02. PWS Attachment (1) - OSCAM IAWF Cert Requirements.xlsx
XLSX spreadsheet 25 KB Posted
- Attached to
- Operating and Support Cost Analysis Model (OSCAM) Support Federal contract opportunity
- Solicitation number
- N0016722Q0180
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 09d. CDRL A001 (Status Report).pdf | ||
| 09d. DI-MGMT-80368A (Status Report) A001.pdf | ||
| N0016722Q0180_CSS.pdf | ||
| 09b. CDRL A003 (Software Doc).pdf | ||
| 09a. CDRL A004 (Training Materials)_S.pdf | ||
| Sole Source-Brand Name Justification _OSCAM_Redacted.pdf | ||
| 09b. DI-IPSC-81756 (Software Documentation) A003.pdf | ||
| 09c. CDRL A002 (Computer Software).pdf | ||
| 09a. DI-ILSS-80872 (Training Materials) A004.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Reference Directions:
1. Column A: List the task area numbers from the SOW that define what they'll be doing.
2. Column B: Based on the duties and the work role descriptions on this reference page, choose the appropriate work role name and code.
3. Column C: Provide a brief description of the cyber duties the individual(s) will be performing.
4. Column D: If the position is primarily management or cybersecurity choose IAM, if it is technical choose IAT. Based on the access level (i.e., local, network or enclave) of cyber duty needed to fill the position, choose level I, II or III. All three proficiency levels (e.g., basic, intermediate or advanced) can be found at each access level.
5. Column E: Investigations are T3, unless the individual will have an .adm, .adp or work on the network in c104.
5. Column F: If the position requires local access (i.e., closed enclave) then it is IT-2. If it requires network or enclave level, then it is an IT-1 which requires a Top Secret investigation.
6. Column G: If the position requires Operating System/Computing Environment (OS/CE) training (e.g., Linux or Win10) before being engaged, it should be stated here. Otherwise, they will have 6 months to get the training once they are engaged.
*The words in red on the Table are examples and are not comprehensive. Please delete and replace with info from your contract. Once complete you can save the worksheet as a PDF to be included in your SOW.
| DoD 8570.01-M Summary of IA Workforce Qualification Requirements | |||
| IAT/IAM Level | Approved Baseline Certifications | System Environment | Recommended Experience |
| IAT I | A+ CE, CCNA-Security, CND, Network+ CE, SSCP | Computing Environment | 0-5 years |
| IAT II | CCNA Security, CySA+ **, GICSP, GSEC, Security+ CE, CND, SSCP | Network/Advanced Computing Environment | at least 3 years |
| IAT III | CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH | Enclave/Advanced Network & Computer | at least 7 years |
| IAM I | CAP, CND, Cloud+, GSLC, Security+ CE | Computing Environment | 0-5 years |
| IAM II | CAP, CASP+ CE, CISM, CISSP (or Associate), GSLC, CCISO | Network | at least 5 years |
| IAM III | CISM, CISSP (or Associate), GSLC, CCISO | Enclave | at least 10 years |
| Glossary | ||
| Core Users/Members | All contractors who provide cyber capability (including coding/software development/web development) at the network or enclave level are core Cyber IT/CSWF members and are required to have an appropriate baseline certification that cannot be education, regardless if it is a secondary duty. | |
| IAM | Information Assurance Management | 51% or more of duties are management or anyone performing cybersecurity. |
| IAT | Information Assurance Technical | 51% or more of duties are technical |
| OS/CE | Operating System/Computing Environment | Obtained within 6 months of start date unless stated otherwise. |
| Baseline Certification | As an extension of Appendix 3 to the DoD 8570.01-Manual, the above certifications have been approved as IA baseline certifications for the IA Workforce. Personnel performing IA functions must obtain one of the certifications required for their position category or specialty and level. Refer to Appendix 3 of 8570.01-M for further implementation guidance. | |
| Cyber IT/CSWF (aka IA Workforce) | Includes IAM/IAT for Cyber IT/CS Workforce | |
| CSWF | Cybersecurity Workforce (subset of Cyber Workforce) | Personnel who secure, defend, and preserve data, networks, net-centric capabilities, and other designated systems by ensuring appropriate security controls and measures are in place, and taking internal defense actions. This includes access to system controls, monitoring, administration, and integration of cybersecurity into all aspects of engineering and acquisition of cyberspace capabilities. |
| Cyber IT WF | Cyberspace Information Technology Workforce (subset of Cyber Workforce) | Personnel who design, build (e.g., software development), configure, operate, and maintain IT, networks, and capabilities. This includes actions to prioritize portfolio investments; architect, engineer, acquire, implement, evaluate, and dispose of IT as well as information resource management; and the management, storage, transmission, and display of data and information. |
| References | |||
| DoD 8570.01-M | Information Assurance Workforce Improvement Program Incorporating Change 4 | 10-Nov-15 | |
| DODD 8140.01 | Cyberspace Workforce Management | 5-Oct-20 | |
| DoD Approved 8570 Baseline Certifications (IASE Summary of IA Workforce Qualification Requirements) | https://cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/ | ||
| Security and Privacy for Computer Systems | DFARS clause subpart 239.71 | https://www.acq.osd.mil/dpap/dars/dfars/html/current/239_71.htm | |
| Information Assurance Contractor Training and Certification | DFARS clause subpart 239.7102-3 | https://www.acq.osd.mil/dpap/dars/dfars/html/current/239_71.htm |
| Work Roles | ||
| Code and Name | Description | Reminders: |
| (411) Technical Support Specialist | Provides technical support to customers who need assistance utilizing client level hardware and software in accordance with established or approved organizational process components. (i.e., Master Incident Management Plan, when applicable). | 1. Education does NOT count for a cyber BASELINE certification per DOD 8570.01-M. |
| (421) Database Administrator | Administers databases and/or data management systems that allow for the storage, query, and utilization of data. | 2. A T5 investigation is required for those requiring .adp or .adm or network IT privileged accounts. |
| (422) Data Analyst | Examines data from multiple disparate sources with the goal of providing new insight. Designs and implements custom algorithms, flow processes and layouts for complex, enterprise-scale data sets used for modeling, data mining, and research purposes. | 3. DOD 8570.01-M "C2.3.9. Contractor personnel supporting IA functions in Chapters 3, 4, 10, and 11 shall obtain the appropriate DoD-approved IA baseline certification prior to being engaged." Evidence of operating system and/or computing environment training must be provided within 6-months of engagement. |
| (431) Knowledge Manager | Responsible for the management and administration of processes and tools that enable the organization to identify, document, and access intellectual capital and information content. | |
| (441) Network Operations Specialist | Plans, implements, and operates network services/systems, to include hardware and virtual environments. | |
| (451) System Administrator | Installs, configures, troubleshoots, and maintains hardware, software, and administers system accounts. | |
| (461) Systems Security Analyst | Responsible for the analysis and development of the integration, testing, operations, and maintenance of systems security. | |
| (612) Security Control Assessor | Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). | |
| (621) Software Developer | Develops, creates, maintains, and writes/codes new (or modifies existing) computer applications, software, or specialized utility programs. | |
| (622) Secure Software Assessor | Analyzes the security of new or existing computer applications, software, or specialized utility programs and provides actionable results. | |
| (631) Information Systems Security Developer | Designs, develops, tests, and evaluates information system security throughout the systems development lifecycle. | |
| (632) Systems Developer | Designs, develops, tests, and evaluates information systems throughout the systems development life cycle. | |
| (641) Requirements Planner | Consults with customers to evaluate functional requirements and translate functional requirements into technical solutions. | |
| (651) Enterprise Architect | Develops and maintains business, systems, and information processes to support enterprise mission needs; develops information technology (IT) rules and requirements that describe baseline and target architectures. | |
| (652) Security Architect | Designs enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes. | |
| (661) Research & Development Specialist | Conducts software and systems engineering and software systems research in order to develop new capabilities, ensuring cybersecurity is fully integrated. Conducts comprehensive technology research to evaluate potential vulnerabilities in cyberspace systems. | |
| (671) Testing and Evaluation Specialist | Plans, prepares, and executes tests of systems to evaluate results against specifications and requirements as well as analyze/report test results. | |
| (801) Program Manager | Leads, coordinates, communicates, integrates and is accountable for the overall success of the program, ensuring alignment with critical agency priorities. | |
| (802) IT Project Manager | Directly manages information technology projects. | |
| (803) Product Support Manager | Manages the package of support functions required to field and maintain the readiness and operational capability of systems and components. | |
| (804) IT Investment/ Portfolio Manager | Manages a portfolio of IT capabilities that align with the overall needs of mission and business enterprise priorities. | |
| (805) IT Program Auditor | Conducts evaluations of an IT program or its individual components, to determine compliance with published standards. |
&"Times New Roman,Bold"&24Directions and References for Information Assurance Workforce Certification Matrix
OSCAM IAWF Certification Req.
Operating and Support Cost Analysis Model (OSCAM) Information Assurance Workforce (IAWF) Certification Requirements
| SOW Task Area | Primary Work Role | |
| Code & Name | IT/CS Duties | IAM/IAT* |
Level
3.1.1. Model Updates and Enhancements (page 1)
3.1.2. Training Course Development and Support (page 2)
| 3.2.2. Major Model and/or Training Enhancement (page 3) | (621) Software Developer | Updates and enhances the Operating and Support Cost Analysis Model (OSCAM) software, which is a standalone, Navy-owned software package. Updates could include capability/functionality improvements, user interface updates, or software compatibility/architecture modifications. Changes require modifying the PowerSim (modeling equations) and/or Delphi (user interface) code. |
| NOTE: Contractor personnel will have no access to any Navy networks, nor will they perform any IA roles or handle any classified data. The contractor will not have NMCI accounts nor will they be issued CACs. | IAT II or IASAE I |
*Personnel performing IA functions must obtain one of the certifications required for their position category or specialty and level: https://public.cyber.mil/cw/cwmp/dod-approved-8570-baseline-certifications/
&"Palatino Linotype,Regular"&18Information Assurance Workforce Certification Matrix &K01+000Contract Number&K000000: &K01+000TBD,&K000000 NSWCCD Code 8110 OSCAM SAPCOM
File details come from the government source that posted it. Updated .