2025.12.08_COF_PWS_Draft.docx

DOCX document 462 KB Posted

Attached to
RFI - CYBERSPACE OPERATIONS FORCES AND SUPPORT (COF) II Federal contract opportunity
Solicitation number
TRANSCOM26D001
Issued by
Department of Defense United States Transportation Command

About this file

This document is a Performance Work Statement (PWS) for Cyberspace Operations Forces and Support (COF) for the United States Transportation Command (USTRANSCOM), covering cybersecurity services from August 2026 through September 2031. The contract requires comprehensive cybersecurity defense for the USTRANSCOM enterprise, encompassing Security Operations Management for on-premises and cloud environments, including DevSecOps ecosystems. Key activities include cybersecurity boundary defense, infrastructure support, intrusion detection monitoring, incident management, cyber threat analysis, security tool suite administration, forensic analysis, and continuous improvement and optimization.

The PWS is structured across three primary task areas: Contract Level and Contract Management Requirements, Cyberspace Operations Support, and Cybersecurity Service Provider (CSSP) Operations Management Support. The contract mandates 24/7 support, with specific requirements for intrusion detection, threat analysis, incident response, and cybersecurity tool administration. The contractor will be responsible for protecting against, defending, and responding to suspicious or malicious cyber activity across USTRANSCOM's enterprise, utilizing managed services best practices to deliver responsive IT services. The contract includes a transition period in August 2026, a base period from September 2026 to September 2027, and four potential option periods extending through September 2031, with estimated annual workload spanning approximately 100,000 labor hours across various cybersecurity and operational support tasks.

View the file

Other files for this federal contract opportunity

Other files attached to RFI - CYBERSPACE OPERATIONS FORCES AND SUPPORT (COF) II, newest first.
File Type Posted
2025.12.09 COF_RFI Amend 001.pdf PDF
2025.12.09_COF_PWS_Draft.docx DOCX document
2025.12.08 COF_RFI.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

PERFORMANCE WORK STATEMENT FOR

CYBERSPACE OPERATIONS FORCES AND SUPPORT (COF)

In Support of the United States Transportation Command TASK ORDER HTC711

08 December 2025

Prepared by

UNITED STATES TRANSPORTATION COMMAND

DIRECTORATE OF COMMAND, CONTROL, COMMUNICATIONS & CYBER SYSTEMS

Table of Contents

1.Description of Services1
1.1Background1
1.2Scope1
2.Specific Tasks2
2.1Task 1: Contract Level and Contract Management Requirements2
2.2Task 2: Cyberspace Operations Support7
2.3Task 3: Cybersecurity Service Provider (CSSP) Security Operations Management Support15
3.Deliverables34
4.Service Delivery Summary (SDS)47
5.Key Personnel48
5.1Task 2: Cyberspace Operations Support50
5.2Task 3: CSSP Operations Management Support53
6.General Information59
6.1Security (Physical, Personnel, Information, Antiterrorism/Force Protection and Industrial)59
6.2Packaging, Packing and Shipping67
6.3Place of Performance67
6.4Period of Performance67
6.5Government Furnished Property (GFP)/Government-Furnished Equipment (GFE)/ Government-Furnished Information (GFI)68
6.6Handling of Non-Public Information68
6.7Cyber Security Incident Handling68
6.8Cybersecurity Incident Reporting69
6.9Cybersecurity Incident Reporting Timelines69
6.10Mandatory Reporting Data69
6.11Incident Reporting Coordination70
6.12Confidentiality and Non-Attribution Statement71
6.13Subcontracts71
6.14Malicious Code Warranty71
6.15Data Rights71
6.16Source Code Configuration Control (Versioning)72
6.17Cyberspace Workforce Management and Qualification (formerly referred to as Information Assurance Workforce Improvement Program (IAWIP))72
6.18Access to Software, Systems, Networks, Enclaves, or Technical Components73
6.19Authorization and Assessment (A&A) Support73
6.20References75
Appendix A: Estimated Workload78
Appendix B: Department of Defense (DoD) Cyber Workforce Framework (DCWF) Code Assignments80
Appendix C: Training to Tool Mapping83
Appendix D: Acronyms86
Appendix E: Operating Systems/Software/Applications Supported92
Appendix F: Protocols in Use93

List of Tables

Table 1. Deliverable Table34
Table 2. SDS47
Table 3. Position Sensitivity Requirements62
1.Description of Services
1.1Background

The United States Transportation Command (USTRANSCOM) located at Scott Air Force Base (AFB), IL, is one of 11 Unified Combatant Commands (UCC). USTRANSCOM provides command and control (C2) for the synchronized transportation, distribution, and sustainment of personnel and assets, making possible the projection and maintenance of national power wherever needed with speed and agility, high efficiency, and a high level of trust and accuracy.

The Cyberspaces Operations Forces’ (COF) mission is to provide Department of Defense Information Network (DODIN) Operations, defensive cyber operations-internal defensive measures, and overall cyberspace operations in support of USTRANSCOM information technology (IT) systems and missions. COF provides mission-tailored, joint capability packages to Combatant Commanders to facilitate the rapid establishment of Joint Force Headquarters, fulfill Global Response Force execution and bridge joint operational requirements. The COF delivers unmatched joint operational command and control enablers to Joint Force Commanders conducting emergent full spectrum operations. The Command, Control, Communications, and Cyber (C4) Systems (C4S) Directorate (J6) provides essential Command, Control, Communications, and Collaboration Support (C5S) services to the USTRANSCOM Commander in performance of the command’s mission to provide mission-tailored, joint capability packages to meet national security objectives.

USTRANSCOM COF operates in an environment which interfaces with numerous on-site and remote commercial, DoD, service, and common-user networks (i.e., Secret Internet Protocol Router Network (SIPRNet), Non-secure Internet Protocol Router Network (NIPRNet), and the Scott AFB Local Area Network (LAN), Wide Area Network (WAN) or Metropolitan Area Network (MAN)). A myriad of applications make use of the USTRANSCOM C4 infrastructure by providing access and services to the USTRANSCOM user community.

USTRANSCOM operates host/network defense infrastructure. The USTRANSCOM Cybersecurity Service Provider (CSSP) cybersecurity suite, supported by COF/TCJ6, is comprised of applications and operating systems on appliances, clients, and servers, both physical and virtual. Supported operating systems, software, and applications are listed in Appendix E: Operating Systems/Software/Applications Supported. Protocols in use are listed in Appendix F: Protocols in Use. The diversity of applications residing within USTRANSCOM network environments increases the complexity and difficulty to integrate new system requirements. The information security infrastructure operating with the USTRANSCOM CSSP cybersecurity suite is a unique integration of products demanding a high degree of technical skills and understanding.

1.2 Scope

The scope of the COF requirement is to provide cybersecurity defense for the USTRANSCOM enterprise. This will be Security Operations Management/CSSP services for on premises and cloud environments, including Development Security Operations (DevSecOps) ecosystems. The major associated activities that the contractor shall perform include: cybersecurity boundary defense; infrastructure support; intrusion detection monitoring and incident management; cyber threat analysis; security tool suite administration; cybersecurity forensic analysis; data integration, playbook generation and detection engineering for Security Orchestration, Automation, and Response (SOAR),, Security Information and Event Management (SIEM), heuristic/analytic lifecycle management, cybersecurity dashboards/visualizations development, cybersecurity data integration into common operating picture (COP), and continuous improvement and optimization.

The COF contract is responsible for protecting against, defending, and responding to suspicious or malicious cyber activity across the USTRANSCOM enterprise. The contractor shall utilize managed services best practices to perform the tasks and subtasks of this Performance Work Statement (PWS) to provide responsive IT service delivery. The required outcomes are delivering COF services to the USTRANSCOM enterprise within agreed service levels and achieving continual cybersecurity improvements to the COF services. The contractor shall be responsible for the coordination, management, resource allocation, and activity coordination to ensure the success of the entire cybersecurity service delivery process as defined in this PWS. The contactor, in concert with the Government, will establish, collect, and report metrics to evaluate and improve service delivery performance.

This contract will also cover and support execution of USTRANSCOM’s CSSP mission, defensive cyberspace operations (DCO), coordination of Cyberspace Protection Team (CPT) missions and requirements, DCO and joint planning to include development of Concepts of Operations (CONOPs) and Operational Plans (OPLANs), joint training and readiness management, spectrum management, Satellite Communications (SATCOM) mission planning, survivable SATCOM operations, senior leader airborne communications support, and tactical communications projects. The contract will require 24/7 on-site support for some COF activities.

2. Specific Tasks The contractor shall provide the knowledge, skills, abilities, staff support, and other related resources necessary to conduct the following Tasks:

Task 1: Contract Level and Contract Management Requirements Task 2: Cyberspace Operations Support Task 3: CSSP Operations Management Support

2.1 Task 1: Contract Level and Contract Management Requirements This task area consists of the functional activities relating to the administration and management of this effort. This task area specifies overarching program management for contractor tasks, personnel resources, and costs to ensure deliverables meet requirements under this PWS. The contractor shall immediately notify the Government when personnel are no longer associated with the project to ensure prompt deactivation of accounts.

The contractor shall provide all deliverables, referenced documents, contractor-generated and Government approved plans, schedules, and milestones. The contractor shall meet Government requirements and milestones. The contractor shall notify the Government, in writing, within 24 hours of the missed deadline.

The contractor shall identify a Program Manager (PM). The contractor shall designate a principal point of contact for technical issues. The PM is the authorized point of contact with the Government Contracting Officer’s Representative (COR). Responsibilities include, but are not limited to, interfacing with Government management personnel, staffing of all tasks, formulating and enforcing work standards, assigning schedules, reviewing work discrepancies, and communicating policies, purposes, and goals of the organization to subordinates.

All decisions regarding Government requirements or Government actions shall be made by Government personnel. The contractor’s representative shall submit evaluations, recommendations, and contract deliverables., to the COR and/or Contracting Officer (CO) for action.

2.1.1 Task 1 Subtask 1: Contract Management Plan

The contractor shall submit a Contract Management Plan within fifteen (15) business days of contract award. The Government will review the plan and provide comments to the contractor within five (5) business days from receipt of the updated Contract Management Plan. The contractor shall have five (5) business days from receipt of the Government’s comments to submit the final plan. The contractor shall update the plan each option year within fifteen (15) business days after the option year is exercised.

2.1.2 Task 1 Subtask 2: Monthly Status Report

The contractor shall provide a Monthly Status Report (MSR) no later than the 15th of the month following the reporting period. In conjunction with the contract end date, the contractor shall submit a final MSR no later than the last business day of the final period of performance.

At a minimum, the MSR shall include the following information:

A list of the accomplishments, projects/assignments, and identified shortfalls/gaps for the reporting period by each active task area.

A synopsis of the efforts completed; deliverables provided; conferences and meetings attended; and trips conducted during the reporting period. The MSR shall include a spending “burn down” financial graph showing funds expended to date and funds remaining against the budgeted amount. The format of the financial chart(s) shall be as agreed between the contractor and the Government.

An overall evaluation of the contract to date, listing per task any issues, problem areas, missed deadlines, problem causes/resolutions and items that require Government action.

Delivery schedule for each project/initiative with breakdown of hours expended.

Ad-hoc Government Requested Metrics.

Staffing status, to include projected vacancies, current vacancies, and efforts towards filling vacant positions.

Cyberspace Workforce certification status of personnel aligned to task(s) being supported, to include basic, specialty and computing environment certifications and associated expiration dates.

Monthly accounting of changes to cybersecurity tool suites performed in the delivery of Task 3, CSSP Operations Management Support activities (e.g., rule/policy modifications implemented, hardware and software updates completed, analytics and visualizations created/updated) Monthly up-time statistics based on service availability for all cybersecurity tool suites utilized in the delivery of Task 3, CSSP Operations Management Support (e.g., firewalls, proxy services, EDR, EPP, WAF, SIEM, SOAR, NIDS, and network securing monitoring services) derived from service assurance monitoring Consolidated list of all monthly on call activity for Task 3. Report shall include time notified, time tech arrived on station, and time issue was resolved. If tech was able to resolve the issue without reporting on station, include only time notified and time resolved Monthly audit report of all privileged accounts on the cybersecurity defense tools and devices Number and type of countermeasures implemented in the delivery of Task 3, CSSP Operations Management Support activities in response to confirmed suspicious / malicious activity or intrusion (e.g., CYBERCOM/DCDC Orders) Consolidated report containing the number of compatible devices with all applicable endpoint modules installed, missing or non-functional Number and description of analytics developed in the delivery of Task 3 Subtask 3.5, Cybersecurity Analytic and Orchestration Development activities Cybersecurity Detection Summary Report identified in Task 3 Subtask 3.6, Cybersecurity Detection Engineering

2.1.3 Task 1 Subtask 3: In-Process Review

The contractor shall conduct quarterly In-Process Reviews (IPRs) as scheduled by the Government. The IPR shall summarize status, progress, recommendations, and concerns in the development of any tasks or documentation described within this PWS. Initial quarterly IPR presentation material provided five (5) business days prior to IPR meeting. Final presentation materials shall be prepared and provided to the COR and the CO two (2) business days prior to the IPR.

2.1.4 Task 1 Subtask 4: Travel

Performance under this contract may require contractor travel within and outside the Continental United States. The Government will reimburse the contractor for travel expenses subject to the Federal Acquisition Regulation (FAR) and the Joint Travel Regulation (JTR). All contractor travel shall be coordinated with and validated by the primary or alternate COR prior to incurring any travel expenses. The contractor shall identify personnel who will be traveling in sufficient time to obtain the lowest possible rates for airfare, rental car, and lodging. For long-distance travel, a minimum of five (5) business days advance notice from the travel commencement date is required. The travel request shall be in writing and contain the dates, location, and estimated travel costs. Contractor invoices (along with associated receipts) shall support all travel reimbursement requests.

2.1.5 Task 1 Subtask 5: Trip Reports

Within five (5) business days of completion of any travel, the contractor shall submit a trip report to include the following details: purpose, location, trip duration, travelers, and travel costs.

2.1.6 Task 1 Subtask 6: Meeting / Conference Minutes

The contractor shall attend meetings or conferences held at USTRANSCOM or other locations as identified by the Government and provide meeting/conference minutes which detail the results as well as the impact of the meeting/conference within three (3) business days after completion of the meeting/conference. Meetings/Conferences will generally take place during normal duty hours.

2.1.7 Task 1 Subtask 7: Personnel Status Report

The contractor shall provide a personnel status report containing names and labor categories and task alignment and Cyberspace Workforce certifications (reference Appendix B) of personnel supporting each major task. The contractor shall provide the report within twenty (20) business days of the contract start date and update the report within five (5) business days of any changes in personnel. The Contractor shall make every reasonable attempt to fill any vacancy of a position described in the Technical and Management Work Plan in a period no longer than a single billing cycle.

2.1.8 Task 1 Subtask 8: Non-Disclosure Agreement (NDA) for Contractor Employees and Company to Company Agreements Due to the sensitive nature of the data and information contractor personnel have access to, the contractor shall provide signed Nondisclosure and Conflict of Interest Agreements for all contractor personnel who perform any work under this contract to ensure contractor personnel do not compromise sensitive or proprietary information. The contractor shall provide a signed NDA for all personnel assigned to this contract. The contractor shall not grant their personnel access to COF information technology or supporting information before the signed NDA is accepted by the COR. The Government will retain these documents. See Appendix G, Nondisclosure and Conflict of Interest Agreements. The contractor shall also be required to sign a non-disclosure agreement in accordance with (IAW) Department of Defense Federal Acquisition Regulation Supplement (DFARS) 227.7103-7 if there is access to technical data or computer software delivered to the Government with restrictions as described in DFARS 227.7103-7. Before obtaining access to another contractor’s proprietary information, IAW FAR 9.505-4, the contractor must agree with the other company to protect the information, complete necessary agreements, and furnish such agreements to the Contracting Officer.

In addition to working with the Government, the Contractor will be required to work with other contractors in support of the TRANSCOM mission. The Contractor may gain access to proprietary information of other companies during contract performance. The Contractor agrees to enter into company-to-company agreements to: (1) protect another company's information from unauthorized use or disclosure for as long as it is considered proprietary by the other company; and (2) to refrain from using the information for any purpose other than that for which it was furnished. For information purposes, the Contractor shall furnish copies of these agreements to the contracting officer. These agreements are not intended to protect information which is available to the Government or to the Contractor from other sources and are furnished voluntarily without restriction.

2.1.9 Task 1 Subtask 9: Transition-In Plan

For the first 30 calendar days, the incoming contractor personnel will be provided with transitional training, i.e., will work side-by-side with or shadow the outgoing contractor on the local processes and procedures for performance of day-to-day duties, specifically deliverables. This effort is not functional in nature but is to familiarize the incoming contractor with the USTRANSCOM work environment as it relates to the requirements of the PWS. The overall goal of the transition period is to ensure uninterrupted support and seamless transfer of responsibilities to the incoming contractor team(s). Management of the overlap between contracts is a government function, and guidance will be issued providing direction and clarification of each contractor's responsibilities within the scope of their respective contracts.

This is the minimum essential task for the incoming contractor; nothing within this task limits the responsibility of the contractor to fully execute the contract from the date scheduled for full performance beginning 30 calendar days after contract start.

2.1.10 Task 1 Subtask 10: Transition-Out Plan

The contractor shall provide a phased transition plan, to be executed if the follow-on contract is awarded to another prime contractor(s). The plan's level of detail must be sufficient for each of the parties to understand and execute; the parties are the Government, the incumbent contractor, and the contractor(s) awarded the follow-on contract. The overall goal of the transition plan is to ensure uninterrupted support to USTRANSCOM and seamless transfer of responsibilities to the incoming contractor team(s). Management of the overlap between contracts is a government function, and guidance will be issued providing direction and clarification of each contractor's responsibilities within the scope of their respective contract. The contractor will ensure Task Continuity Folders (Task 4) are updated and available for review thirty (30) calendar days prior to period of performance expiration.

The transition plan should address the tasks in the PWS. The transition plan shall consist of two parts: transition-in and transition-out. The transition-in commences upon commencement of performance by a follow-on contractor and concludes when the incoming contractor team(s) is ready to assume responsibility for tasks and deliverables. Contract close-out requirements shall be executed by the outgoing contractor during the transition-out.

The incumbent contractor will provide a transition out plan that includes: 1) in-brief for Government and incoming contractor team management; 2) orientation for new contractor personnel; 3) training to incoming contractor personnel on standing COF procedures and use of specific information system applications; 4) transfer of Government property; 5) implementation of subcontractor arrangements; 6) exchange of program-related corporate knowledge; 7) establishment of memoranda of agreements and nondisclosure agreements as required; 8) administrative and logistic requirements (e.g. personnel in- processing, applying for Common Access Card and government system accounts, etc.).

2.1.11 Task 1 Subtask 11: Service Contractor Manpower Report

The contractor shall report in the System for Award Management (SAM): 1) the total dollar amount invoiced for services performed during the previous Government fiscal year under the contract; 2) the prime contractor direct labor hours expended on the services performed during the previous Government fiscal year; and 3) if applicable Tier 1 subcontract number, including Unique Entity Identifier (UEI) and name, and the number of subcontractor direct labor hours expended under the contract. Reporting inputs will be for the labor executed during the period of performance during each Government fiscal year (FY), which runs from October 1 through September 30. The billing cycle for this contract will be monthly, (first calendar day of each month through the last calendar day of that month).

2.1.12 Task 1 Subtask 12: Incident Management

The contractor shall use the Government provided incident handling trouble ticket systems for all trouble tickets, technical issues, and/or service delivery actions.

2.1.13 Task 1 Subtask 13: Mission-Essential Contractor Services Plan The contractor shall provide a plan for Mission-Essential Contractor Services. The plan shall include provisions for providing split operational, as described below, support of tasks during exercises and contingencies. The contractor’s plan shall specify required mission essential services and plan to support per the Government’s approval. If any personnel changes or contract modification occurs that impact the Mission-Essential Plan, a revised plan is due within thirty (30) business days.

The Government functional(s) has identified all or a portion of the services performed under this contract as “Emergency-Essential” as defined and described in DoD Instruction (DODI) 1100.22, “Policy and Procedures for Determining Workforce Mix.” Hereafter, the personnel identified by the contractor to perform these services shall be referred to as “Mission Essential Contractor Personnel.” Requirements affecting contractor personnel performing mission essential services apply to personnel supporting Task Area 2 (Subtasks 1, 4,5, and 6) and Task Area 3 (Subtasks 4.2 and 4.3) during contingencies, emergencies, and/or exercises.

Within 20 business days after contract start, the contractor shall provide a written list of all “Mission Essential Contractor Personnel” to the government functional(s) or designee. The list shall identify individual employee names and their work locations under this contract.

The government functional(s), as required to comply with or perform pursuant to DoD requirements, shall direct the contractor to comply with requirements intended to safeguard the safety and health of Mission Essential Contractor Personnel. The contracting office may communicate the requirements through a letter of notification or other means and subsequently modify the contract to incorporate new requirements as needed.

2.1.14 Task 1 Subtask 14: Equipment Custodian Duties

The contractor shall perform Equipment Custodian (EC) duties within their area of responsibility and maintain proper accountability of all Government owned/purchased hardware IAW United States Transportation Command Instruction (USTCI) 6900.01 Policy for Management of Information Technology Hardware, Software, and required Non-Information Technology Assets and Department of the Air Force Manual (DAFMAN) 17-1203, Information Technology (IT) Asset Management (ITAM), as well as maintain inventory information for all warranty and maintenance contracts. The contractor shall provide inventory information to the Government IAW with USTCI 6900.01, annually or within thirty (30) business days from EC change.

2.2 Task 2: Cyberspace Operations Support

The contractor shall provide support for USTRANSCOM's Cyberspace Operations to include CPT operations, cyberspace operations planning, joint training and readiness management, spectrum management, SATCOM mission planning, survivable SATCOM operations, senior leader airborne communications support, and tactical communications projects.

Support for this task shall be provided during the duty hours listed in paragraph 6.2.

The contractor shall support all sub-tasks using the Government provided automated software tools, when applicable, and IAW the suspense assigned by the Government or through the Government staffing process. The Government estimates up to forty (40) trips annually in support of this task.

2.2.1 Task 2 Subtask 1: Cyberspace Operations Support

The contractor shall support the planning and execution of C4S and Cyberspace Operations IAW command guidance, and current operations timelines, all phases of the Joint Planning Process (JPP) to ensure the incorporation of USTRANSCOM C4S and Cyberspace Operations equities. This support shall include:

Supporting USTRANSCOM orders process by:

Developing draft Cyberspace Operations orders on behalf of government representative Reviewing, commenting on, and coordinating USTRANSCOM orders IAW TCJ6-OC-led orders process Originating and coordinating orders for DODIN Cyber Defense Command (DCDC) release in support of USTRANSCOM’s mission thread analysis Advising on integration of DCO and CPT capabilities to manage/mitigate operational risk resulting from cyberspace threats and vulnerabilities.

Maintaining knowledge and awareness of future joint Cyberspace Operations development efforts/initiatives (for example, Joint All Domain Command and Control (JADC2), Joint Cyber Command and Control (JCC2), and Joint Cyber Warfighting Architecture (JCWA))

1. Ability to support four (4) concurrent USTRANSCOM joint planning efforts per quarter Maintaining knowledge of and advising government functionals on current National and DoD cyber policy, doctrine, guidance, instructions, and orders

· Assisting with writing of USTRANSCOM policy, doctrine, operating techniques, methodology, and procedures for Cyberspace Operations and C4S security, survivability, sustainability, interoperability, and readiness across the Joint Deployment and Distribution Enterprise (JDDE)

· Assisting government representatives with analyzing, writing, and maintaining C4S (Annex K) and Cyberspace Operations (Appendix 16, Annex C) portions of Campaign, Contingency, and Operations Plans IAW prescribed Adaptive Planning and Execution (APEX) formats and JP 5-0 Joint Planning doctrine

· Attending relevant BRE, planning conferences, briefings, and planning teams/groups and providing written minutes on C4S and Cyberspace Operations relevant tasks and/or guidance

· As directed, coordinating with USTRANSCOM planning stakeholders and authors

· Accomplishing TCJ6 assigned joint planning tasks during real world and exercise/training events

· Assist in critical Cyberspace Operations planning:

Through the Cyberspace Operations Integrated Planning Element (CO-IPE) coordinate cyber requirements across multiple DoDIN Areas of Operation (DAO) supporting USTRANSCOM’s operational mission.

Identify system DAO Commanders Identify TRANSCOM Sector cyber operation requirements Originate and coordinate orders for DODIN Cyber Defense Command (DCDC) release Supporting development of USTRANSCOM and TCJ6 strategy documents Recommending and advising on objectives for USTRANSCOM Cyber and C4S strategies Developing supporting tasks and identifying appropriate Office of Primary Responsibility (OPRs) and Office of Coordinating Responsibility (OCRs) Assisting with development of and reporting against strategic assessment metrics Ability to support up to six (6) concurrent CPT operations Facilitating implementation/execution of the USTRANSCOM CPT mission coordination lifecycle from initial nomination to post-mission reporting Developing and maintaining templates and process documentation for the USTRANSCOM CPT mission coordination lifecycle Utilizing approved templates and in coordination with (ICW) the CO-IPE, Prepare CPT mission nominations Draft and coordinate CPT tasking orders, mission plans, and rules of engagement Reporting mission status to internal/external stakeholders via government provided systems/portals IAW mission guidelines and applicable policies Maintaining and validating records/requests and all supporting documents for CPT account creation Tracking CPT account status Identifying and coordinating actions to resolve issues with CPT accounts or access to USTRANSCOM systems and networks Maintaining records of program and system owner responses to mission findings as documented in CPT-produced mission reports and out briefs by Correlating mission findings with security processes/policies Coordinating findings with all applicable program and system owners Receiving and tracking program/system Plans of Action and Milestones (POA&Ms) Monitoring/reporting on mitigation/resolution actions Assisting with identification and implementation of process improvement initiatives Identifying shortfalls/gaps in CPT capability or capacity and ICW CO-IPE, recommend and develop requests for support/direct support IAW Global Force Management processes Advising TCJ6 on impacts/concerns of DoD-wide Defensive Cyberspace Forces resourcing and alignment decisions

2.2.2 Task 2 Subtask 2: Cyber Discovery

The contractor shall be responsible for analyzing, developing, and mapping key dependencies of USTRANSCOM operations. This support shall include:

Developing DCO CONOPs aligning cyberspace domain mission assurance requirements Advising on integration of DCO and CPT capabilities to manage/mitigate operational risk resulting from cyberspace threats and vulnerabilities.

Maintaining knowledge of and advising on current National and DoD cyber policy, doctrine, guidance, instructions, and orders Assisting with writing of USTRANSCOM policy, doctrine, operating techniques, methodology, and procedures for Cyberspace Operations and C4S security, survivability, sustainability, interoperability, and readiness across the JDDE Assisting government representatives with analyzing, writing, and maintaining C4S (Annex K) and Cyberspace Operations (Appendix 16, Annex C) portions of Campaign, Contingency, and Operations Plans IAW prescribed APEX formats and JP 5-0 Joint Planning doctrine Attending relevant BRE, planning conferences, briefings, and planning teams/groups and providing written minutes on C4S and Cyberspace Operations relevant tasks and/or guidance As directed, coordinating with USTRANSCOM planning stakeholders and authors Accomplishing TCJ6 assigned joint planning tasks during real world and exercise/training events

· Assist in critical Cyberspace Operations planning:

Develop Mission Relevant Terrain-Cyber (MRT-C) and Key Terrain-Cyber (KT-C) analysis Facilitating production of a critical asset list /defended asset list (CAL/DAL) based on identified MRT-C and KT-C Identifying gaps and seams in MRT-C and KT-C Coordinate development of Asset Defense Plans (ADPs) and Operational Risk Assessment (ORAs) Develop, maintain, and analyze USTRANSCOM’s mission thread analysis for application into cyber operations Coordinate Requests for Support (RFS) through CO-IPE. Establish priorities IAW USCYBERCOM guidance and communicate emergent requirements with desired cyber effects Identify system DAO Commanders Identify TRANSCOM Sector cyber operation requirements Originate and coordinate orders for DODIN Cyber Defense Command (DCDC) release Advising TCJ6 on impacts/concerns of DoD-wide Defensive Cyberspace Forces resourcing and alignment decisions Map MRT-C and include in functional and operational plans as part of Task Critical Asset (TCA) review Draft and maintain the MRT-C systems spreadsheet and Critical Asset List to use in Battle Rhythm events to share MRT-C status with other directorates, CJCS, DOD, CCMD, component commands and associated Major Commands Decompose missions and identify essential capabilities and supporting assets associated with Mission Relevant Terrain in Cyberspace Work with appropriate asset owners to ensure Mission Assurance Assessment compiled cyber inventories are maintained, updated, and reflected in MRT-C submissions to the Mission Assurance Decision Support System (MADSS).

Monitor the accuracy of data in the Mission Assurance system of record for related, validated Tier 1 and Tier 2 Task Critical Assets and associated Baseline Elements of Information Execute the Manage Operational Risk – Cyber (MOR-C) process to identify, assess, and manage cyberspace risk in a manner that can be synchronized with other identified risk management activities equally, to produce a holistic risk to mission and force assessment Establish and maintain geographic combatant command cyberspace operations alignment Understand USTRANSCOM’s operational mission requirements respective to the geographic command’s requirements for cyberspace coordination Understand geographic command’s operational requirements for USTRANSCOM’s and their cyberspace implications

2.2.3 Task 2 Subtask 3: Support to Joint Exercise Planning

The contractor shall be responsible for analyzing, developing, and planning C4S and Cyberspace Operations support to meet Directorate-approved training objectives and exercise requirements. This support shall include:

Developing exercise plans and participating in exercise planning events for up to up to two (2) Tier 1 Combatant Command (CCMD) exercises and three (3) Command Post/Tabletop Exercises per fiscal year Support up to two (2) wargaming events to include development of scenarios, identification of resources, and collaboration with modeling teams Preparing and maintaining a comprehensive Cyberspace Operations exercise planning schedule that identifies all exercise/training events utilizing USTRANSCOM C4S and Cyberspace Operations resources Serving as interface between USTRANSCOM Operations and Plans Directorate (TCJ3), TCJ6, CO- IPE and Transportation Component Command (TCC) personnel to ensure proper planning for C4S and Cyberspace Operations resources Recommending options for and assisting with resolution of exercise and resource conflicts Serving as Directorate focal point for developing, consolidating, and coordinating TCJ6 exercise/training objectives Building Cyberspace Operations Master Scenario Events List (MSEL) and entering MSELs into applicable GFE databases and portals for Chairman Joint Chiefs of Staff (CJCS), CCMD, and USTRANSCOM exercises Assisting with designing, planning, coordinating, and integrating cyber effects into exercises to achieve the command’s training objectives Identifying requirements for and coordinating/scheduling exercise observers and evaluators Facilitating design of a TCJ6 Cybersecurity Assessment Program (CAP) Developing Cyber Readiness Campaign activities to meet CAP objectives Completing and coordinating required CAP documentation to include production of an annual Cybersecurity Assessment Master Plan (CAMP) Developing and coordinating requests for exercise enabling activities to include Red Teams and cyber threat emulation Preparing and staffing support agreements Documenting rules of engagements Facilitating planning and working sessions with appropriate stakeholders Preparing the TCJ6 Monthly Mission Training Assessment Report, Joint Training Update Brief, Joint Monthly Readiness Report (JMRR) and quarterly Joint Forces Readiness Report (JFRR) Performing an annual update of the Joint Mission Essential Task List (JMETL) Managing the TCJ6 Joint Mission Essential Tasks (JMETs) Overseeing the monthly and quarterly JMET assessments Providing guidance and training to Directorate assessors on the Defense Readiness Reporting System (DRRS) and Joint Training Tool (JTT) Evaluating the C4S and Cyberspace Operations portion of the Command’s readiness reports to determine sufficiency and accuracy of provided information Compiling the data into meaningful readiness indicators Recommending JMET updates/changes and assessment criteria Assisting with preparation for USTRANSCOM joint training meetings and completing any action items and after-action reports as necessary Develop the TCJ6 Joint Training Plan Serving as the TCJ6 Lessons Manager (LM) Managing the USTRANSCOM TCJ6 Joint Lessons Learned Program (JLLP) Providing lessons learned inputs to the USTRANSCOM Joint Lesson Manager, IAW USTCI 3100.01 , after contingency, exercise, and training events.

2.2.4 Task 2 Subtask 4: Communications Spectrum Management

The contractor shall be responsible for supporting all functions of Spectrum Management within USTRANSCOM. This support shall include:

Serving as the USTRANSCOM Point of Contact (POC) for all radio frequency (RF) spectrum related matters Identifying, documenting, and coordinating on RF spectrum resource requirements supporting USTRANSCOM's worldwide missions Submitting frequency-spectrum resource requests IAW mission requirements Reviewing and developing spectrum management portions of operational and exercise plans Interfacing with CCMD/Service/Agency (CC/S/A) representatives to ensure adequacy of spectrum management support for contingency, crisis response, and exercise plans Coordinating with the Joint Chiefs of Staff (JCS), Military Communications-Electronics Board (MCEB), Joint Spectrum Center (JSC), Service’s Spectrum Management Offices, participating Combatant Commander Staffs, and TCCs on spectrum problems that arise during exercises and contingencies Assisting with the development of command-specific policy and guidance for use of the electromagnetic spectrum Advising on the implementation of new, spectrum-efficient technologies for their use in support of the command’s spectrum requirements Performing monthly assessments of spectrum related JMETs Providing technical advice for all spectrum/wireless communications issues Collaborate with USTRANSCOM J39 regarding Electronic Warfare (EW)/Electronic Attack (EA) in support of operations Maintain situational awareness of spectrum interference impacting USTRANSCOM operations

2.2.5 Task 2 Subtask 5: SATCOM Management and Planning

The contractor shall be responsible for supporting all aspects of SATCOM management and planning. This support shall include:

Serving as the USTRANSCOM POC for all SATCOM programs and requirements Reviewing and developing SATCOM portions of operational and exercise plans Providing SATCOM planning support to worldwide USTRANSCOM and TCC end-users for narrowband, wideband, protected, and commercial capabilities Validating all USTRANSCOM-related SATCOM requests, to include satellite and gateway access Maintaining monthly metrics on the number and timeliness of satellite/gateway requests processed, and provide to the Government two (2) business days prior to presentation Arranging, monitoring, and supporting USTRANSCOM SATCOM operations during training, exercise, and contingency/crisis events from pre‐ deployment through execution to termination, supporting USTRANSCOM Command Centers (including alternate sites), and deployed forces Assisting with resolving problems encountered in planning or operating SATCOM terminals Maintaining and supporting USTRANSCOM's and TCC’s satellite database entries Guiding potential users through identification of command‐wide SATCOM requirements and assisting USTRANSCOM in justifying and defending these requirements to the Joint Staff and in validating the command Integrated Communications Database (ICDB) Performing customer interviews and site surveys for any changes to existing SATCOM systems Providing technical assistance with the installation, implementation, configuration, integration, and status of USTRANSCOM SATCOM systems Coordinating with and ensuring each site is prepared to accept delivery of SATCOM hardware Assessing the impact of different SATCOM designs at USTRANSCOM sites Participating in acceptance testing and tracking of maintenance requirements Identifying single points of failure to include recommendation of changes to prevent isolation of SATCOM systems At a minimum, conducting annual technical evaluations of SATCOM to ensure proper interoperability/integration with current and future C2 systems and networks Identifying and documenting hardware/software deficiencies and their impact on operability and security.

Preparing appropriate briefs, information papers, and requirement documents necessary to assess, implement, install, and monitor terminal facilities and supporting systems Notifying IT Operations Management within one (1) hour of any negative impacts to operational status Performing monthly assessments of SATCOM related JMETs Reviewing/recommending, planning, policy development, technical integration and interoperability, implementation, installation, and life-cycle support for tactical C4S Assisting with planning, organizing, developing, and implementing all elements of assigned projects Assisting in ensuring that all projects conform to current DoD guidelines and standards.

2.2.6 Task 2 Subtask 6: Survivable Satellite Communications Terminal Operations and Management The contractor shall be responsible for serving as focal point for communications systems supporting USTRANSCOM’s Emergency Actions Cell (EAC), and its Nuclear Command, Control, and Communications (NC3) functions. This shall include:

Monitoring the status and coordinating operational availability of current and future systems required to fulfill approved EAC communications requirements, to include SATCOM terminals, associated applications, databases, and circuits.

Operating and maintaining government provided survivable communications terminals and associated equipment supporting USTRANSCOM primary and alternate operating facilities.

In coordination with support organizations and system program offices, coordinating restoration of EAC NC3 systems utilizing established Functional Area Communications and Computer Systems Manager (FACCSM), Help Desk, and trouble ticket services and processes.

Producing terminal outage/restoral messages IAW current DoD guidance and sending to required USTRANSCOM IT Operations Management within two (2) hours of awareness of outage/restoral.

Coordinating scheduled system outages through Authorized Service Interruptions (ASIs) process to gain approval from USTRANSCOM and AMC emergency action personnel.

When directed by the EAC or Govt Functional Lead, provide:

24-hour on-call support and 2-hour response time for system outage response/reporting 24-hour operations and maintenance support at primary and alternate USTRANSCOM operating locations When required by the Government, providing hardware user orientation, initial hands-on and back-up operational training for survivable SATCOM terminal equipment for up to six personnel per year.

Supporting communications security (COMSEC) requirements, maintenance and operating activities ICW the USTRANSCOM COMSEC Office and EAC for NC3 systems and equipment in building 1900W, USTRANSCOM Alternate Operating Facilities, and buildings 750/751.

As required, attending survivable satellite communications mission planning and operations training courses. These classified training courses are not commercially available. USTRANSCOM will coordinate attendance and if required fund travel via the contract for initial attendance at the course. If contractor personnel resign or are removed from the contract, costs of training replacement contractor personnel shall be the responsibility of the contractor.

Participating in planning events for system upgrades, enhancements, or augmentation affecting the survivable satellite communications functionality.

As required, participating in on and off-site working NC3 and SATCOM groups and forums to ensure USTRANSCOM NC3 and SATCOM equities are incorporated in DoD-wide activities.

In accordance with USSTRATCOM Service Level Agreement perform local Information Systems Security Manager (ISSM) and/or Information System Security Officer (ISSO) responsibilities.

2.2.7 Task 2 Subtask 7: Airborne Communications Task Management The contractor shall coordinate with Air Mobility Command Senior Leader Command, Control and Communications System (SLC3S) staff personnel. This shall include:

Developing, advocating for, and defending Integrated Priority List (IPL) nomination packages As required, supporting the biennial SLC3S Interim Program Review (IPR) updates to USTRANSCOM Commander (TCCC) by scheduling the IPR with senior USTRANSCOM staff members and distributing read-ahead material to all participants, IAW with Government staffing process Reviewing and providing comments on system specifications, safety, and Operational Test Evaluations (OT&E) requirements IAW Government suspense.

2.2.7 Task 2 Subtask 7: Contingency, Emergency, and Exercise Operations Support During operation of the C4 systems that support USTRANSCOM there may be instances where the Government will increase the level of support due to contingency, emergency, or exercise operations. When increased levels of operation are forecast, the COR will notify the contractor, in writing, ten (10) business days prior to the change. During contingency operations, the Government may require 24-hour continuous C4S support for the USTRANSCOM Global Operations Center, the COR will notify the contractor, in writing, a minimum of 24 hours prior to the need of support. In the event of an unforeseen contingency or emergency, the Government may notify the contractor verbally, to be followed up in writing. Notification will include the identification and scope of the contingency, emergency, or exercise. Extended support shall be activated within 24 hours after notification by the Government unless otherwise specified. The Government may extend the on-site hours during contingencies, emergencies, or exercise to 24-hour operations.

The Government estimates up to seven (7) contingency/emergency/exercise periods per year. The Government will calculate the Firm Fixed Price cost per instance IAW the table below utilizing the labor categories and rates incorporated in the contract for Task 2 Subtasks 1-10.

Exercise
Contingency/Emergency

Task 2 Add'l Hours / day

# of Days Hours Per Instance Add'l Hours / day

# of Days Hours Per Instance

Subtask 1: Cyberspace Operations Support
2
10
20
4
12
48
Subtask 2: Cyber Discovery
2
10
20
2
12
24
Subtask 3: Support to Joint Exercise Planning
2
10
20
0
0
0
Subtask 4: Communications Spectrum Management
2
10
20
1
12
12
Subtask 5: SATCOM Management and Planning
2
10
20
2
12
24
Subtask 6: Survivable SATCOM Terminal O&M
2
10
20
1
12
12

* The Government anticipates (2) Exercise Instances per year and up to (5) Contingency/Emergency Instances Per year

2.3 Task 3: CSSP Operations Management Support

The contractor shall act as subject matter experts (SME) for CSSP associated activities. The contractor shall perform cybersecurity boundary defense; infrastructure support; intrusion detection monitoring and incident management; cyber threat analysis; security solution administration; detection and analysis; cybersecurity forensic analysis; and continuous improvement and optimization.

In this capacity, the contractor shall attend meetings or conferences held at USTRANSCOM and/or other locations as identified by the Government and provide written meeting/conference minutes unless otherwise exempted by the Government.

The contractor shall maintain and enhance the USTRANSCOM CSSP Operations Management using Government-furnished security mechanisms and equipment located at Scott AFB, IL; USTRANSCOM Commercial/Government Cloud Environments; Joint Enabling Capabilities Command (JECC) — Norfolk, VA; Radford, VA; Joint Communications Support Element (JCSE) — McDill AFB, FL; USTRANSCOM component and support locations; and undisclosed alternate facilities. The contractor shall configure, maintain, and enhance Government- furnished security mechanisms hosted on premises and in cloud service provider environments.

The contractor shall support the CSSP in maintaining plans and procedures to augment existing personnel to surge operations in response to major incidents. Surge conditions could last for up to 14 business days or longer depending on the circumstances.

The contractor shall perform all work IAW all applicable laws (e.g., Executive Order 14028, Strengthening the Cybersecurity of Federal Networks and Critical Infrastructure; Clinger Cohen Act (CCA)); regulations and national standards (e.g., National Institute of Standards and Technology (NIST)); DoD, Defense Information Systems Agency (DISA), National Security Agency (NSA), United States Cyber Command (USCYBERCOM), and USTRANSCOM standards and instructions; and commercial best practices.

The contractor personnel supporting Task 3 shall be authorized to telework in the event of inclement weather, health concerns, or additional specific events approved by the CSSP Government staff. All telework activities must be conducted through government provided Virtual Private Network (VPN).

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .