Atch 1-PWS San Clemente.docx
DOCX document 54 KB Posted
- Attached to
- San Clemente Air Transportation Shuttle Services Federal contract opportunity
- Solicitation number
- HTC71125RC005
About this file
This is a Performance Work Statement for air transportation shuttle services between Naval Air Station North Island (NASNI) and San Clemente Island (SCI) in California. The contractor must provide passenger and cargo air transportation services five days per week using multi-engine, turbine-powered aircraft equipped with Ultra High Frequency radios and RNAV GPS Category LPV DA capabilities. The service requires transporting approximately 470 passengers weekly in each direction within specified time windows, with Monday having the highest passenger requirements (155 outbound/49 inbound).
The contractor must base operations at NASNI and maintain Department of Defense air carrier approval throughout the contract. Additional requirements include after-hours flights on weekends/holidays as needed and up to two monthly off-line missions within 550 Great Circle Statute Miles of NASNI. Key performance metrics include 90% on-time flight schedule, 95% achievement of weekly passenger targets, and prompt notification (within 15 minutes) of delays or cancellations. The government will provide aircraft parking at NASNI, office space, and DLA-sourced fuel on a reimbursable basis. The contractor must maintain strict cybersecurity protocols and report any cyber incidents within 72 hours of discovery.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| HTC71125RC005 A0003.pdf | ||
| RFP - HTC71125RC005 A0003 Conformed Copy.pdf | ||
| HTC71125RC0005 A0002 Attach QA Responses.pdf | ||
| QA Responses - HTC71125RC005 San Clemente PAX.docx | DOCX document | |
| HTC71125RC005 A00001 Fix 52.212-1 and Atch 4.pdf | ||
| RFP - HTC71125RC005.pdf | ||
| Atch 2-Aircraft Identification Sheet.docx | DOCX document | |
| Atch 4-Past Performance Questionnaire.docx | DOCX document | |
| Atch 7-Wage Determination.pdf | ||
| Atch 3-Pricing Table.xlsx | XLSX spreadsheet | |
| Atch 5-RFP Offeror Information Sheet.docx | DOCX document | |
| Atch 6-Basic Eligibility.docx | DOCX document |
Show all 12
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
HTC71125RC005
Attachment 1 – Performance Work Statement
PERFORMANCE WORK STATEMENT
NAVY REGION SOUTHWEST (NRSW) N32 AIR OPERATIONS
PASSENGER AIR TRANSPORTATION SHUTTLE SERVICES
PRIMARILY BETWEEN NAVAL AIR STATION NORTH ISLAND (NASNI) AND
SAN CLEMENTE ISLAND (SCI)
31 MAY 2024
1. DESCRIPTION OF SERVICES.
1.1. SCOPE. Except as otherwise stated in this contract, the contractor shall provide all personnel, equipment, tools, materials, supervision, and other items and services necessary to perform air transportation services for military and Government civilian passenger movement and essential cargo (including contractor personnel and equipment performing on unrelated contracts) between Naval Air Station North Island (NASNI), California (CA), (also, known as Halsey Field, Federal Aviation Adminitration (FAA) Location Identification (LID) code NZY, or International Civil Aviation Organization (ICAO) code KNZY) and San Clemente Island (SCI), (also, known as Naval Auxiliary Landing Field (NALF), CA, FAA LID code NUC or ICAO Code KNUC) five days per week (See subparagraph 2.1). The estimated mileage between KNZY and KNUC is 101.5 Great Circle Statute Miles (GCSM). The estimated mileage return leg between KNUC and KNZY is 106.5 GCSM. The roundtrip is 208 GCSM. Additional missions between these locations may be scheduled by mutual agreement during the week, weekends, and holidays (See subparagraph 2.3 After-Hours Flights) as well as to other off-line locations within a 550 GCSM radius of NASNI (See subparagraph 2.4 Off-Line Missions).
1.2. AIRCRAFT. The contractor shall base operations at NASNI, CA. The contractor shall provide air transportation services utilizing aircraft (fixed wing) that are Instrument Flight Rules equipped, multi-engine, and turbine powered (jet or turbo prop). All aircraft used to perform services under this contract must be able to communicate using Ultra High Frequency radios, must be equipped with certified Area Navigation (RNAV) Global Positioning System (GPS) Category Localizer Performance with Vertical Guidance Decision Altitude (LPV DA).
1.3. PILOT TRAINING. Pilots must be trained and proficient with RNAV GPS Category LPV DA and Precision Approach Radar (PAR) approaches (KNZY only). The only approach with low (200’-3/4) minimums will be the RNAV GPS Category LPV DA on KNUC.
1.3.1 DOD APPROVAL AND ADDITIONAL STANDARDS. The carrier operating the aircraft must be an approved DoD air carrier, as determined by the Commercial Airlift Review Board (CARB), and must maintain this approval throughout the performance of this contract. The contractor shall comply with all Federal Aviation Administration (FAA) requirements or equivalent CAA requirements, and with all DoD additional standards including those established by DoD Commercial Airlift Division (i.e., the Air Mobility Command (AMC)/A3B) as published on the following website: https://www.amc.af.mil/Home/AMC-Commercial-Services/.
1.4. CORPORATE LIAISON. Prior to the start of the contract, the contractor shall furnish the name, address, and telephone number of the agent who serves as liaison between the contractor and the Contracting Officer’s Representative (COR). The agent must be on site during normal duty hours and have authority to dispatch aircraft, adjust schedules, provide substitute service, and make decisions pertinent to airlift service in the name of the contractor. The agent shall notify the Government within 15 minutes in the event of a delay or cancellation becomes known including the reason for the delay or cancellation. The agent shall be available during normally scheduled working hours Monday through Friday and via telephone after hours/weekends (subject to an 8-hour return call window).
2. SCHEDULE.
| Schedule |
| Minimum (Min) Passengers (Pax) (NI-SCI) |
KNZY-KNUC
| Flight Window |
| Min Pax (NI-SCI) |
KNZY-KNUC
| Flight Window |
| Day total |
| Monday |
| 95 |
| 0630-1230 |
| 60 |
| 1300-1600 |
| 155 |
| Tuesday |
| 60 |
| 0700-1100 |
| 38 |
| 1300-1600 |
| 98 |
| Wednesday |
| 95 |
| 0700-1100 |
| 30 |
| 1200-1600 |
| 125 |
| Thursday |
| 35 |
| 0700-1100 |
| 19 |
| 1200-1600 |
| 54 |
| Friday |
| 19 |
| 0800-1100 |
| 19 |
| 1200-1600 |
| 38 |
Total am 304
Total pm 166
Total 470
| Schedule |
| Min Pax (SCI-NI) |
KNUC-KNZY
| Flight Window |
| Min Pax (SCI-NI) |
KNUC-KNZY
| Flight Window |
| Day total |
| Monday |
| 30 |
| 0700-1230 |
| 19 |
| 1300-1600 |
| 49 |
| Tuesday |
| 19 |
| 0700-1100 |
| 19 |
| 1300-1600 |
| 38 |
| Wednesday |
| 35 |
| 0700-1100 |
| 75 |
| 1200-1600 |
| 110 |
| Thursday |
| 95 |
| 0700-1100 |
| 95 |
| 1200-1600 |
| 190 |
| Friday |
| 38 |
| 0800-1100 |
| 38 |
| 1200-1600 |
| 76 |
Total am 217
Total pm 246
Total 463
2.1. PASSENGER SERVICES SAN CLEMENTE ISLAND. The contractor shall transport approximately 470 passengers and baggage per week round trip from NASNI to SCI and back to NASNI within timeframes detailed above in paragraph 2, Schedule. Return trips, SCI to NASNI, will be available to carry maximum payload and will be coordinated with the contractor in advance. (Note: The passenger estimates are based on historical data and the number of passengers may vary based upon the Government’s requirement.) If more than one aircraft is scheduled, departure times will be staggered at each location with a minimum of 15-minute intervals, i.e., 0700, 0715, 0730, etc. The planning weight for each passenger with baggage is 250 pounds collectively. The daily flight schedule is above in paragraph 2. Schedule. The contractor shall coordinate with the COR each week to confirm the schedule throughout the year. Contractor shall notify COR of any delay in schedule in excess of 15 minutes published schedule. Contractor shall provide timely notification to COR by quickest means practical (i.e., telephone call or email) any time contractor cannot meet the daily passenger airlift requirement.
2.2. CHANGES TO REGULAR SCHEDULE. During periods of inclement weather, the regular scheduled flights may be delayed, but the passenger airlift requirement must still be met as soon as practical. Flight schedules to San Clemente Island are subject to change (reduced requirements) during federal holidays and the holiday seasons and will be adjusted to meet customer requirements within airfield hours of operations upon coordination with the contractor.
2.3. AFTER-HOURS FLIGHTS. In addition to the regular schedule, additional missions may be required to meet user requirements. Weekend, evening (after 1600), and/or holiday service may be required for flights between NASNI and SCI. For example, a test operation may be scheduled for Friday with a weather or operational back-up date scheduled for the following Saturday and/or Sunday. If the test operation is not performed on Friday, the contractor may be required to fly on Saturday or Sunday, at the completion of the operation, to transport passengers as necessary. The contractor shall coordinate after-hours flights with the COR.
2.4. OFF-LINE MISSIONS. The contractor shall provide airlift service for mission requirements between NASNI and destinations within 550 GCSM not to exceed two per month +/- 24 hours of the requested date. The approval authority for these missions is Commander Navy Region Southwest Air Operations Program Director/Deputy. Off-line mission locations could include Naval Air Station (NAS) Lemoore, NAS Fallon, and NAS Point Mugu to Navy Outlying Field (NOLF) San Nicolas Island. Most typical off-line missions are between Point Mugu and San Nicolas Island (in cargo mode) with some or all seats removed (load dependent), returns empty to KNZY. All flights would originate from NAS North Island.
2.5. NOTIFICATION OF ADDITIONAL REQUIREMENTS. The Government may schedule additional weekday requirements with at least 14 hours advance notice and weekend and holiday requirements with at least 24-hours advance notice. The contractor does not have to accept missions requested inside the 14 or 24-hour advance notice periods. Additional missions will be scheduled so as not to exceed normal crew duty day.
3. SERVICE DELIVERY SUMMARY (SDS). The SDS represents the most important contract objectives. Although not all Performance Work Statement requirements are listed in the SDS, the contractor is fully expected to comply with all requirements in the Performance Work Statement.
| DESCRIPTION |
| PWS REFERENCE |
| PERFORMANCE THRESHOLD |
| Agent shall notify the Government COR within 15 minutes after delay or cancellation becomes known including the reason for the delay or cancellation. |
| 1.4, 2.0, and 2.1 |
| No more than 2 reported instances of untimely notification of schedule delay or contractor cannot meet passenger airlift requirement annually. 100% of missions measured monthly. |
| The agent shall be available during normally scheduled working hours Monday through Friday and via telephone after hours/weekends (subject to an 8-hour return call window). |
| 1.4 |
| No more than 2 reported instances of nonavailability per year. |
| Contractor shall provide service within the flight window indicated in paragraph 2.0 Schedule and 2.1 Passenger Services SCI. |
| 2.0 and 2.1 |
| Maintain 90% on time flight schedule measured monthly for contractor related delays. |
| The contractor shall transport approximately 470 passengers and baggage per week round trip from NASNI to San Clemente Island and back to NASNI within timeframes detailed above in paragraph 2.0 Schedule and 2.1 Passenger Services SCI. |
| 2.0 and 2.1 |
| Contractor shall meet 95% of agreed upon weekly schedule passengers and baggage measured monthly. |
| The contractor shall provide Off-Line Missions airlift service for mission requirements between NASNI and destinations within 550 GCSM not to exceed two per month +/- 24 hours of the requested date. |
| 2.4 |
| Contractor shall meet 90% of scheduled off-line flights -measured monthly. |
| The Government may schedule additional weekday requirements with at least 14 hours advance notice and weekend and holiday requirements with at least 24 hours advance notice. |
| 2.5 |
| Contractor shall meet 90% of additional scheduled flights - measured monthly. |
| Provide timely cyber-incident reporting. |
| 7.4 – 7.6 Cyber-Incident Reporting |
| No more than one late cyber-incident report or unreported cyber-incident in a twelve (12) month period. |
4. GOVERNMENT FURNISHED EQUIPMENT, FACILITIES AND SERVICES.
4.1. GOVERNMENT FURNISHED EQUIPMENT. The Government will provide aircraft parking at NASNI CA. Due to the limited aircraft parking space, the total parking steady state footprint shall be agreed upon between the Government and the contractor and dependent on aircraft size. For example, an aircraft similar to a 19 seat sized aircraft cannot exceed five aircraft or an aircraft similar to a 30 seat sized aircraft cannot exceed three aircraft at NASNI at any time. The Government will also provide office space for operational/paperwork requirements and a lockable, secure area for dry storage of spare aircraft parts. Fueling at NASNI and SCI will be accomplished by Government contracted fueling services; however, the contractor must perform the actual line services (attaching of fueling hose to the aircraft). Fueling at SCI is preferred due to possible extended fuel wait times at NASNI. Due to the lack of availability of Ground Support Equipment (GSE), the Government will not supply tow tractors or tow bars at any military facility. Aircraft starting units or any other types of common or aircraft specific GSE will be provided if available, i.e., generally available at NASNI, generally not available at SCI. Servicing of lavatory facilities shall be accommodated at NASNI. NASNI air terminal maintains lavatory carts. Servicing of aircraft lavatory is the responsibility of the contractor. Equipment will not be provided by the Government for this task. NOTE: Routine aircraft maintenance may be accomplished at NASNI or SCI. However, non-routine maintenance such as aircraft X-Ray or heavy scheduled maintenance (engine changes or Phase maintenance) is not permitted at either location; such non-routine maintenance shall be performed offsite at contractor facilities.
4.2. GOVERNMENT PERSONNEL. The Government is responsible for manifesting, weighing and boarding passengers on the aircraft. A Government representative will provide the contractor with a manifest completed in accordance with Defense Transportation Regulation (DTR) Part I, Ch 103, paragraph P., Passenger Manifesting Procedures, prior to boarding.
4.3. GOVERNMENT FURNISHED FACILITIES AND SERVICES. The Government will provide (at no cost to the contractor) the following services and facilities: airfield safety protection, ground support equipment and auxiliary power units (as available). The Government will also provide (at no cost to the contractor) a small metal building adjacent to the terminal (approx. 800 sq ft.) to be used as an office. The Government will also provide electricity, water, sewage, and Class C telephone hook-ups. The contractor will be responsible for all long-distance charges and for removing their own waste.
4.4. REIMBURSABLE FUEL COSTS. The Government will provide DLA-sourced fuel at the main operating locations of NASNI and SCI. The contractor may purchase fuel at off-station sites as mission requirements dictate; however, DLA is preferred source of fuel. Fuel costs that exceed DLA prices, when DLA-sourced fuel is reasonably available, will only be reimbursed at the DLA-source rate. Fuel purchased for contract flights will be on a cost-reimbursable expense. Fuel for non-contract flights should be purchased by the contractor and will not be reimbursed by the government. Contractor flights not directed by the Government are non-billable, e.g., flights to an offsite maintenance location. All invoices must be accompanied by copies of paid receipts. All indirect costs (e.g., overhead, G&A, profit) are specifically prohibited.
4.5. GOVERNMENT SHALL PROVIDE WHEN AVAILABLE. Hangar space for emergency repairs.
5. GENERAL INFORMATION.
5.1. CONTRACTOR PERSONNEL. All contractor personnel shall comply with all pertinent military regulations and/or directives when in military base flight patterns, and on military installations. NASNI will provide specific airspace training instructions prior to the first flight. Contractor personnel will be required to attend special briefings as needed to affect smooth Government/contractor operations. Compliance with regulations include, but are not limited to, presenting valid identification for installation entrance, obtaining vehicle use passes for all contractor-owned and/or privately-owned vehicles, obeying all posted directives, providing strict adherence to security police direction in instances where security police have been dispatched to a particular location.
5.1.2. IDENTIFICATION OF POTENTIAL ORGANIZATIONAL CONFLICTS OF INTEREST (OCI). All personnel (military, Government civilian, and support contractor) within the TCAQ will have access and work with acquisition/proprietary information governed by Federal Acquisition Regulation (FAR). Organizational conflict of interests shall be avoided, neutralized or mitigated IAW FAR 9.505.
5.1.3. Health and Safety on Government Installations.
5.1.3.1. In performing work under this contract on a Government installation, the contractor shall:
5.1.3.1.1. Take all reasonable steps and precautions to prevent accidents and preserve the health and safety of contractor and Government personnel performing or in any way coming in contact with the performance of this contract; and
5.1.3.1.2. Take such additional immediate precautions as the contracting officer may reasonably require for health and safety purposes.
5.1.3.2. The contracting officer may, by written order, direct health/safety standards as may be required in the performance of this contract and any adjustments resulting from such direction will be in accordance with the Changes clause of this contract.
5.1.3.3. Any violation of these health and safety rules and requirements, unless promptly corrected as directed by the contracting officer, shall be grounds for termination of this contract in accordance with the Default and/or Cause clause of this contract.
5.2. BILLING. Invoices will be submitted either monthly or semi-monthly, at vendor discretion, through Procurement Integrated Enterprise Environment (PIEE) Wide Area Workflow (WAWF) in accordance with DFARS 252.232-7006 Wide Area Workflow Payment Instructions. If invoicing semi-monthly, the dates shall be fixed (1st and 15th or 15th and 30th). Monthly Basing fee may only be invoiced monthly. The contractor shall bill for actual miles flown. Estimated KNZY—KNUC round trip is 208 GCSMs. The contractor may invoice for additional live miles caused by circumstances outside their control, including weather, aborted missions, and other unexpected events as soon as reasonably possible with appropriate documentation. Fuel invoicing may be submitted at the same time as mileage or monthly basing invoice or may be invoiced separately when all records for a particular billing period are received. Initial positioning miles to KNZY and end-of-day repositioning miles from KNZY, including maintenance shuttle miles, are not billable.
6.0 Operations Security
OPSEC must be included in contracts to ensure that critical information is protected. Disclosing this information to the adversary could potentially affect mission success and cause harm to military members, civilians, and contractors and their families. OPSEC is a process used to protect unclassified sensitive information from exploitation by an adversary. Sensitive unclassified information—which is also referred to as critical information or critical program information (CPI)—is defined as information that is not classified but which needs to be protected from unauthorized disclosure. Examples are information labeled CUI, such as proprietary information, contractor sensitive information, limited distribution information, or PII.
6.1 Operations Security Requirements. The prime contractor and all subcontractors shall provide protection for sensitive unclassified information to limit unauthorized disclosures of critical information. The prime contractor and all subcontractors shall employ the countermeasures listed below to protect that information. These OPSEC requirements will be in effect throughout the life of the procurement from award through the conclusion of services at the end of the period of performance or other procurement termination. In any case where uncertainty or ambiguity regarding OPSEC measures exists, the contractor shall consult the requirements or contracting office’s OPSEC coordinator as soon as possible.
6.2 Countermeasures to Unauthorized Disclosure of Critical Information. Countermeasures are required to negate the susceptibility of critical information to exploitation by an adversary or competitor. The contractor shall protect all critical information listed in a manner appropriate to the nature of the information, including use of the necessary countermeasures as listed below applicable to specific items:
· Refrain from including critical information in contract and budget documents, presentations, press releases, and other publications to that which is essential to the performance of this requirement.
· Encryption or password protection of electronically stored critical information.
· Encryption or password protection of e-mail containing critical information.
· Storage of hard copy critical information and storage media in locked containers when not in use.
· Transmission of critical information to the minimum set of recipients with a need to know.
· Immediate and appropriate destruction in a manner precluding reconstruction of all critical information no longer needed under this contract.
· Restricting verbal discussion of critical information to venues and circumstances that prevent the monitoring and interception of the discussion by unauthorized personnel.
· Refraining from the use of unencrypted telephones to transmit critical information.
· Refraining from the use of foreign postal systems to ship critical information.
· Promptly retrieving documents containing critical information printed on printers accessible by persons without a need to know the critical information.
· Use of cover pages or other appropriate means to prevent the viewing of critical information by unauthorized persons.
· The contractor shall notify the COR and USTRANSCOM security office immediately of all known and suspected compromises of critical information. If the COR cannot be reached, the contractor shall notify the supported command duty officer if after normal work hours.
7. CYBERSECURITY
7.1. Operationally Critical Support
The services designated under this contract are “operationally critical support” as defined in DFARS 252.204-7012.
7.2. Cybersecurity Incident Reporting
7.2.1. 6.4.1. In addition to the DFARS 252.204-7012 reporting requirements for unclassified systems and 32 Code of Federal Regulations (CFR) Part 117, National Industrial Security Program Operating Manual (NISPOM) for classified systems, reportable cyber-incidents (regardless of whether the information system contains CDI or there is an impact to performance such as delivery schedule delay) include, but are not limited to, the following::
7.2.1.1. Cyber-incidents as defined in Table 1.
7.2.1.2. Notifications by a federal, state, or local law enforcement agency or cyber-center (i.e., National Cyber Investigative Joint Task Force (NCIJTF), National Cybersecurity & Communications Integration Center (NCCIC)) of being a victim of a successful or unsuccessful cyber-event, anomaly, incident, insider threat, breach, intrusion, or exfiltration.
Table 1.
| Incident Category |
| Description |
| Root Level Intrusion |
| Unauthorized privileged access to an IS. Privileged access, often referred to as administrative or root access, provides unrestricted access to the IS. This category includes unauthorized access to information or unauthorized access to account credentials that could be used to perform administrative functions (e.g., domain administrator). If the IS is compromised with malicious code that provides remote interactive control, it will be reported in this category. |
| User Level Intrusion |
| Unauthorized non-privileged access to an IS. Non-privileged access, often referred to as user level access, provides restricted access to the IS based on the privileges granted to the user. This includes unauthorized access to information or unauthorized access to account credentials that could be used to perform user functions such as accessing Web applications, Web portals, or other similar information resources. If the IS is compromised with malicious code that provides remote interactive control, it will be reported in this category. |
| Denial of Service |
| Denial of Service (Incident)—Activity that denies, degrades, or |
disrupts normal functionality of an IS or DoD information network.
| Malicious Logic |
| Installation of software designed and/or deployed by adversaries with malicious intentions for the purpose of gaining access to resources or information without the consent or knowledge of the user. This only includes malicious code that does not provide remote interactive control of the compromised IS. Malicious code that has allowed interactive access should be categorized as Root or User Level Intrusion incidents. Interactive active access may include automated tools that establish an open channel of communications to and/or from an IS. |
| Ransomware |
| Malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption. Ransomware actors often target and threaten to sell or leak exfiltrated data or authentication information if the ransom is not paid. Ransomware is a reportable incident that may be associated with multiple incident categories depending on the attack vector and execution. |
7.2.2. If the cyber-incident affects a classified system, vulnerabilities associated with the incident will be classified per the current version of USTRANSCOM Instruction 31-02, Security Classification Guide.
7.3. Cybersecurity Incident Reporting Timelines
In addition to providing the notification required by DFARS 252.204-7012, the contractor is required to notify USTRANSCOM as soon as practical, but no later than 72 hours after discovering a reportable cyber-incident. The reporting timeline begins when the incident is discovered or reported to the company, its employees, contractors, or cybersecurity firm responsible for providing cybersecurity and response for the company. The contractor shall contact the USTRANSCOM Cyber Operations Center (CyOC) via phone at 618-817-4222. If the contractor does not immediately reach the CyOC via phone, the contractor shall send an email notification to transcom.scott.tcj6.mbx.cyoc-dodin-operations@mail.mil.
7.4. Mandatory Reporting Data
7.4.1. The contractor shall work with the USTRANSCOM CyOC through resolution of the incident. Within 72 hours of becoming aware of a reportable cyber-incident, the contractor shall provide an initial notification of the incident, even if some details are not yet available, which includes, but is not limited to, the following information:
7.4.1.1. Company Name
7.4.1.2. Who will be the POC with contact information
7.4.1.3. Contracting Officer POC (name, telephone, email)
7.4.1.4. Overall Assessment –Description of incident, data at risk, mitigations applied
7.4.1.5. Indicators of compromise
7.4.1.6. Vector of attack (if known)
7.4.1.7. Estimated time of attack (if known)
7.4.2. The contractor shall provide a follow-on cyber-incident report to the USTRANSCOM CyOC within five calendar days of becoming aware of a reportable cyber-incident, which includes, but is not limited to, the following information:
7.4.2.1. Contractor unique Commercial and Government Entity (CAGE) code
7.4.2.2. Contract numbers affected
7.4.2.3. Facility CAGE code where the incident occurred if different than the prime Contractor location
7.4.2.4. POC if different than the POC recorded in the System for Award Management (name, address, position, telephone, email)
7.4.2.5. Contracting Officer POC (name, telephone, email)
7.4.2.6. Contract clearance level
7.4.2.7. DoD programs, platforms, systems, or information involved
7.4.2.8. Location(s) of compromise
7.4.2.9. Date incident discovered
7.4.2.10. Type of compromise (e.g., unauthorized access, inadvertent release, other)
7.4.2.11. Description of technical information compromised
7.4.2.12. Any additional information relevant to the information compromise
7.5. Incident Reporting Coordination
7.5.1. In the event of a cyber-incident, USTRANSCOM may conduct an on-site review of network or information systems where DoD information is resident on or transiting to assist the contractor in evaluating the extent of the incident and to share information in an effort to minimize the impact to both parties. Date and time of on-site visits will be mutually agreed upon by USTRANSCOM and the contractor in advance.
7.5.2. The contractor agrees to allow follow-on actions by the Government (e.g., USTRANSCOM, Federal Bureau of Investigation, Department of Homeland Security, DC3, etc.) to further characterize and evaluate the suspect activity. The contractor acknowledges that damage assessments might be necessary to ascertain an incident methodology and identify systems compromised as a result of the incident. Once an incident is identified, the contractor agrees to take all reasonable and appropriate steps to preserve any and all evidence, information, data, logs, electronic files and similar type information (reference NIST Special Publication 800-61, Computer Security Incident Handling Guide, (current version)) related to the incident for subsequent forensic analysis so that an accurate and complete damage assessment can be accomplished by the Government.
7.5.3. The contractor is not required to maintain an organic forensic capability, but must ensure data is preserved (e.g., remove an affected system, while still powered on, from the network) and all actions documented until forensic analysis can be performed by the Government or, if the Government is unable to conduct the forensic analysis, a mutually agreed upon third party (e.g., Federally Funded Research and Development Center (FFRDC), commercial security contractor, etc.). Any follow-on actions shall be coordinated with the contractor via the Contracting Officer.
7.5.4. The contractor agrees to indemnify and hold the government harmless for following any recommendations to remedy or mitigate the cyber-incident following the actions under 7.5.1. and 7.5.2.
7.6. Confidentiality and Non-Attribution Statement
The Government may use and disclose reported information as authorized by law and will only provide attribution information on a need-to-know basis to authorized persons for cybersecurity and related purposes (e.g., in support of forensic analysis, incident response, compromise or damage assessments, law enforcement, counterintelligence, threat reporting, and trend analysis). The Government may share threat information with other USTRANSCOM industry partners without attributing or identifying the affected contractor.
File details come from the government source that posted it. Updated .