2023.03.13 FMS_RFI_Atch 1_SOO.pdf

PDF 234 KB Posted

Attached to
TCJ8 Program Analysis and Financial Management Strategy Federal contract opportunity
Solicitation number
TRANSCOM23D013
Issued by
Department of Defense United States Transportation Command

View the file

Other files for this federal contract opportunity

Other files attached to TCJ8 Program Analysis and Financial Management Strategy, newest first.
File Type Posted
2023.03.13 FMS_RFI_Atch 3_DoD J8 FM Strategy.pdf PDF
2023.03.13 FMS_RFI_Atch 2_FM Strategy.pdf PDF
2023.03.13 FMS_RFI.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

STATEMENT OF OBJECTIVES (SOO)

FOR

USTRANSCOM Directorate J8 Program Analysis and Financial Management

AT

Scott Air Force Base, IL 62225

13 March 2023 Version 1.0

Table of Contents

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 General

1.2 Background

1.3 Scope

SECTION II

2.0 PROBLEM STATEMENT

2.1 Applicable Regulations

2.2 Objective(s)

2.3 Final Outcome

SECTION III

3.0 PERFORMANCE OBJECTIVES

SECTION IV

4.0 DELIVERABLES

SECTION V

5.0 TIMELINE AND STAKEHOLDERS

5.1 Timeline

5.2 Stakeholders

SECTION VI

6.0 GENERAL INFORMATION

6.1 Location

6.2 Travel

6.3 Government Furnished Property

6.4 Known or Possible Conflicts of Interest

SECTION VII

7.0 SECURITY (PHYSICAL, PERSONNEL, INFORMATION, ANTITERRORISM /

FORCE PROTECTION AND INDUSTRIAL)

7.1 General Security Information

7.2 Citizenship and Clearance Requirements

7.3 Clearance Requirements and Position Sensitivity

7.4 Security Clearance and Special Access Requirements

7.5 Facilities Clearance (FCL)

7.6 Personnel Clearance Validation

7.7 Common Access Card Issuance Procedures

7.8 Access to Scott Air Force Base or USTRANSCOM Facilities

7.9 Visits by Non-Assigned Contractors to USTRANSCOM/SDDC Buildings

7.10 Visits by Permanently Assigned Contractors

7.11 Supplemental Notes Regarding Visit Information in DISS

7.12 Security and Emergency Operations Training

7.13 Additional Security Conditions

7.14 Derogatory Information

7.15 Accessing NATO Information

7.16 Security Debriefing

7.17 Force Protection

7.18 Note To The Prime Contractor Facility Security Officer (FSO)

SECTION VIII

8.0 DATA RIGHTS

SECTION IX

9.0 APPENDIX A

9.1 Definitions

9.2 Abbreviations and Acronyms

SECTION X

10.0 APPENDIX B

10.1 Government Furnished Equipment

SECTION I

1.0 DESCRIPTION OF SERVICES

1.1 General.

USTRANSCOM J8 (TCJ8) is the Program Analysis and Financial Management Directorate which formulates and integrates the command’s budget while focused on the effective and efficient use of the command’s resources. TCJ8 develops command fiscal policy procedures and resolves issues on use of the -Command wide $8.1 billion Transportation Working Capital Fund (TWCF) budget. This Directorate is the focal point for financial integrating policies and procedures in coordination with our Transportation Component Commands and the Office of the Secretary of Defense. Additionally, the Directorate shapes strategic goals and ensures funding of critical initiatives through the Planning, Programming, Budgeting, and Execution cycle. TCJ8 is the fiscal Corporate Governance Process lead for establishing cost benefit analysis priorities of future investments in Capital Purchases.

1.2 Background.

The National Defense Strategy (NDS) underscored the need to challenge the strategic competition of a re-emergent China and Russia and reform the Department’s business practices for greater performance and affordability. These priorities resulted in refocusing resources from supporting an enduring posture requirement in the Middle East and Central Asia to rebuilding readiness of the Joint Force.

The subsequent drawdown of forces accelerated USTRANSCOM’s Program Analysis and Financial Management Directorate to focus on transforming and modernizing the working capital fund management capabilities and improve the organization’s operational effectiveness and performance. This effort was accomplished through the development of TCJ8’s Strategy.

TCJ8 is now challenged to implement the mission and vision of the existing USTRANSCOM Financial Management (FM) Strategy and its prioritized Lines of Effort organically.

Concentrating specific efforts to build out an organizational roadmap, grounded in the existing USTRANSCOM FM Strategy, will ensure stronger financial insights to be delivered by trusted advisors across the USTRANSCOM Enterprise.

1.3 Scope.

Aligned with the established USTRANSCOM FM Strategy and prioritized lines of effort, this initiative will focus on the implementation and management of an operational project management solution to track timelines and create organizational accountability. Lines of effort are where leaders believe action and resources are needed most. Each line of effort has multiple initiatives that require flight plans. USTRANSCOM requires a contractor to analyze and assess prioritized lines of effort and initiatives and make recommendations on viability. The Government also requires the contractor to identify gaps in business processes and recommend additional lines of effort or initiatives.

Project tasks will incorporate each of the four strategic focus areas.

Operationalizing Financial Information Create an Innovative, Diverse, and Agile Workforce.

Modernization and Systems.

Transparency and Compliance.

USTRANSCOM recognizes that in order to achieve the above prioritized lines of effort, it requires the transformation of the J8 organization through improved structure and business processes.

Program Goals: The operational project management solution should monitor and track the prioritized lines of effort outlined in the USTRANSCOM Financial Management Strategy and initiatives linked to the lines of effort.

Areas of the program going well (no change): Completed development of the Financial Management Human Capital Strategy and the Financial Management Data Strategy. Data Strategy efforts are the most robust of the lines of effort.

Areas of the program that need to be changed: N/A

Program Risks: Substantial risk to a stable Transportation Working Capital Fund (TWCF) and agile comptroller operations essential for resourcing emergent operational requirements and preserving SECDEF and USTRANSCOM/CC decision space when considering options.

SECTION II

2.0 PROBLEM STATEMENT

USTRANSCOM TCJ8 lacks an integrated project management solution outlining required resources and capabilities, track timelines and create organizational accountability. Without a viable integrated project management solution, the lines of effort and initiatives cannot be achieved in an organized way resulting in wasted resources and failure to complete many of the initiatives.

The Contractor shall provide all services, materials, supplies, equipment, travel, and project supervision, as required in connection with this Statement of Objectives (SOO).

2.1 Applicable Regulations.

DOD Financial Management Regulation 7000.14-R and DODI 5158.06 Joint Deployment and Distribution Enterprise (JDDE)

2.2 Objective(s).

Develop an Operational Project Management Solution for the Implementation of the Existing Financial Management Strategy

Develop a 5-year operational project management solution for the implementation of the USTRANSCOM FM Strategy including required resources and capabilities, track detailed timelines and create organizational accountability. Solution should consider communication and managing change in the Financial Management Enterprise. Solution should include an integrated and prioritized schedule.

Analyze and Assess prioritized lines of effort and initiatives and make recommendations on viability.

Identify gaps in business processes and recommend additional lines of effort or initiatives.

2.3 Final Outcome.

At the end of the contract TCJ8 shall have a project managed solution that sets the USTRANSCOM Financial Management Enterprise on a path to provide resources, financial services, and cost and decision support necessary to conduct globally integrated mobility operations, and project and sustain the Joint Force in support of national objectives.

SECTION III

3.0 PERFORMANCE OBJECTIVES

Final deliverable is complete, accurate, incorporates/addresses all Government comments/concerns on initial and midterm deliverables, and meets the objectives of this SOO to provide an integrated project management solution.

Performance Objective

SOO

Para Deliverable/Performance Threshold

Method of Surveillance

Project Management Solution

2.2

Project management solution shall document required resources and capabilities, track timelines and create organizational accountability allowing the USTRANSCOM Financial Management Enterprise to implement the lines of effort and initiatives in an organized and efficient manner.

100% Surveillance – COR will review each document for completeness, accuracy and timeliness.

SECTION IV

4.0 DELIVERABLES

The Contractor shall provide deliverable(s) in a format mutually agreed upon by the Government and the Contractor. The following deliverables are not expected to change. Due Date intervals are not expected to change but actual dates may need to be revised depending on actual contract start date.

Deliverables and Performance are not considered acceptable until the Government provides written notice of acceptance. This can be in the Monthly Status Report (bi-lateral signatures from the contractor and COR) and/or written acceptance via email.

Deliverable Due Date Delivery Method

Weekly Meetings

Weekly meetings with the Government to review status of work in progress, discuss problems/concerns, and receive Government guidance as necessary to facilitate and/or improve development of the final deliverable.

Weekly In-person meetings

Monthly Status Report (MSR)

MSR detailing activities accomplished in the past month, activities projected for the next month, open issues requiring Government resolution, open risks, etc.

No later than the 5th workday of each month

By email to the COR in Microsoft Office formats

Formal Briefings

Deliver agenda, presentation slides, and minutes for up to 3 contractor-led or facilitated formal briefings throughout the life of the contract

Agenda and presentation slides 48 hours prior to formal briefing, minutes 48 hours after formal briefing

By email to the COR in Microsoft Office formats

Service Contract Reporting

Report in the System for Award Management:

1. The total dollar amount invoiced for services performed during the previous Government fiscal year under the contract;

2. The prime contractor direct labor hours expended on the services performed during the previous Government fiscal year; and

3. If applicable Tier 1 subcontract number, including DUNS number/Unique Entity Identifier (UEI) and name, and the number of subcontractor direct labor hours expended under the contract.

10 days prior to 31 October of each year of the contract

(Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs October 1 through September 30.)

By email to the COR showing evidence of submission

5-year Project Management Solution: Reference Objective 2.2

Initial Draft Due three (3) months after contract award

Mid-Term Draft Due five (5) months after contract award

Final Product Due six (6) months after contract award

By email to the COR in Microsoft Office formats

SECTION V

5.0 TIMELINE AND STAKEHOLDERS

5.1 Timeline.

Contractor Proposed. Performance shall not exceed six (6) months.

5.2 Stakeholders.

The collaborating offices for the USTRANSOM Financial Management Enterprise are TCJ8, AMC/FM, MSC/N8, and SDDC/G8.

SECTION VI

6.0 GENERAL INFORMATION

In support of the USTRANSCOM mission, the identified tasks and/or outputs may take the form of information, advice, opinions, alternatives, analyses, evaluations, training, processes to eliminate waste, standardize best practices, reduce cycle times and reduce the cost of doing business, or recommendations to complement the Government’s technical expertise in accomplishing its mission and day-to-day activities. The contractor shall provide a work force possessing the skills, knowledge and training to satisfactorily perform the services required under this contract. The primary work location for contractor personnel will be at Scott Air Force Base, IL. However, other CONUS work locations or travel may be required.

Contractor employees performing services under this contract shall be controlled, directed and supervised at all times by management personnel of the contractor. The contractor's management shall ensure that employees properly comply with the performance standards outlined in this Statement of Objectives and as required by the contracting officer or the contracting officer's representative (COR). Contractor employees shall be capable of performing independently and without the assistance of Government personnel. Actions of contractor employees shall not be interpreted or implemented in any manner which results in a contractor employee creating, modifying or violating Federal policy, obligating the appropriated funds of the U.S. Government, overseeing the work of Federal employees, providing direct personal services to any Federal employee or otherwise violating the prohibitions set forth in Parts 7.5 and 37.1 of the Federal Acquisition Regulation (FAR). If the contractor feels that any actions constitute or are perceived to constitute personal services, it shall be the contractor’s responsibility to notify the COR immediately.

No contractor personnel will perform any work on this contract that can be defined as inherently governmental according to FAR Subpart 7.503(c). Contractor personnel will be performing tasks under FAR Subpart 7.503(d); however, contract personnel will be in a supporting role to the Government task lead and will not be in a decision-making role. The Government will be the sole authority for decisions.

6.1 Location.

The primary place of performance for all services will be performed on Scott AFB, IL. Telework is allowable with prior Government coordination. The Government shall provide workspace for Contractor personnel as required. In addition, the Government will provide Non-Secure Internet

Protocol Router Network (NIPRNET) and Secret Internet Protocol Router Network (SIPRNET) access at USTRANSCOM facilities for Contractor personnel as appropriate. Access to USTRANSCOM Government facilities requires personnel to hold a valid SECRET or Interim SECRET clearance prior to entry.

6.2 Travel.

There are no known travel requirements at this time. In the event travel is required, the Government will modify the contract to increase the price to cover travel. Price shall be determined fair and reasonable.

6.3 Government Furnished Property.

Equipment for use within the performance of this contract shall be managed IAW FAR 52.245-1.

A list of GFP will be provided in Appendix B.

The Contractor will be provided workstations for remote NIPRNet access. The Contractor shall keep the workstations connected to the USTRANSCOM Network and available to receive patches/updates at all times. If the workstation is disconnected from the network for an extended period (over 30 days) and cannot receive patches/updates then the Contractor shall pay for the shipping of the workstation, as well as any travel-related expenses incurred to reimage workstation.

6.4 Known or Possible Conflicts of Interest.

None.

SECTION VII

7.0 SECURITY (PHYSICAL, PERSONNEL, INFORMATION, ANTITERRORISM /

FORCE PROTECTION AND INDUSTRIAL)

7.1 General Security Information.

The majority of daily work associated with this PWS is at the unclassified level, but contractor personnel may be required to access SECRET information and/or classified areas, during performance of this task order.

7.2 Citizenship and Clearance Requirements.

The contractor’s, subcontractors, and/or partner’s personnel performing services under this task order shall be citizens of the United States of America. Overall, all contractor personnel shall possess the appropriate personnel security investigation for the position(s) occupied. Contractor personnel shall be required to have a background investigation that corresponds with the sensitivity level of the tasks to be performed. Note that neither dual citizens nor non-US citizens are eligible for Common Access Cards (CACs) unless they meet the parameters stated in DoDM 1000.13, volume 1.

7.3 Clearance Requirements and Position Sensitivity.

Contractor personnel with IA administrative privileges and/or who will monitor DOD IT systems or software as designated by DOD Instruction 8500.1 and DOD Manual 5200.02 may be rated at the various levels listed below. The stipulation of the numbers and what IT/Automated Data Processing (ADP) levels the contractors will have is approved by the COR or the CO before the start of the task order. The contractor shall comply with all appropriate provisions of applicable security regulations while assigned to this task order for DOD and USTRANSCOM. The following guidance will be followed when determining background investigation and clearance levels for this task order depending on requirements:

POSITION LEVEL:

Information Technology (IT)-II Automated Data Processing (ADP)-II Or Non-Critical Sensitive Positions (SECRET):

IT/ADP-II and Non-Critical Sensitive Positions are those positions that: have access to Secret or Confidential information; Security police/provost marshal-type duties involving the enforcement of law and security duties involving the protection and safeguarding of DOD personnel and property; category II automated data processing positions; duties involving education and orientation of DOD personnel; duties involving the design, operation, or maintenance of intrusion detection systems deployed to safeguard DOD personnel and property;

responsible for the direction, planning, design, operation, or maintenance of a computer system, and whose work is technically reviewed by a higher authority of the ADP-I category to ensure the integrity of the system; and any other position so designated by the head of the Component or designee.

BACKGROUND INVESTIGATION REQUIREMENTS:

(IT-II/ADP-II/Non-Critical Sensitive) Requirements for SECRET – (Tier 3):

Positions designated by the Government at the Non-Critical Sensitive/ADP-II/IT-II rating require a Tier 3 (or acceptable periodic reinvestigation) favorably adjudicated (a favorable adjudication grants eligibility at the SECRET level as prescribed by DODM 5200.02). The IT-II/ADP-II requirement mandates the contractor have a minimum Facilities Clearance Level at the SECRET (or higher) level due to investigation submissions as directed in DOD 5220.22-M Operating Manual, DODM 5200.01 and Defense Information Security System (DISS).

POSITION LEVEL:

Information Technology (IT)-III Automated Data Processing (ADP)-III Or Non-Sensitive Positions (Position of Trust Determination) (No Classified Access–Tier 1) All other positions involved in computer activities and Common Access Card. No clearance is granted for classified access and only a Position of Trust (PoT) is awarded and posted in DISS.

BACKGROUND INVESTIGATION REQUIREMENTS:

(Non-Sensitive/IT-III/ADP-III) Requirements for Position of Trust Determinations (No Classified Access - Tier 1/NACI):

Positions designated by the Government as Non-Sensitive/IT-III/ADP-III require a favorably adjudicated Tier 1/NACI investigation or greater IAW DoDI 5200.46, DoD Investigative and Adjudicative Guidance for Issuing the Common Access Card (CAC), dated 9 Sep 2014, DoDM 1000.13, Vol 1, DoD Identification (ID) Cards: ID Card Life-Cycle, dated 23 Jan 2014, and Defense Counterintellience and Security Agency (DCSA) standards. Before a CAC or NIPRNet access will be granted, a favorable Tier 1/NACI investigation or greater must be on record in Defense Information Security System (DISS), and a favorable Federal Bureau of Investigation (FBI) National Criminal History Check (fingerprint check) on record with DCSA. A CAC may be issued on an interim basis based on a favorable FBI fingerprint check and successful submission of a Tier 1 investigation to DCSA NBIB, and on record in DISS.

NOTE: The above requirements for Non-Sensitive/IT-III/ADP-III positions are for unclassified access and systems only. No classified access will be granted based on the Tier 1 investigation.

USTRANSCOM will only process Tier 1 investigations and will not complete any personnel security investigations (Tier 3/Tier 5) for classified access. It is incumbent upon the contractor to have the appropriate investigations completed upon start of the task order.

7.4 Security Clearance and Special Access Requirements.

All positions on this contract/task order, require a minimum of either an interim SECRET granted by the Vetting Risk Operations Center (VROC) or a completed adjudication of SECRET granted by the DoD Consolidated Adjudication Facility (CAF).

7.5 Facilities Clearance (FCL).

The contractor must have a valid FCL at the SECRET level. FCL procedures and security guidelines for adjudicative requirements are outlined in DOD 5220.22-M. FCLs and interim FCLs must be awarded by the Defense Counterintelligence and Security Agency (DCSA) Facility Clearance Branch.

7.6 Personnel Clearance Validation.

Upon contract/task order award, the contactor shall submit the names of contractor personnel to the USTRANSCOM contracting team, who will provide to TCCS-PR for vetting through DISS or the Defense Information Security System (DISS) to ensure investigative and clearance requirements have been satisfied. This shall be completed before the COR/Trusted Agent (TA) accesses the DOD Trusted Associate Sponsorship System (TASS) and creates CAC applications for contractor personnel. If a contractor’s employee does not have the required investigative or security clearance level based on the Government’s determination, the contractor’s employee will be denied the ability to work in support of this contract/task order.

7.7 Common Access Card Issuance Procedures.

a. For those personnel that do not have the required background investigation (the FSO will make the determination by searching for a valid account for that person in DISS). If a valid account does not exist in DISS, the contracting company must submit to the USTRANSCOM Personnel Security Manager (through the CO or COR), an OF Form 306 (Declaration for Federal Employment), and a SF 85 (questionnaire for Non-Sensitive Positions) it’s only sent after the FSO or equivalent reviews it for accuracy.

b. At the same time, the contractor company will coordinate and obtain electronic fingerprinting for their employee. The third-party Company will "electronically" capture the applicant’s fingerprints, using the USTRANSCOM (SON, SOI, and ALC). Hardcopy fingerprint cards are not acceptable.

These steps shall be completed before the COR/Trusted Agent (TA) accesses the DOD Trusted Associate Sponsorship System (TASS), to create a CAC application.

Basic U. S. Citizen Contractor CAC Requirements:

1. Requires access on a continual basis of 6 months or more.

2. Contract personnel require access to a DoD facility or networks, either on-site or from a remote location.

3. Users need access to systems for platforms that requires CAC login or user authentication.

Basic Non- U. S. Citizens Contractor CAC Requirements:

1. Possess legal U. S. residency for a period of 3 or more years with a completed Tier 1 background investigation and fingerprint card. Also meet (as a direct/indirect DoD hire personnel) the investigative requirements for DoD employment as recognized through international agreements pursuant to subchapter 2131 of DoD 1400.25 (reference M).

2. Possess (as foreign military, employee or contract support personnel), a visit status and security assurance that has been confirmed, documented and processed IAW international agreements pursuant to DoDI 1400.25: Civilian Personnel Management.

CAC Applications:

1. The CAC applications must have an adjudicated Tier 1, Tier 3 or Tier 5 background investigation posted in DISS, or

2. An interim CAC may be approved when the contractor employee has a favorable fingerprint, name and criminal records check completed and has either a Tier 1, Tier 3 or Tier 5 background check “open” with DCSA.

3. The TASS TA will not approve the CAC application in TASS until that TA has verified with a member of USTRANSCOM Protection and Response (TCCS-PR), one of the above requirements.

7.8 Access to Scott Air Force Base or USTRANSCOM Facilities.

Upon receipt of the CAC, permanently assigned contractor personnel located at USTRANSCOM at Scott AFB (SAFB), IL, may obtain the AF 1199 (Restricted Area Badge) if the employee meets the requirements set forth in SAFB Instruction 31-101. This stipulates that personnel who request AF 1199’s be assigned physically on SAFB at least four (4) days a week with a desk computer and phone before a AF 1199 will be issued. The Government will provide unrestricted access to facilities, consistent with security clearance and need to know, necessary for the on-site personnel to perform their work IAW the task order. Contractor personnel assigned on-site at USTRANSCOM will wear and display the Restricted Area badge at all times while in Government facilities. Visits to SAFB by contractor personnel who do not possess the CAC will be facilitated by the COR/CO sponsoring the employee through the online base access system.

7.9 Visits by Non-Assigned Contractors to USTRANSCOM/SDDC Buildings.

Any visit(s) by contractor personnel not permanently assigned to this task order (i.e., company presidents, company security managers, contractor personnel not permanently assigned at SAFB, etc.) require an electronic visit request be submitted using DISS. DISS visits can be forwarded to the Security Management Office (SMO) code: USTC-SDDC. The visit request shall annotate the task order number in the POC block of the visit request and the name/phone number of either the functional, COR or CO in the phone number block.

7.10 Visits by Permanently Assigned Contractors.

Permanently assigned contractor employees on SAFB will require a visit request for the current period of performance posted in DISS to SMO: USTC-CONT. The visit request will annotate the contract number in the POC block of the visit request and the name/phone number of either the functional, COR or CO in the phone number block. Upon in-processing permanently assigned contractors will require a copy of the DD Form 254 for this task order to show the classified access level for this task order and to assist in assigning permissions on restricted area badges.

7.11 Supplemental Notes Regarding Visit Information in DISS.

Personnel requiring access to Government facilities will properly complete the “Visit Information” block in DISS. Otherwise, contractor employees will be denied access to the facility and classified and/or sensitive information. Also, prime contractors will annotate their contract number and subcontractors will provide the name of their Company, with the prime contract number they are assigned to by the Prime, in the “additional information” block of the Visit table. A valid “Reason for the Visit” must be stated and the “visit access” must not exceed that of the contract.

7.12 Security and Emergency Operations Training.

Contractor personnel physically assigned at USTRANSCOM at SAFB shall attend/complete the following training as prescribed by DOD, USTRANSCOM and Air Force Instructions: Annual Security Awareness, OPSEC, DOD Antiterrorism Level I, Active Shooter, Emergency Operations and any Security Stand-down Day Training scheduled by the Commander, USTRANSCOM. Contractor personnel assigned elsewhere shall attend security training established by their respective Government security offices and/or installations.

7.13 Additional Security Conditions.

All contractors assigned to USTRANSCOM on SAFB will complete the contactor in-processing checklist before the start of work on this or any contract/task order in USTRANSCOM.

Contractors starting work on a new contract will report to the Protection Service Desk (PSC), located in Building 1900 Breezeway. In-processing includes the following:

Verification of personal Identification Review of the employee copy of the contract DD-254 Matching information from the DD-254 to the Visitor Notification in DISS Verification of the contractors Security Clearance in DISS Brief and sign the individual SF-312 (Security Agreement) Review of access requirements Issuance of a Temporary Line Badge (AF-1199) for the facility Creation of a personnel file Brief North Atlantic Treaty Organization (NATO) Access

7.14 Derogatory Information.

If the Government notifies the contractor that the employment or the continued employment of any contractor personnel is prejudicial to the interests or endangers the security of the United States of America, that employee shall be removed and barred from the worksite. This includes security deviations/incidents and credible derogatory information on contractor personnel during the course of the task order’s period of performance as noted in DISS. Personnel who have incident reports posted in DISS will be denied the ability to support the task order until the issues have been resolved and the incident has been removed in DISS. The contractor shall make any changes necessary in the appointment(s), at no additional cost to the Government. If any incident involves or may involve the mishandling of classified information or a potential Negligent Discharge of Classified Information, the USTRANSCOM Protection and Response office (618- 220-6554) will be notified within 24 hours during the normal work week and within 72 hours if the incident occurs over the weekend.

7.15 Accessing NATO Information.

No contractor employee will access NATO information without first being indoctrinated on NATO and having that access recorded in DISS. Any NATO information accessed will be only on SIPRNet. Senders of NATO information will ensure the receiving network is accredited and the receiving point is a Sub-Registry or authorized Control Point. No NATO information will be stored with US classified information. Access to NATO information will be based on need-to-know, appropriate access level, and training. NATO information will not be disseminated to unauthorized users. NATO information will not be printed unless authorized by a USTRANSCOM NATO –Sub-Registry person in TCCS-PR. All printed NATO classified information must be strictly controlled and tracked in a NATO registry. Contact the USTRANSCOM Sub-Registry for additional control measures. In accordance with the NISPOM, Chapter 10-706, NATO briefed personnel will be re-briefed on an annual basis. USTRANSCOM will indoctrinate all on-site contractor employees and document in DISS. Contractor personnel assigned to USTRANSCOM facilities will be NATO briefed and debriefed by USTRANSCOM, with appropriate annotations to DISS. Company FSOs may take responsibility for all NATO refresher briefings per NISPOM paragraph 10-706 and record the date of the annual briefings in

DISS.

7.16 Security Debriefing.

Contractor personnel physically working at USTRANSCOM at SAFB, IL, shall complete the out-processing checklist on the last day of the task order or upon termination or reassignment from duties under the current contract or task order. The following closeout tasks will be completed, before the contractor departs:

Review of the contractor’s personnel folder Review and debrief the contractor’s SF-312 Debrief anyone with NATO Access Update and annotate DISS records reflecting the current status of the contractor at

USTRANSCOM

Surrender CAC cards (with a copy of the revocation notice from the COR or TA) Surrender the facility Restricted Area Badge (AF-1199) to the Protection Service Center Contractor personnel shall have surrendered all Government supplies, materials and equipment to the COR

7.17 Force Protection.

Contractor employees will comply with antiterrorism Force Protection conditions (FPCONs) at the location they are performing work on, whether it is CONUS or OCONUS.

7.18 Note To The Prime Contractor Facility Security Officer (FSO).

The prime contractor will forward the name, address, email address and telephone number of the Company FSO and backup to the USTRANSCOM Protection and Response to:

steven.m.strait.civ@mail.mil and andrew.p.daub.civ@mail.mil

USTRANSCOM Protection and Response (Industrial Security) Points of Contact:

USTRANSCOM

Attn: TCCS-PR (Steve Strait or Andrew Daub) 508 Scott Drive Scott AFB IL 62225 Telework cell phone: 618-698-4798 TCCS-PR Approval: Steven M. Strait, USTRANSCOM TCCS-PR Tracking #: USTRANSCOM-TCCS-0XX-21

References: Defense Electronic Libraries:

Acquisition Notes: http://acqnotes.com Assist – Quick Search: http://quicksearch.dla.mil Official Website of the Joint Chiefs of Staff (JCS): https://www.jcs.mil/ Defense Acquisition University (DAU): https://www.dau.mil Department of Defense: http://www.esd.whs.mil/dd/dod-issuances/ Federal Registry: https://www.federalregister.gov/

Joint Electronic Library: https://www.jcs.mil/Doctrine/ USTRANSCOM: https://ww2.ustranscom.mil/FP_2018/fp_index.cfm Security Regulation Guidance:

http://www.dtic.mil/whs/directives/corres/pub1.html Federal Information Processing Standards (FIPS) and National Institute of

Standards and Technology (NIST): https://csrc.nist.gov/publications Military Standards (MIL-STD): https://www.dau.mil/ Committee on National Security Systems (CNSS):

https://www.cnss.gov/CNSS/issuances/Instructions.cm Institute of Electrical and Electronics Engineers (IEEE) Publications:

https://www.ieee.org/publications_standards/index.html

Governing Guidance and Directives:

American National Standards Institute (ANSI)/Electronic Industries Alliance (EIA) 748:

Earned Value Management, current edition CJCS Instruction 5123.01H, Charter of the Joint Requirements Oversight Council (JROC) and Implementation of the Joint Capabilities Integration and Development Systems (JCIDS), August 31, 2018

CJCS Instruction 6510.01F, Information Assurance (IA) and Support to Computer Network Defense (CND), June 9, 2015

CJCSM 3213.02D, Joint Staff Alternative Compensatory Control Measures (ACCM) Program Management Manual (Limited Distribution)

CJCSM 6510.01B, Cyber Incident Handling Program, 10 July 2012 Data Item Management-81861, Data Item Description: Integrated Program Management

Report (IPMR), June 20, 2012 DD Form 254, Contract Security Classification Specification, November 1, 2017 Defense Federal Acquisition Regulation Supplement, current edition DOD 5200.08, Security of DoD Installations and Resources and the DoD Physical Security

Review Board (PSRB), Change 3, November 20, 2015 DOD Instruction 5220.22, National Industrial Security Program, May 1, 2018 DODM 6025.18, Implementation of The Health Insurance Portability and Accountability

Act (HIPAA) Privacy Rule in DoD Health Care Programs, March 13, 2019 DOD Instruction 8500.01, Cybersecurity, Change 1, October 7, 2019 DOD Instruction, 8510.01, Risk Management Framework (RMF) for DoD Information

Technology (IT), Change 2, July 28, 2017 DOD Directive 5230.25, Withholding of Unclassified Technical Data from Public

Disclosure, December 28, 2016 DOD Instruction 8320.02, Data Sharing, in a Net Centric Department of Defense, August

5, 2013 DOD Instruction 1100.22, Policy and Procedures for Determining Workforce Mix, Change 1, December 1, 2017 DOD Instruction 2000.12, DoD Antiterrorism (AT) Program, Change 3, May 8, 2017 DOD Instruction O-2000.16, DoD Antiterrorism (AT) Program Implementation: DoD AT

Standards, Volume 1, November 17, 2016 with C3 May 7, 2021

DOD Instruction O-2000.16, DoD Antiterrorism (AT) Program Implementation: DoD Force Protection Condition (FPCON) System Volume 2, May 8, 2017 with C1 May 8, 2017

DOD Instruction 5025.13, DOD Plain Language Program, January 23, 2020 DOD Instruction 5200.02, “Personnel Security Program,” September 9, 2014 DOD Instruction 8330.01, “Interoperability of Information Technology (IT), Including

National Security Systems (NSS),” December 18, 2017 DOD Instruction 8500.01, “Cybersecurity,” March 14, 2014 DOD Instruction 8510.01, “Risk Management Framework (RMF) for DOD Information

Technology (IT),” July 28, 2017 DOD Instruction 8520.02, “Public Key Infrastructure (PKI) and Public Key (PK)

Enabling,” May 24, 2011 DOD Instruction 8551.01, “Ports, Protocols, and Services Management (PPSM)”, July 27, 2017 DOD Instruction 8582.01, “Security of Unclassified DOD Information on Non-DOD

Information Systems,” October 27, 2017 DOD Manual 1000.13, Volume 1, “DOD Identification (ID) Cards: ID Card Life-

Cycle,” January 23, 2014 with C1 July 28, 2020 DOD Manual 5200.01, Volume 1, “DOD Information Security Program: Overview, Classification, and Declassification,” February 24, 2012 with C2, July 28, 2020 DOD Manual 5200.01 Volume 2, “DOD Information Security Program: Marking of

Classified Information,” March 19, 2013 with C4 July 28, 2020 DOD Manual 5200.01 Volume 3, “DOD Information Security Program: Protection of

Classified Information,” March 19, 2013 with C3, July 2020 DODI 5200.48, “Controlled Unclassified Information,” 6 March 2020 DOD 5200.08-R, Change-1, DoD Physical Security Program, May 27, 2009 DFARS 252.205-7012, Safeguarding Covered Defense Information and Cyber Incident

Reporting DOD Manual 5200.02, “Procedures for the DOD Personnel Security Program (PSP),”

April 3, 2017 with C1 October 29, 2020 DOD Manual 5220.22, Volume 3, “National Industrial Security Program: Procedures for

Government Activities Relating to Foreign Ownership, Control, or Influence (FOCI),” April 17, 2014 with C1 August 5, 2020

DOD Standard MIL-STD-881C, “Work Breakdown Structures (WBS) for Defense Materiel Items,” October 3, 2011

Office of Management and Budget Circular A-11, “Preparing, Submitting, and Executing the Budget,” current edition

USTRANSCOM Instruction 31-02, “Security Classification Guide,” April 6, 2018 USTRANSCOM Instruction 31-12, “Operations Security,” February 19, 2015 USTRANSCOM Instruction 33-1, “Information Systems Security Education, Training, and Awareness Program,” March 27, 2017 USTRANSCOM Instruction 33-48, “Data Management Policy and Responsibilities,”

February 16, 2016 USTRANSCOM Instruction 33-58, “Cyber Workforce Management,” February 26, 2016 Scott Air Force Base: AF Instruction 31-101_AMC, January 4, 2014 FIPS 199, “Standards for Security Categorization of Federal Information and Information

Systems,” February 2004 FIPS 200, “Minimum Security Requirements for Federal Information and Information

Systems,” March 2006 NIST SP 800-18 Revision 1, “Guide for Developing Security Plans for Federal

Information Systems” February 2006 NIST SP 800-30 Revision 1, “Guide for Conducting Risk Assessments,” September 2012 NIST SP 800-37 Revision 2, “Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy,” June 5, NIST SP 800-53, Revision 4, “Security and Privacy Controls for Federal Information Systems and Organizations,” January 22, 2015

NIST SP 800-53A Revision 4, “Assessing Security and Privacy Controls in Federal Information Systems and Organizations: Building Effective Assessment Plans,” December 18, 2014

NIST SP 800-60 Volume 1, Revision 1, “Guide for Mapping Types of Information and Information Systems to Security Categories,” August 2008

NIST SP 800-61 Revision 2, “Computer Security Incident Handling Guide,” August

CNSS Instruction 1253, “Security Categorization and Control Selection for National Security Systems,” March 27, 2014

12207.0-1996 IEEE/EIA Standard Industry Implementation of International Standard ISO/IEC 12207: 1995 (ISO/IEC 12207) Standard for Information Technology Software Life Cycle Processes. Superseded by: 12207-2008 – Standard for Information Technology – Software Life Cycle Processes

12207.1-1997 - Industry implementation of International Standard ISO/IEC 12207: 1995.

(ISO/IEC 12207) Standard FOR Information Technology - Software Life Cycle Processes

- Life Cycle Data superseded by: 15289-2017: 15289-2017 - ISO/IEC/IEEE Draft International Standard - Systems and software engineering -- Content of life-cycle information items (documentation)

Executive Order (E.O.) 13691 of February 13, 2015. Promoting Private Sector Cybersecurity Information Sharing

SECTION VIII

8.0 DATA RIGHTS

The copies of any Contractor generated records, files, documents, data, and work papers, provided to the Government in performance of this task order shall become and remain Government property and shall be maintained and disposed of IAW Air Force Manual 33-363, Management of Records; AFI 33-364, Records Disposition – Procedures and Responsibilities;

and other regulations, as applicable. The copies of any Government generated records, files, documents, data, and work papers, provided to the Contractor in performance of this task order, or derivatives thereof, are and shall remain Government property, and shall be returned to the Government at the completion of this contract. Software licensing terms shall not conflict with Federal law or regulation. In according with the Defense Federal Acquisition Regulation Supplement 239.7602-1, “DoD shall acquire cloud computing services using commercial terms and conditions that are consistent with Federal law, and an agency’s need. Contracting officers shall incorporate any applicable service provider terms and conditions into the contract by attachment or other appropriate mechanism.” The Government shall not be bound by any licensing terms or other restrictions on the use, modification, reproduction, release, performance, or disclosure of software not incorporated by attachment or other appropriate mechanism.

SECTION IX

9.0 APPENDIX A

9.1 Definitions.

Contracting Officer (CO). The duly appointed Government agent authorized to award or administer contracts. The contracting officer is the only person authorized to contractually obligate the Government.

Statement of Objective (SOO). A formal contracting document used to describe the goals and objectives expected from soliciting contractor work.

Organizational Conflict of Interest (OCI). Unequal access and competitive advantage are two conflicts that the government is aware of that could result from Non-Financial Recommendations

(NFR).

Performance Threshold. The minimum performance level of a performance objective required by the Government.

9.2 Abbreviations and Acronyms.

Acronym Definition

ADP Automated Data Processing AFB Air Force Base AMC Air Mobility Command AOA Analysis of Alternatives AT Antiterrorism CAC Common Access Card CO Contracting Officer CMRA Contractor Manpower Reporting Application COCOM Combatant Command COR Contracting Officer Representative CPI Critical Program Information CRIS Commanders' Resource Integration System DAWIA BUS-CE Defense Acquisition Workforce Improvement Act Business Cost

Estimating DEAMS Defense Enterprise Accounting and Management System DEERS Defense Enrollment Eligibility Reporting System

DFARS Department of Defense Federal Acquisition Regulation Supplement

DFAS Defense Finance & Accounting Services DoD Department of Defense DoDI Department of Defense Instruction DPO Distribution Process Owner DSS Defense Security Service EA Economic NLT FAR Federal Acquisition Regulations FCL Facilities Clearance Level FY Fiscal Year FMR Financial Management Regulation IA Information Assurance IAW In Accordance With ICEAA International Cost Estimating and Analysis Association IPR In Progress Review IT Information Technology JFC Joint Finance Center JPAS Joint Personnel Adjudication System LOO Line of Operation MAM Mission Area Manager MOA Memorandum of Agreement MSR Monthly Status Report NACI National Agency Check with Inquiries NACLC National Agency Check with Local Credit NATO North Atlantic Treaty Organization NDA Non-Disclosure Agreement NIPRNET Non-Secure Internet Protocol Router Network NISPOM National Industrial Security Program Operating Manual NLT No Later Than OPSEC Operations Security PBR Program and Budget Revie w PEO Program Executive Office PII Personally Identifiable Information PoT Position of Trust POV Privately Owned Vehicle PPBE Planning, Programming, Budgeting, and Execution PWS Performance Work Statement RAPIDS Real-Time Automated Personnel Identification System SAFB Scott Air Force Base, Illinois SDDC Surface Deployment and Distribution Command SF Standard Form SLIN Sub-Contract Line Item Number SIPRNET Secret Internet Protocol Router Network SLOC Source Lines of code

SMO Security Management Office SSC Protection Services Center STSS Specialized Transportation and Support Services TA Trusted Agent TASS Trusted Associate Sponsorship System TCAQ US Transportation Command Directorate of Acquisition TCB Transportation Corporate Board TCJ8 US Transportation Command Program Analysis And

Financial Management Directorate TFMS Transportation Financial Management System TOC Transportation Oversight Council TWCF Transportation Working Capital Fund USTC United States Transportation Command USTRANSCOM United States Transportation Command WAR Weekly Activity Report

SECTION X

10.0 APPENDIX B

10.1 Government Furnished Equipment.

GFE listing to be provided with RFQ.

File details come from the government source that posted it. Updated .