RFI_Castle_Keep.pdf

PDF 402 KB Posted

Attached to
Castle Keep Federal contract opportunity
Solicitation number
W904TE-19-R-0002
Issued by
Department of the Army Acquisition Support Center PEO Enterprise Information Systems

About this file

RFI for Castle Keep Project

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

REQUEST FOR INFORMATION (RFI)

CASTLE KEEP

This RFI does not constitute an Invitation for Bid or a Request for Proposals, nor should it be considered as a commitment on the part of the Government. The information received WILL NOT obligate the

Government in any manner nor will the Government reimburse companies for any costs associated with providing a response to this RFI. Any information obtained because of this RFI is intended to be used by the Government on a non-attribution basis for market research to identify vendors with the necessary capabilities to support the U.S Army.

By submitting information in response to this RFI, respondents consent to the release and dissemination of submitted information to any Government or non-Government entity to which PEO-EIS TAO releases and/or disseminates the information for review. As such, to the extent that any information submitted in response to this RFI is marked as, or construed to be proprietary or business-sensitive, respondents are hereby notified (a) of the potential that such information may be disclosed to third parties and (b) that submission of information in response to this RFI constitutes consent to disclosure of submitted information. NO phone calls and/or request for a Solicitation will be accepted or acknowledged.

Company Brochures are NOT desired.

Technical questions regarding this RFI should be directed to Ms. Kristen Lawrence, 301-619-1762, or kristen.k.lawrence.civ@mail.mil, or mailed to PEO-EIS, Technology Applications Office, ATTN: SFAE-PS-

TS-TAO-C (Kristen Lawrence), 1671 Nelson Street, Fort Detrick, MD 21702-5044.

The Government requests responses to this RFI be submitted NO LATER THAN 19 October at 11:00 AM

EDT. All Interested parties must submit in writing (no more than 15 pages, single spaced) their capabilities, experience and familiarity with providing the services stated below. Marketing materials are not a sufficient response to the RFI. The responses should be in Adobe Acrobat Portable Document

Format (PDF) or in a format compatible with Microsoft Office. Please submit your responses via email to: Ms. Kristen Lawrence at kristen.k.lawrence.civ@mail.mil.

The United States (U.S.) Army Program Executive Office for Electronic Information Systems (PEO-EIS)

Technology Applications Office (TAO) is requesting information about technical expertise to aid the

Army’s Special Security Office (SSO) with an existing automated management toolset, the technical expertise required includes continued development and testing as well as implementation, deployment, and maintenance support. The SSO management toolset will provide the following to the Army SSO community:

- The ability to conduct continuing review of SCI security programs including oversight and evaluations

- The system must enable the management of training programs for Sensitive

Compartmentalized Information (SCI) security officials.

- The capability to store, share, audit and query all associated records and reports.

- Will support up to 5,000 SSO users

System requirements are as follows and the vendor must have experience with the following:

- NETWORKs: NIPR and the Joint Worldwide Intelligence Communication System (JWICS) o Development, test, and production environment

- Cloud Services:

o Cloud tools provided by Amazon Web Services (AWS). Vendor must have experience with both AWS and Intelligence Community (IC) Commercial Cloud Services (C2S)

- Tools and Standards:

o Java Language o Load balancing o Apache Web o Jboss EAP o Apache Accumulo/Zookeeper o Postgres o Message Queuing o Hadoop Storage o FIPS 140-2 Compliant Encryption o Auto Scaling o 500-27 Compliant Auditing o Role Based Access Management o “Services Oriented Architecture (SOA)” o Department of Defense Architecture Framework (DoDAF) Documentation

The Contractor will be required to provide the following Information Technology (IT) services:

- Software Maintenance

- Software Development and Enhancements (all will be identified and approved by the SSO)

- Support to daily system functionality

- Achieve and maintain system accreditation on JWICS (Authority to Operate) o Must have familiarity with the Risk Management Framework (RMF) o Must be familiar with the security requirements and processes detailed within the

Intelligence Community Directive (ICD) 503, Committee on National Security

Systems (CNSS) 1253, and Risk Management Framework (RMF), NIST 800-37, NIST

Special Publication (SP) 800-53 and 800-53A

- Database Management and Search o Must have familiarity with Accumulo NoSQL o Amazon Web Services (AWS) PostGresSQL Relational Data Service

- Workflow Management

- Account Management

- Limited Training Support (will be very limited and is not a helpdesk)

- System Fielding and Testing

Security Requirements:

- Vendor must have a Defense Security Services (DSS) Facility Security Clearance (FCL) at the

Top Secret (TS) Level and safeguarding at the TS level.

- Vendor must have personnel cleared to TS with access SCI (SI/TK/HCS/G caveats) information in accordance with ICD 704 and/or the Department of Defense Manual (DoDM)

5205.07 Volume II, respectively.

- Ideally the Government would like the vendor to have the ability/capability to safeguard and process information at the TS/SCI Level within their own accredited Sensitive

Compartmented Information Facility (SCIF). Please provide information on possible solutions if this is not currently not possible.

Additional Requirements/Clarifications:

- Vendor has a secure facility located within the National Capital Region (NCR) with the ability to travel infrequently to Charlottesville, VA. Prefer to have the large majority, and all key personnel in the NCR.

- Government anticipates approximately 5-6 Full-Time Equivalents (FTEs) are needed for this contract (1 x Program Manager/Intel Subject Matter Expert (SME), 1 x Security Engineer, 1-2

System Developers, 1 x Software System Engineer, 1 x Mid-Level

Engineer/Documentation/Test)

- Government anticipates a commercial services contract with the potential of being firm-fixed price (FFP).

Responses should include answers to the following questions:

1. Does your company have a Defense Security Services (DSS) Facility Security Clearance (FCL)? If so, what level?

2. Does your company have its own accredited SCIF? If not, does your company currently have an agreement to allow you access to an accredited SCIF? Is that at a government or contractor facility, is there an existing MOA/MOU in place, etc.?

3. Does your company have its own JWICS terminal within your own accredited SCIF; if not, (2) does your company have access to a JWICS terminal within someone else's accredited SCIF? If so, how many can this accommodate, is it a government site, is there an existing MOA/MOU in place, etc.

4. What is your company's experience with the DoD RMF and Assessment & Authorization processes? Does your company have experienced SMEs capable of performing the functions associated with the aforementioned system, IT Services, and security requirements?

5. What is your defined software process? Include details on your process to develop, compile, test, manage versions and deploy software.

The Capability Package must be clear, concise, and complete and shall include {in addition to the technical aspects above), at a minimum:

1. Identify the organization's name, address, telephone number, and point of contact {also with title, phone, fax, and e-mail) on packaging and title pages. The organization name should appear clearly on every page of your submittal and proprietary information must be clearly marked.

2. NAICS Code: 541512

Organization size/ownership of business {i.e. large, small, small disadvantaged, 8{a) Disable-

Veteran, Veteran, Woman-owned Business, Hub Zone).

3. Number of years in business

4. Cage Code

5. DUNS# & Tax ID#

6. Company Profile (Number of employees, annual sales history, locations and if CCR registered).

7. Identify if you are a GSA Schedule Holder

8. Affiliate Contractor {if potential sub) or subcontractors {if potential prime).

9. Contract references in the past five (5) years relevant to the requirement to include: contract number, agency supported, whether or not you were the prime or a subcontractor, period of performance, original contract value, final or current contract value, technical monitor and phone/fax number, POC with current phone/fax number, and a brief description of the effort.

In addition, all responses should be unclassified and marked appropriately to ensure consideration of operational sensitivities.

File details come from the government source that posted it.