Att 1 ASSO_CMDSAPSO Support Svcs PWS.pdf
PDF 392 KB Posted
- Attached to
- Assistant Special Security Officer (ASSO)/ Command Special Access Program Security Officer (CMDSAPSO) Support Services Federal contract opportunity
- Solicitation number
- M68909-25-I-7600
- Issued by
- United States Marine Corps
About this file
This document is a Performance Work Statement (PWS) for the Assistant Special Security Officer (ASSO) and Command Special Access Program Security Officer (CMDSAPSO) Support Services contract with the United States Marine Corps (USMC) Marine Corps Tactical Systems Support Activity (MCTSSA) at Camp Pendleton, CA.
The PWS requires the contractor to provide personnel with the technical and analytical expertise to support the MCTSSA Special Security Officer (SSO)/CMDSAPSO responsibilities. Key requirements include program management, ASSO/CMDSAPSO duties such as developing/evaluating security systems and procedures, conducting security inspections, and providing SCI security support. The contractor must meet security requirements including personnel clearances, base access, and OPSEC. Deliverables include a management plan, monthly status reports, and accident/training reports. This is a pre-solicitation notice, and the USMC is seeking information from interested and capable contractors for this requirement.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| MCEDS 1.0.11.0 Supported Models Oct2.xlsx | XLSX spreadsheet | |
| RFI M68909-25-I-7600 A0002.pdf | ||
| RFI questions and answers 18OCT2024.pdf | ||
| ASSO_CMDSAPSO Support Services PWS 16 Oct 2024.pdf | ||
| RFI M68909-25-I-7600 A0001.pdf | ||
| RFI M68909-25-I-7600.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Performance Work Statement (PWS) for the
Marine Corps Tactical Systems Support Activity (MCTSSA) Assistant Special Security Officer (ASSO)/
Command Special Access Program Security Officer (CMDSAPSO) Support Services
14 August 2024
Prepared by:
UNITED STATES MARINE CORPS
Marine Corps Tactical Systems Support Activity
Camp Pendleton, CA 92055-5171
ASSO/CMDSAPSO PWS
ii
TABLE OF CONTENTS
1 INTRODUCTION
1.1 Background
1.2 Scope
1.2.1 Program Management
1.2.2 ASSO/CMDSAPSO Duties
2 APPLICABLE DOCUMENTS
2.1 Compliance Documents
2.2 Guidance Documents
3 REQUIREMENTS
3.1 General Requirements
3.1.1 Contract Data Requirements List (CDRL) Item Deliverables
3.1.2 Non-Personal Services
3.1.3 Business Relations
3.1.4 Contractor Personnel, Disciplines, and Specialties
3.1.5 Resource Requirements
3.1.5.1 Marine Corps Enterprise Network (MCEN) and Telephone Services
3.1.5.2 Contractor Assets Connectivity to the MCEN
3.1.5.3 Magnetic Hard Drive Storage Devices
3.1.5.4 Common Access Card (CAC)
3.1.6 Security Requirements
3.1.6.1 Eligibility for Access to Classified Information
3.1.6.2 Qualified U.S. Contractors
3.1.6.3 Base Security
3.1.6.4 Site Security
3.1.6.5 Defense Biometric Identification System (DBIDS)
3.1.6.6 Operations Security (OPSEC) Requirements
3.1.6.7 MCTSSA Check-Out Procedures
3.1.7 Safety – Accidents and Mishaps
3.1.8 Locations and Hours of Work
3.1.8.1 Overtime Capability
3.1.9 Dress and Conduct
3.1.10 Travel
3.1.11 Privacy Act Information
3.1.12 Program Management
3.1.12.1 Contract Management Plan
3.1.12.2 Monthly Status Report (MSR)
3.1.12.3 Mobilization/Phase-Out Period
3.1.12.3.1 Mobilization
3.1.12.3.2 Phase-Out
3.1.12.4 Identification of Contractor Personnel
3.1.12.5 Post Award Conference (PAC)
3.1.12.6 Technical Documentation
3.1.12.7 Data
3.1.12.7.1 Data Rights
3.1.12.7.2 Data Management
iii
3.1.12.7.3 Distribution Statement
3.1.13 Government Property
3.1.14 Government-Furnished Information (GFI)
3.1.15 Invoicing
3.1.16 Administrative Authority
3.1.16.1 Contracting Officer
3.1.16.2 Contracting Officer’s Representative (COR)
3.2 Specific Requirements
3.2.1 Program Management
3.2.2 ASSO/CMDSAPSO Duties
3.3 Operational Requirements in a Test Environment
3.4 Service Contract Reporting (SCR)
3.5 Performance Requirement Summary (PRS)
4 ORGANIZATIONAL CONFLICT OF INTEREST
APPENDIX A – ACRONYMS ................................................................................................. A-1
APPENDIX B – CDRL SUMMARY ........................................................................................ B-1
APPENDIX C – PERFORMANCE REQUIREMENTS SUMMARY ..................................... C-1
1 INTRODUCTION
1.1 Background
The Marine Corps Tactical Systems Support Activity (MCTSSA) provides 24/7 global technical support for Command, Control, Communications, Computer, Cyber, and Intelligence (C5I) systems. MCTSSA conducts engineering, test and evaluation (T&E), and experimentation on C5I systems and amphibious platforms allowing for informed acquisition decisions that make the Fleet Marine Force (FMF) more capable.
1.2 Scope
The Contractor shall provide support to the MCTSSA Special Security Officer (SSO)/Command Special Access Program Security Officer (CMDSAPSO).
The Contractor shall provide personnel with the technical and analytical expertise to support responsibilities delineated by MCTSSA to ensure superior performance of all aspects of the tasking defined in this Performance Work Statement (PWS). The Contractor shall ensure technical management and coordination of task activities and provide overall expertise for successful completion of this PWS, as well as ensure administrative support is provided as required.
The Contractor shall provide personnel to perform Assistant Special Security Officer (ASSO)/CMDSAPSO duties.
1.2.1 Program Management
The Contractor shall provide a consistent and responsive Program Manager (PM) for this PWS.
The PM shall be responsible for the accomplishment of all tasks required by this PWS.
The PM shall:
Be the person authorized to commit resources to fulfill PWS requirements.
Organize, plan, schedule, implement, control, analyze, and report on all elements of the
PWS.
Have resources and authority to ensure efficient and timely program execution and shall be the focal point for all required program tasks.
Be prepared to present and discuss the status of PWS activities, requirements, and issues with the MCTSSA point of contact (POC).
See Section 3.2.1 for program management requirements.
1.2.2 ASSO/CMDSAPSO Duties
The Contractor shall provide personnel to perform ASSO/CMDSAPSO duties. See Section 3.2.2 for ASSO/CMDSAPSO requirements.
2 APPLICABLE DOCUMENTS
2.1 Compliance Documents
The current versions of the following documents shall be used when performing the work described in this PWS:
a. Department of the Navy (DON), Secretary of the Navy (SECNAV) Manual M-5216.5 (Change 1), Correspondence Manual, 16 May 2018.
b. Headquarters Marine Corps (HQMC), Marine Corps Order (MCO) 5216.20B (Change 2), Marine Corps Supplement to the Department of the Navy Correspondence Manual, 17 March 2022.
2.2 Guidance Documents
The current version of the following document shall be used as guidance when performing the work described in this PWS:
a. Defense Counterintelligence and Security Agency (DCSA), 32 Code of Federal Regulation (CFR) Part 117 – National Industrial Security Program Operating Manual
(NISPOM).
3 REQUIREMENTS
3.1 General Requirements
3.1.1 Contract Data Requirements List (CDRL) Item Deliverables
The CDRL items shall be delivered to the Government in the current MCTSSA template format consistent with the Data Item Description (DID) and all the other requirements identified in the respective CDRL DD Form 1423. If MCTSSA does not have a template, the products shall be delivered to the Government per commercial best practices, in the current version of Microsoft Office used by MCTSSA. All deliverables are to be submitted to the Government as defined in each CDRL item (APPENDIX B).
The Contractor shall develop and maintain an effective quality control program to ensure services are performed in accordance with this PWS. The Contractor shall develop and implement procedures to identify, prevent, and ensure non-recurrence of defective services, such as a service output that does not meet the standard of performance associated with the PWS. The contractor’s quality control plan shall be defined and described in the contractor’s management plan to support the requirements of this PWS, per Section 3.1.12.1. The final deliverable is due 5 working days after receipt of government comments on the initial submission unless a different schedule is agreed to by the Government and the Contractor.
CDRL B001 – DI‐MISC‐80508B, Technical Report - Study/Services – Management and Technical Plan
3.1.2 Non-Personal Services
The Government shall neither supervise nor control the method by which contractor personnel perform the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor personnel. It shall be the responsibility of the Contractor to manage its personnel and to guard against any actions that are of the nature of personal services, or which give the perception of personal services. If the Contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the Contractor’s responsibility to notify the Procuring Contracting Officer (PCO) immediately.
3.1.3 Business Relations
The Contractor shall successfully integrate and coordinate all activities needed to execute the requirement. The Contractor shall manage the timeliness, completeness, and quality of problem identification. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all contractor personnel.
3.1.4 Contractor Personnel, Disciplines, and Specialties
The Contractor shall satisfy the requirements of this PWS by employing and utilizing personnel with an appropriate combination of education, knowledge, skills, abilities, and experience. The Contractor shall utilize appropriate labor categories and labor hours to perform all the work or tasks identified in this contract. The Contractor shall not employ government personnel (military or civilian) for performance of any work described in this PWS.
3.1.5 Resource Requirements
The Contractor shall provide all personnel, tools, materials, supervision, and quality control necessary to meet the MCTSSA support services requirements defined by this PWS. Personnel training, certifications, and qualifications specified in this PWS shall be provided for by the Contractor at their expense, except for the training listed in Section 3.1.14.
3.1.5.1 Marine Corps Enterprise Network (MCEN) and Telephone Services
Contractor personnel accessing MCTSSA information systems must maintain compliance with United States Marine Corps (USMC) Enterprise Cybersecurity Manual 007 Resource Access Guide. Contractor personnel will submit a DD 2875 and a completion certificate for the CYBERC course located on MarineNet located at https://www.marinenet.usmc.mil. The CYBERC course consist of the Department of Defense (DoD) Cyber Awareness Challenge and the DON Annual Privacy Training (PII). Contractors will have to create a MarineNet account to complete the required training.
MCEN Information Technology (IT) resources, if provided, are designated Controlled Unclassified Information (CUI) and other limited authorized purposes. DoD military, civilian personnel, consultants, and contractor personnel performing duties on MCEN information systems may be assigned to one of three position sensitivity designations.
1. Automated Data Processing (ADP)-I (IT-1): Favorably adjudicated T-5, T5R, (formerly known as Single Scope Background Investigation (SSBI)/SSBI Periodic Reinvestigation (SBPR)/SSBI Phased Periodic Reinvestigation (PPR)).
2. ADP-II (IT-2): Favorably adjudicated T-3, T3R, (formerly known as Access National Agency Check and Inquiries (ANACI)/National Agency Check with Law and Credit (NACLC)/Secret Periodic Review (S-PR)).
3. ADP-III (IT-3): Completed T-1, (formerly known as National Agency Check with Inquiries (NACI)).
Privileged users must maintain the baseline Cyberspace Workforce Information Assurance Technical (IAT) or Information System Security Manager (ISSM) relating to the position being filled. Privileged users are defined as anyone who has privileges over a standard user account, to include system administrators, developers, network administrators, code signing specialist, and service desk technicians.
All MCEN users must read, understand, and comply with policy and guidance to protect classified national security information, CUI, and prevent unauthorized disclosures in accordance with USMC Enterprise Cybersecurity Manual 007 Resource Access Guide and Chairman of the Joint Chiefs of Staff Instruction (CJCSI) 6510.01F.
MCEN IT resources are provided for official government use only and other limited authorized purposes. Authorized purposes may include personal use within limitations as defined by the supervisor or the local command. Auto forwarding of e-mail from MCEN Nonclassified Internet Protocol Router Network (NIPRNet) (MCEN-N) to commercial or private domains (e.g., Hotmail, Yahoo, Gmail) is strictly prohibited. E-mail messages requiring either message integrity or non-repudiation are digitally signed using DoD Public Key Infrastructure (PKI). All e-mail containing CUI, an attachment, or embedded active content must be digitally signed.
MCEN users will follow specific guidelines to safeguard CUI, which includes Personally Identifiable Information (PII) and Health Insurance Portability and Accountability Act (HIPAA) information. Non-official e-mail is not authorized for and will not be used to transmit any CUI.
Non-official e-mail is not authorized for official use unless under specific situations where it is the only means for communication available to meet operational requirements. This can occur when the official MCEN provided e-mail is not available but must be approved prior to use by the Marine Corps Authorizing Official (AO).
All personnel will use DoD authorized PKI certificates to encrypt e-mail messages if they contain any of the following:
CUI.
Any contract sensitive information that normally would not be disclosed to anyone other than the intended recipient as this is considered CUI.
Any privacy data, PII, or information intended for inclusion in an employee’s personal file or any information that would fall under the tenets of Message Identifier (MSGID):
DOC/5 USC 552A. Personal or commercial e-mail accounts are not authorized to transmit unencrypted CUI.
Any medical or health data, to include medical status or diagnosis concerning another individual.
Any operational data regarding status, readiness, location, or deployment of forces or equipment.
3.1.5.2 Contractor Assets Connectivity to the MCEN
The Contractor will comply with MCEN Message (MCENMSG)-Unification 003-14 ENABLING CONTRACTOR ASSET CONNECTIVITY TO THE MCEN. The Contractor representative will transfer the contractor-owned laptops to the MCTSSA, Infrastructure and Information Services Division (I2SD), to have the MCEN images places on each laptop before it is authorized to connect to the MCEN.
All contractor-owned laps must meet or exceed the USMC laptop specifications. A list of laptops authorized to be attached to the MCEN can be obtained from MCTSSA I2SD upon request.
After completion of the contact, or at such time as the contractor reclaims the asset from the USMC, non-government owned internal/external hard drives shall become the property of the U.S. Government. Once the hard drives have been removed, the laptops/assets will be returned to the Contractor. For additional questions regarding current system specifications contact the
MCTSSA I2SD.
3.1.5.3 Magnetic Hard Drive Storage Devices
This section covers the requirements of classified and unclassified internal and removable magnetic and solid state hard drives that store Government data. This includes, but is not limited to, storage area network (SAN) devices, servers, workstations, laptops/notebooks, printers, copiers, scanners, and multi-functional devices (MFDs) with internal hard drives, removable hard drives, and external hard drives. After disposal, replacement, turn in of hard drives or completion of the contract, non-government owned internal/external hard drives shall become the property of the U.S. Government in accordance with General Administrative (GENADMIN) Processing of Magnetic Hard Drive Storage Media for Disposal.
3.1.5.4 Common Access Card (CAC)
The Contracting Officer’s Representative (COR) will identify and only approve those contractor employees performing on this contract that require a CAC to perform their job function. In accordance with Headquarters, USMC-issued guidance relative to Homeland Security Presidential Directive – 12 (HSPD-12), all personnel must meet eligibility criteria to be issued a CAC. To meet the eligibility criteria, contractor employees requiring a CAC must obtain and maintain a favorably adjudicated Personnel Security Investigation (PSI). Prior to authorizing a CAC, the employee’s PSI record must indicate a completed and favorably adjudicated PSI. The minimum acceptable investigation is a T-1 or a NACI. If a contractor employee’s open investigation closes and is not favorably adjudicated, the CAC must be immediately retrieved and revoked. CACs are not issued for convenience.
Facility Security Officers (FSOs) are responsible for notifying the MCTSSA Personnel Security (PERSEC) office at 760-725-1672 if any contractor performing on this contract receives an unfavorable adjudication after being issued a CAC. Due to insider threat concerns, the Contractor is requested to notify the MCTSSA PERSEC Office within 24 hours of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract if they have been issued a CAC and/or a MCTSSA badge.
Each CAC is issued with a “ctr@usmc.mil” e-mail account that the individual contractor is responsible to maintain as active by logging in on a regular basis (at least twice a month), sending an e-mail and clearing any unneeded e-mails. Contractors issued a CAC are prohibited from “auto- forwarding” e-mail from their .mil e-mail account to their .com e-mail account. If the “ctr@usmc.mil” e-mail account is not kept active, G-6 will deactivate the account and the CAC will also lose its functionality.
Contractor employees shall solely use their government furnished “ctr@usmc.mil” e-mail accounts for work supporting the USMC, conducted in fulfillment of this contract, and shall not use a contractor supplied or personal e-mail account to conduct official U.S. Government business. The use of a contractor or personal e-mail account for contractor business or personal use is allowed, but only when using cellular or a commercial internet service provider.
If a contractor loses their eligibility for a CAC due to an adverse adjudicative decision, they have also lost their eligibility to perform on Marine Corps Systems Command (MCSC) contracts.
3.1.6 Security Requirements
The Contractor shall provide personnel to perform all work specified within this PWS.
The selection, assignment, reassignment, transfer, supervision, management, and control of contractor personnel shall be the responsibility of the Contractor.
The Contractor is required to comply with Public Law 105-270, Section 5(2)(A). This law states that Contractors will not perform inherently governmental functions. Section 5(2)(A) of this Public Law defines the term “inherently governmental function” as “a function that is so intimately related to the public interest as to require performance by Federal Government employees.” Per Section 5(2)(B), inherently governmental functions include management of Government programs requiring value judgements, conduct of foreign relations, selection of program priorities, and the direction of intelligence and counterintelligence operations. Per Section 5(2)(C), inherent governmental functions DO NOT include, (i) gathering information for or providing advice, opinions, recommendations, or ideas to Federal Government officials or (ii) any function that is primarily ministerial and internal in nature.
During all hours of operation on government property, all contractor personnel shall wear identification cards that identify the employee’s name and the contractor’s business name, plainly visible in the upper chest area. Any special government badges provided shall be worn and visible. All contractor personnel shall be in professional, suitable attire (appropriate to the particular condition, occasion, location, and job assignment). All contractor personnel shall conduct themselves in a professional, courteous manner and shall comply with the directives pertaining to privately owned vehicles at the specific location.
3.1.6.1 Eligibility for Access to Classified Information
This contract will require Contractors to have a valid Secret Facility Clearance prior to classified performance. It will be the responsibility of the Contractor to obtain and maintain the specified classified access eligibility. The prime contractor and all subcontractors (through the prime contractor) shall adhere to all aspects of 32 CFR Part 117 NISPOM.
All personnel identified to perform on this contract shall maintain compliance with the DoD, DON, and Marine Corps Information and Personnel Security Policy to include completed background investigations (as required) prior to classified performance. This contract shall include a DoD Contract Security Classification Specification (DD-254) as an attachment.
Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. DCSA will not authorize contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements but are required to submit investigations for those employees requiring both Secret access and IT-II designation. The Government Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations. However, the contractor FSO is required to establish, populate, and own the Defense Information System for Security (DISS) record of every contractor processed for and/or issued a CAC or submitted for IT level duties. The Contractor is required to provide a roster of prospective Contractor employees performing IT-I duties to the MCTSSA COR. This roster shall include full names, Social Security numbers, e-mail addresses, and phone numbers for each contractor requiring investigations in support of IT Level designations. The COR will verify the IT-I requirements and forward the roster to the GCASO. Contractors found to be lacking required investigations will be contacted by the GCASO. In accordance with DoD Instruction (DoDI) 5200.48 - DoD CUI, all contractors supporting MCTSSA who receive, store, or generate CUI are required to take the DoD Mandatory CUI training, available on the Security Awareness Hub at:
https://securityawareness.usalearning.gov/cui/index.html. Per DoDI 5200.48 and pursuant to contractual requirements, DoD contractors require initial CUI training and annual CUI refresher training.
Operations Security (OPSEC) requirements – While performing aboard Navy/USMC sites, the Contractor shall comply with the provisions of DoD Directive 5205.02E – DoD Operations Security (OPSEC) Program, SECNAV 3070.2, CMDO 3070.1A, MCO 3070.2A, and the MCSC Order P5510.2B Security Manual, at all other sites the Contractor shall comply with the local command and/or program OPSEC plan. Contractor personnel shall follow OPSEC concepts and principles in the conduct of this requirement to protect critical information, personnel, facilities, equipment, and operations from compromise. All Contractors (including subcontractors) shall supplement their current security practices by requiring any personnel involved in executing this contract to complete government-sponsored and administered OPSEC training. FSOs are responsible for notifying the MCTSSA PERSEC Office at 760-725-1662 if any Contractor performing on this contract receives an unfavorable adjudication as any issued CAC would need to be revoked and retrieved. Due to insider threat concerns, the FSO is also requested to notify the MCTSSA PERSEC Office within 24 hours of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any Contractor performing on this contract, if they have been granted an IT designation, issued a CAC and/or a MCTSSA badge. The FSO shall notify the Government (written notice) within 24 hours of any Contractor personnel added or removed from the contract if they have been granted classified access, granted IT designations, and issued a CAC and/or a MCTSSA Badge.
3.1.6.2 Qualified U.S. Contractors
The Contractor shall certify in writing to the Government that personnel supporting this contract are qualified U.S. Contractors, per DoD 5220.22‐M, Chapter 2, Section 2. Qualified U.S.
Contractors are U.S. citizens and persons admitted lawfully into the United States for permanent residence and are in the United States. All personnel identified on the certification or supporting this contract, or both, shall follow the DoD, DON, and the Marine Corps Information and Personnel Security Policy to include completed background investigations (as required) prior to start.
3.1.6.3 Base Security
The Contractor shall comply with Marine Corps Base (MCB) Camp Pendleton, CA security regulations and policies. The Contractor’s staff shall be U.S. or naturalized citizens, whose military duty (if applicable) was not terminated by a dishonorable or bad conduct discharge, are not subject to an outstanding criminal warrant, have no felony convictions, and have no more than three criminal misdemeanor convictions within the last 7 years. Additionally, the Contractor shall not have any criminal misdemeanor or felony convictions for crimes of a sexual nature, crimes of violence, crimes related to gang activity or hate crimes, or crimes resulting from the possession or distribution of illegal drugs.
Contractor personnel shall comply with all emergency rules and procedures established for MCB Camp Pendleton. All personnel aboard MCB Camp Pendleton, CA are subject to random inspections of their vehicles, personal items, and themselves. Consent to these inspections is given when personnel enter MCB Camp Pendleton, CA.
3.1.6.4 Site Security
In addition to base security requirements (Section 3.1.6.3), the Contractor shall comply with site security regulations and policies. Contractor personnel shall always wear a properly issued MCTSSA badge. The Contractor shall comply with SECNAV Instruction (SECNAVINST) 5510.30C, Jan 2020, DON Personnel Security Program enclosure 10 and Federal Acquisition Regulation (FAR) 52.204‐2 for access to USMC bases and information. All visit requests shall be provided via the DISS system at least 5 working days prior to scheduled visits. Individuals shall have two forms of picture identification.
3.1.6.5 Defense Biometric Identification System (DBIDS)
MCB Camp Pendleton, CA uses DBIDS for base access. The Contractor will need to call 760- 763-7604 for information or go to the Las Pulgas gate to enroll. Failure to participate in the program will restrict access to the base and may not be used as a reason for late or nonperformance of services. All Contractors and their personnel are required by MCB Camp Pendleton, CA regulations to meet the requirement for installation access, pass a background check, and have their identity verified to receive unescorted access. No foreign nationals shall be permitted on MCB Camp Pendleton, CA under this contract.
3.1.6.6 Operations Security (OPSEC) Requirements
OPSEC prevents the inadvertent compromise of sensitive unclassified and classified activities, capabilities, or intentions at the tactical, operational, and strategic levels. Contractor personnel must adhere to all government OPSEC measures currently in place at the government facility.
The Contractor shall provide OPSEC training to all contractor personnel supporting this effort.
Contractor personnel shall not take pictures from any device while aboard the compound or in the test areas.
3.1.6.7 MCTSSA Check-Out Procedures
Upon termination of the contract or contractor personnel no longer performing work under this PWS, contractor personnel must first check out with the MCTSSA Communications Security (COMSEC) Custodian and Personnel Security Managers, before turning the government-issued CAC and MCTSSA badge into the COR.
3.1.7 Safety – Accidents and Mishaps
The Contractor shall comply with all applicable requirements that are established by the Occupational Safety and Health Administration (OSHA) and all applicable installation safety orders and procedures. Accidents and mishaps that involve government property, government personnel, or contractor personnel will be reported to the Government within 24‐hours (8‐hours or less for a Class A mishap). MCTSSA is required to submit an Operations Event/Incident Report (OPREP‐3) or unit Situation Report (SITREP) report and the Contractor is responsible for OSHA notification.
Damage to government property, or injury to Government or Contractor employees must be reported to the COR and Contracting Officer within 4 hours. The Contractor’s initial reports may be verbal but shall be followed up in writing within 24 hours. Contractor reports of incidents with security implications shall include full details of the incident, any remedial actions taken by the Contractor, and shall comply with all applicable security instructions.
The Contractor shall investigate all accidents occurring on government property involving Contractor employees and report the findings (on applicable forms) to the COR and Contracting Officer within 3 calendar days of the incident.
Reportable incidents shall be reported to the Government by the Contractor, per the requirements of this PWS via submission of CDRL B002 – Accident Mishap Report. The data deliverables shall be generated and delivered to the Government for reportable events in accordance with the specific performance requirements and DD Form 1423 per this PWS.
CDRL B002 – DI‐MISC‐82188, Accident Mishap Report
3.1.8 Locations and Hours of Work
Work will be performed primarily at MCTSSA, Camp Pendleton, Monday through Friday, 0800- 1630, excluding government holidays.
All planned absences or changes to the schedule require prior approval by the Government. It is the responsibility of contractor personnel to inform the Government if they will not be present, if there is a change to the schedule, or when working from an alternate location.
3.1.8.1 Overtime Capability
There is no overtime for this PWS.
3.1.9 Dress and Conduct
Contractor personnel shall dress in a manner consistent with the task for which hired, and the work being performed. In most cases, business casual is appropriate. Clothing must not be excessively revealing, worn out, or ill‐fitting. Contractor personnel shall always present a professional demeanor while performing on this contract. Behavior, which is disruptive, unsafe, disrespectful, offensive, or detrimental to morale shall not be tolerated. The Contractor shall ensure that its personnel do not allow personal business to interfere with job performance, nor use government resources for personal business.
3.1.10 Travel
No travel shall be required in performance of this PWS.
3.1.11 Privacy Act Information
The Contractor shall comply with requirements of DoD Directive (DoDD) 5400.11 regarding control of Privacy Act information. Specifically, the Contractor shall ensure that any PII (e.g., individual’s name and associated personal contact information or Social Security numbers) is restricted to access required for execution of this contract and is not disclosed or stored on any unsecure systems. Contractor personnel shall adhere to the Privacy Act, (5 U.S.C. § 552a) and applicable agency rules and regulations. Contractor personnel shall not divulge, or release privacy data or information developed or obtained in the performance of this contract, until made public or specifically authorized by the Government.
3.1.12 Program Management
The Contractor shall designate a primary POC that will be responsible for the accomplishment of all tasks in this PWS. The designated POC shall plan, organize, manage, schedule, implement, control, analyze, and report on all elements of the PWS. The designated POC shall be prepared to present and discuss the status of contract activities, requirements, and issues with the Government. The designated POC shall also be responsible for assessing requirement changes and implementing approved changes, as authorized by the Contracting Officer.
3.1.12.1 Contract Management Plan
The Contractor shall develop a management plan to support the requirements of this PWS. The management plan describes the contractor’s organization, assignment of functions, duties, responsibilities, management procedures and policies, and reporting requirements for the conduct of contractually imposed tasks, projects, or programs. The COR will establish a due date for the management plan. The final deliverable is due 5 working days after receipt of government comments on the initial submission unless a different schedule is agreed to by the Government and the Contractor.
CDRL B001 – DI‐MISC‐80508B, Technical Report - Study/Services – Management and Technical Plan
3.1.12.2 Monthly Status Report (MSR)
The Contractor shall prepare and deliver an MSR for the activities supported during the month.
The MSR shall be delivered in the version of Microsoft Office used by MCTSSA. Contractor format is acceptable. The MSR shall be sent to the Government via e-mail and shall address all data required in the DID, which shall include, at a minimum, a description of the support provided during the reporting period, a list of completed events, and the status of ongoing efforts.
The reporting period will be from the first to last workday of each month, beginning 30 calendar days after contract award.
The MSR shall be provided to the Government on the 6th day of each month for review. The final MSR shall be delivered by the 10th of each month.
CDRL B003 – DI‐MGMT‐81928, Contractor’s Progress Status and Management Report
– Monthly Status Report
3.1.12.3 Mobilization/Phase-Out Period
3.1.12.3.1 Mobilization
During the mobilization period, the Contractor shall prepare to assume full responsibility for all areas of operation in accordance with the terms and conditions of this contract. To minimize any decreases in productivity and to prevent possible negative impacts on services, the Contractor shall have the required personnel on board during the mobilization period. Mobilization requirements will not exceed 30 days. The Contractor shall assume responsibility for all contract requirements the first day of full contract performance.
3.1.12.3.2 Phase-Out
The Contractor shall retain full responsibility for meeting contract requirements until completion of the phase-out period. The Contractor shall provide all support to ensure a smooth transition and minimize impact on operational readiness. The Contractor shall not defer any requirements for the purpose of avoiding responsibility or for transferring such responsibility to the succeeding Contractor. The Contractor shall provide access to all work sites and to all documentation on a not‐to‐interfere basis during the phase-out period when the follow‐on Contractor is mobilizing.
The Contractor shall provide all phase‐out deliverables to the Government prior to the conclusion of the contract period of performance (PoP). Additionally, the Contractor is responsible for maintaining an inventory of all technical data delivered, furnished, or otherwise provided to the Government under this contract and the means for transferring all technical data to the succeeding Contractor. The actual transfer of technical data from the incumbent Contractor to the follow-on Contractor will be made through the Government. The Contractor shall report phase-out status monthly in the MSR, while keeping a running record of previous actions in the MSR, per Section 3.1.12.2.
3.1.12.4 Identification of Contractor Personnel
The Contractor shall provide to the Government the name or names of the responsible supervisory person or persons authorized to act for the Contractor. The Contractor shall remove from the site any individual whose continued employment is deemed by the Contracting Officer to be contrary to the public interest or inconsistent with the best interests of national security.
The Contractor shall provide to the Government, a roster of contractor personnel assigned to the contract and update the list monthly in its MSR submission required to be submitted pursuant to Section 3.1.12.2.
3.1.12.5 Post Award Conference (PAC)
The PAC is the first meeting of key Government and Contractor participants. During the conference, participants will discuss the roles and responsibilities and agree on an interpretation of contract requirements for all parties. The PAC includes a review of contract terms, conditions and requirements, line items, and sequence of events needed for successful execution of the contract effort. The Contractor shall attend and participate in a PAC at the MCTSSA facilities located at Camp Pendleton, CA. The PAC shall be scheduled no later than 10 calendar days after contract award. The Contractor shall coordinate with the Government to arrange a schedule and agenda for the PAC prior to the meeting. The Contractor shall prepare the conference agenda and meeting minutes. A draft deliverable is due by the due date established by the Government. The final deliverable is due 5 working days after receipt of government comments on the initial submission, unless a different schedule is agreed to by the Government and the Contractor.
CDRL B004 – DI‐ADMN‐81249C, Conference Agenda
CDRL B005 – DI‐ADMN‐81250C, Conference/Meeting Minutes
3.1.12.6 Technical Documentation
The Contractor shall develop and deliver technical documentation pursuant to this PWS. A draft deliverable is due by the due date established by the Government. The final deliverable is due 5 working days after receipt of government comments on the initial submission unless a different schedule is agreed to by the Government and the Contractor.
CDRL A001 – DI‐MISC‐80508B, Technical Documentation
3.1.12.7 Data
3.1.12.7.1 Data Rights
Data rights is addressed by the appropriate clauses, which have been inserted into the contract.
Upon disposal, replacement, turn in of hard drives, or completion of the contract, non-government-owned internal/external hard drives shall become the property of the U.S.
Government in accordance with GENADMIN Processing of Magnetic Hard Drive Storage Media for Disposal. This applies to unclassified internal and removable magnetic and Solid- State Drives used to store Government data.
3.1.12.7.2 Data Management
The Contractor shall provide a POC for data oversight that shall ensure data delivered, furnished, or otherwise provided for under this contract includes the appropriate version, format, associated rights, and purpose. The security of the data and the protection of classified, privacy related, or proprietary data shall be the responsibility of the Contractor.
3.1.12.7.3 Distribution Statement
The appropriate distribution statement shall appear on the cover or title page of all new and updated deliverable technical documents, data, and information (e.g., engineering drawings, technical notes and manuals, test plans, test or technical reports, test procedures, and computer software documentation), whether produced in hard copy or soft copy format.
3.1.13 Government Property
There is no reportable government property being furnished to the Contractor in support of the requirements specified in this PWS. In accordance with FAR 45.101, software and intellectual property are not defined as government property or reportable as such per FAR 45.000(b)(4).
Consistent with FAR 45.000(b)(5), government property incidental to the place of performance remains the responsibility of the Government. This includes office space, desks, chairs, telephones, and hand-held radios if issued. The Contractor shall procure, maintain, and ensure serviceability of all IT assets required to accomplish the tasks delineated in the PWS. IT assets requiring connectivity to the MCEN shall be of the make and model identified on the Marine Corps Enterprise Desktop Standardization (MCEDS) Supported Models published list. A list of laptops authorized to be attached to the MCEN, and not projected to be end-of-life before the next refresh cycle, can be obtained from the COR upon request. After award, the Contractor shall notify the COR of all IT assets requiring connectivity to the MCEN. The COR will facilitate the reimaging process of the IT assets for authorization to connect to the MCEN.
Upon completion of the contract, or at such time as the IT assets are removed from use under this contract, the contractor will coordinate with the COR for the destruction of the hard drives.
Once hard drives have been destroyed, the IT assets will be returned to the Contractor. Any materials purchased by the contractor using Other Direct Cost (ODC) funds in support of this PWS will remain the property of the U.S. Government.
3.1.14 Government-Furnished Information (GFI)
The Government will provide the Contractor access to the following information and automated services in support of this PWS:
Access to commercial internet and MCEN. This includes a CAC to support PKI access and Marine Corps web services, if determined by the Government to be necessary for the tasking within this PWS.
A user and e-mail account on the MCEN-N, MCEN SECRET Internet Protocol Router Network (SIPRNet) (MCEN-S), and Combined Enterprise Regional Information Exchange System (CENTRIXS) domains, when determined by the Government to be necessary for the tasking within this PWS.
Contractors are required to complete the classes listed below. The Cyber Awareness Challenge and PII training must be completed on MarineNet (https://www.marinenet.usmc.mil/my.policy) before an e-mail account is issued, and annually thereafter by 30 September.
o Current fiscal year DoD Cyber Awareness Challenge o DON Annual Privacy Training (PII) o Antiterrorism Level I Awareness Training o DON’s Secretary of Defense (SECDEF) Directed OPSEC and Unauthorized Disclosure Training o Counterintelligence Awareness and Reporting (CIAR) o Risk Management for USMC Civilians o Records Management in the DON o CUI Training o Derivative Classification Training (https://securityawarenesstraining.usalearning.gov) o Unauthorized Disclosure and Classification Management (https://securityawarenesstraining.usalearning.gov) o HQMC Annual Sensitive Compartmented Information (SCI) Awareness Brief o Originator Control (ORCON)
Contractor personnel are authorized to receive training on government systems and software when training is not available in the commercial sector.
The training completion certificates shall be delivered to the Government by the Contractor, per the requirements of this PWS via submission of CDRL B006 – Contractor Training Completion Report. The certificates shall be sent to the Government via e-mail in Portable Network Graphics (PNG) or Portable Document Format (PDF) format within 7 days of completion.
CDRL B006 – DI-MGMT-82151, Contractor’s Training Plan – Contractor Training Completion Report
3.1.15 Invoicing
The Contractor shall submit an electronic copy of an invoice, no more than once a month, via the Wide Area Workflow (WAWF) module within the Procurement Integrated Enterprise Environment (PIEE).
The Contractor shall be required to implement the Defense Federal Acquisition Regulation Supplement (DFARS) process to submit an electronic payment request. To implement DFARS
252.232-7003, “Electronic Submission of Payment Requests and Receiving (December 2018)”, the USMC utilizes WAWF – Receipt/Acceptance (WAWF-RA) to electronically process Contractor requests for payment. This process allows DoD Contractors to submit and track invoices and receipt/acceptance documents electronically. The Contractor shall be required to utilize this system when processing invoices and receiving reports. The Contractor shall (1) ensure an Electronic Business Point of Contact (EBPOC) is designated in the System for Award Management (SAM) website at https://sam.gov, and (2) register to use WAWF-RA at the https://wawf.eb.mil website, within 10 calendar days after award of this contract or modification.
The procedures to register are available at https://wawf.eb.mil.
3.1.16 Administrative Authority
3.1.16.1 Contracting Officer
Only the Contracting Officer has the authority to authorize deviations from the terms and conditions of this contract, including deviations from the specifications and requirements stated herein. In the event the Contractor does deviate, without the issuance of a duly executed contract modification, such deviation shall be at the risk of the Contractor, and any costs related thereto, shall be borne by the Contractor.
3.1.16.2 Contracting Officer’s Representative (COR)
The COR is limited to providing program-specific clarification to the Contractor’s task leader and does not have the authority to act, either directly or indirectly, that would change the pricing, quality, place of performance, delivery schedule, or other terms and conditions of this contract, or to direct work beyond the scope of this PWS. If the Contractor perceives that the COR or other government personnel are requesting an effort outside the scope of this contract, the Contractor shall promptly notify the Contracting Officer in writing. No action shall be taken by the Contractor until the Contracting Officer has issued a contractual change or otherwise resolved the issue. The COR will be appointed at the time of contract award. The Government reserves the right to reassign the COR position.
3.2 Specific Requirements
The specific requirements for this PWS include Program Management, and ASSO/CMDSAPSO duties.
3.2.1 Program Management
The Contractor shall provide personnel to manage ASSO support to accomplish PWS requirements and scope. The ideal candidate is required to have 3+ years of PM experience in the DoD security field. The Program Management Professional (PMP) certification is desired.
The PM duties include:
1. The PM shall ensure efficient administration and effective supervision of the efforts under this PWS. A clear line of project authority shall exist among all organizational elements. To support this section, the Contractor and COR will conduct the PAC no more than 10 calendar days after award, per Section 3.1.12.5. The intent is to review the
PWS, deliverables, processes, and directives to ensure concurrence and understanding of the scope and details per this PWS. The PM and COR will coordinate the date, time, location, and agenda for the PAC.
2. The PM shall complete authorized assignments in a manner that thoroughly fulfills performance objectives within established schedule requirements and established cost controls. The PM shall document all accomplishments that are directly relevant to the PWS and provide a monthly status report that documents the status of all efforts pertaining to this PWS, per Section 3.1.12.2.
3. Manage Contractor Support. The Contractor shall manage all subcontracts under their purview to ensure that the tasking of this PWS is fully met.
4. The Contractor’s PM will follow and ensure compliance of all MCTSSA processes guides and directives by civilian and contractor support team members. The MCTSSA POC will provide the current approved guides and directives at the PAC.
3.2.2 ASSO/CMDSAPSO Duties
The Contractor shall provide personnel to perform ASSO/CMDSAPSO duties. The ideal candidate is required to have:
Current DoD Top Secret/Sensitive Compartmented Information (TS/SCI) Access.
Working knowledge of SCI requirements and security policies.
Knowledge of the National Background Investigative Service (NBIS), Joint Deployable Intelligence Support System (JDISS), SCI network, DISS, and the SIPRNet.
Must have a working knowledge of Executive Order 12563.
Familiarity with National, Defense Intelligence Agency (DIA), and DoD SCI security regulatory requirements.
Must have a minimum of 6 years of full-time experience working with SCI in all security disciplines, but specifically in physical security and Sensitive Compartmented Information Facilities (SCIF) accreditation.
Must have attended and completed a formal SSO certification training and SCIF physical security course within the last 5 years.
The ASSO/CMDSAPSO duties include:
1. Develops, evaluates, maintains, and/or operating systems, policies, devices, procedures, and methods used for safeguarding classified SCI information, property, and materials.
2. Investigates SCI security infractions, makes recommendations and prepares required reports.
3. Maintains listings of available SCI electrical and hard copy products, validates product requirements, and ensures dissemination to authorized users.
4. Reviews all derogatory information from the local supporting military law enforcement agency involving SCI-indoctrinated personnel and takes appropriate action.
5. Evaluates SCI risk and recommends appropriate countermeasures.
6. Creates standard operating procedures for operations involving the use or transport of classified and SCI material.
7. Conducts SCI indoctrinations and debriefs for command personnel and Contractors working at MCTSSA.
8. Reports security violations and Practices Dangerous to Security (PDS) per DoD 5105.21-M.
9. Manage PWSs and material submittals for construction and electronic systems contracts in support of SCIF accreditation/remodel actions.
10. Coordinates with the Cognizant Security Authority for pre-con and final fixed facility checklists, construction security plans, and modification security plans.
11. Prepares and revises, as needed, all physical accreditation paperwork, to include the fixed facility checklists.
12. Develops and disseminates guidance to units on escort procedures/requirements for Contractors and ensure compliance through on-site visits.
13. Conducts SCI physical and technical security (Telecommunications Electronics Material Protected From Emanating Spurious Transmissions (TEMPEST)/Technical Surveillance Countermeasures (TSCM)) actions.
14. Assists in providing overall physical security and will ensure that all current and future SCIFs comply with the physical security standards outlined in Intelligence Community Directive (ICD) 705 all other applicable directives and established policies.
15. Conducts an annual SCIF self-inspection and maintains records of these self-inspections for a period of 3 years.
16. Maintains appropriate accreditation documentation for the MCTSSA SCIF, communications system, and information systems under the MCTSSA and System Command’s security cognizance.
17. Obtains approval from DIA/DIA Counterintelligence and Security Activity (DAC) for SCIF modifications. Notifies DIA/DAC of changes to SCIF security posture (e.g., fire, explosion, natural or other disasters).
18. Coordinates and include SCIF security in the Emergency Action Plan (EAP).
19. Requests and coordinate TSCM surveys with Office of Special Investigations (OSI).
20. Conducts penetration exercises annually and alarm tests semiannually and records the events in a logbook.
21. Coordinates with local Provost Marshal’s Office and provides rosters of individuals responsible for the overall security of the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .