3. 70RCSJ24R00000015 Attachment 1 SOW Planning Office Supp.pdf
PDF 380 KB Posted
- Attached to
- Planning Office Support Federal contract opportunity
- Solicitation number
- 70RCSJ24R00000015
About this file
This document is a Statement of Work (SOW) for a federal contract opportunity from the Department of Homeland Security (DHS) Cybersecurity and Infrastructure Security Agency (CISA) to provide support for the CISA Joint Cyber Defense Collaborative (JCDC) Planning Office.
The SOW requires a contractor to provide direct support to the JCDC Planning Office in creating strategies, processes, procedures, capabilities, and tools to develop, implement, and mature the office. The Planning Office is responsible for enabling cyber defense operations by unifying deliberate and crisis action planning across public and private sector partners, and integrating the execution of cyber defense plans. The SOW outlines eight specific tasks the contractor must complete, including providing support for the Planning Office's front office functions, governance, joint cyber defense planning, plan enabling and execution, risk analysis and prioritization, adversary-focused planning, intelligence support and coordination, and optional surge support. The contract has a one-year base period and two one-year option periods. Contractor personnel must maintain Top Secret security clearances with Sensitive Compartmented Information (SCI) eligibility.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 4. 70RCSJ24R00000015 Attachment 2 Pricing Template A0003.xlsx | XLSX spreadsheet | |
| 70RCSJ24R00000015 A0003.pdf | ||
| 8. 70RCSJ24R00000015 Solicitation Draft DD254.pdf | ||
| 2. 70RCSJ24R00000015 Planning Office Support Addendum to FAR 52.212-1 A0002.pdf | ||
| 70RCSJ24R00000015 A0002.pdf | ||
| 4. 70RCSJ24R00000015 Attachment 2 Pricing Template A0002.xlsx | XLSX spreadsheet | |
| 6. 70RCSJ24R00000015 QA Template Attachment 4 Government Responses.pdf | ||
| 70RCSJ24R00000015 A0001.pdf | ||
| 1. 70RCSJ24R00000015 SF1449.pdf | ||
| 2. 70RCSJ24R00000015 SF1449 Addendum to FAR 52-212-1.pdf | ||
| 7. 70RCSJ24R00000015 Section 3. Contract Administration.pdf | ||
| 4. 70RCSJ24R00000015 Attachment 2 Pricing Template.xlsx | XLSX spreadsheet | |
| 6. 70RCSJ24R00000015 Attachment 4 - Q&A Template.xlsx | XLSX spreadsheet | |
| 5. 70RCSJ24R00000015 Attachment 3 - Past Performance Questionnaire.pdf |
Show all 14
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
DEPARTMENT OF HOMELAND SECURITY
STATEMENT OF WORK
FOR
Cybersecurity and Infrastructure Security Agency
Joint Cyber Defense Collaborative Planning Office Support
Request for Quotation: 70RCSJ24R00000015
1.0 GENERAL
1.1 BACKGROUND
1.1.1 The Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency’s (CISA’s) mission is to lead the national effort to protect and enhance the resilience of the nation’s physical and cyber infrastructure. CISA includes the CISA Mission Enabling Offices (MEOs) and six Divisions: the Cybersecurity Division (CSD), the Emergency Communications Division (ECD), the Integrated Operations Division (IOD), Infrastructure Security Division (ISD), the Stakeholder Engagement Division (SED), as well as, the National Risk Management Center (NRMC), which are headquartered within the National Capital Region
(NCR).
1.1.2 CISA is responsible for protecting the Nation’s critical infrastructure from physical and cyber threats through effective coordination and collaboration among a broad spectrum of government and private sector organizations. Within CISA, CSD leads the effort to protect the federal “.gov” domain of civilian government networks and collaborates with the private sector “.com” domain to increase the security of critical networks. CSD’s mission is to reduce cyber risk by being the Nation’s flagship for cyber defense, incident response, and ensuring the resilience of nationally critical functions by delivering capabilities including technology, information, and analytics to support risk reduction. CSD is comprised of five subdivisions:
Threat Hunting, Vulnerability Management, Mission Engineering (formerly Capability Delivery), Capacity Building, and the Joint Cyber Defense Collaborative (JCDC).
1.1.3 The JCDC enables and coordinates operational activities across CSD and engages partner organizations in the execution of those activities. The JCDC is organized into five offices:
Planning, Partnerships, Production, Integration, and Strategic Operations. This structure allows for close collaboration, including, planning towards identified operational outcomes, partnering with operational stakeholders to execute, integrating analytical processes across organizations, and producing technical communications to disseminate to partner communities. This requirement is in support of the JCDC subdivision, and specifically the JCDC Planning Office and JCDC Planning Office Leadership (POL).
1.1.4 The 2021 National Defense Authorization Act established a joint cyber planning function within CISA to “develop, for public and private sector entities, plans for cyber defense operations, including the development of a set of coordinated actions to protect, detect, respond to, and recover from cybersecurity risks or incidents or limit, mitigate, or defend against coordinated, malicious cyber operations that pose a potential risk to critical infrastructure or national interests.” The JCDC Planning Office enables cyber defense operations by working across the public and private sector to unify deliberate and crisis action planning, while integrating the execution of cyber defense plans. The JCDC Planning Office integrates capabilities from CISA elements and from external partners to ensure unified execution of plans, and unified coordination of cyber defense operations across prevention, detection, and response missions.
1.2 SCOPE
1.2.1 JCDC requires a contractor to provide direct support to the CISA, CSD, JCDC subdivision in creating strategies, processes, procedures, capabilities, and tools to develop, implement, and mature the JCDC Planning Office. As JCDC works to develop and implement the joint planning function within the JCDC Planning Office, the Contractor shall provide support and assistance in the following areas:
1. JCDC Planning Office Front Office
2. JCDC Planning Office Governance
3. Joint Cyber Defense Planning
4. JCDC Plan Enabling and Execution
5. Risk Analysis and Risk Prioritization
6. Adversary-focused Planning and Coordination
7. Intelligence Support and Coordination
8. Surge Support (Optional)
1.3 OBJECTIVE
1.3.1 The Contractor shall be responsible for completing all tasks described in this Statement of Work (SOW). Government Personnel and Contractors will perform the tasks as an integrated project team. The Contractor shall be responsible for maintaining documentation for any required deliverables, technical reports, cost/expense reports and notices of acceptance or rejection.
1.4 APPLICABLE DOCUMENTS
DHS Sensitive Compartmented Information (SCI) Systems 4300C Instruction Manual, Version 2.1, March 24, 2017 for TS SCI/C-LAN
1.4.1 Compliance Documents
Compliance Documents are not required.
1.4.2 Reference Documents
• DHS Management Directive 140-01, “Information Technology System Security Program, Sensitive Systems”
• DHS 4300A Policy Directive (Version 13.3, February 13, 2023).
• DHS National Security Systems Policy Directive 4300B, Version 10.1, November 21, 2018 for NSS Collateral (Unclass, Secret or Top-Secret Collateral).
• DHS Sensitive Compartmented Information (SCI) Systems 4300C Instruction Manual, Version 2.2, August 22, 2018 for TS SCI/C-LAN.
2.0 SPECIFIC REQUIREMENTS/TASKS
2.1 TASK ONE: JCDC Planning Front Office
2.1.1 The JCDC Planning Office’s Front Office provides the direction for all Planning Office activities. The JCDC Planning Office also manages all business operations, including: (1) developing and managing the program office plan; (2) developing and managing program and project budget and resources; (3) developing and managing staffing plans and related workforce planning documents; (4) tracking, assigning, and responding to requests for information and executive secretariat taskings; and (5) managing overall program execution.
2.1.2 The Contractor shall provide support for all Front Office functions, by supporting project managers in project planning and execution, customer collaboration, documentation, and follow-up efforts. The Contractor shall provide analytical, planning, documentation and implementation support for performance measurements, metrics analysis and process improvement of office projects and programs.
2.1.3 The Contractor shall:
1) Develop, update, and review Project Management Review (PMR) PowerPoint presentations.
2) Provide and assist with support briefings for leadership and/or external partners by providing the following:
a. Develop and/or review, consolidate, edit technical, management, and operational briefing materials and executive management reports.
b. Prepare and/or present operational briefings to executive management and staff.
c. Develop processes for creating management reports.
d. Prepare management reports.
e. Prepare meeting agendas, attend project meetings, and prepare and distribute meeting minutes.
f. Capture and track meeting action items.
g. Prepare daily, weekly, and ad hoc JCDC Planning Office activity details to report to leadership.
h. Develop format for reports and distribution mechanism.
i. Aid in developing talking points, presentations, documentation, and other communications.
3) Manage training program for JCDC Planning Office:
a. Track and document internal training of Government employees and Contractors.
b. Coordinate external training for Government employees.
4) Coordinate, facilitate and/or participate in technical project management meetings and conferences.
a. Prepare agendas, meeting minutes, and action items. Track action items from beginning to completion.
b. Manage meeting schedules and invitations.
c. Prepare weekly and monthly status reports.
d. Perform other assigned management and administrative tasks related to the office programs/projects, operations, and records.
5) Track and document JCDC Planning Office activities, accomplishments, and deliverables on a weekly, monthly, quarterly, and yearly basis.
2.2 TASK TWO: JCDC Planning Office Governance
2.2.1 The JCDC Planning Office’s governance function leads the development, maintenance, and implementation of the JCDC Planning Office’s internal strategies, policies, processes, and procedures. This function also oversees knowledge management for JCDC Planning Office information and documents.
2.2.2 The Contractor shall:
1) Support the JCDC Planning Office in Developing, maintaining, and implementing JCDC Planning Office-wide program management policies, procedures, processes, templates, and other documents.
2) Develop and implement, at CISA’s direction, a framework for the planning, execution, and prioritization of the JCDC Planning Office’s cyber operations resources and capabilities.
3) Provide process improvement support across JCDC Planning Office functions, to include:
a. Identifying, analyzing, and developing improvements to business processes and methods.
b. Documenting process improvement recommendations including “as is” and “to be” process documentation, and briefing recommendations to JCDC and CSD management.
c. Facilitate implementation of management approved processes.
d. Develop process work products: process descriptions, guidelines, templates, checklists to facilitate process compliance.
e. Provide group facilitation and training for new implemented processes.
f. Continuously refine processes to meet ongoing organizational and business goals.
4) Conduct ongoing organizational lessons learned to identify and document project and process successes and potential improvements.
5) Review and consolidate comments provided by management and staff based on internal and external documents reviews. Review for content, clarity, and grammatical accuracy.
6) Assist with developing workflow documentation (e.g., standard operating procedures, work instructions).
7) Support the development and maintenance of knowledge management principles and processes.
a. Establish and maintain an effective structure for information management and sharing with appropriate stakeholders via agency provided and/or authorized sharing mechanisms which currently include Intelink, SharePoint, Teams, and Confluence/Maestro.
b. Establish and maintain an effective internal branch information sharing and management structure within branch file shares.
c. Build processes and SOPs for information management through SharePoint and organizational file shares.
d. Maintain branch information management SOPs and Policies
8) Create, update, and manage various scheduling tools across the numerous JCDC planning office activity groups to ensure all teams are aligned for cyber incident awareness.
9) Support workforce management and resource planning:
a. Assist the development of organizational structures, staffing plans, position descriptions, hiring and professional development strategies in accordance with the National Initiative for Cybersecurity Education’s (NICE) Workforce Framework for Cybersecurity, support JCDC Planning Office workforce planning.
b. Assist in mapping statutory, policy and organizational requirements to ensure appropriate allocation of staff and resources.
10) Assist with developing JCDC Planning Office metrics and quality assurance by providing the following:
a. Perform quality assurance of documents and other organizational materials.
b. Perform analysis, development and review of program administrative operating plans and procedures.
c. Develop, track, and maintain metrics for Government pilots, and operational planning efforts.
11) Assist with the formulation and coordination and provide input for formal and informal taskers , including but not limited to:
a. Congressional Q&A
b. Media inquiries and talking points
c. GAO audits
d. Leadership briefings
e. Testimony messaging/content
f. Legislative reviews
2.3 TASK THREE. Joint Cyber Defense Planning
2.3.1 The JCDC Planning Office’s joint cyber defense planning function develops deliberate and crisis action plans that enable coordinated cyber defense operations, in coordination with USG, private sector, and state and local partners. The joint cyber defense planning function develops formal plans that leverage the full suite of United States Government (USG) and industry partner operational capabilities in support of cyber defense operations and cybersecurity resilience. This function also pilots new approaches to actively impede or limit the effectiveness of malicious cyber activity for the protection of critical infrastructure through improving situational awareness, information sharing, and joint preparedness.
2.3.2 The Contractor shall:
1) Identify organizational capability, policy, and process gaps across CISA, USG, and outside stakeholders, and develop plans to refine and improve operational processes and procedures.
2) Support CISA in developing and coordinating formal plans for cyber defense operations, to include deliberate and crisis action plans.
a. Facilitate operational planning that aligns with policy guidance and agency priorities and authorities among partners—to include USG; state, local, tribal, and territorial agencies (SLTT); private industry; and international partners—
b. Identify the scope of required planning and develop and manage working groups to ensure representation from all relevant stakeholders across the USG, SLTT, private industry, and international partners.
c. Support working groups convened to develop JCDC frameworks, processes, and plans.
3) Aid in developing preparatory briefings and talking points.
4) Provide research, analysis and recommendations on existing cyber policy and doctrine.
5) Support the execution of joint cyber defense plans.
2.4 TASK FOUR. JCDC Planning Enabling and Execution
2.4.1 The JCDC Planning Office’s future planning function works with USG, industry, and state and local partners to: (1) support the development of a JCDC planning agenda; (2) scope JCDC plans and identify problem statements for these plans; (3) develop core planning teams;
(4) support the execution of cyber defense plans; and (5) measure the effectiveness of JCDC plans. This function also identifies appropriate stakeholder engagement opportunities to share information about the JCDC Planning Office and to receive partner input into JCDC Planning Office activities.
2.4.2 The Contractor shall:
1) Support the JCDC Planning Office’s CISA-wide working group to ensure agency awareness of JCDC planning efforts.
2) Support communication and coordination with internal and external partners.
3) Develop working group schedules, management plans, and other management documentation to govern working group conduct.
4) Prepare meeting agendas, meeting materials, attend project meetings, and prepare and distribute meeting minutes. Capture and track meeting action items.
5) Coordinate document reviews across working group members, consolidate feedback, and prepare revised documents.
6) Support the preparation of outreach materials, such as slick sheets, and other correspondence in engaging working group members.
7) Measure effectiveness of plans when executed in real world scenarios and provide recommendations for improvement, as required.
8) Develop exercises for the JCDC Planning Office and its partners to test plans and capture lessons learned.
9) Provide recommendations for how to improve existing plans or gaps requiring new plans based on lessons learned.
2.5 TASK FIVE. Risk Analysis and Risk Prioritization
2.5.1 The JCDC Planning Office’s risk analysis and risk prioritization function identifies and prioritizes cybersecurity risks to national critical infrastructure to inform the development of cyber operations plans and programs. The JCDC Planning Office integrates information on cyber threats, vulnerabilities, and consequences, and uses resources and capabilities from across public and private sector stakeholders to identify, analyze, and prioritize cybersecurity risks of national significance. The JCDC Planning Office also works closely with CISA Intel and the Intelligence Community (IC) to ensure cyber threat intelligence is integrated into JCDC risk analysis and JCDC joint cyber defense plans. This work supports the development of the JCDC Planning Agenda by providing leadership with an understanding of the greatest cybersecurity risks so they can make informed decisions on the joint cyber defense plan priorities.
2.5.2 The Contractor shall:
1) Support the development of risk analysis models, tools, and methodologies to enable risk prioritization.
2) Support the development of standard risk analysis policies, standard operating procedures, and similar documents to ensure standardized approaches across the JCDC Planning Office.
3) Support the development of risk analysis processes and procedures that incorporate data and capabilities from other CISA offices, USG partners, and nonfederal partners.
4) Maintain a comprehensive understanding of how risk analysis can inform JCDC Planning Office efforts.
5) Identify and collect requirements to support the development of roadmaps, strategies, or plans for analytic tools, software, and platforms.
6) Support the development of methodologies, policies, and procedures for assessing the risk reduction impact of JCDC Planning Office planning and operations.
7) Identify existing information and production efforts on cyber threats, vulnerabilities, and consequences.
8) Prepare recommendations to fill analytic gaps and support risk prioritization.
9) Provide data science expertise to support data integration efforts.
10) Coordinate with CISA Intel and IC partners, including DHS Intelligence and Analysis, to incorporate intelligence into JCDC plans.
11) Monitor intelligence products for the relevance to cyber defense operations and develop recommendations for how to incorporate this intelligence into cyber defense plans and operations.
12) Coordinate with CISA Intel on how to incorporate intelligence into cyber defense plans and operations.
13) Provide recommendations on how to integrate cyber threat intelligence from industry partners with USG intelligence to assist in developing a common operating picture that informs cyber defense plans and operations.
14) Develop and implement, at the direction of CISA, processes for integrating cyber threat intelligence from industry partners with USG intelligence to assist in developing a common operating picture that informs cyber defense plans and operations.
15) Support the JCDC in maintaining the JCDC Intelligence Support Annex—including monitoring, reviewing, and updating the intelligence support process.
16) Establish and maintain an effective structure for information management and sharing with appropriate stakeholders via agency provided and/or authorized sharing mechanisms which currently include Intelink, SharePoint, Teams, and Confluence/Maestro.
2.6 TASK SIX. Adversary-Focused Planning and Coordination
2.6.1 The JCDC Planning Office’s adversary-focused planning and coordination function works closely with USG partners to ensure that CISA equities are represented in whole of government cyber campaign planning efforts and nation state-focused cyber threat working groups, sub-IPCs, and other appropriate events. This function ensures that CISA capabilities are incorporated into unified campaign plans and other whole of government initiatives to address cyber threat activity. This function also identifies ways to integrate cyber campaign planning into cyber defense operations planning efforts. Task six includes contract support to ongoing architecting and operating of the Joint Ransomware Task Force (JRTF). The JRTF is an interagency task force responsible for coordinating federal efforts to address the ransomware threat. It was established in Section 106 of the Cyber Incident Reporting for Critical Infrastructure Act of 2022, is co-led by the Federal Bureau of Investigation (FBI) and is comprised of relevant partners across the interagency.
2.6.2 The Contractor shall:
1) Support coordination for all JRTF-related meetings, including the Executive Steering Group (ESG), Strategic Coordination Group (SCG), and action-officer level working groups. Coordination includes, but is not limited to:
a. Managing meeting logistics.
b. Maintaining coordination with JRTF members and external partners.
c. Developing briefing materials for leadership.
d. Providing subject matter expertise on interagency coordination and combatting ransomware.
2) Support the JCDC Planning Office coordination of ransomware efforts across the agency to ensure CISA equities are understood and inputted into JRTF planning and operations.
3) Support the JCDC Planning Office’s role in the development of cyber campaign plans.
4) Develop, implement, and document repeatable methods and processes to unify CSD efforts and capabilities in support of cyber threat focused planning and plan execution activities.
5) Develop innovative ideas and concepts to expand CSD’s contributions to and equities within unified USG campaign plans and other partner sponsored or whole of government activities to counter, deter, or deny nation state cyber threats.
6) Prepare meeting agendas, meeting materials, attend project meetings, and prepare and distribute meeting minutes. Capture and track meeting action items.
7) Coordinate document reviews across working group members, consolidate feedback, and prepare revised documents.
8) Support the preparation of outreach materials, such as slick sheets, and other correspondence in engaging working group members.
9) Support JCDC Planning Office participation in interagency and White House-led meetings—including but not limited to Cyber Response Group meetings, Interagency Policy Committee (IPC) meetings, and Sub-IPC meetings—by developing talking points, briefing materials, meeting notes, and summaries of conclusion.
10) Support JCDC Planning Office in program management functions related to compartmented intelligence programs.
a. Ensure that these programs align to JCDC objectives and further joint cyber defense planning efforts.
2.7 TASK SEVEN. Intelligence Support and Coordination
2.7.1 The JCDC Planning Office’s intelligence support and coordination function works to provide a holistic, timely, and accurate view and analysis of the cyber threat environment that enables CISA leaders and cyber defense operations planners to make informed decisions. The JCDC Planning Office coordinates the intelligence planning activities by linking planning systems and outputs to JCDC management processes and employ planning methodologies to inform the synchronization of JCDC intelligence resources in support of crisis and steady-state operations. By DHS and CISA policy, JCDC coordinates its intelligence-related activities with the CISA Key Intelligence Official (KIO) and CISA Intel. All intelligence-related work to be conducted under this SOW is to be coordinated with the CISA KIO and CISA Intel, as appropriate, in compliance with DHS and CISA policy.
2.7.2 The Contractor shall:
1) As directed by CISA, support the JCDC in establishing and maintaining relationships with relevant intelligence community (IC) partners to ensure IC input into JCDC joint cyber defense plans and JCDC priority areas.
a. Collaborate with intelligence analysts/targeting organizations involved in related areas.
2) In collaboration with relevant IC partners, support JCDC in identifying and submitting Key Intelligence Questions (KIQs), Priority Intelligence Requirements (PIRs), and Collection Requirements (CRs) that align to JCDC priorities for which the integration of intelligence support is relevant.
3) Monitor for emerging cyber threats or changes to the threat environment.
a. As required, work with relevant IC partners to check holdings for relevant cyber threat intelligence and lead coordination to ensure relevant intelligence is incorporated into the planning process.
b. Monitor CISA internal holdings for relevant commercial cyber threat intelligence that helps inform the threat picture.
c. Analyze cyber threat intelligence from industry partners.
4) Receive and review the initial planning guidance, support JCDC in determining what intelligence is needed to support the plan and, in collaboration with relevant IC partners, support JCDC in facilitating intelligence support.
5) Identify, analyze, and integrate cyber threat intelligence related to core planning team’s development of threat scenario, plan objectives, plan lines of effort, and COAs, and respond to requests for information (RFIs) from core planning team (CPT).
a. Attend and support regular planning CPTs as required.
6) Receive, review, and respond to ad hoc RFIs from JCDC offices, relating to ongoing or future JCDC plans, efforts, or operations.
a. Maintain RFI tool and ensure timely response.
7) Support CISA in working with IC partners to verify appropriate classification of cyber defense plans and associated intelligence and work to downgrade products, as needed.
8) In coordination with relevant IC partners, support CISA in developing intelligence annex and appendices for specific plans and in developing intelligence/threat briefings for JCDC leadership and JCDC Senior Advisory Council (JSAC) review, as needed.
9) In coordination with relevant IC partners, support CISA in planning and organizing threat briefings for external partners, as needed.
10) Support CISA in developing and maintaining any frameworks, processes, or procedures required to formalize how intelligence support and coordination should be conducted within JCDC.
11) Support communication and coordination with internal and external partners.
12) Develop working group schedules, and support the development of management plans, and other management documentation to govern working group conduct.
13) Prepare meeting agendas, meeting materials, attend project meetings, and prepare and distribute Meeting Minutes. Capture and track meeting action items.
14) Support the preparation of briefing materials for senior leadership, partners, and core planning teams.
15) Measure effectiveness of intelligence support and provide recommendations for improvement, as required.
16) Support JCDC Planning Office in program management functions related to compartmented intelligence programs.
a. Ensure that these programs align to JCDC objectives and further joint cyber defense planning efforts.
17) Identify, develop, document, and execute methodologies for incorporating and fusing private sector cyber threat intelligence into JCDC intelligence support.
18) Assist with the coordinating and conducting analytic exchanges involving USG IC partners to develop collaborative and fused concepts, understanding, and support for JCDC operational activities.
2.8 TASK EIGHT. Surge Support (Optional)
2.8.1 Surge support is conducted with the same methodology and procedures and requires the same skills as the work outlined in Tasks 1-7. Surge support is differentiated only by the level of effort and duration of the task requiring surge support, subject to the Government exercising the appropriate CLIN and obtaining funding. Surge support shall be permitted and provided on a Labor Hour basis and only at the direction of the Contracting Officer after advisement by the COR and JCDC leadership. Surge is not intended to be performed as steady state operations. As deemed necessary and as approved by JCDC POL (Branch Chief and Deputy Branch Chief) the Contractor shall provide additional support to meet operational requirements. Surge support will be executed to respond to a cyber event, threat, or national emergency. Once the threat or event has lapsed, the support will resume to steady state levels. The Contractor shall seek advance approval before incurring any surge support. Surge support may require the Contractor staff to work outside normal business hours.
3.0 DELIVERABLES / GOVERNMENT ACCEPTANCE PERIOD
3.1 ACCEPTANCE PERIOD
3.1.1 The COR will review deliverables prior to acceptance and provide the Contractor with an e-mail that provides documented reasons for non-acceptance. If the deliverable is acceptable, the COR will send an e-mail to the Contractor notifying it that the deliverable has been accepted.
3.1.2 The COR will have the right to reject or require correction of any deficiencies found in the deliverables. In the event of a rejected deliverable, the COR will notify the Contractor in writing of the specific reasons for rejection. The Contractor may have an opportunity to correct the rejected deliverable and return it per delivery instructions.
3.1.3 The COR will have 10 business days to review deliverables and make comments. The Contractor shall have 5 business days to make corrections and resubmit.
3.1.4 All other review times and schedules for deliverables shall be agreed upon by the parties based on the final approved Project Plan. The Contractor shall be responsible for timely delivery to Government personnel in the agreed upon review chain, at each stage of the review. The Contractor shall work with personnel reviewing the deliverables to assure that the established schedule is maintained.
3.2 DELIVERABLES
3.2.1 The Contractor shall submit all deliverables via email (electronic format with read/write capability using applications that are compatible with DHS workstations (Microsoft Office Applications), on the appropriate network (depending on classification) to the POC(s) listed in the table below.
3.2.2 The Contractor shall consider items in BOLD as having mandatory due dates. Items in italics are deliverables or events that must be reviewed and/or approved by the COR prior to proceeding to next deliverable or event in this SOW.
Item SOW Para Deliverable/Event Due Distribution
1 3.1
5.9 Weekly team-wide activity reports Weekly JCDC POL
2 2.1
5.9 Monthly team-wide summary of activities Monthly COR, JCDC
POL
3 3.2, 3.5
Process Documentation, workflows, and SOPs As Requested JCDC POL
4 All Working Group Meeting Agendas and Minutes As Requested JCDC POL
5 All Develop and Facilitate Briefings, Memos, and Talking Points As Requested JCDC POL
6 All Program assessment and analysis reports As Requested JCDC POL
7 3.2 Input for Formal and Informal Taskers and RFIs As Requested JCDC POL
8 3.1 Metrics Reports As Requested JCDC POL
9 3.1 5.9
Monthly Financial & Technical Status Report; including projected burn rate Monthly COR, JCDC
POL
10 3.1 5.9
Develop, update, and review Project Management Review (PMR) PowerPoint presentations
Monthly COR, JCDC
POL
11 3.1 Prepare and/or present operational briefings to executive management and staff As Requested JCDC POL
12 3.2 Documenting process improvement As Requested JCDC POL 13 3.2 Provide group facilitation and training As Requested JCDC POL
14 3.1
Prepare and maintain program-specific spend plans, track spending, and provide financial reports to JCDC, CSD, and CISA, as required.
Monthly JCDC POL
15 3.2
Support JCDC in developing JCDC Planning Office-specific doctrine, as required, to ensure a standard approach to cyber operations planning within the Planning Office, CISA, and JCDC partners
As Requested JCDC POL
16 3.4 Develop exercises for JCDC Planning Office and its partners to test plans and capture lessons learned
As Requested JCDC POL
17 3.2
Establish and maintain an effective structure for information management and sharing with appropriate stakeholders via agency provided and/or authorized sharing mechanisms which
30 days from award JCDC POL
Item SOW Para Deliverable/Event Due Distribution currently include Intelink, SharePoint, Teams, and Confluence/Maestro.
18 3.4, 3.7
Develop working group schedules, management plans, and other management documentation to govern working group conduct.
As Requested JCDC POL
19 5.8 Business Continuity Plan 30 days from award
COR, JCDC
POL
Days: Calendar days unless specified otherwise.
4.0 CONTRACTOR PERSONNEL
4.1 Qualified Personnel
The Contractor shall provide qualified personnel to perform all requirements specified in this
SOW.
4.2 Continuity of Support - The Contractor shall ensure that the contractually required level of support for this requirement is appropriately maintained.
4.3 Key Personnel
4.3.1 Before replacing any individual designated as Key by the Government, the Contractor shall notify the Contracting Officer no less than 15 business days in advance, submit written justification for replacement, and provide the name and qualifications of any proposed substitute(s). All proposed substitutes shall possess qualifications equal to or superior to those of the Key person being replaced, unless otherwise approved by the Contracting Officer. The Contractor shall not replace Key Contractor personnel without approval from the Contracting Officer.
The following positions are designated as Key for this requirement:
Position Minimum Education/Experience TASK 1: JCDC Planning Office Front Office - Program Manager
Minimum of 10 years of experience, of which at least 8 years must be specialized experience in project development from inception to deployment, expertise in the management and control of funds and resources using complex reporting mechanisms and demonstrated capability in managing multitask contracts of the same or similar magnitude. The PM shall lead a team that supports CISA's execution of its joint cyber planning authorities--including planning and coordinating with the Intelligence Community and other US Government partners, state and local governments, international partners, and the private sector.
TASK 2: JCDC Planning Office Governance – Project/Business Analyst III
Minimum of 8 years of experience in developing and improving business processes for government or private sector organizations. This position requires extensive
Position Minimum Education/Experience experience analyzing mission requirements to determine what resources and skills are needed to meet objectives.
TASK 3: Joint Cyber Defense Planning - Cyber Operations Planner III
Minimum 8 years of experience developing operational plans that drive defensive or offensive cyber operations. This experience must demonstrate the ability to work with a wide range of partners, preferably including private sector partners, on complex cybersecurity topics. Experience in technical writing and editing, as well as cyber incident management, is preferred.
TASK 4: JCDC Plan Enabling and Execution - Cyber Partner Integration Planner III
Minimum of 8 years’ experience facilitating the development and execution of cyber operations plans across multiple organizations, either public or private. This experience should demonstrate the ability to integrate partners from multiple teams with distinct disciplines into a unified planning effort.
TASK 5: Risk Analysis and Risk Prioritization - Senior Risk and Vulnerability Analyst
Minimum of 8 years of experience using cyber threat intelligence and cyber vulnerability data to develop cyber risk analyses that inform organizational prioritization and cyber operations. This experience must demonstrate proficiency in understanding how to use various data sets and sources of information to develop a defensible and repeatable risk analysis methodology.
TASK 6: Adversary-focused Planning and Coordination - Cyber Operations Planner III
Minimum of 8 years of experience developing operational plans that drive defensive or offensive cyber operations. This experience must demonstrate the ability to work with a wide range of partners, preferably including private sector partners, on complex cybersecurity topics. Experience in technical writing and editing, as well as cyber incident management, is preferred.
TASK 7: Intelligence Support and Coordination - Cyber Intelligence Planner III
Minimum of 8 years of experience developing detailed intelligence plans to satisfy cyber operations requirements.
This experience must demonstrate proficiency in collaborating with cyber operations planners and cyber partner integration planners to identify, validate, and levy requirements for the collection and analysis of cyber threat intelligence.
Key Personnel resumes shall include, to the extent feasible, experience related to the SOW tasks.
4.3.2 The Contractor shall provide a Program Manager (PM) who shall be responsible for the performance of the work and provide overall direction to Contractor personnel working under this contract.
4.3.3 The PM shall be available during normal work hours to meet with CISA leadership in person or as otherwise agreed upon by CISA leadership to discuss problem areas. After normal duty hours, the PM shall be available in accordance with CISA approved escalation procedures.
In the event of disaster recovery or Continuity of Operations (COOP) events, the PM shall be available during periods of no-notice emergencies, including localized acts of nature, accidents, and military or terrorist attacks to plan, direct, and control the overall management and operational functions specified herein.
4.3.4 The PM is also responsible for management and delivery of the quarterly Program Management Reviews (PMRs).
4.3.5 The PM shall be available to the COR via telephone between the hours of 0800 and 1700 EST, Monday through Friday, and shall respond to a request for discussion or resolution of technical problems within two (2) hours of notification.
4.4 Employee Identification
4.4.1 Contractor employees visiting Government facilities shall wear an identification badge that, at a minimum, displays the Contractor name, the employee’s photo, name, clearance-level, and badge expiration date. Visiting Contractor employees shall comply with all Government escort rules and requirements. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent and display all identification and visitor badges in plain view above the waist at all times.
4.4.2 Contractor employees working on-site at Government facilities shall wear a Government issued identification badge. All Contractor employees shall identify themselves as Contractors when their status is not readily apparent (in meetings, when answering Government telephones, in e-mail messages, etc.) and display the Government issued badge in plain view above the waist at all times.
4.5 Employee Conduct
4.5.1 Contractor’s employees shall comply with all applicable Government regulations, policies, and procedures (e.g., fire, safety, sanitation, environmental protection, security, “off limits” areas, wearing of parts of DHS uniforms, and possession of weapons) when visiting or working at Government facilities. The Contractor shall ensure Contractor employees present a professional appearance at all times and that their conduct shall not reflect discredit on the United States or the Department of Homeland Security. The Program Manager shall ensure Contractor employees understand and abide by Department of Homeland Security established rules, regulations and policies concerning safety and security.
4.5.2 Removing Employees for Misconduct or Security Reasons
The Government may, at its sole discretion (via the Contracting Officer), direct the Contractor to remove any Contractor employee from DHS facilities for misconduct or security reasons.
Removal does not relieve the Contractor of the responsibility to continue providing the services required under the contract. The Contracting Officer will provide the Contractor with a written explanation to support any request to remove an employee.
4.6 Security Requirements for Personnel
This SOW requires all Contractor personnel to maintain a Top-Secret security clearance and eligibility for access to Sensitive Compartmented Information (SCI).
5.0 OTHER APPLICABLE CONDITIONS
5.1 Security
Contractor personnel will require access to Top Secret classified information and access to Sensitive Compartmented Information (SCI). Contractor personnel must obtain and retain a Top-Secret clearance and obtain and retain SCI eligibility/access during the performance of the contract.
All Contractor personnel assigned to this task must be U.S. Citizens and meet the requirements contained in DHS Instruction Handbook 121-01-007-Department of Homeland Security Personnel Suitability and Security Program.
Contractor’s request for visit authorization to the Government facility located at the 1110 N.
Glebe Road, Arlington, VA Government facility shall be submitted in accordance with the Glebe Road facility visitor policy. Contractor’s request for visit authorization to the Government facility located at 4601 N. Fairfax Drive, Arlington, VA Government facility shall be submitted in accordance with the Ballston facility visitor policy. Upon request, a copy of each policy will be provided.
5.1.1 Contractor access to CISA Sensitive Information, systems, networks, and reoccurring access to CISA facilities up to the TS/SCI level is required under this SOW; therefore, contractor employees will require DHS Fitness Determination to perform work.
5.1.2 Contract Company must obtain and retain an active final Top Secret facility clearance (FCL), and Safeguarding Level as None granted by the Defense Counterintelligence and Security Agency (DCSA) at the time of solicitation/proposal submission. DHS does not accept Interim FCLs.
5.1.3 Sensitive Information is defined in the DHS Instruction Handbook, 121-01-007, “The Department of Homeland Security, Personnel Security, Suitability and Fitness Program” as “Any information, the loss, misuse, disclosure, unauthorized access to, or modification of, which could adversely affect the national or homeland security interest, the conduct of Federal programs, or the privacy to which individuals are entitled under section 552a of Title 5, United States Code (the Privacy Act), but which has not been specifically authorized under criteria by an Executive Order or an Act of Congress to be kept secret in the interests of national defense, homeland security, or foreign policy. This definition includes one of the following categories of information:
1) Protected Critical Infrastructure Information (PCII) as described in the Critical Infrastructure Information Act of 2002, 6 U.S.C. section 21 1-224; its implementing regulations, 6 C.F.R. Part 29; or the applicable PCII Procedures Manual; or
2) Sensitive Security Information (SSI), as described in 49 C.F.R. Part 1520; or
3) Sensitive but Unclassified Information (SBU) -For Official Use Only -, which consists of any other information which:
a. If provided by the government to the Contractor, is marked in such a way to place a reasonable person on notice of its sensitive nature.
b. Is designated "sensitive" in accordance with subsequently adopted homeland security information handling requirements.”
5.2 Post-Award Instructions Regarding Security Requirements for Contracts/Orders
5.2.1 The procedures outlined below shall be followed for the DHS CISA Personnel Security Division (PSD) to process background investigations, Entry on Duty determinations, and Fitness determinations, as required, in a timely and efficient manner.
5.2.2 Carefully read the security clauses in the contract. Compliance with the security clauses in the contract is not optional.
5.2.3 Contractor employees (to include applicants, temporaries, part-time and replacement employees) under the contract, requiring access to sensitive information, shall undergo a position-sensitivity analysis based on the duties each individual will perform on the contract. The results of the position sensitivity analysis shall identify the appropriate background investigation to be conducted. All background investigations will be processed through the DHS CISA/PSD.
Prospective contractor employees shall submit the below completed forms to the DHS CISA/PSD. The Standard Form (SF) 85-P must be completed electronically through the Office of Personnel Management’s e-QIP SYSTEM. The SF-85P signature pages and other completed forms must be given to the OSCO/PSD no less than thirty (30) days before the start date of the contract or thirty (30) days prior to the requested entry on duty date, for all contractor employees whether a replacement, addition, subcontractor employee, or vendor:
1) Standard Form (SF) 85-P, ―Questionnaire for Public Trust Positions
2) SF-85P Certification
3) SF-85P Authorization for Release of Information
4) FD Form 258, ―Fingerprint Card (2 copies)
5) DHS Form 11000-6 ―Conditional Access To Sensitive But Unclassified Information
Non-Disclosure Agreement
6) DHS Form 11000-9, ―Disclosure and Authorization Pertaining to Consumer Reports
Pursuant to the Fair Credit Reporting Act
7) Only complete packages will be accepted by the DHS OCSO/PSD. Specific instructions on submission of packages will be provided upon award of the contract.
5.2.4 The DHS CISA/PSD may, as it deems appropriate, authorize, and grant a favorable Entry on Duty (EOD) decision based on preliminary checks. A favorable EOD decision allows a contractor employee to commence work temporarily prior to the completion of the full background investigation. The granting of a favorable EOD decision shall not be considered as assurance that a favorable Fitness determination will follow. In addition, a favorable EOD or Fitness determination shall in no way prevent, preclude, or bar DHS from withdrawing or terminating access to government facilities or information, at any time during the term of the contract. No employee of the Contractor shall be allowed unescorted access to a Government facility without a favorable EOD or Fitness determination by the DHS CISA/PSD.
5.2.5 Limited access to Government buildings is allowable without an EOD decision if the Contractor is escorted by a Government employee and the purpose of the visit is to attend a limited number of required briefings or nonrecurring meetings in order to facilitate the transition of a contract. The intent of this statement is to allow a minimum amount of meeting / transition attendances to prepare for the new contract.
5.2.6 The CISA/PSD shall be notified of all terminations/resignations within five days of occurrence. The Contractor shall return to the Contracting Officer’s Representative (COR) all DHS issued identification cards and building passes that have either expired or have been collected from terminated employees. If an identification card or building pass is not available to be returned, a report shall be submitted to the COR, referencing the pass or card number, name of individual to whom it was issued and the last known location and disposition of the pass or card.
5.3 Period of Performance
The period of performance is one 12-month base period and two 12-month option periods.
Period of Performance Date Base Period 07/01/2024 - 06/30/2025 Option Period 1 07/01/2025 - 06/30/2026 Option Period 2 07/01/2026 - 06/30/2027
5.4 Place of Performance
5.4.1 The place of performance will be a combination of the Department of Homeland Security facilities and contractor’s personal residence when telework is authorized by Federal Lead. All employees performing work with an SCI delegation will be performing work within Government Sensitive Compartmented Information Facility (SCIF). The SCIF location is 4601 Fairfax Drive, Arlington VA 22201 and 1110 N. Glebe Road, Arlington VA 22201.
5.4.2 DHS Facility Locations
4601 Fairfax Drive, Arlington, VA 22201 1110 N Glebe Road, Arlington, VA 22201 4200 Wilson Boulevard, Arlington, VA 22203
5.4.3 Contractor Facility Location
TBD
5.5 Contractor Telework/Remote Personal Residence Work Locations
5.5.1 Teleworking for federal government contractors will be considered on a situational basis to the extent practicable to meet DHS mission needs. Teleworking allows contractor personnel to perform their contractual requirements outside of the designated CISA office locations, typically at a contractor’s personal residence or a corporate telecommuting office location.
Telework for contractor personnel provides the government flexibility to meet unique CISA organizational and facility needs and requirements. The goal of teleworking for Contractor personnel is to enhance the delivery of services that support the DHS mission. Teleworking is permitted under the contract in accordance with the requirements below. All work performed outside of the identified Contractor and or Government facilities will be performed at the Unclassified FOUO level and ensuring access to personnel who are authorized access.
5.5.2 Additionally, the provision to permit contractor telecommuting may be revoked at the contract level at any time if the Government makes such determination. The telecommuting provision does not change any contract requirements; all other terms and conditions of the contract remain in full force and effect.
5.5.3 The Contractor shall charge the same applicable fixed hourly rate as for a Government site for those Contractor personnel when they telecommute at their designated telecommuting location.
5.6 Hours of Operation
Contractor employees shall generally perform all work between the hours of 0800 and 1700EST, Monday through Friday (except Federal holidays). However, there may be occasions when Contractor employees shall be required to work other than normal business hours, including weekends and holidays, to fulfill requirements under this SOW. Additionally, the Contractor may be required to support 24X7 coverage during normal operations and in response to CISA’s enhanced operations due to a major cyber event or significant cyber incident.
5.7 Travel
Contractor travel is not required for this requirement.
5.8 Business Continuity Plan
5.8.1 The Contractor shall prepare and submit a Business Continuity Plan (BCP) to the Government. The BCP Plan shall be due 30 business days after the date of award and will be updated on an annual basis. The BCP shall document Contractor plans and procedures to maintain support during an emergency, including natural disasters and acts of terrorism. The BCP, at a minimum, shall include the following:
1) A description of the Contractor’s emergency management procedures and policy.
2) A description of how the Contractor will account for their employees during an emergency.
3) How the Contractor will communicate with the Government during emergencies.
4) A list of primary and alternate Contractor points of contact, each with primary and alternate:
a. Telephone numbers
b. E-mail addresses
5.8.2 Individual BCPs shall be activated…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .