Attachment_J-2_PWS_QASP_Seed_Task_Order_2_Network_Engineering_122018.pdf

PDF 556 KB Posted

Attached to
High Performance Computing Modernization Program (HPCMP) Integrated Technical Services -Restricted (HITS-R) II Federal contract opportunity
Solicitation number
W912DY-19-R-0001
Issued by
Department of the Army Corps of Engineers Engineering Support Center Huntsville

About this file

This document provides details for the High Performance Computing Modernization Program (HPCMP) Integrated Technical Services - Restricted (HITS-R) II solicitation. The U.S. Army Corps of Engineers, Engineering and Support Center requires a single award task order contract to support the DoD Science and Technology, Research and Development, and Test and Evaluation communities accessing the DoD HPCMP Supercomputer systems and associated networks. Services include supporting the five DoD Supercomputing Resource Centers and associated local and wide area networks as well as developing HPC software applications and support environments. The solicitation will be issued in November 2018 as a 100% small business set-aside with a NAICS code of 541513 and size standard of $27.5M. The task orders will be fixed-price and cost-plus-fixed-fee over a five-year ordering period. The proposal due date will be specified in the solicitation.

Seed Task Order 2 PWS_QASP

View the file

Other files for this federal contract opportunity

Other files attached to High Performance Computing Modernization Program (HPCMP) Integrated Technical Services -Restricted (HITS-R) II, newest first.
File Type Posted
ProjNet_Q&A_04_March_2019_.pdf PDF
Attachment_J-2_PWS_QASP_Seed_Task_Order_2_Network_Engineering.pdf PDF
Attachment_J-8a_Technical_Personnel_Skill_Mix_TO1_FFP.xlsx XLSX spreadsheet
Attachment_J-27_Solicitation_Requirements.xlsx XLSX spreadsheet
Attachment_J-4_Seed_TO1_FFP.xlsx XLSX spreadsheet
Attachment_J-5_Seed_TO2_CPFF.xlsb XLSB spreadsheet
Amendment_0004.pdf PDF
Attachment_J-7_FFP_Base_Labor_Detail.xlsb XLSB spreadsheet
Attachment_J-1_PWS_QASP__Seed_Task_Order_1_IT_Telecomm_Support.pdf PDF
Amendment_0003_W912DY-19-R-0001_HITSR2.pdf PDF
Attachment_J-8_Technical_Personnel_Skill_Mix_TO1_FFP_7Feb19.xlsx XLSX spreadsheet
Attachment_J-6_CPFF_Base_Labor_Detail_7Feb19.xlsb XLSB spreadsheet
Attachment_J-8_Technical_Personnel_Skill_Mix_TO2_CPFF_7Feb19.xlsx XLSX spreadsheet
Attachment_J-4_Seed_TO1_FFP.xlsx XLSX spreadsheet
Amendment_0002.pdf PDF
DREN_Overview_Distro_A_Jan2019.pdf PDF
Attachment_J-5_Seed_TO2_CPFF.xlsx XLSX spreadsheet
ProjNet_Answers_5_Feb_19.pdf PDF
Attachment_J-2_PWS_QASP_Seed_Task_Order_2_Network_Engineering.pdf PDF
Attachment_J-7_FFP_Base_Labor_Detail.xlsb XLSB spreadsheet
Government_Furnished_Property_Listing_-_HITS-R.PDF PDF
DREN_Map_Distro_A_as_of_20180629.PDF PDF
Attachment_J-8_Technical_Personnel_Skill_Mix_TO2_CPFF.xlsx XLSX spreadsheet
Amendment_0001.pdf PDF
Attachment_J-14_CDRL_A006_Weekly_Financials_HITS-R2.pdf PDF
Attachment_J-1_Seed_Task_Order_1_PWS_QASP_122018.pdf PDF
Attachment_J-17_CDRL_A009_T&E_Plans_HITS-R2.pdf PDF
Attachment_J-23_CDRL_A015_Kickoff_HITS-R2.pdf PDF
Attachment_J-10_CDRL_A002_Briefing_Material_HITS-R2.pdf PDF
Attachment_J-15_CDRL_A007_Recommendations_HITS-R2.pdf PDF
Attachment_J-18_CDRL_A010_RMF_HITS-R2.pdf PDF
Attachment_J-12_CDRL_A004_Monthly_Status__HITS-R2.pdf PDF
Attachment_J-25_Draft_DD_254.pdf PDF
Attachment_J-27_Solicitation_Requirements.xlsx XLSX spreadsheet
Attachment_J-8_Technical_Personnel_Skill_Mix_CPFF.xlsx XLSX spreadsheet
Attachment_J-22_CDRL_A014_Monthly_Financial_HITS-R2.pdf PDF
Attachment_J-24_CDRL_A016_Specifications_HITS-R2.pdf PDF
Attachment_J-6_CPFF_Pricing_Spreadsheet_Base_Labor_Detail_Locations_BASE.xlsx XLSX spreadsheet
Attachment_J-26_SF1408-14b.pdf PDF
Attachment_J-16_CDRL_A008_Config_plans_HITS-R2.pdf PDF
Attachment_J-19_CDRL_A011_Monthly_Inventory_HITS-R2.pdf PDF
Attachment_J-13_CDRL_A005_Trend_Analysis_HITS-R2.pdf PDF
Attachment_J-4_Seed_Task_Order_1_FFP_Pricing_Spreadsheet_-_Labor_Detail.xlsx XLSX spreadsheet
Attachment_J-7_FFP_Pricing_Spreadsheet_Base_Labor_Detail_Location_BASE.xlsx XLSX spreadsheet
Attachment_J-3_Past_Performance_Questionnaire.pdf PDF
Attachment_J-21_CDRL_A013_Phase_out_HITS-R2.pdf PDF
W912DY-19-R-0001.pdf PDF
Attachment_J-9_CDRL_A001_Trip_Reports_HITS-R2.pdf PDF
Attachment_J-11_CDRL_A003_SAR_HITS-R2.pdf PDF
Attachment_J-5_Seed_Task_Order_2_CPFF_Pricing_Spreadsheet_-_Labor_Detail.xlsx XLSX spreadsheet
Show all 50

High Performance Computing Modernization Program (HPCMP) Integrated Technical Services -Restricted (HITS-R) II has more files on GovTribe.

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement

And

Quality Assurance Surveillance Plan

HITS-R 2

Task Order 2: Network Engineering Support

For: HPCMP

November 26, 2018

1.0 Acronyms.

ACRONYMS DEFINITIONS

ADC Allocated Distributed Center

AFARS Army Federal Acquisition Regulation Supplement

ARL Army Research Laboratory

AASD Assisted Acquisition Services Division

AQL Acceptable Quality Level

ASC Aeronautical Systems Center

C&A Certification and Accreditation

CISSP Certified Information Systems Security Professional

CPCM Certified Professional Contracts Manager

CPSM Certified Professional In Supply Management

CCNP Cisco Certified Network Professional

CARD Cost Analysis Requirements Document

CERT Computer Emergency Response Team

CND Computer Network Defense

CSA Comprehensive Security Assessment

CSSP CyberSecurity Service Provider

COEA Cost and Operational Effectiveness Analysis

COR Contracting Officer’s Representative

CREATE Computational Research and Engineering Acquisition Tools and Environments

Environments

CTA Computational Technology Areas

CTO Command Task Orders

DHPIs Dedicated HPC Investments

DFAR Defense Acquisition FAR Supplement

DOD Department of Defense

DREN Defense Research & Engineer Network

DSRC DOD Supercomputing Resource Center

DIACAP DOD Information Assurance Certification & Accreditation Process

DIARMF DOD Information Assurance Risk Management Framework

DTS Defense Transportation System

ERDC Engineer Research Development Center

FAR Federal Acquisition Regulations

FAS Federal Acquisition Service

HBSS Host Based Security System

HPC High Performance Computing

HPCMP High Performance Computing Modernization Program

HPCMPO High Performance Computing Modernization Program Office

IAM Information Assurance Manager

IMS Integrative Master Schedule

IT Information Technology

ITIL Information Technology Infrastructure Library

IPT Integrated Product Teams

IAVA Information Assurance Vulnerability Alerts

IAVM Information Assurance Vulnerability Management

INFOCON/CYBERCON Information Operations Condition

JPAS Joint Personnel Adjudication System

KO Contracting Officer

LAN Local Area Network

MCSE Microsoft Certified Systems Engineer

MCSD Microsoft Certified Software Developer

MIPR Military Interdepartmental Purchase Request

MOA Memorandum of Agreement

NAVO Naval Oceanographic Office

OR Operational Requirements

OSD Office of the Secretary of Defense

POC Point of Contact

PWS Performance Work Statement

PMP Project Management Professional

QAP Quality Assurance Program

QCP Quality Control Plan

R & D Research and Development

RDT&E Research, Development, Test, and Evaluation

RMF Risk Management Framework

S&T Science and Technology

SAR Situational Awareness Report

SAV Site Assistance Visits

SDP Service Delivery Point

SDREN Secret Defense Research & Engineer Network

ST&E Security, Test and Evaluations

Security Detection, delay and response

Section 508 Section 508 of the Rehabilitation Act of 1973

SOPs Standard Operating Procedures

Specification Technical characteristics or parameters that describe the operational characteristics of a system or product

T&E Test and Evaluation

Timeliness Within the time specified by the performance objective

UAG User Advisory Group

VMS Vulnerability Management System

VPN Virtual Private Network

VS Vulnerability Scanning

WAP or AP Wireless Access Points

WNC Wireless Network Access

2.0 Assumptions:

2.1 Objective. To provide engineering and technical resources to the perform a broad assortment of system engineering and integration functions necessary to accomplish project technical goals such as: system and equipment design analysis and studies, development and verification of design, product, interface, and specifications, technical papers and studies, master test plans and integration, preparation of briefing data, and installation of hardware systems and equipment to support the Defense Research and

Engineering Network (DREN) mission objectives. The main areas of support include

Network Engineering, Network Operations, Network/Security Database Development and Maintenance Support, and Network Security Support.

2.2 Background. The DREN is a technology-led, innovation-focused program committed to extending High Performance Computing to address the DOD’s most significant challenges. The DREN accomplishes this goal my developing and maintaining the

(DREN) and its Secret overlay (SDREN), as part of the High Performance Computing

Modernization Program (HPCMP) ecosystem consisting of DoD Supercomputing

Resource Centers, networking and security, and software applications.

2.3 Place of Performance. The Government anticipates the primary place of performance:

Lorton Support Office, 10501 Furnace Road, Lorton, VA 22079

The DREN Networking Operations Center, Aberdeen Proving Ground, Aberdeen, MD

Space and Naval Warfare Systems Center Atlantic – St Julien’s Creek, Portsmouth, VA

Space and Naval Warfare Systems Center Pacific – San Diego, CA

While any or all of these locations are subject to change, the contractor will be required to provide support for these requirements regardless of location.

The contractor may be required to perform duties at an alternate work location, as designated by the Government. Situations and conditions requiring alternate work locations include, but are not limited to, contingency operations, emergency shutdowns and a declared designated alternate work site. Additionally, the Government anticipates that some work may require travel to the HPC’s subscriber sites.

Tasks may be performed at any of the facilities within the HPCMP footprint, such as locations list below:

Army Research Laboratory (ARL) DSRC: Adelphi, MD

Air Force Research Laboratory (AFRL) DSRC: Wright-Patterson, OH

Navy Oceanographic (NAVO) DSRC: Stennis Center, MS

Engineer Research and Development Center (ERDC): Vicksburg, MS

Maui High Performance Computing Center (MHPCC) DSRC: Maui, Hawaii

2.4 Key Personnel. The contractor shall identify a Task Order Technical Manager who will provide management support to this task order and ensure that all requirements that affect integration efforts are made known to the program manager and his/her alternate for coordination (referenced in the base PWS). The identified task order technical manager on this contract shall have full authority to act on behalf of the contractor for all issues pertaining to contract administration for this task order. This manager will possess at least a Bachelor's degree in computer science, information systems, IT Network Engineering or other related discipline with a minimum of ten (10) years management experience plus a minimum of ten (10) years IT support management experience similar to the size and scope reflected in this PWS. The experience can be Federal or private industry.

Qualifications are subject to Government review and concurrence. The task order manager shall be available during normal working hours to meet at the HPCMPO with

Government personnel designated by the Contracting Officer (KO), HPC Program

Manager (PM) or Contracting Officer's Representative (COR) within two hours of notification.

3.0 Applicable Documents. The following documents apply along with any subsequent updates:

DoDI 8530.01, “Cybersecurity Activities Support to DoD Information Network Operations”

Change 1, July 25, 2017DOD Instruction 5000.2, Defense Acquisition Management Policies and Procedures

CJCSM 6510.01B, “Cyber Incident Handling Program,” July 10, 2012

DoDI 8582.01, “Security of Unclassified DoD Information on Non-DoD Information

Systems” of June 6, 2012

DoDM 5200.01, Volume 4, “DoD Information Security Program: Controlled Unclassified

Information” February, 2012

FAR (48 CFR) Subpart 4.19, “Basic Safeguarding of Contractor Information Systems” (see also FAR Subparts 7, 12, & 52)

DoDI 5000.02, Enclosure 14, “Cybersecurity in the Defense Acquisition System” January 7, DoDD 8140.01, Change 1, “Cyberspace Workforce Management,” 31 July 2017

4.0 Tasks Requirements. In accordance with the HPCMP Integrative Technical Services –

Restricted (HITS-R) Contract, the contractor, as an independent contractor and not as an agent of the Government, shall provide the necessary resources (except for those identified as Government

Furnished Property) to support the following tasks:

4.1.1 Network Engineering. Provide engineering and technical resources to perform system engineering and integration functions necessary to accomplish project technical goals and support the Defense Research and Engineering Network

(DREN). These efforts shall include the designing, configuring, and installation of systems to include but not limited to F5, Palo Alto, Fluency, Fidelis, Bluecoat, Juniper, Brocade and implementation of technologies to include but not limited to DNS routing/filtering, Malware Detection, Web Proxy/Web Content Filtering, Full Packet Capture, Net Flow, Break and Inspect in support DREN requirements.

4.1.2 Investigate HPCMP/DREN program requirements, perform studies, analyze system/equipment performance and submit recommendations for development, upgrades, modifications, or alterations of hardware and/or software as appropriate to improve system operation and enhance security posture in the field environment.

4.1.3 Study ORs to determine system performance criteria and to outline functional requirements. When required, performance specification(s) shall be generated/reviewed in order to specify, in detail, system requirements based upon the operational approach and selected alternative. The contractor shall participate in design reviews, technical reviews and discussions regarding

HPCMP systems, equipment and programs as directed.

4.1.4 Review engineering and technical documentation such as technical manuals, test procedures, test plans and drawings, and as-builts as delivered by other contractor and Government activities and provide comments and recommendations for acceptance, correction or improvements. The contractor will provide engineering and technical expertise for the review of production contract deliverables and drawings, develop and maintain applicable Standard

Operating Procedures (SOPs), develop and maintain deployment and installation documentation (e.g., network diagrams, site surveys), develop regression testing plans, and perform regression testing to support code upgrades on current and future hardware deployed to support the SDREN WAN and DREN ancillary equipment. Current hardware platforms deployed are Juniper routers, and SRX

Firewalls, Juniper SSL VPNs as well as all Raytheon encryptor models.

4.1.5 Conduct R&D based upon HPCMP Technical Directions.

4.1.6 Network Operations (NETOPS). Provide engineering and technical resources to perform system engineering and integration functions necessary to accomplish project technical goals in services for the SDREN NETOPS and deployed DREN

Ancillary, to include Firewalls, Switches, SAMP/DAMPs, Joint Sensors, equipment in the form of deployment and management of all hardware associated with the delivery of SDREN service to a customer location, as well as the

SDREN core network itself, and delivery of stateful inspection firewall capabilities and ancillary equipment such as layer 2 switches, Joint Sensors and

Internet Access Point (IAP) hardware at various DREN locations during operating hours with one person on call each week night. This effort shall support efforts at both the Aberdeen Proving Grounds, MD facility and St

Julien’s Creek, Portsmouth, VA facility. Locations may be subject to change in the future.

4.1.7 Manage Network Operations (NetOps) team.

4.1.8 Manage Key Management of the SDREN closed partition preplaced and firefly keys for all SDREN node locations and provide technical assistance for the

‘Really Simple Key Loader’ (RASKL) and “Simple Key Loader’ (SKL).

4.1.9 Provide the following to SDREN customers on-line:

4.1.9.1 MRTG Statistics

4.1.9.2 IAVA, IAVB, IAVT alerts

4.1.9.3 Symantec, McAfee and Trend Micro software releases.

4.1.9.4 RADIX/CSA Security Analysis Scripts (Unix/MAC Platforms)

4.1.9.5 Performance Tools and Literature, as well as Network Performance Self

Help Documentation as required by the HPCMP

4.1.9.6 Windows Server Update Services (WSUS)

4.1.9.7 Microsoft Baseline Security Analyzer and associated signature files

4.1.10 Other data or documentation as required by the Government.

4.1.11 Build-out, deployment and maintain the HPCMP Joint Sensor

4.1.12 Manage and maintain Communications Security (COMSEC) account for the

SDREN Wide Area Network (WAN)

4.1.13 Be responsible for development and maintenance of SDREN Network

Operations Center (NOC), SDREN WAN and HPC Operations Certification and accreditation/Risk Management Framework (RMF) packages

4.1.14 Support the development and maintenance of policy relevant to DREN/ SDREN security as well as DREN/SDREN Operations.

4.1.15 Support development of DREN Accreditation/RMF documentation in support of

DREN/SDREN. Develop and maintain DREN and SDREN accreditation documentation.

4.1.16 Support management of all U.S Cyber Command and Service level CTOs, Service level CSSP, HPC CSSP and site level firewall block and change requests

4.1.17 Supports management of the acceptance of all DREN Service Agreements and all

SDREN Connection Approval Packages (includes working with sites individually so a complete agreement or package is on file in accordance with

HPCMP policy).

4.1.18 Provide engineering and administration support as well as oversight on

HPCMPO and HPC Operations Local Area Networks (Firewall, SSL VPN, Wireless Access, Backbone switches, servers, Active Directory, Open Directory) to include the following:

4.1.19 Configure and maintain Solarwinds Orion (or other ) network management tools, and JIRA ticketing system software or other network management tools deployed or as directed.

4.1.20 Manage and maintain Domain Name Service on SDREN. This is to include

DNSSec.

4.1.21 Manage and maintain Email Service for SDREN customers.

4.1.22 Manage and maintain DREN and SDREN, CORE and customer, IPv4 and IPv6 addressing plans and allocations.

4.1.23 Provide local Network Performance trouble shooting and assistance as directed using GFE and commercial network performance tools.

4.1.24 Manage maintain, upgrade the DREN Portal as required.

4.1.25 Perform remote management and over the air rekey utilizing Encryptor

Management tools.

4.1.26 Manage, maintain, upgrade and configure current and future hardware platforms to support the SDREN WAN and DREN ancillary equipment. Current hardware platforms deployed are Juniper routers, and Juniper SRX Firewalls, Juniper SSL

VPNs, all encryptor models as well as Brocade switches in an enterprise setting.

4.1.27 Must be proficient in all aspects of IPv4 and IPv6 routing, multicast, jumbo frame configuration on all network and firewall platforms.

4.1.28 Manage and maintain current and future SAN infrastructure to support near real time data replication and Continuity of Operations.

4.1.29 Ensure all managed systems meet DoD 8500.1 IA requirements.

4.1.30 Ensure support personnel meet and maintain DoD 8570 certification requirements commensurate with their abilities and administrative position, and possess these 8570 minimum certifications upon hire. All other required certifications must be obtained within six months of hire. All contractors must enter certifications in ATCTS.

4.1.31 Track and maintain vendor maintenance contracts for all hardware deployed in support of SDREN and DREN Ancillary equipment

4.1.32 Support Communications Security (COMSEC) requirements to support crypto questions, deployment, and keying

4.1.33 Operational Prioritization. Network Operations is critical to HPCMP operations.

Below is the government approved set of priorities established for the Network

Operations Center. To ensure Network Operations is addressed in a timely manner, the contractor shall ensure all prioritized issues are completed with the appropriate level of urgency and effort. In support of performing the tasks above, listed below is the priority structure.

Network Operation Priorities

Priority Category Activity Examples

1 Security Any security related issue.

2 Trouble

Investigating and isolating problems related to loss of connectivity to management devices, loss of customer connectivity and peering networks, loss of support system or application

Priority Category Activity Examples

3 Maintenance Upgrades to hardware operating system or updates to encryption keys

4 Change

Requests to make a rule change in a firewall, updates to encryption device route tables or modify SDREN service delivery router static route tables or BGP filters, DNS updates

5 Installation NetOps support to install new DREN or SDREN hardware

6 Administration

Creation of, or updates to, operating procedures or policy documentation, customer records, network diagrams, review of network, encryptor and server audit logs, updates to the SDREN NOC web site

7 Inquiry Request for information from a site POC or HPCMPO representative

8 Task Development and test of a new design or configuration in preparation for installation of a new device or product in the network

9 Training Participating in a vendor-provided course to increase technical knowledge of new product, appliance, or operating system features

Network Operation Security Ticket Priorities

Priority Activity

Compromise of NetOps network device or support information system or

COMSEC incident

2 Customer classified security incident

3 DoS or DDoS SDREN, NetOps network device or support information system

4 HPCMP CERT Block Request, SJS, DJS restoration

5 IAVM Compliance

6 Security Configuration or Active Directory Group Policy Updates

Network Operations Event Issue Priorities

Priority Examples of Corresponding Events

1. Security - A compromise of any kind on any DREN or SDREN management system or core component and/or a Denial of Service (DOS) or Distributed DOS (DDOS)

Priority Examples of Corresponding Events attack which impacts a customer’s connectivity to DREN or SDREN, or the functionality of the SDREN itself, or the ability to manage NetOps deployed network devices.

- A compromise of any kind on any server or application or a Denial of Service

(DOS) or Distributed DOS (DDOS) attack which impacts server or application access or performance

2. Critical

- Loss of service to any Critical Customer Locations or an outage that affects multiple SDREN customers.

- Loss of access to or loss of a Critical server or Critical application

3. High

- Loss of service to a non-Critical DREN or SDREN enclave or severe performance issue at any DREN or SDREN enclave

- High: Loss of service to a non-Critical server or application

4. Medium

- Network latency or minor throughput performance issues affecting end user applications

- Server performance affecting end user applications, chronic intermittent problems

5. Low

- Minor packet loss

- Minor user complaints

4.1.34 Develop and maintain SDREN/DREN Active Measurement Program

(SAMP/DAMP) systems to include producing SAMP/DAMP outputs regarding network performance and utilization analysis data.

4.1.35 Networking/Security Database Development and Maintenance Support.

This database provides the central location for all DREN and SDREN data and files, providing the basis for annual service pricing determinations and provides for consistent configuration management of Customer data and serves as the central interface for Networking, Security, CSSP, CSA, NOC personnel. Tasks include:

4.1.36 Database Account Management

4.1.37 DREN and Outreach Service Agreement as well as SDREN CAP package and

CSSP databases

4.1.38 DREN and SDREN IPv4 and IPv6 allocation databases

4.1.39 DREN Equipment database

4.1.40 Equipment Order database

4.1.41 Other databases as required by the Government

4.1.42 Provide timely and accurate database information and record data entry management as well as accurate data imports, exports and maintain ODBC connections to other HPCMP databases as required.

4.1.43 DREN Portal management – data entry and validation for all associated DREN and SDREN Service Delivery Points (SDPs) and associated enclaves

4.1.44 Manage and maintain HPCMPO GAL mail distribution list management access as required by the Government (accurate distribution is dependent upon accurate

DREN/SDREN/CSSP POC data)

4.1.45 Manage and maintain DREN NOC POCs (DREN-III CenturyLink NOC notification lists, and DREN-IV NOC notification lists when available)

4.1.46 Manage and maintain DJS/SJS alert distribution lists

4.1.47 Perform recurring semi-annual (every six months) CSSP and Networking communication with DREN and SDREN CSSP subscribers to comply with

DISA’s CSSP Evaluator’s Scoring Metrics (ESM). Additionally, perform DREN and SDREN customer communications as required to ensure customers maintain

DSA and SDREN CAP documentation requirements. Tasks include but are not limited to:

Requests for updates to, or validation of, customer DREN or SDREN enclave network diagrams

Requests for enclave ATOs

Requests for updates to DREN, SDREN, Outreach or CSSP POC information

Providing DSA or SDREN CAP network diagram compliance feedback to customers

Updating customer data files and appropriate customer DREN or

SDREN database records

Providing DREN and SDREN enclave ATC recommendations to the

Government

Drafting DREN or SDREN ATC Letters

4.1.48 Generate, process and manage Telecommunication Service Requests (TSRs) for

DREN DITCO orders

4.1.49 Tracking DITCO TSR status and Acceptance Information

4.1.50 Perform statistical analyses and generate statistical reports related to DREN, SDREN, and CSSP

4.1.51 Management of DREN/SDREN maps

4.1.52 Manage and maintain the central document repository for all DREN and SDREN customers to include DSA, SDREN CAP, Outreach, CSSP alignment, Customer

Invoices, and Security Assessment documentation in various stages of validity and expiration.

4.1.53 Manage property and property inventory, aligning travel and manpower for installation and upgrades with property delivery, if applicable.

4.1.54 Maintain an up-to-date web-based community knowledge base as a reference for

Software Defined Networking and IPv6 technologies.

4.2 Network Security Support. Review and document the organization’s network security requirements to protect sensitive DoD information and prevent unauthorized access. The

Network Systems Security Specialists would be responsible for gathering information necessary to maintain network security documentation and evaluate the threat of cybersecurity vulnerabilities. They will define, create and maintain the security documentation for certification and accreditation of each information system in accordance with DoD requirements and perform the DoD security assessment process on next generation network devices to determine the impacts on network modifications and technological advances. These individuals will review network architectures to identify potential security weaknesses, recommend improvements to resolve vulnerabilities, and document changes/upgrades. Tasks will include:

4.2.1 Provide enterprise network security support for the Defense Research and

Engineering Network (DREN) and Secret DREN (SDREN).

4.2.2 Provide Cybersecurity and privacy analysis and consulting throughout the security assessment and compliance life cycle process.

4.2.3 Maintain responsibility for the planning and continuous monitoring of

Cybersecurity and privacy policies, programs, compliance artifacts, or standards for government and industry security compliance and systems accreditation and management.

4.2.4 Serve as an expert authority for the respective network security activities, including assessments, documentation development/sustainment, and policy implementation oversight.

4.2.5 Provide technical information and coordinate work efforts to influence and persuade staff to accept and implement findings and recommendations.

4.2.6 Develop the documentation, validation, and accreditation processes necessary to ensure network architectures meet security and privacy requirements.

4.2.7 Develop contingency plans (Disaster Recovery or Business Continuation Plans for information technology systems) to ensure availability and accessibility of network resources.

4.2.8 Review and evaluate security incident response policies, identify the need for changes based on new security technologies or threats, test and implement new policies and establish measures to ensure awareness and compliance.

4.2.9 Recommend network security requirements resulting from new Public Law, Presidential directive, or other external mandate, integrate security programs across business units and organizations, and define the scope and level of detail for security plans and policies.

4.2.10 Communicate complex technical requirements to nontechnical personnel, prepare and present briefings to senior management officials on complex/controversial network security issues.

4.2.11 Protect network devices by defining access privileges, control structures, and resources.

4.2.12 Recognize problems by identifying abnormalities and reporting violations.

4.2.13 Recommend network security improvements by assessing current situation;

evaluating trends; and anticipating future requirements.

4.2.14 Understand technical network security controls and recommend implementation approaches.

4.2.15 Complete all requirements and package them to meet requirements for Risk

Management Framework to ensure a successful accreditation.

5.0 Deliverables. The contractor will be required to prepare and provide updates to, or initial documentation as required. The deliverable products are:

Deliverable CDRL # Transmittal Form and

Quantity

Schedule

Trip Reports A001 Electronic copy To Government POC

NLT five (5) business days after return and

Consolidated Monthly

Consolidated Trip

Report

Briefing Material A002 Electronic copy As necessary

Weekly SAR A003 Electronic copy Two (2) business days after the end of reported week.

Monthly Status Report A004 Electronic copy NLT the 10th day of each month

Trend Analysis Reports A005 Electronic copy As necessary

Comments and

Recommendations Base on

Engineering Studies and

Assessments

A007 Electronic copy As necessary

Configuration management plans

A008 Electronic copy As necessary

Test & Evaluation Plans, Procedures, and Test Reports including Data

A009 Electronic copy As necessary

Risk Management Framework

(RMF)

A010 Electronic copy As necessary

Monthly Inventory A011 Electronic copy Five (5) business days after the end of the reported month.

Program Management Plan / A012 Electronic copy Sixty (60) calendar

Task Order Management Plan days after task order award. Thirty (30) calendar days after the start of each exercised option period.

Phase out Plan A013 Electronic copy No later than nine (9) months after task order award and updated annually thereafter.

Any final report(s) due within ten (10) calendar days after the last month of performance.

Monthly Financial Report A014 Electronic copy Ten (10) business days after the end of the reported month.

Initial Kickoff Meeting Minutes A015 Electronic copy No later than ten (10) calendar days after the meeting.

Specifications A016 Electronic copy As necessary

Concept of Operations A017 Electronic copy As necessary

Accreditation Documentation A018 Electronic copy As necessary

User Guides A019 Electronic copy As necessary

Plans of Action and Milestones A020 Electronic copy As requested by the government POC

Product Evaluation/Study

Reports

A021 Electronic copy As necessary

Prototype ancillary hardware, drawings, and preliminary technical manuals

A022 Electronic copy As necessary

Standard Operating Procedures A023 Electronic copy As necessary

Network Diagrams A024 Electronic copy As necessary

Regression Test Plans and

Reports

A025 Electronic copy As necessary

After Action / Lessons Learned

Reports

A026 Electronic copy As necessary

Annual Maintenance Renewal A027 Electronic copy As necessary

6.0 Government Furnished Property.

6.1 Government Property (GP) will be provided to the Contractor and it will be addressed and justified at the Base and Task Order level and these items will be listed in each individual task order RFP. The Contractor shall have a system of internal controls to manage (control, use, preserve, protect, repair and maintain) Government property in its possession in accordance with FAR Clause 52.245-1, 52.245-9, Defense Federal

Acquisition Regulation Supplement (DFARS) 252.211-7003, 252.211-7007, 252.242-

7005, 252.245-7001, 7002, 7003, 7004 and sound business practice to control, protect, preserve and maintain all Government property specified in the contract.

6.2 The contractor shall establish and implement property management plans, systems, and procedures at the contract, program, site or entity level to enable the outcomes outlined in FAR 52.245-1(f). Failure to maintain an acceptable property management system, as defined in DFARS 252.245-7003, may result in disapproval of the system by the Contracting Officer and/or withholding of payments.

6.3 The Contractor shall provide for the maintenance and repair of all GP in their possession unless otherwise specified in the contract.

6.4 The Contractor shall maintain a purchasing and distribution system at the

Administrative Office to provide the GP/ Contractor Acquired Property (CAP) to other sites and associated areas.

6.5 The Contractor shall designate a Property Manager who shall, in conjunction with designated Government representatives, be required to maintain up-to-date

Government property records and inventory of property for all GP/CAP. The

Contractor Property Manager shall maintain accounting documentation regarding the issuance of GP/CAP to all Contractor employees or subcontractors in accordance with

FAR 52.245-1, 52.245-9, DFARS 252.211-7003, 252.211-7007, 252.242-7005,

252.245-7001, 7002, 7003, 7004, and the contractor’s Property Management System.

The Contractor Property Manager shall coordinate with other program contractor property personnel, and designated Government representatives, as applicable, regarding the management and accounting of GP. The Property Manager who shall, in conjunction with designated Government representatives, be required to maintain up-to-date Government property records and inventory of property for all GP and CAP.

The Contractor’s Property Manager shall maintain accounting documentation regarding the issuance of GP/CAP to all Contractor employees or subcontractors in accordance with FAR Clause 52.245-1 and 52.245-9. The Contractor’s Property

Manager shall coordinate with other Contractor property personnel, and designated

Government representatives, as applicable, regarding the management and accounting of GP/CAP. The Contractor’s Property Manager shall at a minimum be a Certified

Professional Property Administrator (CPPA); however, a Certified Professional

Property Manager (CPPM) is preferred.

6.6 The Contractor shall provide property accounting and material management services to include providing accounting for and controlling personal property (contractor owned property); providing inspection and inventory support; providing special program management for, and maintenance and repair for GP.

6.7 The Contractor shall maintain up-to-date Government property records for all GP. All maintenance parts are accountable on the property listing. The Contractor shall maintain a receipt and issue listing, in accordance with FAR Clause 52.245-1 and approval from the Contracting Officer.

6.8 The Contractor shall process lateral transfers and change document lateral transfers as directed and approved by the PCO and/or Government Property Administrator (GPA) by the use of an SF 30 (Amendment of Solicitation/Modification of Contract).

6.9 The Contractor shall process turn-ins of GP/CAP, to include any excess during the life of this contract through the use of the Plant Clearance Automated Reutilization

Screening System (PCARSS) IAW DFARS 252.245-7004. In addition the Contractor shall also report any loss of Government Property through Defense Contract

Management Agency (DCMA) E-Tools IAW DFARS 252.211-7002.

6.10 The Contractor shall conduct inventories/inspections of GP/CAP as directed by the

COR and GPA. The Contractor shall conduct inventories/inspections IAW FAR

Clause 52.245-1.

6.11 The Contractor shall perform annual and periodic inventories in accordance with FAR

Clause 52.245-1, and the Contractor’s Property Management Plan. The Contractor shall post current inventory data to the master property database. Inventory results will be prepared per FAR Clause 52.245-1. The Contractor shall adjust data elements provided as directed by the COR/GPA.

6.12 The Contractor shall prepare all reports and necessary documents on contract closeout

IAW FAR Clause 52.245-1.

6.13 If property will be procured under this contract and said procurement is reimbursed to the contractor these items will become Government Property upon delivery or reimbursement to the Contractor whichever occurs first and what is outlined under 6.2 through 6.6 applies with the addition of 6.14 and 6.15 below.

6.14 The Contractor shall process expendable/durable and non-expendable property item requisitions as needed. The Contractor shall review and verify that the requisitions are completed with required information. The Contractor shall have the COR and the designated representatives sign all property requisitions. The Contractor shall establish a hard-copy supporting document file for each document register entry. The Contractor shall process the requisition in accordance with their established Property Management

System.

6.15 The Contractor shall process receipts of complete and partial shipments, and prepare material receiving reports to be provided to the Property Manager and forwarded to the

GPA and the COR.

6.16 The Government Property Administrator and Plant Clearance Officer is:

Monty A. Spicer

Monty.Spicer@usace.army.mil

256-895-1211

7.0 PATENTS, DATA AND COPYRIGHTS. The Government, from time to time, may make certain software acquired under license available to the Contractor solely for its use in the performance of this task order. The Contractor recognizes and acknowledges that such software or data contained therein may be proprietary and confidential to a third party.

In addition to US Government use, ERDC CERL's ESMS software is being pulled into the commercial sector through technology transfer programs. Both the method patents (CERL inventions) and the noncommercial software developed in-house and by contract (with copyright assignments) are being licensed to the private sector. Consequently, this contract requires both

DFARS 252.227-7014 ("7014") for unlimited rights to software and data developed under the contract with a copyright assignment to the Army. Furthermore, with the 7014 and 252.227-7020

("7020") clauses allowing the Contractor to retain certain rights in software it develops even after assigning the copyright to the government, a special agreement is required to terminate those enumerated rights for the contractor under this contract. Upon conclusion of the contract, the

Contractor will not retain any rights in the software being developed. The effect of this special agreement is that the Government is the only entity with the ability to control distribution, dissemination, modification, making derivatives of and making public the ESMS developed under the contract unless specifically retained as a right provided by DFARS 252.227-7014

(“7014”) and 252-227-7020 (“7020”).

8.0 Identification of Contractor Employee(s).

The contractor shall provide each employee an identification (ID) badge on contract start or employment start date. The ID badge shall be made of nonmetallic material, easily readable and include employee’s name, Contractor’s name, functional area of assignment and color photograph.

8.1 Display of ID Badges. Contractor personnel shall wear the ID badge at all times when performing work under this contract to include attending Government meetings and conferences. Unless otherwise specified in the contract, each Contractor employee shall wear the ID badge in a conspicuous place on the front of exterior clothing and above the waist except when safety or health reasons prohibit such placement.

8.2 Answering Telephones. Contractor personnel shall identify themselves as Contractor employees when answering Government telephones.

8.3 Utilizing Electronic Mail. When prime Contractor or subcontractor personnel send e-mail messages as a part of contract performance (or otherwise relating to contract matters), each sender shall include his/her name (both first and last names), e-mail address and the name of the individual’s employer).

9.0 Task Order Terms and Conditions.

9.1 Period of Performance. The period of performance for this task order will be one year from date of award with four 12 month option periods. Option years subject to availability of funds.

9.2 Contracting Officer’s Representative (COR) Designation. The Contracting Officer will appoint a COR and issue a COR Designation Letter stating the authority of the COR.

9.2.1 Management of this task will primarily be performed by the COR. The COR will participate in project meetings, represent the KO in the technical phases of the work, and receive task order deliverables. The COR will provide technical assistance and clarification required for the performance of this task. The COR will not provide any supervision or instructional assistance to Contractor personnel. The COR is not authorized to change any terms or conditions of the task order. Changes in the task order requirements, price or terms and conditions shall only be made by the KO via properly executed modifications to the task order.

9.3 Subcontractor Terms and Conditions. All task order terms and conditions associated with this task order shall be applicable to all subcontracts. The prime Contractor shall include all applicable terms and conditions in all subcontracting agreements.

10.0 Reimbursable Costs. All reimbursable costs shall be authorized by the COR or KO and be in conformance with task order requirements.

10.1 Travel. Travel is anticipated during the performance of this requirement. Since the anticipated travel cannot be accurately forecast, it shall be awarded on a reimbursable basis for actual allowable costs that apply over the life of the Task Order. All travel shall be in accordance with the Federal Travel Regulations (FTR) and the Joint Travel

Regulations (JTR); Travel will be reimbursed at actual cost in accordance with the limitation set forth in FAR 31.205-46. There will be no profit allowed on Travel or Other

Direct Costs. Only a G&A or Material Handling Fee will be authorized. The Offeror shall propose its G&A or Material Handling Fee to be assessed for the Travel and ODC

CLINs. The Contractor shall ensure that the requested travel costs will not exceed the obligated amount of this task order. Travel shall be submitted through the agency’s reporting system for client approval. A completed Travel Expense Worksheet must be submitted in advance for anticipated travel.

10.2 Prior Approval. Request for travel approval via the Travel Expense Worksheet shall be submitted in advance of the travel with sufficient time to permit review and approval and shall include:

Traveler’s name

Purpose of the trip to include justification as it benefits the government.

Travel dates

Location

Estimated cost (lodging, lodging tax, M&IE, transportation (i.e., air fare, train, bus, rental car, fuel for rental car, private car mileage, tolls, parking, other related expenses))

Identify the task order and CLIN

All travel shall be pre-approved in advance by the COR and be in compliance with the task order and all other applicable requirements.

The contractor shall use only the minimum number of travelers and rental cars needed to accomplish the trip purpose. Travel shall be scheduled during normal duty hours whenever possible. Airfare will be reimbursed for actual common carrier fares which are obtained by the most reasonable and economical means.

10.2.1 Contractor will not be reimbursed for local travel under 50 miles of the established place of work under this task order.

10.2.2 The contractor shall provide the government POC requesting travel a Trip

Report, within five (5) calendar days or as specified after completion, for each trip associated with a travel approval. The contractor shall maintain a summary of all approved travel, to include at a minimum, the name of the traveler, receipts, location of travel, duration of trip, total cost of trip.

10.3 Materials, Equipment and Other Services. The contractor may be required to obtain contract related materials, i.e., supplies, equipment, reproduction, mailing, to support the overall requirement. Those materials must be associated with the overall functions being performed through this task order. The Contractor shall abide by the requirements of the

FAR and other DOD Mandatory sources/contractual vehicles when acquiring supplies and/or materials. The Contractor shall obtain three (3) quotes in accordance with the FAR from suppliers. The contractor shall include documentation of these quotes and submit for approval by the KO. Documentation of purchases will be input into the agency’s reporting system in order for the Government to review them upon request and to ensure compliance with federal procurement regulations. All supplies must be authorized by the

COR or KO and be in compliance with this task order and all other applicable requirements.

10.3.1 The contractor will be required to use Army Computer Hardware, Enterprise

Software and Solutions (CHESS) contracts/blanket purchase agreements IAW

AFARS 5139.101-90 when purchasing hardware and software. The following statements/clauses from CHESS contracts will apply:

10.3.2 IT Equipment/Software Solutions. All materials required for performance of the task order, which are not Government-furnished, shall be furnished by the contractor. Materials acquired by the contractor with Government funds, for performance of this contract, are the property of the Government. The contractor shall utilize Enterprise Software Initiative (ESI) source software and Computer

Hardware, Enterprise Software and Solutions (CHESS) contract source equipment in accordance with applicable provisions. In addition to any other equipment, the contractor shall separately identify ESI source software items and

CHESS contract source equipment in their proposal. For ESI source software, the contractor shall request approval to order from the Government supply sources.

For proposed materials that are not from the identified Government supply sources for ESI source software or CHESS contract source equipment, the contractor shall provide a justification why those sources are not being utilized to support approval by the Contracting Officer.

10.3.3 Mail Services. The following mandatory contracts, to provide domestic express package delivery (next day and second-day delivery) services for DOD, shall be utilized before any other sources are acquired.

CONTRACT # CONTRACTOR ADMINISTRATIVE

CONTRACTING

OFFICE

PERIOD OF

PERFORMANCE

HTC711-11-A-

R001

FEDEX GROUND

PACKAGE

SYSTEMS, INC

USTRANSCOM-AQ-

HTC711- Scott AFB, IL

1 Oct 2011 – 30 Sep

Htc711-12-A-

R001

UNITED PARCEL

SERVICE, Inc

USTRANSCOM-AQ-

HTC711- Scott AFB, IL

1 Oct 2011 – 30 Sep

The contractor must follow the procedures within the respective DOMEX BPA when requesting authorization to participate in the contracts. Contractor shall submit their written request to participate, by completing the Contractor’s Request to Use the BPA form at https://private.amc.af.mil/A4/domexpress/spsindex.html to the KO within 30 days of task order award. A request for exemptions shall be submitted to the designated approval authorities/KO before other sources can be utilized.

11.0 Performance Requirements.

PWS Ref Deliverable or Services

Required

Performance

Standard (s)

Acceptable

Quality Level

(AQL)

Method of

Surveillance

4.1 – 4.1.4 Network

Engineering Support

Network Engineering projects are designed, configured, and implemented on time.

Network Engineering projects are delivered timely or installed with reasonable skill, care and diligence;

the work is performed in a workmanlike manner; and the work, when completed, will be reasonably fit for its intended use.

Functionality defined in task order specification is achieved.

Acceptable quality level is 100%. Any deficiencies identified by client are resolved promptly but always accomplished on or before 5 calendar days.

As needed and/or

Government inspections and acceptance.

4.2 – 4.2.20 Network

Operations Support

Network Operations configured, and implemented on time.

Deliverables are compliant with applicable regulations/ directives, timely, accurate, complete, clear, and well-organized in requested format.

level is 100% unless otherwise specified in the deliverables section. Any deficiencies identified by client are resolved promptly but always accomplished on or before 5 calendar days, or as required by directive, regulation or security guidance.

As needed and/or

Government inspection and acceptance.

Review of reports

4.2.3 – 4.2.20 Network

Provide and respond to all security objectives to & from customers and higher directives.

Network operations security projects are delivered timely or installed with reasonable skill, care and diligence; the work is performed in a workmanlike manner; and the work, when completed, will be reasonably fit for its intended use. Timely completion of

IAVAs.

No more than 2 instances of quality deviation requiring re- performance or re-installation. No more than 1 project in a month delivered or completed more than 3 days late.

As needed and/or

Government inspection and

4.2.7 – 4.2.20 Network

Operations Support

(Paragraph

Maintain and assure network accreditation and risk management framework (RMF) of the network

Network accreditation and

RMF are compliant with applicable regulations/ directives, timely, accurate, complete, clear, and well-organized in requested format.

Acceptable quality level is 100% unless otherwise specified in the deliverables section. Any deficiencies identified by client are resolved promptly but always accomplished on or before 5 calendar days, or as required by directive, regulation or security guidance.

As needed and/or

Government

4.2.20 Network

Maintain and ensure network operational priorities are completed at the appropriate level

Network operational priorities are addressed according to the government approved set of priorities.

Acceptable quality level is 100% unless otherwise specified in the deliverables section. Any deficiencies identified by client are resolved promptly but always accomplished on or before 5 calendar days, or as required.

As needed and/or

Government

4.3 Networking/Security

Database Development and Maintenance

Support

Network Security and database development projects are designed, configured, and implemented on time.

Network operations security projects are delivered timely or installed with reasonable skill, care and diligence; the work is performed in a workmanlike manner; and the work, when completed, will be reasonably fit for its intended use

No more than 2 instances of quality deviation requiring re- performance or re-installation. No more than 1 project in a month delivered or completed more than 3 days late.

As needed and/or

Government

4.4 Network Security

Network Security configured, and implemented on time.

Network operations security projects are delivered timely or installed with reasonable skill, care and diligence; the work is performed in a workmanlike manner; and the work, when completed, will be reasonably fit for its intended use

No more than 2 instances of quality deviation requiring re- performance or re-installation. No more than 1 project in a month delivered or completed more than 3 days late.

As needed and/or

Government

5.0 Deliverables Deliver required

reports

Legible, detailed and professional quality

No more than 3% of the reports to appropriate government contact may be later than the specified time period

Review reports

6.0 Government Property Property

Management

FAR Clause 52.245-1 and 52.245-9, DFARS

Clauses 252.211-

7007, 252.245-7001, 252.245-7002, 252.245-7003, and

252.245-7004.

Pass all 10 outcomes to include the five subsystems of a Property

Management

System

Audit.

10% Monthly Audits

6.0 Government

Property Sensitive Items

Accountability (if applicable)

AR 190-11 (Sep 13), AR 710-2, DA Pam

710-2-2, and AR

740-26.

100% Inventory and accountability of

Sensitive Items

(weapons and other designated items).

100% Physical

Accountability Daily, Monthly and

Quarterly Reporting

Requirement

9.0 Reimbursable Costs

Travel Travel shall be submitted through the agency’s reporting system for client approval. A completed Travel

Expense Worksheet must be submitted in advance for anticipated travel.

100% pre- approval obtained.

As needed

13.0 Personnel Security Security and Privacy Accordance with AT

OPSEC QASP

Accordance with AT

OPSEC QASP

As needed

12.0 Privacy Act. Performance under this task order may require personnel to have access to Privacy

Information. Personnel shall adhere to the Privacy Act, Title 5 of the U. S. Code Section 552a and applicable agency rules and regulations.

13.0 Personnel Security. Employees selected by the contractor for this performance work statement must be able to pass all security requirements IAW the local base policy in order to gain access to the installation. This effort involves the contractor having access to FOUO, Confidential and classified information/material. The contractor shall possess and maintain a top secret facility clearance. The contractor shall provide personnel with clearances up to the “TOP SECRET” for some tasks which are identified and SECRET for all others. The Contractor may require handling/access of classified up to the “Secret” level as well as “Sensitive” Government information including “Acquisition Sensitive” information. Published material may also be unclassified or for official use only.

Network Engineering Support Clearance Level

Required

Exceptions personnel/Clearance

Level

Network Engineering Support SECRET

30% TOP

SECRET/SCI

Network Operations TOP SECRET/SSBI 5% require SECERT

Networking/Security Database Development SECRET

30% TOP

SECRET/SSBI

Network Security Support TOP SECRET/SSBI

13.1 The Contractor will abide by the requirements set forth in…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .