Attachment 1 Draft SOW.docx
DOCX document 49 KB Posted
- Attached to
- Cyber Risk Assessment III Federal contract opportunity
- Solicitation number
- N6893622R0043
View the file
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Cyber Systems Engineering Security Assessment and Solutions Statement of Work (SOW) 2_May 12, 2022
1.0 Background
Current global conflicts reinforce that cyber threats to U.S. infrastructure and military systems are real and significant. Cyberspace is traditionally defined as "a global domain within the information environment consisting of the interdependent network of information technology infrastructures, including the internet, telecommunications networks, computer systems and embedded processors and controllers” (Joint Publication 3-12 (R) Cyberspace Operations). The focus of this Statement of Work (SOW) is embedded systems, to include Circuit Card Assemblies (CCA), processors, controllers, firmware, and Real Time Operating Systems (RTOS).
We live and operate in a wired world that relies on communications technologies; from computers, data centers and the cloud to mobile connectivity. Economies rely on this wired world to operate, as does the military. DoD systems must be sufficiently robust, resilient and sustainable to operate in the increasingly contested and connected cyberspace domain. To know a systems effectiveness, robustness and resiliency, analyses must be performed to determine and mitigate system deficiencies. Starting with the FY16 NDAA section 1647, and consistently echoed in subsequent NDAAs, the DoD was directed to perform Cyber Survivability Risk Assessments (CSRAs) on all major DoD weapons systems, including associated imbedded software and development environments, system communications, and maintenance and support equipment. In addition, CNO has implemented the CYBERSAFE certification process to address cyber warfare and impacts to systems safety.
1.1 Scope
The overall scope of this SOW includes providing cyber resources, expertise and materials to support broad scope Cyber Survivability Risk Assessment (CSRA), Cyber Table Tops (CTTs), Cyber Systems Security Engineering (CSSE), Verification and Validation (V&V) test plans, Cyber Supply Chain Risk Management (C-SCRM), hardware and software based Cyber solutions, and Cyber digital modeling for aircraft, Unmanned Aerial Vehicles (UAV), weapon systems, Training Simulators, associated software, Portable Electronic Maintenance Aid (PEMA) by interviewing system Subject Matter Experts (SMEs), analyzing design and test documentation and operational requirements, conducting cyber analyses and assessments, reverse engineering the design, and developing work products as outlined in the NAVAIR CSRA Standard Work Package (SWP), NAVAIR CSRA Implementation Guide, NAVAIR CYBERSAFE SWP , and NAVAIR CTT SWP to strengthen resiliency and integrity.
2.0 Applicable Documents
The Government will provide all necessary reference documents not generally available to the contractor, as required. Throughout the life of the contract, if any instruction or document is replaced or superseded, the replacement or superseding instruction or document shall be incorporated into the requirements in this SOW, once approved and agreed upon by all parties. These documents will be used as guidance for execution of this SOW and as invoked in Task Orders (TOs) issued under this contract:
2.1 NAVAIR CSRA SWP
2,2 NAVAIR CSRA Implementation Guide
2.3 NAVAIR CYBERSAFE SWP
2.4 NAVAIR Cyber Table Top (CTT) SWP
2.5 NAVAIR Security Classification Guide # 10-033
2.6 National Industrial Security Program Operating Manual (NISPOM), DoD 5220.22-M, incorporating change 2, 18 May 2016
2.7 Distribution Statements on Technical Documents, DoD I-5230.24, incorporating change 3, October 15, 2018
3.0 Requirements
The Contractor shall provide support to the Government in the areas of cooperative CSRA, CTT of fighter/attack (fixed and rotary wing) and surveillance aircraft or similarly complex aircraft, Tactical Unmanned Aerial vehicles (UAV), smart (GPS guided) weapons or similarly complex weapons, Training Simulators, Portable Electronic Maintenance Aids (PEMA) equipment, software and development environments, and associated communications and networks in accordance with NAVAIR CSRA Standard Work Package (SWP), NAVAIR CSRA Implementation Guide, NAVAIR CYBERSAFE SWP, and Cyber Table Top (CTT) SWP.
As part of the CSRA process, the contractor shall provide support to the Government for the following technical cyber areas, as required, when performing a CSRA and CTT: Cyber training, Cyber Systems Security Engineering (CSSE), reverse engineering, Software Assurance, Cyber Incident Response, Cyber Supply Chain Risk Management (C-SCRM), Mission Assurance, and Cyber digital modeling. CSSE is defined as Systems Security Engineering expertise coupled with specific cyber domain knowledge such as but not limited to architecture (HW and SW) analysis, avionics, flight controls, seeker/sensors, Information Assurance (IA) policy and process, software analysis, Static and Dynamic Code Analysis (SCA), Supply Chain analysis, and Cyber Model Based Systems Engineering (C-MBSE).
The Contractor shall support and provide input for the development of a Verification and Validation (V&V) test plan, Penetration Testing or similar intrusion methodologies designed to determine multiple critical system or component entry points, and participate in the Government led testing of fighter/attack (fixed and rotary wing) and surveillance aircraft or similarly complex aircraft, Tactical UAV, smart (GPS guided) weapons or similarly complex weapons, Training Simulators, Portable Electronic Maintenance Aids (PEMA) equipment, software, associated communications and networks in accordance with NAVAIR CSRA SWP, NAVAIR CSRA Implementation Guide, NAVAIR CYBERSAFE SWP, and Cyber Table Top SWP. All documentation developed as part of the final Government reports will be classified and marked in accordance with the NAVAIR Security Classification Guide (SCG) or in the instance where a program SCG exists, the program SCG will take precedence over the NAVAIR SCG.
The contractor shall provide support to the NAWCWD Weapon Systems Protection Engineering Department (WSPER) for the following Cyber Survivability Risk Analysis (CSRA), and associated efforts:
· Manual and automated technical data/information gathering
· Technical analysis of avionics and weapons system cyber resiliency
· Mission analysis
· CSSE digital modeling of Cyber assessment techniques and survivability attributes
· Operational Flight Program (OFP) Software Assurance including Static Code Analysis (SCA)
· Cyber hardware and software supply chain analysis
· Cyber solutions to include organic hardware and software design and development
· Cyber risk analysis and scoring using
· Verification and Validation (V&V) testing of Cyber susceptibilities and Cyber solutions
· Consultation for embedded system Cyber mitigation and remediation CSRAs typically consist of data/document and intelligence gathering, technical system analysis, mission analysis and V&V.
The contractor shall provide cyber engineering support to the Tactical Mobility Integrated Product Team (TacMo IPT) team including supporting:
· Design, develop, integrate cyber solutions for enhancing Cybersecurity in embedded systems
· Perform experimentation to develop and support future proofing of technologies
· Develop firmware to test and evaluate cyber hardware slated for future organic capabilities
· Update Cyber Whitepapers with new cyber hardware/firmware architectural changes
· Provide architectural SME for Intrusion Detection System (IDS)
· Perform algorithm development and evaluation for IDS solution
· Support Cyber capabilities architectural assessment for IDS architecture
· Perform Technical Writing for Cyber Solutions, and provide Configuration Management/Data Management (CM/DM) for handling of documentation products
3.1 Fighter/Attack/Surveillance Platform Assessment and Training Simulators The Contractor shall provide cyber susceptibility/vulnerability analysis and risk assessment of NAVAIR fighter/attack and surveillance aircraft and training simulators.
3.1.1 Cyber Survivability Risk Assessment (CSRA)
The Contractor shall participate in a Government-led team, and shall provide written input for CSRA work products including access point maps, digital models, workbooks, risk analysis, and final assessment report for NAVAIR fighter/attack (fixed and rotary wing) and surveillance aircraft. The Contractor shall submit the CSRA work products to the designated Government representative, in accordance with the appropriate SCG. The Government representative will be designated in each task order. Once work products have been submitted, the Contractor shall send a transmittal letter to the Contracting Officer’s Representative (COR).
3.1.2 Cyber Table Top (CTT) Assessment
The Contractor shall participate in a Government-led team, and shall provide written input for CTT work products including access point maps, workbooks, risk analysis, and final assessment report for NAVAIR fighter/attack (fixed and rotary wing) and surveillance aircraft. The Contractor shall submit the CTT work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.1.3 Verification and Validation (V&V) Testing
The Contractor shall provide input for the development of V&V test plan and observe the Government-led test of NAVAIR fighter/attack and surveillance aircraft. The Contractor shall submit the V&V test plan inputs to the designated Government representative in accordance with the appropriate SCG. Once test plan inputs have been submitted, the Contractor shall send a transmittal letter to the COR.
3.1.4 Penetration Testing
The Contractor shall support and provide input for the development of Penetration Testing, or similar intrusion methodologies designed to determine multiple critical system or component entry points. The contractor shall support the implementation and integration of system hardening recommendations, based on vulnerability analysis and testing results. All documentation developed as part of the final Government reports will be classified and marked in accordance with the NAVAIR Security Classification Guide (SCG), or in the instance where a program SCG exists, the program SCG will take precedence over the NAVAIR SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.1.5 Cyber Incident Response Procedure
The contractor shall support the development of a concept of operations (CONOPS) for NAVAIR fighter/attack (fixed and rotary wing) and surveillance aircraft Cyber Incident Response (C-IR), to include research of existing processes, determination of applicable cyber intrusion event triggers, and recommendations on process improvement and software tools necessary to facilitate the C-IR workflow. Once CONOPS has been submitted, the Contractor shall send a transmittal letter to the COR.
3.1.6 Cyber Digital Engineering Support
The Contractor shall design, implement, and enhance a digital systems engineering solution that enables CSSE SMEs to perform in-depth cyber risk analysis of embedded avionic systems using a set of C-MBSE tools and techniques. As part of a Government-led team, the Contractor shall assist with the C-MBSE requirements definition, design, and prototyping used for conducting CSRAs, CTTs, and Risk Management Framework security controls selection. C-MBSE tasking will be conducted using Cameo Systems Modeler, and associated software suite, and will make use of NAVAIR’s Teamwork Cloud implementation. The C-MBSE solution shall align with NAVAIR’s approved MBSE ontology. The Contractor shall submit the C-MBSE work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.1.7 Cyber Solutions
The Contractor shall provide SME for developing hardware, software, and test capabilities for integration and interoperability (I&I) of new platform organic cyber solutions. As part of a Government-led team, the Contractor shall research new central processing (CPU) and microcontroller unit (MCU) cyber capabilities, perform algorithm development, and provide architectural support for developing a platform Intrusion Detection System (IDS). Other tasks include supporting flight tests with experimentation boards to validate a concept or developmental dependency, developing firmware to test and evaluate cyber hardware, and generate adversarial threat data along with supporting data collection requirements for IDS test and evaluation (T&E). Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.2 Tactical Unmanned Aerial Vehicles (UAV)
The Contractor shall provide cyber susceptibility/vulnerability analysis and risk assessment of NAVAIR tactical UAV’s.
3.2.1 Cyber Survivability Risk Assessment (CSRA)
The Contractor shall participate in a Government-led team, and shall provide written input for CSRA work products including access point maps, digital models, workbooks, risk analysis, and final assessment report for NAVAIR tactical UAV. The Contractor shall submit the CSRA work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.2.2 Cyber Table Top (CTT) Assessment
The Contractor shall participate in a Government-led team, and shall provide written input for CTT work products including access point maps, workbooks, risk analysis, and final assessment report for NAVAIR tactical UAV. The Contractor shall submit the CTT work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.2.3 Cyber Digital Engineering Support
The Contractor shall design, implement, and enhance a digital systems engineering solution that enables CSSE SMEs to perform in-depth cyber risk analysis of embedded avionic systems using a set of C-MBSE tools and techniques. As part of a Government-led team, the Contractor shall assist with the C-MBSE requirements definition, design, and prototyping used for conducting CSRAs, CTTs, and Risk Management Framework security controls selection. C-MBSE tasking will be conducted using Cameo Systems Modeler, and associated software suite, and will make use of NAVAIR’s Teamwork Cloud implementation. The C-MBSE solution shall align with NAVAIR’s approved MBSE ontology. The Contractor shall submit the C-MBSE work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.2.4 Cyber Solutions
The Contractor shall provide SME for developing hardware, software, and test capabilities for integration and interoperability (I&I) of new UAV platform organic cyber solutions. As part of a Government-led team, the Contractor shall research new central processing (CPU) and microcontroller unit (MCU) cyber capabilities, perform algorithm development, and provide architectural support for developing a platform Intrusion Detection System (IDS). Other tasks include supporting flight tests with experimentation boards to validate a concept or developmental dependency, developing firmware to test and evaluate cyber hardware, and generate adversarial threat data along with supporting data collection requirements for IDS test and evaluation (T&E). Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.3 Smart (GPS guided) Weapons Assessment
The Contractor shall provide cyber susceptibility/vulnerability analysis and risk assessment of NAVAIR smart (GPS guided) weapons.
3.3.1 Cyber Table Top (CTT) Assessment
The Contractor shall participate in a Government-led team, and shall provide written input for CTT work products including access point maps, digital models, workbooks, risk analysis, and final assessment report for NAVAIR smart (GPS guided) weapons. The Contractor shall submit the CTT work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.3.2 Cyber Survivability Risk Assessment (CSRA)
The Contractor shall participate in a Government-led team, and shall provide written input for CSRA work products including access point maps, digital models, workbooks, risk analysis, and final assessment report for NAVAIR smart (GPS guided) weapons. The Contractor shall submit the CSRA work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.3.3 Verification and Validation (V&V) Testing
The Contractor shall support the development of V&V test plan and participate in the Government led test of NAVAIR smart (GPS guided) weapons. The Contractor shall submit the V&V work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.3.4 Cyber Digital Engineering Support
The Contractor shall design, implement, and enhance a digital systems engineering solution that enables CSSE SMEs to perform in-depth cyber risk analysis of embedded avionic systems using a set of C-MBSE tools and techniques. As part of a Government-led team, the Contractor shall assist with the C-MBSE requirements definition, design, and prototyping used for conducting CSRAs, CTTs, and Risk Management Framework security controls selection. C-MBSE tasking will be conducted using Cameo Systems Modeler, and associated software suite, and will make use of NAVAIR’s Teamwork Cloud implementation. The C-MBSE solution shall align with NAVAIR’s approved MBSE ontology. The Contractor shall submit the C-MBSE work products to the designated Government representative in accordance with the appropriate SCG. Once work products have been submitted, the Contractor shall send a transmittal letter to the COR.
3.4 Progress Reports
The Contractor shall provide a monthly Contractor’s Progress, Status, and Management Report that shows planned expenditures over the life of the contract and each TO, comparing planned to actual expenditures. All data in the Contractor’s Progress, Status, and Management Report shall be unclassified. Technical tasking progress shall be summarized to include accomplishments; compliance to schedule; issues, problems, and solutions; and risks to completion of the TO effort. The Contractor shall provide a summary of prime and subcontractor labor hours expended by each TO during the reporting period and the cumulative hours expended for each TO during the period of performance. The Travel Section of the report shall contain the following for each travel trip taken during the reporting period: (1) Name(s) of travelers, (2) Travel dates, (3) Destination, (4) Purpose of trip, (5) Accomplishments during trip, and (6) Itemized listing of actual travel costs incurred per individual (CDRL A001).
3.5 Technical Administrative Support
The Contractor shall perform administrative support for the technical tasking in Paragraphs 3.1 -
3.3 to meet Naval Air Warfare Center Weapons Division (NAWCWD) mission requirements. The Contractor shall use Government-furnished data to provide various technical administrative services including, but not limited to, Contractor personnel and visitor badging; coordinate and schedule team meetings and CSRA interviews; coordinate and schedule telecons and Video Teleconference Capabilities (VTCs); complete, submit and track Navy Marine Corps Intranet (NMCI) and Communication Service Requests for team members; update and post project plans, update and post financial reports, and progress reports to Government-owned share drive; coordinate lab/facility access; and track and update team action items.
3.6 Work Location, Facilities and Telework
3.6.1 Work location
Approximately XX percent of work will be performed at Government site and XX percent of work to be performed at Contractor site. Government site(s) include NAWS China Lake and NBVC Pt. Mugu. Contractors performing on-site support will be provided (examples include but are not limited to: Access to workspaces, telephones, printers, facsimile machines, copy machines, shredders, computers, and network access including web servers and applicable databases or other applications) necessary to carry out assigned tasks.
3.6.2 Meeting Support
In support of the tasking outlined in this PWS/SOW, the Contractor shall have the capability to host and conduct meetings at the classification levels up to Secret with the capacity to support a minimum of two (2) persons and have contractor furnished telephone and VTC capability as well as sufficient equipment to conduct meetings with presentations including compatible software as required in Paragraph 3.1.1). This support shall be provided at the contractor’s primary work facility.
3.6.3 Telework
The Contractor, upon notification to, and concurrence from, the Contracting Officer's Representative (COR) that the employees' work tasking is eligible for telework, may utilize alternate worksites/locations and telework to support continued performance of its contract in accordance with company policy. Contractor discretion is required when making alternate worksite and telework decisions based upon the nature of support provided by the employees. In the event telework is utilized, the Contractor remains responsible for performance, and compliance with any applicable cost accounting standards and contract cost principles / procedures.
3.7 Work Schedule
The Holidays applicable to this contract are: New Year's Day, Birthday of Martin Luther King Jr., Washington’s Birthday (President's Day), Memorial Day, Juneteenth National Independence Day, Independence Day, Labor Day, Columbus Day, Veteran's Day, Thanksgiving Day, and Christmas Day.
In the event that any of the above holidays occur on a Saturday or Sunday, or alternate Friday, then such holiday shall be observed as they are by the assigned Government employees at the using activity.
The Naval Air Warfare Center Weapons Division works a 4/5/9 work schedule. Therefore alternate Fridays are not a part of the normal workweek for work performed on-site at a Naval Air Warfare Center Weapons Division site. The majority of the Government offices are closed on alternate Fridays.
No deviation in the normal workweek will be permitted without express advance approval by the designated Contracting Officer with coordination of the using departments.
The Contractor may allow its employees to work the installation work schedule provided the requirements of this PWS/SOW are met. If the contractor chooses to allow its employees to work an alternate schedule in support of this contract, any additional costs associated with the implementation of the alternate schedule vice the standard schedule are unallowable costs under this contract and will not be reimbursed by the Government. Additionally, the alternate schedule shall not prevent Contractor employees from providing necessary staffing and services coverage as required by the Government to the ACOR/COR.
3.7.1 Installation Closure
When Federal facilities are closed by the Government, or when Federal employees are officially excused from work due to a holiday or a special event, severe weather, a security threat, or any other Government facility related problem that prevents Federal personnel from working at the Government facility, contractor personnel assigned to work at that facility in support of such Federal employees shall follow their parent company’s policies.
While generally contractor personnel may not perform work on-site at a Government facility without oversight from Federal personnel, in very limited circumstances, work being performed by contractor personnel may be deemed mission essential and performance of such mission essential work may be authorized to continue at the Government facility despite the facility being otherwise closed for normal operations. The circumstances permitting work being performed by contractor personnel to be deemed mission essential are extremely limited and generally only apply to performance of efforts related to public health, safety, or matters related to national security. The cognizant Contracting Officer must concur with any determination that work being performed by contractor personnel is mission essential.
3.8 Subcontractors and Consultants
Provisions stated herein shall be clearly and effectively communicated to all subcontractors providing support under this contract. All provisions of this PWS/SOW shall flow down to subcontractors providing support under this contract.
3.9 Management of Contractor Personnel
The Government will neither supervise contractor employees nor control the method by which the contractor performs the required tasks. Under no circumstances will the Government assign tasks to, or prepare work schedules for, individual contractor employees. The contractor shall manage its employees and guard against any actions that are of the nature of personal services, or give the perception of personal services.
3.10 Transition Out Strategy
The Contractor’s overall transition out strategy shall be built around maintaining the mission of the WSPER and XDEV programs with minimal impact, not only in terms of timeliness of performance but also to ensure that critical data and knowledge transfer occurs. Upon termination or expiration of the contract, the contractor shall ensure an orderly transition of responsibilities, while minimizing impact to the operation. The contractor shall submit a Transition Out Plan, to include the minimum elements listed below in accordance with CDRL A003.
· Work Turnover. The contractor shall provide a plan of action to effectively transfer tasked work that is in process at the expiration or termination of the contract to the successor company. Establish and maintain effective communication with the incoming contractor or Government personnel for the period of transition via weekly status meetings.
· Quality Assurance. The contractor shall provide a plan of action to ensure continuation of quality review processes during the transition period to the successor company.
· Risk Mitigation Strategies. The contractor shall provide a plan of action to mitigate contract performance risks (quality and schedule) encountered during the transition period.
· Data/Information Transfer. The contractor shall provide a plan of action for the efficient inventory and transfer of program data to the successor company.
4.0 Deliverables
4.1 Status Reports
The Contractor shall submit the Contractor’s Monthly Progress, Status, and Management Report (CDRL A001) via email to the NAWCWD Contracting Officer’s Representative (COR), Technical Point of Contact (TPOC), and Contract Specialist (CS) identified in the contract.
The Contractor shall provide the first status report on the tenth day after the first complete month following award of the contract. The Contractor shall submit subsequent status reports by the tenth calendar day of each subsequent month for the duration of the contract.
4.2 Prototypes and Demonstrations
The Contractor shall develop prototypes of new Cyber Solutions (CDRL A002), and conduct functional demonstrations as part of the engineering and manufacturing development (EMD) phase support for the Network Cyber Defense program of record. Prototypes and demonstrations may include alternates for obsolescence components or the results of studies. Specific information and schedules required to develop prototypes and prototype demonstrations will be provided at the order level. The information will include the prototype functions to be developed, objectives, and purpose of the prototype and demonstration.
4.2.1 Prototypes
The contractor shall develop and deliver firmware and software for prototypes, if requested by the government. The contractor shall generate a technical report detailing each prototype developed. (A002)
4.2.2 Prototype Demonstrations
The contractor shall demonstrate prototype operation or enhancements to the government, conducted at NAWCWD in China Lake, CA, unless otherwise directed by the government. The contractor shall generate a technical summary report summarizing each prototype demonstration conducted. (A002)
5.0 Special Provisions
This section describes the security, travel, and materials for this effort. The following sub- sections provide details of various considerations on this effort.
5.1 Security
The contractor shall provide personnel with the appropriate personnel security clearance levels for the work to be performed. Access to TOP SECRET and SCI information is required in the performance of this contract and shall be in accordance with the DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), incorporating change 2, 18 May 2016, applicable DoD personnel security regulations, and DoD Contract Security Classification Specification (DD Form 254). The contractor shall maintain sufficiently cleared personnel to perform the tasks required by this SOW IAW the DD Form 254 and the contract. All contractor personnel shall possess the requisite security clearance, accesses, and need-to-know commensurate with the requirements of their positions.
All contractor personnel with access to unclassified information systems, including e-mail, shall have at a minimum a favorable Tier 3 (T3) investigation.
5.1.1 Citizenship Requirements
Only U.S. citizens may perform under this contract. If the Contractor cannot find qualified U.S. citizens to perform the work, the Contractor shall submit a citizenship waiver request with justification to the Government Security Office. The waiver request should include:
a. The individual's name, date and place of birth, position title, and current citizenship.
b. A statement that a qualified U.S. citizen cannot be hired in sufficient time to meet the contractual requirements.
c. A statement of the unusual expertise possessed by the applicant.
d. A statement that access will be limited to a specific government contract (specify contract number).
e. A statement that the Contractor has obtained an export license for the information required to perform the contract.
5.1.2 Clearance
All Contractor personnel shall maintain security clearance eligibility commensurate with the level of classification of the work performed as annotated in the Contract's DD-254, Contract Security Classification Specification Form.
Contractor personnel shall require access to classified information in performance of this contract up to and including TOP SECRET/SCI, with a safeguarding level of TOP SECRET/SCI. The Contractor is responsible for ensuring that all personnel receive the requisite investigation and are favorably adjudicated in accordance with DoDM 5220.22, National Industrial Security Program Operating Manual. Contractor employees who fail to meet security clearance requirements may not access classified information or perform sensitive duties. In such cases, the Contractor employee may not perform on the contract.
5.1.3 Common Access Card (CAC)/Public Key Infrastructure (PKI), System Authorization Access Request (SAAR-N) SAAR-N: All contractor personnel requiring access to Government Information Technology (IT) systems shall have an approved System Authorization Access Request (SAAR-N) Form OPNAV 5239/14 (Rev Sep 2011) on file, and complete required Annual Information Awareness Training. New employees must submit their SAAR forms within thirty (30) days of their first day of work. Instructions for processing the SAAR-N forms are available at: OPNAV-5239-14-SAAR-N.pdf. SAAR-N forms shall be submitted to the Contracting Officer’s Representative (COR), Government Technical Point of Contact (TPOC), or to the assigned government Trusted Associate Sponsorship System (TASS) Trusted Associate.
Command Access Cards (CAC) / Local Badges: Contractors requiring access to federal installations shall obtain the appropriate base identification for all contractor personnel who make frequent visits to or perform work at government sites. Contractor personnel are required to wear or prominently display installation identification badges or contractor-furnished identification badges while visiting or performing work on the installation(s) with the exception of contractors working with aircraft or dangerous equipment when the identification could present a safety hazard. In this case, these contractors shall have the proper identification in their possession at all times. The contractor shall be responsible for obtaining required identification for newly assigned personnel and for prompt return of credentials, Common Access Card (CAC), and any other secondary area access badges/identification for any employee who no longer requires access to the work site(s), upon separation, resignation, firing, completion or termination of the contract or expiration of base identification. The contractor shall ensure that all base identification passes to include Common Access Cards and any other secondary area access badges/identification issued to contractor employees are returned to the appropriate component issuing office.
DD-254: The contractor shall comply with security requirements specified in the DD-254 attached to this contract. Information or data that the contractor accesses shall be handled at the appropriate classification level, unclassified information shall be handled as “For Official Use Only”. Distribution is authorized to the Requiring Office’s Organization and supported Activity only. Other requests for deliverables under this contract shall be referred to the TPOC/COR of this contract for approval.
5.1.4 Information Security
Direct Support contractor personnel working under the purview of a DoN Commanding Officer/Commander shall comply with the local security provisions and the requirements of SECNAV M-5510.36B (series). The contractor shall implement and maintain security procedures and controls to prevent unauthorized disclosure of controlled unclassified information and to control distribution of controlled unclassified information in accordance with DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), and SECNAV M-5510.36B. If the work is performed at the Government's facility, the Contractor shall comply with the NAWCWD Command Security Manual.
The contractor shall comply with security requirements specified in the DD-254 attached to this contract. Information or data that the contractor accesses shall be handled at the appropriate classification level. Unclassified information shall be handled in accordance with the appropriate designation (Controlled Unclassified Information; Covered Defense Information). Distribution is authorized to the Requiring Office's Organization and supported Activity only. Other requests for deliverables under this contract shall be referred to the TPOC/COR of this contract for approval.
CUI information generated and/or provided under this contract shall be marked and safeguarded as specified in DoDI 5200.48, Controlled Unclassified Information (CUI). Contractor shall not store or transmit CUI on personal information technology systems or via personal e-mail. Unclassified e-mail containing any DoD CUI shall be encrypted. Prior to sending CUI to any non-Navy Marine Corps Internet (NMCI) addressees, the sender must first positively verify all recipients are authorized access to CUI and have need-to-know. Non-NMCI recipients must have a DoD compliant Private Key Infrastructure (PKI) certificate that enables electronic transmission via unclassified networks while protecting the CUI with a digital signature and encryption. Any product containing Covered Defense Information shall be assigned a distribution statement (distribution statements B through F) using the criteria set forth in DoDI 5230.24.
Marking: All information generated by the Contractor shall be properly marked. CUI generated and/or provided under this contract shall be marked in accordance with DoDI 5200.48 Technical information shall also be marked with appropriate Distribution Statements and Export Control warnings in accordance with DoDI 5230.24 and program Security Classification Guidance.
Disclosure of information is covered by DFARS 252.204-7000 Disclosure of Information, incorporated in Section I of the contract. Concerning subsection (a)(2), “information otherwise in the public domain” is information officially released into the public domain, e.g. via Distribution Statement A, and does not include information in the public domain that has not been officially released. For disclosure of unclassified information that has not been officially released, the contractor must seek specific approval from the Contracting Officer, with approval from the NAWCWD Public Affairs Office (PAO).
Loss, Compromise and/or Electronic Spillage of Classified or Controlled Unclassified Information: All instances of loss, compromise and electronic spillage of classified or controlled unclassified information shall be reported to the COR, TPOC and Government Security Office within 24 hours of the incident occurring.
5.1.5 Physical Security
The Contractor will be provided access to designated classified areas for execution of tasking and be responsible for safeguarding all Government information or property provided for Contractor use. Government information, facilities, equipment and materials shall be secured as specified by the NISPOM and the NAWCWD Command Security Manual.
Direct Support contractor personnel working under the purview of a DoN Commanding Officer/Commander shall comply with the local security provisions and the requirements of SECNAV M- 5510.36 (series). The contractor shall implement and maintain security procedures and controls to prevent unauthorized disclosure of controlled unclassified information and to control distribution of controlled unclassified information in accordance with DoD 5220.22-M, National Industrial Security Program Operating Manual (NISPOM), and SECNAV M-5510.36.
The contractor shall comply with security requirements specified in the DD-254 attached to this contract. Information or data that the contractor accesses shall be handled at the appropriate classification level. Unclassified information shall be handled in accordance with the appropriate designation (Controlled Unclassified Information; Covered Defense Information). Distribution is authorized to the Requiring Office's Organization and supported Activity only. Other requests for deliverables under this contract shall be referred to the TPOC/COR of this contract for approval.
CUI information generated and/or provided under this contract shall be marked and safeguarded as specified in DoDI 5200.48, Controlled Unclassified Information (CUI). Contractor shall not store or transmit CUI on personal information technology systems or via personal e-mail. Unclassified e-mail containing any DoD CUI shall be encrypted. Prior to sending CUI to any non-Navy Marine Corps Internet (NMCI) addressees, the sender must first positively verify all recipients are authorized access to CUI and have need-to-know. Non-NMCI recipients must have a DoD compliant Private Key Infrastructure (PKI) certificate that enables electronic transmission via unclassified networks while protecting the CUI with a digital signature and encryption. Any product containing Covered Defense Information shall be assigned a distribution statement (distribution statements B through F) using the criteria set forth in DoDI 5230.24.
Communications Security (COMSEC). The contractor will require access to COMSEC at government locations. U.S. cryptographic equipment inventory information, as well as the systems and manner in which each particular equipment is used, is for official use only. Publication or release of any related COMSEC information by any means, by the contractor, without prior written approval of the contracting officer is prohibited. The contractor must be a U.S. citizen, have a final Government security clearance with the appropriate personnel security background investigation for the level of classification involved, have strict need-to-know, have the appropriate COMSEC briefing before access is granted, and granted access only in conformance with procedures established for the particular type of COMSEC information involved. The contractor shall adhere to the DD Form 254 COMSEC security requirements, facility COMSEC material control and operating procedures, and all applicable COMSEC regulations, instructions, and policies. Prior approval from the Government Contracting Activity is required in order for a prime contractor to grant COMSEC access to a subcontractor.
Operations Security (OPSEC). The contractor shall comply with the OPSEC requirements outlined within the DD Form 254.
The Contractor shall develop, implement, and maintain an OPSEC program to protect controlled unclassified activities, information, equipment, and material used or developed by the Contractor and any subcontractor during performance of the contract. The Contractor shall be responsible for the subcontractor implementation of the OPSEC requirements. The OPSEC program shall be in accordance with National Security Decision Directive (NSDD) 298, and at a minimum shall include:
1) Assignment of responsibility for OPSEC direction and implementation.
2) Issuance of procedures and planning guidance for the use of OPSEC techniques to identify vulnerabilities and apply applicable countermeasures.
3) Establishment of OPSEC education and awareness training.
4) Provisions for management, annual review, and evaluation of OPSEC programs.
5) Flow down of OPSEC requirements to subcontractors when applicable.
Public Release. Disclosure of information is covered by DFARS 252.204-7000 Disclosure of Information, incorporated in Section I of the contract. Concerning subsection (a)(2), “information otherwise in the public domain” is information officially released into the public domain, e.g. via Distribution Statement A, and does not include information in the public domain that has not been officially released. For disclosure of unclassified information that has not been officially released, the Contractor must seek specific approval from the Contracting Officer in consultation with the Security Department.
While performing aboard NAVAIR or NAVAIR sites, the contractor shall comply with facility OPSEC program instructions and contribute to organization-level OPSEC efforts. Include OPSEC as part of its ongoing security awareness program and take all required Agency training. Be responsive to the Supporting OPSEC Manager on a non-interference basis. Protect sensitive unclassified information and activities, which could compromise classified information or operations, or degrade the planning and execution of operations performed by the RO and contractor in support of the mission.
5.2 Government Furnished Materials
When the performance of contract tasking is required at a Government facility, the Government will make materials, office space, communications capability and information available for use by the Contractor. The Government will provide NMCI assets as required.
5.3 Travel
The Contractor shall be required to travel in performance of this contract. The purpose of the trips is to perform analysis and assessments. Contractors shall plan for non-local trips primarily to China Lake, California, and occasionally to Pt. Mugu, California and Naval Air Warfare Center Aircraft Division (NAWCAD) Patuxent River, Maryland. Specific travel requirements and locations will be identified in individual task orders.
5.4 Materials
Materials may be required for performance of this contract. The Contractor must obtain prior written approval from the COR for any purchases valued over $500. To receive approval for the purchases, the Contractor shall submit a consent package providing a description, price, evidence of adequate price competition, or if unavailable, a justification for use of a single source and a determination that the price is fair and reasonable. These requirements apply to all Contractor purchases.
6.0 Personnel Qualifications
The NAWCWD labor categories and their corresponding BLS labor categories are shown in the below table.
| NAWCWD Labor Category |
| BLS Labor Categories |
| Program Manager |
| Manager, Senior, BLS/SOC 11-1021 |
| Administrative Assistant** |
| Administrative Assistant, Journeyman, BLS/SOC 43-6011 |
| Engineering Analyst |
| System Analyst, Journeyman, BLS/SOC 13-1111 |
| Engineer/Scientist III |
| Electrical Engineer, Journeyman, BLS/SOC 17-2071 Systems Engineer, Journeyman, BLS/SOC 17-2141 Physicist, Journeyman, BLS/SOC 19-2012 |
Computer Engineer, Journeyman, BLS/SOC 17-2061 and 17-2199 Computer Science, Journeyman, BLS/SOC 15-1221 Computer Programmer, Journeyman, BLS/SOC 15-1252 Software Engineer, Journeyman, BLS/SOC 15-1252
| Engineer/Scientist IV* |
| Electrical Engineer, Senior, BLS/SOC 17-2071 Systems Engineer, Senior, BLS/SOC 17-2141 |
Computer Engineer, Senior, BLS/SOC 17-2061 and 17-2199 Software Engineer, Senior, BLS/SOC 15-1252
| Software Engineer IV* |
| Software Engineer, Senior, BLS/SOC 15-1252 |
Computer Engineer, Senior, BLS/SOC 17-2061 and 17-2199
| IT Engineer |
| Information Management and Technology Analyst, Journeyman, BLS/SOC 15-1212 |
| “CM/DM” |
| Information Management and Technology Analyst, Journeyman, BLS/SOC 15-1212 |
| “Tech Writer” |
| Technical Writer, Journeyman, BLS/SCO 27-3042 |
* Key Personnel ** Service Contract Act Category
6.1 The Contractor shall be responsible for employing personnel having at least the minimum level of education, training, and experience as stated under each labor category specified herein. All personnel shall have a minimum secret security clearance.
6.2 Key Personnel are those who will be performing in Key Labor Categories as specified for applicable labor categories below. Some key personnel will be required to have TS clearances to support non-substantial TS/SCI tasking. Personnel with a TS clearance shall be available to perform a minimum of 25% of the estimated level of effort for the program manager and each key personnel labor category.
6.3 College Degree: All degrees shall be obtained from an “accredited college or university” as recognized by the U.S. Department of Education. This includes Associate’s, Bachelor’s, Master’s, and Doctorate degrees.
6.4 Degree Majors: All labor categories requiring Degrees in the Professional Engineering functional area specified below shall have a Major in at least one of the following subjects: Electrical/Electronic engineer, Computer Engineer, Computer Science, Mechanical engineer, Physicist, Systems Engineer
6.5 Technical Certification Training: Systems Administrator will have at a minimum Security Plus certification
6.6 Professional employee Experience and Education Level definitions:
JUNIOR: A Junior level person within a labor category has less than 3 years’ experience and a BA/BS degree. A Junior level person is responsible for assisting more senior positions and/or performing functional duties under the oversight of more senior positions.
JOURNEYMAN: A Journeyman level person within a labor category has 3 to 10 years’ of experience and a BA/BS degree. A Journeyman level person typically performs all functional duties independently.
SENIOR: A Senior level person within a labor category has more than 10 years’ of experience and an MA/MS degree. A Senior level person typically works on high-visibility or mission critical aspects of a given program and performs all functional duties independently. A Senior level person may oversee the efforts of less senior staff and/or be responsible for the efforts of all staff assigned to a specific job.
Additionally, the following qualification substitution chart provides standard experience/education substitutions:
| Bachelor’s Degree |
| 6 years’ additional work experience may be substituted for a Bachelor’s Degree |
| Associate’s Degree plus 4 years’ additional work experience may be substituted for a Bachelor’s Degree |
| Master’s Degree |
| Bachelor’s Degree plus 4 years’ additional work experience may be substituted for a Master’s |
“Years of experience” shall mean full, productive years of participation.
“Productive years” shall mean 52 weeks of work reduced by reasonable amounts of time for holidays, annual and sick leave.
If participation was part-time, or if less than one-half of the standard work week was spent performing qualifying functions, the actual time spent performing qualifying functions may be accumulated to arrive at full years of experience.
Contractor personnel must have performed these functions at least 3 years within the last 5 years for their applicable labor category.
6.7 Labor Qualifications: The following lists the minimum labor category and requirements, if any, and the functional descriptions for each labor category:
DRAFT
| Labor Category |
| Level |
| BLS SOC Code |
| Functional Description |
| Manager |
| Senior |
| 11-1021 |
| See below |
| Electrical/Electronic Engineer |
| Journeyman |
| 17-2071 |
| See below |
| Electrical/Electronic Engineer |
| Senior |
| 17-2071 |
| See below |
| Systems Engineer |
| Journeyman |
| 17-2141 |
| See below |
| Systems Engineer |
| Senior |
| 17-2141 |
| See below |
| Computer Engineer |
| Journeyman |
| 17-2061 |
| See below |
| Computer Engineer |
| Senior |
| 17-2061 |
| See below |
| Computer Science |
| Journeyman |
| 15-1221 |
| See below |
| Systems Analyst |
| Journeyman |
| 13-1111 |
| See below |
| Physicist |
| Journeyman |
| 19-2012 |
| See below |
| Software Engineer |
| Journeyman |
| 15-1252 |
| See below |
| Software Engineer |
| Senior |
| 15-1252 |
| See below |
| System Administrator |
| Journeyman |
| 15-1244 |
| See below |
| Administrative Assistant |
| Journeyman |
| 43-6011 |
| See below |
| Information Management |
| Journeyman |
| 15-1212 |
| See below |
| Technical Writer |
| Journeyman |
| 27-3042 |
| See below |
Manager, Senior, BLS/SOC 11-1021: Must have performed and acted as the…
This is the start of the file's text. The full file is on GovTribe.
File details come from the government source that posted it. Updated .