20R0106 Draft PWS.docx
DOCX document 207 KB Posted
- Attached to
- Tactical Integrated Threat/Target Training Systems (TTS) Federal contract opportunity
- Solicitation number
- N6893620R0106
About this file
This document provides details regarding a pre-solicitation notice for a multiple award contract to provide Tactical Integrated Threat/Target Training Systems support services. The Naval Air Warfare Center Weapons Division intends to award firm fixed price and cost plus fixed fee task orders over five years, with an estimated level of effort of 615,574 hours. Services include sustainment, maintenance, upgrade, and development of air, electronic warfare, and instrumentation training systems and software. The solicitation is expected to be posted on November 9, 2020 on sam.gov for a minimum of 30 days. Questions must be submitted in writing by the specified date. Offerors must be registered in SAM and certified through DLIS to access controlled unclassified information on beta.sam.gov. The applicable NAICS code is 541330 and proposals will be evaluated on best value.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Draft PWS Comments and Responses.xlsx | XLSX spreadsheet |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DRAFT
PERFORMANCE WORK STATEMENT (PWS)
FOR
SUSTAINMENT, UPGRADE, AND DEVELOPMENT
OF
TACTICAL INTEGRATED THREAT/TARGET TRAINING SYSTEMS (TTS)
NAVAL AIR WARFARE CENTER WEAPONS DIVISION
CHINA LAKE, CALIFORNIA
INTEGRATED MOBILE AND THREAT SYSTEMS DIVISION
CODE DB44000
DISTRIBUTION STATEMENT D. Distribution authorized to the Department of Defense and U.S. DoD contractors only (Export Controlled Data) (06 August 2020). Other requests shall be referred to NAWCWD Code DB44P00, China Lake, CA 93555-6100
3/13/2020
TACTICAL INTEGRATED THREAT/TARGET TRAINING SYSTEMS (TTS)
MULTIPLE AWARD CONTRACT (MAC)
SOLICITATION N6893620R0106
“WARNING – this document contains technical data whose export is restricted by the Arms Export Control Act (Title 22, U.S.C., Sec 2751, et seq.) or the Export Administration Act of 1979 (Title 50, U.S.C., App. 2401 et seq.), as amended. Violations of these export laws are subject to severe criminal penalties. Disseminate in accordance with provisions of DoD Directive 5230.25.”
CONTENTS
| 1.0 | PURPOSE | 3 |
| 1.1 | Background | 3 |
| 1.2 | General Scope | 3 |
| 2.0 | APPLICABLE DOCUMENTS | 3 |
| 2.1 | Information Technology (IT) | 4 |
| 2.2 | Clinger-Cohen Act (CCA) | 4 |
| 2.3 | System Software/Application Compliance | 5 |
| 2.4 | Websites, Web Enablement and Application/System Development, Modification, and Maintenance Support Services | 5 |
| 2.5 | Software Development/Server Procurement | 6 |
| 2.6 | Cybersecurity | 6 |
| 2.7 | Enterprise Architecture | 10 |
| 2.8 | Software Process Improvement Initiative (SPII) | 11 |
| 3.0 | REQUIREMENTS | 11 |
| 3.1 | Tactical Combat Training Systems (TCTS) Information Systems Software Baseline Sustainment | 11 |
| 3.2 | Software Development, Modification, and Maintenance | 12 |
| 3.3 | Trusted Cross-Domain Solution | 12 |
| 3.4 | Test and Training Enabling Network Architecture (TENA) and Threat Interfaces | 12 |
| 3.5 | Ranges Instrumentation Systems Spare Parts | 13 |
| 3.6 | Electronic Warfare Server (EWS) and EW Multiplexer (EWMUX) Integration | 13 |
| 3.7 | Ground Threat Simulation Systems Integration | 13 |
| 3.8 | Weapon and Threat Simulations | 14 |
| 3.9 | Studies, Analyses, and Site Surveys | 14 |
| 3.10 | Web-Accessible Database | 14 |
| 3.11 | Tactical Training Ranges (TTR) System Support Activities (SSAs) | 14 |
| 3.12 | Cybersecurity and System Administration | 14 |
| 3.13 | Training | 15 |
| 3.14 | Future Capabilities | 15 |
| 4.0 | DELIVERABLES | 15 |
| 4.1 | Monthly Status Report | 15 |
| 4.2 | Monthly Funds and Man-Hours Expenditure Report | 15 |
| 4.3 | Quality Assurance (QA) | 15 |
| 4.4 | Configuration Management | 15 |
| 4.5 | Earned Value | 16 |
| 4.6 | Product Delivery Schedule | 16 |
| 5.0 | PERTINENT INFORMATION | 16 |
| 5.1 | Material | 16 |
| 5.2 | Government-Furnished Equipment (GFE) | 16 |
| 5.3 | Travel | 16 |
| 5.4 | Facilities | 17 |
| 5.4.1 | Contractor Facilities | 17 |
| 5.4.2 | Integrated Mobile and Threat Systems Facilities | 17 |
| 5.4.3 | DoD/Foreign Facilities | 17 |
| 5.5 | Vehicles | 17 |
| 5.6 | Forklifts General Administrative | 18 |
| 5.7 | Forklifts Equipment Operation (Qualifications, Training, and License) | 18 |
| 5.8 | Data Rights | 18 |
| 6.0 | SECURITY | 18 |
| 6.1 | Security Requirements for Classified Programs | 18 |
| 6.2 | Personnel Security Requirements | 19 |
| 6.3 | Information Security (Access to CUI, For Official Use Only, or Government IT Systems) | 19 |
| 6.4 | Common Access Cards (CACs) | 19 |
| 6.5 | Communications Security (COMSEC) | 20 |
| 6.6 | Operations Security (OPSEC) | 20 |
| 6.7 | Public Release | 20 |
| 6.8 | Visitor Control/Escorting | 21 |
| 6.9 | Open and Close Procedures | 21 |
| 7.0 | ACRONYMS | 22 |
Appendixes:
| A. | Training Ranges Systems and Components | A-1 |
| B. | Potential Sites for TTS Range Work | B-1 |
| C. | CDRLs | C-1 |
PURPOSE
The Mobile and Integration Threat Systems Division at the Naval Air Warfare Center Weapons Division (NAWCWD), China Lake, CA, supports life cycle sustainment of air training systems, electronic warfare (EW) training systems, training range instrumentation systems, and distributed mission training center instrumentation. Tactical Integrated Threat/Target Training Systems (TTS) provides U.S. Navy/Marine Corps/Air Force/Army with training systems required to provide lethal capability and operational readiness primarily in support of the Naval Aviation Training Systems Program Management Activity (PMA 205) and additional Department of Defense (DoD) activities that support the training ranges. All work described in this Performance Work Statement (PWS) will be performed via task orders awarded under an Indefinite Delivery Indefinite Quantity (IDIQ) Multiple Award Contract (MAC).
Background The Mobile and Integrated Threat Systems Division has been designated, by Naval Air Systems Command (NAVAIR), to develop, sustain, and upgrade training systems aimed to improve aircrew lethality and survivability. Training systems include threat simulators, radars, and training instrumentation capable of operation in the Network-Centric Warfare and Battlespace environments. In order to maintain warfighter relevancy, these complex systems are continuously modified and modernized to provide realistic battlefield scenarios. The TTS contract primarily deals with support to the Tactical Combat Training System (TCTS) user community through specialized system software and hardware enhancements, system sustainment activities, user support hotline, and troubleshooting. TCTS systems directly support warfighter training and real-time data for mission debrief events to include live virtual constructive (LVC) data fusion, air-to-air and air-to-ground weapon and threat simulations, and EW threat computations.
General Scope The scope of this contract is to obtain the required services and products in support of DoD and foreign, test and evaluation (T&E), and training ranges; hereafter will be referred to as Ranges. The requirement is to provide research/development, upgrade, sustainment, engineering, integration, testing, and cybersecurity, with the systems listed in Appendix A. In addition, TTS is responsible for the acquisition of spare parts and auxiliary hardware that includes EW, training systems, subsystems and upgrades to Ranges infrastructure required for the operation of threat systems and aircrew training systems.
APPLICABLE DOCUMENTS
a. ANSI/EIA-748 Earned Value Management System (EVMS), March 2013
b. Assistant Secretary of Defense (ASD) Networks and Information Integration (NII) Directive-Type Memorandum (DTM) 08-027 – Security of Unclassified DoD Information on Non-DoD Information Systems, 31 July 2009
c. Chief of Naval Operations/Headquarters, United States Marine Corps (CNO N614/HQMC C4) – Navy-Marine Corps Unclassified Trusted Network Protection (UTN-Protect) Policy, Version 1.0, 31 October 2002
d. CJCSI 6212.01F – Net Ready Key Performance Parameters (NR KPP), 21 March 2012
e. CMS-1 Department of the Navy (DON) Communications Security (COMSEC) Policy and Procedures Manual, 01 Jul 2019
f. Department of Defense Instruction (DoDI) 5200.02 – Department of Defense Personnel Security Program, April 2017
g. DoD 5200.01-M – DoD Information Security Program Manual, Volumes 1-34, 24 February 2012
h. DoD 8523.01 – Communications Security (COMSEC), 22 April 2008
i. DoD Manual 5220.22, Volume 2 – National Industrial Security Program: Industrial Security Procedures for Government Activities, 1 August 2018
j. DoDD 8570.01 – Information Assurance Training, Certification, and Workforce Management, 15 August 2004, certified current as of 23 April 2007
k. MIL-STD-31000A – Technology Data Packages, February 2013
l. MIL-HDBK-61A – Configuration Management Guidance, 7 February 2001
m. National Security Telecommunications and Information Systems Security Policy (NSTISSP) No. 11 – Revised Fact Sheet National Information Assurance Acquisition Policy, July 2003
n. National Security Agency Central Security Service NSA/CSS Manual 1-52 Issue Date: 30 September 2013 Revised: 23 May 2014
o. OPNAVINST 2221.5C – Release of Communications Security (COMSEC) Material to U.S. Industrial Firms Under Contract to the U.S. Navy, 7 February 2007
p. Secretary of the Navy Instruction (SECNAVINST) 3070.2A Operations Security, 9 May 2019
Information Technology (IT) The Government will provide all necessary obsolete reference documents and those not generally available to the contractor as requested.
The Contractor shall not purchase any IT equipment on behalf of NAVAIR in support of this Contract, which reports to PBIS-IT, without a Naval Air Systems Command (NAVAIR) Command Information Officer (CIO) approved NAV-IDAS ITPR.
Clinger-Cohen Act (CCA) The contractor shall conduct analysis of program/project needs, acquisition strategy and program artifacts to identify and capture specific factors required to satisfy the 11 elements of Clinger-Cohen Act (CCA) compliance listed in DODI 5000.02, Enclosure 1, Table 9. Using Microsoft Word, the contractor shall prepare a CCA compliance matrix following the organization and appearance of Table 11 with additional separate columns for the display of artifact: titles, date(s) of approval, page number(s), and paragraph or section number(s). The right-hand column shall include an embedded object permitting the reader to open unclassified artifacts. The column shall identify classified artifacts and shall describe approved classified channels for access of classified artifacts. The contractor shall support the program manager during CCA compliance review and assist in responding to reviewer comments if and when additional supporting information or revisions are required.
Updating approved CCA compliance packages: For updates of approved CCA compliance packages, the contractor shall conduct analysis of program/project needs, acquisition strategy and program artifacts to identify and to determine if each of the Eleven (11) elements of CCA has changed and if no change has occurred a notation stating “no change” shall be entered in the CCA compliance matrix. If changes have been found, the Contractor shall update the CCA compliance matrix to reflect the changes.
The contractor shall support the program manager during CCA compliance review and assist in responding to reviewer comments if and when additional supporting information or revisions are required.
System Software/Application Compliance All Information Technology Systems or software/application development, modification or support shall be performed in accordance with Defense Business Transformation guidance (formerly Business Management Modernization Program (BMMP)), Department of the Navy (DON)/Naval Air Systems Command (NAVAIR) Functional Area Manager (FAM) Policies and Guidance, Network and Server Registration, and Web Enablement mandates.
Websites, Web Enablement and Application/System Development, Modification, and Maintenance Support Services All Information Technology systems, software, and website development, modification or support shall be performed in accordance with all applicable Federal, DoD, DON, and NAVAIR policy, guidance, standards, and strategies, and should be integrated within the NAVAIR Enterprise portal and collaboration environment whenever possible. Any Web sites/servers hosted/located in contractor facilities, or outside NAVAIR enclave, will transition to NAVAIR architecture and infrastructure in accordance with Legacy Shutdown guidance. Policies include, but are not limited to:
a. Office of Management and Budget Management of Federal Information Resources, OMB CIRCULAR NO. A-130 Revised. <http://www.whitehouse.gov/omb/circulars_a130_a130trans4>
b. OMB Policies for Federal Agency Public Websites, OMB M-05-04 <http://www.whitehouse.gov/sites/default/files/omb/memoranda/fy2005/m05-04.pdf>
| c. | Section 508 Amendments to the Rehabilitation Act of 1973. <http://www.section508.gov/Section-508-Of-The- Rehabilitation-Act> |
| d. | Department of Defense Web Policies and Guidelines. <http://www.defense.gov/webmasters> |
| e. | Navy Information Operations Command (NIOC) Norfolk Web Risk Assessment Team Website. <http://www.public.navy.mil/fcc-c10f/niocnorfolk/Pages/AboutWRA.aspx> |
| f. | DON Policy for Content of Publicly Accessible World Wide Web Sites SECNAVINST 5720.47B. <http://www.navy.mil/navydata/internet/secnav5720-47b.pdf> |
| g. | NAVAIR CIO Website (NAVAIR specific policy and guidelines). To request this policy contact the NAVAIR CIO office – 7.2.2 Applications Integration team – Web Manager: Shane Malamphy at 301- 342-1825. |
| h. | Defense Information Systems Agency (DISA) Hosting of All Navy Websites (NAVADMIN 061/08).<http://www.public.navy.mil/bupers- npc/reference/messages/Documents/NAVADMINS/NAV2008/NAV08061.txt> |
| i. | Consolidation of Navy Web Sites - Reduction of IM/IT Footprint NAVADMIN 145/07. <http://www.public.navy.mil/bupers- npc/reference/messages/Documents/NAVADMINS/NAV2007/NAV07145.txt> |
| j. | DON Web Presence Policy: The Registration, Compliance of, and Investment in, All Unclassified Web Sites and Uniform Resource Locators. <http://www.doncio.navy.mil/ContentView.aspx?ID=577> |
| k. | Policy and Procedures for Web Risk Assessment (WRA) of Publicly Accessible Navy Sites (ALCOM 129/09). <www.public.navy.mil/fcc-c10f/niocnorfolk/Documents/NTD-08-09.txt> |
Software Development/Server Procurement Any tools developed that will be hosted by the Navy Marine Corps Intranet (NMCI) or run on NMCI workstations will be certified for NMCI and comply with NMCI policy. Additionally, any servers supporting this effort will be transitioned to meet the requirements of the current NAVAIR Server Consolidation effort.
Cybersecurity The contractor shall conduct investigation and analysis of acquisition program artifacts such as but not limited to Initial Capabilities Document (ICD), Capability Description Document (CDD), Capability Production Document (CPD), Navy urgent operational need (UON) and Marine Corps urgent universal need statement (UUNS), joint urgent operational needs (JUONs), threat assessments and acquisition strategies (AS). Knowledge gained from this analysis shall be used when developing the Cybersecurity Strategy (CS) needed to steer and inform the program’s development of a Security Plan (SP) in accordance with DoDI 8510.01, of 12 March 2014 As a minimum, hardware, firmware, software, documentation (data deliverables) and/or Information Technology (IT) services delivered by this contract shall be in compliance with the following References:
| a. | DoDI 8500.01 Cybersecurity, 14 March 2014 |
| b. | DoDI 8510.01, Risk Management Framework (RMF) for DoD Information Technology (IT), 12 March 2014, Incorporating Change 1, May 24, 2016. |
| c. | Committee on National Security Systems Instruction 1253, “Security Categorization and Control Selection for National Security Systems,” March 27, 2014, as amended. |
| d. | DoDD 8140.01, Cyberspace Workforce Management, 11 August 2015. |
| e. | DoD 8570.01-M Information Assurance Workforce Improvement Program, 15 August 2004, Certified Current as of 10 November 2015. |
The contractor shall conduct investigation and perform analysis including; criticality analysis, threat assessment and vulnerability assessments. All findings and recommendations shall be reported to the government in technical reviews and submitted as written reports or documents as listed in Contract Data Requirements Lists. The contractor shall support government efforts needed for Information systems (IS) (enclaves or major applications), Platform Information Technology (PIT) or PIT systems to successfully categorize the system, achieve favorable assessment for selection, implementation and testing of security controls and authorization (approval to operate) before use or interconnection in an operating environment in accordance with references (a), (b) and (c). This includes IT that is standalone and IT that is connected to other systems, networks or enclaves. Information systems (IS) (enclaves or major applications), Platform Information Technology (PIT) or PIT systems delivered prior to award of this contract but included in the performance of this contract may have been delivered in compliance with Department of Defense Information Assurance Certification and Accreditation Process (DIACAP) and as such shall require transition to Risk Management Framework cybersecurity compliance. Transition planning proposed or performed under this contract shall be in compliance with reference (b) Enclosure 8, Figure 2 and all hardware, firmware and software deliverables shall be capable of receiving Authorization to Operate in accordance with reference (b).
Information technology services shall only be performed by personnel who are qualified and certified in accordance with reference (d). Personnel proposed and/or used in the performance of this contract as certified personnel shall be limited to those whose specifically assigned duties and responsibilities require certification.
Designation of Platform IT (PIT) and PIT Systems:
The contractor shall investigate and conduct analysis in order to provide technical reviews to make a recommendation with data supporting the proposal(s) for the need for designation (or not) of the system, network or enclave as platform IT (PIT) or a PIT system in accordance with DoDI 8500.01, Cybersecurity, 14 March 2014. The proposal shall include all technical data required to engage in collaboration with the security control assessor, the authorizing official (staff) and PIT designating official(s). In the event the collaboration results in redesign or follow-up action after collaboration requiring additional or revised documentation, the contractor shall continue to assist the collaboration process.
System Characterization and Security Control Selection:
The contractor shall investigate and conduct analysis in order to provide technical reviews to make a recommendation with data supporting characterization and selection of security controls in accordance with DoDI 8500.01, Risk Management Framework (RMF) for DoD Information Technology (IT), 12 March 2014 Incorporating Change 1, May 24, 2016, National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4, April 2013, NIST SP 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems, February 2010, Federal Information Processing Standards Publication (FIPS 199, February 2004. Contractor performed analysis shall include; criticality analysis, threat assessment and vulnerability assessments. The contractor shall propose characterization of the system and selection of security controls use Committee on National Security Systems Instruction (CNSSI) 1253, Security Categorization and Control Selection for National Security Systems, 27 March 2014 to tailor the NIST guidance. The proposal shall include all technical data required to engage in collaboration with the security control assessor and the authorizing official (staff). In the event the collaboration results in redesign or follow-up action after collaboration requiring additional or revised documentation, the contractor shall continue to assist the collaboration process.
Security Plan:
The contractor shall investigate and conduct analysis in order to provide technical reviews to make a recommendation with data supporting the development of the Security Plan. Contractor performed analysis shall include; criticality analysis, threat assessment and vulnerability assessments. The security Plan shall be prepared for the first program/project decision point and updated for each subsequent decision point. The proposal shall include all technical data required to engage in collaboration with the security control assessor and the authorizing official (staff). In the event the collaboration results in redesign or follow-up action after collaboration requiring additional or revised documentation, the contractor shall continue to assist the collaboration process.
All Cybersecurity shall be in compliance with the following listed instructions:
| a. | DoDI 8582.01, Security Of Unclassified DoD Information On Non-DoD Information Systems, 06 May 2012 |
| b. | Chairman of the Joint Chiefs of Staff Instruction CJCSI 3170.01I (series), Joint Capabilities Integration and Development System (JCIDS), 23 January 2015. |
| c. | CJCSI 6211.02D, Defense Information System Network (DISN): Policy and Responsibilities, 24 Jan 2012 (Current as of 4 Aug 2015). |
| d. | CJCSI 6251.01D, Narrowband Satellite Communications Requirements, 30 Nov 2012. |
| e. | CJCSI 6510.01F, Information Assurance (IA) and Support to Computer Network Defense (CND), 09 Feb 2011, certified current 9 Jun 2015. |
| f. | Chairman of the Joint Chiefs of Staff Manual CJCSM 6510.01B – Cyber Incident Handling Program, 10 July 2012 (Current as of 18 Dec 2014). |
| g. | Navy Ports Protocols, and Services (NPPS) Manual, Version 1.5, 16 November 2010. |
| h. | Defense Acquisition Guidebook – Chapter 7, Acquiring Information Technology, Including National Security Systems, Section 7.5, Information Assurance (IA). |
| i. | DoD 5220.22-M, National Industrial Security Program Operating Manual, February 28, 2006 (NISPOM) Incorporating Change 2 May 18, 2016. |
| j. | DoD 8570.01-M, Information Assurance Workforce Improvement Program, 19 Dec 2005, (Incorporating Change 3, 24 Jan 2012). |
| k. | DoDD 8000.01, Management of the Department of Defense Information Enterprise, 17 March 2016. |
| l. | DoDD 8100.02, Use of Commercial Wireless Devices, Services, and Technologies in the Department of Defense (DoD) Global Information Grid (GIG), 14 April 2004, Certified Current, 23 April 2007. |
| m. | DoDD 8140.01, Cyberspace Workforce Management, 11 August 2015. |
| n. | DoDI 8330.01, Procedures for Interoperability and Supportability of Information Technology (IT) and National Security Systems (NSS), 21 May 2014. |
| o. | DoDI8500.01, Cybersecurity, 14 March 2014. |
| p. | DoDI 8520.02, Public Key Infrastructure (PKI) and Public Key (PK) Enabling, 24 May 2011. |
| q. | DoDI 8551.01, Ports, Protocols, and Services Management (PPSM), 28 May 2014 |
| r. | DoDI 8580.1, Information Assurance (IA) in the Defense Acquisition System, 9 July 2004. |
| s. | DoDI 8581.01, Information Assurance (IA) Policy for Space Systems Used by the Department of Defense, 8 June 2010. |
| t. | DON CIO Memo 02-10, Department of the Navy Chief Information Officer Memorandum 02-10 Information Assurance Policy Update for Platform Information Technology, 26 April 2010. |
| u. | DON letter 5239 NAVAIR 726/2322 of 18 Feb 09, NAVAIR Data at Rest Policy. |
| v. | Federal Information Processing Standards Publications (FIPS PUB)-199, February 2004. |
| w. | Committee on National Security Systems Policy CNSSP No. 11, 10 June 2013. |
| x. | Office of the Chief of Naval Operations OPNAV INST 5239.1C, Navy Information Assurance (IA) Program, 20 Aug 08. |
| y. | SECNAV M-5239.1, Department of the Navy Information Assurance Program; Information Assurance Manual, November 2005. |
| z. | SECNAVINST 5230.15, Information Management/Information Technology Policy for Fielding of Commercial Off the Shelf Software, 10 April 2009. |
| aa. | SECNAVINST 5239.3C, Department of the Navy Cybersecurity Policy, 2 May 2016. |
| bb. | ECNAVINST 5239.19, Department of the Navy Computer Network Incident Response and Reporting Requirements, 18 March 2008. |
| cc. | The National Security Act of 1947. |
| dd. | Title 40/Clinger-Cohen Act. |
| ee. | Title 44/ Federal Information Security Management Act. |
| ff. | National Institute of Standards and Technology Special Publication 800-53, Security and Privacy Controls for Federal Information Systems and Organizations, Revision 4, April 2013 (Updated 22 Jan 2015). |
All IT procured on behalf of this contract shall meet all DoD/DON and NAVAIR cybersecurity polices. Failure to follow these policies will result in denied access to NMCI, One Net, Integrated Shipboard Network System (ISNS) and other DON, DoD and Joint Networks. These cybersecurity policies are standard across the Department and ensure cybersecurity compatibility and interoperability.
IT systems and or networks operated by contractors pursuant to a NAVAIR contract, regardless of the level of data processed, shall be operated in accordance with the NISPOM.
Approved contractor-owned equipment shall be permitted connections to NAVAIR/DoD networks in order to carry out the performance of this contract. All Contractor-owned hardware and/or software shall meet DoDI 8500.1 Cybersecurity (CS), is subject to validation scanning and must be approved by the NAVAIR site CS Manager prior to connection.
The following specific criteria must be met before the contractor can be connected to any DoD or NAVAIR network in support of this contract. Requirements include:
| a. | Network Vulnerability Scanning. NAVAIR Deputy CIO for Information Assurance maintains authorized auditing tools and shall provide for firewall/port scans, device discovery scan, vulnerability assessment, and other requirements as required to ensure secure interoperability with DoD networks. The contractor shall be responsible for the remediation of any equipment that fails these audits prior to the connection of the system to the networks; Results of approvals shall be documented via Memorandum of Agreement with the Facility Security officer and the Defense Security Service Representative for that contractor. |
| b. | Extent of Validation Scanning. To prevent scanning of corporate assets, all such networks, equipment and connections shall be physically segregated from any government/contractor corporate networks that are not in direct support of DoD contracts. |
| c. | Circuit Provisioning. Any circuit or connection between NAVAIR and/or DoD site and the contractor site shall be provisioned via the Defense information Security Agency and comply with CJCSI 6211.02D, Defense Information System Network (DISN): Policy and Responsibilities, 24 Jan 2012. |
| d. | Servicing Systems from a Remote Contractor Site. Remote Access Service connections that allow off-station operation and/or administration of contractor owned systems, located at any NAVAIR facility or site, shall not be permitted, with the exception of those systems connecting to the Command via the Outreach Services identified in Section 6, Enterprise Architecture. |
| e. | Memorandum of Agreement and Inter-connection Agreements. A Cybersecurity Memorandum of Agreement (MOA) between the contractor owning the equipment and AIR-7.2.6 shall be developed and signed before the equipment can be connected to NAVAIR networks. Failure to comply with the signed MOA shall be grounds for disconnection from the network. |
Enterprise Architecture
a. Contractor Networks and Connections. Contractor-owned and operated networks are prohibited on any Naval Air Systems Command (NAVAIR) facility or site in support of this contract. The contractor may access non- government, external IP space via the NAVAIR-provided Virtual Private Network (VPN) Outreach service or NAVAIR CIO approved Internet Protocol (IP) service.
b. Architecture Compliance. The contractor shall ensure all IT solutions, including database solutions, comply with the appropriate NAE Enterprise Architecture, and are verified by the NAVAIR Enterprise Architect (AIR-7.2.3) prior to build out.
c. Disclosure of pre-existing networks, circuits or connections. Any and all networks, circuits or connections between the contractor and any NAVAIR site related to previous contracts shall be identified in the MOA. Failure to comply and subsequent discovery of an unregistered network, circuit or connection shall be grounds for immediate disconnection.
Software Process Improvement Initiative (SPII) The Contractor shall follow the Software Development Plan (SDP) that they develop and submit in accordance with CDRL A007. The SDP will follow the framework of Institute of Electrical & Electronics Engineers (IEEE)/Electronics Industries Association (EIA) IEEE/EIA Std 12207 regarding subject content, level of detail, and completeness. The SDP shall serve during contract performance as the benchmark for the contractor’s software development effort and shall be periodically evaluated and updated as specified in the CDRL, as a part of continuous process improvement subject to Government review and approval.
REQUIREMENTS
The work shall be performed in accordance with individual Task/Delivery Orders (T/DOs) and Integrated Product/Project Baselines (IPBs). The contractor shall apply systems engineering principles and practices to deliver software, components, building blocks, assemblies, documentation, and complete end items; the contractor shall use the Software Engineering Institute’s (SEI’s) Capability Maturity Model Integrated (CMMI) processes and/or Agile in accordance with the requirements in Section 3. A minimum CMMI Level 2 may be required or a Government approved risk mitigation alternative to CMMI Level 2. This work may be performed on assigned systems, subsystems, equipment, and components.
T/DOs issued under this contract will primarily be completion based level of effort services but may include completion-type orders as described in the following sections. The contractor shall provide performance specifications, manuals, technical data packages, reports, and drawings as specified by T/DOs.
Tactical Combat Training Systems (TCTS) Information Systems Software Baseline Sustainment The contractor shall sustain, maintain, and upgrade the software baselines of TCTS systems such as the Control and Computation Subsystem (CCS), Joint Debriefing System (JDS), Advanced System Operations Console (ASOC), Radar Acquisition Display System (RADS), and Low Activity Pre-Processor (LAPP) utilizing Engineering Investigations (EIs) and Software Trouble Reports (STRs). The contractor shall test new and modified software and subsystem hardware at the Tactical Air Range Integration Facility (TARIF). After successfully completing testing, the contractor shall deliver new/updated software baselines and any necessary hardware to various Ranges for installation. The typical delivery cycles are every six months. Software products and simulations are to be installed on existing range equipment, new range equipment, or equipment not installed on Ranges. Equipment located at facilities off the Ranges could include locations such as software support facilities, debrief centers, laboratories, and research facilities. These software efforts will require fabrication and installation of new mission and project specific computer systems, peripherals, commercial software packages and licenses, interfaces, and software storage media that will be integrated into the existing range assets, to include encryption/decryption equipment. (CDRLs A001, A002, A003, A004, A006, A007, A008, A009, A00A, A00B, A00C, A00D, A00E, A00F, A00G, A00H, A00J, A00K, A00P, A00Q, A00R, A00S, A00V, A00X, and A00Y)
Software Development, Modification, and Maintenance The contractor shall develop and modify software that provides multitasking in real-time that is event driven and time constrained. The software must be able to sense and provide real-time control of external devices such as radar systems, target tracking, and communication systems. It must provide real-time graphical presentation of range operations and exercise event information. The software that is distributed must be able to process through shared or dedicated communication channels. The contractor shall provide full programming capabilities that include submittal/analysis of software deficiency report (DR), software maintenance, upgrade, modernization, loading, and distribution. The programming languages, operating systems, and development platforms will be specified by the T/DOs. (CDRLs A001, A002, A003, A004, A006, A007, A008, A009, A00A, A00B, A00C, A00D, A00E, A00F, A00G, A00H, A00J, A00K, A00P, A00Q, A00R, A00S, A00V, A00X, and A00Y)
Trusted Cross-Domain Solution The contractor shall analyze requirements and recommend course of action to the acquisition of trusted cross-domain solutions or other guards that provide secure sharing of sensitive data between unclassified and classified security domains. The contractor shall program, install, integrate, and sustain trusted cross-domain solutions such as a red/black security boundary separation device. These devices will be integrated and tested at TARIF or other operational locations. The contractor shall provide subject matter expertise to personnel from the Navy’s Cross Domain Solution Office (CDSO) and other Government contractor support organizations with rule-set development and documentation. (CDRLs A001, A00B, A00C, and A00N)
Test and Training Enabling Network Architecture (TENA) and Threat Interfaces The contractor shall sustain, develop, and implement TENA capability or future replacement. The contractor shall develop and test TCTS to TENA Gateway and integrate embedded TENA object models and TENA native capable software into Range’s information systems and TCTS subsystems for distributing data to and from separate operational geographic locations participating in joint training and T&E exercises. The contractor shall analyze and assess threat / EW architecture / TENA efforts supporting the development of the Navy’s threat / EW architecture including the development of TENA object models in accordance with applicable documents. This effort includes the production of hardware, software, and integrated solutions to extend and develop the EW architecture. The EW communication architecture shall be examined to provide solutions for physical connectivity. TENA object models and/or the software to use these models will be provided for communications connectivity. The contractor shall provide threat / EW range communications and connectivity interfaces such as the Range Interface Board (RIB), threat and range gateway TENA interfaces, red/black interfaces, trusted guard interfaces, encryption interfaces, and others. (CDRLs A001, A002, A003, A004, A006, A007, A008, A009, A00A, A00B, A00C, A00D, A00E, A00F, A00G, A00H, A00J, A00K, A00P, A00Q, A00R, A00S, A00V, A00X, and A00Y)
Ranges Instrumentation Systems Spare Parts The contractor shall develop, procure, and deliver parts, assemblies, and subsystems to replace depleted inventory and maintain operational status of training instrumentation and networking capabilities. The characteristics of the spare parts, assemblies, and subsystems will be specified in the PWS of the T/DO.
Electronic Warfare Server (EWS) and EW Multiplexer (EWMUX) Integration The contractor shall develop, field, and sustain an Electronic Warfare Server (EWS) and interface to EW information system (EWMUX). The contractor shall integrate EWMUX with TCTS servers and other target/threat servers at various Ranges. The EWS includes surface-to-air weapons simulations, Integrated Air Defense System (IADS) simulations, and electronic combat environment (ECE) simulations. The contractor shall deliver and install EWS software simulations and models, and supporting functionality in the EWS. Delivered EWS units shall have classified weapon solutions and unclassified threat pointing and control messaging to the EWMUX in support of individual ranges’ cybersecurity requirements. The contractor shall sustain and upgrade the EWS/EWMUX interface hardware and software and implement enhancements to satisfy operational requirements and Armed Forces combat readiness training requirements. (CDRLs A001, A008, A009, A00A, A00B, A00C, A00D, A00E, A00F, A00G, A00H, A00K, A00Q, A00R, and A00S).
Ground Threat Simulation Systems Integration The contractor shall assess EW ground threat simulation systems and provide recommendation for integration via serial data links or Ethernet protocols into the TCTS subsystems. The contractor shall develop interfaces to allow command and control centers to monitor ground threat simulation systems from a mission monitoring or debriefing graphic workstation through the CCS or TCTS EWS. The contractor shall sustain and upgrade ground threat simulators to ensure proper operation in support of Armed Forces combat readiness training requirements. (CDRLs A00N)
Weapon and Threat Simulations The contractor shall analyze Government-furnished characteristics of emerging weapons/threats and develop simulations to enhance TCTS weapons and threat simulations capabilities. (CDRLs A00N)
Studies, Analyses, and Site Surveys The contractor shall analyze, assess, and provide solutions of TCTS functionality. Elements that shall be considered are quality, reliability, maintainability, interoperability, foreign threat intelligence data, frequency allocation applications, vulnerability to high-power irradiation, and EW threat presentation capabilities by the Ranges. Analysis shall include operational risk management (ORM) associated with the operation of threat systems, aircrew training systems, peripheral instrumentation, and networks. (CDRL A00N)
Web-Accessible Database The contractor shall develop, maintain, and upgrade a web-accessible database. This database will host design information, Technical Data Packages (TDPs), software/hardware configuration, prediction analyses, testing and training documentation, data revision tracking information, and procured or licensed original equipment manufacturer (OEM) documentation. The database will provide data entry forms and maintenance data, status of threat/training systems, component accounting information, failure reports, software problem reports (SPRs), corrective action reports, DRs, EI reports, maintenance and repair logs, trouble calls, recommended corrective actions, resource, and analysis tools. The contractor shall maintain the web-accessible database with the most current data within 5 working days after receipt of the data. The contractor shall also maintain a mirror backup site. The website database shall be available 24 hours per day, 7 days per week. The contractor shall notify the Government of changes within 24 hours via email. The website may be down up to 1 hour per week for maintenance. If the website is down any longer than 1 hour, the contractor shall notify the Government and use its mirror backup site (CDRL A001) Tactical Training Ranges (TTR) System Support Activities (SSAs) The contractor shall provide engineering, configuration management/data management (CM/DM), and logistics, in support of threat and training systems SSA located at NAWCWD China Lake. The contractor shall also respond to trouble calls from the Ranges and provide corrective actions and inventory status. The contractor shall provide a response to the caller within 24 hours of received trouble call.
Cybersecurity and System Administration The contractor shall provide the technical expertise to manage networks and servers. The contractor shall also develop documentation in support of threat and training systems compliance with System Security Accreditation Agreement (SSAA), RMF or variants, Authority to Connect (ATC), Interim Authority to Operate (IATT) and Authority to Operate (ATO). (CDRL A00N and A00S)
Training The contractor shall create or modify documentation covering the operational procedures of newly developed or modified end items. The contractor shall provide training for the operation of systems and the preventive field maintenance of systems and components. Training may include hands-on training, classroom training, instruction manuals, or online tutorials. (CDRL A001 and A006)
Future Capabilities The contractor shall assess, prototype, and integrate future concepts and technologies such as Directed Energy, Live-Virtual-Constructive (LVC), Weapons/Threat Simulations, and their impact on combat training systems and readiness. (CDRL A001, A00B, A00C, and A00W)
DELIVERABLES
Monthly Status Report The contractor shall deliver a monthly Cost/Schedule Status Report (C/SSR) that includes cumulative funds/hours expended, a summary of work performed per project and task, problems encountered, problems resolved, compliance to schedules, risks to completion of the T/DO and other relevant information. The Travel Section of the report shall contain the following for each travel trip taken during the month: name(s) of travelers, travel dates, destinations, and purpose of the trip. This report shall be submitted in accordance with CDRL A00L.
Monthly Funds and Man-Hours Expenditure Report The contractor shall submit a report detailing all labor, material, and travel costs to the Government (CDRL A00U).
Quality Assurance (QA) The contractor shall conduct QA in accordance with the T/DO and applicable documents. The contractor shall deliver QA audits conducted on products and software development processes. QA audits shall cover project initialization, project planning, project execution, project closure, requirements management, CM, subcontracting, metrics collected, material purchases. (CDRL A00Z)
0. Configuration Management The contractor shall submit a Configuration Management Plan (CMP) in accordance with CDRL A005 to serve, during the contract performance period, as the benchmark for controls to be used for effective software, hardware, and firmware configuration. The CMP shall be periodically evaluated and updated as specified in CDRL A005, as part of continuous process improvement efforts subject to Government review and approval.
Earned Value When applicable, the contractor shall implement an Earned Value Program. Specific efforts shall include preparation of Work Breakdown Structures (WBSs) with associated cost and schedule plans, work package tracking, status accounting at any level identified in an individual WBS, management reserve control and status accounting, and cost and schedule trend predictions.
Product Delivery Schedule As required by individual T/DOs, the contractor shall provide a delivery schedule. (CDRL A00N)
PERTINENT INFORMATION
Material The contractor shall manage material and consumable supplies at levels to meet mission requirements. The contractor must obtain prior approval from the Contracting Officer’s Representative (COR) for any purchases valued over $3,500. The contractor must obtain prior approval from the Contracting Officer for any purchases valued over $25,000. The contractor shall submit a consent package providing a description, price, evidence of adequate price competition, or if unavailable, a justification for use of a single source, and a determination that the price is fair and reasonable. The contractor shall submit all consent packages to the COR for either approval of material purchasing over $3,500 or initial review of material purchasing over $25,000. The COR will forward consent packages for material purchasing over $25,000 to the Contracting Officer for approval. These requirements apply to all contractor purchases.
Government-Furnished Equipment (GFE) The Government will provide threat systems and equipment that will be called out in applicable IPBs applicable to each order. (CDRL A00T)
Travel The contractor shall be required to travel in performance of this contract. The contractor shall be responsible for all transportation, billeting, and messing for the contractor personnel except in those cases where Government transportation, billeting, and messing are the only services available. All travel will require prior approval of the Technical Point of Contact (TPOC) and COR. All travel shall be conducted in accordance with the Joint Travel Regulations in force during the term of this contract. See Appendix B for potential travel sites of TTS range work. If foreign travel is required, the contractor shall obtain the appropriate U.S. State Department approvals in advance of travel commencing. (CDRL A002)
Facilities The contractor shall perform the above-delineated requirements at a variety of potential locations that are included in Appendix “B” and using a variety of Government and contractor provided facilities as required by the T/DO.
Contractor Facilities The contractor shall maintain suitable facilities for the execution of those tasks not requiring specific performance at government facilities. The Government will not provide facilities unless use of a specific facility at a specific location is necessary to the execution of the T/DO. These facilities shall meet the security requirements as outlined in the applicable DoD Contract Security Classification Specification (DD Form 254, Attachment X).
Integrated Mobile and Threat Systems Facilities The contractor shall perform specified tasks at NAWCWD China Lake. Facilities at China Lake include TARIF, various land ranges at China Lake, test pads, towers, and system integration facilities in the vicinity of Thompson Laboratory. The contractor shall establish and maintain offstation facilities within 10 Miles of NAWS China Lake main gate for required local travel to the ranges and is requiredfor oversight of local personnel and surveillance of work being performed at WD Ranges.
DoD/Foreign Facilities The contractor shall perform specified tasks (such as installation, integration, and testing) at various DoD locations, foreign range locations, or subcontractor and vendor facilities. Appendix B provides a list of potential range work locations.
Vehicles The contractor shall provide all vehicles required for the performance of this contract unless shared access is authorized by the Government. Contractor personnel may use Government Owned Government Operated (GOGO) vehicles managed through the Transportation Office, Naval Facilities Engineering Command (NAVFAC) Southwest, Code 270, under the following conditions: concurrence with the contractor’s need to use GOGO vehicle(s); COR oversight to ensure compliance with DoD 4500.36-R; clause 5252.228-9501, Liability Insurance, is included in this contract and applies to the use of GOGO vehicles; all training and licensing requirements to operate the GOGO vehicles and equipment, as defined in NAVFAC P-300, is met by the contractor; the contractor need for GOGO vehicles and equipment must be less than full time and shall not interfere with Government use of those vehicles and equipment; and use of GOGO vehicles is for work on a Government site, specific destinations within a 5-mile radius of the Naval Air Weapons Station (NAWS) China Lake’s front gate (U.S. Post Office, FEDEX, and contractor’s Office), and for official use only for specific order requirements.
Contractor employees that work primarily at non-Government-provided workspaces (off-site spaces) shall provide their own vehicles and equipment. Transportation Office, NAVFAC Southwest, Code 270, can only issue vehicles and equipment to Government employees. The Government remains responsible for the vehicles and equipment. The Government will only provide vehicle and equipment access to the contractor on an as-available basis.
Forklifts General Administrative The contractor shall provide qualified personnel with current professional forklift operator certifications to execute basic operations support at the NAWCWD TARIF infrastructure. These individuals shall have specific knowledge, skills, and abilities to perform forklift operations. At a minimum, the contractor shall provide personnel certified as forklift operators.
Forklifts Equipment Operation (Qualifications, Training, and License) The contractor shall operate a forklift at NAWCWD TARIF in support of various operations and services required to accomplish equipment removal and relocation. The contractor shall satisfy all training and licensing requirements prior to operating Government-owned equipment in accordance with NAVFAC policy and Naval Supply Systems Command (NAVSUP) Publication 538 (current revision). Use of Government-owned equipment is for work on a Government site and is for official use only. At no time shall any contractor personnel operate a forklift on federal property without proper training and a current license. The Government will provide forklifts required for each specific job.
Data Rights The contract contains clauses defining the Government’s rights regarding technical data computer software and computer software documentation generated under orders issued during the term of the contract. Other than restrictions associated with commercially available products, the contractor shall not use its own proprietary data or intellectual property in the performance of this contract without prior approval of the Government. The contractor shall notify the Government of its intent to use any intellectual property with less than unlimited Government rights prior to responding to a Request for Proposal (RFP) for a new order and shall provide a completed Data Rights Assertion List as required in Defense Federal Acquisition Regulation Supplements (DFARSs) 252.227-7013 and 252.227-7014.
SECURITY
Security Requirements for Classified Programs The security requirements specified herein shall apply to the contractor and subcontractors. The contractor shall safeguard classified information and meet the security requirements and IA/cybersecurity requirements identified in the applicable DoD Contract Security Classification Specification (DD Form 254). The contractor shall enforce these safeguards throughout the life of the contract.
Personnel Security Requirements The contractor shall provide personnel with the appropriate personnel security clearance levels for the work to be performed. The contractor will require access up to and including Top Secret/Sensitive Compartment Information (TS/SCI) and Special Access Program (SAP) information in performance of this contract and shall be in accordance with the DoD 5220.22-M, NISPOM, incorporating Change 2, 18 May 2016, applicable DoD personnel security regulations, and applicable DD Form 254. The contractor shall maintain sufficiently cleared personnel to perform the tasks required by this PWS IAW the DD Form 254 and the contract. All contractor personnel shall possess the requisite security clearance, accesses, and need-to-know commensurate with the requirements of their positions. All contractor personnel with access to unclassified information systems, including email, shall have at a minimum a favorable Tier 3 (T3) investigation.
T/DOs requiring access to TS/SCI or SAP will address the specific security requirements and require an order level DD Form 254.
Information Security (Access to CUI, For Official Use Only, or Government IT Systems) Information Security. Direct Support contractor personnel working under the purview of a DoN Commanding Officer/Commander shall comply with the local security provisions and the requirements of SECNAV M-5510.36 (series).
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .