Attachment 1 Base PWS ERS COMS S.pdf

PDF 568 KB Posted

Attached to
ERS COMS-Systems MATOC Amended RFP 0003 Federal contract opportunity
Solicitation number
M6785420R7828
Issued by
United States Marine Corps

About this file

This is a solicitation for an Equipment Related Services Contractor Operator and Maintenance Services Multiple Award Task Order Contract. The Marine Corps Systems Command seeks to establish an indefinite delivery/indefinite quantity MATOC to provide sustainment support for existing and future training systems such as simulators, virtual trainers, and egress equipment. Services include operations, maintenance, repairs, modifications, and training support. The period of performance is 60 months with option periods. Task orders will be issued for locations including Camp Pendleton, Camp Lejeune, Twenty Nine Palms, and installations in Japan and worldwide. The estimated award is in the second quarter of fiscal year 2021. The North American Industry Classification System code is 811310 with a small business size standard of $8 million. The solicitation intends to award a small business set-aside using firm-fixed-price and cost-reimbursement contract types. Responses are due by December 7, 2020.

View the file

Other files for this federal contract opportunity

Show all 19

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

UNCLASSIFIED

Base Contract Performance Work Statement (PWS) for

Equipment Related Services (ERS)

Contractor Operator and Maintenance

Services (COMS)-Systems

Version 1.5

16 September 2020

Prepared by

Program Manager, Training Systems

DISTRIBUTION STATEMENT A. Approved for public release. Distribution is unlimited.

- 2 -

Table of Contents INTRODUCTION .............................................................................................................….4

GENERAL

SCOPE

APPLICABLE DOCUMENTS

DEPARTMENT OF DEFENSE INSTRUCTIONS, DIRECTIVES, STANDARDS AND

GUIDES

DEPARTMENT OF THE NAVY INSTRUCTIONS, DIRECTIVES, STANDARDS AND

GUIDES

MARINE CORPS ORDERS, MANUALS, DIRECTIVES AND GUIDES

AVAILABILITY OF DOD DOCUMENTS

OTHER DOCUMENTS, DRAWINGS AND PUBLICATIONS

REQUIREMENTS

GENERAL REQUIREMENTS

NON-PERSONAL SERVICES

BUSINESS RELATIONS

CONTRACTOR PERSONNEL, DISCIPLINES, AND SPECIALTIES

RESOURCE REQUIREMENTS

SECURITY REQUIREMENTS

VISIT REQUESTS

SAFETY

LOCATIONS AND HOURS OF WORK

DRESS AND CONDUCT

TRAVEL

PROGRAM MANAGEMENT……

GOVERNMENT PROPERTY………

ENVIRONMENTAL AND SAFETY REQUIREMENTS

SPECIAL QUALIFICATIONS/REQUIREMENTS

3.1.15 HELP DESK

3.1.16 MANAGEMENT INFORMATION REPORT

3.1.17 MAINTENANCE SUPPORT

- 3 -

3.1.18 JANITORIAL MAINTENANCE .....................................................................................….37

3.1.19 OPERATIONAL AVAILABILITY

3.1.20 SYSTEM OPERATIONS

3.1.21 SYSTEM FUNCTIONALITY

3.1.22 SYSTEM REALLOCATION

3.1.23 TRAINING SYSTEM MODIFICATIONS

3.1.24 PRE-MODIFICATION AND POST MODIFICATION INSPECTION

3.1.25 TRANSITION OF TRAINING SYSTEM TO THIRD PARTY CONTRACTOR

3.1.26 SYSTEM FOR AWARD MANAGEMENT (www.sam.gov) SERVICE CONTRACT

REPORTING……………………………………………………………………………….. 40

3.2 DELIVERABLES

3.3 SPECIFIC REQUIREMENTS

APPENDIX A. JOINING CONTRACTOR MACHINE TO THE MCEN

APPENDIX B. USMC CONTRACT SUPPORT USER AGREEMENT FOR THE MCEN… 43

APPENDIX C. CONTRACTS TO BE PERFORMED IN JAPAN

APPENDIX D. STATUS OF FORCES AGREEMENT (SOUTH KOREA)

- 4 -

INTRODUCTION

GENERAL

This Performance Work Statement is in support of the Equipment Related Services (ERS) Contractor Operator and Maintenance Services (COMS)-Systems Multiple Award Task Order Contract (MATOC). This MATOC is structured to provide the Government maximum flexibility in the form of the issuance of task orders (TOs) through an expedited ordering process to satisfy the ERS COMS-Systems requirements for overall total life cycle management, as well as other Marine Corps training requirements that fall within the scope described below. TO Performance Work Statements (PWSs) will provide the specific performance requirements, performance standards, metrics, assessment measures, and schedules for each TO.

SCOPE

All DoD services fall within one of nine (9) Service Portfolio Groups within DoD’s Taxonomy of Services, which is required pursuant to DoD FAR Supplement (DFARS) Policy, Guidance and Instruction (PGI) 237.102-74. PM TRASYS’ contracting authority is limited to MARCORSYSCOM’s authority delegated in SECNAVINST 5400.15C. PM TRASYS is the Marine Corps Systems Command (MARCORSYSCOM) Program Manager responsible for the life cycle systems support for ground training systems, services, environments, and devices. Therefore, PM TRASYS has the authority to award contracts in support of five (5) of the 9 Service Portfolio Groups identified in DoD’s Taxonomy of Services, which includes the ERS Portfolio Group.

PM TRASYS intends to award a Multiple Award Task Order Contract (MATOC) that is aligned with the ERS Service Portfolio Group within DoD’s Taxonomy of Services, and associated with the Product Service Code (PSC) “L069” which correlates to Technical Representative: Training Aids and Devices. The ERS COMS- Systems MATOC includes contractor logistics sustainment support for sustainment support, and training requirements. Notwithstanding, a TO can be issued for any of the Service Portfolios and their subordinate Portfolio Categories and PSCs within the ERS Service Portfolio Group, which includes: Maintenance, Repair and Overhaul; Equipment Modification;

Installation of Equipment; Quality Control; Technical Representative Services; Purchases & Leases;

and Salvage Services. Moreover, there may be occasions where a TO for ERS COMS-Systems operations and maintenance requirements is issued under a separate portfolio group, portfolio, category and code. This judgement is reserved to contracting and financial management personnel, considering the description of the service requirement transmitted by the requiring activity.

The scope of this effort is intended to be broad in nature and entails sustainment support for all existing and any future USMC training systems that are not exclusively utilized on ranges and not subjected to live fire including, but not limited to: Underwater Egress Trainer (UET); Supporting Arms Virtual Trainer (SAVT); Combat Vehicle Training Systems (CVTS); Combat Convoy Simulator (CCS); Virtual Combat Convoy Trainer/Reconfigurable Virtual Simulator (VCCT/RVS);

Indoor Simulated Marksmanship Trainer (ISMT); Operator Driver Simulator (ODS); Improved Moving Target Simulator (IMTS); and the Dry Egress Trainers (DRET). Additional organizations, locations or services may be added, or services may be curtailed or eliminated from existing organizations or locations during the life of this MATOC to best satisfy evolving Marine Corps training and education requirements.

- 5 -

In general, equipment to be supported under this MATOC are simulators or simulations systems that use electronic and/or mechanical means to reproduce conditions necessary for an individual, team, unit, or crew to rehearse operational tasks and technical skills in accordance with training objectives.

The simulators and simulations systems replicate the functions and environment of actual equipment or systems and consist of training devices, machines, or apparatuses that reproduce operational conditions synthetically.

TOs will provide the specific performance requirements, locations, schedules, standards, metrics, and assessment measures for each TO. In the event of a conflict between this Base Contract PWS and the TO PWS, the TO PWS requirements that are specific to the training system take precedence. The specific scope of the TO may include, but is not limited to, the following:

• Providing new equipment, and instructor and key personnel training;

• Creating (new), or modifying (existing) exercise scenarios;

• Performing preventative, field, and depot maintenance on training systems;

• Conducting maintenance trend and obsolescence analysis and submittal of recommend engineering change proposals;

• Developing and providing After Action Reviews (AARs) to training audiences;

• Providing operators in support of ground training and readiness standards;

• Maintaining Operational Availability standards as defined by each applicable TO.

This ERS COMS-Systems MATOC does not include any construction of real property.

Construction of real property is an installation requirement and will be performed by Government personnel or under a NAVFAC contract. Should the ERS COMS Systems Contractor identify a maintenance requirement that requires construction of real property, the Contractor shall notify the Contracting Officer Representative (COR) for appropriate action.

APPLICABLE DOCUMENTS

The current version of the following documents form a part of this PWS to the extent specified herein. Moreover, the latest version of the following documents in effect at the time of the issuance of a TO PWS will supersede the prior version of the document cited in this PWS. In addition, the Contractor shall also comply with all applicable local and base policies. Unless otherwise noted, in the event of a conflict between the PWS and the references cited herein, the text of the TO PWS takes precedence.

DEPARTMENT OF DEFENSE INSTRUCTIONS, DIRECTIVES, STANDARDS AND

GUIDES

• DoDD 4715.E Environmental, Safety, and Occupational Health (ESOH)

• DoDM 5200.1 Volume 1 – DoD Information Security Program: Overview, Classification, and Declassification

• DoDM 5200.1 Volume 2 – DoD Information Security Program: Marking of Classified

Information

• DoDM 5200.1 Volume 3 – DoD Information Security Program: Protection of Classified Information

• DoDI 5200.48 Controlled Unclassified Information

- 6 -

• DoD Directive 5205.02E – DoD Operations Security (OPSEC) Program

• DoDI 5220.22 – National Industrial Security Program (NISP)

• DoD 5220.22-M – National Industrial Security Program Operating Manual

• DoDI 5230.09 – Clearance of DoD Information for Public Release

• DoDI 5230.24 – Distribution Statements on Technical Documents

• DoDD 5230.25 – Withholding of Unclassified Technical Data from Public Disclosure

• DoDI 5400.11 – DoD Privacy and Civil Liberties Programs

• DOD 5500.07-R – Joint Ethics Regulation

• DoDI 6055.01 – DoD Safety and Occupational Health (SOH) Program

• DoDD 8140.01– Cyberspace Workforce Management

• DoDI 8500.01 – Cybersecurity

• DoDI 8510.01 – Risk Management Framework (RMF) for DoD Information Technology (IT)

• DoD 8570.01-M – Information Assurance Workforce Improvement Program

• DoDD 4500.54E DoD Foreign Clearance Program

DEPARTMENT OF THE NAVY INSTRUCTIONS, DIRECTIVES, STANDARDS AND

GUIDES

• SECNAVINST 3070.2 – Operations Security

• SECNAV M-5216.5 – Department of the Navy Correspondence Manual

• SECNAV M-5239.1 – Department of the Navy Information Assurance Manual

• SECNAVINST 5510.30C – Department of the Navy Personnel Security Program

• SECNAVINST 5510.36B – Department of the Navy Information Security Program

MARINE CORPS ORDERS, MANUALS, DIRECTIVES AND GUIDES

• MCO 3070.2A – The Marine Corps Operations Security Program

• MCO 5100.29 B – Marine Corps Safety Program

• MCO 5200.17E – Standardization of Military and Associated Terminology

• MCO 5216.20B – Marine Corps Supplement to the Department of the Navy Correspondence

Manual

• MCO 5216.9Y – Headquarters U.S. Marine Corps Organization and Organization Codes

• MCO 5239.2B – Marine Corps Cybersecurity

• MCO 5510.18B – United States Marine Corps Information and Personnel Security Program

(IPSP)

• MCO 5510.20B – Disclosure of Military Information to Foreign Governments and Interests

• MCO 5530.14A – Marine Corps Physical Security Program Manual

• MCO 11000.5 – Facilities Sustainment, Restoration and Modernization Program

• ALMAR 010/01, USMC Policy on Civilian Guests

• MCBul 5603 – Marine Corps Doctrinal Proponency Assignments

- 7 -

• MCINCR-MCBQO 5530.2 – Access Control Policy

• MSTP Security Standard Operating Procedures (SECSOP)

• NAVMC DIR 5100.8, Marine Corps Occupational Safety and Health (OSH) Program

Manual

AVAILABILITY OF DOD DOCUMENTS

• DoD Directives, Manuals, Instructions and Publications are available online at http://www.DTIC.mil/ or from the National Technical Information Services (NTIS), 5285 Port Royal Road, Springfield, VA 22161

• DoN Directives, Manuals, Instructions and Publications are available online at https://doni.documentservices.dla.mil/default.aspx

• USMC Orders, Manuals, Directives, and Guides are available online at http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/

• Electronic Foreign Clearance Guide available online at https://www.fcg.pentagon.mil/fcg.cfm

OTHER DOCUMENTS, DRAWINGS AND PUBLICATIONS

• CNSS Instruction No. 4009 National Information Assurance (IA) Glossary

• OSHA regulation 1910.142 Occupational Safety and Health Standards

• FED Standard 313, Material Safety Data, Transportation Data, and Disposal Data, For

Hazardous Materials Furnished to Government Activities

• Parts 120-130 of Title 22, Code of Federal Regulations (also known as the “International

Traffic in Arms Regulations”)

• Parts 730-774 of Title 15, Code of Federal Regulations (also known as the “Export

Administration Regulations”)

• United States Forces Korea Regulation 700-19, Appendix B

• JP 1-02 – DoD Dictionary of Military and Associated Terms

• U.S. Forces Japan Instruction 31-207 – Firearms and Other Weapons in Japan

• U.S. Forces Japan Instruction 36-2611 – Change of Status by Persons in Japan to One of the

Categories Authorized by the Status of Forces Agreement

• U.S. Forces Japan Instruction 64-100 – Contract Performance in Japan

• U.S. Forces Japan Instruction 64-102 – United States Contractors and their Employees

• U.S. Forces Korea Regulation 700-19 – The Invited Contractor and Technical Representative

Program

REQUIREMENTS

All tasks identified in this PWS are for providing ERS COMS-Systems services to support Marine Corps training and education requirements of the Fleet Marine Forces, which includes both active duty and reserve components, and supporting establishments.

http://www.dtic.mil/ http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/ http://www.marines.mil/News/Publications/ELECTRONIC-LIBRARY/

- 8 -

GENERAL REQUIREMENTS

NON-PERSONAL SERVICES

The Government will neither supervise Contractor personnel nor control the method by which the Contractor performs the required tasks. The Government will not assign tasks, nor prepare work schedules for individual Contractor personnel. The Contractor shall manage its personnel and guard against any actions that give the perception of personal services. To provide a clear distinction between Government employees and Contractor personnel, Contractor personnel shall identify themselves as such by introducing themselves or being introduced as Contractor personnel and, to the extent a badge does not create a safety issue, displaying distinguishing badges or other visible identification for meetings with Government employees, as well as appropriately identifying themselves as Contractor personnel in telephone conversations and in formal and informal written correspondence. Contractor personnel shall present their badges upon request by Government employees and their representatives. If the Contractor believes that any actions constitute or are perceived to constitute personal services, it shall be the Contractor's responsibility to notify the Contracting Officer (KO) and the Contracting Officer’s Representative (COR) immediately.

BUSINESS RELATIONS

The Contractor shall successfully integrate and coordinate all activities needed to execute the requirements contained herein and in any TO. The Contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The Contractor shall seek to ensure customer satisfaction and professional and ethical behavior of all Contractor personnel.

COOPERATION

While it is not planned, there may be instances in which more than one Marine Corps contractor is required to work on the same base/location. In such instances, it is the expectation of the Government that the Contractor extends basic professional courtesy and collaborative interaction. Should an issue arise, the Contractor shall reach a mutual agreement without the assistance of the Government. In the event that the contractors cannot resolve an issue, it is the responsibility of the Contractor to promptly notify the Contracting Officer in writing and furnish recommendations for a solution. The Contractor shall not be relieved of its obligations under the MATOC (and corresponding TO) or be entitled to any other adjustment because of failure to promptly refer matters to the Contracting Officer or failure to implement the Contracting Officer’s directions. The Contractor is not relieved of any contract requirements or entitled to any adjustments to the contract terms or price because of a failure to resolve a disagreement with another contractor unless the Contractor provides prior notice to the Contracting Officer and proof to the Contracting Officer that the failure to resolve was not due to the Contractor’s negligence, fault, failure to cooperate, or failure to perform its obligations in good faith.

Should Contracting Officer intervention be required, the Government reserves the right to terminate either or both TOs for convenience at no cost to the Government. If a TO is terminated, the Government may make an award to (or negotiate an award with) another MATOC contractor based on proposals received in response to the initial request for TO proposals.

- 9 -

CONSTRUCTIVE CHANGES

No modification, statement, or conduct of Government personnel who might visit the Contractor’s facility or in any other manner communicate with Contractor personnel during the performance of this contract will constitute a change under the “Changes” clause of this contract. No understanding or agreement, contract modification, change order, or other matter deviating from or constituting an alteration or change of the terms of the contract will be effective or binding upon the Government unless formalized by contractual documents executed by the Contracting Officer.

The Contracting Officer is the only person authorized to approve changes in the requirements of this contract, and notwithstanding provisions contained elsewhere in the contract, the said authority remains solely with the Contracting Officer. In the event that the Contractor effects any change(s) at the direction of any person other than the Contracting Officer, these change(s) will be at the Contractor’s expense. No adjustment will be made in the contract price or other contract terms and conditions, as the Contracting Officer did not approve consideration for the unauthorized change.

Further, should the unauthorized change be to the Government’s detriment, the Contractor may be held financially responsible for its correction.

RESPONSIBILITY IN SUBCONTRACTING

The Contractor shall provide the technology processes, test procedures, data, drawings, and other information required to facilitate competition to the fullest extent feasible and ensure performance by selected subcontractors. The Contractor shall be fully responsible for ensuring that all appropriate contractual provisions and clauses are flowed down to its subcontractors and that those provisions are enforced.

TASK ORDERS

Except as otherwise provided in a specific TO, the Contractor shall furnish all materials and services necessary to accomplish the work specified therein. These materials shall include consumable items, device repair parts/components, tools, and test equipment, and support equipment not otherwise provided by the Government to the Contractor. The provisions of this agreement apply to all TOs issued.

Each TO will be individually funded. The appropriation and accounting data required to obligate funds will be included in each TO. As provided in each TO, Contractors may be required to track and invoice multiple lines of accounting (LOA) on each Contract Line Item Number (CLIN). As a result, Contractors must be able to accurately track performance and report based on the applicable

LOA.

3.1.2.5 COR AND ACOR

The use of the term COR throughout this document also includes the term Alternate COR (ACOR), if an ACOR is appointed in writing by the Contracting Officer, unless specifically excluded. An ACOR, if appointed, can only act in the absence of the appointed COR. There can only be one COR for a contract, and the duties of the COR are not delegable.

3.1.2.6 QUALITY ASSURANCE SURVEILLANCE PLAN

The Government conducts surveillance of the Contractor’s performance under this MATOC in accordance with the Quality Assurance Surveillance Plan (QASP). All deliverables will be inspected

- 10 -for content, completeness, accuracy, and conformance to contract requirements by the Government.

This will include inspecting for nonconforming or unjustified markings of data delivered to the Government for acceptance as specified in the contract.

CONTRACTOR PERSONNEL, DISCIPLINES, AND SPECIALTIES

The Contractor shall satisfy the requirements of this PWS and subsequent TOs by employing and utilizing personnel with an appropriate combination of education, knowledge, skills, abilities, and experience (if applicable). The Contractor shall match the appropriate labor categories and the labor hours required to meet all the work required to be performed under the TO. All personnel training, licenses, certification, and qualifications specified in this PWS and/or subsequent TOs shall be obtained, maintained, paid for and otherwise provided for by the Contractor.

RESOURCE REQUIREMENTS

The Contractor shall provide all personnel, equipment, tools, materials, supervision, and quality control necessary to perform the ERS COMS-Systems requirements defined in this PWS and subsequent TOs.

MARINE CORPS ENTERPRISE NETWORK (MCEN)

All computer assets necessary to perform any tasks and that are otherwise required by the Contractor to meet the performance requirements of this PWS and subsequent TOs, whether to be connected to the MCEN or to be employed as standalone assets, shall be provided by the Contractor.

Contractor personnel accessing Marine Corps Systems Command Computer systems, must maintain compliance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide. Contractor personnel will submit a DD 2875, and completion certificates for the CYBERC course located on MarineNet located at https://www.marinenet.usmc.mil The CYBERC course consist of the DOD Cyber Awareness Challenge and Department of the Navy Annual Privacy Training (PII). Contractors will have to create a MarineNet account in order to acquire the required training.

MCEN IT resources if provided are designated For Official Use Only (FOUO) and other limited authorized purposes. DoD military, civilian personnel, consultants, and contractor personnel performing duties on MCEN information systems may be assigned to one of three position sensitivity designations.

1) ADP-I (IT-1): Favorably adjudicated T-5, T5R, Single Scope Background

Investigation (SSBI)/SSBI Periodic Reinvestigation (SBPR)/SSBI Phased Periodic Reinvestigation (PPR)

2) ADP-II (IT-2): Favorably adjudicated T-3, T3R, Access National Agency Check and

Inquiries (ANACI)/ National Agency Check with Law and Credit (NACLC)/Secret Periodic Review (S-PR)

3) ADP-III (IT-3): Completed T-1, National Agency Check with Inquiries (NACI)

All privileged users (IT-1) must undergo an SSBI regardless of the security clearance level required http://www.marinenet.usmc.mil/ http://www.marinenet.usmc.mil/

- 11 -for the position. Privileged users must maintain the baseline Cyberspace Workforce Information Assurance Technical (IAT) or Information Assurance Manager (IAM) relating to the position being filled. Privileged users are defined as anyone who has privileges over a standard user account as in system administrators, developers, network administrators, code signing specialist and Service Desk technicians.

All MCEN users must read, understand, and comply with policy and guidance to protect classified information and CUI, and to prevent unauthorized disclosures in accordance with United States Marine Corps Enterprise Cybersecurity Manual 007 Resource Access Guide and CJCSI 6510.01F.

MCEN Official E-mail usage – MCEN IT resources are provided For Official Use Only (FOUO) and other limited authorized purposes. Authorized purposes may include personal use within limitations as defined by the supervisor or the local Command. Auto forwarding of e- mail from MCEN-N to commercial or private domains (e.g., Hotmail, Yahoo, Gmail, etc.) is strictly prohibited. E-mail messages requiring either message integrity or non-repudiation are digitally signed using DoD PKI. All e-mail containing an attachment or embedded active content must be digitally signed.

MCEN users will follow specific guidelines to safeguard Controlled Unclassified Information (CUI), including PII and For Official Use Only (FOUO). Non-official e-mail is not authorized for and will not be used to transmit CUI to include PII and Health Insurance Portability and Accountability Act (HIPAA) information. Non-official e-mail is not authorized for official use unless under specific situations where it is the only mean for communication available to meet operational requirements. This can occur when the official MCEN provided e-mail is not available but must be approved prior to use by the Marine Corps Authorizing Official (AO).

All personnel will use DoD authorized PKI certificates to encrypt e-mail messages if they contain any of the following:

1. Information that is categorized as For Official Use Only (FOUO).

2. Any contract sensitive information that normally would not be disclosed to anyone other than the intended recipient.

3. Any privacy data, PII, or information that is intended for inclusion in an employee’s personal file or any information that would fall under the tenets of MSGID: DOC/5 USC 552A. Personal or commercial e-mail accounts are not authorized to transmit unencrypted CUI or PII.

4. Any medical or health data, to include medical status or diagnosis concerning another individual.

5. Any operational data regarding status, readiness, location, or deployment of forces or equipment.

Contractor assets connectivity to the MCEN – The contracting company will comply with MCENMSG-Unification 003-14 ENABLING CONTRACTOR ASSET CONNECTIVITY TO THE MCEN. The Contractor representative will transfer the contractor owned laptops to the MCSC G-6, Information Technology Asset Management (ITAM) department to have the MCEN images places on each laptop before it is authorized to connect to the MCEN.

All Contractor owned laps must meet or exceed the USMC laptop specifications. A list of laptops authorized to be attached to the MCEN can be obtained from MCSC G-6 upon request.

- 12 -

Upon completion of the contact or at such time as the contractor reclaims the asset from the USMC, non-Government owned internal\external hard drives shall become the property of the U.S.

Government. Once the hard drives have been removed, the laptops\assets will be returned to the Contractor. For additional questions regarding current system specifications contact the MCSC, ITAM lead at (703) 432-4396.

Magnetic Hard Drive Storage Devices – This paragraph covers the requirements of classified and unclassified internal and removable magnetic and Solid State hard drives that store the Government data. This includes, but is not limited to, storage area network (SAN) devices, servers, workstations, laptops/notebooks, printers, copiers, scanners and multi-functional devices (MFD) with internal hard drives, removable hard drives and external hard drives. Upon disposal, replacement, turn in of hard drives or completion of the contract, non-Government owned internal\external hard drives shall become the property of the U.S. Government in accordance with GENADMIN Processing of Magnetic Hard Drive Storage Media for Disposal.

SECURITY REQUIREMENTS

3.1.5.1 SECURITY REQUIREMENTS

TOs may require the Contractor to have a Facility Clearance and will require certain Contractors to obtain and maintain classified access eligibility. If a Facility Clearance is a requirement of any TO, the Contractor shall not begin performance of any classified work without having a valid Facility Clearance. The prime contractor and all subcontractors (through the prime contractor) shall adhere to all aspects of DoD Directive 5220.22-M and DoD Manual 5220.22 Volume 2. All personnel identified to perform on this contract shall maintain compliance with Department of Defense, Department of the Navy, and Marine Corps Information and Personnel Security Policy to include completed background investigations (as required) prior to classified performance. This contract shall include a DoD Contract Security Classification Specification (DD-254) as an attachment.

Certain contractors will be required to perform IT-I/II duties that will require favorably adjudicated Tier 5/3 Level investigations. The Defense Counterintelligence Security Agency (DCSA) will not authorize contractors to submit the necessary Tier Level investigations solely in support of IT level designation requirements, but are required to submit investigations for those employees requiring both appropriate access and IT-II designation. The Government Contracting Activity Security Office (GCASO) is required to submit any required investigations in support of IT-I level designations.

The Contractor is required to provide a roster of prospective contractor employees performing IT-I duties to the MCSC Contracting Officer’s Representative (COR). This roster shall include: full names, Social Security Numbers, e-mail address and phone number for each contractor requiring investigations in support of IT Level designations. The COR will verify the IT-I requirements and forward the roster to the GCASO. Contractors found to be lacking required investigations will be contacted by the GCASO.

Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2 Personnel Security Office (PERSEC Office) via encrypted e-mail to MCSC_Security@usmc.mil or 703-432- 3374/3952 if any contractor performing on this contract receives an unfavorable adjudication. The FSO must also notify the PERSEC Office, within 24 hours, of any adverse/derogatory information mailto:MCSC_Security@usmc.mil

- 13 -associated with the 13 Adjudicative Guidelines concerning any contractor performing on this contract, if they have been granted an IT designation, issued a CAC, a MCSC Building Badge and/or granted classified access. The FSO shall notify the Government (written notice) within 24 hours of any Contractor personnel added or removed from the contract that have been granted IT designations, issued a Common Access Card (CAC) and/or a MCSC Building badge/access.

3.1.5.2 COMMON ACCESS CARD (CAC) REQUIREMENT

The TO COR will identify and approve those Contractor employees performing on a TO that require CACs in order to perform their job function.

The COR will identify and only approve those contractor employees performing on this contract that require CACs in order to perform their job function. In accordance with Headquarters, United States Marine Corps issued guidance relative to Homeland Security Presidential Directive – 12 (HSPD-12), all personnel must meet eligibility criteria to be issued a CAC. In order to meet the eligibility criteria, contractor employees requiring a CAC must obtain and maintain a favorably adjudicated Personnel Security Investigation (PSI). Prior to authorizing a CAC, the employee’s Joint Personnel Adjudication System (JPAS) record must indicate a completed and favorably adjudicated PSI or (at a minimum) that a PSI has been submitted and accepted (opened). The minimum acceptable investigation is a T-1 or a National Agency Check with Written Inquiries (NACI). If a contractor employee’s open investigation closes and is not favorably adjudicated, the CAC must be immediately retrieved and revoked. CACs are not issued for convenience.

Facility Security Officers (FSOs) are responsible for notifying the MCSC AC/S G-2 Personnel Security Office (PERSEC Office) at 703-432-3490/3952 if any contractor performing on this contract receives an unfavorable adjudication after being issued a CAC. The FSO must also immediately notify the PERSEC Office of any adverse/derogatory information associated with the 13 Adjudicative Guidelines concerning any contractor issued a CAC, regardless of whether a JPAS Incident Report is submitted.

Each CAC is issued with a “ctr@usmc.mil” e-mail account that the individual contractor is responsible to keep active by logging in on a regular basis (at least twice a month), sending an e-mail and clearing any unneeded e-mails. Contractors issued a CAC are prohibited from “auto-forwarding” e-mail from their .mil e-mail account to their .com e-mail account. If the “ctr@usmc.mil” e-mail account is not kept active, G-6 will deactivate the account and the CAC will also lose its functionality. Contractor employees shall solely use their government furnished “ctr@usmc.mil” e-mail accounts for work supporting the USMC, conducted in fulfillment of this contract, and shall not use a contractor supplied or personal e-mail account to conduct FOUO government business. The use of a contractor or personal e-mail account for contractor business or personal use is allowed, but only when using cellular or a commercial internet service provider.

If a contractor loses their eligibility for a CAC due to an adverse adjudicative decision, they have also lost their eligibility to perform on MCSC contracts.

3.1.5.3 PHYSICAL SECURITY

At the close of each work period, Government facilities, equipment, and materials shall be secured.

KEY CONTROL

mailto:ctr@usmc.mil

- 14 -

The Contractor shall establish and implement methods of making sure all keys/key cards issued to the Contractor by the Government are not lost or misplaced and are not used by unauthorized persons. NOTE: All references to keys include electronic key/access cards. No keys issued to the Contractor by the Government shall be duplicated. The Contractor shall develop procedures covering Key Control that shall be included in the Quality Control Plan (QCP). Such procedures shall include turn-in of any issued keys by personnel who no longer require access to locked areas.

The Contractor shall immediately report any occurrences of lost or duplicate keys/key cards to the local Government contracting surveillance individuals within 12 hours and the Contracting Officer within twenty-four hours.

In the event keys, other than master keys, are lost or duplicated, the Contractor shall, upon direction of the TO KO, re-key or replace the affected lock or locks; however, the Government, at its option, may replace the affected lock or locks or perform re-keying. When the replacement of locks or re-keying is performed by the Government, the total cost of re-keying or the replacement of the lock or locks shall be deducted from the monthly payment due the Contractor. In the event a master key is lost or duplicated, all locks and keys for that system shall be replaced by the Government and the total cost deducted from the monthly payment due the Contractor.

The Contractor shall prohibit the use of Government issued keys/key cards by any persons other than the Contractor’s employees. The Contractor shall prohibit the opening of locked areas by Contractor employees to permit entrance of persons other than Contractor employees engaged in the performance of assigned work in those areas, or personnel authorized entrance by the by the COR, KO, or designated Government representative.

LOCK COMBINATIONS

The Contractor shall provide all lock combinations to the COR, and establish and implement methods of ensuring that all lock combinations are not revealed to unauthorized persons. The Contractor shall ensure that lock combinations are changed when personnel having access to the combinations no longer have a need to know such combinations. These procedures shall be included in the Quality Control Plan (QCP), which is referenced below in paragraph 3.1.13.1.5.

PASSWORDS

Passwords shall be protected at all times. The sharing of passwords is strictly prohibited.

WEAPONS SECURITY

Any ERS COMS-Systems training system weapons are simulated/demilitarized weapons utilized for training and are not real weapons. Notwithstanding that they are not real weapons, in some cases a Federal Firearms License is required (see paragraph under Special Qualifications below). However, any ERS COMS-Systems training system weapons shall be securely stored and transported in accordance with federal, state, and other laws and regulations to ensure security, loss prevention and accountability.

SYSTEM SECURITY

1. System Security Plan and Plans of Action and Milestones (SSP/POAM) Reviews

a. Within 30 days of TO award, the Contractor shall make its System Security Plan(s) (SSP(s)) for its covered contractor information system(s) available for review by the Government at the contractor’s facility. The SSP(s) shall implement the security requirements in Defense Federal Acquisition Regulation Supplement (DFARS) clause 252.204-7012, which is included in this

- 15 -contract. The Contractor shall fully cooperate in the Government's review of the SSPs at the Contractor's facility.

b. lf the Government determines that the SSP(s) does not adequately implement the requirements of DFARS clause 252.204-7012 then the Government shall notify the Contractor of each identified deficiency. The Contractor shall correct any identified deficiencies within 30 days of notification by the Government. The contracting officer may provide for a correction period longer than 30 days and, in such a case, may require the Contractor to submit a plan of action and milestones (POAM) for the correction of the identified deficiencies. The Contractor shall immediately notify the contracting officer of any failure or anticipated failure to meet a milestone in such a POAM.

c. Upon the conclusion of the correction period, the Government may conduct a follow-on review of the SSP(s) at the Contractor's facilities. The Government may continue to conduct follow-on reviews until the Government determines that the Contractor has corrected all identified deficiencies in the SSP(s).

d. The Government may, in its sole discretion, conduct subsequent reviews at the Contractor's site to verify the information in the SSP(s). The Government will conduct such reviews at least every three

(3) years (measured from the date of contract award) and may conduct such reviews at any time upon thirty days' notice to the Contractor.

2. Compliance to NIST 800-171

a. The Contractor shall fully implement the CUI Security Requirements (Requirements) and associated Relevant Security Controls (Controls) in NIST Special Publication 800-171 (Rev. I) (NIST SP 800-171), or establish a SSP(s) and POAMs that varies from NIST 800-171 only in accordance with DFARS clause 252.204-7012(b)(2), for all covered contractor information systems affecting this contract.

b. Notwithstanding the allowance for such variation, the contractor shall identify in any SSP and POAM their plans to implement the following, at a minimum:

(1) Implement Control 3.5.3 (Multi-factor authentication). This means that multi-factor authentication is required for all users, privileged and unprivileged accounts that log into a network.

In other words, any system that is not standalone should be required to utilize acceptable multi-factor authentication. For legacy systems and systems that cannot support this requirement, such as CNC equipment, etc., a combination of physical and logical protections acceptable to the Government may be substituted;

(2) Implement Control 3.1.5 (least privilege) and associated Controls, and identify practices that the contractor implements to restrict the unnecessary sharing with, or flow of, covered defense information to its subcontractors, suppliers, or vendors based on need-to-know principles;

(3) Implement Control 3.1.12 (monitoring and control remote access sessions) - Require monitoring and controlling of remote access sessions and include mechanisms to audit the sessions and methods.

(4) Audit user privileges on at least an annual basis;

(5) Implement:

i. Control 3.13.11 (FIPS 140-2 validated cryptology or implementation of NSA or NIST approved algorithms (i.e. FIPS 140-2 Annex A: AES or Triple DES) or compensating controls as documented in a SSP and POAM); and,

- 16 -

ii. NIST Cryptographic Algorithm Validation Program (CAVP) (see https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program);

(6) Implement Control 3.13.16 (Protect the confidentiality of CUI at rest) or provide a POAM for implementation which shall be evaluated by the Navy for risk acceptance.

(7) Implement Control 3.1.19 (encrypt CUI on mobile devices) or provide a plan of action for implementation which can be evaluated by the Government Program Manager for risk to the program.

3. Cyber Incident Response:

a. The Contractor shall, within 15 days of discovering the cyber incident (inclusive of the 72-hour reporting period covered in 3.1.5.9 below), deliver all data used in performance of the contract that the Contractor determines is impacted by the incident and begin assessment of potential warfighter/program impact.

b. Incident data shall be delivered in accordance with the Department of Defense Cyber Crimes Center (DC3) Instructions for Submitting Media available at http:/www.acq.osd.mil/dpap/dars/pgi/docs/Instructions_for_Submitting_Media.docx. In delivery of the incident data, the Contractor shall, to the extent practical, remove contractor-owned information from Government covered defense information.

c. If the Contractor subsequently identifies any such data not previously delivered to DC3, then the Contractor shall immediately notify the contracting officer in writing and shall deliver the incident data within 10 days of identification. In such a case, the Contractor may request a delivery date later than 10 days after identification. The contracting officer will approve or disapprove the request after coordination with DC3.

4. Naval Criminal Investigative Service (NCIS) Outreach

The Contractor shall engage with NCIS industry outreach efforts and consider recommendations for hardening of covered contractor information systems affecting DON programs and technologies.

5. NCIS/Industry Monitoring

a. In the event of a cyber incident or at any time the Government has indication of a vulnerability or potential vulnerability, the Contractor shall cooperate with the Naval Criminal Investigative Service (NCIS), which may include cooperation related to: threat indicators; pre-determined incident information derived from the Contractor's infrastructure systems; and the continuous provision of all Contractor, subcontractor or vendor logs that show network activity, including any additional logs the Contractor, subcontractor or vendor agrees to initiate as a result of the cyber incident or notice of actual or potential vulnerability.

b. If the Government determines that the collection of all logs does not adequately protect its interests, the Contractor and NCIS will work together to implement additional measures, which may include allowing the installation of an appropriate network device that is owned and maintained by NCIS, on the Contractor1s information systems or information technology assets. The specific details (e.g., type of device, type of data gathered, monitoring period) regarding the installation of an NCIS network device shall be the subject of a separate agreement negotiated between NCIS and the Contractor. In the alternative, the Contractor may install network sensor capabilities or a network monitoring service, either of which must be reviewed for acceptability by NCIS. Use of this alternative approach shall also be the subject of a separate agreement negotiated between NCIS and the Contractor.

http://www.acq.osd.mil/dpap/dars/pgi/docs/Instructions

- 17 -

c. In all cases, the collection or provision of data and any activities associated with this performance work statement shall be in accordance with federal, state, and non-US law.

ADDITIONAL SYSTEM SECURITY REQUIREMENTS

To provide adequate security, the Contractor shall implement National Institute of Standards and Technology (NIST) Special Publication 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations, the Contractor shall provide a System Security Plan (SSP) in accordance with Contractor’s SSP (CDRL A001) indicating whether the Contractor has implemented the security requirements therein, plans to implement the security requirements, or that the requirement is not applicable.

The Contractor shall submit a list in accordance with the Contractor’s Record of Tier 1 Level Suppliers Receiving/Developing CUI (CDRL A002) of all supporting Tier 1 Level suppliers receiving or developing covered defense information. In addition, the Contractor shall provide its plan to government review and approval to track flow down of covered defense information and to assess DFARS Clause 252.204-7012 compliance of known Tier 1 Level suppliers.

The Contractor shall document and report all cyber incidents that affect the covered Contractor information system or the covered defense information residing therein, or that affect the Contractor’s ability to perform requirements designated as operationally critical support via the Cyber Incident Reporting (CDRL A003). The Contractor shall submit malicious software discovered and isolated in connection with a reported cyber incident to the DoD Cyber Crime Center. The Contractor shall report all cyber incidents or compromise related to Government CUI in accordance with DFARS 252.204-7012 to the Damage Assessment Office (DAMO) via the DIB-NET Website (http://dibnet.dod.mil) within 72 hours. The Contractor shall if requested, submit media and additional information to support damage assessment.

CDRL A001: DI-MGMT-82247 Contractor’s System Security Plan CDRL A002: DI-MISC-80508B Contractor’s Record of Tier 1 Level Suppliers Receiving/Developing CUI CDRL A003: DI-MISC-80508B Cyber Incident Reporting

VISIT REQUESTS

The Contractor shall comply with DoD 5220.22-M, National Industrial Security Program Operating Manual and SECNAV M‐5510.30, JUN 2006, DoN Personnel Security Program, ALMAR 010/01, USMC Policy on Civilian Guests and Federal Acquisition Regulation (FAR) 52.204‐2 for access to USMC bases and information. All Contractor visits requiring a visit access request shall be provided by the Facility Security Officer (FSO) via the JPAS system a minimum of five working days prior to scheduled visits. Contractor personnel shall have two forms of picture identification, which shall include a valid employee badge issued by the Contractor, when visiting a worksite either at the home work station or while traveling to other sites.

http://dibnet.dod.mil/

- 18 -

SAFETY

ACCIDENTS, MISHAPS AND GOVERNMENT DECLARED EMERGENCIES

The Contractor shall immediately report any accident/incident with safety/security implications or any other conditions or incidents that could reasonably be expected to be of interest to the COR and Contracting Officer no more than four hours from the accident or mishap. Damage to Government property or injury to Government or Contractor employees or civilian guests must be reported to the COR and Contracting Officer within four hours. Contractor initial reports may be verbal but shall be followed up in writing within 24 hours. Contractor reports of incidents with security implications shall include full details of the incident, any remedial actions that were taken by the Contractor and shall comply with all applicable security instructions.

The Contractor shall investigate all accidents occurring on Government property involving Contractor employees and report the findings (on applicable forms) to the COR and Contracting Officer within three calendar days of the incident.

Reportable incidents shall be reported to the Government by the Contractor in accordance with the requirements of this PWS via submission of CDRL B001 - Accident Mishap Report. The data deliverable shall be generated and delivered to the Government for reportable events in accordance with the specific performance requirements that accompany each TO.

The Contractor may experience an unexpected suspension of training or operation aboard USMC facilities due to Government-declared medical or other emergencies. TOs may require Contractor action in response to Government declared medical or other emergencies to ensure the training systems and related equipment continue to be suitable for training.

CDRL B001: DI-MGMT-82188 Accident Mishap Report

LOCATIONS AND HOURS OF WORK

Each TO for services will identify the specific places of performance applicable to the period of performance for that TO. In addition, each TO will also address any specific conditions applicable to the hours of work related to performance under the order.

Federal law (5 U.S.C. §6103) establishes the following public holidays.

• New Year's Day

• Birthday of Martin Luther King, Jr.

• Washington's Birthday

• Memorial Day

• Independence Day

• Labor Day

• Columbus Day

• Veterans Day

• Thanksgiving Day

• Christmas Day

- 19 -

However, the Government may schedule training events on Federal Government holidays that require Contractor support.

This is a performance-based services acquisition implemented through fixed price TOs. This is not a time-and-materials or labor-hours contract. Therefore, the Contractor is required to meet performance requirements as part of the proposed firm-fixed price even where the Government’s needs necessitate Contractor performance beyond the typical eight-hour work day or forty hour work week.

INCLEMENT WEATHER

In the event of inclement weather, the Contractor shall comply with the local installation’s Inclement Weather Policy. The Contractor will provide notice to the Contracting Officer and COR, as soon as is reasonably possible, when inclement weather conditions impact one or more of the places of performance provided for under the contract. The Contractor is not required to return to any Government facilities to survey equipment or conduct operations checks until the installation has announced "all clear."

INSTALLATION ACCESS

The Contractor shall comply with installation, facility, and area commander installation/facility access and local security policies and procedures. The Contractor shall be responsible for all costs it incurs that are associated with unclassified and classified installation access, and providing all of the information required to obtain clearances, permits, passes, or security badges that are required for Contractor personnel or equipment access. This includes information required for police, background checks, or investigations. The Contractor shall be responsible for ensuring such clearances, permits, passes, or security badges are promptly returned to the issuing activity upon the termination of an employee, completion of a project, or termination of a contract or subcontract.

The Contractor shall follow all installation access requirements at host installations. Host installations may require some or all of the following for entry on to the installation: proof of a valid state driver’s license, vehicle…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .