4.01a Attachment 1 - SOW.pdf
PDF 118 KB Posted
- Attached to
- Risk Management Framework Support Services Federal contract opportunity
- Solicitation number
- N0060425Q4076
About this file
This Statement of Work (SOW) details Risk Management Framework (RMF) support services for the Arctic Submarine Laboratory (ASL), focusing on cybersecurity monitoring and Windows operating system upgrades for the Virginia Ice Capability Equipment (VICE) and Seawolf Arctic TEMPALT (SWAT) systems. The contractor's primary responsibilities include conducting annual security reviews, executing vulnerability management plans, transitioning systems from Windows 7/10 to Windows 11, performing regression testing, and preparing documentation for Authority to Operate (ATO) certification.
Key contract details include a 365-day performance period starting from award, with work to be performed at 53370 Cabrillo Memorial Drive in San Diego, CA. The scope encompasses comprehensive cybersecurity services such as testing security controls, performing ACAS/SCAP scans, applying Security Technical Implementation Guides (STIGs), updating system documentation, and integrating Windows 11 configurations. The contractor will be required to work closely with ASL engineers, document findings in eMASS, and address any identified cybersecurity vulnerabilities throughout the monitoring process.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| 4.03a N0060425Q4076 Q&As.pdf | ||
| 4.01c Attachment 3 - 52.212-3 CD & 52.204-24.pdf | ||
| 4.01d Attachment 4 - WD 2015-5635 Rev 27.pdf | ||
| 4.01b Attachment 2 - J&A_Redacted.pdf | ||
| 4.01e Attachment 5 - Applicable FAR & DFARS.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Statement of Work (SOW)
Arctic Submarine Laboratory (ASL) Risk Management Framework (RMF) Support Services
1. Introduction. The following Statement of Work (SOW) outlines the Risk Management Framework (RMF) efforts necessary to support Continuous Monitoring and Windows 11 upgrades for the Virginia Ice Capability Equipment (VICE) and the Seawolf Arctic TEMPALT (SWAT) at the Arctic Submarine Laboratory (ASL).
2. Scope. The contractor shall generate documentation required to meet RMF requirements and submit required documentation to the Arctic Submarine Laboratory (ASL) as required in support of Assess & Authorize (A&A), Assess Only (AO), and Non-IT packages for ASL systems. All RMF activities shall follow the most current applicable guidance including DON RMF Process Guide, DoD Instruction 8510.01, NAVSEA Business Rules, NAVSEA Standard Operating Procedures (SOPs), and the business rules of cognizant review offices for each package. These efforts include, but are not limited to:
a. VICE Continuous Monitoring Cybersecurity Services
1. Conduct and document annual security review including testing security controls, ACAS/SCAP scans and necessary STIGs. Document findings in eMASS.
2. Execute tasking outlined in POA&M.
3. Execute vulnerability and patch management plan.
4. Continue transitioning VICE embedded subsystem from Windows 7 to
Windows 10 operating system, the contractor shall review security documentation provided by the vendor to address pertinent cybersecurity controls. Noted deficiencies shall be added to the POA&M with appropriate mitigation statements.
5. The contractor shall upgrade the SeaBird and SideScan Operating Systems (OS) from Windows 10 to Windows 11, install VICE related applications, and apply all applicable STIGs to the system. The contractor shall update the POA&M with any outstanding vulnerabilities.
6. The contractor shall work with ASL engineers and perform regression testing to ensure VICE applications function properly after STIGs have been applied to the Windows 11 systems.
7. Provide other cybersecurity analysis and engineering services as required to support continuous monitoring.
b. SWAT Continuous Monitoring Cybersecurity Services
1. Conduct and document annual security review including testing security controls, ACAS/SCAP scans and necessary STIGs. Document findings in eMASS.
2. Execute tasking outlined in POA&M.
3. Execute vulnerability and patch management plan.
4. Continue transitioning VICE/SWAT embedded subsystem from Windows 7 to
Windows 10 operating system, the contractor shall review security documentation provided by the vendor to address pertinent cybersecurity controls. Noted deficiencies shall be added to the POA&M with appropriate mitigation statements.
5. The contractor shall upgrade the SeaBird and SideScan Operating Systems (OS) from Windows 10 to Windows 11, install VICE/SWAT related applications, and apply all applicable STIGs to the system. The contractor shall update the POA&M with any outstanding vulnerabilities.
6. The contractor shall work with ASL engineers and perform regression testing to ensure VICE/SWAT applications function properly after STIGs have been applied to the Windows 11 systems.
7. Provide other cybersecurity analysis and engineering services as required to support continuous monitoring.
c. Windows 11 ATO Certification Upgrade Support Services
The contractor shall provide the necessary documentation for ATO Package submission and monitor progress of the ATO approval process including addressing feedback from the Package Submitting Office (PSO), Security Control Assessor Liaison (SCA-L), or Navy Authorizing Official (NAO)/ Functional Authorizing Official (FAO).
Tasking:
1. Review and update documentation in eMASS as required.
2. Update hardware and software configuration documentation and system diagrams.
3. The contractor shall integrate Windows 11 as a Use Case into
VICE/SWAT platform.
4. The contractor shall provide a Navy Qualified Validator to perform the necessary scans, (e.g., Assured Compliance Assessment System (ACAS), Security Content Automation Protocol (SCAP), etc.), run all relevant Security Development Security Technical Implementation Guidance (STIG), and present all findings discovered during testing in a report.
5. The contractor shall assist ASL in developing the Windows 11 Security Assessment Plan
6. The contractor shall update the continuous monitoring strategy to include Windows 11 configurations
3. Base Access
On-site access shall be coordinated with the Point of Contact (POC).
4. Period of Performance
365 Days from Award
5. Place of Performance
Arctic Submarine Laboratory
53370 Cabrillo Memorial Drive, Bldg. 370 San Diego, CA 92152
6. Point of Contact
TBD
File details come from the government source that posted it. Updated .