Attachment 1 - Basic IDIQ SOO.pdf
PDF 187 KB Posted
- Attached to
- Trusted and Elastic Military Platforms and Electronic Warfare (EW) System Technologies (TEMPEST) Federal contract opportunity
- Solicitation number
- FA8650-20-S-1958-Call-03
About this file
This document contains an Indefinite Delivery/Indefinite Quantity (ID/IQ) Statement of Objectives (SOO) for the Agile and Resilient Platform Architectures (ARPA) program. The SOO outlines requirements for developing, demonstrating, and prototyping integrated cybersecurity, agile architecture, and open systems technology solutions to identify and mitigate vulnerabilities in avionics systems, harden avionics against cyberattacks, advance techniques to detect and respond to cyberattacks in real-time, demonstrate integrated mission systems using open architecture standards, and prototype agile platform architectures. Key tasks include maturing cyber assessment and testing tools, cyber hardening technologies, adaptable cyber protections, agile architecture development methods, and demonstrating agile open architectures on prototype systems. The contractor will integrate technologies, conduct experimentation and demonstrations, and enter associate contractor agreements. The Air Force Research Laboratory seeks proposals to address the technical areas and perform the tasks outlined in the SOO.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| TEMPEST Call 03 - ODA2 TO2 SOO Amendment 1.pdf | ||
| Questions and Answers.pdf | ||
| TEMPEST Call 03 Amendment 1.pdf | ||
| Attachment 5 - DD254.pdf | ||
| Call.pdf | ||
| Attachment 3 - Task Order 2 SOO.pdf | ||
| Attachment 6 - Model Contract.pdf | ||
| Attachment 4 - CDRLs.pdf | ||
| Attachment 2 - Task Order 1 SOO.pdf |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
ID/IQ (Indefinite Delivery/Indefinite Quantity)
STATEMENT OF OBJECTIVES (SOO)
Agile and Resilient Platform Architectures (ARPA)
1 October 2020
1.0 OBJECTIVE
The objective of the ARPA program is to perform enhanced development, advanced technology demonstrations, component development and prototyping of tools, techniques, and capabilities to: 1) Identify and mitigate vulnerabilities in avionics systems; 2) Harden and protect avionics systems against cyber‐attack;
3) Advance current techniques to detect, respond, and adapt to novel cyber‐attacks on avionics in real‐time; 4)
Demonstrate integrated mission systems and advanced prototype components leveraging current and emerging open system architecture standards and approaches; and 5) Prototype agile, next‐generation platform and system of systems architectures to enable rapid integration and fielding of enhanced mission system capability.
2.0 SCOPE
The scope of the ARPA program includes developing, demonstrating and prototyping integrated, next‐ generation cyber security, agile architecture, and open systems technology solutions. Responsive research will explore new and emerging concepts related to development, integration, assessment, evaluation, and advanced demonstration of cyber security technologies, Open Systems Architecture (OSA), novel sensor technologies, and multi‐domain technologies. Solutions developed under this program will be applied to a wide‐range of associated platforms operating in diverse, contested environments.
3.0 BACKGROUND
The Air Force (and DoD) needs to rapidly and efficiently field enhanced warfighting capability to maintain technological advantage in highly contested and consistently changing environments. The Resilient & Agile
Avionics Branch (RYWA) in the Sensors Directorate, Air Force Research Laboratory (AFRL) conducts basic and applied research, advanced technology development, demonstration and validation, and engineering development to understand and improve sensor technology, cyber security and system architectural performance and agility of U.S. Air Force (USAF) platforms, weapon systems, and next‐generation tactical platforms operating in multi‐domain environments. This activity involves 1) Developing tools and technologies to assess weapon systems as well as to identify and characterize cyber vulnerabilities in legacy and future weapon systems; 2) Developing technologies and techniques to cyber harden avionics by mitigating identified vulnerabilities in legacy and future weapon systems; 3) Developing protections against cyber‐attack to provide fight‐through cyber resiliency and enhanced mission capability; 4) Developing agile, enabling platform technologies for operating in contested multi‐domain environments; and 5) Developing and promoting the use of Open Systems Architecture (OSA) approaches for the design and development of avionics systems. AFRL solicits innovative research proposals to address these needs and to test, evaluate, prototype, demonstrate and integrate developed technologies into AFRL/RYWA’s Cyber Security, Next‐generation Avionics
Architectures, and the Open Mission Systems (OMS) Laboratories. Performers under this activity will advance the state‐of‐the‐art in USAF systems cyber security, architectural paradigms, OSA approaches, agile multi‐ domain concepts, and modeling and simulation technologies offering novel and innovative techniques to understand and defeat advanced sensors/cyber threats and protect our systems so they operate as intended and provide mission assurance to the warfighter. Some or all elements of the research and prototyping may be performed at AFRL facilities at Wright‐Patterson Air Force Base (WPAFB) or at appropriate contractor facilities.
The integration, test, evaluation, and demonstration will be performed in appropriate facilities at AFRL, WPAFB. AFRL seeks and encourages small business participation through teaming arrangements and/or as performers on individual task and subtask research activities.
4.0 TASKS/TECHNICAL REQUIREMENTS
The ARPA program will develop, mature, prototype and demonstrate different cybersecurity, open system, and agile architecture technologies. Demonstrations will use prototype avionics units in novel agile and open system architectures to display enhanced cyber resilience and mission system capabilities. The effort will develop technology plans for research and development to meet the requirements as identified in specific task areas. The program will integrate, test and, evaluate these technologies. The program will support research and development in the following areas, each with specific objectives defined within task orders.
4.1 TECHNICAL AREAS
4.1.1 Avionics Cyber Assessment and Testing Tools
The contractor will mature, prototype, and demonstrate cyber assessment and testing tools for avionics systems and aircraft platforms. Tools and techniques to thoroughly test for vulnerabilities at the system and component levels as well as tools to automate cyber assessments of aircraft platforms are needed.
Technologies of interest include, but are not limited to: 1) Assessment tools to model platform and system susceptibilities and perform cyber risk analysis; 2) Tools and techniques for testing and assessing avionics systems, sub‐systems, and components for specific vulnerabilities including network and RF negative testing;
3) Tools to emulate an avionics environment to enhance testing capabilities; 4) Tools to instrument avionics systems for the observation of cyber effects in test environments; 5) Tools for testing and assessing software or hardware‐based mitigation and protection technologies and techniques; 6) On‐board tools or instrumentation to perform data capture for in‐flight analysis or post‐mission forensics; and 7) Testbeds and other modeling and simulation technologies to provide a simulated environmental context for cyber testing.
These technologies will enhance assessment and testing capabilities of various Air Force organizations.
4.1.2 Avionics Cyber Hardening Technologies
The contractor will mature, prototype, and demonstrate technologies that reduce weapon system vulnerability to cyber‐attack. Cyber hardening techniques include different methods to remove or mitigate identified system vulnerabilities as well as methods to prevent introduction of malicious elements to the system.
Technologies of interest include, but are not limited to: 1) Technologies to secure and authenticate communications over legacy and next‐generation protocols within or between weapon system platforms; 2)
Attestation techniques that determine if system software, firmware, or data has been improperly modified before, during or after system start‐up; 3) Techniques to prevent the introduction of malicious elements to avionics systems before, during and after the mission; 4) Technologies to enable the secure integration of non‐ organic weapons, pods, roll‐on‐roll‐off equipment, and other systems to weapon system platforms; and 5)
Techniques to prevent unauthorized execution or data access in avionics sub‐systems. In general, these technologies should prevent the origination, introduction, and propagation of malware or malicious elements on avionics platforms.
4.1.3 Adaptable and Resilient Cyber Protections for Avionics
The contractor will mature, prototype, and demonstrate technologies that counter both known and unknown attack vectors that occur during mission operations in cyber contested environments. Advanced research topics conducted in this area include, but are not limited to: 1) Developing algorithms or techniques to identify, detect, and diagnose cyber‐attacks based on real‐time analysis of platform data; 2) Developing techniques to maintain critical mission capabilities in the face of cyber‐attacks; 3) Developing countermeasures that can be deployed during a mission to reduce or to eliminate the impact of cyber‐attacks; and 4) Developing protection techniques that can adapt to novel threats and rapidly evolve to prevent similar attacks. In general, these technologies should enable avionics systems to quickly detect, respond, adapt and fight‐through cyber‐ attacks during critical mission stages.
4.1.4 Agile System Architecture Development and Integration
The contractor will mature and demonstrate integrated methods and technologies, prototype tools, and processes to enable the affordable, rapid integration of emerging mission system warfighting capability. This research area seeks to leverage advances and best practices in leading edge agile development processes, Digital Engineering, Continuous Integration/Continuous Development (CI/CD), Development, Security, and
Operations (DevSecOps), and open system architecture standards and approaches to decrease the time and cost to meet airworthiness and certification requirements, and ultimately deliver warfighting capability at the speed of relevance. Emphasis is placed on integrating best‐of‐breed technologies to enable a digital ecosystem of automated capability to support distributed development, integration, and testing throughout multiple phases of system development.
4.1.5 Agile Open Architectures for Trusted and Agile Platforms
The contractor will leverage technological advances in open system architecture standards and approaches, software, hardware, networking, and processing technologies to demonstrate and prototype cutting‐edge concepts of agile avionics architectures for current and next‐generation avionics systems. Characteristics of trusted and agile platform architectures include, but are not limited to: advanced multi‐function, digital apertures, automatic sensor resource management, enhanced data fusion (i.e., multi‐int), inherent cyber hardening and cyber resiliency, heterogeneous processors, low latency and high throughput, and compliance with open system architecture standards and approaches such as Open Mission Systems (OMS), and Unified
Command and Control Interface (UCI). This task area includes, but is not limited to: 1) Novel data exchanges to support on‐board and off‐board communications; 2) Middleware technologies to enable efficient use of high‐speed network and bus architectures; 3) Technologies that facilitate rapid integration advanced mission system and system of systems capability; 4) Cutting‐edge time‐synchronization capabilities; 5) Integrated approaches for cybersecurity, anti‐tamper, and open system architectures; 6) Approaches to align multiple open system architecture standards to enable standards interoperability; and 7) Implementation of OSA‐based reference architectures for demonstration and experimentation on single as well as multiple, networked platforms (i.e., system of systems) based on operationally relevant scenarios and configurations. Research accomplished in this area may result in proposed changes to existing open system architecture standards.
Proposed changes to the standards will follow the change processes defined by the respective standards.
4.2 Collaborative Integration, Experimentation, and Demonstration
The contractor will integrate technology solutions and advanced prototype components developed in the previous research areas of this SOO to conduct collaborative experimentation and demonstrations of enhanced capability. This area is critical to future adoption by AF and DoD programs and it seeks to evaluate technology prototypes under realistic operating scenarios to the maximum extent possible to reduce risk of adoption. Experimentation and demonstration will consist of both technologies developed under this effort as well as “third‐party” solutions that can be integrated to show enhanced warfighting capability. The task area includes, but is not limited to the following areas:
1. Simulation
a. Simulating/emulating current and legacy avionics systems and components
b. Stimulating avionics systems and components with realistic, coordinated signals in order to observe their operation in realistic/operational environments.
c. Integrating revolutionary or “next‐gen” technology demonstrations into existing test beds.
Examples include “cyber LRUs,” high speed/high capability bus architectures, OSA‐compliant devices, advanced sensor packages, etc. These may be technologies that are developed within
AFRL/RYWA, or technologies that are brought in from a third party solely for integration/demonstration/test/assessment
2. Technology enhancements to support experimentation and demonstration, including but not limited to improve testing and experimentation tools, software and hardware in the loop test beds and environments.
3. Specialized prototype hardware, including Line Replaceable Units (LRU) to support application, exercise, and field test
Due to the nature of the technology areas above, the contractor may be required to participate in technology planning and roadmapping, special field test and evaluation programs, quick deployment and implementation, wargame/exercises, data collection, system engineering, architecture analysis, or training development.
a. This may involve performing one or more areas (listed above) on a system concept(s), research concept(s) or prototype(s). (3600)
b. This may involve performing one or more areas (listed above) on a system or unit currently fielded.
(3400)
4.3 Associate Contractor Agreements
4.3.1 The Contractor shall enter into Associate Contractor Agreements (ACA) for any portion of the contract requiring joint participation in the accomplishment of the Government’s requirement. The agreements shall include the basis for sharing information, data, technical knowledge, expertise, and/or resources essential to the integration of the Agile and Resilient Platform Architectures program, which shall ensure the greatest degree of cooperation for the development of the program to meet the terms of the contract.
4.3.2 Provide a copy of such agreement to the Contracting Officer for review before execution of the document by the cooperating contractors.
4.3.3 ACAs will include the following general information:
Identify the associate contractors and their relationships.
Identify the program involved and the relevant Government contracts of the associate contractors
Describe the associate contractor interfaces by general subject matter
Specify the categories of information to be exchanged or support to be provided
Include the expiration date (or event) of the ACA.
Identify potential conflicts between relevant Government contracts and the ACA; include agreements on protection of proprietary data and restrictions on employees.
4.3.4 The Contractor is not relieved of any contract requirements or entitled to any adjustments to the contract terms because of a failure to resolve a disagreement with an associate contractor.
4.7.5 Liability for the improper disclosure of any proprietary data contained in or referenced by any agreement shall rest with the parties to the agreement, and not the Government.
4.7.6 All costs associated with the agreements are included in the negotiated cost of this contract. Agreements may be amended as required by the Government during the performance of this contract.
4.7.7 The following contractors are associate contractors with whom agreements are required.
Contractor Address Program/Contract Number
5.0 MANAGEMENT
5.1 Program Administrative and Financial Functions. The contractor will follow program management processes to administer the program (functionally and financially) including, at a minimum, scheduling and tracking milestones and activities; managing subcontracts and Contract Data Requirements Lists (CDRLs);
reporting program technical, schedule, and cost status; planning, forecasting, and recommending funding or funding changes; and documenting technical breakthroughs or discoveries.
5.2 Management at Various Facilities. The contractor will support R&D on site (i.e., at a government facility) and off site (i.e., at the contractor’s facility), as appropriate.
5.3 Risk Management. The contractor will maintain a risk management process throughout the program identifying, analyzing, assessing, mitigating, and monitoring technical, schedule, and cost risks which will be included as part of the monthly status report.
6.0 DELIVERABLES
Data will be delivered in accordance with the CDRLs, DD Form 1423‐1. The contractor will document all technical work accomplished and information gained during the performance of this acquisition. This documentation will include all pertinent observations, the nature of any problems, positive and negative results, design criteria established (where applicable), procedures followed, processes developed, lessons learned, and so forth. The contractor will document the details of all technical work to permit full understanding of the techniques and procedures used in evolving the technology or processes developed.
Separate design, engineering, or process specifications delivered during this acquisition will be cross‐ referenced to permit a full understanding of the total acquisition. Final software and hardware (including source code, firmware, libraries, and executables) developed on this effort will be delivered, with unlimited rights and with software in a format acceptable to both parties, at the end of the technical period of performance.
7.0 TECHNICAL REVIEWS
The contractor will hold a kickoff meeting at AFRL within 30 days after contract award. The contractor will host quarterly program management reviews and conduct ad hoc reviews as required with the government, stakeholders, and associate contractors. The contractor will involve required contractors, subcontractors, AFRL, and other research personnel as appropriate.
8.0 SECURITY
8.1 Program Security Requirements. In order for individuals to work on classified portions of this effort, the contractor will ensure that all individuals are U.S. citizens, understanding that they may be required to have
SCI DCID 6/4 Top Secret Eligibility based on a SSBI/SBPR. The contractor will require that all SCI and SAP work be conducted within an accredited Special Access Program Facility (SAPF) and/or a Sensitive Compartmented
Information Facility (SCIF). The government will outline specific security details and requirements in future
TOs. The contractor will ensure that all classified efforts comply with National Industrial Security Program
Operating Manual (NISPOM) and other regulations/policies that may apply to this contract, such as Joint Air
Force‐Army‐Navy (JAFAN) 6/0 (Revision 1); DoD Directive 5205.07 (Volumes 1–4); Air Force Manual (AFMAN)
16‐703 V3; SAF/AAZ Memorandum “Air Force Special Access Programs Nomination Process (SAPNP)” (30 Sep
2013); Under Secretary of Defense for Intelligence (USD(I)) Memorandum, “Special Access Programs
Nomination Process” (20 May 2013); JAFAN 6/3 Implementation Guide, Version 1 (Sep 2006); DoD Security
Assistance Policy Coordinating Office (SAPCO) Memorandum, “Transition to the Risk Management Framework
(RMF)” (18 Dec 2013); Joint Special Access Program Implementation Guide (JSIG) (9 Oct 2013); Intelligence
Community Directives (ICDs) 704 and 705; other applicable SCI regulations and policies; other applicable
Security Classification Guides (SCGs); and other applicable regulations/policies and subsequent revisions.
Access to Joint Worldwide Intelligence Communications System (JWICS) is authorized for performance of SCI work, users shall be briefed NATO SECRET IAW the NISPOM, Para 10‐706, prior to access).
8.2 Operational Security (OPSEC). General Operations Security (OPSEC) procedures, policies and awareness are required in an effort to reduce program vulnerability from successful adversary collection and exploitation of critical information. OPSEC will be applied throughout the life cycle of the contract. The Critical Information
List (CIL) and the RY OPSEC Plan will be provided upon request by AFRL/RYOY Information Protection Office.
While working on the government installation, OPSEC guidance and OPSEC training will be provided by
AFRL/RYOY Information Protection Office. This training will ensure contractors are familiar with RY’s CIL and
RY’s OPSEC Plan as it pertains to their contract. The contractor shall apply OPSEC in their management of their current program IAW AFI 10‐701 Operations Security and WPAFB Supplement to AFI‐10‐701.
8.3 Security Training. The contractor will participate in the U.S. Government’s (USG’s) in‐house and web‐ based security training program under the terms of the contract. The USG will provide the contractor with access to the online system. The contractor will take specialized security training as deemed applicable by
USG.
8.4 Security Duties. The contractor will be required to perform normal services under this contract between the hours of 0600‐1800 excluding Federal Holidays. The contractor shall perform the following security tasks incidental to R&D efforts: End of day security; open, operate and close classified facilities; activate and deactivate alarms which requires access to alarm codes and alarm panel; facilitate access to classified information which will require combinations to locks for safes and doors during normal workhours and extended duty days. This may also include, at the discretion of the government, responsibility for performing after‐hours alarm response which may require 24/7 building access in accordance with AF and DoD requirements. The government maintains the overall responsibility for all security related activities and is incumbent upon the contractor to officially communicate to the government these objectives and requirements have been appropriately completed in a timely and efficient manner.
8.5 Program Protection Plan. All DoD contractors (including subcontractors) shall supplement their current security practices by requiring any personnel involved in executing this contract where critical program information (CPI) has been identified to protect the CPI to the standards articulated in the Program Protection
Plan and in accordance with DoDI 5200.39. Upon contract award, all identified DoD contractors (including subcontractors) shall acknowledge and meet the requirements stated by the Program Manager for the protection of CPI. The DoD contractor must immediately notify the U.S. Government upon the discovery of any nonconformance with CPI protection. Applicable PPPs include, but are not limited to, the following:
“Standards Management Program Protection Plan”, Open Architecture Management Office, Air Force Lifecycle
Management Center (AFLCMC), Wright‐Patterson AFB OH, dated 1 Jan 2019; PlatformNxt (PNxt) Program
Protection Plan (PPP), AFRL/RY, dated 10 May 2018.
9.0 SAFETY
The contractor will comply with all Air Force, federal, state, and local safety and environmental regulations.
The contractor will develop and have an approved Safety Plan (AFI 91‐202 AFRL Sup 1) before any experiment may be conducted outside of a laboratory environment. The contractor will comply with safety requirements contained in MIL‐STD 882E, Section 4, “General Requirements,” for any deliverable system or hardware. The contractor will identify safety‐critical components of those systems or hardware and software interfaces with those components. The contractor will test and verify the safety‐critical hardware and software for safety acceptance.
10.0 BASE SUPPORT
AFRL/RYWA will provide the contractor with laboratory space, equipment (on a non‐interference basis), and computer/network access for conducting this effort, if proposed.
File details come from the government source that posted it. Updated .