4.01a Attachment 1 - SOW.pdf

PDF 118 KB Posted

Attached to
Risk Management Framework Support Services Federal contract opportunity
Solicitation number
N0060425Q4076
Issued by
Department of the Navy Naval Supply Systems Command

About this file

This Statement of Work (SOW) details Risk Management Framework (RMF) support services for the Arctic Submarine Laboratory (ASL), focusing on cybersecurity monitoring and Windows operating system upgrades for the Virginia Ice Capability Equipment (VICE) and Seawolf Arctic TEMPALT (SWAT) systems. The contractor's primary responsibilities include conducting annual security reviews, executing vulnerability management plans, transitioning systems from Windows 7/10 to Windows 11, performing regression testing, and preparing documentation for Authority to Operate (ATO) certification.

Key contract details include a 365-day performance period starting from award, with work to be performed at 53370 Cabrillo Memorial Drive in San Diego, CA. The scope encompasses comprehensive cybersecurity services such as testing security controls, performing ACAS/SCAP scans, applying Security Technical Implementation Guides (STIGs), updating system documentation, and integrating Windows 11 configurations. The contractor will be required to work closely with ASL engineers, document findings in eMASS, and address any identified cybersecurity vulnerabilities throughout the monitoring process.

View the file

Other files for this federal contract opportunity

Other files attached to Risk Management Framework Support Services, newest first.
File Type Posted
4.03a N0060425Q4076 Q&As.pdf PDF
4.01c Attachment 3 - 52.212-3 CD & 52.204-24.pdf PDF
4.01d Attachment 4 - WD 2015-5635 Rev 27.pdf PDF
4.01b Attachment 2 - J&A_Redacted.pdf PDF
4.01e Attachment 5 - Applicable FAR & DFARS.pdf PDF

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Statement of Work (SOW)

Arctic Submarine Laboratory (ASL) Risk Management Framework (RMF) Support Services

1. Introduction. The following Statement of Work (SOW) outlines the Risk Management Framework (RMF) efforts necessary to support Continuous Monitoring and Windows 11 upgrades for the Virginia Ice Capability Equipment (VICE) and the Seawolf Arctic TEMPALT (SWAT) at the Arctic Submarine Laboratory (ASL).

2. Scope. The contractor shall generate documentation required to meet RMF requirements and submit required documentation to the Arctic Submarine Laboratory (ASL) as required in support of Assess & Authorize (A&A), Assess Only (AO), and Non-IT packages for ASL systems. All RMF activities shall follow the most current applicable guidance including DON RMF Process Guide, DoD Instruction 8510.01, NAVSEA Business Rules, NAVSEA Standard Operating Procedures (SOPs), and the business rules of cognizant review offices for each package. These efforts include, but are not limited to:

a. VICE Continuous Monitoring Cybersecurity Services

1. Conduct and document annual security review including testing security controls, ACAS/SCAP scans and necessary STIGs. Document findings in eMASS.

2. Execute tasking outlined in POA&M.

3. Execute vulnerability and patch management plan.

4. Continue transitioning VICE embedded subsystem from Windows 7 to

Windows 10 operating system, the contractor shall review security documentation provided by the vendor to address pertinent cybersecurity controls. Noted deficiencies shall be added to the POA&M with appropriate mitigation statements.

5. The contractor shall upgrade the SeaBird and SideScan Operating Systems (OS) from Windows 10 to Windows 11, install VICE related applications, and apply all applicable STIGs to the system. The contractor shall update the POA&M with any outstanding vulnerabilities.

6. The contractor shall work with ASL engineers and perform regression testing to ensure VICE applications function properly after STIGs have been applied to the Windows 11 systems.

7. Provide other cybersecurity analysis and engineering services as required to support continuous monitoring.

b. SWAT Continuous Monitoring Cybersecurity Services

1. Conduct and document annual security review including testing security controls, ACAS/SCAP scans and necessary STIGs. Document findings in eMASS.

2. Execute tasking outlined in POA&M.

3. Execute vulnerability and patch management plan.

4. Continue transitioning VICE/SWAT embedded subsystem from Windows 7 to

Windows 10 operating system, the contractor shall review security documentation provided by the vendor to address pertinent cybersecurity controls. Noted deficiencies shall be added to the POA&M with appropriate mitigation statements.

5. The contractor shall upgrade the SeaBird and SideScan Operating Systems (OS) from Windows 10 to Windows 11, install VICE/SWAT related applications, and apply all applicable STIGs to the system. The contractor shall update the POA&M with any outstanding vulnerabilities.

6. The contractor shall work with ASL engineers and perform regression testing to ensure VICE/SWAT applications function properly after STIGs have been applied to the Windows 11 systems.

7. Provide other cybersecurity analysis and engineering services as required to support continuous monitoring.

c. Windows 11 ATO Certification Upgrade Support Services

The contractor shall provide the necessary documentation for ATO Package submission and monitor progress of the ATO approval process including addressing feedback from the Package Submitting Office (PSO), Security Control Assessor Liaison (SCA-L), or Navy Authorizing Official (NAO)/ Functional Authorizing Official (FAO).

Tasking:

1. Review and update documentation in eMASS as required.

2. Update hardware and software configuration documentation and system diagrams.

3. The contractor shall integrate Windows 11 as a Use Case into

VICE/SWAT platform.

4. The contractor shall provide a Navy Qualified Validator to perform the necessary scans, (e.g., Assured Compliance Assessment System (ACAS), Security Content Automation Protocol (SCAP), etc.), run all relevant Security Development Security Technical Implementation Guidance (STIG), and present all findings discovered during testing in a report.

5. The contractor shall assist ASL in developing the Windows 11 Security Assessment Plan

6. The contractor shall update the continuous monitoring strategy to include Windows 11 configurations

3. Base Access

On-site access shall be coordinated with the Point of Contact (POC).

4. Period of Performance

365 Days from Award

5. Place of Performance

Arctic Submarine Laboratory

53370 Cabrillo Memorial Drive, Bldg. 370 San Diego, CA 92152

6. Point of Contact

TBD

File details come from the government source that posted it. Updated .