Attachment 1 HPCMP CSSP PWS - Draft Only.pdf

PDF 1 MB Posted

Attached to
HPCMP CSSP Support Services Federal contract opportunity
Solicitation number
W912HZ22R0007
Issued by
Department of the Army Corps of Engineers Engineer Research and Development Center

View the file

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Performance Work Statement (PWS) HPCMP CSSP Contract

DRAFT

Table of Contents

Performance Work Statement (PWS) Table of Contents

1. Introduction

1.1. Mission

1.2. Background

1.3. Scope

1.4. Period of Performance

2. General Requirements

2.1. Non-Personal Services

2.2. Business Relations

2.3. Contract Administration and Management

2.3.1. Contract Management

2.3.2. Contract Administration

2.3.3. Personnel Administration

2.4. Subcontract Management

2.5. Contractor Personnel, Disciplines, and Specialties

2.5.1. Responsive Subscriber Service

2.5.2. Unacceptable Performance

2.5.3. Removal of Personnel at Government Request

2.5.4. Standards of Conduct and Appearance

2.6. Location and Hours of Work

2.6.1. Place of Performance

2.6.2. Hours of Operation

2.7. Federal Holidays

2.8. Government Facility Closure

2.9. Citizenship

2.10. Security Clearances

2.11. Common Access Card (CAC)

2.12. Travel

2.12.1. Travel Approval

2.12.2. Travel Reimbursement

2.12.3. Trip Reports

2.13. Training

2.13.1. Training Approval

2.13.2. Training Reimbursements

2.14. Key Personnel

2.14.1. Program Manager

2.14.2. Lead Detect Analyst(s)

2.14.3. Detect Shift Leads

2.14.4. Lead Protect Analyst

2.14.5. Lead Systems Engineer

2.15. Surge

2.15.1. Surge Approval

2.15.2. Surge Reimbursement

3. Scope of Work

3.1. Program Manager

3.1.1. Personnel Management

3.1.2. On-Call Support

3.2. Detect Services

3.2.1. Lead Detect Analyst(s)

3.2.2. Detect Shift Leads

3.2.3. CSSP Subscriber Response

3.3. Warning Intelligence Services

3.3.1. CSSP Subscriber Response

3.3.2. On-Call Support

3.4. Protect Services

3.4.1. Lead Protect Analyst

3.4.2. Vulnerability Assessment and Analysis

3.4.3. Vulnerability Management

3.4.4. Endpoint Protection

3.4.5. Cybersecurity Protection Condition (CPCON)

3.4.6. Information Security Continuous Monitoring (ISCM)

3.4.7. Insider Threat

3.4.8. CSSP Subscriber Response

3.4.9. On-Call Support

3.5. Infrastructure Services

3.5.1. Operations

3.5.2. Security

3.5.3. Continuity of Operations (COOP)

3.5.4. Issue Tracking

3.5.5. On-Call Support

3.5.6. CSSP Subscriber Response

3.5.7. Lead Systems Engineer

3.6. Boundary Assessment and Analysis Services

3.6.1. CSSP Subscriber Response

3.6.2. On-Call Support

3.7. Sustainment Services

3.7.1. CSSP Subscriber Response

4. Special Requirements

4.1. Security and Safety

4.1.1. Safety

4.1.2. Onsite Access

4.1.3. Access to Certain Restricted Areas

4.1.4. Access to Government Information Systems

4.1.5. AT Level I Training

4.1.6. Access and General Protection/Security Policy and Procedures

4.1.7. iWATCH Training

4.1.8. Contractor Employees Who Require Access to Government Information Systems

4.1.9. Contracts that Require an OPSEC Standing Operating Procedure/Plan

4.1.10. Contracts that Require OPSEC Training

4.1.11. Information Assurance (IA)/Information Technology (IT) Certification

4.1.12. Access to Classified Information

4.1.13. Classified and/or Sensitive Materials and/or Sensitive or Restricted Areas

4.1.14. Clearances

4.2. Government Furnished Property

4.2.1. Government Furnished Property

4.2.2. Property Accountability

4.3. Contractor Furnished Property

4.4. Scope Changes

4.5. Performance Evaluation

4.6. Phase-in/Phase-out

4.7. Employee Conduct

4.8. Security Incidents

4.9. Applicable Directives

4.10. Order-Level Materials (OLM)

4.11. IT Equipment/Software Solutions

5. Deliverables

5.1. Major Requirements Deliverables

5.2. CSSP Operational Update

5.3. Work Availability Schedule

5.4. Monthly Status Report

5.5. Government Furnished Property Inventory

5.6. Report/Record of Meeting Minutes

5.7. Quality Control Plan

5.8. Contractor Performance

5.9. Quality Assurance

1. Introduction The primary purpose of this Performance Work Statement (PWS) is to acquire cybersecurity services in support of the High Performance Computing Modernization Program (HPCMP) Cybersecurity Service Provider (CSSP) mission to protect, monitor, analyze, detect, and respond to unauthorized activity within DoD information systems and computer networks residing on the Defense Research Engineering Network (DREN) and the Secret DREN (SDREN).

The HPCMP CSSP employs cybersecurity principals and includes deliberate actions taken to modify an assurance configuration or condition in response to a cybersecurity alert or threat information. The HPCMP CSSP helps organizations impacted by a cybersecurity compromise determine the extent of the incident, remove the adversary from their systems, and restore their networks to a more secure state; respond to crises or urgent situations within the pertinent domain to mitigate immediate and potential application, system, or network threats; and perform security testing in which assessors mimic real-world attacks to identify methods for circumventing the security features of an application, system, or network.

1.1. Mission

The HPCMP manages the Department of Defense (DoD) Research, Development, Test, and Evaluation (RDT&E) network, the DREN, and its classified counterpart, the SDREN. As a component of the Department of Defense Information Network (DoDIN), the DREN and SDREN provide secure high performance wide area network services in support of DoD scientists and engineers, as well as other related DoD communities and Federal agencies.

1.2. Background

The Engineer Research Development Center (ERDC) Information Technology Laboratory (ITL) is the Executive Agent for the DoD HPCMP. The HPCMP is designated as an Area of Operation (AOR) within the DoDIN due to its operation and management of the DREN and SDREN. The HPCMP operates as a Tier 1 CSSP for the entirety of the DREN and SDREN, and as a Tier 2 CSSP for portions of the DREN and SDREN.

1.3. Scope

The HPCMP has the mission to protect and support the networks, information systems, and the confidentiality, integrity, and availability of the data on the DREN and SDREN. HPCMP provides comprehensive services for Identify; Protect; Monitor, Analyze, and Detect; Respond; and Sustainment functions to maintain a robust and consistent security environment in accordance with (IAW) current Evaluator Scoring Metrics (ESM) and DODI 8530.1, 7 MAR 2016. The HPCMP cybersecurity subscriber base at present includes 138 sites and ~35,000 hosts, which may vary +/- 10%. The HPCMP CSSP currently receives approximately 115,000 intrusion detection system (IDS) alerts per week. Of these alerts, the majority occur during core hours.

1.4. Period of Performance

The period of performance for this task order will be with a one (1) year base period of performance, four (4) one

(1) year options and one (1) six (6) month extension of services option.

2. General Requirements This section describes the general requirements the contractor needs to accomplish. The following sub-sections provide details of various considerations on this effort.

2.1. Non-Personal Services

The Government shall neither supervise contractor employees nor control the method by which the contractor performs the required tasks. Under no circumstances shall the Government assign tasks to, or prepare work schedules for, individual contractor employees. It shall be the responsibility of the contractor to manage its employees and to guard against any actions that are of the nature of personal services, or give the perception of personal services. If the contractor believes that any actions constitute, or are perceived to constitute personal services, it shall be the contractor's responsibility to notify the Procuring Contracting Officer (PCO) immediately.

2.2. Business Relations

The contractor shall successfully integrate and coordinate all activity needed to execute the requirement. The contractor shall manage the timeliness, completeness, and quality of problem identification. The contractor shall provide corrective action plans, proposal submittals, timely identification of issues, and effective management of subcontractors. The contractor shall seek to ensure subscriber satisfaction and professional and ethical behavior of all contractor personnel.

2.3. Contract Administration and Management

The following subsections specify requirements for contract, management, and personnel administration.

2.3.1. Contract Management

The contractor shall establish processes and assign appropriate resources to effectively administer the requirement. The contractor shall respond to Government requests for contractual actions in a timely fashion. The contractor shall have a single point of contact between the Government and Contractor personnel assigned to execute contracts or task orders. The contractor shall assign work effort and maintain proper and accurate time keeping records of personnel assigned to work on the requirement.

2.3.2. Contract Administration

The contractor shall establish processes and assign appropriate resources to effectively administer the requirement. The contractor shall respond to Government requests for contractual actions in a timely fashion. The contractor shall have a single point of contact between the Government and Contractor personnel assigned to support contracts or task orders. The contractor shall assign work effort and maintaining proper and accurate time keeping records of personnel assigned to work on the requirement.

2.3.3. Personnel Administration

The contractor shall provide the following management and support as required. The contractor shall provide for employees during designated Government non-work days or other periods where Government offices are closed due to weather or security conditions. The contractor shall maintain the currency of their employees by providing initial and refresher training as required to meet the PWS requirements. The contractor shall make necessary travel arrangements for employees. The contractor shall provide administrative support to employees in a timely fashion (time keeping, leave processing, pay, emergency needs).

The Contractor shall staff vacant positions within thirty (30) days of being vacant.

2.4. Subcontract Management

The contractor shall be responsible for any subcontract management necessary to integrate work performed on this requirement and shall be responsible and accountable for subcontractor performance on this requirement.

The prime contractor will manage work distribution to ensure there are no Organizational Conflict of Interest (OCI) considerations. Contractors may add subcontractors to their team after notification and approval to the Procuring Contracting Officer (PCO) or Contracting Officer Representative (COR).

2.5. Contractor Personnel, Disciplines, and Specialties

The contractor shall build a quality culture that self-identifies problems or areas for improvement. The contractor shall strive to proactively identify problems, or potential issues, affecting performance and proactively work to resolve them. The contractor shall report these items to the COR as soon as possible. Verbal reports will be followed up with written reports when directed by the COR, or the contractor may submit a written report to identify the issue and how it was resolved in order to record these actions for the Government’s consideration.

Identified discrepancies in which the contractor has proactively taken action to remedy the discrepancy and provide confidence of future compliance, the Government COR may determine that a formal task discrepancy report will not be issued. The contractor remains responsible to correct problems/issues that need resolution. The contractor shall work cooperatively with the Government to resolve issues as they arise.

2.5.1. Responsive Subscriber Service

The contractor shall respond to all tasks, questions, and inquiries from the COR and/or PCO by providing initial written acknowledgement within two (2) business days. All Government questions and inquiries shall be addressed and all tasks completed within the established Government timeframe. The contractor shall provide courteous and competent subscriber service and shall be flexible and responsive to the Government's evolving requirements or emergent activities.

2.5.2. Unacceptable Performance

Unless otherwise directed by the Government, the contractor shall immediately take action to correct or replace all non-conforming services or deliverables at no additional cost to the Government. If the contractor fails to perform at an acceptable quality level, the Government may issue a Task Discrepancy Report (TDR) to the contractor. The contractor shall complete their portion of the TDR and provide any supporting documents to support their response. The TDR response and supporting documents shall be submitted no later than the required due date established by the Government.

2.5.3. Removal of Personnel at Government Request

Contractor personnel do not work for the Government. However, in rare cases, the Government may request removal (permanent or temporary) of contractor personnel from performance of these requirements for security, safety, environmental, or health reasons, upon discovery of fraudulent qualification documentation, or when contractor personnel behave in an unprofessional manner that would be considered unacceptable by a reasonable person. The contractor shall ensure continuation of services such that impact to the Government is minimal and that replacements/substitutions comply with personnel competencies and personnel qualifications.

2.5.4. Standards of Conduct and Appearance

The contractor shall ensure that their employee policy for standards of conduct and personal appearance foster a professional and safe work environment that conforms to the Government’s existing organizational culture and employee standards. Contractor employees who pose a threat to the safety or welfare of the installation or its personnel may be immediately removed and/or barred from the installation.

2.6. Location and Hours of Work

2.6.1. Place of Performance

The current on-site locations of performance are:

- ERDC, 3909 Halls Ferry Road, Vicksburg, Mississippi

- AFRL, Building 271, 2721 Sacramento Street, Dayton, Ohio

- HPCMPO, Kingman Building, Fort Belvoir, Virginia

The maximum seating capacity for each location is identified in Table 1: Maximum Seating Capacity1.

Table 1: Maximum Seating Capacity

On-Site Location Unclassified Maximum Seating Classified Maximum Seating

ERDC 352 241

AFRL 10 101

HPCMPO 4 31

1 These seats are “hot desks” that a contractor employee chooses upon arrival, and are in secure areas with access to classified AND unclassified workstations.

2 Infrastructure Services and Program Manager sit in an unclassified space at ERDC.

(1) Program Manager (3.1). The contractor shall work on-site at ERDC.

(2) Detect Services (3.2). The contractor shall work on-site at ERDC and AFRL. Personnel located at

HPCMPO is optional.

(3) Warning Intelligence Services (3.3). The contractor shall work on-site at ERDC and AFRL.

Personnel located at HPCMPO is optional.

(4) Protect Services (3.4). The contractor shall work on-site at ERDC, AFRL, and HPCMPO.

(5) Infrastructure Services (3.5). The contractor shall work on-site at ERDC and AFRL.

(6) Boundary Assessment and Analysis Services (3.6). The contractor shall work on-site at ERDC, AFRL, HPCMPO, or remotely from any U.S.-based location.

(7) Sustainment Services (3.7). The contractor shall work on-site at ERDC, AFRL, HPCMPO, or remotely from any U.S.-based location.

The contractor may propose to perform Boundary Assessment and Analysis Services (3.6) and/or Sustainment Services (3.7) remotely with positions geographically dispersed, but the Government will not provide a high-speed internet connection or telephone to enable remote support.

Alternate Performance Locations: As directed and approved by the Government, alternate performance locations may be required during the life of this contract. Alternate performance locations may include Government operated and contractor operated locations. Situational teleworking is permissible with prior concurrence from the Government.

2.6.2. Hours of Operation

The contractor shall work during the designated hours of operations for each primary place of performance (ERDC, AFRL, and HPCMPO). Except for services that have been identified as mission essential in accordance with DFARS 252.237-7023, the contactor shall be excluded from working during base closures due to Federal holidays, Government shutdown, weather, or other situations identified by the PCO. Any additional Presidential declared holiday (not one of the standard eleven Federal holidays) or otherwise declared down day will not be a recognized holiday for the contractor.

Tasks requiring 24/7/365 support (e.g., Detect Services) will not be exempt in the event of facility closure and will be considered essential personnel. Personnel will be provided government furnished equipment (GFE) laptops for check-out for proper coverage of tasks in the event of closure. Unclassified work may be accomplished via telework; however classified work must be shifted to alternate CSSP locations identified in Table 1: Maximum Seating Capacity. The contractor shall propose a solution for the coverage of tasks in this event.

a. Program Manager (3.1). The core hours are between 7:00 AM and 5:30 PM, Monday through Friday, local time. The contractor shall provide on-call support during non-core hours, which may require them to work additional hours outside of the core hours.

b. Detect Services (3.2). Performance is on a 24/7/365 basis and are considered mission-essential functions.

c. Warning Intelligence Services (3.3). The core hours are between 7:00 AM and 5:30 PM, Monday through

Friday, local time. The contractor shall provide on-call support during non-core hours, which may require them to work additional hours outside of the core hours.

d. Protect Services (3.4). The core hours are between 7:00 AM and 5:30 PM, Monday through Friday, local time. The contractor shall provide on-call support during non-core hours, which may require them to work additional hours outside of the core hours.

e. Infrastructure Services (3.5). The core hours are between 7:00 AM and 5:30 PM, Monday through Friday, local time. The contractor shall provide on-call support during non-core hours, which may require them to work additional hours outside of the core hours.

f. Boundary Assessment and Analysis Services (3.6). The core hours are between 7:00 AM and 5:30 PM, Monday through Friday, local time. The contractor shall provide on-call support during non-core hours, which may require them to work additional hours outside of the core hours.

g. Sustainment Services (3.7). The core hours are between 7:00 AM and 5:30 PM, Monday through Friday, local time.

The contractor may be required to work additional hours outside of the core hours for Boundary Assessment and Analysis Services, Infrastructure Services, Warning Intelligence Services, Program Manager, and Protect Services as part of the standard (i.e., not Surge) services.

The contractor shall have the capability and capacity to provide surge labor and acquisitions in response to a government directed action as directed in Section 2.15.

2.7. Federal Holidays

Except for the services that are required 24/7/365, the contractor shall not provide services on the following recognized federal holidays without prior authorization from the PCO:

- January 1, New Year's Day

- 3rd Monday in January, Martin Luther King Jr. Holiday

- 3rd Monday in February, Presidents Day

- Last Monday in May, Memorial Day

- June 19, Juneteenth National Independence Day

- July 4, Independence Day

- 1st Monday in September, Labor Day

- 2nd Monday in October, Columbus Day

- November 11, Veterans Day

- 4th Thursday in November, Thanksgiving Day

- December 25, Christmas Day

- Any other day designated by Federal statute, executive order, or presidential proclamation.

When a holiday falls on a Sunday, it is observed on the following Monday, or as by directed by the official US Office of Personnel Management Federal Holiday Schedule. When a holiday falls on a Saturday, it is observed on the previous Friday, or as by directed by the official US Office of Personnel Management Federal Holiday Schedule.

2.8. Government Facility Closure

In the event of a Government facility closure, the contractor employees shall be excused from work at no cost to the government. The contractor shall continuously provide the services that are required 24/7/365.

There may be local determinations relating to adverse weather conditions, national emergencies, energy conservation, executive order determinations, furloughs, etc., which may require one or more facilities to close or reduce facility access. Since there is 24/7 coverage required for this contract, work may be required at the respective facilities to be determined by the local authority.

2.9. Citizenship

Contractor and employees of the contractor are required to be citizens of the United States of America and must maintain such status during the entire duration of the contract.

2.10. Security Clearances

The highest level of clearance required for this order is TOP SECRET (TS) clearance with Sensitive Compartmented Information (SCI). For minimum requirements, refer to Table 2: Minimum Clearance Requirements:

Table 2: Minimum Clearance Requirements

Requirement Minimum Clearance Boundary Assessment and Analysis Services SECRET; privileged access on classified systems requires a favorable Tier 5 (T5) background investigation Warning Intelligence Services TOP SECRET / SCI with T5 investigation Protect Services SECRET; personnel supporting Insider Threat (3.4.7) require

TOP SECRET / SCI; privileged access on classified systems requires a favorable Tier 5 background investigation

Detect Services SECRET; privileged access on classified systems requires a favorable Tier 5 background investigation

Sustainment Services SECRET; privileged access on classified systems requires a favorable Tier 5 background investigation

Infrastructure Services SECRET; privileged access on classified systems requires a favorable Tier 5 background investigation

The Contractor shall perform all TS/SCI functions required on this contract at approved Government locations. The contractor shall provide security at a level necessary to meet the requirements of the tasks requested. The contractor will require access to the Secret Internet Protocol Router Network (SIPRNET), SECRET DREN (SDREN), and the applicable Security Classification Guides (SCGs). SIPRNET/SDREN accounts will be requested through the Government and access to SIPRNET/SDREN will be at Government locations only. The contractor will require access to For Official Use Only and other Controlled Unclassified Information (CUI).

The contractor shall meet the requirements of the contract DD Form 254. The solicitation incorporates a DRAFT DD Form 254. The final, signed DD Form 254, will be incorporated into the order upon award or via modification.

The Contractor shall possess a TOP SECRET facility security clearance. Any proposed subcontractor that will execute any secured portion of this contract must also be included on line 7 of the DD254 and must possess the applicable security clearance level to the work that they will execute under this contract. The Government assumes costs and conducts security investigations for security clearances. The contractor shall request security clearances for personnel requiring access to classified information within 15 calendar days after service award.

Due to costs involved with security investigations, requests for contractor security clearances shall be kept to an absolute minimum necessary to perform service requirements. The contractor shall submit a Visit Request to the appropriate security office before arriving at a Government facility. The contractor shall retrieve all identification media, including vehicle decals, from employees who depart for any reason before the contract expires; e.g., terminated for cause, retirement.

2.11. Common Access Card (CAC)

Each contract employee will be issued a CAC by the Government. The CAC shall be returned by the contract employee to the issuing office upon termination of employment, reassigned outside of this contract, or at the expiration of this contract. Each contract employee shall wear the CAC such that it is readily visible at all times during contract performance at official duty station. The CAC shall not be displayed while away from the official duty station or be left visible in a vehicle.

2.11.1. Contractors who do not require CAC, but require access to a DoD facility or installation Contractor and all associated sub-contractors employees shall comply with adjudication standards and procedures using the National Crime Information Center Interstate Identification Index (NCIC-III) and Terrorist Screening Database (TSDB) (Army Directive 2014-05 / AR 190-13), applicable installation, facility and area commander installation/facility access and local security policies and procedures (provided by government representative, as NCIC and TSDB are available), or, at OCONUS locations, in accordance with status of forces agreements and other theater regulations.

2.12. Travel

The Government may require the contractor to travel to military and non-military locations in support of these requirements. Some travel may support crisis actions/operations. Travel must be approved by the COR and/or PCO and a modification to the contract issued before a trip is begun. If prior Government approval is not obtained, the contractor shall not be reimbursed.

The contractor will not be reimbursed for travel in their local area.

2.12.1. Travel Approval

A contractor-generated travel authorization request form shall be submitted to the COR and/or PCO for approval prior to beginning any travel. The travel request shall, at a minimum, include:

- Traveler(s) name(s)

- Travel dates, inclusive

- Travel location(s)

- Purpose of trip

- Itemized list of expenses to include lodging, lodging tax, meals and incidental expenses

(per diem), transportation costs, tolls, parking, and any other allowable expenses in accordance with FAR 31.205-46.

- Proof of Airfare cost, if applicable

- Proof of Rental car cost, if applicable

- Other information as required by the COR and/or PCO.

All travel requests must be submitted to the COR and/or PCO fifteen (15) calendar days prior to the date of travel, if the need to travel is known and anticipated. Regardless, the contractor shall submit requests with sufficient time for Government review and approval. The PCO will review the contractor request and upon approval, the PCO will execute a modification to the contract for the contractor travel event.

2.12.2. Travel Reimbursement

Travel costs will be reimbursed according to the modification amount agreed to by the contractor and the Government. Travel costs will be set at the allowable rates and in accordance with FAR 31.205-46. Profit shall not be applied to nor allowed on travel costs. Travel shall be in compliance with the contract tasks and all other applicable requirements, and maximum use is to be made of the lowest available customary standard coach or equivalent airfare accommodations available during normal business hours. The Government is not liable for any travel costs that were not pre-approved on the agreed to modification. Minimal overage of costs on prior approved expenses will be paid on a case by case basis. Any overage that is known or realized by the contractor employee shall be immediately communicated to the COR and/or PCO to ensure adequate funding is available for reimbursement. Any increase in costs due to additional temporary duty days (only at the request or direction of the Government) will require prior authorization and further modification. Contractor shall submit all receipts for travel to substantiate their travel reimbursement request.

2.12.3. Trip Reports

The contractor shall deliver a trip report no later than five (5) business days after completion of travel. A trip report shall include the traveler(s) name(s), travel date(s), travel location(s), reason for travel, actions items resolved during travel, and actions still pending resolution. The contractor shall submit the trip report to the COR and PCO and provide a copy of the report with its travel reimbursement request. Contractor format is acceptable.

2.13. Training

The Government may require the contractor to attend courses to acquire knowledge of hardware or software added to Government DoD networks. If travel is involved, that must be approved separately in accordance with PWS 2. “Travel.” Training must be approved by the COR and/or PCO before a course is begun. If prior Government approval is not obtained, the contractor shall not be reimbursed. The contractor will not be reimbursed for formal educational training or general commercial hardware/software system training, or to meet the requirements of 4.1.11.

2.13.1. Training Approval

A contractor-generated training authorization request form shall be submitted to the COR and/or PCO for approval prior to beginning any course. The contractor shall ensure that the requested training costs will not exceed the amount authorized in this order. The training request shall, at a minimum, include:

- Employee(s) name(s)

- Course dates, inclusive

- Course description

- Purpose of training

- Expenses for course registration

- Other information as required by the COR and/or PCO. The COR is authorized to approve training requests.

All training requests must be submitted to the COR and/or PCO thirty (30) calendar days prior to the date the course is scheduled to begin. The PCO will review the contractor request and upon approval, the PCO will execute a firm fixed price modification to the contract for the contractor training event.

2.13.2. Training Reimbursements

Training costs will be reimbursed according to the firm fixed price modification amount agreed to by the contractor and the Government. The Government is not liable for any training costs that were not pre-approved or exceed the funded ceiling amount of the negotiated modification to the contract for the contractor training event. Proof of completion of the training will be required to be submitted with the training reimbursement request.

2.14. Key Personnel

Key personnel are deemed critical to successful performance of the requirements. Any position identified as key shall remain so for the duration of this task order.

The contractor shall, for the term of this task order, not make key personnel substitutions or additions unless necessitated by compelling reasons including, but not limited to: an individual’s illness, death, termination of employment, declining an offer of employment (for those individuals proposed as contingent hires), family friendly leave, or unavailability for any other reason. In such an event, prior to the substitution or addition of key personnel, the contractor shall submit a request of approval to the COR in writing, with approval coming from the PCO. All proposed substitutes (no matter when they are proposed during the performance period) shall have qualifications that are equal to or higher than the qualifications of the person being replaced.

If the PCO determines that suitable and timely replacement of key personnel who have been reassigned, terminated, or have otherwise become unavailable to perform under this task order is not reasonably forthcoming or that the resultant reduction of productive effort would impair the successful performance of the contract requirements, the contract may be terminated by the PCO for default or for the convenience of the Government, as appropriate.

Key Personnel and the related requirements of each are identified in the following subsections:

2.14.1. Program Manager

- Possess at least a Bachelor’s degree in computer science, information systems, cybersecurity, or other related discipline

- Shall have 10 years IT or cybersecurity related experience

- Shall have at least 5 years of program/project manager experience

2.14.2. Lead Detect Analyst(s)

- Shall have at least 5 years intrusion detection experience

- Shall be DoD 8570 compliant with CSSP-A or CSSP-IR requirements

- Shall have additional experience in security or network technology (Unix/Windows OS, Cisco/Juniper routing/switching) within a hands-on implementation or administration role

- Shall demonstrate thorough knowledge of Transmission Control Protocol/Internet Protocol (TCP/IP) protocol implementations for all common network services in addition to demonstrated capability to perform network packet analysis and anomaly detection

2.14.3. Detect Shift Leads

- Shall have at least 5 years experience handling cyber and security incidents (NIST SP 800-641)

- Shall have experience correlating cyber defense trends and reporting

- Shall be DoD 8570 compliant with CSSP-A or CSSP-IR requirements

- Shall have additional experience in security or network technology (Unix/Windows OS, Cisco/Juniper routing/switching) within a hands-on implementation or administration role

- Shall demonstrate thorough knowledge of TCP/IP protocol implementations for all common network services in addition to demonstrated capability to perform network packet analysis and anomaly detection

2.14.4. Lead Protect Analyst

- Shall have at least 5 years ISCM, insider threat, and/or protect services (e.g., Endpoint System Security

(ESS), Assured Compliance Assessment Solution (ACAS), Automated Continuous Endpoint Monitoring (ACEM)) experience

- Shall be DoD 8570 compliant with CSSP-A or CSSP-IR requirements

- Shall have additional experience in Windows and/or Linux management and support within a hands-on implementation or administration role

- Shall demonstrate thorough knowledge of TCP/IP protocol implementations for all common network services in addition to demonstrated capability to perform network packet analysis and anomaly detection

2.14.5. Lead Systems Engineer

- Shall have at least 5 years Network and Systems Engineering experience

- Shall be DoD 8570 compliant with CSSP-IS requirements

- Shall have additional experience in Windows and/or Linux management and support within a hands-on implementation or administration role

- Shall demonstrate thorough knowledge of TCP/IP protocol implementations for all common network services in addition to demonstrated capability to perform network packet analysis and anomaly detection

2.15. Surge

Surge is additional effort that is required to support these requirements due to events that are short-notice, emerging, or rapidly changing. This is typically planned, but may be unplanned to provide a higher level of support during some periods of time. Surge will be separately priced from the baseline requirements of this PWS.

2.15.1. Surge Approval

Surge must be approved by the COR and/or PCO before performance is begun, even if the event is unplanned. The Government will not pay for any surge work that is performed without prior approval or initiated by the Government.

Upon request by the Government, the Contractor shall submit a proposal to the COR and/or PCO detailing the level of effort and costs needed to support the surge event requirements of the Government. These surge requirements can either be planned or unplanned, as identified by the Government. Utilizing the firm fixed price surge labor rates of the contract, the PCO will review, negotiate and approve the contractor submitted proposal and execute a firm fixed price contract modification for the surge event. The contractor shall ensure that the approvedsurge costs will not exceed the amount of funding available on the firm fixed price modification. Only additional surge requirements initiated by the Government shall warrant a further increase to the overall cost of the surge event. In that case, the PCO will initiate a further firm fixed price modification for those additional requirements.

Contractor format is acceptable, but a surge proposal shall, at a minimum, include:

- Date of proposal

- Overview of PWS/Surge Requirements

- Employee name(s)

- Labor category(ies)

- Pre-negotiated surge labor rate(s) (Firm Fixed Price Contract Labor Rates)

- Number of surge labor hours

- Total cost of labor for each employee and total overall cost

- Estimated date/time period for the surge support

- Other information as required by the COR

2.15.2. Surge Reimbursement

The contractor shall prepare a cost breakdown of the surge performed during a billing period, to be submitted with their invoice, which shall include:

- Service period dates (from/to)

- Associated approved surge authorization (Contract Modification Number)

Charges – broken out by duty title(s), labor category(ies), employee name(s), approved hourly labor rate(s), and hours worked

3. Scope of Work

3.1. Program Manager

The Program Manager shall:

- Be onsite during core working hours (Situational telework must be approved by the Government). For non-core hours, the Program Manager shall respond to the Government within thirty (30) minutes of being contacted by the Government.

- Serve as the primary POC for the contract to the Government

- Collect project data in support of HPCMP CSSP reporting, orders, and tasks

- Apply their management skills and specialized functional and technical expertise to guide project teams in delivering CSSP solutions and assist in managing the day-to-day operations.

- Monitor quality across teams

- Establish and maintain technical and financial reports to show progress of task activities to the

Government, organizes and assigns responsibilities to subordinates, and oversees the assigned tasks

- Plan project resources by developing shift schedules, monitoring analyst and staff workloads, and ensuring that performance aligns to the Government’s goals and objectives for providing CSSP services

- Ensure that responsibilities and workloads are properly and evenly distributed throughout all CSSP locations to ensure shared understanding and load amongst the team

- Ensure that all personnel are appropriately trained and cleared to their respective position.

- Communicate any resource constraints, as well as staffing levels and issues with workload to the

Government regularly, timely, and formally through the monthly report

- Be intimately aware of all personnel’s job duties and expectations

- Proactively communicate any foreseen issues in performance, scheduling, and any needed changes in processes or training

- Provide operational and logistical services, as well as recommend updates to project information. This includes participation in project reviews, and the development of formal presentations and information papers

- Support the quarterly CSSP Quality Assurance (QA) process and Weekly Director’s Update Briefing by providing metrics in support of CSSP performance

- Prepare presentations, reports, and maximizing schedule efficiencies based on information provided about subscriber systems to be evaluated to include system specifications and appropriate skill sets

- Be responsible for preparing and coordinating for DoD evaluation and inspection activities, including taking steps to ensure all gaps are addressed in a timely manner prior to and after the evaluation or inspection activity.

- Ensure that all key performance indicator (KPI) targets are being achieved through the QA process

- Coordinate the gathering of periodic status reports/communications to stakeholders on major incidents, other priority incidents and issues through the bimonthly subscriber briefing and other ad hoc report requests

- Provide weekly communication to management on issues, risks, accomplishments, MOA breaches, and KPIs

- Communicate status updates to executive leadership

- Continuously identify, document, and present opportunities of improvements to the Government

- Implement best practices and approved improvements

3.1.1. Personnel Management

Personnel performing cybersecurity functions must be properly trained and equipped in order to maximize effectiveness. The staff must also be sufficiently manned to effectively provide services to their subscribers.

The contractor shall:

- Assist the organization in monitoring training and staffing requirements of Government and Contractor employees to remain fully capable

- With the input and approval of the Government, develop and maintain a documented workforce plan, including both Government and Contractor employees, to include: documented position descriptions for all staff, level of effort, listing of functional roles and responsibilities, required security clearance, investigative, and access requirements, system privilege level requirements, training and certification requirements

- Update the formal workforce plan annually and as needed to sustain current operations

- Verify staff have completed formal screening, are fully qualified IAW DoD Guidance, and are cleared to the appropriate security clearance level as identified in the formal Workforce Plan

- With the input and approval of the Government, develop and maintain a formal training program for the

Contractor

- Document and maintain all training records (e.g., class roster, database (DB), training records, etc.)

related to for all staff. Training program should ensure include requirements IAW DoD 8570/8140 and any other training required by organization. Training program should include all software/hardware cybersecurity tools, products, and organizational cybersecurity Standard Operating Procedures/ Techniques, Tactics, Procedures (SOPs/TTPs) required for use by staff

3.1.2. On-Call Support

The contractor shall provide on-call support during non-core hours.

Support shall consist of normal duties during non-core hours in the event of a cybersecurity event, named operation, or other activity requiring urgent actions.

3.2. Detect Services

Detect services include attack sensing and warning (AS&W) and cyber incident handling. Detect is the collection, normalization, correlation, and characterization of event and incident data to identify anomalous or unauthorized activity, including cyber intrusions, attacks, data loss, or other prohibited activities (pornography, gambling, etc.)

coupled with the notification to command and control, following established guidance for response, and coordinating or escalating with subscribers and higher command. This data comes from all available sources including but not limited to: sensor logs and data, device logs, security application logs, Host Based Security System (HBSS) data, incident tickets, archives, etc. The contractor shall perform this requirement continually on a 24/7/365 basis.

The contractor shall consider the paradigm shift of performing these services for DODIN on premise assets, as well as, DODIN assets that reside in commercial cloud instances. The contractor shall utilize on premise, Government-provided Defensive Cyber Operations (DCO) capabilities, as well as cloud-native DCO capabilities within the cloud.

The CSSP service is designed to protect against, defend, and respond to suspicious or malicious cyber activity associated with network traffic entering or exiting the HPCMP Virtual Private Cloud (VPC) Secure Cloud Computing architecture (SCCA).

Review Time: Critical and high alerts shall be reviewed within fifteen (15) minutes of entering the security information and event management (SIEM) tool. Medium alerts shall be reviewed within forty-five (45) minutes of entering the SIEM. Low alerts shall be reviewed within one (1) hour of entering the SIEM. The contractor shall review 95% of alerts within their associated timelines.

Response Time: Critical and high alerts shall be reviewed and adjudicated within thirty (30) minutes of entering the SIEM. Medium alerts shall be reviewed and adjudicated within ninety (90) minutes of entering the SIEM and low alerts shall be reviewed and adjudicated within twelve (12) hours of entering the SIEM.

In support of these activities, the contractor shall:

- Review/analyze the correlated data from the provided Security Event and Incident Management (SEIM) system. This data comes from a variety of sources (host logs, host based security logs, vulnerability data, network intrusion detection logs, web content filtering, web application firewalls, firewalls, network devices, DNS logs, file hashes, behavioral analytics, indicators of compromise (IOCs), etc.);

- Use correlated data analysis to identify unauthorized activity, evaluate the likelihood of success of the activity based on available information (utilizing ISCM data and knowledge of attack/vulnerability targets), and create incident response tickets for investigation by Incident Responders within reporting timelines outlined in CJCSM 6510.01B;

- Ensure that reports are peer-reviewed and less than 10% of reports are rejected due to error.

- Utilize the Unified Kill Chain model during incident analysis activities to recommend appropriate countermeasures (Detect, Deny, Disrupt, Deceive, etc.) across all layers of the defense-in-depth model to effect all phases of the attack;

- Report all appropriate incidents and events to JIMS or other designated platform within required timelines based on CJCSM 6510.01B requirements;

- Pass the Joint Qualification Requirement (JQR) test and onboarding process within 90 days of assignment;

- Follow Joint Force Headquarters – Department of Defense Information Network (JFHQ-DODIN) guidelines for reporting significant activity (SIGACT), or issuing notifications (e.g., ‘TIPPERs’) to other CSSPs or Area of Operation Commander/Directors when activity is detected;

- Monitor for effectiveness of identified countermeasures, a process generally referred to as Active Cyber Defense Cycle;

- Provide Incident Response, evaluating the efficacy of containment and eradication of intrusions;

- Summarize and categorize security events (notifications, attacks, Trojans, command and control, exploits, etc.) for all DREN/SDREN by subscriber, notifying increases in activity/categories for DREN/SDREN or individual subscribers;

- Monitor log collection/pipeline processing from all sources of sensors/correlated data and immediately notify CSSP Infrastructure when reporting has not occurred in more than 2 hours and has not been previously reported as an outage;

- Identify gaps in coverage or visibility necessary to identify if a possible intrusion has occurred and recommend corrective action to the Government.

- Follow procedures that are IAW NIST SP 800-61 and DOD M-6510.01 Volume I/CJCSM 6510.01B, for the handling of incidents

- Collect intrusion artifacts (e.g., source code, malware, and trojans) and use discovered data to enable mitigation of potential Computer Network Defense incidents within the enterprise

- Correlate incident data to identify specific vulnerabilities and make recommendations that enable expeditious remediation

- Report incidents and events within proper channels and within timelines identified in the CJCSM 6510.01B

- Identify, document, and report unauthorized activity/attacks (including IP addresses and ports, attack vector, and attack timeframe) in all incidents and reports per HPCMP CSSP SOPs

- Take action, if appropriate, to prevent or mitigate potential impact to the DODIN based on cyber threats, and develop and distribute countermeasures and interim guidance to prevent or mitigate threats and/or attacks on DODIN

- Monitor a platform capable of performing information security continuous monitoring (ISCM) for the purposes of detecting cyber intrusions, attacks, anomalous behavior, and possible insider threats.

- Provide a 24/7/365 event/incident handling and analysis capability

- Provide detailed information regarding the event IAW CJCSM 6510.01B

- Provide operations log accessible to personnel documenting all mandated reportable cyber events/incidents

- Analyze detected cyber events to identify incidents

- Categorize and characterize cyber incidents

- Ensure JFHQ-DoDIN and other DOD CSSPs have visibility and insight into detected cyber incidents and cyber incident response actions complete with Course of Action and implementation via the Joint Incident Management System (JIMS), SIGACTs, and tippers

- Ensure proper reporting of incidents requiring Security, Law Enforcement and/or Counter Intelligence (LE/CI) involvement

- Notify affected Subscribers of cyber incidents and collect assessments of mission impact for the loss of the system during the incident response process

- Provide initial response to cyber incidents per HPCMP CSSP SOPs

- Take initial steps to contain cyber incidents

- Ensure forensically sound acquisition and preservation of incident data

- Support Subscriber’s actions in incident response by assisting with cyber component reporting, coordinating countermeasure deployment, and maintaining the subscriber personnel escalation process and up-to-date rosters

- Analyze cyber incidents to develop specific responses

- Develop and implement comprehensive cyber incident process

- Distribute tailored countermeasures or interim guidance to Subscribers to eradicate and prevent cyber incidents across all subscribers

- Perform forensic analysis of systems and malware in cases where subscribers lack the capability and ensure relevant IOCs are shared with Warning Intelligence

- Mitigate operational and/or technical impact due to cyber incidents

- Contain the spread of malware to prevent further damage to IT systems through detection, analysis, and execution of containment measures

- Work to remove incident root causes through data preservation and guiding subscribers in system rebuilds/system functionality restoration

- Assist Subscribers with cyber incident mitigation efforts

- Manage subscriber accounts in Incident Response Tracker (IRT) to include new accounts, modification, and deactivations

- Assist with research and data validation in support of the battle station reporting requirements

- Prepare documentation and coordinate activities associated with DoD evaluation and inspection activities.

Based on historical data, the Government anticipates the following activities within a given work week, with a variation of +/- 10%.

- Alert Volume: 4 critical / 3,000 high / 52,000 medium / 60,000 low

- Incident and Event Reports Filed: 13

- Countermeasures Implemented: 15

- Basic Indicators of Compromise (IPs, domains, etc.) added to SEIM: 1,200

- New Detection Logic (code based detection) added to SIEM: 2

3.2.1. Lead Detect…

This is the start of the file's text. The full file is on GovTribe.

File details come from the government source that posted it. Updated .