A03 Draft PWS - Hack the Actual Pentagon 3.0 PenTest - Revised v2.docx
DOCX document 63 KB Posted
- Attached to
- Hack the Pentagon 3. 0 Pen Test Federal contract opportunity
- Solicitation number
- HQ003423R0073
- Issued by
- DOD Washington Headquarters Service
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
PERFORMANCE WORK STATEMENT (PWS)
ICS/SCADA-OT Penetration Test and Cyber Assessment Services Hack the Pentagon 3.0 January 11, 2023
Part 1
General Information
1. GENERAL: This is a non-personal services contract to provide an Industrial Control Systems/Supervisory Control And Data Acquisition-Operational Technology (ICS/SCADA-OT) Penetration Test and Cyber Assessment exercise (“Assessment” in short) of the Government’s Washington Headquarters Services (WHS) Facilities Services Directorate (FSD) Facility Related Controls System (FRCS) network. The Government shall not exercise any supervision or control over the contract service providers performing the services herein. Such contract service providers shall be accountable solely to the Contractor who, in turn is responsible to the Government.
1.1 Description of Services/Introduction: The Contractor shall provide all personnel, equipment, supplies, facilities, transportation, tools, materials, supervision, and other items and non-personal services necessary to perform the Assessment on the FRCS network as defined in this Performance Work Statement (PWS) except for those items specified as Government furnished property and services. The Contractor shall perform to the standards in this contract.
1.2 Background: The DoD’s computer networks and systems support the Nation’s defense and are critical both for daily business operations and Mission Critical activities. Maintaining the security, confidentiality, availability and integrity of the DoD’s networks and systems is a matter of national security and requires the continuous identification and remediation of vulnerabilities that can be exploited by malicious cyber actors. As part of its responsibility to the public at large, DoD is constantly considering innovative and diverse approaches to meet this goal.
To support DoD’s continual efforts to remain at the forefront of rapidly evolving technologies, and to maintain the highest levels of integrity and security required of its IT infrastructure, DoD has identified the need to leverage highly skilled cybersecurity experts with specific expertise in ICS/SCADA and OT systems, for so-called penetration tests (“pen tests”), cybersecurity assessment, and recommendations for cybersecurity improvement.
FSD is responsible for providing facility management support for the National Capital Region (NCR). FSD also provides administrative and operational support to a vast array of Department of Defense (DOD) activities. Within this Directorate are many programs designed to support all personnel working in the managed and leased buildings overseen by WHS. Of these programs, the Federal Facilities Division (FFD) is responsible for operating and maintaining of the Pentagon Reservation and NCR.
FFD is composed of two building management field offices; one of these offices is the Pentagon Building Management Office (PBMO). PBMO is responsible for all operations and maintenance for the Pentagon, which includes – but is not limited to – the utilities, vertical transportation systems, fire protection systems, and FRCS Network. This PWS requests execution of crowdsourcing practices on the Pentagon FRCS Network.
Overall contract management will be accomplished by WHS FSD.
The FFD is responsible for operating and maintaining the Pentagon Reservation. The Pentagon Reservation includes the Pentagon Building, the Pentagon Heating and Refrigeration Plant (PHRP), the Modular Office Complex (MOC), all ancillary buildings and all Reservation grounds and parking areas.
PBMO is the Reservation facility management office. PBMO is responsible for the Pentagon Building, the MOC, and related grounds and parking areas.
PBMO’s Operations and Maintenance (O&M) program will serve as the Government Point Of Contact (POC) for FSD’s Crowdsourced Vulnerability Discovery and Disclosure exercise of the Pentagon FRCS Network.
1.3 Objectives: With the assistance of the private sector, the Government intends to use existing commercial ICS/SCADA-OT security expertise and best practices, tailored for the Government’s use, to support the DoD in order to enhance its information security. In support of this objective, the DoD intends to partner with a commercial firm(s) that has extensive experience with ICS/SCADA-OT pen testing and assessment activities as a service. Under the resulting Contract, the firm(s) will host an Assessment on behalf of the DoD. Within DoD, Defense Digital Services (DDS) is mandated per OSD/DOD directive 5105.87 to manage technical risks and vulnerabilities, and intends this program to address those risks and vulnerabilities. The overall objective is to obtain support from leading commercial providers in this area for vulnerability discovery, coordination and disclosure activities, assess the current cybersecurity posture of the FRCS Network, identify weaknesses and vulnerabilities, and provide recommendations to improve and strengthen the overall security posture.
1.4 Scope: WHS FSD desires to execute an Assessment program, which will involve unclassified Information Systems and operational technology contained within the Pentagon FRCS Network. The Contractor shall provide all labor, material, equipment, hardware, software and training required to assess the current cybersecurity posture of the FRCS Network, identify weaknesses and vulnerabilities, and provide recommendations to improve and strengthen the overall security posture.
These are sensitive Government assets; therefore, the Contractor will be required to leverage skilled and trusted employees and/or subcontractors, which may be limited to US persons only, with eligibility criteria established by the DoD. Staff conducting the Assessment must be diverse in skillset, and able to conduct penetration testing, reverse engineering, and network and system exploitation in an ICS/SCADA-OT environment.
1.5 Contract Period of Performance: The period of performance for the Contract is the time the Contractor has to operate and manage the Assessment. The start and end dates will be determined upon award of the Contract. The Contract Period of Performance shall be for 12 months.
1.6 Period of Performance to Operate and Manage the Assessment: The Period of Performance to operate and manage the Assessment is the period in which the Contractor has to complete Planning, Onsite Execution, and Post-execution (i.e., final report and recommendations delivery) phases.
The allowed time to complete the three phases to operate and manage the Assessment is not to exceed 16 weeks.
1.6 General Information
1.6.1 Quality Control: The Contractor shall develop and maintain an effective Quality Control Plan (QCP) to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services. The Contractor’s QCP is the means by which it assures itself that its work complies with the requirements of the contract. Within 30 days after contract award, the Contractor shall submit three copies of a comprehensive written QCP to the Contracting Officer (KO) and Contracting Officer’s Representative (COR), and the same within five business days following any Contract changes. After acceptance of the QCP, the Contractor shall receive the KO’s acceptance in writing of any proposed change to its quality control system.
1.6.2 Quality Assurance: The Government shall evaluate the Contractor’s performance under this contract in accordance with the Quality Assurance Surveillance Plan. This plan is primarily focused on what the Government must do to ensure that the Contractor has performed in accordance with the performance standards. It defines how the performance standards will be applied, the frequency of surveillance, and the minimum acceptable defect rate(s).
1.6.3 Recognized Holidays: [Reference 5 U.S.C. §6103.]
New Year’s Day, January 1.
Martin Luther King Jr.’s Birthday, the third Monday in January.
President’s Day, the third Monday in February.
Memorial Day, the last Monday in May.
Juneteenth National Independence Day, June 19.
Independence Day, July 4.
Labor Day, the first Monday in September.
Columbus Day, the second Monday in October.
Veterans Day, November 11.
Thanksgiving Day, the fourth Thursday in November.
Christmas Day, December 25.
1.6.3.1 In addition to the days designated as holidays, the Government observes the following days:
· Any other day designated by Federal Statue
· Any other day designated by Executive Order
· Any other day designated by the President’s Proclamation.
1.6.4 Hours of Operation: The Contractor is generally responsible for conducting business, between the hours of 6:00 a.m. through 4:00 p.m. Monday thru Friday except Federal holidays or when the Government facility is closed due to local or national emergencies, administrative closings, or similar Government directed facility closings. PBMO O&M and the Contractor may also mutually agree additional and/or different hours of operation for conduct of the Assessment.
The Contractor must at all times maintain an adequate workforce for the uninterrupted performance of all tasks defined within this PWS when the Government facility is not closed for the above reasons. When hiring personnel, the Contractor shall keep in mind that the stability and continuity of the workforce are essential.
1.6.5 Place of Performance: The Government expects that the majority of the work to be performed under this contract will be performed onsite at the Pentagon Reservation and ancillary buildings. There will be no remote/telework capabilities for the any work performed under this contract. If required, Contractor access to DoD facilities will be arranged for on-site meetings and execution of work as outlined in this PWS.
1.6.6 Type of Contract: The Government will award a firm fixed priced contract.
1.6.7 Security Requirements:
The Contractor shall ensure that researchers are not on the Government’s terrorist/prohibited persons list, are not residing in a prohibited country, and meet the selection requirements with respect to nationality (US only, “Five Eyes” only, etc.) as specified in the Contract.
ContractContract1.6.7.1 Physical Security: The Contractor shall be responsible for safeguarding all Government equipment, information and property provided for Contractor use. At the close of each work period, Government facilities, equipment, and materials shall be secured.
1.6.7.2 Key Control:
1.6.8 Post Award Conference/Periodic Progress Meetings: The Contractor agrees to attend any post award conference convened by the contracting activity or contract administration office in accordance with Federal Acquisition Regulation Subpart 42.5. The KO, COR, and other Government personnel, as appropriate, may meet periodically with the Contractor to review the Contractor's performance. At these meetings the contracting officer will apprise the Contractor of how the Government views the Contractor's performance and the Contractor will apprise the Government of problems, if any, being experienced. Appropriate action shall be taken to resolve outstanding issues. These meetings shall be at no additional cost to the Government. The Contractor is responsible for taking the meeting minutes and submitting them for review within five (5) working days after the meeting.
1.6.8.1 Monthly Status Report: Reporting requirements for the monthly status reports will be outlined at the initial orientation meeting. The report will be due prior to the 10th of the month. It is expected that these will include, but not be limited to:
1) Program Status, to include objectives met, work completed and work outstanding
2) Issues or obstacles impeding progress and recommended solutions
3) Status of deliverables/milestone
4) Issues and resolutions
5) Resources planning/status
6) Topics or issues identified by the Government COR
7) Budget total to include costs to date and for the reporting period.
1.6.9 Contracting Officer Representative (COR): The (COR) will be identified by separate letter. The COR monitors all technical aspects of the contract and assists in contract administration The COR is authorized to perform the following functions: assure that the Contractor performs the technical requirements of the contract: perform inspections necessary in connection with contract performance: maintain written and oral communications with the Contractor concerning technical aspects of the contract: issue written interpretations of technical requirements, including Government drawings, designs, specifications: monitor Contractor's performance and notifies both the Contracting Officer and Contractor of any deficiencies; coordinate availability of Government furnished property, and provide site entry of Contractor personnel. A letter of designation issued to the COR, a copy of which is sent to the Contractor, states the responsibilities and limitations of the COR, especially regarding changes in cost or price, estimates or changes in delivery dates. The COR is not authorized to change any of the terms and conditions of the resulting Contract.
1.6.10 Inherently Governmental Functions: No inherently Governmental functions as defined in FAR 2.101 and FAR 7.5 shall be performed by the Contractor under this contract. Contractor employees shall not participate in any deliberations or meetings intended to exercise an inherently Governmental function. All final determinations such as binding the United States to take or not take some action, selecting program priorities, and providing direction to Federal employees shall be made by the Government. The Contractor shall immediately notify the COR and the KO if performance of an activity would result in the performance of an inherently Governmental function.
1.6.11 Identification of Contractor Employees: All Contractor personnel attending meetings, answering Government telephones, and working in other situations where their Contractor status is not obvious to third parties are required to identify themselves as such to avoid creating an impression in the minds of members of the public that they are Government officials. They must also ensure that all documents or reports produced by Contractors are suitably marked as Contractor products or that Contractor participation is appropriately disclosed. All Contractor personnel will be required to obtain a Pentagon Facilities Alternative Credential (PFAC) or Common Access Card (CAC) and wear this credential at all times when performing work onsite under this contract.
1.6.12 Contractor Travel: The Contractor will be required to perform work under this contract onsite when the work cannot be performed remotely. It is the Government’s discretion on what work being performed under this contract can and cannot be performed from a remote location. The Contractor shall ensure there are personnel available to travel when required to perform work onsite. The Contractor may be required to travel CONUS and within the NCR during the performance of this contract to attend meetings, conferences, and training. Contractor will be authorized travel expenses consistent with the substantive provisions of the Joint Travel Regulation (JTR) and the limitation of funds specified in this contract. All travel requires Government approval/authorization and notification to the COR.
1.6.13 Other Direct Costs: All costs relating to travel and shipping expenses for the work being performed under this contract shall be included in the firm fixed price amount of this contract. This category includes travel (outlined in 1.6.13), reproduction, and shipping expenses associated with training activities and visits to Contractor facilities.
1.6.14 Data Rights: The Government has unlimited rights to all documents/material produced under this contract. All documents and materials, to include the source codes of any software, produced under this contract shall be Government owned and are the property of the Government with all rights and privileges of ownership/copyright belonging exclusively to the Government. These documents and materials may not be used or sold by the Contractor without written permission from the Contracting Officer. All materials supplied to the Government shall be the sole property of the Government and may not be used for any other purpose. This right does not abrogate any other Government rights.
1.6.15 508 Requirements: Compliance with Section 508 of the Rehabilitation Act of 1973. All Electronic and Information Technology (EIT) procured through this contract must comply with Section 508 of the Rehabilitation Act (29 U.S.C. 794d), as amended by the Workforce Investment Act of 1998 (P.L. 105-220), August 7, 1998, unless an agency exception to this requirement exists. See http://www.section508.gov. The Contractor shall indicate for each line item in the schedule whether each product or service is compliant or on-compliant with these accessibility standards. Further, the proposal must indicate where full details of compliance can be found (e.g., Contractor’s website or other specific location)
1.6.16.1. Installation, Configuration and Integration Services: When the Contractor provides installation, configuration or integration services for equipment and software pursuant to this contract, the Contractor shall not install, configure or integrate the equipment and software in a way that reduces the level of conformance with the applicable Revised 508 Standards.
1.6.16.2. Service Personnel: The Contractor shall ensure the personnel providing the labor hours possess the knowledge, skills, and ability necessary to address the applicable Revised 508 Standards defined in this contract, and shall provide supporting documentation upon request.
1.6.17 Organizational Conflict of Interest: Contractor and subcontractor personnel performing work under this contract may receive, have access to or participate in the development of proprietary or source selection information (e.g., cost or pricing information, budget information or analyses, specifications or work statements, etc.) or perform evaluation services which may create a current or subsequent Organizational Conflict of Interests (OCI) as defined in FAR Subpart 9.5. The Contractor shall notify the KO immediately whenever it becomes aware that such access or participation may result in any actual or potential OCI and shall promptly submit a plan to the KO to avoid or mitigate any such OCI. The Contractor’s mitigation plan will be determined to be acceptable solely at the discretion of the KO and in the event the KO unilaterally determines that any such OCI cannot be satisfactorily avoided or mitigated, the KO may affect other remedies as he or she deems necessary, including prohibiting the Contractor from participation in subsequent contracted requirements which may be affected by the OCI.
1.6.18 DoD Intellectual Property: At its discretion, the DoD may grant the Contractor limited authority to use the official seal of the DoD, or the official seals of DoD Components for limited purposes relating to Contractor performance. If granted, use of all seals or logos must be discontinued at the conclusion of the Contract. Without written approval, no Contractor, or subcontractor, is authorized to use the official seal of DoD for any other purpose.
1.6.19 Release of Information: The Contractor shall not disclose or release to other than Government authorized persons or activities, the content of any Government software, procedures, materials or products generated under this contract, or information provided to the Contractor.
1.6.20 Security: The Contractor will have escorted access to DoD facilities for any physical meetings required and will complete Non-Disclosure Agreements (NDAs) for all Contractor employees and subcontractor employees with access to vulnerability information.
1.6.21 Background Checks: The Contractor shall conduct or confirm that criminal background checks on all researchers have been conducted, before granting them access to any DoD information. Additionally, the Contractor shall have the capability to restrict researcher participation based on criteria set by DoD. This may include ensuring that researchers are U.S., FVEY and NATO persons; are not felons; are not known terrorists, or an associate of a known terrorist or terrorist organization; are not listed on the U.S. department of Treasury’s Specially Designated Nationals List; or are otherwise ineligible to conduct work for DoD.
1.6.22 Phase in/Phase out Period: To minimize any decreases in productivity and to prevent possible negative impacts on additional services, the Contractor shall have personnel on board, during the 30 day phase in/ phase out periods. During the phase in period, the Contractor shall become familiar with performance requirements in order to commence full performance of services on the contract start date.
1.7 Business Relations: The Contractor shall successfully integrate and coordinate all activity specified herein and at the Contract level. The Contractor shall manage the timeliness, completeness, and quality of the contract and Contract deliverables. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of all Contractor personnel (including subcontractors). The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all Contractor personnel.
1.8 Contract Management: The Contractor shall establish clear organizational lines of authority and responsibility to ensure effective management of the program and resources assigned to this requirement. The Contractor must maintain continuity between the support operations at DoD and the Contractor’s corporate offices.
1.9 Contract Administration: The Contractor shall establish processes and assign resources to effectively administer the contract/Contract. The Contractor shall respond to Government requests for contractual actions promptly.
1.10 Contractor Personnel, Disciplines and Specialties: Successful performance under any Contract will include the responsiveness of Contractor personnel in the day-to-day output of work products. While the end product is vital to successful performance, day-to-day oversight also includes client interaction and responsiveness. Accordingly, the Contractor is required to proactively maintain assigned tasks, and be responsive to all entities with professional business relative to the assigned tasks.
The Contractor must maintain an adequate workforce for the uninterrupted performance of all tasks defined within the respective Contract PWS. When hiring personnel, the Contractor shall remember that the stability and continuity of the workforce are essential.
1.11 Managing the Contract and Contract: The Contractor shall maintain a single Point of Contact (POC) or Program Manager for the management and maintenance of the contract. For each Contract, researchers will identify and submit vulnerability reports via the Contractor’s platform. The Contractor will manage the researchers and all communications necessary regarding vulnerability specifics between the Government and the researchers. Certain DoD employees and other Federal Government employees are prohibited by law from receiving any financial reward as it may violate 18 U.S.C. 209 and the Joint Ethics Regulations, DoD 5500.07-R. The Contractor shall ensure that no prohibited individuals, including Government employees (without written approval from the KO prior to Contract execution), receive financial compensation. Each Contract award will be a fixed-firm price payment for services to cover all Contractor support and bounty (researcher) payments. The bounty payout allocation is at the discretion of the Contractor, but the challenge phase will remain active for the duration specified in the Contract. The Government anticipates that each Contract may have option periods for both additional Contractor support and bounty payments as required by the Government if additional research needed.
1.12 Restrictions of Personnel: If required, the Contractor must be able to restrict all Contractor, Subcontractor, and other Contractor agent personnel (e.g., researchers) with access to the Contractor’s platform and the target system to certain groups, including but not limited to:
· US only
· US and UK only
· “Five Eyes” (“FVEY”) only (US, Canada, UK, Australia, New Zealand)
· North Atlantic Treaty Organization (NATO) only This restriction applies to all Contractor personnel or affiliates with access to the vendor platform and the Government system being tested, including but not limited to program managers, penetration testers, executive management and support teams.
1.13 Task Execution: The Government expects that the length of the Assessment may vary. Typically, the ICS/SCADA-OT is expected to last two (2) to four (4) weeks but could extend to 12 weeks or more. All unclassified vulnerability assessments for the specific assets relative to this effort will be provided to the Contractor by the DoD.
1.14 Documentation: Documents, data files, reports, correspondence, and all other documents and writings, regardless of the medium (or media) by which they were produced, preserved, stored, or created in for purpose(s) of work performed under this PWS and contract, shall be delivered directly within the vulnerability reporting platform or other approved method as directed by written request from the COR (i.e., Email, API).
The Contractor shall assume responsibility for protecting the confidentiality of Government records, which are not considered public information. Each Contractor or employee of the Contractor to whom information may be provided or disclosed shall be notified in writing by the Contractor that such information may be disclosed only for purposes and to the extent authorized. The Contractor shall release no information related to this contract to the public, media or other unauthorized persons or organizations unless the Government has conducted the appropriate security review and granted written approval.
1.15 Participation of Government Employees: The Government may request that certain Government employees participate in challenges. Specific details regarding Government personnel participation will be defined, in collaboration with the Contractor, and specified in the contract.
1.16 Background Checks: The Contractor shall have the ability to conduct criminal background checks for all registered participants and all other Contractor personnel directly involved with Contract activities. The Contractor may be required to contract a third-party commercial firm to conduct a commercial background check to ensure DoD resources do not pay bounties to felons or terrorists. The Contractor must conduct thorough background checks of every researcher before they are invited to participate in every/any challenge. This may include ensuring that researchers are U.S. persons (unless non-U.S. persons are explicitly identified in the Contract); are not felons; are not known terrorists, or associates of a known terrorist or terrorist organization; are not listed on the U.S. Department of the Treasury’s Specially Designated Nationals List; or are otherwise ineligible to conduct work for DoD.
1.17 Background Checks – Additional Restrictions: Additionally, the Contractor shall have the capability to further restrict researcher participation and perform additional screening of Contractor personnel with access to the platform and/or Government systems and facilities based on additional criteria set by DoD. This may include ensuring that researchers are US, UK, FVEY, and/or NATO persons; are not felons; are not known terrorists, or an associate of a known terrorist or terrorist organization; are not listed on the U.S. Department of Treasury’s Specially Designated Nationals List; or are otherwise ineligible to conduct work for DoD.
PART 2
DEFINITIONS & ACRONYMS
2. DEFINITIONS AND ACRONYMS:
2.1. DEFINITIONS:
2.1.1. CONTRACTOR. A supplier or vendor awarded a contract to provide specific supplies or service to the Government. The term used in this contract refers to the prime.
2.1.2. CONTRACTING OFFICER. A person with authority to enter into, administer, and or terminate contracts, and make related determinations and findings on behalf of the Government. Note: The only individual who can legally bind the Government.
2.1.3. CONTRACTING OFFICER'S REPRESENTATIVE (COR). An employee of the U.S. Government appointed by the contracting officer to administer the contract. Such appointment shall be in writing and shall state the scope of authority and limitations. This individual has authority to provide technical direction to the Contractor as long as that direction is within the scope of the contract, does not constitute a change, and has no funding implications. This individual does NOT have authority to change the terms and conditions of the contract.
2.1.4. DEFECTIVE SERVICE. A service output that does not meet the standard of performance associated with the Performance Work Statement.
2.1.5. DELIVERABLE. Anything that can be physically delivered, but may include non-manufactured things such as meeting minutes or reports.
2.1.6. KEY PERSONNEL. Contractor personnel that are evaluated in a source selection process and that may be required to be used in the performance of a contract by the Key Personnel listed in the PWS. When key personnel are used as an evaluation factor in best value procurement, an offer can be rejected if it does not have a firm commitment from the persons that are listed in the proposal.
2.1.7. PHYSICAL SECURITY. Actions that prevent the loss or damage of Government property.
2.1.8. QUALITY ASSURANCE. The Government procedures to verify that services being performed by the Contractor are performed according to acceptable standards.
2.1.9. QUALITY ASSURANCE Surveillance Plan (QASP). An organized written document specifying the surveillance methodology to be used for surveillance of Contractor performance.
2.1.10. QUALITY CONTROL. All necessary measures taken by the Contractor to assure that the quality of an end product or service shall meet contract requirements.
2.1.11. SUBCONTRACTOR. One that enters into a contract with a prime Contractor. The Government does not have privity of contract with the subcontractor.
2.1.12. WORK DAY. The number of hours per day the Contractor provides services in accordance with the contract.
2.1.12. WORK WEEK. Monday through Friday, unless specified otherwise.
2.2. ACRONYMS:
| ACOR | Alternate Contracting Officer's Representative | |
| API | Application Programming Interface | |
| BCTF | Boards, Commissions, and Task Forces | |
| CAC | Common Access Card | |
| CFR | Code of Federal Regulations | |
| CONUS | Continental United States (excludes Alaska and Hawaii) | |
| COR | Contracting Officer Representative | |
| COTR | Contracting Officer's Technical Representative | |
| COTS | Commercial-Off-the-Shelf | |
| CVDD | Crowdsourced Vulnerability Discovery and Disclosure | |
| DD Form 254 | Department of Defense Contract Security Requirement List | |
| DDS | Defense Digital Services | |
| DFARS | Defense Federal Acquisition Regulation Supplement | |
| DMDC | Defense Manpower Data Center | |
| DOD | Department of Defense | |
| EIT | Electronic and Information Technology | |
| EM | Enterprise Management Directorate | |
| FAR | Federal Acquisition Regulation | |
| FFD | Federal Facilities Division | |
| FSD | Facilities Services Directorate | |
| FRCS | Facility Related Controls System | |
| FVEY | “Five Eyes” | |
| GFE | Government Furnished Equipment | |
| HIPAA | Health Insurance Portability and Accountability Act of 1996 | |
| ISO | International Organization for Standardization | |
| JSP | Joint Service Provider | |
| JTR | Joint Travel Regulation | |
| KO | Contracting Officer | |
| MOC | Modular Office Complex | |
| NATO | North Atlantic Treaty Organization | |
| NCR | National Capital Region | |
| OCI | Organizational Conflict of Interest | |
| OCONUS | Outside Continental United States (includes Alaska and Hawaii) | |
| ODC | Other Direct Costs | |
| O&M | Operations & Maintenance | |
| OSD | Office of the Secretary of Defense | |
| PBMO | Pentagon Building Management Office | |
| PCAP | Packet Capture | |
| PFAC | Pentagon Facilities Alternative Credential | |
| PHRP | Pentagon Heating & Refrigeration Plant | |
| PIPO | Phase In/Phase Out | |
| POC | Point of Contact | |
| PRS | Performance Requirements Summary | |
| PWS | Performance Work Statement | |
| QA | Quality Assurance | |
| QAP | Quality Assurance Program | |
| QASP | Quality Assurance Surveillance Plan | |
| QC | Quality Control | |
| QCP | Quality Control Program | |
| SME | Subject Matter Expert(s) | |
| SMOC | Secondary Modular Office Complex | |
| TE | Technical Exhibit | |
| TLS | Transport Layer Security | |
| VLAN | Virtual Local Area Network | |
| VRF | Virtual Routing and Forwarding | |
| WHS | Washington Headquarters Services |
PART 3
GOVERNMENT FURNISHED PROPERTY, EQUIPMENT, AND SERVICES
3. GOVERNMENT FURNISHED ITEMS AND SERVICES:
3.1. Services: The Government will provide, when available, the Subject Matter Experts (SME’s) and personnel as required for the Contractor’s use in performance of tasks outlined in this PWS. The Government will provide all information relating to the FRCS Network required by the Contractor for execution of all tasks as outlined in this PWS.
3.2 Facilities: The Government will provide all necessary workspace for the Contractor personnel to perform the tasks as outlined in this PWS, to include but not be limited to: physical desk space, telephones, computers and other items necessary to maintain an office environment. Physical access to this space will be managed by the Government.
3.3 Utilities: The Government will provide all utilities in the facility as required for the Contractor’s use in performance of tasks outlined in this PWS. These utilities include electricity, lighting and water. The Contractor shall instruct employees in utilities conservation practices. The Contractor shall be responsible for operating under conditions that preclude the waste of utilities, which include turning off the water faucets or valves after using the required amount to accomplish cleaning vehicles and equipment.
3.4 Equipment: The Government will provide access to a desktop or laptop as required to perform the tasks outlined in this PWS. All Government Furnished Equipment (GFE) that is provided shall not be removed from the property unless explicitly authorized by the Government. All GFE shall be turned-in immediately upon completion of all tasks as outlined in this PWS. All GFE shall be in its original working condition when turned in. The Contractor shall be financially responsible for any damages to GFE. The Contractor shall notify the COR immediately following the damaging of any GFE. The Government will provide access to scanners, printers, copiers, etc. as required.
3.5 Materials: The Government will provide all relevant Standard Operating Procedures, internal policy documents, network configuration information (IP Address, Subnet Mask, Gateway).
PART 4
CONTRACTOR FURNISHED ITEMS AND SERVICES
4. CONTRACTOR FURNISHED ITEMS AND RESPONSIBILITIES:
4.1 General: The Contractor shall furnish all supplies, equipment, facilities and services required to perform work under this contract that are not listed under Section 3 of this PWS.
4.2. Materials: The Contractor shall furnish materials, supplies, and equipment necessary to meet the requirements under this PWS. The Contractor shall provide the Government the MAC Addresses of each device being introduced to the FRCS Network. The Contractor shall provide a complete inventory of every device provided.
4.3. Equipment: The Contractor shall provide all necessary equipment required to execute the work being performed under this contract. The Contractor shall provide a complete inventory of every piece of equipment being provided.
PART 5
SPECIFIC TASKS
5. Specific Tasks:
5.1. Basic Services. WHS FSD desires to execute a critical bounty (hacker-cyber) program, which will involve unclassified Information Systems and operational technology devices contained within the Pentagon FRCS Network. The Contractor shall provide all labor, material, equipment, hardware, software and training required to assess the current cybersecurity posture of the FRCS Network, identify weaknesses and vulnerabilities, and provide recommendations to improve and strengthen the overall security posture.
5.2. FRCS Network:
The PBMO O&M IT Staff are responsible for overseeing the operations and maintenance of the FRCS Network. The FRCS Network resides on a network transport infrastructure that is owned and maintained by Joint Service Provider (JSP). This network is contained within one (1) virtual routing and forwarding (VRF) and is comprised of twenty-one (21) virtual local area networks (VLANs) but is not limited to expansion and growth.
The FRCS Network is comprised of a combination of Informational Technology (IT) and Operational Technology (OT) assets. Examples of these IT assets are: Microsoft Windows Server 2016 physical and virtual servers, Microsoft Windows 10 desktops and laptops, Linux servers, printers, etc. Examples of these OT assets are: Field Controllers, Primary Logic Controllers (PLCs), Supervisory Devices, utility (water, gas, electricity) meters, Lighting Panels, etc.
5.2.1. The Contractor shall provide all labor, material and equipment required to assess the current cybersecurity posture of the FRCS Network, identify weaknesses and vulnerabilities, and provide recommendations to improve and strengthen the overall security posture. The scope of the Crowdsourced Vulnerability Discovery and Disclosure exercise shall include the following physical locations where the FRCS Network exists but not be limited to:
5.2.1.1. Pentagon Building
5.2.1.1.1. Corridors 1 & 2
5.2.1.1.2. Corridors 3 & 4
5.2.1.1.3. Corridors 5 & 6
5.2.1.1.4. Corridors 7 & 8
5.2.1.1.5. Corridors 9 & 10
5.2.1.1.6. Basement
5.2.1.1.7. Mezzanine
5.2.1.1.8. Remote Delivery Facility (RDF)
5.2.1.1.9. National Military Command Center (NMCC)
5.2.1.1.10. Pentagon Redundant Utility Plant (PRUP)
5.2.1.1.11. Pentagon Generator Support Program (PGSP)
5.2.1.2. Heating & Refrigeration Plant (H&RP)
5.2.1.3. Pentagon Emergency Response Center (PERC)
5.2.1.4. Mark Center
5.2.1.5. Pentagon Support Operations Center (PSOC)
5.2.1.6. Modular Office Complex (MOC)
5.2.1.7. Secondary Modular Office Complex (SMOC)
PART 6
APPLICABLE PUBLICATIONS
6. APPLICABLE PUBLICATIONS (CURRENT EDITIONS)
6.1. The Contractor must abide by all applicable regulations, publications, manuals, and local policies and procedures.
PART 7
ATTACHMENT/TECHNICAL EXHIBIT LISTING
7. Attachment/Technical Exhibit List:
7.1. Attachment 1/Technical Exhibit 1 – Deliverables Schedule
TECHNICAL EXHIBIT 1
DELIVERABLES SCHEDULE
| Deliverable |
| Frequency |
| # of Copies |
| Medium/Format |
| Submit To |
| List of Personnel |
| Once |
1 Digital & 1 Hard Copy
Due 7 days after contract award
| Digitally Signed PDF |
| Contracting Officer, Contracting Officer Representative |
| Meeting Minutes |
| Bi-weekly |
| 1 Digital & 1 Hard Copy |
Due 48 hours following scheduled bi-weekly status meetings
| Word Document |
| Contracting Officer, Contracting Officer Representative, Government IT Staff |
| Quality Control Plan |
| Once |
| 1 Digital & 1 Hard Copy |
Due 30 days after contract award
| Digitally Signed PDF |
| Contracting Officer, Contracting Officer Representative |
| Non-Disclosure Agreement |
| Once |
| 1 Digital & 1 Hard Copy |
Due 5 days after contract award
| Digitally Signed PDF |
| Contracting Officer, Contracting Officer Representative |
File details come from the government source that posted it. Updated .