FY20 CDID CYBER PWS.pdf

PDF 335 KB Posted

Attached to
TCM Cyber Federal contract opportunity
Solicitation number
12092019
Issued by
Department of the Army Materiel Command Mission and Installation Contracting Command Fort Eustis

About this file

This sources sought synopsis describes a requirement for TCM Cyber Training Support and Range Operation services. The services include operational, system, technical capability development support to CM Cyber for Cyberspace Operations including defensive cyberspace operations, offensive cyberspace operations, cyberspace situational understanding, and persistent cyber training environment integration. Interested parties are requested to submit capabilities statements by December 13, 2019 addressing their experience, technical skills, and ability to perform at least 50% of the work. The requirement is set aside for small businesses with a size standard of $15 million. The contract type is anticipated to be an 8(a) small business competition and may include Service Contract Act labor categories. The period of performance consists of one base year and two option years from April 2020 through April 2023.

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT

FOR THE

Capability Manager Cyber (CM Cyber) Contract Support

U. S. ARMY CYBER CENTER of EXCELLENCE

“Cyberspace Operations Capability Development in Support of the Army’s Multi-Domain Operations”

PERIOD OF PERFORMANCE

BASE YEAR: 29 APRIL 2020 THROUGH 28 APRIL 2021

HEADQUARTERS

U.S. ARMY CYBER CENTER OF EXCELLENCE

CAPABILITY DEVELOPMENT & INTEGRATION DIRECTORATE (CDID)

FORT GORDON, GA 30905-5000

PERFORMANCE WORK STATEMENT (PWS)

CAPABILITY MANAGER CYBER

Part 1

General Information

1. General: This is a non-personal services contract to provide defensive cyberspace operations (DCO), offensive cyberspace operations (OCO), cyberspace situational understanding (Cyber SU), and persistent cyber training environment (PCTE) capability development and technical support to the Army Futures Command (AFC) Capability Development Integration Directorate (CDID) Capability Manager Cyber (CM Cyber). The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.

1.1 Description of Services: The Contractor shall provide all personnel, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform technical support to the CM Cyber’s mission of cyberspace operations capability development for DCO, OCO, Cyber SU, and PCTE as defined in this Performance Work Statement, except for those items specified as government furnished property and services. The Contractor shall perform to the standards in this contract.

1.2 Background: CM Cyber is AFC’s centralized capability development integrator for Cyberspace Operations. CM Cyber is the user advocate for doctrine, organizational, training, materiel, leadership and education, personnel, and facilities, and policy (DOTMLPF-P) solutions that enable DCO, OCO, Cyber SU and PCTE capabilities to operational and institutional forces, ensuring mission success across the force in support of unified land operations. CM Cyber executes its mission by coordinating DOTMLPF-P developments to ensure capabilities remain integrated and support operational requirements, including capabilities and advancements in facing near-peer competitors in Multi-Domain Operations (MDO). CM Cyber is responsible for assisting in the implementation of the Army’s Cyber Electromagnetic Activities (CEMA) doctrine with special emphasis on Cyberspace Operations capability development and is AFC’s principle source of expertise to ensure Army commanders have full access to, and are supported by, full spectrum cyberspace capabilities.

US Army Futures Command (AFC) CDID Capability Manager Cyber (CM Cyber) is an integral part of the Capability Development & Integration Directorate (CDID). The CM Cyber mission includes responsibilities for developing cyberspace capabilities related to DCO, OCO, Cyber SU, and PCTE; In addition, CM Cyber plays a key role in the integration of cyberspace and electronic warfare capabilities that enable Cyberspace Electromagnetic Activities (CEMA). Beyond DCO, OCO, Cyber SU, and PCTE capability development efforts, CM Cyber efforts include Cyberspace Support to Corps and Below (CSCB), as well as CEMA optimization.

1.3 Objectives: The contract will secure external human resources to facilitate the completion of deliverables that support existing and projected Programs of Record (PORs) by modifying or creating documentation for the Joint Capabilities Integration and Development System (JCIDS) and/or Business Case Lifecycle (BCL) process.

1.4 Scope: The Contractor shall provide operational, system, technical capability development support to CM Cyber for Cyberspace Operations: DCO, OCO, Cyber SU, Exercises and Experiments and PCTE integration pertaining to critical portions of programmed work within several key capability developments, training and proponent functional areas. Applies comprehensive, technical, operational, and policy expertise to the development of concepts and identifies capability needs that are the foundation for the implementation of JCIDS. Participate in the development of Joint, DOD, and Army concepts that include aspects of DCO, OCO, PCTE and Exercises and Experiments and leverage them in the development of DOD capabilities, with focus on the visualization of future operations. Provide comprehensive expertise in cyberspace operations, research and analysis, as well as, capability requirements development; knowledgeable in all areas of cyberspace operations a strong knowledge in emerging technologies such as unified communications, mobile, cloud and virtualization technologies.

Conducts comprehensive analyses to ensure that the integration of DOTMLPF-P factors are adequate to support current and emerging warfighting systems. Analyze changes in joint and other services’ cyberspace/electronic warfare and related doctrine and techniques to determine impact on DOD operational capabilities. Coordinates analysis results that support recommendations with key stakeholders and presents findings to CM Cyber.

In order to successfully perform this requirement the Contractor shall need to possess a broad understanding and knowledge of government acquisition frameworks and JCIDS processes. This will require coordination and interface across a broad stakeholder community. The Contractor shall use good commercial practices throughout the life of this contract and provide the deliverables specified in this PWS and IAW IPRs conducted with the Government. Services include products and deliverables related to development and review of Joint Capabilities Integration and Development System documentation (e.g., Initial Capability Documents (ICD), Capability Development Documents (CDD), Capability Production Documents (CPD), Requirements Definition Packages (RDP) and Capability Drops (CD), cyberspace operations materiel (software/hardware) requirements documents (to include concepts of operations (CONOPS), cost benefit analyses (C-BA), and test and evaluation plans); capability needs analyses; Participation in demonstrations to evaluate integrated technologies in as realistic an operating environment as possible to assess the performance or cost reduction potential of advanced technology; Capability development efforts directed toward test and assessment of changes to fielded systems or systems already in procurement which alter the performance envelopes; Participation and documentation of discrete evaluations or assessments of synthetic environments, prototypes, and proof-of-principle demonstrations in field exercises to evaluate system upgrades or provide new operational capabilities; applicable portions of doctrine; institutional training (to include the production of cyberspace System Training Plans); leadership and education; personnel skill sets; facilities; and policy.

1.5 Period of Performance: The period of performance for this contract contains a twelve (12) month Base period and two (2) 12-month option years. The Period of Performance reads as follows:

Base Year- 29 April 2020 through 28 April 2021

1.6 General Information

1.6.1 Quality Control: The Contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s quality control program is the means by which it assures work provided complies with the requirement of the contract. When and how the Quality Control Plan (QCP) is to be delivered, i.e. within 30 days after contract award or with the Contractors’ proposal, must be approved by the Contracting Officers Representative (COR). Three copies of a comprehensive written QCP shall be submitted to the KO and COR within 5 working days when changes are made thereafter. After acceptance of the quality control plan the Contractor shall receive the contracting officer’s acceptance in writing of any proposed change to his QC system.

1.6.2 Recognized Holidays: The Contractor is not required to perform services on Federal holidays as defined by Federal law (5 U.S.C. 6103) that are listed below. Official dates by year are published by Office of Personnel Management.

New Year’s Day 1st day of January Martin Luther King Jr.’s Birthday 3rd Monday of January President’s Day 3rd Monday of February Memorial Day last Monday of May Independence Day 4th day of July Labor Day 1st Monday of September Columbus Day 2nd Monday of October Veteran’s Day 11th day of November Thanksgiving Day 4th Thursday of November Christmas Day 25th day of December

1.6.3 Hours of Operation: The Contractor is responsible for conducting business, between the hours of 0730 and 1630 hours Monday thru Friday except Federal holidays or when the government facility is closed due to Federal Holidays, local or national emergencies, administrative closings, or similar government directed facility closings. The work schedule may vary based on mission requirements. The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.

NOTE: Any of the above holidays falling on a Saturday will be observed on the preceding Friday.

Holidays falling on a Sunday will be observed on the following Monday. In addition to the days designated as holidays, the Government any other day designated by Federal Statute, Executive Order or Presidential Proclamation.

1.6.4 Place of Performance: The place of performance for this contract is (US) Army CYBER CoE, CDID, CM Cyber, 506 Chamberlain Avenue, Fort Gordon, GA 30905-5735, unless personnel are designated to conduct duty at another local on a permanent or semi-permanent basis.

Other designated workspace on Fort Gordon may be utilized during the contract period of performance for purposes of facilitating close coordination with user representatives and capturing user requirements. These locations will be coordinated with the contract Site Lead Project Manager and CM Cyber, if required.

1.6.5 Type of Contract: The government will award a firm fixed price contract.

1.6.6 Security Requirements:

1.6.6.1 Contractor employees performing on this contract/task order must be a U.S. citizen. At work performance start date, all Contractor and subcontractor employees, and Project Manager performing on this contract shall have a Top Secret/SCI security clearance based on a current SSBI or current SSBI-Periodic Reinvestigation (PPR) and shall maintain the required security clearance throughout the life of the contract. The Contractor is responsible for acquiring the clearances. The Contractor shall ensure that all assigned personnel understand applicable security policies and directives found in DOD 5220.22-M, National Industry Security Program Operating Manual (NISPOM); AR 380-5, Information Security Program; and all other applicable policies and regulations.

1.6.6.2 JWICS – all contract personnel are required to have and maintain Joint Warfare Intelligence Communications System (JWICS) access. The Contractor shall not access, download or further disseminate any special access data (i.e. intelligence, NATO, COMSEC, etc) outside the execution of the defined contract requirements.

1.6.6.3 SIPRNET – All contract personnel are required to have and maintain SIPRNET access.

The Contractor shall not access, download or further disseminate any special access data (i.e.

intelligence, NATO, COMSEC, etc) outside the execution of the defined contract requirements.

The SIPRNET contains NATO information and a NATO Brief is required for all Contractors prior to access to the SIPRNET. A written acknowledgment shall be maintained. SIPR tokens are the property of the US Government. Should a Contractor depart, either relieved or self terminates their contact, they must relinquish their SIPR token to the COR prior to departure.

1.6.6.4 Handling/Access to Classified Information. The Contractor shall ensure that classified data is controlled, protected, and safeguarded in accordance with AR 380-5 and current Army and DOD policy. Classified information shall be accessed and stored in approved government spaces only. The Contractor shall agree that any data furnished by the government to the Contractor shall be used only for performance under this PWS, and all copies of such data shall be returned to the government upon completion of this effort. The Contractor shall comply will all requirements specified in the attached DD Form 254, Department of Defense Contract Security Classification Specification, is required. The Contractor Facility Security Officer (FSO) will ensure there is a procedure for all terminated employees to out process the installation. The Contractor shall report any adverse action or information that prevents or may prevent a Contractor from retaining access to classified material Contracting Officer Representative (COR) and Contractor FSO immediately.

All Contractors will work with the local security personnel to complete the courier order training within 90 days of starting employment.

1.6.6.5 Cybersecurity (CS)/Information Technology (IT) Training. All Contractor employees and associated subcontractors must complete the DOD Cyber Awareness Challenge Training (https://ia.signal.army.mil/DODIAA) before issuance of network access and annually thereafter.

Certificates of successful completion, for both initial awareness training and annual refresher training shall be provided to the COR. All Contractor employees will successfully complete all required CS training as specified in AR 25-2 and as directed by the Government. All Contractor employees working CS/IT functions must comply with DOD and Army training requirements in DODD 8570.01, DOD 8570.01-M, and AR 25-2.

Contractor employees, to include subcontractors, requiring access to information systems to fulfill their duties must possess the required favorable security investigation. Contractor employees that require access to the Fort Gordon network shall have a minimum of a National Agency Check with Inquiries (NACI) investigation initiated and favorable review before issuance of network access.

The IASO/IANO from the activity that the Contractor employee is assigned to, will submit an electronic DD 2875, System Authorization Access Request (SAAR) to Security & Intelligence Division for verification that the Contractor employee meets the requirements of AR 25-2 for accessing the Fort Gordon network. (Ref AR 25-2)

1.6.6.6 Information Assurance (IA)/Information Technology (IT) Certification. All Contractor employees and associated subcontractors must complete the DOD Cyber Awareness Challenge Training (https://ia.signal.army.mil/DODIAA) before issuance of network access and annually thereafter. Certificates of successful completion, for both initial awareness training and annual refresher training shall be provided to the COR. All Contractor employees will successfully complete all required IA training as specified in AR 25-2 and as directed by the Government. All Contractor employees working IA/IT functions must comply with DOD and Army training requirements in DODD 8570.01, DOD 8570.01-M, and AR 25-2.

1.6.6.7 Annual Security Refresher Training. All Contractor employees, including subcontractors, assigned to this contract shall complete the online Annual Security Refresher Training located on the Army Learning Management System (ALMS) site. Log into AKO, “Self Service”, “My Training”, “ALMS”, “Go To Mandatory Training”. Training must be completed within 30 days of reporting for duty. The Contractor shall submit certificate of completion for each affected Contractor employee and subcontractor employee to the COR and unit/activity security manager. (Ref ALARACT 207/2013, DTG 291848Z Aug 13, Subj: Army Wide Rollout and Requirement for Standardized Computer Web-Based Security Training on the Army Learning Management System (ALMS)).

1.6.6.8 Anti-Terrorism (AT) Level I Training. All Contractor employees, including subcontractors, assigned to this contract shall receive an initial Antiterrorism Level I Brief by a certified ATO Level II Officer within 30 days of reporting for duty. (Monthly briefings will be offered by the Garrison Antiterrorism Officer.) Annual refresher Antiterrorism Level I Training shall be completed on-line at https://atlevel1.dtic.mil/at/ or they may attend the monthly training offered by the Garrison ATO. The Contractor shall submit certificates of completion for each affected Contractor employee and subcontractor employee to the COR and unit/activity security manager. (Ref Department of the Army, US Army Contracting Agency, SFCA-CO, 5 Sep 07, subject: Incorporation of Measures into the Contracting Process and AR 525-13, Antiterrorism).

Note: Contractor personnel shall receive an AOR briefing when traveling OCONUS on TDY.

Briefing must be provided by a certified ATO Level II Officer within 7 working days prior to TDY departure outside the 50 United States, its territories, and possessions. This is separate from the normal annual AT Level I training requirement. (Ref AR 525-13)

1.6.6.9 iWATCH. All Contractor employees, including subcontractors, assigned to this contract shall receive a brief on the local iWATCH program (provided in conjunction with the AT Level I Training). This training will be used to inform employees of the types of behavior to watch for and instruct employees to report suspicious activity to the COR. This training shall be completed within 30 days of reporting to duty and annual refresher training with the results reported to the

COR.

1.6.6.10 Operation Security (OPSEC) Training. All Contractor employees, including subcontractors, assigned to this contract shall complete Level I OPSEC training within 30 days of reporting for duty and then annually thereafter. Initial Level 1 OPSEC training will be conducted monthly by the Garrison OPSEC Officer or a Level II certified OPSEC Officer. (AR 530-1, Operations Security). Annual refresher training shall be completed on-line: Go to Internet Explorer, Fort Gordon website, select Fort Gordon and click on Dir, Plans Training & Mobilization, select Security/Intelligence, and click on Contractor OPSEC Awareness Training.

A record on completion will be provided to the COR and unit/activity security manager. (Ref AR 530-1)

The Contractor shall adhere to local OPSEC policies and procedures of the government requiring activity. When in a TDY status in support of this work effort, the Contractor shall also adhere to any OPSEC policies and procedures in effect at TDY locations.

1.6.6.11 Sexual Harassment/Assault Response and Prevention (SHARP) Training. All Contractors assigned to this contract shall be required to complete SHARP training annually. The COR will ensure Contractors are notified of available training opportunities. The Contractor shall train and educate all assigned personnel to understand applicable security policies and directives.

Personnel who knowingly violate security policies or directives shall be dismissed.

1.6.6.12 Threat Awareness and Reporting Program (TARP) Training. All Contractor employees, including subcontractors, assigned to this contract shall complete TARP training within 30 days of reporting for duty and then annually thereafter. TARP training will be conducted monthly by the 902nd MI Group. The COR will ensure Contractors are notified of available training. Completion of training shall be reported to the COR and the unit/activity security manager. (Ref AR 381-12).

1.6.6.13 Installation Access. All Contractor employees, including subcontractors, shall comply with applicable installation and facility access security policies and procedures at all work and TDY locations. All Contractors and subcontractors will be issued a Common Access Card (CAC) or an Installation Pass issued through the Automated Installation entry (AIE) Security System to access the installation. The Fort Gordon military installation is a limited access post. Unscheduled gate closures by the military police may occur at any time. In accordance with Army Regulation 525-13, paragraph 5-19, all prospective Contractors will undergo a verification process by the installation Provost Marshal Office, Director of Emergency Services to determine the trustworthiness and suitability prior to being granted access to federal property. This will be accomplished using the National Crime Information Center (NCIC) Interstate Identification Index (III). This is the minimum baseline background check for entrance onto Army Installations for non-CAC holders to include entrance of visitors (Ref AR 190-13, paragraph 8-2). All personnel entering or exiting the installation may experience a delay due to vehicle inspections, registration checks, verification of seat belt use, etc. All vehicles and personnel are subject to search and seizure. The search and seizure provisions shall apply to Contractor personnel while within Fort Gordon's area of jurisdiction. Contractor personnel shall comply with all entry control requirements and security policies/procedures in effect. Security procedures may change without notice.

1.6.6.14 Common Access Cards (CAC). Contractors using a government computer shall be required to obtain a CAC. To do so, the Contractor employee shall request a CAC through the COR. The government issued CAC and SIPR tokens are the property of the U.S. Government. All Contractors shall either turn their CAC in to the COR on their last day of employment, or have a completed application transfer in the Trusted Associate Sponsorship System (TASS) to a new TASS site in the case a CAC is still required. The Contractor shall return SIPR tokens to the COR upon expiration of contract or termination.

1.6.6.15 Identification of Contractor Employees. In accordance with FAR 37.114 Contractor employees shall identify themselves as a Contractor at all times while on the job, e.g., in the workplace, when attending meetings, in email, when answering government telephones, or when making phone calls.

ID Badges. The Contractor shall provide each Contractor employee an identification (ID) badge on contract start date or on employment start date. The ID badge shall be made of nonmetallic material, be easily readable, and shall contain the following minimum information: Employee's Name, Contract Company Name and Employee's Photograph. Contract employees shall wear proper identification at Government workplaces at all times.

Display of ID Badges. Contractor employees shall wear the ID badge at all times when performing work under this contract to include attending government meetings and conferences. Unless otherwise specified in the contract, each contract employee shall wear the ID badge in a conspicuous place on the front of exterior clothing and above the waist except when safety or health reasons prohibit such placement.

Answering Telephones. Contractor employees shall identify themselves as a contract employee when answering and making calls on government telephones.

Utilizing Electronic Mail.

(1) When Contractor employees send e-mail messages to government personnel while performing on this contract, the Contractor employee's e-mail address shall include the company name together with the person's name (ex: John Smith, Contractor, ABC Company).

(2) When Contractor employees require access to a government computer, the Contractor employee shall be required to obtain a Common Access Card (CAC).

To do so, the Contractor employee shall request a CAC Card through the COR.

NOTE: The government issued CAC and SIPR Token are the property of the U.S.

Government and shall be returned to the COR upon expiration of the contract, replacement or termination of the contract employee. (CAC and SIPR card must be turned in to the COR on Contractor employee's last day of employment.) Unauthorized possession of the CAC and/or SIPR can be prosecuted criminally under section 701, title 18, United States Code.

1.6.6.16 Eligibility Verification for Employment. E-Verify is an Internet-based system that compares information from an employee's Form I-9, Employment Eligibility Verification, to data from U.S. Department of Homeland Security and Social Security Administration records to confirm employment eligibility. The U.S. Department of Homeland Security is working to stop unauthorized employment. By using E-Verify to determine the employment eligibility of their employees, companies become part of the solution in addressing this problem. All U.S. employers must complete and retain a Form I-9 for each individual they hire for employment in the United States. This includes citizens and noncitizens. On the form, the employer must examine the employment eligibility and identity document(s) an employee presents to determine whether the document(s) reasonably appear to be genuine and relate to the individual and record the document information on the Form I-9. The list of acceptable documents can be found on the last page of the form. E-Verify is mandatory for employers with federal contracts or subcontracts that contain the Federal Acquisition Regulation E-Verify clause.

1.6.6.17 Physical Security. The Contractor shall be responsible for safeguarding all government equipment, information and property provided for Contractor use. At the close of each work period, government facilities, equipment, and materials shall be secured.

1.6.6.18 Key Control. The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include key cards. No keys issued to the Contractor by the Government will be duplicated. The Contractor shall develop procedures covering key control that shall be included in the Quality Control Plan. Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas. The

Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the Contracting Officer.

1.6.6.18.1.1 In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the Contracting Officer, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

1.6.6.18.2 The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the Contracting Officer.

1.6.6.19 Lock Combinations. The Contractor shall establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Contractor’s Quality Control Plan.

1.6.6.20 Contractor Replacement Time. The Contractor shall be responsible for the performance, control, and direction of their on-site personnel to ensure PWS requirements are met. The Contractor has up to 10 business days to replace any Contractor personnel not performing in accordance with the PWS unless otherwise coordinated with the COR.

1.6.6.21 Key Personnel. The Government considers the Project Manager and Cyber SU SME to be key personnel. The Contractor shall provide a Project Manager who shall be responsible for the performance of the work. The name of this person and an alternate, who shall act for the Contractor when the manager is absent, shall be designated in writing to the contracting officer. The Project Manager or alternate shall have full authority to act for the Contractor on all contract matters relating to daily operation of this contract and shall be available 8 hours a day between the hours of 0730-1630, Monday through Friday except for Federal holidays or when the Government facility is close for administrative reasons. The Project Manager shall possess a Top Secret clearance on contract start date and shall maintain it throughout the contract period of performance.

1.6.7 Staffing and Personnel Qualifications. The Contractor is responsible for the overall management and oversight of this contract. It is the Contractor’s responsibility to staff and deploy qualified Contractor personnel to meet all the PWS requirements. The Government’s historical staffing data is provided under Technical Exhibit 3.

The Contractor shall provide Subject Matter Expertise (SME) with the following working knowledge, experience, certifications and proficiency:

1.6.7.1 Project Management (PM) Task Area 5.1 :

A minimum of a master’s degree from an accredited university in one of the following areas: computer science, information technology, information systems management or business administration.

Possess two or more years of experience managing DOD professionals or professionals supporting the DOD.

Possess a Top-Secret security clearance and upon award be immediately eligible for nomination to receive Special Compartmented Information (SCI) access and able to be read on to Special Assess Programs (SAP) and Special Technical Operations (STO).

1.6.7.2 Defensive Cyberspace Operations Task Area 5.2:

Possess a minimum of three (3) years of experience in conducting defensive cyberspace operations in support of USCYBERCOM, INSCOM, Army Cyber Command or NSA cyberspace operations.

Two (2) years of experience with force modernization efforts such as capability development, materiel development, requirements determination/development, and/or force development is preferred but not required.

Possess, a bachelor degree or higher. Degree will have a focus in computer science, information technology, information systems management or computer programing.

In lieu of aforementioned computer science related bachelor’s degree, a bachelor’s degree of any kind along with seven years’ experience in DCO.

Must be certified in one or more IAT Level III certifications. Additionally, must be certified in computer network defender service provider (CNDSP) analyst, CNDSP Infrastructure Support, CNDSP incident responder, CNDSP auditor, or CNDSP manager accordance with 8570.1M.

1.6.7.3 Offensive Cyberspace Operations:

Possess a minimum of three (3) years of experience in conducting offensive cyberspace operations in support of USCYBERCOM, INSCOM, Army Cyber Command cyberspace operations or NSA computer network exploitation missions.

Two (2) years of experience with force modernization efforts such as capability development, materiel development, requirements determination/development, and/or force management is preferred but not required.

Possess at a minimum a bachelor degree or higher. Degree will have a focus in computer science, information technology, information systems management or computer programing.

In lieu of aforementioned computer science related bachelor’s degree, a bachelor’s degree of any kind along with seven years’ experience in OCO or computer network exploitation.

Possess at least one of the following certifications:

Certified Ethical Hacker (CEH) GIAC® Penetration Tester (GPEN) Offensive Security Certified Professional (OCSP)

Must possess a Top-Secret security clearance and upon award be immediately eligible for nomination to receive Special Compartmented Information (SCI) access and able to be read on to Special Assess Programs (SAP) and Special Technical Operations (STO).

1.6.7.4 Persistent Cyber Training Environment:

Have a minimum of two years with designing legacy and current Cyberspace operations infrastructure.

Have minimum of two years’ experience in developing and implementing cyberspace operations training material using virtual machine technology to include simulation computer networks.

Two (2) years’ experience/knowledge of military documentation process, capability development process, or requirements determination process is preferred but not required.

Possess, at minimum a bachelor degree, or higher, with STEM emphasis.

A Top-Secret security clearance and upon award be immediately eligible for nomination to receive Special Compartmented Information (SCI) access.

1.6.7.5 Cyberspace Situational Understanding (SU) Data Analyst:

Must have a minimum of five (5) years’ experience in data management, analytics and visualization.

Two (2) years’ experience/knowledge of DOD force modernization, capability development process, or requirements determination process are preferred but not required.

Possess a bachelor degree, or higher, from an accredited university in automated data management.

A Top-Secret security clearance and upon award be immediately eligible for nomination to receive Special Compartmented Information (SCI) access.

1.6.7.6 Cyberspace Operations Experimental and Exercise: ARMY TO DOD

Possess a minimum of a bachelor’s of science degree in computer science, information systems management, information technology, computer programming, or other relevant information technology (IT) related degree.

In lieu of an IT degree, a bachelor’s degree of any kind along with seven years’ experience in DOD training exercise development, experimentation and testing, may be substituted.

Possess a minimum of 7 years’ of work experience in the area of information technology, computer networking and have experience leading small group discussions, DOD Force modernization, capability development process and requirements determination process.

A Top-Secret security clearance and upon award be immediately eligible for nomination to receive Special Compartmented Information (SCI) access.

1.6.8 Post Award Conference/Periodic Progress Meetings. The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The contracting officer, Contracting Officers Representative (COR), and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor's performance. At these meetings the contracting officer will apprise the Contractor of how the government views the Contractor's performance and the Contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the government.

1.6.9 Contracting Officer Representative (COR). The (COR) will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies;

coordinate availability of government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially with regard to changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting order.

1.6.10 Uses and Safeguarding of Information. Information from the secure web site is considered to be proprietary in nature when the contract number and Contractor identity are associated with the direct labor hours and direct labor dollars. At no time will any data be released to the public with the Contractor name and contract number associated with the data.

1.6.11 Non-Disclosure. The Contractor shall not divulge any information accessed and obtained during the course of performing this task to other Contractor staff or anyone outside the Government. Specifically, in addition to any organizational conflict of interest provision, Contractor employees assigned to this contract will be required, prior to working, to sign a non-disclosure statement for the Government agreeing not to share any information or data with other Contractor personnel not assigned to the project or, if assigned to the project, who have not signed a non-disclosure statement.

1.6.12 Data Rights. The Government shall have unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the Contractor without written permission from the Contracting Officer. The work performed will be as a “work made for hire” as defined under U.S. copyright protection for this work. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights under the applicable Data Rights clause(s). Contractors will sign a NDA prior to commencement of any work on this contract.

1.6.13 Organizational Conflict Of Interest. Contractor and subcontractor personnel performing work under this TO may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the contracting officer immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the contracting officer to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the contracting officer and in the event the contracting officer unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the contracting officer may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.

1.6.14 Government Rights. The Contractor shall be responsible for the performance and conduct of his employees and/or Contractors, to include Contractor employees, at all times while performing under the contract. The Contractor shall maintain provisions for the immediate removal of employees for misconduct or other causes prejudicial to the maintenance of health, welfare, morale or security to Fort Gordon. The Contractor shall be aware of the Installation Commander's responsibility for the general security and well-being of Fort Gordon personnel, and shall ensure that personnel removal provisions support the Installation Commander in this regard. The Government has an inherent right under law, practice and regulation, to control access to its facilities, property and data, including those that are the subject of this contract. The Government's exercise of its right to grant and revoke access by particular individual(s) to its facilities will not constitute a breach or change to this contract, regardless of whether said individual(s) are employed by the Contractor, and regardless of whether said individuals are thereby precluded from performing work under this PWS. Contractor is required to continue performing the requirements under the PWS.

PART 2

DEFINITIONS & ACRONYMS

2. DEFINITIONS AND ACRONYMS:

2.1. DEFINITIONS:

2.1.1. CONTRACT ADMINISTRATOR. The official Government representative delegated authority by the Contracting Officer to administer a contract. This individual is normally a member of the appropriate Contracting/Procurement career field and advises on all technical contractual matters.

2.1.2. CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the government. The term used in this contract refers to the prime.

2.1.3. CONTRACTING OFFICER. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the government. Note: The only individual who can legally bind the government.

2.1.4. CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S.

Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.

2.1.5. DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.

2.1.6. DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.

2.1.7. GOVERNMENT-FURNISHED PROPERTY (GFP) OR GOVERNMENT PROPERTY (GP).

Property in the position of, or directly acquired by, the Government and subsequently made available to the Contractor.

2.1.8. KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS.

When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.

2.1.9. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.

2.1.10. QUALITY ASSURANCE. The government procedures to verify that services being performed by the Contractor are acceptable in accordance with established standards and requirements of this contract.

2.1.11. QUALITY ASSURANCE SPECIALIST. An official Government representative concerned with matters pertaining to the contract administration process and quality assurance/quality control. Acts as technical advisor to the Contracting Officer in these areas.

2.1.12. QUALITY ASSURANCE SURVEILLANCE PLAN (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of Contractor performance.

2.1.13. QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.

2.1.14. SUBCONTRACTOR. One that enters into a contract with a prime Contractor. The Government does not have privity of contract with the subcontractor.

2.1.15. WORK DAY. The number of hours per day the Contractor provides services in accordance with the contract.

2.1.16. WORK WEEK. Monday through Friday, except for Federal holidays unless specified otherwise.

2.2. ACRONYMS:

ACOR Alternate Contracting Officer's Representative AFARS Army Federal Acquisition Regulation Supplement AR Army Regulation CCE Contracting Center of Excellence CFR Code of Federal Regulations CMR Contract Manpower Reporting CONUS Continental United States (excludes Alaska and Hawaii) COR Contracting Officer Representative COTR Contracting Officer's Technical Representative COTS Commercial-Off-the-Shelf CS Cybersecurity DA Department of the Army DD250 Department of Defense Form 250 (Receiving Report) DD254 Department of Defense Contract Security Requirement List DFARS Defense Federal Acquisition Regulation Supplement DMDC Defense Manpower Data Center DOD Department of Defense FAR Federal Acquisition Regulation FSC Federal Service Code HIPAA Health Insurance Portability and Accountability Act of 1996 KO Contracting Officer OCI Organizational Conflict of Interest OCONUS Outside Continental United States (includes Alaska and Hawaii) ODC Other Direct Costs PIPO Phase In/Phase Out PM Project Manager PMP Project Management Professional POC Point of Contact POM Program Objective Memorandum PRS Performance Requirements Summary PWS Performance Work Statement QA Quality Assurance QAP Quality Assurance Program QASP Quality Assurance Surveillance Plan QC Quality Control

QCP Quality Control Program TE Technical Exhibit CyberCoE United States Army Cyber Center of Excellence IA Information Assurance ND Network Defense CEMA Cyber-Electro-Magnetic Activities IT Information Technology TD Training Development TDY Temporary Duty SIPRNET Secure Internet Protocol Routing Network JWICS Joint Worldwide Intelligence Communications System RITMS Residential Individual Training Management System AIS Automation Information Systems ATRRS Army Training Requirements and Resources System

PART 3

GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES

3. GOVERNMENT FURNISHED ITEMS AND SERVICES:

3.1 Facilities: The Government will provide the necessary workspace for the Contractor staff to provide the support outlined in the PWS to include desk space, telephones, computers, and other items necessary to maintain an office environment.

3.2 Utilities: The Government will provide electricity, water, phone service, and network services (NIPRNET, SIPRNET, JWICS & DSN), to the building. The Contractor shall instruct employees in utilities conservation practices. The Contractor shall be responsible for operating under conditions that preclude the waste of utilities, which include turning off the water faucets or valves after using the required amount to accomplish cleaning vehicles and equipment.

3.3 Equipment: The Government will provide Contractor personnel computer equipment, other data collection equipment, telephones, and monitors. The Contractor shall have access to printers, plotters, copy machines, scanners and fax machines. The Contractor shall be responsible for any loss or destruction of or damage to items of Government property that are removed from the installation premises by the Contractor – with or without Government approval.

PART 4

CONTRACTOR FURNISHED ITEMS AND SERVICES

4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES:

4.1 General: The Contractor shall furnish all supplies and services required to perform work under this contract that are not listed under Section 3 of this PWS.

4.2 Top Secret Facility Clearance: The Contractor shall possess and maintain a TOP SECRET/SCI facility clearance from the Defense Security Service. The Contractor’s employees, performing work in support of this contract shall have been granted a TOP SECRET security clearance from the Defense Industrial Security Clearance Office. The DD 254 is provided as Attachment.

4.3 Training / Certification: The Contractor shall provide on day one proof of required training and/or certifications described in this PWS

4.4 Contract Management: The Contractor shall provide all management, administration, security, quality control, and all else required to ensure successful completion of all deliverables.

PART 5

SPECIFIC TASKS

5. Specific Tasks:

5.1. Project Management: The Contractor shall provide complete program management and administrative tasks to ensure the requirements of the contract are met and to ensure the Contractor adequately controls and supervises all personnel who perform services under this contract. The Project Manager shall be the focal point for all issues and shall keep the Government fully informed, both verbally and in writing. The Contractor shall provide all necessary personnel, administrative, financial, and managerial resources required to support this contract. The Program Manger shall also be responsible for the following:

5.1.1 Shall act with the full authority for the Contractor and shall be responsible for the supervision and quality control of all work under this contract.

5.1.2 Coordinate work schedules; resolve concerns and issues and complete administrative tasks associated with this PWS.

5.1.3 Be familiar with all duties and qualifications stated in the PWS under sections 1.6.8.1 and

Part 5.

5.1.4 Have the capability and authority to resolve and respond to issues directly with the COR.

5.1.5 Provide analysis of project requirements and accurate cost estimates. Provide and gather required information to assist with coordination support efforts.

Monitor trends and upcoming changes within the DOD IA/ND community;

analyze the CSB environment; and develops recommended improvements.

Supervise Contractor employees to include resolution of conflict.

Coordinate work schedules/assignments of Contractor employees.

Communicate orally and in writing with COR.

5.2 Defensive Cyberspace Operations:

The Contractor shall provide individuals with technical, operational, and policy expertise in DCO (with…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .