and test handover packages, new capabilities, change sets, and PTR/Discrepancy Report (DR) fixes from Co-developers following established processes. This software shall become part of the formally managed software baseline.
3.8 Cloud Enabled
In support of the Army’s M&S Communities, the Contractor shall execute the systems engineering process and perform requirement analysis, conceptual modeling, engineering design, development, production, test, and integration to incrementally permit OneSAF to be cloud enabled, COE compliant and optimized for all identified use cases. This capability could provide services for user locations as well as test and development environments and look to reduce OneSAF recurring sustainment cost over time. The Contractor shall ensure that any cloud services are implemented in accordance with Defense Information Systems Agency provided Cloud Computing Security Requirements Guidance and IAW established Army objectives, memorandums and directives as outlined in the Army’s Cloud Computing Strategy and Enteprise Architecture for LandWarNet 2020 and Beyond.
3.9 OneSAF Software Product Baseline Release
RESERVED
3.10 Capability Development
RESERVED
3.11 Customer Support
The Contractor shall provide technical expertise, engineering design, capability development, integration and test, on-site support, training and fielding efforts in support of customer requirements as required. The Contractor shall utilize approved processes and procedures to conduct development, sustainment, integration, test, training and fielding activities. When directed by the Government, the Contractor shall integrate and support final acceptance testing of the customer requirements into the OneSAF product baseline. When appropriate, the Contractor shall ensure that all the customer requirements are defined and maintained as part of the established software product baseline. The Contractor shall conduct testing that will demonstrate that the developed capabilities meet the customers’ requirement.
3.11.1 Foreign Military Sales (FMS) Support
The Contractor shall provide technical expertise support, engineering design, capability production, integration and test, on-site support, training, and fielding efforts in support of FMS customer requirements. The Contractor shall utilize approved processes and procedures to conduct development, sustainment, integration, test, training, and fielding activities. The Contractor shall support the host country delivery and installation of OneSAF international version on the host country’s computer systems as directed and required by the Government. If required, the Contractor shall provide the software and instruction needed to establish a software development environment capability at the host country’s facility. The Contractor shall provide initial instruction to the host country’s staff on how to install the current international product baseline. The Contractor shall provide introductory training that demonstrates the product baseline capabilities. The Contractor shall provide technical assistance in developing an assessment for the host country. This assessment shall provide an analysis to maximize the use of the product baseline. The Contractor shall support the host country in determining the appropriate application and configuration of the product baseline. The Contractor shall conduct final acceptance testing that shall demonstrate that the new capabilities, change sets, PTR/DR fixes, and handover packages integrated meet the requirements and their respective Use Cases as provided by the Government.
3.11.2 Synthetic Simulation Transformation (S2T) Product Line Management Support and Core Asset Development and Evolution
The Contractor shall perform necessary tasks and activities to continue the development, evolution, and sustainment of the S2T Product Line Core Assets. The Government will address the specific requirements as part of a Task Order Customer Support CLIN. The following table provides a representative list of tasks and activities that could be required with respect to product line core asset development & evolution:
Architecture development & evolution Domain Analysis Prototyping Variation Management Re-Use Analysis Service/Component Development Requirement Analysis & Engineering Test & Verification Technology Insertion Obsolescence Management and Planning Configuration Management Standards Development and Sustainment Performance Verification & Validation Quality Assurance System of System Model Management & Enhancement
Training as a Service and Infrastructure as a Service Development
Training Development Trade Studies Technology Assessments System Engineering & Design Concept Development Functional Analysis Software Engineering Software Integration System Integration Testing & Test Engineering Fielding Training Verification Testing Validation Testing Post-Production and Deployment Software Support
RMF Testing and Certification
Configuration Management Security Engineering
3.12 OneSAF Help Desk
The Contractor shall provide technical support to the OneSAF user community by means of a Help Desk. The Contractor shall provide and maintain at a minimum telephone, online, and email help desk support capabilities. The phone and email accounts shall be monitored/manned from Monday thru Friday between the hours of 0800 to 1700 hours Eastern Time. Requests made to the email technical support line shall be answered No Later Than (NLT) the next business day following receipt of request. The Contractor shall track and report help desk metrics on a weekly basis as part of the IPT. Help desk metrics include, but are not limited to, reporting organization, number of days to resolve, number of open help desk tickets, running total of all help desk tickets and resolution.
3.13 Software Distribution
The Contractor shall provide and maintain a software distribution capability, delivering the software product to the requesting customers IAW the OneSAF DA. The Contractor shall document and keep metrics, such as receiving organization, Points of Contact, version requested, and purpose of software for all delivered software products. The Contractor shall track and report software distribution metrics on a weekly basis as part of the IPT. Software distribution metrics include, but are not limited to, “Waiting on additional customer data”, “Preparing and waiting on approval signature”, “Approved and pending shipment”, “Shipped” and running totals per release. Recent typical distribution quantity of disk sets is 100 per annual version.
3.14 Training
The Contractor shall provide and maintain a training capability to train all identified user roles and provide optimal utilization of the OneSAF products. The Contractor shall provide training for developers, operators, and maintainers maximizing the train-the-trainer approach. Training is typically one or two weeks, five days per week, and eight hours per day in duration for up to three occasions of each type per year (CONUS).
The baseline OneSAF User and Developer training materials are available from the development environment. The Contractor shall leverage existing training materials to develop updated training manuals for all released versions.
(DI-MISC-80711A) Scientific and Technical Report (OneSAF User Training Material) (DI-MISC-80711A) Scientific and Technical Report (OneSAF Developer Training Material)
3.15 OneSAF Integrated Development Environment (IDE)
The Contractor shall be responsible for the end-to-end lifecycle maintenance and support of the OneSAF development environment. The Contractor shall utilize the existing IDE infrastructure, process, and procedures as defined by the OneSAF IDE Accreditation Package and supplementing documents. The Contractor shall ensure the development environment provides program personnel complete visibility into the system at every stage of development. The Contractor shall ensure historical OneSAF artifacts are retrievable for review (e.g., peer reviews, PTRs, code changes, etc.). The Contractor shall host demonstrations and host international coalition partners within a release ability-restricted environment. The Contractor shall ensure the IDE provides the ability to share information to all authorized Government organizations, users, and developers through the dev.onesaf.mil and rt.onesaf.mil web portals.
3.15.1 IDE Obsolescence/Technology Refresh
The Contractor shall recommend updates to the IDE hardware and software as it relates to obsolescence and technology refresh. The IDE hardware consists of, but not limited to, servers, desktops, routers, and switches. The IDE software consists of, but not limited to, Commercial-off-the-shelf (COTS), Government-off-the-shelf (GOTS), Open-source, and in-house developed software. When possible, recommended updates should promote a more efficient and effective software development environment.
3.15.2 IDE Extensions
The Contractor shall maintain the extension of the IDE to CCTT and SE Core software developers currently located: 12901 Science Drive, Orlando FL 32826 (SE Core) and 12661 Challenger Parkway, Suite 230, Orlando FL 32826 (CCTT). This connection shall provide CCTT and SE Core the ability to operate as an internal co-developer (e.g., commit code, support the EPG processes). The Contractor shall extend the IDE to other developers as directed by the Government.
3.15.3 IDE Documentation
The Contractor shall create, maintain and update all documentation that pertains to the IDE setup, configuration and maintenance. Documentation consists of, but is not limited to, network diagrams, detailed lists and specifications of all the IDE hardware, detailed list of all the IDE software components to include documented modifications, hardware configuration instructions, software configuration instructions, lists of administrator passwords, emergency back-up and restoration procedures and locations of all the data residing within the IDE.
(DI-MISC-80711A) Scientific and Technical Reports (Integrated Development Environment Capability)
3.16 OneSAF Secure Lab Environment Support
The Contractor shall be responsible for the end-to-end lifecycle maintenance and support of the OneSAF Secure Lab. The Contractor shall support the installation of multiple OneSAF baselines, provide troubleshooting, and technical support for the installed OneSAF baseline. The Contractor shall provide operational and technical support for the hosting of integration events, test events, and point-to-point tests. The Contractor shall participate in IPT’s and working groups to support the OneSAF Secure Lab.
3.17 Transition
Immediately upon contract award, the Contractor shall start assuming responsibility of all of the ongoing software maintenance, development, integration, and test activities as well as the support role needed to execute the OneSAF program. The Contractor shall work with APM OneSAF, and if available, the incumbent contractor(s), to transition the conduct of the day-to-day processes and operations from the current OneSAF development environment. The Government plans to provide a 30 (thirty) day overlap with the incumbents to support the transition.
3.17.1 Transition-In Plan
The Contractor shall provide a transition strategy with the Contractor’s proposal that addresses all work efforts identified in the PWS. The transition strategy shall ensure a timely and cost efficient transition of software development and baseline support from the incumbent to the Contractor NTE 30 (thirty) days following contract award.
3.18 Cybersecurity
DoD and Army regulations require an acquisition program to implement cybersecurity throughout the program lifecycle. In support of these requirements, the Contractor shall develop and maintain a cybersecurity process to guide management and actions, document decisions, specify and track cybersecurity requirements, document any necessary certification efforts, and identify possible solutions.
The Contractor shall comply with any required cybersecurity processes in accordance with the most current standard for the effort being performed. Standards that will apply, depending on the circumstance, include:
AR 25-2 (Army Cybersecurity) DFARS clause 252.204-7012 DoDI 8500.01 (Cybersecurity) DoDI 8510.01 (Risk Management Framework DoD Information Technology (IT)) NIST SP 800-171 (Protecting Controlled Unclassified Information in Nonfederal
Information Systems and Organizations)
(DI-MGMT-82000) Risk Management Framework (RMF) Package
3.18.1 OneSAF Application Cybersecurity
The Contractor shall implement a comprehensive approach with respect to cybersecurity for the OneSAF Product Line.
a) The Contractor shall execute the RMF process and ensure compliance with the policies and procedures for obtaining an accreditation IAW DoDI 8510.01 for the OneSAF software product baseline starting with the delivery of Version 9.x. Although not formally approved, the RMF categorization for the Application Version 9.x is anticipated to be Confidentiality: Low; Integrity: Low; and Availability: Low. However, the Army’s approach to evaluating and accepting Application ATOs are still in flux; thus the Contractor should be prepared to consider additional controls which may be applicable to the application. The Contractor shall provide all applicable information to OneSAF program management for review. The Contractor shall accomplish the following for the Assess & Authorize (A&A) efforts:
i. execute cybersecurity, A&A efforts, and connectivity or interconnectivity activities as required, including providing A&A documentation, upon request, in a format acceptable to DoD cybersecurity and A&A activities;
ii. produce all components of the A&A package;
iii. ensure the security requirements and procedures are met IAW all required
DoD and Army regulations.
b) The Contractor shall support Information Assurance Vulnerability Management (IAVM) by executing a security patch process for all maintained baselines. The Contractor shall make these quarterly patches available to the OneSAF community. The security patch process shall include for all maintained baselines applicable Information Assurance Vulnerability Alerts (IAVA) and Information Assurance Vulnerability Bulletins (IAVB) posted on the NETCOM SharePoint site or DISA Information Assurance Support Environment (IASE).
c) The Contractor shall provide a comprehensive and up-to-date software scan using current
Army Best Business Practices for scanning and remediation every month. The Contractor shall report all IAVAs, IAVBs, and Security Technical Implementation Guides (STIGs) within a Plan of Action and Milestone (POA&M) at least monthly, and provide a list outlining which were implemented, those not implemented and why they were not, and how mitigated if mitigation required. The Contractor shall seek Government concurrence for all non-implemented IAVA/IAVB and STIGs.
d) The Contractor shall conduct security assessments of OneSAF capabilities for vulnerabilities and weaknesses prior to each release and implement protective measures (e.g., patching) to address identified vulnerabilities and weaknesses.
e) The Contractor shall ensure Host Based Security System (HBSS) compatibility with the
OneSAF Product Line.
f) The Contractor shall execute FISMA security reviews.
3.18.2 IDE Cybersecurity
The Contractor shall execute all tasks associated with sustaining the OneSAF IDE’s RMF accreditation, to include but not limited to, compliance with current RMF accreditation policies and procedures, executing the reaccreditation of the IDE, annual FISMA reviews, continuous security patching, etc. The OneSAF IDE is currently operating under a DIACAP accreditation but the Government plans for the IDE to be accredited under RMF by the incumbents. The anticipated date of this accreditation is April 2018. The RMF categorization for the IDE has been established as Confidentiality: Low; Integrity: Low; and Availability: Low.
3.18.3 Secure Lab Cybersecurity
The Contractor shall execute all tasks associated with sustaining the OneSAF Secure Lab RMF accreditation, to include but not limited to, compliance with current RMF accreditation policies and procedures, executing the reaccreditation of the Secure Lab, annual FISMA reviews, continuous security patching, etc. The RMF categorization for the Secure Lab has been established as Confidentiality: Moderate; Integrity: Low; and Availability: Low.
3.18.4 Corporate Network
The Government will provide internet access for a Corporate network. The Contractor shall maintain the infrastructure (e.g. firewall, switch …).
3.19 Security and Data Handling
The Contractor shall safeguard and control all unclassified and classified information and material in a manner that meets all Security and Information Assurance requirements identified in the DD Form 254 and the IDE facility’s guidance. The Contractor shall enforce these safeguards throughout the life of the contract.
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .