DO 0003-SOW-CDRLs 7-20-20.pdf
PDF 682 KB Posted
- Attached to
- Cyber TRIDENT Federal contract opportunity
- Solicitation number
- W900KK-20-R-0001
About this file
This is a Statement of Work (SOW) for Delivery Order Three under the Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT) contract. The SOW requires the contractor to provide Platform Capability Production for the Persistent Cyber Training Environment (PCTE) through activities including technology insertion, addressing technology obsolescence and evolution issues, and developing capabilities from the backlog. The contractor must perform engineering, materials, equipment, and testing in accordance with requirements for program management, development operations, cybersecurity, logistics, and testing. Delivery is required over a five-year period from September 2021 through August 2026. The Army's Program Executive Office for Simulation, Training, and Instrumentation is the requiring office.
View the file
Other files for this federal contract opportunity
Show all 31
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
W900KK-21-F-DO03
Section B – Supplies or Services and Prices
ITEM NO SUPPLIES/SERVICES QUANTITY UNIT UNIT PRICE
1001 1 lot
Software Products Development – PCTE Capability Production
CPFF
The contractor shall provide software products IAW Basic Contract, CLIN 0007 # SOW-2020-011, Section 3.2 and DO 0003 SOW # 2020-011-03.
Year 1
CPFF, Completion Form Delivery Order.
All labor, material, travel and other direct costs are included under CLIN 1001.
FOB: Destination
PSC CD: 7010
MAX COST
FIXED FEE
TOTAL MAX COST + FEE
1002 1 lot
Contractor Acquired Property (CAP)
FFP
The contractor shall provide contractor acquired property (materials) as required IAW to Basic Contract, CLIN 0016, # SOW -2020-011, Section 3.1.11 and DO 0003 SOW # 2020-011-03, Section 3.1.7.
Year 1
This CLIN is not separately priced.
2001 1 lot
OPTION Software Products Development – PCTE Capability Production
CPFF
Year 2
All labor, material, travel and other direct costs are included under CLIN 2001.
2002 1 lot OPTION Contractor Acquired Property (CAP)
FFP
The contractor shall provide contractor acquired property (materials) as
Year 2
3001 1 lot
OPTION Software Products Development – PCTE Capability Production
CPFF
Year 3
All labor, material, travel and other direct costs are included under CLIN 3001.
3002 1 lot
OPTION Contractor Acquired Property (CAP) The contractor shall provide contractor acquired property (materials) as
Year 3
MAX COST ___________ __
4001 1 lot
OPTION Software Products Development – PCTE Capability Production
CPFF
Year 4
All labor, material, travel and other direct costs are included under CLIN 4001.
4002 1 lot OPTION Contractor Acquired Property (CAP)
FFP
The contractor shall provide contractor acquired property (materials) as
Year 4
The CLIN is not separately priced.
5001 1 lot
OPTION Software Products Development – PCTE Capability Production
CPFF
Year 5
All labor, material, travel and other direct costs are included under CLIN 5001.
5002 1 lot
OPTION Contractor Acquired Property (CAP)
FFP
The contractor shall provide contractor acquired property (materials) as
Year 5
Section C – Descriptions and Specifications
C1 Order of Precedence
STATEMENT OF WORK
The SOW, under Attachment 1, is incorporated into Section C1 for purposes of FAR Clause 52.215-8, “Order of Precedence.”
Section E – Inspection and Acceptance
INSPECTION AND ACCEPTANCE TERMS
Supplies/services will be inspected/accepted at:
CLIN INSPECT AT INSPECT BY ACCEPT AT ACCEPT BY
1001 Destination Government Destination Government 1002 Destination Government Destination Government 2001 Destination Government Destination Government 2002 Destination Government Destination Government 3001 Destination Government Destination Government 3002 Destination Government Destination Government 4001 Destination Government Destination Government 4002 Destination Government Destination Government 5001 Destination Government Destination Government 5002 Destination Government Destination Government
CLAUSES INCORPORATED BY REFERENCE
52.246-5 Inspection of Services Cost-Reimbursement APR 1984
Section F – Deliveries or Performance
DELIVERY INFORMATION
CLIN DELIVERY DATE QUANTITY SHIP TO ADDRESS DODAAC CAGE
POP 1 SEP 2021 TO
31 AUG 2022
N/A
PEO STRI ORLANDO
JAMES KOZLOWSKI
12211 SCIENCE DRIVE
W906ZL
ORLANDO FL 32826
407-208-5864
1002 POP 1 SEP 2021 TO
31 AUG 2022
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
2001 POP 1 SEP 2022 TO
31 AUG 2023
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
2002 POP 1 SEP 2022 TO
31 AUG 2023
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
3001 POP 1 SEP 2023 TO
31 AUG 2024
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
3002 POP 1 SEP 2023 TO
31 AUG 2024
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
4001 POP 1 SEP 2024 TO
31 AUG 2025
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
4002 POP 1 SEP 2024 TO
31 AUG 2025
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
5001 POP 1 SEP 2025 TO
31 AUG 2026
N/A (SAME AS PREVIOUS
FOB: Destination
LOCATION) W906ZL
5002 POP 1 SEP 2025 TO
31 AUG 2026
N/A (SAME AS PREVIOUS
LOCATION) W906Z
Section G – Contract Administration Data
CLAUSES INCORPORATED BY FULL TEXT
252.232-7006 WIDE AREA WORKFLOW PAYMENT INSTRUCTIONS (DEC 2018)
(a) Definitions. As used in this clause—
“Department of Defense Activity Address Code (DoDAAC)” is a six position code that uniquely identifies a unit, activity, or organization.
“Document type” means the type of payment request or receiving report available for creation in Wide Area WorkFlow (WAWF).
“Local processing office (LPO)” is the office responsible for payment certification when payment certification is done external to the entitlement system.
“Payment request” and “receiving report” are defined in the clause at 252.232-7003, Electronic Submission of Payment Requests and Receiving Reports.
(b) Electronic invoicing. The WAWF systemprovides the method to electronically process vendor payment requests and receiving reports, as authorized by Defense Federal Acquisition Regulation Supplement (DFARS) 252.232- 7003, Electronic Submission of Payment Requests and Receiving Reports.
(c) WAWF access. To access WAWF, the Contractor shall—
(1) Have a designated electronic business point of contact in the System for Award Management at https://www.beta.sam.gov; and
(2) Be registered to use WAWF at https://wawf.eb.mil/ following the step-by-step procedures for self-registration available at this web site.
(d) WAWF training. The Contractor should follow the training instructions of the WAWF
Web-Based Training Course and use the Practice Training Site before submitting payment requests through WAWF. Both can be accessed by selecting the “Web Based Training” link on the WAWF home page at https://wawf.eb.mil/.
(e) WAWF methods of document submission. Document submissions may be via web entry, Electronic Data Interchange, or File Transfer Protocol.
(f) WAWF payment instructions. The Contractor shall use the following information when submitting payment requests and receiving reports in WAWF for this contract or task or delivery order:
(1) Document type. The Contractor shall submit payment requests using the following document type(s):
(i) For cost-type line items, including labor-hour or time-and-materials, submit a cost voucher.
(ii) For fixed price line items—
(A) That require shipment of a deliverable, submit the invoice and receiving report specified by the Contracting Officer.
Combo Type invoice for FFP CLINs Cost Voucher for Cost Reimbursement CLINs
(Contracting Officer: Insert applicable invoice and receiving report document type(s) for fixed price line items that require shipment of a deliverable.)
(B) For services that do not require shipment of a deliverable, submit either the Invoice 2in1, which meets the requirements for the invoice and receiving report, or the applicable invoice and receiving report, as specified by the Contracting Officer.
See (A) above
(Contracting Officer: Insert either “Invoice 2in1” or the applicable invoice and receiving report document type(s) for fixed price line items for services.)
(iii) For customary progress payments based on costs incurred, submit a progress payment request.
(iv) For performance based payments, submit a performance based payment request.
(v) For commercial item financing, submit a commercial item financing request.
(2) Fast Pay requests are only permitted when Federal Acquisition Regulation (FAR) 52.213-1 is included in the contract.
[Note: The Contractor may use a WAWF “combo” document type to create some combinations of invoice and receiving report in one step.]
(3) Document routing. The Contractor shall use the information in the Routing Data Table below only to fill in applicable fields in WAWF when creating payment requests and receiving reports in the system.
Routing Data Table for FFP CLINs*
Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC To be completed at Contract Award Issue By DoDAAC W900KK
Admin DoDAAC** To be completed at Contract Award Inspect By DoDAAC W906ZL Ship To Code
Ship From Code Mark For Code
Service Approver (DoDAAC) W906ZL Service Acceptor (DoDAAC)
Accept at Other DoDAAC
LPO DoDAAC DCAA Auditor DoDAAC N/A Other DoDAAC(s)
Routing Data Table for Cost Reimbursement CLINs
Field Name in WAWF Data to be entered in WAWF Pay Official DoDAAC W900KK Issue By DoDAAC W900KK Admin DoDAAC** To be completed at Contract Award Inspect By DoDAAC W906ZL Ship To Code N/A Ship From Code Mark For Code N/A Service Approver (DoDAAC) Service Acceptor (DoDAAC) W906ZL Accept at Other DoDAAC LPO DoDAAC
DCAA Auditor DoDAAC To be completed at Contract Award Other DoDAAC(s)
(*Contracting Officer: Insert applicable DoDAAC information. If multiple ship to/acceptance locations apply, insert “See Schedule” or “Not applicable.”)
(**Contracting Officer: If the contract provides for progress payments or performance-based payments, insert the DoDAAC for the contract administration office assigned the functions under FAR 42.302(a)(13).)
(4) Payment request. The Contractor shall ensure a payment request includes documentation appropriate to the type of payment request in accordance with the payment clause, contract financing clause, or Federal Acquisition Regulation 52.216-7, Allowable Cost and Payment, as applicable.
(5) Receiving report. The Contractor shall ensure a receiving report meets the requirements of DFARS Appendix F.
(g) Email notification shall be sent with each invoice or voucher submission to the following contacts:
Contracting Officer Representative
Ph 407-208-5864 James.r.kozlowski.c iv@mail.mil
Rebeca Gonzalez Ph 407-384-3968 Rebeca.a.gonzalez.civ@mail.mil mailto:James.r.kozlowski.civ@mail.mil mailto:Rebeca.a.gonzalez.civ@mail.mil
(1) The Contractor may obtain clarification regarding invoicing in WAWF from the following contracting activity’s WAWF point of contact.
- Ronald Crowder, ronald.j.crowder.civ@mail.mil, ph 407-208-3032, Group Administrator (GAM)
- Thomas Bunch, thomas.j.bunch.civ@mail.mil, ph 407-384-3792, GAM
Officer: Insert applicable information or “Not applicable.”)
(2) Contact the WAWF helpdesk at 866-618-5988, if assistance is needed.
(End of clause)
G2 - Contract Administration Data
Payment Instructions:
https://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#pa yment_instructions, G3 AWARD/EXERCIS E OF OPTION
The Government may unilaterally exercise any or all CLINs designated as an option in Section B of this task order. These option CLINs will be exercised at the Government’s discretion to extend the period of performance of the task order up to twelve (12) months, but may be for less time. Such options may be exercised by issuing a contract modification not later than the last day of the current period of performance. The Government shall comply with FAR 52.217-9, “Option to Extend the Term of the Contract” notice requirements.
Option CLINs Description of CLIN Exercise Period
CLIN 2001 Software Products Development 1 Sep 2022 – 31 Aug 2023
CLIN 2002 Contractor Acquired Property 1 Sep 2022 – 31 Aug 2023 CLIN 3001 Software Products Development 1 Sep 2023 – 31 Aug 2024 CLIN 3002 Contractor Acquired Property 1 Sep 2023 – 31 Aug 2024 CLIN 4001 Software Products Development 1 Sep 2024 – 31 Aug 2025 CLIN 4002 Contractor Acquired Property 1 Sep 2024 – 31 Aug 2025 CLIN 5001 Software Products Development 1 Sep 2025 – 31 Aug 2026
CLIN 5002 Contractor Acquired Property 1 Sep 2025 – 31 Aug 2026 mailto:ronald.j.crowder.civ@mail.mil mailto:thomas.j.bunch.civ@mail.mil http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions http://www.acq.osd.mil/dpap/dars/pgi/pgi_htm/current/PGI204_71.htm#payment_instructions
Section I – Contract Clauses
52.245-1 Government Property JAN 2017
Section J - List of Documents, Exhibits and Other Attachments
EXHIBITS AND ATTACHMENTS
Section J - List of Documents, Exhibits and Other Attachments
Attachments Name Date # of Pages Attachment 1 Statement of Work, #2020-011-01 29 Apr 20202 40 pages Attachment 2 DD254, DoD Contract Security
Classification Specification (See Basic Contract, Attach 14)
25 May 2020 3 pages
Attachment 3 Government Furnished Property Listing (See Basic Contract Attach 9)
10 Mar 2020 4 pages
Attachment 4 Government Equipment (PCTE HW-SW) Property Listing (See Basic Contract Attach 10)
09 Mar 2020 16 pages
Exhibits
A301 DI‐MGMT‐81928 CONTRACTORS PROGRESS AND
STATUS REPORT
3 June 2020 1 page
A302 DI‐ADMN‐81505 Report, Record of Meeting/Minutes 3 June 2020 1 page
SOW-2020-011-03
for the
Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT)
Delivery Order 3 – Persistent Cyber Training Environment (PCTE) Platform Capability Production
U.S. Army Program Executive Office for Simulation, Training, and Instrume ntation (PEO STRI)
12211 Science Drive Orlando, FL 32826-3276
Revision Number Date Log of Changes Made and Description of
Reason Changes Approved By
Table of Contents
1. SCOPE 1
1.1 Introduction
2. APPLICABLE DOCUMENTS
3. REQUIR EMENTS
3.1 Program Manage ment
3.1.1 Monthly Report
3.1.2 Associate Contractor Agreements (ACAs)
3.1.3 Schedule 3
3.1.4 Risk Management
3.1.5 Program Management Reviews (PMRs)
3.1.6 Facilities 4
3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions (CHESS) Program
3.2 Development Operations (DEVOPS) Process
3.2.1 Capability Development, Integration, Delivery and Sustainment
3.2.2 Integration Factory
3.2.3 Agile Ceremonies
3.2.4 Continuous Integration (CI)/Continuous Delivery (CD) Pipeline
3.2.5 Agile System Engineering
3.2.6 Requirements
3.2.7 Architecture
3.2.8 Design
3.2.9 Integration
3.2.10 Test
3.2.11 Configuration Management (CM)
3.2.12 Release Management
3.2.13 Metrics
3.3 Cybe rsecurity
3.3.1 Security Engineering
3.3.2 Army Training and Certification Tracking System (ATCTS) Training
3.3.3 OPSEC
3.3.3.1 Requirements for OPSEC Training
3.3.3.2 Anti- Terrorist Training (AT Level 1)
3.3.3.3 Active Shooter Training
3.3.3.4 Access to Government Information Systems
3.3.3.5 Professional Training and Certification
3.3.3.6 Personal Identifiable Information (PII)
3.3.4 Security and Access Controls
3.3.4.1 General Security
3.3.4.2 Security Clearances
3.3.4.3 Access and General Protection/Security Policy and Procedures
3.3.4.4 Handling or Access to Classified Information
3.3.4.5 Disclosure of Information
3.3.4.6 Effective Use of Controls
3.3.4.7 System Security Plan (SSP)
3.4 Logistics
3.4.1 Licensing and Warranty Management
3.4.2 Data Rights and Commercial Software Agreements
3.4.2.1 Commercial Software Agreements
3.5 Test
3.5.1 CI/CD Testing
3.5.2 Defect Management and Resolution
4. ADDITIONAL CONTRACTOR REQUIREMENTS
4.1 Interaction and/or Disclosure with Foreign Country/Foreign National
Personnel APPENDIX A: Epics for the Persistent Cyber Training Environment (PCTE) -
Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber
TRIDENT)
Delivery Order Three (3)
1. SCOPE
This Statement of Work (SOW) defines the scope of the Project Manager Cyber Test and Training (PM CT2) Product Manager Cyber Resiliency and Training (PdM CRT) Cyber Training, Readiness, Integration, Delivery and Enterprise Technology (Cyber TRIDENT) Delivery Order Three (3). The Cyber TRIDENT Indefinite Delivery/Indefinite Quantity (IDIQ) is utilized by Department of Defense (DoD) organizations and other non-DoD agencies that have related cyber training needs. The Cyber TRIDENT IDIQ provides the management, integration, maintenance, and evolution for the PCTE platform, and provides total system/subsystem acquisition life cycle support for the PCTE system baseline.
This Delivery Order Three (3) SOW defines the detailed requirements that PdM CRT requires to have performed under the Cyber TRIDENT IDIQ contract in support of the PCTE Platform Capability Production. PM CT2 defines the PCTE Platform Capability Production under Cyber TRIDENT Delivery Order Three (3) to include:
• Technology Insertion
• Technology Obsolescence and Evolution
• Backlog Capability Development:
1.1 Introduction
Delivery Order Three (3) will provide the necessary contractor support for the Platform Capability Production of the PCTE capabilities. This covers any technology insertion, obsolescence and evolution for the PCTE capabilities, as well as, addressing the backlog of desired capability development as defined in Appendix A of the SOW.
2. APPLICABLE DOCUMENTS
The applicable documents listed in the Base SOW are applicable to Delivery Order 3. Reference Section 2 of the Base SOW for full list.
3. REQUIREMENTS
The contractor shall provide the Platform Capability Production for the PCTE capabilities. The contractor shall design, deliver, and test platform capabilities to be integrated by Task Order 2.
This will require activities that include technology insertion, technology obsolescence and evolution, and backlog capability development to ensure compliance with Delivery Order (DO) requirements and timely delivery of required products. The contractor shall provide engineering, materials, equipment, and testing for the PCTE Delivery Order Three (3) as described in this
SOW.
3.1 Program Management
The contractor shall provide the overall management and administrative effort necessary to ensure that the requirements of this Delivery Order Three (3) are accomplished. The contractor shall track DO progress, deliverables and financials utilizing metrics specified by the Government. The contractor shall participate, contribute, and execute as an attendee in the Task Order 2 hosted agile ceremonies, design reviews, product demonstrations, Integrated Product Team (IPT) meetings, partnering, transition meetings, conferences, installations, post installation assessments, and life cycle planning of current and future systems/software releases.
3.1.1 Monthly Report
The contractor shall submit a Contractor’s Progress and Status Report that provides information to include but not limited to schedules, accomplishments, metrics, risks, issues, problems, and deficiencies related to this DO’s activities. The monthly report shall include, but not be limited to, status on the below requirements:
• Financial Data
• Agile Event Participation
• Agile Reporting and Metrics
• User Feedback/Prioritization
• Release Planning
• Continuous Integration/Continuous Development Pipeline
• Configuration Management
• Testing Metrics
• Status of Risk Management Issues and Resolutions
• Property Management to identify all new contractor acquired property (CAP)
CDRL Number CDRL Name CDRL A301 Contractor’s Progress and Status Report, DI-MGMT-81928
3.1.2 Associate Contractor Agreements (ACAs)
The contractor shall implement ACAs with other PCTE and third-party contractors as required for exchanging data, accessing and using third party software and equipment, receiving technical support, working interface and integration issues, and DoD Cyber user event planning and execution. The contractor shall ensure that ACAs are maintained to achieve development of the platform and maintain PCTE interoperability and event planning and execution, as applicable.
ACAs shall provide for and permit the complete and unbiased exchange of technical information and data relating to PCTE integration, development and deployment. Agreements shall be structured so that all Cyber TRIDENT and PCTE contractors are obligated to protect proprietary data and classified information from all unauthorized use or disclosure. ACAs shall be submitted to the Government for review prior to execution.
3.1.3 Schedule
The contractor shall plan, execute and deliver contributions within the Government agile scrum processes implemented within Task Order 2. The contractor shall align the schedule to trace to the Agile ceremonies and Industry best practices such as sprint duration, release planning, and other appropriate Agile planning processes. The contractor shall deliver in accordance with the government led monthly sprint periods resulting in incremental capability improvement/incorporation leading to six (6)-month formal releases.
3.1.4 Risk Management
The contractor shall promptly notify the Government of contract performance risks, issues, problems, and deficiencies. In accordance with the contractor’s risk management plan, implement risk detection and identification, assignment of risk categories, risk mitigation planning, mitigation plan implementation, corrective action, tracking of compliance, reporting of status and planning for risk abatement. The contractor shall promptly provide and execute corrective actions plans, in consultation with the Government. The contractor shall include in each Contractor’s Progress and Status Report the status of all outstanding contract performance risks, issues, problems, and deficiencies, as well as corrective actions with respect thereto.
3.1.5 Program Management Reviews (PMRs)
The contractor shall host Program Delivery Order (DO) Review quarterly (per year) to inform the Government of program risks and issues. The contractor shall conduct Technical Interchange Meetings (TIMs) and In Progress Reviews (IPRs) as directed by the Government. The reviews shall provide a forum for IPT members to clarify the following areas of this DO that include but not limited to:
• Technology Insertion
• Technology Obsolescence and Evolution
• Backlog Capability Development
The meetings shall be conducted at the contractor’s Orlando facility unless otherwise agreed-to by the Government. PMR shall cover DO program risks and issues that can affect the entire Cyber TRIDENT portfolio, including parallel TOs/DOs-specific issues and risks as appropriate.
The contractor shall post agendas and meeting minutes to established web portals or SharePoint sites.
CDRL Number CDRL Name CDRL A302 Report, Record of Meeting/Minutes, DI-ADMN-81505
3.1.6 Facilities
The PCTE program has implemented an Agile software development methodology requiring active and daily on-site Government presence to conduct the various Agile ceremonies including daily standup meetings, weekly Architectural meetings, monthly sprint planning meetings, and release planning workshops. As a result of this active and daily Government presence and to facilitate Government testing and collaboration, the facility shall be located no more than ten
(10) miles from PEO STRI at 12211 Science Dr, Orlando, FL 32826.
3.1.7 Material Acquisition - Computer Hardware, Enterprise Software Solutions (CHESS) Program The contractor shall procure hardware, software, and licensing to support the Delivery Order 3 Integration Factory activities. Task Order 1 shall track, inventory, and maintain detailed information on procurements made under Delivery Order 3. The contractor shall comply with the Army’s CHESS program. Under Program Executive Office Enterprise Information Systems (PEO EIS), CHESS is the mandatory source for commercial Information Technology (IT) purchases. CHESS contracts provide IT products and services that comply with U. S. Army Network Enterprise Technology Command (NETCOM), Army and DoD policy and standards.
Purchasers of commercial hardware and software must satisfy IT requirements by utilizing CHESS contracts and DoD Enterprise Software Initiative agreements first, regardless of dollar value. Any purchase made outside of CHESS contracts requires a waiver. A complete list of CHESS contracts and the on-line waiver process can be found at https://protect-us.mimecast.com/s/yDPLCR6K3OIrGJ7iqywO R?domain=chess.army.mil
3.2 Development Operations (DEVOPS) Process
3.2.1 Capability Development, Integration, Delivery and Sustainment To develop, integrate, test, deploy, and sustain capabilities for the PCTE Platform, the contractor shall adhere to the holistic Government led Dev Ops process and utilize the integration factory established in Task Order 2: Integration Factory.
3.2.2 Integration Factory
When participating in the DevOps process, the contractor shall use the integration factory which includes but is not limited to a collaborative meeting space, development environment, and tools.
The contractor shall leverage the collaborative meeting space to attend and participate in Agile ceremonies in a multi- vendor environment as directed by the Government. The contractor shall use the remotely accessible development environment to develop, integrate, test, deploy, and sustain capabilities for the PCTE platform. The contractor shall use the integration factory tooling to participate in Agile Ceremonies and Government ceremonies as well develop, integrate, test, deploy, and sustain capabilities for the PCTE platform. The contractor shall collaborate with the integration factory staff and PCTE vendors to manage PCTE hardware and software infrastructure as directed by the Government.
https://protect-us.mimecast.com/s/yDPLCR6K3OIrGJ7iqywOR?domain=chess.army.mil https://protect-us.mimecast.com/s/yDPLCR6K3OIrGJ7iqywOR?domain=chess.army.mil
3.2.3 Agile Ceremonies
The contractor shall participate in Agile ceremonies to develop, refine, and prioritize requirements as well as plan and monitor the development, testing, integration, and deployment of capabilities for the PCTE platform. The contractor shall participate in Agile ceremonies with other PCTE vendors and provide the Government with regular visibility into the status of capability development. The contractor shall use the integration factory tooling to participate in Agile ceremonies. The contractor shall contribute requirements to the Product Backlog and refine them as directed by the Government Product Owner. The contractor shall ensure that the state of the assigned Backlog items aligns with actual development status.
3.2.4 Continuous Integration (CI)/Continuous Delivery (CD) Pipeline The contractor shall collaborate with the integration factory staff to develop Continuous Integration/Continuous Delivery (CI/CD) pipelines to automate the staged build, test, integration, release, and deployment of their capabilities as described in Task Order 2: Integration Factory.
The contractor shall collaborate with integration factory staff to resolve issues that are discovered during the execution of their CI/CD pipelines as directed by the Government. The contractor shall collaborate with the integration factory staff to analyze production errors with their capability to mitigate those problems in the system design stage.
3.2.5 Agile System Engineering
The contractor shall apply Agile methodologies based on industry best practices throughout the PCTE effort, with all work planned in sprints, defined within a product backlog, with the goal of having a shippable product at the end of each sprint. The contractor's agile process shall achieve results through continuous capability enhancements, prompt response to emerging needs, demonstrated reliability, on reoccurring release cycles. The contractor shall participate and contribute in the Task Order 2 hosted agile ceremonies, including sprint planning, daily sprint standups, sprint retrospectives and sprint demonstrations. The contractor shall provide the requisite technical and programmatic support to complete the required tasks of the individual DOs associated with the PCTE engineering and management. These tasks shall encompass the efforts associated with the development, dissemination, engineering, management, and maintenance of the PCTE architecture, components, and documentation. These tasks shall also include the work efforts associated with the engineering, management, and tracking of PCTE fielded products, PCTE services and platform. The contractor shall identify an agile means of developing, integrating, testing and releasing the PCTE platform consisting of various contributions through an agile methodology facilitating CMF user feedback.
3.2.6 Requirements
The contractor shall execute and manage the development of PCTE software in accordance with the requirements in the contractor's software development process plan. The requirements form the basis for all efforts for the design, development, integration, production, testing and fielding of major and minor iterations of PCTE. The contractor shall deliver products, including ancillary support services, hardware, and software, that support the enterprise management. All analysis and results shall be documented in an integrated database and made available to the Government.
As part of this activity, the contractor shall work within the IPT to iterate the system and System- of- System (SoS) software requirements. The contractor shall manage and record the operational concept for the developed products, and assess the impact of the architectural design to the PCTE platform (identifying the components of the system, their interfaces, and a concept of execution among them) and the traceability between the system components and system requirements for standard and non-standard aids and devices necessary for the system to function and operate.
Based upon analysis of system requirements, system design, and other considerations, the contractor shall manage and record the software requirements to be met by each software item, the methods to be used to ensure that each requirement has been met, and the traceability between the software item requirements and system requirements. The contractor shall manage the evaluation of the Information Assurance (IA) requirements to assess any impacts on developed software and provide potential solutions. The contractor shall conduct architecture evaluations, including stakeholders external to the contractor's organization, for each software build.
3.2.7 Architecture
The contractor shall adhere to the PCTE governance processes and ceremonies to develop PCTE system requirements and architecture in accordance with the contractor’s Agile system engineering process established in Task Order 2: Integration Factory. When contributing to the PCTE architecture, the contractor shall consider the entire lifecycle of the system including but not limited to development, maintenance, and deployment. The architecture shall be designed for extensibility, scalability, maintainability, availability, usability and security using an approach that is based on open standards, products and patterns. The contractor shall contribute to the PCTE operational concept for the system, architectural design of the system (identifying the components of the system, their interfaces, and a concept of execution among them), and the traceability between the system components and system requirements.
The contractor shall research and evaluate the existing PCTE architecture documented in the PCTE PDK and amend it to integrate their capabilities. All analysis and results shall be documented using the integration factory tools and in the PCTE PDK as directed by Government team. The contractor is encouraged to suggest revisions to Government requirements where such revisions would result in cost or schedule reduction or performance improvements. The contractor shall evaluate the PCTE cybersecurity requirements to assess any impacts on developed capability and provide potential solutions, if applicable. In addition, the contractor shall determine if existing open source products are capable of meeting any operational capabilities, perform a detailed product reuse evaluation, and document the results of the analysis. The contractor shall conduct architecture evaluations, including stakeholders external to the contractor’s organization, for each iteration of PCTE. As part of this activity, the contractor shall participate in the PCTE Architecture Working Group (AWG) to iterate on the PCTE system architecture as well as conduct evaluations and reviews.
3.2.8 Design
The contractor shall research, investigate, evaluate, and design capabilities to integrate into the PCTE platform to meet system requirements throughout the entire lifecycle of the system. The contractor shall design the capabilities to be integrated into the PCTE platform to be highly cohesive, loosely coupled, and have severable components to have an open systems architecture capable of procuring at the component level. The capabilities shall be designed for extensibility, scalability, maintainability, availability, usability and security using an approach that is based on open standards, products and patterns. The PCTE platform includes the hardware and software infrastructure as well as the networks and other enabling infrastructure required for the CMF operators to access the system. The PCTE platform also includes the vendor software that allows the CMF to plan, prepare, execute, and assess cyber training events.
The contractor shall work within the PCTE AWG to iterate on designs as directed by the Government. The contractor shall review, evaluate, and recommend improvements to existing designs documented in the PCTE PDK as well as the collaborative wiki. The contractor shall review, evaluate, and recommend improvements to PCTE vendor designs as directed by the Government. Design includes not only design to requirements, but selection of existing products, including open source, to meet system requirements and iterating the requirements to allow use of existing products throughout the life of each TO/DO. Products that perform IA functions are considered cybersecurity or cybersecurity-enabled IT products and shall be selected from the DOD Unified Capabilities Approved Product List and configured in accordance with DOD-approved security configuration guidelines. These include databases which must comply with the DISA database Security Technical Implementation Guide (STIG).
The contractor shall document the PCTE platform designs including but not limited to physical designs and logical designs as well as components of the system, their interfaces, and a concept of execution among them. The contractor shall document designs using the PCTE integration factory tools and incorporate them with the PCTE PDK as directed by the Government team.
3.2.9 Integration
The Contractor shall support the acceptance, modification, integration, and test of future capabilities in order to deliver a comprehensive PCTE system. The Government and contractor/subcontractor team members shall be able to exchange information and collaborate in a distributed environment. The integration environment, shall be based on processes and standards construct that supports data and requirements management, stores collaborative artifacts, software, tools, Technical Data Package (TDP), and architecture products. The Contractor's integration and testing processes shall ensure that new provided capabilities, handover packages, change sets, and bug fixes are fully implemented and satisfy their requirements and respective Use Cases without impacting existing capability prior to integration into the main PCTE baseline.
3.2.10 Test
The contractor shall support the continuum of PCTE platform testing across the agile development lifecycle in accordance with Section 3.5.
3.2.11 Configuration Management (CM)
The contractor shall initially sustain and mature the current CM methodology to establish and maintain the integrity of the components, services, products, and assets throughout the PCTE life cycle. CM shall be implemented throughout the entire period of execution for all components, services, products, and assets of the PCTE system. CM shall be a proactive activity within the PCTE system. CM shall identify, track, and document configuration items, control the configuration items and changes to them, and record and report status, and change activities to these configuration items. CM shall function as a multidimensional version of a typical CM process (multi-phased, multi-program, multi-tiered, multi-instantiated, and multi-baseline), binding the PCTE products and activities. CM shall support parallel development, distribution, and build releases. CM shall address use by all developers, products, and vendors.
The contractor’s CM efforts shall:
a) Identify the configuration items, components, and related work products that will be placed under configuration management
b) Establish and maintain a configuration management and change management system for controlling work products
c) Create or release baselines for internal use and for delivery to the customer
d) Track change requests for the configuration items
e) Control changes in the content of configuration items
f) Establish and maintain records describing configuration items, and
g) Perform configuration audits to maintain the integrity of the configuration baselines.
The PCTE CM shall synchronize with all of CM activities for products and product support within the PCTE system and provide an overarching CM method for all assets, artifacts, and processes. The contractor shall document the software handover process for all other PCTE vendors and shall utilize the CM infrastructure to manage these products. The contractor shall ensure a complete audit trail of decisions and design modifications made to systems, hardware, and/or software being developed, managed, or maintained are tracked and reported
3.2.12 Release Management
The contractor shall execute the release management process for the PCTE platform through the CI/CD Agile process. The contractor shall provide examples, instructions, and tools for developers to integrate their components into the PCTE system. The contractor shall work with each vendor to execute the release management through the development, test, and integration process by planning, scheduling, and controlling the entire software build through each six (6) month iteration. The contractor shall update the production environment using an automation of application installation or a combination of manual installations and automation scripts to deploy applications to the production area of PCTE for all components defined in the reference architecture. The contractor shall manage the PCTE capabilities through each delivery monitoring user management, user access controls, communication services, support services, and monitoring services. The contractor shall ensure each iteration of software is tested prior to the deployment onto the production plane of the RCS.
3.2.13 Metrics
The contractor shall execute the capture and reporting of the Operational Effectiveness and Suitability, Usability, Agile Development, technical performance (e.g., performance scaling, pub-sub, serialization, and API conformance), programmatic, and compliance (e.g., test coverage, and compliance of common component dependency) metrics to validate and verify the capabilities and features delivered by each vendor. The contractor shall document these findings and provide the metrics as feedback to the Government to structure and effectively inform the development to result in an operationally effective platform needed to meet the desired end state.
The contractor shall execute the capture and reporting of agile metrics discussed below to focus on the delivery of the PCTE software. The contractor shall execute the capture and reporting of each of these but not limited to the following agile metrics; Sprint Burndown, Epic and Release Burndown, Velocity and Defect Work-off, to ensure the development process runs smoothly and a cumulative flow is available to the Government team and vendors as necessary to ensure the flow of work across the teams and vendors is consistent.
3.3 Cybersecurity
The contractor shall ensure cybersecurity is implemented throughout all capabilities and products developed under Delivery Order 3 to ensure no negative impacts to the PCTE accreditation. The contractor shall implement cybersecurity in products and capabilities at a number of classification levels and environments to include Closed, Restricted Networks (CRNs), Open Secret Internet Protocol (IP) Router (SIPRNET), Open Non-Classified IP Router (NIPRNET), and Top Secret/Sensitive Compartmented Information (SCI).
1. The contractor shall leverage the National Information Assurance Partnership (NIAP) and the Common Criteria Evaluation and Validation Scheme (CCEVS) to ensure Defense Information Systems Agency (DISA) approved software and hardware are utilized within the PCTE construct and PCTE supported components, services, and assets.
2. The contractor shall also ensure that the common components and services developed and maintained within PCTE are implemented in accordance with DISA STIG compliance.
The contractor shall complete the DISA STIGs implementation for the IT technology developed and provide completed STIG checklists to document compliance.
3. The contractor shall evaluate the security of the products created on this delivery order, both physical and logical, identifying exposures and providing protective options for reducing security risk. The contractor shall deliver upgrades to the system in a configuration that will pass a certification and will not negatively impact the existing accreditation.
4. The contractor shall implement protective measures to provide Information Security.
When Classified or Controlled information is introduced into the PCTE, the contractor shall adhere to the provisions within DoD 5220.22M NISPOM and AR 380-5 regarding the classification, transmission, transportation, and safeguarding of this information.
Cryptography shall be Federal Information Processing Standards (FIPS) 140-2 compliant.
There shall be a mechanism established to ensure encrypted data can be recovered in the event the primary encryption system fails.
5. The contractor shall integrate protective mechanisms into the system and applications to provide identification and authentication, access control, accountability, availability, confidentiality, privacy, data integrity, and non-repudiation.
6. The contractor shall test and certify that application software is designed to function in a properly secured operating system environment and is free of elements that might be detrimental to the secure operation of the resource operating system, as described in National Institute of Standards and Technology Special Publication (NIST SP) 800-37.
7. The contractor shall use Government approved assessment tools to perform cyber security testing to document, verify, and validate each applicable operating system security configuration.
8. The contractor shall document the unincorporated security controls defined in the applicable STIG and unincorporated IA and Vulnerability Alerts (IAVA’s) in the Plan of Action and Milestones (POA&M) document.
3.3.1 Security Engineering
The contractor shall comply with the Agile ceremonies, DevOps process, and Security Engineering process created under Task Order 2 that emphasizes the collaboration of PCTE Vendors, Operations Team as well as Cyber Security Teams. The DevOps process shall emphasize cyber security teams collaborating with all teams to ensure the continued secure operations as products and capabilities are developed. When engineering security solutions for the PCTE platform, the contractor shall consider the Authority to Operate (ATO) that is being maintained under Task Order 2. When engineering security solutions, the contractor shall consider the existing security solutions described in the PCTE PDK for efficiency and reuse potential.
The contractor shall implement and integrate a holistic approach to Information Security (IS) and data security that protects against unauthorized (accidental or intentional) disclosure, modification, or destruction.
1. The IS security shall consider the following:
a. All hardware and software functions, characteristics, and features
b. Operational procedures
c. Accountability procedures
d. Access controls, remote computers, and terminal facilities
e. Management constraints
2. The contractor shall provide an adequate level of protection for the IS and data contained in the IS. An adequate system ensures a security approach commensurate with the risk and magnitude of harm resulting from the loss, misuse, or unauthorized access to or modification of information.
3. The IS security and Cybersecurity approach shall include controls that are part of the day- to-day operations of the system, and are compliant with AR 25-2, DoDI 8500.01, DoDI 8510.01, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A and DoDI 8582.01.
The contractor shall collaborate with PCTE Vendors and leverage the integration factory tooling to comply with the established cyber security stages in the CI/CD pipelines for all capabilities and products created to automate the identification of vulnerabilities. The contractor shall perform manual vulnerability analysis on the system when automated solutions do not exist.
When possible, the contractor shall automate the implementation of security controls.
3.3.2 Army Training and Certification Tracking System (ATCTS) Training
The Contractor shall require that lead and support personnel performing Cybersecurity job functions possess the Information Assurance Management (IAM) or Information Assurance Technical (IAT) certification relevant to their role within the execution of this contract and IAW DoDD 8140.01, DoD 8570.01-M, AR 25-2 (4-3 Information Assurance Training), and Army BBP 05-PR-M-002. IA engineers, analysts, and technicians shall complete the required “IA Awareness Training.” Method of training for “IA Awareness training” is https://cs.signal.army.mil/default.asp “DoD Cyber Awareness Mandatory IA Training,” The Contractor’s IA Team shall complete the required “Information Assurance Fundamentals Training.”
1. This shall include the methods, skills, use, and mechanisms to maintain the level of security of the IS.
2. The training shall be geared toward the audience and their roles and responsibilities with respect to the system’s operation and maintenance (i.e., system administrator, network administrator, hardware maintenance, etc.).
3. The contractor shall utilize DOD 8570.01-M as a guide in the development of the IA
Training content.
3.3.3 OPSEC
The contractor shall ensure this DO is in compliance with the base contract existing OPSEC Plan and Standing Operating Procedure/plan within ninety (90) calendar days of DO award making any necessary updates, to be reviewed and approved by the responsible Government OPSEC officer. The plan’s updates shall include a process to identify Critical Information List (CIL), where it is located, who is responsible for it, how to protect it, and why it needs to be protected https://cs.signal.army.mil/default.asp https://cs.signal.army.mil/default.asp in accordance with Security Classification Guides (SCGs). The contractor shall implement OPSEC measures as ordered by the Government. In addition, the contractor shall have an identified certified Level II OPSEC coordinator per AR 530-1.
3.3.3.1 Requirements for OPSEC Training
Per AR 530-1, Operations Security, new contractor employees must complete Level I OPSEC training within thirty (30) calendar days of their reporting for duty. The contractor shall ensure all applicable employees have completed OPSEC initial training, annual refresher training, and shall certify their work force has completed the training through the submission of completion certificates(s) to the COR, or the Contracting Officer when a COR is not assigned, within thirty
(30) days of arrival on the installation. OSPEC training can be accomplished at the Defense Security Services website at: https://securityawareness.usalearning.gov/opsec/
3.3.3.2 Anti-Terrorist Training (AT Level 1)
All contractor employees, to include subcontractor employees, requiring access to DoD installations, facilities and controlled access areas shall complete AT Level I awareness training within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee, to the COR or to the Contracting Officer within 30 calendar days after completion of training by all contractor employees and subcontractor personnel. AT Level I awareness training is available at the following website: https://atlevel1.dtic.mil/at or other Service specific websites.
The contractor shall ensure all US based Contractor employees and associated subcontractor employees to make available and to receive Government provided area of responsibility (AOR) specific AT awareness training as directed by applicable DoD, Service policy and regulations.
Specific AOR training content is directed by the Combatant Commander with the unit Anti- Terrorism Officer (ATO) being the local point of contact.
3.3.3.3 Active Shooter Training
installations, facilities and controlled access areas shall complete active shooter training as directed by applicable DoD, Service policy and regulations within thirty (30) calendar days after DO start date or effective date of incorporation of this requirement into the DO, whichever is applicable. The contractor shall submit certificates of completion for each affected contractor employee and subcontractor employee, to the COR/ACOR or to the Contracting Officer within thirty (30) calendar days after completion of training by all contractor employees and subcontractor personnel.
3.3.3.4 Access to Government Information Systems
All contractor employees with access to a Government Information System must be registered in the applicable Service training and certification system at commencement of DO performance https://protect-us.mimecast.com/s/10sqC4xvMQuBVRwfNKr6z?domain=securityawareness.usalearning.gov https://protect-us.mimecast.com/s/KTyvC5ywNQFZJwrT4smug?domain=atlevel1.dtic.mil and must successfully complete DoD Information Assurance Awareness training prior to being granted access to information systems (IS) and then annually thereafter.
3.3.3.5 Professional Training and Certification
The contractor shall be responsible to ensure that employees, to include subcontractor employees, at all times maintain the required professional training and certifications required for their job description(s) and role(s).
Per DoD 8570.01-M, DoDD 8140.01, Defense Federal…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .