SOW_-_P-CIDC_SOW_10-17-18.docx

DOCX document 186 KB Posted

Attached to
Persistent Cyber Training Environment Federal contract opportunity
Solicitation number
W900KK-19-PCTE
Issued by
Department of the Army Materiel Command Contracting Command Orlando Contracting Center

About this file

This sources sought notice requests information from potential offerors for a consolidated integration and development contract in support of the Persistent Cyber Training Environment platform. The contract will provide integration of software and hardware enhancements from various sources, perform testing prior to fielding, and ensure compliance and timely delivery of products. It will support agile six-month capability releases with direct user feedback. The contractor must provide program management, systems engineering, cybersecurity, logistics support, and sustainment of Regional Compute and Storage nodes at seven locations. Responses are requested by November 2nd and must demonstrate experience with software integration and development for DoD enterprise systems, continuous integration using agile methodology, risk management framework compliance at multiple classification levels, and management of geographically dispersed efforts. The government anticipates awarding an indefinite-delivery/indefinite-quantity contract with a maximum value of $800 million and 5-7 year ordering period.

Statement of Work (DRAFT) for Persistent Cyber Training Environment (PCTE) Requirement

View the file

Other files for this federal contract opportunity

Other files attached to Persistent Cyber Training Environment, newest first.
File Type Posted
Industry Day Slides v4.pptx PPTX presentation
Roster of Attendees - Industry Day Dec 2 2019.xlsx XLSX spreadsheet
CYBER TRIDENT Base SOW v20 - 11-25-19.docx DOCX document
CYBER TRIDENT DO 2 SOW v9 -11-25-19.docx DOCX document
CYBER TRIDENT DO 1 SOW v8 -11-25-19.docx DOCX document
PCTE L and M v11 - Technical-Mgmt.pdf PDF
CYBER TRIDENT DO 3 SOW v10 - 11-25-19.docx DOCX document
Question-Answer_-_Oct_24_2019.docx DOCX document
Response_to_PCTE_Industry_Day_Questions.pdf PDF
Roster_-_Industry_Day_for_Cyber_Trident_11_Jun_2019.xlsx XLSX spreadsheet
PDK_-_PCTE_-_Requesting_Access.pdf PDF
Slides_-_Pre-Solicitation_Conference_Slides_FINAL_06.06.2019.pdf PDF
Roster_-_Industry_Day_for_PCTE_as_of_27_Nov_2018.xlsx XLSX spreadsheet
Industry_Briefing_Slides_-_PCTE_(FINAL).pptx PPTX presentation
Show all 14

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF WORK

for the

Persistent Cyber Training Environment (PCTE) - Consolidated Integration and Development Contract

(P–CIDC)

U.S. Army Program Executive Office for Simulation, Training, and Instrumentation (PEO STRI) 12211 Science Drive Orlando, FL 32826-3276

Table of Contents

1.SCOPE1
1.1Introduction2
1.2Goals and Objectives2
1.3Method of Tasking3
1.4Background3
2.APPLICABLE DOCUMENTS4
2.1Department of Defense Specifications5
2.2Availability of Department of Defense Specifications5
2.3Department of Defense Standards5
2.4Availability of Department of Defense Standards5
2.5Department of Defense Directives5
2.6Availability of Department of Defense Directives5
2.7Department of Defense Instructions5
2.8Availability of Department of Instructions5
2.9Other Government Documents, Drawings, and Publications6
2.10Availability of Other Government Documents and Publications7
2.11Non-Government Standards and Other Publications7
2.12Availability of Non-Government Standards and Other Publications7
3.Requirements7
3.1Program Management7
3.1.1Cyber Innovation Challenge Management Support7
3.1.2Training Exercise Management Support8
3.1.3PCTE Industry Standards Working Group (ISWG)8
3.2Systems Engineering8
3.2.1Hardware Engineering8
3.2.2Software Engineering9
3.2.2.1Software Design and Implementation9
3.2.2.2Software Development Test9
3.2.3Software Requirements and Architecture Development and Review10
3.2.4Agile Software Development Methodology and Process10
3.2.5Continuous Integration / Continuous Deployment (CI/CD)10
3.2.6Development Environment11
3.2.7Test Engineering11
3.2.8System of Systems (SoS) Technical Integration and Testing11
3.2.9Regional Compute and Storage (RCS)12
3.2.10Training as a Service (TaaS), Cloud, and Distributed Environment Support12
3.2.11Standards, Application Programming Interface (API), and Software Development Kit (SDK) Management12
3.2.12Data Analytics13
3.2.13Web-based Portal13
3.2.14Help Desk Support13
3.3Cybersecurity13
3.3.1Information System (IS) Security15
3.3.2Information Assurance Vulnerability Alert (IAVA) for P-CIDC16
3.3.3Risk Management Framework (RMF) Support for P-CIDC16
3.3.4Host Based Security System (HBSS)16
3.4Information Assurance Training17
3.5Maintenance and Logistics17
3.5.1Supply Management and Accountability18
3.5.2Property Management Plan18
3.5.3Software Licensing18
3.5.4Configuration Management19
3.6Anti-Terrorism (AT) Level 1 Awareness Training19
3.6.1Access and General Protection/Security Policy and Procedures19
3.6.2Information Security19
3.6.3Information Assurance Awareness Training/Certification20
3.6.4Interaction and/or Disclosure with Foreign Country/Foreign National Personnel20

Statement of Work Persistent Cyber Training Environment (PCTE) - Consolidated Integration and Development Support (P-CIDC)

1. SCOPE

This Statement of Work (SOW) defines the scope of the Project Manager for Instrumentation, Targets, Threat Simulators and Special Operations Forces (SOF) Training Systems (PM ITTS) Product Manager Cyber Resiliency and Training (PdM CRT) Persistent Cyber Training Environment (PCTE) Integration and Development Support Indefinite Delivery/Indefinite Quantity (ID/IQ) contract (P-CIDC). The P-CIDC IDIQ may be utilized by Department of Defense organizations and other non-DoD agencies that have related cyber training needs. These agencies include, but are not limited to, Army Program Executive Offices (PEOs) and Navy, Marine Corps, Air Force, National Guard, Reserves, Federal Agencies, and Joint Cyber Community organizations in support of DoD cyber training. The P-CIDC will provide the management, integration, maintenance, and evolution for the PCTE platform, and will provide total system/subsystem acquisition life cycle support for the PCTE system baseline.

This SOW defines the general tasks that PdM CRT desires to have performed under the P-CIDC contract in support of the PCTE platform. Individual delivery orders will define the detailed requirements in each respective delivery order SOW. PM ITTS envisions management, maintenance, and evolution of the PCTE platform under P-CIDC to include but not limited to:

· Platform Architecture and Product Management

· Agile Development and Delivery Systems Engineering processes

· Development & Automation

· Hardware and Software Infrastructure Management

· User Event Support (First Use Events, Operational Assessments, Cyber Flag Excursions)

· Cyber Innovation Challenge (CIC) Capability Integration and Event Support

· Development Operations (DevOps) Environment Management

· Third party technology insertion, orchestration and integration into PCTE platform (COTS, GOTS, etc.)

· Distributed Configuration Management amongst various vendors and stakeholders

· Training as a Service (TaaS)/Cloud Computing Initiatives

· Product Development, Enhancements and Deployment

· Platform Governance

· Product Sustainment (synchronization with Joint Staff J7 Technical Operations Management)

· PCTE Infrastructure Tool Management

· Testing Across the Product Release Cycles

· License Management

· Help Desk Support

· Onsite and Remote Support

Introduction

The P-CIDC contract will satisfy PM ITTS CRT’s requirement for a consolidated, streamlined approach for integrating, incrementally releasing and maintaining cyber training capabilities in support of Army PEOs and Navy, Marine Corps, Air Force, National Guard, Reserves and Joint Cyber Community organizations in support of DoD and non-DoD (State and Local Governments) cyber training. This enterprise approach protects and leverages the Army’s future investments in cyber training and related infrastructure. The contract will provide acquisition life-cycle optimization for PCTE as well as continue to evolve the platform, architectural frameworks, and the Development Operations environment while continuing to provide PdM CRT an efficient, effective, and agile method to accomplish:

· Management, maintenance, and evolution of the PCTE products, processes, standards, and platform.

· Acquisition, Technology and Logistics Life-Cycle System Management in support of capabilities/products within PCTE.

· Identify repeatable Acquisition, Technology and Logistics Life-Cycle System Management optimization of systems/products that are developed within PCTE.

· Support of external interoperability initiatives and synchronization with Technical Operations Management organization.

· Insertion and integration of emerging technologies from third parties into the PCTE platform baseline Goals and Objectives The objective of P-CIDC is to provide for the managed evolution of the PCTE Platform and to provide support across all facets of the Acquisition Life Cycle for PCTE. The goal of P-CIDC is to continue development operations with the integration of software and hardware enhancements from third party vendors as technology insertion occurs while conducting testing, providing periodic system updates, and fielding technology upgrades of PCTE to the Cyber Mission Forces (CMF) through an agile cadence. In addition, P-CIDC will provide limited operations and maintenance support for PCTE to ensure high system availability throughout the acquisition life cycle. P-CIDC must be dynamic and agile to support a highly complex joint program operating in a number of classifications at geographically disparate sites.

P-CIDC has the underlying need for standardization, synchronization and management to ensure and maximize reuse, commonality and availability. The support must include dynamic mechanisms for multiphase configuration management, development and support, integration and sustainment labs, and technology insertion and growth.

The P-CIDC contract should support the business goals of PCTE to include:

· Decreasing time to produce and present training scenarios

· Increasing training throughput

· Increasing quality of training

· Increasing the reuse of training scenarios/emulated environments

Method of Tasking Government requirements issued under the basic IDIQ Contract will be met through individual DOs with a DO SOW containing the requirements for specific tasks relating to training system products. DOs may be issued at any time during contract performance, and will be related to scope task outlined in the basic SOW. Additionally, the Government will include a set of data item requirements for the DO in the form of CDRL items.

Background The United States faces threats from cyber warfare, and needs a realistic, persistent training platform that enables personnel to develop the required skills to execute mission. PM ITTS was tasked with developing a training platform to enable individual through force level training for the CMF and entire Department of Defense (DoD) Cyber Workforce. To maintain the operational readiness of a geographically dispersed CMF and entire DoD Cyber Workforce, the training platform must be persistently available around the clock (24/7). The purpose of PCTE is to enable the CMF to conduct joint training, exercises, mission rehearsals, experimentation, certification, re-certification, and assessments of cyber capabilities in support of the National Security Strategy (NSS).

For the Cyber Mission Force (CMF) who need a realistic, high fidelity persistence training environment to conduct the spectrum of cyberspace operations, the Persistent Cyber Training Environment (PCTE) materiel solution provides a holistic, on-demand standardized training platform that enables the end-to-end planning, preparation, execution and assessment various cyber training events across individual, collective, and force level continuum. Unlike the current stove-piped and manpower & time intensive training environments, PCTE provides the CMF a standardized platform with ecosystem of capabilities to rapidly shape, execute, and reuse scenarios and multiple environments simultaneously thereby increasing training quality and throughput. This supports PdM CRT strategic vision to enable cyberspace dominance for the DoD CMF.

PCTE is a capability providing the DOD cyberspace workforce the ability to conduct cyberspace training (including exercises and mission rehearsals), experimentation, certification, as well as the assessment and development of cyber capabilities and tactics, techniques, and procedures for missions that cross boundaries and networks. PCTE provides the capability required to train forces operating in cyberspace in accordance with congressional and Department of Defense (DOD) mandates.

The PCTE acquisition and integration strategy has been composed of procuring advanced prototypes that are able to efficiently integrate within the PCTE platform due to the fact that the capability is required quickly and the technology is readily available. The Program Office has integrated best of breed products and components from a number of vendors to create and establish a baseline PCTE platform. The Program Office is utilizing a SCRUM-like process to enable the rapid prototyping, and produce capability drops on a periodic basis (i.e., every 6 months) while encouraging CMF feedback throughout the process. Once the required authorizations are granted, the capability drops will be deployed to the CMF’s at the 5 sites. The SCRUM-like approach will be utilized until the PCTE platform is fully operationally capable.

In an over-simplified analogy, PCTE is somewhat analogous to an individual and team/unit collective training event on a marksmanship range. Using this analogy, PCTE must build virtual firing positions, targets, obstacles, range towers, etc. It must also build the tools necessary to efficiently and effectively execute a range training exercise, such as command and control, boundaries, after action review, instructors, threat/opposing forces, other role players, etc. (called Event Management).

Unlike a physical marksmanship range, however, PCTE must also virtually build every aspect of the range to provide a realistic landscape like the dirt, bushes, wind, rain, buildings, personnel traffic, etc. (called Environment). It must also connect geographically displaced CMF personnel so that individuals/units can access and participate in training (called Connectivity). In short, PCTE is not a cyber range. It is every aspect of a training exercise that would take place on a range.

Ultimately, PCTE will be a cloud-based training platform to support CMF individual sustainment training, team certification, and provide the foundations for a collective training network (i.e., Cyber Flag, Cyber Guard). It will leverage existing architecture and capability, including current Service tools and connected to the various cyber ranges, in order to provide the emulated environments for virtual cyber training. The materiel development activities for PCTE will include integrating hardware and software into a training platform that orchestrates event planning, training resources, and after action review into a cohesive and networked training event.

The PCTE platform will utilize integrated virtual machines connecting to Service and Cyber Training and Test Ranges. It will be a part of the Cyber Range cloud-based environment allowing the ability to share resources, such as scenarios and content, and providing additional “maneuver space” such as emulated Red (adversarial), Blue (friendly), Gray (neutral), and Industrial Control System (ICS) environments.

PCTE will be located at a number of sites enabling cyber range transport capabilities and existing emulated network environments (maneuver areas). The fielded sites include:

1. Fort Gordon, GA

2. Ft. Meade, MD

3. Suffolk, VA

4. Joint Base San Antonio, TX

5. Oahu, HI

6. Vicksburg, MS

7. Orlando, FL (Development and Operations)

2. APPLICABLE DOCUMENTS

The following documents form a part of this SOW to the extent specified herein. In the event of a conflict between documents referenced herein and the contents of this SOW, the contents of the SOW shall be the governing requirements.

2.1 Department of Defense Specifications

2.2 Availability of Department of Defense Specifications

Copies are available on the WWW at URL: http://quicksearch.dla.mil/

2.3 Department of Defense Standards

MIL-STD-3046 (ARMY)Configuration Management, Interim Standard Practice
MIL-STD-130Identification Marking of U.S. Military Property
MIL-STD-31000Technical Data Packages
MIL-STD-40051Page-Based Technical Manuals
GEIA-STD-0007Logistics Product Data

2.4 Availability of Department of Defense Standards

Copies are available on the WWW at URL: https://assist.dla.mil/online/start/

2.5 Department of Defense Directives

DODD 8570.01Information Assurance (IA) Training, Certification, and Workforce Management
DoDD 5000.01The Defense Acquisition System, dated 20 November 2007

2.6 Availability of Department of Defense Directives

Copies are available on the WWW at URL: http://www.dtic.mil/whs/directives/

2.7 Department of Defense Instructions

DODI 5230.24
Distribution Statements On Technical Documents, 23 August 2012, Incorporating Change 2, 1 November 2017
DODI 8500.01
Cybersecurity, 14 March 2014
DoDI 8510.01
Risk Management Framework (RMF) for DoD Information Technology (IT), 28 July 2017, Incorporated Change 2
DoDI 8582.01
Security of Unclassified DoD Information on Non-DoD Information Systems, 6 June 2012

DoDI 5000.02

DoDI 5200.46

DoDI 5000.74 Operation of the Defense Acquisition System, change 3 dated 10 Aug 2017 DoD Investigative and Adjudicative Guidance for Issuing the Common Access Card (CAC), 9 Sept 2014 Defense Acquisition of Services, Change 1, dated 5 October 2017.

2.8 Availability of Department of Instructions

Copies are available on the WWW at URL: http://www.dtic.mil/whs/directives/

2.9 Other Government Documents, Drawings, and Publications

DoD 8570.01-M
Information Assurance Workforce Improvement Program, 19 December 2005, Incorporating Change 4, 10 November 2015

(http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/857001m.pdf).

DoD 5220.22-M
National Industrial Security Program Operating Manual, 28 February 2006, Incorporating Change 2, May 18, 2016 (http://www.esd.whs.mil/Portals/54/Documents/DD/issuances/dodm/522022M.pdf).
FAR 52.204-2
Security Requirements, August 1996

(www.acquisition.gov/far/).

CNSS No. 11
Acquisition of Information Assurance (IA) and IA-Enabled Information Technology (IT) Products, 10 June 2013

(https://www.cnss.gov/CNSS/issuances/Policies.cfm).

CTO 07-12
Deployment of Host Based Security System (HBSS), 9 October 2007 (https://www.jtfgno.mil/).
MIL-HDBK-189C
Reliability Growth Management, 14 June 2011 Notice 1 dated 18 Mar 2016.

(http://www.dote.osd.mil/docs/dote-temp-guidebook/MIL-HDBK-189C.pdf).

MIL-HDBK-61A
Configuration Management Guidance, 7 February 2001

( acc.dau.mil/adl/en-US/142238/file/27622/MIL-HDBK-61A(SE)%20Configuration%20Management%20Guidance.pdf )

IEEE 12207-2008
International Standard ISO/IEC 12207 dated 2008-02-01- Systems and software engineering – Software Life Cycle Processes

National Security Telecommunications and Information Systems Security Policy (NSTISSP) No. 11, Subject: National Policy Governing the Acquisition of Information Assurance (IA) and IA-Enabled Information Technology (IT) Products.

AR 25-2Information Assurance
AR 25-2BBP 08-CO-M-0001, Information Technology Contingency Plans and Testing.
AR 602-2Human Systems Integration in the System Acquisition Process.
AR 70-1Army Acquisition Policy (Research, Development and Acquisition) dated 16 Jun 2017
AR 73-1Test and Evaluation Policy, dated 1 Aug 2006

AR 380-5 Department of the Army Information Security Program AR 380-10 Foreign Disclosure and Contacts with Foreign Representatives AR 380-49 Industrial Security Program 20 March 2013

2.10 Availability of Other Government Documents and Publications Copies of the above documents are available at PEO STRI, ATTN: Joseph Candelaria, 12350 Research Parkway, Orlando, FL 32826-3276

2.11 Non-Government Standards and Other Publications

ANSI/EIA-748 Earned Value Management System

2.12 Availability of Non-Government Standards and Other Publications Copies are available on the WWW at URL: http://www.nssn.org/search.html

3. Requirements The contractor shall provide overarching for the life cycle operations, products, and support of the PCTE. The contractor shall deliver platform capabilities for integration, to include performing testing prior to fielding the platform. This will require such activities that include software development, system integration, test and system delivery and upgrades to ensure compliance with contract requirements and timely delivery of required products. The contractor shall provide engineering, materials, equipment, testing, technical and operations support for the PCTE as described in this SOW.

3.1 Program Management

The contractor shall provide the overall management and administrative effort necessary to ensure that the requirements of this contract are accomplished. The contractor shall track program progress utilizing metrics specified by the Government. The contractor shall implement an agile process to address improved performance for time to award DOs. The contractor shall plan, implement, and maintain a life cycle cost (LCC) management process to minimize the system cost and use LCC to conduct trade studies, evaluate design, support alternatives, and recommend resource support requirements. As directed by the individual delivery orders, the contractor shall provide support to participate in such activities as requirements reviews, agile ceremonies, design reviews, product demonstrations, Integrated Product Team (IPT) meetings, partnering, transition meetings, conferences, fieldings, post fielding assessments, and life cycle planning of current and future systems/software releases. The contractor shall establish Associate Contractor Agreement(s) (ACA) as required. The contractor shall designate a primary on-site POC at each manned PCTE RCS site.

3.1.1 Cyber Innovation Challenge Management Support

PCTE currently deploys system prototypes, through competitive Cyber Innovation Challenges (CICs), which consist of capabilities to include event management, environment creation, and replication. With the continued evaluation of the CIC prototypes by CMF personnel, the PCTE platform will continue to evolve based on changes to technology, threat, and tactics, techniques and procedures. The contractor shall provide as directed support to include personnel support, provide facilities and equipment to host CICs that includes relevant computers, software, internet access, and network connectivity equipment (e.g., routers, switches, cables) required to conduct the demonstration. The contractor shall support integration of CIC prototypes within the PCTE platform incrementally and iteratively overtime.

3.1.2 Training Exercise Management Support

PCTE conducts a number of user assessment and demonstration events to include Limited User Assessments, First Use Events, Operational Assessments, and excursions to collective cyber exercises (e.g., Cyber Flag). These events include updates of the PCTE program, demonstrate how PCTE has leveraged and integrated existing capabilities into a working platform, provide training on how to operate the platform, receive initial user feedback to fold into PCTE agile scrum processes and provide users continuing access to PCTE platform from their home station. The contractor shall provide support to include personnel support, provide facilities and equipment to host events and demonstrations that includes relevant computers, software, internet access, and network connectivity equipment (e.g., routers, switches, cables) required to conduct the demonstration.

3.1.3 PCTE Industry Standards Working Group (ISWG)

This working group provides an efficient and consistent means of ensuring industry is positioned to understand the process for technology insertion capability development/integration, and software development kit (SDK) standards and architectures within the PCTE ecosystem. The contractor shall be required to provide input and technical expertise to support an ISWG periodically to discuss the progress and enable collaborative exchange of technical information.

3.2 Systems Engineering

The contractor shall apply Agile methodologies throughout the P-CIDC effort, with all work planned in sprints, defined within a product backlog, with the goal of having a shippable product at the end of each sprint. The contractor’s agile process shall achieve results through continuous capability enhancements, prompt response to emerging needs, demonstrated reliability, on a reoccurring 6 month release cycle. The contractor shall plan, schedule, and lead all agile ceremonies, including sprint planning, daily sprint standups, sprint retrospectives and sprint demonstrations. As specified by individual delivery orders, the contractor shall provide the requisite technical and programmatic support to complete the required tasks of the individual delivery orders associated with the PCTE engineering and management. These tasks shall encompass the efforts associated with the development, dissemination, engineering, management, and maintenance of the PCTE architecture, components, and documentation. These tasks shall also include the work efforts associated with the engineering, management, and tracking of PCTE fielded products, PCTE services and platform. The contractor shall identify an agile means of developing, integrating, testing and releasing the PCTE platform consisting of various contributions through an agile methodology facilitating CMF user feedback.

3.2.1 Hardware Engineering

As specified by individual delivery orders, the contractor shall design, develop, integrate, assemble and test the system hardware that satisfies the performance and IA requirements stated in the delivery order. The contractor shall conduct market surveillance and market investigations in order to maximize the use of commercial and non-developmental items. The contractor shall apply the systems engineering process during each level of system development (system, subsystem, and component) to add value (additional detail) to the products defined in the prior application of the process. Through each of the following design stages, information generated shall be documented in an integrated database.

3.2.2 Software Engineering

As specified by individual delivery orders, the contractor shall develop the system software and firmware and shall follow the contractor’s organizational software development practices. The contractor shall provide sufficient evidence that the producing software development organizations have software management and development processes documented. The design process shall incorporate features that promote assessment of open source software products, ease of operation, IA, ease of software maintenance, ease of future updates and modifications, data void work around, and any smart designs that can justify a reduction in the amount of documentation. The contractor shall conduct market surveillance and market investigations, in order to maximize the use of open source software, commercial software and non-developmental software. The contractor shall employ well-defined security policy models, structured, disciplined, and rigorous hardware and software development techniques, and sound system/security engineering principles. The contractor shall follow formal industry-accepted software development practices that are consistent with at least Level 3 of the Capability Maturity Model Integration for Development (CMMI-DEV).

3.2.2.1 Software Design and Implementation

As specified by individual delivery orders, the contractor shall design software, develop executable code, perform unit testing, and integrate software components (with each other and with hardware components) to meet system requirements. Software design includes not only design to requirements, but selection of existing software products including open source software to meet system requirements, and iterating the requirements to allow use of existing products. Products that perform information assurance functions are considered IA or IA-enabled Information Technology products and shall be selected from the DoD Unified Capabilities (UC) Approved Product List (APL) and configured in accordance with DoD-approved security configuration guidelines. These include products which must comply with the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs).

3.2.2.2 Software Development Test

As specified by individual delivery orders, the contractor shall establish and execute a software item qualification test program consisting of program or module and cycle or system levels of testing. The contractor shall document the life cycle activities for each software item subject to verification, the required verification tasks for each life cycle activity, and related resources, responsibilities, and schedule. The contractor shall establish test cases (in terms of inputs, expected results, and evaluation criteria) and establish traceability between the test case and the system requirements, detailed procedures for conducting the test, and test data for testing the software corresponding to each software item. The contractor shall test the software corresponding to each software item. The testing shall be in accordance with the unit test cases and procedures. The contractor shall analyze the results of item testing and shall record the test and analysis results. Prior to the start of final test, the contractor shall upgrade the commercial off the shelf (COTS) products to the latest versions approved by the system software configuration control board. The contractor shall conduct a software item test readiness review prior to initiating the formal qualification test.

3.2.3 Software Requirements and Architecture Development and Review As specified by individual delivery orders, the contractor shall develop software requirements and architecture in accordance with the contractor’s software development process plan. All analysis and results shall be documented in an integrated database. As part of this activity, the contractor shall work within the IPT to iterate the system and System-of-System (SoS) software requirements and architecture. The contractor is encouraged to suggest revisions to government requirements where such revisions would result in cost or schedule reduction or performance improvements. The contractor shall define and record the operational concept for the system, and define and record the architectural design of the system (identifying the components of the system, their interfaces, and a concept of execution among them) and the traceability between the system components and system requirements. Based upon analysis of system requirements, system design, and other considerations, the contractor shall define and record the software requirements to be met by each software item, the methods to be used to ensure that each requirement has been met, and the traceability between the software item requirements and system requirements. The contractor shall evaluate the IA requirements to assess any impacts on developed software and provide potential solutions, if applicable. The contractor shall use the SoS architecture modeling and development environment as a means of conducting modeling and simulation as appropriate for architecture and software validation. In addition, the contractor shall determine if existing open source software products are capable of meeting any operational capabilities, perform a detailed software reuse evaluation, and document the results of the analysis. The contractor shall conduct architecture evaluations, including stakeholders external to the contractor’s organization, for each software build.

3.2.4 Agile Software Development Methodology and Process

The contractor shall maintain and update the current PCTE agile software development process based on industry best practices. The contractor shall leverage a developer operations management tools to provide continuous Government traceability into the tracking of project status. The contractor shall execute the development process to include working with third parties performing technology insertion of new capabilities. The contractor shall act in the role of the Scrum Master for the PCTE platform. The contractor shall work with the Government Product Owner to document product requirements in a manner consistent with the agile development process. The contractor shall maintain configuration management over all backlogs (Product, Sprint) and ensure that the state of the backlogs aligns with actual development status.

3.2.5 Continuous Integration / Continuous Deployment (CI/CD)

The contractor shall implement CI/CD processes and tools, tailored to the specific PCTE system of systems requirement. The CI/CD processes and tools shall enable the rapid integration, test and deployment of currently implemented PCTE COTS capabilities to support continuous user feedback. A key tenant of the PCTE program is to ensure CMF users are provide early looks and access into the system to enable continuous user feedback. The contractor shall enable iterative system assessments of future releases by CMF users in manner that does not impact operational training.

3.2.6 Development Environment

The contractor shall operate and maintain a development environment that includes Government provided PCTE RCS infrastructure to be used as a test bed for system configuration and software development. To facilitate Government testing and collaboration, the facility shall be located no more than 10 miles from PEO STRI. The contractor shall provide the necessary physical space, power, cooling, and network connectivity needed to house the Government Furnished Equipment (GFE) hardware, software, and networking components. The contractor shall implement and manage a virtual infrastructure which enables multiple, independent sandboxed zones within the PCTE development and operations environments. These sandboxed zones shall enable each individual PCTE RCS instance to execute multiple versions of the PCTE baselines in parallel, enabling each chain in the CI/CD baseline maturation process to be standalone to include providing environments for future software integration by third party vendors performing technology insertion.

3.2.7 Test Engineering

As specified by individual delivery orders, the contractor shall support the continuum of PCTE platform testing across the agile software development lifecycle. Testing shall be conducted on the Government owned Development Regional Compute and Storage (RCS) nodes through remote, virtual access. The contractor shall test, stage, and release the PCTE platform by applying iterative processes utilizing the proposed Agile methodology within the 6 month release cycle. The contractor shall identify, plan, execute and provide results/feedback across the PCTE testing continuum to include:

· Application Programming Interface (API) compliance/conformance/functionality testing

· Component level testing

· Automated testing

· System Platform level integration testing

· Scalability, extensibility and distributed network testing performance

· Usability testing

The contractor shall document these findings and provide as feedback to Government for test-fix-test improvements and improving quality assurance of the delivered capability. Solve specific identified problems, conduct research of new capabilities, tools, and tactics, techniques and procedures (TTPs) for potential cyber team use.

3.2.8 System of Systems (SoS) Technical Integration and Testing

The Contractor shall support the acceptance, modification, integration, and test of future capabilities in order to deliver a comprehensive PCTE system. The Contractor shall support complete integration through automation and automated tests and regression testing of the PCTE baseline utilizing supported software configurations and in supported interoperability configurations. The Contractor’s integration and testing processes shall ensure that new provided capabilities, handover packages, change sets, and bug fixes are fully implemented and satisfy their requirements and respective Use Cases without impacting existing capability prior to integration into the main PCTE baseline.

3.2.9 Regional Compute and Storage (RCS)

The PCTE platform leverages software, hardware, and networking from multiple vendors (Dell, Cisco, NetApp, and VMware etc.) to provide a multiple Regional Compute & Storage (RCS) data center which serves as the core environment and foundation for the PCTE platform. The RCS architecture includes the hardware and software infrastructure underlying the PCTE Regional Compute and Storage (RCS) nodes and other enabling infrastructure required for the users to access the system. The contractor shall install and support PCTE software releases and system configurations to the PCTE RCS nodes in a variety of security enclaves, including Unclassified, Secret and TS/SCI. The contractor shall maintain and evolve the system design for the RCS software, hardware, and network configuration. The RCS nodes will be located at a number of sites enabling cyber range transport capabilities and existing emulated network environments (maneuver areas). The fielded sites include:

1. Fort Gordon, GA

2. Ft. Meade, MD

3. Suffolk, VA

4. Joint Base San Antonio, TX

5. Oahu, HI

6. Vicksburg, MS

7. Orlando, FL (Development and Operations)

3.2.10 Training as a Service (TaaS), Cloud, and Distributed Environment Support In support of DOD Cloud initiatives, the Contractor shall execute the systems engineering process and perform requirement analysis, conceptual modeling, engineering design, development, production, test, and integration to permit the PCTE platform to be cloud enabled for a Training as a Service approach. This approach to cloud shall be an incremental and phased strategy. This capability shall provide for support at user locations as well as test and development environments with a business goal of reducing PCTE recurring hardware sustainment cost for the currently fielded RCS nodes. The Contractor shall ensure that any cloud services are implemented in accordance with Defense Information Systems Agency provided Cloud Computing Security Requirements Guidance.

3.2.11 Standards, Application Programming Interface (API), and Software Development Kit (SDK) Management The Contractor shall adhere-to, develop, enforce and implement program-level specifications, standards, API’s and design documents for the PCTE system. The Contractor shall evolve the PCTE standards and SDK over time to address new requirements and to keep pace with the advancing technical environment while allowing means to achieve third party SDK integration within the PCTE platform. Through the system engineering process, the Contractor shall provide updates to applicable standards and API’s. The Contractor shall provide updates to these artifacts as needed to achieve an optimal system design, production software item, and documentation package. The Contractor shall use an open systems approach as the design strategy to:

1. Choose commercially supported specifications and standards for selected system interfaces (external, internal, functional and physical), products, practices, and tools;

2. Integrate cloud-based technology in support of the Army’s goals including data discovery, enrichment, and reuse. The cloud computing capability shall utilize and leverage commercial technology and commodity, non-proprietary components to the maximum extent possible;

3. Build open system architectures as the primary foundation in developing the proposed system and its elements; and

4. Identify the means for ensuring conformance to open systems standards and profiles throughout the development process.

3.2.12 Data Analytics

The contractor shall sustain the Information Technology (IT) components and infrastructure that support the operations of PCTE and shall perform data analytics to support the execution of IT operations and maintenance. Per government direction, the Contractor shall implement and utilize GFE provided data analytics ecosystem to the maximum extent possible.

3.2.13 Web-based Portal

The contractor shall implement and maintain a secure portal, accessible from the Internet, to collect, store, and manage operations, maintenance, supply, and inventory data for PCTE. The portal shall enable PCTE users to submit feedback to the development teams for the reporting of bugs, recommendations and new feature requests. The contractor shall administer, maintain, operate, synchronize, evolve and refresh the portal to align to the operation needs and requirements of PCTE, to allow users access to software, products, documentation, configuration information, or other data/metadata.

3.2.14 Help Desk Support

As specified by individual delivery orders, the contractor shall be the Tier 1, 2, and 3 single point of contact Help Desk providing diagnosis, troubleshooting, and resolution for PCTE user problems, including resolution of complex technical hardware, software, and networking issues.

3.3 Cybersecurity

The contractor shall implement a comprehensive multi-approach methodology with respect to cybersecurity and P-CIDC. The contractor shall implement cybersecurity at a number of classification levels and environments to include Closed, Restricted Networks (CRNs), Open SIPRNET, Open NIPRNET, and Top Secret/SCI.

1. The contractor shall leverage the National Information Assurance Partnership (NIAP) and the Common Criteria Evaluation and Validation Scheme (CCEVS) to ensure Defense Information Systems Agency (DISA) approved software and hardware are utilized within the PCTE construct and PCTE supported components, services, and assets.

2. The contractor shall also ensure that the common components and services developed and maintained within P-CIDC are implemented in accordance with DISA Security Technical Implementation Guide (STIG) compliance. The contractor shall complete the DISA Security Technical Implementation Guides (STIGs) implementation for the IT technology developed and provide completed STIG checklists to document compliance.

3. The contractor shall develop and maintain an IA process to guide management and design actions, document IA decisions and certification efforts, specify and track IA requirements, identify possible IA solutions, synchronize IA with CM activities, and maintain operational systems security.

4. The contractor shall conduct an assessment of the P-CIDC supporting infrastructure for security vulnerabilities and weaknesses. The contractor shall implement protective measures to address identified vulnerabilities and weaknesses.

5. The contractor shall continually evaluate the security of the system, both physical and logical, identifying exposures and providing protective options for reducing security risk. The contractor shall deliver upgrades to the system in a configuration that will pass a certification and will not negatively impact the existing accreditation.

6. The contractor shall implement protective measures to provide Information Security. When Classified or Controlled information is introduced into the PCTE, the contractor shall adhere to the provisions within AR 380-5 regarding the classification, transmission, transportation, and safeguarding of this information. Cryptography shall be FIPS 140-2 compliant. There shall be a mechanism established to ensure encrypted data can be recovered in the event the primary encryption system fails.

7. The contractor shall integrate protective mechanisms into the system and applications to provide identification and authentication, access control, accountability, availability, confidentiality, privacy, data integrity, and non-repudiation.

8. The contractor shall test and certify that application software are designed to function in a properly secured operating system environment and is free of elements that might be detrimental to the secure operation of the resource operating system, as described in NIST SP 800-37.

9. The contractor shall use Government approved assessment tools to perform cyber security testing to document, verify, and validate each applicable operating system IA configuration.

10. The contractor shall document the unincorporated security controls defined in the applicable STIG and unincorporated IAVA’s in the Plan of Action and Milestones (POA&M) document.

3.3.1 Information System (IS) Security

The contractor shall consider and integrate a holistic approach to IS security and data security that protects against unauthorized (accidental or intentional) disclosure, modification, or destruction.

1. The IS security shall consider the following:

a. All hardware and software functions, characteristics, and features

b. Operational procedures

c. Accountability procedures

d. Access controls, remote computers, and terminal facilities

e. Management constraints

2. The contractor shall provide an adequate level of protection for the IS and data contained in the IS. An adequate system ensures a security approach commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.

3. The contractor shall provide/perform auditing function to review and consolidate audit activity as required by DODI 8500.2. The auditing function shall be centralized and have the functionality to view the events using a graphical user interface, sort and filter events, and generate reports. The centralized auditing function shall have the functionality to export events to a file for a specified period of time, while preserving the integrity of the file. The centralized auditing function shall have the functionality to import events from its own exported file format for a specified period of time, so that the file is viewable using the graphical user interface.

4. The contractor shall provide/perform backup and restore functions of IS operating systems, audit logs and software. The backup and restore functions shall be an enterprise-type backup management system that has the functionality to perform back up operations as needed for connected components from one central location and has the functionality to restore to its previous state in case of catastrophic failures.

5. The contractor shall provide/perform anti-virus protection functions for the IS. The Anti-virus shall be a DoD approved centralized software management system that has the functionality to update the anti-virus software and perform scans weekly.

6. The IS security and IA approach shall include controls that are part of the day-to-day operations of the system, and are compliant with AR 25-2, DoDI 8500.01, DoDI 8510.01, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A and DoDI 8582.01.

3.3.2 Information Assurance Vulnerability Alert (IAVA) for P-CIDC The contractor shall implement processes and ensure compliance to the IAVA requirements throughout the life cycle of the P-CIDC.

1. The contractor shall track and record the implementation of the IAVA requirements.

2. The contractor shall acknowledge IAVAs within five days of an alert and comply with IAVAs within thirty days of alert.

3. The contractor shall provide justification for each unincorporated IAVA message (i.e., describe the specific negative impact the IAVA incorporation would have on PCTE operation).

3.3.3 Risk Management Framework (RMF) Support for P-CIDC

The contractor shall provide assistance in the development of the documentation required to achieve Risk Management Framework (RMF) certification and accreditation. The contractor shall develop and maintain RMF accreditation documentation for a number of classification levels and environments to include Closed, Restricted Networks (CRNs), Open SIPRNET, Open NIPRNET, and Top Secret/SCI.

The contractor shall assist the Government during the definition, verification, and validation phases of the certification and accreditation process. The RMF package includes documents defined within the RMF Framework including, but not limited to the System Security Plan (SSP), Risk Assessment Report (RAR), Information Security Continuous Monitoring (ISCM) Plan, Security Assessment Report (SAR), and Plan of Action and Milestones (POA&M).

3.3.4 Host Based Security System (HBSS)

HBSS compatibility and compliance shall be established for any system that touches the Army Network directly or indirectly or has the capability to connect, providing network administrators and security personnel with mechanisms to prevent, detect, track, report, and remediate malicious computer-related activities and incidents across all DoD networks and information systems in accordance with the Joint Task Force for Global Network Operations (JTF-GNO) released Communications Tasking Order (CTO) 07-12 (Deployment of Host Based Security System (HBSS)) mandating the deployment of HBSS on all Component Command, Service and Agency (CC/S/A) networks within DoD. All HBSS compliance and guidance will be coordinated through PEO STRI’s, CIO, and System Engineering Office (SEO).

3.4 Information Assurance Training

The contractor shall develop and provide operator and maintenance training with respect to the nature, personnel, and criticality of the protective mechanisms in place to secure the IS assets.

1. This shall include the methods, skills, use, and mechanisms to maintain the level of security of the IS.

2. The training shall be geared toward the audience and their roles and responsibilities with respect to the system’s operation and maintenance (i.e., system administrator, network administrator, hardware maintain, etc.).

3. The contractor shall utilize DOD 8570.01-M as a guide in the development of the IA Training content.

3.5 Maintenance and Logistics

The contractor shall conduct engineering analyses to establish quantitative and qualitative supportability design guidelines. The contractor shall conduct trade studies, evaluate design and support alternatives, and establish system supportability preliminary design configurations consistent with system readiness and availability and life cycle cost goals. The contractor shall perform the necessary tasks and activities for logistics, fielding and initial sustainment (as required). The Government will address the specific requirements in each DO. The following table provides a representative list of tasks and activities that could be required by specific DOs with respect to Logistics, Support Resources, Publications, Training, and Fielding:

Requirements Analysis
IUID Marking and Reporting
Supply Support
Transition Planning
Test and Evaluation
Training and Support
Maintenance Actions
Training Facility and Equipment
Fielding plans
Reliability Analyses
Validation
Tools and Test Equipment
Verification
Facility Analyses
Support Analyses
Diagnostic Procedures
Repair Level Analyses
Repair Procedures
Commercial Off The Shelf Publications
Support Concepts
Technical Publications
Support and Test Equipment
Initial Spares and Repair Parts Lists
Manpower, Personnel and Training
Provisioning Parts List
Site Support
Serial Numbers
Materiel Component List
Accounting Requirements Codes
Warranty Data
Baseline Drawing Revisions
Source, Maintenance, and Recovery Codes

Maintenance Planning

3.5.1 Supply Management and Accountability

The Contractor shall establish and maintain an automated system that accounts for PEO STRI organizational and installation supplies and equipment. The automated system shall track supplies and equipment by part number, serial number and quantity. The contractor’s automated supply system shall include policies and procedures for the reception, inspection, inventory, loading and unloading, storing, issuing, and delivery of supplies and equipment. The supply management system shall also account for lost, damaged, or destroyed property. The Contractor shall ensure 100% accountability is achieved semi-annually.

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .